Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Cisco > CCNA > 200-301

200-301 Implementing and Administering Cisco Solutions (200-301 CCNA) v1.1 Question and Answers

Question # 4

Which mechanism allows WPA3 to provide a higher degree of security than its predecessors?

A.

special-character support in pre-shared Keys

B.

SAE password-based key exchange

C.

automatic device pairing

D.

certificate-based authentication

Full Access
Question # 5

Which AP mode wirelesssly connects two separate network segments each set up within a different campus building?

A.

mesh

B.

local

C.

bridge

D.

point-to-point

Full Access
Question # 6

In which way does generative AI aid network simulations?

Full Access
Question # 7

What are two benefits of network automation? (Choose two.)

A.

Faster changes with more reliable results

B.

Reduced operational costs

C.

Fewer network failures

D.

Reduced hardware footprint

E.

Increased network security

Full Access
Question # 8

Refer to the exhibit. Drag and drop the learned prefixes from the left onto the preferred route methods from which they were learned on the right.

Full Access
Question # 9

What is the default interface for in-band wirelesss network management on a WLC?

A.

Redundant port

B.

Out-of-band

C.

Service port

D.

Wireless management

Full Access
Question # 10

Refer to the exhibit.

A new VLAN and switch are added to the network. A remote engineer configures OldSwitch and must ensure that the configuration meets these requirements:

• accommodates current configured VLANs

• expands the range to include VLAN 20

• allows for IEEE standard support for virtual LANs

Which configuration on the NewSwitch side of the link meets these requirements?

A)

B)

C)

D)

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 11

Which technology allows multiple operating systems lo run a single physical server?

A.

cloud computing

B.

virtualization

C.

application hosting

D.

containers

Full Access
Question # 12

How are API keys used to enforce rate limiting?

A.

to specify the type of data format the client prefers to receive

B.

to define the network path the API request should take

C.

to encrypt data sent in the API request

D.

to uniquely identify each client application

Full Access
Question # 13

Refer to the exhibit.

Which configuration is needed to configure a WLAN with WPA2 only and with a password that is 63 characters long?

A.

Disable WPA Policy and WPA Encryption and then enable PSK using ASCII.

B.

Enable PSK and FT PSK and then disable WPA Policy.

C.

Disable WPA Encryption and then enable FT PSK.

D.

Enable PSK using Hex format and then disable WPA Policy.

Full Access
Question # 14

Which technology is appropriate for communication between an SDN controller and applications running over the network?

A.

REST API

B.

OpenFlow

C.

Southbound API

D.

NETCONF

Full Access
Question # 15

Refer to the exhibit. An engineer is using the Cisco WLC GUI to configure a WLAN for WPA2 encryption with AES and pre-shared key Cisc0123456. After the engineer selects the WPA + WPA2 option froin the Layer 2 Security drop-down list, which two tasks must they perform to complete the process? (Choose two.)

A.

Select the WPA2 Policy, AES, and TKIP check boxes.

B.

Select ASCII froin the PSK Format drop-down list, enter the key, and leave the Auth Key Mgmt setting blank.

C.

Select PSK froin the Auth Key Mgmt drop-down list, set the PSK Format to ASCII, and enter the key.

D.

Select the WPA2 Policy and AES check boxes.

Full Access
Question # 16

Refer to the exhibit. VLAN 23 is being implemented between SW1 and SW2. The command show interface ethernet0/0 switchport has been issued on SW1. Ethernet0/0 on SW1 is the uplink to SW2. Which command when entered on the uplink interface allows PC 1 and PC 2 to communicate without impact to the communication between PC 11 and PC 12?

A.

switchport trunk allowed vlan 2-1001

B.

switchport trunk allowed vlan add 23

C.

switchport trunk allowed vlan 23

D.

switchport trunk allowed vlan 22-23

Full Access
Question # 17

Refer to the exhibit.

Packets are flowing from 192.168.10.1 to the destination at IP addressss 192.168.20.75. Which next hop will the router select for the packet?

A.

10.10.10.1

B.

10.10.10.11

C.

10.10.10.12

D.

10.10.10.14

Full Access
Question # 18

Refer to the exhibit.

PC A and the file server. Which command must be configured on switch A to prevent interruption of other communications?

A.

switch port trunk allowed vlan 12

B.

switchport trunk allowed vlan none

C.

switchport trunk allowed vlan add 13

D.

switch port trunk allowed vlan remove 10-11

Full Access
Question # 19

How does MAC learning function?

A.

Sends frames with unknown destinations to a multicast group.

B.

Increases security on the management VLAN.

C.

Rewrites the source and destination MAC addresss.

D.

Associates the MAC addresss with the port on which it is received.

Full Access
Question # 20

Which mechanism carries multicast traffic between remote sites and supports encryption?

A.

GRE over IPsec

B.

IPsec over ISATAP

C.

GRE

D.

ISATAP

Full Access
Question # 21

Which set of actions satisfies the requirement for multifactor authentication?

A.

The user enters a user name and password, and then clicks a notification in an authentication app on a mobile device.

B.

The user swipes a key fob, then clicks through an email link.

C.

The user enters a PIN into an RSA token, and then enters the displayed RSA key on a login screen.

D.

The user enters a user name and password, and then re-enters the credentials on a second screen.

Full Access
Question # 22

Which type of hypervisor operates without an underlying OS to host virtual machines?

A.

Type 1

B.

Type 2

C.

Type 3

D.

Type 12

Full Access
Question # 23

What does the term " spirt MAC” refer to in a wirelesss architecture?

A.

divides data link layer functions between the AP and WLC

B.

combines the management and control functions froin the data-forwarding functions

C.

uses different MAC addressses for 2.4 GHz and 5 GHz bands on the same AP

D.

leverages two APs to handle control and data traffic

Full Access
Question # 24

How does a network administrator securely manage an AP in lightweight mode?

A.

using the CLI via an out-of-band connection

B.

using the WLC GUI via HTTPS

C.

using the AP GUI via an in-band SSH connection

D.

using the CLI via a virtual interface with SSH

Full Access
Question # 25

A)

B)

C)

D)

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 26

Drag and drop the TCP and UDP characteristics froin the left onto the supporting protocols on the right. Not all options are used.

Full Access
Question # 27

Which two northbound APIs are found in a software-defined network? (Choose two.)

A.

OpenFlow

B.

REST

C.

OpFlex

D.

SOAP

E.

NETCONF

Full Access
Question # 28

Which signal frequency appears 60 times per minute?

A.

1 Hz signal

B.

1 GHz signal

C.

60 Hz signal

D.

60 GHz signal

Full Access
Question # 29

Refer to the exhibit.

What is the subnet mask for route 172.16.4.0?

A.

255.255.248.0

B.

255.255.254.0

C.

255.255.255.192

D.

255.255.240.0

Full Access
Question # 30

Exhibit.

The switches are connected via a Cat5 Ethernet cable that was successfully tested. The Interfaces are configured as access ports and are both in a ' down " status. What is the cause of this issue?

A.

The switches are configured with incompatible duplex settings.

B.

The distance between the two switches is not supported by Cut5.

C.

The speed settings on the switches are mismatched.

D.

The portfast command is missing froin the configuration.

Full Access
Question # 31

Refer to the exhibit. Which functionalities will this SSID have while being used by wirelesss clients?

A.

decreases network security against offline dictionary attacks and encourages easy access to the network

B.

increases network security against offline dictionary attacks and discourages time-consuming brute force attacks

C.

increases network security against man in the middle attacks and discourages denial of service attacks

D.

decreases network security against air sniffing attacks and discourages the use of complex passwords

Full Access
Question # 32

What is the temporary state that switch ports always enter immediately after the boot process when Rapid PVST+ is used?

A.

discarding

B.

listening

C.

forwarding

D.

learning

Full Access
Question # 33

What is a benefit of a point-to-point leased line?

A.

flexibility of design

B.

simplicity of configuration

C.

low cost

D.

full-mesh capability

Full Access
Question # 34

A network engineer must configure the router R1 GigabitEthernet1/1 interface to connect to the router R2 GigabitEthernet1/1 interface. For the configuration to be applied, the engineer must compress the addresss 2001:0db8:0000:0000:0500:000a:400F:583B. Which command must be issued on the interface?

A.

ipv6 addresss 2001:db8 :: 500:a:400F:583B

B.

ipv6 addresss 2001:0db8 :: 5:a:4F:583B

C.

ipv6 addresss 2001 :: db8:0000 :: 500:a:400F:583B

D.

ipv6 addresss 2001:db8:0 :: 500:a:4F:583B

Full Access
Question # 35

Refer to the exhibit. What is the administrative distance for the advertised prefix that includes the host IP addressss 192.168.20.1?

A.

1

B.

24

C.

192.168.10.2

D.

0

Full Access
Question # 36

Refer to the exhibit Routers R1 R2 and R3 use a protocol to identify their neighbors ' IP addresssses hardware platforms, and software versions. A network engineer must configure R2 to avoid sharing any neighbor information with R3, and maintain its relationship with R1. What action meets this requirement?

A.

Configure the no cdp enable command on gO/2.

B.

Configure the no cdp run command globally.

C.

Configure the no lldp run command globally.

D.

Configure the no lldp receive command on gQV1.

Full Access
Question # 37

What is a characteristic of private IPv4 addresssing?

A.

Reduces the forwarding table on network routers

B.

Used on the external interface of a firewall

C.

Used by ISPs when only one IP is needed to connect to the internet

D.

Address space which is isolated froin the internet

Full Access
Question # 38

Which IPsec mode encapsulates the entire IP packet?

A.

tunnel

B.

Q-in-Q

C.

SSL VPN

D.

transport

Full Access
Question # 39

Why does an administrator choose to implement a remote access IPsec VPN?

A.

to establish an encrypted tunnel between a remote user and a private network over the internet

B.

to allow access to an enterprise network using any internet-enabled location via a web browser using SSL

C.

to provide a secure link between an HTTPS server, authentication subsystem, and an end-user

D.

to use cryptography for authentication between a device and user over a negotiated VPN gateway

Full Access
Question # 40

Refer to the exhibit.

What is the subnet mask for route 172.16.4.0?

A.

255.255.255.192

B.

255.255.254.0

C.

255.255.240.0

D.

255.255.248.0

Full Access
Question # 41

Drag and drop the characteristic from the left onto the IPv6 address type on the right.

Full Access
Question # 42

How does IPsec provide secure networking for applications within an organization?

A.

It takes advantage of FTP to secure file transfers between nodes on the network.

B.

It provides GRE tunnels to transmit traffic securely between network nodes.

C.

It enables sets of security associations between peers.

D.

It leverages TFTP providing secure file transfers among peers on the network.

Full Access
Question # 43

Refer to the exhibit. All routers in the network are configured conrectly, and the expected routes are being exchanged among the routers. Which set of routes are leamed from neighbors and installed on router 2?

A.

10.129.9.0/2310.139.2.0/3010.2.191.0/3010.129.9.0/25

B.

10.129.9.0/2310.40.1.0/3010.2.191.0/3010.129.9.0/25

C.

10.40.1.0/3010.139.2.0/3010.2.191.0/3010.129.9.0/25

D.

10.129.9.0/2310.139.2.0/3010.129.9.0/2510.22.1.0/24

Full Access
Question # 44

A DHCP pool has been created with the name NOCC. The pool is using 192.168.20.0/24 and must use the next to last usable IIP address as the default gateway for the DHCP clients. What is the next step in the process?

A.

default-router192.168.20.253

B.

network 192.168.20.254 255.255.255.0 secondary

C.

ip default-gateway 0.0.0.0 0.0.0.0 192.168.20.253

D.

next-server 192.168.20.254

Full Access
Question # 45

Refer to the exhibit.

The show ip ospf interface command has been executed on R1. How is OSPF configured?

A.

A point-to-point network type is configured.

B.

The default Hello and Dead timers are in use.

C.

There are six OSPF neighbors on this interface.

D.

The interface is not participating in OSPF.

Full Access
Question # 46

Refer to the exhibit.

Which configuration parameter is preventing host C from reaching the internet?

A.

automatic DNS

B.

default gateway

C.

IP network mask

D.

IP addressss assignment

Full Access
Question # 47

Which statement describes virtualization on containers?

A.

It is a type of operating system virtualization that allows the host operating system to control the different CPU memory processes.

B.

It emulates a physical computer and enables multiple machines to run with many operating systems on a physical machine.

C.

It separates virtual machines from each other and allocates memory, processors, and storage to compute.

D.

It contains a guest operating system and virtual partition of hardware for OS and requires application libraries.

Full Access
Question # 48

Refer to the exhibit.

Which interface is chosen to forward traffic to the host at 192.168.0.55?

A.

GigabitEthernet0

B.

GigabitEthernet0/1

C.

Null0

D.

GigabitEthernet0/3

Full Access
Question # 49

Refer to the exhibit. Router-WAN1 has a new connection via Gi0/0 to the ISP. Users running the web applications indicate that connectivity is unstable to the internet. What is causing the interface issue?

A.

Small frames less than 64 bytes are rejected due to size.

B.

The receive buffer is full due to a broadcast storm.

C.

Frames are discarded due to a half-duplex negotiation.

D.

Broadcast packets are rejected because ARP timeout is enabled.

Full Access
Question # 50

Refer to the exhibit. HQC needs to use a configuration that:

handles up to 150,000 concurrent connections

minimizes consumption of public IP addresssses

A.

ip nat pool NATPOOL 209.165.201.1 209.165.201.3 netmask 255.255.255.248  ip nat inside source list HQC pool NATPOOL overload

B.

ip nat pool NATPOOL 209.165.201.1 209.165.201.248 netmask 255.255.255.248  ip nat outside source list HQC pool NATPOOL overload

C.

ip nat pool NATPOOL 209.165.200.225 209.165.200.226 netmask 255.255.255.252  ip nat outside source list HQC pool NATPOOL overload

D.

ip nat pool NATPOOL 209.165.201.1 209.165.201.5 netmask 255.255.255.248  ip nat inside source list HQC interface gigabitEthernet0/0 overload

Full Access
Question # 51

Which type of DNS record is used to specify the mail server responsible for accepting email messages on behalf of a recipient ' s domain?

A.

MX record

B.

TXT record

C.

A record

D.

SRV record

Full Access
Question # 52

An on-site service desk technician must verify the IP addressss and DNS server information on a users Windows computer. Which command must the technician enter at the command prompt on the user ' s computer?

A.

ipconfig /all

B.

ifconfig -a

C.

show interface

D.

netstat -r

Full Access
Question # 53

Drag and drop the DHCP snooping terms from the left onto the descriptions on the right.

Full Access
Question # 54

Refer to the exhibit. Four load-balancing servers are reachable through this router; however, the company is removing all static and default routes on the router.

Server 1 - 10.12.14.14

Server 2 - 192.168.4.4

Server 3 - 209.165.200.5

Server 4 - 209.165.201.26

Which server will handle all traffic after the policy changes take effect?

A.

Server 1 - 10.12.14.14

B.

Server 2 - 192.168.4.4

C.

Server 3 - 209.165.200.5

D.

Server 4 - 209.165.201.26

Full Access
Question # 55

Refer to the exhibit.

A network engineer must configure communication between PC A and the File Server. To prevent interruption for any other communications, which command must be configured?

A.

Switch trunk allowed vlan 12

B.

Switchport trunk allowed vlan none

C.

Switchport trunk allowed vlan add 13

D.

Switchport trunk allowed vlan remove 10-11

Full Access
Question # 56

By default, how does EIGRP determine the metric of a route for the routing table?

A.

it uses the bandwidth and delay values of the path to calculate the route metric

B.

it uses a default metric of 10 for all routes that are learned by the router

C.

it uses a reference bandwidth and the actual bandwidth of the connected link to calculate the route metric

D.

it counts the number of hops between the receiving and destination routers and uses that value as the metric

Full Access
Question # 57

Drag and drop the IPv4 network subnets from the left onto the correct usable host ranges on the right

Full Access
Question # 58

Refer to the exhibit.

Router OldR is replacing another router on the network with the intention of having OldR and R2 exchange routes_ After the engineer applied the initial OSPF

configuration: the routes were still missing on both devices. Which command sequence must be issued before the clear IP ospf process command is entered to enable the neighbor relationship?

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 59

An email user has been lured into clicking a link in an email sent by their company ' s security organization. The webpage that opens reports that it was safe but the link could have contained malicious code. Which type of security program is in place?

A.

Physical access control

B.

Social engineering attack

C.

brute force attack

D.

user awareness

Full Access
Question # 60

What are two benefits of controller-based networking compared to traditional networking?

A.

controller-based increases network bandwidth usage, while traditional lightens the load on the network.

B.

controller-based inflates software costs, while traditional decreases individual licensing costs

C.

Controller-based reduces network configuration complexity, while traditional increases the potential for errors

D.

Controller-based provides centralization of key IT functions. While traditional requires distributed management functions

E.

controller-based allows for fewer network failure, while traditional increases failure rates.

Full Access
Question # 61

What is the purpose of using First Hop Redundancy Protocol in a specific subnet?

A.

Filter traffic based on destination IP addressing

B.

Sends the default route to the hosts on a network

C.

ensures a loop-free physical topology

D.

forwards multicast hello messages between routers

Full Access
Question # 62

Which implementation provides the strongest encryption combination for the wireless environment?

A.

WPA2 + AES

B.

WPA + AES

C.

WEP

D.

WPA + TKIP

Full Access
Question # 63

What occurs when overlapping Wi-Fi channels are implemented?

A.

The wireless network becomes vulnerable to unauthorized access.

B.

Wireless devices are unable to distinguish between different SSIDs

C.

Users experience poor wireless network performance.

D.

Network communications are open to eavesdropping.

Full Access
Question # 64

When DHCP is configured on a router, which command must be entered so the default gateway is automatically distributed?

A.

default-router

B.

default-gateway

C.

ip helper-address

D.

dns-server

Full Access
Question # 65

When implementing a router as a DHCP server, which two features must be configured ' ? (Choose two)

A.

relay agent information

B.

database agent

C.

address pool

D.

smart-relay

E.

manual bindings

Full Access
Question # 66

Which two command sequences must you configure on switch to establish a Layer 3 EtherChannel with an open-standard protocol? (Choose two)

A.

interface GigabitEthernet0/0/1channel-group 10 mode on

B.

interface GigabitEthernet0/0/1channel-group 10 mode active

C.

interface GigabitEthernet0/0/1channel-group 10 mode auto

D.

interface port-channel 10switchportswitchport mode trunk

E.

interface port-channel 10no switchportip address 172.16.0.1.255.255.255.0

Full Access
Question # 67

Refer to the exhibit.

Which configuration on RTR-1 denies SSH access from PC-1 to any RTR-1 interface and allows all other traffic?

A.

access-list 100 deny tcp host 172.16.1.33 any eq 22 access-list 100 permit ip any anyinterface GigabitEthernet0/0 ip access-group 100 in

B.

access-list 100 deny tcp host 172.16.1.33 any eq 22 access-list 100 permit ip any anyline vty 0 15 ip access-group 100 in

C.

access-list 100 deny tcp host 172.16.1.33 any eq 23 access-list 100 permit ip any anyinterface GigabitEthernet0/0 ip access-group 100 in

D.

access-list 100 deny tcp host 172.16.1.33 any eq 23 access-list 100 permit ip any anyline vty 0 15 ip access-group 100 in

Full Access
Question # 68

Which two protocols are supported on service-port interfaces? (Choose two.)

A.

RADIUS

B.

TACACS+

C.

SCP

D.

Telnet

E.

SSH

Full Access
Question # 69

What are two roles of the Dynamic Host Configuration Protocol (DHCP)? (Choose two)

A.

The DHCP server offers the ability to exclude specific IP addresses from a pool of IP addresses

B.

The DHCP client can request up to four DNS server addresses

C.

The DHCP server assigns IP addresses without requiring the client to renew them

D.

The DHCP server leases client IP addresses dynamically.

E.

The DHCP client maintains a pool of IP addresses it can assign.

Full Access
Question # 70

Which statement identifies the functionality of virtual machines?

A.

Virtualized servers run most efficiently when they are physically connected to a switch that is separate from the hypervisor

B.

The hypervisor can virtualize physical components including CPU. memory, and storage

C.

Each hypervisor can support a single virtual machine and a single software switch

D.

The hypervisor communicates on Layer 3 without the need for additional resources

Full Access
Question # 71

Drag and drop the descriptions from the left onto the correct configuration-management technologies on the right.

Full Access
Question # 72

Refer to the exhibit.

After the election process what is the root bridge in the HQ LAN?

A.

Switch 1

B.

Switch 2

C.

Switch 3

D.

Switch 4

Full Access
Question # 73

Which device performs stateful inspection of traffic?

A.

firewall

B.

switch

C.

access point

D.

wireless controller

Full Access
Question # 74

Refer to the exhibit.

An administrator must turn off the Cisco Discovery Protocol on the port configured with address last usable address in the 10.0.0.0/30 subnet. Which command set meets the requirement?

A.

interface gi0/1no cdp enable

B.

interface gi0/1clear cdp table

C.

interface gi0/0no cdp advertise-v2

D.

interface gi0/0no cdp run

Full Access
Question # 75

Drag and drop the network protocols from the left onto the correct transport services on the right.

Full Access
Question # 76

An engineer must configure a /30 subnet between two routers. Which usable IP address and subnet mask combination meets this criteria?

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 77

What is a function of Wireless LAN Controller?

A.

register with a single access point that controls traffic between wired and wireless endpoints.

B.

use SSIDs to distinguish between wireless clients.

C.

send LWAPP packets to access points.

D.

monitor activity on wireless and wired LANs

Full Access
Question # 78

Drag and drop the functions from the left onto the correct network components on the right

Full Access
Question # 79

What is a characteristic of a SOHO network?

A.

connects each switch to every other switch in the network

B.

enables multiple users to share a single broadband connection

C.

provides high throughput access for 1000 or more users

D.

includes at least three tiers of devices to provide load balancing and redundancy

Full Access
Question # 80

Drag the IPv6 DNS record types from the left onto the description on the right.

Full Access
Question # 81

How is the native VLAN secured in a network?

A.

separate from other VLANs within the administrative domain

B.

give it a value in the private VLAN range

C.

assign it as VLAN 1

D.

configure it as a different VLAN ID on each end of the link

Full Access
Question # 82

In software-defined architectures, which plane is distributed and responsible for traffic forwarding?

A.

management plane

B.

control plane

C.

policy plane

D.

data plane

Full Access
Question # 83

Which device tracks the state of active connections in order to make a decision to forward a packet through?

A.

wireless access point

B.

firewall

C.

wireless LAN controller

D.

router

Full Access
Question # 84

A network administrator must enable DHCP services between two sites. What must be configured for the router to pass DHCPDISCOVER messages on to the server?

A.

a DHCP Relay Agent

B.

DHCP Binding

C.

a DHCP Pool

D.

DHCP Snooping

Full Access
Question # 85

What is an advantage of Cisco DNA Center versus traditional campus device management?

A.

It supports numerous extensibility options including cross-domain adapters and third-party SDKs.

B.

It supports high availability for management functions when operating in cluster mode.

C.

It enables easy autodiscovery of network elements m a brownfield deployment.

D.

It is designed primarily to provide network assurance.

Full Access
Question # 86

What uses HTTP messages to transfer data to applications residing on different hosts?

A.

OpenFlow

B.

OpenStack

C.

OpFlex

D.

REST

Full Access
Question # 87

Refer to the exhibit.

A router received these five routes from different routing information sources.

Which two routes does the router install in its routing table? (Choose two)

A.

RIP route 10.0.0.0/30

B.

iBGP route 10.0.0.0/30

C.

OSPF route 10.0.0.0/30

D.

EIGRP route 10.0.0.1/32

E.

OSPF route 10.0.0.0/16

Full Access
Question # 88

Refer to the exhibit. The user has connectivity to devices on network 192.168.3 0/24 but cannot reach users on the network 10.10.1.0724.

What is the first step to verify connectivity?

A.

Is the internet reachable?

B.

Is the default gateway reachable?

C.

Is the DNS server reachable?

Full Access
Question # 89

How is AI used to identify issues within network traffic?

A.

It enhances data packet delivery speeds

B.

It analyzes patterns for anomaly detection

C.

It exclusively predicts device malfunctions

D.

It guarantees zero packet loss in the network

Full Access
Question # 90

What are two characteristics of the distribution layer in a three-tier network architecture? (Choose two.)

A.

serves as the network aggregation point

B.

provides a boundary between Layer 2 and Layer 3 communications

C.

designed to meet continuous, redundant uptime requirements

D.

is the backbone for the network topology

E.

physical connection point for a LAN printer

Full Access
Question # 91

Refer to the exhibit. A packet sourced from 172.16.32.254 is destined for 172.16.32.8. What is the subnet mask of the preferred destination route?

A.

255.255.224.0

B.

255.255.255.0

C.

255.255.255.192

D.

255.255.255.252

Full Access
Question # 92

In which two ways does a password manager reduce the chance of a hacker stealing a users password? (Choose two.)

A.

It automatically provides a second authentication factor that is unknown to the original user.

B.

It uses an internal firewall to protect the password repository from unauthorized access.

C.

It protects against keystroke logging on a compromised device or web site.

D.

It stores the password repository on the local workstation with built-in antivirus and anti-malware functionality

E.

It encourages users to create stronger passwords.

Full Access
Question # 93

What is the maximum bandwidth of a T1 point-to-point connection?

A.

1.544 Mbps

B.

2.048 Mbps

C.

34.368 Mbps

D.

43.7 Mbps

Full Access
Question # 94

Refer to the exhibit.

An engineer is configuring the router to provide static NAT for the webserver Drag and drop the configuration commands from the left onto the letters that correspond to its position in the configuration on the right.

Full Access
Question # 95

An engineer is asked to protect unused ports that are configured in the default VLAN on a switch.

Which two steps will fulfill the request? (Choose two)

A.

Configure the ports in an EtherChannel.

B.

Administratively shut down the ports

C.

Configure the port type as access and place in VLAN 99

D.

Configure the ports as trunk ports

E.

Enable the Cisco Discovery Protocol

Full Access
Question # 96

Which two capacities of Cisco DNA Center make it more extensible as compared to traditional campus device management? (Choose two)

A.

adapters that support all families of Cisco IOS software

B.

SDKs that support interaction with third-party network equipment

C.

customized versions for small, medium, and large enterprises

D.

REST APIs that allow for external applications to interact natively with Cisco DNA Center

E.

modular design that is upgradable as needed

Full Access
Question # 97

Which type of encryption does WPA1 use for data protection?

A.

AES

B.

TKIP

C.

PEAP

D.

EAP

Full Access
Question # 98

Which API is used in controller-based architectures to interact with edge devices?

A.

overlay

B.

northbound

C.

underlay

D.

southbound

Full Access
Question # 99

Refer to the exhibit.

An extended ACL has been configured and applied to router R2 The configuration failed to work as intended Which two

changes stop outbound traffic on TCP ports 25 and 80 to 10.0.20 0 26 from the 10.0.10 0/26 subnet while still allowing all other traffic? (Choose

two )

A.

Add a " permit ip any any " statement to the beginning of ACL 101 for allowed traffic.

B.

Add a " permit ip any any " statement at the end of ACL 101 for allowed traffic

C.

The source and destination IPs must be swapped in ACL 101

D.

The ACL must be configured the Gi0/2 interface inbound on R1

E.

The ACL must be moved to the Gi0/1 interface outbound on R2

Full Access
Question # 100

What does a router do when configured with the default DNS lookup settings, and a URL is entered on the CLI?

A.

initiates a ping request to the URL

B.

prompts the user to specify the desired IP address

C.

continuously attempts to resolve the URL until the command is cancelled

D.

sends a broadcast message in an attempt to resolve the URL

Full Access
Question # 101

Which command entered on a switch configured with Rapid PVST+ listens and learns for a specific time period?

A.

switch(config)#spanning-tree vlan 1 max-age 6

B.

switch(config)#spanning-tree vlan 1 hello-time 10

C.

switch(config)#spanning-tree vlan 1 priority 4096

D.

switch(config)#spanning-tree vlan 1 forward-time 20

Full Access
Question # 102

Which command prevents passwords from being stored in the configuration as plain text on a router or switch?

A.

enable secret

B.

service password-encryption

C.

username Cisco password encrypt

D.

enable password

Full Access
Question # 103

What is the primary purpose of a First Hop Redundancy Protocol?

A.

It allows directly connected neighbors to share configuration information.

B.

It allows a router to use bridge priorities to create multiple loop-free paths to a single destination.

C.

It reduces routing failures by allowing Layer 3 load balancing between OSPF neighbors that have the same link metric.

D.

It reduces routing failures by allowing more than one router to represent itself, as the default gateway of a network.

Full Access
Question # 104

Which command is used to specify the delay time in seconds for LLDP to initialize on any interface?

A.

lldp timer

B.

lldp holdtime

C.

lldp reinit

D.

lldp tlv-select

Full Access
Question # 105

What facilitates a Telnet connection between devices by entering the device name?

A.

SNMP

B.

DNS lookup

C.

syslog

D.

NTP

Full Access
Question # 106

An organization has decided to start using cloud-provided services. Which cloud service allows the organization to install its own operating system on a virtual machine?

A.

platform-as-a-service

B.

software-as-a-service

C.

network-as-a-service

D.

infrastructure-as-a-service

Full Access
Question # 107

How do TCP and UDP differ in the way they provide reliability for delivery of packets?

A.

TCP is a connectionless protocol that does not provide reliable delivery of data, UDP is a connection-oriented protocol that uses sequencing to provide reliable delivery.

B.

TCP does not guarantee delivery or error checking to ensure that there is no corruption of data UDP provides message acknowledgement and retransmits data if lost.

C.

TCP provides flow control to avoid overwhelming a receiver by sending too many packets at once, UDP sends packets to the receiver in a continuous stream without checking for sequencing

D.

TCP uses windowing to deliver packets reliably; UDP provides reliable message transfer between hosts by establishing a three-way handshake

Full Access
Question # 108

In which way does a spine-and-leaf architecture allow for scalability in a network when additional access ports are required?

A.

A spine switch and a leaf switch can be added with redundant connections between them

B.

A spine switch can be added with at least 40 GB uplinks

C.

A leaf switch can be added with a single connection to a core spine switch.

D.

A leaf switch can be added with connections to every spine switch

Full Access
Question # 109

What does a switch use to build its MAC address table?

A.

VTP

B.

DTP

C.

egress traffic

D.

ingress traffic

Full Access
Question # 110

When using Rapid PVST+, which command guarantees the switch is always the root bridge for VLAN 200?

A.

spanning -tree vlan 200 priority 614440

B.

spanning -tree vlan 200 priority 38572422

C.

spanning -tree vlan 200 priority 0

D.

spanning -tree vlan 200 root primary

Full Access
Question # 111

Refer to the exhibit.

which path is used by the router for internet traffic ?

A.

209.165.200.0/27

B.

10.10.10.0/28

C.

0.0.0.0/0

D.

10.10.13.0/24

Full Access
Question # 112

Refer to the exhibit.

What is the next hop address for traffic that is destined to host 10.0.1.5?

A.

10.0.1.3

B.

10.0.1.50

C.

10.0.1.4

D.

Loopback D

Full Access
Question # 113

Refer to the exhibit.

The network administrator wants VLAN 67 traffic to be untagged between Switch 1 and Switch 2 while all other VLANs are to remain tagged.

Which command accomplishes this task?

A.

switchport access vlan 67

B.

switchport trunk allowed vlan 67

C.

switchport private-vlan association host 67

D.

switchport trunk native vlan 67

Full Access
Question # 114

Which type of attack can be mitigated by dynamic ARP inspection?

A.

worm

B.

malware

C.

DDoS

D.

man-in-the-middle

Full Access
Question # 115

What causes a port to be placed in the err-disabled state?

A.

latency

B.

port security violation

C.

shutdown command issued on the port

D.

nothing plugged into the port

Full Access
Question # 116

Which configuration ensures that the switch is always the root for VLAN 750?

A.

Switch(config)#spanning-tree vlan 750 priority 38003685

B.

Switch(config)#spanning-tree vlan 750 root primary

C.

Switch(config)#spanning-tree vlan 750 priority 614440

D.

Switch(config)#spanning-tree vlan 750 priority 0

Full Access
Question # 117

Which network allows devices to communicate without the need to access the Internet?

A.

172.9.0.0/16

B.

172.28.0.0/16

C.

192.0.0.0/8

D.

209.165.201.0/24

Full Access
Question # 118

What describes the operation of virtual machines?

A.

Virtual machines are responsible for managing and allocating host hardware resources

B.

In a virtual machine environment, physical servers must run one operating system at a time.

C.

Virtual machines are the physical hardware that support a virtual environment.

D.

Virtual machines are operating system instances that are decoupled from server hardware

Full Access
Question # 119

Which command enables a router to become a DHCP client?

A.

ip address dhcp

B.

ip helper-address

C.

ip dhcp pool

D.

ip dhcp client

Full Access
Question # 120

Which output displays a JSON data representation?

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 121

Which HTTP status code is returned after a successful REST API request?

A.

200

B.

301

C.

404

D.

500

Full Access
Question # 122

What are two benefits of FHRPs? (Choose two.)

A.

They prevent (loops in the Layer 2 network.

B.

They allow encrypted traffic.

C.

They are able to bundle multiple ports to increase bandwidth

D.

They enable automatic failover of the default gateway.

E.

They allow multiple devices to serve as a single virtual gateway for clients in the network

Full Access
Question # 123

Which two events occur automatically when a device is added to Cisco DNA Center? (Choose two. )

A.

The device Is assigned to the Global site.

B.

The device Is placed into the Unmanaged state.

C.

The device is placed into the Provisioned state.

D.

The device is placed into the Managed state.

E.

The device is assigned to the Local site.

Full Access
Question # 124

A router running EIGRP has learned the same route from two different paths. Which parameter does the router use to select the best path?

A.

cost

B.

administrative distance

C.

metric

D.

as-path

Full Access
Question # 125

How does a Cisco Unified Wireless network respond to Wi-Fi channel overlap?

A.

It alternates automatically between 2.4 GHz and 5 GHz on adjacent access points

B.

It allows the administrator to assign channels on a per-device or per-interface basis.

C.

It segregates devices from different manufacturers onto different channels.

D.

It analyzes client load and background noise and dynamically assigns a channel.

Full Access
Question # 126

What is a characteristic of private IPv4 addressing?

A.

traverse the Internet when an outbound ACL is applied

B.

issued by IANA in conjunction with an autonomous system number

C.

composed of up to 65.536 available addresses

D.

used without tracking or registration

Full Access
Question # 127

Drag and drop the TCP/IP protocols from the left onto the transmission protocols on the right

Full Access
Question # 128

What is a syslog facility?

A.

Host that is configured for the system to send log messages

B.

password that authenticates a network management system to receive log messages

C.

group of log messages associated with the configured severity level

D.

set of values that represent the processes that can generate a log message

Full Access
Question # 129

What is the primary function of a Layer 3 device?

A.

to analyze traffic and drop unauthorized traffic from the Internet

B.

to transmit wireless traffic between hosts

C.

to pass traffic between different networks

D.

forward traffic within the same broadcast domain

Full Access
Question # 130

Refer to the exhibit.

The entire contents of the MAC address table are shown. Sales-4 sends a data frame to Sales-1.

What does the switch do as it receives the frame from Sales-4?

A.

Perform a lookup in the MAC address table and discard the frame due to a missing entry.

B.

Insert the source MAC address and port into the forwarding table and forward the frame to Sales-1.

C.

Map the Layer 2 MAC address to the Layer 3 IP address and forward the frame.

D.

Flood the frame out of all ports except on the port where Sales-1 is connected.

Full Access
Question # 131

Refer to the exhibit.

An engineer is tasked with verifying network configuration parameters on a client workstation to report back to the team lead. Drag and drop the node identifiers from the left onto the network parameters on the right.

Full Access
Question # 132

Refer to the exhibit.

Router R1 Fa0/0 is unable ping router R3 Fa0/1.

Which action must be taken in router R1 to help resolve the configuration issue?

A.

set the default network as 20.20.20.0/24

B.

set the default gateway as 20.20.20.2

C.

configure a static route with Fa0/1 as the egress interface to reach the 20.20.20.0/24 network

D.

configure a static route with 10.10.10.2 as the next hop to reach the 20.20.20.0/24 network

Full Access
Question # 133

Which port type supports the spanning-tree portfast command without additional configuration?

A.

access ports

B.

Layer 3 main Interfaces

C.

Layer 3 suninterfaces

D.

trunk ports

Full Access
Question # 134

Which command must be entered to configure a DHCP relay?

A.

ip helper-address

B.

ip address dhcp

C.

ip dhcp pool

D.

ip dhcp relay

Full Access
Question # 135

What is the difference in data transmission delivery and reliability between TCP and UDP?

A.

TCP transmits data at a higher rate and ensures packet delivery. UDP retransmits lost data to ensure applications receive the data on the remote end.

B.

UDP sets up a connection between both devices before transmitting data. TCP uses the three-way handshake to transmit data with a reliable connection.

C.

UDP is used for multicast and broadcast communication. TCP is used for unicast communication and transmits data at a higher rate with error checking.

D.

TCP requires the connection to be established before transmitting data. UDP transmits data at a higher rate without ensuring packet delivery.

Full Access
Question # 136

Which 802.11 frame type is indicated by a probe response after a client sends a probe request?

A.

action

B.

management

C.

control

D.

data

Full Access
Question # 137

Refer to the exhibit.

Which route type does the routing protocol Code D represent in the output?

A.

internal BGP route

B.

/24 route of a locally configured IP

C.

statically assigned route

D.

route learned through EIGRP

Full Access
Question # 138

Refer to the exhibit.

Which prefix does Router 1 use for traffic to Host A?

A.

10.10.10.0/28

B.

10.10.13.0/25

C.

10.10.13.144/28

D.

10.10.13.208/29

Full Access
Question # 139

A corporate office uses four floors in a building

• Floor 1 has 24 users

• Floor 2 has 29 users

• Floor 3 has 28 users

•Floor 4 has 22 users

Which subnet summarizes and gives the most efficient distribution of IP addresses for the router configuration?

A.

192.168.0.0/26 as summary and 192.168.0.0/29 for each floor

B.

192.168.0.0.24 as summary and 192.168.0.0/28 for each floor

C.

192.168.0.0/23 as summary and 192.168.0.0/25 for each floor

D.

l92.168.0.0/25 as summary and 192.168.0.0/27 for each floor

Full Access
Question # 140

A network administrator must to configure SSH for remote access to router R1 The requirement is to use a public and private key pair to encrypt management traffic to and from the connecting client.

Which configuration, when applied, meets the requirements?

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 141

What makes Cisco DNA Center different from traditional network management applications and their management of networks?

A.

It omits supports auto-discovery of network elements in a greenfield deployment.

B.

It modular design allows someone to implement different versions to meet the specific needs of an organization

C.

It abstracts policy from the actual device configuration

D.

It does not support high availability of management functions when operating in cluster mode

Full Access
Question # 142

With REST API, which standard HTTP header tells a server which media type is expected by the client?

A.

Accept-Encoding: gzip. deflate

B.

Accept-Patch: text/example; charset=utf-8

C.

Content-Type: application/json; charset=utf-8

D.

Accept: application/json

Full Access
Question # 143

What prevents a workstation from receiving a DHCP address?

A.

DTP

B.

STP

C.

VTP

D.

802.10

Full Access
Question # 144

Refer to the exhibit.

Which action is expected from SW1 when the untagged frame is received on the GigabitEthernet0/1 interface?

A.

The frame is processed in VLAN 5.

B.

The frame is processed in VLAN 11

C.

The frame is processed in VLAN 1

D.

The frame is dropped

Full Access
Question # 145

Which two QoS tools provides congestion management? ( Choose two )

A.

CAR

B.

CBWFQ

C.

PQ

D.

PBR

E.

FRTS

Full Access
Question # 146

Refer to the exhibit.

Shortly after SiteA was connected to SiteB over a new single-mode fiber path users at SiteA report intermittent connectivity issues with applications hosted at SiteB What is the cause of the intermittent connectivity issue?

A.

Interface errors are incrementing

B.

An incorrect SFP media type was used at SiteA

C.

High usage is causing high latency

D.

The sites were connected with the wrong cable type

Full Access
Question # 147

A user configured OSPF in a single area between two routers A serial interface connecting R1 and R2 is running encapsulation PPP By default which OSPF network type is seen on this interface when the user types show ip ospf interface on R1 or R2?

A.

port-to-multipoint

B.

broadcast

C.

point-to-point

D.

nonbroadcast

Full Access
Question # 148

An engineer configured an OSPF neighbor as a designated router. Which state verifies the designated router is in the proper mode?

A.

Exchange

B.

2-way

C.

Full

D.

Init

Full Access
Question # 149

What does physical access control regulate?

A.

access to specific networks based on business function

B.

access to servers to prevent malicious activity

C.

access to computer networks and file systems

D.

access to networking equipment and facilities

Full Access
Question # 150

What is a function of the Cisco DNA Center Overall Health Dashboard?

A.

It provides a summary of the top 10 global issues.

B.

It provides detailed activity logging for the 10 devices and users on the network.

C.

It summarizes the operational status of each wireless device on the network.

D.

It summarizes daily and weekly CPU usage for servers and workstations in the network.

Full Access
Question # 151

An engineer must configure a WLAN using the strongest encryption type for WPA2- PSK. Which cipher fulfills the configuration requirement?

A.

WEP

B.

RC4

C.

AES

D.

TKIP

Full Access
Question # 152

What are two recommendations for protecting network ports from being exploited when located in an office space outside of an IT closer? (Choose two.)

A.

enable the PortFast feature on ports

B.

implement port-based authentication

C.

configure static ARP entries

D.

configure ports to a fixed speed

E.

shut down unused ports

Full Access
Question # 153

Which level of severity must be set to get informational syslogs?

A.

alert

B.

critical

C.

notice

D.

debug

Full Access
Question # 154

What is the role of a firewall in an enterprise network?

A.

Forwards packets based on stateless packet inspection

B.

Processes unauthorized packets and allows passage to less secure segments of the network

C.

determines which packets are allowed to cross from unsecured to secured networks

D.

explicitly denies all packets from entering an administrative domain

Full Access
Question # 155

Where does wireless authentication happen?

A.

SSID

B.

radio

C.

band

D.

Layer 2

Full Access
Question # 156

What are network endpoints?

A.

act as routers to connect a user to the service provider network

B.

a threat to the network if they are compromised

C.

support inter-VLAN connectivity

D.

enforce policies for campus-wide traffic going to the internet

Full Access
Question # 157

What is a function of TFTP in network operations?

A.

transfers a backup configuration file from a server to a switch using a username and password

B.

transfers files between file systems on a router

C.

transfers a configuration files from a server to a router on a congested link

D.

transfers IOS images from a server to a router for firmware upgrades

Full Access
Question # 158

When a WLAN with WPA2 PSK is configured in the Wireless LAN Controller GUI which format is supported?

A.

Unicode

B.

base64

C.

decimal

D.

ASCII

Full Access
Question # 159

Refer to the exhibit.

What is the metric of the route to the 192.168.10.33/28 subnet?

A.

84

B.

110

C.

128

D.

192

E.

193

Full Access
Question # 160

What does an SDN controller use as a communication protocol to relay forwarding changes to a southbound API?

A.

OpenFlow

B.

Java

C.

REST

D.

XML

Full Access
Question # 161

Refer to the exhibit.

An engineer configured the New York router with static routes that point to the Atlanta and Washington sites. When command must be configured on the Atlanta and Washington routers so that both sites are able to reach the loopback2 interface on the New York router?

A.

ipv6 route ::/0 Serial 0/0/1

B.

ipv6 route 0/0 Serial 0/0/0

C.

ipv6 route ::/0 Serial 0/0/0

D.

ip route 0.0.0.0.0.0.0.0 Serial 0/0/0

E.

ipv6 route ::/0 2000::2

Full Access
Question # 162

What is a difference between RADIUS and TACACS+?

A.

RADIUS is most appropriate for dial authentication, but TACACS+ can be used for multiple types of authentication

B.

TACACS+ encrypts only password information and RADIUS encrypts the entire payload

C.

TACACS+ separates authentication and authorization, and RADIUS merges them

D.

RADIUS logs all commands that are entered by the administrator, but TACACS+ logs only start, stop, and interim commands

Full Access
Question # 163

Which mode must be set for APs to communicate to a Wireless LAN Controller using the Control and Provisioning of Wireless Access Points (CAPWAP) protocol?

A.

bridge

B.

route

C.

autonomous

D.

lightweight

Full Access
Question # 164

Which two tasks must be performed to configure NTP to a trusted server in client mode on a single network device? (Choose two)

A.

Enable NTP authentication.

B.

Verify the time zone.

C.

Disable NTP broadcasts

D.

Specify the IP address of the NTP server

E.

Set the NTP server private key

Full Access
Question # 165

Refer to the exhibit.

With which metric was the route to host 172.16.0.202 learned?

A.

0

B.

110

C.

38443

D.

3184439

Full Access
Question # 166

Refer to the exhibit.

An engineer deploys a topology in which R1 obtains its IP configuration from DHCP. If

the switch and DHCP server configurations are complete and correct. Which two sets of commands must be configured on R1 and R2 to complete the task? (Choose two)

A.

R1(config)# interface fa0/0R1(config-if)# ip helper-address 198.51.100.100

B.

R2(config)# interface gi0/0R2(config-if)# ip helper-address 198.51.100.100

C.

R1(config)# interface fa0/0R1(config-if)# ip address dhcpR1(config-if)# no shutdown

D.

R2(config)# interface gi0/0R2(config-if)# ip address dhcp

E.

R1(config)# interface fa0/0R1(config-if)# ip helper-address 192.0.2.2

Full Access
Question # 167

What is a characteristic of cloud-based network topology?

A.

wireless connections provide the sole access method to services

B.

onsite network services are provided with physical Layer 2 and Layer 3 components

C.

services are provided by a public, private, or hybrid deployment

D.

physical workstations are configured to share resources

Full Access
Question # 168

What are two descriptions of three-tier network topologies? (Choose two)

A.

The core and distribution layers perform the same functions

B.

The access layer manages routing between devices in different domains

C.

The network core is designed to maintain continuous connectivity when devices fail.

D.

The core layer maintains wired connections for each host

E.

The distribution layer runs Layer 2 and Layer 3 technologies

Full Access
Question # 169

A network analyst is tasked with configure the date and time on a router using EXEC mode. The date must be set to 12:00am. Which command should be used?

A.

Clock timezone

B.

Clock summer-time-recurring

C.

Clock summer-time date

D.

Clock set

Full Access
Question # 170

Refer to the exhibit.

Based on the LACP neighbor status, in which mode is the SW1 port channel configured?

A.

passive

B.

mode on

C.

auto

D.

active

Full Access
Question # 171

How does CAPWAP communicate between an access point in local mode and a WLC?

A.

The access point must directly connect to the WLC using a copper cable

B.

The access point must not be connected to the wired network, as it would create a loop

C.

The access point must be connected to the same switch as the WLC

D.

The access point has the ability to link to any switch in the network, assuming connectivity to the WLC

Full Access
Question # 172

After installing a new Cisco ISE server, which task must the engineer perform on the Cisco WLC to connect wireless clients on a specific VLAN based on their credentials?

A.

Enable the allow AAA Override

B.

Enable the Event Driven RRM.

C.

Disable the LAG Mode or Next Reboot.

D.

Enable the Authorized MIC APs against auth-list or AAA.

Full Access
Question # 173

If a switch port receives a new frame while it is actively transmitting a previous frame, how does it process the frames?

A.

The new frame is delivered first, the previous frame is dropped, and a retransmission request is sent.

B.

The previous frame is delivered, the new frame is dropped, and a retransmission request is sent.

C.

The new frame is placed in a queue for transmission after the previous frame.

D.

The two frames are processed and delivered at the same time.

Full Access
Question # 174

The service password-encryption command is entered on a router. What is the effect of this configuration?

A.

restricts unauthorized users from viewing clear-text passwords in the running configuration

B.

encrypts the password exchange when a VPN tunnel is established

C.

prevents network administrators from configuring clear-text passwords

D.

protects the VLAN database from unauthorized PC connections on the switch

Full Access
Question # 175

What is the same for both copper and fiber interfaces when using SFP modules?

A.

They support an inline optical attenuator to enhance signal strength

B.

They provide minimal interruption to services by being hot-swappable

C.

They offer reliable bandwidth up to 100 Mbps in half duplex mode

D.

They accommodate single-mode and multi-mode in a single module

Full Access
Question # 176

What is the primary different between AAA authentication and authorization?

A.

Authentication verifies a username and password, and authorization handles the communication between the authentication agent and the user database.

B.

Authentication identifies a user who is attempting to access a system, and authorization validates the users password

C.

Authentication identifies and verifies a user who is attempting to access a system, and authorization controls the tasks the user can perform.

D.

Authentication controls the system processes a user can access and authorization logs the activities the user initiates

Full Access
Question # 177

Refer to the exhibit.

Which command configures a floating static route to provide a backup to the primary link?

A.

ip route 0.0.0.0 0.0.0.0 209.165.202.131

B.

ip route 209.165.201.0 255.255.255.224 209.165.202.130

C.

ip route 0.0.0.0 0.0.0.0 209.165.200.224

D.

ip route 209.165.200.224 255.255.255.224 209.165.202.129 254

Full Access
Question # 178

When a switch receives a frame for a known destination MAC address, how is the frame handed?

A.

sent to the port identified for the known MAC address

B.

broadcast to all ports

C.

forwarded to the first available port

D.

flooded to all ports except the one from which it originated

Full Access
Question # 179

An engineer is configuring an encrypted password for the enable command on a router where the local user database has already been configured Drag and drop the configuration commands from the left into the correct sequence on the right Not all commands are used

Full Access
Question # 180

How do traditional campus device management and Cisco DNA Center device management differ in regards to deployment?

A.

Cisco DNA Center device management can deploy a network more quickly than traditional campus device management

B.

Traditional campus device management allows a network to scale more quickly than with Cisco DNA Center device management

C.

Cisco DNA Center device management can be implemented at a lower cost than most traditional campus device management options

D.

Traditional campus device management schemes can typically deploy patches and updates more quickly than Cisco DNA Center device management

Full Access
Question # 181

Refer to the exhibit.

If configuring a static default route on the router with the ip route 0.0.0.0 0.0.0.0 10.13.0.1 120 command how does the router respond?

A.

It ignores the new static route until the existing OSPF default route is removed

B.

It immediately replaces the existing OSPF route in the routing table with the newly configured static route

C.

It starts load-balancing traffic between the two default routes

D.

It starts sending traffic without a specific matching entry in the routing table to GigabitEthernet0/1

Full Access
Question # 182

Refer to the exhibit.

Which two configurations must the engineer apply on this network so that R1 becomes the DR? (Choose two.)

A)

B)

C)

D)

E)

A.

Option A

B.

Option B

C.

Option C

D.

Option D

E.

Option E

Full Access
Question # 183

Which command must be entered when a device is configured as an NTP server?

A.

ntp authenticate

B.

ntp server

C.

ntp peer

D.

ntp master

Full Access
Question # 184

What is the purpose of an SSID?

A.

It provides network security

B.

It differentiates traffic entering access points

C.

It identities an individual access point on a WLAN

D.

It identifies a WLAN

Full Access
Question # 185

Refer to the exhibit.

An engineer is configuring a new router on the network and applied this configuration. Which additional configuration allows the PC to obtain its IP address from a DHCP server?

A.

Configure the ip dhcp relay information command under interface Gi0/1.

B.

Configure the ip dhcp smart-relay command globally on the router

C.

Configure the ip helper-address 172.16.2.2 command under interface Gi0/0

D.

Configure the ip address dhcp command under interface Gi0/0

Full Access
Question # 186

Refer to the exhibit.

Which types of JSDN data is shown

A.

Object

B.

Sequence

C.

String

D.

boolean

Full Access
Question # 187

Refer to the exhibit.

Which two commands must be added to update the configuration of router R1 so that it accepts only encrypted connections? (Choose two )

A.

username CNAC secret R!41!4319115@

B.

ip ssh version 2

C.

line vty 0 4

D.

crypto key generate rsa 1024

E.

transport input ssh

Full Access
Question # 188

Drag and drop the HTTP methods used with REST-Based APIs from the left onto the descriptions on the right.

Full Access
Question # 189

Refer to the exhibit.

A network engineer must update the configuration on Switch2 so that it sends LLDP packets every minute and the information sent via LLDP is refreshed every 3 minutes Which configuration must the engineer apply?

A)

B)

C)

D)

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 190

Refer to the exhibit.

All VLANs are present in the VLAN database. Which command sequence must be applied to complete the configuration?

A.

Interface FastEthernet0/1 switchport trunk native vlan 10 switchport trunk allowed vlan 10,15

B.

Interface FastEthernet0/1 switchport mode trunk switchport trunk allowed vlan 10,15

C.

interface FastEthernet0/1 switchport mode access switchport voice vlan 10

D.

Interface FastEthernet0/1 switchport trunk allowed vlan add 10 vlan 10 private-vlan isolated

Full Access
Question # 191

Refer to the exhibit.

Which configuration allows routers R14 and R86 to form an OSPFv2 adjacency while acting as a central point for exchanging OSPF information between routers?

A)

B)

C)

D)

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 192

Refer to the exhibit.

Which command configures OSPF on the point-to-point link between routers R1 and R2?

A.

router-id 10.0.0.15

B.

neighbor 10.1.2.0 cost 180

C.

ipospf priority 100

D.

network 10.0.0.0 0.0.0.255 area 0

Full Access
Question # 193

Which WLC management connection type is vulnerable to man-in-the-middle attacks?

A.

SSH

B.

HTTPS

C.

Telnet

D.

console

Full Access
Question # 194

Which REST method updates an object in the Cisco DNA Center Intent API?

A.

CHANGE

B.

UPDATE

C.

POST

D.

PUT

Full Access
Question # 195

Refer to the exhibit.

Which route must be configured on R1 so that OSPF routing is used when OSPF is up. but the server is still reachable when OSPF goes down?

A.

ip route 10.1.1.10 255.255.255.255 172.16.2.2 100

B.

ip route 10.1.1.0 255.255.255.0 gi0/1 125

C.

ip route 10.1.1.0 255.255.255.0 172.16.2.2 100

D.

ip route 10.1.1.10 255.255.255.255 gi0/0 125

Full Access
Question # 196

An engineer must configure neighbor discovery between the company router and an ISP

What is the next step to complete the configuration if the ISP uses a third-party router?

A.

Enable LLDP globally.

B.

Disable CDP on gi0/0.

C.

Enable LLDP TLVs on the ISP router.

D.

Disable auto-negotiation.

Full Access
Question # 197

Which two wireless security standards use Counter Mode with Cipher Block Chaining Message Authentication Code Protocol for encryption and data integrity ' ? (Choose two.)

A.

WPA2

B.

WPA3

C.

Wi-Fi 6

D.

WEP

E.

WPA

Full Access
Question # 198

A Cisco engineer must configure a single switch interface to meet these requirements

• accept untagged frames and place them in VLAN 20

• accept tagged frames in VLAN 30 when CDP detects a Cisco IP phone

Which command set must the engineer apply?

A)

B)

C)

D)

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 199

When should an engineer implement a collapsed-core architecture?

A.

for small networks with minimal need for growth

B.

the access and distribution layers must be on the same device

C.

for large networks that are connected to multiple remote sites

D.

only when using VSS technology

Full Access
Question # 200

Which WAN topology has the highest degree of reliability?

A.

full mesh

B.

Point-to-point

C.

hub-and-spoke

D.

router-on-a-stick

Full Access
Question # 201

A network engineer is configuring a switch so that it is remotely reachable via SSH. The engineer has already configured the host name on the router. Which additional command must the engineer configure before entering the command to generate the RSA key?

A.

password password

B.

crypto key generate rsa modulus 1024

C.

ip domain-name domain

D.

ip ssh authentication-retries 2

Full Access
Question # 202

Refer to the exhibit.

All interfaces are configured with duplex auto and ip ospf network broadcast. Which configuration allows routers R14 and R86 to form an OSPFv2 adjacency and act as a central point for exchanging OSPF information between routers?

A.

Option A

B.

Option B

C.

Option C

D.

option D

Full Access
Question # 203

Refer to the exhibit.

Users need to connect to the wireless network with IEEE 802.11r-compatible devices. The connection must be maintained as users travel between floors or to other areas in the building What must be the configuration of the connection?

A.

Select the WPA Policy option with the CCKM option.

B.

Disable AES encryption.

C.

Enable Fast Transition and select the FT 802.1x option.

D.

Enable Fast Transition and select the FT PSK option.

Full Access
Question # 204

An engineer must configure R1 for a new user account. The account must meet these requirements:

* It must be configured in the local database.

* The username is engineer.

* It must use the strongest password configurable. Which command must the engineer configure on the router?

A.

R1 (config)# username engineer2 algorithm-type scrypt secret test2021

B.

R1(config)# username engineer2 secret 5 password S1$b1Ju$kZbBS1Pyh4QzwXyZ

C.

R1(config)# username engineer2 privilege 1 password 7 test2021

D.

R1(config)# username englneer2 secret 4 S1Sb1Ju$kZbBS1Pyh4QzwXyZ

Full Access
Question # 205

What is a requirement when configuring or removing LAG on a WLC?

A.

The Incoming and outgoing ports for traffic flow must be specified If LAG Is enabled.

B.

The controller must be rebooted after enabling or reconfiguring LAG.

C.

The management interface must be reassigned if LAG disabled.

D.

Multiple untagged interfaces on the same port must be supported.

Full Access
Question # 206

Refer to Exhibit.

Rotor to the exhibit. The IP address configurations must be completed on the DC-1 and HQ-1 routers based on these requirements:

DC-1 Gi1/0 must be the last usable address on a /30

DC-1 Gi1/1 must be the first usable address on a /29

DC-1 Gi1/2 must be the last usable address on a /28

HQ-1 Gil/3 must be the last usable address on a /29

Drag and drop the commands from the left onto the destination interfaces on the right. Not all commands are used

Full Access
Question # 207

Which type of IPv6 address is similar to a unicast address but is assigned to multiple devices on the same network at the same time?

A.

global unicast address

B.

anycast address

C.

multicast address

D.

link-local address

Full Access
Question # 208

Refer to the exhibit.

Which action must be taken to ensure that router A is elected as the DR for OSPF area 0?

A.

Configure the OSPF priority on router A with the lowest value between the three routers.

B.

Configure router B and router C as OSPF neighbors of router A.

C.

Configure the router A interfaces with the highest OSPF priority value within the area.

D.

Configure router A with a fixed OSPF router ID

Full Access
Question # 209

Drag and drop the descriptions from the left onto the configuration-management technologies on the right.

Full Access
Question # 210

What is the benefit of configuring PortFast on an interface?

A.

After the cable is connected, the interface uses the fastest speed setting available for that cable type

B.

After the cable is connected, the interface is available faster to send and receive user data

C.

The frames entering the interface are marked with higher priority and then processed faster by a switch.

D.

Real-time voice and video frames entering the interface are processed faster

Full Access
Question # 211

What is the difference between IPv6 unicast and anycast addressing?

A.

IPv6 anycast nodes must be explicitly configured to recognize the anycast address, but IPv6 unicast nodes require no special configuration

B.

IPv6 unicast nodes must be explicitly configured to recognize the unicast address, but IPv6 anycast nodes require no special configuration

C.

An individual IPv6 unicast address is supported on a single interface on one node but an IPv6 anycast address is assigned to a group of interfaces on multiple nodes.

D.

Unlike an IPv6 anycast address, an IPv6 unicast address is assigned to a group of interfaces on multiple nodes

Full Access
Question # 212

What are two characteristics of an SSID? (Choose Two)

A.

It can be hidden or broadcast in a WLAN

B.

It uniquely identifies an access point in a WLAN

C.

It uniquely identifies a client in a WLAN

D.

It is at most 32 characters long.

E.

IT provides secured access to a WLAN

Full Access
Question # 213

Which characteristic differentiates the concept of authentication from authorization and accounting?

A.

user-activity logging

B.

service limitations

C.

consumption-based billing

D.

identity verification

Full Access
Question # 214

Refer to the exhibit.

R1 learns all routes via OSPF Which command configures a backup static route on R1 to reach the 192 168.20.0/24 network via R3?

A.

R1(config)#ip route 192.168.20.0 255.255.0.0 192.168.30.2

B.

R1(config)#ip route 192.168.20.0 255.255.255.0 192.168.30.2 90

C.

R1(config)#ip route 192.168.20.0 255.255.255.0 192.168.30.2 111

D.

R1(config)#ip route 192.168.20.0 255.255.255.0 192.168.30.2

Full Access
Question # 215

Which protocol uses the SSL?

A.

HTTP

B.

SSH

C.

HTTPS

D.

Telnet

Full Access
Question # 216

What is an expected outcome when network management automation is deployed?

A.

A distributed management plane must be used.

B.

Software upgrades are performed from a central controller

C.

Complexity increases when new device configurations are added

D.

Custom applications are needed to configure network devices

Full Access
Question # 217

A network engineer is installing an IPv6-only capable device. The client has requested that the device IP address be reachable only from the internal network. Which type of IPv6 address must the engineer assign?

A.

unique local address

B.

link-local address

C.

aggregatable global address

D.

IPv4-compatible IPv6 address

Full Access
Question # 218

Which two spanning-tree states are bypassed on an interface running PortFast? (Choose two.)

A.

disabled

B.

listening

C.

forwarding

D.

learning

E.

blocking

Full Access
Question # 219

Refer to the exhibit.

R1 has taken the DROTHER role in the OSPF DR/BDR election process. Which configuration must an engineer implement so that R1 is elected as the DR?

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 220

Drag and drop the threat-mitigation techniques from the left onto the types of threat or attack they mitigate on the right.

Full Access
Question # 221

Drag and drop the TCP or UDP details from the left onto their corresponding protocols on the right.

Full Access
Question # 222

Refer to the exhibit.

Traffic sourced from the loopback0 Interface is trying to connect via ssh to the host at 10.0.1.15. What Is the next hop to the destination address?

A.

192.168.0.7

B.

192.168.0.4

C.

192.168.0.40

D.

192.168.3.5

Full Access
Question # 223

Drag and drop the AAA terms from the left onto the description on the right.

Full Access
Question # 224

Which plane is centralized by an SDN controller?

A.

management-plane

B.

control-plane

C.

data-plane

D.

services-plane

Full Access
Question # 225

An organization secures its network with multi-factor authentication using an authenticator app on employee smartphone. How is the application secured in the case of a user’s smartphone being lost or stolen?

A.

The application requires an administrator password to reactivate after a configured Interval.

B.

The application requires the user to enter a PIN before it provides the second factor.

C.

The application challenges a user by requiring an administrator password to reactivate when the smartphone is rebooted.

D.

The application verifies that the user is in a specific location before it provides the second factor.

Full Access
Question # 226

Refer to the exhibit.

A network engineer configures the Cisco WLC to authenticate local wireless clients against a RADIUS server Which task must be performed to complete the process?

A.

Change the Server Status to Disabled

B.

Select Enable next to Management

C.

Select Enable next to Network User

D.

Change the Support for CoA to Enabled.

Full Access
Question # 227

Refer to the exhibit.

Between which zones do wireless users expect to experience intermittent connectivity?

A.

between zones 1 and 2

B.

between zones 2 and 5

C.

between zones 3 and 4

D.

between zones 3 and 6

Full Access
Question # 228

Refer to the exhibit. An engineer is asked to configure router R1 so that it forms an OSPF single-area neighbor relationship with R2. Which command sequence must be implemented to configure the router?

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 229

Refer to the exhibit.

The administrator must configure a floating static default route that points to 2001:db8:1234:2::1 and replaces the current default route only if it fails. Which command must the engineer configure on the CPE?

A.

ipv6 route ::/0 2001:db8:1234:2::1 3

B.

ipv6 route ::/128 2001 :db8:1234:2::1 3

C.

ipv6 route ::/0 2001:db8:1234:2::1 1

D.

ipv6 route ::/0 2001:db8:1234:2::1 2

Full Access
Question # 230

Refer to the exhibit.

Which two commands when used together create port channel 10? (Choose two.)

A.

int range g0/0-1channel-group 10 mode active

B.

int range g0/0-1 channel-group 10 mode desirable

C.

int range g0/0-1channel-group 10 mode passive

D.

int range g0/0-1 channel-group 10 mode auto

E.

int range g0/0-1 channel-group 10 mode on

Full Access
Question # 231

Which protocol requires authentication to transfer a backup configuration file from a router to a remote server?

A.

DTP

B.

FTP

C.

SMTP

D.

TFTP

Full Access
Question # 232

Drag and drop the characteristics of networking from the left onto the networking types on the right.

Full Access
Question # 233

Configure IPv4 and IPv6 connectivity between two routers. For IPv4, use a /28 network from the 192.168.1.0/24 private range. For IPv6, use the first /64 subnet from the 2001:0db8:aaaa::/48 subnet.

1. Using Ethernet0/1 on routers R1 and R2, configure the next usable/28 from the 192.168.1.0/24 range. The network 192.168.1.0/28 is unavailable.

2. For the IPv4 /28 subnet, router R1 must be configured with the first usable host address.

3. For the IPv4 /28 subnet, router R2 must be configured with the last usable host address.

4. For the IPv6 /64 subnet, configure the routers with the IP addressing provided from the topology.

5. A ping must work between the routers on the IPv4 and IPv6 address ranges.

Full Access
Question # 234

All physical cabling is in place. Router R4 and PCI are fully configured and

inaccessible. R4 ' s WAN interfaces use .4 in the last octet for each subnet.

Configurations should ensure that connectivity is established end-to-end.

1 . Configure static routing to ensure RI prefers the path through R2 to

reach only PCI on R4 ' s LAN

2. Configure static routing that ensures traffic sourced from RI will take

an alternate path through R3 to PCI in the event of an outage along

the primary path

3. Configure default routes on RI and R3 to the Internet using the least number of hops

Guidelines

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using

the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Full Access
Question # 235

Physical connectivity is implemented between the two Layer 2 switches,

and the network connectivity between them must be configured.

I . Configure an LACP EtherChanneI and number it as 44; configure it

between switches SWI and SW2 using interfaces EthernetO/O and

Ethernet0/1 on both sides. The LACP mode must match on both ends.

2. Configure the EtherChanneI as a trunk link.

3. Configure the trunk link with 802. Iq tags.

4. Configure VLAN ' MONITORING ' as the untagged VLAN of the

EtherChannel.

==================

Guidelines

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using

the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Full Access
Question # 236

All physical cabling between the two switches is installed. Configure the network connectivity between the switches using the designated VLANs and interfaces.

1. Configure VLAN 100 named Compute and VLAN 200 named Telephony where required for each task.

2. Configure Ethernet0/1 on SW2 to use the existing VLAN named Available.

3. Configure the connection between the switches using access ports.

4. Configure Ethernet0/1 on SW1 using data and voice VLANs.

5. Configure Ethemet0/1 on SW2 so that the Cisco proprietary neighbor discovery protocol is turned off for the designated interface only.

Full Access
Question # 237

Physical connectivity is implemented between the two Layer 2 switches, and the network connectivity between them must be configured

1. Configure an LACP EtherChannel and number it as 1; configure it between switches SW1 and SVV2 using interfaces Ethernet0/0 and Ethernet0/1 on both sides. The LACP mode must match on both ends

2 Configure the EtherChannel as a trunk link.

3. Configure the trunk link with 802.1 q tags.

4. Configure the native VLAN of the EtherChannel as VLAN 15.

Full Access
Question # 238

All physical cabling is in place. A company plans to deploy 32 new sites.

The sites will utilize both IPv4 and IPv6 networks.

1 . Subnet 172.25.0.0/16 to meet the subnet requirements and maximize

the number of hosts

Using the second subnet

• Assign the first usable IP address to e0/0 on Sw1O1

• Assign the last usable IP address to e0/0 on Sw102

2. Subnet to meet the subnet requirements and maximize

the number of hosts

c Using the second subnet

• Assign an IPv6 GUA using a unique 64-Bit interface identifier

on e0/0 on Sw101

• Assign an IPv6 GUA using a unique 64-Bit interface identifier

on eO/O on swi02

Guidelines

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using

the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Full Access
Question # 239

IP connectivity between the three routers is configured. OSPF adjacencies must be established.

1. Configure R1 and R2 Router IDs using the interface IP addresses from the link that is shared between them.

2. Configure the R2 links with a max value facing R1 and R3. R2 must become the DR. R1 and R3 links facing R2 must remain with the default OSPF configuration for DR election. Verify the configuration after clearing the OSPF process.

3. Using a host wildcard mask, configure all three routers to advertise their respective Loopback1 networks.

4. Configure the link between R1 and R3 to disable their ability to add other OSPF routers.

Full Access
Question # 240

IP connectivity and OSPF are preconfigured on all devices where necessary. Do not make any changes to the IP addressing or OSPF. The company policy uses connected interfaces and next hops when configuring static routes except for load balancing or redundancy without floating static. Connectivity must be established between subnet 172.20.20.128/25 on the Internet and the LAN at 192.168.0.0/24 connected to SW1:

1. Configure reachability to the switch SW1 LAN subnet in router R2.

2. Configure default reachability to the Internet subnet in router R1.

3. Configure a single static route in router R2 to reach to the Internet subnet considering both redundant links between routers R1 and R2. A default route is NOT allowed in router R2.

4. Configure a static route in router R1 toward the switch SW1 LAN subnet where the primary link must be through Ethernet0/1. and the backup link must be through Ethernet0/2 using a floating route. Use the minimal administrative distance value when required.

Full Access
Question # 241

Three switches must be configured for Layer 2 connectivity. The company requires only the designated VLANs to be configured on their respective switches and permitted accross any links between switches for security purposes. Do not modify or delete VTP configurations.

The network needs two user-defined VLANs configured:

VLAN 110: MARKETING

VLAN 210: FINANCE

1. Configure the VLANs on the designated switches and assign them as access ports to the interfaces connected to the PCs.

2. Configure the e0/2 interfaces on Sw1 and Sw2 as 802.1q trunks with only the required VLANs permitted.

3. Configure the e0/3 interfaces on Sw2 and Sw3 as 802.1q trunks with only the required VLANs permitted.

Full Access
Question # 242

Connectivity between four routers has been established. IP connectivity must be configured in the order presented to complete the implementation. No dynamic routing protocols are included.

1. Configure static routing using host routes to establish connectivity from router R3 to the router R1 Loopback address using the source IP of 209.165.200.230.

2. Configure an IPv4 default route on router R2 destined for router R4.

3. Configure an IPv6 default router on router R2 destined for router R4.

Full Access
Question # 243

Topology:

All relevant ports are preconfigured as IEEE 802.1Q trunks.

Task 1

Configure SW-1 port Ethernet0/0 to permit only VLANs 5 and 6.

Task 2

Configure ports Ethernet0/1 on SW-1 and SW-2 to use VLAN 77 as the native VLAN.

Task 3

Configure SW-2 port Ethernet0/2 to permit only VLAN 6.

Task 4

Using LACP, create a Port-Channel between SW-3 and SW-4.

    Combine Ethernet0/0 and Ethernet0/1 into a Port-Channel while leaving the existing trunk configurations intact.

    Assign Port-Channel number 34.

    Only SW-3 must initiate LACP negotiations.

Full Access
Question # 244

Connectivity between three routers has been established, and IP services must be configured jn the order presented to complete the implementation Tasks assigned include configuration of NAT, NTP, DHCP, and SSH services.

1. All traffic sent from R3 to the R1 Loopback address must be configured for NAT on R2. All source addresses must be translated from R3 to the IP address of Ethernet0/0 on R2, while using only a standard access list named NAT To verify, a ping must be successful to the R1 Loopback address sourced from R3. Do not use NVI NAT configuration.

2. Configure R1 as an NTP server and R2 as a client, not as a peer, using the IP address of the R1 Ethernet0/2 interface. Set the clock on the NTP server for midnight on January 1, 2019.

3. Configure R1 as a DHCP server for the network 10.1.3.0/24 in a pool named TEST. Using a single command, exclude addresses 1-10 from the range. Interface Ethernet0/2 on R3 must be issued the IP address of 10.1.3.11 via DHCP.

4. Configure SSH connectivity from R1 to R3, while excluding access via other remote connection protocols. Access for user root and password Cisco must be set on router R3 using RSA and 1024 bits. Verify connectivity using an SSH session from router R1 using a destination address of 10.1.3.11. Do NOT modify console access or line numbers to accomplish this task.

Full Access
Question # 245

Topology:

Configure OSPF routing for the network by completing the following tasks:

Task 1

Configure OSPF on R2. Ensure that R1 and R3 become neighbors.

    Use process ID 30.

    Use 10.22.22.22 as the router ID.

    Under the OSPF process, advertise the following specific prefixes:

      10.0.23.0/28

      10.0.12.0/30

Task 2

Ensure that R2 always becomes the designated router (DR).

Full Access
Question # 246

Refer to the exhibit.

The EtherChannel is configured with a speed of 1000 and duplex as full on both ends of channel group 1. What is the next step to configure the channel on switch A to respond to but not initiate LACP communication?

A.

interface range gigabitethernet0/0/0-15 channel-group 1 mode on

B.

interface range gigabitethernet0/0/0-15 channel-group 1 mode desirable

C.

interface port-channel 1 channel-group 1 mode auto

D.

interface port-channel 1 channel-group 1 mode passive

Full Access
Question # 247

Which WPA mode uses PSK authentication?

A.

Local

B.

Client

C.

Enterprise

D.

Personal

Full Access
Question # 248

A WLC sends alarms about a rogue AP, and the network administrator verifies that the alarms are caused by a legitimate autonomous AP.

A.

Place the AP into manual containment.

B.

Remove the AP from WLC management.

C.

Manually remove the AP from Pending state.

D.

Set the AP Class Type to Friendly.

Full Access
Question # 249

When a WPA2-PSK WLAN is configured in the Wireless LAN Controller, what is the minimum number of characters that is required in ASCII format?

A.

6

B.

8

C.

12

D.

18

Full Access
Question # 250

Which command configures the Cisco WLC to prevent a serial session with the WLC CLI from being automatical togged out?

A.

config sessions maxsessions 0

B.

config sessions timeout 0

C.

config serial timeout 0

D.

config serial timeout 9600

Full Access
Question # 251

Refer to the exhibit.

An administrator received a call from a branch office regarding poor application performance hosted at the headquarters. Ethernet 1 is connected between Router1 and the LAN switch. What identifies the issue?

A.

The QoS policy is dropping traffic.

B.

There is a duplex mismatch.

C.

The link is over utilized.

D.

The MTU is not set to the default value.

Full Access
Question # 252

Which two IPv6 addresses are used to provide connectivity between two routers on a shared link? (Choose two)

A.

::ffff:1014:1011/96

B.

2001:701:1046:1111::1/64

C.

;jff06bb43cd4dd111bbff02 4545234d

D.

2002:5121:204b:1111::1/64

E.

FF02::0WlFF00:0l)00/104

Full Access
Question # 253

Refer to the exhibit.

How many JSON objects are presented?

A.

1

B.

2

C.

3

D.

4

Full Access
Question # 254

What is the function of northbound API?

A.

It upgrades software and restores files.

B.

It relies on global provisioning and configuration.

C.

It supports distributed processing for configuration.

D.

It provide a path between an SDN controller and network applications.

Full Access
Question # 255

A network engineer is upgrading a small data center to host several new applications, including server backups that are expected to account for up to 90% of the bandwidth during peak times. The data center connects to the MPLS network provider via a primary circuit and a secondary circuit. How does the engineer inexpensively update the data center to avoid saturation of the primary circuit by traffic associated with the backups?

A.

Assign traffic from the backup servers to a dedicated switch.

B.

configure a dedicated circuit for the backup traffic.

C.

Place the backup servers in a dedicated VLAN.

D.

Advertise a more specific route for the backup traffic via the secondary circuit.

Full Access
Question # 256

Which action implements physical access control as part of the security program of an organization??

A.

backing up syslogs at a remote location

B.

configuring a password for the console port

C.

configuring enable passwords on network devices

D.

setting up IP cameras to monitor key infrastructure

Full Access
Question # 257

Drag and drop the Rapid PVST+ forwarding state actions from the left to the right. Not all actions are used.

Full Access
Question # 258

Drag and drop the Ansible features from the left to the right Not all features are used.

Full Access
Question # 259

Drag and drop the statements about networking from the left onto the corresponding networking types on the right

Full Access
Question # 260

What is a function of an endpoint?

A.

It is used directly by an individual user to access network services

B.

It passes unicast communication between hosts in a network

C.

It transmits broadcast traffic between devices in the same VLAN

D.

It provide security between trusted and untrusted sections of the network.

Full Access
Question # 261

Which type of IPv4 address type helps to conserve the globally unique address classes?

A.

multicast

B.

private

C.

loopback

D.

public

Full Access
Question # 262

Refer to the exhibit.

Which entry is the longest prefix match for host IP address 192.168.10.5?

A.

1

B.

2

C.

3

D.

4

Full Access
Question # 263

hostname CPE

service password-encryption

ip domain name ccna.cisco.com

ip name-server 198.51.100.210

crypto key generate rsa modulus 1024

username admin privilege 15 secret s0m3s3cr3t

line vty 0 4

transport input ssh

login local

Refer to the exhibit. An engineer executed the script and added commands that were not necessary for SSH and now must remove the commands. Which two commands must be executed to correct the configuration? (Choose two.)

A.

no ip name-server 198.51.100.210

B.

no login local

C.

no service password-encryption

D.

no ip domain name ccna.cisco.com

E.

no hostname CPE

Full Access
Question # 264

What is a characteristic of RSA?

A.

It uses preshared keys for encryption

B.

It requires both sides to have identical keys

C.

It is a private-key encryption algorithm

D.

It is a public-key cryptosystem

Full Access
Question # 265

Refer to the exhibit.

An engineer is configuring a new Cisco switch NewSW, to replace SW2 The details have been provided

• Switches SW1 and SW2 are third-party devices without support for trunk ports

• The existing connections must be maintained between PC1 PC2 and PC3

• Allow the switch to pass traffic from future VLAN 10. Which configuration must be applied?

A)

B)

C)

D)

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 266

Which IP header field is changed by a Cisco device when QoS marking is enabled?

A.

Header Checksum

B.

Type of service

C.

DSCP

D.

ECN

Full Access
Question # 267

What must be considered for a locally switched FlexConnect AP if the VLANs that are used by the AP and client access are different?

A.

The APs must be connected to the switch with multiple links in LAG mode

B.

The switch port mode must be set to trunk

C.

The native VLAN must match the management VLAN of the AP

D.

IEEE 802.10 trunking must be disabled on the switch port.

Full Access
Question # 268

Which command implies the use of SNMPv3?

A.

snmp-server host

B.

snmp-server community

C.

snmp-server enable traps

D.

snmp-server user

Full Access
Question # 269

Refer to the exhibit.

What is the prefix length for the route that router1 will use to reach host A?

A.

/25

B.

/27

C.

/28

D.

/29

Full Access
Question # 270

Refer to the exhibit.

PC1 regularly sends 1800 Mbps of traffic to the server. A network engineer needs to configure the EtherChannel to disable Port Channel 1 between SW1 and SW2 when the Ge0/0 and Ge0/1 ports on SW2 go down. Which configuration must the engineer apply to the switch?

A)

B)

C)

D)

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 271

Which type of port is used to connect to the wired network when an autonomous AP maps two VLANs to its WLANs?

A.

LAG

B.

EtherChannel

C.

trunk

D.

access

Full Access
Question # 272

Which protocol is used in Software Defined Access (SDA) to provide a tunnel between two edge nodes in different fabrics?

A.

Generic Router Encapsulation (GRE)

B.

Virtual Local Area Network (VLAN)

C.

Virtual Extensible LAN (VXLAN)

D.

Point-to-Point Protocol

Full Access
Question # 273

What are two disadvantages of a full-mesh topology? (Choose two.)

A.

It needs a high MTU between sites.

B.

It has a high implementation cost.

C.

It must have point-to-point communication.

D.

It requires complex configuration.

E.

It works only with BGP between sites.

Full Access
Question # 274

What is the purpose of configuring different levels of syslog for different devices on the network?

A.

to rate-limit messages for different severity levels from each device

B.

to set the severity of syslog messages from each device

C.

to identify the source from which each syslog message originated

D.

to control the number of syslog messages from different devices that are stored locally

Full Access
Question # 275

Refer to the exhibit.

User traffic originating within site 0 is failing to reach an application hosted on IIP address 192.168.0.10. Which is located within site A What is determined by the routing table?

A.

The default gateway for site B is configured incorrectly

B.

The lack of a default route prevents delivery of the traffic

C.

The traffic is blocked by an implicit deny in an ACL on router2

D.

The traffic to 192.168.0.10 requires a static route to be configured in router 1.

Full Access
Question # 276

Which two features introduced in SNMPv2 provide the ability to retrieve large amounts of data in one request

A.

Get

B.

GetNext

C.

Set

D.

GetBulk

E.

Inform

Full Access
Question # 277

Which remote access protocol provides unsecured remote CLI access?

A.

console

B.

Telnet

C.

Bash

D.

SSH

Full Access
Question # 278

Which protocol must be implemented to support separate authorization and authentication solutions for wireless APs?

A.

RADIUS

B.

TACACS+

C.

802.1X

D.

Kerberos

Full Access
Question # 279

Refer to the exhibit.

A Cisco engineer creates a new WLAN called lantest. Which two actions must be performed so that only high-speed 2.4-GHz clients connect? (Choose two.)

A.

Enable the Broadcast SSID option

B.

Enable the Status option.

C.

Set the Radio Policy option to 802.11g Only.

D.

Set the Radio Policy option to 802.11a Only.

E.

Set the Interface/Interface Group(G) to an interface other than guest

Full Access
Question # 280

Drag and drop the characteristics of transport layer protocols from the left onto the corresponding protocols on the right.

Full Access
Question # 281

What is the put method within HTTP?

A.

It is a read-only operation.

B.

It is a nonldempotent operation.

C.

It replaces data at the destination.

D.

It displays a web site.

Full Access
Question # 282

Which cable type must be used to interconnect one switch using 1000 BASE-SX GBIC modules and another switch using 1000 BASE-SX SFP modules?

A.

LC to SC

B.

SC t ST

C.

SC to SC

D.

LC to LC

Full Access
Question # 283

Why implement VRRP?

A.

to provide end users with a virtual gateway in a multivendor network

B.

to leverage a weighting scheme to provide uninterrupted service

C.

to detect link failures without the overhead of Bidirectional Forwarding Detection

D.

to hand over to end users the autodiscovery of virtual gateways

Full Access
Question # 284

What are two examples of multifactor authentication? (Choose two.)

A.

single sign-on

B.

unique user knowledge

C.

passwords that expire

D.

soft tokens

E.

shared password responsibility

Full Access
Question # 285

A)

B)

C)

D)

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 286

Refer to the exhibit.

Which configuration establishes a Layer 2 LACP EtherChannel when applied to both switches?

A.

Interface range G1/1 – 1/3 switchport mode trunk channel-group 1 mode active no shutdown

B.

Interface range G1/1 – 1/3 switchport mode access channel-group 1 mode passive no shutdown

C.

Interface range G1/1 – 1/3 switchport mode trunkchannel-group 1 mode desirableno shutdown

D.

Interface range G1/1 – 1/3 switchport mode access channel-group 1 mode on no shutdown

Full Access
Question # 287

What is a reason to implement IPv4 private addressing?

A.

Reduce the risk of a network security breach

B.

Comply with PCI regulations

C.

Comply with local law

D.

Reduce the size of the forwarding table on network routers

Full Access
Question # 288

Drag and drop the WLAN components from the left onto the component details on the right.

Full Access
Question # 289

By default, how long will the switch continue to know a workstation MAC address after the workstation stops sending traffic?

A.

200 seconds

B.

300 seconds

C.

600 seconds

D.

900 seconds

Full Access
Question # 290

How do TCP and UDP fit into a query-response model?

A.

TCP establishes a connection prior to sending data, and UDP sends immediately.

B.

TCP uses error detection for packets, and UDP uses error recovery.

C.

TCP avoids using sequencing, and UDP avoids using acknowledgments.

D.

TCP encourages out-of-order packet delivery, and UDP prevents re-ordering.

Full Access
Question # 291

Refer to the exhibit.

A network engineer executes the show ip route command on router D. What is the next hop to network 192.168.1.0/24 and why?

A.

The next hop is 10.0.2.1 because it uses distance vector routing

B.

The next hop is 10.0.2.1 because it is a link-state routing protocol

C.

The next hop is 10.0.0.1 because it has a better administrative distance

D.

The next hop is 10.0.0.1 because it has a higher metric.

Full Access
Question # 292

What is a specification for SSIDS?

A.

They are a Cisco proprietary security feature.

B.

They must include one number and one letter.

C.

They define the VLAN on a switch.

D.

They are case sensitive.

Full Access
Question # 293

What is a reason to configure a trunk port that connects to a WLC distribution port?

A.

Eliminate redundancy with a link failure in the data path.

B.

Allow multiple VLAN to be used in the data path.

C.

Provide redundancy if there is a link failure for out-of-band management.

D.

Permit multiple VLANs to provide out-of-band management.

Full Access
Question # 294

Which Cisco proprietary protocol ensures traffic recovers immediately, transparently, and automatically when edge devices or access circuits fail?

A.

SLB

B.

FHRP

C.

VRRP

D.

HSRP

Full Access
Question # 295

What is used as a solution for protecting an individual network endpoint from attack?

A.

Router

B.

Wireless controller

C.

anti-malware software

D.

Cisco DNA Center

Full Access
Question # 296

Refer to the exhibit.

Host A switch interface is configured in VLAN 2. Host D sends a unicast packet destined for the IP address of host A.

What does the switch do when it receives the frame from host D?

A.

It creates a broadcast storm.

B.

It drops the frame from the MAC table of the switch.

C.

It shuts down the source port and places It In err-disable mode.

D.

It floods the frame out of every port except the source port.

Full Access
Question # 297

SIP-based Call Admission Control must be configuredd in the Cisco WLC GUI. SIP call-snooping ports are configured. Which two actions must be completed next? (Choose two.)

A.

Set the QoS level to silver or greater for voice traffic.

B.

Set the QoS level to platinum for voice traffic.

C.

Enable Media Session Snooping on re WLAN.

D.

Enable traffic shaping for the LAN interface of the WLC.

E.

configure two different QoS rotes tor data and voice traffic.

Full Access
Question # 298

Refer to the exhibit.

A network administrator must permit traffic from the 10.10.0.0/24 subnet to the WAN on interface Serial0. What is the effect of the configuration as the administrator applies the command?

A.

The permit command fails and returns an error code.

B.

The router accepts all incoming traffic to Serial0 with the last octet of the source IP set to 0.

C.

The sourced traffic from IP range 10.0.0.0 -10.0.0.255 is allowed on Serial0.

D.

The router fails to apply the access list to the interface.

Full Access
Question # 299

Refer to the exhibit.

A network engineer must configure R1 so that it sends all packets destined to the 10.0.0.0/24 network to R3, and all packets destined to PCI to R2. Which configuration must the engineer implement?

A)

B)

C)

D)

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 300

Drag and drop the statements about networking from the left onto the corresponding networking types on the right. Not all statements are used.

Full Access
Question # 301

Which interface enables communication between a program on the controller and a program on the networking devices?

A.

northbound interface

B.

software virtual interface

C.

southbound interface

D.

tunnel Interface

Full Access
Question # 302

PC1 tries to send traffic to newly installed PC2. The PC2 MAC address is not listed in the MAC address table of the switch, so the switch sends the packet to all ports in the same VLAN Which switching concept does this describe?

A.

MAC address aging

B.

MAC address table

C.

frame flooding

D.

spanning-tree protocol

Full Access
Question # 303

Drag and drop the SNMP components from the left onto the description on the right.

Full Access
Question # 304

Drag and drop the statements about AAA services from the left onto the corresponding AAA services on the right Not all options are used.

Full Access
Question # 305

Drag and drop the DNS commands from the left onto their effects on the right.

Full Access
Question # 306

When an access point is seeking to join wireless LAN controller, which message is sent to the AP- Manager interface?

A.

Discovery response

B.

DHCP request

C.

DHCP discover

D.

Discovery request

Full Access
Question # 307

Refer to the exhibit.

An engineer must configure a floating static route on an external EIGRP network. The destination subnet is the /29 on the LAN Interface of R86. Which command must be executed on R14?

A.

ip route 10.80.65.0.255.255.248.0.10.73.65.66.1

B.

ip route 10.80.65.0.255.255.255..240 fa0/1 89

C.

ip route 10.80.65.0.255.255.248.0.10.73.65.66.171

D.

ip route 10.80.65.0.0.0.224.10.80.65.0. 255

Full Access
Question # 308

Which protocol does Ansible use to push modules to nodes in a network?

A.

SSH

B.

SNMP

C.

Kerberos

D.

Telnet

Full Access
Question # 309

Why are API keys used to enforce rate limiting?

A.

to uniquely identify clients to monitor their usage patterns

B.

to encrypt data to prevent excessive usage

C.

to contain embedded permissions that automatically expire

D.

to track the geographical location of each request

Full Access
Question # 310

Refer to the exhibit. Which interface does a packet take to reach the destination addresss of 10.10.10.147?

A.

FastEthemet 0/0

B.

Senal0/0

C.

FastEthemet 0/1

Full Access