We will provide one year free update for you after purchase of our study material, thus you can get the newest questions and prepare well for the real test. Before purchase, you can try our free demo questions to check the basic information about our pdf torrent.

[Q31-Q50] Updated Nov-2024 Exam Engine or PDF for the JN0-664 Tests Free Updated Today!

Share

Updated Nov-2024 Exam Engine or PDF for the JN0-664 Tests Free Updated Today!

Ultimate Guide to Prepare JN0-664 with Accurate PDF Questions


Juniper JN0-664 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Describe the concepts, operation, or functionality of OSPFv2 and OSPFv3
  • Label-switched path (LSP) flooding through an IS-IS multi- area network
Topic 2
  • Full mesh versus hub-and-spoke topology
  • Next-generation multicast virtual private networks (MVPNs)
Topic 3
  • Traffic flow—control and data planes
  • Describe Junos OS support for carrier-of-carriers or inter-provider VPN models
Topic 4
  • Given a scenario, demonstrate knowledge of how to configure or monitor single-area or multi-area OSPF
  • Describe the concepts, operation, or functionality of BGP
Topic 5
  • Designated router
  • backup designated router operation
  • Metrics, including external metric types
Topic 6
  • Designated intermediate system (DIS) operation
  • Describe the concepts, operation, or functionality of IS-IS

 

NEW QUESTION # 31
You have an L2VPN connecting two CEs across a provider network. The CEs and provider network are configured with the default MTU setting. You use the ping command from one CE to the other CE with a size of 1500 bytes.
In this scenario, which statement is correct when using the ping command?

  • A. You expect an echo reply.
  • B. You expect an ICMP message too long error.
  • C. You expect a silent discard.
  • D. You expect the ping results to be fragmented.

Answer: A


NEW QUESTION # 32
Exhibit

Referring to the exhibit, PIM-SM is configured on all routers, and Anycast-RP with Anycast-PIM is used for the discovery mechanism on RP1 and RP2. The interface metric values are shown for the OSPF area.
In this scenario, which two statements are correct about which RP is used? (Choose two.)

  • A. Source1 will use RP1 and Receiver1 will use RP1 for group 224.1.1.1.
  • B. Source2 will use RP1 and Receiver2 will use RP1 for group 224.2.2.2.
  • C. Source1 will use RP1 and Receiver1 will use RP2 for group 224.1 1 1
  • D. Source2 will use RP2 and Received will use RP2 for group 224.2.2.2.

Answer: A,D

Explanation:
Explanation
A sham link is a logical link between two PE routers that belong to the same OSPF area but are connected through an L3VPN. A sham link makes the PE routers appear as if they are directly connected, and prevents OSPF from preferring an intra-area back door link over the VPN backbone. A sham link creates an OSPF multihop neighborship between the PE routers using TCP port 646. The PEs exchange Type 1 OSPF LSAs instead of Type 3 OSPF LSAs for the L3VPN routes, which allows OSPF to use the correct metric for route selection1.


NEW QUESTION # 33
Exhibit

Referring to the exhibit, you are receiving the 192.168 0 0/16 route on both R3 and R4 from your EBGP neighbor You must ensure that R1 and R2 receive both BGP routes from the route reflector In this scenario, which BGP feature should you configure to accomplish this behavior?

  • A. add-path
  • B. multihop
  • C. multipath
  • D. route-target

Answer: A

Explanation:
BGP add-path is a feature that allows the advertisement of multiple paths through the same peering session for the same prefix without the new paths implicitly replacing any previous paths. This behavior promotes path diversity and reduces multi-exit discriminator (MED) oscillations. BGP add-path is implemented by adding a path identifier to each path in the NLRI. The path identifier can be considered as something similar to a route distinguisher in VPNs, except that a path ID can apply to any address family. Path IDs are unique to a peering session and are generated for each network3. In this question, we have a route reflector (RR) that receives two routes for the same prefix (192.168.0.0/16) from an EBGP neighbor. By default, the RR will only advertise its best path to its clients (R1 and R2). However, we want R1 and R2 to receive both routes from the RR. To achieve this, we need to configure BGP add-path on the RR and enable it to send multiple paths for the same prefix to its clients.


NEW QUESTION # 34
Exhibit

Which two statements about the configuration shown in the exhibit are correct? (Choose two.)

  • A. A Layer 2 VPN is configured.
  • B. This VPN connects customer sites that use different AS numbers.
  • C. This VPN connects customer sites that use the same AS number
  • D. A Layer 3 VPN is configured.

Answer: B,D

Explanation:
The configuration shown in the exhibit is for a Layer 3 VPN that connects customer sites that use different AS numbers. A Layer 3 VPN is a type of VPN that uses MPLS labels to forward packets across a provider network and BGP to exchange routing information between PE routers and CE routers. A Layer 3 VPN allows customers to use different routing protocols and AS numbers at their sites, as long as they can peer with BGP at the PE-CE interface. In this example, CE-1 is using AS 65530 and CE-2 is using AS 65531, but they can still communicate through the VPN because they have BGP sessions with PE-1 and PE-2, respectively.


NEW QUESTION # 35
Which statement is correct about IS-IS when it performs the Dijkstra algorithm?

  • A. When a new neighbor ID in the tree database matches a router ID in the LSDthe neighbor ID is moved to the candidate database.
  • B. The local router moves its own local tuples into the candidate database.
  • C. The algorithm will stop processing once the tree database is empty.
  • D. Tuples with the lowest cost are moved from the tree database to the LSDB.

Answer: C


NEW QUESTION # 36
Exhibit

Referring to the exhibit, which two statements are true? (Choose two.)

  • A. The devices advertising this route into EVPN are 10 0 2 12 and 10.0.2.22.
  • B. This is an EVPN Type-2 route.
  • C. This route is learned through EBGP
  • D. The device advertising this route into EVPN is 192.168.101.5.

Answer: B,D

Explanation:
Explanation
This is an EVPN Type-2 route, also called a MAC/IP advertisement route, that is used to advertise host IP and MAC address information to other VTEPs in an EVPN network. The route type field in the EVPN NLRI has a value of 2, indicating a Type-2 route. The device advertising this route into EVPN is 192.168.101.5, which is the IP address of the VTEP that learned the host information from the local CE device. This IP address is carried in the MPLS label field of the route as part of the VXLAN encapsulation.


NEW QUESTION # 37
Exhibit

Referring to the exhibit, you must provide Internet access for VPN-A using CE-1 as the hub CE.
Which two statements are correct in this situation? (Choose two.)

  • A. You must use RIB groups to leak routes between the inet. o and vpn-a. inet. o tables.
  • B. Internet traffic from Site 2 takes the path of PE-2 -> PE-1 -> GW-1.
  • C. Internet traffic from Site 2 takes the path of PE-2 -> PE-1 -> CE-1 -> PE-1 -> GW-1.
  • D. RIB groups are not needed to leak routes between the inet. 0 and VPN-A. inet. 0 tables,

Answer: A,C

Explanation:
To provide Internet access for VPN-A using CE-1 as the hub CE, you need to do the following:
* You must use RIB groups to leak routes between the inet.0 and vpn-a.inet.0 tables on PE-1 and CE-1.
RIB groups are routing options that allow you to import routes from one routing table into another routing table based on certain criteria. In this scenario, you need to configure RIB groups on PE-1 and CE-1 to import Internet routes from inet.0 into vpn-a.inet.0 and vice versa.
* Internet traffic from Site 2 takes the path of PE-2 -> PE-1 -> CE-1 -> PE-1 -> GW-1. This is because Site 2 does not have direct Internet access and needs to use CE-1 as its default gateway for Internet traffic. Site 2 sends its Internet traffic to PE-2, which forwards it to PE-1 based on VPN-A routes. PE-1 then sends it to CE-1 based on RIB group import policy. CE-1 then sends it back to PE-1 based on its default route pointing to GW-1. PE-1 then forwards it to GW-1 based on RIB group import policy again.


NEW QUESTION # 38
After a recent power outage, your manager asks you to investigate ways to automatically reduce the impact caused by suboptimal routing in your OSPF and OSPFv3 network after devices reboot.
Which three configuration statements accomplish this task? (Choose three.)

  • A. set protocols ospf overload
  • B. set protocols ospf overload timeout 900
  • C. set protocols ospf3 overload
  • D. set protocols ospf3 realm ipv4-unicast overload timeout 900
  • E. set protocols oapf3 overload timeout 900

Answer: B,C

Explanation:
Explanation
To reduce the impact of suboptimal routing in OSPF and OSPFv3 after devices reboot, you can use the overload feature to prevent a router from being used as a transit router for a specified period of time. This allows the router to stabilize its routing table before forwarding traffic for other routers. To enable the overload feature, you need to do the following:
* For OSPF, configure the overload statement under [edit protocols ospf] hierarchy level. You can also specify a timeout value in seconds to indicate how long the router should remain in overload state after it boots up. For example, set protocols ospf overload timeout 900 means that the router will be in overload state for 15 minutes after it boots up.
* For OSPFv3, configure the overload statement under [edit protocols ospf3] hierarchy level. You can also specify a realm (ipv4-unicast or ipv6-unicast) and a timeout value in seconds to indicate how long the router should remain in overload state after it boots up for each realm. For example, set protocols ospf3 realm ipv4-unicast overload timeout 900 means that the router will be in overload state for 15 minutes after it boots up for IPv4 unicast routing.


NEW QUESTION # 39
Exhibit

You want Site 1 to access three VLANs that are located in Site 2 and Site 3 The customer-facing interface on the PE-1 router is configured for Ethernet-VLAN encapsulation.
What is the minimum number of L2VPN routing instances to be configured to accomplish this task?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: C

Explanation:
To allow Site 1 to access three VLANs that are located in Site 2 and Site 3, you need to configure three L2VPN routing instances on PE-1, one for each VLAN. Each L2VPN routing instance will have a different VLAN ID and a different VNI for VXLAN encapsulation. Each L2VPN routing instance will also have a different vrf-target export value to identify which VPN routes belong to which VLAN. This way, PE-1 can forward traffic from Site 1 to Site 2 and Site 3 based on the VLAN tags and VNIs.


NEW QUESTION # 40
Exhibit

You must ensure that the VPN backbone is preferred over the back door intra-area link as long as the VPN is available. Referring to the exhibit, which action will accomplish this task?

  • A. Enable OSPF traffic-engineering.
  • B. Configure the OSPF metric on the backup intra-area link that is higher than the L3VPN link.
  • C. Create an OSPF sham link between the PE routers.
  • D. Configure an import routing policy on the CE routers that rejects OSPF routes learned on the backup intra-area link.

Answer: C

Explanation:
A sham link is a logical link between two PE routers that belong to the same OSPF area but are connected through an L3VPN. A sham link makes the PE routers appear as if they are directly connected, and prevents OSPF from preferring an intra-area back door link over the VPN backbone. To create a sham link, you need to configure the local and remote addresses of the PE routers under the [edit protocols ospf area area-id] hierarchy level1.


NEW QUESTION # 41
Exhibit

You are attempting to summarize routes from the 203.0.113.128/25 IP block on R8 to AS 64500. You implement the export policy shown in the exhibit and all routes from the routing table stop being advertised.
In this scenario, which two steps would you take to summarize the route in BGP? (Choose two.)

  • A. Add the set routing-options static route 203.0.113.123/25 discard command.
  • B. Add the set protocols bgp family inet unicast add-path command to allow additional routes to the RIB tables. -
  • C. Remove the from protocol bgp command from the export policy.
  • D. Replace exact in the export policy with orlonger.

Answer: A,D

Explanation:
Explanation
To summarize routes from the 203.0.113.128/25 IP block on R8 to AS 64500, you need to do the following:
* Add the set routing-options static route 203.0.113.128/25 discard command. This creates a static route for the summary prefix and discards any traffic destined to it. This is necessary because BGP can only advertise routes that are present in the routing table.
* Replace exact in the export policy with orlonger. This allows R8 to match and advertise any route that is equal or more specific than the summary prefix. The exact term only matches routes that are exactly equal to the summary prefix, which is not present in the routing table.


NEW QUESTION # 42
You want Site 1 to access three VLANs that are located in Site 2 and Site 3. The customer-facing interface on the PE-1 router is configured for Ethernet-VLAN encapsulation.

What is the minimum number of L2VPN routing instances to be configured to accomplish this task?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: C


NEW QUESTION # 43
You are asked to protect your company's customers from amplification attacks. In this scenario, what is Juniper's recommended protection method?

  • A. ASN prepending
  • B. destination-based Remote Triggered Black Hole
  • C. unicast Reverse Path Forwarding
  • D. BGP FlowSpec

Answer: B

Explanation:
Explanation
amplification attacks are a type of distributed denial-of-service (DDoS) attack that exploit the characteristics of certain protocols to amplify the traffic sent to a victim. For example, an attacker can send a small DNS query with a spoofed source IP address to a DNS server, which will reply with a much larger response to the victim. This way, the attacker can generate a large amount of traffic with minimal resources.
One of the methods to protect against amplification attacks is destination-based Remote Triggered Black Hole (RTBH) filtering. This technique allows a network operator to drop traffic destined to a specific IP address or prefix at the edge of the network, thus preventing it from reaching the victim and consuming bandwidth and resources. RTBH filtering can be implemented using BGP to propagate a special route with a next hop of
192.0.2.1 (a reserved address) to the edge routers. Any traffic matching this route will be discarded by the edge routers.


NEW QUESTION # 44
You are responding to an RFP for a new MPLS VPN implementation. The solution must use LDP for signaling and support Layer 2 connectivity without using BGP. The solution must be scalable and support multiple VPN connections over a single MPLS LSP. The customer wants to maintain all routing for their private network.
In this scenario, which solution do you propose?

  • A. LDP Layer 2 circuit
  • B. circuit cross-connect
  • C. translational cross-connect
  • D. BGP Layer 2 VPN

Answer: A


NEW QUESTION # 45
Exhibit

The environment is using BGP All devices are in the same AS with reachability redundancy Referring to the exhibit, which statement is correct?

  • A. Client1 is peered to Client2 and Client3.
  • B. RR2 is in an OpenConfirm State until RR1 becomes unreachable.
  • C. Peering is dynamically discovered between all devices.
  • D. RR1 is peered to Client2 and RR2

Answer: D

Explanation:
BGP route reflectors are BGP routers that are allowed to ignore the IBGP loop avoidance rule and advertise IBGP learned routes to other IBGP peers under specific conditions. BGP route reflectors can reduce the number of IBGP sessions and updates in a network by eliminating the need for a full mesh of IBGP peers.
BGP route reflectors can have three types of peerings:
* EBGP neighbor: A BGP router that belongs to a different autonomous system (AS) than the route reflector.
* IBGP client neighbor: An IBGP router that receives reflected routes from the route reflector. A client does not need to peer with other clients or non-clients.
* IBGP non-client neighbor: An IBGP router that does not receive reflected routes from the route reflector. A non-client needs to peer with other non-clients and the route reflector.
In the exhibit, we can see that RR1 and RR2 are route reflectors in the same AS with reachability redundancy.
They have two types of peerings: EBGP neighbors (R1 and R4) and IBGP client neighbors (Client1, Client2, and Client3). RR1 and RR2 are also peered with each other as IBGP non-client neighbors.


NEW QUESTION # 46
You are asked to protect your company's customers from amplification attacks.
In this scenario, what is Juniper's recommended protection method?

  • A. ASN prepending
  • B. BGP FlowSpec
  • C. unicast Reverse Path Forwarding
  • D. destination-based Remote Triggered Black Hole

Answer: B


NEW QUESTION # 47
Which two statements about IS-IS are correct? (Choose two.)

  • A. CSNPs contain only descriptions of LSPs.
  • B. PSNPs contain only descriptions of LSPs.
  • C. PSNPs are flooded periodically.
  • D. CSNPs are flooded periodically.

Answer: B,D


NEW QUESTION # 48
Which statement is true regarding BGP FlowSpec?

  • A. It uses a remote triggered black hole to protect a network from a denial-of-service attack.
  • B. It uses dynamically created routing policies to protect a network from denial-of-service attacks
  • C. It is used to protect a network from denial-of-service attacks dynamically
  • D. It verifies that the source IP of the incoming packet has a resolvable route in the routing table

Answer: B

Explanation:
Explanation
BGP FlowSpec is a feature that extends the Border Gateway Protocol (BGP) to enable routers to exchange traffic flow specifications, allowing for more precise control of network traffic. The BGP FlowSpec feature enables routers to advertise and receive information about specific flows in the network, such as those originating from a particular source or destined for a particular destination. Routers can then use this information to construct traffic filters that allow or deny packets of a certain type, rate limit flows, or perform other actions1. BGP FlowSpec can also help in filtering traffic and taking action against distributed denial of service (DDoS) attacks by dropping the DDoS traffic or diverting it to an analyzer2. BGP FlowSpec rules are internally converted to equivalent Cisco Common Classification Policy Language (C3PL) representing corresponding match and action parameters2. Therefore, BGP FlowSpec uses dynamically created routing policies to protect a network from denial-of-service attacks.
References: 1: https://www.networkingsignal.com/what-is-bgp-flowspec/ 2:
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/iproute_bgp/configuration/xe-16/irg-xe-16-book/bgp-flowspe


NEW QUESTION # 49
Exhibit

Referring to the exhibit, you are receiving the 192.168 0 0/16 route on both R3 and R4 from your EBGP neighbor You must ensure that R1 and R2 receive both BGP routes from the route reflector In this scenario, which BGP feature should you configure to accomplish this behavior?

  • A. add-path
  • B. multihop
  • C. multipath
  • D. route-target

Answer: A

Explanation:
BGP add-path is a feature that allows the advertisement of multiple paths through the same peering session for the same prefix without the new paths implicitly replacing any previous paths. This behavior promotes path diversity and reduces multi-exit discriminator (MED) oscillations. BGP add-path is implemented by adding a path identifier to each path in the NLRI. The path identifier can be considered as something similar to a route distinguisher in VPNs, except that a path ID can apply to any address family. Path IDs are unique to a peering session and are generated for each network3. In this question, we have a route reflector (RR) that receives two routes for the same prefix (192.168.0.0/16) from an EBGP neighbor. By default, the RR will only advertise its best path to its clients (R1 and R2). However, we want R1 and R2 to receive both routes from the RR. To achieve this, we need to configure BGP add-path on the RR and enable it to send multiple paths for the same prefix to its clients.


NEW QUESTION # 50
......

Pass Juniper With ExamsReviews Exam Dumps: https://easypass.examsreviews.com/JN0-664-pass4sure-exam-review.html