Use Juniper JN0-352 Dumps To Succeed Instantly in JN0-352 Exam
Ultimate Guide to JN0-352 Dumps - Enhance Your Future Career Now
NEW QUESTION # 33
Which two statements are correct about tunnels? (Choose two.)
- A. Tunnel endpoints must have a valid route to the remote tunnel endpoint.
- B. BFD cannot be used to monitor tunnels.
- C. Tunnels add additional overhead to packet size.
- D. IP-IP tunnels are stateful.
Answer: A,C
Explanation:
For a tunnel to be established, the endpoints must have a route to each other. This is essential for the encapsulated packets to reach their destination.
Tunnels encapsulate packets, adding extra headers for the encapsulation protocol, which increases the overall packet size.
NEW QUESTION # 34
When electing a DIS in an IS-IS network, what is used to break a priority tie?
- A. highest MAC address
- B. lowest MAC address
- C. lowest router ID
- D. highest router ID
Answer: A
NEW QUESTION # 35
Which two events cause a router to advertise a connected network to OSPF neighbors? (Choose two.)
- A. When a static route to the 224.0.0.5 address is created.
- B. When a static route to the 224.0.0.6 address is created.
- C. When an OSPF adjacency is established.
- D. When an interface has the OSPF passive option enabled.
Answer: C,D
Explanation:
When an OSPF adjacency is established, the router will begin to advertise its connected networks to its OSPF neighbors.
When an interface is configured with the OSPF passive option, the router will advertise the connected network but will not attempt to form OSPF adjacencies on that interface.
NEW QUESTION # 36
How would you view the metric assigned to a route in OSPF? (Choose two.)
- A. Use the show ospf interface command.
- B. Use the show route protocol ospf command.
- C. Use the show ospf route intra command.
- D. Use the show ospf database extensive command.
Answer: B,C
Explanation:
The metric that OSPF assigns to a destination is visible from two complementary vantage points in Junos. The show route protocol ospf command displays the main routing table filtered to OSPF-learned prefixes, and each entry shows the computed cost alongside the next hop, exactly as it was installed after SPF calculation.
The show ospf route command (which accepts filters such as intra-area, inter-area, and extern) presents the OSPF-specific routing table, organized by route type, and explicitly lists the metric column for every intra- area, inter-area, and external route the local router has calculated. Together these two commands give both the RIB-level and the protocol-level view of route cost. By contrast, show ospf database extensive dumps the raw link-state advertisements, where metrics appear only as link-level values buried inside Router or Network LSAs rather than as a resolved route cost, so it is not the direct tool for viewing a route's metric. show ospf interface reports interface operational state, area, and DR/BDR information but does not present a cost or metric field at all in its standard output. Candidates should be comfortable distinguishing the RIB-oriented and protocol-table-oriented verification commands, since JNCIS-ENT scenarios frequently test whether a candidate reaches for the correct show command layer during troubleshooting. Reference topics: Junos Enterprise Routing - OSPF Operation and Verification, Monitoring OSPF.
NEW QUESTION # 37
Which two statements describe OSPF DR and BDR behavior? (Choose two.)
- A. The DR by default generates Type-2 Network LSAs to describe the multi-access segment.
- B. The BDR by default generates Type-2 Network LSAs to describe the multi-access segment.
- C. The BDR becomes the DR if the DR fails.
- D. The DR elects the area border router for each area.
Answer: A,C
Explanation:
The Backup Designated Router exists specifically to provide immediate failover redundancy for the Designated Router role on a multi-access broadcast or NBMA segment: the BDR maintains full adjacencies with every other router on the segment concurrently with the DR, precisely so that if the DR ever fails or is withdrawn, the BDR can be promoted directly to DR essentially instantaneously, without needing to wait through a fresh, full DR/BDR election process, and a new BDR election then takes place separately among the remaining DROther routers to fill the now-vacant backup role. This immediate promotion behavior confirms the first statement as correct. The Designated Router's other core responsibility on the segment is originating the Type 2 Network LSA, which describes the multi-access network itself as a pseudonode, listing every router attached to that segment; this LSA type exists specifically to avoid the full-mesh explosion of Router LSA adjacency listings that would otherwise be needed to describe a shared broadcast segment, and only the DR - never the BDR, and never any DROther - is responsible for generating and maintaining this particular LSA under normal, stable conditions, which confirms the third statement while directly ruling out the fourth. There is no such thing as the DR 'electing' an area border router; ABR status is instead a role a router acquires organically by having interfaces in more than one OSPF area, entirely independent of any DR
/BDR election process on any individual segment. Reference topics: Junos Enterprise Routing - OSPF, DR
/BDR Roles and Type 2 Network LSA Origination.
NEW QUESTION # 38
You are a network operator troubleshooting BGP connectivity.
Which two statements are correct about the output shown in the exhibit? (Choose two.)
- A. The R1 is configured for AS 65400.
- B. Peer 10.32.1.2 is configured for AS 63645.
- C. The routers are exchanging IPv4 routes.
- D. The BGP session is not established.
Answer: A,C
Explanation:
The local AS is 65400, as indicated by "Local AS: 65400".
The output shows "NLRI for this session: inet-unicast", which indicates that the routers are exchanging IPv4 unicast routes.
NEW QUESTION # 39
What does the * indicate in the output shown in the exhibit?
- A. The switch ports have a router attached.
- B. All interfaces have elected a root bridge.
- C. The interface is active.
- D. The interface is down.
Answer: C
Explanation:
The exhibit shows the output of the command show vlans brief, which displays brief information about VLANs and their associated interfaces.
The output has four columns: Routing instance, VLAN name, Interfaces, and Tagging. The * symbol indicates that the interface is active, meaning that it is up and forwarding traffic. This can be verified by the command show interfaces terse, which displays the status of the interfaces.
NEW QUESTION # 40
Referring to the exhibit, the local router should have an IS-IS adjacency with a neighboring router, but the adjacency never establishes correctly.
What should you do to solve the problem?
- A. Disable level 2 for the interfaces.
- B. Change the local IS-IS area ID to 49.0002.
- C. Disable level 1 for the interfaces.
- D. Disable wide metrics.
Answer: B
NEW QUESTION # 41
Which two statements are correct about VRRP? (Choose two.)
- A. The virtual IP address must be unique on all participating devices
- B. The VRRP group number must match on all participating devices
- C. The virtual IP address must match on all participating devices
- D. The VRRP group number must be unique on all participating devices
Answer: B,C
Explanation:
The virtual IP address must match on all participating devices - All routers in the same VRRP group must be configured with the same virtual IP address to provide redundancy.
The VRRP group number must match on all participating devices - All routers in the same VRRP group must have the same group number to identify the VRRP group.
NEW QUESTION # 42
You are deploying a Juniper Networks EX Series Switch to connect 24 end devices to VLAN 70, with an uplink interface to a distribution switch that carries VLANs 30, 50, and 70. You need to correctly configure the interface type for the end-device interfaces.
In this scenario, which statement is correct?
- A. Use access mode and assign the interfaces to VLAN 70.
- B. Use trunk mode with VLAN 70 set as the native VLAN.
- C. No configuration is needed since VLAN 70 is the highest VLAN-ID.
- D. Use trunk mode with VLAN 70 as the only allowed VLAN.
Answer: A
Explanation:
Each of the 24 end-device-facing interfaces in this scenario needs to carry traffic for exactly one VLAN, and the end devices themselves are ordinary hosts that neither expect nor generate 802.1Q-tagged frames. This is precisely the definition of an access port in Junos: family ethernet-switching interface-mode is set to access, and a single vlan members statement assigns the port to VLAN 70. Access mode ensures frames egressing toward the host are untagged and any frames received are implicitly treated as belonging to the configured VLAN, which is both simpler to manage and more efficient than trunking, since access ports do not carry the
802.1Q tag overhead nor process VLAN pruning logic relevant only to multi-VLAN links. Trunk mode, by contrast, is reserved for switch-to-switch or switch-to-router links that must simultaneously carry frames for multiple VLANs, such as the uplink toward the distribution switch that transports VLANs 30, 50, and 70 together - configuring the 24 host-facing ports as trunks (with or without a native VLAN) would be functionally incorrect and operationally wasteful, since end devices have no need to interpret VLAN tags.
There is also no such behavior in Junos where VLAN-ID numeric value dictates default port behavior, making the 'no configuration needed' option a distractor with no basis in EX Series switching architecture.
Reference topics: Junos Enterprise Switching - VLANs, Configuring Access and Trunk Port Modes.
NEW QUESTION # 43
What determines the preferred route to a destination in an IS-IS network?
- A. the path that passes through a Level 2 router closest to the destination
- B. the path that has the highest accumulated metric value
- C. the path that has the lowest accumulated metric value
- D. the path that has the most recently originated LSP
Answer: C
Explanation:
IS-IS is a link-state protocol that, like OSPF, runs Dijkstra's Shortest Path First algorithm independently on each router against its own copy of the synchronized link-state database to compute the best path toward every reachable destination. Each link within the topology carries an administrator-assigned or default metric, and as the SPF algorithm walks the topology graph from the local router outward, it sums the metrics of every link traversed along a candidate path to produce that path's total accumulated cost. Among all possible paths to a given destination prefix, IS-IS always selects and installs the path (or, in the case of equal-cost multipath, the set of paths) with the numerically lowest total accumulated metric, exactly mirroring the 'lowest cost wins' principle shared by essentially all link-state IGPs. A higher accumulated metric value is by definition a less preferred, more costly path, making that option the direct inverse of correct IS-IS behavior. Level 2 proximity to the destination has no independent bearing on path selection beyond however it happens to be reflected in the accumulated metric itself - IS-IS does not apply a separate rule preferring paths merely for passing near a Level 2 router. Likewise, LSP recency (sequence number or freshness) governs which version of a given LSP is trusted and flooded during database synchronization, ensuring the topology database itself is accurate and loop-free, but it plays no role in the SPF cost comparison once the database is synchronized and consistent. Reference topics: Junos Enterprise Routing - IS-IS, SPF Calculation and Metric-Based Path Selection.
NEW QUESTION # 44
Which statement is true about IP-IP tunnels?
- A. IP-IP tunnels are protocol agnostic.
- B. The time-to-live value of the original packet is decremented.
- C. The packet header is replaced before entering the tunnel.
- D. The packet is encapsulated unchanged before entering the tunnel.
Answer: A
NEW QUESTION # 45
Referring to the output shown in the exhibit, which statement is correct?
- A. 11.0.0.108/32 is being per-flow load-balanced
- B. 11.0.0.102/32 is being per-flow load-balanced
- C. 11.0.0.108/32 is being per-packet load-balanced
- D. 11.0.0.102/32 is being per-packet load-balanced
Answer: C
NEW QUESTION # 46
Which statement concerning Bidirectional Forwarding Detection (BFD) is true for the configuration shown in the exhibit?
- A. The effective interval for neighbor 172.30.1.2 is 500 ms.
- B. The minimum-interval must match on both ends.
- C. The effective interval for neighbor 192.168.100.2 is 500 ms.
- D. The link to neighbor 192.168.100.2 is not using BFD.
Answer: C
NEW QUESTION # 47 
Click the Exhibit button.
You are asked to ensure that there will not be any unwanted STP topology changes affecting your root bridge placement because a rogue switch was introduced into the network at the access layer.
Referring to the exhibit, which interfaces will need to have root protection applied to accomplish this task?
- A. Place root protection on ge-0/0/6 and ge-0/0/8 on Switch-3 and Switch-4.
- B. Place root protection on ge-0/0/6 and ge-0/0/8 on Switch-1 only.
- C. Place root protection on ge-0/0/12 and ge-0/0/13 on Switch-1 and Switch-2.
- D. Place root protection on ge-0/0/6 and ge-0/0/8 on Switch-1 and Switch-2.
Answer: D
Explanation:
Root protection (root guard) must always be applied on the ports of the switches you trust to remain root- bridge-eligible, specifically on the interfaces facing away from the legitimate root and toward parts of the network where an untrusted or rogue device could plausibly appear and begin transmitting superior BPDUs.
In this topology, Switch-1 is the intended, permanent root bridge (lowest priority, 4k), and Switch-2 is its aggregation-layer peer; both sit above the access layer, where Switch-3 and Switch-4 connect downstream toward end-user-facing infrastructure and where an accidental or malicious rogue switch is realistically most likely to be introduced. The ge-0/0/6 and ge-0/0/8 interfaces on Switch-1 and Switch-2 are precisely the downlink ports facing that access layer, meaning they are the exact points at which a rogue switch's superior BPDU (one advertising a lower priority than the legitimate root) would first be received if such a device appeared beneath Switch-3 or Switch-4. Applying root protection on those specific interfaces causes Junos to immediately block (move to a root-inconsistent, discarding state) any port that receives a superior BPDU, preventing the rogue device from ever being accepted as root, while normal, non-superior BPDUs continue to be processed without disruption. Applying root guard on Switch-1 and Switch-2's peer link (ge-0/0/12/13) would be inappropriate, since that link legitimately connects two trusted, root-eligible switches. Reference topics: Junos Enterprise Switching - Spanning Tree Protocols, Root Protection Placement Strategy.
NEW QUESTION # 48
You need to block SSH (TCP port 22) traffic from the 192.168.10.0/24 network.
Which firewall filter term is correct in this scenario?
- A. term block-ssh { from { source-address 192.168.10.0/24; service ssh; } then reject; }
- B. term block-ssh { from { destination-address 192.168.10.0/24; protocol tcp; destination-port 22; } then discard; }
- C. term block-ssh { from { source-address 192.168.10.0/24; protocol tcp; source-port 22; } then discard; }
- D. term block-ssh { from { source-address 192.168.10.0/24; protocol tcp; destination-port 22; } then discard; }
Answer: D
Explanation:
Correctly blocking SSH traffic originating from a specific network requires matching three precise conditions simultaneously in the from clause: the traffic's source-address must equal the 192.168.10.0/24 network, since the requirement is to block traffic coming from that network rather than traffic destined to it; the protocol must be explicitly set to tcp, since SSH operates exclusively over TCP; and the destination-port must be set to
22, because an inbound SSH connection request is always directed at the well-known SSH listening port 22 on the receiving side, regardless of which ephemeral source port the initiating client happens to use. The first option satisfies all three conditions correctly and pairs them with a discard action, cleanly dropping matching traffic. The second option incorrectly substitutes destination-address for source-address, which would match traffic heading toward that /24 rather than traffic originating from it, inverting the intended match direction.
The third option incorrectly uses source-port 22 instead of destination-port 22; since the SSH client's source port is a randomly assigned ephemeral value rather than a fixed 22, this term would almost never match real SSH session-initiation traffic. The fourth option relies on a service ssh match condition, which is not valid syntax within the standard Junos firewall filter grammar for family inet; there is no such application-based keyword available at that hierarchy, making the term invalid regardless of the reject action chosen. Reference topics: Junos Enterprise Switching - Firewall Filters, Matching on Address, Protocol, and Port Conditions.
NEW QUESTION # 49
You need to configure a LAG between your switches. In this scenario, which two statements are correct? (Choose two.)
- A. Duplex and speed settings are not required to match on both participating devices.
- B. Duplex and speed settings are required to match on both participating devices.
- C. Member links are not required to be contiguous ports.
- D. Member links are required to be contiguous ports.
Answer: B,C
Explanation:
Up to 64 Ethernet interfaces can be grouped to form a LAG, and In a Junos Fusion, up to 1,000 LAGs are supported on QFX10002 switches acting as aggregation devices.
The LAG must be configured on both sides of the link.
The interfaces on either side of the link must be set to the same speed and be in full-duplex mode.
NEW QUESTION # 50
You are verifying a new BGP peering session with an ISP. You issue the show bgp summary command, but the output shows the peer in the Active state.
Which statement is correct in this scenario?
- A. The session is waiting to be configured.
- B. The session is idle and disabled.
- C. The session is established, and routing information is being exchanged.
- D. The session is actively trying to establish a TCP connection.
Answer: D
Explanation:
The BGP finite state machine defined in RFC 4271 progresses through Idle, Connect, Active, OpenSent, OpenConfirm, and finally Established. The Active state is entered either directly after Idle, when the local router begins retrying a TCP connection setup toward the configured peer, or after a previous Connect attempt has failed and the ConnectRetry timer has expired, prompting the router to keep trying to complete the underlying TCP three-way handshake. Seeing a peer parked in Active therefore means the local device has a fully valid neighbor configuration and is persistently attempting to reach the remote address on TCP port 179, but the handshake is not succeeding - common root causes include a firewall or ACL blocking TCP 179 between the two endpoints, an unreachable or incorrect peer IP address, the remote BGP process not running or not listening, or an asymmetric routing path preventing the SYN/ACK from returning. It does not indicate a misconfiguration on the local box in the sense of a missing statement (that would typically leave the session as Idle), nor does it indicate an established, functioning session exchanging UPDATE messages (that state is Established), and it is not a deliberately idle/disabled condition, which Junos reports plainly as Idle.
Recognizing Active as 'trying to connect' rather than 'connected' is essential for correct BGP troubleshooting sequencing. Reference topics: Junos Enterprise Routing - BGP Fundamentals, BGP Finite State Machine and Session Verification.
NEW QUESTION # 51
Which two actions are performed by the firewall filter shown in the exhibit? (Choose two.)
- A. All traffic is permitted.
- B. Term two requires a fromstatement.
- C. Frames with the 88:05:00:29:3c:de source MAC address are accepted and logged.
- D. Frames without the 88:05:00:29:3c:de source MAC address are discarded and logged.
Answer: A,C
NEW QUESTION # 52
Which two statements about BGP facilitate the prevention of routing loops within an autonomous system? (Choose two.)
- A. IBGP sessions must be configured as a physical full mesh.
- B. IBGP sessions must be configured as a logical full mesh.
- C. Routes learned from IBGP neighbors are not readvertised to other IBGP neighbors.
- D. Routes learned from IBGP neighbors are only advertised to other IBGP neighbors.
Answer: B,C
NEW QUESTION # 53
Which two statements describe the purpose of a BGP notification message? (Choose two.)
- A. It reports the specific reason why the session must end.
- B. It updates route attributes and keeps the session active.
- C. It refreshes the neighbor's routing table without resetting the session.
- D. It ends the BGP session when a fatal error is detected.
Answer: A,D
Explanation:
A BGP NOTIFICATION message is one of the four core message types defined in RFC 4271, alongside OPEN, UPDATE, and KEEPALIVE, and it serves a very specific and narrow purpose within the protocol:
whenever a BGP speaker detects an unrecoverable, fatal condition in the session - such as a malformed OPEN message, an unsupported capability, a hold-timer expiration, a finite-state-machine error, or an administratively initiated reset - it transmits a NOTIFICATION message to its peer immediately before closing the underlying TCP connection and tearing down the session entirely. This confirms that a NOTIFICATION always signals the termination of the session upon a fatal error, never a routine, in-session update. Structurally, every NOTIFICATION message carries a defined error code and error subcode field, which together precisely classify the category and specific nature of the fault that triggered the termination (for example, 'Cease' with a subcode indicating administrative shutdown, or 'Update Message Error' with a subcode indicating a malformed attribute), giving the receiving peer's administrator concrete diagnostic information about exactly why the session was torn down. Updating route attributes while keeping a session alive is the role of the UPDATE message, not NOTIFICATION, and refreshing a neighbor's table without resetting the session describes the optional Route Refresh capability (a separate, distinct BGP mechanism), neither of which describes NOTIFICATION's function. Reference topics: Junos Enterprise Routing - BGP, BGP Message Types and the NOTIFICATION Message.
NEW QUESTION # 54
Which three protocols support BFD? (Choose three.)
- A. RSTP
- B. LACP
- C. OSPF
- D. BGP
- E. FTP
Answer: B,C,D
Explanation:
https://www.juniper.net/documentation/us/en/software/junos/high-availability/topics/topic-map/bfd-configuring.html
NEW QUESTION # 55
Which two statements are correct about link aggregation? (Choose two.)
- A. All RE-generated traffic traverses the lowest member link.
- B. IP traffic is hashed using source and destination MAC addresses.
- C. Member links must use the same MTU.
- D. LAGs provide physical layer redundancy.
Answer: C,D
NEW QUESTION # 56
Which statement about aggregate routes is correct?
- A. Aggregate routes are used for advertising summarized network prefixes.
- B. Aggregate routes are always preferred over more specific routes, even when the specific routes have a better path.
- C. Aggregate routes are automatically generated for all of the subnets in a routing table.
- D. Aggregate routes can only be used for static routing but not for dynamic routing protocols.
Answer: A
Explanation:
Aggregate routes are used for advertising summarized network prefixes. They help minimize the number of routing tables in an IP network by consolidating selected multiple routes into a single route advertisement. This approach is in contrast to non-aggregation routing, in which every routing table contains a unique entry for each route.
Therefore, option D is correct. Options A, B, and C are not correct because:
Aggregate routes can be used with both static routing and dynamic routing protocols. Aggregate routes are not automatically generated for all of the subnets in a routing table. They need to be manually configured.
Aggregate routes are not always preferred over more specific routes. The route selection process in Junos OS considers several factors, including route preference and metric, before determining the active route.
NEW QUESTION # 57
An update to your organization's network security requirements document requires management traffic to be isolated in a non-default routing-instance. You want to implement this requirement on your Junos-based devices.
Which two commands enable this behavior? (Choose two.)
- A. set routing--instances mgmtjunoa interface ge-0/0/0.0
- B. set routing--instances mgmt_junos
- C. set system management--instance
- D. set routing--instances mgmt_junos interface em1
Answer: B,C
Explanation:
To isolate management traffic in a non-default routing-instance on Junos-based devices, you can use the set system management-instance and set routing-instances mgmt_junos commands. set system management-instance: This command associates the management interface (usually named fxp0 or em0 for Junos OS, or re0:mgmt-* or re1:mgmt-* for Junos OS Evolved) with the non- default virtual routing and forwarding (VRF) instance. After you configure the non-default management VRF instance, management traffic no longer has to share a routing table with other control traffic or protocol traffic.
set routing-instances mgmt_junos: This command creates a new routing instance named mgmt_junos. The name of the dedicated management VRF instance is reserved and hardcoded as mgmt_junos; you cannot configure any other routing instance by the name mgmt_junos.
Therefore, options C and D are correct. Options A and B are not correct because they attempt to assign an interface to the mgmt_junos routing instance, which is not necessary for isolating management traffic.
NEW QUESTION # 58
......
Juniper Dumps - Learn How To Deal With The Exam Anxiety: https://www.examsreviews.com/JN0-352-pass4sure-exam-review.html