Courseiva

Juniper Networks Enterprise Routing and Switching, Professional (JNCIP-ENT, JN0-650) (JNCIP-ENT) (JNCIP-ENT) — Questions 175

332 questions total · 5pages · All types, answers revealed

Page 1 of 5

Page 2
1
Multi-Selectmedium

Which TWO types of OSPF areas allow the generation of Type-7 LSAs? (Choose two)

Select 2 answers
A.Standard OSPF Non-backbone Area
B.Not-So-Stubby Area (NSSA)
C.Standard OSPF Backbone Area (Area 0)
D.NSSA Totally Stubby Area
E.OSPF Stub Area
AnswersB, D

NSSAs allow ASBRs to inject external routes using Type-7 LSAs.

Why this answer

Type-7 LSAs are exclusively generated within Not-So-Stubby Areas (NSSA) and NSSA totally stubby areas by ASBRs connecting external routes.

2
MCQeasy

You are troubleshooting MAC address learning on an EX Series switch and want to display dynamic MAC entries learned specifically on interface ge-0/0/5. Which operational command should you use?

A.show mac-address-table interface ge-0/0/5
B.show ethernet-switching table port ge-0/0/5
C.show l2-learning interface ge-0/0/5 macs
D.show bridge mac-table interface ge-0/0/5
AnswerD

This command filters the bridging table by the specified interface.

Why this answer

The command 'show bridge mac-table interface ge-0/0/5' displays MAC addresses learned on that interface.

3
MCQeasy

You are configuring private VLANs (PVLANs) on a Juniper EX switch to isolate customer ports from one another while sharing a common gateway. Which VLAN type is configured to allow communication only with promiscuous ports?

A.Primary VLAN
B.Community VLAN
C.Isolated VLAN
D.Target VLAN
AnswerC

Isolated VLAN ports can only communicate with the promiscuous port.

Why this answer

Isolated VLAN ports can only communicate with promiscuous ports.

4
Multi-Selectmedium

Which TWO factors can cause an EVPN instance on a Junos device to fail in importing incoming Type-2 MAC/IP routes? (Choose two)

Select 2 answers
A.Configuring an incorrect BGP router ID on the remote peer.
B.Enabling MAC limit suppression on access ports.
C.The EVPN routing instance is missing or has an incorrect instance-type configured.
D.Incorrect loopback MTU settings on the physical underlay interfaces.
E.A mismatch between the import route target on the receiving PE and the export route target on the advertising PE.
AnswersC, E

Without a properly configured EVPN routing instance, the routing table cannot accept EVPN route imports.

Why this answer

Route import failures in EVPN are typically caused by mismatched Route Targets between the advertising and receiving PE, or missing/incorrect EVPN routing instance configurations.

5
MCQeasy

Which standard Junos forwarding class is reserved for control plane traffic such as routing protocols and management traffic?

A.expedited-forwarding
B.assured-forwarding
C.best-effort
D.network-control
AnswerD

network-control is the default class for high-priority control plane traffic.

Why this answer

In Junos, the network-control forwarding class is reserved for control plane traffic to ensure it receives priority handling.

6
Multi-Selecteasy

Which TWO BGP attributes are classified as well-known mandatory attributes that must be recognized by all BGP implementations? (Choose TWO)

Select 2 answers
A.COMMUNITIES
B.MULTI_EXIT_DISC
C.AS_PATH
D.LOCAL_PREF
E.NEXT_HOP
AnswersC, E

AS_PATH is a well-known mandatory attribute.

Why this answer

The well-known mandatory BGP attributes are AS_Path, NEXT_HOP, and ORIGIN. Among the choices, AS_PATH and NEXT_HOP are well-known mandatory attributes.

7
MCQhard

You are troubleshooting a scenario where multi-field classifiers and behavior aggregate classifiers are both configured on the same ingress interface. In what order does Junos process classification?

A.Junos rejects configurations where both BA and MF classifiers are applied to the same interface
B.Both classifiers are executed simultaneously in hardware without precedence
C.Behavior aggregate classification is evaluated first, and multi-field classification can override the result
D.Multi-field classification is evaluated first, followed by behavior aggregate classification
AnswerC

BA classifies based on CoS bits; MF filters can subsequently override the class.

Why this answer

Junos processes Behavior Aggregate (BA) classification first, followed by Multi-Field (MF) classification which can override the BA result.

8
MCQeasy

An engineer needs to ensure that a Junos router balances BGP traffic across multiple paths with unequal IGP costs. Which feature must be configured to achieve this?

A.Setting the MED attribute to zero on all incoming EBGP updates.
B.BGP multipath with the 'as-path-relax' or equivalent multipath options enabled.
C.Configuring static routes with identical preferences for every BGP prefix.
D.Enabling BGP Route Reflection on the local routing engine.
AnswerB

Relaxing strict AS path or IGP cost checks allows multipath load balancing across paths with different metrics.

Why this answer

By default, BGP multipath requires equal cost. To allow paths with different costs, 'as-path-multipath' or variance-based multipath configurations are required depending on specific Junos platform support, but generally standard multipath requires equal IGP cost unless specific multipath relaxation options are set.

9
Multi-Selectmedium

Which THREE statements are true regarding voice VLAN technologies and implementation on Junos EX Series switches? (Choose three.)

Select 3 answers
A.EX switches can advertise voice VLAN information to IP phones using LLDP-MED network policies.
B.An access port can be configured with a native data VLAN and a voice VLAN to support an IP phone with an attached PC.
C.Voice VLAN configuration allows voice traffic to be isolated into a dedicated broadcast domain separate from standard user data.
D.Voice VLANs are restricted exclusively to routed core switch ports.
E.Voice VLANs require the switch to operate in transparent mode without MAC learning.
AnswersA, B, C

LLDP-MED network policies distribute voice VLAN info to endpoints.

Why this answer

Voice VLAN features allow separation of voice and data traffic, support both tagged and untagged configurations, and integrate with discovery protocols.

10
MCQmedium

You want to filter OSPF Type-3 Summary LSAs leaving Area 1 on an ABR running Junos OS. Where must this export policy be applied?

A.Under [edit protocols ospf area <name> area-range <prefix> export]
B.Under [edit protocols ospf area <name> prefix-export]
C.Under [edit protocols ospf lsa-filter]
D.Under [edit protocols ospf export]
AnswerA

Type-3 LSA generation for aggregated prefixes can be controlled and filtered using the area-range export policy on the ABR.

Why this answer

To filter Type-3 summary LSAs generated by an ABR as they leave an area, you apply the export policy using the 'set protocols ospf area <area-id> area-range <prefix> export <policy-name>' hierarchy.

11
MCQmedium

An engineer is troubleshooting a newly configured EVPN-VXLAN multi-homed setup where the Designated Forwarder (DF) is constantly toggling between two PE routers. What is the most likely cause of this DF churn?

A.Incorrect MAC mobility sequence numbers.
B.Mismatched Ethernet Segment Identifiers (ESIs) or unstable BGP connectivity between PEs.
C.Exceeding the maximum MAC address table limit.
D.Using VXLAN instead of MPLS data plane encapsulation.
AnswerB

If ESIs match but BGP session stability or Type-4 route advertisements fluctuate, the DF election re-runs continuously, causing churn.

Why this answer

DF churn typically occurs when BGP sessions or reachability between the PE routers flapping, or when the timers (such as wait-for-timer) are misconfigured, causing conflicting DF election states.

12
MCQeasy

Which command allows an administrator to view the active BGP routes along with their associated communities on a Junos device?

A.show route protocol bgp extensive
B.show bgp group summary
C.show bgp neighbor extensive
D.show route forwarding-table protocol bgp
AnswerA

The 'extensive' output includes detailed route attributes such as communities, AS path, and origin.

Why this answer

The 'show route protocol bgp' command with the 'extensive' modifier displays detailed path attributes including BGP communities.

13
MCQhard

During an audit of a multiregion enterprise network using PIM Sparse-Mode, an engineer needs to ensure that only designated Bootstrap Routers (BSRs) can inject candidate-RP information into the domain. Which Junos configuration feature should be applied on the core routers to secure the BSR domain?

A.Configure an RP-reachability policy under protocols pim static rp.
B.Configure 'set protocols pim bsr-candidate interface' with a strict metric.
C.Configure 'set protocols pim interface <interface> bsr-edge' on downstream boundary interfaces.
D.Configure a firewall filter on the loopback interface matching PIM protocol traffic destined for 224.0.0.13.
AnswerC

The bsr-edge statement prevents BSR messages from crossing into or out of specific interfaces, establishing a security boundary for the PIM domain.

Why this answer

To protect the PIM domain from rogue BSR messages or unauthorized candidate-RP announcements, Junos allows configuring BSR edge boundaries or using a bsr-candidate policy to filter incoming bootstrap messages.

14
MCQeasy

Which command displays the global status, TLV counters, and operational state of LLDP on an EX Series switch?

A.show protocols lldp summary
B.show system lldp status
C.show lldp
D.show ethernet-switching lldp
AnswerC

show lldp is the primary command to check global LLDP status and statistics.

Why this answer

show lldp provides system-wide operational data for LLDP.

15
Multi-Selectmedium

Which TWO commands are used to troubleshoot OSPF issues on Junos devices? (Choose two)

Select 2 answers
A.show ip ospf interface
B.show ospf neighbor
C.show ospf database
D.show protocols ospf status
E.show route ospf-table
AnswersB, C

Displays OSPF neighbor states and adjacency progress.

Why this answer

Operational commands like 'show ospf neighbor' and 'show ospf database' are standard for troubleshooting OSPF adjacencies and LSDB status.

16
Multi-Selecthard

Which THREE statements describe the behavior of critical authentication (fallback) when a RADIUS server becomes unreachable on an EX Series switch? (Choose three)

Select 3 answers
A.The switch moves authenticating clients into a designated critical VLAN or applies a critical profile.
B.The local switch user database is permanently deleted to save memory during server failure.
C.Critical authentication can be configured separately for 802.1X and MAC RADIUS authentication methods.
D.Clients that are already successfully authenticated are immediately disconnected and forced to re-authenticate.
E.The switch continues to probe the primary RADIUS servers at configured intervals to detect recovery.
AnswersA, C, E

Correct. Critical fallback assigns clients to predefined critical parameters.

Why this answer

Critical authentication allows clients to be placed into a critical VLAN or access profile when RADIUS servers are unresponsive, preventing complete network lockout.

17
MCQmedium

You are troubleshooting a Q-in-Q tunneling implementation on an MX Series router where customer VLAN tags are being stripped instead of preserved across the service provider core. Under which configuration hierarchy should the 'vlan-tagging' and 'pop-pop' or 'push' actions be applied on the interface?

A.set interfaces ge-0/0/1 flexible-vlan-tagging
B.set protocols l2-learning interface ge-0/0/1 q-in-q
C.set bridge-domains bd vlan-id-list 10
D.set interfaces ge-0/0/1 encapsulation flexible-ethernet-services
AnswerA

flexible-vlan-tagging is required on the physical interface to process multiple VLAN tags.

Why this answer

For Q-in-Q tunneling on Juniper routing and switching platforms, flexible VLAN tagging is configured under 'interfaces <interface> flexible-vlan-tagging'.

18
MCQmedium

What is the default number of forwarding classes available on Juniper MX Series routers equipped with Modular Port Concentrators (MPCs)?

A.4
B.8
C.64
D.16
AnswerC

Junos supports a maximum of 64 forwarding classes on MPC hardware.

Why this answer

Junos supports up to 64 forwarding classes on modern MPC-based hardware platforms, though default configurations typically use a subset.

19
MCQhard

You are troubleshooting a BGP route selection issue on a Junos device. Two otherwise identical paths are received from external peers. According to the standard BGP route selection algorithm implemented by Junos, which tie-breaking attribute is evaluated immediately AFTER comparing the Router ID (RID) of the advertising routers?

A.AS path length
B.Multi-Exit Discriminator (MED)
C.Cluster list length
D.Lowest neighbor IP address
AnswerD

The Junos BGP decision process evaluates the lowest neighbor IP address immediately after comparing the router ID.

Why this answer

In the Junos BGP route selection algorithm, after comparing local preference, AS path length, origin, MED, eBGP over iBGP, IGP metric to next hop, and router ID (lowest router ID), the next step evaluates the neighbor IP address (lowest neighbor IP address).

20
MCQeasy

Which operational command is used to verify the operational status and peer state of MSDP sessions on a Junos device?

A.show igmp summary
B.show msdp summary
C.show pim summary
D.show multicast summary
AnswerB

This command displays MSDP peer addresses, connection states, and uptime.

Why this answer

The 'show msdp summary' command provides an overview of MSDP peers, state, and connection status.

21
MCQmedium

An administrator wants to configure a static Rendezvous Point (RP) with IP address 192.168.100.1 for all multicast groups on a Junos router. Which configuration accomplishes this?

A.set routing-options multicast rp 192.168.100.1
B.set protocols pim static-rp address 192.168.100.1
C.set protocols igmp rp address 192.168.100.1
D.set protocols pim rp static address 192.168.100.1
AnswerD

This configures a static RP address for all groups under PIM.

Why this answer

Static RPs are defined under protocols pim rp static address. Group ranges can also be specified.

22
MCQhard

When configuring OSPFv3 authentication, which mechanism is natively utilized in modern Junos implementations since OSPFv3 relies on IPv6 AH/ESP or OSPFv3 Authentication Trailer (RFC 7166)?

A.set protocols ospf3 area 0.0.0.0 interface xe-0/0/0.0 md5 key 123
B.set protocols ospf3 security ipsec spi 256
C.set protocols ospf3 interface xe-0/0/0.0 password 123
D.set protocols ospf3 authentication-trailers sa-name AUTH-KEY
AnswerD

Authentication trailers are configured using the authentication-trailers option in OSPFv3.

Why this answer

Junos supports the OSPFv3 Authentication Trailer defined in RFC 7166, configured via the authentication-trailers command under protocols ospf3.

23
MCQeasy

Which OSPFv3 LSA type is responsible for carrying IPv6 prefix information within the same area, replacing the role of Router and Network LSAs carrying IP addresses in OSPFv2?

A.Type 1 (Router LSA)
B.Type 9 (Intra-Area-Prefix LSA)
C.Type 5 (AS-External LSA)
D.Type 3 (Inter-Area-Prefix LSA)
AnswerB

Type 9 LSAs are used in OSPFv3 to advertise IPv6 prefixes associated with a router or transit network within the same area.

Why this answer

OSPFv3 separates topology information from IP prefix information. Type-9 (Intra-Area-Prefix-LSA) carries IPv6 prefixes associated with routers or transit networks within the area.

24
MCQhard

An administrator implements LLDP-MED on an EX Series switch network. To prevent unauthorized devices from masquerading as IP phones and requesting voice VLAN access, which feature should be combined with LLDP-MED?

A.Storm control with broadcast filtering
B.DHCP snooping and Dynamic ARP Inspection (DAI)
C.IEEE 802.1X port-based authentication with dynamic VLAN assignment
D.IP Source Guard
AnswerC

Combining 802.1X or MAC Authentication Bypass (MAB) ensures endpoints are authenticated before receiving secure network policies.

Why this answer

MAC Radius or 802.1X authentication combined with VLAN assignment and LLDP-MED ensures security before voice policies are trusted.

25
Multi-Selecthard

Which TWO of the following characteristics apply to EVPN Route Type 3 (Inclusive Multicast Ethernet Tag Route)? (Choose two)

Select 2 answers
A.It advertises host IP prefixes for inter-subnet routing.
B.It carries the originating router's IP address and an Ethernet Tag/VNI identifier.
C.It dynamically triggers MAC mobility sequence number increments.
D.It performs Designated Forwarder election on multi-homed links.
E.It is used to establish ingress replication lists for BUM traffic distribution.
AnswersB, E

Type 3 route payloads include the originating router's IP and the Ethernet tag or VNI.

Why this answer

Route Type 3 routes are used to construct the multicast/broadcast distribution tree using ingress replication (head-end replication) by advertising the PE's IP address and Ethernet tag/VNI.

26
MCQeasy

Which Junos command displays the link-state database for OSPFv2, showing router LSAs and network LSAs?

A.show route ospf database
B.show link-state ospf database
C.show ospf database
D.show protocols ospf database
AnswerC

This command outputs the complete OSPF LSDB.

Why this answer

The command 'show ospf database' displays the OSPF link-state database on a Junos device.

27
Multi-Selectmedium

Which TWO statements describe the function and operation of a PIM Bootstrap Router (BSR)? (Choose two)

Select 2 answers
A.The BSR acts as the data encapsulation point for multicast sources.
B.The BSR collects Candidate-RP messages and periodically distributes the RP-set to all PIM routers.
C.The BSR forwards multicast data packets directly to receivers.
D.All PIM routers in the domain dynamically learn the RP-set from the BSR messages.
E.The BSR is required to establish MSDP sessions between autonomous systems.
AnswersB, D

The BSR gathers C-RP info and floods bootstrap messages domain-wide.

Why this answer

The BSR collects Candidate-RP advertisements and distributes the RP-set to all routers in the domain via bootstrap messages.

28
MCQeasy

Which statement is true regarding the behavior of the supplicant mode 'single' on an EX Series switch port?

A.Only one supplicant is allowed on the port; if a second device connects, it is blocked or unauthenticated.
B.It allows up to 256 MAC addresses to authenticate simultaneously via MAC RADIUS.
C.Multiple supplicants are allowed, but they must all share the same VLAN and credentials.
D.It enables multi-domain authentication for voice and data devices.
AnswerA

Correct. Single mode restricts the port to one authenticated client.

Why this answer

Single-supplicant mode allows only a single authenticated client on the port. If a hub or IP phone with a PC is connected, only one device passes authentication.

29
Multi-Selectmedium

When configuring voice VLANs and PoE on an EX Series switch, which THREE benefits are achieved by implementing LLDP-MED alongside standard PoE? (Choose three.)

Select 3 answers
A.Dynamic power negotiation allowing devices to request exact wattage rather than class maximums.
B.Elimination of all Layer 2 broadcast traffic on the switch.
C.Enhanced asset management and inventory tracking via TLV exchanges.
D.Automatic configuration of IPsec VPN tunnels on the switch.
E.Automatic voice VLAN discovery and configuration on the IP phone without manual static provisioning.
AnswersA, C, E

LLDP-MED power management allows precise wattage negotiation.

Why this answer

LLDP-MED combined with PoE provides dynamic power negotiation, automated voice VLAN provisioning, and enhanced inventory tracking.

30
MCQhard

You are reviewing syslog messages on an EX Series switch and see frequent entries indicating PoE power budgeting warnings. You want to configure a custom trap/syslog threshold so that warnings trigger when the total power consumption exceeds 85% of the total available PoE budget. How is this configured?

A.set poe budget-threshold 85
B.set system syslog host 192.168.1.10 poe-threshold 85
C.set poe threshold 85
D.set poe management-budget-threshold 85
AnswerA

The budget-threshold statement under the system poe hierarchy sets the percentage threshold for syslog generation.

Why this answer

PoE threshold settings allow operators to set a percentage limit that triggers traps when power consumption nears capacity.

31
MCQhard

An enterprise network uses a BGP route reflector (RR) architecture where client routers reflect routes to each other. A non-client router sends a route with an Originator ID and Cluster List to the RR. How does the route reflector handle these attributes when reflecting the route to other clients?

A.It removes the Originator ID and replaces the Cluster List with its own cluster ID.
B.It increments the Originator ID value by one and clears the Cluster List.
C.It leaves the Originator ID intact and appends its own cluster ID to the Cluster List.
D.It clears both the Originator ID and Cluster List to reset loop detection for the local cluster.
AnswerC

The RR preserves the Originator ID and adds its local cluster ID to the front of the Cluster List.

Why this answer

A route reflector leaves the Originator ID untouched and prepends its own Cluster ID to the existing Cluster List to prevent routing loops.

32
MCQmedium

An administrator wants to configure Candidate-RP (C-RP) advertisements using the Bootstrap Router (BSR) mechanism in PIM sparse-mode. Which hierarchy level in Junos is used to configure the local router as a Candidate-RP?

A.[edit protocols pim bsr]
B.[edit routing-options candidate-rp]
C.[edit protocols pim candidate-rp]
D.[edit protocols igmp candidate-rp]
AnswerC

Candidate RP settings, including local address and group ranges, are configured under protocols pim candidate-rp.

Why this answer

Candidate RPs in Junos are configured under protocols pim candidate-rp.

33
MCQmedium

You need to configure a classifier that inspects the Multiprotocol Label Switching (MPLS) experimental (EXP) bits. Which classifier type must you specify?

A.exp
B.fec
C.ieee-802.1
D.dscp
AnswerA

exp specifies the MPLS experimental bits classifier.

Why this answer

The MPLS EXP bits are classified using the exp classifier type in Junos CoS configurations.

34
MCQmedium

An engineer wants to restrict IGMP membership reports to only accept version 2 on a specific VLAN interface configured on an MX Series router. Which configuration statement achieves this requirement?

A.set protocols pim interface vlan.10 igmp-version 2
B.set protocols igmp interface vlan.10 version 2
C.set routing-options multicast igmp-version 2 interface vlan.10
D.set interfaces vlan.10 igmp-version 2
AnswerB

This explicitly forces the IGMP version on the specified interface to version 2.

Why this answer

Junos allows configuring specific IGMP versions per interface under protocols igmp interface.

35
MCQeasy

In Junos CoS architecture, what role does a forwarding class play?

A.It represents an internal queue abstraction used to group and process packets
B.It specifies the egress interface physical speed
C.It provides static IP routing table entries
D.It defines the physical queue index directly on the ASIC
AnswerA

Forwarding classes group packets for queue scheduling and drop profiles.

Why this answer

Forwarding classes act as internal labels used by the router to group traffic into specific queues for scheduling and drop treatment.

36
Multi-Selecthard

An administrator is troubleshooting BGP route reflector operations in a Junos environment. Which TWO statements regarding route reflection behavior and loop prevention are correct? (Choose two)

Select 2 answers
A.Route reflectors change the BGP next hop to their own IP address when reflecting routes to clients by default.
B.A route reflector ignores any advertised route that contains its own local Cluster ID in the Cluster List.
C.The Originator ID is a 4-byte value created by the route reflector to identify the client that injected the route.
D.Route reflectors remove the AS_PATH attribute when reflecting routes to internal non-client peers.
E.Route reflectors modify the Local Preference attribute to zero for all reflected routes.
AnswersB, C

Cluster Lists prevent routing loops between clustered route reflectors by rejecting paths containing the local cluster ID.

Why this answer

Route reflectors use Originator ID to prevent loops from clients and Cluster Lists to prevent loops between cluster route reflectors.

37
MCQhard

An administrator notices that an EX4300 switch is supplying power using LLDP-MED power negotiation, but the IP phone is drawing more power than the initial hardware class allows. Where would you check the advertised LLDP-MED TLV power value received from the phone?

A.show system lldp-med power-statistics
B.show poe interface ge-0/0/10 lldp-negotiation
C.show lldp neighbor interface ge-0/0/10 detail
D.show ethernet-switching interfaces lldp ge-0/0/10
AnswerC

The detail modifier displays all received TLVs, including LLDP-MED power management details.

Why this answer

The show lldp neighbor interface command displays detailed TLVs received from connected LLDP-MED endpoints, including power requirements.

38
MCQmedium

An administrator configures a BGP routing policy to match routes with community members using regex matching in Junos. Which statement accurately describes how Junos represents standard BGP communities in policy matching?

A.Communities are defined within policy-options using community members specified in AS:number format and matched via community-list.
B.Community matching in Junos requires explicit activation under the forwarding-options hierarchy.
C.Communities must be converted to extended communities before any regular expression can be applied.
D.Communities are matched exclusively using hexadecimal bitmasks in policy match conditions.
AnswerA

Junos uses named community lists with AS:number syntax to match BGP communities.

Why this answer

In Junos, standard BGP communities are represented as target communities or community sets in the form of autonomous_system:identifier or named community lists.

39
MCQhard

When applying a rewrite rule on an interface, you notice that packets are being remarked incorrectly. You realize that both a DSCP rewrite rule and an IEEE 802.1p rewrite rule are configured on the same physical interface. What is the rule regarding multiple rewrite rules on a single interface in Junos?

A.Applying multiple rewrite rules causes an automatic system kernel crash
B.Only one rewrite rule total can be applied per logical interface regardless of type
C.Different rewrite rule types (such as DSCP and ieee-802.1) can be applied simultaneously on the same logical interface
D.Only Layer 2 rewrite rules are permitted on trunk ports
AnswerC

Multiple distinct header rewrite rules can coexist on an interface.

Why this answer

Junos allows only one rewrite rule per packet header type (e.g., one DSCP, one 802.1p) per logical interface, but you can have different header types applied simultaneously if they map to different packet layers.

40
MCQeasy

How do you examine the specific OSPF routing table entries learned via OSPF on a Junos device?

A.show protocols ospf route-table
B.show ospf routes
C.show route protocol ospf
D.show ip route ospf
AnswerC

This command filters the routing table to show only OSPF routes.

Why this answer

The 'show route protocol ospf' command displays routes learned specifically through the OSPF routing protocol.

41
Multi-Selectmedium

Which THREE optional BGP attributes are supported and processed by Junos routing devices? (Choose three)

Select 3 answers
A.COMMUNITY
B.LOCAL_WEIGHT
C.ATOMIC_AGGREGATE
D.NEXT_HOP_OVERRIDE
E.MED (Multi-Exit Discriminator)
AnswersA, C, E

Community attributes are fully supported and widely used in Junos policies.

Why this answer

Junos supports standard optional attributes such as MED, Communities, and Atomic Aggregate.

42
Multi-Selectmedium

An engineer is configuring PIM sparse-mode in an enterprise network. Which TWO characteristics are true regarding PIM sparse-mode operation? (Choose two)

Select 2 answers
A.It requires every interface to run IGMPv3 exclusively.
B.It floods multicast traffic across all router interfaces by default until pruned.
C.It uses explicit join messages (*,G or S,G) sent towards the RP or source.
D.It does not require any unicast routing protocol for RPF checks.
E.It relies on a Rendezvous Point (RP) to bridge sources and receivers during tree establishment.
AnswersC, E

PIM-SM uses explicit joins to build distribution trees rather than flooding and pruning.

Why this answer

PIM sparse-mode assumes that multicast traffic is not wanted across all segments by default, requiring explicit join messages. It relies heavily on a Rendezvous Point (RP) to connect sources and receivers initially.

43
MCQhard

A network engineer troubleshoots an issue where multicast data packets are being dropped due to an RPF (Reverse Path Forwarding) check failure. The unicast routing table uses OSPF, but MBGP is deployed for multicast routing. Which operational command should the engineer use to verify the multicast RPF path for a specific source IP?

A.show msdp rpf 192.0.2.1
B.show pim rpf-table 192.0.2.1
C.show route rpf 192.0.2.1
D.show multicast rpf-failure
AnswerC

The 'show route rpf' command displays the RPF lookup results and path used by multicast routing.

Why this answer

When MBGP is used for multicast RPF separate from unicast routing, the command 'show route rpf <source-ip>' helps check which routing table and next-hop is used for the multicast RPF check.

44
Multi-Selecteasy

Which TWO well-known BGP communities are recognized universally to control route propagation? (Choose two)

Select 2 answers
A.no-export
B.local-only
C.transit-only
D.no-peer
E.no-advertise
AnswersA, E

no-export prevents advertising outside the local AS or confederation.

Why this answer

NO_EXPORT and NO_ADVERTISE are standard well-known communities.

45
MCQmedium

You are configuring MACsec (Media Access Control Security) on an EX Series switch interface to secure Layer 2 links between two enterprise buildings. Which requirement is mandatory for MACsec to establish a secure session successfully between the two switches?

A.Both switches must run RSVP-TE to reserve bandwidth for encrypted frames prior to session establishment.
B.Both switches must have identical pre-shared keys (connectivity association keys) and matching cipher suites configured.
C.Both switches must disable Spanning Tree Protocol on the MACsec-secured interface.
D.Both switches must be configured as part of the same VSTP region.
AnswerB

MACsec encryption relies on matching security keys (CAK/CKN) and negotiated cipher suites.

Why this answer

MACsec requires pre-shared keys (PSK) or MKA (MACsec Key Agreement) with matching connectivity association keys (CAK) and cipher suites.

46
MCQhard

An administrator needs to implement a traffic conditioning profile on a Juniper MX Series router to limit traffic to a specific burst size and drop packets exceeding the rate. Which policing action parameter is required to ensure that exceeding traffic is dropped immediately without coloring?

A.forwarding-class
B.transmit
C.mark-action
D.discard
AnswerD

The discard action drops the packet immediately.

Why this answer

A policer in Junos uses policer action statements like loss-priority or discard. To drop non-compliant traffic immediately, the action discard is configured.

47
MCQeasy

Which Junos configuration command enables MD5 cryptographic authentication on an OSPFv2 interface?

A.set security ospf md5 interface ge-0/0/0.0 key "secret"
B.set protocols ospf area 0.0.0.0 interface ge-0/0/0.0 md5-password "secret"
C.set protocols ospf area 0.0.0.0 interface ge-0/0/0.0 authentication md5 1 key "secret"
D.set protocols ospf area 0.0.0.0 interface ge-0/0/0.0 authentication-type md5
AnswerC

This is the correct Junos syntax for OSPFv2 MD5 authentication.

Why this answer

MD5 authentication for OSPFv2 in Junos is configured under the interface hierarchy with the 'authentication md5' statement followed by a key ID and password.

48
MCQmedium

When redistributing BGP routes into OSPF, what is the default OSPF metric assigned to the redistributed routes in Junos if no metric is specified in the export policy?

A.A default metric of 5 is assigned.
B.A default metric of 10 is assigned.
C.A default metric of 0 is assigned.
D.A default metric of 20 is assigned.
AnswerA

Junos assigns a default metric of 5 for routes redistributed into OSPF when not specified.

Why this answer

When routes are redistributed into OSPF without an explicit metric set in the policy, Junos assigns a default metric of 5 for external routes.

49
MCQhard

An administrator needs to filter Type-3 LSAs entering an OSPF stub area on a Junos routing device. Which statement under the area hierarchy is required?

A.set protocols ospf area 0.0.0.2 type-3-lsa-block
B.set protocols ospf area 0.0.0.2 stub lsa-filter block-type-3
C.set protocols ospf area 0.0.0.2 filter type-3-lsa
D.set protocols ospf area 0.0.0.2 area-range 192.168.1.0/24 restrict
AnswerD

The 'restrict' option prevents the summary LSA from being injected into the area.

Why this answer

In Junos OS, you can filter inbound Type-3 LSAs into a stub or NSSA area using the 'area-range' command with the 'restrict' or 'hidden' parameter, or using an import policy at the area level, but specifically for summarization and blocking, the area-range statement with 'restrict' prevents the LSA from being advertised.

50
MCQeasy

You want to configure voice VLAN functionality on a Juniper EX switch so that IP phones automatically place voice traffic into VLAN 50 while passing PC data through unchanged. Which feature should you configure?

A.MAC-based RADIUS dynamic VLAN assignment
B.Layer 2 protocol tunneling (L2PT)
C.LLDP-MED with voice VLAN assignment
D.IEEE 802.1X supplicant authentication
AnswerC

LLDP-MED provides network policy advertisement, allowing IP phones to discover the voice VLAN.

Why this answer

Voice VLAN feature on EX switches automatically assigns voice traffic from known MAC OUIs to the designated voice VLAN.

51
MCQmedium

You are configuring Ethernet switching on an EX4300 switch and need to implement storm control to prevent broadcast, multicast, and unknown unicast traffic from overwhelming access links. Where is storm-control applied in the Junos configuration hierarchy?

A.set interfaces ge-0/0/1 unit 0 family ethernet-switching storm-control
B.set vlans default storm-control
C.set protocols l2-learning storm-control interface ge-0/0/1
D.set forwarding-options storm-control interface ge-0/0/1
AnswerA

Storm control is configured directly under the ethernet-switching family on the interface.

Why this answer

Storm control is applied under 'interfaces <interface-name> unit 0 family ethernet-switching storm-control'.

52
MCQeasy

Which statement describes the function of a drop-profile in Junos CoS?

A.It maps incoming CoS bits to internal forwarding classes
B.It defines how traffic is shaped to a specific peak rate
C.It rewrites outer VLAN tags on trunk interfaces
D.It determines when and how many packets to drop based on buffer occupancy
AnswerD

Drop-profiles implement Random Early Detection (RED) based on queue fill levels.

Why this answer

A drop-profile defines the packet drop probability as a function of buffer occupancy to implement RED or WRED congestion avoidance.

53
Multi-Selectmedium

An enterprise architect is designing an IP multicast solution using PIM Sparse-Mode and needs to configure a Rendezvous Point (RP) redundantly using Auto-RP. However, Junos OS does not natively support listening to Cisco Auto-RP discovery and announcement messages without specific helper configurations. Which TWO configuration steps are required on Junos to interoperate with or process Auto-RP messages? (Choose two)

Select 2 answers
A.Configure PIM Dense-Mode on interfaces receiving Auto-RP announcement and discovery multicast groups (224.0.1.39 and 224.0.1.40).
B.Enable 'auto-rp compatibility' under the global [edit protocols pim] hierarchy.
C.Set the PIM mode to SSM-only across all core interfaces.
D.Enable MSDP peering between the Auto-RP mapping agent and the Junos router.
E.Configure static RP mappings for the Auto-RP well-known multicast groups 224.0.1.39 and 224.0.1.40.
AnswersA, E

Auto-RP messages use dense-mode flooding over well-known addresses 224.0.1.39 and 224.0.1.40, requiring those groups to operate in dense mode or be statically handled.

Why this answer

Junos does not natively run Auto-RP (Cisco proprietary). To support Auto-RP environments, Junos routers can be configured to map Auto-RP groups using static RP or by using RPM/helper statements, or by mapping Auto-RP group addresses (224.0.1.39 and 224.0.1.40) into PIM dense-mode or static mappings if supported. Specifically, standard deployments map the Auto-RP well-known group addresses or use static RP configurations since Junos natively relies on standard BSR.

54
MCQhard

During BGP route resolution on Junos, an indirect next hop is encountered. What mechanism does Junos use to resolve this indirect next hop to a direct forwarding next hop?

A.BGP Link-State (BGP-LS) topology databases.
B.Multiprotocol Label Switching (MPLS) label imposition without routing table participation.
C.Recursive lookups through the routing table using the active IGP or static route entries.
D.Address Resolution Protocol (ARP) directly against the BGP peer IP address.
AnswerC

Junos performs recursive lookups in the routing table to resolve BGP next hops via the resolving protocol (IGP).

Why this answer

Junos relies on the underlying IGP (OSPF or IS-IS) or static routes to resolve indirect BGP next hops to direct interface and gateway forwarding entries.

55
MCQmedium

You are configuring a BGP Route Reflector (RR) in a Junos environment. To prevent routing loops within the iBGP cluster, what mechanism does the route reflector use to track the path of reflected routes?

A.MED comparison and router ID tie-breakers
B.AS Path prepending and local preference manipulation
C.TTL security decrement and loose reverse path forwarding
D.Cluster List and Originator ID attributes
AnswerD

Cluster List and Originator ID are the standard BGP path attributes designed specifically for route reflection loop prevention.

Why this answer

Route reflectors use the 'Originator ID' (a 4-byte attribute containing the router ID of the route originator) and the 'Cluster List' (a sequence of cluster IDs through which the route has passed) to prevent routing loops.

56
Multi-Selecthard

Which THREE of the following statements describe the behavior and purpose of EVPN Route Type 5 (IP Prefix Route)? (Choose three)

Select 3 answers
A.It is mandatory for establishing basic Layer 2 bridging across a single VLAN.
B.It is frequently used for inter-subnet routing and integration with MPLS L3VPN backbones.
C.It replaces Ethernet Segment Identifiers on multi-homed ports.
D.It can include a gateway IP address to facilitate IP routing across VTEPs.
E.It allows the advertisement of IP prefixes independently of MAC addresses.
AnswersB, D, E

Type 5 routes bridge EVPN data centers with external IP-VRF / L3VPN networks.

Why this answer

Route Type 5 carries IP prefixes independently of MAC addresses, supports inter-subnet forwarding in IP-VRF or EVPN-VXLAN integrations, and can carry gateway IP information.

57
MCQeasy

Which command allows you to verify the real-time PoE power consumption, allocated wattage, and operational status of all interfaces on an EX Series switch?

A.show interfaces diagnostics poe
B.show chassis poe status
C.show lldp poe-status
D.show poe interface
AnswerD

show poe interface is the correct operational command to view PoE statistics on Junos switches.

Why this answer

The show poe interface operational command displays detailed power metrics per port.

58
MCQhard

An enterprise is designing a BGP confederation to reduce iBGP mesh complexity across multiple data centers. Which statement is correct regarding how confederation members interact with BGP attributes?

A.Confederations eliminate the need for any internal iBGP peering within the member sub-ASes.
B.The next-hop IP address is always modified when routes are passed between member sub-ASes within the confederation.
C.Local Preference is automatically reset to zero whenever a route crosses a sub-AS boundary inside a confederation.
D.Sub-AS numbers are preserved in AS_CONFED_SEQUENCE segments inside the confederation but are replaced by the confederation identifier when advertising to external peers.
AnswerD

Confederation member AS numbers are encapsulated in confederation-specific path segments internally and hidden from external peers.

Why this answer

Within a BGP confederation, sub-AS numbers are stripped as routes leave the confederation and are replaced by the confederation identifier. However, within the confederation, sub-AS numbers are kept in the AS_CONFED_SEQUENCE and AS_CONFED_SET path segments to prevent loops, and MED/Local Preference are preserved across member sub-AS boundaries.

59
MCQhard

An EX3400 switch experiences a total PoE power budget exhaustion after multiple high-power IP phones and security cameras are plugged in. You want to ensure that if a power deficit occurs, the switch immediately cuts power to lower-priority ports while maintaining power to executive phones on specific ports. How should you configure this?

A.set poe interface all priority low and set poe interface ge-0/0/1 to ge-0/0/4 priority high
B.set poe power-budget-threshold 80
C.set poe management-mode class-based
D.set interfaces all poe shutdown-on-overload
AnswerA

Setting interface priorities ensures the power management daemon sheds low-priority ports first during an overload condition.

Why this answer

Priority-based PoE allocation allows administrators to assign priorities (high, low, medium) to specific interfaces to dictate shedding order.

60
MCQeasy

An administrator needs to ensure that a Junos routing device performs unequal-cost multi-path (UCMP) load balancing across multiple BGP paths with different local preferences or path attributes. Which BGP feature must be enabled to allow multipath load balancing across paths with different AS path lengths?

A.set protocols bgp multipath as-path-ignore
B.set protocols bgp family inet unicast multipath relax
C.set routing-options rib inet.0 multipath
D.set protocols bgp load-balance per-packet
AnswerA

The as-path-ignore parameter allows Junos to consider paths for BGP multipath even if their AS path lengths do not match exactly.

Why this answer

By default, Junos multipath requires multiple attributes (such as AS path length) to match. To allow BGP multipath even when AS path lengths differ (as long as they have the same length numerically, or using 'as-path-ignore'), the 'as-path-ignore' statement under protocols bgp multipath must be configured.

61
MCQhard

An EX Series switch is configured with multiple-supplicant mode on an access port connected to an IP phone with a PC daisy-chained behind it. The IP phone authenticates via 802.1X, but the PC uses MAC RADIUS. The phone authenticates successfully and moves to the voice VLAN. However, when the PC boots, it fails authentication because the switch rejects a second supplicant on the same logical port index. Which configuration parameter resolves this issue?

A.Configure 'set access-profile captive-portal multiple-logins per-port'.
B.Set the port mode to trunk and enable voice-vlan stacking.
C.Configure the interface with 'set protocols dot1x interface ge-0/0/1 mac-radius multiple-clients'.
D.Configure the interface with 'set protocols dot1x interface ge-0/0/1 supplicant multiple' and ensure multi-supplicant mode is active.
AnswerD

Correct. Enabling multiple supplicants per port allows both the IP phone and the PC to authenticate independently.

Why this answer

In multiple-supplicant mode, you must configure 'supplicant multiple' and ensure the port is configured to support multiple clients using different authentication methods (e.g., multi-supplicant mode rather than single-supplicant).

62
Multi-Selecthard

When designing an EVPN-VXLAN fabric with integrated routing and bridging (IRB), which THREE considerations are critical for proper inter-subnet forwarding across VTEPs? (Choose three)

Select 3 answers
A.Enforcing physical loopback interfaces to run in layer 2 bridging mode.
B.Configuring consistent virtual gateway MAC and IP addresses on all IRB interfaces across leaf VTEPs.
C.Disabling BGP EVPN signaling on all spine nodes to save CPU resources.
D.Mapping each bridge domain to a unique VXLAN Network Identifier (VNI).
E.Advertising host routes or subnet prefixes via EVPN Type-2 or Type-5 routes.
AnswersB, D, E

Anycast gateways require identical virtual MAC and IP settings on every leaf router's IRB interface.

Why this answer

Distributed IRB gateways require consistent anycast gateway MAC and IP configurations across all leaf nodes, correct VNI to bridge domain mappings, and EVPN Type-5 or Type-2 route propagation for host/subnet reachability.

63
MCQhard

You are troubleshooting an IP phone that is failing to discover its voice VLAN via LLDP-MED on an EX4600 switch. You issue the show lldp interface command and see that LLDP is transmitting properly, but the phone reports no voice VLAN TLV received. What is the most likely cause of this issue?

A.The voice VLAN is not configured under the switch-options vlan-group hierarchy.
B.The LLDP-MED network policy for voice has not been defined and mapped to the interface or device profile.
C.IEEE 802.1p priority marking is missing from the global bridge-options statement.
D.LLDP advertisement interval is set too high, causing timeout on the phone.
AnswerB

Without an explicit LLDP-MED network policy defining the voice VLAN ID and DSCP values, the switch will not advertise the voice VLAN TLV.

Why this answer

LLDP-MED network policy must be explicitly configured and tied to the interface or globally mapped so that the switch populates the voice VLAN TLV in its outbound LLDP-MED packets.

64
Multi-Selectmedium

Which TWO statements are true regarding Junos OSPF routing policies and policy evaluation? (Choose two)

Select 2 answers
A.Policy terms are evaluated in sequential order from top to bottom.
B.Routing policies cannot match route prefixes, only protocol types.
C.OSPF import policies evaluate routing updates before they enter the Junos forwarding table.
D.Policy evaluation stops immediately upon matching a 'next-term' action.
E.Export policies default to rejecting routes that do not match any explicit term.
AnswersA, E

Junos processes policy terms sequentially until a match and terminal action occur.

Why this answer

Junos routing policies are evaluated top-to-bottom per term, and if no match is found, the default action depends on the context (reject for export policies, accept for import policies in some contexts, but let's review exact Junos behavior: export policies default to reject, import policies default to accept). Also, route filtering can match specific prefixes.

65
MCQhard

You are configuring OSPF domain-id when redistributing routes between OSPF and BGP (or multiarea setups). Which configuration statement sets the OSPF domain identifier?

A.set protocols ospf area 0.0.0.0 domain-identifier 10.0.0.1
B.set protocols ospf domain-id 10.0.0.1
C.set routing-options autonomous-system 65000 ospf-domain 10.0.0.1
D.set protocols ospf bgp-domain-identifier 10.0.0.1
AnswerB

The 'domain-id' command defines the OSPF domain identifier.

Why this answer

The domain-identifier for OSPF (often used in MPLS VPNs or inter-AS scenarios) is configured under protocols ospf using the domain-id statement.

66
MCQhard

A BGP routing policy on a Junos router uses an 'as-path' regular expression '^[0-9]+$' in a match condition. Which routes will this regular expression match?

A.Routes that contain internal confederation segments.
B.Routes whose AS path contains exactly one AS number ( originated from a directly connected neighboring AS ).
C.Routes whose AS path starts with local AS 65000 and has multiple hops.
D.Any route originating from any AS path of any length.
AnswerB

The anchors ^ and $, combined with digits and plus sign, match exactly a single AS number in the path.

Why this answer

The regex '^[0-9]+$' matches an AS path that consists of exactly one autonomous system number (from the beginning to the end of the path string).

67
MCQhard

When configuring a hierarchical scheduler map on an MX Series router, what is the primary purpose of the aggregate level shaping?

A.To dynamically assign forwarding classes based on IP headers
B.To ensure absolute priority for best-effort traffic
C.To limit the total traffic across all queues associated with the scheduler map
D.To rewrite CoS bits on egress frames
AnswerC

Aggregate shaping controls the sum of all traffic belonging to the child schedulers.

Why this answer

Aggregate level shaping controls the total bandwidth allocated to a group of queues or sub-interfaces, ensuring overall traffic limits are respected.

68
MCQhard

You are troubleshooting a scenario where an MX Series router running an EVPN-VXLAN instance receives Type-2 routes from a remote PE, but the local data plane fails to install the forwarding entries because of a mismatch in encapsulation types. Where is the encapsulation type for VXLAN defined within a Junos EVPN instance?

A.protocols bgp group <name> family evpn encapsulation vxlan
B.interfaces lo0.0 family vxlan
C.routing-instances <name> instance-type evpn; ... encapsulation vxlan;
D.bridge-domains <name> vni <id> encapsulation mpls
AnswerC

Encapsulation vxlan is configured directly inside the routing instance or switch options block.

Why this answer

In Junos OS, the encapsulation for the routing instance or switch options is defined using the 'encapsulation vxlan' statement under the routing-instance or switch-options hierarchy.

69
MCQhard

An enterprise network operates VSTP across 150 VLANs. The network engineering team notices high CPU utilization on the Routing Engine due to VSTP BPDU processing. Which Junos command or feature can mitigate this control-plane load while keeping VSTP operational?

A.set system pfe bpdu-bypass enable
B.set forwarding-options storm-control interfaces all vstp
C.set protocols vstp no-bpdu-generation
D.set protocols vstp hello-time 5
AnswerD

Increasing the hello-time interval reduces the frequency of BPDU transmissions and processing overhead.

Why this answer

BPDU rate-limiting or adjusting VSTP hello timers helps reduce control-plane processing overhead. In Junos, VSTP timer tuning and bpdu processing limits control overhead.

70
MCQeasy

Which command allows you to view the configured drop-profile statistics and monitor packet drop counts on an MX Series router?

A.show class-of-service drop-profile
B.show firewall log
C.show interfaces drop-rate
D.show system drop-stats
AnswerA

This command shows drop-profile states and drop counters.

Why this answer

The show class-of-service drop-profile command displays drop-profile utilization and drop statistics.

71
Multi-Selecteasy

Which TWO operational commands are valid for troubleshooting VSTP on Juniper EX switches? (Choose two)

Select 2 answers
A.show vstp topology-change
B.show spanning-tree vstp-status
C.show vstp vlan
D.show vstp interface
E.show ethernet-switching vstp-neighbors
AnswersC, D

Displays VSTP status per VLAN.

Why this answer

show vstp and show vstp vlan are valid operational commands for VSTP.

72
MCQeasy

An engineer needs to verify which multicast groups have active receivers joined on an interface using IGMP. Which operational command should be used?

A.show igmp group
B.show multicast heap
C.show msdp SA-cache
D.show pim rp statistics
AnswerA

This command displays the multicast groups and receiver memberships learned via IGMP.

Why this answer

The 'show igmp group' command lists the multicast groups joined on interfaces via IGMP.

73
MCQmedium

You are configuring a voice VLAN on an EX Series switch access port where an IP phone is connected in series with a PC. Which configuration is required on the switch interface to handle both tagged voice traffic and untagged data traffic?

A.Configure the port as an RSTP edge port with voice optimization.
B.Configure the port as a pure trunk port blocking all native VLAN traffic.
C.Configure the interface as access mode with both voice-vlan and native-vlan parameters.
D.Configure the port using bridge-domains with dual-tagging (QinQ).
AnswerC

Using an access port with a voice VLAN allows untagged PC traffic to fall into the native VLAN while tagged phone traffic uses the voice VLAN.

Why this answer

IP phones typically act as a mini-switch, requiring an access port configured with a native VLAN for the PC and a voice VLAN for the phone's tagged traffic.

74
MCQeasy

Which command should an engineer use on a Junos device to verify whether a BGP next hop is successfully resolved via the routing table?

A.show route protocol bgp next-hop
B.show bgp neighbor detail
C.show route forwarding-table destination
D.show bgp summary
AnswerA

This command is specifically designed to inspect BGP next-hop resolution state in Junos.

Why this answer

The 'show route protocol bgp next-hop' command displays all BGP next hops and indicates whether they are resolved in the routing table.

75
MCQhard

In an enterprise network running PIM sparse-mode, an engineer notices that multicast traffic is switched from the shared tree (*,G) to the source-specific tree (S,G) prematurely, causing micro-bursts on core links. Which command disables this automatic switchover behavior on a Junos router?

A.set routing-options multicast spt-mode disable
B.set protocols pim disable-spt-switchover
C.set protocols igmp spt-threshold 0
D.set protocols pim spt-threshold infinity
AnswerD

Setting the SPT threshold to infinity prevents the last-hop router from switching to the source-specific tree, keeping it on the shared tree.

Why this answer

By default, last-hop routers switch from (*,G) to (S,G) upon receiving the first packet from source S. To prevent this, the 'spt-threshold infinity' command is configured under [edit protocols pim].

Page 1 of 5

Page 2

All pages