JN0-104 Exam QuestionsBrowse all questions from this exam

JN0-104 Exam - Question 37


Referring to the exhibit, which statement is correct?

Show Answer
Correct Answer: A

The device will attempt to authenticate using the local database if RADIUS and TACACS+ are unresponsive. Junos OS defaults to local password authentication as a last resort if configured RADIUS or TACACS+ servers do not respond. This ensures a fallback method for authentication, which is crucial for maintaining access to the device even when primary authentication methods fail.

Discussion

17 comments
Sign in to comment
Nish202174Option: A
Sep 21, 2022

A is correct. https://www.juniper.net/documentation/us/en/software/junos/user-access/topics/topic-map/junos-os-authentication-order.html

mohi26Option: A
Sep 22, 2022

A is correct.

YgrecOption: A
Apr 16, 2023

A All the vendor included juniper works like that. It's a basic behavior The user local is mandatory if the radius and tacacs server do not respond.

mohdemaOption: A
Oct 17, 2022

authentication-order [ radius tacplus ]; Try configured RADIUS authentication servers. If a RADIUS server is available and authentication is accepted, grant access. If the RADIUS servers fail to respond or the servers return a reject response, try configured TACACS+ servers. If a TACACS+ server is available and authentication is accepted, grant access. If a TACACS+ server is available but authentication is rejected, deny access. If no RADIUS or TACACS+ servers are available, try local password authentication.

MakweenOption: D
Apr 4, 2023

if the show command does not reveal "" (Radius tacplus password) "" in the configuration, when radius and tacacs fails, the system will never attempt to use password

sanbeOption: A
Apr 6, 2023

A is correct. https://www.juniper.net/documentation/us/en/software/junos/user-access/topics/topic-map/junos-os-authentication-order.html

aisa007Option: A
Oct 30, 2022

A is correct

OdvehmirOption: A
Mar 13, 2023

"A" is the correct answer

CradicalOption: A
May 29, 2023

A. The device will attempt to authenticate using the local database if RADIUS and TACACS+ are unresponsive. The authentication-order configuration specifies the order in which authentication methods will be attempted by the device. In this case, the configuration indicates that RADIUS and TACACS+ are the preferred authentication methods as they are listed first in the order. If the RADIUS and TACACS+ servers are unresponsive or unreachable, the device will fall back to the next available method, which is the local database. So, if RADIUS and TACACS+ authentication fails, the device will attempt authentication using the local database as a backup option. Therefore, the correct statement is A: The device will attempt to authenticate using the local database if RADIUS and TACACS+ are unresponsive.

abual3eesOption: D
Sep 21, 2022

i think the correct answer is D

aisa007
Nov 3, 2022

Why is that?

ggelashviliOption: D
Nov 20, 2022

Answer is D: the device must include password as a final authentication order option for the device to attempt local password authentication in the event that the remote authentication servers reject the request

Nebulise
Dec 12, 2022

incorrect

BogarGtz
Feb 1, 2023

If the authentication order includes LDAPS, RADIUS, or TACACS+ servers, but the servers DO NOT RESPOND to a request, Junos OS always defaults to trying local password authentication as a last resort. If the authentication order includes LDAPS, RADIUS, or TACACS+ servers, but the servers REJECT the request, the handling of the request is more complicated. The key is the word UNRESPONSIVE in the A answer.

NasreddOption: A
Jul 7, 2023

A is correct

NicociscoOption: D
Jul 27, 2023

It's D, because in JNCIA courses, we have this example : https://ibb.co/4FVkSnP

bb58b38Option: A
Dec 28, 2023

From the link in the previous comment: If the authentication order includes RADIUS or TACACS+ servers, but the servers do not respond to a request, Junos OS always defaults to trying local password authentication as a last resort.

lanzailanOption: A
Jan 15, 2024

https://www.juniper.net/documentation/us/en/software/junos/user-access/topics/topic-map/junos-os-authentication-order.html authentication-order [ radius tacplus ]; Try configured RADIUS authentication servers. If a RADIUS server is available and authentication is accepted, grant access. If the RADIUS servers fail to respond or the servers return a reject response, try configured TACACS+ servers. If a TACACS+ server is available and authentication is accepted, grant access. If a TACACS+ server is available but authentication is rejected, deny access.

MayTinOption: A
Jan 26, 2024

Correct answer is A

dlolOption: A
Feb 24, 2024

The official Juniper course has this exact example and says that the local database is used if all else fails, even though it is not listed in the output of the command...