About the Exam

This exam is the professional-level certification for Juniper security and Junos OS on SRX Series devices. It is designed for networking professionals with advanced knowledge of Junos OS and verifies understanding of advanced security technologies plus related configuration and troubleshooting skills. The exam covers topics including security policies and zones, Layer 2 security, advanced NAT, IPsec VPNs, advanced policy-based routing, multinode high availability, and automated threat mitigation.

Exam Topics

  • Troubleshooting Security Policies and Security Zones0%
  • Logical Systems and Tenant Systems0%
  • Layer 2 Security0%
  • Advanced Network Address Translation (NAT)0%
  • Advanced IPsec VPNs0%
  • Advanced Policy-Based Routing (APBR)0%
  • Multinode High Availability (HA)0%
  • Automated Threat Mitigation0%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated June 27, 2026 at 6:05 AM

Topic filter
Retired questions
Question sort

QuestionQ1

Automated Threat Mitigation

You have deployed automated threat mitigation using Security Director with Policy Enforcer, Juniper ATP Cloud, SRX Series devices, and EX Series switches.

In this scenario, which device is responsible for blocking infected hosts?

  • A EX Series switch
  • B Juniper ATP Cloud
  • C Policy Enforcer
  • D Security Director
Explanation

Policy Enforcer orchestrates and distributes threat-mitigation policies using intelligence from Juniper ATP Cloud, while the EX Series switch acts as the in-network enforcement point that blocks an infected host. Juniper specifies that enforcing an infected-host policy within the network requires a switch assigned to the site.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Layer 2 Security

Refer to the exhibit below.

Question Image

Based on the exhibit, which mode is the SRX Series device operating in?

  • A transparent
  • B packet
  • C mixed
  • D Ethernet switching
Explanation

The SRX global configuration explicitly reports Global Mode: Transparent bridge, which is the Layer 2 transparent operating mode. Juniper identifies transparent-bridge as the global mode for Layer 2 transparent operation, distinct from Ethernet switching mode.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Advanced Network Address Translation (NAT)

An SRX Series device is deployed at the network edge to protect Internet-bound sessions from local hosts by using source NAT. You need to ensure that users can interact with Internet applications that require more than one TCP session for the same application session.

Which two features meet this requirement?

Choose two
  • A persistent NAT
  • B address persistence
  • C STUN
  • D double NAT
Explanation

Source NAT address persistence assigns a host the same translated IP address for multiple sessions. Persistent NAT maintains a consistent reflexive transport-address mapping for requests from the relevant internal transport address. Together, these features support applications that establish multiple TCP sessions but require consistent NAT identity or mapping.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Advanced IPsec VPNs

You are using AutoVPN to deploy a hub-and-spoke VPN that connects your enterprise sites.

Which two statements are true in this scenario?

Choose two
  • A New spoke sites can be added without explicit configuration on the hub.
  • B AutoVPN requires OSPF over IPsec to discover and add new spokes.
  • C All spoke-to-spoke IPsec communication will pass through the hub.
  • D Direct spoke-to-spoke tunnels can be established automatically.
Explanation

AutoVPN automatically establishes a hub tunnel to each spoke that selects that hub, allowing new spokes to be added without explicit per-spoke configuration on the hub. In a hub-and-spoke topology, spokes build tunnels only to their configured hubs; communication between spokes is therefore routed through a hub. OSPF is optional and direct spoke-to-spoke tunnels are not created in this topology.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Multinode High Availability (HA)

Select the Exhibit button.

Question Image

Based on the exhibit, which statement is true?

  • A SRG1 is configured in hybrid mode.
  • B The ICL is encrypted.
  • C If SRG1 moves to peer 2, peer 1 will forward packets sent to the SRG1 interfaces.
  • D If SRG1 moves to peer 2, peer 1 will drop packets sent to the SRG1 interfaces.
Explanation

For an SRG configured with Process Packet In Backup State: No, the backup node does not process packets for that SRG. After SRG1 moves to peer 2, peer 1 is the backup node and drops packets sent to the SRG1 interfaces. The SWITCHING deployment type is distinct from hybrid mode, and Encrypted: NO indicates that the HA peer connection is not encrypted.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home