Check the Free demo of our JN0-351 Exam Dumps with 67 Questions [Q22-Q39]

Share

Check the Free demo of our JN0-351 Exam Dumps with 67 Questions

Clear your concepts with JN0-351 Questions Before Attempting Real exam


Juniper JN0-351 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Describe the concepts, benefits, operations
  • Demonstrate knowledge how to configure, monitor
Topic 2
  • Describe the concepts, operations, or functionalities of IS-IS
  • Describe the concepts, operations, or functionalities of OSPF
Topic 3
  • Demonstrate knowledge of how to configure, monitor, or troubleshoot BGP
  • Demonstrate knowledge of how to configure, monitor, or troubleshoot IP tunnels
Topic 4
  • Demonstrate knowledge how to configure, monitor
  • Port security, including MAC limiting, DHCP snooping
Topic 5
  • Describe the concepts, benefits, or functionalities of VLANs
  • STP and Rapid Spanning Tree Protocol (RSTP) concepts
Topic 6
  • Identify the concepts, benefits, or operations of Layer 2 firewall filters
  • Demonstrate knowledge how to configure, monitor, or troubleshoot Spanning Tree
Topic 7
  • Identify the concepts, benefits, applications
  • Demonstrate knowledge of how to configure, monitor

 

NEW QUESTION # 22
Exhibit.

The ispi _ inet. 0 route table has currently no routes in it.
What will happen when you commit the configuration shown on the exhibit?

  • A. The inet. 0 route table will be completely overwritten by the ispi . inet. 0 route table.
  • B. The ISPI . inet. 0 route table will be imported into the inet. 0 route table.
  • C. The ISPI . inet. 0 route table will be completely overwritten by the inet. o route table.
  • D. The inet. 0 route table will be imported into the ispi . inet. 0 route table.

Answer: D

Explanation:
Explanation
The configuration shown in the exhibit is an example of a routing instance of type virtual-router. A routing instance is a collection of routing tables, interfaces, and routing protocol parameters that create a separate routing domain on a Juniper device1. A virtual-router routing instance allows administrators to divide a device into multiple independent virtual routers, each with its own routing table2.
The configuration also includes a rib-group statement, which is used to import routes from one routing table to another. A rib-group consists of an import-rib statement, which specifies the source routing table, and an export-rib statement, which specifies the destination routing table.
In this case, the rib-group name is inet-to-ispi, and the import-rib statement specifies inet.0 as the source routing table. The export-rib statement specifies ispi.inet.0 as the destination routing table. This means that the routes from inet.0 will be imported into ispi.inet.0.
Therefore, the correct answer is B. The inet.0 route table will be imported into the ispi.inet.0 route table.
References:
1: Routing Instances Overview 2: Virtual Routing Instances : [rib-group (Routing Options)]


NEW QUESTION # 23
Exhibit

Referring to the exhibit, which two configuration changes must you apply for packets to reach from R1 to R3 using IS-IS? (Choose two.)

  • A. On R3 enable Level 1 on the ge-0/0/4 interface
  • B. On R3 disable Level 2 on the ge-0/0/4 interface.
  • C. On R1, disable Level 2 on the ge-0/0/1 interface.
  • D. On R1, enable Level 1 on the ge-0/0/1 interface.

Answer: A,D

Explanation:
Explanation
A: On R1, enable Level 1 on the ge-0/0/1 interface. In IS-IS, both levels (Level 1 and Level 2) are enabled by default when you enable IS-IS on an interface1. Level 1 systems route within an area2. If the destination is outside an area, Level 1 systems route toward a Level 2 system2. Therefore, enabling Level 1 on the ge-0/0/1 interface on R1 would allow packets to reach from R1 to R3.
D: On R3 enable Level 1 on the ge-0/0/4 interface Similarly, enabling Level 1 on the ge-0/0/4 interface on R3 would allow packets to reach from R1 to R3.
These explanations are based on the IS-IS configuration documents and learning resources available at Juniper Networks1 and Cisco34.


NEW QUESTION # 24
You are receiving multiple BGP routes from an upstream neighbor and only want to advertise a single summarized prefix to your internal OSPF neighbors. This route should only be advertised when you are receiving these BGP routes from this neighbor.
In this scenario, which type of route should you create?

  • A. static route using the resolve feature
  • B. static route using qualified next hops
  • C. aggregate route
  • D. generate route

Answer: C

Explanation:
Explanation
In this scenario, you should create an 1. Aggregate routes are used for advertising summarized network prefixes1. They help minimize the number of routing tables in an IP network by consolidating selected multiple routes into a single route advertisement1. This approach is in contrast to non-aggregation routing, in which every routing table contains a unique entry for each route1.
Therefore, option A is correct. Options B, C, and D are not correct because:
Static route using the resolve feature: This type of route uses the resolve feature to install a static route in the routing table only if a specific condition is met1. However, it does not provide the capability to summarize multiple routes into a single prefix.
Generate route: This type of route generates a route that is always present in the routing table and can be used to summarize routes. However, it does not have the capability to only advertise the route when specific BGP routes are being received from a neighbor1.
Static route using qualified next hops: This type of route allows for the specification of multiple next-hop addresses for a static route1. However, it does not provide the capability to summarize multiple routes into a single prefix.


NEW QUESTION # 25
Exhibit

Your ISP is announcing a default route to both R1 and R2. You want your network routers to forward all Internet traffic through the R1 device Which BGP attribute would you use?

  • A. MED
  • B. origin
  • C. next-hop
  • D. local preference

Answer: D

Explanation:
Explanation
The BGP attribute that you would use to forward all Internet traffic through the R1 device is the local preference1.
The local preference is an attribute that is used within an autonomous system (AS) and exchanged between iBGP routers1. It is used to select an exit point from the AS1. The path with the highest local preference is preferred1. By setting a higher local preference for the routes received from R1, you can make R1 the preferred exit point for all Internet traffic1.


NEW QUESTION # 26
A new network requires multiple topology support. You decide to use IS-IS in this situation. Which three protocol topologies are supported in this scenario? (Choose three.)

  • A. multicast
  • B. IPv6
  • C. IPsec
  • D. IPv4
  • E. anycast

Answer: A,B,D

Explanation:
Explanation
IS-IS (Intermediate System to Intermediate System) is a routing protocol that is designed to move information efficiently within a computer network12. It supports multiple protocol topologies, including IPv4, IPv6, and multicast12. Therefore, options C, E, and D are correct.


NEW QUESTION # 27
Exhibit.

You want to verify prefix information being sent from 10.36.1.4.
Which two statements are correct about the output shown in the exhibit? (Choose two.)

  • A. The routes displayed are being learned from an I BGP peer.
  • B. The output shows routes that are active and rejected by an import policy.
  • C. The routes displayed have traversed one or more autonomous systems.
  • D. The output shows routes that were received prior to the application of any BGP import policies.

Answer: C,D

Explanation:
Explanation
The output shown in the exhibit is the result of the command "show ip bgp neighbor 10.36.1.4 received-routes", which displays all received routes (both accepted and rejected) from the specified neighbor.
Option A is correct, because the routes displayed have traversed one or more autonomous systems. This can be seen from the AS_PATH attribute, which shows the sequence of AS numbers that the route has passed through. For example, the route 10.0.0.0/8 has an AS_PATH of 65001 65002, which means that it has traversed AS 65001 and AS 65002 before reaching the local router.
Option B is correct, because the output shows routes that were received prior to the application of any BGP import policies. This can be seen from the fact that some routes have a status code of "r", which means that they are rejected by an import policy. The"received-routes" keyword shows the routes coming from a given neighbor before the inbound policy has been applied. To see the routes after the inbound policy has been applied, the "routes" keyword should be used instead.
Option C is incorrect, because the output does not show routes that are active and rejected by an import policy.
The status code of "r" means that the route is rejected by an import policy, but it does not mean that it is active. The status code of ">" means that the route is active and selected as the best path. None of the routes in the output have both ">" and "r" status codes.
Option D is incorrect, because the routes displayed are not being learned from an IBGP peer. An IBGP peer is a BGP neighbor that belongs to the same AS as the local router. The output shows that the neighbor 10.36.1.4 has a remote AS of 65001, which is different from the local AS of 65002. Therefore, the neighbor is an EBGP peer, not an IBGP peer.


NEW QUESTION # 28
You have DHCP snooping enabled but no entries are automatically created in the snooping database for an interface on your EX Series switch. What are two reasons for the problem? (Choose two.)

  • A. MAC limiting is enabled on the interface.
  • B. The device that is connected to the interface has performed a DHCPRELEASE.
  • C. The device that is connected to the interface has a static IP address.
  • D. Dynamic ARP inspection is enabled on the interface.

Answer: A,C

Explanation:
Explanation
The DHCP snooping feature in Juniper Networks' EX Series switches works by building a binding database that maps the IP address, MAC address, lease time, binding type, VLAN number, and interface information1. This database is used to filter and validate DHCP messages from untrusted sources1.
However, there are certain conditions that could prevent entries from being automatically created in the snooping database for an interface:
MAC limiting: If MAC limiting is enabled on the interface, it could potentially interfere with the operation of DHCP snooping. MAC limiting restricts the number of MAC addresses that can be learned on a physical interface to prevent MAC flooding attacks1. This could inadvertently limit the number of DHCP clients that can be learned on an interface, thus preventing new entries from being added to the DHCP snooping database.
Static IP address: If the device connected to the interface is configured with a static IP address, it will not go through the DHCP process and therefore will not have an entry in the DHCP snooping database1. The DHCP snooping feature relies on monitoring DHCP messages to build its database1, so devices with static IP addresses that do not send DHCP messages will not have their information added.
Therefore, options B and C are correct. Options A and D are not correct because performing a DHCPRELEASE would simply remove an existing entry from the database1, and Dynamic ARP inspection (DAI) uses the information stored in the DHCP snooping binding database but does not prevent entries from being created1.


NEW QUESTION # 29
Which two types of tunnels are able to be created on all Junos devices? (Choose two.)

  • A. STP
  • B. IP-IP
  • C. GRE
  • D. IPsec

Answer: C,D

Explanation:
Explanation
Junos devices support various types of tunnels for different purposes12.
Option B is correct. Generic Routing Encapsulation (GRE) is a tunneling protocol that can encapsulate a wide variety of network layer protocols inside virtual point-to-point links over an Internet Protocol network1. Junos devices support GRE tunnels1.
Option D is correct. IPsec (Internet Protocol Security) is a protocol suite for securing Internet Protocol (IP) communications by authenticating and encrypting each IP packet of a communication session1. Junos devices support IPsec tunnels1.
Option A is incorrect. Spanning Tree Protocol (STP) is not a type of tunnel. It's a network protocol designed to prevent loops in a bridged Ethernet local area network2.
Option C is incorrect. While Junos devices do support IP-IP (also known as IP tunneling), it's not supported on all Junos devices1.


NEW QUESTION # 30
You are asked to connect an IP phone and a user computer using the same interface on an EX Series switch.
The traffic from the computer does not use a VLAN tag, whereas the traffic from the IP phone uses a VLAN tag.
Which feature enables the interface to receive both types of traffic?

  • A. DHCP snooping
  • B. MAC limiting
  • C. voice VLAN
  • D. native VLAN

Answer: C

Explanation:
Explanation
The feature that enables an interface on an EX Series switch to receive both untagged traffic (from the computer) and tagged traffic (from the IP phone) is the voice VLAN12.
The voice VLAN feature in EX-series switches enables access ports to accept both data (untagged) and voice (tagged) traffic and separate that traffic into different VLANs12. This allows the switch to differentiate between voice and data traffic, ensuring that voice traffic can be treated with a higher priority12. Therefore, option D is correct.


NEW QUESTION # 31
Refer to the exhibit.

Referring to the output shown in the exhibit, which statement is correct?

  • A. An MTU mismatch exists between the OSPF neighbors.
  • B. The state is normal for a DR neighbor.
  • C. An area ID mismatch exists between the OSPF neighbors
  • D. The state is normal for a DRother neighbor

Answer: D

Explanation:
Explanation
In OSPF, the state of the neighbor relationship is determined by the exchange of OSPF packets between routers1. The state "2Way" as shown in the exhibit indicates that bi-directional communication has been established between the two OSPF routers1. This is the normal state for a neighbor that is not the Designated Router (DR) or Backup Designated Router (BDR) on a broadcast, non-broadcast multi-access (NBMA), or point-to-multipoint network1. These neighbors are often referred to as "DRothers"1. Therefore, option B is correct.


NEW QUESTION # 32
Exhibit

Your BGP neighbors, one in the USA and one in France, are not establishing a connection with each other.
Referring to the exhibit, which statement is correct?

  • A. The BFD liveness must be configured on the BGP group.
  • B. The BFD liveness must be configured on the BGP neighbor.
  • C. The BFD liveness is set too high.
  • D. The BFD liveness is set too low.

Answer: B

Explanation:
Explanation
The exhibit shows the configuration of BFD liveness detection for BGP at the global level, which applies to all BGP neighbors by default1. However, this configuration does not specify the session mode, which determines whether BFD uses single-hop or multihop mode to communicate with a neighbor2.
For single-hop BGP neighbors, which are directly connected on the same subnet, the session mode can be either automatic or single-hop. For multihop BGPneighbors, which are not directly connected and require multiple hops to reach, the session mode must be multihop2.
Since your BGP neighbors are in different countries, they are likely to be multihop neighbors. Therefore, you need to configure the session mode as multihop for each neighbor individually at the [edit protocols bgp group group-name neighbor address bfd-liveness-detection] hierarchy level2. For example:
protocols { bgp { group usa { neighbor 192.0.2.1 { bfd-liveness-detection { session-mode multihop; } } } group france { neighbor 198.51.100.1 { bfd-liveness-detection { session-mode multihop; } } } } } If you do not configure the session mode for multihop neighbors, BFD will use the default mode of automatic, which will try to use single-hop mode and fail to establish a BFD session with the remote neighbor2. This will prevent BGP from using BFD to detect liveliness and failover.
Therefore, the answer B is correct, as you need to configure the BFD liveness detection on the BGP neighbor level with the appropriate session mode for multihop neighbors.


NEW QUESTION # 33
Which two statements about BGP facilitate the prevention of routing loops between two autonomous systems?
(Choose two.)

  • A. EBGP routers will append their AS number when advertising routes to their neighbors.
  • B. EBGP routers will prepend their AS number when advertising routes to their neighbors
  • C. EBGP routers will drop routes that contain their own AS number in the AS_PATH
  • D. EBGP routers will only accept routes that contain their own AS number in the AS_PATH.

Answer: A,C

Explanation:
Explanation
BGP (Border Gateway Protocol) is a protocol designed to exchange routing and reachability information among autonomous systems (AS) on the internet1.
Option A is correct. When an EBGP router advertises routes to its neighbors, it appends its AS number to the AS_PATH attribute1. This is a key mechanism in BGP to prevent routing loops1.
Option C is correct. BGP has a built-in loop prevention mechanism whereby if a BGP router detects its own AS in the AS_PATH attribute, it will drop the prefix and will not continue to advertise it2. This helps to prevent routing loops2.
Option B is incorrect. EBGP routers do not accept routes that contain their own AS number in the AS_PATH2. Instead, they drop such routes as part of the loop prevention mechanism2.
Option D is incorrect. While it's true that EBGP routers append their AS number when advertising routes, they do not prepend their AS number1. The term "prepend" in BGP usually refers to a technique used to influence path selection by artificially lengthening the AS_PATH3.


NEW QUESTION # 34
You are attempting to configure the initial two aggregated Ethernet interfaces on a router but there are no aggregated Ethernet interfaces available.
In this scenario, which configuration will enable these interfaces on this router?

  • A.
  • B.
  • C.
  • D.

Answer: B

Explanation:
Explanation
The correct answer to your question is
Option C shows the configuration of the statement, which defines the properties of the router chassis, such as the number of aggregated Ethernet interfaces, the number of FPCs, and the number of PICs1.
To enable aggregated Ethernet interfaces on a router, you need to specify the aggregated-devices statement under the chassis parameter to the desired number of interfaces2. For example, to enable two aggregated Ethernet interfaces, you can use the following configuration:
chassis { aggregated-devices { ethernet { device-count 2; } } }
Option C shows this configuration with the device-count set to 2, which will enable two aggregated Ethernet interfaces on the router. The other options do not show this configuration and will not enable any aggregated Ethernet interfaces on the router.
Therefore, option C is the correct answer to your question.


NEW QUESTION # 35
You have two OSPF routers forming an adjacency. R1 has a priority of 32 and a router ID of 192.168.1.2. R2 has a priority of 64 and a router ID of 192.168.1.1. The routers were started at the same time and all other OSPF settings are the default settings.
Which statement is correct in this scenario?

  • A. Router IDs must match for an adjacency to form.
  • B. At least three routers are required for a DR/BDR election
  • C. R2 will be the BDR.
  • D. R1 will be the BDR.

Answer: D

Explanation:
Explanation
In OSPF, the Designated Router (DR) and Backup Designated Router (BDR) are elected based on the priority of the routers1. The router with the highest priority becomes the DR, and the router with the second highest priority becomes the BDR1. If there is a tie in priority, then the router with the highest Router ID is chosen1.
In this scenario, R2 has a higher priority (64) than R1 (32), so R2 will become the DR1. Since R1 has the second highest priority, it will become the BDR1. Therefore, option D is correct.


NEW QUESTION # 36
Which two statements are correct about using firewall filters on EX Series switches? (Choose two.)

  • A. You can apply firewall filters to both Layer 2 and Layer 3 traffic on an EX Series switch.
  • B. You can deploy both stateless and stateful firewall filters on an EX Series switch.
  • C. You can only apply firewall filters to Layer 2 traffic on an EX Series switch.
  • D. You can deploy only stateless firewall filters on an EX Series switch.

Answer: A,D

Explanation:
A is correct because you can deploy only stateless firewall filters on an EX Series switch. A stateless firewall filter is a filter that evaluates each packet individually based on the header information, such as source and destination addresses, protocol, and port numbers1. A stateless firewall filter does not keep track of the state or context of a packet flow, such as the sequence number, flags, or sessioninformation1. EX Series switches support only stateless firewall filters, which are also called access control lists (ACLs) or packet filters2.
C is correct because you can apply firewall filters to both Layer 2 and Layer 3 traffic on an EX Series switch. Layer 2 traffic is traffic that is switched within a VLAN or a bridge domain, while Layer 3 traffic is traffic that is routed between VLANs or networks3. EX Series switches support three types of firewall filters: port (Layer 2) firewall filters, VLAN firewall filters, and router (Layer 3) firewall filters4. You can apply these filters to different interfaces and directions to control the traffic entering or exiting the switch.


NEW QUESTION # 37
Exhibit

Referring to the exhibit, which statement is correct?

  • A. The local device is using a bridge priority of 4k.
  • B. The root bridge is using a bridge priority of 4k.
  • C. The local device is the root bridge for this RSTP topology.
  • D. The root bridge has not been elected for this RSTP topology.

Answer: C

Explanation:
Explanation
In a Rapid Spanning Tree Protocol (RSTP) topology, the root bridge is determined by the switch with the lowest bridge priority value12. If all switches have the same priority, then the root bridge is assigned to the switch whose MAC address's hex value is the lowest2. The default bridge priority value is 3276832. However, without the actual exhibit, it's difficult to definitively determine which device is the root bridge. But based on the options provided, if we assume that the local device has a lower bridge priority or a lower MAC address than other devices in the network, then it could be considered as the root bridge for this RSTP topology45.


NEW QUESTION # 38
Which three protocols support BFD? (Choose three.)

  • A. FTP
  • B. RSTP
  • C. LACP
  • D. OSPF
  • E. BGP

Answer: C,D,E

Explanation:
Explanation
BFD is a protocol that can be used to quickly detect failures in the forwarding path between two adjacent routers or switches. BFD can be integrated with various routing protocols and link aggregation protocols to provide faster convergence and fault recovery.
According to the Juniper Networks documentation, the following protocols support BFD on Junos OS devices1:
BGP: BFD can be used to monitor the connectivity between BGP peers and trigger a session reset if a failure is detected. BFD can be configured for both internal and external BGP sessions, as well as for IPv4 and IPv6 address families2.
OSPF: BFD can be used to monitor the connectivity between OSPF neighbors and trigger a state change if a failure is detected. BFD can be configured for both OSPFv2 and OSPFv3 protocols, as well as for point-to-point and broadcast network types3.
LACP: BFD can be used to monitor the connectivity between LACP members and trigger a link state change if a failure is detected. BFD can be configured for both active and passive LACP modes, as well as for static and dynamic LAGs4.
Other protocols that support BFD on Junos OS devices are:
IS-IS: BFD can be used to monitor the connectivity between IS-IS neighbors and trigger a state change if a failure is detected. BFD can be configured for both level 1 and level 2 IS-IS adjacencies, as well as for point-to-point and broadcast network types.
RIP: BFD can be used to monitor the connectivity between RIP neighbors and trigger a route update if a failure is detected. BFD can be configured for both RIP version 1 and version 2 protocols, as well as for IPv4 and IPv6 address families.
VRRP: BFD can be used to monitor the connectivity between VRRP routers and trigger a priority change if a failure is detected. BFD can be configured for both VRRP version 2 and version 3 protocols, as well as for IPv4 and IPv6 address families.
The protocols that do not support BFD on Junos OS devices are:
RSTP: RSTP is a spanning tree protocol that provides loop prevention and rapid convergence in layer 2 networks. RSTP does not use BFD to detect link failures, but relies on its own hello mechanism that sends BPDU packets every 2 seconds by default.
FTP: FTP is an application layer protocol that is used to transfer files between hosts over a TCP connection. FTP does not use BFD to detect connection failures, but relies on TCP's own retransmission and timeout mechanisms.
References:
1: [Configuring Bidirectional Forwarding Detection] 2: [Configuring Bidirectional Forwarding Detection for BGP] 3: [Configuring Bidirectional Forwarding Detection for OSPF] 4: [Configuring Bidirectional Forwarding Detection for Link Aggregation Control Protocol] : [Configuring Bidirectional Forwarding Detection for IS-IS] : [Configuring Bidirectional Forwarding Detection for RIP] : [Configuring Bidirectional Forwarding Detection for VRRP] : [Understanding Rapid Spanning Tree Protocol] : [Understanding FTP]


NEW QUESTION # 39
......

Get professional help from our JN0-351 Dumps PDF: https://www.actual4dumps.com/JN0-351-study-material.html

Give You Free Regular Updates on JN0-351 Exam Questions: https://drive.google.com/open?id=1bGjsGG3fBE503TWoiNHxMpzkbTEK2Emz