View Full Juniper JN0-336 Exam Dumps and Practice Test Dumps
Question 321.
Which BGP attribute is primarily used to influence outbound path selection within an AS?
- Local preference
- MED value
- Origin code
- AS path length
Correct Answer: 1
Explanation:
BGP local preference is an attribute used within an autonomous system to influence which exit path routers prefer for outbound traffic. A higher local-preference value is generally preferred when selecting among available BGP routes. Because it is propagated through the internal BGP domain, administrators can consistently influence outbound routing decisions across multiple routers. MED serves a different purpose by providing information about preferred entry points into an AS. AS path length and origin type are also considered during BGP route selection, but they do not provide the same internal outbound-path control as local preference.
Question 322.
Which BGP attribute can suggest a preferred entry point into an autonomous system?
- Local preference
- MED
- Community
- Router ID
Correct Answer: 2
Explanation:
The Multi-Exit Discriminator, or MED, is a BGP attribute that can communicate a preference for which entry point should be used when another autonomous system has multiple connections into the advertising AS. A lower MED is generally preferred when comparing otherwise suitable routes from the same neighboring AS. MED is commonly used to influence inbound traffic decisions, although its actual effect depends on routing policy and implementation. Local preference instead controls outbound path selection inside an AS, while communities and router IDs serve different purposes in BGP processing.
Question 323.
Which BGP feature allows routes to be grouped for policy matching?
- Router IDs
- MED values
- Communities
- Origin codes
Correct Answer: 3
Explanation:
BGP communities provide a flexible method for tagging routes with attributes that can later be matched by routing policies. Administrators can use communities to classify routes according to business, topology, or administrative requirements. Policies can then apply different actions to routes carrying particular community values. This makes communities useful for controlling route advertisements, preferences, filtering, and other routing behavior across an environment. Router IDs identify BGP speakers, MED communicates path information between autonomous systems, and origin codes describe how routes entered BGP. Communities therefore provide the tagging mechanism described in this question.
Question 324.
Which OSPF feature connects an area to another area when direct connectivity is unavailable?
- Passive interface
- DR election
- Authentication
- Virtual link
Correct Answer: 4
Explanation:
An OSPF virtual link provides a logical connection through an existing OSPF area when an area requires connectivity to the backbone but does not have the required direct physical or logical connection. The virtual link is configured between two routers that share a transit area, allowing OSPF control traffic to traverse that area. This mechanism is particularly associated with maintaining Area 0 connectivity in certain network designs. Passive interfaces prevent adjacency formation on selected interfaces, DR election manages multiaccess segments, and authentication protects routing exchanges rather than extending backbone connectivity.
Question 325.
What is the primary purpose of an OSPF passive interface?
- Reduce route metrics
- Suppress hello transmission
- Change area numbers
- Elect additional DRs
Correct Answer: 2
Explanation:
An OSPF passive interface prevents OSPF neighbor adjacency formation on that interface while still allowing the connected network to be advertised through OSPF. This is useful on interfaces where no OSPF neighbor should exist, such as user-facing or certain edge segments. By suppressing OSPF hello exchanges, unnecessary adjacency attempts are avoided and the interface does not participate in neighbor discovery. The connected prefix can nevertheless remain part of the OSPF topology. Passive interfaces do not modify route metrics, change area assignments, or create additional designated routers.
Question 326.
On a broadcast OSPF network, which routers establish the designated-router role?
- Highest interface cost
- Lowest router ID
- Highest router priority
- Longest uptime
Correct Answer: 3
Explanation:
On a broadcast OSPF network, designated-router election uses OSPF interface priority as a major selection factor. The router with the highest eligible priority becomes the DR, while another eligible router can become the BDR. If priorities are equal, the router ID is used as a tie-breaking factor. DR and BDR roles reduce the number of full adjacencies required on multiaccess networks and help optimize OSPF flooding behavior. Interface cost, router uptime, and other operational characteristics are not the primary criteria for selecting the DR.
Question 327.
Which security mechanism can protect BGP sessions from unauthorized peers?
- TCP authentication
- OSPF encryption
- DNS validation
- ICMP filtering
Correct Answer: 1
Explanation:
BGP sessions can use TCP authentication mechanisms to provide stronger protection against unauthorized or forged session establishment. TCP MD5 authentication, where supported, can validate segments exchanged between configured BGP peers using a shared secret. This helps protect the control-plane relationship from certain spoofing and session-injection attempts. BGP itself does not use OSPF encryption or DNS validation for peer authentication. ICMP filtering can control diagnostic traffic but does not authenticate BGP sessions. Appropriate BGP session protection should therefore be combined with peer restrictions and routing policy controls.
Question 328.
Which BGP policy action commonly changes the next hop to the local router?
- Community tagging
- MED modification
- Next-hop self
- AS-path removal
Correct Answer: 3
Explanation:
The next-hop self behavior causes a BGP router to advertise itself as the next-hop address when advertising routes to another BGP peer. This is particularly useful in internal BGP designs where the original external next hop may not be reachable by internal routers. By making the advertising router the next hop, the routing topology becomes easier to manage and can prevent recursive forwarding problems. Community tagging only attaches classification information, MED modification changes a path attribute, and AS-path manipulation affects path information rather than directly replacing the next-hop address.
Question 329.
What does route leaking between routing instances allow?
- Shared interface ownership
- Cross-instance route exchange
- Duplicate security zones
- Common authentication tables
Correct Answer: 2
Explanation:
Route leaking allows selected routes to be exchanged between separate routing instances. Routing instances normally maintain independent routing information, which provides logical separation for different networks or administrative domains. In some designs, however, one instance may need controlled access to routes maintained by another instance. Route leaking enables this exchange through explicit configuration and policy mechanisms. It does not merge the routing instances into one table or automatically share all routes. Proper filtering is important because only intended prefixes should cross the routing-instance boundary.
Question 330.
Which NAT behavior translates source ports along with source addresses?
- Static mapping
- Address-only translation
- Port-address translation
- Destination rewriting
Correct Answer: 3
Explanation:
Port-address translation, commonly called PAT, translates source IP addresses while also modifying source port numbers when necessary to distinguish multiple sessions sharing a translated address. This allows numerous internal hosts to access external networks using a smaller pool of public addresses. The translated port information is maintained in the session state so return traffic can be mapped to the correct internal connection. Static mappings generally provide fixed address relationships, while destination rewriting changes destination information. PAT therefore provides the port-sharing behavior described in this question.
Question 331.
How does a NAT pool typically allocate addresses for translated sessions?
- From configured pool members
- From OSPF neighbors
- From interface metrics
- From BGP communities
Correct Answer: 1
Explanation:
A NAT pool contains a configured range or collection of addresses that can be assigned to translated sessions according to the configured translation behavior. When a new connection requires address translation, the firewall selects an available address from the defined pool and records the mapping in session state. Depending on the translation type and configuration, ports may also be allocated to distinguish simultaneous connections. OSPF neighbors, interface metrics, and BGP communities are routing-related elements and do not provide addresses for NAT allocation. Pool design therefore directly determines available translated address resources.
Question 332.
Which packet condition can prevent normal transmission when the DF bit is set and fragmentation is required?
- Oversized VLAN tag
- Missing route policy
- Excessive application timeout
- Path MTU limitation
Correct Answer: 4
Explanation:
When the Don’t Fragment, or DF, bit is set, an IP packet cannot be fragmented by an intermediate router. If the packet exceeds the maximum transmission unit supported by a downstream path, the packet may require special handling rather than being fragmented. Path MTU discovery helps endpoints determine an appropriate packet size for the route. Firewalls and routers may also provide mechanisms for handling packets affected by MTU limitations. VLAN tags, route policies, and application timeouts do not directly explain the fragmentation restriction caused by the DF bit.
Question 333.
Which TCP event normally indicates graceful session termination?
- FIN exchange
- SYN retransmission
- RST generation
- ACK duplication
Correct Answer: 1
Explanation:
A TCP FIN flag is used to begin graceful termination of a TCP connection. Because TCP is full duplex, each direction can be closed independently, so a normal termination may involve FIN and acknowledgment exchanges in both directions. This allows already transmitted data to be handled while the connection transitions through its closing states. An RST instead indicates an abrupt reset rather than normal graceful closure. SYN packets are associated with connection establishment, while duplicate acknowledgments can indicate packet loss or reordering. Session monitoring systems use these TCP states when tracking connection lifecycle behavior.
Question 334.
Which TCP mechanism can immediately terminate an established connection?
- FIN acknowledgment
- RST segment
- Window update
- Duplicate ACK
Correct Answer: 2
Explanation:
A TCP reset, or RST, can immediately terminate an existing connection when the connection cannot continue normally or when an endpoint rejects the session. Unlike a FIN exchange, which supports graceful termination, an RST represents an abrupt termination of the TCP state. Firewalls and security devices may encounter reset packets during rejected, invalid, or unexpectedly closed connections. Window updates control flow and buffering, while duplicate acknowledgments generally provide information about missing or reordered data. Understanding the distinction between FIN and RST is important when interpreting session logs and troubleshooting TCP connection behavior.
Question 335.
What can a TCP proxy do with half-open connections?
- Translate DNS requests
- Maintain independent TCP states
- Modify OSPF areas
- Assign NAT pools
Correct Answer: 2
Explanation:
A TCP proxy can maintain separate TCP sessions on the client-facing and server-facing sides of a connection. This allows the security device to inspect and control traffic while independently tracking the state of each TCP leg. Such behavior can help manage half-open connections and provide additional protection against abnormal or incomplete TCP exchanges. A proxy may therefore act as an intermediary rather than simply forwarding packets unchanged. DNS translation, OSPF area modification, and NAT pool assignment are unrelated functions and are not the primary purpose of TCP proxy state management.
Question 336.
Which capture feature limits how much packet data can be retained in memory?
- Capture buffer
- Route preference
- Security zone
- Policy schedule
Correct Answer: 1
Explanation:
A packet-capture buffer defines the storage available for captured traffic before older information is discarded or the configured capture process reaches its limit. Proper buffer sizing is important during troubleshooting because packet captures can consume significant resources when traffic volume is high. Administrators may configure capture parameters to focus on relevant interfaces, hosts, or protocols and avoid unnecessary data collection. Route preference determines path selection, security zones define trust boundaries, and policy schedules control time-based policy behavior. None of those mechanisms directly determines how much captured packet information can be retained.
Question 337.
What is the purpose of VLAN tagging on a logical interface?
- Select routing protocol
- Identify VLAN traffic
- Change TCP states
- Assign BGP communities
Correct Answer: 2
Explanation:
VLAN tagging allows Ethernet frames to carry an identifier that associates the traffic with a particular VLAN. A physical interface can therefore support multiple logical interfaces or subinterfaces, each associated with different VLANs. The tag provides the Layer 2 separation needed to distinguish traffic arriving over a shared physical connection. Routing protocols operate at higher layers and do not define VLAN membership, while TCP states and BGP communities serve entirely different functions. Correct logical-interface and VLAN configuration is important when connecting trunked Ethernet networks to a firewall or router.
Question 338.
Which monitoring method can trigger action when a configured RPM test fails?
- BGP community matching
- DNS category lookup
- IP monitoring
- OSPF DR election
Correct Answer: 3
Explanation:
IP monitoring can use reachability tests to determine whether a monitored destination remains accessible. When a configured test fails, the resulting status can be used by redundancy or routing mechanisms to influence failover behavior, depending on the overall configuration. RPM provides the underlying active-probing capability, while IP monitoring can connect the observed reachability state to a broader operational decision. BGP communities classify routes, DNS category lookup supports security filtering, and OSPF DR election manages multiaccess routing relationships. These mechanisms do not directly provide the described RPM failure response.
Question 339.
What does UTM licensing status help an administrator determine?
- Available security services
- OSPF neighbor count
- BGP router identity
- VLAN membership
Correct Answer: 1
Explanation:
UTM licensing status helps administrators determine whether subscribed or licensed security services are available for use on the device. Depending on the platform and subscription, services may include capabilities such as antivirus, antispam, web filtering, or related security functions. License availability can affect whether a feature can operate normally and whether current service updates can be obtained. OSPF neighbor relationships, BGP router identities, and VLAN membership are independent networking functions. Checking licensing status is therefore useful when troubleshooting why a particular UTM capability cannot be enabled or used as expected.
Question 340.
Which BGP attribute describes how a route entered the BGP system?
- Local preference
- Community value
- Origin attribute
- MED setting
Correct Answer: 3
Explanation:
The BGP origin attribute identifies the manner in which a route was introduced into BGP. Common origin codes include IGP, EGP, and incomplete, with the attribute participating in the BGP route-selection process. An IGP origin generally represents a route introduced through a network statement, while incomplete commonly indicates redistribution or another method of introduction. Local preference influences outbound path selection within an AS, MED can communicate preferred entry points, and communities provide route classification. The origin attribute therefore supplies information about the route’s method of entry into BGP.