Courseiva

JNCIP-ENT · topic practice

Layer 2 Authentication And Access Control practice questions

Practise Juniper Networks Enterprise Routing and Switching, Professional (JNCIP-ENT, JN0-650) (JNCIP-ENT) Layer 2 Authentication And Access Control practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Layer 2 Authentication And Access Control

What the exam tests

What to know about Layer 2 Authentication And Access Control

Layer 2 Authentication And Access Control questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Layer 2 Authentication And Access Control exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Layer 2 Authentication And Access Control questions

20 questions · select your answer, then reveal the explanation

Question 1hardmulti select
Open the full VLAN trunking answer →

Which THREE features or parameters can be configured under the 'protocols dot1x' interface hierarchy on an EX Series switch? (Choose two) -> wait, prompt says Which THREE, let's select three: supplicant timeout, max-retries, and guest-vlan.

Question 2easymultiple choice
Study the full AAA explanation →

What is the primary function of the RADIUS server attribute 'Tunnel-Medium-Type' (Attribute 65) when received during an 802.1X authentication exchange on an EX Series switch?

Which command allows an administrator to verify the active supplicant states and authentication status on a specific EX Series switch interface?

Question 4mediummultiple choice
Study the full AAA explanation →

You are troubleshooting an 802.1X deployment on an EX4300 switch. Clients fail to authenticate when using Supplicant-based authentication combined with MAC RADIUS fallback. You notice that the switch does not attempt MAC RADIUS after 802.1X times out. Which configuration error most likely caused this?

An enterprise network administrator needs to configure 802.1X authentication on EX Series switches. Which statement is correct regarding the default behavior of the supplicant timeout timer?

Question 6mediummultiple choice
Study the full AAA explanation →

You are implementing MAC RADIUS authentication on an EX4600 switch. You notice that when a device connects, the switch sends the MAC address in the Username attribute (RADIUS attribute 1) with hyphen separators (e.g., aa-bb-cc-dd-ee-ff). Your RADIUS server expects colons (aa:bb:cc:dd:ee:ff). Where must you configure this format change on Junos OS?

Question 7mediummultiple choice
Review the full subnetting walkthrough →

You are configuring a captive portal on an EX Series switch. You want to ensure that specific management traffic and critical server subnets are accessible to clients *before* they authenticate through the captive portal. Which configuration feature accomplishes this?

Question 8hardmultiple choice
Open the full VLAN trunking answer →

An EX Series switch is configured with multiple-supplicant mode on an access port connected to an IP phone with a PC daisy-chained behind it. The IP phone authenticates via 802.1X, but the PC uses MAC RADIUS. The phone authenticates successfully and moves to the voice VLAN. However, when the PC boots, it fails authentication because the switch rejects a second supplicant on the same logical port index. Which configuration parameter resolves this issue?

Question 9hardmultiple choice
Review the full routing breakdown →

You are configuring captive portal on an EX Series switch using J-Web and CLI. Users are redirected to the captive portal page, but after successful authentication, they still cannot access the external network. Inspecting the routing table and firewall filters, what is the most likely reason for this post-authentication restriction?

Question 10hardmultiple choice
Open the full VLAN trunking answer →

An administrator configures 802.1X authentication with local server fallback on an EX Series switch. When the external RADIUS server is unreachable, the switch fails over to the local user database. However, users authenticated via the local database are placed in the default access VLAN instead of the VLAN specified in their local user profile. What is the cause of this behavior?

Which statement accurately describes the function of the 'server-timeout' setting within a Juniper access profile?

Question 12easymultiple choice
Study the full AAA explanation →

Which command is used to clear dynamic MAC RADIUS authentication states and force a re-authentication on interface ge-0/0/5?

You are configuring captive portal on an EX Series switch. You want users to be redirected to an external web server hosted at https://portal.enterprise.com/login. Where do you specify this redirection URL in the Junos OS CLI?

Question 14hardmultiple choice
Study the full AAA explanation →

An EX Series switch is configured with 802.1X and MAC RADIUS. A client device connects that does not support 802.1X. The switch attempts 802.1X, times out, and successfully falls back to MAC RADIUS. However, the administrator notices a significant delay (several seconds) before the MAC RADIUS request is sent to the server. What parameter should be tuned to reduce this delay?

Question 15mediummultiple choice
Open the full VLAN trunking answer →

You are configuring MAC RADIUS authentication on an EX Series switch and want to ensure that devices failing MAC RADIUS are assigned to a restricted quarantine VLAN. Where is the quarantine VLAN configured for failed MAC RADIUS attempts?

Question 16hardmultiple choice
Open the full VLAN trunking answer →

An enterprise deploys 802.1X with dynamic VLAN assignment. When a user authenticates, the RADIUS server returns the correct VLAN name, but the switch places the port into a different VLAN. Upon checking the switch, you find that the VLAN name returned by RADIUS does not match any VLAN configured in the local 'vlans' configuration hierarchy. How does Junos OS handle this discrepancy?

What is the default authentication order when authentication is enabled on an EX Series switch interface without explicit ordering configuration?

Question 18mediummultiple choice
Study the full AAA explanation →

You are configuring an EX Series switch to support MAC RADIUS authentication. You want to ensure that the switch sends accounting start and stop packets to the RADIUS server. Which configuration hierarchy is required to enable RADIUS accounting for access clients?

An EX4300 switch is configured with captive portal authentication. Unauthenticated users are successfully redirected when attempting HTTP traffic, but HTTPS traffic fails to redirect properly and instead shows a certificate warning or connection timeout in the user's browser. What is the fundamental reason for this behavior with standard captive portal implementations?

You are troubleshooting an issue where an 802.1X supplicant on a Windows client fails to connect to an EX Series switch port. The switch logs show 'EAPOL-TIMEOUT' errors. What does this error indicate?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Layer 2 Authentication And Access Control sessions

Start a Layer 2 Authentication And Access Control only practice session

Every question in these sessions is drawn from the Layer 2 Authentication And Access Control domain — nothing else.

Related practice questions

Related JNCIP-ENT topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the JNCIP-ENT exam test about Layer 2 Authentication And Access Control?
Layer 2 Authentication And Access Control questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Layer 2 Authentication And Access Control questions in a focused session?
Yes — the session launcher on this page draws every question from the Layer 2 Authentication And Access Control domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other JNCIP-ENT topics?
Use the topic links above to move to related areas, or go back to the JNCIP-ENT question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the JNCIP-ENT exam covers. They are not copied from any real exam or dump site.