Skip to main content

JN0-1332 Real Exam Questions

Security Design, Specialist (JNCDS-SEC)

65 questions available · Page 1 of 7

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

You are designing an enterprise WAN network that must connect multiple sites. You must provide a design proposal for the security elements needed to encrypt traffic between the remote sites.

Which feature will secure the traffic?

  1. A

    BFD

  2. B

    OSPF

  3. C

    GRE

  4. D

    IPsec

Show answer and explanation

Correct answer: D

Question 2 Single choice

You are implementing Routing Engine protection, and packets are processed in a specific order.

In this scenario, which function processed a received packet last?

  1. A

    loopback interface input policer

  2. B

    loopback interface input firewall filter

  3. C

    physical interface input firewall filters

  4. D

    physical interface input policer

Show answer and explanation

Correct answer: D

Explanation

References:
https://www.juniper.net/documentation/partners/ibm/junos11.4-oemlitedocs/config-guide-firewall-policer.pdf

Question 3 Single choice

You are asked to design a VPN solution between 25 branches of a company. The company wants to have the sites talk directly to each other in the event of a hub device failure. The solution should follow industry standards.

Which solution would you choose in this scenario?

  1. A

    AutoVPN

  2. B

    Auto Discovery VPN

  3. C

    Group VPN

  4. D

    full mesh VPN

Show answer and explanation

Correct answer: B

Explanation

References:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-auto-discovery-vpns.html

Question 4 Single choice

You must design a small branch office firewall solution that provides application usage statistics.

In this scenario, which feature would accomplish this task?

  1. A

    AppFW

  2. B

    AppTrack

  3. C

    UTM

  4. D

    AppQoS

Show answer and explanation

Correct answer: B

Explanation

References:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-application-tracking.html

Question 5 Single choice

A hosting company is migrating to cloud-based solutions. Their customers share a physical firewall cluster, subdivided into individual logical firewalls for each customer. Projection data shows that the cloud service will soon deplete all the resources within the physical firewall. As a consultant, you must propose a

scalable solution that continues to protect all the cloud customers while still securing the existing physical network.

In this scenario, which solution would you propose?

  1. A

    Deploy a vSRX cluster in front of each customer's servers while keeping the physical firewall cluster

  2. B

    Deploy a software-defined networking solution

  3. C

    Remove the physical firewall cluster and deploy vSRX clusters dedicated to each customer's servers

  4. D

    Replace the physical firewall cluster with a higher-performance firewall

Show answer and explanation

Correct answer: C

Question 6 Multiple choice

You are designing a solution to protect a service provider network against volumetric denial-of-service

attacks. Your main concern is to protect the network devices.

Which two solutions accomplish this task? (Choose two.)

  1. A

    next-generation firewall

  2. B

    screens

  3. C

    intrusion prevention system

  4. D

    BGP FlowSpec

Show answer and explanation

Correct answers: C, D

Explanation

References:
https://www.juniper.net/documentation/en_US/day-one-books/DO_BGP_FLowspec.pdf

Question 7 Multiple choice

Which two features are used to stop IP spoofing in and out of your network? (Choose two.)

  1. A

    GeoIP

  2. B

    firewall filters

  3. C

    unicast reverse path forwarding

  4. D

    IPS

Show answer and explanation

Correct answers: C, D

Explanation

References:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-attacker-evasion-technique.html

Question 8 Multiple choice

You are creating a security design proposal for an enterprise customer. As part of the design, you are implementing 802.1x authentication on your EX Series devices.

In this scenario, which two statements are correct? (Choose two.)

  1. A

    The supplicant is the device that prevents the authenticator's access until it is authenticated

  2. B

    The supplicant is the device that is being authenticated

  3. C

    The authenticator is the device that is being authenticated

  4. D

    The authenticator is the device that prevents the supplicant's access until it is authenticated

Show answer and explanation

Correct answers: B, D

Explanation

References:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/802-1x-authentication-switching-devices.html

Question 9 Single choice

You want to deploy a VPN that will connect branch locations to the main office. You will eventually add additional branch locations to the topology, and you must avoid additional configuration on the hub when those sites are added.

In this scenario, which VPN solution would you recommend?

  1. A

    Site-to-Site VPN

  2. B

    Hub-and-Spoke VPN

  3. C

    AutoVPN

  4. D

    Group VPN

Show answer and explanation

Correct answer: C

Explanation

References:
https://www.juniper.net/assets/us/en/local/pdf/solutionbriefs/3510477-en.pdf

Question 10 Multiple choice

What are two reasons for using cSRX over vSRX? (Choose two.)

  1. A

    cSRX loads faster

  2. B

    cSRX uses less memory

  3. C

    cSRX supports the BGP protocol

  4. D

    cSRX supports IPsec

Show answer and explanation

Correct answers: A, B

Explanation

References:
https://www.juniper.net/documentation/en_US/csrx/information-products/pathway-pages/
security-csrx-linux-bm-guide-pwp.pdf