Design, Associate (JNCIA-DESIGN) Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 218 questions. Use the simulator for timed and flashcard mode.

Try Simulator

JN0-1103 Sample Questions

  1. Question 1

    Q1

    An architect is designing a large-scale, multi-tenant data center using a spine-and-leaf IP fabric. The design must be highly scalable and avoid complex IGP configurations or route reflectors within the fabric. The primary goal is simple, robust routing between leaf switches.

    Given the requirements for scalability and operational simplicity, which routing protocol design is optimal for the IP fabric underlay?

    graph TD subgraph "eBGP Underlay Design" Spine1(Spine - ASN 65000) Spine2(Spine - ASN 65000) Leaf1(Leaf - ASN 65001) Leaf2(Leaf - ASN 65002) Leaf3(Leaf - ASN 65003) Leaf1 -- eBGP --> Spine1 Leaf1 -- eBGP --> Spine2 Leaf2 -- eBGP --> Spine1 Leaf2 -- eBGP --> Spine2 Leaf3 -- eBGP --> Spine1 Leaf3 -- eBGP --> Spine2 end
    Show answer & explanation

    Correct answer: C

    Using eBGP for the underlay is a common and highly scalable design pattern for IP fabrics. Assigning a unique ASN to each leaf and a common ASN to the spines simplifies the configuration, as it eliminates the need for an IGP like OSPF or IS-IS and avoids the complexity of iBGP route reflectors. This design leverages BGP's path selection capabilities and is inherently loop-free, meeting the goals of simplicity and scalability.

  2. Question 2

    Q2Multiple answers

    A global enterprise is transitioning from a traditional MPLS-based WAN to a modern SASE architecture to better support its remote workforce and cloud applications. The design team must select components that align with the core tenants of a SASE framework.

    Which TWO of the following capabilities are fundamental components of a Juniper SASE solution? (Select TWO)

    Show answer & explanation

    Correct answers: B, C

    A core pillar of any SASE architecture is a comprehensive, cloud-delivered security stack, often called the Security Service Edge (SSE). This includes services like Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), and Zero Trust Network Access (ZTNA).

    The second fundamental pillar of SASE is a flexible and intelligent network fabric that connects users and devices to the cloud security services. Juniper provides this through its AI-driven SD-WAN, which optimizes application routing over any available transport.

  3. Question 3

    Q3

    A university is modernizing its campus network to support seamless mobility and simplified network segmentation across multiple buildings. The design calls for an EVPN-VXLAN fabric. A key requirement is to extend Layer 2 domains between buildings without relying on traditional Spanning Tree Protocol (STP).

    In an EVPN-VXLAN campus fabric, what is the primary function of the VXLAN Tunnel Endpoints (VTEPs)?

    Show answer & explanation

    Correct answer: B

    VTEPs (VXLAN Tunnel Endpoints) are the core components of a VXLAN overlay. Their primary role is to encapsulate the original Layer 2 Ethernet frame from an endpoint into a UDP packet, which is then routed over the Layer 3 IP underlay network. This process allows Layer 2 segments to be extended across routed boundaries, effectively replacing the need for STP to manage Layer 2 loops. The EVPN control plane manages MAC address learning and distribution.

  4. Question 4

    Q4

    A large e-commerce company is designing its new data center network for maximum resiliency. The core of the design is an EVPN-VXLAN fabric using QFX Series switches. A critical server farm, hosting the company's main application, requires active-active multihoming to two different leaf switches (Leaf-1 and Leaf-2) for both load balancing and redundancy. The servers are connected using standard LACP bonds.

    The primary design goal is to ensure that if either Leaf-1 or its uplinks fail, traffic continues to flow through Leaf-2 without any service interruption or need for the server to detect a link failure on its LACP bundle. The solution must prevent traffic black-holing and ensure rapid convergence. The solution should be standards-based and avoid proprietary link aggregation protocols.

    Which Juniper technology should be implemented on Leaf-1 and Leaf-2 to meet these active-active multihoming requirements for the server farm?

    Show answer & explanation

    Correct answer: C

    ESI-LAG is the standard-based solution within an EVPN-VXLAN fabric for active-active server multihoming. By configuring the same ESI on the aggregated Ethernet interfaces of both Leaf-1 and Leaf-2 that connect to the server, the EVPN control plane recognizes them as a single logical connection point. This allows the server to form a standard LACP bond that is actively used by both leaf switches simultaneously. EVPN's aliasing and mass-withdraw features ensure that if one leaf fails, traffic is immediately redirected to the other without black-holing. While MC-LAG and Virtual Chassis can provide multihoming, ESI-LAG is the native and most scalable method specifically for EVPN-VXLAN fabrics.

  5. Question 5

    Q5

    True or False: A "brownfield" network design project implies that the new network components must integrate with, or replace parts of, a pre-existing, operational network infrastructure.

    Show answer & explanation

    Correct answer: A

    The term "brownfield" refers to a deployment scenario where a new system or components are introduced into an environment with existing legacy systems. This contrasts with a "greenfield" deployment, which starts from a clean slate with no pre-existing infrastructure to consider. Brownfield projects typically involve more complex planning around migration, interoperability, and phased rollouts.

  6. Question 6

    Q6

    A retail company is deploying a Juniper AI-driven SD-WAN solution to its 200 store locations. Each store has a primary broadband link and a secondary LTE link. The design requires that Point-of-Sale (POS) transaction traffic always uses the link with the lowest latency, while guest Wi-Fi traffic should be load-balanced across both links.

    Where is the real-time path selection decision for the POS traffic made in a Juniper SD-WAN architecture?

    Show answer & explanation

    Correct answer: C

    In Juniper's SD-WAN solution, while policies are centrally managed and orchestrated from the Mist Cloud, the actual real-time path selection decisions based on link performance metrics (like latency, jitter, and packet loss) are made locally at the branch device. The device continuously monitors the health of the WAN links and steers traffic according to the predefined application policies. This allows for rapid adaptation to changing network conditions without waiting for instructions from the cloud controller.

  7. Question 7

    Q7

    A systems administrator is physically racking new equipment for a spine-and-leaf data center fabric. The design includes four spine switches and thirty-two leaf switches. The administrator questions the physical cabling plan.

    What is the fundamental physical connectivity rule for a non-blocking spine-and-leaf architecture?

    Show answer & explanation

    Correct answer: C

    The core principle of a Clos-based spine-and-leaf fabric is that every leaf switch must be connected to every spine switch. This design creates a large, non-blocking fabric where traffic from any leaf has a predictable, equal-cost path to any other leaf (always traversing from leaf-to-spine-to-leaf). Direct connections between leaf switches or between spine switches are not part of this architecture and would break the model.

  8. Question 8

    Q8

    A security architect is designing a Zero Trust network for a financial institution. The core principle is "never trust, always verify." A key part of the design involves dynamically adjusting a user's access rights based on their behavior, device posture, and location in real-time.

    Which concept is most critical for implementing this dynamic, context-aware access control in a Zero Trust model?

    Show answer & explanation

    Correct answer: B

    Zero Trust moves beyond static, perimeter-based security. A fundamental component is the concept of continuous verification. An adaptive trust engine constantly assesses signals (user identity, device health, location, behavior) and adjusts access permissions dynamically. If a user's device becomes non-compliant or their behavior is anomalous, access can be restricted or revoked in real-time. Static ACLs, perimeter firewalls, and basic VLAN segmentation are traditional security measures that do not provide this continuous, dynamic enforcement.

  9. Question 9

    Q9

    True or False: In the SRX chassis cluster configuration shown below, if the primary node (node0) fails, the cluster will maintain stateful connections for existing TCP sessions that fail over to the new primary node (node1).

    graph TD subgraph "SRX Chassis Cluster" SRX1[node0 - Primary] SRX2[node1 - Backup] SRX1 ---|Control Link| SRX2 SRX1 ---|Fabric Link for RTOs| SRX2 end Internet((Internet)) --reth0--> SRX1 Internet --reth0--> SRX2 LAN[Internal LAN] --reth1--> SRX1 LAN --reth1--> SRX2
    Show answer & explanation

    Correct answer: A

    This statement is true. A key feature of a Juniper SRX chassis cluster is its ability to perform stateful failover. The fabric link is used to synchronize session state information, including connection tables for TCP (called Real-Time Objects or RTOs), from the primary node to the backup node. When a failover occurs, the new primary node has the necessary session information to continue processing existing traffic without requiring sessions to be re-established, ensuring business continuity.

  10. Question 10

    Q10Multiple answers

    A network designer is planning a new enterprise WLAN deployment for a multi-floor office building using the Juniper Mist platform. To ensure a successful outcome, the designer must follow a structured process.

    Which THREE of the following activities are critical during the initial design and planning phases, before any hardware is deployed? (Select THREE)

    Show answer & explanation

    Correct answers: B, C, D

    A predictive survey is a crucial first step to model RF coverage and capacity, allowing for optimal AP placement planning before any physical installation occurs.

    Understanding the business needs (e.g., how many users, what applications they will use, are there voice/video requirements) is fundamental to designing a WLAN that meets expectations.

    Translating business needs into technical specifications (e.g., minimum signal strength, required throughput per user, WPA3 security) is a critical part of the planning phase.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the JN0-1103 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 218 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon