JNCIP-ENT Layer 2 Authentication And Access Control Practice Question
An administrator configures 802.1X authentication with local server fallback on an EX Series switch. When the external RADIUS server is unreachable, the switch fails over to the local user database. However, users authenticated via the local database are placed in the default access VLAN instead of the VLAN specified in their local user profile. What is the cause of this behavior?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Local database user profiles on Junos do not support dynamic VLAN assignment attributes natively, requiring interface-level default fallback VLANs.
When using local fallback authentication on Junos switches, local user database entries lack the rich attribute support (like dynamic VLAN assignment via RADIUS VSA equivalents) unless explicitly mapped or configured via local database profiles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The local fallback profile was not bound to the interface using the 'fallback-profile' command.
Why it's wrong here
Incorrect. Local fallback uses the standard system authentication order.
- ✓
Local database user profiles on Junos do not support dynamic VLAN assignment attributes natively, requiring interface-level default fallback VLANs.
Why this is correct
Correct. Junos local authentication has limited attribute return capabilities compared to external RADIUS.
- ✗
The local database uses PAP, which strips VLAN assignment attributes from the authentication reply.
Why it's wrong here
Incorrect. PAP vs CHAP does not govern Junos local attribute parsing.
- ✗
RADIUS accounting was disabled, preventing local attribute synchronization.
Why it's wrong here
Incorrect. Accounting does not affect authorization attributes.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
Courseiva writes every JNCIP-ENT question from scratch — 336 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Juniper Networks exam blueprint
This JNCIP-ENT practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JNCIP-ENT exam.