Juniper JN0-331 Exam Overview:
| Certification Vendor: | Juniper Networks |
| Exam Name: | SEC, Specialist (JNCIS-SEC) |
| Exam Number: | JN0-331 |
| Certificate Validity Period: | 3 years |
| Exam Format: | Multiple-choice |
| Real Exam Qty: | 65-75 |
| Exam Duration: | 90 minutes |
| Available Languages: | English |
| Related Certifications: | Juniper Networks Certified Internet Specialist - Security (JNCIS-SEC) |
| Exam Price: | USD 200 |
| Sample Questions: | Juniper JN0-331 Sample Questions |
| Exam Way: | Pearson VUE testing center or online proctored exam |
| Pre Condition: | Typically requires JNCIA-Junos or equivalent foundational Junos knowledge. |
| Official Syllabus URL: | https://www.juniper.net/us/en/training/certification.html |
Juniper JN0-331 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| High Availability and Troubleshooting | - Chassis cluster
|
| Security Fundamentals | - Junos security architecture
|
| Virtual Private Networks | - IPsec VPN
|
| Application Security Features | - User and application awareness
|
| Network Address Translation | - Source NAT
|
| Zones and Security Policies | - Security policies
|
Juniper SEC,Specialist(JNCIS-SEC) Sample Questions:
1. Click the Exhibit button.
Referring to the exhibit, you are not able to telnet to 192.168.10.1 from client PC 192.168.10.10.
What is causing the problem?
A) Telnet is not being permitted by self policy.
B) Telnet is not allowed because it is not considered secure.
C) Telnet is not enabled as a host-inbound service on the zone.
D) Telnet is not being permitted by security policy.
2. Which attribute is required for all IKE phase 2 negotiations?
A) main or aggressive mode
B) preshared key
C) Diffie-Hellman group key
D) proxy-ID
3. Regarding an IPsec security association (SA), which two statements are true? (Choose two.)
A) IKE SA is established during phase 2 negotiations.
B) IPsec SA is bidirectional.
C) IPsec SA is established during phase 2 negotiations.
D) IKE SA is bidirectional.
4. Click the Exhibit button.
[edit security zones security-zone trust]
user@host# show
host-inbound-traffic {
system-services {
all;
}}
interfaces {
ge-0/0/0.0;
}
Referring to the exhibit, which two traffic types are permitted when the destination is the ge-
0/0/0.0 IP address? (Choose two.)
A) Telnet
B) OSPF
C) RIP
D) ICMP
5. Which two statements are true regarding IDP? (Choose two.)
A) IDP inspects traffic up to the Application layer.
B) IDP cannot be used in conjunction with other JUNOS Software security features such as SCREEN options, zones, and security policy.
C) IDP inspects traffic up to the Presentation layer.
D) IDP can be used in conjunction with other JUNOS Software security features such as SCREEN options, zones, and security policy.
Solutions:
| Question # 1 Answer: C | Question # 2 Answer: D | Question # 3 Answer: A,D | Question # 4 Answer: A,D | Question # 5 Answer: A,D |

We're so confident of our products that we provide no hassle product exchange.


By Prudence


