Valentine Day Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Cisco 300-410 Implementing Cisco Enterprise Advanced Routing and Services (ENARSI) Exam Practice Test

Page: 1 / 56
Total 563 questions

Implementing Cisco Enterprise Advanced Routing and Services (ENARSI) Questions and Answers

Question 1

Refer to the exhibit.

Question # 1

Which set of commands restore reachability to loopback0?

A)

Question # 1

B)

Question # 1

C)

Question # 1

D)

Question # 1

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 2

Question # 2

Question # 2

Refer to the exhibit. An engineer applied filter on R1 The interface flapped between R1 and R2 and cleaning the BGP session did not restore the BGP session and failed Which action must the engineer take to restore the BGP session from R2 to R1?

Options:

A.

Apply the IPv6 traffic filter in the outbound direction on the interface

B.

ICMPv6 must be permitted by the IPv6 traffic filter

C.

Enable the BGP session, which went down when the session was cleared.

D.

Swap the source and destination IP addresses in the IPv6 traffic filter

Question 3

An engineer configured a router with this configuration

ip access-hst DENY TELNET

10 deny tcp any any eq 23 log-input

The router console starts receiving log message :%SEC-6-IPACCESSLOGP: list DENY_TELNET denied tcp 192.168.1.10(1022)(FastEthernet1/0 D508.89gb.003f) ->192.168.2.20(23), 1 packet"

Which action stops messages on the console while still denying Telnet?

Options:

A.

Configure a 20 permit ip any any command

B.

Remove log-Input keyword from the access list.

C.

Replace log-input keyword with the log keyword in the access list.

D.

Configure a 20 permit ip any any log-input command.

Question 4

Refer to the exhibit.

Question # 4

The Customer Edge router (AS 65500) wants to use ASC100 as the preferred ISP for all external routes.

Question # 4

This configuration failed to send routes to AS 100 as the preferred path. Which set of configuration resolves the issue?

Question # 4

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 5

What is a function of IPv6 Source Guard?

Options:

A.

It works with address glean or ND to find existing addresses.

B.

It inspects ND and DHCP packets to build an address binding table.

C.

It denies traffic from known sources and allocated addresses.

D.

It notifies the ND protocol to inform hosts if the traffic is denied by it.

Question 6

Refer to the exhibit.

Question # 6

Router R2 should be learning the route for 10.123.187.0/24 via EIGRP. Which action resolves the issue without introducing more issues?

Options:

A.

Use distribute-list to modify the route as an internal EIGRP route

B.

Redistribute the route in EIGRP with metric, delay, and reliability

C.

Use distribute-list to filter the external router in OSPF

D.

Remove route redistribution in R2 for this route in OSPF

Question 7

Refer to the exhibit.

Question # 7

The branch router is configured with a default route toward the internet and has no routes configured for the HQ site that is connected through interface G2/0. The HQ router is fully configured and does not require changes. Which configuration on the branch router makes the intranet website (TCP port 80) available to the branch office users?

A)

Question # 7

B)

Question # 7

C)

Question # 7

D)

Question # 7

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 8

A network administrator cannot connect to a device via SSH. The line vty configuration is as follows:

Question # 8

Which action resolves this issue?

Options:

A.

Increase the session timeout

B.

Change the stopbits to 10.

C.

Configure the transport input SSH

D.

initialize the SSH key

Question 9

Refer to the exhibit.

Question # 9

Although summarization is configured for R1 to receive 10.0.0.0/8. more specific routes are received by R1. How should the 10.0.0.0/8 summary route be received from the neighbor, attached to R1 via Fast Ethernet0/0 interface?

Options:

A.

R1 should configure the ip summary-address eigrp 10.0.0.0.255.0.0.0 command under the Fast Ethernet 0/0 interface.

B.

The summarization condition is not met Router 10 1 100.10 requires a route for 10 0.0.0/8 that points to null 0

C.

The summarization condition is not met. The network 10.1.100.0/24 should be changed to 172.16.0.0/24.

D.

R1 should configure the ip summary-address eigrp 10.0.0.0 0.0.0.255 command under the Fast Ethernet 0/0 interface.

Question 10

Refer to the exhibit.

Question # 10

The none area 0 routers in OSPF still receive more specific routes of 10.1.1.0.10.1.2.0.10.1.3.0 from area 0. Which action resolves the issue?

Options:

A.

Configure route summarization on OSPF-enabled interfaces.

B.

Summarize by using the summary-address 10.1.0.0 255.255.252.0 command.

C.

Summarize by using the area range command on ABRs

D.

Configure the summary-address 10.1.0.0 255.255.252.0 command under OSPF process.

Question 11

Refer to the exhibit.

Question # 11

R1 is configured with IP SLA to check the availability of the server behind R6 but it kept failing. Which configuration resolves the issue?

Options:

A.

R6(config)# ip sla responder

B.

R6(config)# ip sla responder udp-echo ip address 10.10.10.1 port 5000

C.

R6(config)# ip access-list extended DDOS

R6(config ext-nac)# 5 permit icmp host 10.66 66.66 host 10.10.10.1

D.

R6(config)# ip access-list extended DDOS

R6(confg ext-nac)# 5 permit icmp host 10.10.10.1 host 10.66.66.66

Question 12

Refer to the exhibit.

Question # 12

The connected routers do not show up as OSPF neighbors. Which action resolves the issue?

Options:

A.

Change the R1 dead timer to 20.

B.

Change the R2 dead timer to 20.

C.

Change the R2 hello timer to 20.

D.

Change the R1 hello timer to 20.

Question 13

Question # 13

Question # 13

Refer to the exhibit. The administrator is troubleshooting a BGP peering between PE1 and PE3 that is unable to establish Which action resolves the issue?

Options:

A.

P2 must have a route to PE3 to establish a BGP session to PE1

B.

Disable sending ICMP unreachables on P2 to allow PE1 to establish a session with PE3

C.

Ensure that the PE3 loopback address is used as a source for BGP peering to PE1

D.

Remove the traffic filtering rules on P2 blocking the BGP communication between PE1 and PE3

Question 14

A customer reports that traffic is not passing on an EIGRP enabled multipoint interface on a router configured as below:

interface Serial0/0

no ip address

interface Server0/0/0.9 multipoint

ip address 10.1.1.1 255.255.255.248

ip split-horizon eigrp 1

Which action resolves the issue?

Options:

A.

Enable poison reverse

B.

Enable split horizon

C.

Disable poison reverse

D.

Disable split horizon

Question 15

Refer to the exhibit.

Question # 15

Question # 15

An OSPF neighbor relationship between R2 and R3 is showing stuck in EXCHANGE/EXSTART state. The neighbor is established between R1 and R2. The network engineer can ping from R2 to R3 and vice versa, but the

neighbor is still down. Which action resolves the issue?

Options:

A.

Restore the Layer 2/Layer 3 conectivity issue in the ISP network.

B.

Match MTU on both router interfaces or ignore MTU.

C.

Administrative "shut then no shut" both router interfaces.

D.

Enable OSPF on the interface, which is required.

Question 16

Which IPv6 feature enables a device to reject traffic when it is originated from an address that is not stored in the device binding table?

Options:

A.

IPv6 Snooping

B.

IPv6 Source Guard

C.

IPv6 DAD Proxy

D.

IPv6 RA Guard

Question 17

Question # 17

Refer lo lhe exhibit. The Customer Edge rouler wants to use AS 100 as the preferred ISP for all external routes and ISP-2 as a backup.

Question # 17

After this configuration, all the backup routes have disappeared from the BGP table on the Customer Edge router. Which set of configurations resolves the issue on the Customer Edge router?

A)

Question # 17

B)

Question # 17

C)

Question # 17

D)

Question # 17

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 18

Question # 18

Refer to lhe exhibit An engineer must filter EIGRP updates that are received to block all 10 10 10.0/24 prefixes The engineer tests the distribute list and finds one associated prefix. Which action resolves the issue?

Options:

A.

There is a permit in the route map that allows this prefix A deny 20 statement is required with a match condition to match a new ACL that denies all prefixes

B.

There is a permit in the ACL that allows this prefix into EI6RP. The ACL should be modified to deny 10.10.10.0 0.0.0.255.

C.

There is a permit in the route map that allows this prefix A deny 20 statement is required with no match condition to block the prefix.

D.

There is a permit in the ACL that allows this prefix into EIGRP. The ACL should be modified to deny 10.10.10.0 255.255.255.0.

Question 19

Exhibit.

Question # 19

Question # 19

Refer to the exhibit. A network is configured for EIGRP equal-cost load balancing, but the traffic destined to the servers is not load balanced. Link metrics from router R2 to R3 and R4 are the same. Which delay value must be configured to resolve the issue?

Options:

A.

208 oon R3 E0/0

B.

120 on R4 E0/1

C.

120/on R3 E0/1

D.

2200 on R4 E0/1

Question 20

How do devices operate in MPLS L3VPN topology?

Options:

A.

P and associated PE routers with IGP populate the VRF table in different VPNs.

B.

CE routers connect to the provider network and perform LSP functionality

C.

P routers provide connectivity between PE devices with MPLS switching.

D.

P routers support PE to PE VPN tunnel without LSP functionality

Question 21

An engineer configured VRF-Lite on a router for VRF blue and VRF red. OSPF must be enabled on each VRF to peer to a directly connected router in each VRF. Which configuration forms OSPF neighbors over the network 10.10.10.0/28 for VRF blue and 192.168.0.0/30 for VRF red?

Question # 21

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 22

Which two solutions are used to overcome a flapping link that causes a frequent label binding

exchange between MPLS routers? (Choose two)

Options:

A.

Create link dampening on links to protect the session.

B.

Increase input queue on links to protect the session.

C.

Create targeted hellos to protect the session.

D.

Increase a hold-timer to protect the session.

E.

Increase a session delay to protect the session.

Question 23

Refer to the exhibit.

Question # 23

Users in VLAN46 cannot get the IP from the DHCP server. Assume that all the parameters are configured properly in VLAN 10 and on the DHCP server Which command on interlace VLAN46 allows users to receive IP from the DHCP server?

Options:

A.

ip dhcp-addreos 10.221.10.10

B.

ip dhcp server 10.221.10.10

C.

ip helper-addrets 10.221.10.10

D.

ip dhcp relay information trust-all

Question 24

Refer to the exhibit.

Question # 24

After configuring OSPF in R1, some external destinations in the network became unreachable. Which action resolves the issue?

Options:

A.

Clear the OSPF process on R1 to flush stale LSAs sent by other routers.

B.

Change the R1 router ID from 10.255.255.1 to a unique value and clear the process.

C.

Increase the SPF delay interval on R1 to synchronize routes.

D.

Disconnect the router with the OSPF router ID 0.0.0.0 from the network.

Question 25

Refer to the exhibit.

Question # 25

An engineer must configure OSPF with R9 and R10 and configure redistribution between OSPF and RIP causing a routing loop Which configuration on R9 and R10 meets this objective?

A)

Question # 25

B)

Question # 25

C)

Question # 25

D)

Question # 25

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Question 26

A network administrator performed a Compact Flash Memory upgrade on a Cisco Catalyst 6509 Switch. Everything is functioning normally except SNMP, which was configured to monitor the bandwidth of key interfaces but the interface indexes are changed. Which global configuration resolves the issue?

Options:

A.

snmp-server ifindex permanent

B.

snmp ifindex permanent

C.

snmp-server ifindex persist

D.

snmp ifindex persist

Question 27

Question # 27

Refer to the exhibit. R1 uses SP1 as the primary path. A network engineer must force all SSH traffic generated from R1 toward SP2. Which configuration accomplishes the task?

A)

Question # 27

B)

Question # 27

C)

Question # 27

D)

Question # 27

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Question 28

IPv6 is enabled in the infrastructure to support customers with an IPv6 network over WAN and to connect the head office to branch offices in the local network. One of the customers is already running IPv6 and wants to enable IPv6 over the DMVPN network infrastructure between the headend and branch sites. Which configuration command must be applied to establish an mGRE IPv6 tunnel neighborship?

Options:

A.

tunnel protection mode ipv6

B.

ipv6 unicast-routing

C.

ipv6 nhrp holdtime 30

D.

tunnel mode gre multipoint ipv6

Question 29

Question # 29

Refer to the exhibit The route to 192 168 200 0 is flapping between R1 and R2 Which set of configuration changes resolves the flapping route?

Question # 29

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 30

Question # 30

Refer to the exhibit. The default route is not advertised to the neighboring router. Which action resolves the issue?

Options:

A.

Configure the redistribute static metric 200 subnets command under OSPF.

B.

Configure OSPF on the Dialer0 interface.

C.

Configure the network 0.0.0.0 255.255.255.255 area 0 command under OSPF.

D.

Configure the default-information originate command under OSPF.

Question 31

Question # 31

Refer to the exhibit A network engineer is troubleshooting an AAA authentication issue for R1 from R2 When an engineer tries to open a telnet connection to R1 it opens the connection but shows a %Authorization failed error message on the terminal and closes the connection silently Which action resolves the issue?

Options:

A.

Resolve tacacs+ server host IP authentication miss configuration on the R1 router

B.

Resolve tacacs+ server reachability from the R1 router.

C.

Configure the tacacs+ server host IP on the R1 router

D.

Configure authorization commands in the tacacs* server for the R1 router.

Question 32

Question # 32

Refer to the exhibit An engineer is troubleshooting an OSPF adjacency issue between directly connected routers R1 and R2 Which configuration resolves the issue?

A)

Question # 32

B)

Question # 32

C)

Question # 32

D)

Question # 32

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 33

Question # 33

Refer to the exhibit. R1 must advertise all loopback interfaces IP addresses to neighbors, but EIGRP neighbors receive a summary route. Which action resolves the issue?

Options:

A.

Redistribute connected routes into EIGRP Enable

B.

EIGRP on loopback Interfaces.

C.

Disable auto summarization on R1.

D.

Remove the 10.100.1.0/24 static route.

Question 34

Question # 34

Options:

A.

access-list 20 permit 10.221.10.12

B.

snmp-server group NETVIEW v2c priv read NETVIEW access 20

C.

snmp-server group NETADMIN v3 priv read NETVIEW write NETADMIN access 22

D.

access-list 20 permit 10.221.10.11

Question 35

Which control plane process allows the MPLS forwarding state to recover when a secondary RP takes over from a failed primary RP?

Options:

A.

MP-BGP uses control plane services for label prefix bindings in the MPLS forwarding table

B.

LSP uses NSF to recover from disruption *i control plane service

C.

FEC uses a control plane service to distribute information between primary and secondary processors

D.

LDP uses SSO to recover from disruption in control plane service

Question 36

Refer to the exhibit.

Question # 36

Which configuration enables OSPF for area 0 interfaces to adjacency with a neighboring router with the same VRF?

Options:

A.

router ospf 1 vrf CCNP

interface Ethernet1

ip ospf 1 area 0.0.0.0

interface Ethernet2

ip ospf 1 area 0.0.0.0

B.

router ospf 1

interface Ethernet1

ip ospf 1 area 0.0.0.0

interface Ethernet2

ip ospf 1 area 0.0.0.0

C.

router ospf 1 vrf CCNP

network 10.1.1.1 0.0.0.0 area 0

network 10.2.2.2 0.0.0.0 area 0

D.

router ospf 1 vrf CCNP

network 10.0.0.0 0.0.255.255 area 0

Question 37

Question # 37

Refer to the exhibit. An engineer configured SNMP traps to record spoofed packets drop of more than 48000 a minute on the ethernet0/0 interlace. During an IP spoofing attack, the engineer noticed that no notifications have been received by the SNMP server. Which configuration resolves the issue on R1?

Options:

A.

ip verity unicast notification threshold 48000

B.

ip verify unicast notification threshold 8000

C.

ip verify unicast notification threshold 800

D.

ip verify unicast notification threshold 80

Question 38

What is a characteristic of Layer 3 MPLS VPNs?

Options:

A.

LSP signaling requires the use of unnumbered IP links for traffic engineering.

B.

Traffic engineering supports multiple IGP instances

C.

Traffic engineering capabilities provide QoS and SLAs.

D.

Authentication is performed by using digital certificates or preshared keys.

Question 39

Question # 39

Question # 39

Refer to the exhibit. An administrator must harden a router, but the administrator failed to test the SSH access successfully to the router. Which action resolves the issue?

Options:

A.

Configure SSH on the remote device to log m using SSH

B.

SSH syntax must be ssh -I user ip to log in to the remote device

C.

Configure enable secret to log in to the device

D.

SSH must be allowed with the transport output ssh command

Question 40

Refer to the exhibit.

Question # 40

An engineer is trying to add an encrypted user password that should not be visible in the router configuration. Which two configuration commands resolve the issue? (Choose two)

Options:

A.

password encryption aes

B.

username Admin password Cisco@maedeh motamedi

C.

username Admin password 5 Cisco@maedeh motamedi

D.

username Admin secret Cisco@maedeh motamedi

E.

no service password-encryption

F.

service password-encryption

Question 41

A network administrator must optimize the segment size of the TCP packet on the DMVPN IPsec protected tunnel interface, which carries application traffic from the head office to a designated branch. The TCP segment size must not overwhelm the MTU of the outbound link. Which configuration must be applied to the router to improve the application performance?

Question # 41

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 42

Question # 42

Refer to the exhibit. An engineer is investigating an OSPF issue reported by the Cisco DNA Assurance Center. Which action resolves the issue?

Options:

A.

One of the neighbor links is down Bring the interface up by running shut and no shut

B.

One of the interfaces is using the wrong MTU Match interface MTU on both links

C.

An ACL entry blocking multicast on the interfaces Allow multicast through the interface ACL

D.

One of the interfaces is using the wrong authentication Match interface authentication on both links

Question 43

How does an MPLS Layer 3 VPN differentiate the IP address space used between each VPN?

Options:

A.

by RD

B.

by address family

C.

by MP-BGP

D.

byRT

Question 44

An engineer failed to run diagnostic commands on devices using Cisco DNA Center. Which action in Cisco DNA Center resolves the issue?

Options:

A.

Enable Command Runner

B.

Enable APIs

C.

Enable CDP

D.

Enable Secure Shell

Question 45

A customer requested a GRE tunnel through the provider network between two customer sites using loopback to hide internal networks. Which configuration on R2 establishes the tunnel with R1?

Options:

A.

R2(config)# interface Tunnel 1

R2(config-if)# ip address 172.20.1.2 255.255.255.0

R2(config-if)# ip mtu 1400

R2(config-if)# ip tcp adjust-mss 1360

R2(config-if)# tunnel source 192.168.20.1

R2(config-if)# tunnel destination 192.168.10.1

B.

R2(config)# interface Tunnel 1

R2(config-if)# ip address 172.20.1.2 255.255.255.0

R2(config-if)# ip mtu 1400

R2(config-if)# ip tcp adjust-mss 1360

R2(config-if)# tunnel source 10.10.2.2

R2(config-if)# tunnel destination 10.10.1.1

C.

R2(config)# interface Tunnel 1

R2(config-if)# ip address 172.20.1.2 255.255.255.0

R2(config-if)# ip mtu 1500

R2(config-if)# ip tcp adjust-mss 1360

R2(config-if)# tunnel source 192.168.20.1

R2(config-if)# tunnel destination 10.10.1.1

D.

R2(config)# interface Tunnel 1

R2(config-if)# ip address 172.20.1.2 255.255.255.0

R2(config-if)# ip mtu 1500

R2(config-if)# ip tcp adjust-mss 1360

R2(config-if)# tunnel source 10.10.2.2

R2(config-if)# tunnel destination 10.10.1.1

Question 46

Refer to the exhibit.

Question # 46

An engineer configured NetFlow on R1, but the NMS server cannot see the flow from ethernet 0/0 of R1. Which configuration resolves the issue?

Options:

A.

flow monitor Flowmonitor1

source Ethernet0/0

B.

interface Ethernet0/1

ip flow monitor Flowmonitor1 input

ip flow monitor Flowmonitor1 output

C.

interface Ethernet0/0

ip flow monitor Flowmonitor1 input

ip flow monitor Flowmonitor1 output

D.

flow exporter FlowAnalyzer1

source Ethernet0/0

Question 47

Options:

A.

Redistribute the static metric in EIGRP.

B.

Add the eigrp stub connected static command.

C.

Redistribute the connected metric in EIGRP.

D.

Remove the eigrp stub connected command.

Question 48

In a DMVPN network, the Spoke1 user observed that the voice traffic is coming to Spoke2 users via the hub router. Which command is required on both spoke routers to communicate directly to one another?

Options:

A.

ip nhrp map dynamic

B.

ip nhrp shortcut

C.

ip nhrp nhs multicast

D.

ip nhrp redirect

Question 49

Refer to the exhibit.

Question # 49

A bank ATM site has difficulty connecting with the bank server. A network engineer troubleshoots the issue and finds that R4 has no active route to the bank ATM site. Which action resolves the issue?

Options:

A.

Advertise 10.10.30.0/24 subnet in R1 EIGRP AS.

B.

EIGRP peering between R3 and R4 to be fixed.

C.

EIGRP peering between R1 and R2 to be fixed.

D.

Advertise 10.10.30.0/24 subnet in R3 EIGRP AS.

Question 50

Refer to the exhibit.

Question # 50

An error message "an OSPF-4-FLOOD_WAR” is received on SW2 from SW1. SW2 is repeatedly receiving its own link-state advertisement and flushes it from the network. Which action resolves the issue?

Options:

A.

Change area 5 to a normal area from a nonstub area

B.

Resolve different subnet mask issue on the link

C.

Configure Layer 3 port channel on interfaces between switches

D.

Resolve duplicate IP address issue in the network

Question 51

Refer to the exhibit.

Question # 51

Question # 51

The network engineer configured the summarization of the RIP routes into the OSPF domain on R5 but

still sees four different 172.16.0.0/24 networks on R4. Which action resolves the issue?

Options:

A.

R5(config)#router ospf 1

R5(config-router)#no area

R5(config-router)#summary-address 172.16.0.0 255.255.252.0

B.

R4(config)#router ospf 99

R4(config-router)#network 172.16.0.0 0.255.255.255 area 56

R4(config-router)#area 56 range 172.16.0.0 255,255.255.0

C.

R4(config)#router ospf 1

R4(config-router)#no area

R4(config-router)#summary-address 172.16.0.0 255.255.252.0

D.

R5(config)#router ospf 99

R5(config-router)#network 172.16.0.0 0.255.255.255 area 56

R5(config-router)#area 56 range 172.16.0.0 255.255.255.0

Question 52

Question # 52

Refer to the exhibit. A network engineer lost remote access to the router due to a network problem. The engineer used the console to access the router and noticed continuous logs on the console terminal. Which configuration limits the number of log messages on the console to critical and higher seventy level messages?

Options:

A.

term no monitor

B.

logging console 2

C.

no logging console

D.

logging console 5

Question 53

Refer to the exhibit.

Question # 53

A network administrator successfully logs in to a switch using SSH from a (RADIUS server When the network administrator uses a console port to access the switch the RADIUS server returns shell:priv-lvl=15’’ and the switch asks to enter the enable command \ the command is entered, it gets rejected. Which command set is used to troubleshoot and reserve this issue?

Options:

A.

line con 0

aaa authorization console

authorization exec

!

line vty 0 4

transport input ssh

B.

line con 0

aaa authorization console

!

line vty 0 4

authorization exec

C.

line con 0

aaa authorization console priv15

!

line vty 0 4

authorization exec

D.

line con 0

aaa authorization console

authorization priv15

!

line vty 0 4

transport input ssh

Question 54

The network administrator configured the router for Control Plane Policing to limit OSPF traffic to be

policed to 1 Mbps. Any traffic that exceeds this limit must also be allowed at this point for traffic

analysis. The router configuration is:

access-list 100 permit ospf any any

!

class-map CM-OSPF

match access-group 100

!

policy-map PM-COPP

class CM-OSPF

police 1000000 conform-action transmit

!

control-plane

service-policy output PM-COPP

The Control Plane Policing failed to monitor and police OSPF traffic. Which configuration resolves this

issue?

Question # 54

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 55

Question # 55

Refer to the exhibit An engineer must ensure that R3 sees only type 1 and 2 LSAs in area 1. Which command must the engineer apply on R2?

Options:

A.

Area 1 stub nssa

B.

Area 1nssa no-summary

C.

Area a stub no-summary

D.

Area 1 stub

Question 56

Refer to the exhibit.

Question # 56

A network administrator must block ping from user 3 to the App Server only. An inbound standard access list is applied to R1 interface G0/0 to block ping. The network administrator was notified that user 3 cannot even ping user 9 anymore. Where must the access list be applied in the outgoing direction to resolve the issue?

Options:

A.

R2 interface G1/0

B.

R2 interface G0/0

C.

SW1 interface G1/10

D.

SW1 interface G2/21

Question 57

An engineer configured SNMP notifications sent to the management server using authentication and encrypting data with DES. An error in the response PDU is received as "UNKNOWNUSERNAME. WRONGDIGEST". Which action resolves the issue?

Options:

A.

Configure the correct authentication password using SNMPv3 authPriv .

B.

Configure the correct authentication password using SNMPv3 authNoPriv.

C.

Configure correct authentication and privacy passwords using SNMPv3 authNoPriv.

D.

Configure correct authentication and privacy passwords using SNMPv3 authPriv.

Question 58

Question # 58

An engineer sets up a DMVPN connection to connect branch 1 and branch 2 to HQ branch 1 and branch 2 cannot communicate with each other. Which change must be made to resolve this issue?

Question # 58

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 59

Refer to Exhibit:

Question # 59

Question # 59

AS 111 wanted to use AS 200 as the preferred path for 172.20.5.0/24 and AS 100 as the backup. After the configuration, AS 100 is not used for any other routes. Which configuration resolves the issue?

Options:

A.

route-mmap SETLP permit 10

match ip address prefix-list PLIST1

set local-preference 99

route-map SETLP permit 20

B.

route-map SETLP permit 10

match ip address prefix-list PLIST1

set local-preference 110

route-map SETLP permit 20

C.

router bgp 111

no neighbor 192.168.10.1 route-map SETLP in

neighbor 192.168.10.1 route-map SETLP out

D.

router bap 111

no neighbor 192.168.10.1 route-map SETLP in

neighbor 192.168.20.2 route-map SE TLP in

Question 60

Which Ipv6 first-hop security feature helps to minimize denial of service attacks?

Options:

A.

IPv6 Router Advertisement Guard

B.

IPv6 Destination Guard

C.

DHCPv6 Guard

D.

IPv6 MAC address filtering

Question 61

Exhibit:

Question # 61

Which action resolves the authentication problem?

Options:

A.

Configure the user name on the TACACS+ server

B.

Configure the UDP port 1812 to be allowed on the TACACS+ server

C.

Configure the TCP port 49 to be reachable by the router

D.

Configure the same password between the TACACS+ server and router.

Question 62

Question # 62

Refer to the exhibit. A network administrator redistributed the default static route into OSPF toward all internal routers to reach to Internet. Which set of commands restores reachability to the Internet by internal routers?

Options:

A.

router ospf 1

default-information originate

B.

router ospf 1

network 0.0.0.0 0.0.0.0 area 0

C.

router ospf 1

redistribute connected 0.0.0.0

D.

router ospf 1

redistribute static subnets

Question 63

Clients on ALS2 receive IPv4 and IPv6 addresses but clients on ALS1 receive only IPv4 addresses and not IPv6 addresses. Which action on DSW1 allows clients on ALS1 to receive IPv6 addresses?

Question # 63

Options:

A.

Configure DSW1(config-if)#ipv6 helper address 2002:404:404::404:404

B.

Configure DSW1(dhcp-config)#default-router 2002:A04:A01::A04:A01

C.

Configure DSW1(config)#ipv6 route 2002:404:404:404:404/128 FastEthernet1/0

D.

Configure DSW1(config-if)#ipv6 dhcp relay destination 2002:404:404::404:404 GigabitEthernet1/2

E.

Option A

F.

Option B

G.

Option C

Question 64

Question # 64

Question # 64

Refer to the exhibit. The Los Angeles and New York routers are receiving routes from Chicago but not from each other. Which configuration fixes the issue?

Options:

A.

Interface Tunnel1

no ip split-horizon eigrp 111

B.

Interface Tunnel1

Ip next-hop-self elgrp 111

C.

Interface Tunnel1

tunnel mode Ipsec Ipv4

D.

Interface Tunnel1

tunnel protection ipsec profile IPSec-PROFILE

Question 65

Question # 65

Question # 65

Refer to the exhibit. R2 has two paths to reach 192.168.13.0/24. but traffic is sent only through R3. Which action allows traffic to use both paths?

Options:

A.

Configure the bandwidth 2000 command under interface FastEthernet0/0 on R2.

B.

Configure the variance 4 command under the EIGRP process on R2.

C.

Configure the delay 1 command under interface FastEthernet0/0 on R2.

D.

Configure the variance 2 command under the EIGRP process on R2

Question 66

Drag and drop the LDP features from the left onto the descriptions on the right

Question # 66

Options:

Question 67

Which two components are needed for a service provider to utilize the LVPN MPLS application? (Choose two.)

Options:

A.

The P routers must be configured for MP-iBGP toward the PE routers

B.

The P routers must be configured with RSVP.

C.

The PE routers must be configured for MP-iBGP with other PE routers

D.

The PE routers must be configured for MP-eBGP to connect to CEs

E.

The P and PE routers must be configured with LDP or RSVP

Question 68

Refer to the exhibit.

Question # 68

PC-2 failed to establish a Telnet connection to the terminal server. Which configuration resolves the issue?

Question # 68

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 69

Question # 69

Refer to the exhibit. R1 and R2 cannot establish an EIGRP adjacency. Which action establishes EIGRP adjacency?

Options:

A.

Remove the current autonomous system number on one of the routers and change to a different value.

B.

Remove the passive-interface command from the R2 configuration so that it matches the R1 configuration.

C.

Add the no auto-summary command to the R2 configuration so that it matches the R1 configuration.

D.

Add the passive-interface command to the R1 configuration so that it matches the R2 configuration.

Question 70

Refer to Exhibit.

Question # 70

A network administrator added one router in the Cisco DNA Center and checked its discovery and health from the Network Health Dashboard. The network administrator observed that the router is still showing up as unmonitored. What must be configured on the router to mount it in the Cisco DNA Center?

Options:

A.

Configure router with NetFlow data

B.

Configure router with the telemetry data

C.

Configure router with routing to reach Cisco DNA Center

D.

Configure router with SNMPv2c or SNMPv3 traps

Question 71

Question # 71

Refer to the exhibit. Which action restores the routes from neighbors while still filtering 1.1.1.0/24?

Options:

A.

Add a second line in the access list to permit any.

B.

Modify the route map to permit the access list instead of deny it

C.

Modify the access list to deny instead of permit it.

D.

Add a second sequence in the route map permit 20

Question 72

An engineer needs dynamic routing between two routers and is unable to establish OSPF adjacency. The output of the show ip ospf neighbor command shows that the neighbor state is EXSTART/EXCHANGE. Which action should be taken to resolve this issue?

Options:

A.

match the passwords

B.

match the hello timers

C.

match the MTUs

D.

match the network types

Question 73

Refer to the exhibit.

Question # 73

Which interface configuration must be configured on the HUB router to enable MVPN with mGRE mode?

Question # 73

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 74

Exhibit:

Question # 74

Bangkok is using ECMP to reach to the 192.168.5.0/24 network. The administrator must configure Bangkok in such a way that Telnet traffic from 192.168.3.0/24 and192.168.4.0/24 networks uses the HongKong router as the preferred router. Which set of configurations accomplishes this task?

Options:

A.

access-list 101 permit tcp 192.168.3.0 0.0.0.255 192.168.5.0 0.0.0.255

access-list 101 permit tcp 192.168.4.0 0.0.0.255 192.168.5.0 0.0.0.255

!

route-map PBR1 permit 10

match ip address 101

set ip next-hop 172.18.1.2

interface Ethernet0/3

ip policy route-map PBR1

B.

access-list 101 permit tcp 192.168.3.0 0.0.0.255 192.168.5.0 0.0.0.255 eq 23

access-list 101 permit tcp 192.168.4.0 0.0.0.255 192.168.5.0 0.0.0.255 eq 23

!

route-map PBR1 permit 10

match ip address 101

set ip next-hop 172.18.1.2

interface Ethernet0/1

ip policy route-map PBR1

C.

access-list 101 permit tcp 192.168.3.0 0.0.0.255 192.168.5.0 0.0.0.255 eq 23

access-list 101 permit tcp 192.168.4.0 0.0.0.255 192.168.5.0 0.0.0.255 eq 23

!

route-map PBR1 permit 10

match ip address 101

set ip next-hop 172.18.1.2

!

interface Ethernet0/3

ip policy route-map PBR1

D.

access-list 101 permit tcp 192.168.3.0 0.0.0.255 192.168.5.0 0.0.0.255

access-list 101 permit tcp 192.168.4.0 0.0.0.255 192.168.5.0 0.0.0.255

!

route-map PBR1 permit 10

match ip address 101

set ip next-hop 172.18.1.2

!

interface Ethernet0/1

ip policy route-map PBR1

Question 75

Refer to the exhibit.

Question # 75

Which action resolves the failed authentication attempt to the router?

Options:

A.

Configure aaa authorization login command on line vty 0 4

B.

Configure aaa authorization login command on line console 0

C.

Configure aaa authorization console global command

D.

Configure aaa authorization console command on line vty 0 4

Question 76

Question # 76

Refer to the exhibit. An engineer has successfully set up a floating static route from the BRANCH router to the HQ network using HQ_R1 as the primary default gateway When the g0/0 goes down on HQ_R1, the branch network cannot reach the HQ network 192.168.20.0/24. Which set of configurations resolves the issue?

Options:

A.

HQ_R3(config)# ip sla responder

HQ_R3(config)# ip sla responder icmp-echo 172.16.35.1

B.

BRANCH(config)# ip sla 1

BRANCH(config-ip-sla)# icmp-echo 192.168.100.2

C.

HQ R3(config)# Ip sla responder

HQ R3(config)# Ip sla responder Icmp-echo 172.16.35.5

D.

BRANCH(config)# Ip sla 1

BRANCH(config-ip-sta)# Icmp-echo 192.168.100.1

Question 77

Refer to the exhibit.

Question # 77

An engineer receives this error message when trying to access another router in-band from the serial interface connected to the console of R1. Which configuration is needed on R1 to resolve this issue?

Question # 77

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 78

Question # 78

Refer to the exhibit. The DHCP client is unable to receive an IP address from the DHCP server RouterB is configured as follows:

Interface fastethernet 0/0

description Client DHCP ID 394482431

Ip address 172 31 11 255 255.255 0

!

ip route 172.16.1.0 255 255 255.0 10.1.1.2

Which command is required on the fastethernet 0/0 interface of RouterB to resolve this issue?

Options:

A.

RouterB(config-if)#lp helper-address 172.31.1.1

B.

RouterBiconfig-ififclp helper-address 255.255 255 255

C.

RouterB(config-if)#lp helper-address 172.16.1.1

D.

RouterB(config-if)#lp helper-address 172.16.1.2

Question 79

Refer to the exhibit.

Question # 79

An IT staff member comes into the office during normal office hours and cannot access devices through SSH Which action should be taken to resolve this issue?

Options:

A.

Modify the access list to use the correct IP address.

B.

Configure the correct time range.

C.

Modify the access list to correct the subnet mask

D.

Configure the access list in the outbound direction.

Question 80

An engineer must configure a Cisco router to initiate secure connections from the router to other devices in the network but kept failing. Which two actions resolve the issue? (Choose two.)

Options:

A.

Configure a source port for the SSH connection to initiate

B.

Configure a TACACS+ server and enable it

C.

Configure transport input ssh command on the console

D.

Configure a domain name

E.

Configure a crypto key to be generated

Question 81

Refer to the exhibit.

Question # 81

Question # 81

The administrator can see the traps for the failed login attempts, but cannot see the traps of successful login attempts. What command is needed to resolve the issue?

Options:

A.

Configure logging history 2

B.

Configure logging history 3

C.

Configure logging history 4

D.

Configure logging history 5

Question 82

Refer to the exhibit.

Question # 82

A user cannot SSH to the router. What action must be taken to resolve this issue?

Options:

A.

Configure transport input ssh

B.

Configure transport output ssh

C.

Configure ip ssh version 2

D.

Configure ip ssh source-interface loopback0

Question 83

Refer to the exhibit.

Question # 83

The R1 and R2 configurations are:

Question # 83

The neighbor is not coming up. Which two sets of configurations bring the neighbors up? (Choose two.)

Options:

A.

R2

ip route 10.1.1.1 255.255.255.255 192.168.1.1

router bgp 200

neighbor 10.1.1.1 tti-security hops 1

neighbor 10.1.1.1 update-source loopback 0

B.

R2

ip route 10.1.1.1 255.255.255.255 192.168.1.1

router bgp 200

neighbor 10.1.1.1 disable-connected-check

neighbor 10.1.1.1 update-source loopback 0

C.

R2

ip route 10.1.1.2 255.255.255.255 192.168.1.2

router bgp 100neighbor 10.1.1.2 ttl-security hops 1

neighbor 10.1.1.2 update-source loopback 0

D.

R1

ip route 10.1.1.2 255.255.255.255 192.168.1.2

router bgp 100

neighbor 10.1.1.1 ttl-security hops 1

neighbor 10.1.1.2 update-source loopback 0

E.

R1

ip route 10.1.1.2 255.255.255.255 192.168.1.2

router bgp 100

neighbor 10.1.1.2 disable-connected-check

neighbor 10.1.1.2 update-source Loopback0

Question 84

How does an MPLS Layer 3 VPN function?

Options:

A.

set of sites use multiprotocol BGP at the customer site for aggregation

B.

multiple customer sites interconnect through service provider network to create secure tunnels between customer edge devices

C.

set of sites interconnect privately over the Internet for security

D.

multiple customer sites interconnect through a service provider network using customer edge to provider edge connectivity

Question 85

An engineer configured access list NON-CISCO in a policy to influence routes

Question # 85

What are the two effects of this route map configuration? (Choose two.)

Options:

A.

Packets are not evaluated by sequence 10.

B.

Packets are evaluated by sequence 10.

C.

Packets are forwarded to the default gateway.

D.

Packets are forwarded using normal route lookup.

E.

Packets are dropped by the access list.

Question 86

Refer to the exhibit.

Question # 86

Question # 86

An engineer configured BGP between routers R1 and R3 The BOP peers cannot establish neighbor adjacency to be able to exchange routes. Which configuration resolves this issue?

Options:

A.

R3

router bgp 6502

address-family ipv6

neighbor AB01:2011:7:100::1 activate

B.

R1

router bgp 6501

address-family ipv6

neighbor AB01:2011:7:100;:3 activate

C.

R3

router bgp 6502

neighbor AB01:2011:7:100::1 ebgp-muttlhop 255

D.

R1

router bgp 6501 neighborAB01:2011:7:100::3ebgp-multihop255

Question 87

Refer to the exhibit.

Question # 87

An IPv6 network was newly deployed in the environment and the help desk reports that R3 cannot SSH to the R2s Loopback interface. Which action resolves the issue?

Options:

A.

Modify line 10 of the access list to permit instead of deny.

B.

Remove line 60 from the access list.

C.

Modify line 30 of the access list to permit instead of deny.

D.

Remove line 70 from the access list.

Question 88

Refer to the exhibits.

Question # 88

A user on the 192.168.1.0/24 network can successfully ping 192.168.3.1, but the administrator cannot ping 192.168.3.1 from the LA router. Which set of configurations fixes the issue?

A)

Question # 88

B)

Question # 88

C)

Question # 88

D)

Question # 88

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 89

Refer to the exhibit.

Question # 89

A network administrator reviews the branch router console log to troubleshoot the OSPF adjacency issue with the DR router. Which action resolves this issue?

Options:

A.

Advertise the branch WAN interface matching subnet for the DR site.

B.

Configure matching hello and dead intervals between sites.

C.

Configure the WAN interface for DR site in the related OSPF area.

D.

Stabilize the DR site flapping link to establish OSPF adjacency.

Question 90

Question # 90

Refer to the exhibit. A network administrator configured an IPv6 access list to allow TCP return traffic only, but it is not working as expected. Which changes resolve this issue?

Options:

A.

ipv6 access-list inbound

permit tcp any any syn

deny ipv6 any any log

!

interface gi0/0

ipv6 traffic-filter inbound out

B.

ipv6 access-list inbound

permit tcp any any syn

deny ipv6 any any log

!

interface gi0/0

ipv6 traffic-filter inbound in

C.

ipv6 access-list inbound

permit tcp any any established

deny ipv6 any any log

!

interface gi0/0

ipv6 traffic-filter inbound in

D.

ipv6 access-list inbound

permit tcp any any established

deny ipv6 any any log

!

interface gi0/0

ipv6 traffic-filter inbound out

Question 91

Drag and drop the actions from the left into the correct order on the right to configure a policy to avoid following packet forwarding based on the normal routing path.

Question # 91

Options:

Question 92

Question # 92

Refer to the exhibit. The administrator configured route advertisement to a remote low resources router to use only the default route to reach any network but failed. Which action resolves this issue?

Options:

A.

Change the direction of the distribute-list command from out to in.

B.

Remove the line with the sequence number 5 from the prefix list.

C.

Remove the prefix keyword from the distribute-list command.

D.

Remove the line with the sequence number 10 from the prefix list.

Question 93

An engineer is troubleshooting on the console session of a router and turns on multiple debug commands. The console screen is filled with scrolling debug messages that none of the commands can be verified if entered correctly or display any output. Which action allows the engineer to see entered console commands while still continuing the analysis of the debug messages?

Options:

A.

Configure the logging synchronous command

B.

Configure the no logging console debugging command globally

C.

Configure the logging synchronous level all command

D.

Configure the term no mon command globally

Question 94

Refer to the exhibit.

Question # 94

AS65510 iBGP is configured for directly connected neighbors. R4 cannot ping or traceroute network 192 168.100.0/24 Which action resolves this issue?

Options:

A.

Configure R4 as a route reflector server and configure R1 as a route reflector client

B.

Configure R1 as a route reflector server and configure R2 and R3 as route reflector clients

C.

Configure R4 as a route reflector server and configure R2 and R3 as route reflector clients.

D.

Configure R1 as a route reflector server and configure R4 as a route reflector client

Question 95

Drag and drop the MPLS concepts from the left onto the descriptions on the right.

Question # 95

Options:

Question 96

Refer to the exhibit.

Question # 96

The network administrator can see the DHCP discovery packet in R1. but R2 is not replying to the DHCP request. The R1 related interface is configured with the DHCP helper address. If the PC is directly connected to the FaO/1 interface on R2, the DHCP server assigns as IP address from the DHCP pool to the PC. Which two commands resolve this issue? (Choose two.)

Options:

A.

service dhcp-relay command on R1

B.

ip dhcp option 82 command on R2

C.

service dhcp command on R1

D.

ip dhcp relay information enable command on R1

E.

ip dhcp relay information trust-all command on R2

Question 97

Refer to Exhibit.

Question # 97

Which two configurations allow clients to get dynamic ip addresses assigned?

Options:

A.

Configure access-list 100 permit udp any any eq 61 as the first line

B.

Configure access-list 100 permit udp any any eq 86 as the first line

C.

Configure access-list 100 permit udp any any eq 68 as the first line

D.

Configure access-list 100 permit udp any any eq 69 as the first line

E.

Configure access-list 100 permit udp any any eq 67 as the first line

Question 98

Refer to the exhibit.

Question # 98

A network administrator configured mutual redistribution on R1 and R2 routers, which caused instability in the network. Which action resolves the issue?

Options:

A.

Set a tag in the route map when redistributing EIGRP into OSPF on R1. and match the same tag on R2 to allow when redistributing OSPF into EIGRP.

B.

Apply a prefix list of EIGRP network routes in OSPF domain on R1 to propagate back into the EIGRP routing domain.

C.

Set a tag in the route map when redistributing EIGRP into OSPF on R1, and match the same tag on R2 to deny when redistributing OSPF into EIGRP.

D.

Advertise summary routes of EIGRP to OSPF and deny specific EIGRP routes when redistributing into OSPF.

Question 99

Refer to the exhibit.

Question # 99

To provide reachability to network 10.1.1.0 /24 from R5, the network administrator redistributes EIGRP into OSPF on R3 but notices that R4 is now taking a ........... path through R5 to reach 10.1.1.0/24 network. Which action fixes the issue while keeping the reachability from R5 to 10.1.1.0/24 network?

Options:

A.

Change the administrative distance of the external EIGRP to 90.

B.

Apply the outbound distribution list on R5 toward R4 in OSPF.

C.

Change the administrative distance of OSPF to 200 on R5.

D.

Redistribute OSPF into EIGRP on R4

Question 100

Refer to Exhibit.

Question # 100

A network administrator enables DHCP snooping on the Cisco Catalyst 3750-X switch and configures the uplink port (Port-channel2) as a trusted port. Clients are not receiving an IP address, but when DHCP snooping is disabled, clients start receiving IP addresses. Which global command resolves the issue?

Options:

A.

No ip dhcp snooping information option

B.

ip dhcp snooping

C.

ip dhcp relay information trust portchannel2

D.

ip dhcp snooping trust

Question 101

How are MPLS Layer 3 VPN services deployed?

Options:

A.

The RD and RT values must match under the VRR

B.

The RD and RT values under a VRF must match on the remote PE router

C.

The import and export RT values under a VRF must always be the same.

D.

The label switch path must be available between the local and remote PE routers.

Question 102

Refer to the exhibit.

Question # 102

R1 is being monitored using SNMP and monitoring devices are getting only partial information. What action should be taken to resolve this issue?

Options:

A.

Modify the CoPP policy to increase the configured exceeded limit for SNMP.

B.

Modify the access list to include snmptrap.

C.

Modify the CoPP policy to increase the configured CIR limit for SNMP.

D.

Modify the access list to add a second line to allow udp any any eq snmp

Question 103

Refer to the exhibit.

Question # 103

Question # 103

An engineer identifier a Layer 2 loop using DNAC. Which command fixes the problem in the SF-D9300-1 switch?

Options:

A.

no spanning-tree uplinkfast

B.

spanning-tree loopguard default

C.

spanning-tree backbonesfast

D.

spanning-tree portfast bpduguard

Question 104

An engineer configured Reverse Path Forwarding on an interface and noticed that the routes are dropped when a route lookup fails on that interface for a prefix that is available in the routing table Which interface configuration resolves the issue?

Options:

A.

ip verify unicast source reachable-via rx

B.

ip verify unicast source reachable-via any

C.

ip verify unicast source reachable-via allow-default

D.

ip verify unicast source reachable-via 12-src

Question 105

What is the minimum time gap required by the local system before putting a BFD control packet on the wire?

Options:

A.

Detect Mult

B.

Required Min Echo RX Interval

C.

Desired Min TX Interval

D.

Required Min RX Interval

Question 106

Refer to the exhibits.

Question # 106

When DMVPN is configured, which configuration allows spoke-to-spoke communication using loopback as a tunnel source?

Options:

A.

Configure crypto isakmp key cisco address 0.0.0.0 on the hub.

B.

Configure crypto isakmp key Cisco address 200.1.0.0 255.255.0.0 on the hub.

C.

Configure crypto isakmp key cisco address 200.1.0.0 255.255.0.0 on the spokes.

D.

Configure crypto isakmp key cisco address 0.0.0.0 on the spokes.

Question 107

Refer to the exhibit.

Question # 107

Which two actions restrict access to router R1 by SSH? (Choose two.)

Options:

A.

Configure transport input ssh on line vty and remove sequence 30 from access list 100.

B.

Configure transport output ssh on line vty and remove sequence 20 from access list 100.

C.

Remove class-map ANY from service-policy CoPP

D.

Configure transport output ssh on line vty and remove sequence 10 from access list 199.

E.

Remove sequence 10 from access list 100 and add sequence 20 deny tcp any any eq telnet to access list 199

Question 108

A DMVPN single hub topology is using IPsec + mGRE with OSPF. What should be configured on the hub to ensure it will be the designated router?

Options:

A.

tunnel interface of the hub with ip nhrp ospf dr

B.

OSPF priority to 0

C.

route map to set the metrics of learned routes to 110

D.

OSPF priority greater than 1

Question 109

What statement about route distinguishes in an MPLS network is true?

Options:

A.

Route distinguishes make a unique VPNv4 address across the MPLS network.

B.

Route distinguishers allow multiple instances of a routing table to coexist within the edge router.

C.

Route distinguishes are used for label bindings

D.

Route distinguishes define which prefixes are imported and exported on the edge router

Question 110

Refer to the exhibit.

Question # 110

R1 is connected with R2 via GigabitEthernet0/0, and R2 cannot ping R1. What action will fix the issue?

Options:

A.

Fix route dampening configured on the router.

B.

Replace the SFP module because it is not supported.

C.

Fix IP Event Dampening configured on the interface.

D.

Correct the IP SLA probe that failed.

Question 111

Refer to the exhibit.

Question # 111

Question # 111

All the serial between R1, R2, and R3 have the Same bandwidth. User on the 192.168.1.0/24 network report slow response times while they access resource on network 192.168.3.0/24. When a traceroute is run on the path. It shows that the packet is getting forwarded via R2 to R3 although the link between R1 and R3 is still up. What must the network administrator to fix the slowness?

Options:

A.

Change the Administrative Distance of EIGRP to 5.

B.

Add a static route on R1 using the next hop of R3.

C.

Remove the static route on R1.

D.

Redistribute theR1 route to EIGRP

Question 112

Refer to the exhibit.

Question # 112

A network administrator is using the DNA Assurance Dashboard panel to troubleshoot an OSPF adjacency that failed between Edge_NYC interface GigabitEthernet1/3 with Neighbor Edge_SNJ. The administrator observes that the neighborship is stuck in exstart state. How does the administrator fix this issue?

Options:

A.

Configure to match the OSPF interface speed and duplex settings on both routers.

B.

Configure to match the OSPF interface MTU settings on both routers.

C.

Configure to match the OSPF interface unique IP address and subnet mask on both routers.

D.

Configure to match the OSPF interface network types on both routers.

Question 113

Which security feature can protect DMVPN tunnels?

Options:

A.

IPsec

B.

TACACS+

C.

RTBH

D.

RADIUS

Question 114

During the maintenance window an administrator accidentally deleted the Telnet-related

configuration that permits a Telnet connection from the inside network (Eth0/0) to the outside of the networking between Friday – Sunday night hours only. Which configuration resolves the issue?

A)

Question # 114

B)

Question # 114

C)

Question # 114

D)

Question # 114

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 115

An engineer is configuring a network and needs packets to be forwarded to an interface for any destination address that is not in the routing table. What should be configured to accomplish this task?

Options:

A.

set ip next-hop

B.

set ip default next-hop

C.

set ip next-hop recursive

D.

set ip next-hop verify-availability

Question 116

Refer to the exhibit.

Question # 116

An engineer is trying to generate a summary route in OSPF for network 10.0.0.0/8, but the

summary route does not show up in the routing table. Why is the summary route missing?

Options:

A.

The summary-address command is used only for summarizing prefixes between areas.

B.

The summary route is visible only in the OSPF database, not in the routing table.

C.

There is no route for a subnet inside 10.0.0.0/8, so the summary route is not generated.

D.

The summary route is not visible on this router, but it is visible on other OSPF routers in the same area.

Question 117

Drag and Drop the IPv6 First-Hop Security features from the left onto the definitions on the right.

Question # 117

Options:

Question 118

Which statement about route distinguishers in an MPLS network is true?

Options:

A.

Route distinguishers allow multiple instances of a routing table to coexist within the edge router.

B.

Route distinguishers are used for label bindings.

C.

Route distinguishers make a unique VPNv4 address across the MPLS network.

D.

Route distinguishers define which prefixes are imported and exported on the edge router.

Question 119

Which statement about IPv6 RA Guard is true?

Options:

A.

It does not offer protection in environments where IPv6 traffic is tunneled.

B.

It cannot be configured on a switch port interface in the ingress direction.

C.

Packets that are dropped by IPv6 RA Guard cannot be spanned.

D.

It is not supported in hardware when TCAM is programmed.

Question 120

Which is statement about IPv6 inspection is true?

Options:

A.

It teams and secures bindings for stateless autoconfiguration addresses in Layer 3 neighbor tables

B.

It learns and secures bindings for stateful autoconfiguration addresses in Layer 3 neighbor tables

C.

It teams and secures bindings for stateful autoconfiguration addresses in Layer 2 neighbor tables

D.

It team and secures binding for stateless autoconfiguration addresses in Layer 2 neighbor tables.

Question 121

Refer to the exhibit.

Question # 121

An engineer configures a static route on a router, but when the engineer checks the route

to the destination, a different next hop is chosen. What is the reason for this?

Options:

A.

Dynamic routing protocols always have priority over static routes.

B.

The metric of the OSPF route is lower than the metric of the static route.

C.

The configured AD for the static route is higher than the AD of OSPF.

D.

The syntax of the static route is not valid, so the route is not considered.

Question 122

Which list defines the contents of an MPLS label?

Options:

A.

20-bit label; 3-bit traffic class; 1-bit bottom stack; 8-bit TTL

B.

32-bit label; 3-bit traffic class; 1-bit bottom stack; 8-bit TTL

C.

20-bit label; 3-bit flow label; 1-bit bottom stack; 8-bit hop limit

D.

32-bit label; 3-bit flow label; 1-bit bottom stack; 8-bit hop limit

Question 123

Which protocol does VRF-Lite support?

Options:

A.

IS-IS

B.

ODR

C.

EIGRP

D.

IGRP

Question 124

What is a prerequisite for configuring BFD?

Options:

A.

Jumbo frame support must be configured on the router that is using BFD.

B.

All routers in the path between two BFD endpoints must have BFD enabled.

C.

Cisco Express Forwarding must be enabled on all participating BFD endpoints.

D.

To use BFD with BGP, the timers 3 9 command must first be configured in the BGP routing process.

Question 125

Refer the exhibit.

Question # 125

Which action resolves intermittent connectivity observed with the SNMP trap

packets?

Options:

A.

Decrease the committed burst Size of the mgmt class map

B.

Increase the CIR of the mgmt class map

C.

Add a new class map to match TCP traffic

D.

Add one new entry in the ACL 120 to permit the UDP port 161

Question 126

Refer to Exhibit.

Question # 126

Which statement about redistribution from BGP into OSPF process 10 is true?

Options:

A.

Network 172.16.1.0/24 is not redistributed into OSPF.

B.

Network 10.10 10.0/24 is not redistributed into OSPF

C.

Network 172.16.1.0/24 is redistributed with administrative distance of 1.

D.

Network 10.10.10.0/24 is redistributed with administrative distance of 20.

Question 127

Drag and drop the addresses from the left onto the correct IPv6 filter purposes on the right.

Question # 127

Options:

Question 128

Refer to the exhibit.

Question # 128

A company is evaluating multiple network management system tools. Trending graphs generated by SNMP data are returned by the NMS and appear to have multiple gaps. While troubleshooting the issue, an engineer noticed the relevant output. What solves the gaps in the graphs?

Options:

A.

Remove the exceed-rate command in the class map.

B.

Remove the class map NMS from being part of control plane policing.

C.

Configure the CIR rate to a lower value that accommodates all the NMS tools

D.

Separate the NMS class map in multiple class maps based on the specific protocols with appropriate CoPP actions

Question 129

Which statement about MPLS LDP router ID is true?

Options:

A.

If not configured, the operational physical interface is chosen as the router ID even if a loopback is configured.

B.

The loopback with the highest IP address is selected as the router ID.

C.

The MPLS LDP router ID must match the IGP router ID.

D.

The force keyword changes the router ID to the specified address without causing any impact.

Question 130

An engineer configured a company’s multiple area OSPF head office router and Site A cisco

routers with VRF lite. Each site router is connected to a PE router of an MPLS backbone.

Question # 130

After finishing both site router configurations, none of the LSA 3,4 5, and 7 are installed at Site A router. Which configuration resolves this issue?

Options:

A.

configure capability vrf-lite on Site A and its connected PE router under router ospf 1 vrf abc

B.

configure capability vrf-lite on Head Office and its connected PE router under router ospf 1 vrf abc

C.

configure capability vrf-lite on both PE routers connected to Head Office and Site A routers under routtr ospf 1 vrf abc

D.

configure capability vrf-lite on Head Office and Site A routers under router ospf 1 vrf abc

Question 131

Which command is used to check IP SLA when an interface is suspected to receive lots of traffic with options?

Options:

A.

show track

B.

show threshold

C.

show timer

D.

show delay

Question 132

Which attribute eliminates LFAs that belong to protected paths in situations where links in a network are connected through a common fiber?

Options:

A.

shared risk link group-disjoint

B.

linecard-disjoint

C.

lowest-repair-path-metric

D.

interface-disjoint

Question 133

Refer to the following output:

Router#show ip nhrp detail

10.1.1.2/8 via 10.2.1.2, Tunnel1 created 00:00:12, expire 01:59:47

TypE. dynamic, Flags: authoritative unique nat registered used

NBMA address: 10.12.1.2

What does the authoritative flag mean in regards to the NHRP information?

Options:

A.

It was obtained directly from the next-hop server.

B.

Data packets are process switches for this mapping entry.

C.

NHRP mapping is for networks that are local to this router.

D.

The mapping entry was created in response to an NHRP registration request.

E.

The NHRP mapping entry cannot be overwritten.

Question 134

Drag and drop the MPLS VPN concepts from the left onto the correct descriptions on the right.

Question # 134

Options:

Question 135

Refer to the exhibit.

Question # 135

An engineer is trying to connect to a device with SSH but cannot connect. The engineer connects by using the console and finds the displayed output when troubleshooting. Which command must be used in configuration mode to enable SSH on the device?

Options:

A.

no ip ssh disable

B.

ip ssh enable

C.

ip ssh version 2

D.

crypto key generate rsa

Question 136

Which configuration adds an IPv4 interface to an OSPFv3 process in OSPFv3 address family configuration?

Options:

A.

Router ospf3 1 address-family ipv4

B.

Router(config-router)#ospfv3 1 ipv4 area 0

C.

Router(config-if)#ospfv3 1 ipv4 area 0

D.

Router ospfv3 1 address-family ipv4 unicast

Question 137

Which statement about IPv6 ND inspection is true?

Options:

A.

It learns and secures bindings for stateless autoconfiguration addresses in Layer 3 neighbor tables.

B.

It learns and secures bindings for stateless autoconfiguration addresses in Layer 2 neighbor tables.

C.

It learns and secures bindings for stateful autoconfiguration addresses in Layer 3 neighbor tables.

D.

It learns and secures bindings for stateful autoconfiguration addresses in Layer 2 neighbor tables.

Question 138

Refer to the exhibit.

Question # 138

The network administrator configured VRF lite for customer A. The technician at the remote site misconfigured VRF on the router. Which configuration will resolve connectivity for both sites of customer_a?

Question # 138

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 139

Which protocol is used to determine the NBMA address on the other end of a tunnel when mGRE is used?

Options:

A.

NHRP

B.

IPsec

C.

MP-BGP

D.

OSPF

Question 140

Drag and drop the MPLS VPN device types from me left onto the definitions on the right.

Question # 140

Options:

Question 141

An engineer configured the wrong default gateway for the Cisco DNA Center enterprise interface during the install. Which command must the engineer run to correct the configuration?

Options:

A.

sudo maglev-config update

B.

sudo maglev install config update

C.

sudo maglev reinstall

D.

sudo update config install

Question 142

Refer to the exhibit.

Question # 142

Which interface configuration must be configured on the spoke A router to enable a dynamic DMVPN tunnel with the spoke B router?

Question # 142

Question # 142

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 143

Refer to the exhibit.

Question # 143

Which control plane policy limits BGP traffic that is destined to the CPU to 1 Mbps and

ignores BGP traffic that is sent at higher rate?

Options:

A.

policy-map SHAPE_BGP

B.

policy-map LIMIT_BGP

C.

policy-map POLICE_BGP

D.

policy-map COPP

Question 144

Refer to the exhibit.

Question # 144

Why is the remote NetFlow server failing to receive the NetFlow data?

Options:

A.

The flow exporter is configured but is not used.

B.

The flow monitor is applied in the wrong direction.

C.

The flow monitor is applied to the wrong interface.

D.

The destination of the flow exporter is not reachable.

Question 145

Drag and drop the DHCP messages from the left onto the correct uses on the right.

Question # 145

Options:

Question 146

Refer to the exhibit.

Question # 146

R2 is a route reflector, and R1 and R3 are route reflector clients. The route reflector learns the route to 172.16.25.0/24 from R1, but it does not advertise to R3. What is the reason the route is not advertised?

Options:

A.

R2 does not have a route to the next hop, so R2 does not advertise the prefix to other clients.

B.

Route reflector setup requires full IBGP mesh between the routers.

C.

In route reflector setup, only classful prefixes are advertised to other clients.

D.

In route reflector setups, prefixes are not advertised from one client to another.

Question 147

Refer to the exhibit.

Question # 147

Which subnet is redistributed from EIGRP to OSPF routing protocols?

Options:

A.

10.2.2.0/24

B.

10.1.4.0/26

C.

10.1.2.0/24

D.

10.2.3.0/26

Question 148

Refer to the exhibit.

Question # 148

The ACL is placed on the inbound Gigabit 0/1 interface of the router. Host

192.168.10.10cannot SSH to host 192.168.100.10 even though the flow is permitted. Which action

resolves the issue without opening full access to this router?

Options:

A.

Move the SSH entry to the beginning of the ACL

B.

Temporarily move the permit ip any any line to the beginning of the ACL to see if the flow works

C.

Temporarily remove the ACL from the interface to see if the flow works

D.

Run the show access-list FILTER command to view if the SSH entry has any hit statistic associated with it

Question 149

Refer to the exhibit.

Question # 149

An engineer is trying to block the route to 192.168.2.2 from the routing table by using the

configuration that is shown. The route is still present in the routing table as an OSPF route. Which action blocks the route?

Options:

A.

Use an extended access list instead of a standard access list.

B.

Change sequence 10 in the route-map command from permit to deny.

C.

Use a prefix list instead of an access list in the route map.

D.

Add this statement to the route map: route-map RM-OSPF-DL deny 20.

Question 150

Users were moved from the local DHCP server to the remote corporate DHCP server. After the move,

none of the users were able to use the network.

Which two issues will prevent this setup from working properly? (Choose two)

Options:

A.

Auto-QoS is blocking DHCP traffic.

B.

The DHCP server IP address configuration is missing locally

C.

802.1X is blocking DHCP traffic

D.

The broadcast domain is too large for proper DHCP propagation

E.

The route to the new DHCP server is missing

Question 151

Refer to the exhibit.

Question # 151

After redistribution is enabled between the routing protocols; PC2, PC3, and PC4 cannot reach PC1. Which action can the engineer take to solve the issue so that all the PCs are reachable?

Options:

A.

Set the administrative distance 100 under the RIP process on R2.

B.

Filter the prefix 10.1.1.0/24 when redistributed from OSPF to EIGRP.

C.

Filter the prefix 10.1.1.0/24 when redistributed from RIP to EIGRP.

D.

Redistribute the directly connected interfaces on R2.

Question 152

Refer to the exhibit.

Question # 152

An engineer is monitoring reachability of the configured default routes to ISP1 and ISP2. The default route from ISP1 is preferred if available. How is this issue resolved?

Options:

A.

Use the icmp-echo command to track both default routes

B.

Use the same AD for both default routes

C.

Start IP SLA by matching numbers for track and ip sla commands

D.

Start IP SLA by defining frequency and scheduling it

Question 153

A network engineer needs to verify IP SLA operations on an interface that shows on indication of

excessive traffic.

Which command should the engineer use to complete this action?

Options:

A.

show frequency

B.

show track

C.

show reachability

D.

show threshold

Question 154

Which SNMP verification command shows the encryption and authentication protocols that are used in

SNMPV3?

Options:

A.

show snmp group

B.

show snmp user

C.

show snmp

D.

show snmp view

Question 155

Refer to the exhibit.

Question # 155

AAA server 10.1.1.1 is configured with the default authentication and accounting settings, but the switch cannot communicate with the server Which action resolves this issue?

Options:

A.

Match the authentication port

B.

Match the accounting port

C.

Correct the timeout value.

D.

Correct the shared secret.

Question 156

Refer to the exhibit.

Question # 156

The output of the trace route from R5 shows a loop in the network. Which configuration

prevents this loop?

A)

Question # 156

B)

Question # 156

C)

Question # 156

D)

Question # 156

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 157

Which command allows traffic to load-balance in an MPLS Layer 3 VPN configuration?

Options:

A.

multi-paths eibgp 2

B.

maximum-paths 2

C.

Maximum-paths ibgp 2

D.

multi-paths 2

Question 158

Which label operations are performed by a label edge router?

Options:

A.

SWAP and POP

B.

SWAP and PUSH

C.

PUSH and PHP

D.

PUSH and POP

Question 159

While troubleshooting connectivity issues to a router, these details are noticed:

  • Standard pings to all router interfaces, including loopbacks, are successful.
  • Data traffic is unaffected.
  • SNMP connectivity is intermittent.
  • SSH is either slow or disconnects frequently.

Which command must be configured first to troubleshoot this issue?

Options:

A.

show policy-map control-plane

B.

show policy-map

C.

show interface | inc drop

D.

show ip route

Question 160

Refer to the exhibit.

Question # 160

Drag and drop the credentials from the left onto the remote login information on the right to resolve a failed login attempt to vtys. Not all credentials are uf SLA by defining frequency and schedulingsed

Question # 160

Options:

Question 161

Refer to the exhibit.

Question # 161

An engineer is troubleshooting BGP on a device but discovers that the clock on the device does not correspond to the time stamp of the log entries. Which action ensures consistency between the two times?

Options:

A.

Configure the service timestamps log uptime command in global configuration mode.

B.

Configure the logging clock synchronize command in global configuration mode.

C.

Configure the service timestamps log datetime localtime command in global configuration mode.

D.

Make sure that the clock on the device is synchronized with an NTP server.

Question 162

Refer to the exhibit.

Question # 162

Which configuration configures a policy on R1 to forward any traffic that is sourced from

the 192.168.130.0/24 network to R2?

Question # 162

Question # 162

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 163

Refer to the exhibit.

Question # 163

A router receiving BGP routing updates from multiple neighbors for routers in AS 690. What is the reason that the router still sends traffic that is destined to AS 690 to a neighbor other than 10.222.1.1?

Options:

A.

The local preference value in another neighbor statement is higher than 250.

B.

The local preference value should be set to the same value as the weight in the route map.

C.

The route map is applied in the wrong direction.

D.

The weight value in another neighbor statement is higher than 200.

Question 164

Refer to the exhibit.

Question # 164

An engineer is trying to configure local authentication on the console line, but the device is trying to authenticate using TACACS+. Which action produces the desired configuration?

Options:

A.

Add the aaa authentication login default none command to the global configuration.

B.

Replace the capital “C” with a lowercase “c” in the aaa authentication login Console local command.

C.

Add the aaa authentication login default group tacacs+ local-case command to the global

configuration.

D.

Add the login authentication Console command to the line configuration

Question 165

What is the output of the following command:

show ip vrf

Options:

A.

Show's default RD values

B.

Displays IP routing table information associated with a VRF

C.

Show's routing protocol information associated with a VRF.

D.

Displays the ARP table (static and dynamic entries) in the specified VRF

Question 166

An engineer configured a leak-map command to summarize EIGRP routes and advertise specifically loopback 0 with an IP of 10.1.1.1.255.255.255.252 along with the summary route. After finishing configuration, the customer complained not receiving summary route with specific loopback address. Which two configurations will fix it? (Choose two.)

Question # 166

Options:

A.

Configure access-list 1 permit 10.1.1.0.0.0.0.3.

B.

Configure access-list 1 permit 10.1.1.1.0.0.0.252.

C.

Configure access-list 1 and match under route-map Leak-Route.

D.

Configure route-map Leak-Route permit 10 and match access-list 1.

E.

Configure route-map Leak-Route permit 20.

Question 167

Which configuration enabled the VRF that is labeled “Inet” on FastEthernet0/0?

Options:

A.

R1(config)# ip vrf Inet

R1(config-vrf)#interface FastEthernet0/0

R1(config-if)#ip vrf forwarding Inet

B.

R1(config)#router ospf 1 vrf Inet

R1(config-router)#ip vrf forwarding FastEthernet0/0

C.

R1(config)#ip vrf Inet FastEthernet0/0

D.

R1(config)# ip vrf Inet

R1(config-vrf)#ip vrf FastEthernet0/0

Question 168

Refer to the exhibit.

Question # 168

An IP SLA was configured on router R1 that allows the default route to be modified in the event that Fa0/0 loses reachability with the router R3 Fa0/0 interface. The route has changed to flow through

router R2. Which debug command is used to troubleshoot this issue?

Options:

A.

debug ip flow

B.

debug ip sla error

C.

debug ip routing

D.

debug ip packet

Page: 1 / 56
Total 563 questions