JN0-1331 Dumps with Practice Exam Questions Answers [Q37-Q55]

Share

JN0-1331 Dumps with Practice Exam Questions Answers

JN0-1331 by JNCDS-SEC Actual Free Exam Practice Test


Juniper JN0-1331 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Junos Space management platform
  • Securing the Enterprise WAN
  • Securing the individual devices
Topic 2
  • Describe the design considerations for security management
  • Describe the security design considerations for a service provider WAN
Topic 3
  • Advance Security Concepts
  • Fundamental Security Concepts
Topic 4
  • Describe the security design considerations in a data center
  • Securing the Service Provider WAN
Topic 5
  • Describe the design considerations of high availability in a secure networks
  • Stateful security policies
Topic 6
  • Describe the design considerations for automating security
  • Describe the security design considerations within a campus or branch network
Topic 7
  • Junos Space Security Director and Log Director
  • Describe the various tenets of common security features
Topic 8
  • Describe the security design considerations for an enterprise WAN
  • Describe advanced security features
Topic 9
  • Internet edge security design principles
  • Asymmetrical traffic handling
Topic 10
  • Security Automation and Management
  • Securing data center interconnects

 

NEW QUESTION 37
You are required to design a university network to meet the conditions shown below.
* Users connected to the university network should be able to access the Internet and the research department lab network.
* The research department lab network should not be able to reach the Internet.
Which three actions satisfy the design requirements? (Choose three.)

  • A. Use a global deny security policy for the research lab
  • B. Use separate security zones for each department
  • C. Use a global permit policy for Internet traffic
  • D. Use the default deny security policy for the research lab
  • E. Use a static NAT rule between the internal zones for the research lab

Answer: A,B,C

 

NEW QUESTION 38
You are asked to include anti-malware features into an existing network design. Traffic from the infected machines must be moved to a quarantined VLAN.
Which product will provide this segregation?

  • A. Sky ATP
  • B. Software Defined Secure Network
  • C. unified threat management
  • D. screens

Answer: B

 

NEW QUESTION 39
Your customer needs help designing a single solution to protect their combination of various Junos network devices from unauthorized management access.
Which Junos OS feature will provide this protection?

  • A. Use a firewall filter applied to the lo0 interface
  • B. Use the management zone host-inbound-traffic feature
  • C. Use a firewall filter applied to the fxp0 interface
  • D. Use a security policy with the destination of the junos-host zone

Answer: C

 

NEW QUESTION 40
You are designing an SDSN security solution for a new campus network. The network will consist of Juniper Networks Policy Enforcer, Juniper Networks switches, third-party switches, and SRX Series devices. The switches and the SRX Series devices will be used as security enforcement points.
Which component supports the SRX Series devices in this scenario?

  • A. RADIUS server
  • B. certificate server
  • C. Security Director
  • D. DHCP server

Answer: C

 

NEW QUESTION 41
You are creating a security design proposal for an enterprise customer. As part of the design, you are implementing 802.1x authentication on your EX Series devices.
In this scenario, which two statements are correct? (Choose two.)

  • A. The authenticator is the device that is being authenticated
  • B. The authenticator is the device that prevents the supplicant's access until it is authenticated
  • C. The supplicant is the device that is being authenticated
  • D. The supplicant is the device that prevents the authenticator's access until it is authenticated

Answer: B,C

Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/802-1x-authentication- switching-devices.html

 

NEW QUESTION 42
You are working on a network design that will use EX Series devices as Layer 2 access switches in a campus environment. You must include Junos Space in your design. You want to take advantage of security features supported on the devices.
Which two security features would satisfy this requirement? (Choose two.)

  • A. Stateful Firewall
  • B. ALG
  • C. Access Control
  • D. SDSN

Answer: A,C

 

NEW QUESTION 43
You want to deploy JATP in your network that uses SRX Series devices.
In this scenario, which feature must you enable on the SRX Series devices?

  • A. AppSecure
  • B. IPS
  • C. UTM antivirus
  • D. SSL forward proxy

Answer: D

 

NEW QUESTION 44
Which two steps should be included in your security design process? (Choose two.)

  • A. Define overall security policies
  • B. Identify the firewall enforcement points
  • C. Define safety requirements for the customer's organization
  • D. Identify external attackers

Answer: A,B

Explanation:
Explanation/Reference: https://www.juniper.net/assets/us/en/local/pdf/whitepapers/2000591-en.pdf

 

NEW QUESTION 45
You are required to design a university network to meet the conditions shown below.
Users connected to the university network should be able to access the Internet and the research department lab network.
The research department lab network should not be able to reach the Internet.
Which three actions satisfy the design requirements? (Choose three.)

  • A. Use the default deny security policy for the research lab
  • B. Use separate security zones for each department
  • C. Use a global permit policy for Internet traffic
  • D. Use a global deny security policy for the research lab
  • E. Use a static NAT rule between the internal zones for the research lab

Answer: A,B,C

 

NEW QUESTION 46
You are concerned about users downloading malicious attachments at work while using encrypted Web mail. You want to block these malicious files using your SRX Series device.
In this scenario, which two features should you use? (Choose two.)

  • A. Sky ATP HTTP scanning
  • B. Sky ATP SMTP scanning
  • C. SSL forward proxy
  • D. SSL reverse proxy

Answer: B,C

 

NEW QUESTION 47
You must allow applications to connect to external servers. The session has embedded IP address information to enable the remote system to establish a return session.
In your design, which function should be implemented?

  • A. HTTP redirect
  • B. destination NAT
  • C. application layer gateway
  • D. source NAT

Answer: D

 

NEW QUESTION 48
Which two features are used to stop IP spoofing in and out of your network? (Choose two.)

  • A. GeoIP
  • B. unicast reverse path forwarding
  • C. IPS
  • D. firewall filters

Answer: A,B

 

NEW QUESTION 49
You are asked to design a secure enterprise WAN where all payload data is encrypted and branch sites communicate directly without routing all traffic through a central hub.
Which two technologies would accomplish this task? (Choose two.)

  • A. Auto Discovery VPN
  • B. AutoVPN
  • C. MPLS Layer 3 VPN
  • D. group VPN

Answer: A,C

 

NEW QUESTION 50
What are two benefits of the vSRX in a virtualized private or public cloud multitenant environment? (Choose two.)

  • A. full logical systems capabilities
  • B. 100GbE interface support
  • C. stateful firewall protection at the tenant edge
  • D. OSPFv3 capabilities

Answer: A,C

 

NEW QUESTION 51
You are designing a new campus Internet access service that implements dynamic NAT for customer IP addressing. The customer requires services that allow peer-to-peer networking and online gaming.
In this scenario, what will accomplish this task?

  • A. EVPN over IPsec
  • B. one-to-one NAT
  • C. stacked VLAN tagging
  • D. endpoint independent mapping

Answer: C

 

NEW QUESTION 52
Which two protocols are supported natively by the Junos automation stack? (Choose two.)

  • A. PyEZ
  • B. CIP
  • C. Jenkins
  • D. NETCONF

Answer: A,D

Explanation:
Explanation/Reference:

 

NEW QUESTION 53
You are creating a security design proposal for an enterprise customer. As part of the design, you are implementing 802.1x authentication on your EX Series devices.
In this scenario, which two statements are correct? (Choose two.)

  • A. The authenticator is the device that is being authenticated
  • B. The authenticator is the device that prevents the supplicant's access until it is authenticated
  • C. The supplicant is the device that is being authenticated
  • D. The supplicant is the device that prevents the authenticator's access until it is authenticated

Answer: B,C

 

NEW QUESTION 54
You are designing a data center interconnect between two sites across a service provider Layer 2 leased line.
The sites require Layer 2 connectivity between hosts, and the connection must be secure.
In this scenario, what will accomplish this task?

  • A. MACsec encryption
  • B. IPsec encryption
  • C. IRB VLAN routing
  • D. EVPN over IPsec

Answer: D

 

NEW QUESTION 55
......

Free JNCDS-SEC JN0-1331 Exam Question: https://www.practicevce.com/Juniper/JN0-1331-practice-exam-dumps.html