JN0-1330 Exam Questions
60 real JN0-1330 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Data Center Security
Which security solution protects against zero-day attacks?
zero-day attacksadvanced anti-malwarethreat preventionSky ATP - Question #2Data Center Security
Which three statements about Sky Advanced Threat Prevention are true? (Choose three.)
Sky Advanced Threat Preventiondynamic analysismachine learningmalware detection - Question #3Data Center Management and Automation
Your client modifies an event script and needs to update 100 SRX Series devices with this new script. They want to use the refresh-from parameter to refresh the script from a centr...
event scriptsscript refreshSRX automationcentralized script management - Question #5Data Center Security
You are designing a WAN solution for a small service provider. The service provider has asked you to include ways to mitigate potential DDoS attacks against their customers. Which...
BGP flowspecremote triggered blackholeDDoS mitigationservice provider security - Question #6Data Center Security
Your customer is purchasing another company. They must establish communication between the two corporate networks, which use an overlapping IPv4 address space. The customer knows t...
static NAToverlapping address spacenetwork address translationIP renumbering - Question #7
Which component of the Juniper NFV solution architecture acts as the VNF manager?
- Question #8Data Center Security
In the ever-changing threat landscape, you are seeking to deploy a dynamic anti-malware solution. What are three characteristics of the Sky Advanced Threat Prevention public cloud...
Sky ATPpublic cloud infrastructuremachine learningcache lookups - Question #9Data Center Security
You need to provide wireless access to the user community without reducing security. Which action accomplishes this task?
EAP-TLSwireless authentication802.1Xnetwork access security - Question #10
Where are the security policies enforced for next-generation firewalls?
- Question #11Data Center Management and Automation
You are designing a Log Director deployment that must be able to handle 6,500 sustained events per second. What is the minimum deployment scenario?
Log Directorlog collector sizingevents per secondSIEM deployment - Question #12Data Center Virtualization
Which two components are required to implement a Contrail service chain? (Choose two.)
Contrailservice chainvirtual networkservice policy - Question #13Data Center Security
You must implement access control lists to protect the control plane of a service provider's core devices. What are two ways to accomplish this task? (Choose two.)
control plane protectionACL filteringRFC 1918fragment filtering - Question #15Data Center Security
Due to changes in security requirements you must place a firewall between an existing Web server farm and a database server farm residing in the same subnet. In this scenario, why...
transparent mode firewallsame-subnet insertionLayer 2 securityIP address preservation - Question #16Data Center Management and Automation
Spotlight Secure provides which benefit?
Spotlight Securecentralized security managementdevice managementJunos Space Security Director - Question #17Data Center Security
What are three characteristics of the integrated user firewall feature? (Choose three.)
integrated user firewallSRX log collectionlog concentratoridentity-based policy - Question #19Data Center Security
You are asked to implement port-based authentication on your access switches. Security and ease of access are the two primary requirements. Which authentication solution satisfies...
MAC RADIUSport-based authentication802.1Xaccess switch security - Question #20Secure Access and VPN Design
What is one way to increase the security of a site-to-site IPsec VPN tunnel?
IPsec VPNtraffic selectorssite-to-site VPNIKE - Question #21Secure Access and VPN Design
Your customer is planning the deployment of a new hub-and-spoke WAN architecture that must support dual stack. They have decided against using a dynamic routing protocol. They are...
route-based VPNtraffic selectorshub-and-spokedual stack - Question #22Threat Management Design
What are the three activities in the reconnaissance phase of an attack? (Choose three.)
reconnaissanceattack phasesport scanningnetwork mapping - Question #23Security Automation and Orchestration Design
Your customer is assessing their network incident response plan. They need to improve their recovery time when a networking issue occurs, especially when involves JTAC support. The...
incident responseService NowJTAC supportnetwork management - Question #24Security Platform Architectures
Your customer is planning to secure a data center with webservers reachable through two ISP connections terminating on each node of an active/passive SRX Series chassis cluster. IS...
chassis clusterISP redundancyBGPinterface monitoring - Question #25Secure Access and VPN Design
You are asked to provide user-based network access through an SRX Series device. The implementation must use Active Directory credentials for user account validation. Which two sol...
user firewallActive Directoryfirewall authenticationSRX access control - Question #26Security Platform Architectures
What are two design requirements for deploying a chassis cluster across a Layer 2 network? (Choose two.)
chassis clusterLayer 2 HAfabric linkshigh availability - Question #27Secure Access and VPN Design
Your company is establishing a BYOD policy and you are asked to create the appropriate security infrastructure. In the policy, Internet access should only be provided to the BYOD w...
BYOD802.1Xguest VLANnetwork access control - Question #28Network Segmentation Design
Click the Exhibit button. Given the data center topology shown in the exhibit, what are two designs that enable the SRX Series devices to inspect all traffic between the webserver...
VLAN segmentationSRX traffic inspectionvirtual routerJunos Fusion - Question #29Secure Access and VPN Design
You are asked to provide a design proposal for a campus network. As part of the design, the customer requires that all end user devices must be authenticated before being granted a...
802.1Xdevice authenticationLayer 2campus network - Question #30Core Security Design Concepts
Which three actions are part of an in-depth network defense strategy? (Choose three.)
defense in depthsecurity awarenessleast privilegeauditing - Question #31Network Segmentation Design
Your company must enable high-speed Layer 2 connectivity between two data centers connected by private fiber. Your security policy mandates that all company data is encrypted betwe...
MACsecLayer 2 encryptiondata center interconnectWAN security - Question #32Security Virtualization Design
Your customer is in the design stage for a new data center. They have historically used the SRX5600. To improve the security of the data center, you will be suggesting they deploy...
vSRXvirtual firewallVM traffic inspectiondata center virtualization - Question #33Secure Access and VPN Design
Which statements about IPsec tunnels is true?
IPsectunnel encryptionVPN fundamentalssecurity - Question #34Security Virtualization Design
A client wants to deploy a vSRX chassis cluster across two existing ESXi hosts without changing the external switch configuration. Which two actions must you perform to meet this r...
vSRXchassis clusterESXidistributed virtual switch - Question #35Threat Management Design
Click the Exhibit button. Referring to the network shown in the exhibit, a SYN flood attacks is initiated by an attacker that has a public IP address from ISP B within the 200.200....
SYN floodDDoS mitigationingress filteringspoofed source addresses - Question #36Threat Management Design
You are asked to deploy user access to the Internet, and you want to determine which applications are passing through the firewall. Which feature accomplishes this task?
AppTrackapplication visibilitytraffic monitoringfirewall - Question #37Security Automation and Orchestration Design
A customer is globally expanding their retail stores exponentially. Their IT department is small. The effort to deploy new services is delaying the project. The customer's requirem...
network orchestrationzero-touch provisioningNFX platformIPsec automation - Question #38Security Automation and Orchestration Design
You are designing a network management solution for a customer's data center. Your design must include a solution that supports the collection of events from SRX Series devices, as...
Secure AnalyticsSIEMevent collectionthird-party integration - Question #39Security Platform Architectures
Click the Exhibit button. The data center shown in the exhibit is running an active/active SRX Series chassis cluster and an active/ active network infrastructure. Customer A needs...
chassis clusterZ-mode trafficactive/active HAtraffic symmetry - Question #41Threat Management Design
Your company's IT policy restricts general access to recruitment websites from within the corporate network. However, the human resources department requires access to these sites....
URL filteringenhanced web filteringURL whitelistweb access control - Question #42Network Segmentation Design
In the data center, what are two characteristics of access tier VLAN termination at the firewall? (Choose two.)
VLAN terminationinter-VLAN trafficfirewall servicesdata center access tier - Question #43Threat Management Design
Your company is migrating an existing enterprise application to use TLS. The application is written in PHP and must have IPS protection. Which two actions will ensure that the appl...
SSL reverse proxyIPS policyTLS inspectionPHP signatures - Question #44Security Platform Architectures
You are asked to deploy security in your data center with the criteria listed below. -The deployment must allow for selective firewall redirect. -The deployment must allow for sele...
one-arm firewallselective redirectfirewall bypassdata center deployment - Question #45Network Segmentation Design
You are asked to implement network segmentation to increase security within your internal network. Which three statements are correct in this scenario? (Choose three.)
network segmentationtraffic visibilitygranular access controlasset protection - Question #46Security Platform Architectures
You are designing a network for a customer who has given you specific requirements for the Internet gateway: -The device must validate BGP peers, and -Administrators must be able t...
BGP peer authenticationrouting protocol authenticationpacket countinginternet gateway - Question #47Security Automation and Orchestration Design
You are preparing for the initial deployment of 100 SRX Series devices, and you want to leverage the autoinstallation feature. Which three prerequisites are required before you beg...
autoinstallationDHCPTFTPzero-touch provisioning - Question #48Threat Management Design
Which three functions are licensed UTM features? (Choose three.)
UTMantispamantivirusenhanced web filtering - Question #49Security Platform Architectures
You are asked to design a high availability solution for a customer that wants to use a chassis cluster with two redundancy groups (RG0 and RG1). Their requirements dictate that th...
chassis clusterredundancy groupsinterface monitoringHA failover - Question #50Security Virtualization Design
Click the Exhibit button. Referring to the diagram shown in the exhibit, which three statements are true? (Choose three.)
vSRXlink aggregationVMware KVM hypervisorNIC management - Question #51Core Security Design Concepts
Click the Exhibit button. Your customer needs to make Server's HTTP service and Server2's SMTP service available to the Internet behind a single public IP address. Referring to the...
destination NATport forwardingsingle public IPmultiple services - Question #52Threat Management Design
You are designing the security improvements needed to protect an application that your company is about to deploy. The only traffic that the application can receive is valid HTTP t...
AppSecureIPSsecurity policyapplication layer protection - Question #53Secure Access and VPN Design
You are asked to design security policies for your corporate network where policy-based VPNs will be used. In this scenario, which three statements for a traffic match are true? (C...
policy-based VPNIPsec tunnel establishmentsecurity policyIKE gateway - Question #54Core Security Design Concepts
What are two reasons to add Routing Engine protection? (Choose two.)
Routing Engine protectionDDoS protectioninfrastructure securityloopback filtering