New Questions - Part 5 Flashcards
+ detects suspicious web activity: Web Security Appliance
+ analyzes network behavior and detects anomalies: StealthWatch
+ uses pxGrid to remediate security threats: Identity Services Engine
What are two characteristics of Cisco SD-Access elements? (Choose two)
A. Fabric endpoints are connected directly to the border node
B. The border node is required for communication between fabric and nonfabric devices
C. The control plane node has the full RLOC-to-EID mapping database
D. Traffic within the fabric always goes through the control plane node
E. The border node has the full RLOC-to-EID mapping database
B. The border node is required for communication between fabric and nonfabric devices
C. The control plane node has the full RLOC-to-EID mapping database
Refer to the exhibit.
Current configuration: 142 bytes vrf definition STAFF ! ! interface GigabitEthernet1 vrf forwarding STAFF no ip address negotiation auto no mop enabled no mop sysid end
An engineer must assign an IP address of 192.168.1.1/24 to the GigabitEthemet1 interface. Which two commands must be added to the existing configuration to accomplish this task? (Choose two)
A. Router(config-vrf)#address-family ipv6
B. Router(config-if)#ip address 192.168.1.1 255.255.255.0
C. Router(config-vrf)#ip address 192.168.1.1 255.255.255.0
D. Router(config-if)#address-family ipv4
E. Router(config-vrf)#address-family ipv4
B. Router(config-if)#ip address 192.168.1.1 255.255.255.0
E. Router(config-vrf)#address-family ipv4
What is the data policy in a Cisco SD-WAN deployment?
A. list of ordered statements that define node configurations and authentication used within the SD-WAN overlay
B. Set of statements that defines how data is forwarded based on IP packet information and specific VPNs
C. detailed database mapping several kinds of addresses with their corresponding location
D. group of services tested to guarantee devices and links liveliness within the SD-WAN overlay
B. Set of statements that defines how data is forwarded based on IP packet information and specific VPNs
Refer to the exhibit.
Which action resolves the EtherChannel issue between SW2 and SW3?
A. Configure switchport mode trunk on SW2
B. Configure switchport nonegotiate on SW3
C. Configure channel-group 1 mode desirable on both interfaces
D. Configure channel-group 5 mode active on both interfaces
C. Configure channel-group 1 mode desirable on both interfaces
Refer to the exhibit.
A network engineer configures OSPF and reviews the router configuration. Which interface or interfaces are able to establish OSPF adjacency?
A. GigabitEthemet0/1 and GigabitEthernet0/1.40
B. Gigabit Ethernet0/0 and GigabitEthemet0/1
C. only GigabitEthernet0/0
D. only GigabitEthernet0/1
C. only GigabitEthernet0/0
Refer to the exhibit.
Postman_error_show_control_connections.jpg
Postman_error.jpg
What step resolves the authentication issue?
A. restart the vsmart host
B. target 192.168.100.82 in the URI
C. change the port to 12446
D. use basic authentication
B. target 192.168.100.82 in the URI
Refer to the exhibit.
A network engineer must simplify the IPsec configuration by enabling IPsec over GRE using IPsec profiles. Which two configuration changes accomplish this? (Choose two)
A. Apply the crypto map to the tunnel interface and change the tunnel mode to tunnel mode ipsec ipv4
B. Remove all configuration related to crypto map from R1 and R2 and eliminate the ACL 100
C. Remove the crypto map and modify the ACL to allow traffic between 10.10.0.0/24 to 10.20.0.0/24
D. Create an IPsec profile, associate the transform-set, and apply the profile to the tunnel interface
B. Remove all configuration related to crypto map from R1 and R2 and eliminate the ACL 100
D. Create an IPsec profile, associate the transform-set, and apply the profile to the tunnel interface
Which encryption hashing algorithm does NTP use for authentication?
A. SSL
B. AES256
C. AES128
D. MD5
D. MD5
What is a VPN in a Cisco SD-WAN deployment?
A. virtual channel used to carry control plane information
B. attribute to identify a set of services offered in specific places in the SD-WAN fabric
C. common exchange point between two different services
D. virtualized environment that provides traffic isolation and segmentation in the SD-WAN fabric
D. virtualized environment that provides traffic isolation and segmentation in the SD-WAN fabric
Ansible:
+ uses playbooks
+ procedural
Puppet:
+ uses a pull model
+ declarative
Refer to the exhibit.
Communication between London and New York is down. Which command set must be applied to resolve this issue?
A.
NewYork(config)#int f0/1
NewYork(config)#switchport nonegotiate
NewYork(config)#end
NewYork#
B.
NewYork(config)#int f0/1
NewYork(config)#switchport trunk encap dot1q
NewYork(config)#end
NewYork#
C.
NewYork(config)#int f0/1
NewYork(config)#switchport mode dynamic desirable
NewYork(config)#end
NewYork#
D.
NewYork(config)#int f0/1
NewYork(config)#switchport mode trunk
NewYork(config)#end
NewYork#
B.
NewYork(config)#int f0/1
NewYork(config)#switchport trunk encap dot1q
NewYork(config)#end
NewYork#
Refer to the exhibit.
Communication between London and New York is down. Which command set must be applied to resolve this issue?
A.
NewYork(config)#int f0/1
NewYork(config)#switchport nonegotiate
NewYork(config)#end
NewYork#
B.
NewYork(config)#int f0/1
NewYork(config)#switchport trunk encap dot1q
NewYork(config)#end
NewYork#
C.
NewYork(config)#int f0/1
NewYork(config)#switchport mode dynamic desirable
NewYork(config)#end
NewYork#
D.
NewYork(config)#int f0/1
NewYork(config)#switchport mode trunk
NewYork(config)#end
NewYork#
B.
NewYork(config)#int f0/1
NewYork(config)#switchport trunk encap dot1q
NewYork(config)#end
NewYork#
What is an emulated machine that has dedicated compute, memory, and storage resources and a fully installed operating system?
A. host
B. virtual machine
C. container
D. mainframe
B. virtual machine
Which two methods are used to reduce the AP coverage area? (Choose two)
A. Reduce AP transmit power
B. Increase minimum mandatory data rate
C. Reduce channel width from 40 MHz to 20 MHz
D. Enable Fastlane
E. Disable 2.4 GHz and use only 5 GHz
A. Reduce AP transmit power
B. Increase minimum mandatory data rate
VSS:
+ supported on the Cisco 4500 and 6500 series
+ combines exactly two devices
+ supports devices that are geographically separated
Explanation
The following characteristics are correct for StackWise (but not VSS):
+ can be connected in up to 9 devices
+ is supported only on line 3750 and (2960/3650/3850/3750+)
+ uses proprietary cable for connection
Refer to the exhibit.
All switches are configured with the default port priority value. Which two commands ensure that traffic from PC1 is forwarded over Gi1/3 trunk port between DSW1 and DSW2? (Choose two)
A. DWS1(config-if)#spanning-tree port-priority 0
B. DSW2(config-if)#spanning-tree port-priority 16
C. DSW1(config-if)#interface gi1/3
D. DSW2(config-if)#interface gi1/3
E. DSW2(config-if)#spanning-tree port-priority 128
B. DSW2(config-if)#spanning-tree port-priority 16
D. DSW2(config-if)#interface gi1/3
In a three-tier hierarchical campus network design, which action is a design best-practice for the core layer?
A. provide QoS prioritization services such as marking, queueing, and classification for critical network traffic
B. provide advanced network security features such as 802. IX, DHCP snooping, VACLs, and port security
C. provide redundant Layer 3 point-to-point links between the core devices for more predictable and faster convergence
D. provide redundant aggregation for access layer devices and first-hop redundancy protocols such as VRRP
C. provide redundant Layer 3 point-to-point links between the core devices for more predictable and faster convergence
Which two network problems indicate a need to implement QoS in a campus network? (Choose two)
A. port flapping
B. misrouted network packets
C. excess jitter
D. bandwidth-related packet loss
E. duplicate IP addresses
C. excess jitter
D. bandwidth-related packet loss
In a Cisco SD-Access solution, what is the role of the Identity Services Engine?
A. It provides GUI management and abstraction via apps that share context.
B. It is leveraged for dynamic endpoint to group mapping and policy definition.
C. It is used to analyze endpoint to app flows and monitor fabric status.
D. It manages the LISP EID database.
B. It is leveraged for dynamic endpoint to group mapping and policy definition.
A customer has completed the installation of a Wi-Fi 6 greenfield deployment at their new campus. They want to leverage Wi-Fi 6 enhanced speeds on the trusted employee WLAN. To configure the employee WLAN, which two Layer 2 security policies should be used? (Choose two)
A. WPA (AES)
B. WPA2 (AES) + WEP
C. 802.1X
D. OPEN
C. 802.1X
D. OPEN