Courseiva

CCNA User Interfaces Questions

62 questions · User Interfaces · All types, answers revealed

1
MCQmedium

You are managing a Juniper EX4300 switch that serves as a Layer 3 access switch for a campus network. The switch has multiple VLANs configured with IRB interfaces. Users in VLAN 10 report that they cannot reach the default gateway (IRB.10) even though other VLANs are working fine. You check the configuration and see that interface irb.10 is configured with an IP address. You also verify that the VLAN is associated with the correct access ports. However, when you ping the IRB.10 address from the switch itself, it fails. You suspect that the issue might be that the IRB interface is not 'up'. Which command would you use to quickly verify the operational status of the IRB interface?

A.show interfaces terse irb.10
B.show ethernet-switching table
C.show configuration interfaces irb.10
D.show vlan
AnswerA

The 'show interfaces terse irb.10' command provides a concise operational summary of the IRB interface, displaying its link state (up/down), protocol status, and the assigned IP address in a single line. This is the correct command because it directly verifies both the operational and protocol state of the IRB, which is essential for confirming that the L3 gateway is active. Unlike configuration commands, it reflects the current runtime status, including whether the underlying VLAN is active and associated with a physical port.

Why this answer

`show interfaces terse irb.10` displays the operational status (up/down) of the IRB interface along with its configured IP address. Since the issue is that the IRB interface may not be 'up', this command quickly confirms whether the interface is operationally active, which is essential for Layer 3 forwarding.

Exam trap

The trap here is that candidates often check the configuration (`show configuration`) assuming it reflects the operational state, but Junos separates configuration from operational status, so a correctly configured IRB can still be down due to missing VLAN association or no active member ports.

How to eliminate wrong answers

Option B is wrong because `show ethernet-switching table` displays MAC address-to-VLAN mappings for Layer 2 forwarding, not the operational status of IRB interfaces. Option C is wrong because `show configuration interfaces irb.10` only shows the configured (intended) settings, not the current operational state; the interface could be configured but still down. Option D is wrong because `show vlan` displays VLAN membership and associated interfaces but does not show the operational status of IRB interfaces or their IP addresses.

2
MCQmedium

While in configuration mode, an engineer types 'show' and sees a different output than when typing 'run show configuration'. Why?

A.'show' shows the active configuration; 'run show configuration' shows the candidate.
B.'show' shows the candidate configuration; 'run show configuration' shows the active configuration.
C.Both commands produce identical output.
D.'run show configuration' is not allowed from configuration mode.
AnswerB

This option correctly describes the behavior of the two commands. Junos maintains two separate configuration databases: the candidate configuration, which holds all uncommitted changes made in configuration mode, and the active configuration, which represents the last committed state that is actually in effect. Typing 'show' in configuration mode displays the candidate configuration, complete with pending modifications. 'run show configuration' invokes the operational command 'show configuration' from inside configuration mode, thereby displaying the active configuration. This distinction is essential for verifying changes before committing.

Why this answer

In Junos, when you are in configuration mode and type 'show', it displays the candidate configuration (the changes you have made but not yet committed). The command 'run show configuration' executes the operational-mode command 'show configuration' from within configuration mode, which displays the active (committed) configuration. Therefore, option B correctly identifies that 'show' shows the candidate configuration and 'run show configuration' shows the active configuration.

Exam trap

The trap here is that candidates often confuse the behavior of 'show' in configuration mode with the operational-mode 'show configuration' command, mistakenly thinking both display the same configuration or that 'show' always shows the active configuration.

How to eliminate wrong answers

Option A is wrong because it reverses the roles: 'show' shows the candidate configuration, not the active configuration, and 'run show configuration' shows the active configuration, not the candidate. Option C is wrong because the two commands produce different outputs: 'show' displays the candidate configuration (which may include uncommitted changes), while 'run show configuration' displays the active (committed) configuration. Option D is wrong because 'run show configuration' is allowed from configuration mode; the 'run' command is specifically designed to execute operational-mode commands while in configuration mode.

3
Multi-Selectmedium

Which TWO commands can be used to view the current active configuration on a Junos device? (Choose two.)

Select 2 answers
A.show configuration | display set
B.show system configuration
C.show configuration
D.show | compare
E.show interfaces
AnswersA, C

The 'show configuration' command, when executed from operational mode, displays the complete active configuration in hierarchical format. Adding the '| display set' filter converts that output into a flat sequence of 'set' commands, one per configured leaf value. This is the authoritative representation of the current active configuration, and the set-format output is particularly useful for scripting, auditing, and reproducibly applying configuration to another device.

Why this answer

Option C, `show configuration`, is correct because it displays the active configuration in Junos's hierarchical (curly-brace) format, which is the standard way to view the currently committed configuration. Option A, `show configuration | display set`, is also correct because it renders that same active configuration as flat `set` commands, which is useful for viewing or copying the configuration in a script-friendly form. Both commands read the committed active configuration, so they satisfy the requirement.

Option B, `show system configuration`, is not a valid Junos operational command for displaying the configuration. Option D, `show | compare`, only shows the difference between the candidate configuration and the active configuration (a diff), not the full active configuration. Option E, `show interfaces`, displays interface status and statistics rather than the device configuration.

Exam trap

The trap here is that candidates confuse 'show configuration' with 'show system configuration' (which does not exist) or mistakenly think 'show | compare' shows the active configuration, when it actually shows differences between configurations.

4
MCQmedium

A user wants to discard all uncommitted changes and return to the last committed configuration without exiting configuration mode. Which command should they use?

A.rollback 0
B.load override
C.reload
D.commit check
AnswerA

rollback 0 is the correct command because it copies the active (committed) configuration into the candidate configuration, removing any uncommitted edits on the fly. It operates entirely within configuration mode and does not reboot the device or alter the running configuration, making it the standard way to abandon all pending changes since the last commit.

Why this answer

'rollback 0' discards all uncommitted changes and reverts the candidate configuration to the last committed configuration, all while staying in configuration mode. In Junos, rollback 0 specifically refers to the most recently committed configuration, making it the exact command to undo uncommitted edits without exiting.

Exam trap

The trap here is that Cisco engineers often confuse 'reload' (a Cisco command to reboot) with Junos 'rollback', or mistakenly think 'load override' is the correct way to revert to the last committed configuration, when in fact 'load override' requires a specific file and does not automatically target the last committed state.

How to eliminate wrong answers

Option B is wrong because 'load override' replaces the entire candidate configuration with the contents of a specified file, but it does not automatically revert to the last committed configuration; it loads whatever file is specified, which may not be the last committed one. Option C is wrong because 'reload' is not a valid Junos command; it is a Cisco IOS command that reboots the device, not something used to discard uncommitted changes in configuration mode. Option D is wrong because 'commit check' validates the syntax of the candidate configuration without committing it; it does not discard any changes, so uncommitted edits remain in place.

5
MCQmedium

A technician is troubleshooting a routing issue and needs to see real-time updates of BGP prefixes being received. Which command should be used?

A.monitor route bgp
B.monitor traffic interface ge-0/0/0
C.show route advertising-protocol bgp
D.show route protocol bgp
AnswerA

The 'monitor route bgp' command is the correct choice because it subscribes to the BGP Routing Information Base (RIB) and prints route add, change, and withdrawal events in real time. Unlike static show commands, it remains active until you stop it, making it the only option that provides continuous, dynamic monitoring of BGP route changes for live troubleshooting.

Why this answer

The 'monitor route bgp' command in Junos OS provides a real-time, continuously updated view of BGP routes as they are learned or withdrawn. Unlike static show commands, this monitor command refreshes the output dynamically, making it ideal for observing live BGP prefix updates during troubleshooting.

Exam trap

The trap here is that candidates familiar with Cisco IOS often expect a 'debug ip bgp updates' equivalent, but Junos uses 'monitor route bgp' for real-time BGP route updates, while 'monitor traffic' is for packet-level analysis, not routing protocol events.

How to eliminate wrong answers

Option B is wrong because 'monitor traffic interface ge-0/0/0' captures raw packet headers on the interface, not BGP route table updates; it shows traffic flows, not routing protocol prefix changes. Option C is wrong because 'show route advertising-protocol bgp' displays routes that the local router is advertising to a specific BGP peer, not routes being received in real time. Option D is wrong because 'show route protocol bgp' shows a static snapshot of the current BGP route table, not a live, updating feed of incoming prefixes.

6
Multi-Selecthard

Which TWO statements are true about commit operations in Junos? (Choose two.)

Select 2 answers
A.The rollback 0 command will cause a system reboot.
B.The commit command requires the candidate configuration to be syntactically correct.
C.The commit confirmed command will automatically revert to the previous configuration if not confirmed within the default 10 minutes.
D.The commit check command applies the configuration to the running system.
E.The commit at command is used to schedule a system reboot.
AnswersB, C

The commit command in Junos performs a syntactic and, in some cases, semantic validation of the candidate configuration before it is activated. If the candidate contains syntax errors, the commit fails and the active configuration remains unchanged, preventing the device from being put into an invalid state. Thus, the requirement that the candidate be syntactically correct is a fundamental safeguard of the commit operation.

Why this answer

Option B is correct because the commit command validates the candidate configuration for syntax and semantic errors before merging it into the active configuration; if the candidate is not syntactically correct, the commit fails and the running configuration remains unchanged. Option C is correct because commit confirmed activates the candidate configuration on a trial basis and, if the operator does not issue a confirming commit within the default 10-minute window, Junos automatically rolls back to the previously active configuration. Option A is wrong because rollback 0 loads the last committed (active) configuration into the candidate, it does not reboot the device.

Option D is wrong because commit check only validates the candidate configuration for syntax and commit-time errors without applying it to the running system. Option E is wrong because commit at schedules a configuration commit at a specified time, not a system reboot.

Exam trap

The trap here is confusing `commit confirmed` with a simple commit, or assuming that `rollback 0` triggers a reboot, which is a common misconception from other network operating systems where rollback might involve a reload.

7
MCQmedium

Refer to the exhibit. An administrator needs to ensure that all emergency (emerg) messages are logged to the console. Based on the configuration shown, which statement is correct?

A.Emergency messages are logged to the console only.
B.Emergency messages are logged to all destinations.
C.Emergency messages are logged only to the file 'messages'.
D.Emergency messages are logged only to the remote host.
AnswerB

Emergency messages are indeed logged to all destinations because each configured syslog target has a severity threshold that includes 'emerg'. The console's 'any warning' means it logs warning and everything more severe (emerg, alert, crit, err), the file 'messages' with 'any any' logs every severity including emerg, and the remote host with 'any critical' logs critical and above, which again includes emerg. Since all thresholds capture severity level 0, every destination receives emergency messages, making this the correct statement.

Why this answer

The configuration shown includes the 'any' facility and 'emerg' severity for the console, file, and remote host destinations. In JUNOS, when a severity level is set for a syslog destination, all messages of that severity and higher are logged. Since 'emerg' is the highest severity, it applies to all configured destinations, not just one.

Exam trap

The trap here is that candidates may assume that configuring 'emerg' for a specific destination limits logging to that destination, but in JUNOS, the severity level applies independently to each destination, and all destinations with that severity configured will receive the messages.

How to eliminate wrong answers

Option A is wrong because the configuration explicitly defines syslog destinations for console, file, and remote host, so emergency messages are not limited to the console only. Option C is wrong because the file destination is configured with 'any emerg', meaning emergency messages are logged to the file, but they are also logged to other destinations. Option D is wrong because the remote host is configured with 'any emerg', but emergency messages are not logged only to the remote host; they are logged to all destinations.

8
MCQhard

An engineer wants to apply a candidate configuration and automatically revert to the previous configuration after 10 minutes if the commit is not confirmed. Which command should be used?

A.commit confirmed 10
B.commit at 10
C.set system commit timer 10
D.commit check
AnswerA

The `commit confirmed 10` command commits the active candidate configuration immediately and starts a 10-minute rollback timer. If you do not issue a confirming commit (such as `commit confirm` or `commit`) before the timer expires, Junos automatically reverts to the previous configuration. This protects against remote device lockout by ensuring that an unconfirmed commit is undone, making it the correct way to apply a candidate config with an automatic safety rollback.

Why this answer

The `commit confirmed 10` command commits the candidate configuration and starts a 10-minute timer. If the commit is not explicitly confirmed with another `commit` command within that time, Junos automatically reverts to the previous configuration. This is the correct method for a timed automatic rollback after a commit.

Exam trap

The trap here is confusing the `commit confirmed` timer with the `commit at` scheduling feature, which sets an absolute time for a commit rather than a countdown for automatic rollback.

How to eliminate wrong answers

Option B is wrong because `commit at 10` schedules a commit to occur at the 10th minute of the hour, not a 10-minute confirmation timer. Option C is wrong because `set system commit timer 10` is not a valid Junos command; there is no such configuration statement. Option D is wrong because `commit check` only validates the syntax of the candidate configuration without committing it, so it cannot initiate a confirmed commit or automatic rollback.

9
MCQeasy

A user wants to ensure that a configuration change is applied across both Routing Engines in a dual-RE system. Which command must be used?

A.commit and-quit
B.commit confirmed
C.commit full
D.commit synchronize
AnswerD

commit synchronize is the correct command because it commits the candidate configuration on both Routing Engines in a single operation. The Junos OS first performs the commit on the local RE and then pushes the same configuration to the standby RE, verifying that both accept the change. This ensures configuration consistency across the control planes, which is essential for hitless failover and smooth operation in a dual-RE chassis.

Why this answer

The 'commit synchronize' command applies the candidate configuration to both Routing Engines simultaneously in a dual-RE system. This ensures configuration consistency across the master and backup RE, which is critical for high availability and seamless failover in Junos.

Exam trap

The trap here is that candidates often confuse 'commit synchronize' with 'commit full' or 'commit confirmed', assuming any commit command applies to both REs, but only 'commit synchronize' explicitly ensures dual-RE consistency.

How to eliminate wrong answers

Option A is wrong because 'commit and-quit' is used to commit the configuration and exit the configuration mode, but it does not synchronize changes to the backup RE. Option B is wrong because 'commit confirmed' is used to roll back a commit automatically if not confirmed within a specified time (for safe testing), not for synchronizing across REs. Option C is wrong because 'commit full' forces a full commit of the entire configuration, but it does not inherently synchronize to the backup RE; it is used to rebuild the configuration database from scratch.

10
MCQmedium

A network engineer is in configuration mode and wants to see the configuration in a format that can be directly pasted into another router to reproduce the configuration. Which output modifier should they use?

A.| display inheritance
B.| display set
C.| display xml
D.| count
AnswerB

The 'display set' pipe option transforms the entire Junos configuration into a series of 'set' commands, one per line, in configuration-mode syntax. This output can be copied and pasted directly into another Junos device's configuration mode, or used in scripts, version control, and automated provisioning, making it the standard way to capture a reproducible configuration.

Why this answer

The '| display set' output modifier converts the current Junos configuration into a series of 'set' commands. This format is directly pasteable into another router's CLI to reproduce the exact configuration, making it ideal for configuration migration or backup restoration.

Exam trap

The trap here is that candidates familiar with Cisco IOS often expect 'show running-config' to output pasteable commands, but Junos requires the explicit '| display set' modifier to achieve the same effect, leading them to choose '| display xml' or '| display inheritance' due to unfamiliarity with Junos output modifiers.

How to eliminate wrong answers

Option A is wrong because '| display inheritance' shows inherited configuration data from groups or hierarchy levels, not a pasteable command format. Option C is wrong because '| display xml' outputs the configuration in XML format, which is not directly executable as CLI commands. Option D is wrong because '| count' simply counts the number of lines in the output, providing no configuration reproduction capability.

11
MCQeasy

Refer to the exhibit. What does this command accomplish?

A.Displays help for syslog messages that include 'error'.
B.Displays all syslog messages.
C.Displays syslog messages containing the word 'error'.
D.Displays the error log file.
AnswerC

This is correct because the command combines a log display command with a match filter. For example, `show log messages | match error` displays every line from the messages log that contains the substring "error" (case-sensitive by default in Junos). This is a standard way for an operator to quickly search a system log for error-related entries without reading the whole file. It is not restricted to a specific severity class; it is simply a text-pattern match against the log output.

Why this answer

The command shown filters the output of the system log file to display only lines containing the substring 'error'. This allows the administrator to quickly see log entries related to errors, rather than viewing all messages or a dedicated error log file.

Exam trap

Candidates often assume that the 'match' operator performs a whole-word search or that there is a dedicated error log file, but in Junos it performs a substring match on the default messages log.

How to eliminate wrong answers

Option B is wrong because 'show log messages' alone displays all syslog messages, but the pipe with 'match error' filters the output, so it does not display all messages. Option C is wrong because the 'match' filter performs a substring match, not a whole-word match; it would also match messages containing 'error' as part of a larger word (e.g., 'error-handling'), so it does not strictly display only messages containing the word 'error'. Option D is wrong because there is no separate 'error log file' in Junos; syslog messages are stored in the messages log file, and this command filters that file, not a dedicated error log.

12
MCQeasy

An administrator wants to navigate to the configuration mode to make changes to the device. Which command should be used?

A.set
B.edit
C.configure
D.cli
AnswerC

The 'configure' command is the correct Junos operational-mode command used to enter configuration mode, where the active or candidate configuration can be viewed and manipulated. When you type 'configure' at the operational prompt, the CLI switches to the configuration hierarchy, and the prompt changes to 'edit' (e.g., 'user@router#'). Variants like 'configure exclusive' or 'configure private' provide additional control over locking or private copies, but the base command is the standard entry point. Thus, 'configure' is the right answer.

Why this answer

The correct command to enter configuration mode on a Juniper device is 'configure'. This command transitions the CLI from operational mode to configuration mode, allowing the administrator to make changes to the device's configuration. In JUNOS, the CLI has two distinct modes: operational mode (for monitoring and troubleshooting) and configuration mode (for modifying the active or candidate configuration).

Exam trap

The trap here is that Cisco engineers often confuse 'configure terminal' (Cisco IOS) with JUNOS commands, mistakenly thinking 'set' or 'edit' are the entry points to configuration mode, when in fact 'configure' is the required command to enter configuration mode from operational mode.

How to eliminate wrong answers

Option A is wrong because 'set' is a configuration mode command used to add or modify configuration statements, not a command to enter configuration mode itself. Option B is wrong because 'edit' is a configuration mode command that navigates to a specific hierarchy level within the configuration, not a command to enter configuration mode from operational mode. Option D is wrong because 'cli' is used to access the JUNOS CLI from the shell or to restart the CLI process, not to enter configuration mode.

13
MCQeasy

An administrator wants to view the current operational status of interface ge-0/0/1 on a Junos device. Which command displays this information?

A.show interfaces terse ge-0/0/1
B.show configuration interfaces ge-0/0/1
C.monitor interface ge-0/0/1
D.show interface ge-0/0/1
AnswerA

The show interfaces terse ge-0/0/1 command displays each interface as a single line containing the key operational states: administrative status (enabled/disabled), link state (up/down), and active protocol addresses. For the specified interface ge-0/0/1, this reveals immediately whether the interface is physically connected and configured for operation, without the noise of packet counters or detailed error statistics. It is the standard one-shot operational inquiry for a quick health check.

Why this answer

The 'show interfaces terse ge-0/0/1' command displays a concise, one-line summary of the operational status of the specified interface, including its administrative and link state, protocol status, and configured IP addresses. This is the correct command for viewing the current operational status because 'terse' filters the output to show only the essential operational details without configuration data.

Exam trap

The trap here is that Cisco engineers often expect 'show interface' (singular) to work, but Junos strictly requires the plural 'interfaces' for operational commands, and candidates may confuse 'show configuration' (which shows config) with 'show interfaces terse' (which shows operational status).

How to eliminate wrong answers

Option B is wrong because 'show configuration interfaces ge-0/0/1' displays the configured settings for the interface, not its current operational status; it shows what is configured, not whether the interface is up or down. Option C is wrong because 'monitor interface ge-0/0/1' is used for real-time, continuous monitoring of interface statistics and traffic, not for a single snapshot of operational status. Option D is wrong because 'show interface ge-0/0/1' is not a valid Junos command; the correct syntax uses the plural 'interfaces' (e.g., 'show interfaces ge-0/0/1'), and this option omits the 's', which would result in a CLI error.

14
MCQmedium

An administrator is in configuration mode and wants to see only the interfaces configuration block while editing. Which command will display just that section?

A.show interfaces
B.show
C.display set | match interfaces
D.run show interfaces
AnswerA

In configuration mode, show interfaces is the correct command to display the configured interfaces hierarchy. Unlike the operational mode command of the same name, this variant is context-sensitive and outputs only the configuration statements under the interfaces hierarchy, such as interface names, units, and family configuration. It does not show operational status or statistics, but rather the exact configured parameters, which is what an administrator reviewing the configuration needs.

Why this answer

In Junos configuration mode, the 'show interfaces' command displays only the interfaces configuration block without leaving configuration mode. This is a Junos-specific feature where 'show' commands within configuration mode show the current candidate configuration, not operational state. The command filters the output to show only the 'interfaces' hierarchy, allowing the administrator to review just that section.

Exam trap

The trap here is that candidates familiar with Cisco IOS might expect 'show running-config | section interfaces' or 'show run interface' and mistakenly choose 'run show interfaces' (Option D), which in Junos shows operational state, not configuration, or they might think 'show' alone (Option B) is sufficient, not realizing it shows the entire configuration from the current level.

How to eliminate wrong answers

Option B is wrong because 'show' alone displays the entire candidate configuration from the current hierarchy level, not just the interfaces block, which would be too verbose if the administrator is at the top of the configuration tree. Option C is wrong because 'display set | match interfaces' is a valid pipe filter but 'display set' is a configuration mode command that converts the configuration to set format; however, the correct syntax would be 'show | display set | match interfaces', and the option as written is incomplete and would not work as intended. Option D is wrong because 'run show interfaces' executes the operational mode command 'show interfaces', which displays the current operational status of interfaces (like link state, IP addresses), not the configuration block, and it temporarily exits configuration mode to run the command.

15
MCQeasy

A technician needs to display the contents of a configuration file stored on the device's hard disk. Which operational mode command should they use?

A.show configuration
B.file show
C.file list
D.view file
AnswerB

The `file show <filename>` operational command is the correct way to display the contents of a file from the Junos file system, including configuration backup files such as /config/juniper.conf.0. It reads the file directly from disk and prints it to the terminal, making it ideal for inspecting configuration files, logs, or any other text file. For a technician seeking to see the actual contents of a configuration file, this is the precise command to use.

Why this answer

The 'file show' command in Junos operational mode is used to display the contents of a file stored on the device's hard disk, such as a configuration file. Unlike 'show configuration', which displays the active candidate or committed configuration, 'file show' reads the raw file from the filesystem, making it the correct choice for viewing a stored configuration file.

Exam trap

The trap here is that candidates often confuse 'show configuration' with viewing a file on disk, but 'show configuration' only shows the configuration from the system's operational database, not the raw file contents stored on the hard disk.

How to eliminate wrong answers

Option A is wrong because 'show configuration' displays the active or candidate configuration from the system's configuration database, not the raw contents of a file on the hard disk. Option C is wrong because 'file list' only lists the names of files in a directory, not their contents. Option D is wrong because 'view file' is not a valid Junos operational mode command; the correct syntax is 'file show'.

16
MCQmedium

A network administrator has made several configuration changes and now wants to revert all uncommitted changes back to the last committed configuration. Which command should they use?

A.rollback 1
B.load override terminal
C.commit check
D.rollback 0
AnswerD

The correct action to discard all uncommitted changes is rollback 0, because the rollback database stores a snapshot of each configuration that has been committed, and index 0 always refers to the most recently committed one. This command copies that snapshot over your candidate configuration, instantly removing any changes you made after the last commit. The active (running) configuration is unaffected until you issue a commit, at which point the rollback 0 snapshot becomes the new active configuration. This is the standard Junos workflow for reverting a series of uncommitted edits.

Why this answer

The 'rollback 0' command reverts all uncommitted changes and restores the active configuration to the last committed configuration. In Junos, candidate configurations are stored in numbered rollback slots (0 being the most recent committed configuration), so 'rollback 0' discards any uncommitted edits and loads the last committed state.

Exam trap

The trap here is that candidates confuse 'rollback 0' with 'rollback 1', mistakenly thinking that 'rollback 1' reverts to the last committed configuration, when in fact 'rollback 0' is the correct slot for the most recent committed state.

How to eliminate wrong answers

Option A is wrong because 'rollback 1' loads the configuration from the second most recent committed configuration (rollback slot 1), not the last committed one, so it would revert to an older committed state rather than discarding uncommitted changes. Option B is wrong because 'load override terminal' replaces the entire candidate configuration with text entered via terminal, which is used for merging or replacing configurations, not for reverting uncommitted changes. Option C is wrong because 'commit check' validates the syntax and semantics of the candidate configuration without committing it, so it does not revert any changes.

17
MCQhard

A network administrator is trying to configure a firewall filter on a Juniper device. They enter configuration mode and type 'set firewall family inet filter BLOCK-ICMP term 1 from protocol icmp'. They then type 'set firewall family inet filter BLOCK-ICMP term 1 then reject'. After committing, they notice that ICMP traffic is not being blocked. They run 'show configuration firewall' and see the filter is present. They run 'show firewall filter BLOCK-ICMP' to see the counters and notice the packet count is zero. What is the most likely reason?

A.The protocol icmp is not correct; it should be 'icmp6'.
B.The filter is not applied to any interface.
C.The term 'then reject' should be 'then discard'.
D.The filter must be applied under the 'edit firewall' hierarchy.
AnswerB

In Junos, a firewall filter takes effect only when it is applied to an interface, typically under the "family" hierarchy using an "apply-filter" statement. Without such a binding, the filter remains defined in the configuration but is never evaluated, so all traffic—including ICMP echo requests—continues to pass. The filter must be attached to the appropriate interface and address family to actually block traffic.

Why this answer

A firewall filter in Junos must be applied to an interface to take effect. Simply configuring the filter under the 'edit firewall' hierarchy does not activate it; the filter must be referenced with a 'family inet' statement under the interface configuration (e.g., 'set interfaces ge-0/0/0 unit 0 family inet filter input BLOCK-ICMP'). Without this application, the filter exists in the configuration but never processes traffic, resulting in zero packet counts.

Exam trap

The trap here is that candidates often assume configuring a firewall filter under the 'edit firewall' hierarchy automatically activates it, similar to Cisco IOS where ACLs are applied globally or to interfaces with separate commands, but Junos requires explicit interface application for the filter to process traffic.

How to eliminate wrong answers

Option A is wrong because 'protocol icmp' is correct for IPv4 ICMP; 'icmp6' is used for IPv6 ICMP, which is not relevant here. Option C is wrong because 'then reject' is a valid action that drops packets and sends an ICMP unreachable message; 'then discard' would also drop packets but without notification, and the issue is not about the action type. Option D is wrong because the 'edit firewall' hierarchy is the correct location for configuring firewall filters; the problem is the filter is not applied to an interface, not that it is configured in the wrong place.

18
MCQmedium

Refer to the exhibit. An administrator sees the following configuration output. What is the purpose of the 'description' statement in this context?

A.It sets the SNMP ifAlias to the interface's MAC address.
B.It sets the administrative comment visible in the config.
C.It sets the interface description visible in 'show interfaces description'.
D.It sets the interface's syslog tag.
AnswerC

The `description` statement sets a free-form text label for an interface, and that label is precisely what appears under the Description column when you issue `show interfaces description`. This operational command is specifically designed to display these strings, making them useful for documenting purpose, circuit ID, or peer information without needing to view the full interface configuration. Additionally, the same value is propagated to the SNMP ifAlias object, allowing external NMS tools to read it.

Why this answer

In Junos, the 'description' statement under an interface configuration sets a text string that is displayed in the output of 'show interfaces description'. This is the standard way to provide a human-readable label for the interface, such as 'Link to Core Router A'. It does not affect SNMP, administrative comments, or syslog tags.

Exam trap

The trap here is that candidates often confuse the 'description' statement with the SNMP ifAlias or administrative comments, assuming they serve the same purpose as in other vendors' syntax, but Junos explicitly separates these functions.

How to eliminate wrong answers

Option A is wrong because the SNMP ifAlias is set by the 'snmp ifAlias' statement, not by the 'description' statement; the description does not automatically populate the MAC address. Option B is wrong because the 'description' statement is not an administrative comment; administrative comments in Junos are added using the 'annotate' command or inline comments with '/* ... */'. Option D is wrong because the 'description' statement does not set a syslog tag; syslog tags are configured under the 'syslog' hierarchy or via structured syslog messages.

19
MCQmedium

Refer to the exhibit. The interface ge-0/0/0 is configured as shown, but the interface is operationally down. Which command would provide the most detailed information about the interface status and errors?

A.show interfaces ge-0/0/0
B.show configuration interfaces ge-0/0/0
C.show interfaces ge-0/0/0 terse
D.show interfaces ge-0/0/0 extensive
AnswerD

The `show interfaces ge-0/0/0 extensive` command is the most detailed operational view available in Junos, providing a comprehensive output that includes all interface flags, encapsulation type, link status, input/output rates, per-protocol packet counters, and an exhaustive listing of error counters such as CRC errors, framing errors, and drops. It also reveals interface history like last flap time and any coincident packet loss, which is essential for troubleshooting. This is the correct choice when the exhibit refers to detailed interface information including errors, because the extensive keyword expands the output to the full diagnostic level.

Why this answer

The correct option is D, 'show interfaces ge-0/0/0 extensive', because the extensive keyword produces the most detailed output for a Junos interface, including physical and logical interface status, error counters (input/output errors, drops, framing, CRC, collisions), MAC/PHY details, and operational flags needed to diagnose why ge-0/0/0 is operationally down. Option A, 'show interfaces ge-0/0/0', gives a standard summary with basic status and counters but omits the deeper diagnostic detail. Option B, 'show configuration interfaces ge-0/0/0', only displays the configured statements and cannot reveal live operational state or errors.

Option C, 'show interfaces ge-0/0/0 terse', provides a brief one-line-per-interface summary, which is the least detailed for troubleshooting.

20
MCQmedium

A junior engineer accidentally enters 'set interfaces ge-0/0/0 unit 0 family inet address 192.0.2.1/24' in operational mode. What will happen?

A.An error message is displayed, and no changes are made.
B.The IP address is configured successfully.
C.The command is queued for later execution.
D.The CLI automatically switches to configuration mode.
AnswerA

When a `set` command is entered at the operational-mode prompt (`user@host>`), the Junos CLI parser immediately recognizes that `set` is not a valid operational command. It displays an error such as `error: unknown command` or `syntax error`, and because the command is rejected at parse time, no changes are made to the running or candidate configuration. The CLI does not attempt to reinterpret the input or apply any partial configuration.

Why this answer

In Junos OS, the 'set' command is a configuration mode command used to modify the candidate configuration. When entered in operational mode (indicated by the '>' prompt), the CLI does not recognize it as a valid operational command. Junos will immediately display an error message such as 'unknown command' and make no changes to the running or candidate configuration.

Exam trap

The trap here is that candidates accustomed to Cisco IOS, where 'configure terminal' is not required for every command and some configuration commands can be entered from privileged EXEC mode, mistakenly assume Junos behaves similarly, leading them to expect the command to succeed or the CLI to auto-switch modes.

How to eliminate wrong answers

Option B is wrong because the command is not executed; Junos strictly separates operational and configuration modes, and 'set' is not a valid operational command. Option C is wrong because Junos does not queue configuration commands for later execution; it either rejects them immediately or, if in configuration mode, applies them to the candidate configuration. Option D is wrong because the CLI does not automatically switch modes; the engineer must explicitly enter configuration mode using the 'configure' command.

21
Multi-Selecthard

Which TWO statements are true about the 'commit confirmed' command? (Choose two.)

Select 2 answers
A.It is used to schedule a commit at a future time.
B.The default timeout is 10 minutes.
C.It saves the configuration to a file before applying.
D.The timeout can be set only in multiples of 5 minutes.
E.It requires a confirmation within the specified time to make the commit permanent.
AnswersB, E

When you issue 'commit confirmed' without explicitly specifying a timeout, Junos applies a default of 10 minutes. This means the new configuration remains active for exactly 10 minutes, and if no confirmation is received before the timer expires, the system automatically restores the previous configuration. You can override this default by appending a numeric value to the command, such as 'commit confirmed 5'.

Why this answer

Option B is correct because the 'commit confirmed' command in Junos OS uses a default rollback timeout of 10 minutes, during which the configuration is active but not yet permanent. Option E is correct because the commit only becomes permanent if the administrator issues a confirming 'commit' command within that timeout window; otherwise, the device automatically rolls back to the previous configuration. Option A is incorrect because scheduling a commit for a future time is done with the 'commit at' command, not 'commit confirmed'.

Option C is incorrect because 'commit confirmed' does not save the configuration to a file before applying; it applies the candidate configuration with an automatic rollback timer. Option D is incorrect because the timeout can be set to any value from 1 to 65,535 minutes using the 'commit confirmed <minutes>' syntax, not only in multiples of 5 minutes.

Exam trap

The trap here is confusing 'commit confirmed' with 'commit at' (scheduling) or assuming the timeout is restricted to 5-minute increments, when in fact it accepts any integer minute value.

22
MCQmedium

A network engineer wants to view the OSPF log entries in real time. They type 'show log messages | match ospf' and get output, but it does not update. What should they do to see real-time updates of OSPF log entries?

A.Use 'monitor start messages | match ospf'
B.Use 'show log messages | tail'
C.Use 'monitor traffic interface ge-0/0/0'
D.Use 'request system syslog'
AnswerA

This is the correct tool for real-time OSPF log viewing. 'monitor start messages' continuously follows /var/log/messages, displaying new syslog entries as they arrive, until you press Ctrl+C or issue 'monitor stop'. Piping the output to 'match ospf' applies a case-sensitive regular-expression filter so only lines containing 'ospf' are shown on screen.

Why this answer

The 'monitor start messages' command in Junos OS enables real-time streaming of syslog messages to the terminal, similar to 'tail -f' on a log file. Piping the output through '| match ospf' filters the live feed to show only OSPF-related entries. In contrast, 'show log messages' is a one-time snapshot that does not update automatically.

Exam trap

The trap here is that candidates familiar with Cisco IOS may confuse 'show log' (which in Cisco can be used with 'monitor' for real-time output) with Junos 'show log', which is static, and overlook the Junos-specific 'monitor start' command for live log streaming.

How to eliminate wrong answers

Option B is wrong because 'show log messages | tail' only displays the last few lines of the static log file and does not provide real-time updates; it is still a one-time command. Option C is wrong because 'monitor traffic interface ge-0/0/0' captures raw packet headers on the interface, not OSPF log entries from the syslog messages file. Option D is wrong because 'request system syslog' is used to configure syslog settings (e.g., remote logging) and does not display log entries in real time.

23
Multi-Selectmedium

An engineer needs to view the current operational state of the device, including system uptime, CPU load, and memory usage. Which two commands would provide this information? (Choose two.)

Select 2 answers
A.show system processes
B.show system uptime
C.show system storage
D.show system memory
E.show chassis hardware
AnswersB, D

show system uptime is the correct command for viewing the current operational state of the system's CPU. It reports the time since the last reboot, the current time, and critically, the 1-, 5-, and 15-minute load averages, which reflect the average number of threads in the run queue over those intervals. These load averages directly indicate overall CPU demand and are the standard first check for system health on Junos.

Why this answer

Option B, 'show system uptime,' is correct because on Junos devices this command reports the current time, how long the device has been running (system uptime), and the load averages for 1, 5, and 15 minutes, directly satisfying the uptime and CPU load requirements. Option D, 'show system memory,' is correct because it displays memory utilization statistics, including total, used, and free memory, which fulfills the memory usage portion of the request. Option A, 'show system processes,' lists running processes and their CPU/memory consumption per process rather than the overall system uptime and aggregate load, so it does not match the scenario as directly.

Option C, 'show system storage,' reports disk and filesystem space usage, not CPU load or memory, and Option E, 'show chassis hardware,' displays hardware inventory and component information, neither of which provides the requested operational state.

Exam trap

The trap here is that candidates often confuse 'show system processes' with providing CPU load averages and memory totals, when in fact it only shows per-process statistics and not the aggregate system load or overall memory usage.

24
MCQmedium

A network administrator accidentally deleted a vital part of the configuration while in configuration mode. They need to revert to the previous configuration without losing recent changes that are correct. Which action should they take?

A.deactivate
B.rollback 1
C.delete
D.rollback 0
AnswerD

Rollback 0 resets the candidate configuration to match the current active committed configuration, discarding any uncommitted changes. Because the accidental deletion was never committed, this command reverts that deletion while leaving all previously committed correct changes intact. This is exactly the requirement: undo the uncommitted mistake without affecting the committed configuration. It is the standard way to abandon a set of uncommitted edits in Junos.

Why this answer

The 'rollback 0' command reverts the candidate configuration to the most recently committed configuration (the current active configuration), discarding any uncommitted changes. This allows the administrator to undo the accidental deletion without affecting any recently committed correct changes, as those are already part of the active configuration. Option B, 'rollback 1', would revert to the previous commit, which could remove recently committed correct changes if they were made in the most recent commit.

Therefore, 'rollback 0' is the safer choice when you want to preserve correct changes that have already been committed.

Exam trap

The trap is that candidates often confuse 'rollback 0' (reverts to current active config) with 'rollback 1' (reverts to previous config). While 'rollback 1' might seem like it goes back one step, it could discard recently committed changes. The correct approach to undo an uncommitted deletion while preserving committed correct changes is to use 'rollback 0'.

How to eliminate wrong answers

Option A is wrong because 'deactivate' disables a configuration statement without removing it, but it does not revert the configuration to a previous state; it only suppresses the active effect of the specified statement. Option C is wrong because 'delete' removes configuration statements from the candidate configuration, which would worsen the situation by further deleting parts of the configuration. Option D is wrong because 'rollback 0' reverts to the current active configuration (the one that was last committed), which would discard all uncommitted changes, including any correct recent modifications the administrator wants to keep.

25
MCQhard

A junior admin tries to commit a configuration but receives a 'commit error: syntax error' message. They suspect a missing closing brace. Which CLI command helps identify the exact line with the error?

A.commit check
B.rollback 0
C.load merge
D.show configuration
AnswerA

Commit check is the correct command because it validates the candidate configuration against the Junos schema without committing it. It reports syntax errors with exact line numbers and hierarchy paths, allowing you to identify and fix the problematic statement. This dry-run validation is the safest first step because it never impacts active services and pinpoints the exact source of the failure.

Why this answer

The 'commit check' command validates the candidate configuration for syntax errors without committing it. When a syntax error like a missing closing brace is present, commit check outputs the exact line number and file where the error occurs, allowing the admin to locate and fix the issue before attempting a commit again.

Exam trap

The trap here is that candidates may confuse 'show configuration' with a validation tool, not realizing it only displays the configuration text without any syntax checking, whereas 'commit check' is the dedicated command for identifying syntax errors before commit.

How to eliminate wrong answers

Option B is wrong because 'rollback 0' reverts the candidate configuration to the last committed configuration, which does not help identify the syntax error line. Option C is wrong because 'load merge' is used to merge a configuration file into the candidate configuration, not to validate syntax or pinpoint errors. Option D is wrong because 'show configuration' displays the current candidate configuration but does not perform syntax validation or highlight error lines.

26
MCQmedium

Refer to the exhibit. What is the purpose of the 'unit 0' statement?

A.Enables IPv6.
B.Sets the MTU.
C.Defines a physical interface.
D.Defines a logical interface.
AnswerD

The 'unit 0' statement in Junos defines a logical interface on a physical interface. Logical interfaces allow you to configure separate Layer 3 properties (IP addresses, protocol families, VLAN tags) on the same physical port. Unit 0 is the default logical unit for untagged traffic, and additional units (1, 2, ...) correspond to subinterfaces or VLAN-tagged logical interfaces.

Why this answer

In Junos, the 'unit 0' statement is used to define a logical interface (also known as a subinterface) under a physical interface. Every physical interface must have at least one logical unit, and unit 0 is the default logical interface that carries Layer 3 configuration such as IP addresses. This is fundamental to Junos architecture, where all protocol configurations are applied at the logical unit level, not the physical interface level.

Exam trap

The trap here is that candidates familiar with Cisco IOS might assume 'unit 0' is a physical interface or a default MTU setting, but in Junos, the unit number always defines a logical interface, and physical interfaces are configured separately without a unit keyword.

How to eliminate wrong answers

Option A is wrong because 'unit 0' does not enable IPv6; IPv6 is enabled by configuring a family inet6 address under the logical unit, not by the unit number itself. Option B is wrong because the MTU is set using the 'mtu' statement at the physical interface level (e.g., 'set interfaces ge-0/0/0 mtu 1500'), not by the 'unit 0' statement. Option C is wrong because a physical interface is defined by the interface name (e.g., ge-0/0/0), not by the 'unit' statement; 'unit 0' creates a logical subinterface on top of that physical interface.

27
MCQeasy

A technician wants to view the system log messages in real time. Which command should they use?

A.show system log
B.monitor start messages
C.start shell
D.show log messages
AnswerB

This is the correct command. It continuously outputs new lines appended to the /var/log/messages file, effectively 'tailing' the log in real time, until you cancel it with Ctrl-C or issue 'monitor stop'. It's the operational-mode command designed specifically for live log monitoring on Junos.

Why this answer

The 'monitor start messages' command is used in Junos OS to display system log messages in real time as they are generated. This is the correct command for live monitoring of system events, similar to 'tail -f' on Unix systems.

Exam trap

The trap here is that candidates familiar with Cisco IOS might expect 'show log' or 'show logging' to provide real-time output, but in Junos, 'show log messages' only shows the static file, while 'monitor start messages' is the live tail command.

How to eliminate wrong answers

Option A is wrong because 'show system log' is not a valid Junos command; the correct command to view stored logs is 'show log messages'. Option C is wrong because 'start shell' drops the user into a Unix shell environment, not a real-time log viewer. Option D is wrong because 'show log messages' displays the current contents of the messages log file, but does not provide real-time updates; it shows a static snapshot.

28
MCQhard

A senior network administrator is logged into a Juniper device in operational mode. They need to make a configuration change to the BGP group 'INTERNAL'. They type 'configure terminal' and receive 'unknown command'. They then type 'configure' and enter configuration mode. They make the needed changes and exit configuration mode using 'exit'. They then try to view the active configuration to verify the changes by typing 'show configuration | match INTERNAL'. They see no output. What is the most likely reason?

A.The command 'show configuration' only shows the candidate configuration, not the active.
B.They exited configuration mode without committing, so the changes were lost.
C.They should have used 'commit' before exiting configuration mode.
D.They need to be in configuration mode to run 'show configuration'.
AnswerC

To make configuration changes take effect in Junos, you must execute 'commit' from configuration mode. The commit command copies the candidate configuration to the active configuration, activating the changes. If the administrator exits configuration mode without committing, the active configuration remains unchanged, which explains why the changes did not appear to take effect. Therefore, the correct action before exiting is to commit the candidate configuration.

Why this answer

In Junos, configuration changes made in configuration mode are stored in a candidate configuration until explicitly committed using the 'commit' command. Exiting configuration mode with 'exit' does not discard the candidate configuration; the changes remain in the candidate but are not part of the active configuration. The 'show configuration' command displays the active (committed) configuration, which explains why no output matching 'INTERNAL' was seen.

The administrator needed to use 'commit' to activate the changes before viewing them with 'show configuration'.

Exam trap

The trap here is that candidates familiar with other platforms may expect 'exit' to discard changes (as in some OS) or that 'show configuration' shows the candidate configuration. In Junos, the candidate persists after exit, but the active configuration is only updated upon 'commit'.

How to eliminate wrong answers

Option A is wrong because 'show configuration' in operational mode displays the active (committed) configuration, not the candidate configuration; the candidate configuration is viewed with 'show | compare' or by being in configuration mode. Option B is wrong because exiting configuration mode without committing does not automatically lose changes—the candidate configuration persists until explicitly discarded with 'rollback' or overridden, but the changes are not active until committed; however, the question states they exited and then ran 'show configuration', which shows the active config, so the changes were effectively not visible because they were never committed. Option D is wrong because 'show configuration' can be run from operational mode (it is a valid operational command) and does not require being in configuration mode.

29
Multi-Selecteasy

Which TWO statements about the Junos CLI are correct?

Select 2 answers
A.The `commit confirmed` command saves the configuration permanently.
B.The pipe character (|) can be used to filter command output.
C.The `run` command allows operational mode commands to be executed from configuration mode.
D.The `set cli screen-length 0` command disables command-line editing features.
E.The `rollback 0` command reverts to the previous committed configuration.
AnswersB, C

The pipe character (|) is a fundamental Junos CLI feature that enables filtering and manipulating command output. You can use it with keywords such as `match`, `except`, `find`, `count`, `display`, and `save` to refine displayed data. For example, `show interfaces | match ge-0/0/0` shows only lines containing that interface name, making it an essential tool for quickly extracting relevant information from verbose operational output.

Why this answer

Option B is correct because the pipe character (|) in the Junos CLI is used to filter or manipulate the output of show commands, for example with match, except, find, count, or display set. Option C is correct because from configuration mode the run command (or its abbreviation run) executes operational mode commands without leaving configuration mode, e.g., run show interfaces terse. Option A is incorrect because commit confirmed applies the candidate configuration temporarily and automatically rolls back after 10 minutes unless confirmed with a second commit, so it does not save permanently.

Option D is incorrect because set cli screen-length 0 disables paging of output, not command-line editing features. Option E is incorrect because rollback 0 loads the currently active committed configuration, while rollback 1 reverts to the previous committed configuration.

30
MCQhard

You are a junior network engineer at a company that uses Juniper MX routers. You are troubleshooting a connectivity issue on a branch router. The branch router has two upstream links to the corporate network: ge-0/0/0 (10.1.1.1/30, connected to core router A) and ge-0/0/1 (10.1.1.5/30, connected to core router B). The branch router runs OSPF and has a default route learned from both upstream routers. The routing table shows two equal-cost default routes via both next hops. However, traffic from the branch to the corporate network is experiencing intermittent high latency and some packet loss. You suspect that asymmetric routing is causing issues because the return traffic is not following the same path. You want to influence the router to prefer one upstream link for all traffic to the corporate network. You have decided to adjust the OSPF metric on the branch router to make the link to core router A more preferred. You are in configuration mode on the branch router. Which single configuration change will accomplish this goal?

A.set interfaces ge-0/0/1 unit 0 family inet cost 200
B.set protocols ospf area 0 interface ge-0/0/1 passive
C.set protocols ospf area 0 interface ge-0/0/1 metric 200
D.set interfaces lo0 unit 0 family inet address 10.0.0.1/32 metric 100
AnswerC

This is the correct configuration because in JUNOS, OSPF interface metric is explicitly set with the `metric` statement under `protocols ospf` for the specific interface. By assigning a metric of 200 to ge-0/0/1, the router's OSPF cost calculation makes that interface significantly more expensive than ge-0/0/0 (which retains the default metric, typically 10 for Ethernet), thereby forcing transit traffic to prefer ge-0/0/0. This effectively shifts traffic away from ge-0/0/1 while still allowing the OSPF adjacency to remain established, so the link stays available for redundancy or less-preferred use.

Why this answer

Setting the OSPF metric on interface ge-0/0/1 to a higher value (200) increases the cost of that link, making the default route via ge-0/0/0 (which retains the default OSPF metric of 1 on a Gigabit Ethernet interface) more preferred. This influences the branch router to use the lower-cost path through core router A for all traffic to the corporate network, resolving asymmetric routing issues.

Exam trap

The trap here is that candidates often confuse the 'metric' configuration under the OSPF protocol hierarchy with the 'cost' parameter under interfaces, or mistakenly think that making an interface passive or adjusting loopback metrics will influence OSPF path selection.

How to eliminate wrong answers

Option A is wrong because the 'cost' parameter is not a valid configuration statement under 'set interfaces'; OSPF cost is configured under the OSPF protocol hierarchy, not directly on the interface. Option B is wrong because setting the interface to 'passive' prevents OSPF from sending or receiving hello packets on that interface, which would break OSPF adjacency entirely, rather than simply adjusting path preference. Option D is wrong because the 'metric' statement under the loopback interface is used for static routes or other protocols, not for OSPF interface cost; OSPF uses a cost value derived from interface bandwidth or explicitly set under 'protocols ospf'.

31
MCQeasy

During a maintenance window, an engineer makes critical changes and wants the configuration to automatically revert if they lose connectivity. Which command should they use before committing?

A.commit
B.commit confirmed
C.commit check
D.commit at
AnswerB

`commit confirmed` activates the candidate configuration for a specified confirmation period (default 10 minutes unless you append a time). The engineer must issue a second commit—either `commit` or another `commit confirmed`—before the timer expires; otherwise, Junos automatically rolls back to the previous configuration. This provides a crucial safety net for critical maintenance changes: if connectivity is lost or the change breaks something, the device restores the working configuration without manual intervention.

Why this answer

'commit confirmed', is correct because it allows the engineer to commit a configuration change with a default 10-minute rollback timer. If the engineer loses connectivity and does not confirm the commit within that period, the system automatically reverts to the previous configuration, ensuring the device remains reachable.

Exam trap

The trap here is that candidates may confuse 'commit confirmed' with 'commit check', thinking syntax validation alone provides safety, or they may assume 'commit at' offers automatic rollback, but neither command includes the confirmation-based rollback mechanism that 'commit confirmed' provides.

How to eliminate wrong answers

Option A is wrong because 'commit' applies the configuration permanently with no automatic rollback, which could leave the device unreachable if the changes break connectivity. Option C is wrong because 'commit check' only validates the syntax of the configuration without committing it, so it does not provide any automatic rollback mechanism. Option D is wrong because 'commit at' schedules a commit at a specific time but does not include a confirmation or automatic rollback feature if connectivity is lost.

32
MCQhard

After upgrading Junos, a router fails to boot with a file system error. The admin needs to recover the system from the backup partition. Which key should be pressed during boot to access the boot menu?

A.Ctrl+C
B.Esc
C.Enter
D.Space
AnswerD

Pressing the Space bar at the Junos boot prompt halts the automatic boot and displays the boot loader menu, which lists available Junos partitions and snapshots. This menu lets you select an alternate root partition, such as a prior stable snapshot or the other disk, which is essential when the current primary partition has a corrupted filesystem and cannot boot. The message 'Hit [Space] to halt, [Enter] to immediately boot' specifically identifies Space as the correct key to reach this recovery and partition-selection interface.

Why this answer

Pressing the Space bar during the boot process on a Juniper device interrupts the normal boot sequence and presents the boot menu. From this menu, the administrator can select the backup Junos partition (typically labeled as '1' or 'backup') to recover the system when the primary partition has a file system error.

Exam trap

The trap here is that candidates familiar with Cisco IOS might confuse the Juniper boot menu access (Space bar) with Cisco's Ctrl+Break or other interrupt keys, leading them to select Ctrl+C or Esc incorrectly.

How to eliminate wrong answers

Option A is wrong because Ctrl+C is used to abort the current command in the Junos CLI, not to access the boot menu during system startup. Option B is wrong because the Esc key is not used for boot menu access on Juniper devices; it may be used in other contexts like editing CLI commands. Option C is wrong because pressing Enter during boot simply continues the normal boot process without interrupting it, which would not allow selection of the backup partition.

33
MCQmedium

Refer to the exhibit. An engineer sees that the interface ge-0/0/0 has 'Admin up' and 'Link up'. What does this indicate?

A.The interface is administratively down.
B.The interface is a loopback interface.
C.The interface has an IPv6 address only.
D.The interface is up and the physical link is up.
AnswerD

The 'Admin up' state indicates the interface is administratively enabled, while 'Link up' indicates the physical layer has detected a valid link signal from the connected peer. When both are up, the interface is operationally up and able to carry traffic according to the configured protocol families. This accurately matches the exhibit, making it the correct answer.

Why this answer

When an interface shows 'Admin up' and 'Link up', it means the interface has been administratively enabled (no 'shutdown' command applied) and the physical layer has detected a carrier signal from the connected device. In Junos, this is the normal operational state for a functioning interface, confirming that both the administrative configuration and the physical link are active.

Exam trap

The trap here is that candidates may confuse 'Admin up' with 'Link up', thinking one implies the other, or incorrectly assume 'Admin up' alone means the interface is fully operational, when in fact both must be 'up' for traffic to flow.

How to eliminate wrong answers

Option A is wrong because 'Admin up' explicitly indicates the interface is administratively enabled, not down. Option B is wrong because loopback interfaces are virtual (lo0) and do not have physical link states like 'Link up'; they are always logically up unless administratively disabled. Option C is wrong because the presence of an IPv6 address is unrelated to the administrative or link status; an interface can have an IPv6 address and still show 'Admin up' and 'Link up'.

34
MCQhard

Refer to the exhibit. What does this output indicate?

A.There is a syntax error.
B.The commit succeeded.
C.The configuration is identical.
D.The candidate configuration differs from the active configuration.
AnswerD

The '+' and '-' markers in the exhibit are the Junos CLI representation of differences between two configuration revisions. When run without arguments, 'show configuration | compare' compares the active configuration (the one in use) with the candidate configuration (the one being edited but not yet committed). Lines prefixed with '-' exist only in the active configuration, while lines prefixed with '+' exist only in the candidate configuration, demonstrating that the candidate differs from the active configuration.

Why this answer

The output shows the 'show | compare' command, which displays the differences between the candidate configuration and the active (committed) configuration. The presence of lines prefixed with '+' (additions) and '-' (deletions) indicates that the candidate configuration is not identical to the active configuration, confirming that they differ.

Exam trap

The trap here is that candidates may confuse the 'show | compare' output with a commit confirmation or syntax check, when in fact it only indicates that uncommitted changes exist in the candidate configuration.

How to eliminate wrong answers

Option A is wrong because a syntax error would be reported by the commit check or commit command, not by the 'show | compare' output, which only shows configuration differences. Option B is wrong because a successful commit would make the candidate configuration identical to the active configuration, resulting in no output from 'show | compare'. Option C is wrong because if the configuration were identical, the 'show | compare' command would produce no output (empty), but the exhibit shows lines with '+' and '-', indicating differences.

35
MCQmedium

A network engineer needs to revert to the configuration that was active before the last commit. Which command accomplishes this?

A.rollback 1
B.rollback 0
C.load override
D.revert
AnswerA

Rollback 1 loads the configuration committed immediately before the current one into the candidate configuration. This allows a network engineer to undo the most recent commit and return to the prior operational state, though the resulting candidate must still be committed by running commit. Since the goal is to revert to the previous configuration, rollback 1 is the correct command.

Why this answer

The 'rollback 1' command reverts the active configuration to the configuration that was committed immediately before the most recent commit. Junos maintains up to 50 previous committed configurations (rollback 0 being the current active configuration, rollback 1 the previous, and so on). This command is the correct way to undo the last commit without manually editing the configuration.

Exam trap

The trap here is that candidates familiar with Cisco IOS may expect a 'revert' command or confuse 'rollback 0' (current config) with the previous commit, leading them to select the wrong rollback number or a non-existent command.

How to eliminate wrong answers

Option B (rollback 0) is wrong because rollback 0 refers to the currently active configuration, not the one before the last commit; using it would load the same configuration already in use. Option C (load override) is wrong because it is used to replace the entire candidate configuration with a configuration from a file or URL, not to revert to a previous commit. Option D (revert) is wrong because 'revert' is not a valid Junos CLI command; the correct command is 'rollback'.

36
MCQmedium

A network engineer needs to view the operational status of all interfaces on a Junos device, including those that are disabled. Which command should be used?

A.show interfaces
B.show configuration interfaces
C.show interfaces terse
D.monitor interface traffic
AnswerC

Correct — 'show interfaces terse' displays a single-line-per-interface summary with columns for Interface, Admin, Link, Proto, and Local address, covering both physical and logical interfaces. It explicitly shows administratively disabled interfaces with an 'admin-down' flag, while also indicating the actual operational link state ('up' or 'down'). This makes it the most efficient command for quickly surveying the operational status of all interfaces on a Junos device.

Why this answer

The 'show interfaces' command displays detailed information for all interfaces, including those that are administratively disabled. However, 'show interfaces terse' provides a concise, one-line-per-interface summary that is more efficient for quickly viewing the operational status of all interfaces, including disabled ones. For the JNCIA exam, 'show interfaces terse' is the recommended command for this purpose because it offers a clear and compact overview of interface status across the device.

Exam trap

The trap is that candidates may assume 'show interfaces' only shows enabled interfaces, but in fact it shows all interfaces including disabled. The common mistake is to choose 'show interfaces' thinking 'show interfaces terse' might omit some interfaces. However, 'show interfaces terse' also includes disabled interfaces and is more efficient for a quick overview of operational status.

How to eliminate wrong answers

Option A is wrong because 'show interfaces' displays detailed information only for interfaces that are physically present and enabled; it does not show interfaces that are administratively disabled unless they are explicitly specified. Option B is wrong because 'show configuration interfaces' displays the configured interface statements from the candidate or active configuration, not the operational status (e.g., up/down, disabled state). Option D is wrong because 'monitor interface traffic' is used for real-time traffic monitoring and statistics, not for viewing the administrative or operational status of interfaces.

37
MCQhard

During a maintenance window, an engineer needs to apply a configuration change that reverts automatically if the commit fails or the administrator does not confirm within a set time. Which feature should be used?

A.commit confirmed
B.commit check
C.commit synchronize
D.commit at 03:00
AnswerA

The 'commit confirmed' command activates the configuration immediately but initiates a rollback timer (default 10 minutes). If the engineer does not issue a 'commit confirm' within that window, Junos automatically reverts to the previous configuration, ensuring the device returns to a known-good state without manual intervention during the maintenance window. This is the correct choice because it provides a safety net for remote or risky configuration changes, allowing the engineer to verify connectivity and operations before finalizing the change.

Why this answer

The 'commit confirmed' feature allows an engineer to apply a configuration change that automatically reverts to the previous configuration if the commit is not confirmed within a specified time period (default 10 minutes). This ensures that if the commit fails or the administrator loses connectivity, the system rolls back safely without manual intervention.

Exam trap

The trap here is that candidates often confuse 'commit confirmed' with 'commit check' or 'commit synchronize', mistakenly thinking that syntax validation or dual-RE synchronization provides the same automatic rollback safety, but only 'commit confirmed' implements the timed confirmation and automatic revert mechanism.

How to eliminate wrong answers

Option B is wrong because 'commit check' only validates the syntax and semantics of the candidate configuration without actually applying it; it does not provide any automatic rollback or confirmation mechanism. Option C is wrong because 'commit synchronize' is used in a dual-RE (Routing Engine) chassis to apply the configuration to both REs simultaneously, not to provide a timed automatic rollback. Option D is wrong because 'commit at 03:00' schedules the commit to occur at a specific time but does not include a confirmation or automatic rollback feature; once committed, the change persists unless manually reverted.

38
Multi-Selecthard

Which THREE CLI features are available in Junos OS to assist with command entry?

Select 3 answers
A.? (question mark) for context-sensitive help.
B.Ctrl+R to repeat the last command.
C.Up arrow key to recall previous commands.
D.Ctrl+Z to undo the last command.
E.Tab key for command completion.
AnswersA, C, E

In Junos CLI, the question mark (?) is a context-sensitive help feature that displays all valid commands, subcommands, or arguments at the current input position, along with brief descriptions. For instance, typing 'show ?' lists every possible option following the 'show' command, aiding discoverability without requiring manual lookup. This interactive help is indispensable for constructing valid commands in an unfamiliar operating system like Junos.

Why this answer

Option A is correct because in Junos OS CLI, typing ? at any point displays context-sensitive help listing valid commands, keywords, or options available at that position. Option C is correct because the Up arrow key scrolls backward through the command history buffer, allowing the user to recall and re-execute previously entered commands. Option E is correct because the Tab key performs command and option completion, automatically finishing a partially typed command or keyword when the entry is unambiguous.

Option B is incorrect because Ctrl+R is not a Junos OS command-recall feature; command history is navigated with the Up/Down arrow keys or the show cli history command. Option D is incorrect because Ctrl+Z is not an undo function in Junos OS; it is not a supported command-entry aid in the CLI.

Exam trap

The trap here is that candidates familiar with Cisco IOS may mistakenly associate Ctrl+Z with undo functionality (since in IOS it exits configuration mode) or Ctrl+R with repeating commands, but Junos uses different key bindings and relies on the Up arrow and Tab for command recall and completion.

39
MCQeasy

A junior network engineer is learning JunOS CLI and wants to view the last 10 lines of the system log file. They log into the device and type 'show log messages | last 10'. They receive an error: 'unknown pipe command'. Which pipe command should they use instead?

A.| last 10
B.| display 10
C.| head 10
D.| tail 10
AnswerD

The 'tail' pipe command in Junos CLI displays the last N lines of the output buffer. Appending '| tail 10' to a show command returns the final 10 lines, which is exactly what the engineer needs to view the most recent information. This is a standard Junos pipe filter for limiting output to the end of the result.

Why this answer

In JunOS CLI, the pipe command to display the last N lines of output is '| tail N', not '| last N'. The 'tail' command filters the output to show only the final lines, analogous to the Unix 'tail' utility. Option D is correct because '| tail 10' will show the last 10 lines of the system log file.

Exam trap

The trap here is that candidates familiar with Cisco IOS may expect '| last 10' to work, but JunOS uses Unix-style pipe commands where 'tail' is the correct filter for displaying the end of output.

How to eliminate wrong answers

Option A is wrong because '| last 10' is not a valid JunOS pipe command; it triggers an 'unknown pipe command' error. Option B is wrong because '| display 10' is not a valid pipe command; 'display' is used for XML or set format output, not for line count filtering. Option C is wrong because '| head 10' would show the first 10 lines, not the last 10, and is the opposite of what the engineer needs.

40
MCQhard

You are a network engineer for a service provider that recently deployed a Juniper MX router at a new Point of Presence (PoP). The router is used to aggregate customer connections and exchange routes with upstream providers via BGP. After the initial configuration, you notice that the router is not learning any routes from one of the upstream BGP peers. You have verified that the BGP session is established (state Established) and that the peer is sending routes. You suspect that the issue might be related to the firewall filter or routing policy. You want to determine if any inbound routes are being rejected and why. Which command would provide the most direct information about why routes are being rejected?

A.show route protocol bgp
B.show route receive-protocol bgp 192.0.2.1
C.show bgp summary
D.show firewall filter <filter-name>
AnswerB

show route receive-protocol bgp 192.0.2.1 shows the exact updates received from that specific neighbor before they pass through the routing table, including the import-policy decision. The output marks each prefix with an 'A' (accept) or 'I' (ignore/reject) and, when rejected, prints the policy name and reason. This makes it the right diagnostic for verifying why a route from 192.0.2.1 was not installed, because it exposes the BGP input policy evaluation on every received prefix.

Why this answer

'show route receive-protocol bgp 192.0.2.1', is correct because it displays the exact routes received from a specific BGP peer along with any policy or filter actions applied (e.g., reject, accept). This command directly shows whether routes are being rejected and the reason (e.g., due to an import policy or firewall filter), making it the most direct diagnostic tool for the described issue.

Exam trap

The trap here is that candidates often assume 'show bgp summary' or 'show route protocol bgp' will reveal route rejection details, but they only show aggregated statistics or installed routes, not the per-peer policy decisions that cause routes to be hidden or rejected.

How to eliminate wrong answers

Option A is wrong because 'show route protocol bgp' displays all BGP routes in the routing table, but it does not show why routes were rejected or filtered before installation. Option C is wrong because 'show bgp summary' only shows BGP session state and statistics (e.g., prefixes received), not the specific routes or rejection reasons. Option D is wrong because 'show firewall filter <filter-name>' shows firewall filter counters and rules, but it does not directly correlate to BGP route rejection unless the filter is explicitly applied to the BGP session; it is indirect and less specific than the receive-protocol command.

41
MCQhard

A junior engineer is troubleshooting a routing issue and wants to see the route table for IPv4 unicast routes. Which command will display this information?

A.show route table inet.0
B.show route table inet6.0
C.show route forwarding-table
D.show route protocol bgp
AnswerA

The `show route table inet.0` command is the correct choice because `inet.0` is the default IPv4 unicast routing table on Junos. When a junior engineer needs to investigate a generic routing issue involving IPv4 destinations, this command displays the active routes, protocol next-hops, and preference/metric values that determine how packets are forwarded. It directly exposes whether the expected route is present, hidden, or missing, which is the first step in diagnosing reachability problems. Unlike protocol-specific or forwarding-table views, this master table includes all protocols that contribute to IPv4 forwarding decisions.

Why this answer

The command 'show route table inet.0' displays the IPv4 unicast route table in Junos. The inet.0 table is the default routing table for IPv4 unicast routes, containing all active routes learned via various protocols (e.g., OSPF, BGP, static). This command is the standard way to view the IPv4 unicast routing information base (RIB) on Juniper devices.

Exam trap

The trap here is that candidates often confuse the routing table (RIB) with the forwarding table (FIB), or they may think 'show route protocol bgp' shows all routes, when it only shows routes from a specific protocol.

How to eliminate wrong answers

Option B is wrong because 'show route table inet6.0' displays the IPv6 unicast route table, not IPv4 unicast routes. Option C is wrong because 'show route forwarding-table' displays the forwarding table (FIB), which contains the actual next-hop information used for packet forwarding, not the route table (RIB) that stores all learned routes. Option D is wrong because 'show route protocol bgp' filters the route table to show only routes learned via BGP, not the entire IPv4 unicast route table.

42
MCQmedium

Refer to the exhibit. An engineer notices high error counts on the interface. Based on the output, what is the most likely cause?

A.The interface has a hardware fault.
B.The interface is experiencing excessive broadcasts.
C.The interface is operating in half-duplex mode.
D.The interface is connected to a device configured for half-duplex.
AnswerD

When a local full-duplex interface connects to a remote half-duplex device, the remote cannot simultaneously transmit and receive, and it performs CSMA/CD to avoid collisions. If the remote begins transmitting while the full-duplex side is also transmitting, the half-duplex side detects a collision and may truncate or jam the frame; the full-duplex side then observes a late collision or undersized frame. Because the local link is full-duplex, collisions can only originate from a remote device operating half-duplex, making a duplex mismatch the correct explanation for the high error counts.

Why this answer

The output shows high error counts on the interface, which is a classic symptom of a duplex mismatch. When one end of an Ethernet link operates in full-duplex and the other in half-duplex, collisions occur on the half-duplex side because it expects to wait for the carrier to be clear before transmitting, while the full-duplex side transmits at any time. This leads to frame check sequence (FCS) errors, alignment errors, and runts on the half-duplex interface.

Option D is correct because the local interface is likely full-duplex (default on modern Juniper devices), and the connected device is configured for half-duplex, causing the mismatch.

Exam trap

The trap here is that candidates often assume high error counts always indicate a hardware fault (Option A), but in JNCIA-JUNOS, the specific error types (e.g., collisions, late collisions) point to a duplex mismatch, not a physical layer failure.

How to eliminate wrong answers

Option A is wrong because a hardware fault typically manifests as a high rate of CRC errors or interface resets, not the specific pattern of errors seen in a duplex mismatch (e.g., excessive collisions and late collisions). Option B is wrong because excessive broadcasts cause high CPU utilization and broadcast storms, not physical-layer errors like FCS or alignment errors on the interface counters. Option C is wrong because if the local interface were operating in half-duplex, it would not be the cause of the high error counts; rather, the mismatch with a full-duplex peer would still be the issue, and the question states the engineer notices high error counts on the interface, implying the local interface is likely full-duplex.

43
MCQhard

Refer to the exhibit. An engineer runs the command shown. What does this output indicate?

A.The candidate configuration matches the committed configuration.
B.The candidate configuration has an IP address change.
C.The rollback 0 configuration is being displayed.
D.The interface ge-0/0/0 has been deleted.
AnswerB

In the diff output, the `-` line shows the committed IP address (10.0.0.1) being removed from interface ge-0/0/0, and the `+` line shows the candidate IP address (192.0.2.1) replacing it under `family inet`. This is a classic unified diff format: the `-` line is the old value, the `+` line is the new value. Since only the address line changes while the interface and its family structure remain, this correctly identifies an IP address change.

Why this answer

The output shows the candidate configuration differs from the committed configuration, as indicated by the 'show | compare' command displaying a change under the [edit interfaces ge-0/0/0 unit 0 family inet] hierarchy. Specifically, it shows the address 192.168.1.1/24 being replaced with 192.168.1.2/24, which is an IP address change. This confirms option B is correct because the candidate configuration has an IP address change that has not yet been committed.

Exam trap

The trap here is that candidates often confuse 'show | compare' with 'show configuration | display set' or assume no output means no candidate changes exist, but in reality, 'show | compare' outputs only differences, and any output indicates a pending change that does not match the committed configuration.

How to eliminate wrong answers

Option A is wrong because the output shows a difference between the candidate and committed configurations (the IP address change), so they do not match; a matching configuration would produce no output from 'show | compare'. Option C is wrong because the command 'show | compare' compares the candidate configuration to the active (committed) configuration, not specifically to rollback 0; while rollback 0 is the most recent commit, the command compares to the current active configuration, and the output does not indicate a rollback operation. Option D is wrong because the output shows the interface ge-0/0/0 still exists with a unit and family inet configuration; only the IP address is changed, not the interface being deleted.

44
MCQmedium

An engineer wants to view system log messages as they are generated in real-time. Which command should they use?

A.start log messages
B.monitor log messages
C.request system log
D.show log messages
AnswerB

The 'monitor log messages' command is the correct operational command for real-time log viewing. It streams new log entries to the terminal as they are written by the syslog process, similar to the Unix 'tail -f' command. The engineer can stop the streaming output by pressing Ctrl+C, and can optionally use the 'match' filter to display only relevant messages.

Why this answer

The 'monitor log messages' command in Junos OS provides a real-time view of system log messages as they are generated, similar to the 'tail -f' command on Unix systems. It streams new log entries to the terminal without requiring manual refresh, making it ideal for live monitoring of events.

Exam trap

The trap here is that candidates familiar with Cisco IOS may confuse 'show log' (which in Cisco shows a static log) with Junos 'show log messages', and incorrectly assume it provides real-time output, while 'monitor log messages' is the correct real-time equivalent.

How to eliminate wrong answers

Option A is wrong because 'start log messages' is not a valid Junos command; the correct command to begin logging is 'set system syslog' or similar configuration, not a real-time view. Option C is wrong because 'request system log' is used for operations like rotating or archiving log files, not for live viewing. Option D is wrong because 'show log messages' displays the contents of the /var/log/messages file at the time of execution, but does not provide real-time updates; it shows a static snapshot.

45
Multi-Selecteasy

Which TWO commands can be used to view the current operational state of an interface? (Choose two.)

Select 2 answers
A.show interfaces extensive
B.show log
C.show configuration interfaces
D.show interfaces terse
E.show route
AnswersA, D

This is correct because 'show interfaces extensive' reads the live runtime state from the device and displays the physical link status, administrative status, media type, speed, MTU, and detailed error and discard counters. Unlike configuration output, it shows what the interface is actually doing right now, including carrier transitions, alarms, and other operational details. It is more verbose than 'show interfaces terse', but both commands query current operational data, so it is one of the two valid choices.

Why this answer

The 'show interfaces extensive' command displays detailed operational state information, including current status, errors, and statistics. The 'show interfaces terse' command provides a concise operational view showing interface names, administrative status, link status, and protocol families. Both commands query the current operational state of interfaces from the Junos OS kernel.

Exam trap

The trap here is that candidates confuse 'show configuration interfaces' (which shows the intended configuration) with commands that show the actual operational state, leading them to select option C instead of the correct operational commands.

46
MCQmedium

A network engineer needs to commit a configuration change but wants to ensure the change can be easily reverted if it causes issues. Which approach should the engineer take?

A.Use the 'commit and-quit' command to apply changes.
B.Use the 'commit confirmed' command with a timeout.
C.Use the 'commit check' command before committing.
D.Use the 'rollback 0' command after committing.
AnswerB

The 'commit confirmed' command with a timeout (e.g., 'commit confirmed 5') activates the configuration for a temporary interval, defaulting to 10 minutes. If the administrator does not issue a confirming 'commit' before the timer expires, Junos automatically rolls back to the previous configuration. This self-reverting behavior prevents permanent lockouts caused by misconfigured access settings.

Why this answer

The 'commit confirmed' command allows the engineer to commit a configuration change with a default timeout of 10 minutes (configurable). If the change causes issues and the engineer does not confirm the commit within the timeout period, Junos automatically reverts to the previous active configuration, providing a safe rollback mechanism.

Exam trap

The trap here is that candidates often confuse 'commit check' (syntax validation) with a rollback mechanism, or assume 'rollback 0' provides automatic reversion, when in fact it requires manual execution after the fact.

How to eliminate wrong answers

Option A is wrong because 'commit and-quit' is not a valid Junos command; the correct command is 'commit and-quit' to exit the configuration mode after committing, but it does not provide any automatic rollback capability. Option C is wrong because 'commit check' only validates the syntax and semantics of the candidate configuration without applying it; it does not allow reverting a change after it has been committed. Option D is wrong because 'rollback 0' reverts to the most recently committed configuration, but it must be issued manually after the change is already active, and it does not provide an automatic or timed rollback.

47
Multi-Selecthard

A junior administrator is learning to navigate the Junos CLI. Which three statements about CLI modes are correct? (Choose three.)

Select 3 answers
A.Operational mode is indicated by a > prompt.
B.Configuration mode is entered using the 'configure' command.
C.The 'commit' command is available in both operational and configuration modes.
D.You can switch from configuration mode to operational mode using the 'exit configuration' command.
E.You can execute operational mode commands from configuration mode by prefixing with 'run'.
AnswersA, B, E

The Junos CLI displays a distinct prompt suffix for each mode. When the prompt ends with a greater-than sign (>)—for example, user@host>—the CLI is in operational mode, which is the default after login. This mode provides commands for monitoring, measuring, and troubleshooting the device, such as 'show', 'ping', and 'request'. Unlike configuration mode, operational mode does not allow changes to the active configuration.

Why this answer

Option A is correct because Junos operational mode is indeed identified by the '>' prompt (e.g., user@host>), which is where monitoring and show commands are executed. Option B is correct because the 'configure' command is the standard way to enter configuration mode from operational mode, changing the prompt to '#' (e.g., user@host#). Option E is correct because from configuration mode you can run operational commands by prefixing them with 'run', such as 'run show interfaces', without leaving configuration mode.

Option C is incorrect because 'commit' is only available in configuration mode, not operational mode. Option D is incorrect because the proper way to return to operational mode is the 'exit' command (or 'exit configuration-mode' in some contexts), not 'exit configuration'.

Exam trap

The trap here is that candidates familiar with Cisco IOS may assume the 'commit' command is available in both modes, but in Junos it is strictly a configuration-mode command, and the 'exit configuration' command is a common misremembering of the correct syntax 'exit' or 'exit configuration-mode'.

48
MCQhard

During troubleshooting, an engineer needs to view real-time logging messages on a Junos device. Which command should be used?

A.file show /var/log/messages
B.monitor start messages
C.show log messages
D.traceoptions
AnswerB

monitor start messages streams real-time log messages to the terminal from the messages log file, satisfying the requirement to view live logging. It differs from show log messages, which displays existing entries rather than continuously tailing new output.

Why this answer

The 'monitor start messages' command enables real-time, tail-like display of the /var/log/messages log file on a Junos device, allowing the engineer to view new log entries as they are generated. This is the correct command for live troubleshooting because it continuously updates the terminal with incoming syslog messages, unlike static file viewing commands.

Exam trap

The trap here is that candidates often confuse 'show log messages' (a static snapshot) with 'monitor start messages' (a live streaming view), because both involve the 'messages' log file, but only the latter provides real-time output.

How to eliminate wrong answers

Option A is wrong because 'file show /var/log/messages' displays the entire contents of the log file at once, not in real-time, and is not suitable for monitoring live events. Option C is wrong because 'show log messages' displays the current contents of the messages log file but does not provide a live, streaming view; it shows a snapshot. Option D is wrong because 'traceoptions' is a configuration statement used to enable debug logging for specific protocols or features, not a command to view real-time log output.

49
MCQmedium

An administrator needs to see which interfaces are configured and their current operational status in a concise format. Which command provides this information?

A.show interfaces
B.show configuration interfaces
C.show interfaces terse
D.show interfaces descriptions
AnswerC

`show interfaces terse` is the correct command because it outputs a concise, one-line summary for each interface and logical unit, including the interface name, admin status (enabled/disabled), and protocol status (up/down). This makes it easy to see at a glance which interfaces are configured—they appear with their configured logical units and address families—and their operational state. It is the standard Junos command for a quick, human-readable snapshot of the interface configuration and status, without the clutter of full interface details.

Why this answer

The 'show interfaces terse' command displays a concise, table-like output listing all interfaces (including logical units) along with their administrative status (up/down) and operational status (up/down). This is the most efficient way to see both configured interfaces and their current state in a compact format, as required by the question.

Exam trap

The trap here is that candidates familiar with Cisco IOS often expect 'show interfaces' to be the concise status command, but in Junos, 'show interfaces terse' is the equivalent of 'show ip interface brief' — a distinction that catches those who assume cross-platform command similarity.

How to eliminate wrong answers

Option A is wrong because 'show interfaces' provides detailed per-interface statistics and configuration, which is verbose and not concise. Option B is wrong because 'show configuration interfaces' displays the configured interface hierarchy from the candidate or active configuration, not the current operational status. Option D is wrong because 'show interfaces descriptions' shows only the description field for interfaces, not their operational status.

50
MCQmedium

An engineer is editing the candidate configuration on a Junos device and wants to verify the changes she has made so far without leaving configuration mode or committing anything. She also needs to see only the lines she has added or modified relative to the active configuration. Which command accomplishes this?

A.show configuration | display set
B.commit check
C.rollback 0
D.show | compare
AnswerD

In configuration mode, show | compare displays the difference between the candidate configuration and the active (committed) configuration, showing added lines with a plus sign and removed lines with a minus sign. It does not commit or exit configuration mode, and it lets the engineer confirm exactly what would change before running commit.

Why this answer

The compare pipe in configuration mode shows the delta between the candidate and active configurations, marking additions and deletions. It is the standard way to preview pending edits before a commit, working entirely within configuration mode. Commands that render the whole candidate, validate syntax, or revert the candidate do not satisfy the need to see only modified lines.

Exam trap

The trap here is assuming that viewing the candidate configuration with display set or validating it with commit check reveals which lines changed, when only the compare pipe shows the delta against the active configuration.

51
MCQhard

What permission bit must be included in a custom login class to allow a user to execute the ping command?

A.view
B.control
C.system
D.network
AnswerD

The 'network' permission is the specific permission bit that enables users to run network diagnostic tools, including ping, traceroute, and similar utilities. Without this bit, these commands are not available even if other permissions are present. Therefore, to create a custom login class that can ping, you must include the 'network' permission.

Why this answer

Network. In Junos, the 'network' permission bit controls access to network diagnostic commands such as ping, traceroute, and ssh. Without this permission, a user cannot execute these commands even if they have other permissions like view or control.

Exam trap

The trap here is that candidates often assume 'view' or 'control' permissions are sufficient for basic troubleshooting commands, but Junos requires the specific 'network' permission bit for any command that sends or receives network traffic.

How to eliminate wrong answers

Option A is wrong because 'view' permission allows read-only access to configuration and operational data, but does not permit execution of diagnostic commands like ping. Option B is wrong because 'control' permission allows modifying the configuration and managing system operations, but does not grant access to network diagnostic commands. Option C is wrong because 'system' permission controls system-level commands such as halt, reboot, and file system operations, not network diagnostic tools like ping.

52
MCQeasy

A network engineer needs to revert to the configuration that was committed two commits ago. Which rollback number should they use?

A.rollback 0
B.rollback 2
C.rollback 1
D.rollback 3
AnswerB

Junos maintains up to 50 previous committed configurations in its rollback log. The rollback command uses an index where 0 is the current active configuration, 1 is the most recent previous commit, and 2 is the commit before that. Thus, "rollback 2" precisely stages the configuration from two commits ago into the candidate, allowing the engineer to then commit it and revert to that earlier state.

Why this answer

The rollback command in Junos OS allows reverting to a previously committed configuration. The rollback number corresponds to the number of commits ago, starting with rollback 0 for the most recent commit, rollback 1 for the commit before that, and so on. Therefore, to revert to the configuration committed two commits ago, the correct rollback number is 2.

Exam trap

The trap here is confusing the rollback number with the number of commits to revert, where candidates might mistakenly think rollback 1 means one commit ago (which is correct) but then incorrectly apply that logic to two commits ago by choosing rollback 1 instead of rollback 2.

How to eliminate wrong answers

Option A is wrong because rollback 0 refers to the most recent committed configuration, not two commits ago. Option C is wrong because rollback 1 refers to the configuration committed one commit ago, not two. Option D is wrong because rollback 3 refers to the configuration committed three commits ago, which is further back than needed.

53
MCQeasy

An administrator wants to see the differences between the candidate configuration and the active configuration. Which command should be used?

A.show | display set
B.run show configuration
C.show | compare
D.show configuration
AnswerC

`show | compare` is the correct Junos CLI command to display the differences between the candidate configuration and the active committed configuration. It outputs a unified diff-style output with `+` for lines added in the candidate and `-` for lines removed, making pending changes immediately visible. If there are no uncommitted changes, the command produces no output, but when changes exist, this is the definitive tool for reviewing them.

Why this answer

The 'show | compare' command displays the differences between the candidate configuration and the active (committed) configuration. This is the standard Junos method for reviewing uncommitted changes before committing them, as it outputs a diff-style output showing lines added, deleted, or modified.

Exam trap

The trap here is that candidates often confuse 'show | compare' with 'show configuration' or 'show | display set', thinking they all show differences, but only 'show | compare' provides the explicit diff output between candidate and active configurations.

How to eliminate wrong answers

Option A is wrong because 'show | display set' reformats the output of the 'show' command into 'set' commands, but does not compare configurations. Option B is wrong because 'run show configuration' is used to display the active configuration on the RE (Routing Engine) from the shell, not to compare candidate and active configurations. Option D is wrong because 'show configuration' displays the entire active configuration, not the differences between candidate and active.

54
MCQeasy

An engineer needs to view the current active configuration of a Junos device without making any changes. Which CLI mode should they use?

A.Operational mode
B.Privileged mode
C.Configuration mode
D.Exclusive configuration mode
AnswerA

Operational mode is the default Junos CLI state, where an engineer can execute read-only commands such as 'show configuration' and 'show interfaces'. It provides a complete view of the active configuration without permitting any direct edits. To change the configuration, the engineer must explicitly enter configuration mode, making operational mode strictly for monitoring and verification.

Why this answer

Operational mode is the default CLI mode in Junos, used for monitoring, troubleshooting, and viewing the current active configuration without making any changes. Commands in this mode are read-only and do not modify the device's configuration. The active configuration is the one currently running on the device, and it can be viewed using commands like 'show configuration' in operational mode.

Exam trap

The trap here is that candidates familiar with Cisco IOS may confuse 'Privileged mode' (which allows viewing and some changes) with Junos operational mode, but Junos strictly separates read-only (operational) and read-write (configuration) modes.

How to eliminate wrong answers

Option B is wrong because 'Privileged mode' is a Cisco IOS term, not a Junos CLI mode; Junos uses operational mode for read-only access and configuration mode for changes. Option C is wrong because Configuration mode is used to modify the candidate configuration, not just view the active configuration; entering this mode allows changes to be made. Option D is wrong because Exclusive configuration mode is a variant of configuration mode that locks the configuration database to prevent other users from making changes, but it still allows modifications and is not for read-only viewing.

55
MCQeasy

A user wants to see all available commands starting with 'show'. Which key should they press after typing 'show'?

A.Space
B.?
C.Tab
D.Ctrl-P
AnswerB

The '?' character is the Junos CLI's context-sensitive help trigger. When typed after a partial command like 'sh', the CLI immediately displays a list of all available commands that begin with that prefix, such as 'show' and 'show log'. This differs from completion or recall functions because it explicitly shows all matching possibilities rather than filling in one result or retrieving history.

Why this answer

In the Junos CLI, pressing the '?' key after typing a partial command like 'show' displays a list of all available commands or options that start with that string. This is the standard context-sensitive help feature in Junos, which is distinct from other CLI behaviors.

Exam trap

The trap here is that candidates familiar with Cisco IOS may expect the Tab key to list completions, but in Junos, Tab only auto-completes a unique command, while '?' is used to list all available options.

How to eliminate wrong answers

Option A is wrong because pressing the Space bar after 'show' would execute the command if it is complete, or cause an error if incomplete; it does not display available commands. Option C is wrong because the Tab key in Junos CLI performs command completion (auto-fills the command if unique), not listing all available options. Option D is wrong because Ctrl-P is a readline shortcut that recalls the previous command from the history buffer, not related to showing available commands.

56
MCQeasy

A junior engineer uses 'set system host-name R1' in configuration mode and exits without committing. After a reboot, the hostname reverts to the original. What step did the engineer miss?

A.They must use 'run set system host-name' instead.
B.They must save the configuration to a file.
C.They must reboot after setting the hostname.
D.They must commit the configuration with 'commit'.
AnswerD

Junos uses a candidate configuration model: all `set` commands are staged in the candidate configuration until explicitly activated. The `commit` command validates the candidate, applies it to the active configuration, and writes it as the permanent configuration that persists across reboots. For the hostname change to become effective immediately and survive a future reboot, you must run `commit` from configuration mode. Without this step, the change remains staged but inactive.

Why this answer

In Junos OS, configuration changes made in configuration mode are stored in a candidate configuration and do not take effect until explicitly committed using the 'commit' command. Rebooting without committing discards all uncommitted changes, causing the hostname to revert to its original value. Option D is correct because the engineer must issue 'commit' to activate the new hostname permanently.

Exam trap

The trap here is that candidates familiar with Cisco IOS may assume changes take effect immediately in configuration mode, but Junos requires an explicit 'commit' to activate changes, and rebooting does not save uncommitted changes.

How to eliminate wrong answers

Option A is wrong because 'run set system host-name' is not a valid command; 'run' executes operational-mode commands, while 'set system host-name' is a configuration-mode command. Option B is wrong because saving the configuration to a file (e.g., with 'save') is not required for activation; the candidate configuration is automatically stored in memory and only needs to be committed to become the active configuration. Option C is wrong because rebooting is unnecessary and does not commit changes; in fact, rebooting without committing discards uncommitted changes, which is the opposite of the desired outcome.

57
MCQhard

Tom is a junior network engineer who recently joined a service provider. He is tasked with configuring a new BGP session on an MX240 router to peer with a customer. He accesses the router via SSH and enters configuration mode using the `configure` command. He then navigates to `edit protocols bgp` and begins configuring. He sets the local AS number, adds a group named 'CUSTOMER-A', and specifies the peer IP address 192.0.2.2. After completing the configuration, he attempts to commit by typing `commit`. The system returns a syntax error and indicates that the configuration is invalid. Tom is unsure what went wrong and wants to identify the error before making any changes. What should Tom do next?

A.Issue the `commit check` command to validate the candidate configuration syntax.
B.Issue the `show | compare` command to see the differences from the previous committed configuration.
C.Issue the `run show configuration protocols bgp` command to display the current active configuration.
D.Issue the `edit protocols bgp` command again to re-enter the hierarchy and review the settings.
AnswerA

The `commit check` command performs the same full syntax and validation checks as `commit` but without actually activating the candidate configuration. If there is a syntax error, it will immediately report the specific line and the nature of the problem, allowing you to fix it before any impact to the live network. This is the correct first step when a user sees an invalid configuration error.

Why this answer

The correct action is to issue the `commit check` command (option A), which validates the candidate configuration for syntax and semantic errors without actually committing it, exactly what Tom needs to identify the invalid statement before making changes. On Junos, `commit` itself failed with a syntax error, so running `commit check` will report the specific error location and reason while leaving the active configuration untouched. Option B (`show | compare`) only shows the diff between the candidate and the last committed configuration and does not validate syntax or explain the error.

Option C (`run show configuration protocols bgp`) displays the active committed BGP configuration, not the candidate, so it would not reveal Tom's invalid edits. Option D merely re-enters the BGP hierarchy and shows the candidate text but performs no validation, so it would not identify the syntax error.

58
MCQmedium

You are a network engineer responsible for a Juniper MX240 router in a data center. The router is running Junos 18.2R1 and you need to upgrade it to 19.1R2 to fix a critical security vulnerability. You establish an SSH session to the router and enter configuration mode to prepare the upgrade. While in configuration mode, you notice that the candidate configuration contains several uncommitted changes from a previous engineer that attempted to modify BGP settings but introduced a syntax error. The candidate configuration fails any commit operation due to this error. The currently active configuration is stable and the router is handling production traffic. The upgrade process requires you to change the boot media and specify the new image. Which action should you take to clear the candidate configuration and proceed with the upgrade?

A.Reboot the router to clear the candidate configuration and then start the upgrade.
B.Execute the 'rollback 0' command to discard the candidate and replace it with the active configuration, then proceed with the upgrade commands.
C.Run the 'load override terminal' command and paste the active configuration from memory, then commit and upgrade.
D.Use the 'commit force' command to override the syntax error and commit the candidate, then perform the upgrade.
AnswerB

The 'rollback 0' command is the correct recovery action because it discards the entire candidate configuration and copies the last committed active configuration into the candidate, giving you a clean, syntactically valid starting point. This operation is local to the configuration database and does not affect the running system until you commit, so you can safely rollback, verify with 'show configuration', and then proceed with the standard software upgrade commands such as 'request system software add'.

Why this answer

The 'rollback 0' command discards all uncommitted changes in the candidate configuration and replaces it with the active, committed configuration. This clears the syntax error without affecting the running router, allowing you to proceed with the upgrade commands (e.g., 'request system software add') without a reboot or forced commit.

Exam trap

The trap here is that candidates may think a reboot is needed to clear uncommitted changes (Option A) or that 'commit force' can bypass syntax errors (Option D), when in fact Junos provides a dedicated 'rollback' command to safely discard the candidate configuration without impacting the active state.

How to eliminate wrong answers

Option A is wrong because rebooting the router would disrupt production traffic and is unnecessary; the candidate configuration is not stored in active memory that requires a reboot to clear. Option C is wrong because 'load override terminal' is used to load a configuration from a terminal session, not to discard the candidate; it would require manually pasting the active config, which is error-prone and redundant when 'rollback 0' exists. Option D is wrong because 'commit force' does not override syntax errors; it only bypasses certain validation warnings (e.g., missing root password), and a syntax error in the candidate will still cause the commit to fail.

59
MCQmedium

An administrator is troubleshooting an interface and wants to see real-time packet statistics. Which command should they use?

A.traceoptions
B.show interfaces statistics
C.show interfaces extensive
D.monitor interface
AnswerD

The 'monitor interface' operational command is specifically designed to display interface statistics in real time, refreshing periodically so the administrator can see counters update as traffic flows. It shows live packet and error counters, making it ideal for troubleshooting dynamic issues such as intermittent link errors or traffic spikes. This is the correct choice for real-time interface statistics.

Why this answer

The 'monitor interface' command in Junos provides real-time, continuously updated packet statistics for a specified interface, making it the correct choice for live troubleshooting. Unlike static commands, it refreshes statistics every second until interrupted, allowing the administrator to observe traffic patterns as they occur.

Exam trap

The trap here is that candidates often confuse 'show interfaces statistics' (a static snapshot) with real-time monitoring, failing to recognize that only 'monitor interface' provides live, continuously updated data.

How to eliminate wrong answers

Option A is wrong because 'traceoptions' is used for debugging control-plane protocols (e.g., OSPF, BGP) by logging events to a file, not for viewing real-time interface packet statistics. Option B is wrong because 'show interfaces statistics' displays a static snapshot of cumulative packet counts at the moment the command is issued, not real-time updates. Option C is wrong because 'show interfaces extensive' provides detailed static output including errors and queue information, but it does not refresh automatically or show live statistics.

60
Multi-Selecteasy

Which THREE modes can be used to enter configuration mode in Junos? (Choose three.)

Select 3 answers
A.configure static
B.configure private
C.configure shared
D.configure dynamic
E.configure exclusive
AnswersB, C, E

`configure private` opens a private configuration session, giving the user an exclusive candidate configuration that is merged into the shared one only on commit. This satisfies the stem's requirement for a valid configuration-mode entry command, alongside `configure` and `configure exclusive`, without affecting other users' uncommitted changes.

Why this answer

In Junos, the CLI configuration mode can be entered with different locking behaviors: 'configure private' (option B) gives each user a private candidate configuration so concurrent users don't interfere, 'configure shared' (option C) lets multiple users edit the same shared candidate configuration, and 'configure exclusive' (option E) locks the candidate configuration so only one user can make changes at a time. These three are valid Junos commands for entering configuration mode with the specified locking semantics. Options A ('configure static') and D ('configure dynamic') are not valid Junos configuration-mode commands; there is no 'static' or 'dynamic' configure variant in Junos.

Exam trap

The trap here is that candidates may confuse Junos configuration modes with Cisco IOS configuration modes (like 'configure terminal' or 'configure memory'), leading them to select non-existent options like 'configure static' or 'configure dynamic'.

61
Multi-Selectmedium

Which THREE pipe modifiers can be used to filter command output? (Choose three.)

Select 3 answers
A.no-more
B.count
C.display set
D.match
E.except
AnswersB, D, E

The count pipe modifier computes and displays the total number of lines in the command output, replacing all content with a single integer. This effectively filters out every line's actual data and presents only a summary statistic. It is useful for quick size assessment—e.g., counting routes or interfaces—without viewing individual entries, but it does not selectively include or exclude lines based on a pattern.

Why this answer

In network CLI environments such as Junos, the pipe modifier 'count' (option B) filters command output by returning only the number of lines the preceding command produces, which is a valid way to filter/summarize output. The 'match' modifier (option D) filters output by displaying only lines that match a given regular expression, directly narrowing the returned text. The 'except' modifier (option E) filters output by excluding lines that match a specified pattern, the inverse of match, and is likewise a legitimate output filter.

The unmarked options do not belong: 'no-more' (option A) is a terminal display control that disables paging, not a filter, and 'display set' (option C) is a configuration display format command, not a pipe modifier for filtering output.

Exam trap

The trap here is that candidates often confuse pipe modifiers that change display behavior (like 'no-more' or 'display set') with those that actually filter the output content, leading them to select 'no-more' as a filtering modifier when it only controls pagination.

62
MCQmedium

An engineer is troubleshooting a connectivity issue and wants to see real-time interface traffic statistics. Which command provides continuous updates?

A.show interface statistics
B.monitor interface traffic
C.monitor start messages
D.show interfaces extensive
AnswerB

The monitor interface traffic command enters a real-time monitoring mode that periodically refreshes the interface throughput, packet rate, and error counters on screen. Its continuous updates let an engineer watch how counters change moment by moment, making it straightforward to correlate a spike or drop with other events. This is the most direct way to confirm whether traffic is actually passing on the interface at the time of the problem.

Why this answer

The `monitor interface traffic` command in Junos OS provides a real-time, continuously updating display of interface traffic statistics, making it the correct choice for live monitoring. Unlike static commands that show a single snapshot, this command refreshes the output at a default interval (typically 1 second) until the user interrupts it with Ctrl+C.

Exam trap

The trap here is that candidates often confuse `monitor interface traffic` with `show interface statistics`, assuming both provide live updates, but only the `monitor` command offers continuous real-time output in Junos OS.

How to eliminate wrong answers

Option A is wrong because `show interface statistics` displays a static snapshot of interface counters at the moment the command is executed, not continuous updates. Option C is wrong because `monitor start messages` is used to monitor system log messages in real time, not interface traffic statistics. Option D is wrong because `show interfaces extensive` provides a detailed static output of interface configuration and statistics, but does not offer continuous, live updates.

Ready to test yourself?

Try a timed practice session using only User Interfaces questions.