Courseiva
Layer 2 Authentication And Access ControlhardMultiple ChoiceObjective-mapped

JNCIP-ENT Layer 2 Authentication And Access Control Practice Question

An administrator configures 802.1X authentication with local server fallback on an EX Series switch. When the external RADIUS server is unreachable, the switch fails over to the local user database. However, users authenticated via the local database are placed in the default access VLAN instead of the VLAN specified in their local user profile. What is the cause of this behavior?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Local database user profiles on Junos do not support dynamic VLAN assignment attributes natively, requiring interface-level default fallback VLANs.

When using local fallback authentication on Junos switches, local user database entries lack the rich attribute support (like dynamic VLAN assignment via RADIUS VSA equivalents) unless explicitly mapped or configured via local database profiles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The local fallback profile was not bound to the interface using the 'fallback-profile' command.

    Why it's wrong here

    Incorrect. Local fallback uses the standard system authentication order.

  • Local database user profiles on Junos do not support dynamic VLAN assignment attributes natively, requiring interface-level default fallback VLANs.

    Why this is correct

    Correct. Junos local authentication has limited attribute return capabilities compared to external RADIUS.

  • The local database uses PAP, which strips VLAN assignment attributes from the authentication reply.

    Why it's wrong here

    Incorrect. PAP vs CHAP does not govern Junos local attribute parsing.

  • RADIUS accounting was disabled, preventing local attribute synchronization.

    Why it's wrong here

    Incorrect. Accounting does not affect authorization attributes.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every JNCIP-ENT question from scratch — 336 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Juniper Networks exam blueprint

This JNCIP-ENT practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JNCIP-ENT exam.