JNCDS-SEC JN0-1331 Exam Dumps and Certification Test Engine [Q15-Q35]

Share

(PDF) JNCDS-SEC JN0-1331 Exam and Certification Test Engine

Use JN0-1331 Exam Dumps (2021 PDF Dumps) To Have Reliable JN0-1331 Test Engine


Juniper JN0-1331 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Advance Security Concepts
  • Fundamental Security Concepts
Topic 2
  • Internet edge security design principles
  • Asymmetrical traffic handling
Topic 3
  • Junos Space Security Director and Log Director
  • Describe the various tenets of common security features
Topic 4
  • Junos Space management platform
  • Securing the Enterprise WAN
  • Securing the individual devices
Topic 5
  • Describe the security design considerations in a data center
  • Securing the Service Provider WAN
Topic 6
  • Describe the design considerations for automating security
  • Describe the security design considerations within a campus or branch network
Topic 7
  • Security Automation and Management
  • Securing data center interconnects
Topic 8
  • Describe the security design considerations for an enterprise WAN
  • Describe advanced security features
Topic 9
  • Describe the design considerations for security management
  • Describe the security design considerations for a service provider WAN
Topic 10
  • Describe the design considerations of high availability in a secure networks
  • Stateful security policies

 

NEW QUESTION 15
You are asked to provide a design proposal for a campus network. As part of the design, the customer requires that all end user devices must be authenticated before being granted access to their Layer 2 network.
Which feature meets this requirement?

  • A. ALGs
  • B. 802.1X
  • C. NAT
  • D. IPsec

Answer: B

 

NEW QUESTION 16
Which two protocols are supported natively by the Junos automation stack? (Choose two.)

  • A. PyEZ
  • B. CIP
  • C. Jenkins
  • D. NETCONF

Answer: A,D

 

NEW QUESTION 17
Which solution centralizes the management of security devices in your data center?

  • A. Junos Space Security Director
  • B. Juniper Networks Secure Analytics
  • C. J-Web
  • D. Junos CLI

Answer: A

 

NEW QUESTION 18
You must allow applications to connect to external servers. The session has embedded IP address information to enable the remote system to establish a return session.
In your design, which function should be implemented?

  • A. HTTP redirect
  • B. destination NAT
  • C. application layer gateway
  • D. source NAT

Answer: C

 

NEW QUESTION 19
You are asked to deploy a security solution in your data center that ensures all traffic flows through the SRX Series devices.
Which firewall deployment method meets this requirement?

  • A. transparent
  • B. inline
  • C. two-arm
  • D. one-arm

Answer: B

 

NEW QUESTION 20
You are working on a network design that will use EX Series devices as Layer 2 access switches in a campus environment. You must include Junos Space in your design. You want to take advantage of security features supported on the devices.
Which two security features would satisfy this requirement? (Choose two.)

  • A. SDSN
  • B. ALG
  • C. Access Control
  • D. Stateful Firewall

Answer: A,C

 

NEW QUESTION 21
You have a site that has two Internet connections but no switch on the outside of the firewall. You want to use ISP-A over ISP-B during normal operations.
Which type of chassis cluster design would you propose to satisfy this requirement?

  • A. Propose active/active cluster deployment with separate redundancy groups
  • B. Propose active/passive cluster deployment without separate redundancy groups
  • C. Propose active/active cluster deployment without separate redundancy groups
  • D. Propose active/passive cluster deployment with separate redundancy groups

Answer: A

 

NEW QUESTION 22
You are designing an Internet security gateway (ISG) for your company and are considering a centralized versus a distributed model for ISGs.
Which two statements are correct in this scenario? (Choose two.)

  • A. Distributed ISGs typically require extra bandwidth for management
  • B. Distributed ISGs reduce bandwidth for end users
  • C. Distributed ISGs typically have less latency compared to centralized ISGs
  • D. Distributed ISGs are harder to manage compared to centralized ISGs

Answer: C,D

 

NEW QUESTION 23
You must allow applications to connect to external servers. The session has embedded IP address information to enable the remote system to establish a return session.
In your design, which function should be implemented?

  • A. HTTP redirect
  • B. destination NAT
  • C. application layer gateway
  • D. source NAT

Answer: D

 

NEW QUESTION 24
You want to deploy a VPN that will connect branch locations to the main office. You will eventually add additional branch locations to the topology, and you must avoid additional configuration on the hub when those sites are added.
In this scenario, which VPN solution would you recommend?

  • A. Hub-and-Spoke VPN
  • B. Group VPN
  • C. AutoVPN
  • D. Site-to-Site VPN

Answer: C

 

NEW QUESTION 25
You are asked to include anti-malware features into an existing network design. Traffic from the infected machines must be moved to a quarantined VLAN.
Which product will provide this segregation?

  • A. Sky ATP
  • B. Software Defined Secure Network
  • C. unified threat management
  • D. screens

Answer: B

 

NEW QUESTION 26
You are deploying Security Director with the logging and reporting functionality for VMs that use SSDs. You expect to have approximately 20,000 events per second of logging in your network.
In this scenario, what is the minimum number of logging and reporting devices that should be used?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: B

Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos-space17.1/topics/task/multi-task/junos- space-sd-log-collector-installing.html

 

NEW QUESTION 27
You are designing a new campus Internet access service that implements dynamic NAT for customer IP addressing. The customer requires services that allow peer-to-peer networking and online gaming.
In this scenario, what will accomplish this task?

  • A. EVPN over IPsec
  • B. one-to-one NAT
  • C. stacked VLAN tagging
  • D. endpoint independent mapping

Answer: C

 

NEW QUESTION 28
You are asked to install a mechanism to protect an ISP network from denial-of-service attacks from a small number of sources.
Which mechanism will satisfy this requirement?

  • A. Sky ATP
  • B. GeoIP
  • C. UTM
  • D. RTBH

Answer: D

 

NEW QUESTION 29
You are asked to design a VPN solution between 25 branches of a company. The company wants to have the sites talk directly to each other in the event of a hub device failure. The solution should follow industry standards.
Which solution would you choose in this scenario?

  • A. full mesh VPN
  • B. Group VPN
  • C. Auto Discovery VPN
  • D. AutoVPN

Answer: C

Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-auto-discovery- vpns.html

 

NEW QUESTION 30
You are working with a customer to create a design proposal using SRX Series devices. As part of the design, you must consider the requirements shown below:
* You must ensure that every packet entering your device is independently inspected against a set of rules.
* You must provide a way to protect the device from undesired access attempts.
* You must ensure that you can apply a different set of rules for traffic leaving the device than are in use
* for traffic entering the device.
In this scenario, what do you recommend using to accomplish these requirements?

  • A. unified threat management
  • B. intrusion prevention system
  • C. firewall filters
  • D. screens

Answer: C

 

NEW QUESTION 31
You are deploying Security Director with the logging and reporting functionality for VMs that use SSDs. You expect to have approximately 20,000 events per second of logging in your network.
In this scenario, what is the minimum number of log receiver devices that you should use?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: B

Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos-space17.1/topics/task/multi-task/junos- space-sd-log-collector-installing.html

 

NEW QUESTION 32
Your company has outgrown its existing secure enterprise WAN that is configured to use OSPF, AutoVPN, and IKE version 1. You are asked if it is possible to make a design change to improve the WAN performance without purchasing new hardware.
Which two design changes satisfy these requirements? (Choose two.)

  • A. Migrate to IKE version 2
  • B. Implement Auto Discovery VPN
  • C. Modify the IPsec proposal from AES-128 to AES-256
  • D. Change the IGP from OSPF to IS-IS

Answer: A,C

 

NEW QUESTION 33
You are working on a network design that will use EX Series devices as Layer 2 access switches in a campus environment. You must include Junos Space in your design. You want to take advantage of security features supported on the devices.
Which two security features would satisfy this requirement? (Choose two.)

  • A. Stateful Firewall
  • B. ALG
  • C. Access Control
  • D. SDSN

Answer: A,C

Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/concept/ex-series-security- overview.html

 

NEW QUESTION 34
You are designing an Internet security gateway (ISG) for your company and are considering a centralized versus a distributed model for ISGs.
Which two statements are correct in this scenario? (Choose two.)

  • A. Distributed ISGs are harder to manage compared to centralized ISGs
  • B. Distributed ISGs reduce bandwidth for end users
  • C. Distributed ISGs typically have less latency compared to centralized ISGs
  • D. Distributed ISGs typically require extra bandwidth for management

Answer: C,D

 

NEW QUESTION 35
......

JN0-1331 Dumps Full Questions with Free PDF Questions to Pass: https://www.newpassleader.com/Juniper/JN0-1331-exam-preparation-materials.html