
Juniper NetworksCertified Specialist, Security (JNCIS-SEC)
Domain 2Objective 2
IPsec Traffic Processing JN0-336 Practice Questions (Page 4)
Part of the IPsec VPN domain, which makes up ~16% of our current practice bank. Juniper Networks does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
10concepts
Questions 16–20
- 16
Which protocol and port are typically used by NAT-T for UDP encapsulation of IPsec packets?
Select an answer first - 17
A network engineer is configuring an IPsec VPN between two sites. Site A has a static public IP, and Site B has a dynamic public IP behind a NAT device. The engineer wants to ensure the VPN is resilient to IP address changes at Site B. Which configuration approach should be used?
Select an answer first - 18
In IPsec traffic processing, what is the primary role of the Security Parameter Index (SPI)?
Select an answer first - 19
A network architect is designing a solution to encrypt traffic between two application servers in different data centers. The servers communicate using a custom protocol that relies on the source IP address being preserved. The architect is considering IPsec transport mode. What is the primary advantage of using transport mode over tunnel mode in this scenario?
Select an answer first - 20
In outbound IPsec processing, what is the purpose of adding the IPsec header after encryption?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Juniper Networks. “JN0-336” is a trademark of its owner, used for identification only.