Pass JN0-334 Exam in First Attempt Guaranteed 2021 Dumps!
JN0-334 Dumps Full Questions - Exam Study Guide
NEW QUESTION 19
Which solution should you use if you want to detect known attacks using signature-based methods?
- A. IPS
- B. JIMS
- C. SSL proxy
- D. ALGs
Answer: A
NEW QUESTION 20
The AppQoE module of AppSecure provides which function?
- A. The AppQoE module prioritizes important applications.
- B. The AppQoE module blocks access to risky applications.
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-appqoe.html#jd0e28 - C. The AppQoE module provides application-based routing.
- D. The AppQoE module provides routing, based on network conditions.
Answer: D
NEW QUESTION 21
Which two statements describe application-layer gateways (ALGs)? (Choose two.)
- A. ALGs are designed for specific protocols that use a single TCP session.
- B. ALGs are designed for specific protocols that require multiple sessions.
- C. ALGs can only be configured using Security Director.
- D. ALGs are used with protocols that use multiple ports.
Answer: B,D
NEW QUESTION 22
Exhibit.
Referring to the exhibit, which statement is true?
- A. IDP blocks all users
- B. IDP ignores the connection on matched sessions
- C. IDP blocks not users
- D. IDP closes the connection on matched sessions.
Answer: C
NEW QUESTION 23
What are two management methods for cSRX? (Choose two.)
- A. Network Director
- B. Contrail
- C. J-Web
- D. UCLI
Answer: A,D
NEW QUESTION 24
After a software upgrade on an SRX5800 chassis cluster, you notice that both node0 and node1 are in the primary state, when node1 should be secondary. All control and fabric links are operating normally.
In this scenario, which step must you perform to recover the cluster?
- A. Execute the request system reboot command on node0.
- B. Execute the request system reboot command on node1.
- C. Execute the request system software add command on node1.
- D. Execute the request system software rollback command on node0.
Answer: B
NEW QUESTION 25
You must ensure that all encrypted traffic passing through your SRX device uses strong protocols and ciphers.
Which feature should you implement to satisfy this requirement?
- A. JATP
- B. SSL proxy
- C. AppSecure
- D. JIMS
Answer: B
NEW QUESTION 26
What is the default timeout period for a TCP session in the session table of a Junos security device?
- A. 60 minutes
- B. 1 minute
- C. 15 minutes
- D. 30 minutes
Answer: D
NEW QUESTION 27
You are asked to convert two standalone SRX Series devices to a chassis cluster deployment. You must ensure that your IPsec tunnels will be compatible with the new deployment In this scenario: which two interfaces should be used when binding your tunnel endpoints? (Choose two)
- A. reth
- B. lo0
- C. ge
- D. pp0
Answer: D
NEW QUESTION 28
You must configure JSA to accept events from an unsupported third-party log source In this scenario. what should you do?
- A. Separate event collection and flow collection on separate collectors
- B. Configure an RPM for a third-party device service module
- C. Configure JSA to silently discard unsupported log types
- D. Configure a universal device service module
Answer: A
NEW QUESTION 29
When considering managed sessions, which configuration parameter determines how full the session table must be to implement the early age-out function?
- A. high waremark
- B. session service timeout
- C. policy rematch
- D. low watermark
Answer: A
Explanation:
Explanation
NEW QUESTION 30
Which two statements describe how rules are used with Juniper Secure Analytics? (Choose two )
- A. Rules are defined on Junos Space Security Director, and then pushed to JSA log collectors
- B. When a rule is triggered. JSA can respond by sending an e-mail to JSA administrators.
- C. When a rule is triggered. JSA can respond by blocking all traffic from a specific source address
- D. A rule defines matching criteria and actions that should be taken when an event matches the rule
Answer: A,C
NEW QUESTION 31
Which statement is true about JATP incidents?
- A. Incidents are sorted by category, followed by severity.
- B. Incidents are always automatically mitigated.
- C. Incidents consist of all the events associated with a single threat.
- D. Incidents have an associated threat number assigned to them.
Answer: D
NEW QUESTION 32
Which two statements describe SSL proxy on SRX Series devices? (Choose two.)
- A. SSL proxy supports TLS version 1.2.
- B. Client-protection is also known as reverse proxy.
- C. SSL proxy relies on Active Directory to provide secure communication.
- D. SSL proxy is supported when enabled within logical systems.
Answer: A,D
NEW QUESTION 33
A routing change occurs on an SRX Series device that involves choosing a new egress interface.
In this scenario, which statement is true for all affected current sessions?
- A. The current sessions might change based on the corresponding security policy.
- B. The current sessions do not change.
- C. The current sessions are torn down and go through first path processing based on the new route.
- D. The current session are torn dowm only if the policy-rematch option has been enabled.
Answer: C
NEW QUESTION 34
You must block the lateral spread of Remote Administration Tools (RATs) that use SMB to propagate within the network, using the JATP solution.
Which action would accomplish this task?
- A. Configure the SAML settings.
- B. Configure whitelist rules
- C. Configure YARA rules.
- D. Configure a new anti-virus configuration rule.
Answer: C
NEW QUESTION 35
Which two solutions provide a sandboxing feature for finding zero-day malware threats? (Choose two.)
- A. Sky ATP
- B. IPS
- C. JATP
- D. UTM
Answer: A,C
NEW QUESTION 36
After a software upgrade on an SRX5800 chassis cluster you notice that both node1 and node1 are in the primary state, when node1 should be secondary All control and fabric links are operating normally.
In this scenario which step must you perform to recover the duster?
- A. Execute the request system reboot command on node1
- B. Execute the request system reboot command on node1
- C. Execute the request system software add command on node1.
- D. Execute the request system software rollback command on node1
Answer: B
NEW QUESTION 37
What information does JIMS collect from domain event log sources? (Choose two)
- A. For user login events. JIMS collects the username and group membership information.
- B. For user login events. JIMS collects the login source IP address and username information
- C. For device login events. JIMS collects the device IP address and machine name information
- D. For device login events. JIMS collects the device IP address and operating system version.
Answer: C
NEW QUESTION 38
How many nodes are configurable in a chassis cluster using SRX Series devices?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
NEW QUESTION 39
Click the Exhibit button.
The output shown in the exhibit is displayed in which format?
- A. sd-syslog
- B. syslog
- C. binary
- D. WELF
Answer: B
NEW QUESTION 40
Exhibit.
Referring to the SRX Series flow module diagram shown in the exhibit. where is IDP/IPS processed'
- A. Screens
- B. Security Policy
- C. Services ALGs
- D. Forwarding Lookup
Answer: D
NEW QUESTION 41
After performing a software upgrade on an SRX5800 chassis cluster, you notice that node1 is in the primary state and node0 is in the backup state. Your network standards dictate that node0 should be in the primary state.
In this scenario, which command should be used to comply with the network standards?
- A. request chassis cluster failover redundancy-group 0 node 0
- B. request chassis cluster failover redundancy-group 254 node 1
- C. request chassis cluster failover redundancy-group 0 node 1
- D. request chassis cluster failover redundancy-group 254 mode 0
Answer: A
Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-chassis-cluster- redundancy-group-failover.html
NEW QUESTION 42
......
JNCIS-SEC Free Certification Exam Material from Exam4PDF with 93 Questions: https://www.exam4pdf.com/JN0-334-dumps-torrent.html

