Skip to main content

JN0-636 Real Exam Questions

Service Provider Routing and Switching Professional (JNCIP-SP)

92 questions available · Page 1 of 10

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Multiple choice

Exhibit

Referring to the exhibit, which three protocols will be allowed on the ge-0/0/5.0 interface? (Choose three.)

  1. A

    IBGP

  2. B

    OSPF

  3. C

    IPsec

  4. D

    DHCP

  5. E

    NTP

Show answer and explanation

Correct answers: B, D, E

Explanation

Explanation: The exhibit shows the output of the "show interfaces ge-0/0/5.0 extensive" command on an SRX Series device. The output includes a section called "Security" that lists the protocols that are allowed on the ge-0/0/5.0 interface. The protocols that are allowed on the ge-0/0/5.0 interface are: OSPF DHCP
NTP
It's important to notice that the output don't have IBGP, IPsec, so these protocols are not allowed on the ge-0/0/5.0 interface.

Question 2 Multiple choice

In Juniper ATP Cloud, what are two different actions available in a threat prevention policy to deal with an infected host? (Choose two.)

  1. A

    Send a custom message

  2. B

    Close the connection.

  3. C

    Drop the connection silently.

  4. D

    Quarantine the host.

Show answer and explanation

Correct answers: B, D

Explanation

Explanation: In Juniper ATP Cloud, a threat prevention policy allows you to define how the system should handle an infected host. Two of the available actions are: Close the connection: This action will close the connection between the infected host and the destination to which it is trying to connect. This will prevent the host from communicating with the destination and will stop any malicious activity. Quarantine the host: This action will isolate the infected host from the network by placing it in a quarantine VLAN. This will prevent the host from communicating with other devices on the network, which will prevent it from spreading malware or exfiltrating data.
Sending a custom message is used to notify the user and administrator of the action taken. Drop the connection silently is not an action available in Juniper ATP Cloud.

Question 3 Single choice

Exhibit

You are validating bidirectional traffic flows through your IPsec tunnel. The 4546 session represents traffic being sourced from the remote end of the IPsec tunnel. The 4547 session represents traffic that is sourced from the local network destined to the remote network.

Which statement is correct regarding the output shown in the exhibit?

  1. A

    The remote gateway address for the IPsec tunnel is 10.20.20.2

  2. B

    The session information indicates that the IPsec tunnel has not been established

  3. C

    The local gateway address for the IPsec tunnel is 10.20.20.2

  4. D

    NAT is being used to change the source address of outgoing packets

Show answer and explanation

Correct answer: B

Question 4 Single choice

What is the purpose of the Switch Microservice of Policy Enforcer?

  1. A

    to isolate infected hosts

  2. B

    to enroll SRX Series devices with Juniper ATP Cloud

  3. C

    to inspect traffic for malware

  4. D

    to synchronize security policies to SRX Series devices

Show answer and explanation

Correct answer: D

Explanation

Explanation: The Switch Microservice of Policy Enforcer is used to synchronize security policies to SRX
Series devices. It receives the policy configuration from the Policy Manager and pushes it to the SRX Series devices. It's responsible for configuring the security policies on the SRX devices, including firewall rules, VPN configurations, and other security features.

The purpose of the Switch Microservice of Policy Enforcer is to synchronize security policies to SRX Series devices. It allows administrators to quickly apply security policies across their network devices, ensuring consistent security settings. Additionally, it can help to prevent unauthorized access and malware propagation.

Question 5 Single choice

SRX Series device enrollment with Policy Enforcer fails To debug further, the user issues the following
command show configuration services security--intelligence url

https : //cloudfeeds . argon . juniperaecurity . net/api/manifeat. xml

and receives the following output:

What is the problem in this scenario?

  1. A

    The device is directly enrolled with Juniper ATP Cloud.

  2. B

    The device is already enrolled with Policy Enforcer.

  3. C

    The SRX Series device does not have a valid license.

  4. D

    Junos Space does not have matching schema based on the

Show answer and explanation

Correct answer: C

Question 6 Multiple choice

You are asked to deploy filter-based forwarding on your SRX Series device for incoming traffic sourced from the 10.10 100 0/24 network in this scenario, which three statements are correct? (Choose three.)

  1. A

    You must create a forwarding-type routing instance.

  2. B

    You must create and apply a firewall filter that matches on the source address 10.10.100.0/24 and then sends this traffic to your routing

  3. C

    You must create and apply a firewall filter that matches on the destination address 10 10.100.0/24 and then sends this traffic to your routing instance.

  4. D

    You must create a RIB group that adds interface routes to your routing instance.

  5. E

    You must create a VRF-type routing instance.

Show answer and explanation

Correct answers: B, C, D

Explanation

Explanation: In order to deploy filter-based forwarding on an SRX Series device for incoming traffic sourced from the 10.10.100.0/24 network, you must first create and apply a firewall filter that matches on

the source address 10.10.100.0/24. Then, you must create a RIB group that adds interface routes to your routing instance and apply it. The filter will forward the traffic matching the source address to the routing instance. You don't need to create a forwarding-type routing instance or a VRF-type routing instance.

Question 7 Multiple choice

What are two valid modes for the Juniper ATP Appliance? (Choose two.)

  1. A

    flow collector

  2. B

    event collector

  3. C

    all-in-one

  4. D

    core

Show answer and explanation

Correct answers: A, C

Explanation

Explanation: The Juniper ATP Appliance supports two valid modes of operation:
Flow Collector: This mode allows the Juniper ATP Appliance to collect and analyze network flow data to detect malicious activity.
All-in-One: This mode allows the Juniper ATP Appliance to perform both flow collection and event collection. It includes all the features of the Flow Collector and Event Collector mode.
Event collector and core are not valid modes for the Juniper ATP Appliance, the first one is focused on collecting events and the second one is a term that's not related to the appliance.

Question 8 Multiple choice

Exhibit

Referring to the exhibit, which three statements are true? (Choose three.)

  1. A

    The packet's destination is to an interface on the SRX Series device.

  2. B

    The packet's destination is to a server in the DMZ zone.

  3. C

    The packet originated within the Trust zone.

  4. D

    The packet is dropped before making an SSH connection.

  5. E

    The packet is allowed to make an SSH connection.

Show answer and explanation

Correct answers: A, C, D

Question 9 Single choice

Exhibit

You have recently configured Adaptive Threat Profiling and notice 20 IP address entries in the monitoring section of the Juniper ATP Cloud portal that do not match the number of entries locally on the SRX Series device, as shown in the exhibit.

What is the correct action to solve this problem on the SRX device?

  1. A

    You must configure the DAE in a security policy on the SRX device.

  2. B

    Refresh the feed in ATP Cloud.

  3. C

    Force a manual download of the Proxy__Nodes feed.

  4. D

    Flush the DNS cache on the SRX device.

Show answer and explanation

Correct answer: C

Question 10 Multiple choice

Exhibit

Referring to the exhibit, which two statements are true? (Choose two.)

  1. A

    The data that traverses the ge-0/070 interface is secured by a secure association key.

  2. B

    The data that traverses the ge-070/0 interface can be intercepted and read by anyone.

  3. C

    The data that traverses the ge-070/0 interface cannot be intercepted and read by anyone.

  4. D

    The data that traverses the ge-O/0/0 interface is secured by a connectivity association key.

Show answer and explanation

Correct answers: B, C