Summer Certification Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Free Practice Questions for the Juniper JNCIS-ENT JN0-352 Exam (2026 Updated)

At Marks4sure, we are dedicated to providing IT professionals with the most accurate and reliable preparation materials for the Juniper JN0-352 exam. To support your certification journey, we have made a selection of our premium 2026 JNCIS-ENT practice questions and answers available completely free. You can take this practice test as many times as you need. Every question includes a detailed, expertly verified explanation to ensure you fully grasp the core security concepts before test day.

Questions 4

[Exhibit]

JN0-352 Question 4

Click the Exhibit button.

An OSPF broadcast segment has four routers with roles as shown in the exhibit. R1 is currently offline, and default OSPF settings are in place.

In this scenario, what happens when R1 comes back online?

Options:

A.

DR roles do not change; R1 becomes DROther.

B.

R1 becomes the DR and R2 becomes the BDR.

C.

R1 becomes the DR and R3 remains the BDR.

D.

R1 cannot join the OSPF area until the current DR (R2) is restarted.

Buy Now
Questions 5

[Exhibit]

JN0-352 Question 5

Click the Exhibit button.

You are asked to ensure that there will not be any unwanted STP topology changes affecting your root bridge placement because a rogue switch was introduced into the network at the access layer.

Referring to the exhibit, which interfaces will need to have root protection applied to accomplish this task?

Options:

A.

Place root protection on ge-0/0/6 and ge-0/0/8 on Switch-1 only.

B.

Place root protection on ge-0/0/6 and ge-0/0/8 on Switch-3 and Switch-4.

C.

Place root protection on ge-0/0/6 and ge-0/0/8 on Switch-1 and Switch-2.

D.

Place root protection on ge-0/0/12 and ge-0/0/13 on Switch-1 and Switch-2.

Buy Now
Questions 6

Which two statements describe OSPF DR and BDR behavior? (Choose two.)

Options:

A.

The BDR becomes the DR if the DR fails.

B.

The DR elects the area border router for each area.

C.

The DR by default generates Type-2 Network LSAs to describe the multi-access segment.

D.

The BDR by default generates Type-2 Network LSAs to describe the multi-access segment.

Buy Now
Questions 7

How would you view the metric assigned to a route in OSPF? (Choose two.)

Options:

A.

Use the show route protocol ospf command.

B.

Use the show ospf route intra command.

C.

Use the show ospf database extensive command.

D.

Use the show ospf interface command.

Buy Now
Questions 8

A Juniper Networks EX Series Switch has storm control enabled on all interfaces. The ge-0/0/1 interface carrying several VLANs hits its storm control limit and is shut down.

In this scenario, which command allows you to manually clear the violation?

Options:

A.

clear ethernet-switching table

B.

clear interface statistics

C.

clear log messages

D.

clear ethernet-switching recovery-timeout

Buy Now
Questions 9

You are creating an aggregated Ethernet bundle using LACP on your Juniper Networks EX Series device.

In this scenario, which statement is correct?

Options:

A.

LACP active mode is required on at least one side of the bundle.

B.

You must use different LACP system priorities for each switch.

C.

By default, LACP is in active mode on aggregated Ethernet interfaces.

D.

LACP active mode is required on both sides of the bundle.

Buy Now
Questions 10

You are troubleshooting a Layer 2 topology issue in a campus network. The switches are running RSTP. You need to verify which switch is currently acting as the root bridge and identify the root port on the local device.

Which operational command should the administrator use to view this information?

Options:

A.

show spanning-tree interface

B.

show spanning-tree bridge

C.

show ethernet-switching table

D.

show ethernet-switching interface

Buy Now
Questions 11

Two Juniper Networks EX Series Switches are connected with four 1-GbE links configured as a single link aggregation group (LAG). One of the physical member links experiences a failure.

By default, what impact will this failure have on traffic forwarding between the switches?

Options:

A.

The LAG continues forwarding traffic across the remaining member links.

B.

All traffic will be dropped because the LAG goes administratively down.

C.

Only broadcast traffic continues to be forwarded across the LAG.

D.

The LAG renegotiates and temporarily disables all member links.

Buy Now
Questions 12

Which statement describes how Rapid Spanning Tree Protocol (RSTP) identifies an alternate port?

Options:

A.

An alternate port is the upstream port that is not receiving BPDUs from the root bridge.

B.

An alternate port is the upstream port that provides the least-cost path to the root bridge.

C.

An alternate port is the upstream port that provides a backup path to the root bridge and stays in the discarding state.

D.

An alternate port is the upstream port that forwards traffic only when the designated port is overloaded.

Buy Now
Questions 13

[Exhibit]

JN0-352 Question 13

Click the Exhibit button.

Referring to the exhibit, all possible firewall filters are configured along the path from Server A to Server B.

In which order will Switch 1 process transmit (Tx) and receive (Rx) firewall filters?

Options:

A.

Rx-Port -- > Rx-VLAN -- > Rx-Router -- > Tx-Router -- > Tx-VLAN - > Tx-Port

B.

Rx-Port -- > Rx-VLAN -- > Rx-Router -- > Tx-VLAN -- > Tx-Port

C.

Rx-Port -- > Rx-VLAN -- > Tx-VLAN -- > Tx-Port

D.

Rx-Port -- > Rx-Router -- > Tx-Router -- > Tx-Port

Buy Now
Questions 14

You are deploying a Juniper Networks EX Series Switch to connect 24 end devices to VLAN 70, with an uplink interface to a distribution switch that carries VLANs 30, 50, and 70. You need to correctly configure the interface type for the end-device interfaces.

In this scenario, which statement is correct?

Options:

A.

Use trunk mode with VLAN 70 set as the native VLAN.

B.

No configuration is needed since VLAN 70 is the highest VLAN-ID.

C.

Use trunk mode with VLAN 70 as the only allowed VLAN.

D.

Use access mode and assign the interfaces to VLAN 70.

Buy Now
Questions 15

You are configuring a GRE tunnel between Router A (192.168.1.1) and Router B (192.168.2.1) to connect two isolated networks. The tunnel interfaces (gr-0/0/0) need to support IPv4 traffic.

In this scenario, which configuration ensures the tunnel endpoints are correctly defined and reachable?

Options:

A.

set interfaces gr-0/0/0 unit 0 tunnel source 192.168.1.1 destination 192.168.2.1

B.

set interfaces gr-0/0/0 unit 0 family inet6

C.

set interfaces gr-0/0/0 unit 0 family inet address 192.168.1.1

D.

set interfaces gr-0/0/0 unit 0 tunnel destination 192.168.2.1

Buy Now
Questions 16

[Exhibit]

JN0-352 Question 16

Click the Exhibit button.

You have two routers on your network that are not able to establish BGP sessions.

Which two statements are correct in this scenario? (Choose two.)

Options:

A.

The routers do not have matching address families configured.

B.

The BGP neighbors may have duplicate IP addresses.

C.

The routers do not have NTP configured.

D.

BGP authentication is not enabled.

Buy Now
Questions 17

[Exhibit]

JN0-352 Question 17

Click the Exhibit button.

Which three statements about this BGP session are correct? (Choose three.)

Options:

A.

The export routing policy has been processed.

B.

The routes are active.

C.

The routes are stored in the default routing instance.

D.

The routes originate from an external AS.

E.

R1 modifies the BGP next hop.

Buy Now
Questions 18

Which statement is correct about how a Juniper Networks EX Series Switch learns MAC addresses?

Options:

A.

The switch adds destination MAC addresses to the bridge table after forwarding frames.

B.

The switch learns MAC addresses by polling connected hosts periodically.

C.

The switch learns MAC addresses only after a spanning-tree topology change occurs.

D.

The switch learns source MAC addresses from received frames and records the ingress interface and timestamp.

Buy Now
Questions 19

You need to block SSH (TCP port 22) traffic from the 192.168.10.0/24 network.

Which firewall filter term is correct in this scenario?

Options:

A.

term block-ssh { from { source-address 192.168.10.0/24; protocol tcp; destination-port 22; } then discard; }

B.

term block-ssh { from { destination-address 192.168.10.0/24; protocol tcp; destination-port 22; } then discard; }

C.

term block-ssh { from { source-address 192.168.10.0/24; protocol tcp; source-port 22; } then discard; }

D.

term block-ssh { from { source-address 192.168.10.0/24; service ssh; } then reject; }

Buy Now
Exam Code: JN0-352
Exam Name: Enterprise Routing and Switching, Specialist (JNCIS-ENT)
Last Update: Aug 29, 2026
Questions: 65

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11