JN0-106 Junos OS Fundamentals Practice Question
A company wants to implement best practice for password recovery on Juniper devices to avoid service disruption. Which of the following is the recommended method?
⚠ Common exam trap
Candidates often confuse Juniper's single-user mode recovery with Cisco's password recovery process, which often involves a configuration register change and may require a factory reset; Juniper's method is designed to preserve the configuration, while Cisco's recovery can sometimes erase the startup configuration if not done carefully.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Boot the device into single-user mode from the console and reset the root password
Booting the device into single-user mode from the console is the standard, secure method for password recovery on Juniper devices. This process allows an administrator with physical console access to reset the root password without affecting the running configuration or causing service disruption, as the device boots with a minimal kernel and does not load the full configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform a factory reset to default configuration
Why it's wrong here
A factory reset erases the entire configuration, including interfaces, routing and security policies, causing exactly the service disruption the company wants to avoid. It is tempting as a guaranteed way back in when credentials are lost, and it would be acceptable only on a lab device with no production configuration to preserve.
- ✓
Boot the device into single-user mode from the console and reset the root password
Why this is correct
Booting into single-user mode from the console grants root shell access without loading the full configuration, allowing the root password to be reset without wiping the device. This preserves existing configuration and avoids the service disruption that a factory reset would cause.
- ✗
Use SNMP to modify the password field in the configuration
Why it's wrong here
SNMP sets OIDs in a running MIB; it cannot rewrite the encrypted password hash stored in the Juniper configuration, and no MIB object exposes that field. It is tempting because SNMP is used for device monitoring and configuration polling, but password recovery requires console access and a configuration edit, not an SNMP write.
- ✗
Contact JTAC to remotely reset the password
Why it's wrong here
Contacting JTAC introduces a support-ticket delay, so recovery depends on Juniper's response time rather than local action — service disruption persists meanwhile. It is tempting because JTAC can perform privileged recovery when root credentials are genuinely lost and no other administrative access exists, but routine best practice requires a documented, self-service recovery path configured beforehand.
Go deeper
Related to this question
About these practice questions
Courseiva writes every JN0-106 question from scratch — 326 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This JN0-106 practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JN0-106 exam.