Juniper JN0-1331 - Security Design, Specialist (JNCDS-SEC) Exam
Page: 2 / 13
Total 65 questions
Question #6 (Topic: Topic 1)
You are creating a security design proposal for an enterprise customer. As part of the design, you are implementing 802.1x authentication on your EX Series
devices.
In this scenario, which two statements are correct? (Choose two.)
devices.
In this scenario, which two statements are correct? (Choose two.)
A. The supplicant is the device that prevents the authenticatorג€™s access until it is authenticated
B. The supplicant is the device that is being authenticated
C. The authenticator is the device that is being authenticated
D. The authenticator is the device that prevents the supplicantג€™s access until it is authenticated
Answer: BD
Question #7 (Topic: Topic 1)
You are asked to install a mechanism to protect an ISP network from denial-of-service attacks from a small number of sources.
Which mechanism will satisfy this requirement?
Which mechanism will satisfy this requirement?
A. RTBH
B. UTM
C. Sky ATP
D. GeoIP
Answer: A
Question #8 (Topic: Topic 1)
You are responding to an RFP for securing a large enterprise. The RFP requires an onsite security solution which can use logs from third-party sources to prevent
threats. The solution should also have the capability to detect and stop zero-day attacks.
Which Juniper Networks solution satisfies this requirement?
threats. The solution should also have the capability to detect and stop zero-day attacks.
Which Juniper Networks solution satisfies this requirement?
A. IDP
B. Sky ATP
C. JSA
D. JATP
Answer: D
Question #9 (Topic: Topic 1)
You are designing an SDSN security solution for a new campus network. The network will consist of Juniper Networks Policy Enforcer, Juniper Networks switches,
third-party switches, and SRX Series devices. The switches and the SRX Series devices will be used as security enforcement points.
Which component supports the SRX Series devices in this scenario?
third-party switches, and SRX Series devices. The switches and the SRX Series devices will be used as security enforcement points.
Which component supports the SRX Series devices in this scenario?
A. Security Director
B. RADIUS server
C. certificate server
D. DHCP server
Answer: A
Question #10 (Topic: Topic 1)
Your company has outgrown its existing secure enterprise WAN that is configured to use OSPF, AutoVPN, and IKE version 1. You are asked if it is possible to
make a design change to improve the WAN performance without purchasing new hardware.
Which two design changes satisfy these requirements? (Choose two.)
make a design change to improve the WAN performance without purchasing new hardware.
Which two design changes satisfy these requirements? (Choose two.)
A. Modify the IPsec proposal from AES-128 to AES-256
B. Change the IGP from OSPF to IS-IS
C. Migrate to IKE version 2
D. Implement Auto Discovery VPN
Answer: BD