Juniper JN0-336 Exam Overview:
| Certification Vendor: | Juniper Networks |
|---|---|
| Exam Name: | Juniper Networks Certified Specialist Security (JNCIS-SEC) |
| Exam Number: | JN0-336 |
| Exam Price: | $300 USD |
| Real Exam Qty: | 65 |
| Exam Duration: | 90 minutes |
| Available Languages: | English |
| Exam Format: | Multiple choice |
| Related Certifications: | JNCIA-SEC JNCIE-SEC JNCIP-SEC |
| Passing Score: | Variable (approximately 60% - 70%) |
| Certificate Validity Period: | 3 years |
| Recommended Training: | Juniper Learning Portal |
| Exam Registration: | Pearson VUE Registration |
| Sample Questions: | Juniper JN0-336 Sample Questions |
| Exam Way: | Online proctored or onsite at Pearson VUE test centers |
| Pre Condition: | Juniper Networks Certified Associate Security (JNCIA-SEC) certification |
| Official Syllabus URL: | https://www.juniper.net/us/en/training/certification/tracks/security/jncis-sec.html |
Juniper JN0-336 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Topic 1: SSL Proxy | - SSL reverse proxy - SSL forward proxy - Certificate management - Configuration and troubleshooting |
| Topic 2: Identity-Aware Security | - Integration with directory services - Juniper Identity Management Service (JIMS) - Identity-based policies |
| Topic 3: IPsec VPNs | - VPN monitoring and troubleshooting - Remote access VPN - Site-to-site IPsec VPN |
| Topic 4: Application Security | - Application identification - Application Quality of Service (QoS) - Configuration, monitoring and troubleshooting - Advanced Policy-Based Routing (APBR) - Application firewall |
| Topic 5: Virtual SRX / cSRX | - Deployment and architecture - Resource allocation and scaling - Configuration and management |
| Topic 6: Advanced Threat Prevention (ATP) | - Configuration, monitoring and troubleshooting - File analysis and threat intelligence - Juniper ATP Cloud - Juniper ATP On-Premises |
| Topic 7: High Availability (HA) Clustering | - Cluster architecture and concepts - Failover and synchronization - Monitoring and troubleshooting - Chassis cluster configuration |
| Topic 8: Advanced Security Policies | - Session management - Application Layer Gateways (ALGs) - Scheduling - Logging - Configuration, monitoring and troubleshooting - Unified security policies |
| Topic 9: Security Director | - Deployment and configuration - Policy management - Management and monitoring |
| Topic 10: Juniper Secure Analytics (JSA) | - Integration with SRX devices - Log collection and analysis - Event correlation and reporting |
| Topic 11: Intrusion Detection and Prevention (IDP/IPS) | - IPS database management - Configuration, monitoring and troubleshooting - IPS policies |
Juniper Security, Specialist (JNCIS-SEC) Sample Questions:
Question 1
Regarding static attack object groups, which two statements are true? (Choose two.)
A. Group membership automatically changes when Juniper updates the IPS signature database.
B. Group membership does not automatically change when Juniper updates the IPS signature database.
C. Matching attack objects are automatically added to a custom group.
D. You must manually add matching attack objects to a custom group.
Question 2
Which two statements about PC probes sent by the JIMS server are correct? (Choose two.)
A. PC probes are triggered only when there is no IP-to-username mapping present in the event log.
B. PC probes are sent by the JIMS server to domain PCs every 60 seconds.
C. If a probe is successful, the authentication entry is updated on the JIMS server and pushed to the SRX.
D. PC probes are sent by the JIMS server to domain PCs every 30 seconds.
Question 3
Which SRX Series device configuration setting must be configured first to use Juniper ATP Cloud?
A. Apply the firewall rules on the SRX Series device.
B. Configure the anti-malware policies on the SRX Series device.
C. Enable connectivity between the SRX Series device and Juniper ATP Cloud.
D. Start up the anti-malware service on the SRX Series device.
Question 4
Which two steps are necessary to prepare the Active Directory domain for a JIMS installation? (Choose two.)
A. Create three limited access user accounts.
B. Add limited access user accounts to Active Directory groups.
C. Add one full access user account to Active Directory groups.
D. Create two limited access user accounts.
Question 5
Which two statements are correct about fabric interfaces on an SRX Series Firewall? (Choose two.)
A. In an active/active configuration, inter-chassis traffic uses the fab link.
B. In an active/passive configuration, inter-chassis traffic uses the fab link.
C. The node ID is reflected in the fabric interface name.
D. The cluster ID is reflected in the fabric interface name.
Solutions:
| Question 1 Answer: B,D | Question 2 Answer: A,C | Question 3 Answer: C | Question 4 Answer: B,D | Question 5 Answer: A,B |

We're so confident of our products that we provide no hassle product exchange.


By Jason


