Courseiva
EVPNmediumMultiple ChoiceObjective-mapped

JNCIP-ENT EVPN Practice Question

An administrator configures EVPN with VXLAN encapsulation and wants to ensure that interfaces assigned to bridge domains drop frames whose source MAC address is not learned or is unauthorized. Which feature should be enabled?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

MAC security / MAC limit with drop action

Configuring MAC limit or bpdu protection/port security features on access interfaces prevents unauthorized MAC learning, while EVPN sticky MAC features can lock MACs to specific interfaces.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • MAC security / MAC limit with drop action

    Why this is correct

    MAC limit features with action drop protect bridge domains from MAC flooding and unauthorized source MACs.

  • Ingress replication disabling

    Why it's wrong here

    Disabling ingress replication breaks BUM traffic forwarding.

  • BGP route filtering

    Why it's wrong here

    BGP route filtering affects control plane advertisements across routers, not local switch port source MACs.

  • EVPN Route Type 4 filtering

    Why it's wrong here

    Type-4 routes are for multi-homed segment discovery.

Visual reference

SW1 Root Bridge SW2 SW3 BLK DP DP RP RP STP blocks one link to prevent loops DP = Designated Port RP = Root Port BLK = Blocked

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every JNCIP-ENT question from scratch — 336 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Juniper Networks exam blueprint

This JNCIP-ENT practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JNCIP-ENT exam.