SM.2 Flashcards

1
Q

Refer to the exhibit. What will router R1 do with a packet that has a destination IPv6 address of 2001:db8:cafe:5::1?

A

forward the packet out Serial0/0/0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Refer to the exhibit. Currently router R1 uses an EIGRP route learned from Branch2 to reach the 10.10.0.0/16 network. Which floating static route would create a backup route to the 10.10.0.0/16 network in the event that the link between R1 and Branch2 goes down? Your AD has to be higher than EIGRP(90). OSPF is 110.

A

ip route 10.10.0.0 255.255.0.0 209.165.200.225 100

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Refer to the exhibit. R1 was configured with the static route command ip route 209.165.200.224 255.255.255.224 S0/0/0 and consequently users on network 172.16.0.0/16 are unable to reach resources on the Internet. How should this static route be changed to allow user traffic from the LAN to reach the Internet?

A

Change the destination network and mask to 0.0.0.0 0.0.0.0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which option shows a correctly configured IPv4 default static route?

A

ip route 0.0.0.0 0.0.0.0 S0/0/0 this is the default static route that match all destination networks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Refer to the exhibit. Which static route command can be entered on R1 to forward traffic to the LAN connected to R2?

A

ipv6 route 2001:db8:12:10::/64 S0/0/1 fe80::2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A cybersecurity analyst is using the macof tool to evaluate configurations of switches deployed in the backbone network of an organization. Which type of LAN attack is the analyst targeting during this evaluation?

A

MAC address table overflow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a method to launch a VLAN hopping attack?

A

introducing a rogue switch and enabling trunking

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Refer to the exhibit. A network administrator is configuring a router as a DHCPv6 server. The administrator issues a show ipv6 dhcp pool command to verify the configuration. Which statement explains the reason that the number of active clients is 0?

A

The state is not maintained by the DHCPv6 server under stateless DHCPv6 operation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Refer to the exhibit. A network administrator configured routers R1 and R2 as part of HSRP group 1. After the routers have been reloaded, a user on Host1 complained of lack of connectivity to the Internet. The network administrator issued the show standby brief command on both routers to verify the HSRP operations. In addition, the administrator observed the ARP table on Host1. Which entry should be seen in the ARP table on Host1 in order to gain connectivity to the Internet?

A

the virtual IP address and the virtual MAC address for the HSRP group 1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Match the forwarding characteristic to its type. (Not all options are used.)

A

cut-through:
-Appropriate for high performance computing applications
-forwarding process can begin after receiving DESTINATION ADDRESS
-may forward INVALID frames

store-and-forward:
-error checking before –
-forwarding process can begin after receiving ENTIRE FRAME
-only forwards VALID frames

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which statement is correct about how a Layer 2 switch determines how to forward frames?

A
  • Frame forwarding decisions are based on MAC address and port mappings in the CAM table.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

. Which statement describes a result after multiple Cisco LAN switches are interconnected?

A
  • The broadcast domain expands to all switches
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Match the link state to the interface and protocol status. (Not all options are used.)

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Refer to the exhibit. How is a frame sent from PCA forwarded to PCC if the MAC address table on switch SW1 is empty?

A

SW1 floods the frame on all ports on SW1, excluding the port through which the frame entered the switch.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

An administrator is trying to remove configurations from a switch. After using the command erase startup-config and reloading the switch, the administrator finds that VLANs 10 and 100 still exist on the switch. Why were these VLANs not removed?

A

Because these VLANs are stored in a file that is called vlan.dat that is located in flash memory, this file must be manually deleted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Match the description to the correct VLAN type. (Not all options are used.)

A
  • Configure to carry user –> data VLAN
  • all switchports are assigned to this VLAN –> default VLAN
  • carries untagged traffic –> native VLAN
  • an IP address and subnet mask are assigned to this VLAN –> management VLAN
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Refer to the exhibit. A network administrator has connected two switches together using EtherChannel technology. If STP is running, what will be the end result?

A

STP will block one of the redundant links

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is a secure configuration option for remote access to a network device?

A

Configure SSH

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Which wireless encryption method is the most secure?

A

WPA2 with AES

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

After attaching four PCs to the switch ports, configuring the SSID and setting authentication properties for a small office network, a technician successfully tests the connectivity of all PCs that are connected to the switch and WLAN. A firewall is then configured on the device prior to connecting it to the Internet. What type of network device includes all of the described features?

A

wireless router

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Refer to the exhibit. Host A has sent a packet to host B. What will be the source MAC and IP addresses on the packet when it arrives at host B?

A

Source MAC: 00E0.FE91.7799
Source IP: 10.1.1.10

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Refer to the exhibit. In addition to static routes directing traffic to networks 10.10.0.0/16 and 10.20.0.0/16, Router HQ is also configured with the following command: ip route 0.0.0.0.0.0.0.0 serial 0/1/1

A

Packets with a destination network that is not 10.10.0.0/16 or is not 10.20.0.0/16 or is not a directly connected network will be forwarded to the Internet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What protocol or technology disables redundant paths to eliminate Layer 2 loops?

A

STP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Refer to the exhibit. Based on the exhibited configuration and output, why is VLAN 99 missing?

A

because VLAN 99 has not yet been created

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Which two VTP modes allow for the creation, modification, and deletion of VLANs on the local switch? (Choose two.)

A
  • server
  • transparent
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Which three steps should be taken before moving a Cisco switch to a new VTP management domain? (Choose three.)

A
  • Configure the switch with the name of the new management domain
  • Select the correct VTP mode and version.
  • Reboot the switch.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

A network administrator is preparing the implementation of Rapid PVST+ on a production network. How are the Rapid PVST+ link types determined on the switch interfaces?

A

Link types are determined automatically

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Refer to the exhibit. All the displayed switches are Cisco 2960 switches with the same default priority and operating at the same bandwidth. Which three ports will be STP designated ports? (Choose three.)

A
  • fa0/13
  • fa0/10
  • fa0/21
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

How will a router handle static routing differently if Cisco Express Forwarding is disabled?

A

Ethernet multiaccess interfaces will require fully specified static routes to avoid routing inconsistencies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Compared with dynamic routes, what are two advantages of using static routes on a router? (Choose two.)

A
  • They improve network security.
  • They use fewer router resources
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Refer to the exhibit. Which route was configured as a static route to a specific network using the next-hop address?

A

S 10.17.2.0/24 [1/0] via 10.16.2.2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

What is the effect of entering the spanning-tree portfast configuration command on a switch?

A

It enables portfast on a specific switch interface.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

What is the IPv6 prefix that is used for link-local addresses?

A
  • FE80::/10
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Which two statements are characteristics of routed ports on a multilayer switch? (Choose two.)

A
  • In a switched network, they are mostly configured between switches at the core and distribution layers.
  • They are not associated with a particular VLAN.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Successful inter-VLAN routing has been operating on a network with multiple VLANs across multiple switches for some time. When an inter-switch trunk link fails and Spanning Tree Protocol brings up a backup trunk link, it is reported that hosts on two VLANs can access some, but not all the network resources that could be accessed previously. Hosts on all other VLANS do not have this problem. What is the most likely cause of this problem?

A

The protected edge port function on the backup trunk interfaces has been disabled.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Which command will start the process to bundle two physical interfaces to create an EtherChannel group via LACP?

A

interface range GigabitEthernet 0/4 – 5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

What action takes place when a frame entering a switch has a multicast destination MAC address?

A

The switch will forward the frame out all ports except the incoming port.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

A junior technician was adding a route to a LAN router. A traceroute to a device on the new network revealed a wrong path and unreachable status. What should be done or checked?

A

Check the configuration of the exit interface on the new static route.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

Select the three PAgP channel establishment modes. (Choose three.)

A
  • auto
  • desirable
  • on
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

A static route has been configured on a router. However, the destination network no longer exists. What should an administrator do to remove the static route from the routing table?

A

Remove the route using the no ip route command.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

Refer to the exhibit. What can be concluded about the configuration shown on R1?

A

R1 is configured as a DHCPv4 relay agent.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

Match the step to each switch boot sequence description. (Not all options are used.)

A
  • perform low-level CPU Initialization: STEP 3
  • execute POST: STEP 1
  • flash file system initialization: STEP 4
  • load and boot loader from ROM: STEP 2
  • load the IOS: STEP 5
  • transfer switch control to the IOS: STEP 6
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

Refer to the exhibit. R1 has been configured as shown. However, PC1 is not able to receive an IPv4 address. What is the problem?

A

The ip helper-address command was applied on the wrong interface

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

What two default wireless router settings can affect network security? (Choose two.)

A
  • The SSID is broadcast.
  • A well-known administrator password is set.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

What is the common term given to SNMP log messages that are generated by network devices and sent to the SNMP server?

A

traps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

A network administrator is adding a new WLAN on a Cisco 3500 series WLC. Which tab should the administrator use to create a new VLAN interface to be used for the new WLAN?

A

CONTROLLER

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

A network administrator is configuring a WLAN. Why would the administrator change the default DHCP IPv4 addresses on an AP?

A

to reduce outsiders intercepting data or accessing the wireless network by using a well-known address range

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

Which two functions are performed by a WLC when using split media access control (MAC)? (Choose two.)

A
  • frame translation to other protocols
  • association and re-association of roaming clients
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

On what switch ports should BPDU guard be enabled to enhance STP stability?

A

all PortFast-enabled ports

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

Which network attack is mitigated by enabling BPDU guard?

A

rogue switches on a network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
51
Q

Why is DHCP snooping required when using the Dynamic ARP Inspection feature?

A

It uses the MAC-address-to-IP-address binding database to validate an ARP packet.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
52
Q

Refer to the exhibit. Router R1 has an OSPF neighbor relationship with the ISP router over the 192.168.0.32 network. The 192.168.0.36 network link should serve as a backup when the OSPF link goes down. The floating static route command ip route 0.0.0.0 0.0.0.0 S0/0/1 100 was issued on R1 and now traffic is using the backup link even when the OSPF link is up and functioning. Which change should be made to the static route command so that traffic will only use the OSPF link when it is up?

A

Change the administrative distance to 120.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
53
Q

Refer to the exhibit. What is the metric to forward a data packet with the IPv6 destination address 2001:DB8:ACAD:E:240:BFF:FED4:9DD2?

A

2682112

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
54
Q

A network administrator is configuring a new Cisco switch for remote management access. Which three items must be configured on the switch for the task? (Choose three.)

A
  • IP address
  • vty lines
  • default gateway
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
55
Q

Refer to the exhibit. Which statement shown in the output allows router R1 to respond to stateless DHCPv6 requests?

A

ipv6 nd other-config-flag

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
56
Q

Refer to the exhibit. A Layer 3 switch routes for three VLANs and connects to a router for Internet connectivity. Which two configurations would be applied to the switch? (Choose two.)

A
  1. (config)# interface gigabitethernet 1/1
    (config-if)# no switchport
    (config-if)# ip address 192.168.1.2 255.255.255.252
  2. (config)# ip routing
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
57
Q

A technician is troubleshooting a slow WLAN and decides to use the split-the-traffic approach. Which two parameters would have to be configured to do this? (Choose two.)

A
  • Configure the 5 GHz band for streaming multimedia and time sensitive traffic.
  • Configure the 2.4 GHz band for basic internet traffic that is not time sensitive.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
58
Q

A company has just switched to a new ISP. The ISP has completed and checked the connection from its site to the company. However, employees at the company are not able to access the internet. What should be done or checked?

A

Ensure that the old default route has been removed from the company edge routers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
59
Q

Which information does a switch use to populate the MAC address table?

A

the source MAC address and the incoming port

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
60
Q

Refer to the exhibit. A network administrator is reviewing the configuration of switch S1. Which protocol has been implemented to group multiple physical ports into one logical link?

A

PAgP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
61
Q

Which type of static route is configured with a greater administrative distance to provide a backup route to a route learned from a dynamic routing protocol?

A

floating static route

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
62
Q

What action takes place when a frame entering a switch has a unicast destination MAC address appearing in the MAC address table?

A

The switch forwards the frame out of the specified port.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
63
Q

The exhibit shows two PCs called PC A and PC B, two routes called R1 and R2, and two switches. PC A has the address 172.16.1.1/24 and is connected to a switch and into an interface on R1 that has the IP address 172.16.1.254. PC B has the address 172.16.2.1/24 and is connected to a switch that is connected to another interface on R1 with the IP address 172.16.2.254. The serial interface on R1 has the address 172.16.3.1 and is connected to the serial interface on R2 that has the address 172.16.3.2/24. R2 is connected to the internet cloud. Which command will create a static route on R2 in order to reach PC B?

A

R2(config)# ip route 172.16.2.0 255.255.255.0 172.16.3.1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
64
Q

What protocol or technology allows data to transmit over redundant switch links?

A

EtherChannel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
65
Q

Refer to the exhibit. Which three hosts will receive ARP requests from host A, assuming that port Fa0/4 on both switches is configured to carry traffic for multiple VLANs? (Choose three.)

A
  • host C
  • host D
  • host F
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
66
Q

Refer to the exhibit. The network administrator configures both switches as displayed. However, host C is unable to ping host D and host E is unable to ping host F. What action should the administrator take to enable this communication?

A

Configure either trunk port in the dynamic desirable mode

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
67
Q

What is the effect of entering the shutdown configuration command on a switch?

A

It disables an unused port.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
68
Q

What would be the primary reason an attacker would launch a MAC address overflow attack?

A

so that the attacker can see frames that are destined for other hosts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
69
Q

During the AAA process, when will authorization be implemented?

A

Immediately after successful authentication against an AAA data source

70
Q

A company security policy requires that all MAC addressing be dynamically learned and added to both the MAC address table and the running configuration on each switch. Which port security configuration will accomplish this?

A

sticky secure MAC addresses

71
Q

Which three Wi-Fi standards operate in the 2.4GHz range of frequencies? (Choose three.)

A
  • 802.11b
  • 802.11g
  • 802.11n
72
Q

To obtain an overview of the spanning tree status of a switched network, a network engineer issues the show spanning-tree command on a switch. Which two items of information will this command display? (Choose two.)

A
  • The root bridge BID.
  • The role of the ports in all VLANs.
73
Q

Refer to the exhibit. Which trunk link will not forward any traffic after the root bridge election process is complete?

A

Trunk2

74
Q

Which method of IPv6 prefix assignment relies on the prefix contained in RA messages?

A

SLAAC

75
Q

Which two protocols are used to provide server-based AAA authentication? (Choose two.)

A
  • TACACS+
  • RADIUS
76
Q

A network administrator is configuring a WLAN. Why would the administrator disable the broadcast feature for the SSID?

A

to eliminate outsiders scanning for available SSIDs in the area

77
Q

Which mitigation technique would prevent rogue servers from providing false IP configuration parameters to clients?

A

turning on DHCP snooping

78
Q

A network administrator configures the port security feature on a switch. The security policy specifies that each access port should allow up to two MAC addresses. When the maximum number of MAC addresses is reached, a frame with the unknown source MAC address is dropped and a notification is sent to the syslog server. Which security violation mode should be configured for each access port?

A

restrict

79
Q

What protocol or technology defines a group of routers, one of them defined as active and another one as standby?

A

HSRP

80
Q

Refer to the exhibit. After attempting to enter the configuration that is shown in router RTA, an administrator receives an error and users on VLAN 20 report that they are unable to reach users on VLAN 30. What is causing the problem?

A

RTA is using the same subnet for VLAN 20 and VLAN 30.

81
Q

Which three pairs of trunking modes will establish a functional trunk link between two Cisco switches? (Choose three.)

A
82
Q

A technician is configuring a router for a small company with multiple WLANs and doesn’t need the complexity of a dynamic routing protocol. What should be done or checked?

A

Create static routes to all internal networks and a default route to the internet.

83
Q

A company is deploying a wireless network in the distribution facility in a Boston suburb. The warehouse is quite large and it requires multiple access points to be used. Because some of the company devices still operate at 2.4GHz, the network administrator decides to deploy the 802.11g standard. Which channel assignments on the multiple access points will make sure that the wireless channels are not overlapping?

A

channels 1, 6, and 11

84
Q

A network administrator of a small advertising company is configuring WLAN security by using the WPA2 PSK method. Which credential do office users need in order to connect their laptops to the WLAN?

A

a user passphrase

85
Q

Refer to the exhibit. What are the possible port roles for ports A, B, C, and D in this RSTP-enabled network?

A

alternate, designated, root, root

86
Q

Refer to the exhibit. Which static route would an IT technician enter to create a backup route to the 172.16.1.0 network that is only used if the primary RIP learned route fails?

A

ip route 172.16.1.0 255.255.255.0 s0/0/0 121

87
Q

What mitigation plan is best for thwarting a DoS attack that is creating a MAC address table overflow?

A

Enable port security.

88
Q

A network engineer is troubleshooting a newly deployed wireless network that is using the latest 802.11 standards. When users access high bandwidth services such as streaming video, the wireless network performance is poor. To improve performance the network engineer decides to configure a 5 Ghz frequency band SSID and train users to use that SSID for streaming media services. Why might this solution improve the wireless network performance for that type of service?

A

The 5 GHz band has more channels and is less crowded than the 2.4 GHz band, which makes it more suited to streaming multimedia.

89
Q

Which DHCPv4 message will a client send to accept an IPv4 address that is offered by a DHCP server?

A

broadcast DHCPREQUEST

90
Q

Refer to the exhibit. Which destination MAC address is used when frames are sent from the workstation to the default gateway?

A

MAC address of the virtual router

91
Q

After a host has generated an IPv6 address by using the DHCPv6 or SLAAC process, how does the host verify that the address is unique and therefore usable?

A

The host sends an ICMPv6 neighbor solicitation message to the DHCP or SLAAC-learned address and if no neighbor advertisement is returned, the address is considered unique.

92
Q

Match the purpose with its DHCP message type. (Not all options are used.)

A
93
Q

Which protocol adds security to remote connections?

A

SSH

94
Q

Refer to the exhibit. A network administrator is verifying the configuration of inter-VLAN routing. Users complain that PC2 cannot communicate with PC1. Based on the output, what is the possible cause of the problem?

A

The encapsulation dot1Q 5 command contains the wrong VLAN.

95
Q

Refer to the exhibit. A network administrator is configuring inter-VLAN routing on a network. For now, only one VLAN is being used, but more will be added soon. What is the missing parameter that is shown as the highlighted question mark in the graphic?

A

It identifies the VLAN number.

96
Q

Match each DHCP message type with its description. (Not all options are used.)

A
97
Q

What network attack seeks to create a DoS for clients by preventing them from being able to obtain a DHCP lease?

A

DHCP starvation

98
Q

Refer to the exhibit. If the IP addresses of the default gateway router and the DNS server are correct, what is the configuration problem?

A

The IP address of the default gateway router is not contained in the excluded address list.

99
Q

Which three components are combined to form a bridge ID?

A
  • extended system ID
  • bridge priority
  • MAC address
100
Q
  1. Refer to the exhibit. A network administrator has added a new subnet to the
    network and needs hosts on that subnet to receive IPv4 addresses from the
    DHCPv4 server.
    What two commands will allow hosts on the new subnet to receive addresses
    from the DHCP4 server? (Choose two.)
A

R1(config-if)# ip helper-address 10.2.0.250

R1(config)# interface G0/0

101
Q

What protocol or technology uses source IP to destination IP as a load balancing mechanism?

A

EtherChannel

102
Q

What protocol should be disabled to help mitigate VLAN attacks?

A

DTP

103
Q

What protocol or technology requires switches to be in server mode or client
mode?

A

VTP

104
Q

What are two reasons a network administrator would segment a network with
a Layer 2 switch? (Choose two.)

A
  • to enhance user bandwidth
  • to isolate traffic between segments
105
Q

What command will enable a router to begin sending messages that allow it
to configure a link-local address without using an IPv6 DHCP server?

A

the ipv6 unicast-routing command

106
Q

A network administrator is using the router-on-a-stick model to configure a
switch and a router for inter-VLAN routing. What configuration should be made on the switch port that connects to the router?

A

Configure the port as an 802.1q trunk port

107
Q

What are three techniques for mitigating VLAN attacks? (Choose three.)

A
  • Enable trunking manually
  • Disable DTP
  • Set the native VLAN to an unused VLAN.
108
Q

Match the DHCP message types to the order of the DHCPv4 process. (Not all
options are used.)

A

Step 1 - DHCCPREQUEST
Step2- DHCPOFFER
Step 3 - DHCPREQUEST
Step 4- DHCPACK

109
Q

In which situation would a technician use the show interfaces switch
command?

A

when packets are being dropped from a particular directly attached host

110
Q

What is a drawback of the local database method of securing device access that can be solved by using AAA with centralized servers?

A

User accounts must be configured locally on each device, which is an
unscalable authentication solution

111
Q

What action does a DHCPv4 client take if it receives more than one
DHCPOFFER from multiple DHCP servers?

A

It sends a DHCPREQUEST that identifies which lease offer the client is
accepting.

112
Q
A
  • This port is currently up.
  • Security violations will cause this port to shut down immediately.
  • The switch port mode for this interface is access mode
113
Q

What method of wireless authentication is dependent on a RADIUS
authentication server?

A

WPA2 Enterprise

113
Q

A network administrator has found a user sending a double-tagged 802.1Q
frame to a switch. What is the best solution to prevent this type of attack?

A

The VLANs for user access ports should be different VLANs than any native
VLANs used on trunk ports

114
Q
A
  • The EtherChannel is down.
  • The port channel ID is 2.
115
Q

Match the step number to the sequence of stages that occur during the HSRP
failover process. (Not all options are used.)

A

Step 1 - The forwarding router falls

Step 2 - The standby router stops seeing hello messages from the forwarding router

Step 3 - The standby router assumes the role of the forwarding router using both the IP MAC addresses of the virtual router

116
Q

On a Cisco 3504 WLC Summary page ( Advanced > Summary ), which tab
allows a network administrator to configure a particular WLAN with a WPA2
policy?

A

WLANs

117
Q
A

ipv6 route ::/0 serial 0/1/1

118
Q

Users are complaining of sporadic access to the internet every afternoon.
What should be done or checked?

A

Check the statistics on the default route for oversaturation

119
Q

What action takes place when the source MAC address of a frame entering a switch appears in the MAC address table associated with a different port?

A

The switch replaces the old entry and uses the more current port.

120
Q

A network administrator is configuring a WLAN. Why would the administrator
use a WLAN controller?

A

to facilitate group configuration and management of multiple WLANs through a
WLC

121
Q

A new Layer 3 switch is connected to a router and is being configured for
interVLAN routing. What are three of the five steps required for the configuration?
(Choose three.)

A

Case 1 -
-entering “no switchport” on the port connected to the router
-assigning ports to VLANs
- enabling IP routing

CASE 2
- assigning ports to VLANs
- creating SVI interfaces
- creating VLANs

CASE 3
- assigning ports to VLANs
-enabling IP routing
- entering “no switchport” on the port connected to the router

CASE 4
- enabling IP routing
- assigning ports to VLANs
- creating SVI interfaces

CASE 5
- assigning prts to VLANs
- enabling IP routing
- creating SVI interfaces

CASE 6
- enabling IP routing
- entering “no switchport” on the port connected to the router
-assigning ports to VLANs

122
Q

. Which three statements accurately describe duplex and speed settings on
Cisco 2960 switches? (Choose three.)

A

*An autonegotiation failure can result in connectivity issues.

  • When the speed is set to 1000 Mb/s, the switch ports will operate in full-duplex
    mode.
  • The duplex and speed settings of each switch port can be manually
    configured.
123
Q

Refer to the exhibit. A network administrator configures R1 for inter-VLAN
routing between VLAN 10 and VLAN 20. However, the devices in VLAN 10 and
VLAN 20 cannot communicate. Based on the configuration in the exhibit, what is
a possible cause for the problem?

A

The encapsulation is misconfigured on a subinterface.

124
Q

A network administrator uses the spanning-tree portfast bpduguard default global configuration command to enable BPDU guard on a switch. However, BPDU guard is not activated on all access ports. What is the cause of the issue?

A

PortFast is not configured on all access ports.

125
Q

Which two types of spanning tree protocols can cause suboptimal traffic
flows because they assume only one spanning-tree instance for the entire
bridged network? (Choose two.)

A
  • RSTP
  • STP
126
Q
A

stateful

127
Q

A WLAN engineer deploys a WLC and five wireless APs using the CAPWAP
protocol with the DTLS feature to secure the control plane of the network devices. While testing the wireless network, the WLAN engineer notices that data traffic is being exchanged between the WLC and the APs in plain-text and is not being
encrypted. What is the most likely reason for this?

A

Although DTLS is enabled by default to secure the CAPWAP control channel, it
is disabled by default for the data channel.

128
Q

A new switch is to be added to an existing network in a remote office. The
network administrator does not want the technicians in the remote office to be able to add new VLANs to the switch, but the switch should receive VLAN
updates from the VTP domain. Which two steps must be performed to configure VTP on the new switch to meet these conditions? (Choose two.)

A
  • Configure the new switch as a VTP client.
  • Configure the existing VTP domain name on the new switch.
129
Q
A

to Fa0/1, Fa0/2, and Fa0/3 only

130
Q

What action takes place when the source MAC address of a frame entering a switch is not in the MAC address table?

A

The switch adds the MAC address and incoming port number to the table.

131
Q

Employees are unable to connect to servers on one of the internal networks.
What should be done or checked?

A

Employees are unable to connect to servers on one of the internal networks.
What should be done or checked?

132
Q

What is the effect of entering the ip dhcp snooping configuration command
on a switch?

A

What is the effect of entering the ip dhcp snooping configuration command
on a switch?

133
Q

An administrator notices that large numbers of packets are being dropped
on one of the branch routers. What should be done or checked?

A

Check the routing table for a missing static route

134
Q

What are two switch characteristics that could help alleviate network
congestion? (Choose two.)

A
  • fast internal switching
  • large frame buffers
135
Q

What is a result of connecting two or more switches together?

A

The size of the broadcast domain is increased.

136
Q
A
137
Q

Branch users were able to access a site in the morning but have had no
connectivity with the site since lunch time. What should be done or checked?

A

Use the “show ip interface brief” command to see if an interface is down

138
Q

What is the effect of entering the switchport port-security configuration
command on a switch?

A

It enables port security on an interface.

139
Q

A network administrator is configuring a WLAN. Why would the administrator
use multiple lightweight APs?

A

to facilitate group configuration and management of multiple WLANs through a
WLC

140
Q
A

The VLAN that is used by PC-A is not in the list of allowed VLANs on the trunk.

141
Q

A network administrator is configuring a WLAN. Why would the administrator
use RADIUS servers on the network?

A

to restrict access to the WLAN by authorized, authenticated users only

142
Q

What is the effect of entering the switchport mode access configuration
command on a switch?

A

It disables DTP on a non-trunking interface.

143
Q

A network administrator has configured a router for stateless DHCPv6
operation. However, users report that workstations are not receiving DNS server information. Which two router configuration lines should be verified to ensure that stateless DHCPv6 service is properly configured? (Choose two.)

A
  • The dns-server line is included in the ipv6 dhcp pool section.
  • The ipv6 nd other-config-flag is entered for the interface that faces the LAN
    segment
144
Q

A network administrator is configuring a WLAN. Why would the administrator
disable the broadcast feature for the SSID?

A

to eliminate outsiders scanning for available SSIDs in the area

145
Q
A

The interface is incorrect

146
Q

. What action takes place when a frame entering a switch has a unicast
destination MAC address that is not in the MAC address table?

A

The switch will forward the frame out all ports except the incoming port

147
Q

A junior technician was adding a route to a LAN router. A traceroute to a
device on the new network revealed a wrong path and unreachable status. What should be done or checked?

A

Check the configuration of the exit interface on the new static route.

148
Q

What is the effect of entering the ip arp inspection vlan 10 configuration
command on a switch?

A

It enables DAI on specific switch interfaces previously configured with DHCP
snooping.

149
Q

What protocol or technology manages trunk negotiations between switches?

A

DTP

150
Q

A network administrator is configuring a WLAN. Why would the administrator
apply WPA2 with AES to the WLAN?
Advanced encryption standard- encrypt and decrypt protected data

A

to provide privacy and integrity to wireless traffic by using encryption

151
Q

Users on a LAN are unable to get to a company web server but are able to get elsewhere. What should be done or checked?

A

Verify that the static route to the server is present in the routing table.

151
Q

What IPv6 prefix is designed for link-local communication?

A

fe80::/10

152
Q

What is the effect of entering the ip dhcp snooping limit rate 6 configuration command on a switch?

A

It restricts the number of discovery messages, per second, to be received on the interface.

153
Q

A network administrator is configuring a WLAN. Why would the administrator change the default DHCP IPv4 addresses on an AP?

A

to reduce outsiders intercepting data or accessing the wireless network by using a well-known address range

154
Q

What is the effect of entering the ip arp inspection validate src-mac configuration command on a switch?

A

It checks the source L2 address in the Ethernet header against the sender L2 address in the ARP body.

155
Q

What protocol or technology is a Cisco proprietary protocol that is automatically enabled on 2960 switches?

A

DTP

156
Q

What address and prefix length is used when configuring an IPv6 default static route?

A

::/0

157
Q

What are two characteristics of Cisco Express Forwarding (CEF)? (Choose two.)

A
  • This is the fastest forwarding mechanism on Cisco routers and multilayer switches.
  • Packets are forwarded based on information in the FIB and an adjacency table.
158
Q

Which term describes the role of a Cisco switch in the 802.1X port-based access control?

A

authenticator

159
Q

Which Cisco solution helps prevent ARP spoofing and ARP poisoning attacks?

A

Dynamic ARP Inspection

160
Q

What is an advantage of PVST+? PVST+ Results in optimum load balancing

A

PVST+ optimizes performance on the network through load sharing.

161
Q

What protocol or technology uses a standby router to assume packet-forwarding responsibility if the active router fails?

A

HSRP

162
Q

What is the effect of entering the show ip dhcp snooping binding configuration command on a switch?

A

It displays the IP-to-MAC address associations for switch interfaces

163
Q

What action takes place when the source MAC address of a frame entering a switch is in the MAC address table?

A

The switch updates the refresh timer for the entry.

164
Q

A small publishing company has a network design such that when a broadcast is sent on the LAN, 200 devices receive the transmitted broadcast. How can the network administrator reduce the number of devices that receive broadcast traffic?

A

Segment the LAN into smaller LANs and route between them.

165
Q

What defines a host route on a Cisco router?

A

An IPv4 static host route configuration uses a destination IP address of a specific device and a /32 subnet mask.

166
Q

What else is required when configuring an IPv6 static route using a next-hop link-local address?

A

interface number and type

167
Q

A technician is configuring a wireless network for a small business using a SOHO wireless router. Which two authentication methods are used, if the router is configured with WPA2? (Choose two.)

A
  • personal
  • enterprise
168
Q

Which mitigation technique would prevent rogue servers from providing false IPv6 configuration parameters to clients?

A

enabling DHCPv6 Guard

169
Q

A PC has sent an RS message to an IPv6 router attached to the same network. Which two pieces of information will the router send to the client? (Choose two.)

A
  • prefix length
  • prefix
170
Q

While attending a conference, participants are using laptops for network connectivity. When a guest speaker attempts to connect to the network, the laptop fails to display any available wireless networks. The access point must be operating in which mode?

A

active