Courseiva

CCNA Junos Configuration Basics Questions

58 questions · Junos Configuration Basics · All types, answers revealed

1
MCQeasy

A junior administrator wants to discard all uncommitted changes made in the current configuration session. Which command accomplishes this?

A.commit check
B.rollback 0
C.load factory-default
D.clear configuration
AnswerB

In Junos, `rollback 0` is the command used to discard all uncommitted configuration changes. It loads the active committed configuration (rollback index 0) into the candidate configuration, overwriting any edits made since the last commit. This is the correct way to revert uncommitted edits without affecting the committed configuration.

Why this answer

The `rollback 0` command reverts the candidate configuration to the active committed configuration, effectively discarding all uncommitted changes made during the current session. In Junos, configuration changes are stored in a candidate configuration until explicitly committed; `rollback 0` loads the last committed configuration (index 0) into the candidate, wiping out any uncommitted edits.

Exam trap

The trap here is that candidates familiar with Cisco IOS might expect a `clear configuration` command or think `commit check` discards changes, but Junos requires `rollback 0` to revert uncommitted edits without affecting the active configuration.

How to eliminate wrong answers

Option A is wrong because `commit check` only validates the syntax and semantics of the candidate configuration without committing it; it does not discard any changes. Option C is wrong because `load factory-default` overwrites the entire configuration with the factory-default settings, which is far more drastic than simply discarding uncommitted changes and would also remove committed configurations. Option D is wrong because `clear configuration` is not a valid Junos CLI command; the correct approach to discard uncommitted changes is `rollback 0`.

2
MCQmedium

An engineer needs to add a set of configuration parameters to a group that can be inherited by multiple interfaces. Which configuration element should be used?

A.prefix lists
B.set default
C.configuration groups with apply-groups
D.load merge
AnswerC

Configuration groups are the correct Junos mechanism for defining reusable configuration blocks. You define named groups under the 'groups' hierarchy, then reference them with 'apply-groups' at any hierarchy level where you want the group's parameters to be inherited. When the configuration is evaluated, Junos merges the group's settings into the active configuration, and changes to the group automatically propagate to all points that apply it. This is distinct from one-time load operations or routing-policy filters, and it also supports 'apply-groups-except' to exclude specific groups below a certain level for granular control.

Why this answer

Configuration groups with apply-groups allow you to define a set of configuration parameters in a named group and then apply that group to multiple interfaces (or other hierarchy levels) using the 'apply-groups' statement. This enables inheritance and reduces repetitive configuration, which is the exact requirement in the question.

Exam trap

The trap here is that candidates may confuse 'load merge' (a file operation) with a configuration inheritance mechanism, or think 'set default' is a valid command for setting default interface parameters, when in fact Junos uses 'apply-groups' for this purpose.

How to eliminate wrong answers

Option A is wrong because prefix lists are used for route filtering (e.g., in routing policy) and cannot be inherited by interfaces as configuration parameters. Option B is wrong because 'set default' is not a valid Junos configuration element; the correct term for setting default values is 'apply-default' or using default configuration groups, but 'set default' does not exist. Option D is wrong because 'load merge' is a command used to merge a configuration file into the active configuration, not a mechanism for defining reusable, inheritable configuration groups.

3
MCQeasy

An engineer wants to revert all uncommitted changes in the candidate configuration and start fresh from the currently active configuration. Which command should be used?

A.rollback 0
B.commit check
C.rollback 1
D.load override terminal
AnswerA

In Junos, `rollback 0` directly loads the most recently committed configuration into the candidate configuration, discarding any uncommitted edits or staged changes. This makes the candidate an exact mirror of the active, running configuration without modifying that active configuration until a subsequent commit. It is the standard, intended way to revert all uncommitted changes while preserving the currently effective operational state.

Why this answer

The `rollback 0` command reverts all uncommitted changes in the candidate configuration and restores it to match the currently active configuration (the one most recently committed). This is because Junos stores the last 50 committed configurations, with index 0 always representing the active configuration. Using `rollback 0` effectively discards any uncommitted edits and starts fresh from the last committed state.

Exam trap

The trap here is that candidates often confuse `rollback 0` with `rollback 1`, mistakenly thinking that `rollback 1` reverts uncommitted changes, when in fact `rollback 1` reverts to the configuration before the last commit, not the current active configuration.

How to eliminate wrong answers

Option B is wrong because `commit check` only validates the syntax and semantics of the candidate configuration without committing it; it does not revert any changes. Option C is wrong because `rollback 1` reverts to the configuration that was active before the most recent commit (the previous committed version), not to the currently active configuration. Option D is wrong because `load override terminal` replaces the entire candidate configuration with text entered via the terminal, but it does not automatically revert to the active configuration; it requires manual input and is not a simple undo of uncommitted changes.

4
MCQeasy

A Juniper device has multiple candidate configurations loaded. The administrator wants to discard all uncommitted changes and revert to the last committed configuration. Which command should be used?

A.rollback 0
B.delete configuration
C.clear configuration
D.load override terminal
AnswerA

The `rollback 0` command reverts the candidate configuration to the last committed configuration by loading revision 0 from the configuration history, which always represents the most recently committed state. This directly satisfies the requirement to discard all uncommitted changes without affecting previously committed configurations, as rollback numbers increment with each commit and 0 is the fixed reference for the last committed configuration.

Why this answer

The 'rollback 0' command reverts the candidate configuration to the last committed configuration, discarding all uncommitted changes. In Junos, the rollback command uses a numeric index where 0 always refers to the most recently committed configuration, effectively undoing any uncommitted edits.

Exam trap

The trap here is that candidates may confuse 'rollback 0' with 'rollback 1', thinking 0 means 'no rollback' or that a higher number is needed to revert changes, when in fact 0 discards uncommitted edits and 1 reverts the last commit.

How to eliminate wrong answers

Option B is wrong because 'delete configuration' is not a valid Junos command; the correct approach to remove configuration is using 'delete' within configuration mode for specific statements, not a global delete. Option C is wrong because 'clear configuration' is not a valid Junos command; 'clear' is used for operational tasks like clearing counters or logs, not for reverting configuration. Option D is wrong because 'load override terminal' is used to replace the entire candidate configuration with text pasted from the terminal, but it does not revert to the last committed configuration; it loads new configuration from scratch.

5
MCQeasy

An engineer has modified the configuration and wants to apply changes but also wants to verify that the changes are syntactically correct before committing. What command should the engineer use?

A.rollback
B.commit confirmed
C.commit check
D.commit
AnswerC

The 'commit check' command validates the syntax, semantics, and consistency of the candidate configuration against the Junos schema without activating it. It reports errors such as invalid statements, missing mandatory parameters, or referencing non-existent interfaces, but it never modifies the running configuration. Because the engineer wants to apply the modified configuration, commit check is the correct first step to ensure the changes are valid before performing an actual commit, but note that it does not itself apply the configuration—it only verifies it.

Why this answer

The `commit check` command validates the candidate configuration for syntax errors without activating it. This allows the engineer to verify that the changes are syntactically correct before committing, ensuring the configuration is valid and reducing the risk of committing a broken configuration.

Exam trap

The trap here is that candidates confuse `commit check` with `commit confirmed`, thinking both validate syntax, but `commit confirmed` actually commits the configuration and relies on a rollback timer, not a pre-commit syntax check.

How to eliminate wrong answers

Option A is wrong because `rollback` reverts the candidate configuration to a previously committed configuration, not to validate syntax. Option B is wrong because `commit confirmed` commits the configuration but automatically rolls back after a timeout if not confirmed, which does not verify syntax before committing. Option D is wrong because `commit` applies the candidate configuration immediately without any prior syntax validation, which could activate a faulty configuration.

6
MCQhard

A network administrator needs to temporarily disable a set of configuration statements for testing without deleting them. Which approach should be used?

A.use the 'deactivate' command to mark the statements inactive
B.delete the statements and later re-add from a backup
C.comment out the lines using #
D.set the configuration to a different group and remove apply-groups
AnswerA

The 'deactivate' command is the Junos-native method for temporarily disabling a statement or hierarchy from the active configuration. It prepends an 'inactive:' marker to the statement in the candidate configuration, so the configuration text remains fully intact and editable, but the statement is ignored during commit. This allows you to quickly re-enable the configuration with the 'activate' command without re-entering it, and it can be applied to any hierarchy level, from a single parameter to an entire protocol stanza.

Why this answer

The 'deactivate' command in Junos allows an administrator to temporarily disable a set of configuration statements without removing them from the configuration. When a statement is deactivated, it is prefixed with 'inactive:' in the configuration hierarchy, and the commit operation ignores it. This is ideal for testing changes, as the statements can be easily re-enabled using the 'activate' command.

Exam trap

The trap here is that candidates familiar with Cisco IOS may assume that commenting out lines with '!' or '#' is a valid method, but Junos uses a structured hierarchy and requires the 'deactivate' command for temporary disabling.

How to eliminate wrong answers

Option B is wrong because deleting configuration statements and later re-adding them from a backup is error-prone, time-consuming, and does not provide a simple toggle mechanism for testing. Option C is wrong because Junos does not support using '#' to comment out configuration lines; the '#' character is used for comments in shell scripts, not in the Junos configuration hierarchy. Option D is wrong because setting the configuration to a different group and removing apply-groups is a complex workaround that affects the entire group configuration and is not a direct method for temporarily disabling individual statements.

7
MCQhard

While in configuration mode, an administrator wants to see the difference between the candidate configuration and the active configuration. Which command accomplishes this?

A.show configuration
B.run show configuration
C.show | compare
D.show system commit
AnswerC

`show | compare` pipes the candidate configuration through Junos's comparison filter, displaying a diff against the active configuration. The pipe operator applies the comparison to the current candidate, satisfying the requirement to view pending changes before commit. Other `show` variants display committed state only, revealing no delta.

Why this answer

The 'show | compare' command, when executed in configuration mode, displays the differences between the candidate configuration and the active (committed) configuration. This pipe filter compares the current candidate configuration against the last committed configuration, highlighting additions, deletions, and changes, which is the exact requirement for seeing the difference.

Exam trap

The trap here is that candidates confuse 'show configuration' (which shows the full candidate config) with 'show | compare' (which shows only the differences), or they mistakenly think 'run show configuration' provides a diff, when it simply runs the same full-config display command from operational mode.

How to eliminate wrong answers

Option A is wrong because 'show configuration' in configuration mode displays the entire candidate configuration, not the difference between candidate and active configurations. Option B is wrong because 'run show configuration' executes the operational mode command 'show configuration' from within configuration mode, which also shows the full candidate configuration, not a comparison. Option D is wrong because 'show system commit' displays the commit history (list of past commits with timestamps and IDs), not a diff between candidate and active configurations.

8
MCQhard

A company runs a Juniper SRX firewall cluster consisting of two nodes (node0 primary, node1 secondary). The cluster has been stable. During maintenance, you modify the configuration on node0 and commit. After the commit, the cluster status shows node1 as 'ineligible'. You suspect a configuration mismatch. What should you do to synchronize the configuration without disrupting traffic?

A.On the primary node, execute 'commit synchronize'.
B.Reboot both nodes to force synchronization.
C.Manually copy the configuration file from primary to secondary.
D.On the secondary node, execute 'commit synchronize'.
AnswerA

On the primary node, execute 'commit synchronize' is the correct approach because in a Juniper chassis cluster, the primary node is the sole controller that can propagate configuration changes to its cluster peer. This command commits the local configuration and then replicates that same candidate configuration to the secondary node over the control link, followed by a commit on both nodes. Without specifying 'synchronize', a normal commit only updates the node on which it is executed, so this is the definitive way to ensure both nodes run identical configurations.

Why this answer

The 'commit synchronize' command on the primary node (node0) pushes the active configuration to the secondary node (node1) and commits it on both nodes, ensuring configuration consistency without requiring a reboot or traffic disruption. In a Juniper SRX cluster, the primary node is the authoritative source for configuration synchronization, and this command is the standard method to resolve a configuration mismatch that causes a node to become 'ineligible'.

Exam trap

The trap here is that candidates may think the secondary node can initiate synchronization (option D) or that a manual file copy (option C) is acceptable, but Juniper clusters require the primary to be the source of truth for configuration synchronization to maintain cluster integrity and avoid split-brain scenarios.

How to eliminate wrong answers

Option B is wrong because rebooting both nodes is an unnecessary and disruptive action that would cause traffic loss; it does not directly synchronize the configuration and may not resolve the mismatch if the secondary's configuration remains out of sync. Option C is wrong because manually copying the configuration file from primary to secondary is not a supported or safe method in a cluster; it bypasses Junos's internal synchronization mechanisms and could lead to file corruption or cluster instability. Option D is wrong because executing 'commit synchronize' on the secondary node (node1) is ineffective; the secondary node cannot push its configuration to the primary, and the command would fail or not achieve synchronization since the primary is the authoritative source for cluster configuration.

9
MCQhard

During troubleshooting, an engineer notices that BGP sessions are flapping. They suspect that the issue might be related to the maximum number of routes allowed. To see if the BGP import policy is rejecting routes, which operational command would provide immediate insight?

A.show version
B.show interfaces terse
C.show route protocol bgp
D.show bgp neighbor x.x.x.x
AnswerD

show bgp neighbor x.x.x.x is the primary troubleshooting command for BGP peering. It displays the session state (Idle, Connect, Active, OpenConfirm, Established), timers, TCP connection details, and per-neighbor capabilities. Crucially, it shows the counts of received and accepted prefixes, and a separate count of rejected prefixes, along with the policy names that caused that rejection. This allows an engineer to quickly determine whether the session is up but the exchange is failing, or whether the session itself is down.

Why this answer

The 'show bgp neighbor x.x.x.x' command displays detailed BGP session information, including the number of received and accepted routes, as well as any prefix-limit or policy-related rejections. If the BGP import policy is rejecting routes due to exceeding the maximum allowed, this command will show the 'received prefixes' count alongside the 'accepted prefixes' count, immediately revealing if routes are being dropped. This provides direct insight into whether the flapping is caused by route limit enforcement.

Exam trap

The trap here is that candidates often think 'show route protocol bgp' will show all BGP routes including rejected ones, but it only shows routes that passed the import policy and were installed in the routing table, missing the critical rejection information that 'show bgp neighbor' provides.

How to eliminate wrong answers

Option A is wrong because 'show version' displays only the Junos OS version, system uptime, and hardware model, which is irrelevant to BGP route acceptance or policy rejection. Option B is wrong because 'show interfaces terse' shows interface status and IP addresses but provides no BGP-specific information such as route counts or policy actions. Option C is wrong because 'show route protocol bgp' displays the routing table entries learned via BGP, but it does not show rejected routes or the reason for rejection; it only shows routes that have already been accepted and installed, so it cannot reveal if the import policy is discarding routes.

10
MCQmedium

Scenario: Your company has a Juniper SRX300 firewall used as a branch gateway. It runs Junos 15.1X49. The firewall has multiple security policies, NAT rules, and VPN tunnels. Recently, you added a new security policy to allow traffic from the internal network to a specific public server. After committing, you notice that the firewall is logging repeated denials for traffic that should be matched by the new policy. The policy appears correctly configured in the candidate configuration. You want to verify that the policy is actually active and check for any hidden rules that might be causing the issue. Which of the following is the most effective first step to troubleshoot this problem?

A.Roll back to the previous configuration to ensure the device is in a known state.
B.Run 'show configuration | display set | match policy' to verify the policy is present.
C.Run 'show security policies detail' and examine the policy order to see if a previous policy is denying the traffic.
D.Check the firewall logs with 'show log messages | match deny' to see which policy is denying.
AnswerC

The 'show security policies detail' command displays all active security policies in their actual evaluation order, including the specific match criteria, actions, and sequence numbers. By inspecting the order, you can quickly determine whether a preceding policy with a higher priority matches the same traffic and denies it before your new policy is ever reached, making it the most direct diagnostic for ordering problems.

Why this answer

The most common cause of traffic being denied despite a seemingly correct new policy is that a preceding policy in the security policy order matches the traffic and denies it before the new policy is evaluated. Junos security policies are evaluated in sequential order from top to bottom, and the first matching policy is applied. Running 'show security policies detail' displays the active configured policy order, allowing you to see if an earlier policy is intercepting the traffic.

Note: default policies are not shown with this command; use 'show security policies default' for that.

Exam trap

The trap here is that candidates assume a correctly configured policy will automatically be applied, but Junos requires careful attention to policy order, and the exam tests whether you know to verify the active policy sequence rather than just the configuration syntax.

How to eliminate wrong answers

Option A is wrong because rolling back to a previous configuration is a disruptive step that does not help diagnose why the new policy is not being matched; it only reverts to an older state without revealing the policy order issue. Option B is wrong because 'show configuration | display set | match policy' only shows the candidate configuration, not the active policy order; the policy may be present in the configuration but still be overridden by a higher-priority deny policy in the active commit. Option D is wrong because checking logs with 'show log messages | match deny' can show that traffic is being denied, but it does not reveal which policy is responsible or the policy order; it only confirms the symptom, not the root cause.

11
MCQhard

Scenario: Your company has a Juniper MX Series router at a branch office running Junos 18.4. The device has been in production for two years with a stable configuration. Yesterday, a senior engineer made several changes to the OSPF configuration to optimize routing for a new link. They committed the changes and left for the day. This morning, the branch office experiences intermittent connectivity, and the OSPF neighbor relationships are flapping. You suspect the recent OSPF changes caused the issue. You have remote console access to the router. The goal is to restore network stability as quickly as possible while preserving the ability to re-apply the changes after troubleshooting. Which course of action should you take?

A.Use 'deactivate protocols ospf' to disable OSPF entirely and then manually re-enable pieces.
B.Immediately delete the OSPF configuration sections that were changed and re-add the original settings manually.
C.Use 'rollback 1' to revert to the configuration before the changes, then 'commit confirmed 10' to verify stability.
D.Perform a 'load factory-default' and 'commit' to reset the device to base settings, then reconfigure from backup.
AnswerC

This is the correct approach because rollback 1 reverts the candidate configuration to the last committed configuration prior to the current one, which is exactly the stable state you want. Issuing commit confirmed 10 activates that configuration for 10 minutes; if nothing else is done, the system automatically rolls back to the previous config, ensuring connectivity is restored without a permanent lock-in. You can later issue commit (or commit confirmed again) to make the change permanent once you have verified OSPF stability.

Why this answer

'rollback 1' reverts the active configuration to the previous committed version (before the problematic OSPF changes), and 'commit confirmed 10' applies that rollback with a 10-minute confirmation timer. If connectivity stabilizes, the rollback becomes permanent; if not, the router automatically reverts to the previous configuration, ensuring no prolonged outage. This approach restores stability quickly while preserving the ability to later re-apply and test the OSPF changes in a controlled manner.

Exam trap

The trap here is that candidates may choose Option A (deactivate OSPF) thinking it is a quick fix, but they overlook that deactivating the entire protocol causes a complete routing disruption, whereas 'rollback' with 'commit confirmed' is the precise, safe, and reversible method Junos provides for this exact scenario.

How to eliminate wrong answers

Option A is wrong because 'deactivate protocols ospf' disables the entire OSPF process, which would drop all OSPF adjacencies and potentially cause a complete routing blackout, not just intermittent flapping, and it does not preserve the changed configuration for later re-application. Option B is wrong because manually deleting and re-adding configuration sections is error-prone, time-consuming, and does not leverage Junos's built-in rollback capability, which is the fastest and safest method to revert to a known-good state. Option D is wrong because 'load factory-default' resets the entire device to factory settings, wiping all configurations, including interfaces, security policies, and routing protocols, which would cause a total outage and require full reconfiguration from backup, far exceeding the goal of quickly restoring stability.

12
MCQmedium

When configuring a new Juniper router, an engineer needs to ensure that configuration changes are not automatically committed after a certain time if not explicitly confirmed. Which configuration parameter controls this?

A.commit check
B.commit at
C.commit synchronize
D.commit confirmed
AnswerD

The 'commit confirmed' command makes the candidate configuration active and then automatically rolls back to the previous configuration if the engineer does not issue a confirming commit within the default timeout interval (10 minutes, configurable). This is essential when configuring a new router remotely, because it ensures that a mistaken change that severs the management session will be undone automatically, letting the engineer regain access.

Why this answer

The 'commit confirmed' command is used to apply a configuration change that will automatically roll back to the previous configuration if not explicitly confirmed within a specified time period (default 10 minutes). This ensures that changes are not permanently applied unless the engineer verifies them, preventing accidental lockout or misconfiguration.

Exam trap

The trap here is that candidates often confuse 'commit confirmed' with 'commit at' or 'commit synchronize', thinking any time-based or dual-RE feature provides automatic rollback, but only 'commit confirmed' enforces a confirmation window to prevent permanent unverified changes.

How to eliminate wrong answers

Option A is wrong because 'commit check' only validates the syntax and semantics of the candidate configuration without committing it; it does not provide any automatic rollback mechanism. Option B is wrong because 'commit at' schedules a commit to occur at a specific future time, but once committed, the change is permanent and not automatically reverted. Option C is wrong because 'commit synchronize' is used on a dual Routing Engine system to commit the configuration on both REs simultaneously; it does not involve a confirmation timeout or automatic rollback.

13
MCQmedium

A technician needs to load a new configuration file that replaces only the specific hierarchy paths present in the file, leaving all other existing configuration unchanged. Which load statement is appropriate?

A.load replace
B.load set
C.load override
D.load merge
AnswerD

The 'load merge' command is the correct choice because it combines the contents of the configuration file with the current candidate configuration, adding or updating only the statements present in the file while leaving all other existing configuration untouched. It accepts both hierarchical configuration files and files containing 'set' commands, making it flexible for various file formats. This precisely matches the technician's need to load a new configuration file that applies changes without discarding existing settings.

Why this answer

The 'load merge' command is correct because it merges the contents of the specified configuration file with the current candidate configuration, adding or updating only the hierarchy paths present in the file while preserving all other existing configuration. This matches the requirement to replace only specific hierarchy paths without affecting the rest of the configuration.

Exam trap

The trap here is that candidates often confuse 'load merge' with 'load replace' or 'load override', mistakenly thinking 'replace' means partial replacement, when in fact 'replace' replaces the entire candidate configuration, while 'merge' is the correct command for targeted, non-destructive updates.

How to eliminate wrong answers

Option A is wrong because 'load replace' replaces the entire candidate configuration with the contents of the file, not just specific hierarchy paths. Option B is wrong because 'load set' is used to load a set of configuration commands (in 'set' format) and applies them sequentially, which can add or modify paths but does not inherently restrict changes to only the paths in the file—it can also delete or override if the set commands include 'delete' statements. Option C is wrong because 'load override' completely replaces the entire candidate configuration with the file, discarding all existing configuration.

14
Multi-Selectmedium

Which TWO statements are true about the 'commit' operation in Junos?

Select 2 answers
A.The commit command validates the configuration syntax before applying it.
B.The commit command automatically saves the configuration to a file on the hard disk.
C.After a commit, the candidate configuration is replaced with the active configuration.
D.A commit can include a comment for documentation purposes.
E.A successful commit overwrites the rollback configurations.
AnswersA, D

The commit command validates the configuration syntax before applying it. Junos runs a validation phase that checks for parser errors, unsupported statements, and semantic issues such as incorrect interface references. If validation fails, the commit is aborted and the active configuration remains unchanged. This is distinct from the optional 'commit check' command, which validates without actually applying the configuration.

Why this answer

Option A is correct because when you issue commit in Junos, the candidate configuration is first checked for syntax and semantic errors, and only a valid configuration is merged into the active configuration. Option D is correct because Junos supports commit comment "text", which stores a descriptive comment with the committed configuration for documentation and audit purposes. Option B is not correct because commit applies the candidate configuration to the active configuration; it does not by itself save a configuration file to disk, which is done with save or file-related commands.

Option C is not correct because after a commit the candidate configuration remains as the working copy and is not replaced by the active configuration. Option E is not correct because a successful commit does not overwrite the rollback configurations; Junos maintains up to 50 previous committed configurations for rollback.

Exam trap

The trap here is that candidates often confuse the 'commit' operation with saving to persistent storage (like Cisco's 'copy running-config startup-config'), but in Junos, 'commit' only activates the configuration in memory and does not automatically write to a file; persistent storage requires an explicit save command.

15
MCQeasy

A network engineer wants to quickly restore the device to a known good configuration after a failed change. What is the recommended approach?

A.Use the 'request system configuration rescue save' command.
B.Use the 'rollback 0' command.
C.Use the 'rollback rescue' command.
D.Use the 'load override terminal' command.
AnswerC

The 'rollback rescue' command loads the previously saved rescue configuration from the rescue area into the candidate configuration. This is the correct restore mechanism because it explicitly retrieves the snapshot created via 'request system configuration rescue save'. The command does not automatically commit the change; the engineer must still run 'commit' to apply the rescued configuration to the active Janos configuration.

Why this answer

The 'rollback rescue' command restores the device to the rescue configuration, which is a known good configuration saved explicitly for recovery after a failed change. The rescue configuration is stored as a separate file and is not affected by normal commit operations, making it the recommended approach for quick restoration.

Exam trap

The trap here is that candidates confuse 'rollback rescue' with 'rollback 0', mistakenly thinking the most recent committed configuration is always a safe fallback, but 'rollback 0' includes the failed change if it was committed, whereas 'rollback rescue' restores a deliberately saved known good state.

How to eliminate wrong answers

Option A is wrong because 'request system configuration rescue save' is used to save the current active configuration as the rescue configuration, not to restore it; it is a save action, not a restore action. Option B is wrong because 'rollback 0' reverts to the most recently committed configuration, which may include the failed change if it was committed; it does not guarantee a known good state. Option D is wrong because 'load override terminal' is used to load a configuration from terminal input, overwriting the candidate configuration; it is not a quick restore mechanism and requires manual entry or pasting of configuration data.

16
MCQmedium

An administrator wants to save the current configuration as a rescue configuration. Which command sequence is correct?

A.copy configuration rescue
B.request system configuration rescue save
C.save rescue-config
D.commit rescue
AnswerB

This is the correct operational mode command: it stores a snapshot of the current active (committed) configuration as the rescue configuration, which Junos saves to a dedicated location on the file system. The rescue configuration is not tied to the normal commit rollback list; it is a custom recovery point that can be restored later with 'rollback rescue' or 'load rescue'. Because it is a request, not a commit, it does not alter the running configuration—it simply preserves a known-good state for emergency recovery.

Why this answer

The correct command sequence to save the current configuration as a rescue configuration in Junos is 'request system configuration rescue save'. This command stores a copy of the active configuration as a rescue configuration, which can be loaded later using 'request system configuration rescue recover' if the device becomes unreachable or the configuration is corrupted. The rescue configuration is stored in a special file (rescue.conf.gz) and is not overwritten by normal commits.

Exam trap

The trap here is that candidates may confuse the rescue configuration with a normal configuration backup or commit operation, leading them to choose 'copy configuration rescue' or 'commit rescue' instead of the correct 'request system configuration rescue save' command.

How to eliminate wrong answers

Option A is wrong because 'copy configuration rescue' is not a valid Junos command; Junos uses the 'request system configuration rescue' hierarchy for rescue operations, not a 'copy' command. Option C is wrong because 'save rescue-config' is not a valid Junos command; the correct syntax uses 'request system configuration rescue save', and 'save' alone is used for saving configurations to files, not for rescue-specific operations. Option D is wrong because 'commit rescue' does not exist; the 'commit' command applies changes to the active configuration, but rescue configuration is managed separately via the 'request system configuration rescue' commands.

17
Multi-Selecthard

Which THREE statements about the 'commit' command are correct?

Select 3 answers
A.The 'commit check' command validates the syntax of the candidate configuration.
B.The 'commit synchronize' command is used on a dual-RE system to commit on both REs.
C.The 'commit full' command activates the configuration without performing any validation.
D.The 'commit' command can only be issued when no other users are in configuration mode.
E.The 'commit confirmed 5' command will roll back the configuration after 5 minutes if not confirmed.
AnswersA, B, E

'commit check' parses and validates the candidate configuration against the schema without loading it into the running configuration, reporting syntax or semantic errors. This satisfies the stem's requirement for a statement about commit command behaviour on Junos devices.

Why this answer

Option A is correct because 'commit check' parses and validates the candidate configuration's syntax and semantics without actually activating it, so errors are reported before a real commit. Option B is correct because on a dual-RE (redundant Routing Engine) system, 'commit synchronize' commits the candidate configuration on both Routing Engines, keeping the primary and backup REs in sync. Option E is correct because 'commit confirmed 5' activates the configuration but automatically rolls back to the previous configuration after 5 minutes unless the administrator confirms it with a subsequent 'commit'.

Option C is wrong because 'commit full' forces a full commit that re-evaluates the entire configuration and does perform validation, rather than skipping it. Option D is wrong because multiple users can be in configuration mode simultaneously; the 'commit' command is not restricted to a single user, though a commit lock may be used to prevent conflicting changes.

Exam trap

The trap here is that candidates often confuse 'commit full' with a validation-skipping command, when in fact it performs a more thorough validation, and they may incorrectly assume that multiple users cannot commit simultaneously in Junos, unlike some other network operating systems.

18
MCQmedium

An engineer needs to apply a configuration change to the Junos device that must survive a reboot. Which configuration mode command should be used to save the changes?

A.commit
B.commit confirmed
C.commit synchronize
D.commit check
AnswerA

The 'commit' command permanently activates the candidate configuration by copying it into the active configuration and applying it to the routing and forwarding planes. It also writes the configuration to non-volatile storage (e.g., flash), ensuring it survives a reboot or power cycle. This is the standard, definitive way to make configuration changes persistent in Junos.

Why this answer

The 'commit' command is the standard way to apply a candidate configuration to the active configuration in Junos. When you issue 'commit', the changes are saved to the /config/juniper.conf.gz file, which is loaded upon reboot, ensuring the configuration survives a restart.

Exam trap

The trap here is that candidates may confuse 'commit' with 'commit confirmed', thinking the latter is required for persistence, but 'commit confirmed' is specifically designed for safe rollback during maintenance windows, not for permanent saves.

How to eliminate wrong answers

Option B is wrong because 'commit confirmed' temporarily activates the configuration but automatically rolls back to the previous configuration if not confirmed within the default 10-minute timeout, so it does not guarantee survival across a reboot unless explicitly confirmed. Option C is wrong because 'commit synchronize' is used in a chassis cluster to commit the configuration on both nodes simultaneously; it is not a general-purpose command for saving changes on a standalone device. Option D is wrong because 'commit check' only validates the syntax and semantics of the candidate configuration without applying or saving it, so no changes survive a reboot.

19
MCQmedium

A network engineer needs to add an additional IP address to an interface that already has a primary IP configured. Which method should be used?

A.set interfaces ge-0/0/0 unit 0 family inet address 10.0.0.2/24
B.set interfaces ge-0/0/0 unit 0 family inet address 10.0.0.2/24 secondary
C.set interfaces ge-0/0/0 unit 0 family inet secondary address 10.0.0.2/24
D.set interfaces ge-0/0/0 unit 0 family inet address 10.0.0.2/24 primary
AnswerB

This is the correct Junos syntax for adding an additional IP address while keeping the existing primary address intact. The secondary keyword immediately follows the address prefix within the family inet address hierarchy, telling the configuration engine that this address is not the primary. You can configure multiple secondary addresses on the same interface unit, and all existing addresses remain unchanged after commit. This precisely matches the engineer's requirement.

Why this answer

In Junos, to add an additional IP address to an interface that already has a primary IP configured, you must append the 'secondary' keyword to the address configuration statement. This allows multiple IPv4 addresses on the same logical interface unit, with the first address assigned being the primary and subsequent addresses marked as secondary.

Exam trap

The trap here is that candidates familiar with Cisco IOS might use the 'secondary' keyword as a subcommand under the interface (e.g., 'ip address 10.0.0.2 255.255.255.0 secondary'), but in Junos, the correct syntax places 'secondary' after the address in the same configuration line, not as a separate hierarchy.

How to eliminate wrong answers

Option A is wrong because it attempts to configure a second IP address without the 'secondary' keyword, which would replace the existing primary address rather than add an additional one. Option C is wrong because the syntax 'set interfaces ... family inet secondary address' is invalid; the 'secondary' keyword is a property of the address, not a separate hierarchy level. Option D is wrong because the 'primary' keyword is used to designate a specific address as the primary when multiple addresses exist, not to add a new address; adding 'primary' to a new address would conflict with the existing primary.

20
MCQmedium

Refer to the exhibit. What will happen if the engineer commits this configuration?

A.The interface will have two primary IP addresses.
B.The configuration will fail because inet and inet6 cannot coexist.
C.The interface will support both IPv4 and IPv6 traffic.
D.Only the family inet will be applied.
AnswerC

Configuring both family inet and family inet6 on an interface makes it dual-stacked, meaning it can forward IPv4 packets using the inet stack and IPv6 packets using the inet6 stack simultaneously. Each family has its own address, routing table entries, and protocol behavior, and both are active after the configuration is committed. This allows the interface to carry both IPv4 and IPv6 traffic without the need for tunneling or translation.

Why this answer

The configuration shown includes both `family inet` and `family inet6` under the same interface. Junos allows multiple address families to coexist on a single interface, enabling the interface to process both IPv4 and IPv6 traffic simultaneously. This is a standard feature of Junos, not an error.

Exam trap

The trap here is that candidates may mistakenly think Junos requires separate interfaces for IPv4 and IPv6, or that configuring both families will cause a commit error, when in fact dual-stack is a standard and expected configuration in Junos.

How to eliminate wrong answers

Option A is wrong because Junos does not allow two primary IP addresses on the same interface; only one primary address per address family is permitted, and the configuration shows separate families, not two primaries in the same family. Option B is wrong because `inet` and `inet6` can absolutely coexist on a Junos interface; this is a fundamental capability of dual-stack networking, and Junos supports it natively. Option D is wrong because both `family inet` and `family inet6` are explicitly configured and will be applied; Junos does not ignore one family when both are present.

21
MCQhard

In a dual Routing Engine (RE) setup, an engineer commits a configuration change that should be applied to both REs synchronously. What is the correct command to ensure both REs receive the same configuration immediately?

A.commit confirmed
B.commit check synchronize
C.commit and-quit
D.commit synchronize
AnswerD

This commits the candidate configuration to both Routing Engines in a single atomic operation, ensuring both have identical active configurations. It is the standard command for applying changes in a dual-RE chassis, and it is essential for maintaining consistency and enabling clean failover. The commit is performed on the local RE and the other RE simultaneously.

Why this answer

The 'commit synchronize' command commits the configuration on the master Routing Engine and then automatically copies and commits the same configuration to the backup RE, ensuring both REs have identical active configurations immediately. This is the standard Junos method for synchronizing configurations in a dual-RE chassis.

Exam trap

The trap here is that candidates confuse 'commit synchronize' with 'commit check' or 'commit confirmed', not realizing that only 'commit synchronize' explicitly pushes the configuration to the backup RE in a dual-RE setup.

How to eliminate wrong answers

Option A is wrong because 'commit confirmed' is used to automatically roll back a commit after a specified timeout if not confirmed, not for synchronizing configurations between REs. Option B is wrong because 'commit check synchronize' is not a valid Junos command; 'commit check' validates syntax but does not apply changes, and the 'synchronize' option is only valid with 'commit'. Option C is wrong because 'commit and-quit' is used in configuration mode to commit and exit, but it does not synchronize the configuration to the backup RE.

22
Multi-Selectmedium

Which THREE statements about the commit operation are correct? (Choose three.)

Select 3 answers
A.The 'commit check' command validates the syntax of the candidate configuration without activating it.
B.After a successful commit, the candidate configuration becomes the active configuration.
C.A commit can be scheduled to revert automatically if not confirmed within a certain time.
D.The candidate configuration is stored in a file named 'juniper.conf' on the flash drive.
E.A commit operation automatically saves the rescue configuration.
AnswersA, B, C

The 'commit check' command performs a dry-run validation of the candidate configuration, parsing the configuration statements and verifying that their syntax is correct, but it does not activate the changes. It is useful for pre-commit validation in production environments because it leaves the running configuration untouched and reports any syntax errors before an actual commit is attempted.

Why this answer

Option A is correct because 'commit check' performs a syntax and semantic validation of the candidate configuration and reports errors without activating or applying it, leaving the active configuration unchanged. Option B is correct because a successful commit copies the candidate configuration into the active configuration (the running configuration that the device uses), making the candidate the active one. Option C is correct because a commit can be issued with a confirmation timeout (for example, 'commit confirmed 10'), which automatically reverts to the previous configuration unless the commit is confirmed within that period.

Option D is not correct because the active configuration is stored in 'juniper.conf' (with backups like juniper.conf.1.gz), while the candidate configuration is held in a separate candidate database, not in 'juniper.conf'. Option E is not correct because the rescue configuration is not saved automatically by a commit; it must be saved explicitly with 'request system configuration rescue save'.

Exam trap

The trap here is that candidates often confuse the candidate configuration with the active configuration file (juniper.conf) or assume that a commit automatically updates the rescue configuration, when in fact the rescue configuration is a manually saved snapshot used for disaster recovery.

23
MCQmedium

Refer to the exhibit. What is the effect of the pending changes?

A.The IP address 10.0.0.2 will be replaced by 10.0.0.1 after commit.
B.The comparison shows no changes.
C.The interface will have two IP addresses: 10.0.0.1 and 10.0.0.2.
D.The candidate configuration will be empty after commit.
AnswerA

The plus sign next to 10.0.0.1 and the minus sign next to 10.0.0.2 in the `show | compare` output indicate that 10.0.0.2 is scheduled for deletion while 10.0.0.1 is scheduled for addition. Because both lines refer to the same address family (inet) and the same interface, the resulting operation is a replacement, not an addition. After commit, the active configuration will therefore have only 10.0.0.1 on the interface, with no trace of 10.0.0.2.

Why this answer

The candidate configuration shows that the IP address 10.0.0.2 is being deleted and replaced with 10.0.0.1 on interface ge-0/0/0. In Junos, pending changes are staged in the candidate configuration and only take effect after a commit. The 'replace:' tag indicates that the existing address 10.0.0.2 will be removed and 10.0.0.1 will be added upon commit.

Exam trap

The trap here is that candidates may misinterpret the 'replace:' tag as an addition rather than a replacement, leading them to think both IP addresses will coexist, or they may assume no changes are shown because they overlook the 'replace:' indicator.

How to eliminate wrong answers

Option B is wrong because the comparison clearly shows a change: the 'replace:' tag indicates that 10.0.0.2 is being replaced by 10.0.0.1, so there is a pending modification. Option C is wrong because Junos does not allow two IP addresses in the same subnet on the same interface without additional configuration; the 'replace:' operation removes the old address before adding the new one, so both addresses will not coexist. Option D is wrong because the candidate configuration contains the new address 10.0.0.1, so it will not be empty after commit; only the old address is removed.

24
MCQmedium

When configuring OSPF on a Juniper router, an engineer applies the 'area 0.0.0.0 interface ge-0/0/1.0 passive' command. What is the effect of this configuration?

A.The interface will not be advertised in OSPF at all, and no OSPF traffic will be transmitted.
B.The interface will only accept incoming OSPF packets but will not send any.
C.The interface will not send OSPF hellos, but the connected network will still be advertised in OSPF.
D.The interface will actively send OSPF hellos and attempt to form adjacencies.
AnswerC

The passive setting on an OSPF interface in Junos disables hello transmission on that interface, preventing the formation of any OSPF adjacency with a directly connected peer. However, the interface's subnet is still advertised as a stub network in the router's OSPF link-state advertisements, allowing other routers to learn the route without requiring a neighbor on that link. This matches the correct behavior for a passive interface.

Why this answer

The 'passive' configuration on an OSPF interface in Junos prevents the interface from sending OSPF Hello packets, which stops the formation of neighbor adjacencies. However, the interface's connected network prefix is still advertised as a stub network in OSPF Type 1 LSAs, ensuring reachability to that subnet without dynamic neighbor relationships.

Exam trap

The trap here is that candidates often confuse 'passive' with 'disable' or assume it blocks all OSPF traffic, when in fact it only stops Hello transmission while still advertising the network.

How to eliminate wrong answers

Option A is wrong because the passive interface does not suppress the advertisement of the connected network; the prefix is still injected into OSPF. Option B is wrong because the passive interface does not accept incoming OSPF packets either; it simply does not send Hellos, but it will still process received OSPF packets if they arrive (though without Hellos, no adjacency forms). Option D is wrong because the passive command explicitly prevents the interface from sending OSPF Hellos, so it will not actively attempt to form adjacencies.

25
MCQeasy

A network engineer is configuring a new Juniper SRX Series firewall and wants to verify the configuration before committing it. The engineer wants to check the syntax and semantic validity of the candidate configuration without activating it. Which command should the engineer use?

A.commit check
B.show | compare
C.commit confirmed
D.commit
AnswerA

The commit check command validates the candidate configuration for syntax and semantic errors without committing it. It is the correct choice to verify the configuration before making it active. This command allows the engineer to catch mistakes early without affecting the running configuration.

Why this answer

The commit check command is specifically designed to validate the candidate configuration for errors without committing it. It performs the same validation as a commit but stops short of activating the changes. This allows the engineer to ensure the configuration is correct before applying it to the device.

Exam trap

The trap here is assuming that commit check also commits the configuration, when in fact it only validates and does not change the active configuration.

26
MCQeasy

A network engineer needs to make a change to a Junos device and ensure the change can be reverted if it causes issues. Which feature should be used?

A.configure exclusive
B.commit confirmed
C.commit check
D.rollback 0
AnswerB

The `commit confirmed` operation commits the candidate configuration and starts a rollback timer (default 10 minutes, up to 285 minutes with `commit confirmed <minutes>`). If the engineer does not issue a confirming `commit` or `commit confirm` before the timer expires, Junos automatically reverts to the previous active configuration. This provides a safety net for testing break-fix changes, making it the correct answer.

Why this answer

The `commit confirmed` command allows an engineer to commit a configuration change with a timer (default 10 minutes). If the change causes issues and the engineer does not confirm the commit within the timer, the device automatically reverts to the previous active configuration. This provides a safety net to revert changes without manual intervention.

Exam trap

The trap here is that candidates may confuse `commit confirmed` with `rollback 0`, thinking both revert changes, but `rollback 0` is a manual step that does not provide automatic, time-based reversion.

How to eliminate wrong answers

Option A is wrong because `configure exclusive` locks the candidate configuration to a single user, preventing others from making changes, but it does not provide any automatic rollback mechanism if the change causes issues. Option C is wrong because `commit check` validates the syntax and semantics of the candidate configuration without committing it; it does not revert a change after it has been applied. Option D is wrong because `rollback 0` reverts to the most recently committed configuration, but this is a manual action and does not provide an automatic, time-based revert if the change causes issues.

27
MCQeasy

An administrator makes changes to the candidate configuration and wants to automatically revert to the previous configuration if the changes cause a loss of connectivity. Which method should be used?

A.Use the 'commit check' command.
B.Use the 'commit synchronize' command.
C.Use the 'rollback' command.
D.Use the 'commit confirmed' command.
AnswerD

The 'commit confirmed' command activates the candidate configuration immediately and starts a default 10-minute confirmation timer, after which the system automatically reverts to the prior configuration if no confirmation is received. The administrator can extend or shorten this window with the optional minutes argument and must issue 'commit confirm' to make the change permanent. This automatic rollback preserves the device's reachability, making it the ideal command for the scenario described.

Why this answer

The 'commit confirmed' command is the correct method because it allows an administrator to commit a candidate configuration with a confirmation timeout (default 10 minutes). If connectivity is lost and the commit is not confirmed within the timeout, Junos automatically reverts to the previous configuration, ensuring the device remains reachable.

Exam trap

The trap here is that candidates confuse 'commit confirmed' with 'commit check' or 'rollback', not realizing that 'commit confirmed' is the only option that provides an automatic, time-based reversion mechanism specifically designed to prevent loss of connectivity.

How to eliminate wrong answers

Option A is wrong because 'commit check' only validates the syntax and semantics of the candidate configuration without committing it, so it cannot automatically revert changes. Option B is wrong because 'commit synchronize' is used on a Junos cluster to commit the configuration on both nodes simultaneously, not to provide automatic rollback on connectivity loss. Option C is wrong because 'rollback' is a manual command that reverts to a previously committed configuration, but it does not provide automatic reversion upon connectivity loss.

28
MCQhard

During a maintenance window, an engineer issues 'commit confirmed 5' but the change causes a connectivity loss. The engineer is unable to reconnect to the device before the timeout expires. What will happen?

A.The engineer must manually rollback using the rollback command.
B.The change remains committed until the next reboot.
C.The device reloads with factory defaults.
D.The device automatically reverts to the previous active configuration.
AnswerD

Commit confirmed automatically rolls back after the timeout if not confirmed.

Why this answer

The 'commit confirmed 5' command activates a candidate configuration and starts a 5-minute rollback timer. If the engineer does not issue a 'commit' or 'commit check' before the timer expires, Junos automatically reverts to the previously active configuration. This ensures the device returns to a known working state without manual intervention, preserving connectivity after the failed change.

Exam trap

The trap here is that candidates may think a 'commit confirmed' requires a manual rollback command (Option A) or that the change persists until a reboot (Option B), but Junos automatically reverts the configuration upon timeout, making it a safety mechanism for remote changes.

How to eliminate wrong answers

Option A is wrong because the automatic rollback occurs without requiring manual intervention; the engineer does not need to use the 'rollback' command after the timeout. Option B is wrong because a confirmed commit is explicitly designed to not remain committed; it automatically reverts if not confirmed, so the change does not persist until the next reboot. Option C is wrong because the device does not reload with factory defaults; it reverts only to the previous active configuration, not to a factory-reset state.

29
MCQmedium

An engineer needs to apply a configuration change that adds a new static route to the Junos device. The engineer wants to ensure the change takes effect immediately and is persistent across reboots. Which command should the engineer use?

A.load override
B.commit confirmed
C.rollback
D.commit
AnswerD

This is the correct command. In Junos, configuration changes are staged in the candidate configuration, and commit validates and activates those changes, making them part of the active configuration. Once committed, the configuration persists across reboots and becomes the new baseline for future rollback operations.

Why this answer

The 'commit' command is correct because it immediately activates the candidate configuration (including the new static route) and makes it the active configuration that survives a reboot. Junos uses a two-stage configuration model where changes are first made to the candidate configuration and then committed to become the active, persistent configuration.

Exam trap

The trap here is that candidates familiar with Cisco IOS might assume 'copy running-config startup-config' is needed for persistence, but in Junos, a single 'commit' both activates the change and saves it permanently, making additional save commands unnecessary.

How to eliminate wrong answers

Option A is wrong because 'load override' replaces the entire candidate configuration with a new file, but it does not activate the configuration; a subsequent 'commit' is still required. Option B is wrong because 'commit confirmed' is used to automatically roll back to a previous configuration if the commit is not confirmed within a specified time (default 10 minutes), which is not appropriate for a permanent static route addition. Option C is wrong because 'rollback' reverts the candidate configuration to a previously committed version, which would remove any pending changes rather than applying them.

30
MCQeasy

An administrator wants to view the differences between the current candidate configuration and the last committed configuration. Which command displays this?

A.show configuration
B.commit check
C.show | compare
D.rollback ?
AnswerC

The pipeline 'show | compare' is the Junos way to display the difference between the candidate configuration and the last committed configuration (also known as rollback slot 0). It generates a unified-diff style output, with '+' for lines that will be added, '-' for lines that will be removed, and '!' to indicate changed statements. This directly fulfills the administrator's request to view what is different. Optionally, 'show | compare rollback N' compares the candidate against a specific prior snapshot.

Why this answer

The 'show | compare' command displays the differences between the candidate and the active (committed) configuration.

31
Multi-Selecteasy

Which TWO statements about configuration archival in Junos are true?

Select 2 answers
A.Archival stores the candidate configuration.
B.The 'system archival' hierarchy enables automatic backup of configurations.
C.Archival only saves the rescue configuration.
D.Archival can use FTP or SCP to transfer files.
E.Archival automatically archives after every commit without any configuration.
AnswersB, D

This configuration block defines archival settings.

Why this answer

The 'system archival' hierarchy in Junos is specifically designed to enable automatic backup of configuration files. This feature allows administrators to configure periodic transfers of committed configurations to a remote server, ensuring configuration history is preserved without manual intervention.

Exam trap

The trap here is that candidates often confuse the candidate configuration with the committed configuration, assuming archival saves the uncommitted changes, when in fact it only archives the active committed configuration after a successful commit.

32
MCQmedium

A network engineer needs to restore the factory-default configuration on a Junos device. Which command sequence is correct?

A.set system host-name factory-default
B.request system zeroize
C.load factory-default and then commit
D.delete configuration and reboot
AnswerC

`load factory-default` loads the vendor-provided factory-default configuration file into the candidate configuration, replacing all existing candidate settings. The subsequent `commit` promotes that candidate to the active (committed) configuration, thereby returning the device to its out-of-box state without erasing logs or other non-configuration files. This is the standard, supported procedure for restoring factory defaults on a Junos device.

Why this answer

The correct command sequence to restore factory-default configuration on a Junos device is 'load factory-default' followed by 'commit'. The 'load factory-default' command replaces the current candidate configuration with the factory-default configuration, but it does not take effect until a 'commit' is issued. This ensures the device reverts to its original settings without affecting the currently running configuration until explicitly committed.

Exam trap

The trap here is that candidates confuse 'load factory-default' with 'request system zeroize', thinking both achieve the same result, but 'zeroize' is a security wipe that destroys all data and requires a reboot, while 'load factory-default' is a configuration-only reset that is committed without rebooting.

How to eliminate wrong answers

Option A is wrong because 'set system host-name factory-default' only changes the hostname to 'factory-default', it does not restore the entire configuration to factory defaults. Option B is wrong because 'request system zeroize' is used to erase all data, including configuration files, logs, and user data, for security purposes before decommissioning a device; it does not simply restore factory-default configuration and requires a reboot to complete. Option D is wrong because 'delete configuration and reboot' is not a valid Junos command sequence; deleting the configuration without using 'load factory-default' would leave the device with an empty configuration, potentially causing boot issues or requiring manual recovery.

33
MCQmedium

A junior engineer is tasked with configuring a firewall filter to only allow SSH access to the management interface. The management interface is fxp0. Which configuration is correct?

A.set interfaces lo0 unit 0 family inet filter input allow-ssh
B.set groups management-filter interfaces fxp0 unit 0 family inet filter input allow-ssh
C.set interfaces ge-0/0/0 unit 0 family inet filter input allow-ssh
D.set interfaces fxp0 unit 0 family inet filter input allow-ssh
AnswerD

This command correctly applies the firewall filter 'allow-ssh' to the management interface fxp0 under the inet family. fxp0 is the dedicated out-of-band management port on many Junos platforms, and because 'unit 0' is the logical unit for that interface, the input filter will inspect all IPv4 traffic arriving on it. With this configuration, SSH traffic is filtered according to the 'allow-ssh' term, providing a targeted control-plane protection mechanism separate from data-plane interfaces.

Why this answer

The management interface on Juniper devices is fxp0, and applying a firewall filter to its inet family input direction restricts inbound traffic. The filter 'allow-ssh' must permit only TCP port 22, blocking all other management access. This configuration ensures SSH-only access to the management interface.

Exam trap

The trap here is confusing the management interface (fxp0) with the loopback interface (lo0) or a data-plane interface (ge-0/0/0), leading candidates to apply the filter to the wrong interface.

How to eliminate wrong answers

Option A is wrong because lo0 is the loopback interface, not the management interface; applying a filter there would affect all traffic destined to the device, not just management traffic. Option B is wrong because 'groups management-filter' is a configuration group syntax, not a direct interface filter application; it requires additional apply-groups statements and does not directly attach the filter to fxp0. Option C is wrong because ge-0/0/0 is a standard network interface, not the dedicated management interface (fxp0), so it would not restrict access to the management interface.

34
Multi-Selecthard

Which TWO statements about configuration groups in Junos are correct? (Choose two.)

Select 2 answers
A.Configuration groups are defined under the [edit groups] hierarchy.
B.Configuration groups are stored in separate files that are imported using the 'file' statement.
C.The 'apply-groups' statement is used to include a group's configuration at a specific hierarchy level.
D.The 'replace' tag is used to reference a configuration group.
E.Configuration groups are applied only at the [edit interfaces] hierarchy level.
AnswersA, C

Junos stores reusable configuration groups beneath the [edit groups] hierarchy, where each group is named and contains a partial configuration. Groups remain inactive until referenced elsewhere, so defining them there alone changes no device behaviour.

Why this answer

Option A is correct because configuration groups in Junos are created and stored under the [edit groups] hierarchy, where each group is defined by a name and contains configuration statements that can be inherited elsewhere. Option C is correct because the apply-groups statement is the mechanism used to insert a group's configuration at a specific point in the configuration hierarchy, causing the group's statements to be inherited at that level. Option B is incorrect because configuration groups are not stored in separate files imported with the file statement; the file statement is used for loading configuration snippets from files, not for defining groups.

Option D is incorrect because the replace tag is used to override inherited configuration values, not to reference a configuration group. Option E is incorrect because configuration groups can be applied at many hierarchy levels, not only at [edit interfaces].

Exam trap

The trap here is that candidates often confuse configuration groups with Junos's 'apply-path' or 'apply-macro' features, or mistakenly think groups are external files, when in fact they are defined inline under [edit groups] and applied via 'apply-groups'.

35
MCQmedium

An administrator needs to change a portion of the configuration by matching a pattern and replacing it with new text. Which Junos configuration mode command should be used?

A.rename
B.replace pattern
C.copy
D.set replace pattern
AnswerB

The replace pattern command in Junos configuration mode uses a Perl-like regular expression to search for a pattern and replace it with specified text in a configuration statement or hierarchy. It is the appropriate way to alter a portion of the configuration that may recur, such as changing an IP address or hostname across multiple sections. The syntax is `replace pattern <pattern> with <replacement>` (with optional before/after context).

Why this answer

The 'replace pattern' command in Junos configuration mode allows an administrator to search for a specific text pattern using regular expressions and replace it with new text. This is the correct command for pattern-based substitution within the configuration hierarchy, as it directly matches and replaces text without requiring manual deletion or re-entry.

Exam trap

The trap here is that candidates may confuse 'replace pattern' with 'set replace pattern' (which does not exist) or assume 'rename' can perform pattern-based substitution, leading them to select an incorrect option due to familiarity with similar commands in other vendors' syntax.

How to eliminate wrong answers

Option A is wrong because 'rename' is used to change the name of a configuration element (e.g., an interface or policy) but does not support pattern matching or text replacement. Option C is wrong because 'copy' duplicates a configuration stanza or element, not modifies existing text by pattern matching. Option D is wrong because 'set replace pattern' is not a valid Junos command; the correct syntax is 'replace pattern' at the configuration mode prompt, not prefixed with 'set'.

36
MCQeasy

Which configuration group feature allows an administrator to apply common configuration settings to multiple interfaces without repeating the configuration?

A.groups statement
B.interface-range
C.apply-groups
D.apply-path
AnswerC

The "apply-groups" statement is the correct feature; it references a named group defined under the "groups" hierarchy and applies that group's configuration to the current hierarchy level. When placed at a particular level, it causes the configuration from the referenced group to be merged or overlaid, providing inheritance and override capabilities. This is the standard method for reusing configuration blocks and applying them to multiple levels.

Why this answer

The `apply-groups` statement is the correct feature because it allows an administrator to define a common configuration template within a `groups` hierarchy and then apply that template to multiple interfaces (or other configuration sections) using the `apply-groups` command. This avoids repeating the same configuration statements across individual interfaces, streamlining management and reducing errors.

Exam trap

The trap here is that candidates confuse `groups` (the definition container) with `apply-groups` (the activation command), often selecting Option A because they think defining the group is sufficient, but without `apply-groups`, the group configuration is never applied.

How to eliminate wrong answers

Option A is wrong because `groups` is the container where common configuration is defined, but it is not the feature that applies the configuration to interfaces; without `apply-groups`, the group configuration is inactive. Option B is wrong because `interface-range` is a feature for creating a named range of interfaces to apply a single configuration block, but it is not a configuration group feature; it is used with `set interfaces interface-range <name>` and applies configuration directly, not via a reusable group template. Option D is wrong because `apply-path` is used to dynamically derive configuration values from the contents of a specified path in the configuration hierarchy (e.g., for BGP or firewall filters), not for applying common settings to multiple interfaces.

37
MCQmedium

An administrator is configuring a new Junos device and wants to ensure that configuration changes are applied only after explicit commit confirmation. Which configuration statement should be used?

A.commit synchronize
B.commit at
C.commit check
D.commit confirmed
AnswerD

commit confirmed applies the candidate configuration immediately and starts a countdown timer, defaulting to 10 minutes. If the administrator does not explicitly confirm the commit before the timer expires, the device automatically reverts to the previous configuration. This prevents network lockouts and allows the administrator to test the change, and if it is successful, a simple 'commit' command makes it permanent. This is exactly the functionality needed when configuring a new device remotely.

Why this answer

The 'commit confirmed' statement allows an administrator to apply configuration changes that automatically revert to the previous configuration if not explicitly confirmed within a specified timeout period (default 10 minutes). This ensures changes are only permanently applied after an explicit 'commit' confirmation, providing a safety mechanism to prevent lockout or misconfiguration.

Exam trap

The trap here is that candidates often confuse 'commit confirmed' with 'commit check' or 'commit at', mistakenly thinking that syntax validation or scheduled commits provide the same automatic rollback safety net, when in fact only 'commit confirmed' enforces explicit confirmation to prevent permanent changes.

How to eliminate wrong answers

Option A is wrong because 'commit synchronize' is used on dual Routing Engine (RE) systems to apply the configuration to both REs simultaneously, not to require explicit confirmation. Option B is wrong because 'commit at' schedules a commit to occur at a specific time, but does not require explicit confirmation before the changes become permanent. Option C is wrong because 'commit check' validates the syntax and semantics of the candidate configuration without applying it, but does not provide a mechanism to automatically revert changes if not confirmed.

38
Multi-Selecthard

Which TWO statements about the rescue configuration are correct? (Choose two.)

Select 2 answers
A.The rescue configuration is automatically saved after every commit.
B.The 'rollback rescue' command loads the factory-default configuration.
C.The rescue configuration is designed to provide a method of last-resort recovery.
D.The rescue configuration can be saved by issuing the 'request system configuration rescue save' command.
E.The rescue configuration can be used to restore only a subset of the configuration.
AnswersC, D

The rescue configuration exists as a deliberately preserved, known-good configuration snapshot used for last-resort recovery. If a misapplied change makes the device unreachable or unusable, an administrator can invoke 'rollback rescue' from the CLI or a console to restore the device to a previously working state. This provides a safety net distinct from the normal rollback log, which may be lost or overwritten after many commits.

Why this answer

Option C is correct because the rescue configuration exists specifically as a last-resort recovery mechanism, allowing an administrator to return a device to a known-good configuration when the active configuration is broken or inaccessible. Option D is correct because on Junos devices the rescue configuration is created and stored by running the operational-mode command 'request system configuration rescue save', which snapshots the current candidate configuration as the rescue configuration. Option A is wrong because the rescue configuration is not saved automatically on every commit; it must be saved explicitly by the administrator.

Option B is wrong because 'rollback rescue' loads the previously saved rescue configuration, not the factory-default configuration, which would be loaded with 'load factory-default' or 'rollback 0' depending on context. Option E is wrong because the rescue configuration restores the entire saved configuration, not just a subset of it.

Exam trap

The trap here is that candidates often confuse the rescue configuration with the factory-default configuration or assume it is automatically saved, leading them to select options A or B incorrectly.

39
MCQhard

An engineer is designing a network and needs to ensure that management traffic (SSH, SNMP) is always permitted, even if an interface firewall filter is applied. Which Juniper best practice should be followed?

A.Use a firewall filter that permits all management traffic at the top of the list on each interface
B.Apply a firewall filter on the loopback interface (lo0) to protect the device
C.Apply a firewall filter to the management interface (fxp0)
D.Disable the firewall filter on all interfaces
AnswerB

The loopback interface (lo0) represents the device's control plane, and all traffic destined to the device's own IP addresses—such as SSH, SNMP, BGP, and OSPF—is processed through it, regardless of the physical ingress interface. Applying a firewall filter to lo0 in the input direction provides a single, centralized point to secure management and routing protocol access. This Juniper-recommended practice ensures consistent protection and simplifies administration, as the filter is applied once rather than on every interface.

Why this answer

Applying a firewall filter to the loopback interface (lo0) is the Juniper best practice for protecting management traffic because the loopback interface is the logical termination point for all control plane traffic, including SSH and SNMP. This ensures that management traffic is always permitted regardless of which physical interface it arrives on, while still allowing interface-specific filters to be applied for data plane traffic without risk of blocking management access.

Exam trap

The trap here is that candidates often think management traffic must be permitted on each physical interface individually (Option A), not realizing that Junos uses the loopback interface as the central control plane filter point, making interface-specific filters unnecessary for management access.

How to eliminate wrong answers

Option A is wrong because placing a firewall filter that permits all management traffic at the top of the list on each interface is not scalable and can inadvertently allow unwanted traffic if the filter is misconfigured or omitted on a new interface; it also violates the principle of separating control plane and data plane filtering. Option B is wrong because it is actually the correct answer, not a wrong option. Option C is wrong because applying a firewall filter to the management interface (fxp0) only protects traffic arriving on that dedicated management port, but management traffic like SSH and SNMP can also arrive on other interfaces (e.g., ge-0/0/0), leaving the device unprotected on those paths.

Option D is wrong because disabling firewall filters on all interfaces removes all traffic filtering, which is not a best practice and would expose the device to unauthorized access or attacks.

40
MCQmedium

An engineer issues the 'rollback 3' command in configuration mode. What is the effect?

A.The candidate configuration is saved as the third rollback slot.
B.The candidate configuration is replaced with the configuration from three commits ago.
C.The active configuration is replaced with the candidate configuration.
D.The device reboots and loads configuration version 3.
AnswerB

When an engineer issues 'rollback 3' in Junos configuration mode, Junos loads the configuration snapshot that was active exactly three commits ago from the rollback store into the candidate configuration. Rollback identifies the desired version by its commit counter offset from the current committed configuration, not by a slot number in a list. The candidate now contains that older configuration, which must be reviewed and committed to make it active.

Why this answer

The 'rollback 3' command in Junos configuration mode replaces the current candidate configuration with the configuration from the third most recent commit. Junos maintains up to 50 rollback slots (numbered 0 through 49), where slot 0 is the most recent commit, slot 1 is the commit before that, and so on. Therefore, 'rollback 3' retrieves the configuration saved three commits ago, overwriting any uncommitted changes in the candidate configuration.

Exam trap

The trap here is that candidates often confuse 'rollback' with 'commit' or 'save' operations, mistakenly thinking it saves the current candidate configuration rather than retrieving a previous one, or they assume it directly modifies the active configuration without requiring a subsequent commit.

How to eliminate wrong answers

Option A is wrong because the 'rollback' command does not save the candidate configuration; it retrieves a previously committed configuration from a rollback slot. Saving the candidate configuration to a specific rollback slot is done with the 'commit confirm' or 'commit at' commands, not 'rollback'. Option C is wrong because the 'rollback' command does not replace the active (running) configuration; it only modifies the candidate configuration, which must then be committed to become active.

Option D is wrong because 'rollback' does not cause a reboot or load a configuration version from a file; it simply loads a previously committed configuration into the candidate configuration space from the device's rollback database.

41
MCQeasy

Refer to the exhibit. If the administrator now enters the command 'delete interfaces ge-0/0/0 unit 0 family inet address 192.168.1.1/24' and then commits, what will be the result?

A.Only the address 192.168.1.1/24 will be removed, and 192.168.1.2/24 will remain.
B.The commit will fail due to an attempt to delete a non-existent address.
C.The entire unit 0 will be deleted.
D.Both addresses will be removed from the configuration.
AnswerA

In Junos, the delete command operates on the exact hierarchy node identified by the address. The configuration node for 192.168.1.1/24 is a separate leaf under unit 0's family inet address list. Deleting that specific leaf removes only that address, leaving 192.168.1.2/24 intact in the same unit. This is standard behavior when using the explicit address form of the delete command.

Why this answer

The 'delete' command in Junos is hierarchical and targets the exact configuration hierarchy specified. In this case, the command specifies 'address 192.168.1.1/24' under 'family inet', so only that specific address is removed. The other address (192.168.1.2/24) remains because it is a separate leaf under the same 'address' statement and is not affected by the deletion.

Exam trap

The trap here is that candidates may assume deleting one address under a 'family inet' block will remove all addresses, similar to how some other platforms (e.g., Cisco IOS) treat the 'ip address' command as replacing the entire address list, but Junos treats each address as an independent leaf.

How to eliminate wrong answers

Option B is wrong because the address 192.168.1.1/24 does exist in the configuration (as shown in the exhibit), so the delete command targets a valid leaf and will not cause a commit failure. Option C is wrong because the command specifies the exact address leaf, not the 'unit 0' hierarchy; deleting a specific address does not remove the entire unit. Option D is wrong because the command is scoped to only one address; Junos does not cascade the deletion to other addresses under the same 'family inet' unless explicitly targeted.

42
MCQhard

After a series of configuration changes, an engineer wants to see only the lines that will be added or modified when the candidate is committed. Which command achieves this?

A.show configuration | except
B.show configuration | display set
C.commit check | match
D.show | compare
AnswerD

In configuration mode, "show" without a specific statement displays the candidate configuration, and appending "| compare" instructs the CLI to produce a diff against the active (committed) configuration. The output uses plus (+) and minus (-) prefixes to indicate lines to be added and removed upon commit, along with markers for changed lines. This is precisely the Junos idiom for reviewing pending changes before committing. It directly answers the question of "what will change."

Why this answer

The 'show | compare' command displays the differences between the candidate configuration and the active configuration, showing only the lines that will be added, modified, or deleted upon commit. This is the standard Junos method for reviewing pending changes before committing them.

Exam trap

The trap here is that candidates often confuse 'show | compare' with 'show configuration | display set' or 'commit check', thinking that displaying the full candidate configuration or validating syntax is equivalent to viewing only the changes, but only 'show | compare' provides the targeted diff output.

How to eliminate wrong answers

Option A is wrong because 'show configuration | except' filters out lines matching a pattern, but does not show only added or modified lines; it shows all lines except those matching the pattern. Option B is wrong because 'show configuration | display set' converts the configuration into 'set' commands, but it shows the entire candidate configuration, not just the changes. Option C is wrong because 'commit check | match' validates the candidate configuration for syntax errors and then filters the output with 'match', but it does not display a diff of added or modified lines.

43
MCQhard

A junior administrator is told to implement configuration changes that must survive a reboot. Which statement is correct?

A.Performing a 'commit' saves the active configuration to non-volatile storage.
B.The 'commit confirmed' command ensures persistence.
C.Changes made using 'set' commands are automatically saved to the startup config.
D.The 'commit' command only writes to RAM, so a 'request system configuration save' is needed.
AnswerA

In Junos, the 'commit' operation takes the candidate configuration, validates it, and installs it as the active configuration while simultaneously writing it to persistent storage on the device's disk. This means the committed configuration is retained in non-volatile memory, such as the /config directory on Junos, and will survive a reboot or power cycle. Therefore, a simple commit is sufficient to ensure the configuration is permanently active.

Why this answer

In Junos, the 'commit' command activates the candidate configuration and saves it to non-volatile storage (the /config directory on the flash drive), ensuring it survives a reboot. This is the standard method for making configuration changes persistent across system restarts.

Exam trap

The trap here is that candidates familiar with Cisco IOS often assume 'commit' only writes to running-config (RAM) and that a separate 'copy running-config startup-config' is needed, but in Junos, 'commit' inherently saves to non-volatile storage, making option D a common distractor.

How to eliminate wrong answers

Option B is wrong because 'commit confirmed' temporarily activates a configuration for a specified timeout period (default 10 minutes) and automatically rolls back if not confirmed with a standard 'commit', so it does not ensure persistence unless followed by a regular commit. Option C is wrong because changes made with 'set' commands are only stored in the candidate configuration in volatile memory (RAM) until explicitly committed; they are not automatically saved to the startup configuration. Option D is wrong because the 'commit' command writes the active configuration to non-volatile storage (the /config directory), not just RAM, and there is no 'request system configuration save' command in Junos (the correct command for saving the active configuration to a file is 'request system configuration rescue save' or 'save' within the CLI).

44
MCQhard

An administrator is troubleshooting a configuration issue where a route filter is unexpectedly dropping traffic. The filter uses an 'exact' match type. Which statement correctly describes the behavior of the 'exact' match type in a prefix list?

A.The route mask must be equal to or greater than the specified prefix length.
B.The route must match the prefix and prefix length exactly.
C.The prefix 0.0.0.0/0 is never matched by 'exact' filters.
D.The route mask must be greater than the specified prefix length.
AnswerB

This is the correct definition of an `exact` match in Junos route-filter matching. When you specify `route-filter 192.168.0.0/16 exact`, the filter evaluates both the prefix (the network bits) and the prefix length (the subnet mask) against the route's destination. The route must have the same network address and the same prefix length — a route like 192.168.1.0/24 would fail because the prefix length differs, and 192.168.0.0/15 would fail because the network bits differ. This strict equality distinguishes `exact` from `longer` or `orlonger`, which are used to match more-specific routes.

Why this answer

The 'exact' match type in a Junos prefix list requires the route's prefix and prefix length to match the specified prefix and length identically. This is defined in the Junos routing policy framework, where 'exact' is used for precise route filtering, such as matching a specific network like 192.168.1.0/24 without allowing any subnets or supernets.

Exam trap

The trap here is that candidates often confuse 'exact' with 'orlonger' or 'longer' match types, especially when troubleshooting route filter behavior, leading them to select options that describe less restrictive matching.

How to eliminate wrong answers

Option A is wrong because it describes the 'orlonger' match type, where the route mask must be equal to or greater than the specified prefix length, not 'exact'. Option C is wrong because the prefix 0.0.0.0/0 can be matched by an 'exact' filter if the route is exactly 0.0.0.0/0, which is a valid default route; the statement is a common misconception. Option D is wrong because it describes the 'longer' match type, where the route mask must be greater than the specified prefix length, not 'exact'.

45
Multi-Selecthard

Which THREE of the following are characteristics of configuration groups in Junos?

Select 3 answers
A.The 'apply-groups' statement is used to specify which group(s) should be inherited.
B.A maximum of 10 groups can be applied to a single configuration statement.
C.Groups can be nested (i.e., a group can inherit another group).
D.They allow a set of configuration statements to be defined once and inherited by multiple sections.
E.Configuration groups do not allow individual statements within the group to be overridden in the main configuration.
AnswersA, C, D

The 'apply-groups' statement is the mechanism that activates configuration-group inheritance at a specific hierarchy level. When included, Junos pulls the named group's statements into the configuration as if they were explicitly defined at that level. It can be placed at multiple levels, enabling selective inheritance, and multiple groups can be listed in a single apply-groups statement for apply-order precedence.

Why this answer

Option A is correct because Junos uses the 'apply-groups' statement (and 'apply-groups-except') to specify which configuration group(s) a given hierarchy level should inherit from. Option C is correct because Junos configuration groups support nesting: a group can itself contain an 'apply-groups' statement, allowing one group to inherit from another group. Option D is correct because the core purpose of configuration groups is to define a reusable set of configuration statements once and have them inherited by multiple sections of the configuration, reducing duplication.

Option B is incorrect because there is no limit of 10 groups per statement; Junos allows up to 50 groups to be applied at a single hierarchy level. Option E is incorrect because statements inherited from a group can be overridden by explicitly configuring the same statement in the main configuration, which takes precedence over the inherited value.

Exam trap

The trap here is that candidates often assume configuration groups are rigid and cannot be overridden, but in reality the main configuration always overrides group settings, and there is no arbitrary limit like 10 groups per statement.

46
MCQhard

A company has two Juniper routers in a high-availability cluster with dual Routing Engines. The administrator performs a commit on the primary RE. What is the effect of using the 'commit synchronize' command?

A.It performs a commit check on both REs but does not activate the config.
B.It commits the configuration on both Routing Engines simultaneously.
C.It commits the configuration only on the primary RE.
D.It commits the configuration only on the backup RE.
AnswerB

The correct behavior is 'commit synchronize', a Junos command that loads and activates the candidate configuration on both the primary and backup Routing Engines simultaneously, ensuring they operate with identical active configurations. This is critical for high-availability clusters because it prevents config drift, so failover to the backup will use the same settings and policies as the primary. The simultaneous commit minimizes the window of inconsistency and is the standard method for configuring both REs in one operation.

Why this answer

The 'commit synchronize' command on Juniper routers with dual Routing Engines ensures that the configuration is committed on both the primary and backup REs simultaneously. This is critical for maintaining configuration consistency in a high-availability cluster, as it prevents a split-brain scenario where the backup RE has a different active configuration than the primary. The command performs a full commit (including validation and activation) on both REs, not just a check.

Exam trap

The trap here is that candidates often confuse 'commit synchronize' with 'commit check' or assume it only affects one RE, failing to recognize that Juniper's high-availability design requires explicit synchronization to maintain configuration consistency across both Routing Engines.

How to eliminate wrong answers

Option A is wrong because 'commit synchronize' performs a full commit (validation and activation) on both REs, not just a commit check; the 'commit check' command is used for validation only. Option C is wrong because 'commit synchronize' explicitly commits on both REs, not only the primary; committing only on the primary would leave the backup out of sync. Option D is wrong because 'commit synchronize' commits on both REs, not only the backup; committing only on the backup would not update the primary's active configuration.

47
MCQmedium

An engineer needs to configure a static route on a Juniper device. Which statement is true regarding the configuration process?

A.The set command activates the change for 10 minutes by default.
B.Configuration changes must be committed to become active.
C.The configuration is immediately active upon entering the set command.
D.The commit command requires a reboot to take effect.
AnswerB

In Junos, the CLI operates on a candidate configuration that is separate from the active, committed configuration. When you enter a `set` command, the change is stored in the candidate but is not yet applied to the router's runtime processes. The `commit` command validates the candidate, installs it as the new active configuration, and applies it immediately without reboot, making commit the mandatory step for any configuration change to take effect.

Why this answer

In Junos, configuration changes are made in a candidate configuration and do not take effect until explicitly committed using the 'commit' command. This two-phase model (edit then commit) ensures that changes are validated before activation, preventing partial or incorrect configurations from disrupting network operations. Option B correctly identifies this requirement.

Exam trap

The trap here is that candidates familiar with Cisco IOS, where 'set' or 'configure terminal' commands take effect immediately, mistakenly assume Junos behaves the same way, overlooking the mandatory commit step.

How to eliminate wrong answers

Option A is wrong because the 'set' command does not activate a change for any duration; it merely modifies the candidate configuration, which remains inactive until committed. Option C is wrong because the configuration is not immediately active upon entering the 'set' command; Junos uses a commit model where changes only become active after a successful 'commit'. Option D is wrong because the 'commit' command does not require a reboot; it applies the candidate configuration to the active configuration dynamically without restarting the device.

48
MCQmedium

Refer to the exhibit. An engineer has made changes to the candidate configuration. What will happen when the engineer issues the 'commit' command?

A.The commit will succeed but the security policy will be ignored due to a syntax error.
B.Only the interface address change will be committed because security policies require a reboot.
C.The configuration will be validated; if errors exist, the commit will fail.
D.Both the interface address and security policy will be activated.
AnswerD

The commit command in Junos atomically activates all changes in the candidate configuration, including both the interface address and the security policy. There is no separate commit process or reboot needed for security policies, so both changes take effect simultaneously. The validation performed during commit confirms that the configuration is syntactically correct, and since the exhibit shows no errors, both changes will be applied.

Why this answer

In Junos, the 'commit' command activates all changes in the candidate configuration atomically. Both the interface address change and the security policy will be applied simultaneously after validation. Junos does not require a reboot for security policy changes, and syntax errors cause the commit to fail, not be ignored.

Exam trap

The trap here is that candidates may think security policies require a reboot (a common misconception from other platforms) or that syntax errors are silently ignored, but Junos enforces strict validation and atomic commits.

How to eliminate wrong answers

Option A is wrong because Junos performs full syntax and semantic validation during commit; a syntax error would cause the commit to fail, not be ignored. Option B is wrong because security policies in Junos are activated immediately upon commit without requiring a reboot; only certain hardware or kernel-level changes might need a reboot. Option C is wrong because while validation does occur, if errors exist the commit fails, but the question implies no errors are present, so the commit will succeed and activate both changes.

49
Multi-Selecteasy

Which TWO statements are true about the Junos configuration hierarchy?

Select 2 answers
A.Configuration is organized into two main hierarchies: system and interfaces.
B.The configuration is divided into a hierarchical tree.
C.Each configuration statement is terminated by a semicolon.
D.Configuration must be entered in a specific order.
E.It is a flat structure with no grouping.
AnswersB, C

Junos stores its configuration as a hierarchy of statements, which is exactly a tree structure: a root level branching into containers, each containing additional statements or containers. This tree model lets you navigate and address individual configuration nodes using a path, and it underpins how configuration is displayed, edited, and committed.

Why this answer

Option B is correct because the Junos configuration is fundamentally a hierarchical tree of statements, organized under top-level stanzas such as system, interfaces, protocols, and routing-options, which can be nested to arbitrary depth. Option C is correct because in Junos configuration syntax every configuration statement must be terminated by a semicolon, for example 'set system host-name router1' or 'host-name router1;' in curly-brace format. Option A is incorrect because system and interfaces are just two of many top-level hierarchies, not the only two main hierarchies.

Option D is incorrect because Junos allows statements to be entered in any order; the commit process validates and orders the configuration logically. Option E is incorrect because the Junos configuration is explicitly hierarchical, not flat, and statements are grouped into nested hierarchies.

Exam trap

The trap here is that candidates often assume configuration must be entered in a specific order (like Cisco IOS), but Junos allows any order because the hierarchy is defined by the structure, not the sequence of commands.

50
Multi-Selectmedium

Which TWO statements about the 'commit' operation in Junos are correct?

Select 2 answers
A.The commit operation validates syntax before applying, and if errors are found, the commit fails.
B.The commit operation automatically rolls back changes after 10 minutes if not confirmed.
C.The commit operation allows you to commit only a specific portion of the configuration.
D.The commit operation applies the configuration changes at the next system reboot.
E.The commit operation activates the candidate configuration as the new active configuration.
AnswersA, E

The commit operation first checks the candidate configuration for syntactic and schema errors using the Junos configuration validation engine. If an error is found — such as an invalid IP prefix, a missing mandatory statement, or an unknown hierarchy — the commit aborts and the candidate configuration remains unchanged. No part of the configuration is applied until the entire candidate passes validation, ensuring that only well-formed configurations become active.

Why this answer

Option A is correct because when you run commit, Junos first performs a syntax check on the candidate configuration, and if any syntax errors are detected, the commit fails and the candidate configuration is not activated. Option E is correct because the commit operation merges the candidate configuration into the active configuration, making it the new running (active) configuration on the device. Option B is incorrect because automatic rollback after 10 minutes only occurs with the 'commit confirmed' command, not a standard commit.

Option C is incorrect because Junos commits the entire candidate configuration; partial commits are not supported (you would use configuration groups or 'commit check' for validation instead). Option D is incorrect because commit applies changes immediately, not at the next system reboot.

Exam trap

The trap here is confusing the standard 'commit' with 'commit confirmed', which includes a 10-minute rollback timer, and assuming that Junos allows partial commits like some other platforms (e.g., Cisco's 'commit' with 'only' option).

51
MCQeasy

A network engineer needs to configure an interface on a Juniper device to use DHCP to obtain an IP address. Which hierarchy is used to apply this configuration?

A.set interfaces ge-0/0/0 unit 0 family inet dhcp
B.set interfaces ge-0/0/0 dhcp-client
C.set interfaces ge-0/0/0 unit 0 family inet6 dhcp
D.set interfaces ge-0/0/0 unit 0 family ppp dhcp
AnswerA

This is the correct Junos syntax for enabling a DHCP client on an interface. The configuration is placed under the logical interface (unit 0) and specifically within the 'family inet' hierarchy, which governs IPv4. By using the 'dhcp' statement there, the interface will send DHCPv4 discovery messages and accept a dynamically allocated IPv4 address, default route, and DNS servers from the DHCP server. This statement is the only valid among the options that correctly targets IPv4 DHCP.

Why this answer

On Juniper devices, DHCP client functionality for IPv4 is configured under the `family inet` hierarchy within a logical interface unit. The command `set interfaces ge-0/0/0 unit 0 family inet dhcp` enables the interface to obtain an IPv4 address via DHCP, which is the standard method for dynamic address assignment on Ethernet interfaces.

Exam trap

The trap here is that Cisco engineers often expect DHCP client configuration to be applied directly under the physical interface (like `ip address dhcp` on Cisco IOS), but Junos requires it under the logical unit and address family hierarchy, leading candidates to choose option B.

How to eliminate wrong answers

Option B is wrong because `set interfaces ge-0/0/0 dhcp-client` is not a valid Junos configuration hierarchy; DHCP client settings must be applied under the logical unit and address family, not directly under the physical interface. Option C is wrong because `family inet6 dhcp` is used for DHCPv6 (IPv6), not for obtaining an IPv4 address via DHCP, which is the requirement in the question. Option D is wrong because `family ppp dhcp` is not a standard Junos configuration; PPP interfaces use different mechanisms (like IPCP) for address assignment, and DHCP is not applied under `family ppp`.

52
Multi-Selecthard

Which THREE statements correctly describe the behavior of the 'replace pattern' command in Junos configuration mode?

Select 3 answers
A.It validates the replacement configuration for correctness before applying.
B.It automatically commits the changes after replacement.
C.It can be used to change interface names or IP addresses throughout the configuration.
D.It operates on the candidate configuration, not the active configuration.
E.It uses regular expressions to match and replace text patterns in the configuration.
AnswersC, D, E

A typical use case for this command is a bulk rename, such as converting all occurrences of an interface name from 'fe-0/0/0' to 'xe-0/0/0' or updating an IP address across numerous units. Because the pattern is applied across the entire configuration, you can effect broad changes with a single command rather than editing each statement manually. For this to work reliably, the regex must be precise enough to match only the intended occurrences.

Why this answer

Option C is correct because the 'replace pattern' command performs a global find-and-replace across the candidate configuration, making it ideal for renaming interfaces or changing IP addresses everywhere they appear. Option D is correct because 'replace pattern' edits the candidate configuration, not the active configuration, so changes must still be committed to take effect. Option E is correct because the command matches text using regular expressions (e.g., 'replace pattern ge-0/0/0 with ge-0/0/1'), allowing flexible pattern-based substitutions.

Option A is not correct because 'replace pattern' does not itself validate the replacement for correctness before applying; validation occurs at commit time via 'commit check' or the commit process. Option B is not correct because 'replace pattern' does not automatically commit changes; the user must explicitly issue a 'commit' command afterward.

Exam trap

The trap here is that candidates often assume 'replace pattern' performs validation or auto-commits, confusing it with other Junos commands like 'load replace' or 'commit check', when in fact it is a simple text substitution tool that requires a separate commit to take effect.

53
MCQeasy

An administrator is configuring a static route to a remote network 10.10.10.0/24 via next-hop 192.168.1.1. Which command correctly adds this route?

A.set routing-options route 10.10.10.0/24 static next-hop 192.168.1.1
B.set routing-options static route 10.10.10.0 next-hop 192.168.1.1 mask 255.255.255.0
C.set routing-options static next-hop 192.168.1.1
D.set routing-options static route 10.10.10.0/24 next-hop 192.168.1.1
AnswerD

This is the correct Junos syntax for a static route. The hierarchy is 'routing-options static route' followed by the destination prefix in CIDR notation, then the 'next-hop' statement with the gateway address. This configuration installs a route to 10.10.10.0/24 via 192.168.1.1 into the routing table and is the expected format for Junos candidates.

Why this answer

The Junos syntax for configuring a static route uses the hierarchy `set routing-options static route <destination-prefix> next-hop <address>`. The prefix must include the subnet mask in CIDR notation (e.g., /24). This command installs a route to 10.10.10.0/24 with next-hop 192.168.1.1 into the routing table.

Exam trap

The trap here is that candidates familiar with Cisco IOS may try to use a separate `mask` parameter (as in Option B) or place the route directly under `routing-options route` (as in Option A), failing to recognize Junos requires the `static route` hierarchy and CIDR notation in the destination.

How to eliminate wrong answers

Option A is wrong because the hierarchy is incorrect; `route` is not a direct child of `routing-options` — static routes must be under `routing-options static route`. Option B is wrong because it incorrectly uses a separate `mask` parameter instead of CIDR notation; Junos requires the prefix length in the destination (e.g., 10.10.10.0/24), not a separate mask. Option C is wrong because it omits the destination prefix entirely; a static route must specify both the destination network and the next-hop.

54
MCQhard

Refer to the exhibit. An engineer notices that SNMP traffic from source 10.1.1.1 is being rejected on interface ge-0/0/1. The engineer wants to allow SNMP from this source while still blocking other SNMP traffic from the 10.0.0.0/8 range. Which change should be made?

A.Add a term at the end to permit all from 10.1.1.1
B.Change the source-address in term 1 to 10.0.0.0/8 except 10.1.1.1
C.Insert a term 0 before term 1 to permit SNMP from 10.1.1.1
D.Remove the filter and apply a new filter that permits SNMP from 10.1.1.1
AnswerC

Inserting a term 0 before term 1 is the correct fix because firewall filters evaluate terms in ascending order and stop at the first match. The new term can match SNMP traffic (e.g., destination UDP port 161/162) from source 10.1.1.1 and apply an accept action, ensuring this specific traffic is permitted before any subsequent deny or reject terms are evaluated. This placement creates a precise exception, allowing the engineer to keep the existing filter's broader rules intact while restoring SNMP access for the identified host.

Why this answer

Firewall filters in Junos are evaluated sequentially from the lowest term number. By inserting a new term 0 before the existing term 1 that explicitly permits SNMP traffic (UDP ports 161/162) from source 10.1.1.1, the filter will match and accept this traffic before reaching the deny term for the 10.0.0.0/8 range. This ensures the specific host is allowed while still blocking other SNMP traffic from the broader subnet.

Exam trap

The trap here is that candidates often think they can use an 'except' keyword or add a term at the end to override a previous deny, not realizing that Junos filters stop processing after the first match and do not support exclusion syntax within a source-address match.

How to eliminate wrong answers

Option A is wrong because adding a term at the end would never be evaluated if the preceding term 1 (which denies 10.0.0.0/8) already matches and rejects the traffic; Junos firewall filters stop processing after the first match. Option B is wrong because Junos does not support an 'except' modifier on source-address in a firewall filter term; you cannot exclude a single host from a prefix match within the same term. Option D is wrong because it is unnecessarily disruptive and inefficient; the existing filter can be modified by inserting a term, which is the standard Junos practice for such requirements.

55
MCQmedium

An engineer is preparing a Juniper EX Series switch for deployment and wants to load a previously saved configuration from a USB device into the candidate configuration without deleting any existing candidate statements. The saved file is named ex-config.conf and is located in the /var/tmp directory. Which command accomplishes this?

A.load set /var/tmp/ex-config.conf
B.load override /var/tmp/ex-config.conf
C.load merge /var/tmp/ex-config.conf
D.load replace /var/tmp/ex-config.conf
AnswerC

The load merge command reads the specified file and merges its contents into the candidate configuration, preserving all existing candidate statements. It is the correct choice when the requirement is to add configuration without removing what is already present. The path /var/tmp/ex-config.conf is valid and the merge action keeps existing hierarchies intact.

Why this answer

The load merge command is designed to combine a saved configuration file with the current candidate configuration, keeping all existing candidate statements intact. The requirement is to add the saved configuration without deleting anything, so merge is the correct action. Other load variants either replace hierarchies, override the entire candidate, or expect a different file format.

Exam trap

The trap here is assuming that any load command preserves existing configuration, when in fact load override and load replace can delete candidate statements.

56
MCQhard

An engineer needs to load a full configuration from a text file onto a Junos device, replacing the entire candidate configuration. Which command should be used?

A.load set /path/to/config.txt
B.load override /path/to/config.txt
C.load patch /path/to/config.txt
D.load merge /path/to/config.txt
AnswerB

`load override` reads the text file as a complete hierarchical configuration and replaces the entire candidate configuration with its contents. Every existing statement in the candidate is discarded, and the resulting candidate matches the file exactly. This is the correct command when the goal is to load a full configuration from a text file, because it guarantees that statements absent from the file are removed and the device processes the file as the definitive configuration.

Why this answer

The 'load override' command replaces the entire candidate configuration with the contents of the specified text file, discarding any existing candidate changes. This is the correct choice because the engineer explicitly needs to replace the full configuration, not merge or patch it.

Exam trap

The trap here is that candidates often confuse 'load override' with 'load merge' because both load a file, but only 'load override' discards the existing candidate configuration, while 'load merge' preserves it and can cause configuration conflicts or residual settings.

How to eliminate wrong answers

Option A is wrong because 'load set' is not a valid Junos command; the correct syntax for loading a set-based configuration is 'load set terminal' or 'load set filename', but 'load set /path/to/config.txt' is not standard and would fail. Option C is wrong because 'load patch' applies only incremental changes (diffs) to the candidate configuration, not a full replacement. Option D is wrong because 'load merge' combines the text file with the existing candidate configuration, potentially retaining old settings and not achieving a full replacement.

57
MCQhard

Refer to the exhibit. An administrator wants to remove the address 10.0.0.2/24 from unit 0. Which configuration mode command achieves this without affecting other configuration?

A.delete interfaces ge-0/0/1 unit 0
B.delete interfaces ge-0/0/1 unit 0 family inet address
C.delete interfaces ge-0/0/1 unit 0 family inet address 10.0.0.2/24
D.delete interfaces ge-0/0/1 unit 1 family inet address 10.0.0.2/24
AnswerC

Junos treats addresses under 'family inet' as a list of prefix-form entries. By specifying '10.0.0.2/24' with the exact prefix length, the delete operation becomes a subtraction from that list, affecting only that entry. Any other addresses on unit 0 remain untouched; this precisely matches the administrator's intention.

Why this answer

The command `delete interfaces ge-0/0/1 unit 0 family inet address 10.0.0.2/24` specifically removes only the IPv4 address 10.0.0.2/24 from the logical unit 0, leaving all other configuration (such as other addresses, VLAN tagging, or protocol families) intact. In Junos, addresses are hierarchical under `family inet address`, and deleting a specific address entry does not affect sibling addresses or the unit itself.

Exam trap

The trap here is that candidates often confuse deleting the entire unit or address family with deleting a single address, leading them to choose options that remove more configuration than intended, which is a common mistake in Junos hierarchical configuration management.

How to eliminate wrong answers

Option A is wrong because `delete interfaces ge-0/0/1 unit 0` removes the entire logical unit 0, including all its addresses, protocol families, and any other configuration (e.g., VLAN ID, filters), which is too broad. Option B is wrong because `delete interfaces ge-0/0/1 unit 0 family inet address` removes all IPv4 addresses under unit 0, not just the specific 10.0.0.2/24, potentially deleting other configured addresses. Option D is wrong because it targets unit 1 instead of unit 0, so it would not affect the address on unit 0 at all; it either does nothing or modifies the wrong interface unit.

58
MCQmedium

A network operations team has received a new Juniper router to replace an existing legacy router. The team needs to apply a baseline configuration that includes system settings, interfaces, and security policies. The configuration is provided as a text file containing Junos configuration hierarchy syntax (e.g., 'system { host-name... }'). The engineer connects to the console and sees the prompt 'root@%'. What is the most efficient way to apply the configuration?

A.Use the 'load set' command to load a set of configuration commands.
B.Use FTP to transfer the file and then commit.
C.Enter configuration mode and manually type each command.
D.Use the 'load merge' command to merge the configuration file.
AnswerD

The 'load merge' command is the correct choice because it reads a configuration file in the Junos hierarchy format and merges its contents into the current candidate configuration. This is the standard way to apply a full or partial configuration file without wiping out existing settings; overlapping statements are updated while untouched parts remain intact. After the merge, the candidate can be reviewed and then committed with 'commit'.

Why this answer

The engineer is at the shell prompt (root@%), not in configuration mode. The 'load merge' command is used within configuration mode to merge a configuration file (in Junos hierarchy syntax) into the candidate configuration, which is the most efficient way to apply a pre-written baseline configuration without manual typing or complex file transfers.

Exam trap

The trap here is that candidates may confuse the shell prompt (root@%) with the configuration mode prompt (root@#) and attempt to use 'load merge' directly at the shell, which fails; they must first enter configuration mode with 'configure' or 'edit' before loading the file.

How to eliminate wrong answers

Option A is wrong because 'load set' is used to load a file containing 'set' commands (flat format), not the hierarchical configuration syntax provided; using it on a hierarchy file would cause syntax errors. Option B is wrong because FTP transfer is unnecessary and inefficient; Junos supports loading configuration files directly from local storage or via SCP/HTTP, and FTP adds security risks and extra steps. Option C is wrong because manually typing each command is time-consuming and error-prone, defeating the purpose of having a pre-written configuration file.

Ready to test yourself?

Try a timed practice session using only Junos Configuration Basics questions.