[Q34-Q56] Real Exam Questions JN0-1331 Dumps Exam Questions in here [Jul-2021]

Share

Real Exam Questions JN0-1331 Dumps Exam Questions in here [Jul-2021]

Get Latest Jul-2021 Conduct effective penetration tests using  JN0-1331

NEW QUESTION 34
You are asked to design a secure enterprise WAN where all payload data is encrypted and branch sites communicate directly without routing all traffic through a central hub.
Which two technologies would accomplish this task? (Choose two.)

  • A. AutoVPN
  • B. MPLS Layer 3 VPN
  • C. Auto Discovery VPN
  • D. group VPN

Answer: C,D

 

NEW QUESTION 35
You are designing a data center security architecture. The design requires automated scaling of security services according to real-time traffic flows.
Which two design components will accomplish this task? (Choose two.)

  • A. telemetry with an SDN controller
  • B. VRF segmentation on high-capacity physical security appliances
  • C. VNF security devices deployed on x86 servers
  • D. JFlow traffic monitoring with event scripts

Answer: A,D

 

NEW QUESTION 36
You are designing an Internet security gateway (ISG) for your company and are considering a centralized versus a distributed model for ISGs.
Which two statements are correct in this scenario? (Choose two.)

  • A. Distributed ISGs typically have less latency compared to centralized ISGs
  • B. Distributed ISGs reduce bandwidth for end users
  • C. Distributed ISGs are harder to manage compared to centralized ISGs
  • D. Distributed ISGs typically require extra bandwidth for management

Answer: A,C

 

NEW QUESTION 37
You are designing a data center interconnect between two sites across a service provider Layer 3 VPN service. The sites require Layer 2 connectivity between hosts, and the connection must be secure.
In this scenario, what will accomplish this task?

  • A. EVPN over IPsec
  • B. stacked VLAN tagging
  • C. MACsec encryption
  • D. SSL VPN encryption

Answer: C

 

NEW QUESTION 38
You want to deploy a VPN that will connect branch locations to the main office. You will eventually add additional branch locations to the topology, and you must avoid additional configuration on the hub when those sites are added.
In this scenario, which VPN solution would you recommend?

  • A. Site-to-Site VPN
  • B. Group VPN
  • C. AutoVPN
  • D. Hub-and-Spoke VPN

Answer: C

 

NEW QUESTION 39
Your company has 500 branch sites and the CIO is concerned about minimizing the potential impact of a VPN router being stolen from an enterprise branch site. You want the ability to quickly disable a stolen VPN router while minimizing administrative overhead.
Which solution accomplishes this task?

  • A. Modify your IKE proposals to use Diffie-Hellman group 14 or higher
  • B. Use firewall filters to block traffic from the stolen VPN router
  • C. Rotate VPN pre-shared keys every month
  • D. Implement a certificate-based VPN using a public key infrastructure (PKI)

Answer: B

Explanation:
Explanation/Reference:

 

NEW QUESTION 40
Click the Exhibit button.

You are designing the virtualized server deployment shown in the exhibit in your data center. The vSRX device is acting as a Layer 2 firewall and the two VMs must communicate through the vSRX device.
Which two actions must you perform to accomplish this task? (Choose two.)

  • A. Place both VMs in the same VLAN
  • B. Place both VMs in different vSwitches
  • C. Place both VMs in the same vSwitch
  • D. Place both VMs in different VLANs

Answer: A,B

 

NEW QUESTION 41
You are designing an enterprise WAN network that must connect multiple sites. You must provide a design proposal for the security elements needed to encrypt traffic between the remote sites. Which feature will secure the traffic?

  • A. BFD
  • B. OSPF
  • C. IPsec
  • D. GRE

Answer: C

 

NEW QUESTION 42
You are deploying a data center Clos architecture and require secure data transfers within the switching fabric.
In this scenario, what will accomplish this task?

  • A. stacked VLAN tagging on the core switches
  • B. IRB VLAN routing between hosts
  • C. LAG Layer 2 hashing
  • D. MACsec encryption

Answer: D

 

NEW QUESTION 43
You are asked to include anti-malware features into an existing network design. Traffic from the infected machines must be moved to a quarantined VLAN.
Which product will provide this segregation?

  • A. Sky ATP
  • B. screens
  • C. unified threat management
  • D. Software Defined Secure Network

Answer: A

 

NEW QUESTION 44
You are asked to virtualize numerous stateful firewalls in your customer's data center. The customer wants the solution to use the existing Kubernetes-orchestrated architecture.
Which Juniper Networks product would satisfy this requirement?

  • A. vSRX
  • B. cSRX
  • C. vMX
  • D. CTP Series

Answer: B

 

NEW QUESTION 45
You will be managing 1000 SRX Series devices. Each SRX Series device requires basic source NAT to access the Internet.
Which product should you use to manage these NAT rules on the SRX Series devices?

  • A. CSO
  • B. Contrail
  • C. Security Director
  • D. JSA

Answer: C

 

NEW QUESTION 46
You are creating a security design proposal for a customer who is connecting their headquarters to a remote branch site over an unsecured Internet connection. As part of your design, you must recommend a solution to connect these sites together and ensure that the communication is secured and encrypted.
In this scenario, which solution do you recommend?

  • A. MPLS
  • B. XMPP
  • C. IPsec
  • D. GRE

Answer: C

 

NEW QUESTION 47
You want to deploy JATP in your network that uses SRX Series devices.
In this scenario, which feature must you enable on the SRX Series devices?

  • A. UTM antivirus
  • B. IPS
  • C. AppSecure
  • D. SSL forward proxy

Answer: D

 

NEW QUESTION 48
Click the Exhibit button.

You are designing the virtualized server deployment shown in the exhibit in your data center. The vSRX device is acting as a Layer 2 firewall and the two VMs must communicate through the vSRX device.
Which two actions must you perform to accomplish this task? (Choose two.)

  • A. Place both VMs in the same VLAN
  • B. Place both VMs in different vSwitches
  • C. Place both VMs in the same vSwitch
  • D. Place both VMs in different VLANs

Answer: A,B

 

NEW QUESTION 49
Click the Exhibit button.

Which type of security solution is shown in this exhibit?

  • A. centralized model
  • B. inline security model
  • C. de-centralized model
  • D. service chain model

Answer: D

 

NEW QUESTION 50
Your customer needs help designing a single solution to protect their combination of various Junos network devices from unauthorized management access.
Which Junos OS feature will provide this protection?

  • A. Use a security policy with the destination of the junos-host zone
  • B. Use a firewall filter applied to the lo0 interface
  • C. Use the management zone host-inbound-traffic feature
  • D. Use a firewall filter applied to the fxp0 interface

Answer: D

 

NEW QUESTION 51
You are concerned about users downloading malicious attachments at work while using encrypted Web mail. You want to block these malicious files using your SRX Series device.
In this scenario, which two features should you use? (Choose two.)

  • A. Sky ATP SMTP scanning
  • B. SSL reverse proxy
  • C. Sky ATP HTTP scanning
  • D. SSL forward proxy

Answer: A,D

 

NEW QUESTION 52
You are designing a solution to protect a service provider network against volumetric denial-of-service attacks. Your main concern is to protect the network devices.
Which two solutions accomplish this task? (Choose two.)

  • A. intrusion prevention system
  • B. BGP FlowSpec
  • C. screens
  • D. next-generation firewall

Answer: A,B

Explanation:
Explanation/Reference:
Reference: https://www.juniper.net/documentation/en_US/day-one-books/DO_BGP_FLowspec.pdf

 

NEW QUESTION 53
You are designing a data center security architecture. The design requires automated scaling of security services according to real-time traffic flows.
Which two design components will accomplish this task? (Choose two.)

  • A. VRF segmentation on high-capacity physical security appliances
  • B. JFlow traffic monitoring with event scripts
  • C. VNF security devices deployed on x86 servers
  • D. telemetry with an SDN controller

Answer: B,C

Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/learn-about/LearnAbout_NFV.pdf

 

NEW QUESTION 54
You are asked to deploy a security solution in your data center that ensures all traffic flows through the SRX Series devices.
Which firewall deployment method meets this requirement?

  • A. inline
  • B. one-arm
  • C. transparent
  • D. two-arm

Answer: A

Explanation:
Explanation/Reference: https://www.juniper.net/us/en/local/pdf/implementation-guides/8010046-en.pdf

 

NEW QUESTION 55
You are working with a customer to create a design proposal using SRX Series devices. As part of the design, you must consider the requirements shown below:
You must ensure that every packet entering your device is independently inspected against a set of rules.
You must provide a way to protect the device from undesired access attempts.
You must ensure that you can apply a different set of rules for traffic leaving the device than are in use for traffic entering the device.
In this scenario, what do you recommend using to accomplish these requirements?

  • A. firewall filters
  • B. intrusion prevention system
  • C. screens
  • D. unified threat management

Answer: A

 

NEW QUESTION 56
......

Authentic Best resources for JN0-1331 Online Practice Exam: https://www.dumpsvalid.com/JN0-1331-still-valid-exam.html