Courseiva
Junos OS Fundamentals →mediumMultiple Choice

JN0-106 Junos OS Fundamentals Practice Question

Exhibit

Refer to the exhibit.

Configuration snippet:
system {
    syslog {
        file messages {
            any notice;
            authorization info;
        }
        file interactive-commands {
            interactive-commands any;
        }
    }
}

Refer to the exhibit. Which log file will contain messages about authorization events?

⚠ Common exam trap

Candidates often confuse 'interactive-commands' (which logs CLI commands) with authorization logging, assuming that because commands require authorization, the log file would contain authorization events, but Junos separates command logging from authorization event logging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

messages

In Junos, the 'messages' log file (typically /var/log/messages) records system log messages, including authorization events such as user login failures, privilege escalation attempts, and configuration changes. Authorization events are generated by the system's authentication, authorization, and accounting (AAA) framework and are logged at the 'info' severity level by default, which is captured in the messages file. The 'interactive-commands' log file specifically records CLI commands entered by users, not authorization events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    messages

    Why this is correct

    The `file messages` syslog configuration in the exhibit contains an explicit `authorization info` statement, which tells the Junos syslog daemon to capture authorization events at priority `info` and above. Because the event shown is an authorization event, it matches this filter and is written to `/var/log/messages`. No other file in the exhibit has an authorization filter, so `messages` is the correct destination.

  • ✗

    Both messages and interactive-commands

    Why it's wrong here

    The `file interactive-commands` block, as shown in the exhibit, is configured to log only the `interactive-commands` facility (CLI command entries). It does not include an `authorization` facility/severity filter, so authorization events are not sent to `interactive-commands`. Only `messages` has the matching `authorization info` filter, so 'both' is not supported by the configuration.

  • ✗

    Neither

    Why it's wrong here

    Authorization events are not ignored by default when an explicit filter exists. The exhibit shows `authorization info` under `file messages`, which is a specific, valid filter that ensures authorization messages are logged. Therefore, at least one file—the `messages` file—will contain the event, so 'neither' is false.

  • ✗

    interactive-commands

    Why it's wrong here

    The `interactive-commands` file is intended for logging interactive CLI commands, such as `show` or `configure` commands, through the `interactive-commands` facility. The exhibit's configuration for that file does not include an `authorization` statement, so authorization events are not routed there. They are routed to the `messages` file because of its `authorization info` filter.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This JN0-106 question is part of Courseiva's 326-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This JN0-106 practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JN0-106 exam.