Practice JNCIS-ENT Layer 2 Security questions with full explanations on every answer.
Start practicing
Layer 2 Security — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An engineer configures storm control on an EX Series switch to protect against broadcast floods. The configuration uses a bandwidth-percentage rate limit of 20%. Which traffic types are targeted by default when storm control is applied to an interface?
2Which command allows an administrator to verify storm control statistics and drop counts on an EX Series switch interface?
3You are troubleshooting port security on an EX Series switch. An interface has been configured with 'action-on-violation shutdown', and a violation occurs. What is the default operational state of the interface after the violation, and how is it restored?
4You have enabled DHCP snooping on an EX Series switch. What must be configured on the interface connecting to the legitimate corporate DHCP server to prevent rogue DHCP server replies?
5An administrator configures MACsec with pre-shared keys (PSK) between two EX Series switches. After applying the configuration, the secure channel fails to establish. Which operational command should be used to troubleshoot the MKA session state and connectivity?
6Which feature is required to be enabled on an access switch to populate the DHCP snooping database binding table with legitimate client IP-to-MAC address mappings?
7You are configuring MACsec on a pair of Juniper EX4300 switches to secure data links between wiring closets. Which key agreement protocol is used by default in Junos MACsec to dynamically negotiate and manage encryption keys?
8Which Junos configuration command enables Dynamic ARP Inspection (DAI) for a specific VLAN named 'VLAN10'?
9An administrator configures IP Source Guard on an access switch port. When a client connects, its traffic is dropped even though it acquired an IP via DHCP. Reviewing logs shows no DHCP snooping binding. What is the root cause?
10You need to write a Layer 2 firewall filter to drop inbound frames with a specific source MAC address on an EX Series switch. Where must this filter be applied to take effect?
11An administrator enables Dynamic ARP Inspection (DAI) on a VLAN that uses DHCP snooping for IP binding verification. A static client on the same VLAN cannot communicate with the default gateway. What is the most likely cause of this issue?
12Which Junos command displays the active DHCP snooping binding database entries on an EX Series switch?
13You want to configure IP Source Guard on interface ge-0/0/5 to verify both IP and MAC addresses against the binding table. Which configuration statement is required?
14Which command is used to clear the Dynamic ARP Inspection violation counters on an EX Series switch?
15An administrator configures a Layer 2 firewall filter to match on EtherType 0x88cc (LLDP) and discard those frames on an access port. However, LLDP packets are still reaching adjacent connected devices. Why?
16An administrator implements port security on a switch stack. A user moves their IP phone (which has an integrated PC attached to it) to a port configured with a MAC limit of one. Only the IP phone works, and the PC is blocked. What feature should be configured to allow multiple authenticated MAC addresses behind a single port securely?
17You need to configure MACsec on an EX4300 switch interface. Which cipher suite is configured by default when MACsec is enabled without specifying an explicit cipher suite?
18Which statement is true regarding the behavior of storm control when the traffic rate exceeds the configured threshold?
19An administrator configures MACsec on a point-to-point link between two EX switches. Encrypted frames are received by the remote switch, but decryption fails, and packets are dropped. What is the most likely reason for this decryption failure?
20Which Junos configuration hierarchy is used to configure secure access port features such as DHCP snooping and Dynamic ARP Inspection?
21You have enabled DHCP snooping on an access switch. During troubleshooting, you notice that DHCP Request messages from clients are being dropped on untrusted switch ports. Why is this occurring?
22An administrator configures a Layer 2 firewall filter to drop all ARP packets with a specific invalid sender hardware address. The filter is applied to a VLAN interface. What special consideration must be taken when applying Layer 2 filters to VLANs in Junos?
23Which statement accurately describes port security MAC-limit behavior?
24Which operational command displays the status of MACsec connections and associated security association parameters on an EX Series switch?
25You configure port security on a switch interface and set the violation action to 'restrict'. What happens when a port security violation occurs under this setting?
26An administrator configures Dynamic ARP Inspection (DAI) on an access switch. To ensure legitimate ARP packets from the default gateway (which uses a statically configured IP address on a core router) are not dropped, what must be configured?
27An engineer deploys MACsec across an untrusted Metro Ethernet Layer 2 transport circuit. After enabling MACsec, packets larger than 1500 bytes fail to pass through the link. What is the most likely cause of this issue?
28Which traffic rate-limiting mechanism is primarily used by storm control to protect switch CPU and interfaces from broadcast and multicast storms?
29You are troubleshooting IP Source Guard on an EX Series switch. You want to see which interfaces have IP Source Guard enabled and their operational state. Which operational command should you use?
30You are configuring storm control on an EX Series switch and want to specify the rate limit in absolute bandwidth (kilobits per second) rather than a percentage. Which statement achieves this?
31Which TWO statements describe characteristics of port security in Junos OS? (Choose two)
32Which TWO features rely on the DHCP snooping binding database to function properly? (Choose two)
33An administrator implements Dynamic ARP Inspection (DAI) on an EX Series switch. Legitimate ARP replies from a static server are being dropped. Rather than making the entire port trusted, how can the administrator permit this specific static server's ARP traffic?
34When configuring Layer 2 firewall filters on an EX Series switch, which THREE statements are correct regarding filter structure and application? (Choose three)
35Which THREE parameters must match between two peer devices to successfully establish a MACsec secure session using pre-shared keys (PSK)? (Choose three)
36Which THREE actions can be configured as a response to a Dynamic ARP Inspection (DAI) violation on an EX Series switch? (Choose three)
37Which TWO commands are valid Junos operational commands used to verify secure access port features? (Choose two)
38Which TWO statements are true regarding IP Source Guard? (Choose two)
39Which TWO conditions must be met for Dynamic ARP Inspection (DAI) to successfully forward an ARP request or reply packet on an access port? (Choose two)
40Which THREE statements describe the behavior and requirements of DHCP snooping? (Choose three)
41An administrator implements MACsec to secure links between switches. Which THREE operational tasks or verifications are relevant when troubleshooting MACsec and MKA? (Choose three)
42Which TWO options are valid violation actions available for port security configurations in Junos OS? (Choose two)
43Which TWO parameters can be configured when setting up storm control on an EX Series switch interface? (Choose two)
44Which THREE features are considered part of the secure access port feature suite in Junos OS? (Choose three)
45An administrator configures a Layer 2 firewall filter to drop broadcast packets while permitting unicast traffic on an access VLAN. Which THREE configuration elements are required to implement this filter properly? (Choose three)
46Which TWO traffic conditions will trigger storm control drops on a configured switch interface? (Choose two)
47An administrator wants to deploy MACsec between two EX Series switches using MKA with pre-shared keys. Which THREE configuration steps must be performed on both switches? (Choose three)
48An administrator wants to prevent a malicious user from flooding an EX Series switch with a high volume of broadcast traffic from an untrusted end-user device. Which feature should be configured?
49You are troubleshooting a Dynamic ARP Inspection (DAI) deployment on an EX4300 switch. Clients on VLAN 20 are experiencing intermittent loss of connectivity. You run 'show arp inspection statistics' and notice dropped packets due to 'invalid-ip'. What is the most likely cause of these drops?
50You are configuring MACsec on a link between two EX Series switches to secure data in transit. Which operational command verifies that the MACsec secure channels are established and operational?
51An access port on an EX Series switch is configured with port security to allow a maximum of 2 MAC addresses. When a 3rd device is connected, the port immediately shuts down. Which action statement under 'ethernet-switching-options secure-access-port' achieves this behavior?
52When implementing Layer 2 firewall filters on an EX Series switch, which packet characteristic can be matched in a filter term?
53You need to apply a Layer 2 firewall filter named 'block-rogue-mac' to inbound traffic on all access ports of an EX2300 switch. Under which hierarchy level must the filter be bound?
54Which THREE components are required for Dynamic ARP Inspection (DAI) to function properly on an EX Series switch? (Choose three)
55Which THREE features are part of the secure access port feature set on Juniper EX Series switches? (Choose three)
The Layer 2 Security domain covers the key concepts tested in this area of the JNCIS-ENT exam blueprint published by Juniper Networks. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all JNCIS-ENT domains — no account required.
The Courseiva JNCIS-ENT question bank contains 55 questions in the Layer 2 Security domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Layer 2 Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included