Limited-Time Offer: Enjoy 50% Savings! - Ends In 0d 00h 00m 00s Coupon code: 50OFF
Free Exam Questions

JN0-650 Exam Questions & Answers

Enterprise Routing and Switching, Professional  •  Juniper

72 Questions Updated Sep 2026 99% Pass Rate
Get Full Access

100% money-back guarantee

Sample JN0-650 Questions

Practice with real exam-style questions, each with the verified correct answer and explanation.

Q1 MultipleChoice

Exhibit.

Referring to the exhibit, which two statements are correct? (Choose two.)

Correct Answer: C, D
Explanation:

The exhibit shows an OSPF network where Area 1 is configured as a Not-So-Stubby Area (NSSA). R5 is an Autonomous System Boundary Router (ASBR) injecting an External Route (203.0.113.0/24) into this area.

NSSA ASBR Behavior (Option D): Within an OSPF NSSA, external routes cannot be advertised as standard Type 5 LSAs because stubby areas do not support them. Instead, the ASBR (R5) advertises the external prefix using a Type 7 LSA (NSSA External LSA). This LSA is flooded throughout Area 1.

ABR Translation Behavior (Option C): When the Type 7 LSA reaches the Area Border Router (R1), the ABR is responsible for translating it into a Type 5 LSA (AS External LSA). This allows the external route to be propagated into the backbone (Area 0) and subsequently to the rest of the OSPF domain.

Incorrect Statements (A & B): Option A is incorrect because Type 7 LSAs are local to the NSSA and are never advertised into Area 0. Option B is incorrect because Type 5 LSAs are strictly prohibited within an NSSA.

Q2 MultipleChoice

Which three statements about VSTP are correct? (Choose three.)

Correct Answer: A, D, E
Explanation:

VSTP (VLAN Spanning Tree Protocol) is designed for interoperability with environments running Cisco's Per-VLAN Spanning Tree Plus (PVST+).

Per-VLAN Instances (Option E): The core function of VSTP is to maintain a separate spanning tree instance for every VLAN configured on the switch. This allows for different root bridges and different topologies per VLAN, enabling traffic load-balancing across various physical links.

BPDU Generation (Option A): Because each VLAN has its own instance, VSTP must send separate BPDUs for each VLAN. These BPDUs are tagged with the respective VLAN ID to ensure the receiving switch can process them for the correct instance.

Instance Limits (Option D): On many Juniper platforms, VSTP is limited to supporting a maximum of 253 unique spanning tree topologies (instances). If the number of VLANs exceeds this limit, additional VLANs will not have spanning tree protection unless migrated to a different protocol like MSTP.

Incorrect Statements: Option B is incorrect because VSTP is compatible with RSTP; it actually uses RSTP algorithms (Rapid-VSTP) by default in modern Junos versions to provide fast convergence. Option C is incorrect because STP or RSTP is usually the default spanning tree protocol on EX Series switches, not VSTP.

Q3 MultipleChoice

Your organization uses 802 1X with a RADIUS server. If the RADIUS server stops responding, you want the fallback action to continue to permit access for devices that currently have authorization but deny any new access attempts.

Which fallback action provides this capability?

Correct Answer: D
Explanation:

Junos OS 24.4 provides several server-failover options for 802.1X authentication to maintain network availability when the RADIUS server is unreachable.

Fallback Behavior (Option D): The use-cache fallback action allows the switch to consult its local cache of previously authenticated MAC addresses.

If a device was already authorized and its information is in the cache, the switch will continue to permit access based on those cached credentials.

However, if a new device (not in the cache) attempts to connect while the server is down, the switch cannot verify its credentials and will deny the access attempt. This matches the specific requirement to permit authorized devices while denying new ones.

Other Fallback Options:

permit (Option C): This would allow all devices (even new ones) to access the network, typically in a restricted 'guest' or 'bypass' VLAN.

deny (Option A): This would drop all traffic from all devices on the port if the server is unreachable.

vlan-name (Option B): This moves authenticated or unauthenticated users into a specific fallback VLAN.

Q4 MultipleChoice

You are troubleshooting a multicast deployment in a network. Some multicast groups operate in PIM-ASM mode and others operate in PIM-SSM mode. While troubleshooting, you note the following:

- The network uses IGMPv2 for some segments and IGMPv3 for others.

- For group 232.1.1.1, receivers know the exact source IP of the multicast sender

- For group 239.10.10.10. receivers do not know the source address in advance.

Which two statements correctly describe the operational differences between these two modes in Junos OS? (Choose two.)

Correct Answer: A, D
Explanation:

Junos OS 24.4 handles multicast traffic using two distinct models based on whether the source is known in advance.

Knowledge and Sources (Option A): PIM-ASM (Any Source Multicast) is designed for 'many-to-many' communication where receivers join a group ($*,G$) and rely on a Rendezvous Point (RP) to discover active sources. In contrast, PIM-SSM (Source-Specific Multicast) is for 'one-to-many' scenarios where receivers must already know the exact source IP ($S,G$) before joining.

Protocol and RP Logic (Option D): PIM-SSM bypasses the RP entirely. It relies on IGMPv3 messages from the host, which explicitly include both the source address and the group address. This allows the last-hop router to build a Shortest Path Tree (SPT) directly toward the source immediately.

Register Process (Option B): While PIM-ASM does use registers, it is the First-Hop Router (Designated Router on the source segment) that sends the register to the RP, not the receiver's DR.

RP Role (Option C): This is exactly backwards; PIM-ASM requires an RP for source discovery, whereas PIM-SSM does not use one at all.

Q5 MultipleChoice

Exhibit

You are asked to configure VLAN load balancing on your network using MSTP. Referring to the exhibit, which two statements are correct? (Choose two.)

Correct Answer: B, D
Explanation:

The exhibit shows the MSTP configuration for two switches, switch1 and switch2. MSTP allows you to group multiple VLANs into a single Multiple Spanning Tree Instance (MSTI), enabling different root bridges and topologies for different sets of VLANs.

Root Bridge Election (Option B): For any Spanning Tree instance, the switch with the lowest bridge priority is elected as the root bridge.

For msti 2, switch1 has a priority of 4k (4096), while switch2 has a priority of 8k (8192).

Since 4096 < 8192, switch1 is elected the root bridge for msti 2.

Failover Behavior (Option D): Spanning Tree is designed for redundancy. If a primary root bridge fails, the remaining switches in the network re-elect a new root based on the next lowest priority.

If switch2 goes down, switch1 becomes the only switch in the region.

Regardless of its original priority (4k or 8k), switch1 will take over as the root bridge for both msti 1 and msti 2 because there are no other contenders with a better (lower) priority.

Incorrect Statements: Option A is incorrect because for msti 1, switch2 has the lower priority (4k vs. 8k), making switch2 the root bridge. Option C is incorrect because it contradicts the fundamental high-availability nature of Spanning Tree.

Get access to all 72 verified questions with detailed answers.

Unlock All JN0-650 Questions

Frequently Asked Questions

The JN0-650 is Juniper's Enterprise Routing and Switching, Professional level certification exam. It validates advanced knowledge and skills in designing, implementing, and troubleshooting complex enterprise routing and switching environments using Juniper technologies.

Juniper recommends that candidates have the JN0-648 (Enterprise Routing and Switching, Associate) certification or equivalent hands-on experience with Juniper routing and switching technologies. Prior experience with enterprise networking concepts and protocols is also highly recommended.

The exam covers advanced topics including MPLS, BGP, advanced OSPF, high availability, security policies, firewall filters, and service provider technologies. It also includes content on troubleshooting complex network issues and optimizing network performance in large-scale environments.

The JN0-650 exam is 120 minutes long and consists of approximately 65-75 questions in multiple-choice and scenario-based formats. Candidates must score approximately 70% or higher to pass the exam, though the exact passing score may vary.

Juniper offers official training courses, study guides, and hands-on labs to help candidates prepare. Many candidates also benefit from studying for the JN0-648 exam first, gaining practical experience with Juniper equipment, and using third-party study materials and practice exams.
Exam Details
  • Exam CodeJN0-650
  • VendorJuniper
  • Total Questions72
  • LanguageEnglish
  • Last UpdatedSep 5, 2026
4.9/5

Pass JN0-650 First Time

Get all 72 exam questions with verified answers and 90-day free updates.

Buy Now & Pass
  • PDF + Practice Test Bundle
  • 90-Day Free Updates
  • 100% Money-Back Guarantee
  • Instant Download
  • 24/7 Customer Support
99% Pass Rate Trusted by 50,000+ IT professionals