Practice JNCIP-ENT Layer 2 Authentication And Access Control questions with full explanations on every answer.
Start practicing
Layer 2 Authentication And Access Control — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
What is the primary function of the RADIUS server attribute 'Tunnel-Medium-Type' (Attribute 65) when received during an 802.1X authentication exchange on an EX Series switch?
2Which command allows an administrator to verify the active supplicant states and authentication status on a specific EX Series switch interface?
3You are troubleshooting an 802.1X deployment on an EX4300 switch. Clients fail to authenticate when using Supplicant-based authentication combined with MAC RADIUS fallback. You notice that the switch does not attempt MAC RADIUS after 802.1X times out. Which configuration error most likely caused this?
4An enterprise network administrator needs to configure 802.1X authentication on EX Series switches. Which statement is correct regarding the default behavior of the supplicant timeout timer?
5You are implementing MAC RADIUS authentication on an EX4600 switch. You notice that when a device connects, the switch sends the MAC address in the Username attribute (RADIUS attribute 1) with hyphen separators (e.g., aa-bb-cc-dd-ee-ff). Your RADIUS server expects colons (aa:bb:cc:dd:ee:ff). Where must you configure this format change on Junos OS?
6You are configuring a captive portal on an EX Series switch. You want to ensure that specific management traffic and critical server subnets are accessible to clients *before* they authenticate through the captive portal. Which configuration feature accomplishes this?
7An EX Series switch is configured with multiple-supplicant mode on an access port connected to an IP phone with a PC daisy-chained behind it. The IP phone authenticates via 802.1X, but the PC uses MAC RADIUS. The phone authenticates successfully and moves to the voice VLAN. However, when the PC boots, it fails authentication because the switch rejects a second supplicant on the same logical port index. Which configuration parameter resolves this issue?
8You are configuring captive portal on an EX Series switch using J-Web and CLI. Users are redirected to the captive portal page, but after successful authentication, they still cannot access the external network. Inspecting the routing table and firewall filters, what is the most likely reason for this post-authentication restriction?
9An administrator configures 802.1X authentication with local server fallback on an EX Series switch. When the external RADIUS server is unreachable, the switch fails over to the local user database. However, users authenticated via the local database are placed in the default access VLAN instead of the VLAN specified in their local user profile. What is the cause of this behavior?
10Which statement accurately describes the function of the 'server-timeout' setting within a Juniper access profile?
11Which command is used to clear dynamic MAC RADIUS authentication states and force a re-authentication on interface ge-0/0/5?
12You are configuring captive portal on an EX Series switch. You want users to be redirected to an external web server hosted at https://portal.enterprise.com/login. Where do you specify this redirection URL in the Junos OS CLI?
13An EX Series switch is configured with 802.1X and MAC RADIUS. A client device connects that does not support 802.1X. The switch attempts 802.1X, times out, and successfully falls back to MAC RADIUS. However, the administrator notices a significant delay (several seconds) before the MAC RADIUS request is sent to the server. What parameter should be tuned to reduce this delay?
14You are configuring MAC RADIUS authentication on an EX Series switch and want to ensure that devices failing MAC RADIUS are assigned to a restricted quarantine VLAN. Where is the quarantine VLAN configured for failed MAC RADIUS attempts?
15An enterprise deploys 802.1X with dynamic VLAN assignment. When a user authenticates, the RADIUS server returns the correct VLAN name, but the switch places the port into a different VLAN. Upon checking the switch, you find that the VLAN name returned by RADIUS does not match any VLAN configured in the local 'vlans' configuration hierarchy. How does Junos OS handle this discrepancy?
16What is the default authentication order when authentication is enabled on an EX Series switch interface without explicit ordering configuration?
17You are configuring an EX Series switch to support MAC RADIUS authentication. You want to ensure that the switch sends accounting start and stop packets to the RADIUS server. Which configuration hierarchy is required to enable RADIUS accounting for access clients?
18An EX4300 switch is configured with captive portal authentication. Unauthenticated users are successfully redirected when attempting HTTP traffic, but HTTPS traffic fails to redirect properly and instead shows a certificate warning or connection timeout in the user's browser. What is the fundamental reason for this behavior with standard captive portal implementations?
19You are troubleshooting an issue where an 802.1X supplicant on a Windows client fails to connect to an EX Series switch port. The switch logs show 'EAPOL-TIMEOUT' errors. What does this error indicate?
20Which RADIUS attribute is commonly used to assign a specific session timeout value to an 802.1X authenticated client on an EX Series switch?
21You are configuring an EX Series switch for 802.1X authentication. You want to ensure that if a supplicant fails authentication, the port is moved into a specific guest VLAN. Where is the guest VLAN referenced within the dot1x interface configuration?
22An administrator implements MAC RADIUS authentication on an EX Series switch. Several legacy printers connected to the ports fail to authenticate because they send their MAC addresses in uppercase letters with no separators (AABBCCDDEEFF), while the RADIUS server expects lowercase with colons (aa:bb:cc:dd:ee:ff). How can you resolve this mismatch on the Junos switch?
23Which statement is true regarding the behavior of the supplicant mode 'single' on an EX Series switch port?
24An enterprise network uses 802.1X authentication with dynamic VLAN assignment on EX Series switches. A client authenticates, and the RADIUS server returns both a VLAN name and a set of dynamic firewall filter names via RADIUS attributes (Filter-Id). When the client connects, the VLAN assignment works perfectly, but the firewall filters are not applied to the interface. What is the most likely cause?
25Which Junos command displays the status of all captive portal sessions currently active on an EX Series switch?
26You are configuring an EX Series switch to use MAC RADIUS authentication. You notice that when devices connect, the switch sends authentication requests, but the accounting start packets are not being sent. What configuration is missing?
27Which TWO statements are correct regarding the behavior and configuration of multi-supplicant mode on EX Series switches? (Choose two)
28Which THREE attributes or conditions must be met for successful dynamic VLAN assignment via RADIUS during 802.1X authentication on Junos EX Series switches? (Choose three)
29Which TWO actions occur when an 802.1X supplicant fails authentication and a guest VLAN is configured on the EX Series switch port? (Choose two)
30Which TWO options are valid authentication methods that can be specified in the 'authentication-order' statement on an EX Series switch interface? (Choose two)
31Which THREE parameters must be configured when implementing captive portal on an EX Series switch? (Choose three)
32Which THREE diagnostic tools or show commands are useful when troubleshooting MAC RADIUS authentication failures on an EX Series switch? (Choose three)
33Which TWO statements are correct regarding captive portal redirection behavior on EX Series switches? (Choose two)
34Which TWO conditions must be satisfied for an EX Series switch to successfully process a RADIUS Change of Authorization (CoA) request? (Choose two)
35Which TWO options are valid configurable parameters under an access profile in Junos OS? (Choose two)
36Which THREE statements describe the behavior of critical authentication (fallback) when a RADIUS server becomes unreachable on an EX Series switch? (Choose three)
The Layer 2 Authentication And Access Control domain covers the key concepts tested in this area of the JNCIP-ENT exam blueprint published by Juniper Networks. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all JNCIP-ENT domains — no account required.
The Courseiva JNCIP-ENT question bank contains 36 questions in the Layer 2 Authentication And Access Control domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Layer 2 Authentication And Access Control domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included