Skip to main content

JN0-334 Real Exam Questions

Security, Specialist (JNCIS-SEC)

90 questions available · Page 1 of 9

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

A routing change occurs on an SRX Series device that involves choosing a new egress interface.

In this scenario, which statement is true for all affected current sessions?

  1. A

    The current session are torn down only if the policy-rematch option has been enabled.

  2. B

    The current sessions do not change.

  3. C

    The current sessions are torn down and go through first path processing based on the new route.

  4. D

    The current sessions might change based on the corresponding security policy.

Show answer and explanation

Correct answer: C

Question 2 Multiple choice

Which two statements describe JSA? (Choose two.)

  1. A

    Security Director must be used to view third-party events rom JSA flow collectors.

  2. B

    JSA supports events and flows from Junos devices, including third-party devices.

  3. C

    JSA events must be manually imported into Security Directory using an SSH connection.

  4. D

    JSA can be used as a log node with Security Director or as a standalone solution.

Show answer and explanation

Correct answers: B, D

Question 3 Multiple choice

You must deploy AppSecure in your network to block risky applications.

In this scenario, which two AppSecure features are required? (Choose two.)

  1. A

    AppFW

  2. B

    AppID

  3. C

    APBR

  4. D

    AppTrack

Show answer and explanation

Correct answers: B, D

Question 4 Multiple choice

Which two statements describe superflows in Juniper Secure Analytics? (Choose two.)

  1. A

    JSA only supports Type A and Type C superflows.

  2. B

    Superflows can negatively impact licensing limitations.

  3. C

    Disk space usage is reduced on the JSA device.

  4. D

    Superflows combine many flows into a single flow.

Show answer and explanation

Correct answers: C, D

Question 5 Single choice

After a software upgrade on an SRX5800 chassis cluster, you notice that both node0 and node1 are in the primary state, when node1 should be secondary. All control and fabric links are operating normally.

In this scenario, which step must you perform to recover the cluster?

  1. A

    Execute the request system reboot command on node1.

  2. B

    Execute the request system software rollback command on node0.

  3. C

    Execute the request system software add command on node1.

  4. D

    Execute the request system reboot command on node0.

Show answer and explanation

Correct answer: A

Question 6 Single choice

Where is AppSecure executed in the flow process on an SRX Series device?

  1. A

    screens

  2. B

    security policy

  3. C

    zones

  4. D

    services

Show answer and explanation

Correct answer: D

Question 7 Single choice

What is the default session timeout value for ICMP and UDP traffic?

  1. A

    30 seconds

  2. B

    30 minutes

  3. C

    60 seconds

  4. D

    5 minutes

Show answer and explanation

Correct answer: C

Question 8 Multiple choice

You want to deploy vSRX in Amazon Web Services (AWS) virtual private clouds (VPCs).

Which two statements are true in this scenario? (Choose two.)

  1. A

    The vSRX devices serving as local enforcement points for VPCs can be managed by a centralized

    Junos Space Network Director instance.

  2. B

    MPLS LSPs can be used to connect vSRXs in different VPCs.

  3. C

    IPsec tunnels can be used to connect vSRX in different VPCs.

  4. D

    The vSRX devices serving as local enforcement points for VPCs can be managed by a centralized

    Junos Space Security Director instance.

Show answer and explanation

Correct answers: C, D

Question 9 Multiple choice

Click the Exhibit button.

Which two statements are true about the session shown in the exhibit? (Choose two.)

  1. A

    Two security policies are required for bidirectional traffic flow.

  2. B

    The ALG was enabled by manual configuration.

  3. C

    The ALG was enabled by default.

  4. D

    One security policy is required for bidirectional traffic flow.

Show answer and explanation

Correct answers: A, B

Question 10 Single choice

Click the Exhibit button.

Referring to the exhibit, which statement is true?

  1. A

    Hosts are always able to communicate through the SRX Series device no matter the threat score

    assigned to them on the infected host feed.

  2. B

    Hosts are unable to communicate through the SRX Series device after being placed on the infected

    host feed with a high enough threat score.

  3. C

    Malicious HTTP file downloads are never blocked.

  4. D

    Malicious HTTP file downloads are always blocked.

Show answer and explanation

Correct answer: B