
Juniper NetworksCertified Specialist, Security (JNCIS-SEC)
Domain 2Objective 5
Configure, Monitor, or Troubleshoot IPsec VPNs JN0-336 Practice Questions (Page 1)
Part of the IPsec VPN domain, which makes up ~16% of our current practice bank. Juniper Networks does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 11 practice questions to prepare you well beyond it. (estimate)
11questions here
3free pages
3concepts
Questions 1–5
- 1
In Junos OS, which configuration hierarchy is used to define the parameters for an IKE proposal, such as authentication method, encryption algorithm, and Diffie-Hellman group?
Select an answer first - 2
A Junos device is configured with an IPsec VPN to a remote site. The tunnel is not establishing. The administrator runs 'show security ike security-associations' and sees the IKE SA is in state 'IKE_SA_INIT'. What does this indicate?
Select an answer first - 3
A company is setting up an IPsec VPN between two Junos devices. The security policy requires that the IKE phase 1 use AES-256 encryption and SHA-256 authentication. The administrator configures the IKE proposal accordingly. However, the tunnel fails to establish. What is the most likely cause?
Select an answer first - 4
When an IPsec SA fails to establish, which Junos operational command would you use to check whether the IKE phase 1 SA is up and to view its state?
Select an answer first - 5
Which Junos operational command displays the active IPsec security associations, including the tunnel index, gateway, and traffic statistics?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Juniper Networks. “JN0-336” is a trademark of its owner, used for identification only.