Skip to main content

JN0-1331 Online Practice Questions

Security Design, Specialist (JNCDS-SEC)

65 questions available · Page 1 of 7

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

You are designing an SDSN security solution for a new campus network. The network will consist of Juniper Networks Policy Enforcer, Juniper Networks switches, third-party switches, and SRX Series devices. The switches and the SRX Series devices will be used as security enforcement points.

Which component supports the SRX Series devices in this scenario?

  1. A

    Security Director

  2. B

    RADIUS server

  3. C

    certificate server

  4. D

    DHCP server

Show answer and explanation

Correct answer: A

Explanation

References:
https://www.juniper.net/documentation/en_US/release-independent/solutions/topics/concept/
sg-006a-sdsn-product-components.html

Question 2 Single choice

You are deploying Security Director with the logging and reporting functionality for VMs that use SSDs.
You expect to have approximately 20,000 events per second of logging in your network.

In this scenario, what is the minimum number of log receiver devices that you should use?

  1. A

    4

  2. B

    3

  3. C

    2

  4. D

    1

Show answer and explanation

Correct answer: D

Explanation

References:
https://www.juniper.net/documentation/en_US/junos-space17.1/topics/task/multi-task/junos-space-sd-log-collector-installing.html

Question 3 Single choice

Which solution provides a certificate based on user identity for network access?

  1. A

    network access control

  2. B

    user firewall

  3. C

    IP filtering

  4. D

    MAC filtering

Show answer and explanation

Correct answer: A

Explanation

References:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-user-auth-control-network-access.html

Question 4 Single choice

Which statement is correct about service chaining?

  1. A

    Service chaining uses IPsec to connect together two or more VMs

  2. B

    Service chaining evaluates traffic by using multiple security features on the same instance

  3. C

    Service chaining redirects traffic back through the same device for additional processing

  4. D

    Service chaining combines multiple VNF instances together in the data flow

Show answer and explanation

Correct answer: D

Question 5 Multiple choice

You are designing a data center security architecture. The design requires automated scaling of security services according to real-time traffic flows.

Which two design components will accomplish this task? (Choose two.)

  1. A

    telemetry with an SDN controller

  2. B

    JFlow traffic monitoring with event scripts

  3. C

    VNF security devices deployed on x86 servers

  4. D

    VRF segmentation on high-capacity physical security appliances

Show answer and explanation

Correct answers: B, C

Explanation

References:
https://www.juniper.net/documentation/en_US/learn-about/LearnAbout_NFV.pdf

Question 6 Multiple choice

You are designing a network management solution that provides automation for Junos devices. Your customer wants to know which solutions would require additional software to be deployed to existing Junos devices.

Which two solutions satisfy this scenario? (Choose two.)

  1. A

    SaltStack

  2. B

    Ansible

  3. C

    Puppet

  4. D

    Chef

Show answer and explanation

Correct answers: A, D

Question 7 Single choice

You are designing a new network for your organization with the characteristics shown below.

All traffic must pass inspection by a security device.

A center-positioned segmentation gateway must provide deep inspection of each packet using 10 Gbps interfaces.

Policy enforcement must be centrally managed.

Which security model should you choose for your network design?

  1. A

    Intrazone Permit

  2. B

    trust but verify

  3. C

    user-role firewall policies

  4. D

    Zero Trust

Show answer and explanation

Correct answer: D

Explanation

References:
https://www.juniper.net/assets/cn/zh/local/pdf/whitepapers/2000749-en.pdf

Question 8 Single choice

You are asked to provide a design proposal for a campus network. As part of the design, the customer requires that all end user devices must be authenticated before being granted access to their Layer 2 network.

Which feature meets this requirement?

  1. A

    IPsec

  2. B

    802.1X

  3. C

    NAT

  4. D

    ALGs

Show answer and explanation

Correct answer: B

Explanation

References:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/802-1x-
authentication-switching-devices.html

Question 9 Single choice

You want to deploy a VPN that will connect branch locations to the main office. You will eventually add additional branch locations to the topology, and you must avoid additional configuration on the hub when those sites are added.

In this scenario, which VPN solution would you recommend?

  1. A

    Site-to-Site VPN

  2. B

    Hub-and-Spoke VPN

  3. C

    AutoVPN

  4. D

    Group VPN

Show answer and explanation

Correct answer: C

Explanation

References:
https://www.juniper.net/assets/us/en/local/pdf/solutionbriefs/3510477-en.pdf

Question 10 Multiple choice

Which two steps should be included in your security design process? (Choose two.)

  1. A

    Identify external attackers

  2. B

    Define safety requirements for the customer's organization

  3. C

    Identify the firewall enforcement points

  4. D

    Define overall security policies

Show answer and explanation

Correct answers: C, D

Explanation

References:
https://www.juniper.net/assets/us/en/local/pdf/whitepapers/2000591-en.pdf