Juniper JN0-336 Exam Overview:
| Certification Vendor: | Juniper Networks |
| Exam Name: | Juniper Networks Certified Specialist Security (JNCIS-SEC) |
| Exam Number: | JN0-336 |
| Related Certifications: | JNCIA-SEC JNCIP-SEC |
| Exam Format: | Multiple Choice, Multiple Select |
| Passing Score: | 65 |
| Real Exam Qty: | 65 |
| Exam Price: | $200 USD |
| Available Languages: | English |
| Certificate Validity Period: | 3 years |
| Exam Duration: | 90 minutes |
| Sample Questions: | Juniper JN0-336 Sample Questions |
| Exam Way: | Pearson VUE testing center / Online Proctoring |
| Pre Condition: | JNCIA-SEC (Junos Security) certification is recommended but not required |
| Official Syllabus URL: | https://www.juniper.net/us/en/training/certification/ |
Juniper JN0-336 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Screen Options | 15% | - Attack Detection and Mitigation - Custom Screen Options - Screen Options Configuration |
| Security Policy | 25% | - Policy Components and Structure - Policy Scheduling - Policy Troubleshooting - Policy Logging |
| UTM (Unified Threat Management) | 15% | - Antispam - Content Filtering - Antivirus - Web Filtering |
| High Availability Clustering | 20% | - Chassis Cluster Architecture - Control and Data Plane Synchronization - Configuration and Troubleshooting - Failover Behavior |
| IPsec VPNs | 25% | - VPN High Availability - Route-Based VPNs - VPN Troubleshooting - Policy-Based VPNs - IKE Phase 1 and Phase 2 |
Juniper Security, Specialist (JNCIS-SEC) Sample Questions:
1. How does Juniper's identity-aware firewall facilitate compliance with security policies and regulations?
A) by simplifying the design of the network architecture
B) by granting access based on user roles or identities
C) by increasing network capacity to accommodate user requirements
D) by enforcing the need for user confidentiality
2. Using Junos Space Security Director, you want to configure a unique firewall policy for a specific SRX Series device.
Which firewall policy rules would satisfy the requirement?
A) all devices policy prerules
B) device policy rules
C) group policy prerules
D) all devices policy postrules
3. Which two statements are correct about the security associations of an IPsec VPN? (Choose two.)
A) IPsec security associations are established during IKEv1 Phase 1 negotiations.
B) IKEv1 security associations are established during IKEv1 Phase 1 negotiations.
C) IPsec security associations are established during IKEv1 Phase 2 negotiations.
D) IKEv1 security associations are established during IKEv1 Phase 2 negotiations.
4. Which two statements about proxy IDs are correct? (Choose two.)
A) By default, for a route-based IPsec VPN, a Junos security device sets the proxy ID to 0.0.0.0/0.
B) Proxy IDs must match on both peers for a Phase 2 tunnel to establish.
C) Proxy IDs cannot override default Junos behavior.
D) Proxy IDs are created during IKE Phase 1.
5. You work on the security operations team that manages firewalls only. In your data center, there are two SRX chassis clusters. These clusters operate on VLAN 1042. The network team advises you that they see the same MAC address coming from both chassis clusters for reth0.
Why is this occurring?
A) The same cluster ID was used on both clusters.
B) RGO is active on both node0 and node1 due to split-brain.
C) Link Aggregation Control Protocol is not synchronized.
D) Chassis clusters must be on separate VLANs.
Solutions:
| Question # 1 Answer: B | Question # 2 Answer: B | Question # 3 Answer: B,C | Question # 4 Answer: A,B | Question # 5 Answer: A |
We're so confident of our products that we provide no hassle product exchange.


By Maurice

