Courseiva

JN0-106 Junos Configuration Basics Practice Question

An administrator is troubleshooting a configuration issue where a route filter is unexpectedly dropping traffic. The filter uses an 'exact' match type. Which statement correctly describes the behavior of the 'exact' match type in a prefix list?

⚠ Common exam trap

Many exam-takers confuse 'exact' with 'orlonger' or 'longer' match types, especially when troubleshooting route filter behavior, leading them to select options that describe less restrictive matching.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The route must match the prefix and prefix length exactly.

The 'exact' match type in a Junos prefix list requires the route's prefix and prefix length to match the specified prefix and length identically. This is defined in the Junos routing policy framework, where 'exact' is used for precise route filtering, such as matching a specific network like 192.168.1.0/24 without allowing any subnets or supernets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The route mask must be equal to or greater than the specified prefix length.

    Why it's wrong here

    It describes an `orlonger` match behavior, not an `exact` match. In Junos, the `exact` keyword requires the route's prefix length to be identical to the configured prefix length — no longer, no shorter. Saying the mask must be "equal to or greater than" the prefix length would allow routes with supernet masks (e.g., 10.0.0.0/8 matching a filter for 10.0.0.0/16), which violates the strict equality enforced by `exact`. Junos route-filter lists use `exact`, `longer`, `orlonger`, and `through` to express different matching semantics, and only `exact` imposes bit-for-bit and length-for-length equality.

  • ✓

    The route must match the prefix and prefix length exactly.

    Why this is correct

    This is the correct definition of an `exact` match in Junos route-filter matching. When you specify `route-filter 192.168.0.0/16 exact`, the filter evaluates both the prefix (the network bits) and the prefix length (the subnet mask) against the route's destination. The route must have the same network address and the same prefix length — a route like 192.168.1.0/24 would fail because the prefix length differs, and 192.168.0.0/15 would fail because the network bits differ. This strict equality distinguishes `exact` from `longer` or `orlonger`, which are used to match more-specific routes.

  • ✗

    The prefix 0.0.0.0/0 is never matched by 'exact' filters.

    Why it's wrong here

    This option is false because the default route 0.0.0.0/0 can absolutely be matched by an `exact` filter if you explicitly configure it, e.g., `route-filter 0.0.0.0/0 exact`. Junos does not treat 0.0.0.0/0 as a special exception for `exact` matching; the same equality rules apply — the route's prefix length must be 0 and the address must be 0.0.0.0. The misconception likely arises because 0.0.0.0/0 is often used as a "catch-all" with `orlonger`, but that is a choice of filter semantics, not a limitation of `exact`.

  • ✗

    The route mask must be greater than the specified prefix length.

    Why it's wrong here

    Requiring the mask to be strictly greater than the specified prefix length defines a `longer` match, not an `exact` match. In Junos, the `longer` keyword is used to match only routes that are more specific than the specified prefix (e.g., `route-filter 10.0.0.0/8 longer` matches 10.1.0.0/16 or 10.1.2.0/24, but not 10.0.0.0/8 itself). The `exact` keyword does not allow any difference in mask length — it demands the mask be exactly the same as the configured prefix length. Confusing `exact` with `longer` or `orlonger` is a common source of route-filter misconfiguration, especially when an administrator intends to match only a single subnet.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This JN0-106 question is part of Courseiva's 326-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This JN0-106 practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JN0-106 exam.