[2021] JN0-1331 by JNCDS-SEC Actual Free Exam Practice Test
Free JNCDS-SEC JN0-1331 Exam Question
Juniper JN0-1331 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
| Topic 10 |
|
NEW QUESTION 18
You are asked to include anti-malware features into an existing network design. Traffic from the infected machines must be moved to a quarantined VLAN.
Which product will provide this segregation?
- A. Sky ATP
- B. screens
- C. Software Defined Secure Network
- D. unified threat management
Answer: C
NEW QUESTION 19
You have multiple SRX chassis clusters on a single broadcast domain.
Why must you assign different cluster IDs in this scenario?
- A. to avoid redundancy group conflicts
- B. to avoid MAC address conflicts
- C. to avoid node numbering conflicts
- D. to avoid control link conflicts
Answer: B
NEW QUESTION 20
Which statement about IPsec tunnels is true?
- A. They are used to secure and encrypt traffic between tunnel endpoints
- B. They are used to prevent routing loops in a Layer 2 environment
- C. They are used to combine multiple interfaces into a single bundle
- D. They are used to provide in-depth packet inspection for traffic leaving your network
Answer: A
NEW QUESTION 21
You are designing a solution to protect a service provider network against volumetric denial-of-service attacks.
Your main concern is to protect the network devices.
Which two solutions accomplish this task? (Choose two.)
- A. BGP FlowSpec
- B. screens
- C. next-generation firewall
- D. intrusion prevention system
Answer: A,D
NEW QUESTION 22
Which two protocols are supported natively existing Kubernetes-orchestrated unos automation stack? (Choose two.)
- A. NETCONF
- B. CIP
- C. Jenkins
- D. PyEZ
Answer: A,D
NEW QUESTION 23
You are asked to design a VPN solution between 25 branches of a company. The company wants to have the sites talk directly to each other in the event of a hub device failure. The solution should follow industry standards.
Which solution would you choose in this scenario?
- A. Auto Discovery VPN
- B. full mesh VPN
- C. Group VPN
- D. AutoVPN
Answer: A
Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-auto-discovery- vpns.html
NEW QUESTION 24
You are designing an SDSN security solution for a new campus network. The network will consist of Juniper Networks Policy Enforcer, Juniper Networks switches, third-party switches, and SRX Series devices. The switches and the SRX Series devices will be used as security enforcement points.
Which component supports the SRX Series devices in this scenario?
- A. RADIUS server
- B. certificate server
- C. Security Director
- D. DHCP server
Answer: C
NEW QUESTION 25
A hosting company is migrating to cloud-based solutions. Their customers share a physical firewall cluster, subdivided into individual logical firewalls for each customer. Projection data shows that the cloud service will soon deplete all the resources within the physical firewall. As a consultant, you must propose a scalable solution that continues to protect all the cloud customers while still securing the existing physical network.
In this scenario, which solution would you propose?
- A. Deploy a vSRX cluster in front of each customer's servers while keeping the physical firewall cluster
- B. Remove the physical firewall cluster and deploy vSRX clusters dedicated to each customer's servers
- C. Deploy a software-defined networking solution
- D. Replace the physical firewall cluster with a higher-performance firewall
Answer: B
NEW QUESTION 26
Which two protocols are supported natively by the Junos automation stack? (Choose two.)
- A. NETCONF
- B. CIP
- C. Jenkins
- D. PyEZ
Answer: A,D
NEW QUESTION 27
You must design a small branch office firewall solution that provides application usage statistics.
In this scenario, which feature would accomplish this task?
- A. AppQoS
- B. AppTrack
- C. UTM
- D. AppFW
Answer: B
Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-application- tracking.html
NEW QUESTION 28
You are concerned about users downloading malicious attachments at work while using encrypted Web mail. You want to block these malicious files using your SRX Series device.
In this scenario, which two features should you use? (Choose two.)
- A. Sky ATP SMTP scanning
- B. Sky ATP HTTP scanning
- C. SSL forward proxy
- D. SSL reverse proxy
Answer: A,C
NEW QUESTION 29
You work for an ISP that wants to implement remote-triggered black hole (RTBH) filters.
What are three considerations in this scenario? (Choose three.)
- A. BGP FlowSpec improves the RTBH model by implementing dynamic firewall filters
- B. Destination RTBH requires uRPF to be implemented on the service provider's network edge
- C. Source RTBH can block legitimate traffic on the network
- D. Destination RTBH essentially completes the attack on the victim's IP
- E. Source RTBH requires uRPF to be implemented on the service provider's network core
Answer: A,C,E
NEW QUESTION 30
You are deploying Security Director with the logging and reporting functionality for VMs that use SSDs. You expect to have approximately 20,000 events per second of logging in your network.
In this scenario, what is the minimum number of logging and reporting devices that should be used?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos-space17.1/topics/task/multi-task/junos- space-sd-log-collector-installing.html
NEW QUESTION 31
What are two benefits of the vSRX in a virtualized private or public cloud multitenant environment? (Choose two.)
- A. OSPFv3 capabilities
- B. stateful firewall protection at the tenant edge
- C. 100GbE interface support
- D. full logical systems capabilities
Answer: B,D
Explanation:
Reference:
https: //www.juniper.net/documentation/en_US/junos/topics/topic-map/logical-systems-overview.html
NEW QUESTION 32
You must allow applications to connect to external servers. The session has embedded IP address information to enable the remote system to establish a return session.
In your design, which function should be implemented?
- A. source NAT
- B. application layer gateway
- C. destination NAT
- D. HTTP redirect
Answer: B
NEW QUESTION 33
You are creating a security design proposal for an enterprise customer. As part of the design, you are implementing 802.1x authentication on your EX Series devices.
In this scenario, which two statements are correct? (Choose two.)
- A. The supplicant is the device that is being authenticated
- B. The authenticator is the device that is being authenticated
- C. The authenticator is the device that prevents the supplicant's access until it is authenticated
- D. The supplicant is the device that prevents the authenticator's access until it is authenticated
Answer: A,C
NEW QUESTION 34
You are deploying Security Director with the logging and reporting functionality for VMs that use SSDs. You expect to have approximately 20,000 events per second of logging in your network.
In this scenario, what is the minimum number of logging and reporting devices that should be used?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
NEW QUESTION 35
What are two reasons for using cSRX over vSRX? (Choose two.)
- A. cSRX supports the BGP protocol
- B. cSRX supports IPsec
- C. cSRX loads faster
- D. cSRX uses less memory
Answer: C,D
NEW QUESTION 36
Click the Exhibit button.
You are designing the virtualized server deployment shown in the exhibit in your data center. The vSRX device is acting as a Layer 2 firewall and the two VMs must communicate through the vSRX device.
Which two actions must you perform to accomplish this task? (Choose two.)
- A. Place both VMs in different VLANs
- B. Place both VMs in different vSwitches
- C. Place both VMs in the same vSwitch
- D. Place both VMs in the same VLAN
Answer: B,D
NEW QUESTION 37
You are designing an SDSN security solution for a new campus network. The network will consist of Juniper Networks Policy Enforcer, Juniper Networks switches, third-party switches, and SRX Series devices. The switches and the SRX Series devices will be used as security enforcement points. The design must be able to change the VLAN mapping of the switch port of a user that is already authenticated to the network in the event that the end user device becomes compromised.
Which component satisfies this requirement?
- A. RADIUS server
- B. certificate server
- C. Security Director
- D. DHCP server
Answer: C
NEW QUESTION 38
You are asked to design a secure enterprise WAN where all payload data is encrypted and branch sites communicate directly without routing all traffic through a central hub.
Which two technologies would accomplish this task? (Choose two.)
- A. group VPN
- B. Auto Discovery VPN
- C. MPLS Layer 3 VPN
- D. AutoVPN
Answer: A,B
NEW QUESTION 39
What are two benefits of the vSRX in a virtualized private or public cloud multitenant environment?
(Choose two.)
- A. OSPFv3 capabilities
- B. stateful firewall protection at the tenant edge
- C. 100GbE interface support
- D. full logical systems capabilities
Answer: B,D
Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/vsrx/topics/concept/security-vsrx-overview- generic.html
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/logical-systems-overview.html
NEW QUESTION 40
......
Juniper JN0-1331 Actual Questions and Braindumps: https://www.vcetorrent.com/JN0-1331-valid-vce-torrent.html