JN0-106 Networking Fundamentals Practice Question
A network engineer is troubleshooting connectivity between two hosts on the same VLAN connected to different Juniper EX switches. The MAC address table on each switch shows the correct MAC addresses for both hosts, but ping fails. What is the most likely cause?
⚠ Common exam trap
The trap is that MAC address table correctness only confirms Layer 2 reachability, not Layer 3 IP reachability. Candidates may blame trunk VLAN filtering without realizing that MAC learning would not occur if the VLAN were not allowed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The hosts are configured with IP addresses in different subnets
Since both switches have correctly learned the MAC addresses of both hosts, Layer 2 forwarding across the trunk is working, meaning the VLAN is allowed. The ping failure therefore points to a Layer 3 issue: the hosts are configured with IP addresses in different subnets. They cannot communicate via IP without a router, even though they are on the same VLAN. The correct answer is B.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The VLAN is not allowed on the trunk between the switches
Why it's wrong here
When hosts are in the same VLAN but the trunk port connecting the switches does not have that VLAN in its allowed list, the switches will not forward frames for that VLAN across the trunk. Even though each switch learns MAC addresses from its own access ports, the frames sent between hosts never traverse the trunk because the VLAN is pruned or not permitted. This causes Layer 2 connectivity failure despite both MAC entries being present in the respective switches' forwarding tables.
- ✓
The hosts are configured with IP addresses in different subnets
Why this is correct
If the hosts are on the same VLAN but in different IP subnets, they cannot communicate directly at Layer 3. However, the scenario indicates that the switches have learned MAC addresses for both hosts on their access ports, which is a Layer 2 function and would still occur regardless of IP subnet. The ping failure would then be due to a missing default gateway or router, not because the MAC forwarding table lacks the necessary entries.
- ✗
The ARP cache on the hosts is stale
Why it's wrong here
A stale ARP cache would cause a host to send unicast frames to an incorrect MAC address, so the frames would reach the wrong port. In that case, the switch would still have learned the correct MAC addresses for both hosts on their access ports, but the frames would not be delivered to the intended destination. The presence of both MAC entries in the switch table indicates that frames have been successfully sent and received at Layer 2, which would not happen if a stale ARP cache prevented proper frame delivery.
- ✗
Spanning Tree Protocol is blocking a port
Why it's wrong here
If STP were blocking a port on the trunk between the switches, that port would not forward frames, and the switches would not learn MAC addresses on that port. However, the troubleshooting output shows that both switches have MAC table entries for the hosts on their access ports, which means the access ports are forwarding normally. STP blocking would not explain why both MAC entries are present while connectivity fails; it would instead prevent MAC learning on the blocked port.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 326 original JN0-106 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This JN0-106 practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JN0-106 exam.