Skip to content

Design, Associate (JNCIA-DESIGN) Practice Questions

Prepare for JN0-1103 with more than an answer.

218 questions in the full set20 sample questionsUpdated Jan 18, 2026
Exam fee
$200 USD
Level
Associate
Valid for
3 years
Domains covered on the exam 6
  1. Understanding Customer Network Design Requirements17%
  2. Understanding Securing the Network17%
  3. Understanding Network Management and Reliability17%
  4. Understanding Campus and Branch LAN Design17%
  5. Campus and Branch WAN Design16%
  6. Understanding Data Center Network Design16%
  1. 1

    A network security engineer is designing the security for a new data center. The design uses a spine-leaf architecture. A key concern is preventing the lateral movement of threats between different application tiers (e.g., web, application, database) hosted on virtual machines within the same Layer 2 domain.

    Which security design principle is most effective for mitigating this internal, or "East-West," threat?

    Show answer details

    Correct answer: B

    Micro-segmentation is a security technique specifically designed to control East-West (server-to-server) traffic within a data center. By deploying distributed firewalls, such as the vSRX virtual firewall, policies can be enforced at a granular level between individual virtual machines or application tiers, even if they reside on the same physical host or in the same subnet. This effectively creates secure zones around each workload, preventing lateral movement of threats.

  2. 2

    A university is planning a network upgrade for a new engineering building. The design must accommodate 500 students, each expected to use an average of 5 Mbps of bandwidth during peak hours. The network core must also have at least 40% additional capacity available for future growth and unexpected traffic spikes.

    What is the minimum required aggregate bandwidth capacity for the network core to meet these design requirements?

    Show answer details

    Correct answer: C

    The capacity planning calculation is as follows:

    1. Calculate peak user bandwidth: 500 students * 5 Mbps/student = 2500 Mbps or 2.5 Gbps.
    2. Calculate the required headroom for growth: 2.5 Gbps * 40% (0.40) = 1.0 Gbps.
    3. Add the peak bandwidth and the headroom to find the total minimum capacity: 2.5 Gbps + 1.0 Gbps = 3.5 Gbps.
      Therefore, the network core must be designed to handle at least 3.5 Gbps of aggregate traffic.
  3. 3

    What is a primary business driver for adopting an SD-WAN solution over a traditional WAN architecture?

    Show answer details

    Correct answer: B

    One of the main drivers for SD-WAN adoption is cost reduction. SD-WAN allows organizations to leverage multiple, inexpensive transport options like broadband, fiber internet, and LTE/5G, either to replace or augment expensive MPLS circuits. The technology intelligently steers application traffic over the best available path, providing a good user experience without relying solely on costly private links.

  4. 4

    A network automation engineer wants to implement a script that runs directly on a Juniper switch. The script needs to automatically archive the device's configuration to a remote server every night at 2 AM. The solution should use native Junos OS features without relying on external controllers like Ansible or Python scripts running on a separate server.

    Which Junos OS feature should the engineer use to meet this on-box automation requirement?

    Show answer details

    Correct answer: C

    Junos OS provides a powerful on-box automation framework using event policies and scripts. The engineer can create an event script (written in SLAX or Python) that performs the configuration archive action. Then, an event policy can be configured to trigger this script based on a time-of-day event (using the time-of-day command), effectively creating a cron-like job directly on the device. The other options are all examples of off-box automation.

  5. 5

    In a typical multi-tier application (Web -> App -> Database) hosted within a data center, what is the traffic flow between the application servers and the database servers commonly called?

    Show answer details

    Correct answer: B

    East-West traffic refers to communication that occurs between servers within the data center. The interaction between an application server and a database server is a classic example of this. In contrast, North-South traffic refers to communication that enters or leaves the data center, such as a user on the internet accessing the web server.

  6. 6

    An architect is designing a large-scale, multi-tenant data center using a spine-and-leaf IP fabric. The design must be highly scalable and avoid complex IGP configurations or route reflectors within the fabric. The primary goal is simple, robust routing between leaf switches.

    Given the requirements for scalability and operational simplicity, which routing protocol design is optimal for the IP fabric underlay?

    graph TD subgraph "eBGP Underlay Design" Spine1(Spine - ASN 65000) Spine2(Spine - ASN 65000) Leaf1(Leaf - ASN 65001) Leaf2(Leaf - ASN 65002) Leaf3(Leaf - ASN 65003) Leaf1 -- eBGP --> Spine1 Leaf1 -- eBGP --> Spine2 Leaf2 -- eBGP --> Spine1 Leaf2 -- eBGP --> Spine2 Leaf3 -- eBGP --> Spine1 Leaf3 -- eBGP --> Spine2 end
    Show answer details

    Correct answer: C

    Using eBGP for the underlay is a common and highly scalable design pattern for IP fabrics. Assigning a unique ASN to each leaf and a common ASN to the spines simplifies the configuration, as it eliminates the need for an IGP like OSPF or IS-IS and avoids the complexity of iBGP route reflectors. This design leverages BGP's path selection capabilities and is inherently loop-free, meeting the goals of simplicity and scalability.

  7. 7

    A global enterprise is transitioning from a traditional MPLS-based WAN to a modern SASE architecture to better support its remote workforce and cloud applications. The design team must select components that align with the core tenants of a SASE framework.

    Which TWO of the following capabilities are fundamental components of a Juniper SASE solution? (Select TWO)

    Show answer details

    Correct answer: B, C

    A core pillar of any SASE architecture is a comprehensive, cloud-delivered security stack, often called the Security Service Edge (SSE). This includes services like Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), and Zero Trust Network Access (ZTNA).

    The second fundamental pillar of SASE is a flexible and intelligent network fabric that connects users and devices to the cloud security services. Juniper provides this through its AI-driven SD-WAN, which optimizes application routing over any available transport.

  8. 8

    A university is modernizing its campus network to support seamless mobility and simplified network segmentation across multiple buildings. The design calls for an EVPN-VXLAN fabric. A key requirement is to extend Layer 2 domains between buildings without relying on traditional Spanning Tree Protocol (STP).

    In an EVPN-VXLAN campus fabric, what is the primary function of the VXLAN Tunnel Endpoints (VTEPs)?

    Show answer details

    Correct answer: B

    VTEPs (VXLAN Tunnel Endpoints) are the core components of a VXLAN overlay. Their primary role is to encapsulate the original Layer 2 Ethernet frame from an endpoint into a UDP packet, which is then routed over the Layer 3 IP underlay network. This process allows Layer 2 segments to be extended across routed boundaries, effectively replacing the need for STP to manage Layer 2 loops. The EVPN control plane manages MAC address learning and distribution.

  9. 9

    A large e-commerce company is designing its new data center network for maximum resiliency. The core of the design is an EVPN-VXLAN fabric using QFX Series switches. A critical server farm, hosting the company's main application, requires active-active multihoming to two different leaf switches (Leaf-1 and Leaf-2) for both load balancing and redundancy. The servers are connected using standard LACP bonds.

    The primary design goal is to ensure that if either Leaf-1 or its uplinks fail, traffic continues to flow through Leaf-2 without any service interruption or need for the server to detect a link failure on its LACP bundle. The solution must prevent traffic black-holing and ensure rapid convergence. The solution should be standards-based and avoid proprietary link aggregation protocols.

    Which Juniper technology should be implemented on Leaf-1 and Leaf-2 to meet these active-active multihoming requirements for the server farm?

    Show answer details

    Correct answer: C

    ESI-LAG is the standard-based solution within an EVPN-VXLAN fabric for active-active server multihoming. By configuring the same ESI on the aggregated Ethernet interfaces of both Leaf-1 and Leaf-2 that connect to the server, the EVPN control plane recognizes them as a single logical connection point. This allows the server to form a standard LACP bond that is actively used by both leaf switches simultaneously. EVPN's aliasing and mass-withdraw features ensure that if one leaf fails, traffic is immediately redirected to the other without black-holing. While MC-LAG and Virtual Chassis can provide multihoming, ESI-LAG is the native and most scalable method specifically for EVPN-VXLAN fabrics.

  10. 10

    True or False: A "brownfield" network design project implies that the new network components must integrate with, or replace parts of, a pre-existing, operational network infrastructure.

    Show answer details

    Correct answer: A

    The term "brownfield" refers to a deployment scenario where a new system or components are introduced into an environment with existing legacy systems. This contrasts with a "greenfield" deployment, which starts from a clean slate with no pre-existing infrastructure to consider. Brownfield projects typically involve more complex planning around migration, interoperability, and phased rollouts.

Create an account to continue.