Courseiva
Layer 2 SecuritymediumMultiple ChoiceObjective-mapped

JNCIS-ENT Layer 2 Security Practice Question

You are troubleshooting port security on an EX Series switch. An interface has been configured with 'action-on-violation shutdown', and a violation occurs. What is the default operational state of the interface after the violation, and how is it restored?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The interface is disabled and must be manually re-enabled using a clear command or by disabling/re-enabling the interface.

When an interface is shut down due to a port security violation, it enters a disabled state. It remains down until explicitly re-enabled using 'clear ethernet-switching security-violation' or by toggling the interface status.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The interface automatically recovers after a default hold-down timer of 300 seconds.

    Why it's wrong here

    Junos does not automatically recover shutdown interfaces without an explicit clear command or configuration.

  • The interface is disabled and must be manually re-enabled using a clear command or by disabling/re-enabling the interface.

    Why this is correct

    Correct. The shutdown violation action puts the port in a disabled state requiring administrator intervention.

  • The interface drops violating packets but remains operationally up until manually disabled.

    Why it's wrong here

    The shutdown action physically disables the interface, not just dropping packets.

  • The interface transitions to a blocked state and flushes its MAC table every 60 seconds until cleared.

    Why it's wrong here

    The shutdown action completely disables the port rather than transitioning it to a blocked state.

About these practice questions

Courseiva writes every JNCIS-ENT question from scratch — 519 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Juniper Networks exam blueprint

This JNCIS-ENT practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JNCIS-ENT exam.