JNCIP-ENT · domain
Layer 2 Authentication And Access Control
Practise Juniper Networks Enterprise Routing and Switching, Professional (JNCIP-ENT, JN0-650) (JNCIP-ENT) Layer 2 Authentication And Access Control practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Layer 2 Authentication And Access Control questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Layer 2 Authentication And Access Control
Layer 2 Authentication And Access Control questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Layer 2 Authentication And Access Control exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Layer 2 Authentication And Access Control questions (36)
Click any question to see the full explanation, or start a practice session above.
Which THREE statements describe the behavior of critical authentication (fallback) when a RADIUS server becomes unreachable on an EX Series switch? (Choose three)
Hard2Which statement is true regarding the behavior of the supplicant mode 'single' on an EX Series switch port?
Easy3An EX Series switch is configured with multiple-supplicant mode on an access port connected to an IP phone with a PC daisy-chained behind it. The IP phone authenticates via 802.1X, but the PC uses MAC RADIUS. The phone authenticates successfully and moves to the voice VLAN. However, when the PC boots, it fails authentication because the switch rejects a second supplicant on the same logical port index. Which configuration parameter resolves this issue?
Hard4Which command allows an administrator to verify the active supplicant states and authentication status on a specific EX Series switch interface?
Easy5What is the default authentication order when authentication is enabled on an EX Series switch interface without explicit ordering configuration?
Easy6Which TWO actions occur when an 802.1X supplicant fails authentication and a guest VLAN is configured on the EX Series switch port? (Choose two)
Medium7An EX4300 switch is configured with captive portal authentication. Unauthenticated users are successfully redirected when attempting HTTP traffic, but HTTPS traffic fails to redirect properly and instead shows a certificate warning or connection timeout in the user's browser. What is the fundamental reason for this behavior with standard captive portal implementations?
Hard8Which TWO statements are correct regarding the behavior and configuration of multi-supplicant mode on EX Series switches? (Choose two)
Medium9An EX Series switch is configured with 802.1X and MAC RADIUS. A client device connects that does not support 802.1X. The switch attempts 802.1X, times out, and successfully falls back to MAC RADIUS. However, the administrator notices a significant delay (several seconds) before the MAC RADIUS request is sent to the server. What parameter should be tuned to reduce this delay?
Hard10An administrator configures 802.1X authentication with local server fallback on an EX Series switch. When the external RADIUS server is unreachable, the switch fails over to the local user database. However, users authenticated via the local database are placed in the default access VLAN instead of the VLAN specified in their local user profile. What is the cause of this behavior?
Hard11You are troubleshooting an 802.1X deployment on an EX4300 switch. Clients fail to authenticate when using Supplicant-based authentication combined with MAC RADIUS fallback. You notice that the switch does not attempt MAC RADIUS after 802.1X times out. Which configuration error most likely caused this?
Medium12You are configuring an EX Series switch to support MAC RADIUS authentication. You want to ensure that the switch sends accounting start and stop packets to the RADIUS server. Which configuration hierarchy is required to enable RADIUS accounting for access clients?
Medium13An administrator implements MAC RADIUS authentication on an EX Series switch. Several legacy printers connected to the ports fail to authenticate because they send their MAC addresses in uppercase letters with no separators (AABBCCDDEEFF), while the RADIUS server expects lowercase with colons (aa:bb:cc:dd:ee:ff). How can you resolve this mismatch on the Junos switch?
Hard14You are configuring captive portal on an EX Series switch. You want users to be redirected to an external web server hosted at https://portal.enterprise.com/login. Where do you specify this redirection URL in the Junos OS CLI?
Medium15Which TWO conditions must be satisfied for an EX Series switch to successfully process a RADIUS Change of Authorization (CoA) request? (Choose two)
Medium16You are implementing MAC RADIUS authentication on an EX4600 switch. You notice that when a device connects, the switch sends the MAC address in the Username attribute (RADIUS attribute 1) with hyphen separators (e.g., aa-bb-cc-dd-ee-ff). Your RADIUS server expects colons (aa:bb:cc:dd:ee:ff). Where must you configure this format change on Junos OS?
Medium17What is the primary function of the RADIUS server attribute 'Tunnel-Medium-Type' (Attribute 65) when received during an 802.1X authentication exchange on an EX Series switch?
Easy18An enterprise network administrator needs to configure 802.1X authentication on EX Series switches. Which statement is correct regarding the default behavior of the supplicant timeout timer?
Easy19Which TWO statements are correct regarding captive portal redirection behavior on EX Series switches? (Choose two)
Medium20Which statement accurately describes the function of the 'server-timeout' setting within a Juniper access profile?
Easy21Which TWO options are valid configurable parameters under an access profile in Junos OS? (Choose two)
Medium22Which command is used to clear dynamic MAC RADIUS authentication states and force a re-authentication on interface ge-0/0/5?
Easy23Which RADIUS attribute is commonly used to assign a specific session timeout value to an 802.1X authenticated client on an EX Series switch?
Easy24Which THREE diagnostic tools or show commands are useful when troubleshooting MAC RADIUS authentication failures on an EX Series switch? (Choose three)
Hard25You are configuring MAC RADIUS authentication on an EX Series switch and want to ensure that devices failing MAC RADIUS are assigned to a restricted quarantine VLAN. Where is the quarantine VLAN configured for failed MAC RADIUS attempts?
Medium26Which THREE attributes or conditions must be met for successful dynamic VLAN assignment via RADIUS during 802.1X authentication on Junos EX Series switches? (Choose three)
Hard27You are configuring captive portal on an EX Series switch using J-Web and CLI. Users are redirected to the captive portal page, but after successful authentication, they still cannot access the external network. Inspecting the routing table and firewall filters, what is the most likely reason for this post-authentication restriction?
Hard28Which THREE parameters must be configured when implementing captive portal on an EX Series switch? (Choose three)
Hard29You are configuring an EX Series switch for 802.1X authentication. You want to ensure that if a supplicant fails authentication, the port is moved into a specific guest VLAN. Where is the guest VLAN referenced within the dot1x interface configuration?
Medium30An enterprise network uses 802.1X authentication with dynamic VLAN assignment on EX Series switches. A client authenticates, and the RADIUS server returns both a VLAN name and a set of dynamic firewall filter names via RADIUS attributes (Filter-Id). When the client connects, the VLAN assignment works perfectly, but the firewall filters are not applied to the interface. What is the most likely cause?
Hard31Which Junos command displays the status of all captive portal sessions currently active on an EX Series switch?
Easy32An enterprise deploys 802.1X with dynamic VLAN assignment. When a user authenticates, the RADIUS server returns the correct VLAN name, but the switch places the port into a different VLAN. Upon checking the switch, you find that the VLAN name returned by RADIUS does not match any VLAN configured in the local 'vlans' configuration hierarchy. How does Junos OS handle this discrepancy?
Hard33You are configuring an EX Series switch to use MAC RADIUS authentication. You notice that when devices connect, the switch sends authentication requests, but the accounting start packets are not being sent. What configuration is missing?
Medium34You are configuring a captive portal on an EX Series switch. You want to ensure that specific management traffic and critical server subnets are accessible to clients *before* they authenticate through the captive portal. Which configuration feature accomplishes this?
Medium35You are troubleshooting an issue where an 802.1X supplicant on a Windows client fails to connect to an EX Series switch port. The switch logs show 'EAPOL-TIMEOUT' errors. What does this error indicate?
Medium36Which TWO options are valid authentication methods that can be specified in the 'authentication-order' statement on an EX Series switch interface? (Choose two)
MediumOther domains
All JNCIP-ENT exam domains
Frequently asked questions
- What does the Layer 2 Authentication And Access Control domain cover on the JNCIP-ENT exam?
- Layer 2 Authentication And Access Control questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 36 Layer 2 Authentication And Access Control questions in the JNCIP-ENT question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Layer 2 Authentication And Access Control questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.