Pre-Summer Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Cisco 200-301 Implementing and Administering Cisco Solutions (200-301 CCNA) v1.1 Exam Practice Test

Page: 1 / 124
Total 1240 questions

Implementing and Administering Cisco Solutions (200-301 CCNA) v1.1 Questions and Answers

Question 1

Refer to the exhibit.

Question # 1

An extended ACL has been configured and applied to router R2 The configuration failed to work as intended Which two

changes stop outbound traffic on TCP ports 25 and 80 to 10.0.20 0 26 from the 10.0.10 0/26 subnet while still allowing all other traffic? (Choose

two )

Options:

A.

Add a " permit ip any any " statement to the beginning of ACL 101 for allowed traffic.

B.

Add a " permit ip any any " statement at the end of ACL 101 for allowed traffic

C.

The source and destination IPs must be swapped in ACL 101

D.

The ACL must be configured the Gi0/2 interface inbound on R1

E.

The ACL must be moved to the Gi0/1 interface outbound on R2

Question 2

Refer to the exhibit.

Question # 2

A router received these five routes from different routing information sources.

Which two routes does the router install in its routing table? (Choose two)

Options:

A.

RIP route 10.0.0.0/30

B.

iBGP route 10.0.0.0/30

C.

OSPF route 10.0.0.0/30

D.

EIGRP route 10.0.0.1/32

E.

OSPF route 10.0.0.0/16

Question 3

What are two fundamentals of virtualization? (Choose two)

Options:

A.

The environment must be configured with one hypervisor that serves solely as a network manager to monitor SNMP traffic

B.

It allows logical network devices to move traffic between virtual machines and the rest of the physical network

C.

It allows multiple operating systems and applications to run independently on one physical server.

D.

It allows a physical router to directly connect NICs from each virtual machine into the network

E.

It requires that some servers, virtual machines and network gear reside on the Internet

Question 4

Refer to the exhibit.

Question # 4

Which password must an engineer use to enter the enable mode?

Options:

A.

adminadmin123

B.

default

C.

testing1234

D.

cisco123

Question 5

In which two ways does a password manager reduce the chance of a hacker stealing a users password? (Choose two.)

Options:

A.

It automatically provides a second authentication factor that is unknown to the original user.

B.

It uses an internal firewall to protect the password repository from unauthorized access.

C.

It protects against keystroke logging on a compromised device or web site.

D.

It stores the password repository on the local workstation with built-in antivirus and anti-malware functionality

E.

It encourages users to create stronger passwords.

Question 6

How do servers connect to the network in a virtual environment?

Options:

A.

wireless to an access point that is physically connected to the network

B.

a cable connected to a physical switch on the network

C.

a virtual switch that links to an access point that is physically connected to the network

D.

a software switch on a hypervisor that is physically connected to the network

Question 7

Drag and drop the characteristics of network architectures from the left onto the type of architecture on the right.

Question # 7

Options:

Question 8

Drag and drop the DHCP snooping terms from the left onto the descriptions on the right.

Question # 8

Options:

Question 9

which purpose does a northbound API serve in a controller-based networking architecture?

Options:

A.

communicates between the controller and the physical network hardware

B.

reports device errors to a controller

C.

generates statistics for network hardware and traffic

D.

facilitates communication between the controller and the applications

Question 10

Which command on a port enters the forwarding state immediately when a PC is connected to it?

Options:

A.

switch(config)#spanning-tree portfast default

B.

switch(config)#spanning-tree portfast bpduguard default

C.

switch(config-if)#spanning-tree portfast trunk

D.

switch(config-if)#no spanning-tree portfast

Question 11

What is the difference regarding reliability and communication type between TCP and UDP?

Options:

A.

TCP is reliable and is a connection-oriented protocol UDP is not reliable and is a connectionless protocol

B.

TCP is not reliable and is a connection-oriented protocol; UDP is reliable and is a connectionless protocol

C.

TCP is not reliable and is a connectionless protocol; UDP is reliable and is a connection-oriented protocol

D.

TCP is reliable and is a connectionless protocol; UDP is not reliable and is a connection-oriented protocol

Question 12

What is a practice that protects a network from VLAN hopping attacks?

Options:

A.

Enable dynamic ARP inspection

B.

Configure an ACL to prevent traffic from changing VLANs

C.

Change native VLAN to an unused VLAN ID

D.

Implement port security on internet-facing VLANs

Question 13

Which feature on the Cisco Wireless LAN Controller when enabled restricts management access from specific networks?

Options:

A.

CPU ACL

B.

TACACS

C.

Flex ACL

D.

RADIUS

Question 14

What is a network appliance that checks the state of a packet to determine whether the packet is legitimate?

Options:

A.

Layer 2 switch

B.

load balancer

C.

firewall

D.

LAN controller

Question 15

Drag and drop the WLAN components from the left onto the correct descriptions on the right.

Question # 15

Options:

Question 16

Which technology is used to improve web traffic performance by proxy caching?

Options:

A.

WSA

B.

Firepower

C.

ASA

D.

FireSIGHT

Question 17

What is a role of wireless controllers in an enterprise network?

Options:

A.

centralize the management of access points in an enterprise network

B.

support standalone or controller-based architectures

C.

serve as the first line of defense in an enterprise network

D.

provide secure user logins to devices on the network.

Question 18

Which CRUD operation corresponds to the HTTP GET method?

Options:

A.

read

B.

update

C.

create

D.

delete

Question 19

Which two command sequences must you configure on switch to establish a Layer 3 EtherChannel with an open-standard protocol? (Choose two)

Options:

A.

interface GigabitEthernet0/0/1channel-group 10 mode on

B.

interface GigabitEthernet0/0/1channel-group 10 mode active

C.

interface GigabitEthernet0/0/1channel-group 10 mode auto

D.

interface port-channel 10switchportswitchport mode trunk

E.

interface port-channel 10no switchportip address 172.16.0.1.255.255.255.0

Question 20

Which access layer threat-mitigation technique provides security based on identity?

Options:

A.

Dynamic ARP Inspection

B.

using a non-default native VLAN

C.

802.1x

D.

DHCP snooping

Question 21

What occurs to frames during the process of frame flooding?

Options:

A.

Frames are sent to every port on the switch in the same VLAN except from the originating port

B.

Frames are sent to every port on the switch that has a matching entry in the MAC address table.

C.

Frames are sent to all ports, including those that are assigned to other VLANs.

D.

Frames are sent to every port on the switch in the same VLAN.

Question 22

Which device controls the forwarding of authentication requests for users when connecting to the network using a lightweight access point?

Options:

A.

TACACS server

B.

wireless access point

C.

RADIUS server

D.

wireless LAN controller

Question 23

Refer to the exhibit.

Question # 23

Which switch becomes the root of the spanning tree for VLAN 110?

Question # 23

Options:

A.

Switch 1

B.

Switch 2

C.

Switch 3

D.

Switch 4

Question 24

When a floating static route is configured, which action ensures that the backup route is used when the primary route fails?

Options:

A.

The floating static route must have a higher administrative distance than the primary route so it is used as a backup

B.

The administrative distance must be higher on the primary route so that the backup route becomes secondary.

C.

The floating static route must have a lower administrative distance than the primary route so it is used as a backup

D.

The default-information originate command must be configured for the route to be installed into the routing table

Question 25

How does Cisco DNA Center gather data from the network?

Options:

A.

Network devices use different services like SNMP, syslog, and streaming telemetry to send data to the controller

B.

Devices establish an IPsec tunnel to exchange data with the controller

C.

Devices use the call-home protocol to periodically send data to the controller.

D.

The Cisco CU Analyzer tool gathers data from each licensed network device and streams it to the controller.

Question 26

Which QoS Profile is selected in the GUI when configuring a voice over WLAN deployment?

Options:

A.

Bronze

B.

Platinum

C.

Silver

D.

Gold

Question 27

An email user has been lured into clicking a link in an email sent by their company ' s security organization. The webpage that opens reports that it was safe but the link could have contained malicious code. Which type of security program is in place?

Options:

A.

Physical access control

B.

Social engineering attack

C.

brute force attack

D.

user awareness

Question 28

What is a difference between local AP mode and FlexConnect AP mode?

Options:

A.

Local AP mode creates two CAPWAP tunnels per AP to the WLC

B.

FlexConnect AP mode fails to function if the AP loses connectivity with the WLC

C.

FlexConnect AP mode bridges the traffic from the AP to the WLC when local switching is configured

D.

Local AP mode causes the AP to behave as if it were an autonomous AP

Question 29

What is recommended for the wireless infrastructure design of an organization?

Options:

A.

group access points together to increase throughput on a given channel

B.

configure the first three access points are configured to use Channels 1, 6, and 11

C.

include a least two access points on nonoverlapping channels to support load balancing

D.

assign physically adjacent access points to the same Wi-Fi channel

Question 30

Where does the configuration reside when a helper address Is configured lo support DHCP?

Options:

A.

on the router closest to the server

B.

on the router closest to the client

C.

on every router along the path

D.

on the switch trunk interface

Question 31

An engineer must configure the IPv6 address 2001:0db8:0000:0000:0700:0003:400F:572B on the serial0/0 interface of the HQ router and wants to compress it for easier configuration. Which command must be issued on the router interface?

Options:

A.

ipv6 address 2001:db8::700:3:400F:572B

B.

ipv6 address 2001:db8:0::700:3:4F:572B

C.

ipv6 address 2001:Odb8::7:3:4F:572B

D.

ipv6 address 2001::db8:0000::700:3:400F:572B

Question 32

What is an advantage of Cisco DNA Center versus traditional campus device management?

Options:

A.

It supports numerous extensibility options including cross-domain adapters and third-party SDKs.

B.

It supports high availability for management functions when operating in cluster mode.

C.

It enables easy autodiscovery of network elements m a brownfield deployment.

D.

It is designed primarily to provide network assurance.

Question 33

Drag and drop the descriptions from the left onto the correct configuration-management technologies on the right.

Question # 33

Options:

Question 34

Which two capacities of Cisco DNA Center make it more extensible as compared to traditional campus device management? (Choose two)

Options:

A.

adapters that support all families of Cisco IOS software

B.

SDKs that support interaction with third-party network equipment

C.

customized versions for small, medium, and large enterprises

D.

REST APIs that allow for external applications to interact natively with Cisco DNA Center

E.

modular design that is upgradable as needed

Question 35

Refer to the exhibit.

Question # 35

Which switch in this configuration will be elected as the root bridge?

Question # 35

Options:

A.

SW1

B.

SW2

C.

SW3

D.

SW4

Question 36

When DHCP is configured on a router, which command must be entered so the default gateway is automatically distributed?

Options:

A.

default-router

B.

default-gateway

C.

ip helper-address

D.

dns-server

Question 37

Which WAN topology provides a combination of simplicity quality, and availability?

Options:

A.

partial mesh

B.

full mesh

C.

point-to-point

D.

hub-and-spoke

Question 38

Drag and drop the attack-mitigation techniques from the left onto the Types of attack that they mitigate on the right.

Question # 38

Options:

Question 39

Which two encoding methods are supported by REST APIs? (Choose two)

Options:

A.

YAML

B.

JSON

C.

EBCDIC

D.

SGML

E.

XML

Question 40

What are two roles of Domain Name Services (DNS)? (Choose Two)

Options:

A.

builds a flat structure of DNS names for more efficient IP operations

B.

encrypts network Traffic as it travels across a WAN by default

C.

improves security by protecting IP addresses under Fully Qualified Domain Names (FQDNs)

D.

enables applications to identify resources by name instead of IP address

E.

allows a single host name to be shared across more than one IP address

Question 41

In software-defined architectures, which plane is distributed and responsible for traffic forwarding?

Options:

A.

management plane

B.

control plane

C.

policy plane

D.

data plane

Question 42

Refer to the exhibit.

Question # 42

The network administrator wants VLAN 67 traffic to be untagged between Switch 1 and Switch 2 while all other VLANs are to remain tagged.

Which command accomplishes this task?

Options:

A.

switchport access vlan 67

B.

switchport trunk allowed vlan 67

C.

switchport private-vlan association host 67

D.

switchport trunk native vlan 67

Question 43

Refer to the exhibit.

Question # 43

What commands are needed to add a subinterface to Ethernet0/0 on R1 to allow for VLAN 20, with IP address 10.20.20.1/24?

Options:

A.

R1(config)#interface ethernet0/0R1(config)#encapsulation dot1q 20R1(config)#ip address 10.20.20.1 255.255.255.0

B.

R1(config)#interface ethernet0/0.20R1(config)#encapsulation dot1q 20R1(config)#ip address 10.20.20.1 255.255.255.0

C.

R1(config)#interface ethernet0/0.20R1(config)#ip address 10.20.20.1 255.255.255.0

D.

R1(config)#interface ethernet0/0R1(config)#ip address 10.20.20.1 255.255.255.0

Question 44

Which mode must be used to configure EtherChannel between two switches without using a negotiation protocol?

Options:

A.

on

B.

auto

C.

active

D.

desirable

Question 45

Which attribute does a router use to select the best path when two or more different routes to the same destination exist from two different routing protocols.

Options:

A.

dual algorithm

B.

metric

C.

administrative distance

D.

hop count

Question 46

Refer to the exhibit.

Question # 46

What two conclusions should be made about this configuration? (Choose two)

Options:

A.

The designated port is FastEthernet 2/1

B.

This is a root bridge

C.

The spanning-tree mode is Rapid PVST+

D.

The spanning-tree mode is PVST+

E.

The root port is FastEthernet 2/1

Question 47

What is a benefit of using a Cisco Wireless LAN Controller?

Options:

A.

Central AP management requires more complex configurations

B.

Unique SSIDs cannot use the same authentication method

C.

It supports autonomous and lightweight APs

D.

It eliminates the need to configure each access point individually

Question 48

Refer to the exhibit.

Question # 48

What is the next hop address for traffic that is destined to host 10.0.1.5?

Options:

A.

10.0.1.3

B.

10.0.1.50

C.

10.0.1.4

D.

Loopback D

Question 49

Which two functions are performed by the core layer in a three-tier architecture? (Choose two)

Options:

A.

Provide uninterrupted forwarding service.

B.

Police traffic that is sent to the edge of the network.

C.

Provide direct connectivity for end user devices.

D.

Ensure timely data transfer between layers.

E.

Inspect packets for malicious activity.

Question 50

What uses HTTP messages to transfer data to applications residing on different hosts?

Options:

A.

OpenFlow

B.

OpenStack

C.

OpFlex

D.

REST

Question 51

An organization has decided to start using cloud-provided services. Which cloud service allows the organization to install its own operating system on a virtual machine?

Options:

A.

platform-as-a-service

B.

software-as-a-service

C.

network-as-a-service

D.

infrastructure-as-a-service

Question 52

What causes a port to be placed in the err-disabled state?

Options:

A.

latency

B.

port security violation

C.

shutdown command issued on the port

D.

nothing plugged into the port

Question 53

Which command automatically generates an IPv6 address from a specified IPv6 prefix and MAC address of an interface?

Options:

A.

ipv6 address dhcp

B.

ipv6 address 2001:DB8:5:112::/64 eui-64

C.

ipv6 address autoconfig

D.

ipv6 address 2001:DB8:5:112::2/64 link-local

Question 54

Question # 54

Refer to the exhibit. Routers R1 and R2 have been configured with their respective LAN interfaces. The two circuits are operational and reachable across the WAN. Which command set establishes failover redundancy if the primary circuit goes down?

Question # 54

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 55

Refer to the exhibit.

Question # 55

Which switch becomes the root bridge?

Options:

A.

S1

B.

S2

C.

S3

D.

S4

Question 56

Refer to the exhibit.

Question # 56

How must router A be configured so that it only sends Cisco Discovery Protocol Information to router C?

Question # 56

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 57

What software-defined architecture plane assists network devices with making packet-forwarding decisions by providing Layer 2 reachability and Layer 3 routing information?

Options:

A.

data plane

B.

control plane

C.

policy plane

D.

management plane

Question 58

What criteria is used first during the root port selection process?

Options:

A.

local port ID

B.

lowest path cost to the root bridge

C.

lowest neighbor ' s bridge ID

D.

lowest neighbor ' s port ID

Question 59

Which option about JSON is true?

Options:

A.

uses predefined tags or angle brackets () to delimit markup text

B.

used to describe structured data that includes arrays

C.

used for storing information

D.

similar to HTML, it is more verbose than XML

Question 60

What does a router do when configured with the default DNS lookup settings, and a URL is entered on the CLI?

Options:

A.

initiates a ping request to the URL

B.

prompts the user to specify the desired IP address

C.

continuously attempts to resolve the URL until the command is cancelled

D.

sends a broadcast message in an attempt to resolve the URL

Question 61

Drag and drop the AAA functions from the left onto the correct AAA services on the right

Question # 61

Options:

Question 62

An engineer needs to add an old switch back into a network. To prevent the switch from corrupting the VLAN database which action must be taken?

Options:

A.

Add the switch in the VTP domain with a lower revision number

B.

Add the switch with DTP set to dynamic desirable

C.

Add the switch in the VTP domain with a higher revision number

D.

Add the switch with DTP set to desirable

Question 63

Question # 63

Question # 63

IP connectivity between the three routers is configured. OSPF adjacencies must be established.

1. Configure R1 and R2 Router IDs using the interface IP addresses from the link that is shared between them.

2. Configure the R2 links with a max value facing R1 and R3. R2 must become the DR. R1 and R3 links facing R2 must remain with the default OSPF configuration for DR election. Verify the configuration after clearing the OSPF process.

3. Using a host wildcard mask, configure all three routers to advertise their respective Loopback1 networks.

4. Configure the link between R1 and R3 to disable their ability to add other OSPF routers.

Options:

Question 64

Question # 64

All physical cabling between the two switches is installed. Configure the network connectivity between the switches using the designated VLANs and interfaces.

1. Configure VLAN 100 named Compute and VLAN 200 named Telephony where required for each task.

2. Configure Ethernet0/1 on SW2 to use the existing VLAN named Available.

3. Configure the connection between the switches using access ports.

4. Configure Ethernet0/1 on SW1 using data and voice VLANs.

5. Configure Ethemet0/1 on SW2 so that the Cisco proprietary neighbor discovery protocol is turned off for the designated interface only.

Question # 64

Options:

Question 65

Question # 65

Question # 65

Question # 65

IP connectivity and OSPF are preconfigured on all devices where necessary. Do not make any changes to the IP addressing or OSPF. The company policy uses connected interfaces and next hops when configuring static routes except for load balancing or redundancy without floating static. Connectivity must be established between subnet 172.20.20.128/25 on the Internet and the LAN at 192.168.0.0/24 connected to SW1:

1. Configure reachability to the switch SW1 LAN subnet in router R2.

2. Configure default reachability to the Internet subnet in router R1.

3. Configure a single static route in router R2 to reach to the Internet subnet considering both redundant links between routers R1 and R2. A default route is NOT allowed in router R2.

4. Configure a static route in router R1 toward the switch SW1 LAN subnet where the primary link must be through Ethernet0/1. and the backup link must be through Ethernet0/2 using a floating route. Use the minimal administrative distance value when required.

Options:

Question 66

All physical cabling is in place. A company plans to deploy 32 new sites.

The sites will utilize both IPv4 and IPv6 networks.

1 . Subnet 172.25.0.0/16 to meet the subnet requirements and maximize

the number of hosts

Using the second subnet

• Assign the first usable IP address to e0/0 on Sw1O1

• Assign the last usable IP address to e0/0 on Sw102

2. Subnet to meet the subnet requirements and maximize

the number of hosts

c Using the second subnet

• Assign an IPv6 GUA using a unique 64-Bit interface identifier

on e0/0 on Sw101

• Assign an IPv6 GUA using a unique 64-Bit interface identifier

on eO/O on swi02

Guidelines

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using

the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Question # 66

Options:

Question 67

Question # 67

Question # 67

Connectivity between three routers has been established, and IP services must be configured jn the order presented to complete the implementation Tasks assigned include configuration of NAT, NTP, DHCP, and SSH services.

1. All traffic sent from R3 to the R1 Loopback address must be configured for NAT on R2. All source addresses must be translated from R3 to the IP address of Ethernet0/0 on R2, while using only a standard access list named NAT To verify, a ping must be successful to the R1 Loopback address sourced from R3. Do not use NVI NAT configuration.

2. Configure R1 as an NTP server and R2 as a client, not as a peer, using the IP address of the R1 Ethernet0/2 interface. Set the clock on the NTP server for midnight on January 1, 2019.

3. Configure R1 as a DHCP server for the network 10.1.3.0/24 in a pool named TEST. Using a single command, exclude addresses 1-10 from the range. Interface Ethernet0/2 on R3 must be issued the IP address of 10.1.3.11 via DHCP.

4. Configure SSH connectivity from R1 to R3, while excluding access via other remote connection protocols. Access for user root and password Cisco must be set on router R3 using RSA and 1024 bits. Verify connectivity using an SSH session from router R1 using a destination address of 10.1.3.11. Do NOT modify console access or line numbers to accomplish this task.

Options:

Question 68

Physical connectivity is implemented between the two Layer 2 switches,

and the network connectivity between them must be configured.

I . Configure an LACP EtherChanneI and number it as 44; configure it

between switches SWI and SW2 using interfaces EthernetO/O and

Ethernet0/1 on both sides. The LACP mode must match on both ends.

2. Configure the EtherChanneI as a trunk link.

3. Configure the trunk link with 802. Iq tags.

4. Configure VLAN ' MONITORING ' as the untagged VLAN of the

EtherChannel.

==================

Guidelines

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using

the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Question # 68

Options:

Question 69

All physical cabling is in place. Router R4 and PCI are fully configured and

inaccessible. R4 ' s WAN interfaces use .4 in the last octet for each subnet.

Configurations should ensure that connectivity is established end-to-end.

1 . Configure static routing to ensure RI prefers the path through R2 to

reach only PCI on R4 ' s LAN

2. Configure static routing that ensures traffic sourced from RI will take

an alternate path through R3 to PCI in the event of an outage along

the primary path

3. Configure default routes on RI and R3 to the Internet using the least number of hops

Guidelines

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using

the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Question # 69

Options:

Question 70

Question # 70

Three switches must be configured for Layer 2 connectivity. The company requires only the designated VLANs to be configured on their respective switches and permitted accross any links between switches for security purposes. Do not modify or delete VTP configurations.

The network needs two user-defined VLANs configured:

VLAN 110: MARKETING

VLAN 210: FINANCE

1. Configure the VLANs on the designated switches and assign them as access ports to the interfaces connected to the PCs.

2. Configure the e0/2 interfaces on Sw1 and Sw2 as 802.1q trunks with only the required VLANs permitted.

3. Configure the e0/3 interfaces on Sw2 and Sw3 as 802.1q trunks with only the required VLANs permitted.

Question # 70

Options:

Question 71

Configure IPv4 and IPv6 connectivity between two routers. For IPv4, use a /28 network from the 192.168.1.0/24 private range. For IPv6, use the first /64 subnet from the 2001:0db8:aaaa::/48 subnet.

1. Using Ethernet0/1 on routers R1 and R2, configure the next usable/28 from the 192.168.1.0/24 range. The network 192.168.1.0/28 is unavailable.

2. For the IPv4 /28 subnet, router R1 must be configured with the first usable host address.

3. For the IPv4 /28 subnet, router R2 must be configured with the last usable host address.

4. For the IPv6 /64 subnet, configure the routers with the IP addressing provided from the topology.

5. A ping must work between the routers on the IPv4 and IPv6 address ranges.

Question # 71Question # 71

Options:

Question 72

Physical connectivity is implemented between the two Layer 2 switches, and the network connectivity between them must be configured

1. Configure an LACP EtherChannel and number it as 1; configure it between switches SW1 and SVV2 using interfaces Ethernet0/0 and Ethernet0/1 on both sides. The LACP mode must match on both ends

2 Configure the EtherChannel as a trunk link.

3. Configure the trunk link with 802.1 q tags.

4. Configure the native VLAN of the EtherChannel as VLAN 15.

Question # 72Question # 72

Options:

Question 73

Connectivity between four routers has been established. IP connectivity must be configured in the order presented to complete the implementation. No dynamic routing protocols are included.

1. Configure static routing using host routes to establish connectivity from router R3 to the router R1 Loopback address using the source IP of 209.165.200.230.

2. Configure an IPv4 default route on router R2 destined for router R4.

3. Configure an IPv6 default router on router R2 destined for router R4.

Question # 73Question # 73

Options:

Question 74

Drag and drop the application protocols from the left onto the transport protocols that it uses on the right

Question # 74

Options:

Question 75

What is the primary function of a Layer 3 device?

Options:

A.

to analyze traffic and drop unauthorized traffic from the Internet

B.

to transmit wireless traffic between hosts

C.

to pass traffic between different networks

D.

forward traffic within the same broadcast domain

Question 76

Refer to the exhibit.

Question # 76

The entire contents of the MAC address table are shown. Sales-4 sends a data frame to Sales-1.

Question # 76

What does the switch do as it receives the frame from Sales-4?

Options:

A.

Perform a lookup in the MAC address table and discard the frame due to a missing entry.

B.

Insert the source MAC address and port into the forwarding table and forward the frame to Sales-1.

C.

Map the Layer 2 MAC address to the Layer 3 IP address and forward the frame.

D.

Flood the frame out of all ports except on the port where Sales-1 is connected.

Question 77

How does QoS optimize voice traffic?

Options:

A.

reducing bandwidth usage

B.

by reducing packet loss

C.

by differentiating voice and video traffic

D.

by increasing jitter

Question 78

Refer to Exhibit.

Question # 78

How does SW2 interact with other switches in this VTP domain?

Options:

A.

It processes VTP updates from any VTP clients on the network on its access ports.

B.

It receives updates from all VTP servers and forwards all locally configured VLANs out all trunk ports

C.

It forwards only the VTP advertisements that it receives on its trunk ports.

D.

It transmits and processes VTP updates from any VTP Clients on the network on its trunk ports

Question 79

How does CAPWAP communicate between an access point in local mode and a WLC?

Options:

A.

The access point must directly connect to the WLC using a copper cable

B.

The access point must not be connected to the wired network, as it would create a loop

C.

The access point must be connected to the same switch as the WLC

D.

The access point has the ability to link to any switch in the network, assuming connectivity to the WLC

Question 80

Which statement correctly compares traditional networks and controller-based networks?

Options:

A.

Only traditional networks offer a centralized control plane

B.

Only traditional networks natively support centralized management

C.

Traditional and controller-based networks abstract policies from device configurations

D.

Only controller-based networks decouple the control plane and the data plane

Question 81

Which goal is achieved by the implementation of private IPv4 addressing on a network?

Options:

A.

provides an added level of protection against Internet exposure

B.

provides a reduction in size of the forwarding table on network routers

C.

allows communication across the Internet to other private networks

D.

allows servers and workstations to communicate across public network boundaries

Question 82

What are two characteristics of a public cloud implementation? (Choose two.)

Options:

A.

It is owned and maintained by one party, but it is shared among multiple organizations.

B.

It enables an organization to fully customize how It deploys network resources.

C.

It provides services that are accessed over the Internet.

D.

It Is a data center on the public Internet that maintains cloud services for only one company.

E.

It supports network resources from a centralized third-party provider and privately-owned virtual resources

Question 83

A device detects two stations transmitting frames at the same time. This condition occurs after the first 64 bytes of the frame is received interface counter increments?

Options:

A.

collision

B.

CRC

C.

runt

D.

late collision

Question 84

Which statement about Link Aggregation when implemented on a Cisco Wireless LAN Controller is true?

Options:

A.

To pass client traffic two or more ports must be configured.

B.

The EtherChannel must be configured in " mode active "

C.

When enabled the WLC bandwidth drops to 500 Mbps

D.

One functional physical port is needed to pass client traffic

Question 85

An office has 8 floors with approximately 30-40 users per floor What command must be configured on the router Switched Virtual Interface to use address space efficiently?

Options:

A.

ip address 192.168.0.0 255.255.0.0

B.

ip address 192.168.0.0 255.255.254.0

C.

ip address 192.168.0.0 255.255.255.128

D.

ip address 192.168.0.0 255.255.255.224

Question 86

Refer to the exhibit.

Question # 86

Which action is expected from SW1 when the untagged frame is received on the GigabitEthernet0/1 interface?

Options:

A.

The frame is processed in VLAN 5.

B.

The frame is processed in VLAN 11

C.

The frame is processed in VLAN 1

D.

The frame is dropped

Question 87

Refer to the exhibit.

Question # 87

An engineer is tasked with verifying network configuration parameters on a client workstation to report back to the team lead. Drag and drop the node identifiers from the left onto the network parameters on the right.

Question # 87

Options:

Question 88

Using direct sequence spread spectrum, which three 2.4-GHz channels are used to limit collisions?

Options:

A.

1,6,11

B.

1,5,10

C.

1,2,3

D.

5,6,7

Question 89

Where does wireless authentication happen?

Options:

A.

SSID

B.

radio

C.

band

D.

Layer 2

Question 90

Refer to the exhibit.

Question # 90

A network engineer must block access for all computers on VLAN 20 to the web server via HTTP All other computers must be able to access the web server Which configuration when applied to switch A accomplishes this task?

Question # 90

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 91

A network administrator needs to aggregate 4 ports into a single logical link which must negotiate layer 2 connectivity to ports on another switch. What must be configured when using active mode on both sides of the connection?

Options:

A.

802.1q trunks

B.

Cisco vPC

C.

LLDP

D.

LACP

Question 92

What is a function of TFTP in network operations?

Options:

A.

transfers a backup configuration file from a server to a switch using a username and password

B.

transfers files between file systems on a router

C.

transfers a configuration files from a server to a router on a congested link

D.

transfers IOS images from a server to a router for firmware upgrades

Question 93

A network administrator is asked to configure VLANs 2, 3 and 4 for a new implementation. Some ports must be assigned to the new VLANs with unused remaining. Which action should be taken for the unused ports?

Options:

A.

configure port in the native VLAN

B.

configure ports in a black hole VLAN

C.

configure in a nondefault native VLAN

D.

configure ports as access ports

Question 94

What is the effect when loopback interfaces and the configured router ID are absent during the OSPF Process configuration?

Options:

A.

No router ID is set, and the OSPF protocol does not run.

B.

The highest up/up physical interface IP address is selected as the router ID.

C.

The lowest IP address is incremented by 1 and selected as the router ID.

D.

The router ID 0.0.0.0 is selected and placed in the OSPF process.

Question 95

An engineer configured an OSPF neighbor as a designated router. Which state verifies the designated router is in the proper mode?

Options:

A.

Exchange

B.

2-way

C.

Full

D.

Init

Question 96

What benefit does controller-based networking provide versus traditional networking?

Options:

A.

moves from a two-tier to a three-tier network architecture to provide maximum redundancy

B.

provides an added layer of security to protect from DDoS attacks

C.

allows configuration and monitoring of the network from one centralized port

D.

combines control and data plane functionality on a single device to minimize latency

Question 97

Drag and drop to the characteristics of networking from the left onto the correct networking types on the right.

Question # 97

Options:

Question 98

Which condition must be met before an NMS handles an SNMP trap from an agent?

Options:

A.

The NMS software must be loaded with the MIB associated with the trap.

B.

The NMS must be configured on the same router as the SNMP agent

C.

The NMS must receive a trap and an inform message from the SNMP agent within a configured interval

D.

The NMS must receive the same trap from two different SNMP agents to verify that it is reliable.

Question 99

An engineer is configuring NAT to translate the source subnet of 10.10.0.0/24 to any of three addresses 192.168.30.1, 192.168.3.2, 192.168.3.3 Which configuration should be used?

Question # 99

Question # 99

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 100

Which set of action satisfy the requirement for multifactor authentication?

Options:

A.

The user swipes a key fob, then clicks through an email link

B.

The user enters a user name and password, and then clicks a notification in an authentication app on a mobile device

C.

The user enters a PIN into an RSA token, and then enters the displayed RSA key on a login screen

D.

The user enters a user name and password and then re-enters the credentials on a second screen

Question 101

An engineer observes high usage on the 2.4 GHz channels and lower usage on the 5 GHz channels. What must be configured to allow clients to preferentially use 5 GHz access points?

Options:

A.

Re- Anchor Roamed Clients

B.

11ac MU-MIMO

C.

OEAP Split Tunnel

D.

Client Band Select

Question 102

How do traditional campus device management and Cisco DNA Center device management differ in regards to deployment?

Options:

A.

Cisco DNA Center device management can deploy a network more quickly than traditional campus device management

B.

Traditional campus device management allows a network to scale more quickly than with Cisco DNA Center device management

C.

Cisco DNA Center device management can be implemented at a lower cost than most traditional campus device management options

D.

Traditional campus device management schemes can typically deploy patches and updates more quickly than Cisco DNA Center device management

Question 103

Refer to the exhibit.

Question # 103

Only four switches are participating in the VLAN spanning-tree process.

Branch-1 priority 614440

Branch-2: priority 39082416

Branch-3: priority 0

Branch-4: root primary

Which switch becomes the permanent root bridge for VLAN 5?

Options:

A.

Branch-1

B.

Branch-2

C.

Branch-3

D.

Branch-4

Question 104

Refer to the exhibit.

Question # 104

If R1 receives a packet destined to 172.161.1, to which IP address does it send the packet?

Options:

A.

192.168.12.2

B.

192.168.13.3

C.

192.168.14.4

D.

192.168.15.5

Question 105

What is a characteristic of private IPv4 addressing?

Options:

A.

traverse the Internet when an outbound ACL is applied

B.

issued by IANA in conjunction with an autonomous system number

C.

composed of up to 65.536 available addresses

D.

used without tracking or registration

Question 106

Which two outcomes are predictable behaviors for HSRP? (Choose two)

Options:

A.

The two routers share a virtual IP address that is used as the default gateway for devices on the LAN.

B.

The two routers negotiate one router as the active router and the other as the standby router

C.

Each router has a different IP address both routers act as the default gateway on the LAN, and traffic is load balanced between them.D The two routers synchronize configurations to provide consistent packet forwarding

D.

The two routed share the same IP address, and default gateway traffic is load-balanced between them

Question 107

Refer to the exhibit.

Question # 107

Which command configures a floating static route to provide a backup to the primary link?

Options:

A.

ip route 0.0.0.0 0.0.0.0 209.165.202.131

B.

ip route 209.165.201.0 255.255.255.224 209.165.202.130

C.

ip route 0.0.0.0 0.0.0.0 209.165.200.224

D.

ip route 209.165.200.224 255.255.255.224 209.165.202.129 254

Question 108

R1 has learned route 10.10.10.0/24 via numerous routing protocols. Which route is installed?

Options:

A.

route with the lowest cost

B.

route with the next hop that has the highest IP

C.

route with the shortest prefix length

D.

route with the lowest administrative distance

Question 109

which IPv6 address block forwards packets to a multicast address rather than a unicast address?

Options:

A.

2000::/3

B.

FC00::/7

C.

FE80::/10

D.

FF00::/12

Question 110

Drag and drop the IPv6 address type characteristics from the left to the right.

Question # 110

Options:

Question 111

Which two values or settings must be entered when configuring a new WLAN in the Cisco Wireless LAN Controller GUI? (Choose two)

Options:

A.

management interface settings

B.

QoS settings

C.

Ip address of one or more access points

D.

SSID

E.

Profile name

Question 112

Refer to the exhibit.

Question # 112

Question # 112

A network administrator assumes a task to complete the connectivity between PC A and the File Server. Switch A and Switch B have been partially configured with VLAN 10, 11, 12, and 13. What is the next step in the configuration?

Options:

A.

Add PC A to VLAN 10 and the File Server to VLAN 11 fa VLAN segmentation

B.

Add VLAN 13 to the trunk links on Switch A and Switch B for VLAN propagation

C.

Add a router on a stick between Switch A and Switch B allowing for Inter-VLAN routing.

D.

Add PC A to the same subnet as the Fie Server allowing for intra-VLAN communication.

Question 113

What is a difference between RADIUS and TACACS+?

Options:

A.

RADIUS is most appropriate for dial authentication, but TACACS+ can be used for multiple types of authentication

B.

TACACS+ encrypts only password information and RADIUS encrypts the entire payload

C.

TACACS+ separates authentication and authorization, and RADIUS merges them

D.

RADIUS logs all commands that are entered by the administrator, but TACACS+ logs only start, stop, and interim commands

Question 114

Refer to the exhibit.

Question # 114

Which route type does the routing protocol Code D represent in the output?

Options:

A.

internal BGP route

B.

/24 route of a locally configured IP

C.

statically assigned route

D.

route learned through EIGRP

Question 115

A network administrator must to configure SSH for remote access to router R1 The requirement is to use a public and private key pair to encrypt management traffic to and from the connecting client.

Which configuration, when applied, meets the requirements?

Question # 115

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 116

Refer to the exhibit.

Question # 116

An engineer must configure GigabitEthernet1/1 to accommodate voice and data traffic Which configuration accomplishes this task?

Question # 116

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 117

Refer to the exhibit.

Question # 117

How does router R1 handle traffic to 192.168.10.16?

Options:

A.

It selects the IS-IS route because it has the shortest prefix inclusive of the destination address.

B.

It selects the EIGRP route because it has the lowest administrative distance.

C.

It selects the OSPF route because it has the lowest cost.

D.

It selects the RIP route because it has the longest prefix inclusive of the destination address.

Question 118

What does an SDN controller use as a communication protocol to relay forwarding changes to a southbound API?

Options:

A.

OpenFlow

B.

Java

C.

REST

D.

XML

Question 119

Refer to the exhibit.

Question # 119

An engineer is bringing up a new circuit to the MPLS provider on the Gi0/1 interface of Router1 The new circuit uses eBGP and teams the route to VLAN25 from the BGP path What s the expected behavior for the traffic flow for route 10.10.13.0/25?

Options:

A.

Traffic to 10.10.13.0.25 is load balanced out of multiple interfaces

B.

Route 10.10.13.0/25 is updated in the routing table as being learned from interface Gi0/1.

C.

Traffic to 10.10.13.0/25 is asymmetrical

D.

Route 10.10.13.0/25 learned via the GiO/0 interface remains in the routing table

Question 120

How are the switches in a spine-and-leaf topology interconnected?

Options:

A.

Each leaf switch is connected to one of the spine switches.

B.

Each leaf switch is connected to two spine switches, making a loop.

C.

Each leaf switch is connected to each spine switch.

D.

Each leaf switch is connected to a central leaf switch, then uplinked to a core spine switch.

Question 121

What are two differences between optical-fiber cabling and copper cabling? (Choose two)

Options:

A.

Light is transmitted through the core of the fiber

B.

A BNC connector is used for fiber connections

C.

The glass core component is encased in a cladding

D.

Fiber connects to physical interfaces using Rj-45 connections

E.

The data can pass through the cladding

Question 122

What are two reasons for an engineer to configure a floating static route? (Choose two)

Options:

A.

to automatically route traffic on a secondary path when the primary path goes down

B.

to route traffic differently based on the source IP of the packet

C.

to enable fallback static routing when the dynamic routing protocol fails

D.

to support load balancing via static routing

E.

to control the return path of traffic that is sent from the router

Question 123

When a WPA2-PSK WLAN is configured in the wireless LAN Controller, what is the minimum number of characters that in ASCII format?

Options:

A.

6

B.

8

C.

12

D.

18

Question 124

Which protocol does an access point use to draw power from a connected switch?

Options:

A.

Internet Group Management Protocol

B.

Adaptive Wireless Path Protocol

C.

Cisco Discovery Protocol

D.

Neighbor Discovery Protocol

Question 125

An engineer must configure traffic for a VLAN that is untagged by the switch as it crosses a trunk link. Which command should be used?

Options:

A.

switchport trunk allowed vlan 10

B.

switchport trunk native vlan 10

C.

switchport mode trunk

D.

switchport trunk encapsulation dot1q

Question 126

Drag and drop the TCP or UDP details from the left onto their corresponding protocols on the right.

Question # 126

Options:

Question 127

Drag and drop the IPv6 addresses from the left onto the corresponding address types on the right.

Question # 127

Options:

Question 128

Drag and drop the elements of a security program from the left onto the corresponding descriptions on the right.

Question # 128

Options:

Question 129

Refer to the exhibit.

Question # 129

An engineer is asked to insert the new VLAN into the existing trunk without modifying anything previously configured Which command accomplishes this task?

Options:

A.

switchport trunk allowed vlan 100-104

B.

switchport trunk allowed vlan add 104

C.

switchport trunk allowed vlan all

D.

switchport trunk allowed vlan 104

Question 130

Refer to the exhibit.

Question # 130

An engineer is configuring a new router on the network and applied this configuration. Which additional configuration allows the PC to obtain its IP address from a DHCP server?

Options:

A.

Configure the ip dhcp relay information command under interface Gi0/1.

B.

Configure the ip dhcp smart-relay command globally on the router

C.

Configure the ip helper-address 172.16.2.2 command under interface Gi0/0

D.

Configure the ip address dhcp command under interface Gi0/0

Question 131

Drag and drop the QoS terms from the left onto the descriptions on the right.

Question # 131

Options:

Question 132

An engineer is configuring SSH version 2 exclusively on the R1 router. What is the minimum configuration required to permit remote management using the cryptographic protocol?

Question # 132

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 133

An organization secures its network with multi-factor authentication using an authenticator app on employee smartphone. How is the application secured in the case of a user’s smartphone being lost or stolen?

Options:

A.

The application requires an administrator password to reactivate after a configured Interval.

B.

The application requires the user to enter a PIN before it provides the second factor.

C.

The application challenges a user by requiring an administrator password to reactivate when the smartphone is rebooted.

D.

The application verifies that the user is in a specific location before it provides the second factor.

Question 134

Refer to the exhibit.

Question # 134

A company is configuring a failover plan and must implement the default routes in such a way that a floating static route will assume traffic forwarding when the primary link goes down. Which primary route configuration must be used?

Options:

A.

ip route 0.0.0.0 0.0.0.0 192.168.0.2 GigabitEthernet1/0

B.

ip route 0.0.0.0 0.0.0.0 192.168.0.2 tracked

C.

ip route 0.0.0.0 0.0.0.0 192.168.0.2 floating

D.

ip route 0.0.0.0 0.0.0.0 192.168.0.2

Question 135

An engineer is tasked to configure a switch with port security to ensure devices that forward unicasts multicasts and broadcasts are unable to flood the port The port must be configured to permit only two random MAC addresses at a time Drag and drop the required configuration commands from the left onto the sequence on the right Not all commands are used.

Question # 135

Options:

Question 136

Which WLC management connection type is vulnerable to man-in-the-middle attacks?

Options:

A.

SSH

B.

HTTPS

C.

Telnet

D.

console

Question 137

What is a function of an endpoint on a network?

Options:

A.

forwards traffic between VLANs on a network

B.

connects server and client devices to a network

C.

allows users to record data and transmit to a tile server

D.

provides wireless services to users in a building

Question 138

Drag and drop each characteristic of device-management technologies from the left onto the deployment type on the right.

Question # 138

Options:

Question 139

Which protocol is used for secure remote CLI access?

Options:

A.

HTTPS

B.

HTTP

C.

Telnet

D.

SSH

Question 140

Refer to the exhibit.

Question # 140

Load-balanced traffic is coming in from the WAN destined to a host at 172.16.1.190. Which next-hop is used by the router to forward the request?

Options:

A.

192.168.7.4

B.

192.168.7.7

C.

192.168.7.35

D.

192.168.7.40

Question 141

Refer to the exhibit.

Question # 141

An OSPF neighbor relationship must be configured using these guidelines:

• R1 is only permitted to establish a neighbor with R2

• R1 will never participate in DR elections

• R1 will use a router-id of 10.1.1.1

Which configuration must be used?

A)

Question # 141

B)

Question # 141

C)

Question # 141

D)

Question # 141

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Question 142

Drag and drop the Rapid PVST+ forwarding state actions from the loft to the right. Not all actions are used.

Question # 142

Options:

Question 143

Which two practices are recommended for an acceptable security posture in a network? (Choose two)

Options:

A.

Backup device configurations to encrypted USB drives for secure retrieval

B.

maintain network equipment in a secure location

C.

Use a cryptographic keychain to authenticate to network devices

D.

Place internal email and file servers in a designated DMZ

E.

Disable unused or unnecessary ports, interfaces and services

Question 144

Which QoS traffic handling technique retains excess packets in a queue and reschedules these packets for later transmission when the configured maximum bandwidth has been surpassed?

Options:

A.

weighted random early detection

B.

traffic policing

C.

traffic shaping

D.

traffic prioritization

Question 145

What is a feature of WPA?

Options:

A.

802.1x authentication

B.

preshared key

C.

TKIP/MIC encryption

D.

small Wi-Fi application

Question 146

Refer to the exhibit.

Question # 146

Between which zones do wireless users expect to experience intermittent connectivity?

Options:

A.

between zones 1 and 2

B.

between zones 2 and 5

C.

between zones 3 and 4

D.

between zones 3 and 6

Question 147

Refer to the exhibit.

Question # 147

Which command configures OSPF on the point-to-point link between routers R1 and R2?

Options:

A.

router-id 10.0.0.15

B.

neighbor 10.1.2.0 cost 180

C.

ipospf priority 100

D.

network 10.0.0.0 0.0.0.255 area 0

Question 148

What is an expected outcome when network management automation is deployed?

Options:

A.

A distributed management plane must be used.

B.

Software upgrades are performed from a central controller

C.

Complexity increases when new device configurations are added

D.

Custom applications are needed to configure network devices

Question 149

Refer to the exhibit.

Question # 149

An engineer assumes a configuration task from a peer Router A must establish an OSPF neighbor relationship with neighbor 172.1.1.1 The output displays the status of the adjacency after 2 hours. What is the next step in the configuration process for the routers to establish an adjacency?

Options:

A.

Configure router A to use the same MTU size as router B.

B.

Set the router B OSPF ID to a nonhost address.

C.

Configure a point-to-point link between router A and router B.

D.

Set the router B OSPF ID to the same value as its IP address

Question 150

Question # 150

Refer to the exhibit. Each router must be configured with the last usable IP address in the subnet. Which configuration fulfills this requirement?

Question # 150

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 151

Which action implements physical access control as part of the security program of an organization?

Options:

A.

configuring a password for the console port

B.

backing up syslogs at a remote location

C.

configuring enable passwords on network devices

D.

setting up IP cameras to monitor key infrastructure

Question 152

Which wireless security protocol relies on Perfect Forward Secrecy?

Options:

A.

WPA3

B.

WPA

C.

WEP

D.

WPA2

Question 153

R1 as an NTP server must have:

• NTP authentication enabled

• NTP packets sourced from Interface loopback 0

• NTP stratum 2

• NTP packets only permitted to client IP 209.165.200.225

How should R1 be configured?

A)

Question # 153

B)

Question # 153

C)

Question # 153

D)

Question # 153

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 154

What is the MAC address used with VRRP as a virtual address?

Options:

A.

00-00-0C-07-AD-89

B.

00-00-5E-00-01-0a

C.

00-07-C0-70-AB-01

D.

00-C6-41-93-90-91

Question 155

Refer to the exhibit.

Question # 155

Which two commands must be added to update the configuration of router R1 so that it accepts only encrypted connections? (Choose two )

Options:

A.

username CNAC secret R!41!4319115@

B.

ip ssh version 2

C.

line vty 0 4

D.

crypto key generate rsa 1024

E.

transport input ssh

Question 156

What is the purpose of an SSID?

Options:

A.

It provides network security

B.

It differentiates traffic entering access points

C.

It identities an individual access point on a WLAN

D.

It identifies a WLAN

Question 157

OSPF must be configured between routers R1 and R2. Which OSPF configuration must be applied to router R1 to avoid a DR/BDR election?

Options:

A.

router ospf 1network 192.168.1.1 0.0.0.0 area 0interface e1/1ip address 192.168.1.1 255.255.255.252ip ospf network broadcast

B.

router ospf 1network 192.168.1.1 0.0.0.0 area 0interface e1/1ip address 192.168.1.1 255.255.255.252ip ospf network point-to-point

C.

router ospf 1network 192.168.1.1 0.0.0.0 area 0interface e1/1ip address 192.168.1.1 255.255.255.252ip ospf cost 0

D.

router ospf 1network 192.168.1.1 0.0.0.0 area 0hello interval 15interface e1/1Ip address 192.168.1.1 255.255.255.252

Question 158

Which PoE mode enables powered-device detection and guarantees power when the device is detected?

Options:

A.

dynamic

B.

static

C.

active

D.

auto

Question 159

What is a function performed by a web server?

Options:

A.

provide an application that is transmitted over HTTP

B.

send and retrieve email from client devices

C.

authenticate and authorize a user ' s identity

D.

securely store files for FTP access

Question 160

Which interface mode must be configured to connect the lightweight APs in a centralized architecture?

Options:

A.

WLAN dynamic

B.

management

C.

trunk

D.

access

Question 161

Refer to the exhibit.

Question # 161

A network engineer is in the process of establishing IP connectivity between two sites. Routers R1 and R2 are partially configured with IP addressing. Both routers have the ability to access devices on their respective LANs. Which command set configures the IP connectivity between devices located on both LANs in each site?

Question # 161

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 162

Which type of network attack overwhelms the target server by sending multiple packets to a port until the half-open TCP resources of the target are exhausted?

Options:

A.

SYN flood

B.

reflection

C.

teardrop

D.

amplification

Question 163

Drag and drop the lightweight access point operation modes from the left onto the descriptions on the right

Question # 163

Options:

Question 164

What is a capability of FTP in network management operations?

Options:

A.

encrypts data before sending between data resources

B.

devices are directly connected and use UDP to pass file information

C.

uses separate control and data connections to move files between server and client

D.

offers proprietary support at the session layer when transferring data

Question 165

An engineer configures interface Gi1/0 on the company PE router to connect to an ISP Neighbor Discovery is disabled

Question # 165

Which action is necessary to complete the configuration if the ISP uses third-party network devices?

Options:

A.

Enable LLDP globally

B.

Disable autonegotiation

C.

Disable Cisco Discovery Protocol on the interface

D.

Enable LLDP-MED on the ISP device

Question 166

How does Rapid PVST+ create a fast loop-free network topology?

Options:

A.

lt requires multiple links between core switches

B.

It generates one spanning-tree instance for each VLAN

C.

It maps multiple VLANs into the same spanning-tree instance

D.

It uses multiple active paths between end stations.

Question 167

Which set of 2.4 GHz nonoverlapping wireless channels is standard in the United States?

Options:

A.

channels 2, 7, 9, and 11

B.

channels 1, 6, 11, and 14

C.

channels 2, 7, and 11

D.

channels 1, 6, and 11

Question 168

Which QoS per-hop behavior changes the value of the ToS field in the IPv4 packet header?

Options:

A.

shaping

B.

classification

C.

policing

D.

marking

Question 169

Why does a switch flood a frame to all ports?

Options:

A.

The frame has zero destination MAC addresses.

B.

The source MAC address of the frame is unknown

C.

The source and destination MAC addresses of the frame are the same

D.

The destination MAC address of the frame is unknown.

Question 170

Refer to the exhibit.

Question # 170

What are two conclusions about this configuration? {Choose two.)

Options:

A.

The spanning-tree mode is Rapid PVST+.

B.

This is a root bridge.

C.

The root port is FastEthernet 2/1.

D.

The designated port is FastEthernet 2/1.

E.

The spanning-tree mode is PVST+.

Question 171

Which function is performed by DHCP snooping?

Options:

A.

propagates VLAN information between switches

B.

listens to multicast traffic for packet forwarding

C.

provides DDoS mitigation

D.

rate-limits certain traffic

Question 172

What is the purpose of the ip address dhcp command?

Options:

A.

to configure an Interface as a DHCP server

B.

to configure an interface as a DHCP helper

C.

to configure an interface as a DHCP relay

D.

to configure an interface as a DHCP client

Question 173

What is the collapsed layer in collapsed core architectures?

Options:

A.

core and WAN

B.

access and WAN

C.

distribution and access

D.

core and distribution

Question 174

What is a requirement for nonoverlapping Wi-Fi channels?

Options:

A.

different security settings

B.

discontinuous frequency ranges

C.

different transmission speeds

D.

unique SSIDs

Question 175

Refer to the exhibit.

Question # 175

A network engineer must update the configuration on Switch2 so that it sends LLDP packets every minute and the information sent via LLDP is refreshed every 3 minutes Which configuration must the engineer apply?

A)

Question # 175

B)

Question # 175

C)

Question # 175

D)

Question # 175

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 176

Refer to the exhibit.

Question # 176

Which network prefix was learned via EIGRP?

Options:

A.

172.16.0.0/16

B.

192.168.2.0/24

C.

207.165.200.0/24

D.

192.168.1.0/24

Question 177

Refer to the exhibit.

Question # 177

Which next-hop IP address does Routed use for packets destined to host 10 10.13.158?

Options:

A.

10.10.10.5

B.

10.10.11.2

C.

10.10.12.2

D.

10.10.10.9

Question 178

A network engineer is installing an IPv6-only capable device. The client has requested that the device IP address be reachable only from the internal network. Which type of IPv6 address must the engineer assign?

Options:

A.

unique local address

B.

link-local address

C.

aggregatable global address

D.

IPv4-compatible IPv6 address

Question 179

Refer to the exhibit.

Question # 179

The ntp server 192.168.0.3 command has been configured on router 1 to make it an NTP client of router 2. Which command must be configured on router 2 so that it operates in server-only mode and relies only on its internal clock?

Options:

A.

Router2(config)#ntp passive

B.

Router2(config)#ntp server 172.17.0.1

C.

Router2(config)#ntp master 4

D.

Router2(config)#ntp server 192.168.0.2

Question 180

Refer to the exhibit.

Question # 180

The router has been configured with a supernet to accommodate the requirement for 380 users on a subnet The requirement already considers 30% future growith. Which configuration verifies the IP subnet on router R4?

A)

Question # 180

B)

Question # 180

C)

Question # 180

D)

Question # 180

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 181

Refer to the exhibit.

Question # 181

For security reasons, automatic Neighbor Discovery must be disabled on the R5 Gi0/1 interface. These tasks must be completed:

• Disable all Neighbor Discovery methods on R5 interface GiO/1.

• Permit Neighbor Discovery on R5 interface GiO/2.

• Verify there are no dynamically learned neighbors on R5 interface Gi0/1.

• Display the IP address of R6*s interface Gi0/2.

Which configuration must be used?

Question # 181

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 182

An administrator must use the password complexity not manufacturer-name command to prevent users from adding “cisco” as a password. Which command must be issued before this command?

Options:

A.

Password complexity enable

B.

confreg 0x2142

C.

Login authentication my-auth-list

D.

service password-encryption

Question 183

Refer to the exhibit.

Question # 183

Which two commands when used together create port channel 10? (Choose two.)

Options:

A.

int range g0/0-1channel-group 10 mode active

B.

int range g0/0-1 channel-group 10 mode desirable

C.

int range g0/0-1channel-group 10 mode passive

D.

int range g0/0-1 channel-group 10 mode auto

E.

int range g0/0-1 channel-group 10 mode on

Question 184

Refer to the exhibit.

Question # 184

What is the next hop for traffic entering R1 with a destination of 10.1.2.126?

Options:

A.

10.165.20.126

B.

10.165.20.146

C.

10.165.20.166

D.

10.165.20.226

Question 185

Which characteristic differentiates the concept of authentication from authorization and accounting?

Options:

A.

user-activity logging

B.

service limitations

C.

consumption-based billing

D.

identity verification

Question 186

Refer to the exhibit.

Question # 186

Which command must be issued to enable a floating static default route on router A?

Options:

A.

ip route 0.0.0.0 0.0.0.0 192.168.1.2

B.

ip default-gateway 192.168.2.1

C.

ip route 0.0.0.0 0.0.0.0 192.168.2.1 10

D.

ip route 0.0.0.0 0.0.0.0 192.168.1.2 10

Question 187

Which switch port configuration must be configured when connected to an AP running in FlexConnect mode, and the WLANs use flex local switching?

Options:

A.

access port with one VLAN

B.

trunk port with pruned VLANs

C.

Layer 3 port with an IP addressss

D.

tagged port with MAC Filtering enabled

Question 188

Drag and drop the characteristic from the left onto the IPv6 address type on the right.

Question # 188

Options:

Question 189

What does the term " spirt MAC” refer to in a wirelesss architecture?

Options:

A.

divides data link layer functions between the AP and WLC

B.

combines the management and control functions froin the data-forwarding functions

C.

uses different MAC addressses for 2.4 GHz and 5 GHz bands on the same AP

D.

leverages two APs to handle control and data traffic

Question 190

Why is UDP more suitable than TCP tor applications that require low latency, such as VoIP?

Options:

A.

UDP reliably guarantees delivery of all packets and TCP drops packets under heavy load.

B.

TCP sends an acknowledgment for every packet that is received and UDP operates without acknowledgments.

C.

UDP uses sequencing data for packets to arrive in order, and TCP offers the capability to receive packets in random order.

D.

TCP uses congestion control for efficient packet delivery and UDP uses flow control mechanisms for the delivery of packets.

Question 191

Question # 191

Refer to the exhibit. Which functionalities will this SSID have while being used by wirelesss clients?

Options:

A.

decreases network security against offline dictionary attacks and encourages easy access to the network

B.

increases network security against offline dictionary attacks and discourages time-consuming brute force attacks

C.

increases network security against man in the middle attacks and discourages denial of service attacks

D.

decreases network security against air sniffing attacks and discourages the use of complex passwords

Question 192

What is the main difference between traditional networks and controller-based networking?

Options:

A.

Controller-based networks increase TCO for the company, and traditional networks require less investment.

B.

Controller-based networks provide a framework for Innovation, and traditional networks create efficiency.

C.

Controller-based networks are open for application requests, and traditional networks operate manually.

D.

Controller-based networks are a closed ecosystem, and traditional networks take advantage of programmability.

Question 193

Refer to the exhibit.

Question # 193

What is occurring on this switch?

Options:

A.

A high number of frames smaller than 64 bytes are received.

B.

Frames are dropped after 16 failed transmission attempts.

C.

The internal transmit buffer is overloaded.

D.

An excessive number of frames greater than 1518 bytes are received.

Question 194

What is a similarity between global and unique local IPv6 addressses?

Options:

A.

They are allocated by the same organization.

B.

They are routable on the global internet.

C.

They use the same process for subnetting.

D.

They are part of the multicast IPv6 group type.

Question 195

Question # 195

Refer to the exhibit. HQC needs to use a configuration that:

handles up to 150,000 concurrent connections

minimizes consumption of public IP addresssses

Options:

A.

ip nat pool NATPOOL 209.165.201.1 209.165.201.3 netmask 255.255.255.248  ip nat inside source list HQC pool NATPOOL overload

B.

ip nat pool NATPOOL 209.165.201.1 209.165.201.248 netmask 255.255.255.248  ip nat outside source list HQC pool NATPOOL overload

C.

ip nat pool NATPOOL 209.165.200.225 209.165.200.226 netmask 255.255.255.252  ip nat outside source list HQC pool NATPOOL overload

D.

ip nat pool NATPOOL 209.165.201.1 209.165.201.5 netmask 255.255.255.248  ip nat inside source list HQC interface gigabitEthernet0/0 overload

Question 196

What is the temporary state that switch ports always enter immediately after the boot process when Rapid PVST+ is used?

Options:

A.

discarding

B.

listening

C.

forwarding

D.

learning

Question 197

What is the role of syslog level 7 in network device health monitoring?

Options:

A.

It provides information about error conditions visible on the network device.

B.

It shares normal operational messages froin the network equipment.

C.

It sends outputs from various debug commands on the device.

D.

It warns about emergency conditions on the network appliance.

Question 198

Question # 198

Refer to the exhibit. Which interface does a packet take to reach the destination addresss of 10.10.10.147?

Options:

A.

FastEthemet 0/0

B.

Senal0/0

C.

FastEthemet 0/1

Question 199

How does network automation help reduce network downtime?

Options:

A.

Changes can be implemented in parallel across multiple devices at once, which increases the speed of the change rate.

B.

By using automation platforms with intent-based configuration, all changes are checked for possible outages before being implemented.

C.

Emails can be generated based on when a network admin performs a network change, which increases visibility.

D.

Configuration templates and testing can be built into implementation, which increases the success rate of a network change.

Question 200

An engineer must configure a core router with a floating static default route to the backup router at 10.200.0.2. Which command meets the requirements?

Options:

A.

ip route 0.0.0.0 0.0.0.0 10.200.0.2 1

B.

Ip route 0.0.0.0 0.0.0.0 10.200.0.2 floating

C.

ip route 0.0.0.0 0.0.0.0 10.200.0.2

D.

Ip route 0.0.0.0 0.0.0.0 10.200.0.2 10

Question 201

A network administrator wants the syslog server to filter incoming messages into different files based on their Importance. Which filtering criteria must be used?

Options:

A.

level

B.

message body

C.

process ID

D.

facility

Question 202

Question # 202

Refer to the exhibit. How does router R1 handle traffic to the 172.16.1.4/30 subnet?

Options:

A.

It sends all traffic over the path via 172.16.9.5 using 172.16.4.4 as a backup.

B.

It sends all traffic over the path via 172.16.4.4.

C.

It load-balances traffic over 172.16.9.5 and 172.16.4.4.

D.

It sends all traffic over the path via 10.0.1.100

Question 203

Question # 203

Refer to the exhibit. An administrator is configuring a new WLAN for a wirelesss network that has these requirements:

Dual-band clients that connect to the WLAN must be directed to the 5-GHz spectrum.

Wireless clients on this WLAN must be able to apply VLAN settings from RADIUS attributes.

Which two actions meet these requirements? (Choose two.)

Options:

A.

Enable the Aironet IE option.

B.

Enable the Coverage Hole Detection option.

C.

Set the MFP Client Protection option to Required

D.

Enable the client band select option.

E.

Enable the allow AAA Override option

Question 204

Which interface is used to send traffic to the destination network?

10.249.210.56/25 [90/6144] via G0/15

10.249.210.56/25 [90/45053] via G0/13

10.249.210.56/25 [110/3693] via G0/16

10.249.210.56/25 [110/360] via G0/12

Options:

A.

G0/16

B.

G0/15

C.

G0/13

D.

G0/12

Question 205

Question # 205

Refer to the exhibit. Configurations for the switch and PCs are complete.

Which configuration must be applied so that VLANs 2 and 3 communicate back and forth?

Options:

A.

interface GigabitEthernet0/0 ip addresss 10.10.2.10 255.255.252.0

B.

interface GigabitEthernet0/0.3 encapsulation dot1Q 3 native ip addresss 10.10.2.10 255.255.252.0

C.

interface GigabitEthernet0/0.10 encapsulation dot1Q 3

D.

interface GigabitEthernet0/0.3 encapsulation dot1Q 10 ip addresss 10.10.2.10 255.255.252.0

Question 206

Which default condition must be considered when an encrypted mobility tunnel is used between two Cisco WLCs?

Options:

A.

TCP port 443 and UDP 21 are used.

B.

Control and data traffic encryption are enabled.

C.

The tunnel uses the IPsec protocol for encapsulation.

D.

The tunnel uses the EolP protocol to transmit data traffic.

Question 207

Which IPsec mode encapsulates the entire IP packet?

Options:

A.

tunnel

B.

Q-in-Q

C.

SSL VPN

D.

transport

Question 208

Refer to the exhibit.

Question # 208

A network engineer is configuring a WLAN to connect with the 172.16.10.0/24 network on VLAN 20. The engineer wants to limit the number of devices that connect to the WLAN on the USERWL SSID to 125. Which configuration must the engineer perform on the WLC?

Options:

A.

In the Management Software activation configuration, set the Clients value to 125.

B.

In the Controller IPv6 configuration, set the Throttle value to 125.

C.

In the WLAN configuration, set the Maximum Allowed Clients value to 125.

D.

In the Advanced configuration, set the DTIM value to 125.

Question 209

Which interface is used to send traffic to the destination network?

O 10.76.170 161/26 |110/102] via FO/17

O 10.76.170 161/26[110/27e31] via FO/20

R 10.76.170.161/261120/15] via FO/8

R 10.76.170.161/26 [120/10] via FO/12

Options:

A.

F0/8

B.

FO/20

C.

FO/12

D.

FO/17

Question 210

Question # 210

Refer to the exhibit. How will router R1 handle packets destined to 192.168.64.22?

Options:

A.

It will use the static route to 10.1.1.1.

B.

It will use the route with the highest AD and highest destination IP.

C.

It will route the packets to 10.1.1.2.

D.

It will drop the packets.

Question 211

Which authentication method requires the user to provide a physical attribute to authenticate successfully?

Options:

A.

password

B.

muftifactor

C.

biometric

D.

certificate

Question 212

Refer to the exhibit.

Question # 212

What is the subnet mask for route 172.16.4.0?

Options:

A.

255.255.255.192

B.

255.255.254.0

C.

255.255.240.0

D.

255.255.248.0

Question 213

A network engineer is implementing a corporate SSID for WPA3-Personal security with a PSK. Which encryption cipher must be configured?

Options:

A.

GCMP256

B.

GCMP128

C.

CCMP256

D.

CCMP128

Question 214

What is a characteristic of an SSID in wirelesss networks?

Options:

A.

provides protection against spyware

B.

eliminates network piggybacking

C.

associates a name to a wirelesss network

D.

allows easy file sharing between endpoints

Question 215

Which two QoS tools provide congestion management? (Choose two.)

Options:

A.

PBR

B.

FRTS

C.

PQ

D.

CBWFQ

E.

CAR

Question 216

A new DHCP server has been deployed in a corporate environment with lease time set to eight hours. Which CMD command on a Windows-based device allows the engineer to verify the DHCP lease expiration?

Options:

A.

ipconfig /renew

B.

ipconfig

C.

ipconfig /all

D.

ipconfig /displaydns

Question 217

What is a benefit of a point-to-point leased line?

Options:

A.

flexibility of design

B.

simplicity of configuration

C.

low cost

D.

full-mesh capability

Question 218

Why would a network administrator choose to implement RFC 1918 addresss space?

Options:

A.

to route traffic on the internet

B.

to provide flexibility in the IP network design

C.

to provide overlapping addresss space with another network

D.

to limit the number of hosts on the network

Question 219

Refer to the exhibit.

Question # 219

Which set of commands must be applied to the two switches to configure an LACP Layer 2 EtherChannel?

A)

Question # 219

B)

Question # 219

C)

Question # 219

D)

Question # 219

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 220

Drag and drop the characteristic from the left onto the IPv6 address type on the right.

Question # 220

Options:

Question 221

Which interface condition is occurring in this output?

Question # 221

Options:

A.

duplex mismatch

B.

queueing

C.

bad NIC

D.

broadcast storm

Question 222

Refer to the exhibit.

Question # 222

In which structure does the word " warning " directly reside?

Options:

A.

array

B.

object

C.

Boolean

D.

string

Question 223

What is the difference between an IPv6 link-local addresss and a unique local addresss?

Options:

A.

The scope of an IPv6 link-local addresss is limited to a loopback addresss, and an IPv6 unique local addresss is limited to a directly attached interface.

B.

The scope of an IPv6 link-local addresss can be used throughout a company site or network, but an IPv6 unique local addresss is limited to a loopback addresss.

C.

The scope of an IPv6 link-local addresss is global, but the scope of an IPv6 unique local addresss is limited to a loopback addresss.

D.

The scope of an IPv6 link-local addresss is limited to a directly attached interface, but an IPv6 unique local addresss is used throughout a company site or network.

Question 224

Which feature, when used on a WLC, allows it to bundle its distribution system ports into one 802.3ad group?

Options:

A.

QinQ

B.

ISL

C.

PAgP

D.

LAG

Question 225

Refer to the exhibit.

Question # 225

Of the routes learned with dynamic routing protocols, which has the least preferred metric?

Options:

A.

Local

B.

EIGRP

C.

OSPF

D.

RIP

Question 226

What is a reason why an administrator would choose to implement an automated network management approach?

Options:

A.

Reduce inconsistencies in the network configuration.

B.

Enable " box by box " configuration and deployment.

C.

Decipher simple password policies.

D.

Increase recurrent management costs.

Question 227

A wirelesss access point is needed and must meet these requirements:

• " zero-touch " deployed and managed by a WLC

• process only real-time MAC functionality

• used in a split-MAC architecture. Which access point type must be used?

Options:

A.

autonomous

B.

lightweight

C.

mesh

D.

cloud-based

Question 228

Refer to the exhibit.

Question # 228

Refer to the exhibit. The IPv6 address for the LAN segment on router R1 must be configured using the EUI-64 format. When configured which ipv6 address is produced by the router?

Options:

A.

2001:db8:1a44:41a4:C801:BEFF:FE4A:1

B.

2001:db8:1a44:41a4:C081:BFFF:FE4A:1

C.

2001:db8:1a44:41a4:4562:098F:FE36:1

D.

2001:db8:1a44:41a4:C800:BAFE:FF00:1

Question 229

Drag and drop the characteristic froin the left onto the IPv6 addresss type on the right.

Question # 229

Options:

Question 230

How does MAC learning function?

Options:

A.

Enabled by default on all VLANs and interfaces

B.

Forwards frames to a neighbor port using CDP

C.

Overwrites the known source MAC addresss in the addresss table

D.

Protects against denial of service attacks

Question 231

Which type of hypervisor operates without an underlying OS to host virtual machines?

Options:

A.

Type 1

B.

Type 2

C.

Type 3

D.

Type 12

Question 232

What must be considered before deploying virtual machines?

Options:

A.

location of the virtual machines within the data center environment

B.

whether to leverage VSM to map multiple virtual processors to two or more virtual machines

C.

resource limitations, such as the number of CPU cores and the amount of memory

D.

support for physical peripherals, such as monitors, keyboards, and mice

Question 233

Refer to the exhibit.

Question # 233

The LACP EtherChannel is configured, and the last change is to modify the interfaces on SwitchA to respond to packets received, but not to initiate negotiation. The interface range gigabitethernet0/0-15 command is entered. What must be configured next?

Options:

A.

SwitchA(config-if-range) #channel-group 1 mode desirable

B.

SwitchA(config-if-range) #channel-group 1 mode auto

C.

SwitchA(config-if-range) #channel-group 1 mode active

D.

SwitchA(config-if-range) #channel-group 1 mode passive

Question 234

Refer to the exhibit.

Question # 234

A network engineer configures the CCNA WLAN so that clients must authenticate hourly and to limit the number of simultaneous connections to the WLAN to Which two actions complete this configuration? (Choose two.)

Options:

A.

Enable the Enable Session Timeout option and set the value to 3600.

B.

Set the Maximum Allowed Clients value to 10.

C.

Enable the Client Exclusion option and set the value to 3600.

D.

Enable the Wi-Fi Direct Clients Policy option.

E.

Set the Maximum Allowed Clients Per AP Radio value to 10.

Question 235

Question # 235

SW1 supports connectivity for a lobby conference room and must be secured. The engineer must limit the connectivity from PC1 to the SW1 and SW2 network. The MAC addresses allowed must be Limited to two. Which configuration secures the conference room connectivity?

A)

Question # 235

B)

Question # 235

C)

Question # 235

D)

Question # 235

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 236

What is the role of SNMP in the network?

Options:

A.

to monitor network devices and functions using a TCP underlay that operates on the presentation layer

B.

to collect data directly from network devices using an SSL underlay that operates on the transport layer

C.

to monitor and manage network devices using a UDP underlay that operates on the application layer

D.

to collect telemetry and critical information from network devices using an SSH underlay that operates on the network layer

Question 237

What is the main purpose of SSH management access?

Options:

A.

To support DES 56-bit and 3DES (168-bit) ciphers

B.

To enable secured access to the inbound management interface

C.

To validate management access with username and domain name only

D.

To allow passwords protected with HTTPS encryption to be sent

Question 238

What is represented by the word " switch " within this JSDN schema?

Question # 238

Options:

A.

array

B.

value

C.

key

D.

object

Question 239

Question # 239

Refer to the exhibit. The My_WLAN wirelesss LAN was configured with WPA2 Layer 2 PSK security. Which additional configuration must the administrator perform to allow users to connect to this WKAN on a different subnet called Data?

Options:

A.

Enable Broadcast SSID and select data froin the Interface/Interface Group drop-down list.

B.

Enable Status and select data froin the Interface/Interface Group drop-down list.

C.

Enable Status and set the NAS-ID to data.

D.

Enable Status and enable Broadcast SSID.

Question 240

Drag and drop the AAA features froin the left onto the corresponding AAA security services on the right Not all options are used.

Question # 240

Options:

Question 241

What is a characteristic of private IPv4 addresssing?

Options:

A.

Reduces the forwarding table on network routers

B.

Used on the external interface of a firewall

C.

Used by ISPs when only one IP is needed to connect to the internet

D.

Address space which is isolated froin the internet

Question 242

Which security protocol is appropriate for a WPA3 implementation?

Options:

A.

CCMP

B.

MD5

C.

TKIP

D.

GCMP

Question 243

In which circumstance would a network architect decide to implement a global unicast subnet instead of a unique local unicast subnet?

Options:

A.

when the subnet must be available only within an organization

B.

when the subnet does not need to be routable

C.

when the addressses on the subnet must be equivalent to private IPv4 addressses

D.

when the subnet must be routable over the internet

Question 244

An engineer is configuring en encrypted password for the enable command on a router where the local user database has already been configured. Drag and drop the configuration commands froin the let into the correct sequence on the right. Not all commends are used.

Question # 244

Options:

Question 245

Which security element uses a combination of one-time passwords, a login name, and a personal smartphone?

Options:

A.

software-defined segmentation

B.

multifactor authentication

C.

attribute-based access control

D.

rule-based access control

Question 246

What is the primary purpose of a console port on a Cisco WLC?

Options:

A.

In-band management via an asynchronous transport

B.

out-of-band management via an IP transport

C.

in-band management via an IP transport

D.

out-of-band management via an asynchronous transport

Question 247

Which device separates networks by security domains?

Options:

A.

firewall

B.

access point

C.

intrusion protection system

D.

wireless controller

Question 248

Which function generally performed by a traditional network device is replaced by a software-defined controller?

Options:

A.

encryption and decryption for VPN link processing

B.

building route tables and updating the forwarding table

C.

changing the source or destination address during NAT operations

D.

encapsulation and decapsulation of packets in a data-link frame

Question 249

Refer to the exhibit.

Question # 249

An engineer must configure the interface that connects to PC 1 and secure it in a way that only PC1 is allowed to use the port No VLAN tagging can be used except for a voice VLAN. Which command sequence must be entered to configure the switch?

A)

Question # 249

B)

Question # 249

C)

Question # 249

D)

Question # 249

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 250

Refer to the exhibit

Question # 250

A network engineer started to configure port security on a new switch. These requirements must be met:

* MAC addresses must be learned dynamically

* Log messages must be generated without disabling the interface when unwanted traffic is seen

Which two commands must be configuredd to complete this task " ? (Choose two)

Options:

A.

SW(config-if)=switchport port-security mac-address sticky

B.

SW(config-if)=switchport port-security violation restrict

C.

SW(config-if)sswitchport port-security mac-address 0010.7B84.45E6

D.

SW(config-if)switchport port-security maximum 2

E.

SW(config-if)=switchport port-security violation shutdown

Question 251

Refer to the exhibit.

Question # 251

What is the prefix length for the route that router1 will use to reach host A?

Options:

A.

/25

B.

/27

C.

/28

D.

/29

Question 252

The address block 192 168 32 0/24 must be subnetted into smaller networks The engineer must meet these requirements

• Create 8 new subnets

• Each subnet must accommodate 30 hosts

• Interface VLAN 10 must use the last usable IP in the first new subnet

• A Layer 3 interface is used

Which configuration must be applied to the interface?

A)

Question # 252

B)

Question # 252

C)

Question # 252

D)

Question # 252

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 253

What are two characteristics of a small office / home office connection environment? (Choose two.)

Options:

A.

It requires 10Gb ports on all uplinks.

B.

It supports between 50 and 100 users.

C.

It supports between 1 and 50 users.

D.

It requires a core, distribution, and access layer architecture.

E.

A router port connects to a broadband connection.

Question 254

Drag and drop the DNS commands from the left onto their effects on the right.

Question # 254

Options:

Question 255

What is a specification for SSIDS?

Options:

A.

They are a Cisco proprietary security feature.

B.

They must include one number and one letter.

C.

They define the VLAN on a switch.

D.

They are case sensitive.

Question 256

Which action implements physical access control as part of the security program of an organization??

Options:

A.

backing up syslogs at a remote location

B.

configuring a password for the console port

C.

configuring enable passwords on network devices

D.

setting up IP cameras to monitor key infrastructure

Question 257

Refer to the exhibit.

Question # 257

An engineer is configuring a Layer 3 port-channel interface with LACP. The configuration on the first device is complete, and it is verified that both interfaces have registered the neighbor device in the CDP table. Which task on the neighbor device enables the new port channel to come up without negotiating the channel?

Options:

A.

Change the EtherChannel mode on the neighboring interfaces to auto.

B.

Configure the IP address of the neighboring device.

C.

Bring up the neighboring interfaces using the no shutdown command.

D.

Modify the static EtherChannel configuration of the device to passive mode.

Question 258

A packet from a company s branch office is destined to host 172.31.0.1 at headquarters. The sending router has three possible matches in its routing table for the packet prefixes: 172.31.0.0/16, 172.31.0.0/24, and 172.31.0.0/25. How does the router handle the packet?

Options:

A.

It sends the traffic via prefix 172.31.0.0/16

B.

It sends the traffic via the default gateway 0.0.0.0/0.

C.

It sends the traffic via prefix 172.31.0.0/24

D.

It sends the traffic via prefix 172.31.0.0/25

Question 259

Refer to the exhibit

.

Question # 259

After configuring a new static route on the CPE. the engineer entered this series of commands to verify that the new configuration is operating normally When is the static default route installed into the routing table?

Options:

A.

when 203 0 113.1 is no longer reachable as a next hop B. when the default route learned over external BGP becomes invalid

B.

when a route to 203.0 113 1 is learned via BGP

C.

when the default route over external BGP changes its next hop

Question 260

What is the role of nonoverlapping channels in a wireless environment?

Options:

A.

to reduce interference

B.

to allow for channel bonding

C.

to stabilize the RF environment

D.

to increase bandwidth

Question 261

Refer to the exhibit.

Traffic from R1 to the 10.10.2.0/24 subnet uses 192.168.1.2 as its next hop. An network engineer wants to update the R1 configuration so that traffic with destination 10.10.2.1 passes through router R3, and all other traffic to the 10.10.20/24 subnet passes through r2. Which command must be used?

Question # 261

Options:

A.

ip route 10.10.2.1 255.255.255.255 192.168.1.4 115

B.

ip route 10.10.2.0 255.255.255.0 192.168.1.4 100

C.

ip route 10.10.2.0 255.255.255.0 192.168.1.4 115

D.

ip route 10.10.2.1 255.255.255.255 192.168.1.4 100

Question 262

Question # 262

Refer to the exhibit. What is represented by “R1” and “SW1” within the JSON output?

object

value

Options:

A.

key

B.

array

Question 263

Refer to the exhibit.

Question # 263

A Cisco engineer creates a new WLAN called lantest. Which two actions must be performed so that only high-speed 2.4-GHz clients connect? (Choose two.)

Options:

A.

Enable the Broadcast SSID option

B.

Enable the Status option.

C.

Set the Radio Policy option to 802.11g Only.

D.

Set the Radio Policy option to 802.11a Only.

E.

Set the Interface/Interface Group(G) to an interface other than guest

Question 264

What does the implementation of a first-hop redundancy protocol protect against on a network?

Options:

A.

root-bridge loss

B.

spanning-tree loops

C.

default gateway failure

D.

BGP neighbor flapping

Question 265

Which device segregates a network into separate zones that have their own security policies?

Options:

A.

IPS

B.

firewall

C.

access point

D.

switch

Question 266

Refer to the exhibit.

Question # 266

An engineer is configuring a new Cisco switch NewSW, to replace SW2 The details have been provided

• Switches SW1 and SW2 are third-party devices without support for trunk ports

• The existing connections must be maintained between PC1 PC2 and PC3

• Allow the switch to pass traffic from future VLAN 10. Which configuration must be applied?

A)

Question # 266

B)

Question # 266

C)

Question # 266

D)

Question # 266

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 267

What is the functionality of the Cisco DNA Center?

Options:

A.

data center network policy control

B.

console server that permits secure access to all network devices

C.

IP address pool distribution scheduler

D.

software-defined controller for automation of devices and services

Question 268

An engineer is configuring a switch port that is connected to a VoIP handset. Which command must the engineer configure to enable port security with a manually assigned MAC address of abcd.abcd.abcd on voice VLAN 4?

Options:

A.

switchport port-security mac-address abcd.abcd.abcd

B.

switchport port-security mac-address abed.abed.abed vlan 4

C.

switchport port-security mac-address sticky abcd.abcd.abcd vlan 4

D.

switchport port-security mac-address abcd.abcd.abcd vlan voice

Question 269

Refer to the exhibit.

Question # 269

An administrator received a call from a branch office regarding poor application performance hosted at the headquarters. Ethernet 1 is connected between Router1 and the LAN switch. What identifies the issue?

Options:

A.

The QoS policy is dropping traffic.

B.

There is a duplex mismatch.

C.

The link is over utilized.

D.

The MTU is not set to the default value.

Question 270

What is a purpose of traffic shaping?

Options:

A.

It enables dynamic flow identification.

B.

It enables policy-based routing.

C.

It provide best-effort service.

D.

It limits bandwidth usage.

Question 271

Question # 271

Refer to the exhibit. The router R1 is in the process of being configured. Routers R2 and R3 are configured correctly for the new environment. Which two commands must be configuredd on R1 for PC1 to communicate to all PCs on the 10.10.10.0/24 network? (Choose two.)

Options:

A.

ip route 10.10.10.0 255.255.255.0 192.168.2.3

B.

ip route 10.10.10.10 255.255.255.255 192.168.2.2

C.

ip route 10.10.10.10 255.255.255.255 g0/1

D.

ip route 10.10.10.8 255.255.255.248 g0/1

E.

ip route 10.10.10.0 255.255.255.248 192.168.2.2

Question 272

Under which condition is TCP preferred over UDP?

Options:

A.

UDP is used when low latency is optimal, and TCP is used when latency is tolerable.

B.

TCP is used when dropped data is more acceptable, and UDP is used when data is accepted out- of-order.

C.

TCP is used when data reliability is critical, and UDP is used when missing packets are acceptable.

D.

UDP is used when data is highly interactive, and TCP is used when data is time-sensitive.

Question 273

Refer to the exhibit.

Question # 273

A network engineer started to configure two directly-connected routers as shown. Which command sequence must the engineer configure on R2 so that the two routers become OSPF neighbors?

A)

Question # 273

B)

Question # 273

C)

Question # 273

D)

Question # 273

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 274

Refer to the exhibit.

Question # 274

Drag and drop the learned prefixes from the left onto the subnet masks on the right

Question # 274

Options:

Question 275

Which interface enables communication between a program on the controller and a program on the networking devices?

Options:

A.

northbound interface

B.

software virtual interface

C.

southbound interface

D.

tunnel Interface

Question 276

Which cipher is supported for wireless encryption only with the WPA2 standard?

Options:

A.

AES256

B.

AES

C.

RC4

D.

SHA

Question 277

Which IP header field is changed by a Cisco device when QoS marking is enabled?

Options:

A.

Header Checksum

B.

Type of service

C.

DSCP

D.

ECN

Question 278

Refer to the exhibit.

Question # 278

A)

Question # 278

B)

Question # 278

C)

Question # 278

D)

Question # 278

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 279

Refer to the exhibit.

Question # 279

The network engineer is configuring router R2 as a replacement router on the network After the initial configuration is applied it is determined that R2 failed to show R1 as a neighbor Which configuration must be applied to R2 to complete the OSPF configuration and enable it to establish the neighbor relationship with R1?

A)

Question # 279

B)

Question # 279

C)

Question # 279

D)

Question # 279

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Question 280

Drag and drop the WLAN components from the left onto the component details on the right.

Question # 280

Options:

Question 281

Which channel-group mode must be configuredd when multiple distribution interfaces connected to a WLC are bundled?

Options:

A.

Channel-group mode passive.

B.

Channel-group mode on.

C.

Channel-group mode desirable.

D.

Channel-group mode active.

Question 282

Refer to the exhibit.

Question # 282

Drag and drop the destination IPs from the left onto the paths to reach those destinations on the right.

Question # 282

Options:

Question 283

Which property is shared by 10GBase-SR and 10GBase-LR interfaces?

Options:

A.

Both require fiber cable media for transmission.

B.

Both require UTP cable media for transmission.

C.

Both use the single-mode fiber type.

D.

Both use the multimode fiber type.

Question 284

Refer to the exhibit.

Question # 284

The Router1 routing table has multiple methods to reach 10.10.10.0/24 as shown. The default Administrative Distance is used. Drag and drop the network conditions from the left onto the routing methods that Router1 uses on the right.

Question # 284

Options:

Question 285

What is the put method within HTTP?

Options:

A.

It is a read-only operation.

B.

It is a nonldempotent operation.

C.

It replaces data at the destination.

D.

It displays a web site.

Question 286

Refer to the exhibit.

Question # 286

R1 has just received a packet from host A that is destined to host B. Which route in the routing table is used by R1 to reach host B?

Options:

A.

10.10.13.0/25 [108/0] via 10.10.10.10

B.

10.10.13.0/25 [110/2] via 10.10.10.2

C.

10.10.13.0/25 [110/2] via 10.10.10.6

D.

10.10.13.0/25 [1/0] via 10.10.10.2

Question 287

Which Cisco proprietary protocol ensures traffic recovers immediately, transparently, and automatically when edge devices or access circuits fail?

Options:

A.

SLB

B.

FHRP

C.

VRRP

D.

HSRP

Question 288

What is a characteristic of a collapsed-core network topology?

Options:

A.

It allows the core and distribution layers to run as a single combined layer.

B.

It enables the core and access layers to connect to one logical distribution device over an EtherChannel.

C.

It enables all workstations in a SOHO environment to connect on a single switch with internet access.

D.

It allows wireless devices to connect directly to the core layer, which enables faster data transmission.

Question 289

Drag and drop the statements about networking from the left onto the corresponding networking types on the right

Question # 289

Options:

Question 290

Which enhancement is implemented in WPA3?

Options:

A.

applies 802.1x authentication

B.

uses TKIP

C.

employs PKI to identify access points

D.

protects against brute force attacks

Question 291

A network engineer is upgrading a small data center to host several new applications, including server backups that are expected to account for up to 90% of the bandwidth during peak times. The data center connects to the MPLS network provider via a primary circuit and a secondary circuit. How does the engineer inexpensively update the data center to avoid saturation of the primary circuit by traffic associated with the backups?

Options:

A.

Assign traffic from the backup servers to a dedicated switch.

B.

configure a dedicated circuit for the backup traffic.

C.

Place the backup servers in a dedicated VLAN.

D.

Advertise a more specific route for the backup traffic via the secondary circuit.

Question 292

Refer to the exhibit.

Question # 292

An engineer is updating the management access configuration of switch SW1 to allow secured, encrypted remote configuration. Which two commands or command sequences must the engineer apply to the switch? (Choose two.)

Options:

A.

SW1(config)#enable secret ccnaTest123

B.

SW1(config)#username NEW secret R3mote123

C.

SW1(config)#line vty 0 15 SW1(config-line)#transport input ssh

D.

SW1(config)# crypto key generate rsa

E.

SW1(config)# interface f0/1 SW1(config-if)# switchport mode trunk

Question 293

PC1 tries to send traffic to newly installed PC2. The PC2 MAC address is not listed in the MAC address table of the switch, so the switch sends the packet to all ports in the same VLAN Which switching concept does this describe?

Options:

A.

MAC address aging

B.

MAC address table

C.

frame flooding

D.

spanning-tree protocol

Question 294

Which WPA mode uses PSK authentication?

Options:

A.

Local

B.

Client

C.

Enterprise

D.

Personal

Question 295

Which two IPv6 addresses are used to provide connectivity between two routers on a shared link? (Choose two)

Options:

A.

::ffff:1014:1011/96

B.

2001:701:1046:1111::1/64

C.

;jff06bb43cd4dd111bbff02 4545234d

D.

2002:5121:204b:1111::1/64

E.

FF02::0WlFF00:0l)00/104

Question 296

Which encryption method is used by WPA3?

Options:

A.

PSK

B.

TKIP

C.

SAE

D.

AES

Question 297

What is the purpose of configuring different levels of syslog for different devices on the network?

Options:

A.

to rate-limit messages for different severity levels from each device

B.

to set the severity of syslog messages from each device

C.

to identify the source from which each syslog message originated

D.

to control the number of syslog messages from different devices that are stored locally

Question 298

Refer to the exhibit.

Question # 298

The loopback1 interface of the Atlanta router must reach the loopback3 interface of the Washington router.

Options:

A.

ipv6 route 2000::1/128 2012::2

B.

ipv6 route 2000::1/128 2012::1

C.

ipv6 route 2000:3 123 s0/0/0

D.

ipv6 route 2000::3/128 2023::3

E.

ipv6 route 2000::1/128 s0/0/1

Question 299

Which advantage does the network assurance capability of Cisco DNA Center provide over traditional campus management?

Options:

A.

Cisco DNA Center correlates information from different management protocols to obtain insights, and traditional campus management requires manual analysis.

B.

Cisco DNA Center handles management tasks at the controller to reduce the load on infrastructure devices, and traditional campus management uses the data backbone.

C.

Cisco DNA Center leverages YANG and NETCONF to assess the status of fabric and nonfabric devices, and traditional campus management uses CLI exclusively.

D.

Cisco DNA Center automatically compares security postures among network devices, and traditional campus management needs manual comparisons.

Question 300

Drag and drop the characteristics of northbound APIs from the left onto any position on the right. Not all characteristics are used.

Question # 300

Options:

Question 301

What are two reasons a switch experiences frame flooding? (Choose two.)

Options:

A.

A defective patch cable is connected to the switch port

B.

Topology changes are occurring within spanning-tree

C.

An aged MAC table entry is causing excessive updates

D.

Port-security is configured globally

E.

The forwarding table has overflowed

Question 302

Refer to the exhibit.

Question # 302

Clients on the WLAN are required to use 802.11r. What action must be taken to meet the requirement?

Options:

A.

Under Protected Management Frames, set the PMF option to Required.

B.

Enable CCKM under Authentication Key Management.

C.

Set the Fast Transition option and the WPA gtk-randomize State to disable.

D.

Set the Fast Transition option to Enable and enable FT 802.1X under Authentication Key Management.

Question 303

What is the primary purpose of private address space?

Options:

A.

conserve globally unique address space

B.

simplify the addressing in the network

C.

limit the number of nodes reachable via the Internet

D.

reduce network complexity

Question 304

Which cable type must be used to interconnect one switch using 1000 BASE-SX GBIC modules and another switch using 1000 BASE-SX SFP modules?

Options:

A.

LC to SC

B.

SC t ST

C.

SC to SC

D.

LC to LC

Question 305

Refer to the exhibit.

Question # 305

A network engineer executes the show ip route command on router D. What is the next hop to network 192.168.1.0/24 and why?

Options:

A.

The next hop is 10.0.2.1 because it uses distance vector routing

B.

The next hop is 10.0.2.1 because it is a link-state routing protocol

C.

The next hop is 10.0.0.1 because it has a better administrative distance

D.

The next hop is 10.0.0.1 because it has a higher metric.

Question 306

Refer to the exhibit.

Question # 306

An engineer must configure a floating static route on an external EIGRP network. The destination subnet is the /29 on the LAN Interface of R86. Which command must be executed on R14?

Options:

A.

ip route 10.80.65.0.255.255.248.0.10.73.65.66.1

B.

ip route 10.80.65.0.255.255.255..240 fa0/1 89

C.

ip route 10.80.65.0.255.255.248.0.10.73.65.66.171

D.

ip route 10.80.65.0.0.0.224.10.80.65.0. 255

Question 307

Which protocol is used in Software Defined Access (SDA) to provide a tunnel between two edge nodes in different fabrics?

Options:

A.

Generic Router Encapsulation (GRE)

B.

Virtual Local Area Network (VLAN)

C.

Virtual Extensible LAN (VXLAN)

D.

Point-to-Point Protocol

Question 308

Drag and drop the steps in a standard DNS lookup operation from the left into the order on the right.

Question # 308

Options:

Question 309

Why implement VRRP?

Options:

A.

to provide end users with a virtual gateway in a multivendor network

B.

to leverage a weighting scheme to provide uninterrupted service

C.

to detect link failures without the overhead of Bidirectional Forwarding Detection

D.

to hand over to end users the autodiscovery of virtual gateways

Question 310

What is used as a solution for protecting an individual network endpoint from attack?

Options:

A.

Router

B.

Wireless controller

C.

anti-malware software

D.

Cisco DNA Center

Page: 1 / 124
Total 1240 questions