Courseiva
Junos OS Fundamentals →hardMultiple Choice

JN0-106 Junos OS Fundamentals Practice Question

Exhibit

Refer to the exhibit.
user@router> show log messages | match "sshd"
Mar 20 10:20:00 router sshd[1234]: Failed password for root from 192.168.1.100 port 22 ssh2
Mar 20 10:20:10 router sshd[1235]: Failed password for root from 192.168.1.100 port 22 ssh2
Mar 20 10:20:20 router sshd[1236]: Failed password for root from 192.168.1.100 port 22 ssh2

Refer to the exhibit. An administrator notices repeated failed login attempts. What should be configured to mitigate this attack?

⚠ Common exam trap

Candidates often confuse mitigation (stopping an ongoing attack) with prevention (hardening against future attacks), leading them to choose retry limits or password changes instead of the immediate IP-blocking solution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a firewall filter to block the source IP

A firewall filter can block traffic from the source IP address of the repeated failed login attempts, preventing further access from that host. This is a direct and immediate mitigation against an ongoing brute-force attack, as it stops the attacker's traffic at the network layer before it reaches the SSH or login service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set login retry limit

    Why it's wrong here

    Setting a login retry limit only throttles authentication attempts; it does not block the attacker's IP at the packet level. The current brute-force stream is already in flight and continues until the limit is hit, and even then the attacker can simply source a new IP or continue at a lower rate. Thus it lacks the immediate, IP-level enforcement needed to mitigate an active attack.

  • ✓

    Configure a firewall filter to block the source IP

    Why this is correct

    Creating a firewall filter that discards (or rejects) traffic from the offending source IP at the interface or loopback level causes Junos to drop those packets before they reach the SSH or login process. This stops the brute-force traffic immediately at Layer 3/4, preserving the SSH service for legitimate sources. On Junos, applying an input filter to the loopback interface (lo0) is a common method to filter management-plane traffic, which directly halts further attempts from that specific IP.

  • ✗

    Disable SSH

    Why it's wrong here

    Disabling SSH shuts down the service entirely, which stops the attack but also blocks all administrative access via SSH—an unacceptable operational impact. Disabling SSH on a Junos device removes the management path for legitimate administrators and may be an overreaction. A more granular security response targets the attacker's source IP without disrupting authorized access.

  • ✗

    Change the root password

    Why it's wrong here

    Changing the root password invalidates the credentials the attacker is trying to guess for the current attack, but it only helps if the attacker is targeting the old password. It does nothing to stop the password-guessing packets from reaching the device, and if the attacker is using a dictionary of common passwords or has other compromised credentials, they may succeed again immediately. The brute-force traffic continues to consume CPU and management-plane resources, so source-IP filtering or other rate-limiting is necessary.

Quick reference

OSI Model Reference

LayerNamePDUKey Protocols / Devices
7ApplicationDataHTTP, HTTPS, DNS, SMTP, FTP, SSH
6PresentationDataTLS / SSL, JPEG, ASCII encoding
5SessionDataNetBIOS, RPC, SIP
4TransportSegment / DatagramTCP, UDP
3NetworkPacketIP, ICMP, OSPF — Routers
2Data LinkFrameEthernet, Wi-Fi, PPP — Switches, Bridges
1PhysicalBitsCables, NICs, Hubs, Repeaters

About these practice questions

Courseiva writes every JN0-106 question from scratch — 326 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This JN0-106 practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JN0-106 exam.