JN0-106 Junos OS Fundamentals Practice Question
Exhibit
Refer to the exhibit. user@router> show log messages | match "sshd" Mar 20 10:20:00 router sshd[1234]: Failed password for root from 192.168.1.100 port 22 ssh2 Mar 20 10:20:10 router sshd[1235]: Failed password for root from 192.168.1.100 port 22 ssh2 Mar 20 10:20:20 router sshd[1236]: Failed password for root from 192.168.1.100 port 22 ssh2
Refer to the exhibit. An administrator notices repeated failed login attempts. What should be configured to mitigate this attack?
⚠ Common exam trap
Candidates often confuse mitigation (stopping an ongoing attack) with prevention (hardening against future attacks), leading them to choose retry limits or password changes instead of the immediate IP-blocking solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a firewall filter to block the source IP
A firewall filter can block traffic from the source IP address of the repeated failed login attempts, preventing further access from that host. This is a direct and immediate mitigation against an ongoing brute-force attack, as it stops the attacker's traffic at the network layer before it reaches the SSH or login service.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set login retry limit
Why it's wrong here
Setting a login retry limit only throttles authentication attempts; it does not block the attacker's IP at the packet level. The current brute-force stream is already in flight and continues until the limit is hit, and even then the attacker can simply source a new IP or continue at a lower rate. Thus it lacks the immediate, IP-level enforcement needed to mitigate an active attack.
- ✓
Configure a firewall filter to block the source IP
Why this is correct
Creating a firewall filter that discards (or rejects) traffic from the offending source IP at the interface or loopback level causes Junos to drop those packets before they reach the SSH or login process. This stops the brute-force traffic immediately at Layer 3/4, preserving the SSH service for legitimate sources. On Junos, applying an input filter to the loopback interface (lo0) is a common method to filter management-plane traffic, which directly halts further attempts from that specific IP.
- ✗
Disable SSH
Why it's wrong here
Disabling SSH shuts down the service entirely, which stops the attack but also blocks all administrative access via SSH—an unacceptable operational impact. Disabling SSH on a Junos device removes the management path for legitimate administrators and may be an overreaction. A more granular security response targets the attacker's source IP without disrupting authorized access.
- ✗
Change the root password
Why it's wrong here
Changing the root password invalidates the credentials the attacker is trying to guess for the current attack, but it only helps if the attacker is targeting the old password. It does nothing to stop the password-guessing packets from reaching the device, and if the attacker is using a dictionary of common passwords or has other compromised credentials, they may succeed again immediately. The brute-force traffic continues to consume CPU and management-plane resources, so source-IP filtering or other rate-limiting is necessary.
Quick reference
OSI Model Reference
| Layer | Name | PDU | Key Protocols / Devices |
|---|---|---|---|
| 7 | Application | Data | HTTP, HTTPS, DNS, SMTP, FTP, SSH |
| 6 | Presentation | Data | TLS / SSL, JPEG, ASCII encoding |
| 5 | Session | Data | NetBIOS, RPC, SIP |
| 4 | Transport | Segment / Datagram | TCP, UDP |
| 3 | Network | Packet | IP, ICMP, OSPF — Routers |
| 2 | Data Link | Frame | Ethernet, Wi-Fi, PPP — Switches, Bridges |
| 1 | Physical | Bits | Cables, NICs, Hubs, Repeaters |
Go deeper
Related to this question
About these practice questions
Courseiva writes every JN0-106 question from scratch — 326 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This JN0-106 practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JN0-106 exam.