Courseiva

JNCIS-ENT · topic practice

Layer 2 Security practice questions

Practise Juniper Networks Enterprise Routing and Switching, Specialist (JNCIS-ENT, JN0-352) (JNCIS-ENT) Layer 2 Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Layer 2 Security

What the exam tests

What to know about Layer 2 Security

Layer 2 Security questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Layer 2 Security exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Layer 2 Security questions

20 questions · select your answer, then reveal the explanation

An administrator needs to configure port security on an access switch running Junos OS to limit the number of learned MAC addresses on interface ge-0/0/1 to a maximum of two. Which configuration statement accomplishes this?

Question 2mediummultiple choice
Read the full Layer 2 Security explanation →

You are configuring a Layer 2 firewall filter to count packets originating from an unauthorized server MAC address '00:11:22:33:44:55'. Which filter term structure correctly matches this MAC address?

Which TWO traffic types are monitored and controlled by default when storm control is applied to an interface on an EX Series switch? (Choose two)

Which TWO methods can be used to recover an EX Series switch interface that has been shut down due to a port security violation? (Choose two)

Question 5mediummultiple choice
Read the full DHCP explanation →

An administrator notices that a rogue DHCP server on access port ge-0/0/1.0 is handing out incorrect IP addresses to clients on a Juniper Networks EX Series switch running Junos OS. Which configuration statement enables DHCP snooping and correctly trusts the uplink interface ge-0/0/24.0 connected to the legitimate core switch?

Which TWO parameters can be configured when setting up storm control on an EX Series switch? (Choose two)

An engineer configures storm control on an EX Series switch to protect against broadcast floods. The configuration uses a bandwidth-percentage rate limit of 20%. Which traffic types are targeted by default when storm control is applied to an interface?

Which command allows an administrator to verify storm control statistics and drop counts on an EX Series switch interface?

Question 9mediummultiple choice
Read the full Layer 2 Security explanation →

You are troubleshooting port security on an EX Series switch. An interface has been configured with 'action-on-violation shutdown', and a violation occurs. What is the default operational state of the interface after the violation, and how is it restored?

Question 10mediummultiple choice
Read the full DHCP explanation →

You have enabled DHCP snooping on an EX Series switch. What must be configured on the interface connecting to the legitimate corporate DHCP server to prevent rogue DHCP server replies?

An administrator configures MACsec with pre-shared keys (PSK) between two EX Series switches. After applying the configuration, the secure channel fails to establish. Which operational command should be used to troubleshoot the MKA session state and connectivity?

Question 12easymultiple choice
Read the full DHCP explanation →

Which feature is required to be enabled on an access switch to populate the DHCP snooping database binding table with legitimate client IP-to-MAC address mappings?

Question 13mediummultiple choice
Read the full Layer 2 Security explanation →

You are configuring MACsec on a pair of Juniper EX4300 switches to secure data links between wiring closets. Which key agreement protocol is used by default in Junos MACsec to dynamically negotiate and manage encryption keys?

Question 14easymultiple choice
Open the full VLAN trunking answer →

Which Junos configuration command enables Dynamic ARP Inspection (DAI) for a specific VLAN named 'VLAN10'?

Question 15hardmultiple choice
Read the full DHCP explanation →

An administrator configures IP Source Guard on an access switch port. When a client connects, its traffic is dropped even though it acquired an IP via DHCP. Reviewing logs shows no DHCP snooping binding. What is the root cause?

Question 16mediummultiple choice
Read the full Layer 2 Security explanation →

You need to write a Layer 2 firewall filter to drop inbound frames with a specific source MAC address on an EX Series switch. Where must this filter be applied to take effect?

Question 17hardmultiple choice
Open the full VLAN trunking answer →

An administrator enables Dynamic ARP Inspection (DAI) on a VLAN that uses DHCP snooping for IP binding verification. A static client on the same VLAN cannot communicate with the default gateway. What is the most likely cause of this issue?

Question 18easymultiple choice
Read the full DHCP explanation →

Which Junos command displays the active DHCP snooping binding database entries on an EX Series switch?

Question 19mediummultiple choice
Read the full Layer 2 Security explanation →

You want to configure IP Source Guard on interface ge-0/0/5 to verify both IP and MAC addresses against the binding table. Which configuration statement is required?

Which command is used to clear the Dynamic ARP Inspection violation counters on an EX Series switch?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Layer 2 Security sessions

Start a Layer 2 Security only practice session

Every question in these sessions is drawn from the Layer 2 Security domain — nothing else.

Related practice questions

Related JNCIS-ENT topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the JNCIS-ENT exam test about Layer 2 Security?
Layer 2 Security questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Layer 2 Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Layer 2 Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other JNCIS-ENT topics?
Use the topic links above to move to related areas, or go back to the JNCIS-ENT question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the JNCIS-ENT exam covers. They are not copied from any real exam or dump site.