2024年最新のJN0-636プレミアム資料テストPDFの無料問題集お試しセット [Q26-Q47]

Share

2024年最新のJN0-636プレミアム資料テストPDFの無料問題集お試しセット

試験合格を向けてJN0-636今すぐ弊社のJNCIP-SEC試験パッケージを使おう

質問 # 26
Exhibit

You areasked to establish an IBGP peering between the SRX Series device and the router, but the session is not being established. In the security flow trace on the SRX device, packet drops are observed as shown in the exhibit.
What is the correct action to solve the problem on the SRX device?

  • A. Add BGP to the Allowed host-inbound-traffic for the interface
  • B. Configure destination NAT for BGP traffic.
  • C. Modify the security policy to allow the BGP traffic.
  • D. Create a firewall filter to accept the BGP traffic

正解:D


質問 # 27
You are asked to allocate security profile resources to the interconnect logical system for it to work properly.
In this scenario, which statement is correct?

  • A. The NAT resources must be defined in the security profile for the interconnect logical system.
  • B. The flow-session resource must be defined in the security profile for the interconnect logical system.
  • C. No resources are needed to be allocated to the interconnect logical system.
  • D. The resources must be calculated based on the amount of traffic that will flow between the logical systems.

正解:B

解説:
The flow-session resource is needed in order to ensure adequate and secure communication between the two logical systems.
The flow-session resource must be defined in the security profile for the interconnect logical system because the interconnect logical system is responsible for forwarding traffic between other logical systems. The flow-session resource determines the maximum number of sessions that the interconnect logical system can create and maintain. If the flow-session resource is not allocated or is insufficient, the interconnect logical system might drop packets or fail to establish sessions1.
The NAT resources are not needed to be allocated to the interconnect logical system because the interconnect logical system does not perform any NAT operations on the traffic. The NAT resources are only relevant for the logical systems that need to translate the source or destination IP addresses or ports of the traffic1.
No resources are not needed to be allocated to the interconnect logical system is incorrect because the interconnect logical system still requires some resources to function properly, such as the flow-session resource. The interconnect logical system cannot operate without any resources allocated to it1.
The resources must be calculated based on the amount of traffic that will flow between the logical systems is partially correct, but not the best answer. The resources must be calculated based on the amount of traffic and the type of traffic that will flow between the logical systems. For example, the flow-session resource depends on the number and duration of sessions, the security-log-stream-number resource depends on the number and size of logs, and the NAT resource depends on the number and type of NAT rules1.
Reference:
Security Profiles for Logical Systems | Junos OS | Juniper Networks


質問 # 28
You are asked to share threat intelligence from your environment with third party tools so that those tools can be identify and block lateral threat propagation from compromised hosts.
Which two steps accomplish this goal? (Choose Two)

  • A. Configure application tokens in the SRX Series firewalls to limit who has access
  • B. Enable Juniper ATP Cloud to share threat intelligence
  • C. Enable SRX Series firewalls to share Threat intelligence with third party tool.
  • D. Configure application tokens in the Juniper ATP Cloud to limit who has access

正解:B、D

解説:
To share threat intelligence from your environment with third party tools, you need to enable Juniper ATP Cloud to share threat intelligence and configure application tokens in the Juniper ATP Cloud to limit who has access. The other options are incorrect because:
A) Configuring application tokens in the SRX Series firewalls is not necessary or sufficient to share threat intelligence with third party tools. Application tokens are used to authenticate and authorize requests to the Juniper ATP Cloud API, which can be used to perform various operations such as submitting files, querying C&C feeds, and managing allowlists and blocklists1. However, to share threat intelligence with third party tools, you need to enable the TAXII service in the Juniper ATP Cloud, which is a different protocol for exchanging threat information2.
D) Enabling SRX Series firewalls to share threat intelligence with third party tools is not possible or supported. SRX Series firewalls can send potentially malicious objects and files to the Juniper ATP Cloud for analysis and receive threat intelligence from the Juniper ATP Cloud to block malicious traffic3. However, SRX Series firewalls cannot directly share threat intelligence with third party tools. You need to use the Juniper ATP Cloud as the intermediary for threat intelligence sharing.
Therefore, the correct answer is B and C. You need to enable Juniper ATP Cloud to share threat intelligence and configure application tokens in the Juniper ATP Cloud to limit who has access. To do so, you need to perform the following steps:
Enable and configure the TAXII service in the Juniper ATP Cloud. TAXII (Trusted Automated eXchange of Indicator Information) is a protocol for communication over HTTPS of threat information between parties. STIX (Structured Threat Information eXpression) is a language used for reporting and sharing threat information using TAXII. Juniper ATP Cloud can contribute to STIX reports by sharing the threat intelligence it gathers from file scanning. Juniper ATP Cloud also uses threat information from STIX reports as well as other sources for threat prevention2. To enable and configure the TAXII service, you need to select Configure > Threat Intelligence Sharing in the Juniper ATP Cloud WebUI, move the knob to the right to Enable TAXII, and move the slidebar to designate a file sharing threshold2.
Configure application tokens in the Juniper ATP Cloud. Application tokens are used to authenticate and authorize requests to the Juniper ATP Cloud API and the TAXII service. You can create and manage application tokens in the Juniper ATP Cloud WebUI by selecting Configure > Application Tokens. You can specify the name, description, expiration date, and permissions of each token. You can also revoke or delete tokens as needed. You can use the application tokens to limit who has access to your shared threat intelligence by granting or denying permissions to the TAXII service1.
Reference:
Threat Intelligence Open API Setup Guide
Configure Threat Intelligence Sharing
About Juniper Advanced Threat Prevention Cloud


質問 # 29
Exhibit

You have recently configured Adaptive Threat Profiling and notice 20 IP address entries in the monitoring section of the Juniper ATP Cloud portal that do not match the number of entries locally on the SRX Series device, as shown in the exhibit.
What is the correct action to solve this problem on the SRX device?

  • A. Refresh the feed in ATP Cloud.
  • B. Flush the DNS cache on the SRX device.
  • C. Force a manual download of the Proxy__Nodes feed.
  • D. You must configure the DAE in a security policy on the SRX device.

正解:A

解説:
The correct action to solve this problem on the SRX device is to refresh the feed in ATP Cloud. This is because the number of IP address entries in the monitoring section of the Juniper ATP Cloud portal does not match the number of entries locally on the SRX Series device. This discrepancy can be caused by a number of factors, such as the SRX device not being properly configured for Adaptive Threat Profiling, or the feed not being properly downloaded from the Juniper ATP Cloud portal. By refreshing the feed in ATP Cloud, the SRX device can synchronize its local feed with the latest feed from the cloud service and ensure that the entries are consistent and accurate. Reference: Juniper Security, Professional (JNCIP-SEC) Reference Materials source and documents: https://www.juniper.net/documentation/en_US/junos/topics/task/configuration/security-adaptive-threat-profiling-configuring.html


質問 # 30
Your company wants to use the Juniper Seclntel feeds to block access to known command and control servers, but they do not want to use Security Director to manage the feeds.
Which two Juniper devices work in this situation? (Choose two)

  • A. MX Series devices
  • B. QFX Series devices
  • C. SRX Series devices
  • D. EX Series devices

正解:B


質問 # 31
To analyze and detect malware, Juniper ATP Cloud performs which two functions? (Choose two.)

  • A. cache lookup: to see if the file is seen already and known to be malicious
  • B. dynamic analysis: to see what happens if you execute the file in a real environment
  • C. antivirus scan: with a single vendor solution to see if the file contains any potential threats
  • D. static analysis: to see what happens if you execute the file in a real environment

正解:C、D


質問 # 32
Exhibit

Referring to the exhibit, which two statements are true about the CAK status for the CAK named "FFFP"?
(Choose two.)

  • A. SAK is not generated using this key.
  • B. CAK is used for encryption and decryption of the MACsec session.
  • C. SAK is successfully generated using this key.
  • D. CAK is not used for encryption and decryption of the MACsec session.

正解:A、B


質問 # 33
You have set up Security Director with Policy Enforcer and have configured 12 third-party feeds and a Sky ATP feed. You are also injecting 16 feeds using the available open API. You want to add another compatible feed using the available open API, but Policy Enforcer is not receiving the new feed.
What is the problem in this scenario?

  • A. You have reached the maximum limit of 29 total feeds
  • B. You must wait 48 hours for the feed to update
  • C. You cannot add more than 16 feeds through the available open API
  • D. You cannot add more than 16 feeds with the available open API

正解:A

解説:
https://www.juniper.net/documentation/en_US/release-independent/sky-atp/information- products/pathway-pages/sky-atp-admin-guide.pdf page 110


質問 # 34
You are validating bidirectional traffic flows through your IPsec tunnel. The 4546 session represents traffic being sourced from the remote end of the IPsec tunnel. The 4547 session represents traffic that is sourced from the local network destined to the remote network.
Which statement is correct regarding the output shown in the exhibit?

  • A. The local gateway address for the IPsec tunnel is 10.20.20.2
  • B. The session information indicates that the IPsec tunnel has not been established
  • C. NAT is being used to change the source address of outgoing packets
  • D. The remote gateway address for the IPsec tunnel is 10.20.20.2

正解:D


質問 # 35
You must troubleshoot ongoing problems with IPsec tunnels and security policy processing. Your network consists of SRX340s and SRX5600s.
In this scenario, which two statements are true? (Choose two.)

  • A. IPsec logs are written to the kmd log file by default
  • B. You must enable data plane logging on the SRX340 devices to generate security policy logs
  • C. IKE logs are written to the messages log file by default
  • D. You must enable data plane logging on the SRX5600 devices to generate security policy logs

正解:A、D


質問 # 36
Exhibit

Referring to the exhibit, which three statements are true? (Choose three.)

  • A. The packet's destination is to a server in the DMZ zone.
  • B. The packet is dropped before making an SSH connection.
  • C. The packet originated within the Trust zone.
  • D. The packet is allowed to make an SSH connection.
  • E. The packet's destination is to an interface on the SRX Series device.

正解:B、C、E


質問 # 37
Exhibit

You are validating bidirectional traffic flows through your IPsec tunnel. The 4546 session represents traffic being sourced from the remote end of the IPsec tunnel. The 4547 session represents traffic that is sourced from the local network destined to the remote network.
Which statement is correct regarding the output shown in the exhibit?

  • A. The local gateway address for the IPsec tunnel is 10.20.20.2
  • B. The session information indicates that the IPsec tunnel has not been established
  • C. NAT is being used to change the source address of outgoing packets
  • D. The remote gateway address for the IPsec tunnel is 10.20.20.2

正解:A

解説:
According to the output shown in the exhibit, which is a security flow session on an SRX Series device, the correct statement is that the local gateway address for the IPsec tunnel is 10.20.20.2. This is indicated by the line In: 10.20.20.2/2060 -> 10.20.20.1/3382, which shows that the source IP address of the incoming packet is 10.20.20.2, which is the local gateway address of the IPsec tunnel. The destination IP address of the incoming packet is 10.20.20.1, which is the remote gateway address of the IPsec tunnel.
The following statements are incorrect or not supported by the output:
The remote gateway address for the IPsec tunnel is 10.20.20.2. This is false, as explained above. The remote gateway address for the IPsec tunnel is 10.20.20.1, not 10.20.20.2.
The session information indicates that the IPsec tunnel has not been established. This is false, as the output shows that there are two active sessions with the communication tag IPSec VPN: vpn1, which indicates that the IPsec tunnel has been established and is named vpn11.
NAT is being used to change the source address of outgoing packets. This is not supported by the output, as there is no indication of NAT being applied to the outgoing packets. The source IP address of the outgoing packet is 192.168.1.1, which is the same as the source IP address of the original packet. If NAT was being used, the source IP address of the outgoing packet would be different from the source IP address of the original packet.


質問 # 38
You are asked to deploy filter-based forwarding on your SRX Series device for incoming traffic sourced from the 10.10.100.0/24 network.
In this scenario, which three statements are correct? (Choose three.)

  • A. You must create and apply a firewall filter that matches on the destination address 10.10.100.0/24 and then sends this traffic to your routing instance.
  • B. You must create a RIB group that adds interface routes to your routing instance.
  • C. You must create and apply a firewall filter that matches on the source address 10.10.100.0/24 and then sends this traffic to your routing
  • D. You must create a VRF-type routing instance.
  • E. You must create a forwarding-type routing instance.

正解:A、C、D


質問 # 39
Which two statements about AppQoS are true? (Choose two.)

  • A. AppQoS remarking supersedes interface remarking.
  • B. AppQoS supports rate limiting.
  • C. AppQoS supports forwarding class assignment.
  • D. AppQoS supports bandwidth reservation.

正解:B、C


質問 # 40
You are required to secure a network against malware. You must ensure that in the event that a compromised host is identified within the network. In this scenario after a threat has been identified, which two components are responsible for enforcing MAC-level infected host ?

  • A. Juniper ATP Appliance
  • B. SRX Series device
  • C. EX Series device
  • D. Policy Enforcer

正解:C、D

解説:
You are required to secure a network against malware. You must ensure that in the event that a compromised host is identified within the network, the host is isolated from the rest of the network. In this scenario, after a threat has been identified, the two components that are responsible for enforcing MAC-level infected host are:
C) Policy Enforcer. Policy Enforcer is a software solution that integrates with Juniper ATP Cloud and Juniper ATP Appliance to provide automated threat remediation across the network. Policy Enforcer can receive threat intelligence feeds from Juniper ATP Cloud or Juniper ATP Appliance and apply them to the security policies on the SRX Series devices and the EX Series devices. Policy Enforcer can also enforce MAC-level infected host, which is a feature that allows you to quarantine a compromised host by blocking its MAC address on the switch port. Policy Enforcer can communicate with the EX Series devices and instruct them to apply the MAC-level infected host policy to the infected host1.
D) EX Series device. EX Series devices are Ethernet switches that can provide Layer 2 and Layer 3 switching capabilities and security features. EX Series devices can integrate with Policy Enforcer and Juniper ATP Cloud or Juniper ATP Appliance to provide automated threat remediation across the network. EX Series devices can support MAC-level infected host, which is a feature that allows them to quarantine a compromised host by blocking its MAC address on the switch port. EX Series devices can receive instructions from Policy Enforcer and apply the MAC-level infected host policy to the infected host2.
The other options are incorrect because:
A) SRX Series device. SRX Series devices are high-performance firewalls that can provide Layer 3 and Layer 4 security features and integrate with Juniper ATP Cloud or Juniper ATP Appliance to provide advanced threat prevention. SRX Series devices can receive threat intelligence feeds from Juniper ATP Cloud or Juniper ATP Appliance and apply them to the security policies. However, SRX Series devices cannot enforce MAC-level infected host, which is a feature that requires Layer 2 switching capabilities and is supported by EX Series devices3.
B) Juniper ATP Appliance. Juniper ATP Appliance is a hardware solution that provides advanced threat prevention by detecting and blocking malware, ransomware, and other cyberattacks. Juniper ATP Appliance can analyze the network traffic and identify the compromised hosts based on their behavior and communication patterns. Juniper ATP Appliance can also send threat intelligence feeds to Policy Enforcer and SRX Series devices to enable automated threat remediation across the network. However, Juniper ATP Appliance cannot enforce MAC-level infected host, which is a feature that requires Layer 2 switching capabilities and is supported by EX Series devices.
Reference:
Policy Enforcer Overview
EX Series Switches Overview
SRX Series Services Gateways Overview
[Juniper ATP Appliance Overview]


質問 # 41
You are connecting two remote sites to your corporate headquarters site.
You must ensure that all traffic is secured and sent directly between sites.
In this scenario, which VPN should be used?

  • A. hub-and-spoke IPsec VPN
  • B. Layer 2 VPN
  • C. IPsec ADVPN
  • D. full mesh Layer 3 VPN with EBGP

正解:A


質問 # 42
You have initiated the download of the IPS signature database on your SRX Series device.
Which command would you use to confirm the download has completed?

  • A. request security idp security-package download
  • B. request security idp security-package install status
  • C. request security idp security-package install
  • D. request security idp security-package download status

正解:D


質問 # 43
You are asked to ensure that your IPS engine blocks attacks. You must ensure that your system continues to drop additional malicious traffic without additional IPS processing for up to 30 minutes. You must ensure that the SRX Series device does send a notification packet when the traffic is dropped.
Which statement is correct?

  • A. Use the IP-Block action.
  • B. Use the Drop Packet action.
  • C. Use the Drop Connection action.
  • D. Use the IP-Close action.

正解:D


質問 # 44
Your manager asks you to show which attacks have been detected on your SRX Series device using the IPS feature.
Which command would you use to accomplish this task?

  • A. show security idp attack detail
  • B. show security idp counters
  • C. show security idp attack table
  • D. show security idp memory

正解:C


質問 # 45
You have noticed a high number of TCP-based attacks directed toward your primary edge device. You are asked to configure the IDP feature on your SRX Series device to block this attack.
Which two IDP attack objects would you configure to solve this problem? (Choose two.)

  • A. Signature
  • B. Protocol anomaly
  • C. Network
  • D. host

正解:A、B


質問 # 46
You are asked to control access to network resources based on the identity of an authenticated device Which three steps will accomplish this goal on the SRX Series firewalls? (Choose three )

  • A. Reference the end-user-profile in the security policy.
  • B. Configure the authentication source to be used to authenticate the device
  • C. Apply the end-user-profile at the interface connecting the devices
  • D. Reference the end-user-profile in the security zone
  • E. Configure an end-user-profile that characterizes a device or set of devices

正解:A、B、E

解説:
To control access to network resources based on the identity of an authenticated device on the SRX Series firewalls, you need to perform the following steps:
A) Configure an end-user-profile that characterizes a device or set of devices. An end-user-profile is a device identity profile that contains a collection of attributes that are characteristics of a specific group of devices, or of a specific device, depending on the attributes configured in the profile. The end-user-profile must contain a domain name and at least one value in each attribute. The attributes include device-identity, device-category, device-vendor, device-type, device-os, and device-os-version1. You can configure an end-user-profile by using the Junos Space Security Director or the CLI2.
C) Reference the end-user-profile in the security policy. A security policy is a rule that defines the action to be taken for the traffic that matches the specified criteria, such as source and destination addresses, zones, protocols, ports, and applications. You can reference the end-user-profile in the source-end-user-profile field of the security policy to identify the traffic source based on the device from which the traffic issued. The SRX Series device matches the IP address of the device to the end-user-profile and applies the security policy accordingly3. You can reference the end-user-profile in the security policy by using the Junos Space Security Director or the CLI4.
E) Configure the authentication source to be used to authenticate the device. An authentication source is a system that provides the device identity information to the SRX Series device. The authentication source can be Microsoft Windows Active Directory or a third-party network access control (NAC) system. You need to configure the authentication source to be used to authenticate the device and to send the device identity information to the SRX Series device. The SRX Series device stores the device identity information in the device identity authentication table5. You can configure the authentication source by using the Junos Space Security Director or the CLI6.
The other options are incorrect because:
B) Referencing the end-user-profile in the security zone is not a valid step to control access to network resources based on the identity of an authenticated device. A security zone is a logical grouping of interfaces that have similar security requirements. You can reference the user role in the security zone to identify the user who is accessing the network resources, but not the end-user-profile7.
D) Applying the end-user-profile at the interface connecting the devices is also not a valid step to control access to network resources based on the identity of an authenticated device. You cannot apply the end-user-profile at the interface level, but only at the security policy level. The end-user-profile is not a firewall filter or a security policy, but a device identity profile that is referenced in the security policy1.
Reference:
End User Profile Overview
Creating an End User Profile
source-end-user-profile
Creating Firewall Policy Rules
Understanding the Device Identity Authentication Table and Its Entries
Configuring the Authentication Source for Device Identity
user-role


質問 # 47
......

2024年最新の問題をマスターJNCIP-SEC合格目指してJN0-636リアル試験!:https://www.passtest.jp/Juniper/JN0-636-shiken.html

完全版は2024年最新のJN0-636試験問題集ガイドはトレーニング専門PassTest:https://drive.google.com/open?id=1RcXiyxBY_iPJl0ZWLL8m6RC7fTEDA4WC