JN0-106 Networking Fundamentals Practice Question
Which TWO statements about VLANs are correct? (Choose two.)
⚠ Common exam trap
The trap here is that Juniper Networks often tests the misconception that a switch port can belong to only one VLAN, but this is only true for access ports—trunk ports can carry multiple VLANs, and some platforms support voice VLANs that allow a port to be in both a data and voice VLAN simultaneously.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Trunk links can carry traffic for multiple VLANs.
Option C is correct because a trunk link (typically 802.1Q) tags frames so it can carry traffic for multiple VLANs between switches or to a router/switch, unlike an access port. Option D is correct because each VLAN defines its own broadcast domain, so broadcasts are confined within the VLAN and do not propagate to other VLANs, which is the core purpose of VLAN segmentation. Option A is incorrect because MAC addresses are not shared across VLANs; each VLAN maintains its own MAC address table and forwarding domain. Option B is incorrect because a VLAN does not strictly require a unique IP subnet — VLANs can be Layer 2 only, and multiple VLANs can theoretically share a subnet in unusual designs, though best practice is one subnet per VLAN. Option E is incorrect because a single switch port can belong to multiple VLANs when configured as a trunk (or in some vendor-specific modes), not only one VLAN.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MAC addresses are shared across VLANs.
Why it's wrong here
MAC addresses are tied to individual network interfaces, and a switch maintains a separate MAC forwarding table (or forwarding database) per VLAN. A host's MAC address is not globally 'shared' across VLANs; the switch learns it in the context of a specific VLAN and uses it only when forwarding frames within that VLAN. Even if a device is multi-homed into multiple VLANs, it uses distinct MAC addresses for each interface or virtual interface, so the original statement is incorrect.
- ✗
Each VLAN must be assigned a unique IP subnet.
Why it's wrong here
VLANs operate at Layer 2 and do not inherently require an IP subnet; IP addressing is a Layer 3 concern. While it is a common best practice to map one VLAN to one IP subnet to simplify routing, you could have multiple VLANs sharing the same subnet or a single VLAN with multiple subnets, though this often creates routing complexities. The word 'must' makes the statement false because it is a recommendation, not a protocol requirement.
- ✓
Trunk links can carry traffic for multiple VLANs.
Why this is correct
Trunk links are designed to multiplex traffic from multiple VLANs onto a single physical link using IEEE 802.1Q VLAN tagging. Each Ethernet frame is tagged with a VLAN ID, allowing the receiving switch to correctly associate the frame with its VLAN even though frames from many VLANs travel over the same cable. This enables efficient switch-to-switch and switch-to-router connections without needing separate cables per VLAN.
- ✓
VLANs segment a network into separate broadcast domains.
Why this is correct
A VLAN is a logical segmentation of a switched network into distinct broadcast domains. When a switch receives a broadcast frame, it forwards it only to ports in the same VLAN, not to all ports on the switch, thus confining broadcast traffic and preventing broadcast storms from affecting the entire network. This isolation also limits the flooding of unknown unicast traffic, so each VLAN behaves like an independent Layer 2 network.
- ✗
A single switch port can belong to only one VLAN.
Why it's wrong here
While an access port is indeed assigned to a single untagged VLAN, a trunk port can be a member of many VLANs simultaneously by carrying tagged traffic for each of those VLANs. Trunk ports use VLAN tagging (802.1Q) to identify which VLAN a frame belongs to, so a single switch port can belong to multiple VLANs. The statement is therefore an overgeneralization that ignores trunk links, which are common in enterprise networks.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every JN0-106 question from scratch — 326 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This JN0-106 practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JN0-106 exam.