JN0-683 Sample Questions & Answers
Expect questions on EVPN-VXLAN signaling through multiprotocol BGP, IP fabric architecture and how it scales, core VXLAN concepts and its control plane, data center interconnect, multitenancy and security, zero-touch provisioning, and monitoring.
Launch the full JN0-683 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Layer 3 Fabrics (IP Fabrics) · IP Fabric Architecture
A network architect is troubleshooting poor ECMP load-balancing in a spine-leaf fabric. Traffic from a single high-volume flow between two servers is consistently using only one of the available four paths to the spine. The architect wants to ensure that traffic is balanced based on more than just source/destination IP addresses. Which configuration change will achieve per-packet load balancing for all traffic?
Show answer & explanation
Correct answer: B
By default, Junos devices perform per-flow load balancing based on a hash of Layer 3 and Layer 4 information. To override this for all traffic and force a round-robin distribution, a policy-statement with the
load-balance per-packetaction must be created and then applied as an export policy to the forwarding table under[edit routing-options forwarding-table]. This ensures all packets, regardless of flow, are distributed across available ECMP paths. - Question 2Intermediate
VXLAN · VXLAN Data Plane
When troubleshooting BUM (Broadcast, Unknown Unicast, Multicast) traffic in an EVPN-VXLAN fabric that uses ingress replication, where does the traffic replication occur and which EVPN route type is used to build the list of remote VTEPs?
Show answer & explanation
Correct answer: B
In an ingress replication model, the source (ingress) leaf VTEP is responsible for creating a copy of the BUM frame for every other remote VTEP participating in that VNI. The list of remote VTEPs to replicate to is built from the EVPN Type 3 Inclusive Multicast Ethernet Tag (IMET) routes advertised by all VTEPs in the fabric for that VNI.
- Question 3Advanced
Data Center Multitenancy and Security · Group-Based Policy (GBP)
A cloud provider is using Group-Based Policy (GBP) to enforce micro-segmentation in their multi-tenant EVPN-VXLAN fabric. A new security requirement states that web servers (GBP Tag 10) can initiate connections to database servers (GBP Tag 20), but database servers cannot initiate connections back to the web servers. How is this unidirectional policy typically enforced within the fabric?
Show answer & explanation
Correct answer: C
GBP policies are enforced at the ingress VTEP. When a packet from a web server (Tag 10) arrives, the ingress VTEP checks the policy. A rule allowing Tag 10 to communicate with Tag 20 would permit the packet. When a packet from a database server (Tag 20) tries to initiate a connection to a web server (Tag 10), the ingress VTEP for the database server would check its policy and, finding no explicit allow rule, would drop the packet. This allows for stateful-like enforcement in a distributed manner.
- Question 4Advanced
Data Center Interconnect (DCI) · DCI with Type 5 Routes
Case Study
A healthcare provider, "Veridian Health," is modernizing its primary data center and building a new disaster recovery (DR) site. Both sites are built as EVPN-VXLAN fabrics using QFX Series switches in a spine-leaf topology. The primary goal is to provide seamless workload mobility and active-active access to critical applications hosted in both locations.
The network team has chosen to implement a Layer 3 DCI using EVPN Type 5 routes. The design uses two QFX10002 switches at each site as DCI gateways. Tenant VRFs from the local fabric are extended to the DCI gateways. The gateways at each site peer with each other over a dedicated dark fiber link.
During testing, the team observes that while tenants can communicate with their counterparts in the other DC, all traffic from the DR site to the primary site is taking a suboptimal, higher-latency path through a backup MPLS link instead of the primary dark fiber link. Both links are advertising the tenant prefixes via EBGP.
What is the most likely cause and the best practice solution to ensure traffic prefers the primary dark fiber link?
Show answer & explanation
Correct answer: D
In BGP path selection, the LOCAL_PREF attribute is checked before MED, AS-PATH, or router ID, and it is the standard mechanism for influencing outbound path selection within an autonomous system. By setting a higher LOCAL_PREF (e.g., 200) for routes learned via the primary dark fiber link and a lower default value (100) for the backup MPLS link, all outbound traffic from the DCI gateways will prefer the dark fiber path.
- Question 5Beginner
Data Center Deployment and Management · Zero-Touch Provisioning (ZTP)
A network engineer is configuring a new leaf switch using Zero-Touch Provisioning (ZTP). The switch successfully obtains an IP address from DHCP but fails to download its configuration file. The DHCP server is confirmed to be sending the correct file path in DHCP Option 67. The file is hosted on a central TFTP server. What is the MOST likely cause of this ZTP failure?
Show answer & explanation
Correct answer: C
When a switch boots in a ZTP environment, it receives its IP address, netmask, and potentially other options from DHCP. However, to reach a TFTP server on a different subnet, it needs a default gateway. If the DHCP server does not provide Option 3 (Router/Default Gateway), the switch will have no route to the TFTP server and the file download will fail. This is a very common ZTP setup issue.
- Question 6Intermediate
EVPN-VXLAN Signaling · EVPN Route Types
What is the primary function of an EVPN Type 1 Ethernet Auto-Discovery (A-D) route in a multihoming scenario?
Show answer & explanation
Correct answer: C
The EVPN Type 1 route is used for mass withdrawal and aliasing in active-active multihoming. All PEs connected to the same Ethernet Segment (identified by a unique ESI) advertise a Type 1 route for that ESI. This allows remote PEs to learn all paths to the segment and perform load balancing (aliasing). It is also used for fast convergence; if a PE loses connectivity to the segment, it withdraws its Type 1 route, signaling remote PEs to stop sending traffic to it.
- Question 7Intermediate
Data Center Deployment and Management · Monitoring and Analytics
You are tasked with monitoring the health of a large-scale IP fabric. You need to collect high-frequency data for interface counters and per-queue statistics without impacting the CPU of the QFX switches. Which telemetry protocol and transport mechanism should you use?
Show answer & explanation
Correct answer: D
For high-frequency, low-impact telemetry, Juniper Telemetry Interface (JTI) using UDP as the transport is the ideal choice. UDP is connectionless and has lower overhead than TCP, which is used by gRPC. JTI with native sensors can push data directly from the Packet Forwarding Engine (PFE), minimizing CPU involvement and allowing for very high-frequency data collection suitable for interface and queue statistics.
- Question 8Intermediate
EVPN-VXLAN Signaling · Edge-Routed Bridging (ERB)
In an Edge-Routed Bridging (ERB) EVPN-VXLAN fabric, multiple leaf switches are configured with the same IP and MAC address on their IRB interfaces for a given VLAN. What is this feature called and what is its primary benefit?
Show answer & explanation
Correct answer: B
This feature is known as an Anycast Gateway. Its primary benefit is that a host (server or VM) can use the same default gateway IP address regardless of which leaf switch it is connected to. This enables seamless mobility (e.g., vMotion) across the fabric without requiring any changes to the host's network configuration and ensures that egress traffic is always routed by the local leaf switch, providing optimal forwarding.
- Question 9Beginner
Layer 3 Fabrics (IP Fabrics) · IP Fabric Scaling
True or False: In a 5-stage Clos (super-spine) IP fabric, direct physical connections exist between leaf switches in different pods.
Show answer & explanation
Correct answer: B
This statement is false. A fundamental principle of Clos topologies, whether 3-stage or 5-stage, is that switches at the same layer do not connect to each other. In a 5-stage fabric, leaf switches connect to spine switches within their pod. The spine switches then connect to the super-spine switches, which interconnect the pods. All inter-pod traffic must traverse the spine and super-spine layers.
- Question 10AdvancedSelect 2
Data Center Multitenancy and Security · Filter-Based Forwarding (FBF)
Case Study
A retail company, "Global Mart," operates an e-commerce platform hosted in a primary data center. To improve security and segment traffic, they have implemented a service chaining solution using Filter-Based Forwarding (FBF). All traffic from the Web VRF destined for the Database VRF must be redirected through a virtual firewall service instance running on a pair of SRX devices.
The network topology involves leaf switches connected to the SRX firewalls. The leaf switches use FBF to steer traffic. The configuration appears correct, but during a security audit, it is discovered that if the primary SRX firewall fails, traffic is not automatically redirected to the standby SRX. Instead, traffic between the Web and Database VRFs is black-holed.
Which two actions are required to provide automatic failover for the firewall service chain? (Select TWO)
Show answer & explanation
Correct answers: C, D
BFD provides a low-overhead, rapid failure detection mechanism. By establishing BFD sessions from the leaf switches to the service interfaces on both SRX devices, the leaf can detect a failure in milliseconds.
The
next-hop-groupfeature allows you to define a list of next-hops for forwarding. When combined with BFD, the switch will monitor the liveness of each next-hop in the group. If the BFD session to the primary SRX fails, the switch automatically removes it from the forwarding path and starts using the secondary SRX next-hop.
Ready for the real thing?
The full JN0-683 simulator has every exam-style question, timed mode, and instant scoring.