Get 2022 Updated Free Juniper JN0-1332 Exam Questions & Answer
JN0-1332 Dumps PDF and Test Engine Exam Questions
NEW QUESTION 29
Which automation language would you use to create on-box and off-box scripts for SRX Series devices?
- A. Ruby
- B. Python
- C. Pert
- D. Java
Answer: A
NEW QUESTION 30
You must implement a security solution that uses a central database to authenticate devices without EAP-M05 based on their network interface address. Which solution will accomplish this task'?
- A. MAC RADIUS
- B. static MAC bypass
- C. 802.1X multiple
- D. 802.1X single secure
Answer: D
NEW QUESTION 31
Your network design requires that you ensure privacy between WAN endpoints.
Which transport technology requires an IPsec overlay to satisfy this requirement?
- A. L3VPN
- B. L2VPN
- C. internet
- D. leased line
Answer: A
NEW QUESTION 32
According to Juniper Networks, what are two focus points when designing a secure network? (Choose two.)
- A. automation
- B. performance
- C. distributed control
- D. classification
Answer: B,D
NEW QUESTION 33
As part of a design requirement you are asked to allow users in a specific department to authenticate only on their laptops and no other devices on the same network port. Which mode of 802 .1X authentication will you use to satisfy this requirement?
- A. MAC RADIUS
- B. single
- C. multiple
- D. single-secure
Answer: C
NEW QUESTION 34
When two security services process a packet whether it is being processed in the first-packet path or the fast path? (Choose two.)
- A. route lookup
- B. policy lookup
- C. screen options
- D. ALG
Answer: A,B
NEW QUESTION 35
You are designing a security solution that includes SRX Series firewalls in a chassis cluster.
In this scenario. which two dements must be part of the design? (Choose two.)
- A. The node 10 must be the same on both SRX Series devices
- B. The physical interface on each SRX Series device making up the reth interface must be in the same L2 domain
- C. The duster ID must be the same on both SRX Series devices
- D. The physical interface on each SRX Series device making up the reth interface must be in separate L2 domains
Answer: D
NEW QUESTION 36
You are asked to provide a security solution to secure corporate traffic across the Internet between sites. This solution must provide data integrity, confidentiality and encryption Which security feature will accomplish this task?
- A. IGRE tunnel
- B. IPsecVPN
- C. Layer 3 VPN
- D. IP-IP tunnel
Answer: B
NEW QUESTION 37
You must ensure that all 10GbE interfaces have an MTU of 9192 and that an of the ge-0/0>4.0 interfaces on the SRX Series devices are in a specific zone.
Which type of a script would you use to accomplish this task?
- A. commit script
- B. op script
- C. event script
- D. REST script
Answer: B
NEW QUESTION 38
Which firewall service is used as a first line of defense and often used by a security device to protect itself?
- A. stateless firewall filter
- B. network address translation
- C. intrusion prevention system
- D. unified Threat management
Answer: C
NEW QUESTION 39
When considering the data center, which two security aspects must be considered? (Choose two)
- A. theoretical
- B. physical
- C. logical
- D. conceptual
Answer: A
NEW QUESTION 40
You are designing a service provider network. As part of your design you must ensure that the OSPF, BGP, and RSVP protocol communications are secured using the same authentication method. Which authentication protocol will accomplish this task?
- A. SHA-RSA
- B. HMAC-MD5
- C. simple authentication
- D. SHA-256
Answer: C
NEW QUESTION 41
You are asked to deploy multiple kiosk locations around the country. Their locations will change frequently and will need to access services in the corporate data center as well as other kiosk locations You need a central key location In this scenario, which solution would you deploy?
- A. Juniper Secure Connect
- B. Group VPN
- C. Mesh VPN
- D. Auto VPN
Answer: D
NEW QUESTION 42
You are designing a security solution for an existing data center. All traffic most be secured using SRX Series devices, however, you are unable to change the existing IP addressing scheme. Which firewall deployment method satisfies this requirement?
- A. transparent deployment
- B. inline deployment
- C. two-arm deployment
- D. one-arm deployment
Answer: A
NEW QUESTION 43
As part of your service provider WAN network design, you are asked to create a design that secures BGP communication .
In this scenario, what are two reasons you would choose BGP Generated TTL Security Mechanism (GTSM)? (Choose two.)
- A. All of your router BGP connections are point-to-multipoint.
- B. AlI of your router BGP connections are point-to-point
- C. You have an automated method of rotating MD5 hashes on each router.
- D. You do not have an easy method of rotating MD5 hashes on each router
Answer: A,D
NEW QUESTION 44
Refer to the Exhibit.
You are asked to provide a proposal for security elements in the service provider network shown in the exhibit. You must provide DOoS protection for Customer A from potential upstream attackers.
Which statements correct in this scenario?
- A. You should implement DDoS protection to drop offending traffic on the customer edge device.
- B. You should implement DDoS protection to drop offending traffic on the core devices.
- C. You should implement DDoS protection to drop offending traffic on the edge devices closest to the destination of the attack.
- D. You should implement DDoS protection to drop offending traffic on the edge devices closest to the source of the attack.
Answer: B
NEW QUESTION 45
You are designing Enterprise WAN attachments and want to follows Jumper recommended security practices In 0*s scenario. which two statements are correct? (Choose two.)
- A. Authentication authorization and accounting should be implemented on network resources
- B. The branch CPE should be configured to all outbound Ml:
- C. Network management traffic should be segmented from data traffic
- D. Printer traffic should be segmented from data traffic.
Answer: A,C
NEW QUESTION 46
You are designing an IP camera solution for your warehouse You must block command and control servers from communicating with the cameras. In this scenario. which two products would you need to include in your design? (Choose two)
- A. Juniper ATP Cloud
- B. Security Director
- C. SRX Series device
- D. IPS
Answer: A,D
NEW QUESTION 47
You are asked to enable denial of service protection for a webserver behind an SRX Series device In this scenario, which feature would you enable?
- A. Juniper ATP
- B. screens
- C. Web filtering
- D. App Secure
Answer: A
NEW QUESTION 48
When designing security for the service provider WAN. you are asked to implement unicast reverse path forwarding (uRPF) in this scenario. on which interfaces would you choose to implement loose mode uRPF?
- A. On interfaces that are user access interfaces
- B. On interfaces where the best forwarding path fee routes is through the receiving interface
- C. On interfaces that participate in multihomes environments
- D. On interfaces where all data originates on the same network as that of the router interface
Answer: A
NEW QUESTION 49
Which two statements describe Juniper ATP Cloud? (Choose two)
- A. Juniper ATP Cloud can use a sandbox to detect threats that use evasion techniques.
- B. Juniper ATP Cloud runs mime with network traffic to Nock all traffic before reaching endpoint.
- C. Juniper ATP Cloud provides protection against zero-day threats
- D. Juniper ATP Cloud is an added app that must be instated with Security Director
Answer: A,D
NEW QUESTION 50
As part of your design to secure a service provider WAN. you are asked to design a destination-based remote triggered black hole (RTBH) solution What arc two reasons for using this design? (Choose two)
- A. You do not know the source address of DDoS packets
- B. The attack comes from a limited number of source IP addresses
- C. The attack is focused on a single IP address
- D. You want to ensure that the destination IP remains reachable
Answer: D
NEW QUESTION 51
Physical security devices are ''blind'' to which type of traffic?
- A. private VLAN
- B. intra-server traffic
- C. bare metal server to VM
- D. management
Answer: A
NEW QUESTION 52
You are asked to deploy a product that will provide east-west protection between virtual machines hosted on the same physical server with a requirement to participate with local routing instances. Which product would you use in this scenario?
- A. cSRX
- B. QFX
- C. SRX
- D. vSRX
Answer: D
NEW QUESTION 53
Your company just purchased another company that uses the same IP address space as your company. You are asked to design a solution that allows both company's to use each other's IT resources. Which two actions would you use to accomplish this task? (Choose two.)
- A. Implement three non-overlapping equal-size address blocks.
- B. Implement double NAT
- C. Implement two non-overlapping equal-size address blocks
- D. Implement persisted mat
Answer: A
NEW QUESTION 54
......
Juniper JN0-1332 Exam Topics:
| Section | Objectives |
|---|---|
| Security Virtualization | Describe the security design considerations for a virtualized environment
|
| Fundamental Security Concepts | Describe the various tenets of common security features
|
| Security Automation and Management | Describe the design considerations for security management
Describe the design considerations for automating security.
|
| Securing the Data Center | Describe the security design considerations in a data center
|
| Advanced SecurityConcepts | Describe advanced security features
|
| Securing the Enterprise WAN | Describe the security design considerations for an enterprise WAN
|
Verified JN0-1332 exam dumps Q&As with Correct 66 Questions and Answers: https://www.examsreviews.com/JN0-1332-pass4sure-exam-review.html