JN0-650 Exam Questions & Answers
Enterprise Routing and Switching, Professional • Juniper
100% money-back guarantee
Sample JN0-650 Questions
Practice with real exam-style questions, each with the verified correct answer and explanation.
Exhibit.

Referring to the exhibit, which two statements are correct? (Choose two.)
The exhibit shows an OSPF network where Area 1 is configured as a Not-So-Stubby Area (NSSA). R5 is an Autonomous System Boundary Router (ASBR) injecting an External Route (203.0.113.0/24) into this area.
NSSA ASBR Behavior (Option D): Within an OSPF NSSA, external routes cannot be advertised as standard Type 5 LSAs because stubby areas do not support them. Instead, the ASBR (R5) advertises the external prefix using a Type 7 LSA (NSSA External LSA). This LSA is flooded throughout Area 1.
ABR Translation Behavior (Option C): When the Type 7 LSA reaches the Area Border Router (R1), the ABR is responsible for translating it into a Type 5 LSA (AS External LSA). This allows the external route to be propagated into the backbone (Area 0) and subsequently to the rest of the OSPF domain.
Incorrect Statements (A & B): Option A is incorrect because Type 7 LSAs are local to the NSSA and are never advertised into Area 0. Option B is incorrect because Type 5 LSAs are strictly prohibited within an NSSA.
Which three statements about VSTP are correct? (Choose three.)
VSTP (VLAN Spanning Tree Protocol) is designed for interoperability with environments running Cisco's Per-VLAN Spanning Tree Plus (PVST+).
Per-VLAN Instances (Option E): The core function of VSTP is to maintain a separate spanning tree instance for every VLAN configured on the switch. This allows for different root bridges and different topologies per VLAN, enabling traffic load-balancing across various physical links.
BPDU Generation (Option A): Because each VLAN has its own instance, VSTP must send separate BPDUs for each VLAN. These BPDUs are tagged with the respective VLAN ID to ensure the receiving switch can process them for the correct instance.
Instance Limits (Option D): On many Juniper platforms, VSTP is limited to supporting a maximum of 253 unique spanning tree topologies (instances). If the number of VLANs exceeds this limit, additional VLANs will not have spanning tree protection unless migrated to a different protocol like MSTP.
Incorrect Statements: Option B is incorrect because VSTP is compatible with RSTP; it actually uses RSTP algorithms (Rapid-VSTP) by default in modern Junos versions to provide fast convergence. Option C is incorrect because STP or RSTP is usually the default spanning tree protocol on EX Series switches, not VSTP.
Your organization uses 802 1X with a RADIUS server. If the RADIUS server stops responding, you want the fallback action to continue to permit access for devices that currently have authorization but deny any new access attempts.
Which fallback action provides this capability?
Junos OS 24.4 provides several server-failover options for 802.1X authentication to maintain network availability when the RADIUS server is unreachable.
Fallback Behavior (Option D): The use-cache fallback action allows the switch to consult its local cache of previously authenticated MAC addresses.
If a device was already authorized and its information is in the cache, the switch will continue to permit access based on those cached credentials.
However, if a new device (not in the cache) attempts to connect while the server is down, the switch cannot verify its credentials and will deny the access attempt. This matches the specific requirement to permit authorized devices while denying new ones.
Other Fallback Options:
permit (Option C): This would allow all devices (even new ones) to access the network, typically in a restricted 'guest' or 'bypass' VLAN.
deny (Option A): This would drop all traffic from all devices on the port if the server is unreachable.
vlan-name (Option B): This moves authenticated or unauthenticated users into a specific fallback VLAN.
You are troubleshooting a multicast deployment in a network. Some multicast groups operate in PIM-ASM mode and others operate in PIM-SSM mode. While troubleshooting, you note the following:
- The network uses IGMPv2 for some segments and IGMPv3 for others.
- For group 232.1.1.1, receivers know the exact source IP of the multicast sender
- For group 239.10.10.10. receivers do not know the source address in advance.
Which two statements correctly describe the operational differences between these two modes in Junos OS? (Choose two.)
Junos OS 24.4 handles multicast traffic using two distinct models based on whether the source is known in advance.
Knowledge and Sources (Option A): PIM-ASM (Any Source Multicast) is designed for 'many-to-many' communication where receivers join a group ($*,G$) and rely on a Rendezvous Point (RP) to discover active sources. In contrast, PIM-SSM (Source-Specific Multicast) is for 'one-to-many' scenarios where receivers must already know the exact source IP ($S,G$) before joining.
Protocol and RP Logic (Option D): PIM-SSM bypasses the RP entirely. It relies on IGMPv3 messages from the host, which explicitly include both the source address and the group address. This allows the last-hop router to build a Shortest Path Tree (SPT) directly toward the source immediately.
Register Process (Option B): While PIM-ASM does use registers, it is the First-Hop Router (Designated Router on the source segment) that sends the register to the RP, not the receiver's DR.
RP Role (Option C): This is exactly backwards; PIM-ASM requires an RP for source discovery, whereas PIM-SSM does not use one at all.
Exhibit


You are asked to configure VLAN load balancing on your network using MSTP. Referring to the exhibit, which two statements are correct? (Choose two.)
The exhibit shows the MSTP configuration for two switches, switch1 and switch2. MSTP allows you to group multiple VLANs into a single Multiple Spanning Tree Instance (MSTI), enabling different root bridges and topologies for different sets of VLANs.
Root Bridge Election (Option B): For any Spanning Tree instance, the switch with the lowest bridge priority is elected as the root bridge.
For msti 2, switch1 has a priority of 4k (4096), while switch2 has a priority of 8k (8192).
Since 4096 < 8192, switch1 is elected the root bridge for msti 2.
Failover Behavior (Option D): Spanning Tree is designed for redundancy. If a primary root bridge fails, the remaining switches in the network re-elect a new root based on the next lowest priority.
If switch2 goes down, switch1 becomes the only switch in the region.
Regardless of its original priority (4k or 8k), switch1 will take over as the root bridge for both msti 1 and msti 2 because there are no other contenders with a better (lower) priority.
Incorrect Statements: Option A is incorrect because for msti 1, switch2 has the lower priority (4k vs. 8k), making switch2 the root bridge. Option C is incorrect because it contradicts the fundamental high-availability nature of Spanning Tree.
Get access to all 72 verified questions with detailed answers.
Unlock All JN0-650 Questions