Courseiva
Junos OS Fundamentals →mediumMultiple Select

JN0-106 Junos OS Fundamentals Practice Question

Which two statements correctly describe Junos OS login classes? (Choose two.)

⚠ Common exam trap

Test-takers frequently confuse login classes with user accounts, assuming classes are automatically applied or immutable, when in fact they are manually assigned and fully configurable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

They are defined under the [edit system login class] hierarchy.

Option B is correct because login classes are configured at the [edit system login class class-name] hierarchy in Junos OS, where you define permissions and other login parameters. Option D is correct because a login class can include or exclude the configure permission, thereby restricting whether a user can enter configuration mode. Options A, C, and E are incorrect: login classes do not force operational-mode-only access (that depends on permissions such as configure), they are not automatically assigned to all users by default (each user must be associated with a class, otherwise the default class applies), and they can be modified or deleted after creation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    They allow users to enter only operational mode.

    Why it's wrong here

    Login classes define permissions that determine whether a user can access operational mode, configuration mode, or both. The default login class, 'super-user', permits both operational and configuration commands, while a custom class can be configured with a permission set that includes or excludes the 'configure' permission. Therefore, a login class does not inherently restrict a user to operational mode only; it is the specific permissions within the class that control mode access, and many classes allow both modes depending on their configuration.

  • ✓

    They are defined under the [edit system login class] hierarchy.

    Why this is correct

    Login classes are indeed configured under the [edit system login class] hierarchy in the Junos OS configuration. This hierarchy allows an administrator to define named classes, such as 'super-user', 'read-only', or custom classes, and assign permissions to each. For example, the command 'set system login class myclass permissions view' creates a class under that hierarchy, confirming that this is the definitive location for defining login class attributes in Junos.

  • ✗

    They are automatically assigned to all users by default.

    Why it's wrong here

    Login classes are not automatically assigned to all users; they must be explicitly associated with a user account. In Junos OS, a user is created under the [edit system login user] hierarchy, and the 'class' statement is required to specify which login class the user belongs to. Without this explicit assignment, the user account is not fully configured and cannot be used for login, so there is no implicit default class applied universally to all users.

  • ✓

    They can restrict access to configuration mode.

    Why this is correct

    Login classes have a 'permissions' field that can explicitly deny access to configuration mode. By setting permissions to include only operational commands (e.g., 'view' or 'operational') and excluding the 'configure' permission, a class restricts the user from entering configuration mode. For example, a class with 'permissions view' allows 'show' commands but not 'configure' or 'edit', demonstrating that login classes are a key mechanism for enforcing administrative access boundaries.

  • ✗

    They cannot be modified after creation.

    Why it's wrong here

    Login classes are fully modifiable after they are created. An administrator can use the 'set' or 'edit' commands in configuration mode to change a class's permissions, add or remove allowed commands, or alter its description. For instance, 'set system login class myclass permissions configure' adds the ability to enter configuration mode to an existing class, and the change takes effect immediately for future logins, so the idea that they are immutable is incorrect.

About these practice questions

One of 326 original JN0-106 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This JN0-106 practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JN0-106 exam.