Juniper JN0-636 Online Practice
Questions and Exam Preparation
JN0-636 Exam Details
Exam Code
:JN0-636
Exam Name
:Service Provider Routing and Switching Professional (JNCIP-SP)
Certification
:Juniper Certifications
Vendor
:Juniper
Total Questions
:92 Q&As
Last Updated
:Jan 25, 2026
Juniper JN0-636 Online Questions &
Answers
Question 1:
You want to identify potential threats within SSL-encrypted sessions without requiring SSL proxy to decrypt the session contents. Which security feature achieves this objective?
A. infected host feeds B. encrypted traffic insights C. DNS security D. Secure Web Proxy
C. DNS security
Question 2:
Your company uses non-Juniper firewalls and you are asked to provide a Juniper solution for zero-day malware protection. Which solution would work in this scenario?
A. Juniper ATP Cloud B. Juniper Secure Analytics C. Juniper ATP Appliance D. Juniper Security Director
A. Juniper ATP Cloud explanation:
Explanation/Reference:
Juniper ATP Cloud provides zero-day malware protection for non-Juniper firewalls. It's a cloud-based service that analyzes files and network traffic to detect and prevent known and unknown (zero-day) threats. It uses a combination of static and dynamic analysis techniques, as well as machine learning, to detect and block malicious files, even if they are not known to traditional anti-virus software. It also provides real-time visibility and detailed forensics for incident response and remediation.
Question 3:
You want to use selective stateless packet-based forwarding based on the source address.
In this scenario, which command will allow traffic to bypass the SRX Series device flow daemon?
A. set firewall family inet filter bypaa3_flowd term t1 then skip--services accept B. set firewall family inet filter bypass_flowd term t1 then routing-instance stateless C. set firewall family inet filter bypas3_flowd term t1 then virtual-channel stateless D. set firewall family inet filter bypass__f lowd term t1 then packet--mode
C. set firewall family inet filter bypas3_flowd term t1 then virtual-channel stateless
Question 4:
You are configuring transparent mode on an SRX Series device. You must permit IP-based traffic only, and BPDUs must be restricted to the VLANs from which they originate.
Which configuration accomplishes these objectives?
You are asked to deploy filter-based forwarding on your SRX Series device for incoming traffic sourced from the 10.10 100 0/24 network in this scenario, which three statements are correct? (Choose three.)
A. You must create a forwarding-type routing instance. B. You must create and apply a firewall filter that matches on the source address 10.10.100.0/24 and then sends this traffic to your routing C. You must create and apply a firewall filter that matches on the destination address 10 10.100.0/24 and then sends this traffic to your routing instance. D. You must create a RIB group that adds interface routes to your routing instance. E. You must create a VRF-type routing instance.
B. You must create and apply a firewall filter that matches on the source address 10.10.100.0/24 and then sends this traffic to your routing C. You must create and apply a firewall filter that matches on the destination address 10 10.100.0/24 and then sends this traffic to your routing instance. D. You must create a RIB group that adds interface routes to your routing instance. explanation:
Explanation/Reference:
In order to deploy filter-based forwarding on an SRX Series device for incoming traffic sourced from the 10.10.100.0/24 network, you must first create and apply a firewall filter that matches on the source address 10.10.100.0/24. Then, you must create a RIB group that adds interface routes to your routing instance and apply it. The filter will forward the traffic matching the source address to the routing instance. You don't need to create a forwarding-type routing instance or a VRF-type routing instance.
Question 6:
Which two log format types are supported by the JATP appliance? (Choose two.)
Which two additional configuration actions are necessary for the third-party feed shown in the exhibit to work properly? (Choose two.)
A. You must create a dynamic address entry with the IP filter category and the ipfilter_office365 value. B. You must create a dynamic address entry with the CandC category and the cc_offic365 value. C. You must apply the dynamic address entry in a security policy. D. You must apply the dynamic address entry in a security intelligence policy.
A. You must create a dynamic address entry with the IP filter category and the ipfilter_office365 value. C. You must apply the dynamic address entry in a security policy.
Question 8:
Exhibit Referring to the exhibit, which three statements are true? (Choose three.)
A. The packet's destination is to an interface on the SRX Series device. B. The packet's destination is to a server in the DMZ zone. C. The packet originated within the Trust zone. D. The packet is dropped before making an SSH connection. E. The packet is allowed to make an SSH connection.
A. The packet's destination is to an interface on the SRX Series device. C. The packet originated within the Trust zone. D. The packet is dropped before making an SSH connection.
Question 9:
Your company wants to use the Juniper Seclntel feeds to block access to known command and control servers, but they do not want to use Security Director to manage the feeds. Which two Juniper devices work in this situation? (Choose two)
A. EX Series devices B. MX Series devices C. SRX Series devices D. QFX Series devices
B. MX Series devices C. SRX Series devices explanation:
Explanation/Reference:
Juniper MX and SRX series devices support the integration of Seclntel feeds, which provide information about known command and control servers, for the purpose of blocking access to them. These devices can be configured to use the Seclntel feeds without the need for Security Director to manage the feeds. EX series and QFX series devices are not capable of working in this situation, as they do not support the integration of Seclntel feeds.
Question 10:
Click the Exhibit button.
Referring to the exhibit, which three topologies are supported by Policy Enforcer? (Choose three.)
A. Topology 3 B. Topology 5 C. Topology 2 D. Topology 4 E. Topology 1
A. Topology 3 D. Topology 4 E. Topology 1 explanation:
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Juniper exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your JN0-636 exam preparations
and Juniper certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.