JN0-1331 Exam Questions
127 real JN0-1331 exam questions with expert-verified answers and explanations. Page 1 of 3.
- Question #1Security Platform Architectures
You are deploying Security Director with the logging and reporting functionality for VMs that use SSDs. You expect to have approximately 20,000 events per second of logging in your...
Security Directorlogging and reportingSSDevents per second - Question #2
You are concerned about users attacking the publicly accessible servers in your data center through encrypted channels. You want to block these attacks using your SRX Series device...
- Question #3Core Security Design Concepts
Your customer needs help designing a single solution to protect their combination of various Junos network devices from unauthorized management access. Which Junos OS feature will...
management access protectionfirewall filterfxp0Junos devices - Question #4
You must allow applications to connect to external servers. The session has embedded IP address information to enable the remote system to establish a return session. In your desig...
- Question #5Threat Management Design
You are using SRX Series devices to secure your network and you require sandboxing for malicious file detonation. However, per company policy, you cannot send potentially malicious...
sandboxingJATPon-premise ATPmalware detonation - Question #6Secure Access and VPN Design
You are creating a security design proposal for an enterprise customer. As part of the design, you are implementing 802.1x authentication on your EX Series devices. In this scenari...
802.1Xsupplicantauthenticatorport-based access control - Question #7
You are asked to install a mechanism to protect an ISP network from denial-of-service attacks from a small number of sources. Which mechanism will satisfy this requirement?
- Question #8
You are responding to an RFP for securing a large enterprise. The RFP requires an onsite security solution which can use logs from third-party sources to prevent threats. The solut...
- Question #9Security Automation and Orchestration Design
You are designing an SDSN security solution for a new campus network. The network will consist of Juniper Networks Policy Enforcer, Juniper Networks switches, third-party switches,...
SDSNPolicy EnforcerSecurity Directorenforcement points - Question #10
Your company has outgrown its existing secure enterprise WAN that is configured to use OSPF, AutoVPN, and IKE version 1. You are asked if it is possible to make a design change to...
- Question #11Threat Management Design
You are concerned about malicious attachments being transferred to your e-mail server at work through encrypted channels. You want to block these malicious files using your SRX Ser...
Sky ATPSSL forward proxySMTP scanningencrypted traffic inspection - Question #12
Click the Exhibit button. Which type of security solution is shown in this exhibit?
- Question #13
You are designing an Internet security gateway (ISG) for your company and are considering a centralized versus a distributed model for ISGs. Which two statements are correct in thi...
- Question #14
You are creating a data center security design. Virtual security functions must be performed on east-west traffic. Security functions must be commissioned and decommissioned freque...
- Question #15Security Virtualization Design
What are two reasons for using cSRX over vSRX? (Choose two.)
cSRXvSRXcontainer firewallsecurity virtualization - Question #16
You will be managing 1000 SRX Series devices. Each SRX Series device requires basic source NAT to access the Internet. Which product should you use to manage these NAT rules on the...
- Question #17
Which two features are used to stop IP spoofing in and out of your network? (Choose two.)
- Question #18
What are two benefits of the vSRX in a virtualized private or public cloud multitenant environment? (Choose two.)
- Question #19
You are designing a new network for your organization with the characteristics shown below. - All traffic must pass inspection by a security device. - A center-positioned segmentat...
- Question #20
A hosting company is migrating to cloud-based solutions. Their customers share a physical firewall cluster, subdivided into individual logical firewalls for each customer. Projecti...
- Question #21
You are working on a network design that will use EX Series devices as Layer 2 access switches in a campus environment. You must include Junos Space in your design. You want to tak...
- Question #22
You are designing a data center interconnect between two sites across a service provider Layer 2 leased line. The sites require Layer 2 connectivity between hosts, and the connecti...
- Question #23
You are designing a new campus Internet access service that implements dynamic NAT for customer IP addressing. The customer requires services that allow peer-to-peer networking and...
- Question #24
You are designing a network management solution that provides automation for Junos devices. Your customer wants to know which solutions would require additional software to be depl...
- Question #25
You are asked to virtualize numerous stateful firewalls in your customer's data center. The customer wants the solution to use the existing Kubernetes-orchestrated architecture. Wh...
- Question #26
Your customer is getting ready to deploy a new WAN architecture. It must be simple to set up, address hub scaling concerns, and allow the automatic addition of new sites without re...
- Question #27
You are designing a solution to protect a service provider network against volumetric denial-of- service attacks. Your main concern is to protect the network devices. Which two sol...
- Question #28
You have multiple SRX chassis clusters on a single broadcast domain. Why must you assign different cluster IDs in this scenario?
- Question #29
You are implementing Routing Engine protection, and packets are processed in a specific order. In this scenario, which function processed a received packet last?
- Question #30
You are creating a security design proposal for a customer who is connecting their headquarters to a remote branch site over an unsecured Internet connection. As part of your desig...
- Question #31
You are required to design a university network to meet the conditions shown below. - Users connected to the university network should be able to access the Internet and the resear...
- Question #32
Click the Exhibit button. You are designing the virtualized server deployment shown in the exhibit in your data center. The vSRX device is acting as a Layer 2 firewall and the two...
- Question #33
Which two protocols are supported natively by the Junos automation stack? (Choose two.)
- Question #34
Which solution centralizes the management of security devices in your data center?
- Question #35Secure Access and VPN Design
Which solution provides a certificate based on user identity for network access?
NACcertificate-based authenticationuser identitynetwork access control - Question #36
You are concerned about users downloading malicious attachments at work while using encrypted Web mail. You want to block these malicious files using your SRX Series device. In thi...
- Question #37
You are designing an enterprise WAN network that must connect multiple sites. You must provide a design proposal for the security elements needed to encrypt traffic between the rem...
- Question #38
You must design a small branch office firewall solution that provides application usage statistics. In this scenario, which feature would accomplish this task?
- Question #39Core Security Design Concepts
You are designing a corporate WAN using SRX Series devices as a combined firewall and router at each site. Regarding packet-mode and flow-mode operations in this scenario, which st...
packet-modeflow-modeSRXsecurity services - Question #40Threat Management Design
You are asked to include anti-malware features into an existing network design. Traffic from the infected machines must be moved to a quarantined VLAN. Which product will provide t...
Sky ATPquarantine VLANinfected machinesautomated threat response - Question #41
Policy Enforcer provides which benefit?
- Question #42
Which statement about IPsec tunnels is true?
- Question #43
You work for an ISP that wants to implement remote-triggered black hole (RTBH) filters. What are three considerations in this scenario? (Choose three.)
- Question #44
You are designing a DDoS solution for an ISP using BGP FlowSpec. You want to ensure that BGP FlowSpec does not overwhelm the ISP's edge routers. Which two requirements should be in...
- Question #45
You are designing an SDSN security solution for a new campus network. The network will consist of Juniper Networks Policy Enforcer, Juniper Networks switches, third-party switches,...
- Question #46
You are designing a data center interconnect between two sites across a service provider Layer 3 VPN service. The sites require Layer 2 connectivity between hosts, and the connecti...
- Question #47Network Segmentation Design
You have a campus location with multiple WAN links. You want to specify the primary link used for your VoIP traffic. In this scenario, which type of WAN load balancing would you us...
WAN load balancingfilter-based forwardingVoIPFBF - Question #48Network Segmentation Design
You are deploying a data center Clos architecture and require secure data transfers within the switching fabric. In this scenario, what will accomplish this task?
Clos architecturedata center fabricIRBVLAN routing - Question #49
In a data center, what are two characteristics of access tier VLAN termination on the aggregation tier? (Choose two.)
- Question #50
What is the maximum number of SRX Series devices in a chassis cluster?