Black Friday Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Juniper JN0-1332 Security Design Specialist (JNCDS-SEC) Exam Practice Test

Demo: 9 questions
Total 65 questions

Security Design Specialist (JNCDS-SEC) Questions and Answers

Question 1

When designing the security for a service provider core router, you are asked to add a firewall fitter on the to0 interface in this scenario, which two protocols would you want to allow through the filter? (Choose two.)

Options:

A.

LLDP

B.

SSH

C.

BGP

D.

STP

Question 2

You are designing a security solution that includes SRX Series firewalls in a chassis cluster.

In this scenario. which two dements must be part of the design? (Choose two.)

Options:

A.

The physical interface on each SRX Series device making up the reth interface must be in the same L2 domain

B.

The physical interface on each SRX Series device making up the reth interface must be in separate L2 domains

C.

The duster ID must be the same on both SRX Series devices

D.

The node 10 must be the same on both SRX Series devices

Question 3

Refer to the Exhibit.

You are asked to provide a proposal for security elements in the service provider network shown in the exhibit. You must provide DOoS protection for Customer A from potential upstream attackers.

Which statements correct in this scenario?

Options:

A.

You should implement DDoS protection to drop offending traffic on the edge devices closest to the destination of the attack.

B.

You should implement DDoS protection to drop offending traffic on the edge devices closest to the source of the attack.

C.

You should implement DDoS protection to drop offending traffic on the core devices.

D.

You should implement DDoS protection to drop offending traffic on the customer edge device.

Question 4

Which solution would you deploy to accomplish this task?

Options:

A.

Junes Space Log Director

B.

Juniper Networks Central insights

C.

Junos Space Security Director

D.

Juniper Networks Secure Analytics

Question 5

Which two statements are true about WAN security considerations? (Choose two.)

Options:

A.

MACsec increases protection on alt WAN types

B.

Provider VPN circuit require iPsec

C.

internal connections are susceptible to fragmentation

D.

IPsec increases protection on all WAN types

Question 6

You want to reduce the possibility of your data center's server becoming an unwilling participant in a DDoS attack When tvA3 features should you use on your SRX Series devices to satisfy this requirement? (Choose two.)

Options:

A.

dynamic IPsec tunnels

B.

Juniper ATP Cloud GeolP

C.

UTMWebtaering

D.

Juniper ATP Cloud CC feeds

Question 7

A new virus is sheading across the Internet, with the potential to affect your customer's network

Which two statements describe how Policy Enforcer interacts with other devices to ensure that the network is protected in this scenario? (Choose two.)

Options:

A.

Policy Enforcer pulls security intelligence feeds from Juniper ATP Cloud to apply to SRX Series devices

B.

Policy Enforcer pulls security policies from Juniper ATP cloud and apples them to SRX Series devices

C.

Policy Enforcer automates the enrollment of SRX Series devices with Jumper ATP Cloud

D.

Security Director pulls security intelligence feeds from Juniper ATP Cloud and applies them to Policy Enforcer

Question 8

Which two steps should be included in your security design process? (Choose two )

Options:

A.

Define an overall routing strategy

B.

identity external attackers

C.

Identify permitted communications

D.

Identify security requirements for the customer's organization

Question 9

Which feature is evaluated first when a packet is received on an interface of an SRX Series device?

Options:

A.

UTM

B.

ALG

C.

stateless firewall filter

D.

screens

Demo: 9 questions
Total 65 questions