[Jul 28, 2021] JN0-1331 Dumps Full Questions - Exam Study Guide [Q38-Q60]

Share

[Jul 28, 2021] JN0-1331 Dumps Full Questions - Exam Study Guide

JNCDS-SEC  Free Certification Exam Material from TroytecDumps with 66 Questions

NEW QUESTION 38
You are designing a solution to protect a service provider network against volumetric denial-of-service attacks.
Your main concern is to protect the network devices.
Which two solutions accomplish this task? (Choose two.)

  • A. intrusion prevention system
  • B. BGP FlowSpec
  • C. screens
  • D. next-generation firewall

Answer: A,B

 

NEW QUESTION 39
You will be managing 1000 SRX Series devices. Each SRX Series device requires basic source NAT to access the Internet.
Which product should you use to manage these NAT rules on the SRX Series devices?

  • A. CSO
  • B. Contrail
  • C. Security Director
  • D. JSA

Answer: C

 

NEW QUESTION 40
In a data center, what are two characteristics of access tier VLAN termination on the aggregation tier? (Choose two.)

  • A. Multiple VLANs can be part of one security zone
  • B. Inter-VLAN traffic within a zone can bypass firewall services
  • C. Inter-VLAN traffic is secured through firewall services
  • D. A security zone is limited to a single VLAN

Answer: A,C

 

NEW QUESTION 41
What are two reasons for using cSRX over vSRX? (Choose two.)

  • A. cSRX supports IPsec
  • B. cSRX uses less memory
  • C. cSRX supports the BGP protocol
  • D. cSRX loads faster

Answer: B,D

Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/csrx/information-products/pathway-pages/ security-csrx-linux-bm-guide-pwp.pdf

 

NEW QUESTION 42
What are two benefits of the vSRX in a virtualized private or public cloud multitenant environment? (Choose two.)

  • A. 100GbE interface support
  • B. stateful firewall protection at the tenant edge
  • C. full logical systems capabilities
  • D. OSPFv3 capabilities

Answer: B,C

 

NEW QUESTION 43
You are asked to design a VPN solution between 25 branches of a company. The company wants to have the sites talk directly to each other in the event of a hub device failure. The solution should follow industry standards.
Which solution would you choose in this scenario?

  • A. AutoVPN
  • B. Auto Discovery VPN
  • C. Group VPN
  • D. full mesh VPN

Answer: B

Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-auto-discovery- vpns.html

 

NEW QUESTION 44
You are responding to an RFP for securing a large enterprise. The RFP requires an onsite security solution which can use logs from third-party sources to prevent threats. The solution should also have the capability to detect and stop zero-day attacks.
Which Juniper Networks solution satisfies this requirement?

  • A. IDP
  • B. Sky ATP
  • C. JATP
  • D. JSA

Answer: C

 

NEW QUESTION 45
What is the maximum number of SRX Series devices in a chassis cluster?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: C

 

NEW QUESTION 46
You are asked to virtualize numerous stateful firewalls in your customer's data center. The customer wants the solution to use the existing Kubernetes-orchestrated architecture.
Which Juniper Networks product would satisfy this requirement?

  • A. vSRX
  • B. cSRX
  • C. vMX
  • D. CTP Series

Answer: B

 

NEW QUESTION 47
A hosting company is migrating to cloud-based solutions. Their customers share a physical firewall cluster, subdivided into individual logical firewalls for each customer. Projection data shows that the cloud service will soon deplete all the resources within the physical firewall. As a consultant, you must propose a scalable solution that continues to protect all the cloud customers while still securing the existing physical network.
In this scenario, which solution would you propose?

  • A. Replace the physical firewall cluster with a higher-performance firewall
  • B. Remove the physical firewall cluster and deploy vSRX clusters dedicated to each customer's servers
  • C. Deploy a vSRX cluster in front of each customer's servers while keeping the physical firewall cluster
  • D. Deploy a software-defined networking solution

Answer: C

 

NEW QUESTION 48
You are asked to design a VPN solution between 25 branches of a company. The company wants to have the sites talk directly to each other in the event of a hub device failure. The solution should follow industry standards.
Which solution would you choose in this scenario?

  • A. AutoVPN
  • B. Group VPN
  • C. full mesh VPN
  • D. Auto Discovery VPN

Answer: B

 

NEW QUESTION 49
You want to deploy a VPN that will connect branch locations to the main office. You will eventually add additional branch locations to the topology, and you must avoid additional configuration on the hub when those sites are added.
In this scenario, which VPN solution would you recommend?

  • A. Site-to-Site VPN
  • B. Group VPN
  • C. AutoVPN
  • D. Hub-and-Spoke VPN

Answer: C

Explanation:
Explanation/Reference: https://www.juniper.net/assets/us/en/local/pdf/solutionbriefs/3510477-en.pdf

 

NEW QUESTION 50
Which two features are used to stop IP spoofing in and out of your network? (Choose two.)

  • A. unicast reverse path forwarding
  • B. IPS
  • C. firewall filters
  • D. GeoIP

Answer: A,B

 

NEW QUESTION 51
You are designing a solution to protect a service provider network against volumetric denial-of-service attacks. Your main concern is to protect the network devices.
Which two solutions accomplish this task? (Choose two.)

  • A. intrusion prevention system
  • B. BGP FlowSpec
  • C. screens
  • D. next-generation firewall

Answer: A,B

 

NEW QUESTION 52
You are working with a customer to create a design proposal using SRX Series devices. As part of the design, you must consider the requirements shown below:
* You must ensure that every packet entering your device is independently inspected against a set of rules.
* You must provide a way to protect the device from undesired access attempts.
* You must ensure that you can apply a different set of rules for traffic leaving the device than are in use for traffic entering the device.
In this scenario, what do you recommend using to accomplish these requirements?

  • A. firewall filters
  • B. intrusion prevention system
  • C. screens
  • D. unified threat management

Answer: A

Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/example/firewall-filter-stateless- example-trusted-source-block-telnet-and-ssh-access.html

 

NEW QUESTION 53
Which two protocols are supported natively by the Junos automation stack? (Choose two.)

  • A. Jenkins
  • B. CIP
  • C. PyEZ
  • D. NETCONF

Answer: C,D

Explanation:
Explanation/Reference:

 

NEW QUESTION 54
You are using SRX Series devices to secure your network and you require sandboxing for malicious file detonation. However, per company policy, you cannot send potentially malicious files outside your network for sandboxing.
Which feature should you use in this situation?

  • A. Sky ATP
  • B. UTM antivirus
  • C. IPS
  • D. JATP

Answer: D

Explanation:
Explanation
Juniper Advanced Threat Prevention Appliance

 

NEW QUESTION 55
You are deploying a data center Clos architecture and require secure data transfers within the switching fabric.
In this scenario, what will accomplish this task?

  • A. stacked VLAN tagging on the core switches
  • B. IRB VLAN routing between hosts
  • C. LAG Layer 2 hashing
  • D. MACsec encryption

Answer: D

 

NEW QUESTION 56
Which two protocols are supported natively by the Junos automation stack? (Choose two.)

  • A. Jenkins
  • B. CIP
  • C. PyEZ
  • D. NETCONF

Answer: C,D

 

NEW QUESTION 57
Your company has 500 branch sites and the CIO is concerned about minimizing the potential impact of a VPN router being stolen from an enterprise branch site. You want the ability to quickly disable a stolen VPN router while minimizing administrative overhead.
Which solution accomplishes this task?

  • A. Modify your IKE proposals to use Diffie-Hellman group 14 or higher
  • B. Use firewall filters to block traffic from the stolen VPN router
  • C. Rotate VPN pre-shared keys every month
  • D. Implement a certificate-based VPN using a public key infrastructure (PKI)

Answer: B

 

NEW QUESTION 58
You are concerned about users downloading malicious attachments at work while using encrypted Web mail. You want to block these malicious files using your SRX Series device.
In this scenario, which two features should you use? (Choose two.)

  • A. Sky ATP SMTP scanning
  • B. SSL reverse proxy
  • C. Sky ATP HTTP scanning
  • D. SSL forward proxy

Answer: A,D

 

NEW QUESTION 59
Your company has outgrown its existing secure enterprise WAN that is configured to use OSPF, AutoVPN, and IKE version 1. You are asked if it is possible to make a design change to improve the WAN performance without purchasing new hardware.
Which two design changes satisfy these requirements? (Choose two.)

  • A. Modify the IPsec proposal from AES-128 to AES-256
  • B. Migrate to IKE version 2
  • C. Change the IGP from OSPF to IS-IS
  • D. Implement Auto Discovery VPN

Answer: C,D

 

NEW QUESTION 60
......

Dumps Brief Outline Of The JN0-1331 Exam: https://www.troytecdumps.com/JN0-1331-troytec-exam-dumps.html