Security Design - Specialist (JNCDS-SEC) (JN0-1331) - Juniper Actual Exam Questions
Last updated on April 30, 2026
You are designing an SDSN security solution for a new campus network. The network will consist of Juniper Networks Policy Enforcer, Juniper Networks switches, third-party switches, and SRX Series devices. The switches and the SRX Series devices will be used as security enforcement points. Which component supports the SRX Series devices in this scenario?
Security Director
RADIUS server
certificate server
DHCP server
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
You are deploying a data center Clos architecture and require secure data transfers within the switching fabric. In this scenario, what will accomplish this task?
MACsec encryption
LAG Layer 2 hashing
IRB VLAN routing between hosts
stacked VLAN tagging on the core switches
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
You are concerned about malicious attachments being transferred to your e-mail server at work through encrypted channels. You want to block these malicious files using your SRX Series device. Which two features should you use in this scenario? (Choose two.)
Sky ATP SMTP scanning
Sky ATP HTTP scanning
SSL forward proxy
SSL reverse proxy
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
Which two protocols are supported natively by the Junos automation stack? (Choose two.)
NETCONF
PyEZ
Jenkins
CIP
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
You are designing a DDoS solution for an ISP using BGP FlowSpec. You want to ensure that BGP FlowSpec does not overwhelm the ISP’s edge routers. Which two requirements should be included in your design? (Choose two.)
Specify a maximum number BGP FlowSpec prefixes per neighbor
Implement a route policy to limit advertised routes to /24 subnets
Implement a route policy to limit advertised routes to any public IP space
Specify a maximum number of BGP FlowSpec prefixes per device
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
Finish Practice?
Are you sure you want to finish? This will end your practice session.