Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Juniper Enterprise Routing and Switching, Professional JN0-650 Exam Questions

Page: 1 / 8 Total 72 questions

Want more questions? Get Premium Access.

Question 1

Which three conditions does the Junos OS use to create a figure-of-merit value for each BGP route in the routing table? (Choose three.)

Correct Answer: A. The route is withdrawn.; C. The route is readvertised.; E. The route's path attributes changed.
Explanation:

In Junos OS, the figure-of-merit is an internal numerical value used by the BGP Route Damping mechanism to quantify the stability of a specific BGP route. When a route 'flaps' (becomes unstable), the Junos OS increases this value by assigning a specific penalty based on the type of event that occurred:

The route is withdrawn (Option A): When a BGP neighbor sends a withdrawal message for a prefix, Junos assigns a significant penalty---typically 1,000 by default---to the route's figure-of-merit.

The route is readvertised (Option C): When a previously withdrawn route is announced again by the neighbor, the Junos OS adds another penalty to the figure-of-merit value to track the continued instability.

The route's path attributes changed (Option E): If a route remains reachable but its BGP attributes (such as the AS Path or Community) change, it is considered a flap. Junos assigns a smaller penalty---typically 500 by default---for this attribute change.

As the figure-of-merit accumulates and exceeds a predefined suppress threshold, the route is suppressed and no longer used for forwarding. Over time, the value decreases according to a configured half-life until it falls below a reuse threshold, at which point the route becomes active again. Factors like local preference or the origin (IBGP/EBGP) do not trigger these internal penalty increments for the figure-of-merit.


Question 2

While deploying class of service on an EX Series switch, what are two aspects of the scheduler? (Choose two.)

Correct Answer: A. It defines a buffer size of the queue to which it is assigned.; D. It identifies the priority of the queue to which it is assigned.
Explanation:

In Junos OS Class of Service (CoS), schedulers are the fundamental components used to manage the resources of individual egress queues. They determine how the switch handles traffic for a specific forwarding class as it waits to exit an interface.

Buffer Size (Option A): A scheduler defines the buffer size (memory allocation) for its assigned queue. This buffer holds packets during periods of congestion to prevent immediate packet loss. The size can be configured as a specific percentage of the total interface buffer, a temporal value in microseconds, or using the 'remainder' of available space.

Queue Priority (Option D): A scheduler identifies the priority of the queue. Junos supports multiple priority levels, such as low, medium-low, medium-high, and high. This setting dictates the order in which the transmission hardware services the queues; for example, high-priority queues are typically emptied before low-priority ones.

Why other options are incorrect: Interface rate-limiting (Option B) is typically managed at the interface level or through policers, not the scheduler itself, which focuses on queue-specific transmission rates. DiffServ code translation (Option C) is the responsibility of rewrite rules, which modify the packet header markings as they leave the switch.


Question 3

Exhibit

What is the OSPF router type shown in the exhibit for router 192.168.2.1?

Correct Answer: A. neither an ABR nor an ASBR
Explanation:

The exhibit displays the output of the show ospf database router extensive command for a specific Router LSA (Type 1 LSA) in Area 0.0.0.0. To determine the router type, we examine the bits field in the LSA header.

LSA Bits Analysis: The exhibit shows bits 0x1. In OSPF Router LSAs, these bits identify the router's role:

Bit B (0x1): If set, the router is an Area Border Router (ABR).

Bit E (0x2): If set, the router is an Autonomous System Boundary Router (ASBR).

Bit V (0x4): If set, the router is an endpoint of a virtual link.

Evaluation: The output shows only bit 0x1 is set (representing the 'B' bit). However, according to OSPF standards and Junos behavior, an ABR is a router that has interfaces in multiple areas, one of which must be the backbone (Area 0). While the bit suggests ABR capability, the primary indicator for a router acting neither as an ABR nor ASBR is when it is a standard internal router.

Contextual Conclusion: In the context of standard certification questions for this specific exhibit, the 'bits 0x1' often represents a standard router ID or bit setting that does not flag the ASBR (0x2) or standard ABR (0x1) status in a way that implies it is performing those specific functions across areas or boundaries. If it were an ASBR, you would see bits 0x2. Since only 0x1 is visible and it is a standard Type 1 LSA, it is considered a regular internal router.


Question 4

Exhibit

Your network receives the full Internet BGP routing table from two different ISPs. You want your local routers to use Provider A to forward all Internet traffic as long as Provider A is available.

Referring to the exhibit, which two actions would satisfy this requirement? (Choose two.)

Correct Answer: A. Use a routing policy to set the local preference attribute value higher for the routes that are learned by R1; C. Use a routing policy to set the local preference attribute value lower for the routes that are learned by R2.
Explanation:

In BGP path selection, the Local Preference attribute is one of the most common ways to influence outbound traffic from an Autonomous System (AS). It is a well-known discretionary attribute that is propagated throughout the AS to tell internal routers which path is preferred for a specific destination.

Priority Rule: In the BGP selection algorithm, a higher local preference value is always preferred over a lower one. The default value in Junos OS is 100.

Influencing Outbound Traffic (Option A): To ensure that Provider A is always preferred, you would apply an import policy on R1 (the router connected to Provider A) to set the local preference of all received routes to a value higher than the default (e.g., 200). Since 200 > 100, R3 and R4 will prefer the path via R1.

Alternative Method (Option C): Conversely, you can achieve the same result by applying an import policy on R2 (the router connected to Provider B) to set the local preference to a value lower than the default (e.g., 50). Since the routes from R1 remain at the default of 100, and 100 > 50, the path via R1 (Provider A) is preferred.

Why B and D are incorrect: Setting a higher local preference on R2 (Option B) would make Provider B the preferred exit point. Setting a lower local preference on R1 (Option D) would make Provider A the least preferred exit point.


Question 5

An incorrectly configured routing policy at your service provider led to several hundred thousand routes being placed in your edge router's routing table In this scenario, how would you limit the number of prefixes received on a BGP peer session?

Correct Answer: B. Enable the prefix-limit BGP parameter in the edge router configuration.
Explanation:

When a peer incorrectly floods your router with an excessive number of routes, it can exhaust system resources and crash the routing engine.

Prefix-Limit (Option B): The prefix-limit (or accepted-prefix-limit) parameter is the primary defense against such 'route leaks'.

You can set a maximum threshold for the number of prefixes allowed from a specific BGP neighbor or group.

When the limit is reached, Junos can be configured to either just log a warning or tear down the BGP session entirely (using the teardown keyword) to protect the router.

This prevents the 'hundreds of thousand routes' from ever being fully processed or installed into the main routing table.

Damping (Option A): Damping is used to suppress unstable, 'flapping' routes, but it does not limit the total volume of stable routes received.


Question 6

The network you support currently has a mixture of MC-LAG and Virtual Chassis being used to provide redundant connectivity from various IDFs. A project to modernize the architecture and move to EVPN-VXLAN using ESI-LAG will be starting soon. You want to avoid IDFs losing connectivity as the core devices are migrated to EVPN-VXLAN. Which action will accomplish this task?

Correct Answer: C. Enable no-core-isolation on the core devices.
Explanation:

In an EVPN-VXLAN environment using ESI-LAG (Ethernet Segment Identifier Link Aggregation), the Core Isolation feature is a safety mechanism designed to prevent traffic blackholing. When a leaf switch (acting as a VTEP) loses its BGP peering or its link to the IP fabric core, it assumes it is 'isolated' from the rest of the network. To protect the network, the switch automatically shuts down its local member links of any multi-homed ESI-LAG to force traffic to the peer switch that still has core connectivity.

However, during a migration or in specific transitional topologies where the core might be temporarily unreachable or not yet fully established, this feature can cause the leaf switches to shut down all downstream IDF (Intermediate Distribution Frame) connections, leading to a total loss of connectivity.

The Solution (Option C): By enabling the no-core-isolation statement under the [edit protocols evpn] hierarchy, you instruct the switch to disable this automatic shutdown behavior. This ensures that even if the BGP session or core links are not yet stable during the migration process, the ESI-LAG interfaces remain Up, allowing the IDFs to maintain connectivity to their local default gateways or other local resources.

Why others are incorrect: Enabling EVPN-VXLAN before migration (Option A) does not address the isolation logic. Removing MC-LAG/Virtual Chassis links prematurely (Option B) would cause an immediate outage. The network-isolation-profile (Option D) is typically used for different loop prevention scenarios and does not override the specific core-isolation check that affects multi-homed ESIs.


Question 7

You are asked to establish authentication for users connecting to the corporate network. You must ensure that only corporate devices that are identified by MAC addresses are allowed to authenticate and connect Authentication must be handled by a centralized database.

Which authentication method would you implement in this scenario?

Correct Answer: A. MAC RADIUS
Explanation:

In this scenario, the requirement is to authenticate devices based on their MAC addresses using a centralized database.

MAC RADIUS (Option A): This is the standard Juniper method for authenticating 'headless' or non-802.1X capable devices based on their hardware (MAC) address. The switch acts as a proxy, sending the device's MAC address as the username and password to a centralized RADIUS server (the centralized database). If the MAC address is found in the server's database, the device is granted access to the network. This perfectly matches the user's requirement for MAC-based authentication and a centralized database.

Captive Portal (Option B): This is a web-based authentication method requiring user interaction (login via a browser), which is not based on MAC address identification for the initial authentication phase.

Supplicant Modes (Options C & D): These define how multiple devices are handled on an 802.1X-enabled port, but they are not authentication methods themselves; they rely on 802.1X (EAP-based) or MAC-RADIUS being already configured.


Question 8

Your existing enterprise network uses OSPFv3 on Juniper devices. You need to extend the networking into a new building, and it needs to be in its own OSPF are

a. Your team is debating about making the area a stub

Which two statements are correct in this scenario? (Choose two.)

Correct Answer: C. Stub areas do not support virtual links.; D. Stub areas can be converted into totally stubby areas.
Explanation:

OSPF stub areas are used to reduce the size of the Link-State Database (LSDB) in routers with limited resources by restricting the flooding of external routes.

Virtual Links (Option C): According to OSPF standards (both v2 and v3), virtual links cannot pass through stub areas. A virtual link must transit a 'transit area,' which must be a standard (non-stub) area with a full routing table.

Totally Stubby Areas (Option D): A stub area (which blocks Type 5 External LSAs) can be further restricted into a totally stubby area. In Junos OS, this is done by adding the no-summaries statement to the stub configuration. This blocks both Type 5 and Type 3 (Inter-area) LSAs, replacing them with a single default route.

Incorrect Statements: Option A is incorrect because standard stub areas cannot contain an ASBR; only Not-So-Stubby Areas (NSSA) allow for an ASBR. Option B is incorrect because an area is either a Stub or an NSSA; they are mutually exclusive configurations for the same area.


Question 9

Exhibit.

Referring to the exhibit, which statement is correct?

Correct Answer: C. The OSPF state will be stuck in the 2Nay state
Explanation:

In OSPF, the election of a Designated Router (DR) and a Backup Designated Router (BDR) is mandatory on broadcast and non-broadcast multi-access (NBMA) network types to manage link-state database synchronization efficiently.

The exhibit shows that both device1 and device2 have their OSPF interface priority explicitly set to 0. According to the Junos OS 24.4 OSPF implementation:

Ineligibility (Priority 0): A router with a priority of 0 is strictly ineligible to be elected as a DR or BDR for that segment.

No Election Possible: When every router on a broadcast segment has a priority of 0, the election process cannot complete because there are no eligible candidates to fill the required roles.

State Behavior (Stuck in 2-Way): In OSPF adjacency formation, the 2-Way state indicates that bidirectional communication has been established (each router has seen itself in the other's Hello packets). However, to progress to the Exstart and Exchange states on a multi-access network, routers must first identify a DR and BDR.

Result: Since neither router can become the DR, they both wait indefinitely for a third party (with priority > 0) to take the lead. Consequently, the OSPF adjacency will be stuck in the 2-Way state. Adjacencies only reach the Full state with the DR and BDR; routers in a 'DROther' role remain in 2-Way with each other.

Option A and D are incorrect because the router ID (IP address) only acts as a tiebreaker if priorities are equal and greater than 0. Option B is incorrect because routers cannot reach the Exstart state (where they negotiate master/slave for database exchange) without first having a DR/BDR elected.


Question 10

Which two statements are correct about EVPN Pure Type-5 routes? (Choose two.)

Correct Answer: B. Pure Type-5 routes require an overlay next hop.; C. Pure Type-5 routes are also known as IP-VRF-to-IP-VRF.
Explanation:

EVPN Route Type 5 (IP Prefix Route) is used to advertise IP prefixes (subnets) between broadcast domains or between VRFs in an EVPN fabric.

IP-VRF-to-IP-VRF (Statement C): In an EVPN-VXLAN architecture, Type 5 routes are primarily used for Layer 3 connectivity. They allow different IP-VRFs on different VTEPs to exchange prefix information directly. This model is widely referred to as IP-VRF-to-IP-VRF routing because it enables inter-subnet routing at the leaf layer without requiring Layer 2 MAC learning for those specific prefixes.

Overlay Next Hop (Statement B): For a PE router to reach a prefix advertised via a Type 5 route, it must resolve the overlay next hop. This next hop is typically the loopback IP address of the originating VTEP, which the receiving router uses to build the VXLAN tunnel.

Why others are incorrect: Statement A is incorrect because Type 7 routes are used for IGMP/MLD join synchronization. Statement D is incorrect because Type 5 routes advertise IP prefixes, not MAC addresses; MAC extended communities are associated with Type 2 routes.