Skip to main content

JN0-335 Real Exam Questions

Security, Specialist (JNCIS-SEC)

98 questions available · Page 1 of 10

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Multiple choice

What are two types of system logs that Junos generates? (Choose two.)

  1. A

    SQL log files

  2. B

    data plane logs

  3. C

    system core dump files

  4. D

    control plane logs

Show answer and explanation

Correct answers: B, D

Explanation

The two types of system logs that Junos generates are control plane logs and data plane logs. Control plane logs are generated by the Junos operating system and contain system-level events such as system startup and shutdown, configuration changes, and system alarms. Data plane logs are generated by the network protocol processes and contain messages about the status of the network and its components, such as routing, firewall, NAT, and IPS. SQL log files and system core dump files are not types of system logs generated by Junos.

Question 2 Single choice

What information does encrypted traffic insights (ETI) use to notify SRX Series devices about known malware sites?

  1. A

    certificates

  2. B

    dynamic address groups

  3. C

    MAC addresses

  4. D

    domain names

Show answer and explanation

Correct answer: D

Explanation

Encrypted traffic insights (ETI) uses domain names to notify SRX Series devices about known malware sites. ETI is a feature of the SRX Series firewall that can detect and block malware that is hidden in encrypted traffic. It works by analyzing the domain names of the websites that the encrypted traffic is attempting to access. If the domain name matches a known malware site, ETI will send an alert to the SRX

Series device, which can then take appropriate action to block the traffic. ETI is a useful tool for protecting against threats that attempt to evade detection by hiding in encrypted traffic.

Question 3 Single choice

You enable chassis clustering on two devices and assign a cluster ID and a node ID to each device.

In this scenario, what is the correct order for rebooting the devices?

  1. A

    Reboot the secondary device, then the primary device.

  2. B

    Reboot only the secondary device since the primary will assign itself the correct cluster and node ID.

  3. C

    Reboot the primary device, then the secondary device.

  4. D

    Reboot only the primary device since the secondary will assign itself the correct cluster and node ID.

Show answer and explanation

Correct answer: C

Explanation

when enabling chassis clustering on two devices, the correct order for rebooting them is to reboot the primary device first, followed by the secondary device. It is not possible for either device to assign itself the correct cluster and node ID, so both devices must be rebooted to ensure the proper configuration is applied.

Question 4 Multiple choice

Which two features are configurable on Juniper Secure Analytics (JSA) to ensure that alerts are triggered when matching certain criteria? (Choose two.)

  1. A

    building blocks

  2. B

    assets

  3. C

    events

  4. D

    tests

Show answer and explanation

Correct answers: C, D

Explanation

The two configurable features on Juniper Secure Analytics (JSA) that can be used to ensure that alerts are triggered when matching certain criteria are events and tests. Events refer to the collection of data from different sources, while tests are used to define the criteria for which an alert is triggered. For example, you can use events to collect data from a firewall and tests to define criteria such as IP address, port number, and the type of traffic. The Security, Specialist (JNCIS-SEC) Study guide provides further information on how to configure these features on JSA.

Question 5 Single choice

Click the Exhibit button.

You have implemented SSL client protection proxy. Employees are receiving the error shown in the exhibit.

How do you solve this problem?

  1. A

    Load a known good, but expired. CA certificate onto the SRX Series device.

  2. B

    Install a new SRX Series device to act as the client proxy

  3. C

    Reboot the SRX Series device.

  4. D

    Import the existing certificate to each client device.

Show answer and explanation

Correct answer: D

Explanation

SSL client protection proxy is a feature that allows you to decrypt and inspect the SSL traffic from clients to servers. To do this, you need to install a certificate authority (CA) certificate on the SRX Series device and import the same certificate to each client device. This way, the SRX Series device can act as a proxy between the client and the server and perform security checks on the decrypted traffic. If the client device does not have the certificate installed, it will receive an error message like the one shown in the exhibit.
References:
JNCIS-SEC Certification, Open Learning - Security, Specialist (JNCIS-SEC), SSL Proxy
Configuration

Question 6 Multiple choice

Which two statements are true about application identification? (Choose two.)

  1. A

    Application identification can identity nested applications that are within Layer 7.

  2. B

    Application identification cannot identify nested applications that are within Layer 7.

  3. C

    Application signatures are the same as IDP signatures.

  4. D

    Application signatures are not the same as IDP signatures.

Show answer and explanation

Correct answers: A, D

Explanation

Application identification is a feature that enables SRX Series devices to identify and classify network traffic based on application signatures or custom rules. Application identification can enhance security, visibility, and control over network applications. Two statements that are true about application identification are: Application identification can identify nested applications that are within Layer 7: Nested applications are applications that run within another application protocol, such as HTTP or SSL.
For example, Facebook or YouTube are nested applications within HTTP. Application identification can identify nested applications by inspecting the application payload and matching it against predefined or custom signatures.
Application signatures are not the same as IDP signatures: Application signatures are patterns of bytes or strings that uniquely identify an application protocol or a nested application. IDP signatures are patterns of bytes or strings that indicate an attack or an exploit against a vulnerability. Application signatures are used for application identification and classification, while IDP signatures are used for intrusion detection and prevention.
References:
[Application Identification Overview], [Application Identification Concepts], [Understanding
Signature Rules and Protocol Anomaly Rules]

Question 7 Multiple choice

Which two statements are correct about a reth LAG? (Choose two.)

  1. A

    Links must have the same speed and duplex setting.

  2. B

    Links must use the same cable type

  3. C

    You must have a "minimum-links" statement value of two.

  4. D

    You should have two or more interfaces.

Show answer and explanation

Correct answers: A, D

Explanation

A reth LAG is a redundant Ethernet link aggregation group that combines multiple physical interfaces into a single logical interface in a chassis cluster. A reth LAG provides load balancing and redundancy for traffic within or between redundancy groups. Two statements that are correct about a reth LAG are: Links must have the same speed and duplex setting: To form a reth LAG, the physical interfaces must have the same speed and duplex setting. This ensures that the links can operate at the same capacity and avoid performance issues or errors.
You should have two or more interfaces: To create a reth LAG, you need to have at least two physical interfaces. One interface should be connected to node 0 and the other interface should be connected to node 1. You can also have more than two interfaces in a reth LAG for increased bandwidth and redundancy.
References:
Configuring Redundant Ethernet Interfaces, [Understanding Redundant Ethernet
Interfaces]

Question 8 Single choice

Which statement defines the function of an Application Layer Gateway (ALG)?

  1. A

    The ALG uses software processes for permitting or disallowing specific IP address ranges.

  2. B

    The ALG uses software that is used by a single TCP session using the same port numbers as the application.

  3. C

    The ALG contains protocols that use one application session for each TCP session.

  4. D

    The ALG uses software processes for managing specific protocols.

Show answer and explanation

Correct answer: D

Explanation

The statement that defines the function of an Application Layer Gateway (ALG) is: The ALG uses software processes for managing specific protocols. An ALG is a security component that operates at the application layer (layer 7) of the OSI model and handles data associated with certain application protocols, such as SIP, FTP, RTSP, etc. An ALG acts as a proxy or intermediary between the client and the server applications and performs various functions, such as address and port translation, resource allocation, application response control, and synchronization of data and control traffic. An ALG can also inspect and modify the application payload to enable firewall or NAT traversal, prevent spoofing or DoS attacks, or enforce granular security policies based on application-specific commands.
References:
Application-level gateway - Wikipedia, What Is an Application Layer Gateway (ALG)? | F5, What is ALG Application Layer
Gateway | 3CX

Question 9 Multiple choice

Exhibit

Which two statements are correct about the configuration shown in the exhibit? (Choose two.)

  1. A

    The session-class parameter in only used when troubleshooting.

  2. B

    The others 300 parameter means unidentified traffic flows will be dropped in 300 milliseconds.

  3. C

    Every session that enters the SRX Series device will generate an event

  4. D

    Replacing the session-init parameter with session-lose will log unidentified flows.

Show answer and explanation

Correct answers: B, C

Explanation

The configuration shown in the exhibit is for a Juniper SRX Series firewall. The session-init parameter is used to control how the firewall processes unknown traffic flows. With the session-init parameter set to 300, any traffic flows that the firewall does not recognize will be dropped after 300 milliseconds.
Additionally, every session that enters the device, whether it is known or unknown, will generate an event, which can be used for logging and troubleshooting purposes. The session-lose parameter is used to control how the firewall handles established sessions that are terminated.

Question 10 Multiple choice

You want to set up JSA to collect network traffic flows from network devices on your network.

Which two statements are correct when performing this task? (Choose two.)

  1. A

    BGP FlowSpec is used to collect traffic flows from Junos OS devices.

  2. B

    Statistical sampling increases processor utilization

  3. C

    Statistical sampling decreases event correlation accuracy.

  4. D

    Superflows reduce traffic licensing requirements.

Show answer and explanation

Correct answers: A, C

Explanation

The two correct statements when performing this task are
A. BGP FlowSpec is used to collect traffic flows from Junos OS devices, and
C. Statistical sampling decreases event correlation accuracy. BGP FlowSpec is a Junos OS feature that allows network devices to send traffic flow information to a Juniper security device using BGP. This allows the Juniper security device to monitor and collect the traffic flows and analyze them for suspicious activity. Statistical sampling increases processor utilization by selecting only a subset of the data to be analyzed, which can help reduce the amount of data sent to the security device.
However, this also decreases the accuracy of event correlation, as some events may be missed due to the sampling. Superflows reduce traffic licensing requirements by offloading the processing of certain traffic flows to the device itself, instead of having it sent to the security device.