View Full Juniper JN0-336 Exam Dumps and Practice Test Dumps
Question 341.
Which BGP attribute can carry multiple administrative tags on a route?
- Community attribute
- Origin attribute
- MED attribute
- Local preference
Correct Answer: 1
Explanation:
The BGP community attribute allows routes to carry administrative tags that can be used by routing policies. Multiple communities can be associated with a route, enabling administrators to classify traffic according to operational or business requirements. Policies can then match these communities and perform actions such as accepting, rejecting, modifying, or selectively advertising routes. Communities are especially useful in larger environments where consistent routing behavior must be coordinated across multiple peers. Origin, MED, and local preference have different roles in BGP processing and do not provide the same flexible multi-tag classification capability.
Question 342.
Which BGP attribute is normally preferred when its value is lower?
- Local preference
- MED
- Community
- Origin
Correct Answer: 2
Explanation:
The Multi-Exit Discriminator, or MED, is generally preferred when it has a lower value, assuming the routes are otherwise comparable and the relevant BGP decision process applies MED. It is commonly used to communicate a preference for how another autonomous system should enter the advertising network when multiple links exist between the organizations. MED should not be confused with local preference, where a higher value is generally preferred internally. Communities are policy tags rather than direct path-selection metrics, while the origin attribute describes how a route entered BGP.
Question 343.
What does a BGP community policy commonly control?
- Interface bandwidth
- Route treatment
- TCP window size
- VLAN numbering
Correct Answer: 2
Explanation:
A BGP community policy can control how routes are treated based on community tags attached to those routes. For example, an administrator can classify routes and then apply policies that alter their handling, including selective advertisement, acceptance, rejection, or attribute modification. This provides a scalable way to implement consistent routing rules without creating separate policies for every individual prefix. Interface bandwidth, TCP window size, and VLAN numbering are unrelated to BGP community processing. Community-based policies are therefore particularly useful when routing decisions depend on administrative classification rather than only on destination prefixes.
Question 344.
Which OSPF mechanism helps connect a disconnected backbone area through another area?
- Passive interface
- DR election
- Virtual link
- Router priority
Correct Answer: 3
Explanation:
An OSPF virtual link provides a logical connection through a transit area to restore or maintain connectivity with the OSPF backbone. This mechanism is useful when the physical topology does not provide the required direct connection to Area 0. The virtual link is established between routers that share a common transit area and uses that area as the logical path. Passive interfaces suppress neighbor formation, DR election manages multiaccess segments, and router priority participates in DR and BDR selection. Virtual links therefore address a specific OSPF topology-connectivity requirement.
Question 345.
What happens when an OSPF interface is configured as passive?
- Adjacency formation stops
- Area membership disappears
- Route metrics reset
- Database synchronization expands
Correct Answer: 1
Explanation:
A passive OSPF interface does not form OSPF neighbor adjacencies because hello packets are not exchanged for neighbor discovery on that interface. However, the connected network can still be advertised into the OSPF routing domain. This behavior is useful when an interface connects to hosts or another network segment where OSPF neighbors are not expected. Making an interface passive does not remove its area membership or automatically reset route metrics. It also does not increase database synchronization. Its primary effect is suppressing OSPF adjacency formation while retaining route advertisement.
Question 346.
Which factor is checked after equal OSPF interface priorities during DR election?
- Interface bandwidth
- Router ID
- Area number
- LSDB age
Correct Answer: 2
Explanation:
When eligible OSPF routers have the same interface priority during a designated-router election, the router ID is used to break the tie. The router with the higher router ID is selected when the relevant election conditions are otherwise equal. This deterministic process ensures that the DR and BDR roles can be selected consistently on a broadcast or similar multiaccess network. Interface bandwidth, area number, and LSDB age are not the tie-breaking criterion for this election. Understanding the election order helps explain unexpected DR or BDR selection during troubleshooting.
Question 347.
Which BGP feature can authenticate peers using a shared TCP-level secret?
- TCP MD5
- OSPF digest
- DNSSEC
- IPsec ESP
Correct Answer: 1
Explanation:
TCP MD5 authentication can protect BGP peer sessions by allowing participating devices to validate TCP segments using a shared secret. This provides an additional security layer for the BGP control connection and can help reduce the risk of unauthorized session establishment or forged packets. The authentication is associated with the TCP session carrying BGP rather than with route attributes themselves. OSPF authentication is specific to OSPF, DNSSEC protects DNS data, and ESP provides IPsec packet protection. TCP MD5 therefore represents the mechanism described for BGP peer-session protection.
Question 348.
Which BGP behavior makes the advertising router the next hop for learned routes?
- MED rewriting
- Community tagging
- Next-hop self
- Origin modification
Correct Answer: 3
Explanation:
The next-hop self behavior causes a BGP router to advertise itself as the next-hop address when passing routes to a peer. This is particularly useful when an internal router receives routes from an external peer but other internal routers cannot directly reach the original external next-hop address. Setting the local router as the next hop provides a reachable forwarding point and simplifies internal routing. MED rewriting changes a path attribute, community tagging adds administrative classification, and origin modification changes route-origin information. None of those directly replaces the next-hop address.
Question 349.
What is the main effect of route leaking between routing instances?
- Shares selected routes
- Merges security zones
- Copies interface states
- Combines user databases
Correct Answer: 1
Explanation:
Route leaking permits selected routing information to cross boundaries between separate routing instances. Each routing instance normally maintains its own routing table, providing logical separation between networks. When controlled connectivity is required, administrators can configure policies or mechanisms that make specific routes available across those boundaries. Route leaking does not merge security zones, synchronize interface operational states, or combine user databases. Because routing instances are often used for segmentation, careful route selection is important when implementing leaking. Only the required prefixes should normally be exposed to the other routing context.
Question 350.
Which NAT method can multiplex many internal sessions through one public address?
- Static NAT
- Destination NAT
- Port translation
- One-to-one mapping
Correct Answer: 3
Explanation:
Port translation allows multiple internal sessions to share a single translated public address by assigning distinct source-port combinations to the connections. The firewall maintains translation state so returning packets can be associated with the correct internal host and session. This technique greatly increases the number of connections that can use a limited public IPv4 address space. Static NAT and one-to-one mappings generally preserve a fixed address relationship, while destination NAT modifies destination information for inbound traffic. Port-based multiplexing is therefore the defining characteristic of the described translation method.
Question 351.
What determines the available addresses for pool-based source translation?
- Configured address range
- OSPF database
- BGP neighbor table
- Security log stream
Correct Answer: 1
Explanation:
A source NAT pool uses a configured collection or range of addresses that can be assigned to translated sessions. The available addresses in that pool determine the address resources that the firewall can use when creating translations. Depending on the translation configuration, port allocation may allow many simultaneous sessions to share individual pool addresses. OSPF databases and BGP neighbor tables contain routing information rather than NAT resources, while security log streams record events. Administrators therefore need to size and configure NAT pools appropriately for the expected number of translated connections.
Question 352.
What can occur when a packet exceeds the outgoing interface MTU with DF set?
- It is automatically fragmented
- It requires MTU handling
- It becomes an OSPF LSA
- It changes BGP attributes
Correct Answer: 2
Explanation:
When a packet exceeds the outgoing interface MTU and the Don’t Fragment bit is set, the packet cannot simply be fragmented to fit the smaller MTU. Appropriate MTU handling is therefore required, commonly involving Path MTU Discovery and an indication that the sender should reduce packet size. This behavior helps endpoints adapt transmission sizes to the capabilities of the path. The packet does not become an OSPF link-state advertisement or modify BGP attributes. Understanding DF behavior is important when troubleshooting connectivity problems involving tunnels, encapsulation, or paths with smaller MTUs.
Question 353.
Which TCP flag normally starts an orderly connection shutdown?
- SYN
- ACK
- FIN
- PSH
Correct Answer: 3
Explanation:
The TCP FIN flag is used to begin an orderly shutdown of a TCP connection. A FIN indicates that the sender has finished transmitting data in that direction. The receiving endpoint acknowledges the FIN and can independently close its own sending direction, which is why a normal TCP termination involves multiple control exchanges. SYN is used during connection establishment, ACK confirms received information, and PSH requests prompt delivery of buffered data to the receiving application. FIN therefore specifically represents the control signal associated with graceful TCP session termination.
Question 354.
Which TCP flag is associated with abrupt session termination?
- ACK
- RST
- FIN
- SYN
Correct Answer: 2
Explanation:
The TCP reset, represented by the RST flag, is used to terminate a connection abruptly rather than through the normal FIN-based shutdown sequence. A reset may occur when a connection is rejected, an unexpected segment is received, or an application or security device determines that the session cannot continue. FIN supports graceful termination, SYN is associated with establishing a connection, and ACK confirms receipt of TCP information. Monitoring RST packets can therefore help administrators distinguish rejected or abruptly terminated connections from normal session closures.
Question 355.
Why can a TCP proxy maintain separate connection states?
- It terminates each TCP side
- It disables packet inspection
- It removes routing tables
- It bypasses session tracking
Correct Answer: 1
Explanation:
A TCP proxy can terminate the client-side TCP connection and establish a separate server-side TCP connection. Because the proxy manages both sides independently, it can maintain separate TCP states and inspect traffic between them. This intermediary architecture provides greater control than simple packet forwarding and can support security inspection, connection validation, and protection against certain abnormal TCP behaviors. The proxy does not disable packet inspection, remove routing information, or bypass session tracking. Instead, its independent connection handling is what enables deeper control over TCP session behavior.
Question 356.
Which packet-capture resource limits retained captured traffic?
- Capture buffer
- Route table
- Policy database
- Session timeout
Correct Answer: 1
Explanation:
The packet-capture buffer determines how much captured traffic can be retained for examination. When capture volume exceeds available buffer capacity, older information may be overwritten or the capture process may reach its configured limit, depending on the implementation and settings. Administrators can reduce unnecessary traffic by applying suitable capture filters and selecting only relevant interfaces or protocols. A route table determines forwarding paths, a policy database stores security rules, and a session timeout controls connection aging. None of these directly defines the storage capacity available for packet-capture data.
Question 357.
What does an IEEE 802.1Q tag identify in an Ethernet frame?
- VLAN membership
- TCP sequence state
- BGP path length
- OSPF area type
Correct Answer: 1
Explanation:
An IEEE 802.1Q tag identifies VLAN information within an Ethernet frame. The tag allows network devices to distinguish traffic belonging to different VLANs when multiple logical networks share a physical trunk connection. This provides Layer 2 segmentation while allowing a single physical interface to carry traffic for several VLANs. TCP sequence state operates at the transport layer, BGP path length belongs to routing decisions, and OSPF area type describes routing topology. VLAN tagging therefore provides the Layer 2 identification necessary to separate traffic on trunked Ethernet links.
Question 358.
Which monitoring result can be used to influence redundancy behavior?
- DNS response size
- RPM reachability status
- VLAN identifier
- BGP community text
Correct Answer: 2
Explanation:
RPM reachability status can provide information about whether a monitored destination remains accessible. When combined with configured IP-monitoring or redundancy mechanisms, the result of an RPM test can influence operational behavior such as triggering a failover condition. This allows network availability decisions to consider not only the local interface state but also the reachability of important remote destinations. DNS response size, VLAN identifiers, and BGP community values do not directly provide the reachability test result used for this purpose. RPM therefore supplies an active measurement that can support higher-level redundancy decisions.
Question 359.
Which BGP attribute indicates how a route was introduced?
- Community
- MED
- Origin
- Local preference
Correct Answer: 3
Explanation:
The BGP origin attribute identifies how a route entered the BGP routing system. Its common values indicate whether the route originated through an IGP method, an older EGP mechanism, or an incomplete process such as redistribution. The origin attribute participates in route selection when comparing otherwise suitable paths. Communities are used primarily for administrative tagging, MED communicates path preferences between connected autonomous systems, and local preference influences outbound path selection inside an autonomous system. Therefore, the origin attribute specifically provides information about the route’s method of introduction into BGP.
Question 360.
Which setting can make multiple BGP routes share a common administrative classification?
- Interface priority
- Community tagging
- OSPF cost
- TCP window scaling
Correct Answer: 2
Explanation:
BGP community tagging allows administrators to assign common administrative classifications to multiple routes. Routes carrying the same community can then be matched by routing policies and handled consistently. This is particularly useful for large networks where manually creating separate policies for every individual prefix would be difficult to maintain. Interface priority affects certain interface-level elections, OSPF cost influences path calculations, and TCP window scaling controls transport behavior. Community tagging therefore provides a scalable mechanism for grouping routes according to administrative requirements and applying consistent routing-policy treatment.