JN0-336 Sample Questions & Answers
IPsec VPN, Juniper's Advanced Threat Prevention Cloud and chassis-cluster high availability tie for the top weight, alongside configuring intrusion detection and prevention, identity-aware policies, SSL proxy, and Security Director.
Launch the full JN0-336 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Juniper Advanced Threat Prevention (ATP) Cloud · Encrypted Traffic Insights (ETI)
Company Background:
Global-Retail Inc. operates a large e-commerce platform hosted in a private data center. They are expanding their security infrastructure to gain visibility into encrypted traffic and protect against advanced threats. The company has a strict user privacy policy that limits the decryption of traffic related to financial and healthcare services.Current Situation:
They have deployed a pair of SRX4200 firewalls in a chassis cluster. They have also subscribed to Juniper ATP Cloud. All outbound web traffic from their corporate network is routed through the SRX cluster. The security team is tasked with inspecting web traffic for malware and command-and-control (C2) communication, while adhering to the privacy policy.Requirements:
- All outbound web traffic (HTTP and HTTPS) must be inspected for threats.
- HTTPS traffic to known financial and healthcare domains must NOT be decrypted.
- The solution must still provide threat intelligence for the non-decrypted HTTPS traffic.
- The configuration should minimize performance impact on the SRX cluster.
Problem:
The team needs to select the most effective combination of Junos security features to meet all requirements. Which approach should they take?Show answer & explanation
Correct answer: C
This is the optimal solution. It meets all requirements by using a multi-layered approach:
- SSL Forward Proxy with a whitelist: This selectively decrypts general web traffic while bypassing decryption for sensitive domains (Requirement 2).
- ATP Cloud on decrypted traffic: This allows deep inspection for malware in the non-sensitive traffic (Requirement 1).
- Encrypted Traffic Insights (ETI): ETI analyzes metadata from ALL sessions, including the non-decrypted ones. This provides threat intelligence (like C2 detection based on connection patterns and certificate info) for the whitelisted traffic without violating privacy (Requirement 3).
- Selective Decryption: This approach minimizes the performance load compared to decrypting all traffic (Requirement 4).
- Question 2Intermediate
Intrusion Detection and Prevention (IDP) · Custom Attack Objects
When implementing a custom IDP attack object on an SRX Series device, which component specifies the direction of the traffic to be inspected for the attack signature?
Show answer & explanation
Correct answer: B
Within the configuration of a custom IDP attack object, the
directionattribute is used to specify the flow direction of the traffic to be matched. The options are typicallyclient-to-server,server-to-client, orany. This is a fundamental part of the attack signature definition itself. - Question 3Intermediate
Security Director · Device Onboarding
A network engineer is managing a large-scale deployment of SRX firewalls using Junos Space Security Director. To streamline the onboarding of 50 new branch office firewalls, a Zero Touch Provisioning (ZTP) approach is required. Which Security Director feature is specifically designed to apply a standardized base configuration, including management settings and security policies, to devices as they are onboarded via ZTP?
Show answer & explanation
Correct answer: C
Preprovision profiles in Security Director are used to define a template of settings that are automatically applied to a device when it is first discovered and onboarded, particularly through ZTP. This profile can include device-specific settings, authentication details, and initial configuration templates, ensuring that new devices come online with a correct and secure baseline configuration.
- Question 4Beginner
High Availability (HA) Clustering · Chassis Cluster Components
What is the primary function of the fabric link in an SRX chassis cluster?
Show answer & explanation
Correct answer: B
The fabric link (or data link) is a dedicated connection between the two nodes of a chassis cluster. Its main purpose is to synchronize the real-time objects (RTOs), such as session state, for redundancy groups RG1 and higher. This ensures that if a failover occurs, the new primary node has all the necessary session information to continue processing traffic without interruption.
- Question 5IntermediateSelect 2
IPsec VPN · IPsec Troubleshooting
An administrator is troubleshooting an IPsec VPN tunnel where IKE Phase 1 completes successfully, but IKE Phase 2 fails. The
show security ipsec security-associationscommand shows no active SAs. The administrator suspects a mismatch in the IPsec proposals. Which two settings are negotiated during IKE Phase 2 and could be the cause of the failure? (Select TWO).Show answer & explanation
Correct answers: C, D
The IPsec protocol, which determines whether to use Encapsulating Security Payload (ESP) or Authentication Header (AH), is a key parameter negotiated during the IKE Phase 2 (Quick Mode) exchange.
The encryption algorithm (e.g., AES, 3DES) and the authentication algorithm (e.g., SHA-256, HMAC-SHA1) used to protect the actual data traffic are defined in the IPsec proposal and negotiated during IKE Phase 2. A mismatch here is a common cause of Phase 2 failure.
- Question 6Beginner
Juniper Advanced Threat Prevention (ATP) Cloud · Security Feeds
A security analyst is reviewing logs from their SRX firewall and notices traffic being blocked by a security policy that uses a dynamic address entry fed from Juniper ATP Cloud. The entry corresponds to a known Command and Control (C2) server. Which ATP Cloud security feed is responsible for providing this information to the SRX?
Show answer & explanation
Correct answer: C
Juniper ATP Cloud provides several security feeds to enforcement points like the SRX. The Command and Control (C&C or C2) feed is specifically designed to provide a dynamic list of known malicious C2 servers. The SRX can use this feed in a security policy to automatically block traffic to or from these hosts.
- Question 7Intermediate
SSL Proxy · Configuration
What is the correct command to load a new local certificate and private key file named
corp-cert.peminto an SRX Series device for use with SSL Proxy?Show answer & explanation
Correct answer: C
The correct operational mode command to load a local certificate and its corresponding private key from a file on the device is
request security pki local-certificate load. You must specify acertificate-idfor referencing it in the configuration and thefilenameof the PEM file which contains both the certificate and the key. - Question 8Advanced
IPsec VPN · Route-Based VPN Integration
Background:
A multinational corporation uses a hub-and-spoke IPsec VPN topology to connect its remote branches to the headquarters. The headquarters uses an SRX5800 chassis cluster, and each branch has a single SRX345. Dynamic routing (OSPF) is used over the VPNs to exchange routes. The company is acquiring a new subsidiary that has a strict policy against running dynamic routing protocols with external partners.Current Setup:
- HQ SRX Cluster: Node 0 (Primary for RG1+), Node 1 (Backup)
- VPNs: Route-based, using st0 interfaces in a dedicated VPN routing instance.
- Routing: OSPF area 0 runs over all st0 interfaces.
New Requirement:
The new subsidiary must be connected via an IPsec VPN. Their network is 172.16.100.0/24. They will only accept a VPN configuration that relies on static routing; they will not peer via OSPF. The existing OSPF-based VPNs for other branches must remain operational.Challenge:
How can the network administrator integrate the new subsidiary's VPN into the existing HQ chassis cluster and routing design while meeting all requirements? The following diagram shows the desired state.graph TD subgraph HQ Data Center HQ_Cluster[SRX5800 Cluster] end subgraph Branches Branch1[SRX345 - OSPF] Branch2[SRX345 - OSPF] end subgraph New Subsidiary Sub1[3rd-Party FW - Static] end HQ_Cluster -- VPN1 --- Branch1 HQ_Cluster -- VPN2 --- Branch2 HQ_Cluster -- "New VPN3 (Static Route)" --- Sub1Show answer & explanation
Correct answer: B
This is the correct and most scalable solution. By creating another route-based VPN with a new st0 interface (e.g., st0.2), it maintains consistency with the existing design. A static route is then configured to direct traffic for the subsidiary's network over this new tunnel interface, satisfying their requirement. To allow the other OSPF-enabled branches to reach the new subsidiary, this static route must be redistributed into OSPF. This integrates the statically routed peer into the dynamic routing domain without requiring the peer to participate in OSPF.
- Question 9Intermediate
Security Director · Policy Management
True or False: In a Junos Space Security Director environment, publishing and updating a security policy automatically commits the changes to the managed SRX devices.
Show answer & explanation
Correct answer: B
This statement is false. In Security Director, publishing a policy saves the changes within the Security Director database. The 'Update Device' action is a separate, explicit step that must be performed to push the configuration changes to the managed devices. This two-step process allows administrators to stage multiple changes before deploying them to the network.
- Question 10Beginner
Intrusion Detection and Prevention (IDP) · IDP Policy
A security administrator is configuring IDP on an SRX device. They want to use one of Juniper's pre-defined policy templates as a baseline. Which template is designed to provide a high level of security by enabling attack objects with a severity of 'critical', 'major', and 'minor'?
Show answer & explanation
Correct answer: C
The 'Recommended' IDP policy template is Juniper's suggested baseline for comprehensive protection. It is designed to defend against a wide range of common and critical threats by enabling attack objects across all major severity levels (critical, major, and minor) while aiming to minimize false positives.
Ready for the real thing?
The full JN0-336 simulator has every exam-style question, timed mode, and instant scoring.