Summer Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

200-301 Questions and Answers

Question # 6

Question # 6

A)

Question # 6

B)

Question # 6

C)

Question # 6

D)

Question # 6

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 7

An engineer is configuring a switch port that is connected to a VoIP handset. Which command must the engineer configure to enable port security with a manually assigned MAC address of abcd.abcd.abcd on voice VLAN 4?

A.

switchport port-security mac-address abcd.abcd.abcd

B.

switchport port-security mac-address abed.abed.abed vlan 4

C.

switchport port-security mac-address sticky abcd.abcd.abcd vlan 4

D.

switchport port-security mac-address abcd.abcd.abcd vlan voice

Full Access
Question # 8

Which Cisco proprietary protocol ensures traffic recovers immediately, transparently, and automatically when edge devices or access circuits fail?

A.

SLB

B.

FHRP

C.

VRRP

D.

HSRP

Full Access
Question # 9

When configuring a WLAN with WPA2 PSK in the Cisco Wireless LAN Controller GUI, which two formats are available to select? (Choose two)

A.

ASCII

B.

base64

C.

binary

D.

decimal

E.

hexadecimal

Full Access
Question # 10

Refer to the exhibit.

Question # 10

Router R14 is in the process of being configured. Which configuration must be used to establish a host route to PC 10?

A.

ip route 10.80.65.10 255.255.255.254 10.80.65.1

B.

ip route 10.8065.10 255.255.255.255 10.73.65.66

C.

ip route 1073.65.65 255.0.0.0 10.80.65.10

D.

ip route 10.73.65.66 0.0.0.255 10.80.65.10

Full Access
Question # 11

Refer to the exhibit.

Question # 11

An engineer is updating the management access configuration of switch SW1 to allow secured, encrypted remote configuration. Which two commands or command sequences must the engineer apply to the switch? (Choose two.)

A.

SW1(config)#enable secret ccnaTest123

B.

SW1(config)#username NEW secret R3mote123

C.

SW1(config)#line vty 0 15 SW1(config-line)#transport input ssh

D.

SW1(config)# crypto key generate rsa

E.

SW1(config)# interface f0/1 SW1(config-if)# switchport mode trunk

Full Access
Question # 12

Which action implements physical access control as part of the security program of an organization??

A.

backing up syslogs at a remote location

B.

configuring a password for the console port

C.

configuring enable passwords on network devices

D.

setting up IP cameras to monitor key infrastructure

Full Access
Question # 13

What must be considered for a locally switched FlexConnect AP if the VLANs that are used by the AP and client access are different?

A.

The APs must be connected to the switch with multiple links in LAG mode

B.

The switch port mode must be set to trunk

C.

The native VLAN must match the management VLAN of the AP

D.

IEEE 802.10 trunking must be disabled on the switch port.

Full Access
Question # 14

How does encryption protect the wireless network?

A.

via integrity checks to identify wireless forgery attacks in the frame

B.

via specific ciphers to detect and prevent zero-day network attacks

C.

via an algorithm to change wireless data so that only the access point and client understand it

D.

via a policy to prevent unauthorized users from communicating on the wireless network

Full Access
Question # 15

Refer to the exhibit.

Question # 15

A network engineer must provide configured IP addressing details to investigate a firewall rule Issue. Which subnet and mask Identify what is configured on the en0 interface?

A.

10.8.0.0/16

B.

10.8.64.0/18

C.

10.8.128.0/19

D.

10.8.138.0/24

Full Access
Question # 16

What is the role of nonoverlapping channels in a wireless environment?

A.

to reduce interference

B.

to allow for channel bonding

C.

to stabilize the RF environment

D.

to increase bandwidth

Full Access
Question # 17

Refer to Exhibit.

Question # 17

The loopback1 interface of the Atlanta router must reach the loopback3 interface of the Washington router. Which two static host routes must be configured on the New York router? (Choose two)

A.

ipv6 route 2000::1/128 2012::1

B.

ipv6 route 2000::3/128 2023::3

C.

ipv6 route 2000::3/128 s0/0/0

D.

ipv6 route 2000::1/128 2012::2

E.

ipv6 route 2000::1/128 s0/0/1

Full Access
Question # 18

What are two benefits of controller-based networking compared to traditional networking?

A.

controller-based increases network bandwidth usage, while traditional lightens the load on the network.

B.

controller-based inflates software costs, while traditional decreases individual licensing costs

C.

Controller-based reduces network configuration complexity, while traditional increases the potential for errors

D.

Controller-based provides centralization of key IT functions. While traditional requires distributed management functions

E.

controller-based allows for fewer network failure, while traditional increases failure rates.

Full Access
Question # 19

Refer to the exhibit.

Question # 19

Which switch in this configuration will be elected as the root bridge?

Question # 19

A.

SW1

B.

SW2

C.

SW3

D.

SW4

Full Access
Question # 20

What is the maximum bandwidth of a T1 point-to-point connection?

A.

1.544 Mbps

B.

2.048 Mbps

C.

34.368 Mbps

D.

43.7 Mbps

Full Access
Question # 21

What are two southbound APIs? (Choose two)

A.

OpenFlow

B.

NETCONF

C.

Thrift

D.

CORBA

E.

DSC

Full Access
Question # 22

Refer to the exhibit.

Question # 22

A network engineer must configure communication between PC A and the File Server. To prevent interruption for any other communications, which command must be configured?

A.

Switch trunk allowed vlan 12

B.

Switchport trunk allowed vlan none

C.

Switchport trunk allowed vlan add 13

D.

Switchport trunk allowed vlan remove 10-11

Full Access
Question # 23

Refer to the exhibit.

Question # 23

What commands are needed to add a subinterface to Ethernet0/0 on R1 to allow for VLAN 20, with IP address 10.20.20.1/24?

A.

R1(config)#interface ethernet0/0R1(config)#encapsulation dot1q 20R1(config)#ip address 10.20.20.1 255.255.255.0

B.

R1(config)#interface ethernet0/0.20R1(config)#encapsulation dot1q 20R1(config)#ip address 10.20.20.1 255.255.255.0

C.

R1(config)#interface ethernet0/0.20R1(config)#ip address 10.20.20.1 255.255.255.0

D.

R1(config)#interface ethernet0/0R1(config)#ip address 10.20.20.1 255.255.255.0

Full Access
Question # 24

Refer to the exhibit.

Question # 24

How must router A be configured so that it only sends Cisco Discovery Protocol Information to router C?

Question # 24

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 25

What is the advantage of separating the control plane from the data plane within an SDN network?

A.

decreases overall network complexity

B.

limits data queries to the control plane

C.

reduces cost

D.

offloads the creation of virtual machines to the data plane

Full Access
Question # 26

Refer to the exhibit.

Question # 26

A newly configured PC fails to connect to the internet using TCP port 80 to www cisco com Which setting must be modified for the connection to work?

A.

Subnet Mask

B.

DNS Servers

C.

Default Gateway

D.

DHCP Server

Full Access
Question # 27

What is the functionality of the Cisco DNA Center?

A.

data center network policy control

B.

console server that permits secure access to all network devices

C.

IP address pool distribution scheduler

D.

software-defined controller for automation of devices and services

Full Access
Question # 28

What is the role of community strings in SNMP operations?

A.

It serves as a sequence tag on SNMP traffic messages.

B.

It serves as a password to protect access to MIB objects.

C.

It passes the Active Directory username and password that are required for device access

D.

It translates alphanumeric MIB output values to numeric values.

Full Access
Question # 29

Refer to the exhibit.

Question # 29

Which switch becomes the root of the spanning tree for VLAN 110?

Question # 29

A.

Switch 1

B.

Switch 2

C.

Switch 3

D.

Switch 4

Full Access
Question # 30

What is the primary effect of the spanning-tree portfast command?

A.

it enables BPDU messages

B.

It minimizes spanning-tree convergence time

C.

It immediately puts the port into the forwarding state when the switch is reloaded

D.

It immediately enables the port in the listening state

Full Access
Question # 31

What are two fundamentals of virtualization? (Choose two)

A.

The environment must be configured with one hypervisor that serves solely as a network manager to monitor SNMP traffic

B.

It allows logical network devices to move traffic between virtual machines and the rest of the physical network

C.

It allows multiple operating systems and applications to run independently on one physical server.

D.

It allows a physical router to directly connect NICs from each virtual machine into the network

E.

It requires that some servers, virtual machines and network gear reside on the Internet

Full Access
Question # 32

Drag and drop the AAA functions from the left onto the correct AAA services on the right

Question # 32

Full Access
Question # 33

Which QoS tool is used to optimize voice traffic on a network that is primarily intended for data traffic?

A.

FIFO

B.

WFQ

C.

PQ

D.

WRED

Full Access
Question # 34

How do TCP and UDP differ in the way that they establish a connection between two endpoints?

A.

TCP uses synchronization packets, and UDP uses acknowledgment packets.

B.

UDP uses SYN, SYN ACK and FIN bits in the frame header while TCP uses SYN, SYN ACK and ACK bits

C.

UDP provides reliable message transfer and TCP is a connectionless protocol

D.

TCP uses the three-way handshake and UDP does not guarantee message delivery

Full Access
Question # 35

Which two actions are performed by the Weighted Random Early Detection mechanism? (Choose two)

A.

It drops lower-priority packets before it drops higher-priority packets

B.

It can identify different flows with a high level of granularity

C.

It guarantees the delivery of high-priority packets

D.

It can mitigate congestion by preventing the queue from filling up

E.

It supports protocol discovery

Full Access
Question # 36

An engineer must configure interswitch VLAN communication between a Cisco switch and a third-party switch. Which action should be taken?

A.

configure IEEE 802.1p

B.

configure IEEE 802.1q

C.

configure ISL

D.

configure DSCP

Full Access
Question # 37

What does a switch use to build its MAC address table?

A.

VTP

B.

DTP

C.

egress traffic

D.

ingress traffic

Full Access
Question # 38

Which command prevents passwords from being stored in the configuration as plain text on a router or switch?

A.

enable secret

B.

service password-encryption

C.

username Cisco password encrypt

D.

enable password

Full Access
Question # 39

Drag and drop the threat-mitigation techniques from the left onto the types of threat or attack they mitigate on the right.

Question # 39

Full Access
Question # 40

Drag and drop the functions from the left onto the correct network components on the right

Question # 40

Full Access
Question # 41

Which function does the range of private IPv4 addresses perform?

A.

allows multiple companies to each use the same addresses without conflicts

B.

provides a direct connection for hosts from outside of the enterprise network

C.

ensures that NAT is not required to reach the internet with private range addressing

D.

enables secure communications to the internet for all external hosts

Full Access
Question # 42

Refer to the exhibit.

Question # 42

Which prefix did router R1 learn from internal EIGRP?

A.

192.168.10/24

B.

192.168.3.0/24

C.

192.168.2.0/24

D.

172.16 1.0/24

Full Access
Question # 43

Drag and drop the descriptions of AAA services from the left onto the corresponding services on the right.

Question # 43

Full Access
Question # 44

Which QoS traffic handling technique retains excess packets in a queue and reschedules these packets for later transmission when the configured maximum bandwidth has been surpassed?

A.

weighted random early detection

B.

traffic policing

C.

traffic shaping

D.

traffic prioritization

Full Access
Question # 45

What is the difference between IPv6 unicast and anycast addressing?

A.

IPv6 anycast nodes must be explicitly configured to recognize the anycast address, but IPv6 unicast nodes require no special configuration

B.

IPv6 unicast nodes must be explicitly configured to recognize the unicast address, but IPv6 anycast nodes require no special configuration

C.

An individual IPv6 unicast address is supported on a single interface on one node but an IPv6 anycast address is assigned to a group of interfaces on multiple nodes.

D.

Unlike an IPv6 anycast address, an IPv6 unicast address is assigned to a group of interfaces on multiple nodes

Full Access
Question # 46

Refer to the exhibit.

Question # 46

A static route must be configured on R14 to forward traffic for the 172.21.34.0/25 network that resides on R86 Which command must be used to fulfill the request?

A.

ip route 172.21.34.0 255.255.255.192 10.73.65.65

B.

ip route 172.21.34.0 255.255.255.0 10.73.65.65

C.

ip route 172.21.34.0 255.255.128.0 10.73.65.64

D.

ip route 172.21.34.0 255.255.255.128 10.73.65.66

Full Access
Question # 47

What is a function of Cisco Advanced Malware Protection for a Next-Generation IPS?

A.

authorizing potentially compromised wireless traffic

B.

inspecting specific files and file types for malware

C.

authenticating end users

D.

URL filtering

Full Access
Question # 48

Which plane is centralized by an SDN controller?

A.

management-plane

B.

control-plane

C.

data-plane

D.

services-plane

Full Access
Question # 49

Refer to the exhibit.

Question # 49

Load-balanced traffic is coming in from the WAN destined to a host at 172.16.1.190. Which next-hop is used by the router to forward the request?

A.

192.168.7.4

B.

192.168.7.7

C.

192.168.7.35

D.

192.168.7.40

Full Access
Question # 50

Which action is taken by a switch port enabled for PoE power classification override?

A.

When a powered device begins drawing power from a PoE switch port a syslog messageage is generated

B.

As power usage on a PoE switch port is checked data flow to the connected device is temporarily paused

C.

If a switch determines that a device is using less than the minimum configured power it assumes the device has failed and disconnects

D.

Should a monitored port exceeds the maximum administrative value for power, the port is shutdown and err-disabled

Full Access
Question # 51

What is a function performed by a web server?

A.

provide an application that is transmitted over HTTP

B.

send and retrieve email from client devices

C.

authenticate and authorize a user ' s identity

D.

securely store files for FTP access

Full Access
Question # 52

Drag and drop the statements about networking from the left onto the corresponding networking types on the right

Question # 52

Full Access
Question # 53

Refer to the exhibit.

Question # 53

Which action must be taken to ensure that router A is elected as the DR for OSPF area 0?

A.

Configure the OSPF priority on router A with the lowest value between the three routers.

B.

Configure router B and router C as OSPF neighbors of router A.

C.

Configure the router A interfaces with the highest OSPF priority value within the area.

D.

Configure router A with a fixed OSPF router ID

Full Access
Question # 54

Refer to the exhibit.

Question # 54

Between which zones do wireless users expect to experience intermittent connectivity?

A.

between zones 1 and 2

B.

between zones 2 and 5

C.

between zones 3 and 4

D.

between zones 3 and 6

Full Access
Question # 55

How does Rapid PVST+ create a fast loop-free network topology?

A.

lt requires multiple links between core switches

B.

It generates one spanning-tree instance for each VLAN

C.

It maps multiple VLANs into the same spanning-tree instance

D.

It uses multiple active paths between end stations.

Full Access
Question # 56

What provides centralized control of authentication and roaming In an enterprise network?

A.

a lightweight access point

B.

a firewall

C.

a wireless LAN controller

D.

a LAN switch

Full Access
Question # 57

Drag and drop the TCP or UDP details from the left onto their corresponding protocols on the right.

Question # 57

Full Access
Question # 58

Refer to the exhibit.

Question # 58

Router R1 must be configured to reach the 10.0.3.0/24 network from the 10.0.1.0/24 segment.

Which command must be used to configure the route?

A.

ip route 10.0.3.0 255.255.255.0 10.0.4.2

B.

route add 10.0.3.0 mask 255.255.255.0 10.0.4.3

C.

ip route 10.0.3.0 255.255.255.0 10.0.4.3

D.

route add 10.0.3.0 0.255.255.255 10.0.4.2

Full Access
Question # 59

Refer to the exhibit.

Question # 59

Which minimum configuration items are needed to enable Secure Shell version 2 access to R15?

A)

Question # 59

B)

Question # 59

C)

Question # 59

D)

Question # 59

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 60

Refer to the exhibit.

Question # 60

Which two commands when used together create port channel 10? (Choose two.)

A.

int range g0/0-1channel-group 10 mode active

B.

int range g0/0-1 channel-group 10 mode desirable

C.

int range g0/0-1channel-group 10 mode passive

D.

int range g0/0-1 channel-group 10 mode auto

E.

int range g0/0-1 channel-group 10 mode on

Full Access
Question # 61

Refer to the exhibit.

Question # 61

A network engineer is in the process of establishing IP connectivity between two sites. Routers R1 and R2 are partially configured with IP addressing. Both routers have the ability to access devices on their respective LANs. Which command set configures the IP connectivity between devices located on both LANs in each site?

Question # 61

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 62

Refer to the exhibit.

Question # 62

The administrator must configure a floating static default route that points to 2001:db8:1234:2::1 and replaces the current default route only if it fails. Which command must the engineer configure on the CPE?

A.

ipv6 route ::/0 2001:db8:1234:2::1 3

B.

ipv6 route ::/128 2001 :db8:1234:2::1 3

C.

ipv6 route ::/0 2001:db8:1234:2::1 1

D.

ipv6 route ::/0 2001:db8:1234:2::1 2

Full Access
Question # 63

Refer to the exhibit.

Question # 63

Which network prefix was learned via EIGRP?

A.

172.16.0.0/16

B.

192.168.2.0/24

C.

207.165.200.0/24

D.

192.168.1.0/24

Full Access
Question # 64

Which protocol requires authentication to transfer a backup configuration file from a router to a remote server?

A.

DTP

B.

FTP

C.

SMTP

D.

TFTP

Full Access
Question # 65

R1 has learned route 192.168.12.0/24 via IS-IS. OSPF, RIP. and Internal EIGRP Under normal operating conditions, which routing protocol is installed in the routing table?

A.

IS-IS

B.

RIP

C.

Internal EIGRP

D.

OSPF

Full Access
Question # 66

What mechanism carries multicast traffic between remote sites and supports encryption?

A.

ISATAP

B.

GRE over IPsec

C.

IPsec over ISATAP

D.

GRE

Full Access
Question # 67

What is the collapsed layer in collapsed core architectures?

A.

core and WAN

B.

access and WAN

C.

distribution and access

D.

core and distribution

Full Access
Question # 68

Which type of network attack overwhelms the target server by sending multiple packets to a port until the half-open TCP resources of the target are exhausted?

A.

SYN flood

B.

reflection

C.

teardrop

D.

amplification

Full Access
Question # 69

Refer to the exhibit.

Question # 69

An engineer built a new Layer 2 LACP EtherChannel between SW1 and SW2 and executed these show commands to verify the work. Which additional task allows the two switches to establish an LACP port channel?

A.

Change the channel-group mode on SW2 to auto

B.

Change the channel-group mode on SW1 to desirable.

C.

Configure the interface port-channel 1 command on both switches.

D.

Change the channel-group mode on SW1 to active or passive.

Full Access
Question # 70

Refer to the exhibit.

Question # 70

The ntp server 192.168.0.3 command has been configured on router 1 to make it an NTP client of router 2. Which command must be configured on router 2 so that it operates in server-only mode and relies only on its internal clock?

A.

Router2(config)#ntp passive

B.

Router2(config)#ntp server 172.17.0.1

C.

Router2(config)#ntp master 4

D.

Router2(config)#ntp server 192.168.0.2

Full Access
Question # 71

Refer to the exhibit.

Question # 71

Which command configures OSPF on the point-to-point link between routers R1 and R2?

A.

router-id 10.0.0.15

B.

neighbor 10.1.2.0 cost 180

C.

ipospf priority 100

D.

network 10.0.0.0 0.0.0.255 area 0

Full Access
Question # 72

A network administrator is setting up a new IPv6 network using the 64-bit address 2001 0EB8 00C1 2200:0001 0000 0000 0331/64 To simplify the configuration the administrator has decided to compress the address Which IP address must the administrator configure?

A.

ipv6 address 21:EB8:C1:2200:1::331/64

B.

ipv6 address 2001:EB8:C1:22:1::331/64

C.

ipv6 address 2001:EB8:C1:2200:1::331/64

D.

ipv6 address 2001:EB8:C1:2200:1:0000:331/64

Full Access
Question # 73

What is the benefit of using FHRP?

A.

reduced management overhead on network routers

B.

balancing traffic across multiple gateways in proportion to their loads

C.

higher degree of availability

D.

reduced ARP traffic on the network

Full Access
Question # 74

How does authentication differ from authorization?

A.

Authentication verifies the identity of a person accessing a network, and authorization determines what resource a user can access.

B.

Authentication is used to record what resource a user accesses, and authorization is used to determine what resources a user can access

C.

Authentication is used to determine what resources a user is allowed to access, and authorization is used to track what equipment is allowed access to the network

D.

Authentication is used to verify a person ' s identity, and authorization is used to create syslog messages for logins.

Full Access
Question # 75

Refer to the exhibit.

Question # 75

An IP subnet must be configured on each router that provides enough addresses for the number of assigned hosts and anticipates no more than 10% growth for new hosts. Which configuration script must be used?

A)

Question # 75

B)

Question # 75

C)

Question # 75

D)

Question # 75

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 76

Which two components comprise part of a PKI? (Choose two.)

A.

preshared key that authenticates connections

B.

RSA token

C.

CA that grants certificates

D.

clear-text password that authenticates connections

E.

one or more CRLs

Full Access
Question # 77

A network engineer must configure two new subnets using the address block 10.70.128.0/19 to meet these requirements:

• The first subnet must support 24 hosts

• The second subnet must support 472 hosts

• Both subnets must use the longest subnet mask possible from the address block

Which two configurations must be used to configure the new subnets and meet a requirement to use the first available address in each subnet for the router interfaces? (Choose two )

A.

interface vlan 1234ip address 10.70.159.1 255.255.254.0

B.

interface vlan 1148ip address 10.70.148.1 255.255.254.0

C.

interface vlan 4722ip address 10.70.133.17 255.255.255.192

D.

interface vlan 3002ip address 10.70.147.17 255.255.255.224

E.

interface vlan 155ip address 10.70.155.65 255.255.255.224

Full Access
Question # 78

Refer to the exhibit.

Question # 78

A company is configuring a failover plan and must implement the default routes in such a way that a floating static route will assume traffic forwarding when the primary link goes down. Which primary route configuration must be used?

A.

ip route 0.0.0.0 0.0.0.0 192.168.0.2 GigabitEthernet1/0

B.

ip route 0.0.0.0 0.0.0.0 192.168.0.2 tracked

C.

ip route 0.0.0.0 0.0.0.0 192.168.0.2 floating

D.

ip route 0.0.0.0 0.0.0.0 192.168.0.2

Full Access
Question # 79

What are two benefits of FHRPs? (Choose two.)

A.

They enable automatic failover of the default gateway.

B.

They allow multiple devices to serve as a single virtual gateway for clients in the network.

C.

They are able to bundle multiple ports to increase bandwidth.

D.

They prevent loops in the Layer 2 network.

E.

They allow encrypted traffic.

Full Access
Question # 80

Refer to the exhibit.

Question # 80

An engineer is configuring the HO router. Which IPv6 address configuration must be applied to the router Fa0/1 interface for the router to assign a unique 64-brt IPv6 address to Itself?

A.

ipv6 address 2001:DB8:0:1:C601:42FF:FE0F:7/64

B.

ipv6 address 2001:DB8:0:1:C601:42FE:800F:7/64

C.

ipv6 address 2001 :DB8:0:1:FFFF:C601:420F:7/64

D.

iov6 address 2001 :DB8:0:1:FE80:C601:420F:7/64

Full Access
Question # 81

Refer to the exhibit.

Question # 81

For security reasons, automatic Neighbor Discovery must be disabled on the R5 Gi0/1 interface. These tasks must be completed:

• Disable all Neighbor Discovery methods on R5 interface GiO/1.

• Permit Neighbor Discovery on R5 interface GiO/2.

• Verify there are no dynamically learned neighbors on R5 interface Gi0/1.

• Display the IP address of R6*s interface Gi0/2.

Which configuration must be used?

Question # 81

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 82

Drag and drop the Cisco IOS attack mitigation features from the left onto the types of network attack they mitigate on the right.

Question # 82

Full Access
Question # 83

Drag and drop the facts about wireless architectures from the left onto the types of access point on the right. Not all options are used.

Question # 83

Full Access
Question # 84

Refer to the exhibit.

Question # 84

Users need to connect to the wireless network with IEEE 802.11r-compatible devices. The connection must be maintained as users travel between floors or to other areas in the building What must be the configuration of the connection?

A.

Select the WPA Policy option with the CCKM option.

B.

Disable AES encryption.

C.

Enable Fast Transition and select the FT 802.1x option.

D.

Enable Fast Transition and select the FT PSK option.

Full Access
Question # 85

An engineer must configure neighbor discovery between the company router and an ISP

Question # 85

What is the next step to complete the configuration if the ISP uses a third-party router?

A.

Enable LLDP globally.

B.

Disable CDP on gi0/0.

C.

Enable LLDP TLVs on the ISP router.

D.

Disable auto-negotiation.

Full Access
Question # 86

Which set of 2.4 GHz nonoverlapping wireless channels is standard in the United States?

A.

channels 2, 7, 9, and 11

B.

channels 1, 6, 11, and 14

C.

channels 2, 7, and 11

D.

channels 1, 6, and 11

Full Access
Question # 87

Drag and drop the TCP or UDP details from the left onto their corresponding protocols on the right.

Question # 87

Full Access
Question # 88

A Cisco engineer is configuring a factory-default router with these three passwords:

• The user EXEC password for console access is p4ssw0rd1

• The user EXEC password for Telnet access is s3cr3t2

• The password for privileged EXEC mode is pr1v4t3p4ss Which command sequence must the engineer configured

A)

Question # 88

B)

Question # 88

C)

Question # 88

D)

Question # 88

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 89

Why would VRRP be implemented when configuring a new subnet in a multivendor environment?

A.

when a gateway protocol is required that support more than two Cisco devices for redundancy

B.

to enable normal operations to continue after a member failure without requiring a change In a host ARP cache

C.

to ensure that the spanning-tree forwarding path to the gateway is loop-free

D.

to interoperate normally with all vendors and provide additional security features for Cisco devices

Full Access
Question # 90

What is a similarity between 1000BASE-LX and 1000BASE-T standards?

A.

Both use the same data-link header and trailer formats

B.

Both cable types support RJ-45 connectors

C.

Both cable types support Rj-45 connectors

D.

Both support up to 550 meters between nodes

Full Access
Question # 91

Refer to the exhibit.

Question # 91

How many JSON objects are represented?

A.

1

B.

2

C.

3

D.

4

Full Access
Question # 92

Refer to the exhibit.

Question # 92

An engineer is configuring an EtherChannel using LACP between Switches 1 and 2 Which configuration must be applied so that only Switch 1 sends LACP initiation packets?

A.

Switch 1 (config-if)#channel-group 1 mode onSwrtch2(config-if)#channel-group 1 mode passive

B.

Switch1(config-if)#channel-group 1 mode passiveSwitch2(config-if)#channel-group 1 mode active

C.

Switch1{config-if)£channel-group 1 mode activeSwitch2(config-if)#channel-group 1 mode passive

D.

Switch1(config-if)#channel-group 1 mode onSwitch2(config-if)#channel-group 1 mode active

Full Access
Question # 93

When a site-to-site VPN is configured, which IPsec mode provides encapsulation and encryption of the entire original IP packet?

A.

IPsec tunnel mode with AH

B.

IPsec transport mode with AH

C.

IPsec tunnel mode with ESP

D.

IPsec transport mode with ESP

Full Access
Question # 94

Refer to the exhibit.

Question # 94

Users on existing VLAN 100 can reach sites on the Internet. Which action must the administrator take to establish connectivity to the Internet for users in VLAN 200?

A.

Define a NAT pool on the router.

B.

Configure static NAT translations for VLAN 200.

C.

Configure the ip nat outside command on another interface for VLAN 200.

D.

Update the NAT INSIDF RANGFS ACL

Full Access
Question # 95

Refer to the exhibit.

Question # 95

Packets received by the router from BGP enter via a serial interface at 209.165.201.10. Each route is present within the routing table. Which interface is used to forward traffic with a destination IP of 10.10.10.24?

A.

F0/10

B.

F0/11

C.

F0/12

D.

F0/13

Full Access
Question # 96

Refer to the exhibit.

Question # 96

Which two commands were used to create port channel 10? (Choose two )

Question # 96

A.

Option A

B.

Option B

C.

Option C

D.

Option D

E.

Option E

Full Access
Question # 97

What is one reason to implement LAG on a Cisco WLC?

A.

to increase security and encrypt management frames

B.

to provide link redundancy and load balancing

C.

to allow for stateful and link-state failover

D.

to enable connected switch ports to failover and use different VLANs

Full Access
Question # 98

Which value is the unique identifier that an access point uses to establish and maintain wireless connectivity to wireless network devices?

A.

VLAN ID

B.

SSID

C.

RFID

D.

WLANID

Full Access
Question # 99

What are two characteristics of an SSID? (Choose Two)

A.

It can be hidden or broadcast in a WLAN

B.

It uniquely identifies an access point in a WLAN

C.

It uniquely identifies a client in a WLAN

D.

It is at most 32 characters long.

E.

IT provides secured access to a WLAN

Full Access
Question # 100

A Cisco engineer must configure a single switch interface to meet these requirements

• accept untagged frames and place them in VLAN 20

• accept tagged frames in VLAN 30 when CDP detects a Cisco IP phone

Which command set must the engineer apply?

A)

Question # 100

B)

Question # 100

C)

Question # 100

D)

Question # 100

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 101

An engineer must configure R1 for a new user account. The account must meet these requirements:

* It must be configured in the local database.

* The username is engineer.

* It must use the strongest password configurable. Which command must the engineer configure on the router?

A.

R1 (config)# username engineer2 algorithm-type scrypt secret test2021

B.

R1(config)# username engineer2 secret 5 password S1$b1Ju$kZbBS1Pyh4QzwXyZ

C.

R1(config)# username engineer2 privilege 1 password 7 test2021

D.

R1(config)# username englneer2 secret 4 S1Sb1Ju$kZbBS1Pyh4QzwXyZ

Full Access
Question # 102

What are two reasons that cause late collisions to increment on an Ethernet interface? (Choose two)

A.

when the sending device waits 15 seconds before sending the frame again

B.

when the cable length limits are exceeded

C.

when one side of the connection is configured for half-duplex

D.

when Carrier Sense Multiple Access/Collision Detection is used

E.

when a collision occurs after the 32nd byte of a frame has been transmitted

Full Access
Question # 103

Topology:

Question # 103

All relevant ports are preconfigured as IEEE 802.1Q trunks.

Task 1

Configure SW-1 port Ethernet0/0 to permit only VLANs 5 and 6.

Task 2

Configure ports Ethernet0/1 on SW-1 and SW-2 to use VLAN 77 as the native VLAN.

Task 3

Configure SW-2 port Ethernet0/2 to permit only VLAN 6.

Task 4

Using LACP, create a Port-Channel between SW-3 and SW-4.

    Combine Ethernet0/0 and Ethernet0/1 into a Port-Channel while leaving the existing trunk configurations intact.

    Assign Port-Channel number 34.

    Only SW-3 must initiate LACP negotiations.

Full Access
Question # 104

Refer to the exhibit.

Question # 104

An engineer assumes a configuration task from a peer Router A must establish an OSPF neighbor relationship with neighbor 172.1.1.1 The output displays the status of the adjacency after 2 hours. What is the next step in the configuration process for the routers to establish an adjacency?

A.

Configure router A to use the same MTU size as router B.

B.

Set the router B OSPF ID to a nonhost address.

C.

Configure a point-to-point link between router A and router B.

D.

Set the router B OSPF ID to the same value as its IP address

Full Access
Question # 105

Question # 105

Full Access
Question # 106

Which field within the access-request packet is encrypted by RADIUS?

A.

authorized services

B.

authenticator

C.

username

D.

password

Full Access
Question # 107

Which two values or settings must be entered when configuring a new WLAN in the Cisco Wireless LAN Controller GUI? (Choose two)

A.

management interface settings

B.

QoS settings

C.

Ip address of one or more access points

D.

SSID

E.

Profile name

Full Access
Question # 108

A network engineer must configure the router R1 GigabitEthernet1/1 interface to connect to the router R2 GigabitEthernet1/1 interface. For the configuration to be applied the engineer must compress the address 2001:0db8:0000:0000:0500:000a:400F:583B. Which command must be issued on the interface?

A.

ipv6 address 2001:0db8::5: a: 4F 583B

B.

ipv6 address 2001:db8::500:a:400F:583B

C.

ipv6 address 2001 db8:0::500:a:4F:583B

D.

ipv6 address 2001::db8:0000::500:a:400F:583B

Full Access
Question # 109

A network administrator needs to aggregate 4 ports into a single logical link which must negotiate layer 2 connectivity to ports on another switch. What must be configured when using active mode on both sides of the connection?

A.

802.1q trunks

B.

Cisco vPC

C.

LLDP

D.

LACP

Full Access
Question # 110

Which result occurs when PortFast is enabled on an interface that is connected to another switch?

A.

Spanning tree may fail to detect a switching loop in the network that causes broadcast storms

B.

VTP is allowed to propagate VLAN configuration information from switch to switch automatically.

C.

Root port choice and spanning tree recalculation are accelerated when a switch link goes down

D.

After spanning tree converges PortFast shuts down any port that receives BPDUs.

Full Access
Question # 111

Refer to the exhibit.

Question # 111

PC1 is trying to ping PC3 for the first time and sends out an ARP to S1 Which action is taken by S1?

A.

It forwards it out G0/3 only

B.

It is flooded out every port except G0/0.

C.

It drops the frame.

D.

It forwards it out interface G0/2 only.

Full Access
Question # 112

Drag and drop the application protocols from the left onto the transport protocols that it uses on the right

Question # 112

Full Access
Question # 113

Refer to the exhibit.

Question # 113

What is the next hop address for traffic that is destined to host 10.0.1.5?

A.

10.0.1.3

B.

10.0.1.50

C.

10.0.1.4

D.

Loopback D

Full Access
Question # 114

How do traditional campus device management and Cisco DNA Center device management differ in regards to deployment?

A.

Cisco DNA Center device management can deploy a network more quickly than traditional campus device management

B.

Traditional campus device management allows a network to scale more quickly than with Cisco DNA Center device management

C.

Cisco DNA Center device management can be implemented at a lower cost than most traditional campus device management options

D.

Traditional campus device management schemes can typically deploy patches and updates more quickly than Cisco DNA Center device management

Full Access
Question # 115

Which two protocols must be disabled to increase security for management connections to a Wireless LAN Controller? (Choose two.)

A.

Telnet

B.

SSH

C.

HTTP

D.

HTTPS

E.

TFTP

Full Access
Question # 116

Which mode must be set for APs to communicate to a Wireless LAN Controller using the Control and Provisioning of Wireless Access Points (CAPWAP) protocol?

A.

bridge

B.

route

C.

autonomous

D.

lightweight

Full Access
Question # 117

Which goal is achieved by the implementation of private IPv4 addressing on a network?

A.

provides an added level of protection against Internet exposure

B.

provides a reduction in size of the forwarding table on network routers

C.

allows communication across the Internet to other private networks

D.

allows servers and workstations to communicate across public network boundaries

Full Access
Question # 118

Refer to the exhibit.

Question # 118

R5 is the current DR on the network, and R4 is the BDR. Their interfaces are flapping, so a network engineer wants the OSPF network to elect a different DR and BDR. Which set of configurations must the engineer implement?

A)

Question # 118

B)

Question # 118

C)

Question # 118

D)

Question # 118

A.

Option

B.

Option

C.

Option

D.

Option

Full Access
Question # 119

How does QoS optimize voice traffic?

A.

reducing bandwidth usage

B.

by reducing packet loss

C.

by differentiating voice and video traffic

D.

by increasing jitter

Full Access
Question # 120

Drag and drop the functions of DHCP from the left onto any of the positions on the right Not all functions are used

Question # 120

Full Access
Question # 121

which IPv6 address block forwards packets to a multicast address rather than a unicast address?

A.

2000::/3

B.

FC00::/7

C.

FE80::/10

D.

FF00::/12

Full Access
Question # 122

An engineer configured an OSPF neighbor as a designated router. Which state verifies the designated router is in the proper mode?

A.

Exchange

B.

2-way

C.

Full

D.

Init

Full Access
Question # 123

What is the primary different between AAA authentication and authorization?

A.

Authentication verifies a username and password, and authorization handles the communication between the authentication agent and the user database.

B.

Authentication identifies a user who is attempting to access a system, and authorization validates the users password

C.

Authentication identifies and verifies a user who is attempting to access a system, and authorization controls the tasks the user can perform.

D.

Authentication controls the system processes a user can access and authorization logs the activities the user initiates

Full Access
Question # 124

What is a characteristic of private IPv4 addressing?

A.

traverse the Internet when an outbound ACL is applied

B.

issued by IANA in conjunction with an autonomous system number

C.

composed of up to 65.536 available addresses

D.

used without tracking or registration

Full Access
Question # 125

An engineer requires a scratch interface to actively attempt to establish a trunk link with a neighbor switch. What command must be configured?

A.

switchport mode trunk

B.

switchport mode dynamic desirable

C.

switchport mode dynamic auto

D.

switchport nonegotiate

Full Access
Question # 126

What is the primary function of a Layer 3 device?

A.

to analyze traffic and drop unauthorized traffic from the Internet

B.

to transmit wireless traffic between hosts

C.

to pass traffic between different networks

D.

forward traffic within the same broadcast domain

Full Access
Question # 127

Refer to the exhibit.

Question # 127

An administrator is tasked with configuring a voice VLAN. What is the expected outcome when a Cisco phone is connected to the GigabitEthernet3/1/4 port on a switch?

A.

The phone and a workstation that is connected to the phone do not have VLAN connectivity

B.

The phone and a workstation that is connected to the phone send and receive data in VLAN 50.

C.

The phone sends and receives data in VLAN 50, but a workstation connected to the phone has no VLAN connectivity

D.

The phone sends and receives data in VLAN 50, but a workstation connected to the phone sends and receives data in VLAN 1

Full Access
Question # 128

Which protocol prompts the Wireless LAN Controller to generate its own local web administration SSL certificate for GUI access?

A.

HTTPS

B.

RADIUS

C.

TACACS+

D.

HTTP

Full Access
Question # 129

What prevents a workstation from receiving a DHCP address?

A.

DTP

B.

STP

C.

VTP

D.

802.10

Full Access
Question # 130

Refer to the exhibit.

Question # 130

To which device does Router1 send packets that are destined to host 10.10.13.165?

A.

Router2

B.

Router3

C.

Router4

D.

Router5

Full Access
Question # 131

How are VLAN hopping attacks mitigated?

A.

enable dynamic ARP inspection

B.

manually implement trunk ports and disable DTP

C.

activate all ports and place in the default VLAN

D.

configure extended VLANs

Full Access
Question # 132

Refer to Exhibit.

Question # 132

How does SW2 interact with other switches in this VTP domain?

A.

It processes VTP updates from any VTP clients on the network on its access ports.

B.

It receives updates from all VTP servers and forwards all locally configured VLANs out all trunk ports

C.

It forwards only the VTP advertisements that it receives on its trunk ports.

D.

It transmits and processes VTP updates from any VTP Clients on the network on its trunk ports

Full Access
Question # 133

Refer to the exhibit.

Question # 133

Router R2 is configured with multiple routes to reach network 10 1.1 0/24 from router R1. What protocol is chosen by router R2 to reach the destination network 10.1 1 0/24?

A.

eBGP

B.

static

C.

OSPF

D.

EIGRP

Full Access
Question # 134

Which configuration is needed to generate an RSA key for SSH on a router?

A.

Configure the version of SSH

B.

Configure VTY access.

C.

Create a user with a password.

D.

Assign a DNS domain name

Full Access
Question # 135

When a switch receives a frame for a known destination MAC address, how is the frame handed?

A.

sent to the port identified for the known MAC address

B.

broadcast to all ports

C.

forwarded to the first available port

D.

flooded to all ports except the one from which it originated

Full Access
Question # 136

Drag and drop the DNS lookup components from the left onto the functions on the right.

Question # 136

Full Access
Question # 137

Refer to Exhibit.

Question # 137

An engineer is configuring the NEW York router to reach the Lo1 interface of the Atlanta router using interface Se0/0/0 as the primary path. Which two commands must be configured on the New York router so that it can reach the Lo1 interface of the Atlanta router via Washington when the link between New York and Atlanta goes down? (Choose two)

A.

ipv6 router 2000::1/128 2012::1

B.

ipv6 router 2000::1/128 2012::1 5

C.

ipv6 router 2000::1/128 2012::2

D.

ipv6 router 2000::1/128 2023::2 5

E.

ipv6 router 2000::1/128 2023::3 5

Full Access
Question # 138

What is a difference between RADIUS and TACACS+?

A.

RADIUS is most appropriate for dial authentication, but TACACS+ can be used for multiple types of authentication

B.

TACACS+ encrypts only password information and RADIUS encrypts the entire payload

C.

TACACS+ separates authentication and authorization, and RADIUS merges them

D.

RADIUS logs all commands that are entered by the administrator, but TACACS+ logs only start, stop, and interim commands

Full Access
Question # 139

How does WPA3 improve security?

A.

It uses SAE for authentication.

B.

It uses a 4-way handshake for authentication.

C.

It uses RC4 for encryption.

D.

It uses TKIP for encryption.

Full Access
Question # 140

How are the switches in a spine-and-leaf topology interconnected?

A.

Each leaf switch is connected to one of the spine switches.

B.

Each leaf switch is connected to two spine switches, making a loop.

C.

Each leaf switch is connected to each spine switch.

D.

Each leaf switch is connected to a central leaf switch, then uplinked to a core spine switch.

Full Access
Question # 141

Which action does the router take as it forwards a packet through the network?

A.

The router replaces the source and destination labels with the sending router interface label as a source and the next hop router label as a desbnabon

B.

The router encapsulates the source and destination IP addresses with the sending router P address as the source and the neighbor IP address as the destination

C.

The router replaces the original source and destination MAC addresses with the sending router MAC address as the source and neighbor MAC address as the destination

D.

The router encapsulates the original packet and then includes a tag that identifies the source router MAC address and transmit transparently to the destination

Full Access
Question # 142

When a site-to-site VPN is used, which protocol is responsible for the transport of user data?

A.

IKEv2

B.

IKEv1

C.

IPsec

D.

MD5

Full Access
Question # 143

Refer to the exhibit.

Question # 143

A network engineer must block access for all computers on VLAN 20 to the web server via HTTP All other computers must be able to access the web server Which configuration when applied to switch A accomplishes this task?

Question # 143

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 144

A network engineer must create a diagram of a multivendor network. Which command must be configured on the Cisco devices so that the topology of the network can be mapped?

A.

Device(Config)#lldp run

B.

Device(Config)#cdp run

C.

Device(Config-if)#cdp enable

D.

Device(Config)#flow-sampler-map topology

Full Access
Question # 145

Refer to the exhibit.

Question # 145

Which command must be executed for Gi1.1 on SW1 to become a trunk port if Gi1/1 on SW2 is configured in desirable or trunk mode?

A.

switchport mode trunk

B.

switchport mode dot1-tunnel

C.

switchport mode dynamic auto

D.

switchport mode dynamic desirable

Full Access
Question # 146

Refer to Exhibit.

Question # 146

Which action do the switches take on the trunk link?

A.

The trunk does not form and the ports go into an err-disabled status.

B.

The trunk forms but the mismatched native VLANs are merged into a single broadcast domain.

C.

The trunk does not form, but VLAN 99 and VLAN 999 are allowed to traverse the link.

D.

The trunk forms but VLAN 99 and VLAN 999 are in a shutdown state.

Full Access
Question # 147

A wireless administrator has configured a WLAN; however, the clients need access to a less congested 5-GHz network for their voice quality. What action must be taken to meet the requirement?

A.

enable AAA override

B.

enable RX-SOP

C.

enable DTIM

D.

enable Band Select

Full Access
Question # 148

Which two events occur automatically when a device is added to Cisco DNA Center? (Choose two. )

A.

The device Is assigned to the Global site.

B.

The device Is placed into the Unmanaged state.

C.

The device is placed into the Provisioned state.

D.

The device is placed into the Managed state.

E.

The device is assigned to the Local site.

Full Access
Question # 149

Refer to the exhibit.

Question # 149

An engineer booted a new switch and applied this configuration via the console port. Which additional configuration must be applied to allow administrators to authenticate directly to enable privilege mode via Telnet using a local username and password?

Question # 149

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 150

Which two primary drivers support the need for network automation? (Choose two.)

A.

Eliminating training needs

B.

Increasing reliance on self-diagnostic and self-healing

C.

Policy-derived provisioning of resources

D.

Providing a ship entry point for resource provisioning

E.

Reducing hardware footprint

Full Access
Question # 151

Refer to the exhibit.

Question # 151

An engineer deploys a topology in which R1 obtains its IP configuration from DHCP. If

the switch and DHCP server configurations are complete and correct. Which two sets of commands must be configured on R1 and R2 to complete the task? (Choose two)

A.

R1(config)# interface fa0/0R1(config-if)# ip helper-address 198.51.100.100

B.

R2(config)# interface gi0/0R2(config-if)# ip helper-address 198.51.100.100

C.

R1(config)# interface fa0/0R1(config-if)# ip address dhcpR1(config-if)# no shutdown

D.

R2(config)# interface gi0/0R2(config-if)# ip address dhcp

E.

R1(config)# interface fa0/0R1(config-if)# ip helper-address 192.0.2.2

Full Access
Question # 152

Which type of traffic is sent with pure IPsec?

A.

broadcast packets from a switch that is attempting to locate a MAC address at one of several remote sites

B.

multicast traffic from a server at one site to hosts at another location

C.

spanning-tree updates between switches that are at two different sites

D.

unicast messages from a host at a remote site to a server at headquarters

Full Access
Question # 153

How does a Cisco Unified Wireless network respond to Wi-Fi channel overlap?

A.

It alternates automatically between 2.4 GHz and 5 GHz on adjacent access points

B.

It allows the administrator to assign channels on a per-device or per-interface basis.

C.

It segregates devices from different manufacturers onto different channels.

D.

It analyzes client load and background noise and dynamically assigns a channel.

Full Access
Question # 154

Refer to the exhibit.

Question # 154

What is the metric of the route to the 192.168.10.33/28 subnet?

A.

84

B.

110

C.

128

D.

192

E.

193

Full Access
Question # 155

How does the dynamically-learned MAC address feature function?

A.

The CAM table is empty until ingress traffic arrives at each port

B.

Switches dynamically learn MAC addresses of each connecting CAM table.

C.

The ports are restricted and learn up to a maximum of 10 dynamically-learned addresses

D.

It requires a minimum number of secure MAC addresses to be filled dynamically

Full Access
Question # 156

Refer to the exhibit.

Question # 156

What action establishes the OSPF neighbor relationship without forming an adjacency?

A.

modify helto interval

B.

modify process ID

C.

modify priority

D.

modify network type

Full Access
Question # 157

Refer to the exhibit.

Question # 157

R1 has just received a packet from host A that is destined to host B. Which route in the routing table is used by R1 to reach host B?

A.

10.10.13.0/25 [108/0] via 10.10.10.10

B.

10.10.13.0/25 [110/2] via 10.10.10.2

C.

10.10.13.0/25 [110/2] via 10.10.10.6

D.

10.10.13.0/25 [1/0] via 10.10.10.2

Full Access
Question # 158

When the LAG configuration is updated on a Cisco WLC which additional task must be performed when changes are complete?

A.

Flush all MAC addresses from the WLC

B.

Re-associate the WLC with the access point.

C.

Re-enable the WLC interfaces

D.

Reboot the WLC

Full Access
Question # 159

Connectivity between four routers has been established. IP connectivity must be configured in the order presented to complete the implementation. No dynamic routing protocols are included.

1. Configure static routing using host routes to establish connectivity from router R3 to the router R1 Loopback address using the source IP of 209.165.200.230.

2. Configure an IPv4 default route on router R2 destined for router R4.

3. Configure an IPv6 default router on router R2 destined for router R4.

Question # 159Question # 159

Full Access
Question # 160

Physical connectivity is implemented between the two Layer 2 switches,

and the network connectivity between them must be configured.

I . Configure an LACP EtherChanneI and number it as 44; configure it

between switches SWI and SW2 using interfaces EthernetO/O and

Ethernet0/1 on both sides. The LACP mode must match on both ends.

2. Configure the EtherChanneI as a trunk link.

3. Configure the trunk link with 802. Iq tags.

4. Configure VLAN ' MONITORING ' as the untagged VLAN of the

EtherChannel.

==================

Guidelines

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using

the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Question # 160

Full Access
Question # 161

Question # 161

All physical cabling between the two switches is installed. Configure the network connectivity between the switches using the designated VLANs and interfaces.

1. Configure VLAN 100 named Compute and VLAN 200 named Telephony where required for each task.

2. Configure Ethernet0/1 on SW2 to use the existing VLAN named Available.

3. Configure the connection between the switches using access ports.

4. Configure Ethernet0/1 on SW1 using data and voice VLANs.

5. Configure Ethemet0/1 on SW2 so that the Cisco proprietary neighbor discovery protocol is turned off for the designated interface only.

Question # 161

Full Access
Question # 162

Question # 162

Question # 162

IP connectivity between the three routers is configured. OSPF adjacencies must be established.

1. Configure R1 and R2 Router IDs using the interface IP addresses from the link that is shared between them.

2. Configure the R2 links with a max value facing R1 and R3. R2 must become the DR. R1 and R3 links facing R2 must remain with the default OSPF configuration for DR election. Verify the configuration after clearing the OSPF process.

3. Using a host wildcard mask, configure all three routers to advertise their respective Loopback1 networks.

4. Configure the link between R1 and R3 to disable their ability to add other OSPF routers.

Full Access
Question # 163

Topology:

Question # 163

Configure OSPF routing for the network by completing the following tasks:

Task 1

Configure OSPF on R2. Ensure that R1 and R3 become neighbors.

    Use process ID 30.

    Use 10.22.22.22 as the router ID.

    Under the OSPF process, advertise the following specific prefixes:

      10.0.23.0/28

      10.0.12.0/30

Task 2

Ensure that R2 always becomes the designated router (DR).

Full Access
Question # 164

Question # 164

Question # 164

Connectivity between three routers has been established, and IP services must be configured jn the order presented to complete the implementation Tasks assigned include configuration of NAT, NTP, DHCP, and SSH services.

1. All traffic sent from R3 to the R1 Loopback address must be configured for NAT on R2. All source addresses must be translated from R3 to the IP address of Ethernet0/0 on R2, while using only a standard access list named NAT To verify, a ping must be successful to the R1 Loopback address sourced from R3. Do not use NVI NAT configuration.

2. Configure R1 as an NTP server and R2 as a client, not as a peer, using the IP address of the R1 Ethernet0/2 interface. Set the clock on the NTP server for midnight on January 1, 2019.

3. Configure R1 as a DHCP server for the network 10.1.3.0/24 in a pool named TEST. Using a single command, exclude addresses 1-10 from the range. Interface Ethernet0/2 on R3 must be issued the IP address of 10.1.3.11 via DHCP.

4. Configure SSH connectivity from R1 to R3, while excluding access via other remote connection protocols. Access for user root and password Cisco must be set on router R3 using RSA and 1024 bits. Verify connectivity using an SSH session from router R1 using a destination address of 10.1.3.11. Do NOT modify console access or line numbers to accomplish this task.

Full Access
Question # 165

Question # 165

Question # 165

Question # 165

IP connectivity and OSPF are preconfigured on all devices where necessary. Do not make any changes to the IP addressing or OSPF. The company policy uses connected interfaces and next hops when configuring static routes except for load balancing or redundancy without floating static. Connectivity must be established between subnet 172.20.20.128/25 on the Internet and the LAN at 192.168.0.0/24 connected to SW1:

1. Configure reachability to the switch SW1 LAN subnet in router R2.

2. Configure default reachability to the Internet subnet in router R1.

3. Configure a single static route in router R2 to reach to the Internet subnet considering both redundant links between routers R1 and R2. A default route is NOT allowed in router R2.

4. Configure a static route in router R1 toward the switch SW1 LAN subnet where the primary link must be through Ethernet0/1. and the backup link must be through Ethernet0/2 using a floating route. Use the minimal administrative distance value when required.

Full Access
Question # 166

All physical cabling is in place. A company plans to deploy 32 new sites.

The sites will utilize both IPv4 and IPv6 networks.

1 . Subnet 172.25.0.0/16 to meet the subnet requirements and maximize

the number of hosts

Using the second subnet

• Assign the first usable IP address to e0/0 on Sw1O1

• Assign the last usable IP address to e0/0 on Sw102

2. Subnet to meet the subnet requirements and maximize

the number of hosts

c Using the second subnet

• Assign an IPv6 GUA using a unique 64-Bit interface identifier

on e0/0 on Sw101

• Assign an IPv6 GUA using a unique 64-Bit interface identifier

on eO/O on swi02

Guidelines

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using

the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Question # 166

Full Access
Question # 167

Physical connectivity is implemented between the two Layer 2 switches, and the network connectivity between them must be configured

1. Configure an LACP EtherChannel and number it as 1; configure it between switches SW1 and SVV2 using interfaces Ethernet0/0 and Ethernet0/1 on both sides. The LACP mode must match on both ends

2 Configure the EtherChannel as a trunk link.

3. Configure the trunk link with 802.1 q tags.

4. Configure the native VLAN of the EtherChannel as VLAN 15.

Question # 167Question # 167

Full Access
Question # 168

All physical cabling is in place. Router R4 and PCI are fully configured and

inaccessible. R4 ' s WAN interfaces use .4 in the last octet for each subnet.

Configurations should ensure that connectivity is established end-to-end.

1 . Configure static routing to ensure RI prefers the path through R2 to

reach only PCI on R4 ' s LAN

2. Configure static routing that ensures traffic sourced from RI will take

an alternate path through R3 to PCI in the event of an outage along

the primary path

3. Configure default routes on RI and R3 to the Internet using the least number of hops

Guidelines

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using

the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Question # 168

Full Access
Question # 169

Question # 169

Three switches must be configured for Layer 2 connectivity. The company requires only the designated VLANs to be configured on their respective switches and permitted accross any links between switches for security purposes. Do not modify or delete VTP configurations.

The network needs two user-defined VLANs configured:

VLAN 110: MARKETING

VLAN 210: FINANCE

1. Configure the VLANs on the designated switches and assign them as access ports to the interfaces connected to the PCs.

2. Configure the e0/2 interfaces on Sw1 and Sw2 as 802.1q trunks with only the required VLANs permitted.

3. Configure the e0/3 interfaces on Sw2 and Sw3 as 802.1q trunks with only the required VLANs permitted.

Question # 169

Full Access
Question # 170

Configure IPv4 and IPv6 connectivity between two routers. For IPv4, use a /28 network from the 192.168.1.0/24 private range. For IPv6, use the first /64 subnet from the 2001:0db8:aaaa::/48 subnet.

1. Using Ethernet0/1 on routers R1 and R2, configure the next usable/28 from the 192.168.1.0/24 range. The network 192.168.1.0/28 is unavailable.

2. For the IPv4 /28 subnet, router R1 must be configured with the first usable host address.

3. For the IPv4 /28 subnet, router R2 must be configured with the last usable host address.

4. For the IPv6 /64 subnet, configure the routers with the IP addressing provided from the topology.

5. A ping must work between the routers on the IPv4 and IPv6 address ranges.

Question # 170Question # 170

Full Access
Question # 171

Which interface condition is occurring in this output?

Question # 171

A.

duplex mismatch

B.

queueing

C.

bad NIC

D.

broadcast storm

Full Access
Question # 172

Which group of channels in the 802.1ib/g/n/ac/ax 2.4 GHz frequency Bands are nonoverlapping channels?

A.

channels 1, 5, and 10

B.

channels 1,6, and 11

C.

channels 1,5, and 11

D.

channels 1,6, and 10

Full Access
Question # 173

Question # 173

Refer to the exhibit. Which configuration for RTR-1 denies SSH access from PC-1 to any RTR-1 interface and allows all other traffic?

A.

access list 100 deny tcp host 172.16.1.33 any eq 23access list 100 permit ip any anyinterface GigabitEthernet0/0ip access-group 100 in

B.

access list 100 deny tcp host 172.16.1.33 any eq 22access list 100 permit ip any anyinterface GigabitEthernet0/0ip access-group 100 in

C.

access list 100 deny tcp host 172.16.1.33 any eq 22access list 100 permit ip any anyline vty 0 15access-class 100 in

D.

access list 100 deny tcp host 172.16.1.33 any eq 23access list 100 permit ip any anyline vty 0 15access-class 100 in

Full Access
Question # 174

Which group of channels in the 802.11b/g/n/ax 2.4 GHz frequency bands are non-overlapping channels?

A.

channels 1, 5, and 10

B.

channels 1, 5, and 11

C.

channels 1, 6, and 10

D.

channels 1, 6, and 11

Full Access
Question # 175

Which enhancements were implemented as part of WPA3?

A.

802.1x authentication and AES-128 encryption

B.

TKIP encryption improving WEP and per-packet keying

C.

AES-64 m personal mode and AES-128 in enterprise mode

D.

forward secrecy and SAE in personal mode for secure initial key exchange

Full Access
Question # 176

What does a switch search for in the CAM table when forwarding a frame?

A.

source MAC addresss and aging time

B.

destination MAC addresss and flush time

C.

source MAC addresss and source port

D.

destination MAC addresss and destination port

Full Access
Question # 177

Refer to the exhibit.

Question # 177

Which configuration parameter is preventing host C from reaching the internet?

A.

automatic DNS

B.

default gateway

C.

IP network mask

D.

IP addressss assignment

Full Access
Question # 178

Which technology allows multiple operating systems lo run a single physical server?

A.

cloud computing

B.

virtualization

C.

application hosting

D.

containers

Full Access
Question # 179

What is a characteristic of private IPv4 addresssing?

A.

Reduces the forwarding table on network routers

B.

Used on the external interface of a firewall

C.

Used by ISPs when only one IP is needed to connect to the internet

D.

Address space which is isolated froin the internet

Full Access
Question # 180

Question # 180

Refer to the exhibit. After applying this configuration to router R1, a network engineer is verifying the implementation. If all links are operating normally, and the engineer sends a series of packets from PC1 to PC3. how are the packets routed?

A.

They are routed to 172.16.20.2.

B.

They are routed to 192.168.100.2.

C.

They are distributed sent round robin to interfaces SO/0/0 and SO/0/1.

D.

They are routed to 10.0.0.2.

Full Access
Question # 181

Question # 181

Refer to the exhibit. A network engineer must replicate the AccessSw1 NTP configuration on a new switch. The engineer could not access privileged mode on AccessSw1 to view its configuration.

Which command must be applied to the new switch to replicate the configuration?

A.

ntp master

B.

ntp master 3

C.

ntp server 2001:db8:12::1

D.

ntp server 127.127.1.1

Full Access
Question # 182

What differentiates the Cisco OfficeExtend AP mode from FlexConnect AP mode?

A.

FlexConnect allows a personal SSID to be configured on the AP, and personal SSIDs are not supported with OfficeExtend.

B.

OfficeExtend does not support DTLS tunneling of traffic to the WLC, and FlexConnect tunnels traffic to the WLC with DTLS.

C.

OfficeExtend tunnels all traffic through the WLC, and FlexConnect terminates client traffic at the AP switch port.

D.

FlexConnect must be deployed behind a router that NATs the client traffic, and OfficeExtend uses public IP sources.

Full Access
Question # 183

A network architect planning a new Wi-Fi network must decide between autonomous, cloud-based, and split MAC architectures. Which two facts should the architect consider? (Choose two.)

A.

Lightweight access points are solely used by split MAC architectures.

B.

Cloud-based architectures uniquely use the CAPWAP protocol to communicate between access points and clients.

C.

Each of the three architectures must use WLCs to manage their access points.

D.

All three architectures use access points to manage the wirelesss devices connected to the wired infrastructure.

E.

Autonomous architectures exclusively use tunneling protocols to manage access points remotely.

Full Access
Question # 184

Refer to the exhibit.

Question # 184

The LACP EtherChannel is configured, and the last change is to modify the interfaces on SwitchA to respond to packets received, but not to initiate negotiation. The interface range gigabitethernet0/0-15 command is entered. What must be configured next?

A.

SwitchA(config-if-range) #channel-group 1 mode desirable

B.

SwitchA(config-if-range) #channel-group 1 mode auto

C.

SwitchA(config-if-range) #channel-group 1 mode active

D.

SwitchA(config-if-range) #channel-group 1 mode passive

Full Access
Question # 185

Which mechanism carries multicast traffic between remote sites and supports encryption?

A.

GRE over IPsec

B.

IPsec over ISATAP

C.

GRE

D.

ISATAP

Full Access
Question # 186

Which protocol does Ansible use to push modules to nodes in a network?

A.

SSH

B.

SNMP

C.

Kerberos

D.

Telnet

Full Access
Question # 187

Refer to the exhibit.

Question # 187

Packets are flowing from 192.168 10.1 to the destination at IP addressss 192.168.20 75. Which next hop will the router select for the packet?

A.

10.10101

B.

10.10.10.11

C.

10.10.10.12

D.

10.101014

Full Access
Question # 188

Refer to the exhibit.

Question # 188

Switch AccSw2 has just been added to the network along with PC2. All VLANs have been implemented on AccSw2. How must the ports on AccSw2 be configured to establish Layer 2 connectivity between PC1 and PC2?

A.
B.

B.

C.

C.

D.

D.

Full Access
Question # 189

Drag and drop the statements about AAA froin the left onto the corresponding AAA services on the right. Not all options are used.

Question # 189

Full Access
Question # 190

Question # 190

Refer to the exhibit. What is represented in line 2 within this JSDN schema?

A.

key

B.

value

C.

object

D.

array

Full Access
Question # 191

How does MAC learning function?

A.

Sends frames with unknown destinations to a multicast group.

B.

Increases security on the management VLAN.

C.

Rewrites the source and destination MAC addresss.

D.

Associates the MAC addresss with the port on which it is received.

Full Access
Question # 192

Refer to the exhibit.

Question # 192

How many objects, keys and JSDN list values are present?

A.

three objects, two keys, and three JSDN list values

B.

three objects, three keys and two JSDN Ml values

C.

one object, three keys, and three JSDN list values

D.

one object, three keys and two JSDN list values

Full Access
Question # 193

An engineer requires a switch interface to actively attempt to establish a trunk link with a neighbor switch. What command must be configured?

A.

switchport mode dynamic desirable

B.

switchport mode trunk

C.

switchport nonegotiate

D.

switchport mode dynamic auto

Full Access
Question # 194

How does a network administrator securely manage an AP in lightweight mode?

A.

using the CLI via an out-of-band connection

B.

using the WLC GUI via HTTPS

C.

using the AP GUI via an in-band SSH connection

D.

using the CLI via a virtual interface with SSH

Full Access
Question # 195

Question # 195

Refer to the exhibit. The Wi-Fi SSID " Office_WLAN " has Layer 2 Security configured with MAC filtering enabled. What additional security is provided by this specific feature?

A.

There is an extra layer of security that ensures only authorized devices with known MAC addressses connect to the network

B.

There is strong mutual authentication used between NAC and the network devices using X.509 standard

C.

All data frames exchanged between the client and the access point are encrypted

D.

There is a Galcis cache algorithm configured that provides strong encryption and authentication

Full Access
Question # 196

A new DHCP server has been deployed in a corporate environment with lease time set to eight hours. Which CMD command on a Windows-based device allows the engineer to verify the DHCP lease expiration?

A.

ipconfig /renew

B.

ipconfig

C.

ipconfig /all

D.

ipconfig /displaydns

Full Access
Question # 197

Which type of hypervisor operates without an underlying OS to host virtual machines?

A.

Type 1

B.

Type 2

C.

Type 3

D.

Type 12

Full Access
Question # 198

A switch is forwarding a frame out of an interfaces except the interface that received the frame. What is the technical term for this process?

A.

ARP

B.

CDP

C.

flooding

D.

multicast

Full Access
Question # 199

What is an enhancement implemented in WPA3?

A.

employs PKI and RADIUS to identify access points

B.

applies 802.1x authentication and AES-128 encryption

C.

uses TKIP and per-packet keying

D.

defends against deauthentication and disassociation attacks

Full Access
Question # 200

Refer to the exhibit.

Question # 200

What is occurring on this switch?

A.

A high number of frames smaller than 64 bytes are received.

B.

Frames are dropped after 16 failed transmission attempts.

C.

The internal transmit buffer is overloaded.

D.

An excessive number of frames greater than 1518 bytes are received.

Full Access
Question # 201

What is a benefit of a point-to-point leased line?

A.

flexibility of design

B.

simplicity of configuration

C.

low cost

D.

full-mesh capability

Full Access
Question # 202

Which two features are provided by Ansible in network automation? (Choose two.)

A.

supplying network credentials

B.

role-based access control

C.

agentless deployment

D.

manual playbook runs

E.

launching job templates using version control

Full Access
Question # 203

What is a characteristic of an SSID in wirelesss networks?

A.

provides protection against spyware

B.

eliminates network piggybacking

C.

associates a name to a wirelesss network

D.

allows easy file sharing between endpoints

Full Access
Question # 204

Drag and drop the common functions froin the left onto the cofresponding network topology architecture layer on the right. Not all common functions are used.

Question # 204

Full Access
Question # 205

What is represented in line 3 within this JSDN schema?

Question # 205

A.

object

B.

key

C.

array

D.

value

Full Access
Question # 206

Refer to the exhibit.

Question # 206

Packets are flowing from 192.168.10.1 to the destination at IP addressss 192.168.20.75. Which next hop will the router select for the packet?

A.

10.10.10.1

B.

10.10.10.11

C.

10.10.10.12

D.

10.10.10.14

Full Access
Question # 207

Drag and drop the characteristic from the left onto the IPv6 address type on the right.

Question # 207

Full Access
Question # 208

Which key function is provided by the data plane?

A.

Making routing decisions

B.

Originating packets

C.

Forwarding traffic to the next hop

D.

Exchanging routing table data

Full Access
Question # 209

Question # 209

Refer to the exhibit. The My_WLAN wirelesss LAN was configured with WPA2 Layer 2 PSK security. Which additional configuration must the administrator perform to allow users to connect to this WKAN on a different subnet called Data?

A.

Enable Broadcast SSID and select data froin the Interface/Interface Group drop-down list.

B.

Enable Status and select data froin the Interface/Interface Group drop-down list.

C.

Enable Status and set the NAS-ID to data.

D.

Enable Status and enable Broadcast SSID.

Full Access
Question # 210

Which components are contained within a virtual machine?

A.

physical resources, including the NIC, RAM, disk, and CPU

B.

configuration files backed by physical resources froin the Hypervisor

C.

applications running on the Hypervisor

D.

processes running on the Hypervisor and a guest OS

Full Access
Question # 211

What describes a northbound REST API for SDN?

A.

application-facing interface for SNMP GET requests

B.

network-element-facing interface for GET POST PUT and DELETE methods

C.

network-element-facing interface for the control and data planes

D.

application-facing interface for GET, POST, PUT, and DELETE methods

Full Access
Question # 212

Which event has occurred if a router sends a notice level message to a syslog server?

A.

An ICMP connection has been built

B.

A certificate has expired

C.

An interface line has changed status

D.

A TCP connection has been torn down

Full Access
Question # 213

Which interface condition is occurring in this output?

Question # 213

A.

duplex mismatch

B.

bad NIC

C.

high throughput

D.

broadcast storm

Full Access
Question # 214

What are two behaviors of a point-to-point WAN topology? (Choose two.)

A.

It uses a single router to route traffic between sites.

B.

It leverages a dedicated connection.

C.

It connects remote networks through a single line.

D.

t delivers redundancy between the central office and branch offices.

E.

It provides direct connections between each router in the topology.

Full Access
Question # 215

Question # 215

Refer to the exhibit. Of the routes learned with dynamic routing protocols, which has the least preferred metric?

A.

EIGRP

B.

OSPF

C.

Local

D.

RIP

Full Access
Question # 216

Which AP mode serves as the primary hub in a point-to-multipoint network topology.

A.

FlexConnect

B.

SE-Connect

C.

bridge

D.

local

Full Access
Question # 217

Refer to the exhibit.

Question # 217

The switch cat9k acc.1 connects users to the campus LAN. Printing services are inaccessible through the network. Which interface issue is causing the connectivity problems?

A.

A large number of broadcast packets are resulting in a port reset

B.

Excessive collisions are causing dropped frames.

C.

The interface output queue cannot process the Ethernet frames.

D.

A bad checksum is causing Ethernet frames to drop.

Full Access
Question # 218

How are API keys used to enforce rate limiting?

A.

To define the network path the API request should take

B.

To uniquely identify each client application

C.

To specify the type of data format the client prefers to receive

D.

To encrypt data sent in the API request

Full Access
Question # 219

Question # 219

Refer to the exhibit. IPv6 must be implemented on R1 to the ISP The uplink between R1 and the ISP must be configured with a manual assignment, and the LAN interface must be self-provisioned Both connections must use the applicable IPv6 networks Which two configurations must be applied to R1? (Choose two.)

A.

interface Gi0/1ipv6 addresss 2001:db8:0F1B:FCCB:ACCE:FCED:ABCD:FA02:/127

B.

interface Gi0/0ipv6 addresss 2001:db8:1:AFFF::/64 eui-64

C.

interface Gi0/1ipv6 addresss 2001:db8:0F1B:FCCB:ACCE:FCED:ABCD:FA00:/127

D.

interface Gi0/0ipv6 addresss 2001:db8:0:AFFF::/64 eui-64

E.

interface Gi0/0ipv6 addresss 2001:db8:0F1B:FCCB:ACCE:FCED:ABCD:FA03;/127

Full Access
Question # 220

Question # 220

Refer to the exhibit. What is the value of the administrative distance for the default gateway?

A.

10

B.

0

C.

1

D.

110

Full Access
Question # 221

A router received three destination prefixes:10.0.0/18, and 10.0.0/24. When the show ip route command is executed, which output does it return?

A)

Question # 221

B)

Question # 221

C)

Question # 221

D)

Question # 221

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 222

Which advantage does machine learning offer for network security?

A.

It improves real-time threat detection

B.

It enforces password complexity requirements

C.

It manages firewall rule sets

D.

It controls VPN access permissions

Full Access
Question # 223

Which two HTTP methods are suitable for actions performed by REST-based APIs? (Choose two.)

A.

REMOVE

B.

REDIRECT

C.

POST

D.

GET

E.

PUT

Full Access
Question # 224

Question # 224

Refer to the exhibit. With a reference bandwidth of 100 Gb on all routers, which path does router Y use to get to network 192.168.1.0/24?

A.

router C > D > A > B > F

B.

router C > D > A > F

C.

router E > F

D.

router E > B > F

Full Access
Question # 225

Question # 225

Refer to the exhibit. What is the administrative distance for the advertised prefix that includes the host IP addressss 10.30.0.1?

A.

10.0.0.2

B.

110

C.

30

D.

2

Full Access
Question # 226

What does traffic shaping do?

A.

It modifies the QoS attributes of a packet

B.

It queues excess traffic

C.

It organizes traffic into classes.

D.

It sets QoS attributes within a packet.

Full Access
Question # 227

Which interface is used to send traffic to the destination network?

10.249.210.56/25 [90/6144] via G0/15

10.249.210.56/25 [90/45053] via G0/13

10.249.210.56/25 [110/3693] via G0/16

10.249.210.56/25 [110/360] via G0/12

A.

G0/16

B.

G0/15

C.

G0/13

D.

G0/12

Full Access
Question # 228

What is the purpose of classifying network traffic in QoS?

A.

Writes the class identifier of a packet to a dedicated field in the packet header

B.

Services traffic according to its class

C.

Configures traffic-matching rules on network devices

D.

Identifies the type of traffic that will receive a particular treatment

Full Access
Question # 229

Question # 229

Refer to the exhibit. Inter-VLAN routing is configured on SW1. Client A is running Linux as an OS in VLAN 10 with a default gateway IP 10.0.0.1 but cannot ping client B in VLAN 20 running Windows. What action must be taken to verify that client A has the correct IP settings?

A.

Run the ipconfig command on client A and ensure that the IP addressss is within the host range of 10.0.0.1 - 10.0.255.254.

B.

Run the ifconfig command on client A to confirm that its IP and subnet mask fall within 255.254.0.0.

C.

Run the ipconfig command on client A to confirm that the correct 10.0.0.1 default gateway is used.

D.

Run the ifconfig command on client A to confirm that the subnet mask is set to 255.255.128.0.

Full Access
Question # 230

What is the function of a controller in a software-defined network?

A.

multicast replication at the hardware level

B.

forwarding packets

C.

fragmenting and reassembling packets

D.

setting packet-handling policies

Full Access
Question # 231

A network engineer is configuring a new router at a branch office. The router is connected to an upstream WAN network that allows the branch to communicate with the head office. The central time server with IP addressss 172.24.54.8 is located behind a firewall at the head office. Which command must the engineer configure so that the software clock of the new router synchronizes with the time server?

A.

ntp master 172.24.54.8

B.

ntp client 172.24.54.8

C.

ntp peer 172.24.54.8

D.

ntp server 172.24.54.8

Full Access
Question # 232

Drag and drop the Ansible terms from the left onto the right.

Question # 232

Full Access
Question # 233

What are two disadvantages of a full-mesh topology? (Choose two.)

A.

It needs a high MTU between sites.

B.

It has a high implementation cost.

C.

It must have point-to-point communication.

D.

It requires complex configuration.

E.

It works only with BGP between sites.

Full Access
Question # 234

Refer to the exhibit.

Question # 234

How many objects are present in the given JSON-encoded data?

A.

one

B.

four

C.

seven

D.

nine

Full Access
Question # 235

Which syslog severity level is considered the most severe and results in the system being considered unusable?

A.

Alert

B.

Error

C.

Emergency

D.

Critical

Full Access
Question # 236

Refer to the exhibit

Question # 236

A network engineer started to configure port security on a new switch. These requirements must be met:

* MAC addresses must be learned dynamically

* Log messages must be generated without disabling the interface when unwanted traffic is seen

Which two commands must be configuredd to complete this task " ? (Choose two)

A.

SW(config-if)=switchport port-security mac-address sticky

B.

SW(config-if)=switchport port-security violation restrict

C.

SW(config-if)sswitchport port-security mac-address 0010.7B84.45E6

D.

SW(config-if)switchport port-security maximum 2

E.

SW(config-if)=switchport port-security violation shutdown

Full Access
Question # 237

What is an advantage of using auto mode versus static mode for power allocation when an access point is connected to a PoE switch port?

A.

All four pairs of the cable are used

B.

It detects the device is a powered device

C.

The default level is used for the access point

D.

Power policing is enabled at the same time

Full Access
Question # 238

The clients and DHCP server reside on different subnets. Which command must be used to forward requests and replies between clients on the 10.10.0.1/24 subnet and the DHCP server at 192.168.10.1?

A.

ip route 192.168.10.1

B.

ip default-gateway 192.168.10.1

C.

ip helper-address 192.168.10.1

D.

ip dhcp address 192.168.10.1

Full Access
Question # 239

Which channel-group mode must be configuredd when multiple distribution interfaces connected to a WLC are bundled?

A.

Channel-group mode passive.

B.

Channel-group mode on.

C.

Channel-group mode desirable.

D.

Channel-group mode active.

Full Access
Question # 240

Why would a network administrator choose to implement automation in a network environment?

A.

To simplify the process of maintaining a consistent configuration state across all devices

B.

To centralize device information storage

C.

To implement centralized user account management

D.

To deploy the management plane separately from the rest of the network

Full Access
Question # 241

Refer to the exhibit.

Question # 241

An engineer is configuring a Layer 3 port-channel interface with LACP. The configuration on the first device is complete, and it is verified that both interfaces have registered the neighbor device in the CDP table. Which task on the neighbor device enables the new port channel to come up without negotiating the channel?

A.

Change the EtherChannel mode on the neighboring interfaces to auto.

B.

Configure the IP address of the neighboring device.

C.

Bring up the neighboring interfaces using the no shutdown command.

D.

Modify the static EtherChannel configuration of the device to passive mode.

Full Access
Question # 242

Refer to the exhibit.

Question # 242

Which two values does router R1 use to determine the best path to reach destinations in network 10.0.0.0/8? (Choose two.)

A.

longest prefix match

B.

highest administrative distance

C.

highest metric

D.

lowest metric

E.

lowest cost to reach the next hop

Full Access
Question # 243

What is the definition of backdoor malware?

A.

malicious code that is installed onto a computer to allow access by an unauthorized user

B.

malicious code with the main purpose of downloading other malicious code

C.

malicious program that is used to launch other malicious programs

D.

malicious code that infects a user machine and then uses that machine to send spam

Full Access
Question # 244

What is a reason to implement IPv4 private addressing?

A.

Reduce the risk of a network security breach

B.

Comply with PCI regulations

C.

Comply with local law

D.

Reduce the size of the forwarding table on network routers

Full Access
Question # 245

Which property is shared by 10GBase-SR and 10GBase-LR interfaces?

A.

Both require fiber cable media for transmission.

B.

Both require UTP cable media for transmission.

C.

Both use the single-mode fiber type.

D.

Both use the multimode fiber type.

Full Access
Question # 246

What is the primary purpose of private address space?

A.

conserve globally unique address space

B.

simplify the addressing in the network

C.

limit the number of nodes reachable via the Internet

D.

reduce network complexity

Full Access
Question # 247

Refer to the exhibit.

Question # 247

The image server and client A are running an application that transfers an extremely high volume of data between the two. An engineer is configuring a dedicated circuit between R1 and R2. Which set of commands must the engineer apply to the routers so that only traffic between the image server and client A is forces to use the new circuit?

A.

R1(config)#ip route 10.10.13.10 255.255.255.255 10.10.10.6R2(config)#ip route 192.168.0.100 255.255.255.255 10.10.10.5

B.

R1(config)#ip route 10.10.13.10 255.255.255.128 10.10.10.6R2(config)#lp route 192.168.0.100 255.255.255.0 10.10.10.5

C.

R1(config)#ip route 10.10.13.10 255.255.255.252 10.10.10.6R2(config)#tp route 192.168.0.100 255.255.255.252 10.10.10.5

D.

R1(config)#ip route 10.10.13.10 255.255.255.255 10.10.10.2R2(config)#ip route 192.168.0.100 255.255.255.255 10.10.10.1

Full Access
Question # 248

Which type of address is shared by routers in a HSRP implementation and used by hosts on the subnet as their default gateway address?

A.

multicast address

B.

loopback IP address

C.

virtual IP address

D.

broadcast address

Full Access
Question # 249

What is a characteristic of RSA?

A.

It uses preshared keys for encryption

B.

It requires both sides to have identical keys

C.

It is a private-key encryption algorithm

D.

It is a public-key cryptosystem

Full Access
Question # 250

Which protocol is used in Software Defined Access (SDA) to provide a tunnel between two edge nodes in different fabrics?

A.

Generic Router Encapsulation (GRE)

B.

Virtual Local Area Network (VLAN)

C.

Virtual Extensible LAN (VXLAN)

D.

Point-to-Point Protocol

Full Access
Question # 251

Refer to the exhibit.

Question # 251

An engineer is configuring a new Cisco switch NewSW, to replace SW2 The details have been provided

• Switches SW1 and SW2 are third-party devices without support for trunk ports

• The existing connections must be maintained between PC1 PC2 and PC3

• Allow the switch to pass traffic from future VLAN 10. Which configuration must be applied?

A)

Question # 251

B)

Question # 251

C)

Question # 251

D)

Question # 251

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 252

Drag and drop the TCP/IP protocols from the left onto their primary transmission protocols on the right.

Question # 252

Full Access
Question # 253

Refer to the exhibit.

Question # 253

What is the subnet mask of the route to the 10.10.13.160 prefix?

A.

255.255.255.240

B.

255.255.255.128

C.

255.255.248.

D.

255.255.255.248

Full Access
Question # 254

What is the function of northbound API?

A.

It upgrades software and restores files.

B.

It relies on global provisioning and configuration.

C.

It supports distributed processing for configuration.

D.

It provide a path between an SDN controller and network applications.

Full Access
Question # 255

Which enhancement is implemented in WPA3?

A.

applies 802.1x authentication

B.

uses TKIP

C.

employs PKI to identify access points

D.

protects against brute force attacks

Full Access
Question # 256

Drag and drop the Wi-Fi terms from the left onto the descriptions on the right.

Question # 256

Full Access
Question # 257

What does a switch do when it receives a frame whose destination MAC address is missing from the MAC address table?

A.

It floods the frame unchanged across all remaining ports in the incoming VLAN.

B.

It appends the table with a static entry for the MAC and shuts down the port.

C.

It updates the CAM table with the destination MAC address of the frame.

D.

It changes the checksum of the frame to a value that indicates an invalid frame.

Full Access
Question # 258

Refer to the exhibit.

Question # 258

The network engineer is configuring a new WLAN and is told to use a preshared key for authentication instead of the RADIUS servers. Which additional set of tasks must the engineer perform to complete the configuration?

A.

Disable PMF Enable PSK Enable 802.1x

B.

Select WPA Policy Enable CCKM Enable PSK

C.

Select WPA Policy Select WPA2 Policy Enable FT PSK

D.

Select WPA2 Policy Disable PMF Enable PSK

Full Access
Question # 259

Refer to the exhibit.

Question # 259

An engineer is checking the routing table in the main router to identify the path to a server on the network. Which route does the router use to reach the server at 192.168.2.2?

A.

S 192.168.0.0/20 [1/0] via 10.1.1.1

B.

S 192.168.2.0/29 [1/0] via 10.1.1.1

C.

S 192.168.2.0/28 [1/0] via 10.1.1.1

D.

S 192.168.1.0/30 [1/0] via 10.1.1.1

Full Access
Question # 260

Question # 260

Refer to the exhibit. An engineer must configure a static network route between two networks so that host A communicates with host B. Drag and drop the commands from the left onto the routers where they must be configuredd on the right. Not all commands are used.

Question # 260

Full Access
Question # 261

Refer the exhibit.

Question # 261

What is the cause of poor performance on router R19?

A.

excessive collisions

B.

speed and duplex mismatch

C.

port oversubscription

D.

excessive CRC errors

Full Access
Question # 262

Refer to the exhibit.

Question # 262

What is the prefix length for the route that router1 will use to reach host A?

A.

/25

B.

/27

C.

/28

D.

/29

Full Access
Question # 263

Drag and drop the statement about AAA services from the left to the corresponding AAA services on the right.

Question # 263

Full Access
Question # 264

Drag and drop the characteristics of transport layer protocols from the left onto the corresponding protocols on the right.

Question # 264

Full Access
Question # 265

When a WPA2-PSK WLAN is configured in the Wireless LAN Controller, what is the minimum number of characters that is required in ASCII format?

A.

6

B.

8

C.

12

D.

18

Full Access
Question # 266

Refer to the exhibit.

Question # 266

Wireless LAN access must be set up to force all clients from the NA WLAN to authenticate against the local database. The WLAN is configured for local EAP authentication. The time that users access the network must not be limited. Which action completes this configuration?

A.

Uncheck the Guest User check box

B.

Check the Guest User Role check box

C.

Set the Lifetime (seconds) value to 0

D.

Clear the Lifetime (seconds) value

Full Access
Question # 267

Question # 267

Refer to the exhibit. Local access for R4 must be established and these requirements must be met:

• Only Telnet access is allowed.

• The enable password must be stored securely.

• The enable password must be applied in plain text.

• Full access to R4 must be permitted upon successful login.

Which configuration script meets the requirements?

A)

Question # 267

B)

Question # 267

C)

Question # 267

D)

Question # 267

A.

Option

B.

Option

C.

Option

D.

Option

Full Access
Question # 268

Refer to the exhibit.

Question # 268

Which action by the router when a packet is sourced from 10.10.10.2 and destined 10.10.10.16?

A.

It queues the packets waiting for the route to be learned.

B.

It floods packets to all learned next hops.

C.

It discards the packets.

D.

It uses a route that is similar to the destination address.

Full Access
Question # 269

PC1 tries to send traffic to newly installed PC2. The PC2 MAC address is not listed in the MAC address table of the switch, so the switch sends the packet to all ports in the same VLAN Which switching concept does this describe?

A.

MAC address aging

B.

MAC address table

C.

frame flooding

D.

spanning-tree protocol

Full Access
Question # 270

Refer to the exhibit.

An engineer assigns IP addressing to the current VLAN with three PCs. The configuration must also account for the expansion of 30 additional VLANS using the same Class C subnet for subnetting and host count. Which command set fulfills the request while reserving address space for the expected growth?Question # 270

A.

Switch(config)#interface vlan 10Switch(config-if)#ip address 192.168.0.1 255.255.255.252

B.

Switch(config)#interface vlan 10Switch(config-if)#ip address 192.168.0.1 255.255.255.248

C.

Switch(config)#interface vlan 10Switch(config-if)#ip address 192.168.0.1 255.255.255.0

D.

Switch(config)#interface vlan 10Switch(config-if)#ip address 192.168.0.1 255.255.255.128

Full Access
Question # 271

A network engineer must configure an interface with IIP address 10.10.10.145 and a subnet mask equivalent to 11111111.11111111.11111111.11111000. Which subnet mask must the engineer use?

A.

/29

B.

/30

C.

/27

D.

/28

Full Access
Question # 272

Which functionality is provided by the console connection on a Cisco WLC?

A.

out-of-band management

B.

secure in-band connectivity for device administration

C.

unencrypted in-band connectivity for file transfers

D.

HTTP-based GUI connectivity

Full Access
Question # 273

Which security method is used to prevent man-in-the-middle attack?

A.

authorization

B.

authentication

C.

anti-replay

D.

accounting

Full Access
Question # 274

Which access layer threat-mitigation technique provides security based on identity?

A.

Dynamic ARP Inspection

B.

using a non-default native VLAN

C.

802.1x

D.

DHCP snooping

Full Access
Question # 275

Which 802.11 management frame type is sent when a client roams between access points on the same SSID?

A.

Reassociation Request

B.

Probe Request

C.

Authentication Request

D.

Association Request

Full Access
Question # 276

Which resource is able to be shared among virtual machines deployed on the same physical server?

A.

disk

B.

applications

C.

VM configuration file

D.

operating system

Full Access
Question # 277

Which WLC port connects to a switch to pass normal access-point traffic?

A.

redundancy

B.

console

C.

distribution system

D.

service

Full Access
Question # 278

What does a router do when configured with the default DNS lookup settings, and a URL is entered on the CLI?

A.

initiates a ping request to the URL

B.

prompts the user to specify the desired IP address

C.

continuously attempts to resolve the URL until the command is cancelled

D.

sends a broadcast message in an attempt to resolve the URL

Full Access
Question # 279

Refer to the exhibit.

Question # 279

Which password must an engineer use to enter the enable mode?

A.

adminadmin123

B.

default

C.

testing1234

D.

cisco123

Full Access
Question # 280

Refer to the exhibit.

Question # 280

which path is used by the router for internet traffic ?

A.

209.165.200.0/27

B.

10.10.10.0/28

C.

0.0.0.0/0

D.

10.10.13.0/24

Full Access
Question # 281

Which device controls the forwarding of authentication requests for users when connecting to the network using a lightweight access point?

A.

TACACS server

B.

wireless access point

C.

RADIUS server

D.

wireless LAN controller

Full Access
Question # 282

Which option about JSON is true?

A.

uses predefined tags or angle brackets () to delimit markup text

B.

used to describe structured data that includes arrays

C.

used for storing information

D.

similar to HTML, it is more verbose than XML

Full Access
Question # 283

Which switch technology establishes a network connection immediately when it is plugged in?

A.

PortFast

B.

BPDU guard

C.

UplinkFast

D.

BackboneFast

Full Access
Question # 284

Which two WAN architecture options help a business scalability and reliability for the network? (Choose two)

A.

asynchronous routing

B.

single-homed branches

C.

dual-homed branches

D.

static routing

E.

dynamic routing

Full Access
Question # 285

An engineer needs to add an old switch back into a network. To prevent the switch from corrupting the VLAN database which action must be taken?

A.

Add the switch in the VTP domain with a lower revision number

B.

Add the switch with DTP set to dynamic desirable

C.

Add the switch in the VTP domain with a higher revision number

D.

Add the switch with DTP set to desirable

Full Access
Question # 286

Refer to exhibit.

Question # 286

Which statement explains the configuration error message that is received?

A.

It is a broadcast IP address

B.

The router does not support /28 mask.

C.

It belongs to a private IP address range.

D.

It is a network IP address.

Full Access
Question # 287

Which mode allows access points to be managed by Cisco Wireless LAN Controllers?

A.

autonomous

B.

lightweight

C.

bridge

D.

mobility express

Full Access
Question # 288

Which protocol does an IPv4 host use to obtain a dynamically assigned IP address?

A.

ARP

B.

DHCP

C.

CDP

D.

DNS

Full Access
Question # 289

Which two outcomes are predictable behaviors for HSRP? (Choose two.)

A.

The two routers synchronize configurations to provide consistent packet forwarding

B.

The two routers negotiate one router as the active router and the other as the standby router

C.

Each router has a different IP address, both routers act as the default gateway on the LAN, and traffic is load-balanced between them

D.

The two routers share a virtual IP address that is used as the default gateway for devices on the LAN

E.

The two routers share the same interface IP address and default gateway traffic is load-balanced between them

Full Access
Question # 290

Refer to the exhibit.

Question # 290

How does the router manage traffic to 192.168.12.16?

A.

It selects the RIP route because it has the longest prefix inclusive of the destination address.

B.

It chooses the OSPF route because it has the longest prefix inclusive of the destination address.

C.

it load-balances traffic between all three routes

D.

It chooses the EIGRP route because it has the lowest administrative distance

Full Access
Question # 291

A network engineer must back up 20 network router configurations globally within a customer environment. Which protocol allows the engineer to perform this function using the Cisco IOS MIB?

A.

CDP

B.

SNMP

C.

SMTP

D.

ARP

Full Access
Question # 292

If a notice-level messaging is sent to a syslog server, which event has occurred?

A.

A network device has restarted

B.

An ARP inspection has failed

C.

A routing instance has flapped

D.

A debug operation is running

Full Access
Question # 293

Question # 293

Refer to the exhibit. Router R1 Fa0/0 is unable to ping router R3 Fa0/1. Which action must be taken on router R1 to resolve the configuration issue?

A.

set the default network as 20.20.20.0/24

B.

set the default gateway as 20.20.20.2

C.

configure a static route with Fa0/1 as the egress interface to reach the 20.20.20.0/24 network

D.

configure a static route with 10.10.10.2 as the next hop to reach the 20.20.20.0/24 network

Full Access
Question # 294

How do TCP and UDP differ in the way they provide reliability for delivery of packets?

A.

TCP is a connectionless protocol that does not provide reliable delivery of data, UDP is a connection-oriented protocol that uses sequencing to provide reliable delivery.

B.

TCP does not guarantee delivery or error checking to ensure that there is no corruption of data UDP provides message acknowledgement and retransmits data if lost.

C.

TCP provides flow control to avoid overwhelming a receiver by sending too many packets at once, UDP sends packets to the receiver in a continuous stream without checking for sequencing

D.

TCP uses windowing to deliver packets reliably; UDP provides reliable message transfer between hosts by establishing a three-way handshake

Full Access
Question # 295

An organization has decided to start using cloud-provided services. Which cloud service allows the organization to install its own operating system on a virtual machine?

A.

platform-as-a-service

B.

software-as-a-service

C.

network-as-a-service

D.

infrastructure-as-a-service

Full Access
Question # 296

In software-defined architectures, which plane is distributed and responsible for traffic forwarding?

A.

management plane

B.

control plane

C.

policy plane

D.

data plane

Full Access
Question # 297

Which feature on the Cisco Wireless LAN Controller when enabled restricts management access from specific networks?

A.

CPU ACL

B.

TACACS

C.

Flex ACL

D.

RADIUS

Full Access
Question # 298

Which implementation provides the strongest encryption combination for the wireless environment?

A.

WPA2 + AES

B.

WPA + AES

C.

WEP

D.

WPA + TKIP

Full Access
Question # 299

Which CRUD operation modifies an existing table or view?

A.

read

B.

create

C.

replace

D.

update

Full Access
Question # 300

Which network action occurs within the data plane?

A.

compare the destination IP address to the IP routing table.

B.

run routing protocols (OSPF, EIGRP, RIP, BGP)

C.

make a configuration change from an incoming NETCONF RPC

D.

reply to an incoming ICMP echo request

Full Access
Question # 301

Refer to the exhibit.

Question # 301

After running the code in the exhibit, which step reduces the amount of data that the NETCONF server returns to the NETCONF client, to only the interface ' s configuration?

A.

Use the Ixml library to parse the data returned by the NETCONF server for the interface ' s configuration.

B.

Create an XML filter as a string and pass it to get_config() method as an argument.

C.

Create a JSON filter as a string and pass it to the get_config() method as an argument.

D.

Use the JSON library to parse the data returned by the NETCONF server for the interface ' s configuration.

Full Access
Question # 302

In which situation is private IPv4 addressing appropriate for a new subnet on the network of an organization?

A.

There is limited unique address space, and traffic on the new subnet will stay local within the organization.

B.

The network has multiple endpoint listeners, and it is desired to limit the number of broadcasts.

C.

Traffic on the subnet must traverse a site-to-site VPN to an outside organization.

D.

The ISP requires the new subnet to be advertised to the internet for web services.

Full Access
Question # 303

What is a DHCP client?

A.

a host that is configured to request an IP address automatically

B.

a server that dynamically assigns IP addresses to hosts

C.

a workstation that requests a domain name associated with its IP address

D.

a router that statically assigns IP addresses to hosts

Full Access
Question # 304

Drag and drop the attack-mitigation techniques from the left onto the Types of attack that they mitigate on the right.

Question # 304

Full Access
Question # 305

What is the function of a hub-and-spoke WAN topology?

A.

allows access restrictions to be implemented between subscriber sites.

B.

provides direct connections between subscribers

C.

supports Layer 2 VPNs

D.

supports application optimization

Full Access
Question # 306

Drag and drop the SNMP manager and agent identifier commands from the left onto the functions on the right

Question # 306

Full Access
Question # 307

What are two functions of a server on a network? (Choose two)

A.

achieves redundancy by exclusively using virtual server clustering

B.

runs applications that send and retrieve data for workstations that make requests

C.

handles requests from multiple workstations at the same time

D.

runs the same operating system in order to communicate with other servers

E.

housed solely in a data center that is dedicated to a single client

Full Access
Question # 308

Drag and drop the network protocols from the left onto the correct transport services on the right.

Question # 308

Full Access
Question # 309

Which command entered on a switch configured with Rapid PVST+ listens and learns for a specific time period?

A.

switch(config)#spanning-tree vlan 1 max-age 6

B.

switch(config)#spanning-tree vlan 1 hello-time 10

C.

switch(config)#spanning-tree vlan 1 priority 4096

D.

switch(config)#spanning-tree vlan 1 forward-time 20

Full Access
Question # 310

Refer to the exhibit.

Question # 310

If the network environment is operating normally, which type of device must be connected to interface FastEthernet 0/1?

A.

DHCP client

B.

access point

C.

router

D.

PC

Full Access