City security reviewers fear ZTP means switches will pull unauthenticated configuration from anywhere on the Internet. Which description best reflects ZTP’s trust boundary in a Juniper DC design?
Select an answer to reveal the explanation.
Short Explanation
ZTP is not “download config from the open Internet”—it is more like a badge-gated warehouse on the city management LAN. Reviewers should focus on locking down DHCP and the file server the leaves are pointed to. Controlled provisioning paths beat fear of random Internet grabs.
Full Explanation
Operational ZTP designs provision from administratively controlled DHCP and file infrastructure reachable on the management network. Security posture comes from how those services are scoped, authenticated where applicable, and isolated—not from assuming open Internet config pulls. Data-plane VLANs and blanket outbound access are not the defining ZTP trust model. Reviewers should validate management-network controls rather than reject ZTP as inherently unscoped.