
JN0-1331 Dumps with Practice Exam Questions Answers
JN0-1331 by JNCDS-SEC Actual Free Exam Practice Test
Juniper JN0-1331 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
| Topic 10 |
|
NEW QUESTION 37
You are required to design a university network to meet the conditions shown below.
* Users connected to the university network should be able to access the Internet and the research department lab network.
* The research department lab network should not be able to reach the Internet.
Which three actions satisfy the design requirements? (Choose three.)
- A. Use a global deny security policy for the research lab
- B. Use separate security zones for each department
- C. Use a global permit policy for Internet traffic
- D. Use the default deny security policy for the research lab
- E. Use a static NAT rule between the internal zones for the research lab
Answer: A,B,C
NEW QUESTION 38
You are asked to include anti-malware features into an existing network design. Traffic from the infected machines must be moved to a quarantined VLAN.
Which product will provide this segregation?
- A. Sky ATP
- B. Software Defined Secure Network
- C. unified threat management
- D. screens
Answer: B
NEW QUESTION 39
Your customer needs help designing a single solution to protect their combination of various Junos network devices from unauthorized management access.
Which Junos OS feature will provide this protection?
- A. Use a firewall filter applied to the lo0 interface
- B. Use the management zone host-inbound-traffic feature
- C. Use a firewall filter applied to the fxp0 interface
- D. Use a security policy with the destination of the junos-host zone
Answer: C
NEW QUESTION 40
You are designing an SDSN security solution for a new campus network. The network will consist of Juniper Networks Policy Enforcer, Juniper Networks switches, third-party switches, and SRX Series devices. The switches and the SRX Series devices will be used as security enforcement points.
Which component supports the SRX Series devices in this scenario?
- A. RADIUS server
- B. certificate server
- C. Security Director
- D. DHCP server
Answer: C
NEW QUESTION 41
You are creating a security design proposal for an enterprise customer. As part of the design, you are implementing 802.1x authentication on your EX Series devices.
In this scenario, which two statements are correct? (Choose two.)
- A. The authenticator is the device that is being authenticated
- B. The authenticator is the device that prevents the supplicant's access until it is authenticated
- C. The supplicant is the device that is being authenticated
- D. The supplicant is the device that prevents the authenticator's access until it is authenticated
Answer: B,C
Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/802-1x-authentication- switching-devices.html
NEW QUESTION 42
You are working on a network design that will use EX Series devices as Layer 2 access switches in a campus environment. You must include Junos Space in your design. You want to take advantage of security features supported on the devices.
Which two security features would satisfy this requirement? (Choose two.)
- A. Stateful Firewall
- B. ALG
- C. Access Control
- D. SDSN
Answer: A,C
NEW QUESTION 43
You want to deploy JATP in your network that uses SRX Series devices.
In this scenario, which feature must you enable on the SRX Series devices?
- A. AppSecure
- B. IPS
- C. UTM antivirus
- D. SSL forward proxy
Answer: D
NEW QUESTION 44
Which two steps should be included in your security design process? (Choose two.)
- A. Define overall security policies
- B. Identify the firewall enforcement points
- C. Define safety requirements for the customer's organization
- D. Identify external attackers
Answer: A,B
Explanation:
Explanation/Reference: https://www.juniper.net/assets/us/en/local/pdf/whitepapers/2000591-en.pdf
NEW QUESTION 45
You are required to design a university network to meet the conditions shown below.
Users connected to the university network should be able to access the Internet and the research department lab network.
The research department lab network should not be able to reach the Internet.
Which three actions satisfy the design requirements? (Choose three.)
- A. Use the default deny security policy for the research lab
- B. Use separate security zones for each department
- C. Use a global permit policy for Internet traffic
- D. Use a global deny security policy for the research lab
- E. Use a static NAT rule between the internal zones for the research lab
Answer: A,B,C
NEW QUESTION 46
You are concerned about users downloading malicious attachments at work while using encrypted Web mail. You want to block these malicious files using your SRX Series device.
In this scenario, which two features should you use? (Choose two.)
- A. Sky ATP HTTP scanning
- B. Sky ATP SMTP scanning
- C. SSL forward proxy
- D. SSL reverse proxy
Answer: B,C
NEW QUESTION 47
You must allow applications to connect to external servers. The session has embedded IP address information to enable the remote system to establish a return session.
In your design, which function should be implemented?
- A. HTTP redirect
- B. destination NAT
- C. application layer gateway
- D. source NAT
Answer: D
NEW QUESTION 48
Which two features are used to stop IP spoofing in and out of your network? (Choose two.)
- A. GeoIP
- B. unicast reverse path forwarding
- C. IPS
- D. firewall filters
Answer: A,B
NEW QUESTION 49
You are asked to design a secure enterprise WAN where all payload data is encrypted and branch sites communicate directly without routing all traffic through a central hub.
Which two technologies would accomplish this task? (Choose two.)
- A. Auto Discovery VPN
- B. AutoVPN
- C. MPLS Layer 3 VPN
- D. group VPN
Answer: A,C
NEW QUESTION 50
What are two benefits of the vSRX in a virtualized private or public cloud multitenant environment? (Choose two.)
- A. full logical systems capabilities
- B. 100GbE interface support
- C. stateful firewall protection at the tenant edge
- D. OSPFv3 capabilities
Answer: A,C
NEW QUESTION 51
You are designing a new campus Internet access service that implements dynamic NAT for customer IP addressing. The customer requires services that allow peer-to-peer networking and online gaming.
In this scenario, what will accomplish this task?
- A. EVPN over IPsec
- B. one-to-one NAT
- C. stacked VLAN tagging
- D. endpoint independent mapping
Answer: C
NEW QUESTION 52
Which two protocols are supported natively by the Junos automation stack? (Choose two.)
- A. PyEZ
- B. CIP
- C. Jenkins
- D. NETCONF
Answer: A,D
Explanation:
Explanation/Reference:
NEW QUESTION 53
You are creating a security design proposal for an enterprise customer. As part of the design, you are implementing 802.1x authentication on your EX Series devices.
In this scenario, which two statements are correct? (Choose two.)
- A. The authenticator is the device that is being authenticated
- B. The authenticator is the device that prevents the supplicant's access until it is authenticated
- C. The supplicant is the device that is being authenticated
- D. The supplicant is the device that prevents the authenticator's access until it is authenticated
Answer: B,C
NEW QUESTION 54
You are designing a data center interconnect between two sites across a service provider Layer 2 leased line.
The sites require Layer 2 connectivity between hosts, and the connection must be secure.
In this scenario, what will accomplish this task?
- A. MACsec encryption
- B. IPsec encryption
- C. IRB VLAN routing
- D. EVPN over IPsec
Answer: D
NEW QUESTION 55
......
Free JNCDS-SEC JN0-1331 Exam Question: https://www.practicevce.com/Juniper/JN0-1331-practice-exam-dumps.html