2021 Valid JN0-1331 test answers & Juniper Exam PDF [Q31-Q53]

Share

2021 Valid JN0-1331  test answers & Juniper Exam PDF

Free Juniper JN0-1331 Exam Questions & Answer from Training Expert Lead2PassExam


Juniper JN0-1331 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Junos Space management platform
  • Securing the Enterprise WAN
  • Securing the individual devices
Topic 2
  • Describe the design considerations for security management
  • Describe the security design considerations for a service provider WAN
Topic 3
  • Describe the security design considerations in a data center
  • Securing the Service Provider WAN
Topic 4
  • Describe the design considerations for automating security
  • Describe the security design considerations within a campus or branch network
Topic 5
  • Junos Space Security Director and Log Director
  • Describe the various tenets of common security features
Topic 6
  • Describe the security design considerations for an enterprise WAN
  • Describe advanced security features
Topic 7
  • Advance Security Concepts
  • Fundamental Security Concepts
Topic 8
  • Security Automation and Management
  • Securing data center interconnects
Topic 9
  • Describe the design considerations of high availability in a secure networks
  • Stateful security policies
Topic 10
  • Internet edge security design principles
  • Asymmetrical traffic handling

 

NEW QUESTION 31
You are creating a security design proposal for an enterprise customer. As part of the design, you are implementing 802.1x authentication on your EX Series devices.
In this scenario, which two statements are correct? (Choose two.)

  • A. The supplicant is the device that is being authenticated
  • B. The authenticator is the device that is being authenticated
  • C. The authenticator is the device that prevents the supplicant's access until it is authenticated
  • D. The supplicant is the device that prevents the authenticator's access until it is authenticated

Answer: A,C

Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/802-1x-authentication- switching-devices.html

 

NEW QUESTION 32
You are concerned about users downloading malicious attachments at work while using encrypted Web mail.
You want to block these malicious files using your SRX Series device.
In this scenario, which two features should you use? (Choose two.)

  • A. Sky ATP SMTP scanning
  • B. Sky ATP HTTP scanning
  • C. SSL forward proxy
  • D. SSL reverse proxy

Answer: A,C

 

NEW QUESTION 33
You are responding to an RFP for securing a large enterprise. The RFP requires an onsite security solution which can use logs from third-party sources to prevent threats. The solution should also have the capability to detect and stop zero-day attacks.
Which Juniper Networks solution satisfies this requirement?

  • A. Sky ATP
  • B. JSA
  • C. IDP
  • D. JATP

Answer: D

Explanation:
Explanation/Reference: https://www.juniper.net/uk/en/products-services/security/advanced-threat-prevention/

 

NEW QUESTION 34
Your company has outgrown its existing secure enterprise WAN that is configured to use OSPF, AutoVPN, and IKE version 1. You are asked if it is possible to make a design change to improve the WAN performance without purchasing new hardware.
Which two design changes satisfy these requirements? (Choose two.)

  • A. Migrate to IKE version 2
  • B. Change the IGP from OSPF to IS-IS
  • C. Implement Auto Discovery VPN
  • D. Modify the IPsec proposal from AES-128 to AES-256

Answer: A,D

 

NEW QUESTION 35
You are asked to deploy a security solution in your data center that ensures all traffic flows through the SRX Series devices.
Which firewall deployment method meets this requirement?

  • A. one-arm
  • B. two-arm
  • C. transparent
  • D. inline

Answer: D

Explanation:
Explanation/Reference: https://www.juniper.net/us/en/local/pdf/implementation-guides/8010046-en.pdf

 

NEW QUESTION 36
Your customer needs help designing a single solution to protect their combination of various Junos network devices from unauthorized management access.
Which Junos OS feature will provide this protection?

  • A. Use a firewall filter applied to the fxp0 interface
  • B. Use the management zone host-inbound-traffic feature
  • C. Use a security policy with the destination of the junos-host zone
  • D. Use a firewall filter applied to the lo0 interface

Answer: A

 

NEW QUESTION 37
You are designing a data center security solution for a customer. The customer asks that you provide a DDoS solution. Several IPsec tunnels will be terminated at the data center gateway.
Which type of security is your customer asking you to implement?

  • A. segmentation
  • B. compliance
  • C. intra-data center policy enforcement
  • D. perimeter protection

Answer: D

 

NEW QUESTION 38
You are designing an SDSN security solution for a new campus network. The network will consist of Juniper Networks Policy Enforcer, Juniper Networks switches, third-party switches, and SRX Series devices. The switches and the SRX Series devices will be used as security enforcement points.
Which component supports the SRX Series devices in this scenario?

  • A. RADIUS server
  • B. certificate server
  • C. Security Director
  • D. DHCP server

Answer: C

Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/release-independent/solutions/topics/concept/sg-
006a-sdsn-product-components.html

 

NEW QUESTION 39
You are designing an Internet security gateway (ISG) for your company and are considering a centralized versus a distributed model for ISGs.
Which two statements are correct in this scenario? (Choose two.)

  • A. Distributed ISGs are harder to manage compared to centralized ISGs
  • B. Distributed ISGs reduce bandwidth for end users
  • C. Distributed ISGs typically have less latency compared to centralized ISGs
  • D. Distributed ISGs typically require extra bandwidth for management

Answer: C,D

 

NEW QUESTION 40
You are asked to design a secure enterprise WAN where all payload data is encrypted and branch sites communicate directly without routing all traffic through a central hub.
Which two technologies would accomplish this task? (Choose two.)

  • A. MPLS Layer 3 VPN
  • B. group VPN
  • C. Auto Discovery VPN
  • D. AutoVPN

Answer: A,C

Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-auto-discovery- vpns.html

 

NEW QUESTION 41
You are implementing Routing Engine protection, and packets are processed in a specific order.
In this scenario, which function processed a received packet last?

  • A. loopback interface input policer
  • B. physical interface input firewall filters
  • C. loopback interface input firewall filter
  • D. physical interface input policer

Answer: D

 

NEW QUESTION 42
You are deploying Security Director with the logging and reporting functionality for VMs that use SSDs. You expect to have approximately 20,000 events per second of logging in your network.
In this scenario, what is the minimum number of log receiver devices that you should use?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D

 

NEW QUESTION 43
You are creating a security design proposal for an enterprise customer. As part of the design, you are implementing 802.1x authentication on your EX Series devices.
In this scenario, which two statements are correct? (Choose two.)

  • A. The supplicant is the device that is being authenticated
  • B. The authenticator is the device that is being authenticated
  • C. The authenticator is the device that prevents the supplicant's access until it is authenticated
  • D. The supplicant is the device that prevents the authenticator's access until it is authenticated

Answer: A,C

 

NEW QUESTION 44
You are designing a new campus Internet access service that implements dynamic NAT for customer IP addressing. The customer requires services that allow peer-to-peer networking and online gaming.
In this scenario, what will accomplish this task?

  • A. one-to-one NAT
  • B. stacked VLAN tagging
  • C. EVPN over IPsec
  • D. endpoint independent mapping

Answer: B

 

NEW QUESTION 45
You are designing a data center interconnect between two sites across a service provider Layer 2 leased line. The sites require Layer 2 connectivity between hosts, and the connection must be secure.
In this scenario, what will accomplish this task?

  • A. IPsec encryption
  • B. MACsec encryption
  • C. EVPN over IPsec
  • D. IRB VLAN routing

Answer: B

 

NEW QUESTION 46
Click the Exhibit button.

You are designing the virtualized server deployment shown in the exhibit in your data center. The vSRX device is acting as a Layer 2 firewall and the two VMs must communicate through the vSRX device.
Which two actions must you perform to accomplish this task? (Choose two.)

  • A. Place both VMs in different VLANs
  • B. Place both VMs in different vSwitches
  • C. Place both VMs in the same vSwitch
  • D. Place both VMs in the same VLAN

Answer: B,D

 

NEW QUESTION 47
You are deploying Security Director with the logging and reporting functionality for VMs that use SSDs. You expect to have approximately 20,000 events per second of logging in your network.
In this scenario, what is the minimum number of logging and reporting devices that should be used?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D

 

NEW QUESTION 48
You are required to design a university network to meet the conditions shown below.
* Users connected to the university network should be able to access the Internet and the research department lab network.
* The research department lab network should not be able to reach the Internet.
Which three actions satisfy the design requirements? (Choose three.)

  • A. Use separate security zones for each department
  • B. Use a static NAT rule between the internal zones for the research lab
  • C. Use a global permit policy for Internet traffic
  • D. Use a global deny security policy for the research lab
  • E. Use the default deny security policy for the research lab

Answer: A,C,D

 

NEW QUESTION 49
You must design a small branch office firewall solution that provides application usage statistics.
In this scenario, which feature would accomplish this task?

  • A. AppQoS
  • B. AppTrack
  • C. UTM
  • D. AppFW

Answer: B

Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-application- tracking.html

 

NEW QUESTION 50
Your company has 500 branch sites and the CIO is concerned about minimizing the potential impact of a VPN router being stolen from an enterprise branch site. You want the ability to quickly disable a stolen VPN router while minimizing administrative overhead.
Which solution accomplishes this task?

  • A. Use firewall filters to block traffic from the stolen VPN router
  • B. Rotate VPN pre-shared keys every month
  • C. Implement a certificate-based VPN using a public key infrastructure (PKI)
  • D. Modify your IKE proposals to use Diffie-Hellman group 14 or higher

Answer: A

 

NEW QUESTION 51
Which two steps should be included in your security design process? (Choose two.)

  • A. Define safety requirements for the customer's organization
  • B. Identify external attackers
  • C. Define overall security policies
  • D. Identify the firewall enforcement points

Answer: C,D

Explanation:
Explanation/Reference: https://www.juniper.net/assets/us/en/local/pdf/whitepapers/2000591-en.pdf

 

NEW QUESTION 52
You are designing a new network for your organization with the characteristics shown below.
All traffic must pass inspection by a security device.
A center-positioned segmentation gateway must provide deep inspection of each packet using 10 Gbps interfaces.
Policy enforcement must be centrally managed.
Which security model should you choose for your network design?

  • A. Intrazone Permit
  • B. trust but verify
  • C. user-role firewall policies
  • D. Zero Trust

Answer: D

 

NEW QUESTION 53
......

Top Juniper JN0-1331 Courses Online: https://www.lead2passexam.com/Juniper/valid-JN0-1331-exam-dumps.html