Juniper JN0-664 Dumps Updated Feb 22, 2026 WIith 99 Questions
View All JN0-664 Actual Free Exam Questions Feb 22, 2026 Updated
Juniper JN0-664 (Service Provider, Professional (JNCIP-SP)) certification exam is designed for individuals who have a strong understanding of the Junos OS routing and switching technology in a service provider environment. Service Provider, Professional (JNCIP-SP) certification exam is a part of the Juniper Networks Certified Professional Service Provider (JNCIP-SP) certification track. Passing JN0-664 exam validates an individual's ability to configure, implement, and troubleshoot a variety of service provider routing and switching technologies.
One of the main benefits of earning the JN0-664 certification is that it can help you stand out in a crowded job market. Employers are always looking for knowledgeable and skilled professionals who can help them stay ahead of the competition, and the JN0-664 certification can set you apart from the competition.
Juniper JN0-664 exam is aimed at professionals who are responsible for designing, implementing, and supporting service provider networks. JN0-664 exam is designed to test the candidate's knowledge and skills in the areas of routing, switching, and service provider technologies. The JN0-664 exam is a rigorous test that requires candidates to demonstrate their knowledge of networking technologies and their ability to apply that knowledge in real-world scenarios.
NEW QUESTION # 29
You want to ensure that L1 IS-IS routers have only the most specific routes available from L2 IS- IS routers.
Which action accomplishes this task?
- A. Configure the ignore-attached-bit parameter on all L1 routers.
- B. Configure all routers to be L1.
- C. Configure the ignore-attached-bit parameter on all L2 routers.
- D. Configure all routers to allow wide metrics.
Answer: A
NEW QUESTION # 30
Referring to the exhibit, which statement is true?
- A. The 10.101.1.0/24 route will be shared if the auto-export parameter is configured.
- B. The 10.101.1.0/24 route will be shared if the vrf-table-label parameter is configured.
- C. The 10.101.1.0/24 route will be shared if there are other VRFs that use the same route target community.
- D. The 10.101.1.0/24 route will only be shared if BGP is configured in the routing instance.
Answer: C
NEW QUESTION # 31
Referring to the exhibit. PE-1 and PE-2 are getting route updates for VPN-B when neither of them service that VPN.
Which two actions would optimize this process? (Choose two.)
- A. Configure the resolution rib bgp.l3vpn.0 resolution-ribs inet.0 statement on the PEs.
- B. Configure the family route-target statement on the PEs.
- C. Configure the resolution rib bgp.l3vpn.0 resolution-ribs inet.0 statement on the RR.
- D. Configure the family route-target statement on the RR.
Answer: C,D
Explanation:
BGP route target filtering can be configured on PE devices or on route reflectors (RRs).
Configuring BGP route target filtering on RRs is more efficient and scalable, as it reduces the number of BGP sessions and updates between PE devices. To configure BGP route target filtering on RRs, the following steps are required:
Configure the family route-target statement under the BGP group or neighbor configuration on the RRs. This enables the exchange of the route-target address family between the RRs and their clients (PE devices). Configure the resolution rib bgp.l3vpn.0 resolution-ribs inet.0 statement under the routing-options configuration on the RRs. This enables the RRs to resolve next hops for VPN routes using the inet.0 routing table.
NEW QUESTION # 32 
Click the Exhibit button.
You have an EVI implemented between PE-1, PE-2, and PE-3 to allow communication between CE-1 and CE-2. CE-2 receives unicast traffic from CE-1 on both links to PE-2 and PE-3. When CE-1 sends broadcast traffic, CE-2 receives it on only one of the multihomed links.
Referring to the exhibit, which EVPN route type enables this behavior?
- A. Type 1
- B. Type 3
- C. Type 4
- D. Type 2
Answer: B
Explanation:
In the context of Ethernet VPN (EVPN) and the behavior described in the exhibit, it's essential to understand the different EVPN route types and their specific functionalities. Here, CE-2 is receiving unicast traffic on both of its multihomed links to PE-2 and PE-3, but broadcast traffic is received only on one of these links.
**Explanation of EVPN Route Types**:
1. **Type 1 (Ethernet Auto-Discovery Routes)**:
- These routes are used for auto-discovery of Ethernet segments and for advertising VLAN membership.
- They do not directly influence the behavior described in the question.
2. **Type 2 (MAC/IP Advertisement Routes)**:
- These routes are used to advertise MAC addresses and IP-to-MAC bindings within the EVPN.
- They handle unicast traffic forwarding and are crucial for populating the MAC address tables on the PE devices.
- While important, they do not explain the selective broadcast behavior.
3. **Type 3 (Inclusive Multicast Ethernet Tag Routes)**:
- These routes are used to build multicast distribution trees for delivering broadcast, unknown unicast, and multicast (BUM) traffic.
- They ensure that BUM traffic is sent only once per Ethernet segment, preventing duplicate frames from being sent to multihomed CEs.
- This aligns with the behavior described where CE-2 receives broadcast traffic on only one link to prevent duplication.
4. **Type 4 (Ethernet Segment Routes)**:
- These routes are used to advertise the presence of an Ethernet segment and are crucial for Designated Forwarder (DF) election processes in multihoming scenarios.
- While relevant to multihoming, they are not directly responsible for the selective broadcast behavior.
**Conclusion**:
The behavior described, where CE-2 receives broadcast traffic on only one of its multihomed links, is controlled by Type 3 routes. These routes are specifically designed to handle inclusive multicast and broadcast traffic efficiently in EVPN environments, ensuring that such traffic is not duplicated across multiple links to the same CE.
**References**:
- Juniper Networks EVPN Documentation: [EVPN
Overview](https://www.juniper.net/documentation/en_US/junos/topics/concept/evpn-overview.html)
- RFC 7432, BGP MPLS-Based Ethernet VPN: [RFC 7432](https://tools.ietf.org/html/rfc7432) provides detailed descriptions of EVPN route types and their functions.
- Junos OS EVPN Configuration Guide: [Junos OS EVPN Configuration
Guide](https://www.juniper.net/documentation/en_US/junos/topics/topic-map/evpn.html)
NEW QUESTION # 33
Which two statements are correct about VPLS tunnels? (Choose two.)
- A. LDP-signaled VPLS tunnels use auto-discovery to provision sites.
- B. BGP-signaled VPLS tunnels can use either RSVP or LDP between the PE routers.
- C. BGP-signaled VPLS tunnels require manual provisioning of sites.
- D. LDP-signaled VPLS tunnels only support control bit 0.
Answer: B,D
NEW QUESTION # 34
You are asked to protect your company's customers from amplification attacks. In this scenario, what is Juniper's recommended protection method?
- A. BGP FlowSpec
- B. destination-based Remote Triggered Black Hole
- C. unicast Reverse Path Forwarding
- D. ASN prepending
Answer: B
Explanation:
Explanation
amplification attacks are a type of distributed denial-of-service (DDoS) attack that exploit the characteristics of certain protocols to amplify the traffic sent to a victim. For example, an attacker can send a small DNS query with a spoofed source IP address to a DNS server, which will reply with a much larger response to the victim. This way, the attacker can generate a large amount of traffic with minimal resources.
One of the methods to protect against amplification attacks is destination-based Remote Triggered Black Hole (RTBH) filtering. This technique allows a network operator to drop traffic destined to a specific IP address or prefix at the edge of the network, thus preventing it from reaching the victim and consuming bandwidth and resources. RTBH filtering can be implemented using BGP to propagate a special route with a next hop of
192.0.2.1 (a reserved address) to the edge routers. Any traffic matching this route will be discarded by the edge routers.
NEW QUESTION # 35
Exhibit.
Referring to the exhibit; the 10.0.0.0/24 EBGP route is received on R5; however, the route is being hidden.
What are two solutions that will solve this problem? (Choose two.)
- A. Add the external interface prefix to the IGP routing tables
- B. On R4, create a policy to change the BGP next hop to itself and apply it to IBGP as an export policy
- C. On R4, create a policy to change the BGP next hop to 172.16.1.1 and apply it to IBGP as an export policy
- D. Add the internal interface prefix to the BGP routing tables.
Answer: A,B
Explanation:
Explanation
the default behavior for iBGP is to propagate EBGP-learned prefixes without changing the next-hop. This can cause issues if the next-hop is not reachable via the IGP. One solution is to use the next-hop self command on R4, which will change the next-hop attribute to its own loopback address. This way, R5 can reach the next-hop via the IGP and install the route in its routing table.
Another solution is to add the external interface prefix (120.0.4.16/30) to the IGP routing tables of R4 and R5.
This will also make the next-hop reachable via the IGP and allow R5 to use the route. According to 2, this is a possible workaround for a pure IP network, but it may not work well for an MPLS network.
NEW QUESTION # 36
Exhibit
Referring to the exhibit, CE-1 is providing NAT services for the hosts at Site 1 and you must provide Internet access for those hosts Which two statements are correct in this scenario? (Choose two.)
- A. You must configure a RIB group on PE-1 to leak the 10 1 2.0/24 prefix from the VPN-A.inet.0 table to the inet.0 table.
- B. You must configure a static route in the main routing instance for the 10 1 2.0/24 prefix that uses the VPN-A.inet.0 table as the next hop
- C. You must configure a RIB group on PE-1 to leak a default route from the inet.0 table to the VPN-A.inet.
0 table. - D. You must configure a static route in the main routing instance for the 203.0.113.1/32 prefix that uses the VPN-A.inet.0 table as the next hop.
Answer: C,D
NEW QUESTION # 37
Exhibit
A network is using IS-IS for routing.
In this scenario, why are there two TLVs shown in the exhibit?
- A. Both IPv4 and IPv6 are being used in the topology
- B. The interface specified a metric of 100 for L2.
- C. There are both narrow and wide metric devices in the topology
- D. Wide metrics have specifically been requested
Answer: C
Explanation:
TLVs are tuples of (Type, Length, Value) that can be advertised in IS-IS packets. TLVs can carry different kinds of information in the Link State Packets (LSPs). IS-IS supports both narrow and wide metrics for link costs. Narrow metrics use a single octet to encode the link cost, while wide metrics use three octets. Narrow metrics have a maximum value of 63, while wide metrics have a maximum value of 16777215. If there are both narrow and wide metric devices in the topology, IS-IS will advertise two TLVs for each link: one with the narrow metric and one with the wide metric. This allows backward compatibility with older devices that only support narrow metrics12.
NEW QUESTION # 38
A packet is received on an interface configured with transmission scheduling. One of the configured queues In this scenario, which two actions will be taken by default on a Junos device? (Choose two.)
- A. The excess traffic will use bandwidth available from other queueses
- B. The excess traffic will be discarded
- C. The exceeding queue will be considered to have negative bandwidth credit.
- D. The exceeding queue will be considered to have positive bandwidth credit
Answer: B,C
Explanation:
Explanation
Transmission scheduling is a CoS feature that allows you to allocate bandwidth among different queues on an interface. Each queue has a configured bandwidth percentage that determines how much of the available bandwidth it can use. If a queue exceeds its allocated bandwidth, it is considered to have negative bandwidth credit and its excess traffic will be discarded by default. If a queue does not use all of its allocated bandwidth, it is considered to have positive bandwidth credit and its unused bandwidth can be shared by other queues.
NEW QUESTION # 39
Exhibit
Referring to the exhibit, which statement is correct?
- A. The route-diatinguisher configuration will stop routes from being shared between CE-1 and CE-2.
- B. The route-distinguisher configuration will allow overlapping routes to be shared between CE-1 and CE-2.
- C. The vrf-target configuration will stop routes from being shared between CE-1 and CE-2.
- D. The vrf-target configuration will allow routes to be shared between CE-1 and CE-2.
Answer: B
Explanation:
The route distinguisher (RD) is a BGP attribute that is used to create unique VPN IPv4 prefixes for each VPN in an MPLS network. The RD is a 64-bit value that consists of two parts: an administrator field and an assigned number field. The administrator field can be an AS number or an IP address, and the assigned number field can be any arbitrary value chosen by the administrator. The RD is prepended to the IPv4 prefix to create a VPN IPv4 prefix that can be advertised across the MPLS network without causing any overlap or conflict with other VPNs. In this question, we have two PE routers (PE-1 and PE-2) that are connected to two CE devices (CE-1 and CE-2) respectively. PE-1 and PE-2 are configured with VRFs named Customer-A and Customer-B respectively.
NEW QUESTION # 40
Exhibit.
Referring to the exhibit, which path would traffic passing through R1 take to get to R4?
- A. R1 -> R4
- B. R1 -> R3 -> R4
- C. R1 -> R2 -> R3 -> R4
- D. R1 -> R2 -> R4
Answer: D
Explanation:
The OSPF cost is carried in the LSAs that are exchanged within an OSPF area. When a router calculates the cost to a destination it uses the cost of the exit interface of each router in the path to the destination.
NEW QUESTION # 41
You are configuring a BGP signaled Layer 2 VPN across your MPLS enabled core network. Your PE-2 device connects to two sites within the same VPN.
In this scenario, which statement is correct?
- A. By default on PE-2, the site's local ID is automatically assigned a value of 0 and must be configured to match the total number of attached sites.
- B. By default on PE-2, the remote site IDs are automatically assigned based on the order that you add the interfaces to the site configuration.
- C. You must create a unique Layer 2 VPN routing instance for each site on the PE-2 device.
- D. You must use separate physical interfaces to connect PE-2 to each site.
Answer: B
NEW QUESTION # 42
A router running IS-IS is configured with an ISO address of 49.0001.00a0.c96b.c490.00.
Which part of this address is the system ID?
- A. c96b.c490 is the system identifier.
- B. 0001.00a0.c96b.c490 is the system identifier.
- C. 00a0.c96b.c490 is the system identifier.
- D. c490 is the system identifier.
Answer: C
Explanation:
In IS-IS (Intermediate System to Intermediate System) routing, each router is identified by a unique ISO (International Organization for Standardization) address, also known as a Network Entity Title (NET). The NET consists of three parts:
1. **Area Identifier**: Indicates the area to which the router belongs.
2. **System Identifier**: Uniquely identifies the router within the area.
3. **NSAP Selector (NSEL)**: Typically set to 00 for a router, indicating the Network Service Access Point.
The format of the ISO address is `49.XXXX.YYYY.YYYY.ZZZZ.ZZZZ.00`, where:
- `49` is the AFI (Authority and Format Identifier) indicating a private address.
- `XXXX` is the Area Identifier.
- `YYYY.YYYY.YYYY` is the System Identifier.
- `ZZZZ.ZZZZ` is the NSAP Selector.
Given the address `49.0001.00a0.c96b.c490.00`:
- **Area Identifier**: `49.0001`
- **System Identifier**: `00a0.c96b.c490`
- **NSAP Selector**: `00`
**Explanation**:
- **A. 00a0.c96b.c490 is the system identifier**:
- Correct. The System Identifier in an ISO address is a 48-bit (6-byte) field used to uniquely identify the router. In this address, `00a0.c96b.c490` is the correct 6-byte System Identifier.
- **B. 0001.00a0.c96b.c490 is the system identifier**:
- Incorrect. This includes the Area Identifier as part of the System Identifier, which is not correct.
- **C. c96b.c490 is the system identifier**:
- Incorrect. This is only part of the System Identifier. The full System Identifier must be 6 bytes long.
- **D. c490 is the system identifier**:
- Incorrect. This is an incomplete and incorrect part of the System Identifier.
**Conclusion**:
The correct part of the address that represents the System Identifier is:
**A. 00a0.c96b.c490 is the system identifier.**
**References**:
- Juniper Networks Documentation on IS-IS: [IS-IS Configuration](https://www.juniper.net/documentation
/en_US/junos/topics/task/configuration/isis-configuring.html)
- ISO/IEC 10589, the IS-IS routing protocol standard.
NEW QUESTION # 43
Exhibit
You want to use both links between R1 and R2 Because of the bandwidth difference between the two links, you must ensure that the links are used as much as possible.
Which action will accomplish this goal?
- A. Enable per-prefix load balancing.
- B. Define a policy to tag routes with the appropriate bandwidth community.
- C. Ensure that the metric-out parameter on the Gigabit Ethernet interface is higher than the 10 Gigibit Ethernet interface.
- D. Disable multipath.
Answer: B
Explanation:
https://www.juniper.net/documentation/us/en/software/junos/sampling-forwarding-monitoring/bgp/topics/concep
NEW QUESTION # 44
A network designer would like to advertise a single summary route from R4 to IS-IS level 2 neighbors as shown in the exhibit, but the configuration is not working.
Which three configuration changes will accomplish this task? (Choose three.)
- A. set policy-options policy-statement summary-v6 term DC-routes from route-filter
2001:dbS:a:fa00::/6l exact - B. set policy-options policy-statement summary-v6 term suppress then reject
- C. delete policy-options policy-statement summary-v6 term DC-routes from route-filter
2001:db5:a:fa00::/61 longer - D. delete protocols isis export summary-v6
- E. set protocols isis import summary-v6
Answer: A,B,C
NEW QUESTION # 45
You are configuring a Layer 3 VPN between two sites. You are configuring the vrf-target target:
65100:100 statement in your routing instance.
In this scenario, which two statements describe the vrf-target configuration? (Choose two.)
- A. This value is used to add a target community to BGP routes advertised to the remote PE device.
- B. This value is used to add a target community to BGP routes advertised to the local CE device.
- C. This value is used to identify BGP routes learned from the remote PE device.
- D. This value is used to identify BGP routes learned from the local CE device.
Answer: A,C
NEW QUESTION # 46
You want Site 1 to access three VLANs that are located in Site 2 and Site 3. The customer-facing interface on the PE-1 router is configured for Ethernet-VLAN encapsulation.
What is the minimum number of L2VPN routing instances to be configured to accomplish this task?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
NEW QUESTION # 47
Referring to the exhibit, CE-1 is providing NAT services for the hosts at Site 1 and you must provide Internet access for those hosts.
Which two statements are correct in this scenario? (Choose two.)
- A. You must configure a static route in the main routing instance for the 10.1.2.0/24 prefix that uses the VPN-A.inet.0 table as the next hop.
- B. You must configure a RIB group on PE-1 to leak a default route from the inet.0 table to the VPN-A.inet.0 table.
- C. You must configure a static route in the main routing instance for the 203.0.113.1/32 prefix that uses the VPN-A.inet.0 table as the next hop.
- D. You must configure a RIB group on PE-1 to leak the 10.1.2.0/24 prefix from the VPN-A.inet.0 table to the inet.0 table.
Answer: B,C
Explanation:
We want a static route to the public IP. The private IP is hidden behind the NATed public IP, so a static route to the private range is useless to us.
NEW QUESTION # 48
Exhibit
You are running a service provider network and must transport a customer's IPv6 traffic across your IPv4-based MPLS network using BGP You have already configured mpis ipv6-tunneling on your PE routers.
Which two statements are correct about the BGP configuration in this scenario? (Choose two.)
- A. You must configure family inet6 unicaat between PE and CE routers.
- B. You must configure family inet6 unicast between PE routers
- C. You must configure family inet6 labcled-unicast between PE routers.
- D. You must configure family inet6 add-path between PE and CE routers.
Answer: A,C
Explanation:
Explanation
To transport IPv6 traffic over an IPv4-based MPLS network using BGP, you need to configure two address families: family inet6 labeled-unicast and family inet6 unicast. The former is used to exchange IPv6 routes with MPLS labels between PE routers, and the latter is used to exchange IPv6 routes without labels between PE and CE routers. The mpis ipv6-tunneling command enables the PE routers to encapsulate the IPv6 packets with an MPLS label stack and an IPv4 header before sending them over the MPLS network.
NEW QUESTION # 49
Exhibit
Referring to the exhibit, which three statements are correct about route 10 0 0.0/16 when using the default BGP advertisement rules'? (Choose three.)
- A. R1 will prepend AS 65531 when advertising 10 0.0 0/16 to R2.
- B. R2 will advertise 10.0.0.0/16 to R4 with 172.16.1.1 as the next hop
- C. R1 will advertise 10.0.0.0/16 to R2 with 192 168 1 1 as the next hop.
- D. R4 will advertise 10 0.0 0/16 to R6 with 172.16 1 1 as the next hop
- E. R2 will advertise 10.0.0.0/16 to R3 with 192.168.1 1 as the next hop
Answer: A,B,E
NEW QUESTION # 50
Exhibit.

Referring to the exhibit, what must be changed to establish a Level 1 adjacency between routers R1 and R2?
- A. Change the level l disable parameter under the R1 protocols isis interface lo0.0 hierarchy to the level 2 disable parameter.
- B. Remove the level 1 disable parameter under the R2 protocols isis interface lo0.0 configuration hierarchy.
- C. Add IP addresses to the interface ge-1/2/3 unit 0 family iso hierarchy on both R1 and R2.
- D. Change the level 1 disable parameter under the R2 protocols isis interface ge-l/2/3.0 hierarchy to the level 2 disable parameter.
Answer: D
NEW QUESTION # 51
Exhibit
Referring to the exhibit, which two statements are true? (Choose two.)
- A. The devices advertising this route into EVPN are 10 0 2 12 and 10.0.2.22.
- B. This route is learned through EBGP
- C. This is an EVPN Type-2 route.
- D. The device advertising this route into EVPN is 192.168.101.5.
Answer: C,D
Explanation:
This is an EVPN Type-2 route, also called a MAC/IP advertisement route, that is used to advertise host IP and MAC address information to other VTEPs in an EVPN network. The route type field in the EVPN NLRI has a value of 2, indicating a Type-2 route. The device advertising this route into EVPN is 192.168.101.5, which is the IP address of the VTEP that learned the host information from the local CE device. This IP address is carried in the MPLS label field of the route as part of the VXLAN encapsulation.
NEW QUESTION # 52
Which origin code is preferred by BGP?
- A. External
- B. Internal
- C. Null
- D. Incomplete
Answer: D
Explanation:
Explanation
BGP uses several attributes to select the best path for a destination prefix. One of these attributes is origin, which indicates how BGP learned about a route. The origin attribute can have one of three values: IGP, EGP, or Incomplete. IGP means that the route was originated by a network or aggregate statement within BGP or by redistribution from an IGP into BGP. EGP means that the route was learned from an external BGP peer (this value is obsolete since BGP version 4). Incomplete means that the route was learned by some other means, such as redistribution from a static route into BGP. BGP prefers routes with lower origin values, so Incomplete is preferred over EGP, which is preferred over IGP.
NEW QUESTION # 53
......
New JN0-664 Exam Questions Real Juniper Dumps: https://quizguide.actualcollection.com/JN0-664-exam-questions.html