Skip to content

Juniper Security Specialist (JNCIS-SEC) Practice Questions

Prepare for JN0-336 with more than an answer.

174 questions in the full set20 sample questionsUpdated Nov 9, 2025
Exam fee
$200 USD
Level
Specialist
Valid for
3 years
Domains covered on the exam 7
  1. Intrusion Detection and Prevention (IDP)14%
  2. IPsec VPN17%
  3. Juniper Advanced Threat Prevention (ATP) Cloud17%
  4. High Availability (HA) Clustering17%
  5. Identity-Aware Security Policies14%
  6. SSL Proxy14%
  7. Security Director7%
  1. 1

    Which two statements accurately describe the characteristics of Juniper's Encrypted Traffic Insights (ETI)? (Select TWO).

    Show answer details

    Correct answer: B, C

    ETI's core function is to analyze metadata associated with encrypted sessions. This includes information from the TLS handshake, certificate details, and behavioral data like connection frequency and data transfer volume, without needing to see the encrypted payload itself.

    By correlating the collected metadata with threat intelligence, ETI is designed to identify threats like C2 callbacks and malware distribution that leverage encryption to evade traditional inspection methods. It looks for anomalies and known malicious indicators in the metadata.

  2. 2

    A hospital is using JIMS to enforce security policies based on staff roles defined in Active Directory. A policy is written to allow users in the 'Doctors' AD group to access the 'Medical-Records' application. A doctor reports being unable to access the application. You verify the doctor is in the correct AD group and that the JIMS server has a current IP-to-user mapping for them. The SRX policy is configured to use 'Doctors' as the source-identity. What is the next logical step in troubleshooting this issue on the SRX device?

    Show answer details

    Correct answer: B

    The command show security user-identification authentication-table displays the user-to-IP and group mapping information that the SRX device has received from JIMS. This is the crucial next step to confirm that the identity information has been successfully pushed to or queried by the SRX. If the user or their group membership is not present in this table on the SRX, the identity-aware policy will not match, even if JIMS has the correct data.

  3. 3

    What is a key difference between SSL Forward Proxy and SSL Reverse Proxy on an SRX Series device?

    Show answer details

    Correct answer: A

    This statement accurately captures the primary use case for each proxy type. SSL Forward Proxy is deployed to inspect encrypted traffic originating from internal clients going out to the Internet. SSL Reverse Proxy is deployed to terminate and inspect incoming encrypted traffic destined for internal servers (like a web server), protecting them from attacks.

  4. 4

    You are managing an SRX chassis cluster. You need to verify which node is currently the primary for redundancy group 1 (RG1) and check the status of its monitored interfaces. Which command provides this specific information?

    Show answer details

    Correct answer: C

    The command show chassis cluster redundancy-group 1 is the most direct way to view the detailed status of a specific redundancy group. The output will clearly state which node is primary, which is secondary, the group's current state (e.g., primary, secondary-hold), its priority, and the status of any interfaces being monitored by that group for failover.

  5. 5

    What is the role of Perfect Forward Secrecy (PFS) in an IPsec VPN?

    Show answer details

    Correct answer: B

    Perfect Forward Secrecy (PFS) is a security property that ensures if a long-term key (like the IKE Phase 1 key) is compromised, it cannot be used to decrypt past sessions. In IPsec, this is achieved by performing a new Diffie-Hellman key exchange during IKE Phase 2 negotiations. This generates a fresh, independent session key for the data channel that is not mathematically derived from the initial Phase 1 keying material.

  6. 6

    A financial institution is deploying a chassis cluster with two SRX4600 devices to protect their core banking application. The requirements state that the cluster must maintain stateful session persistence for all traffic, including management sessions to the devices themselves. During a failover test, the administrator observes that while user traffic fails over correctly, their SSH session to the primary Routing Engine (RE) is terminated. Which configuration element is most likely responsible for this behavior?

    Show answer details

    Correct answer: B

    In a Junos OS chassis cluster, redundancy group 0 (RG0) is responsible for the failover of the Routing Engines. However, by default, RG0 does not synchronize the state of host-inbound traffic (like SSH or Telnet sessions to the device itself). User transit traffic is handled by data plane redundancy groups (RG1+), which do synchronize session states. Therefore, the termination of the SSH session during an RE failover is expected default behavior.

  7. 7

    An organization is using Juniper ATP Cloud integrated with their SRX firewall. They want to prevent users from downloading potentially malicious files, but also need to allow specific business-critical executable files from a trusted partner to be downloaded without inspection. How should this be configured within the ATP Cloud policy framework?

    Show answer details

    Correct answer: B

    Juniper ATP Cloud allows for exceptions to be made using allowlists (whitelists) and blocklists (blacklists). To allow a specific file regardless of its threat score, its SHA256 hash should be added to the allowlist. This ensures that only that exact file is permitted, providing a more secure and granular exception than whitelisting an entire IP address, URL, or file type.

  8. 8

    A network security engineer is establishing a new site-to-site IPsec VPN between two SRX devices. The remote peer is a third-party device that requires the use of a specific proxy-id. The local network is 192.168.10.0/24 and the remote network is 10.10.20.0/24. After configuring the IKE and IPsec proposals, the tunnel fails to establish. Which configuration approach is necessary to accommodate the third-party requirement?

    Show answer details

    Correct answer: C

    While policy-based VPNs inherently use the policy match for the proxy-id, the modern and more flexible approach on SRX devices is to use a route-based VPN. To interoperate with devices that require specific proxy-ids (also known as traffic selectors), you can define them explicitly within the [edit security ipsec vpn ] hierarchy. This allows the flexibility of a route-based VPN (using st0 interfaces) while satisfying the strict traffic selector requirements of the peer.

  9. 9

    A security team has deployed Juniper Identity Management Service (JIMS) to create identity-aware security policies on their SRX firewalls. They have a requirement to apply a strict policy to all users in the 'Contractors' Active Directory group. After configuration, they notice that some contractors can still access resources that should be blocked. A review of the JIMS server shows it is correctly receiving user-to-IP mappings from the Domain Controllers. What is the most likely reason for the policy enforcement failure on the SRX? (Select TWO).

    Show answer details

    Correct answer: A, C

    If the SRX cannot authenticate and communicate with the JIMS server via the REST API, it cannot retrieve the required user and group information. An incorrect IP address or a mismatched client secret will cause this communication to fail, preventing the SRX from enforcing identity-based policies.

    Junos security policies are evaluated sequentially from top to bottom. If a broader policy that permits the traffic (e.g., from source-address any to destination-address any) is placed before the more specific identity-aware policy, the traffic will match the first rule and be permitted. The identity-aware policy will never be evaluated.

  10. 10

    True or False: When configuring SSL Forward Proxy on an SRX Series device, the root CA certificate used to sign the proxied server certificates must be installed on the SRX device, but it is not necessary to distribute this root CA to the client browsers.

    Show answer details

    Correct answer: B

    This statement is false. For SSL Forward Proxy to function without causing certificate errors on client machines, the root CA certificate configured on the SRX must be installed and trusted by the clients' web browsers. The SRX acts as a man-in-the-middle, re-signing server certificates with its own CA. If clients do not trust this CA, they will receive security warnings for every HTTPS site they visit.

Create an account to continue.