Data Center Multitenancy and Security
JNCIP-DC · 50 questions
- A city data center hosts Parks recreation apps and Police records apps that must not share broadcast or routing tables. Which design best delivers tenant traffic isolation for both Layer 2 and Layer 3?
- During a county audit, Parks and Transit are discovered on the same VLAN even though policy requires Layer 2 tenant isolation. What is the primary isolation failure?
- Health and Finance each have separate VRFs, but an engineer adds a broad route-leak policy that imports Finance prefixes into Health. What is the main multitenancy risk?
- A municipal payment VRF that handles PCI cardholder traffic must never reach the guest Wi-Fi VRF. Which approach best preserves strict Layer 3 isolation?
- Two unrelated city agencies share one L2 VNI while ops tries to separate them with different IRB subnets. Why is this a poor isolation design?
- A municipal multitenant data center can stretch Layer 2 to a remote site for one agency but must not offer that stretch to others. What isolation principle applies?
- City architects want east-west microsegmentation inside the Libraries tenant and also hard isolation from the Courts tenant. How should those goals be treated?
- A single city IT organization owns the whole fabric but still separates production and development with different VRFs. What does this illustrate?
- On a Juniper EVPN-VXLAN municipal leaf, how are Layer 2 and Layer 3 tenant isolation mechanisms typically mapped?
- A shared-services tenant hosts DNS and directory servers that selected agencies must reach without opening full mesh connectivity. Which pattern fits?
- Two agencies independently used 10.10.0.0/16 inside their own networks and now onboard to the same EVPN-VXLAN fabric. What enables that overlapping addressing?
- An auditor asks for proof that Parks servers cannot ARP Courts servers across the municipal fabric. Which verification concept matters most for Layer 2 isolation?
- On QFX leaves in a city EVPN-VXLAN fabric, what Junos construct is primarily used to separate tenant Layer 3 tables for multitenancy?
- City fabric engineers map each agency to a Junos routing instance used as a tenant VRF on EVPN-VXLAN leaves. Which instance approach best matches common DC tenant separation at describe depth?
- A tenant routing instance on a municipal leaf must advertise and learn overlay routes for its VNI. What binding is required?
- Operators place every municipal agency's tenant interfaces and routes into inet.0 on the leaves. Why does that undermine multitenancy?
- In a multitenant EVPN-VXLAN city fabric, why must route distinguishers be unique per tenant routing instance?
- Two unrelated agency VRFs accidentally share the same route target import/export values. What is the likely result?
- A small township data center runs one IT organization with no agency isolation requirements. Which architecture statement is most accurate?
- Planners propose hundreds of routing instances on each leaf for tiny municipal departments. Beyond raw platform limits, what operational concern should they weigh?
- Under an ERB design, where should a tenant's IRB interface be placed for correct multitenancy?
- Municipal operators need leaf management reachability without exposing tenant VRFs. Which separation practice is most appropriate?
- Internet breakout is available from a shared edge VRF. How should municipal tenant instances receive a default route?
- Across dozens of municipal leaves, tenant routing-instance names and IDs drift (vrf-parks vs ParksVRF vs tnt3). Why does consistent naming matter for multitenancy?
- An engineer moves a VLAN interface from the Parks routing instance into the Courts instance during a change window. What is the most accurate impact statement?
- A city data-center leaf must steer traffic from a permitting-office subnet into an inspection routing instance before it reaches tenant servers. Which Junos mechanism selects an alternate forwarding routing instance based on a packet filter match?
- Operations staff propose a firewall discard term to “secure” guest VLAN traffic the same way filter-based forwarding would. What is the key difference they must understand?
- A municipal guest Wi-Fi portal must redirect unauthenticated client traffic into a captive-portal routing instance on the EVPN-VXLAN leaf. Which approach best matches a classic filter-based forwarding use case?
- A county backup system marks bulk replication with a specific DSCP value, and the fabric must send those flows into a low-priority path routing instance. How should filter-based forwarding classify and steer that traffic?
- After deploying FBF toward a security VRF, a city auditor finds some matched flows still bypass inspection. What troubleshooting mindset should the engineer apply first?
- In an ERB EVPN-VXLAN design, tenant workloads attach through IRB interfaces in a tenant routing instance. Where should the city fabric typically attach filter-based forwarding to steer that tenant traffic?
- A township steers client-to-server traffic toward an inspection service with FBF but leaves the return path on the normal tenant instance. What pitfall should the designer anticipate?
- A township wants selected agency traffic forced out a specific DCI path rather than the default tenant exit. How can filter-based forwarding support that traffic-engineering goal?
- An engineer adds an FBF term to steer finance-subnet traffic, yet counters show an earlier accept term always hits first. What principle explains why the FBF action never applies?
- A city security design must send suspicious Internet-facing flows into a scrubbing routing instance and then return cleaned traffic to the normal tenant forwarding path. Which pattern best describes this FBF role?
- The operations team debates installing heavy, complex FBF policies on every leaf versus steering at a smaller set of centralized choke points. What placement tradeoff should drive the decision?
- An auditor asks how filter-based forwarding relates to VRF-based tenant isolation in the municipal fabric. Which statement best describes their complementary roles?
- A municipal zero-trust initiative needs microsegmentation with group tags and policy inside an existing EVPN-VXLAN VNI rather than creating a new VNI per tier. Which Juniper data-center security approach fits that goal?
- Operations asks why the city should use GBP instead of creating a separate VNI for every application tier that needs isolation. What advantage should be emphasized?
- After 802.1X or similar authentication, a civic endpoint should land in a GBP group that drives allow/deny policy in the fabric. What concept is being applied?
- Policy requires that the cameras group must not initiate sessions to the finance group on the city EVPN-VXLAN fabric. How does GBP express that intent?
- A city still maintains per-agency VRFs and VNIs while introducing GBP for finer controls inside some overlays. What layered-isolation principle applies?
- Engineers need every leaf to enforce the same GBP decisions for a mobile municipal workload. At a describe-level understanding, how does group information typically stay consistent across the fabric?
- A mis-tagged application server is placed in the wrong GBP group and suddenly reaches systems it should not. What does this incident highlight?
- Compared with maintaining traditional per-IP or per-port ACL sprawl on every leaf, what operational benefit does GBP microsegmentation provide for the municipal fabric?
- For east-west traffic between workloads on an EVPN-VXLAN city fabric, where is GBP policy commonly enforced?
- During GBP design review, stakeholders debate default deny between groups versus default allow with explicit denies. What should the team recognize about that choice?
- The municipality wants GBP group membership informed by its existing identity and access management (IAM) results rather than only static switch port maps. What conceptual integration is appropriate?
- Troubleshooting shows EVPN reachability to a remote VTEP is healthy, yet application flows between two groups still fail. What GBP-related explanation should be considered?
- A design review for the city’s first GBP rollout debates starting with dozens of hyper-granular groups versus a few coarse groups refined over time. Which approach is more practical?