2.11 Flashcards

1
Q

1 Refer to the exhibit. Assuming that the routing tables are up to date and no ARP messages are needed, after a packet leaves H1, how many times is the L2 header rewritten in the path to H3?

1
2    
3
4
5
6
A

2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

2 Refer to the exhibit. Which highlighted value represents a specific destination network in the routing table?

0.0.0.0
172.16.100.128
172.16.100.2
110
791

A

172.16.100.128

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

3 On which two routers would a default static route be configured? (Choose two.)

stub router connection to the rest of the corporate or campus network
any router where a backup route to dynamic routing is needed for reliability
edge router connection to the ISP
any router running an IOS prior to 12.0
the router that serves as the gateway of last resort

A

stub router connection to the rest of the corporate or campus network

edge router connection to the ISP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

4 Which command will create a static route on R2 in order to reach PC B?

R2(config)# ip route 172.16.2.1 255.255.255.0 172.16.3.1
R2(config)# ip route 172.16.2.0 255.255.255.0 172.16.2.254
R2(config)# ip route 172.16.2.0 255.255.255.0 172.16.3.1
R2(config)# ip route 172.16.3.0 255.255.255.0 172.16.2.254

A

R2(config)# ip route 172.16.2.0 255.255.255.0 172.16.3.1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

5 Refer to the exhibit. R1 was configured with the static route command ip route 209.165.200.224 255.255.255.224 S0/0/0 and consequently users on network 172.16.0.0/16 are unable to reach resources on the Internet. How should this static route be changed to allow user traffic from the LAN to reach the Internet?

Add the next-hop neighbor address of 209.165.200.226.
Change the exit interface to S0/0/1.
Change the destination network and mask to 0.0.0.0 0.0.0.0.
Add an administrative distance of 254.

A

Change the destination network and mask to 0.0.0.0 0.0.0.0. *

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

6 A router has used the OSPF protocol to learn a route to the 172.16.32.0/19 network. Which command will implement a backup floating static route to this network?

ip route 172.16.0.0 255.255.240.0 S0/0/0 200
ip route 172.16.32.0 255.255.224.0 S0/0/0 200
ip route 172.16.0.0 255.255.224.0 S0/0/0 100
ip route 172.16.32.0 255.255.0.0 S0/0/0 100

A

ip route 172.16.32.0 255.255.224.0 S0/0/0 200*

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

7 Refer to the exhibit. Router R1 has an OSPF neighbor relationship with the ISP router over the 192.168.0.32 network. The 192.168.0.36 network link should serve as a backup when the OSPF link goes down. The floating static route command ip route 0.0.0.0 0.0.0.0 S0/0/1 100 was issued on R1 and now traffic is using the backup link even when the OSPF link is up and functioning. Which change should be made to the static route command so that traffic will only use the OSPF link when it is up?​

Add the next hop neighbor address of 192.168.0.36.
Change the administrative distance to 1.
Change the destination network to 192.168.0.34.
Change the administrative distance to 120.

A

Change the administrative distance to 120.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

8 Which statement describes a route that has been learned dynamically?

It is automatically updated and maintained by routing protocols.
It is unaffected by changes in the topology of the network.
It has an administrative distance of 1.
It is identified by the prefix C in the routing table.

A

It is automatically updated and maintained by routing protocols.*

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

9 Compared with dynamic routes, what are two advantages of using static routes on a router? (Choose two.)

They improve netw​ork security.
They use fewer router resources.
They improve the efficiency of discovering neighboring networks.
They take less time to converge when the network topology changes.
They automatically switch the path to the destination network when the topology changes.

A

They improve netw​ork security.*

They use fewer router resources.*

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

10 Refer to the exhibit. All hosts and router interfaces are configured correctly. Pings to the server from both H1 and H2 and pings between H1 and H2 are not successful. What is causing this problem?

RIPv2 does not support VLSM.
RIPv2 is misconfigured on router R1.
RIPv2 is misconfigured on router R2.
RIPv2 is misconfigured on router R3.
RIPv2 does not support discontiguous networks.
A

RIPv2 is misconfigured on router R2.*

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

12 A network administrator reviews the routing table on the router and sees a route to the destination network 172.16.64.0/18 with a next-hop IP address of 192.168.1.1. What are two descriptions of this route? (Choose two.)

default route
supernet route
ultimate route
parent route
level 2 child route
A

ultimate route

level 2 child route

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

13 Which two factors are important when deciding which interior gateway routing protocol to use? (Choose two.)

scalability
ISP selection
speed of convergence
the autonomous system that is used
campus backbone architecture
A

scalability

speed of convergence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

14 What is a basic function of the Cisco Borderless Architecture access layer?

aggregates Layer 2 broadcast domains
aggregates Layer 3 routing boundaries
provides access to the user
provides fault isolation

A

provides access to the user*

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

16 What will a Cisco LAN switch do if it receives an incoming frame and the destination MAC address is not listed in the MAC address table?

Drop the frame.
Send the frame to the default gateway address.
Use ARP to resolve the port that is related to the frame.
Forward the frame out all ports except the port where the frame is received.

A

Forward the frame out all ports except the port where the frame is received

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

17 Which advantage does the store-and-forward switching method have compared with the cut-through switching method?

collision detecting
frame error checking
faster frame forwarding
frame forwarding using IPv4 Layer 3 and 4 information

A

frame error checking

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

18 Which switching method drops frames that fail the FCS check?

borderless switching
cut-through switching
ingress port buffering
store-and-forward switching

A

store-and-forward switching

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

19 In what situation would a Layer 2 switch have an IP address configured?

when the Layer 2 switch needs to forward user traffic to another device
when the Layer 2 switch is the default gateway of user traffic
when the Layer 2 switch needs to be remotely managed
when the Layer 2 switch is using a routed port

A

when the Layer 2 switch needs to be remotely managed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

20 A network administrator is configuring a new Cisco switch for remote management access. Which three items must be configured on the switch for the task? (Choose three.)

IP address   
VTP domain
vty lines
default VLAN
default gateway
loopback address
A

IP address

vty lines

default gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

21 As part of the new security policy, all switches on the network are configured to automatically learn MAC addresses for each port. All running configurations are saved at the start and close of every business day. A severe thunderstorm causes an extended power outage several hours after the close of business. When the switches are brought back online, the dynamically learned MAC addresses are retained. Which port security configuration enabled this?

auto secure MAC addresses
dynamic secure MAC addresses
static secure MAC addresses
sticky secure MAC addresses

A

sticky secure MAC addresses*

20
Q

22 A network administrator is configuring port security on a Cisco switch. The company security policy specifies that when a violation occurs, packets with unknown source addresses should be dropped and no notification should be sent. Which violation mode should be configured on the interfaces?

off
restrict
protect
shutdown

A

protect*

21
Q

23 What caused the following error message to appear?

01: 11:12: %PM-4-ERR_DISABLE: psecure-violation error detected on Fa0/8, putting Fa0/8 in err-disable state
01: 11:12: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occurred, caused by MAC address 0011.a0d4.12a0 on port FastEthernet0/8.
01: 11:13: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/8, changed state to down
01: 11:14: %LINK-3-UPDOWN: Interface FastEthernet0/8, changed state to down

Another switch was connected to this switch port with the wrong cable.
An unauthorized user tried to telnet to the switch through switch port Fa0/8.
NAT was enabled on a router, and a private IP address arrived on switch port Fa0/8.
A host with an invalid IP address was connected to a switch port that was previously unused.
Port security was enabled on the switch port, and an unauthorized connection was made on switch port Fa0/8.

A

Port security was enabled on the switch port, and an unauthorized connection was made on switch port Fa0/8.*

22
Q

24 Refer to the exhibit. A small business uses VLANs 2, 3, 4, and 5 between two switches that have a trunk link between them. What native VLAN should be used on the trunk if Cisco best practices are being implemented?

1
2
3
4
5
6
A

6*

23
Q

25 Which statement describes a characteristic of the extended range VLANs that are created on a Cisco 2960 switch?

They are numbered VLANs 1002 to 1005.
They cannot be used across multiple switches.
They are reserved to support Token Ring VLANs.
They are not stored in the vlan.dat file.

A

They are not stored in the vlan.dat file.*

24
Q

26 A network administrator is using the router-on-a-stick method to configure inter-VLAN routing. Switch port Gi1/1 is used to connect to the router. Which command should be entered to prepare this port for the task?

Switch(config)# interface gigabitethernet 1/1
Switch(config-if)# spanning-tree vlan 1

Switch(config)# interface gigabitethernet 1/1
Switch(config-if)# spanning-tree portfast

Switch(config)# interface gigabitethernet 1/1
Switch(config-if)# switchport mode trunk

Switch(config)# interface gigabitethernet 1/1
Switch(config-if)# switchport access vlan 1

A

Switch(config)# interface gigabitethernet 1/1

Switch(config-if)# switchport mode trunk***

25
Q

27 A network administrator is configuring an ACL with the command access-list 10 permit 172.16.32.0 0.0.15.255. Which IPv4 address matches the ACE?

  1. 16.20.2
  2. 16.26.254
  3. 16.47.254
  4. 16.48.5
A

172.16.47.254

26
Q

28 The computers used by the network administrators for a school are on the 10.7.0.0/27 network. Which two commands are needed at a minimum to apply an ACL that will ensure that only devices that are used by the network administrators will be allowed Telnet access to the routers? (Choose two.)

access-class 5 in

access-list 5 deny any

access-list standard VTY
permit 10.7.0.0 0.0.0.127

access-list 5 permit 10.7.0.0 0.0.0.31

ip access-group 5 out

ip access-group 5 in

A

access-class 5 in*

access-list 5 permit 10.7.0.0 0.0.0.31*

27
Q

29 A network engineer has created a standard ACL to control SSH access to a router. Which command will apply the ACL to the VTY lines?

access-group 11 in
access-class 11 in
access-list 11 in
access-list 110 in

A

access-class 11 in*

28
Q

30 What is the reason why the DHCPREQUEST message is sent as a broadcast during the DHCPv4 process?

to notify other DHCP servers on the subnet that the IP address was leased
to notify other hosts not to request the same IP address
for hosts on other subnets to receive the information
for routers to fill their routing tables with this new information

A

to notify other DHCP servers on the subnet that the IP address was leased*

29
Q

31 What will be the result of adding the command ip dhcp excluded-address 172.16.4.1 172.16.4.5 to the configuration of a local router that has been configured as a DHCP server?

Traffic that is destined for 172.16.4.1 and 172.16.4.5 will be dropped by the router.
Traffic will not be routed from clients with addresses between 172.16.4.1 and 172.16.4.5.
The DHCP server function of the router will not issue the addresses from 172.16.4.1 through 172.16.4.5 inclusive.
The router will ignore all traffic that comes from the DHCP servers with addresses 172.16.4.1 and 172.16.4.5.

A

The DHCP server function of the router will not issue the addresses from 172.16.4.1 through 172.16.4.5 inclusive.*

30
Q

32 A host on the 10.10.100.0/24 LAN is not being assigned an IPv4 address by an enterprise DHCP server with the address 10.10.200.10/24. What is the best way for the network engineer to resolve this problem?

Issue the command ip helper-address 10.10.200.10 on the router interface that is the 10.10.100.0/24 gateway.
Issue the command default-router 10.10.200.10 at the DHCP configuration prompt on the 10.10.100.0/24 LAN gateway router.
Issue the command ip helper-address 10.10.100.0 on the router interface that is the 10.10.200.0/24 gateway.
Issue the command network 10.10.200.0 255.255.255.0 at the DHCP configuration prompt on the 10.10.100.0/24 LAN gateway router.

A

Issue the command ip helper-address 10.10.200.10 on the router interface that is the 10.10.100.0/24 gateway.*

31
Q

33 What is used in the EUI-64 process to create an IPv6 interface ID on an IPv6 enabled interface?

the MAC address of the IPv6 enabled interface
a randomly generated 64-bit hexadecimal address
an IPv6 address that is provided by a DHCPv6 server
an IPv4 address that is configured on the interface

A

the MAC address of the IPv6 enabled interface*

32
Q

34 Refer to the exhibit. Which statement shown in the output allows router R1 to respond to stateless DHCPv6 requests?

ipv6 unicast-routing
dns-server 2001:DB8:8::8​
ipv6 dhcp server LAN1​
ipv6 nd other-config-flag
prefix-delegation 2001:DB8:8::/48 00030001000E84244E70
A

ipv6 nd other-config-flag*​

33
Q

35 Refer to the exhibit. NAT is configured on Remote and Main. The PC is sending a request to the web server. What IPv4 address is the source IP address in the packet between Main and the web server?

  1. 130.5.76
  2. 165.200.245
  3. 0.113.5
  4. 16.1.10
  5. 0.2.1
  6. 165.200.226
A

203.0.113.5*

34
Q

36 Refer to the exhibit. NAT is configured on RT1 and RT2. The PC is sending a request to the web server. What IPv4 address is the source IP address in the packet between RT2 and the web server?

  1. 0.2.2
  2. 16.1.10
  3. 0.113.10
  4. 16.1.254
  5. 168.1.5
  6. 165.200.245
A

209.165.200.245*

35
Q

37 Refer to the exhibit. Which two statements are correct based on the output as shown in the exhibit? (Choose two.)

The output is the result of the show ip nat translations command.
The host with the address 209.165.200.235 will respond to requests by using a source address of 192.168.10.10.
The host with the address 209.165.200.235 will respond to requests by using a source address of 209.165.200.235.
Traffic with the destination address of a public web server will be sourced from the IP of 192.168.1.10.
The output is the result of the show ip nat statistics command.

A

The output is the result of the show ip nat translations command.
The host with the address 209.165.200.235 will respond to requests by using a source address of 192.168.10.10.

36
Q

38 Refer to the exhibit. A company has an internal network of 172.16.25.0/24 for their employee workstations and a DMZ network of 172.16.12.0/24 to host servers. The company uses NAT when inside hosts connect to outside network. A network administrator issues the show ip nat translations command to check the NAT configurations. Which one of source IPv4 addresses is translated by R1 with PAT?

  1. 0.0.31
  2. 16.12.5
  3. 16.12.33
  4. 16.25.35
  5. 168.1.10
A

172.16.25.35

37
Q

39 What benefit does NAT64 provide?

It allows sites to use private IPv6 addresses and translates them to global IPv6 addresses.
It allows sites to connect multiple IPv4 hosts to the Internet via the use of a single public IPv4 address.
It allows sites to connect IPv6 hosts to an IPv4 network by translating the IPv6 addresses to IPv4 addresses.
It allows sites to use private IPv4 addresses, and thus hides the internal addressing structure from hosts on public IPv4 networks.

A

It allows sites to connect IPv6 hosts to an IPv4 network by translating the IPv6 addresses to IPv4 addresses.*

38
Q

40 A network engineer is interested in obtaining specific information relevant to the operation of both distribution and access layer Cisco devices. Which command provides common information relevant to both types of devices?

show ip protocols
show ip interface
show cdp neighbors
show port-security
show mac-address-table
A

show cdp neighbors

39
Q

41 What are three functions provided by the syslog service? (Choose three.)

to gather logging information for monitoring and troubleshooting
to select the type of logging information that is captured
to specify the destinations of captured messages
to periodically poll agents for data
to provide statistics on packets that are flowing through a Cisco device
to provide traffic analysis

A

to gather logging information for monitoring and troubleshooting*
to select the type of logging information that is captured
to specify the destinations of captured messages

40
Q

42 A network administrator is verifying a configuration that involves network monitoring. What is the purpose of the global configuration command logging trap 4?

System messages will be forwarded to the number following the logging trap argument.
System messages that exist in levels 4-7 must be forwarded to a specific logging server.
System messages that match logging levels 0-4 will be forwarded to a specified logging device.
System messages will be forwarded using a SNMP version that matches the argument that follows the logging trap command.

A

System messages that match logging levels 0-4 will be forwarded to a specified logging device.*

41
Q

43 Refer to the exhibit. An administrator is examining the message in a syslog server. What can be determined from the message?

This is a notification message for a normal but significant condition.
This is an alert message for which immediate action is needed.
This is an error message for which warning conditions exist.
This is an error message that indicates the system is unusable.

A

This is a notification message for a normal but significant condition.*

42
Q

44 What is the purpose of the Cisco PAK?

It is a key for enabling an IOS feature set.
It is a proprietary encryption algorithm.
It is a compression file type used when installing IOS 15 or an IOS upgrade.
It is a way to compress an existing IOS so that a newer IOS version can be co-installed on a router.

A

It is a key for enabling an IOS feature set.*

43
Q

45 Refer to the exhibit. An administrator is trying to configure PAT on R1, but PC-A is unable to access the Internet. The administrator tries to ping a server on the Internet from PC-A and collects the debugs that are shown in the exhibit. Based on this output, what is most likely the cause of the problem?

The address on Fa0/0 should be 64.100.0.1.
The NAT source access list matches the wrong address range.
The inside global address is not on the same subnet as the ISP.
The inside and outside NAT interfaces have been configured backwards.

A

The inside global address is not on the same subnet as the ISP.*

44
Q

46 Refer to the exhibit. Which three hosts will receive ARP requests from host A, assuming that port Fa0/4 on both switches is configured to carry traffic for multiple VLANs? (Choose three.)

host B
host C    
host D 
host E
host F
host G
A

host C*
host D*
host F*

45
Q

47 Refer to the exhibit. The network administrator enters these commands into the

R1 router:
R1# copy running-config tftp
Address or name of remote host [ ]?

When the router prompts for an address or remote host name, what IP address should the administrator enter at the prompt?

  1. 168.9.254
  2. 168.10.1
  3. 168.10.2
  4. 168.11.252
  5. 168.11.254
A

192.168.11.252*

46
Q

48 Refer to the exhibit. Based on the exhibited configuration and output, why is VLAN 99 missing?

because there is a cabling problem on VLAN 99
because VLAN 99 is not a valid management VLAN
because VLAN 1 is up and there can only be one management VLAN on the switch
because VLAN 99 has not yet been created

A

because VLAN 99 has not yet been created*