Security, Specialist (JNCIS-SEC) JN0-332-Exam

Identify concepts, general features and functionality of Junos OS security Junos security architecture Branch vs. high-end platforms Major hardware components of SRX Series services gateways Packet flow Packet-based vs. session-based forwarding Security, Specialist (JNCIS-SEC)

This list provides a general view of the skill set required to successfully complete the specified certification exam. Topics listed are subject to change. Junos Security Overview Zones Security Policies Firewall User Authentication Screens NAT IPSec VPNs High Availability (HA) Clustering Unified Threat Management (UTM) Security, Specialist (JNCIS-SEC)

Sample Questions Question No 1 What is the maximum number of layers of decompression that juniper-express-engine (express AV) can decompress for the HTTP protocol? Options A. 0 B. 1 C. 4 D. 8 Answer: B

Question No 2 Which URL will match the URLpattern Options A. B. C. D. Answer: B

Question No 3 Which two statements are true for both express antivirus and full file-based antivirus? (Choose two.) Options A. Signature updates of the pattern database are obtained from Symantec. B. Intelligent prescreening functionality is identical in both express antivirus and full antivirus. C. Both express antivirus and full file-based antivirus use the same scan engines. D. The database pattern server is available through both HTTP and HTTPS. Answer: B,D

Question No 4 You are troubleshooting a security policy. The operational command show security flow session does not show any sessions for this policy. Which statement is correct? Options A. Logging on session initialization has not been enabled in the policy. B. Logging on session closure has not been enabled in the policy. C. The traffic is not being matched by the policy. D. The security monitoring performance session command should be used to show sessions. Answer: C

Question No 5 Which two statements are true about route-based IPsec VPNs on an SRX Series device? (Choose two.) Options A. Route-based VPNs must use IKE aggressive mode. B. New tunnels are generated with each new flow of traffic. C. An st0 interface must be bound to each VPN. D. A security policy must permit the traffic. Answer: C,D

