Verified & Latest JN0-636 Dump Q&As with Correct Answers [Q49-Q65]

Share

Verified & Latest JN0-636 Dump Q&As with Correct Answers

Latest JN0-636 dumps - Instant Download PDF


Juniper JN0-636 exam is designed for professionals who are already working in the security domain and want to enhance their skills and credibility. JN0-636 exam is suitable for security professionals who have experience in configuring and managing Juniper security technologies. JN0-636 exam is also suitable for professionals who wish to validate their knowledge and skills in Juniper security technologies. Juniper's JNCIP-SEC certification is one of the most respected certifications in the security industry, and passing the JN0-636 exam is an essential step towards achieving this certification.


The JN0-636 Certification Exam is meant for security professionals who have a thorough understanding of Juniper Networks’ security features and solutions. JN0-636 exam covers a broad range of topics, including security policies, firewall filters, VPNs, intrusion prevention, and security management. The JN0-636 exam is an advanced-level certification exam that is aimed at professionals who have a minimum of three years of experience in the field.

 

NEW QUESTION # 49
A hub member of an ADVPN is not functioning correctly.

Referring the exhibit, which action should you take to solve the problem?

  • A. [edit interfaces]
    root@vSRX-1# delete st0.0 multipoint
  • B. [edit security]
    user@hub-1# delete ike gateway advpn-gateway advpn partner
  • C. [edit interfaces]
    user@hub-1# delete ipsec vpn advpn-vpn traffic-selector
  • D. [edit security]
    user@hub-1# set ike gateway advpn-gateway advpn suggester disable

Answer: C


NEW QUESTION # 50
Exhibit

You are not able to ping the default gateway of 192.168 100 1 (or your network that is located on your SRX Series firewall.
Referring to the exhibit, which two commands would correct the configuration of your SRX Series device? (Choose two.) A)

B)

C)

D)

  • A. Option A
  • B. Option C
  • C. Option D
  • D. Option B

Answer: B


NEW QUESTION # 51
You are asked to implement the AppFW feature on an SRX Series device.
Which three tasks must be performed to make the feature work? (Choose three.)

  • A. Configure a firewall filter that includes the application-firewall policy.
  • B. Install an AppSecure license.
  • C. Configure a security policy that includes the application-firewall policy.
  • D. Configure an application-firewall policy.
  • E. Install an IPS license.

Answer: B,C,D


NEW QUESTION # 52
You are asked to share threat intelligence from your environment with third party tools so that those tools can be identify and block lateral threat propagation from compromised hosts.
Which two steps accomplish this goal? (Choose Two)

  • A. Enable SRX Series firewalls to share Threat intelligence with third party tool.
  • B. Configure application tokens in the Juniper ATP Cloud to limit who has access
  • C. Enable Juniper ATP Cloud to share threat intelligence
  • D. Configure application tokens in the SRX Series firewalls to limit who has access

Answer: B,C

Explanation:
To share threat intelligence from your environment with third party tools, you need to enable Juniper ATP Cloud to share threat intelligence and configure application tokens in the Juniper ATP Cloud to limit who has access. The other options are incorrect because:
A) Configuring application tokens in the SRX Series firewalls is not necessary or sufficient to share threat intelligence with third party tools. Application tokens are used to authenticate and authorize requests to the Juniper ATP Cloud API, which can be used to perform various operations such as submitting files, querying C&C feeds, and managing allowlists and blocklists1. However, to share threat intelligence with third party tools, you need to enable the TAXII service in the Juniper ATP Cloud, which is a different protocol for exchanging threat information2.
D) Enabling SRX Series firewalls to share threat intelligence with third party tools is not possible or supported. SRX Series firewalls can send potentially malicious objects and files to the Juniper ATP Cloud for analysis and receive threat intelligence from the Juniper ATP Cloud to block malicious traffic3. However, SRX Series firewalls cannot directly share threat intelligence with third party tools. You need to use the Juniper ATP Cloud as the intermediary for threat intelligence sharing.
Therefore, the correct answer is B and C. You need to enable Juniper ATP Cloud to share threat intelligence and configure application tokens in the Juniper ATP Cloud to limit who has access. To do so, you need to perform the following steps:
Enable and configure the TAXII service in the Juniper ATP Cloud. TAXII (Trusted Automated eXchange of Indicator Information) is a protocol for communication over HTTPS of threat information between parties. STIX (Structured Threat Information eXpression) is a language used for reporting and sharing threat information using TAXII. Juniper ATP Cloud can contribute to STIX reports by sharing the threat intelligence it gathers from file scanning. Juniper ATP Cloud also uses threat information from STIX reports as well as other sources for threat prevention2. To enable and configure the TAXII service, you need to select Configure > Threat Intelligence Sharing in the Juniper ATP Cloud WebUI, move the knob to the right to Enable TAXII, and move the slidebar to designate a file sharing threshold2.
Configure application tokens in the Juniper ATP Cloud. Application tokens are used to authenticate and authorize requests to the Juniper ATP Cloud API and the TAXII service. You can create and manage application tokens in the Juniper ATP Cloud WebUI by selecting Configure > Application Tokens. You can specify the name, description, expiration date, and permissions of each token. You can also revoke or delete tokens as needed. You can use the application tokens to limit who has access to your shared threat intelligence by granting or denying permissions to the TAXII service1.
Reference:
Threat Intelligence Open API Setup Guide
Configure Threat Intelligence Sharing
About Juniper Advanced Threat Prevention Cloud


NEW QUESTION # 53
Exhibit

Referring to the exhibit, which two statements are true? (Choose two.)

  • A. You can only use the Proxy_Node3 feed as the destination-address match criteria of another security policy on a different SRX Series device.
  • B. The SRX-1 device can use the Proxy__Nodes feed in another security policy.
  • C. You can use the Proxy_Nodes feed as the source-address and destination-address match criteria of another security policy on a different SRX Series device.
  • D. The SRX-1 device creates the Proxy_wodes feed, so it cannot use it in another security policy.

Answer: B,D


NEW QUESTION # 54
Exhibit

You configure Source NAT using a pool of addresses that are in the same subnet range as the external ge-0/0/0 interface on your vSRX device. Traffic that is exiting the internal network can reach external destinations, but the return traffic is being dropped by the service provider router.
Referring to the exhibit, what must be enabled on the vSRX device to solve this problem?

  • A. DNS Doctoring
  • B. Persistent NAT
  • C. Proxy ARP
  • D. STUN

Answer: C

Explanation:
Proxy ARP is a technique used by routers to answer ARP requests on one network segment on behalf of hosts on another network segment. This is useful in situations where a host on one network segment needs to communicate with a host on another network segment, but the two hosts are not directly connected. In this case, the router acts as a proxy, answering ARP requests on behalf of the other host. In the exhibit, the vSRX device is configured to use a pool of addresses that are in the same subnet as the external interface ge-0/0/0 for source NAT. This means that the vSRX device will translate the source IP address of the internal hosts to one of the addresses in the pool before sending the packets to the external network. However, the external hosts will not know how to reach the NATed addresses, since they are not directly connected to the vSRX device. They will send ARP requests for the NATed addresses, expecting to receive a MAC address from the vSRX device. If proxy ARP is not enabled on the vSRX device, it will not respond to these ARP requests, since it does not have the NATed addresses configured on its interface. The ARP requests will time out and the packets will be dropped by the external hosts or the service provider router. To solve this problem, proxy ARP must be enabled on the vSRX device for the NATed addresses. This will allow the vSRX device to respond to the ARP requests from the external hosts, providing its own MAC address as the destination. The external hosts will then send the packets to the vSRX device, which will reverse the NAT and forward the packets to the internal hosts. Reference:
Configuring Proxy ARP (CLI Procedure)
[SRX] When and how to configure Proxy ARP (https://supportportal.juniper.net/s/article/SRX-Dynamic-VPN-scenario-for-configuring-Proxy-ARP-on-SRX?language=en_US)


NEW QUESTION # 55
Exhibit

You are using ATP Cloud and notice that there is a host with a high number of ETI and C&C hits sourced from the same investigation and notice that some of the events have not been automatically mitigated.
Referring to the exhibit, what is a reason for this behavior?

  • A. The C&C events are false positives.
  • B. The infected host score is globally set above a threat level of 5.
  • C. The ETI events are false positives.
  • D. The infected host score is globally set bellow a threat level of 5.

Answer: B

Explanation:
According to the Juniper documentation, the infected host score is a global setting that determines the minimum threat level required for a host to be considered infected and blocked by Juniper ATP Cloud. The infected host score can be configured from 1 to 10, where 1 is the lowest and 10 is the highest. The default infected host score is 5, which means that any host with a threat level of 5 or higher will be automatically blocked by Juniper ATP Cloud. However, the infected host score can be changed to a higher value, such as 6 or 7, to reduce the number of false positives and allow more traffic to pass through. In the exhibit, the host has a threat level of 5, which indicates that it is infected with malware and has attempted to contact command-and-control servers. However, some of the events have not been automatically mitigated, which means that the host has not been blocked by Juniper ATP Cloud. A possible reason for this behavior is that the infected host score is globally set above a threat level of 5, such as 6 or 7, which means that the host does not meet the minimum threshold for blocking. Therefore, the correct answer is C. The infected host score is globally set above a threat level of 5. Reference: [Configuring the Infected Host Score] 1, [Compromised Hosts: More Information] 2
1: https://www.juniper.net/documentation/us/en/software/sky-atp/atp-cloud-user-guide/topics/task/sky-atp-infected-host-score.html 2: https://www.juniper.net/documentation/us/en/software/sky-atp/atp-cloud-user-guide/topics/concept/sky-atp-infected-host-overview.html


NEW QUESTION # 56
you configured a security policy permitting traffic from the trust zone to the untrust zone but your traffic not hitting the policy.
In this scenario, which cli command allows you to troubleshoot traffic problem using the match criteria?

  • A. show security application-tracking counters
  • B. show security match-policies
  • C. show security policy-report
  • D. request security policies check

Answer: B

Explanation:
To troubleshoot the traffic problem using the match criteria, you need to use the show security match-policies CLI command. The other options are incorrect because:
A) The show security policy-report CLI command displays the policy report, which is a summary of the policy usage statistics, such as the number of sessions, bytes, and packets that match each policy. It does not show the match criteria or the reason why the traffic is not hitting the policy1.
B) The show security application-tracking counters CLI command displays the application tracking counters, which are the statistics of the application usage, such as the number of sessions, bytes, and packets that match each application. It does not show the match criteria or the reason why the traffic is not hitting the policy2.
D) The request security policies check CLI command checks the validity and consistency of the security policies, such as the syntax, the references, and the conflicts. It does not show the match criteria or the reason why the traffic is not hitting the policy3.
Therefore, the correct answer is C. You need to use the show security match-policies CLI command to troubleshoot the traffic problem using the match criteria. The show security match-policies CLI command displays the policies that match the specified criteria, such as the source and destination addresses, the zones, the protocols, and the ports. It also shows the action and the hit count of each matching policy. You can use this command to verify if the traffic is matching the expected policy or not, and if not, what policy is blocking or rejecting the traffic4


NEW QUESTION # 57
Exhibit:
Referring to the exhibit, your company's infrastructure team implemented new printers To make sure that the policy enforcer pushes the updated Ip address list to the SRX.
Which three actions are required to complete the requirement? (Choose three )

  • A. Configure Security Director to create a C&C feed.
  • B. Configure Security Director to create a dynamic address feed
  • C. Configure server feed URL as https://172.25.10.254/myprinters.
  • D. Create a security policy that uses the dynamic address feed to allow access
  • E. Configure the server feed URL as http://172.25.10.254/myprinters

Answer: B,D,E

Explanation:
Referring to the exhibit, your company's infrastructure team implemented new printers. To make sure that the policy enforcer pushes the updated IP address list to the SRX, you need to perform the following actions:
A) Configure the server feed URL as http://172.25.10.254/myprinters. The server feed URL is the address of the remote server that provides the custom feed data. You need to configure the server feed URL to match the location of the file that contains the IP addresses of the new printers. In this case, the file name is myprinters and the server IP address is 172.25.10.254, so the server feed URL should be http://172.25.10.254/myprinters1.
B) Create a security policy that uses the dynamic address feed to allow access. A security policy is a rule that defines the action to be taken for the traffic that matches the specified criteria, such as source and destination addresses, zones, protocols, ports, and applications. You need to create a security policy that uses the dynamic address feed as the source or destination address to allow access to the new printers. A dynamic address feed is a custom feed that contains a group of IP addresses that can be entered manually or imported from external sources. The dynamic address feed can be used in security policies to either deny or allow traffic based on either source or destination IP criteria2.
C) Configure Security Director to create a dynamic address feed. Security Director is a Junos Space application that enables you to create and manage security policies and objects. You need to configure Security Director to create a dynamic address feed that contains the IP addresses of the new printers. You can create a dynamic address feed by using the local file or the remote file server option. In this case, you should use the remote file server option and specify the server feed URL as http://172.25.10.254/myprinters3.
The other options are incorrect because:
D) Configuring Security Director to create a C&C feed is not required to complete the requirement. A C&C feed is a security intelligence feed that contains the IP addresses of servers that are used by malware or attackers to communicate with infected hosts. The C&C feed is not related to the new printers or the dynamic address feed.
E) Configuring the server feed URL as https://172.25.10.254/myprinters is not required to complete the requirement. The server feed URL can use either the HTTP or the HTTPS protocol, depending on the configuration of the remote server. In this case, the exhibit shows that the remote server is using the HTTP protocol, so the server feed URL should use the same protocol1.
Reference:
Configuring the Server Feed URL
Dynamic Address Overview
Creating Custom Feeds
[Command and Control Feed Overview]


NEW QUESTION # 58
Exhibit:

Referring to the exhibit, the operator user is unable to save configuration files to a usb stick the is plugged into SRX. What should you do to solve this problem?

  • A. Add the interface-control permission flag to the operation class
  • B. Add the floppy permission flag to the operations class
  • C. Add the system-control permission flag to the operation class
  • D. Add the system permission flag to the operation class

Answer: C

Explanation:
To solve the problem of the operator user being unable to save configuration files to a USB stick that is plugged into SRX, you need to add the system-control permission flag to the operations class. The other options are incorrect because:
A) Adding the floppy permission flag to the operations class is not sufficient or necessary to save configuration files to a USB stick. The floppy permission flag allows the user to access the floppy drive, but not the USB drive. The USB drive is accessed by the system permission flag, which is already included in the operations class1.
C) Adding the interface-control permission flag to the operations class is also not sufficient or necessary to save configuration files to a USB stick. The interface-control permission flag allows the user to configure and monitor interfaces, but not to save configuration files. The configuration permission flag, which is also already included in the operations class, allows the user to save configuration files1.
D) Adding the system permission flag to the operations class is redundant and ineffective to save configuration files to a USB stick. The system permission flag allows the user to access the system directory, which includes the USB drive. However, the operations class already has the system permission flag by default1. The problem is not the lack of system permission, but the lack of system-control permission.
Therefore, the correct answer is B. You need to add the system-control permission flag to the operations class to solve the problem. The system-control permission flag allows the user to perform system-level operations, such as rebooting, halting, or snapshotting the device1. These operations are required to mount, unmount, and copy files to and from the USB drive2. To add the system-control permission flag to the operations class, you need to perform the following steps:
Enter the configuration mode: user@host> configure
Navigate to the system login class hierarchy: user@host# edit system login class operations Add the system-control permission flag: user@host# set permissions system-control Commit the changes: user@host# commit Reference:
login (System)
How to mount a USB drive on EX/SRX/MX/QFX Series platforms to import/export files


NEW QUESTION # 59
Which two modes are supported on Juniper ATP Cloud? (Choose two.)

  • A. transparent mode
  • B. private mode
  • C. Layer 3 mode
  • D. global mode

Answer: A,C

Explanation:
According to the Juniper documentation, Juniper ATP Cloud supports the following modes:
Layer 3 mode: In this mode, the SRX Series device acts as a Layer 3 gateway and routes traffic between different subnets. The SRX Series device performs NAT and security policy enforcement on the traffic and sends a copy of the traffic to Juniper ATP Cloud for analysis. This mode is suitable for networks that have multiple subnets and require NAT and firewall functions1 Transparent mode: In this mode, the SRX Series device acts as a Layer 2 bridge and forwards traffic between the same subnet. The SRX Series device does not perform NAT or security policy enforcement on the traffic, but sends a copy of the traffic to Juniper ATP Cloud for analysis. This mode is suitable for networks that have a single subnet and do not require NAT or firewall functions1 The other two modes, global mode and private mode, are not supported by Juniper ATP Cloud. Global mode is a configuration option for Juniper ATP Appliance, which is an on-premises solution that provides threat detection and prevention. Private mode is a configuration option for Juniper ATP Private Cloud, which is a cloud-based solution that provides threat detection and prevention within a private network23 Reference:
1: Juniper Advanced Threat Prevention Cloud | ATP Cloud | Juniper Networks 2: Juniper Advanced Threat Prevention Appliance | ATP Appliance | Juniper Networks 3: [Juniper Advanced Threat Prevention Private Cloud | ATP Private Cloud | Juniper Networks]


NEW QUESTION # 60
In Juniper ATP Cloud, what are two different actions available in a threat prevention policy to deal with an infected host? (Choose two.)

  • A. Drop the connection silently.
  • B. Send a custom message
  • C. Quarantine the host.
  • D. Close the connection.

Answer: A,C


NEW QUESTION # 61
You are connecting two remote sites to your corporate headquarters site.You must ensure that all traffic is secured and sent directly between sites In this scenario, which VPN should be used?

  • A. full mesh Layer 3 VPN with EBGP
  • B. IPsec ADVPN
  • C. Layer 2 VPN
  • D. hub-and-spoke IPsec VPN

Answer: D


NEW QUESTION # 62
Referring to the exhibit, which two statements are true? (Choose two.)

  • A. The c-1 TSYS has no reservation for the security flow resource.
  • B. The c-1 TSYS has a reservation for the security flow resource.
  • C. The c-1 TSYS can use security flow resources up to the system maximum.
  • D. The c-1 TSYS cannot use any security flow resources.

Answer: A,D


NEW QUESTION # 63
Exhibit

The exhibit shows a snippet of a security flow trace.
In this scenario, which two statements are correct? (Choose two.)

  • A. This packet arrived on interface ge-0/0/4.0.
  • B. The capture is a packet from the source address 172.20.101.10 destined to 10.0.1.129.
  • C. Destination NAT occurs.
  • D. An existing session is found in the table.

Answer: B,D


NEW QUESTION # 64
Click the Exhibit button.

You are asked to look at a configuration that is designed to take all traffic with a specific source IP address and forward the traffic to a traffic analysis server for further evaluation. The configuration is not working as intended.
Referring to the exhibit, which change must be made to correct the configuration?

  • A. Apply the filter as an output filter on interface xe-0/1/0.0
  • B. Create a routing instance named default
  • C. Apply the filter as an input filter on interface xe-0/0/1.0
  • D. Apply the filter as an input filter on interface xe-0/2/1.0

Answer: C


NEW QUESTION # 65
......

The Ultimate Juniper JN0-636 Dumps PDF Review: https://troytec.getvalidtest.com/JN0-636-brain-dumps.html