View Full Juniper JN0-336 Exam Dumps and Practice Test Dumps
Question 241.
Which feature can inspect DNS queries for malicious domains?
- DNS security
- Route policy
- Session mirror
- Interface monitor
Correct Answer: 1
Explanation:
DNS security can inspect DNS-related activity and identify queries associated with malicious or suspicious domains when the appropriate security service and intelligence sources are configured. DNS-based threats can be detected before a client establishes a connection to a harmful destination, making DNS inspection an important security control. Route policies influence routing decisions, session mirroring supports traffic analysis, and interface monitoring observes connectivity conditions. Effective DNS security depends on current threat information and appropriate policy configuration. Administrators should also consider how DNS requests are routed through the security device when troubleshooting unexpected domain-resolution or threat-detection results.
Question 242.
What does certificate revocation checking verify?
- Interface availability
- Certificate validity status
- Route convergence
- Session bandwidth
Correct Answer: 2
Explanation:
Certificate revocation checking determines whether a digital certificate has been revoked before its normal expiration date. A certificate authority may revoke a certificate because its private key was compromised, the certificate was issued incorrectly, or another trust-related condition occurred. Revocation information can be obtained through mechanisms such as certificate revocation lists or online status services, depending on the configuration. Interface availability, routing convergence, and session bandwidth are unrelated. Revocation checking strengthens certificate-based security because simply verifying a certificate’s signature and expiration date does not necessarily establish that the certificate remains trusted.
Question 243.
Which protocol can provide online certificate revocation status?
- FTP
- NTP
- OCSP
- SNMP
Correct Answer: 3
Explanation:
OCSP, or Online Certificate Status Protocol, allows a system to query certificate status information from an online responder. Instead of relying only on a periodically downloaded certificate revocation list, OCSP can provide a more direct status response for a particular certificate. This can be useful when certificate validity needs to be checked during secure communications. FTP transfers files, NTP synchronizes time, and SNMP provides network management information. When certificate-based inspection or authentication depends on revocation checking, administrators should verify that the relevant OCSP configuration, responder accessibility, and trust relationships are correctly established.
Question 244.
What can a captive portal redirect timeout control?
- Route advertisement
- DNS recursion
- Antivirus scanning
- Portal session duration
Correct Answer: 4
Explanation:
A captive portal redirect timeout can influence how long a user remains subject to the portal-related access process before the session or redirect condition expires. Captive portals are commonly used to require users to authenticate before receiving normal network access. Timeout behavior helps control the duration of portal-related sessions and can affect user experience when authentication is delayed or incomplete. Route advertisement, DNS recursion, and antivirus scanning have separate purposes. Administrators configuring captive portal access should consider timeout values together with authentication requirements so users receive predictable behavior without unnecessarily prolonged or repeated authentication prompts.
Question 245.
Which authentication source can validate users through an external server?
- RADIUS server
- Local address book
- Security log
- Route database
Correct Answer: 1
Explanation:
A RADIUS server can provide external authentication for users connecting through supported security services. Instead of maintaining all credentials locally, the security device communicates with the centralized RADIUS infrastructure to validate authentication requests. This approach can simplify account administration and support consistent authentication across multiple network devices. An address book stores network objects, security logs record events, and a route database contains routing information. When implementing RADIUS authentication, administrators should verify server reachability, shared-secret configuration, authentication parameters, and the expected user response because any of these can affect successful authentication.
Question 246.
What does a firewall authentication table primarily track?
- Route advertisements
- Authenticated user sessions
- Antivirus signatures
- Interface descriptions
Correct Answer: 2
Explanation:
A firewall authentication table maintains information associated with users who have been authenticated through supported firewall authentication mechanisms. This information can allow security policies to associate network traffic with user identities rather than relying solely on source addresses. Such identity information can then support user-aware access control and monitoring. Route advertisements, antivirus signatures, and interface descriptions serve different purposes. When troubleshooting identity-based policies, administrators should verify that users are successfully authenticated and that their sessions are correctly represented in the authentication information used by the security device.
Question 247.
Which feature can associate authenticated users with directory groups?
- Packet capture
- Route redistribution
- LDAP group mapping
- Interface redundancy
Correct Answer: 3
Explanation:
LDAP group mapping associates authenticated identities with groups maintained in an LDAP directory. This allows security controls to use directory membership when determining which users should receive particular access privileges or policy treatment. Group-based identity controls can simplify administration because policies can reference organizational groups rather than requiring individual user definitions. Packet capture collects traffic, route redistribution handles routing information, and interface redundancy provides availability. Accurate LDAP mapping requires appropriate directory connectivity, group queries, and matching configuration. Administrators should verify group membership resolution when an identity-aware policy does not behave as expected.
Question 248.
Which authentication protocol is commonly associated with centralized device administration?
- TACACS+
- FTP
- RTSP
- ICMP
Correct Answer: 1
Explanation:
TACACS+ is commonly used for centralized authentication, authorization, and accounting of administrative access to network devices. It can help organizations manage administrator authentication through a centralized service rather than maintaining separate local credentials on every device. This can support consistent access control and auditing practices. FTP is a file-transfer protocol, RTSP controls multimedia streaming, and ICMP supports network control and diagnostic messaging. When TACACS+ is deployed, administrators should verify server communication, authentication settings, and authorization behavior so that legitimate administrative access remains available while centralized controls are enforced.
Question 249.
What can two-factor authentication add to user verification?
- Route redundancy
- Interface monitoring
- Additional identity proof
- Packet compression
Correct Answer: 3
Explanation:
Two-factor authentication adds an additional verification requirement beyond a single authentication factor. Typically, the factors involve different categories, such as something the user knows and something the user possesses or controls. Requiring multiple independent forms of proof can strengthen identity verification for remote or administrative access. Route redundancy concerns network availability, interface monitoring observes connectivity, and packet compression concerns traffic efficiency. Two-factor authentication must be integrated with an appropriate authentication workflow, and administrators should ensure that the additional verification mechanism is reachable and correctly associated with the relevant users or authentication service.
Question 250.
What does user session mapping associate?
- Users with network traffic
- Routes with interfaces
- Certificates with domains
- Policies with log files
Correct Answer: 4
Explanation:
User session mapping associates authenticated users with network sessions or traffic so that security controls can make decisions based on identity. This is useful for environments where multiple users may share network infrastructure or addresses and where address-based identification alone is insufficient. By maintaining a relationship between user identity and observed traffic, the security device can support identity-aware policies and more meaningful monitoring. Route-to-interface relationships, certificate-domain associations, and policy-log relationships serve different purposes. Accurate session mapping depends on reliable authentication and timely identity information so that policies continue to reflect the correct user.
Question 251.
What can a security intelligence feed refresh interval determine?
- Interface MTU
- Threat data update timing
- VPN tunnel mode
- TCP window size
Correct Answer: 2
Explanation:
A security intelligence feed refresh interval determines how frequently the security device attempts to obtain updated threat information from a configured intelligence source. Regular updates help ensure that newly identified malicious indicators can become available to security controls in a timely manner. Interface MTU controls packet size, VPN tunnel mode determines encapsulation behavior, and TCP window size affects transport-level flow control. Administrators should select an appropriate refresh interval based on operational requirements and feed characteristics. They should also monitor update status because a configured interval does not guarantee successful retrieval when connectivity or authentication problems exist.
Question 252.
Which IDP component groups related attack signatures?
- Attack object
- DNS profile
- Address book
- Route policy
Correct Answer: 1
Explanation:
An IDP attack object can group related attack signatures so that administrators can apply a common security treatment to a defined collection of threats. This simplifies IDP policy configuration by allowing multiple signatures to be managed through a logical object rather than individually in every policy. DNS profiles manage DNS-related security behavior, address books define network objects, and route policies influence routing decisions. Attack objects are useful when organizations need consistent actions for a category of related attacks. Administrators should review the signatures included in an attack object to understand exactly which traffic patterns the policy will affect.
Question 253.
What can a custom IDP signature context specify?
- Interface bandwidth
- Routing preference
- Protocol-specific matching
- Certificate expiration
Correct Answer: 3
Explanation:
A custom IDP signature can use protocol-specific characteristics to identify traffic patterns associated with a particular threat or application behavior. Defining an appropriate context helps narrow detection to the traffic characteristics that matter rather than relying on broad network attributes alone. This can be useful when a required attack pattern is not adequately represented by predefined signatures. Interface bandwidth, routing preference, and certificate expiration are unrelated to signature matching context. Custom IDP signatures should be tested carefully because overly broad conditions may produce false detections, while overly restrictive conditions may fail to identify the intended traffic.
Question 254.
What does anomaly-based IPS detection examine?
- Normal traffic patterns
- Certificate ownership
- DNS server hierarchy
- Route export rules
Correct Answer: 4
Explanation:
Anomaly-based intrusion prevention examines traffic for behavior that deviates from expected or established protocol patterns. Instead of relying exclusively on a known attack signature, anomaly detection can identify unusual protocol behavior that may indicate malformed, suspicious, or potentially hostile traffic. Certificate ownership, DNS hierarchy, and route export rules are unrelated to anomaly detection. Administrators should understand that anomaly-based controls may require careful tuning because unusual legitimate traffic can sometimes resemble abnormal behavior. Appropriate thresholds and security actions help balance detection coverage with the risk of unnecessary blocking or alert generation.
Question 255.
Which screen feature can record detected security events?
- Screen action logging
- Route aggregation
- Interface bundling
- DNS forwarding
Correct Answer: 1
Explanation:
Screen action logging records information about security-screen events and the actions taken when configured traffic matches a protection condition. Security screens can detect various abnormal traffic patterns, including floods, scans, and malformed packets. Logging these events provides administrators with visibility into detected activity and can help correlate security events with traffic behavior. Route aggregation, interface bundling, and DNS forwarding address different networking functions. When investigating repeated security-screen detections, administrators can use the logs to identify event timing, affected interfaces, and relevant traffic characteristics.
Question 256.
What is a SYN cookie mechanism designed to mitigate?
- DNS amplification
- TCP connection exhaustion
- Route instability
- Certificate replay
Correct Answer: 2
Explanation:
SYN cookies help mitigate TCP connection-exhaustion attacks in which an attacker sends many initial SYN requests without completing the corresponding TCP handshakes. Instead of immediately allocating extensive connection state for every request, a SYN-cookie mechanism can encode information into the response so that resources are committed only after a legitimate handshake progresses. DNS amplification, route instability, and certificate replay represent different security or networking concerns. SYN protection is particularly relevant to services exposed to untrusted networks, where large numbers of incomplete TCP connection attempts could otherwise consume resources and reduce service availability.
Question 257.
Which protection targets excessive UDP traffic?
- TCP proxy
- UDP flood protection
- DNS caching
- Route filtering
Correct Answer: 3
Explanation:
UDP flood protection is designed to detect and control excessive UDP traffic that could consume network or security-device resources. Because UDP does not establish connections in the same manner as TCP, large volumes of unsolicited or abusive UDP packets can place significant processing and bandwidth demands on a system. TCP proxying addresses connection handling, DNS caching improves name-resolution efficiency, and route filtering controls routing information. Appropriate UDP flood thresholds help distinguish abnormal traffic from legitimate high-volume UDP applications. Administrators should consider expected traffic patterns when selecting protection thresholds to avoid unnecessarily affecting valid services.
Question 258.
What does port-scan detection identify?
- Multiple service probes
- Certificate chain errors
- Route metric changes
- DNS cache misses
Correct Answer: 4
Explanation:
Port-scan detection identifies patterns in which a source probes multiple destination ports to discover available services. Such activity is commonly associated with network reconnaissance because an attacker can use responses to determine which services may be accessible. Security-screen mechanisms can detect these patterns and apply configured actions or generate logs. Certificate chain errors, route metric changes, and DNS cache misses represent unrelated conditions. Administrators should interpret port-scan detections within the broader traffic context because legitimate security scanning or network-management activity can also generate similar patterns when authorized testing is performed.
Question 259.
Which attack protection addresses malformed fragmented IP traffic?
- Land attack protection
- IP sweep detection
- Tear-drop protection
- Port-scan filtering
Correct Answer: 3
Explanation:
Tear-drop protection addresses attacks involving malformed or overlapping IP fragments that can cause problems for vulnerable systems during packet reassembly. The security device can detect suspicious fragmentation patterns and apply the configured protection action. Land attack protection addresses packets designed with matching source and destination characteristics, while IP sweep detection identifies probing across multiple addresses. Port-scan filtering focuses on service-probing behavior. Fragmentation-related protections are useful because malformed packet structures can exploit weaknesses in protocol processing even when the traffic does not resemble a conventional application-level attack.
Question 260.
What does TCP timestamp checking examine?
- TCP option information
- DNS query content
- OSPF area type
- VPN user identity
Correct Answer: 1
Explanation:
TCP timestamp checking examines timestamp-related information carried within TCP options. TCP options can provide additional information used by endpoints during communication, and security screening can validate or restrict certain characteristics when configured. This is different from inspecting DNS query content, determining OSPF area types, or identifying VPN users. Protocol validation mechanisms can help reject traffic containing unusual or potentially problematic TCP characteristics. Administrators troubleshooting legitimate applications should consider whether security-screen settings affecting TCP options could interfere with specialized traffic, particularly when packet captures show unexpected handling of TCP segments.