JN0-1332 Training & Certification Get Latest JNCDS-SEC Updated on Aug 28, 2021
Certification Training for JN0-1332 Exam Dumps Test Engine
NEW QUESTION 10
You are designing Enterprise WAN attachments and want to follows Jumper recommended security practices In 0*s scenario. which two statements are correct? (Choose two.)
- A. Network management traffic should be segmented from data traffic
- B. Authentication authorization and accounting should be implemented on network resources
- C. The branch CPE should be configured to all outbound Ml:
- D. Printer traffic should be segmented from data traffic.
Answer: A,B
NEW QUESTION 11
Multiple customers use the shared infrastructure of your data center. These customers require isolation for compliance and security reasons.
What would you do to satisfy this requirement?
- A. Deploy a single logical security control point.
- B. Isolate each customer by using different physical hard//are
- C. Deploy multiple physical security control points
- D. Place each customers VLANs separate virtual router
Answer: A
NEW QUESTION 12
Which solution would you deploy to accomplish this task?
- A. Juniper Networks Central insights
- B. Junes Space Log Director
- C. Juniper Networks Secure Analytics
- D. Junos Space Security Director
Answer: B
NEW QUESTION 13
Your network design requires that you ensure privacy between WAN endpoints.
Which transport technology requires an IPsec overlay to satisfy this requirement?
- A. leased line
- B. L2VPN
- C. internet
- D. L3VPN
Answer: D
NEW QUESTION 14
Which two statements are true about WAN security considerations? (Choose two.)
- A. internal connections are susceptible to fragmentation
- B. IPsec increases protection on all WAN types
- C. Provider VPN circuit require iPsec
- D. MACsec increases protection on alt WAN types
Answer: A
NEW QUESTION 15
Refer to the Exhibit.
You are asked to provide a proposal for security elements in the service provider network shown in the exhibit. You must provide DOoS protection for Customer A from potential upstream attackers.
Which statements correct in this scenario?
- A. You should implement DDoS protection to drop offending traffic on the edge devices closest to the source of the attack.
- B. You should implement DDoS protection to drop offending traffic on the customer edge device.
- C. You should implement DDoS protection to drop offending traffic on the edge devices closest to the destination of the attack.
- D. You should implement DDoS protection to drop offending traffic on the core devices.
Answer: D
NEW QUESTION 16
In yew network design, you must include a method to block IP addresses from certain countries that will automatically update within the SRX Series devices' security policies.
Which technology would accomplish this goal?
- A. dynamic DNS
- B. IPS
- C. GeolP
- D. UTM
Answer: A
NEW QUESTION 17
Which two steps should be included in your security design process? (Choose two )
- A. Identify permitted communications
- B. identity external attackers
- C. Identify security requirements for the customer's organization
- D. Define an overall routing strategy
Answer: A,B
NEW QUESTION 18
When using Contra! networking, security policies are distributed as access control list to which component?
- A. vRouter
- B. vSwith
- C. vSRX
- D. vMX
Answer: A
NEW QUESTION 19
You must design a separate network within your trust network with added security and separation. What is the common name for this type of network?
- A. enclave
- B. guest
- C. DMZ
- D. trust
Answer: A
NEW QUESTION 20
What are two characteristics of an overlay network design? (Choose two.)
- A. The physical network contains per-tenant state.
- B. The physical network uses tunnels to transfer traffic
- C. The overlay network contains per-tenant state
- D. The overlay network uses tunnels to transfer traffic.
Answer: C
NEW QUESTION 21
You are asked to provide a network design proposal for a service provider As part of this design you must provide a solution that allows the service provider to mitigate DDoS attacks on their customers Which two features will satisfy this requirement? (Choose two)
- A. Storm control
- B. 8GP traffic engineering
- C. 8GP FlowSpec
- D. remote triggered Hack hole (RTBH)
Answer: D
NEW QUESTION 22
Physical security devices are ''blind'' to which type of traffic?
- A. private VLAN
- B. management
- C. intra-server traffic
- D. bare metal server to VM
Answer: A
NEW QUESTION 23
Which firewall service is used as a first line of defense and often used by a security device to protect itself?
- A. intrusion prevention system
- B. stateless firewall filter
- C. unified Threat management
- D. network address translation
Answer: A
NEW QUESTION 24
When designing the security for a service provider core router, you are asked to add a firewall fitter on the to0 interface in this scenario, which two protocols would you want to allow through the filter? (Choose two.)
- A. SSH
- B. LLDP
- C. BGP
- D. STP
Answer: B,C
NEW QUESTION 25
Which technology enables IPS inspection for users browsing websites that use Transport Layer Security (TLS)?
- A. defense in-depth
- B. screens
- C. SSL reverse proxy
- D. SSL forward proxy
Answer: D
NEW QUESTION 26
You are asked to deploy multiple kiosk locations around the country. Their locations will change frequently and will need to access services in the corporate data center as well as other kiosk locations You need a central key location In this scenario, which solution would you deploy?
- A. Mesh VPN
- B. Juniper Secure Connect
- C. Group VPN
- D. Auto VPN
Answer: D
NEW QUESTION 27
You must implement a solution to deploy end-to-end security services on network elements.
Which solution will accomplish this task?
- A. JSA
- B. SRX Series devices
- C. Network Director
- D. Security Director
Answer: A
NEW QUESTION 28
When considering the data center, which two security aspects must be considered? (Choose two)
- A. theoretical
- B. physical
- C. conceptual
- D. logical
Answer: A
NEW QUESTION 29
As part of a design requirement you are asked to allow users in a specific department to authenticate only on their laptops and no other devices on the same network port. Which mode of 802 .1X authentication will you use to satisfy this requirement?
- A. single
- B. multiple
- C. MAC RADIUS
- D. single-secure
Answer: B
NEW QUESTION 30
You are asked to segment the networks connected to an SRX Series device into distinct logical groups with different security requirements.
How would you accomplish this task?
- A. Define different intrusion prevention policies for each network segment.
- B. Define different security zones for each network segment
- C. Define different NAT policies for each network segment.
- D. Define different security policies for each network segment.
Answer: D
NEW QUESTION 31
Refer to the exhibit.
You arc designing a security solution using an SRX Series chassis duster in two separate buildings In this scenario, what are three considerations? (Choose three )
- A. Latency on the fabric path must be under 1000 ms
- B. Latency on the control path must be under 100 ms
- C. The switches connecting to interface fab1 must support jumbo frames
- D. Both HA Inks must be on physically different switches.
- E. The switches connecting to interface fxp: must support jumbo frames
Answer: B,C,E
NEW QUESTION 32
What are two factors you must consider when designing a network for security intelligence? (Choose two.)
- A. the Junos OS version
- B. the third-party management application
- C. the number and model of SRX Series devices
- D. the number and model of JSA Series devices
Answer: B
NEW QUESTION 33
......
Step by Step Guide to Prepare for JN0-1332 Exam: https://www.dumpstillvalid.com/JN0-1332-prep4sure-review.html
