1 | Page
JUNIPER NETWORKS CERTIFIED
SPECIALIST – SERVICE PROVIDER
ROUTING AND SWITCHING (JNCIS-SP)
PRACTICE EXAM 2026/2027QUESTIONS
WITH VERIFIED ANSWERS & COMPLETE
RATIONALES
**1. A network engineer needs to leak interface routes from the
default routing table (inet.0) to a custom routing instance table
named 'cust-A.inet.0'. Which configuration element is required
to achieve this objective?**
A. A firewall filter applied to the interface
B. A RIB group with import-rib statement
C. A routing policy with a match on interface
D. A static route in the custom routing instance
**Correct answer:** B
**Rationale:** To leak interface routes between routing tables, a
RIB group must be created specifying the primary and
secondary routing tables using the 'import-rib' statement. The
primary table (inet.0) is listed first, followed by the secondary
table (cust-A.inet.0). This RIB group is then applied globally
under the [edit routing-options interface-routes] hierarchy to
,2 | Page
instruct the router to place direct interface routes into both
tables.
**2. A service provider requires traffic engineering based on
source IP address and application type. HTTP traffic from
subnet 10.1.1.0/24 must be routed to ISP-1, while all other
traffic follows the default route to ISP-2. The design must
minimize impact on the global routing table. Which combination
of configuration elements is required?**
A. A firewall filter with 'then routing-instance' action pointing to a
forwarding-type routing instance
B. A policy-statement applied under [edit protocols bgp] with
community matching
C. A static route with a qualified next-hop in inet.0
D. A VRF routing instance with route targets
**Correct answer:** A
**Rationale:** Filter-Based Forwarding (FBF) relies on a firewall
filter applied to the ingress interface. The filter evaluates traffic
and uses the 'then routing-instance' action for matched
packets, directing them to a custom routing instance. To isolate
this forwarding plane without creating full virtual routers, the
instance is typically configured as 'instance-type forwarding'
and populated with the necessary next-hop routes. Traffic not
matching the filter falls through to the global routing table.
, 3 | Page
**3. When comparing aggregate and generated routes in Junos
OS, which TWO statements accurately describe their
characteristics? (Select TWO)**
A. Both have a default route preference of 130
B. Aggregate routes use a reject next-hop by default, while
generated routes can inherit a real next-hop
C. Aggregate routes appear in the routing table only if at least
one contributing route exists
D. Generated routes always require a contributing route to be
active
**Correct answer:** B, C
**Rationale:** Both aggregate and generated routes are used
to summarize routing information. By default, an aggregate
route is assigned a next-hop of reject (or discard), preventing
routing loops for subnets within the summary that do not exist.
A generated route can inherit the real next-hop of the primary
contributing route, allowing it to forward traffic dynamically. Both
appear in the routing table only if at least one or more specific
contributing subnets exist.
JUNIPER NETWORKS CERTIFIED
SPECIALIST – SERVICE PROVIDER
ROUTING AND SWITCHING (JNCIS-SP)
PRACTICE EXAM 2026/2027QUESTIONS
WITH VERIFIED ANSWERS & COMPLETE
RATIONALES
**1. A network engineer needs to leak interface routes from the
default routing table (inet.0) to a custom routing instance table
named 'cust-A.inet.0'. Which configuration element is required
to achieve this objective?**
A. A firewall filter applied to the interface
B. A RIB group with import-rib statement
C. A routing policy with a match on interface
D. A static route in the custom routing instance
**Correct answer:** B
**Rationale:** To leak interface routes between routing tables, a
RIB group must be created specifying the primary and
secondary routing tables using the 'import-rib' statement. The
primary table (inet.0) is listed first, followed by the secondary
table (cust-A.inet.0). This RIB group is then applied globally
under the [edit routing-options interface-routes] hierarchy to
,2 | Page
instruct the router to place direct interface routes into both
tables.
**2. A service provider requires traffic engineering based on
source IP address and application type. HTTP traffic from
subnet 10.1.1.0/24 must be routed to ISP-1, while all other
traffic follows the default route to ISP-2. The design must
minimize impact on the global routing table. Which combination
of configuration elements is required?**
A. A firewall filter with 'then routing-instance' action pointing to a
forwarding-type routing instance
B. A policy-statement applied under [edit protocols bgp] with
community matching
C. A static route with a qualified next-hop in inet.0
D. A VRF routing instance with route targets
**Correct answer:** A
**Rationale:** Filter-Based Forwarding (FBF) relies on a firewall
filter applied to the ingress interface. The filter evaluates traffic
and uses the 'then routing-instance' action for matched
packets, directing them to a custom routing instance. To isolate
this forwarding plane without creating full virtual routers, the
instance is typically configured as 'instance-type forwarding'
and populated with the necessary next-hop routes. Traffic not
matching the filter falls through to the global routing table.
, 3 | Page
**3. When comparing aggregate and generated routes in Junos
OS, which TWO statements accurately describe their
characteristics? (Select TWO)**
A. Both have a default route preference of 130
B. Aggregate routes use a reject next-hop by default, while
generated routes can inherit a real next-hop
C. Aggregate routes appear in the routing table only if at least
one contributing route exists
D. Generated routes always require a contributing route to be
active
**Correct answer:** B, C
**Rationale:** Both aggregate and generated routes are used
to summarize routing information. By default, an aggregate
route is assigned a next-hop of reject (or discard), preventing
routing loops for subnets within the summary that do not exist.
A generated route can inherit the real next-hop of the primary
contributing route, allowing it to forward traffic dynamically. Both
appear in the routing table only if at least one or more specific
contributing subnets exist.