JN0-1331 Free Update With 100% Exam Passing Guarantee [2021]
[Oct-2021] Verified Juniper Exam Dumps with JN0-1331 Exam Study Guide
NEW QUESTION 34
Which statement about IPsec tunnels is true?
- A. They are used to secure and encrypt traffic between tunnel endpoints
- B. They are used to provide in-depth packet inspection for traffic leaving your network
- C. They are used to combine multiple interfaces into a single bundle
- D. They are used to prevent routing loops in a Layer 2 environment
Answer: A
NEW QUESTION 35
What are two reasons for using cSRX over vSRX? (Choose two.)
- A. cSRX supports IPsec
- B. cSRX uses less memory
- C. cSRX supports the BGP protocol
- D. cSRX loads faster
Answer: B,D
NEW QUESTION 36
What are two reasons for using cSRX over vSRX? (Choose two.)
- A. cSRX supports IPsec
- B. cSRX uses less memory
- C. cSRX supports the BGP protocol
- D. cSRX loads faster
Answer: B,D
Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/csrx/information-products/pathway-pages/ security-csrx-linux-bm-guide-pwp.pdf
NEW QUESTION 37
Policy Enforcer provides which benefit?
- A. command and control protection
- B. IPsec encryption
- C. centralized management of security devices
- D. log management
Answer: C
NEW QUESTION 38
You are designing a data center security architecture. The design requires automated scaling of security services according to real-time traffic flows.
Which two design components will accomplish this task? (Choose two.)
- A. VRF segmentation on high-capacity physical security appliances
- B. JFlow traffic monitoring with event scripts
- C. VNF security devices deployed on x86 servers
- D. telemetry with an SDN controller
Answer: B,C
Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/learn-about/LearnAbout_NFV.pdf
NEW QUESTION 39
You are designing an enterprise WAN network that must connect multiple sites. You must provide a design proposal for the security elements needed to encrypt traffic between the remote sites. Which feature will secure the traffic?
- A. BFD
- B. OSPF
- C. IPsec
- D. GRE
Answer: C
NEW QUESTION 40
You are concerned about malicious attachments being transferred to your e-mail server at work through encrypted channels. You want to block these malicious files using your SRX Series device.
Which two features should you use in this scenario? (Choose two.)
- A. Sky ATP SMTP scanning
- B. SSL reverse proxy
- C. Sky ATP HTTP scanning
- D. SSL forward proxy
Answer: A,D
Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/release-independent/sky-atp/help/information- products/pathway-pages/email-scanning-sky-atp.html
NEW QUESTION 41
Which two steps should be included in your security design process? (Choose two.)
- A. Identify the firewall enforcement points
- B. Identify external attackers
- C. Define overall security policies
- D. Define safety requirements for the customer's organization
Answer: A,C
Explanation:
Explanation/Reference: https://www.juniper.net/assets/us/en/local/pdf/whitepapers/2000591-en.pdf
NEW QUESTION 42
You are asked to install a mechanism to protect an ISP network from denial-of-service attacks from a small number of sources.
Which mechanism will satisfy this requirement?
- A. Sky ATP
- B. GeoIP
- C. RTBH
- D. UTM
Answer: C
NEW QUESTION 43
You are implementing Routing Engine protection, and packets are processed in a specific order.
In this scenario, which function processed a received packet last?
- A. loopback interface input firewall filter
- B. physical interface input firewall filters
- C. physical interface input policer
- D. loopback interface input policer
Answer: C
NEW QUESTION 44
You are working with a customer to create a design proposal using SRX Series devices. As part of the design, you must consider the requirements shown below:
You must ensure that every packet entering your device is independently inspected against a set of rules.
You must provide a way to protect the device from undesired access attempts.
You must ensure that you can apply a different set of rules for traffic leaving the device than are in use for traffic entering the device.
In this scenario, what do you recommend using to accomplish these requirements?
- A. firewall filters
- B. intrusion prevention system
- C. screens
- D. unified threat management
Answer: A
NEW QUESTION 45
You have multiple SRX chassis clusters on a single broadcast domain.
Why must you assign different cluster IDs in this scenario?
- A. to avoid control link conflicts
- B. to avoid node numbering conflicts
- C. to avoid MAC address conflicts
- D. to avoid redundancy group conflicts
Answer: C
NEW QUESTION 46
You are asked to design a VPN solution between 25 branches of a company. The company wants to have the sites talk directly to each other in the event of a hub device failure. The solution should follow industry standards.
Which solution would you choose in this scenario?
- A. AutoVPN
- B. Auto Discovery VPN
- C. Group VPN
- D. full mesh VPN
Answer: B
Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-auto-discovery- vpns.html
NEW QUESTION 47
You are designing a data center interconnect between two sites across a service provider Layer 3 VPN service. The sites require Layer 2 connectivity between hosts, and the connection must be secure.
In this scenario, what will accomplish this task?
- A. EVPN over IPsec
- B. stacked VLAN tagging
- C. MACsec encryption
- D. SSL VPN encryption
Answer: C
NEW QUESTION 48
You are concerned about users downloading malicious attachments at work while using encrypted Web mail.
You want to block these malicious files using your SRX Series device.
In this scenario, which two features should you use? (Choose two.)
- A. Sky ATP SMTP scanning
- B. SSL reverse proxy
- C. Sky ATP HTTP scanning
- D. SSL forward proxy
Answer: A,D
NEW QUESTION 49
You are responding to an RFP for securing a large enterprise. The RFP requires an onsite security solution which can use logs from third-party sources to prevent threats. The solution should also have the capability to detect and stop zero-day attacks.
Which Juniper Networks solution satisfies this requirement?
- A. IDP
- B. Sky ATP
- C. JATP
- D. JSA
Answer: C
NEW QUESTION 50
What are two benefits of the vSRX in a virtualized private or public cloud multitenant environment? (Choose two.)
- A. 100GbE interface support
- B. stateful firewall protection at the tenant edge
- C. full logical systems capabilities
- D. OSPFv3 capabilities
Answer: B,C
Explanation:
Reference:
https: //www.juniper.net/documentation/en_US/junos/topics/topic-map/logical-systems-overview.html
NEW QUESTION 51
Your customer needs help designing a single solution to protect their combination of various Junos network devices from unauthorized management access.
Which Junos OS feature will provide this protection?
- A. Use a security policy with the destination of the junos-host zone
- B. Use a firewall filter applied to the lo0 interface
- C. Use the management zone host-inbound-traffic feature
- D. Use a firewall filter applied to the fxp0 interface
Answer: D
NEW QUESTION 52
Your customer needs help designing a single solution to protect their combination of various Junos network devices from unauthorized management access.
Which Junos OS feature will provide this protection?
- A. Use a firewall filter applied to the lo0 interface
- B. Use a security policy with the destination of the junos-host zone
- C. Use a firewall filter applied to the fxp0 interface
- D. Use the management zone host-inbound-traffic feature
Answer: A
NEW QUESTION 53
Which two features are used to stop IP spoofing in and out of your network? (Choose two.)
- A. unicast reverse path forwarding
- B. firewall filters
- C. IPS
- D. GeoIP
Answer: A,D
NEW QUESTION 54
Click the Exhibit button.
You are designing the virtualized server deployment shown in the exhibit in your data center. The vSRX device is acting as a Layer 2 firewall and the two VMs must communicate through the vSRX device.
Which two actions must you perform to accomplish this task? (Choose two.)
- A. Place both VMs in the same VLAN
- B. Place both VMs in different vSwitches
- C. Place both VMs in the same vSwitch
- D. Place both VMs in different VLANs
Answer: A,B
NEW QUESTION 55
You are working with a customer to create a design proposal using SRX Series devices. As part of the design, you must consider the requirements shown below:
* You must ensure that every packet entering your device is independently inspected against a set of rules.
* You must provide a way to protect the device from undesired access attempts.
* You must ensure that you can apply a different set of rules for traffic leaving the device than are in use
* for traffic entering the device.
In this scenario, what do you recommend using to accomplish these requirements?
- A. firewall filters
- B. intrusion prevention system
- C. screens
- D. unified threat management
Answer: A
NEW QUESTION 56
......
Authentic Best resources for JN0-1331 Online Practice Exam: https://www.realvce.com/JN0-1331_free-dumps.html