
Verified JN0-1331 Dumps Q&As - JN0-1331 Test Engine with Correct Answers
Pass Your JN0-1331 Dumps as PDF Updated on 2021 With 66 Questions
Juniper JN0-1331 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
| Topic 10 |
|
NEW QUESTION 11
You are designing a corporate WAN using SRX Series devices as a combined firewall and router at each site.
Regarding packet-mode and flow-mode operations in this scenario, which statement is true?
- A. Packet-mode is only supported on high-end SRX Series devices
- B. Packet-mode on SRX Series devices is required for deep packet inspection
- C. Flow-mode on SRX Series devices is required for security services
- D. An SRX Series device in flow-mode cannot forward packet-mode traffic
Answer: C
Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-srx-devices- processing-overview.xml.html
NEW QUESTION 12
You are asked to design a secure enterprise WAN where all payload data is encrypted and branch sites communicate directly without routing all traffic through a central hub.
Which two technologies would accomplish this task? (Choose two.)
- A. MPLS Layer 3 VPN
- B. group VPN
- C. Auto Discovery VPN
- D. AutoVPN
Answer: A,C
NEW QUESTION 13
You are concerned about malicious attachments being transferred to your e-mail server at work through encrypted channels. You want to block these malicious files using your SRX Series device.
Which two features should you use in this scenario? (Choose two.)
- A. Sky ATP SMTP scanning
- B. Sky ATP HTTP scanning
- C. SSL forward proxy
- D. SSL reverse proxy
Answer: A,C
NEW QUESTION 14
Which two protocols are supported natively by the Junos automation stack? (Choose two.)
- A. NETCONF
- B. CIP
- C. Jenkins
- D. PyEZ
Answer: A,D
NEW QUESTION 15
You are designing an enterprise WAN network that must connect multiple sites. You must provide a design proposal for the security elements needed to encrypt traffic between the remote sites. Which feature will secure the traffic?
- A. OSPF
- B. GRE
- C. IPsec
- D. BFD
Answer: C
NEW QUESTION 16
You have a site that has two Internet connections but no switch on the outside of the firewall. You want to use ISP-A over ISP-B during normal operations.
Which type of chassis cluster design would you propose to satisfy this requirement?
- A. Propose active/active cluster deployment without separate redundancy groups
- B. Propose active/passive cluster deployment without separate redundancy groups
- C. Propose active/active cluster deployment with separate redundancy groups
- D. Propose active/passive cluster deployment with separate redundancy groups
Answer: B
NEW QUESTION 17
You want to deploy JATP in your network that uses SRX Series devices.
In this scenario, which feature must you enable on the SRX Series devices?
- A. IPS
- B. SSL forward proxy
- C. AppSecure
- D. UTM antivirus
Answer: B
NEW QUESTION 18
You are designing an SDSN security solution for a new campus network. The network will consist of Juniper Networks Policy Enforcer, Juniper Networks switches, third-party switches, and SRX Series devices. The switches and the SRX Series devices will be used as security enforcement points.
Which component supports the SRX Series devices in this scenario?
- A. RADIUS server
- B. certificate server
- C. Security Director
- D. DHCP server
Answer: C
Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/release-independent/solutions/topics/concept/sg-
006a-sdsn-product-components.html
NEW QUESTION 19
You are asked to install a mechanism to protect an ISP network from denial-of-service attacks from a small number of sources.
Which mechanism will satisfy this requirement?
- A. Sky ATP
- B. RTBH
- C. GeoIP
- D. UTM
Answer: B
NEW QUESTION 20
You must design a small branch office firewall solution that provides application usage statistics.
In this scenario, which feature would accomplish this task?
- A. AppQoS
- B. AppTrack
- C. UTM
- D. AppFW
Answer: B
NEW QUESTION 21
You are asked to deploy a security solution in your data center that ensures all traffic flows through the SRX Series devices.
Which firewall deployment method meets this requirement?
- A. one-arm
- B. two-arm
- C. transparent
- D. inline
Answer: D
NEW QUESTION 22
You are deploying a data center Clos architecture and require secure data transfers within the switching fabric.
In this scenario, what will accomplish this task?
- A. LAG Layer 2 hashing
- B. stacked VLAN tagging on the core switches
- C. MACsec encryption
- D. IRB VLAN routing between hosts
Answer: C
NEW QUESTION 23
You are designing a data center interconnect between two sites across a service provider Layer 3 VPN service. The sites require Layer 2 connectivity between hosts, and the connection must be secure.
In this scenario, what will accomplish this task?
- A. MACsec encryption
- B. EVPN over IPsec
- C. SSL VPN encryption
- D. stacked VLAN tagging
Answer: A
NEW QUESTION 24
You are designing a solution to protect a service provider network against volumetric denial-of-service attacks.
Your main concern is to protect the network devices.
Which two solutions accomplish this task? (Choose two.)
- A. BGP FlowSpec
- B. screens
- C. next-generation firewall
- D. intrusion prevention system
Answer: A,D
NEW QUESTION 25
Your customer needs help designing a single solution to protect their combination of various Junos network devices from unauthorized management access.
Which Junos OS feature will provide this protection?
- A. Use a firewall filter applied to the fxp0 interface
- B. Use the management zone host-inbound-traffic feature
- C. Use a security policy with the destination of the junos-host zone
- D. Use a firewall filter applied to the lo0 interface
Answer: A
Explanation:
Explanation/Reference: https://www.juniper.net/documentation/en_US/junos/topics/concept/junos-software-router- security-supported-features.html
NEW QUESTION 26
Your company has outgrown its existing secure enterprise WAN that is configured to use OSPF, AutoVPN, and IKE version 1. You are asked if it is possible to make a design change to improve the WAN performance without purchasing new hardware.
Which two design changes satisfy these requirements? (Choose two.)
- A. Implement Auto Discovery VPN
- B. Modify the IPsec proposal from AES-128 to AES-256
- C. Migrate to IKE version 2
- D. Change the IGP from OSPF to IS-IS
Answer: A,D
NEW QUESTION 27
You are designing a network management solution that provides automation for Junos devices. Your customer wants to know which solutions would require additional software to be deployed to existing Junos devices.
Which two solutions satisfy this scenario? (Choose two.)
- A. Chef
- B. Puppet
- C. Ansible
- D. SaltStack
Answer: A,D
NEW QUESTION 28
......
Pass Juniper JN0-1331 Exam Info and Free Practice Test: https://www.dumpsvalid.com/JN0-1331-still-valid-exam.html