Summer Special Discount 60% Offer - Ends in 0d 00h 00m 00s - Coupon code: brite60

ExamsBrite Dumps

Cisco Certified Network Associate Question and Answers

Cisco Certified Network Associate

Last Update Oct 2, 2025
Total Questions : 1191

We are offering FREE 200-301 Cisco exam questions. All you do is to just go and sign up. Give your details, prepare 200-301 free exam questions and then go for complete pool of Cisco Certified Network Associate test questions that will help you more.

200-301 pdf

200-301 PDF

$46  $114.99
200-301 Engine

200-301 Testing Engine

$54  $134.99
200-301 PDF + Engine

200-301 PDF + Testing Engine

$70  $174.99
Questions 1

Refer to the exhibit. What is the administrative distance for the advertised prefix that includes the host IP address 10.30.0.1?

Options:

A.  

10.0.0.2

B.  

110

C.  

30

D.  

2

Discussion 0
Questions 2

What is the function of generative AI in network operations?

Options:

A.  

It disables unused services.

B.  

It deploys network firmware updates.

C.  

It creates synthetic network configurations.

D.  

It computes optimal data storage solutions.

Discussion 0
Questions 3

Refer to the exhibit. A network engineer is adding another physical interface as a new member to the existing Port-Channel1 bundle.

Which command set must be configured on the new interface to complete the process?

Options:

A.  

switchport mode trunk channel-group 1 mode active

B.  

no switchport channel-group 1 mode active

C.  

no switchport channel-group 1 mode on

D.  

switchport switchport mode trunk

Discussion 0
Questions 4

What is represented by the word "LB13" within this JSON schema?

Options:

A.  

value

B.  

object

C.  

array

D.  

key

Discussion 0
Questions 5

IP connectivity and OSPF are preconfigured on all devices where necessary. Do not make any changes to the IP addressing or OSPF. The company policy uses connected interfaces and next hops when configuring static routes except for load balancing or redundancy without floating static. Connectivity must be established between subnet 172.20.20.128/25 on the Internet and the LAN at 192.168.0.0/24 connected to SW1:

1. Configure reachability to the switch SW1 LAN subnet in router R2.

2. Configure default reachability to the Internet subnet in router R1.

3. Configure a single static route in router R2 to reach to the Internet subnet considering both redundant links between routers R1 and R2. A default route is NOT allowed in router R2.

4. Configure a static route in router R1 toward the switch SW1 LAN subnet where the primary link must be through Ethernet0/1. and the backup link must be through Ethernet0/2 using a floating route. Use the minimal administrative distance value when required.

Options:

Discussion 0
Questions 6

Refer to the exhibit. Configurations for the switch and PCs are complete.

Which configuration must be applied so that VLANs 2 and 3 communicate back and forth?

Options:

A.  

interface GigabitEthernet0/0 ip address 10.10.2.10 255.255.252.0

B.  

interface GigabitEthernet0/0.3 encapsulation dot1Q 3 native ip address 10.10.2.10 255.255.252.0

C.  

interface GigabitEthernet0/0.10 encapsulation dot1Q 3

D.  

interface GigabitEthernet0/0.3 encapsulation dot1Q 10 ip address 10.10.2.10 255.255.252.0

Discussion 0
Questions 7

What is the main purpose of SSH management access?

Options:

A.  

To support DES 56-bit and 3DES (168-bit) ciphers

B.  

To enable secured access to the inbound management interface

C.  

To validate management access with username and domain name only

D.  

To allow passwords protected with HTTPS encryption to be sent

Discussion 0
Questions 8

Drag and drop the characteristic from the left onto the IPv6 address type on the right.

Options:

Discussion 0
Questions 9

Refer to the exhibit. What is the administrative distance for the advertised prefix that includes the host IP address 192.168.20.1?

Options:

A.  

0

B.  

192.168.10.2

C.  

24

D.  

1

Discussion 0
Questions 10

What is a function of a northbound API in an SDN environment?

Options:

A.  

It supports distributed processing for configuration.

B.  

It relies on global provisioning and configuration.

C.  

It upgrades software and restores files.

D.  

It provides orchestration and network automation services.

Discussion 0
Questions 11

A wireless administrator has configured a WLAN; however, the clients need access to a less congested 5-GHz network for their voice quality. What action must be taken to meet the requirement?

Options:

A.  

enable AAA override

B.  

enable RX-SOP

C.  

enable DTIM

D.  

enable Band Select

Discussion 0
Questions 12

IP connectivity between the three routers is configured. OSPF adjacencies must be established.

1. Configure R1 and R2 Router IDs using the interface IP addresses from the link that is shared between them.

2. Configure the R2 links with a max value facing R1 and R3. R2 must become the DR. R1 and R3 links facing R2 must remain with the default OSPF configuration for DR election. Verify the configuration after clearing the OSPF process.

3. Using a host wildcard mask, configure all three routers to advertise their respective Loopback1 networks.

4. Configure the link between R1 and R3 to disable their ability to add other OSPF routers.

Options:

Discussion 0
Questions 13

Which IP address is used when an administrator must open a web-based management session with a lightweight AP?

Options:

A.  

WLCIP

B.  

gateway IP

C.  

autonomous AP IP

D.  

ACS IP

Discussion 0
Questions 14

Refer to the exhibit. VLAN 23 is being implemented between SW1 and SW2. The command show interface ethernet0/0 switchport has been issued on SW1. Ethernet0/0 on SW1 is the uplink to SW2. Which command when entered on the uplink interface allows PC 1 and PC 2 to communicate without impact to the communication between PC 11 and PC 12?

Options:

A.  

switchport trunk allowed vlan 2-1001

B.  

switchport trunk allowed vlan add 23

C.  

switchport trunk allowed vlan 23

D.  

switchport trunk allowed vlan 22-23

Discussion 0
Questions 15

Configure IPv4 and IPv6 connectivity between two routers. For IPv4, use a /28 network from the 192.168.1.0/24 private range. For IPv6, use the first /64 subnet from the 2001:0db8:aaaa::/48 subnet.

1. Using Ethernet0/1 on routers R1 and R2, configure the next usable/28 from the 192.168.1.0/24 range. The network 192.168.1.0/28 is unavailable.

2. For the IPv4 /28 subnet, router R1 must be configured with the first usable host address.

3. For the IPv4 /28 subnet, router R2 must be configured with the last usable host address.

4. For the IPv6 /64 subnet, configure the routers with the IP addressing provided from the topology.

5. A ping must work between the routers on the IPv4 and IPv6 address ranges.

Options:

Discussion 0
Questions 16

Which interface condition is occurring in this output?

Options:

A.  

duplex mismatch

B.  

queueing

C.  

bad NIC

D.  

broadcast storm

Discussion 0
Questions 17

Which two features are provided by Ansible in network automation? (Choose two.)

Options:

A.  

supplying network credentials

B.  

role-based access control

C.  

agentless deployment

D.  

manual playbook runs

E.  

launching job templates using version control

Discussion 0
Questions 18

What is a similarity between global and unique local IPv6 addresses?

Options:

A.  

They are allocated by the same organization.

B.  

They are routable on the global internet.

C.  

They use the same process for subnetting.

D.  

They are part of the multicast IPv6 group type.

Discussion 0
Questions 19

Why are API keys used to enforce rate limiting?

Options:

A.  

to uniquely identify clients to monitor their usage patterns

B.  

to encrypt data to prevent excessive usage

C.  

to contain embedded permissions that automatically expire

D.  

to track the geographical location of each request

Discussion 0
Questions 20

Why would a network administrator choose to implement RFC 1918 address space?

Options:

A.  

to route traffic on the internet

B.  

to provide flexibility in the IP network design

C.  

to provide overlapping address space with another network

D.  

to limit the number of hosts on the network

Discussion 0
Questions 21

Refer to the exhibit. What is preventing host A from reaching the internet?

Options:

A.  

The domain name server is unreachable.

B.  

LAN and WAN network segments are different.

C.  

IP address assignment is incorrect.

D.  

The default gateway should be the first usable IP address.

Discussion 0
Questions 22

Which role do predictive Al models play in network load balancing?

Options:

A.  

They anticipate future traffic spikes.

B.  

They assign IP addresses to devices.

C.  

They select correct cabling types for deployment.

D.  

They solely monitor historical traffic volumes.

Discussion 0
Questions 23

Why would a network administrator implement the HSRP protocol?

Options:

A.  

To provide network redundancy in the case of a router failure

B.  

To use an open standard protocol that is configured on Cisco and third-party routers

C.  

To allow hosts in a network to use the same default gateway virtual IP when load-balancing traffic

D.  

To allow clients to be configured with multiple default gateway IPs

Discussion 0
Questions 24

Which default condition must be considered when an encrypted mobility tunnel is used between two Cisco WLCs?

Options:

A.  

TCP port 443 and UDP 21 are used.

B.  

Control and data traffic encryption are enabled.

C.  

The tunnel uses the IPsec protocol for encapsulation.

D.  

The tunnel uses the EolP protocol to transmit data traffic.

Discussion 0
Questions 25

Which header must be included in a REST request from an application that requires JSON-formatted content?

Options:

A.  

Content-Type: application/json

B.  

Accept-Encoding: application/json

C.  

Accept: application/json

D.  

Accept-Language: application/json

Discussion 0
Questions 26

Aswitch receives a frame with the destination MAC address 3C:5D: 7E:9F: 1A:2B.

Switch# show ethernet-frame-and-mac-address-table

How does the switch handle the frame?

Options:

A.  

It ages out the frame until the MAC address becomes known.

B.  

It drops the frame to avoid unnecessary network congestion.

C.  

It switches the frame to a predetermined port based on settings.

D.  

It floods the frame to all ports except the incoming port.

Discussion 0
Questions 27

Refer to the exhibit.

What is occurring on this switch?

Options:

A.  

A high number of frames smaller than 64 bytes are received.

B.  

Frames are dropped after 16 failed transmission attempts.

C.  

The internal transmit buffer is overloaded.

D.  

An excessive number of frames greater than 1518 bytes are received.

Discussion 0
Questions 28

Which interface on the WLC is used exclusively as a DHCP relay?

Options:

A.  

distribution

B.  

service

C.  

AP-manager

D.  

virtual

Discussion 0
Questions 29

Which interface is used to send traffic to the destination network?

O 10.76.170 161/26 |110/102] via FO/17

O 10.76.170 161/26[110/27e31] via FO/20

R 10.76.170.161/261120/15] via FO/8

R 10.76.170.161/26 [120/10] via FO/12

Options:

A.  

F0/8

B.  

FO/20

C.  

FO/12

D.  

FO/17

Discussion 0
Questions 30

Drag and drop the lightweight access point operation modes from the left onto the descriptions on the right

Options:

Discussion 0
Questions 31

Refer to the exhibit.

How does router R1 forward packets destined to 10.0.4.10?

Options:

A.  

via 10.0.4.2

B.  

via 10.0.0.2

C.  

via FastEthernet0/1

D.  

via FastEthernet1/1

Discussion 0
Questions 32

What are two behaviors of a point-to-point WAN topology? (Choose two.)

Options:

A.  

It uses a single router to route traffic between sites.

B.  

It leverages a dedicated connection.

C.  

It connects remote networks through a single line.

D.  

t delivers redundancy between the central office and branch offices.

E.  

It provides direct connections between each router in the topology.

Discussion 0
Questions 33

All physical cabling is in place. Router R4 and PCI are fully configured and

inaccessible. R4's WAN interfaces use .4 in the last octet for each subnet.

Configurations should ensure that connectivity is established end-to-end.

1 . Configure static routing to ensure RI prefers the path through R2 to

reach only PCI on R4's LAN

2. Configure static routing that ensures traffic sourced from RI will take

an alternate path through R3 to PCI in the event of an outage along

the primary path

3. Configure default routes on RI and R3 to the Internet using the least number of hops

Guidelines

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using

the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Options:

Discussion 0
Questions 34

A new DHCP server has been deployed in a corporate environment with lease time set to eight hours. Which CMD command on a Windows-based device allows the engineer to verify the DHCP lease expiration?

Options:

A.  

ipconfig /renew

B.  

ipconfig

C.  

ipconfig /all

D.  

ipconfig /displaydns

Discussion 0
Questions 35

Refer to the exhibit.

The LACP EtherChannel is configured, and the last change is to modify the interfaces on SwitchA to respond to packets received, but not to initiate negotiation. The interface range gigabitethernet0/0-15 command is entered. What must be configured next?

Options:

A.  

SwitchA(config-if-range) #channel-group 1 mode desirable

B.  

SwitchA(config-if-range) #channel-group 1 mode auto

C.  

SwitchA(config-if-range) #channel-group 1 mode active

D.  

SwitchA(config-if-range) #channel-group 1 mode passive

Discussion 0
Questions 36

Refer to the exhibit. The route for 10.220.100.96/27 has been very unstable. The same route has four backups to routers A, B, C, and D via the respective methods. The routing protocol defaults for router Y have not been changed. When the current route for 10.220.100.96/27 becomes unavailable, which router will router Y use to route traffic to 10.220.100.96/27?

Options:

A.  

router D

B.  

router B

C.  

router C

D.  

router A

Discussion 0
Questions 37

What is the purpose of the service-set identifier?

Options:

A.  

It identifies the wired network to which a network device is connected.

B.  

It identifies a wireless network for a mobile device to connect.

C.  

It identifies the wireless network to which an application must connect.

D.  

It identifies the wired network to which a user device is connected.

Discussion 0
Questions 38

Refer to the exhibit. The static routes were implemented on the border router. What is the next hop IP address for a ping sent to 172.16.153.154 from the border router?

Options:

A.  

10.56.65.56

B.  

10.56.65.65

C.  

10.65.56.56

D.  

10.65.65.65

Discussion 0
Questions 39

What is a characteristic of private IPv4 addressing?

Options:

A.  

alleviates the shortage of IPv4 addresses

B.  

reduces the forwarding table on network routers

C.  

enables secure connectivity over the internet

D.  

used as the NAT outside global IP address

Discussion 0
Questions 40

Which fact must the engineer consider when implementing syslog on a new network?

Options:

A.  

Syslog defines the software or hardware component that triggered the message.

B.  

There are 16 different logging levels (0-15).

C.  

By default, all message levels are sent to the syslog server.

D.  

The logging level defines the severity of a particular message.

Discussion 0
Questions 41

How does MAC learning function?

Options:

A.  

Enabled by default on all VLANs and interfaces

B.  

Forwards frames to a neighbor port using CDP

C.  

Overwrites the known source MAC address in the address table

D.  

Protects against denial of service attacks

Discussion 0
Questions 42

Three switches must be configured for Layer 2 connectivity. The company requires only the designated VLANs to be configured on their respective switches and permitted accross any links between switches for security purposes. Do not modify or delete VTP configurations.

The network needs two user-defined VLANs configured:

VLAN 110: MARKETING

VLAN 210: FINANCE

1. Configure the VLANs on the designated switches and assign them as access ports to the interfaces connected to the PCs.

2. Configure the e0/2 interfaces on Sw1 and Sw2 as 802.1q trunks with only the required VLANs permitted.

3. Configure the e0/3 interfaces on Sw2 and Sw3 as 802.1q trunks with only the required VLANs permitted.

Options:

Discussion 0
Questions 43

Refer to the exhibit. An administrator is configuring a new WLAN for a wireless network that has these requirements:

    Dual-band clients that connect to the WLAN must be directed to the 5-GHz spectrum.

    Wireless clients on this WLAN must be able to apply VLAN settings from RADIUS attributes.

Which two actions meet these requirements? (Choose two.)

Options:

A.  

Enable the Aironet IE option.

B.  

Enable the Coverage Hole Detection option.

C.  

Set the MFP Client Protection option to Required

D.  

Enable the client band select option.

E.  

Enable the allow AAA Override option

Discussion 0
Questions 44

An engineer requires a switch interface to actively attempt to establish a trunk link with a neighbor switch. What command must be configured?

Options:

A.  

switchport mode dynamic desirable

B.  

switchport mode trunk

C.  

switchport nonegotiate

D.  

switchport mode dynamic auto

Discussion 0
Questions 45

Physical connectivity is implemented between the two Layer 2 switches, and the network connectivity between them must be configured

1. Configure an LACP EtherChannel and number it as 1; configure it between switches SW1 and SVV2 using interfaces Ethernet0/0 and Ethernet0/1 on both sides. The LACP mode must match on both ends

2 Configure the EtherChannel as a trunk link.

3. Configure the trunk link with 802.1 q tags.

4. Configure the native VLAN of the EtherChannel as VLAN 15.

Options:

Discussion 0
Questions 46

Refer to the exhibit. A guest WLAN must be created that prompts the client for a username and password on the local web page of the WLC. Which two actions must be performed on the Layer 2 tab before enabling the Authentication option on the Layer 3 tab? (Choose two.)

Options:

A.  

Uncheck the WPA Policy option check box, and check the WPA2 Policy option check box.

B.  

Uncheck the MAC Filtering option check box.

C.  

Change the WPA Encryption option from TKIP to CCMP(128AES).

D.  

Set the Security Type option to Personal.

E.  

Set the Layer 2 Security option to None.

Discussion 0
Questions 47

Where are the real-time control functions processed in a split MAC architecture?

Options:

A.  

Centralized cloud management platform

B.  

Central WLC

C.  

Individual AP

D.  

Client device

Discussion 0
Questions 48

Refer to the exhibit. Which two commands, when configured on router R1. fulfill these requirements? (Choose two.) ' Packets toward the entire network 2001:db8:23: :/64 must be forwarded through router R2. ' Packets toward host 2001: db8:23::14 preferably must be forwarded through R3.

Options:

A.  

ipv6 route 2001:db8:23: :/128 fd00:12::2

B.  

Ipv6 route 2001:db8:23::14/128 fd00:13::3

C.  

ipv6 route 2001:db8:23::14/64 fd00:12::2 200

D.  

ipv6 route 2001:db8:23: l4/64 fd00:12::2

E.  

ipv6 route 2001:db8:23: :/64 fd00:12::2

Discussion 0
Questions 49

Physical connectivity is implemented between the two Layer 2 switches,

and the network connectivity between them must be configured.

I . Configure an LACP EtherChanneI and number it as 44; configure it

between switches SWI and SW2 using interfaces EthernetO/O and

Ethernet0/1 on both sides. The LACP mode must match on both ends.

2. Configure the EtherChanneI as a trunk link.

3. Configure the trunk link with 802. Iq tags.

4. Configure VLAN 'MONITORING' as the untagged VLAN of the

EtherChannel.

==================

Guidelines

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using

the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Options:

Discussion 0
Questions 50

What is an advantage of using SDN versus traditional networking when it comes to security?

Options:

A.  

SDN security is managed near the perimeter of the network with firewalls, VPNs, and IPS, and traditional networking security policies are created based on telemetry data.

B.  

SDN exposes an API to configure locally per device for security policies, and traditional networking uses northbound API for network admin interface for configuring security policies.

C.  

SDN creates a unified control point making security policies consistent across all devices, and traditional networking must be configured device by device, leaving room for error.

D.  

SDN devices communicate with each other to establish a security policy, and in traditional networking, devices communicate upstream to a central location to establish a security policy.

Discussion 0
Questions 51

Refer to the exhibit. Which tasks must be performed on the Download File tab to install new software using TCP port 22?)

Options:

A.  

Set the File Type to Code, set the Transfer Mode to SFTP, and specify the IP address of the WLC.

B.  

Set the File Type to Configuration, set the Transfer Mode to FTP, and specify the IP address of the file server.

C.  

Set the File Type to Code, set the Transfer Mode to SFTP, and specify the IP address of the file server.

D.  

Set the File Type to Configuration, set the Transfer Mode to SFTP, and specify the IP address of the WLC.

Discussion 0
Questions 52

Drag and drop the characteristic from the left onto the cable type on the right.

Options:

Discussion 0
Questions 53

Drag and drop the IPv6 address from the left onto the type on the right.

Options:

Discussion 0
Questions 54

Which two principles must be considered when using per-hop behavior in QoS? (Choose two.)

Options:

A.  

Policing is not supported on subinterfaces.

B.  

Shaping and rate limiting have the same effect.

C.  

Shaping drops excessive traffic without adding traffic delay.

D.  

Shaping levels out traffic bursts by delaying excess traffic.

E.  

Policing is performed in the inbound and outbound directions.

Discussion 0
Questions 55

Refer to the exhibit. An LACP EtherChannel between two directly connected switches is in the configuration process.

Which command must be configured on switch SW2’s Gi0/1-2 interfaces to establish the channel to SW1?

Options:

A.  

channel-group 1 mode desirable

B.  

channel-group 1 mode on

C.  

channel-group 1 mode auto

D.  

channel-group 1 mode active

Discussion 0
Questions 56

Connectivity between four routers has been established. IP connectivity must be configured in the order presented to complete the implementation. No dynamic routing protocols are included.

1. Configure static routing using host routes to establish connectivity from router R3 to the router R1 Loopback address using the source IP of 209.165.200.230.

2. Configure an IPv4 default route on router R2 destined for router R4.

3. Configure an IPv6 default router on router R2 destined for router R4.

Options:

Discussion 0
Questions 57

Refer to the exhibit.

Which configuration is needed to configure a WLAN with WPA2 only and with a password that is 63 characters long?

Options:

A.  

Disable WPA Policy and WPA Encryption and then enable PSK using ASCII.

B.  

Enable PSK and FT PSK and then disable WPA Policy.

C.  

Disable WPA Encryption and then enable FT PSK.

D.  

Enable PSK using Hex format and then disable WPA Policy.

Discussion 0
Questions 58

Drag and drop the IPv6 address type characteristics from the left to the right.

Options:

Discussion 0
Questions 59

What are two characteristics of a public cloud Implementation? (Choose two.)

Options:

A.  

It is owned and maintained by one party, but it is shared among multiple organizations.

B.  

It enables an organization to fully customize how It deploys network resources.

C.  

It provides services that are accessed over the Internet.

D.  

It Is a data center on the public Internet that maintains cloud services for only one company.

E.  

It supports network resources from a centralized third-party provider and privately-owned virtual resources

Discussion 0
Questions 60

All physical cabling between the two switches is installed. Configure the network connectivity between the switches using the designated VLANs and interfaces.

1. Configure VLAN 100 named Compute and VLAN 200 named Telephony where required for each task.

2. Configure Ethernet0/1 on SW2 to use the existing VLAN named Available.

3. Configure the connection between the switches using access ports.

4. Configure Ethernet0/1 on SW1 using data and voice VLANs.

5. Configure Ethemet0/1 on SW2 so that the Cisco proprietary neighbor discovery protocol is turned off for the designated interface only.

Options:

Discussion 0
Questions 61

What is the difference between the TCP and UDP protocols?

Options:

A.  

TCP ensures ordered, reliable data delivery, and UDP offers low latency and high throughput.

B.  

TCP is used for transmitting data over the internet, and UDP is used for transmitting data over a local network.

C.  

TCP manages multicast and broadcast data transfers, and UDP only handles unicast communications.

D.  

TCP is used to ensure data integrity in a file transfer, and UDP is used to broadcast a message to multiple recipients.

Discussion 0
Questions 62

Which two tasks must be performed to configure NTP to a trusted server in client mode on a single network device? (Choose two)

Options:

A.  

Enable NTP authentication.

B.  

Verify the time zone.

C.  

Disable NTP broadcasts

D.  

Specify the IP address of the NTP server

E.  

Set the NTP server private key

Discussion 0
Questions 63

How does a network administrator securely manage an AP in lightweight mode?

Options:

A.  

using the CLI via an out-of-band connection

B.  

using the WLC GUI via HTTPS

C.  

using the AP GUI via an in-band SSH connection

D.  

using the CLI via a virtual interface with SSH

Discussion 0
Questions 64

An engineer must update the configuration on two PCs in two different subnets to communicate locally with each other. One PC is configured with IP address 192.168.25.128/25 and the other with 192.168.25.100/25. Which network mask must the engineer configure on both PCs to enable the communication?

Options:

A.  

255.255.255.224

B.  

255.255.255.248

C.  

255.255.255.0

D.  

255.255.255.252

Discussion 0
Questions 65

Refer to Exhibit.

Which configuration must be applied to the router that configures PAT to translate all addresses in VLAN 200 while allowing devices on VLAN 100 to use their own IP addresses?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 66

While examining excessive traffic on the network, it is noted that all incoming packets on an interface appear to be allowed even though an IPv4 ACL is applied to the interface.

Which two misconfigurations cause this behavior? (Choose two)

Options:

A.  

The packets fail to match any permit statement

B.  

A matching permit statement is too high in the access test

C.  

A matching permit statement is too broadly defined

D.  

The ACL is empty

E.  

A matching deny statement is too high in the access list

Discussion 0
Questions 67

Which function is performed by DHCP snooping?

Options:

A.  

propagates VLAN information between switches

B.  

listens to multicast traffic for packet forwarding

C.  

provides DDoS mitigation

D.  

rate-limits certain traffic

Discussion 0
Questions 68

Refer to the exhibit.

Shortly after SiteA was connected to SiteB over a new single-mode fiber path users at SiteA report intermittent connectivity issues with applications hosted at SiteB What is the cause of the intermittent connectivity issue?

Options:

A.  

Interface errors are incrementing

B.  

An incorrect SFP media type was used at SiteA

C.  

High usage is causing high latency

D.  

The sites were connected with the wrong cable type

Discussion 0
Questions 69

Which interface is used to send traffic to the destination network?

10.90.207.87/26 [110/1912] via F0/7

10.90.207.87/26 [110/28968] via F0/6

10.90.207.87/26 [120/14] via F0/4

10.90.207.87/26 [120/11] via F0/5

Options:

A.  

F0/7

B.  

F0/5

C.  

F0/4

D.  

F0/6

Discussion 0
Questions 70

How does automation affect network management processes?

Options:

A.  

It interoperates with ISE to define and manage patch and update schedules.

B.  

It performs configuration updates based on user profiles.

C.  

It improves the efficiency of system lifecycle management.

D.  

It provides a reactive support model.

Discussion 0
Questions 71

Refer to the exhibit. A secondary route is required on router R1 to pass traffic to the LAN network on R2 if the primary link fails. Which command must be entered to configure the router?

Options:

A.  

ip route 10.0.2.0 255.255.255.240 10.0.0.7 92

B.  

ip route 10.0.2.0 255.255.255.248 10.0.0.6 91

C.  

ip route 10.0.2.0 256.255.255.240 10.0.0.6 91

D.  

ip route 10.0.2.0 255.255.255.248 null0 93

Discussion 0
Questions 72

Refer to the exhibit.

Users will be using a preconfigured secret key and SSID and must have a secured key hashing algorithm configured. The AAA server must not be used for the user authentication method. Which action completes the task?

Options:

A.  

Enable AutoConfig iPSK.

B.  

SetCCMP128(AES).

C.  

Configure PSK Format HEX with key string.

D.  

Configure PSK-SHA2.

Discussion 0
Questions 73

Which technology allows multiple operating systems lo run a single physical server?

Options:

A.  

cloud computing

B.  

virtualization

C.  

application hosting

D.  

containers

Discussion 0
Questions 74

How is Al used to identify issues within network traffic?

Options:

A.  

II exclusively predicts device malfunctions.

B.  

It enhances data packet delivery speeds.

C.  

It simplifies traffic route mapping.

D.  

It analyzes patterns for anomaly detection.

Discussion 0
Questions 75

What is represented by the word "switch" within this JSON schema?

Options:

A.  

array

B.  

value

C.  

key

D.  

object

Discussion 0
Questions 76

What is the maximum length of characters used in an SSID?

Options:

A.  

16

B.  

32

C.  

48

D.  

64

Discussion 0
Questions 77

What are two differences between optical-fiber cabling and copper cabling? (Choose two)

Options:

A.  

Light is transmitted through the core of the fiber

B.  

A BNC connector is used for fiber connections

C.  

The glass core component is encased in a cladding

D.  

Fiber connects to physical interfaces using Rj-45 connections

E.  

The data can pass through the cladding

Discussion 0
Questions 78

Which unified access point mode continues to serve wireless clients after losing connectivity to the Cisco Wireless LAN Controller?

Options:

A.  

sniffer

B.  

mesh

C.  

flexconnect

D.  

local

Discussion 0
Questions 79

What are two benefits of network automation? (Choose two)

Options:

A.  

reduced operational costs

B.  

reduced hardware footprint

C.  

faster changes with more reliable results

D.  

fewer network failures

E.  

increased network security

Discussion 0
Questions 80

Which set of action satisfy the requirement for multifactor authentication?

Options:

A.  

The user swipes a key fob, then clicks through an email link

B.  

The user enters a user name and password, and then clicks a notification in an authentication app on a mobile device

C.  

The user enters a PIN into an RSA token, and then enters the displayed RSA key on a login screen

D.  

The user enters a user name and password and then re-enters the credentials on a second screen

Discussion 0
Questions 81

Refer to the exhibit. During initial configuration testing, the Windows workstation PC1 cannot connect with the 172.16.2.0/24 network.

Which set of actions corrects the configuration?

Options:

A.  

Change the IP address to 172.16.1.6 and change the subnet mask to 255.255.255.248.

B.  

Change the IP address to 172.16.1.6 and change the DNS servers to 172.16.1.12 and 172.16.1.13.

C.  

Change the IP address to 172.16.1.9 and change the default gateway to 172.16.1.7.

D.  

Change the IP address to 172.16.1.9 and change the DNS server to 172.16.1.12 only.

Discussion 0
Questions 82

A network administrator enabled port security on a switch interface connected to a printer. What is the next configuration action in order to allow the port to learn the MAC address of the printer and insert it into the table automatically?

Options:

A.  

enable dynamic MAC address learning

B.  

implement static MAC addressing.

C.  

enable sticky MAC addressing

D.  

implement auto MAC address learning

Discussion 0
Questions 83

How does the dynamically-learned MAC address feature function?

Options:

A.  

The CAM table is empty until ingress traffic arrives at each port

B.  

Switches dynamically learn MAC addresses of each connecting CAM table.

C.  

The ports are restricted and learn up to a maximum of 10 dynamically-learned addresses

D.  

It requires a minimum number of secure MAC addresses to be filled dynamically

Discussion 0
Questions 84

What is the benefit of configuring PortFast on an interface?

Options:

A.  

After the cable is connected, the interface uses the fastest speed setting available for that cable type

B.  

After the cable is connected, the interface is available faster to send and receive user data

C.  

The frames entering the interface are marked with higher priority and then processed faster by a switch.

D.  

Real-time voice and video frames entering the interface are processed faster

Discussion 0
Questions 85

Refer to the exhibit.

Which change to the configuration on Switch?

allows the two switches to establish an GtherChannel?

Options:

A.  

Change the protocol to EtherChannel mode on.

B.  

Change the LACP mode to active

C.  

Change the LACP mode to desirable

D.  

Change the protocol to PAqP and use auto mode

Discussion 0
Questions 86

Refer to the exhibit.

A network engineer is in the process of establishing IP connectivity between two sites. Routers R1 and R2 are partially configured with IP addressing. Both routers have the ability to access devices on their respective LANs. Which command set configures the IP connectivity between devices located on both LANs in each site?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 87

A Cisco IP phone receive untagged data traffic from an attached PC. Which action is taken by the phone?

Options:

A.  

It allows the traffic to pass through unchanged

B.  

It drops the traffic

C.  

It tags the traffic with the default VLAN

D.  

It tags the traffic with the native VLAN

Discussion 0
Questions 88

Which action is taken by a switch port enabled for PoE power classification override?

Options:

A.  

When a powered device begins drawing power from a PoE switch port a syslog message is generated

B.  

As power usage on a PoE switch port is checked data flow to the connected device is temporarily paused

C.  

If a switch determines that a device is using less than the minimum configured power it assumes the device has failed and disconnects

D.  

Should a monitored port exceeds the maximum administrative value for power, the port is shutdown and err-disabled

Discussion 0
Questions 89

Refer to the exhibit.

An engineer is required to verify that the network parameters are valid for the users wireless LAN connectivity on a /24 subnet. Drag and drop the values from the left onto the network parameters on the right. Not all values are used.

Options:

Discussion 0
Questions 90

How do traditional campus device management and Cisco DNA Center device management differ in regards to deployment?

Options:

A.  

Cisco DNA Center device management can deploy a network more quickly than traditional campus device management

B.  

Traditional campus device management allows a network to scale more quickly than with Cisco DNA Center device management

C.  

Cisco DNA Center device management can be implemented at a lower cost than most traditional campus device management options

D.  

Traditional campus device management schemes can typically deploy patches and updates more quickly than Cisco DNA Center device management

Discussion 0
Questions 91

Which protocol prompts the Wireless LAN Controller to generate its own local web administration SSL certificate for GUI access?

Options:

A.  

HTTPS

B.  

RADIUS

C.  

TACACS+

D.  

HTTP

Discussion 0
Questions 92

An engineer is configuring NAT to translate the source subnet of 10.10.0.0/24 to any of three addresses 192.168.30.1, 192.168.3.2, 192.168.3.3 Which configuration should be used?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 93

What is a difference between RADIUS and TACACS+?

Options:

A.  

RADIUS is most appropriate for dial authentication, but TACACS+ can be used for multiple types of authentication

B.  

TACACS+ encrypts only password information and RADIUS encrypts the entire payload

C.  

TACACS+ separates authentication and authorization, and RADIUS merges them

D.  

RADIUS logs all commands that are entered by the administrator, but TACACS+ logs only start, stop, and interim commands

Discussion 0
Questions 94

Refer to the exhibit.

Router R1 is running three different routing protocols. Which route characteristic is used by the router to forward the packet that it receives for destination IP 172.16.32.1?

Options:

A.  

longest prefix

B.  

metric

C.  

cost

D.  

administrative distance

Discussion 0
Questions 95

Refer to the exhibit.

What action establishes the OSPF neighbor relationship without forming an adjacency?

Options:

A.  

modify hello interval

B.  

modify process ID

C.  

modify priority

D.  

modify network type

Discussion 0
Questions 96

Which protocol requires authentication to transfer a backup configuration file from a router to a remote server?

Options:

A.  

DTP

B.  

FTP

C.  

SMTP

D.  

TFTP

Discussion 0
Questions 97

Refer to the exhibit.

An administrator configures four switches for local authentication using passwords that are stored in a cryptographic hash. The four switches must also support SSH access for administrators to manage the network infrastructure. Which switch is configured correctly to meet these requirements?

Options:

A.  

SW1

B.  

SW2

C.  

SW3

D.  

SW4

Discussion 0
Questions 98

A network administrator must to configure SSH for remote access to router R1 The requirement is to use a public and private key pair to encrypt management traffic to and from the connecting client.

Which configuration, when applied, meets the requirements?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 99

Refer to the exhibit.

A network administrator assumes a task to complete the connectivity between PC A and the File Server. Switch A and Switch B have been partially configured with VLAN 10, 11, 12, and 13. What is the next step in the configuration?

Options:

A.  

Add PC A to VLAN 10 and the File Server to VLAN 11 fa VLAN segmentation

B.  

Add VLAN 13 to the trunk links on Switch A and Switch B for VLAN propagation

C.  

Add a router on a stick between Switch A and Switch B allowing for Inter-VLAN routing.

D.  

Add PC A to the same subnet as the Fie Server allowing for intra-VLAN communication.

Discussion 0
Questions 100

What role does a hypervisor provide for each virtual machine in server virtualization?

Options:

A.  

infrastructure-as-a-service.

B.  

Software-as-a-service

C.  

control and distribution of physical resources

D.  

services as a hardware controller.

Discussion 0
Questions 101

The service password-encryption command is entered on a router. What is the effect of this configuration?

Options:

A.  

restricts unauthorized users from viewing clear-text passwords in the running configuration

B.  

encrypts the password exchange when a VPN tunnel is established

C.  

prevents network administrators from configuring clear-text passwords

D.  

protects the VLAN database from unauthorized PC connections on the switch

Discussion 0
Questions 102

Refer to me exhibit.

Which action is taken by the router when a packet is sourced from 10.10.10.2 and destined for 10.10.10.16?

Options:

A.  

It uses a route that is similar to the destination address

B.  

It discards the packets.

C.  

It floods packets to all learned next hops.

D.  

It Queues the packets waiting for the route to be learned.

Discussion 0
Questions 103

How do AAA operations compare regarding user identification, user services and access control?

Options:

A.  

Authorization provides access control and authentication tracks user services

B.  

Authentication identifies users and accounting tracks user services

C.  

Accounting tracks user services, and authentication provides access control

D.  

Authorization identifies users and authentication provides access control

Discussion 0
Questions 104

With REST API, which standard HTTP header tells a server which media type is expected by the client?

Options:

A.  

Accept-Encoding: gzip. deflate

B.  

Accept-Patch: text/example; charset=utf-8

C.  

Content-Type: application/json; charset=utf-8

D.  

Accept: application/json

Discussion 0
Questions 105

Which networking function occurs on the data plane?

Options:

A.  

forwarding remote client/server traffic

B.  

facilitates spanning-tree elections

C.  

processing inbound SSH management traffic

D.  

sending and receiving OSPF Hello packets

Discussion 0
Questions 106

What is a function of a Layer 3 switch?

Options:

A.  

move frames between endpoints limited to IP addresses

B.  

transmit broadcast traffic when operating in Layer 3 mode exclusively

C.  

forward Ethernet frames between VLANs using only MAC addresses

D.  

flood broadcast traffic within a VLAN

Discussion 0
Questions 107

R1 has learned route 10.10.10.0/24 via numerous routing protocols. Which route is installed?

Options:

A.  

route with the lowest cost

B.  

route with the next hop that has the highest IP

C.  

route with the shortest prefix length

D.  

route with the lowest administrative distance

Discussion 0
Questions 108

which IPv6 address block forwards packets to a multicast address rather than a unicast address?

Options:

A.  

2000::/3

B.  

FC00::/7

C.  

FE80::/10

D.  

FF00::/12

Discussion 0
Questions 109

An administrator must secure the WLC from receiving spoofed association requests. Which steps must be taken to configure the WLC to restrict the requests and force the user to wait 10 ms to retry an association request?

Options:

A.  

Enable Security Association Teardown Protection and set the SA Query timeout to 10

B.  

Enable MAC filtering and set the SA Query timeout to 10

C.  

Enable 802.1x Layer 2 security and set me Comeback timer to 10

D.  

Enable the Protected Management Frame service and set the Comeback timer to 10

Discussion 0
Questions 110

Refer to the exhibit.

To which device does Router1 send packets that are destined to host 10.10.13.165?

Options:

A.  

Router2

B.  

Router3

C.  

Router4

D.  

Router5

Discussion 0
Questions 111

Which protocol does an access point use to draw power from a connected switch?

Options:

A.  

Internet Group Management Protocol

B.  

Adaptive Wireless Path Protocol

C.  

Cisco Discovery Protocol

D.  

Neighbor Discovery Protocol

Discussion 0
Questions 112

What Is the path for traffic sent from one user workstation to another workstation on a separate switch In a Ihree-lter architecture model?

Options:

A.  

access - core - distribution - access

B.  

access - distribution - distribution - access

C.  

access - core - access

D.  

access -distribution - core - distribution - access

Discussion 0
Questions 113

What are two benefits of FHRPs? (Choose two.)

Options:

A.  

They prevent (oops in the Layer 2 network.

B.  

They allow encrypted traffic.

C.  

They are able to bundle muftlple ports to increase bandwidth

D.  

They enable automatic failover of the default gateway.

E.  

They allow multiple devices lo serve as a single virtual gateway for clients in the network

Discussion 0
Questions 114

Refer to the exhibit.

The entire contents of the MAC address table are shown. Sales-4 sends a data frame to Sales-1.

What does the switch do as it receives the frame from Sales-4?

Options:

A.  

Perform a lookup in the MAC address table and discard the frame due to a missing entry.

B.  

Insert the source MAC address and port into the forwarding table and forward the frame to Sales-1.

C.  

Map the Layer 2 MAC address to the Layer 3 IP address and forward the frame.

D.  

Flood the frame out of all ports except on the port where Sales-1 is connected.

Discussion 0
Questions 115

Refer to the exhibit.

The nip server 192.168.0.3 command has been configured on router 1 to make it an NTP client of router 2. Which command must be configured on router 2 so that it operates in server-only mode and relies only on its internal clock?

Options:

A.  

Router2(config)#ntp passive

B.  

Router2(config)#ntp server 172.17.0.1

C.  

Router2(config)#ntp master 4

D.  

Router2(config)#ntp server 192.168.0.2

Discussion 0
Questions 116

Which action does the router take as rt forwards a packet through the network?

Options:

A.  

The router replaces the source and desinaoon labels wth the sending router uterface label as a source and the next hop router label as a desbnabon

B.  

The router encapsulates the source and destination IP addresses with the sending router P address as the source and the neighbor IP address as the destination

C.  

The router replaces the original source and destination MAC addresses with the sending router MAC address as the source and neighbor MAC address as the destination

D.  

The router encapsulates the original packet and then includes a tag that identifies the source router MAC address and transmit transparently to the destination

Discussion 0
Questions 117

What is the purpose of an SSID?

Options:

A.  

It provides network security

B.  

It differentiates traffic entering access posits

C.  

It identities an individual access point on a WLAN

D.  

It identifies a WLAN

Discussion 0
Questions 118

Refer to the exhibit.

Which prefix does Router 1 use for traffic to Host A?

Options:

A.  

10.10.10.0/28

B.  

10.10.13.0/25

C.  

10.10.13.144/28

D.  

10.10.13.208/29

Discussion 0
Questions 119

Refer to the exhibit.

Which command must be executed for Gi1.1 on SW1 to become a trunk port if Gi1/1 on SW2 is configured in desirable or trunk mode?

Options:

A.  

switchport mode trunk

B.  

switchport mode dot1-tunnel

C.  

switchport mode dynamic auto

D.  

switchport mode dynamic desirable

Discussion 0
Questions 120

Which two actions influence the EIGRP route selection process? (Choose two)

Options:

A.  

The router calculates the reported distance by multiplying the delay on the exiting Interface by 256.

B.  

The router calculates the best backup path to the destination route and assigns it as the feasible successor.

C.  

The router calculates the feasible distance of all paths to the destination route

D.  

The advertised distance is calculated by a downstream neighbor to inform the local router of the bandwidth on the link

E.  

The router must use the advertised distance as the metric for any given route

Discussion 0
Questions 121

What are two descriptions of three-tier network topologies? (Choose two)

Options:

A.  

The core and distribution layers perform the same functions

B.  

The access layer manages routing between devices in different domains

C.  

The network core is designed to maintain continuous connectivity when devices fail.

D.  

The core layer maintains wired connections for each host

E.  

The distribution layer runs Layer 2 and Layer 3 technologies

Discussion 0
Questions 122

How does CAPWAP communicate between an access point in local mode and a WLC?

Options:

A.  

The access point must directly connect to the WLC using a copper cable

B.  

The access point must not be connected to the wired network, as it would create a loop

C.  

The access point must be connected to the same switch as the WLC

D.  

The access point has the ability to link to any switch in the network, assuming connectivity to the WLC

Discussion 0
Questions 123

What benefit does controller-based networking provide versus traditional networking?

Options:

A.  

moves from a two-tier to a three-tier network architecture to provide maximum redundancy

B.  

provides an added layer of security to protect from DDoS attacks

C.  

allows configuration and monitoring of the network from one centralized port

D.  

combines control and data plane functionality on a single device to minimize latency

Discussion 0
Questions 124

Which two values or settings must be entered when configuring a new WLAN in the Cisco Wireless LAN Controller GUI? (Choose two)

Options:

A.  

management interface settings

B.  

QoS settings

C.  

Ip address of one or more access points

D.  

SSID

E.  

Profile name

Discussion 0
Questions 125

What are two recommendations for protecting network ports from being exploited when located in an office space outside of an IT closer? (Choose two.)

Options:

A.  

enable the PortFast feature on ports

B.  

implement port-based authentication

C.  

configure static ARP entries

D.  

configure ports to a fixed speed

E.  

shut down unused ports

Discussion 0
Questions 126

An engineer observes high usage on the 2.4GHz channels and lower usage on the 5GHz channels. What must be configured to allow clients to preferentially use 5GH2 access points?

Options:

A.  

Re- Anchor Roamed Clients

B.  

11ac MU-MIMO

C.  

OEAP Split Tunnel

D.  

Client Band Select

Discussion 0
Questions 127

Drag the descriptions of IP protocol transmissions from the left onto the IP traffic types on the right.

Options:

Discussion 0
Questions 128

Which WPA3 enhancement protects against hackers viewing traffic on the Wi-Fi network?

Options:

A.  

TKiP encryption

B.  

AES encryption

C.  

scrambled encryption key

D.  

SAE encryption

Discussion 0
Questions 129

What is a similarly between 1000BASE-LX and 1000BASE-T standards?

Options:

A.  

Both use the same data-link header and trailer formats

B.  

Both cable types support LP connectors

C.  

Both cable types support Rj-45 connectors

D.  

Both support up to 550 meters between nodes

Discussion 0
Questions 130

A user configured OSPF in a single area between two routers A serial interface connecting R1 and R2 is running encapsulation PPP By default which OSPF network type is seen on this interface when the user types show ip ospf interface on R1 or R2?

Options:

A.  

port-to-multipoint

B.  

broadcast

C.  

point-to-point

D.  

nonbroadcast

Discussion 0
Questions 131

What does an SDN controller use as a communication protocol to relay forwarding changes to a southbound API?

Options:

A.  

OpenFlow

B.  

Java

C.  

REST

D.  

XML

Discussion 0
Questions 132

Refer to Exhibit.

How does SW2 interact with other switches in this VTP domain?

Options:

A.  

It processes VTP updates from any VTP clients on the network on its access ports.

B.  

It receives updates from all VTP servers and forwards all locally configured VLANs out all trunk ports

C.  

It forwards only the VTP advertisements that it receives on its trunk ports.

D.  

It transmits and processes VTP updates from any VTP Clients on the network on its trunk ports

Discussion 0
Questions 133

What is a characteristic of spine-and-leaf architecture?

Options:

A.  

Each device is separated by the same number of hops

B.  

It provides variable latency

C.  

It provides greater predictability on STP blocked ports.

D.  

Each link between leaf switches allows for higher bandwidth.

Discussion 0
Questions 134

Which plane is centralized by an SDN controller?

Options:

A.  

management-plane

B.  

control-plane

C.  

data-plane

D.  

services-plane

Discussion 0
Questions 135

Which command must be entered to configure a DHCP relay?

Options:

A.  

ip helper-address

B.  

ip address dhcp

C.  

ip dhcp pool

D.  

ip dhcp relay

Discussion 0
Questions 136

If a switch port receives a new frame while it is actively transmitting a previous frame, how does it process the frames?

Options:

A.  

The new frame is delivered first, the previous frame is dropped, and a retransmission request is sent.

B.  

The previous frame is delivered, the new frame is dropped, and a retransmission request is sent.

C.  

The new frame is placed in a queue for transmission after the previous frame.

D.  

The two frames are processed and delivered at the same time.

Discussion 0
Questions 137

What prevents a workstation from receiving a DHCP address?

Options:

A.  

DTP

B.  

STP

C.  

VTP

D.  

802.10

Discussion 0
Questions 138

What is the primary function of a Layer 3 device?

Options:

A.  

to analyze traffic and drop unauthorized traffic from the Internet

B.  

to transmit wireless traffic between hosts

C.  

to pass traffic between different networks

D.  

forward traffic within the same broadcast domain

Discussion 0
Questions 139

Drag and drop the SNMP components from the left onto the description on the right.

Options:

Discussion 0
Questions 140

An engineer is configuring a switch port that is connected to a VoIP handset. Which command must the engineer configure to enable port security with a manually assigned MAC address of abod-bod on voice VLAN 4?

Options:

A.  

switchport port-security mac-address abcd.abcd.abcd

B.  

switchport port-security mac-address abed.abed.abed vlan 4

C.  

switchport port-security mac-address sticky abcd.abcd.abcd vlan 4

D.  

switchport port-security mac-address abcd.abcd.abcd vlan voice

Discussion 0
Questions 141

Which set of actions satisfies the requirement for multifactor authentication?

Options:

A.  

The user enters a user name and password, and then clicks a notification in an authentication app on a mobile device.

B.  

The user swipes a key fob, then clicks through an email link.

C.  

The user enters a PIN into an RSA token, and then enters the displayed RSA key on a login screen.

D.  

The user enters a user name and password, and then re-enters the credentials on a second screen.

Discussion 0
Questions 142

To improve corporate security, an organization is planning to implement badge authentication to limit access to the data center. Which element of a security program is being deployed?

Options:

A.  

user training

B.  

user awareness

C.  

vulnerability verification

D.  

physical access control

Discussion 0
Questions 143

How does MAC learning function on a switch?

Options:

A.  

broadcasts frames to all ports without queueing

B.  

adds unknown source MAC addresses to the address table

C.  

sends a retransmission request when a new frame is received

D.  

sends frames with unknown destinations to a multicast group

Discussion 0
Questions 144

What are two facts that differentiate optical fiber cabling from copper cabling? (Choose two.)

Options:

A.  

It has a greater sensitivity to changes in temperature and moisture.

B.  

It carries signals for longer distances.

C.  

It carries electrical current further distances for PoE devices.

D.  

It is less expensive when purchasing patch cables.

E.  

It provides greater throughput options.

Discussion 0
Questions 145

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 146

What is the difference between 1000BASE-LX/LH and 1000BASE-ZX interfaces?

Options:

A.  

1000BASE-ZX is supported on links up to 1000km, and 1000BASE-LX/LH operates over links up to 70 km.

B.  

1000BASE-LX/LH interoperates with multimode and single-mode fiber, and 10008ASE-ZX needs a conditioning patch cable with a multimode.

C.  

1000BASE-LX/LH is supported on links up to 10km, and 1000BASE-ZX operates over links up to 70 km

D.  

1000BASE-ZX interoperates with dual-rate 100M/1G 10Km SFP over multimode fiber, and 1000BASE-LX/LH supports only single-rate.

Discussion 0
Questions 147

Refer to the exhibit.

Which interface is chosen to forward traffic to the host at 192.168.0.55?

Options:

A.  

GigabitEthernet0

B.  

GigabitEthernet0/1

C.  

Null0

D.  

GigabitEthernet0/3

Discussion 0
Questions 148

Refer to the exhibit. A multivendor network exists and the company is implementing VoIP over the network for the first time.

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 149

Refer to the exhibit.

What is represented beginning with line 1 and ending with line 5?

Options:

A.  

value

B.  

object

C.  

key

D.  

array

Discussion 0
Questions 150

Refer to the exhibit. Each router must be configured with the last usable IP address in the subnet. Which configuration fulfills this requirement?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 151

Which advantage does machine learning offer for network security?

Options:

A.  

It improves real-time threat detection.

B.  

It manages firewall rule sets.

C.  

It enforces password complexity requirements.

D.  

It controls VPN access permissions.

Discussion 0
Questions 152

A router received three destination prefixes:10.0.0/18, and 10.0.0/24. When the show ip route command is executed, which output does it return?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 153

Refer to the exhibit.

Drag and drop the destination IPs from the left onto the paths to reach those destinations on the right.

Options:

Discussion 0
Questions 154

Which WAN topology has the highest degree of reliability?

Options:

A.  

full mesh

B.  

Point-to-point

C.  

hub-and-spoke

D.  

router-on-a-stick

Discussion 0
Questions 155

Refer to the exhibit.

How many JSON objects are represented?

Options:

A.  

1

B.  

2

C.  

3

D.  

4

Discussion 0
Questions 156

Which Rapid PVST+ feature should be configured on a switch port to immediately send traffic to a connected server as soon as it is active?

Options:

A.  

BPDU guard

B.  

loop guard

C.  

portfast

D.  

uplinkfast

Discussion 0
Questions 157

Refer to the exhibit. A network engineer is configuring a WLAN to use a WPA2 PSK and allow only specific clients to join. Which two actions must be taken to complete the process? (Choose two.)

Options:

A.  

Enable the 802.1X option for Authentication Key Management

B.  

Enable the WPA2 Policy option

C.  

Enable the CCKM option for Authentication Key Management

D.  

Enable the MAC Filtering option

E.  

Enable the OSEN Policy option

Discussion 0
Questions 158

Which action must be taken when password protection is Implemented?

Options:

A.  

Use less than eight characters in length when passwords are complex.

B.  

Store passwords as contacts on a mobile device with single-factor authentication.

C.  

Include special characters and make passwords as long as allowed.

D.  

Share passwords with senior IT management to ensure proper oversight.

Discussion 0
Questions 159

What is the primary purpose of private address space?

Options:

A.  

conserve globally unique address space

B.  

simplify the addressing in the network

C.  

limit the number of nodes reachable via the Internet

D.  

reduce network complexity

Discussion 0
Questions 160

Which advantage does the network assurance capability of Cisco DNA Center provide over traditional campus management?

Options:

A.  

Cisco DNA Center correlates information from different management protocols to obtain insights, and traditional campus management requires manual analysis.

B.  

Cisco DNA Center handles management tasks at the controller to reduce the load on infrastructure devices, and traditional campus management uses the data backbone.

C.  

Cisco DNA Center leverages YANG and NETCONF to assess the status of fabric and nonfabric devices, and traditional campus management uses CLI exclusively.

D.  

Cisco DNA Center automatically compares security postures among network devices, and traditional campus management needs manual comparisons.

Discussion 0
Questions 161

A network engineer is implementing a corporate SSID for WPA3-Personal security with a PSK. Which encryption cipher must be configured?

Options:

A.  

GCMP2S6

B.  

GCMP128

C.  

CCMP256

D.  

CCMP128

Discussion 0
Questions 162

Drag and drop the REST API call method for HTTP from the left onto the action they perform on the right.

Options:

Discussion 0
Questions 163

Drag and drop the TCP or UDP details from the left onto their corresponding protocols on the right.

Options:

Discussion 0
Questions 164

Refer to the exhibit.

Switch AccSw2 has just been added to the network along with PC2. All VLANs have been implemented on AccSw2. How must the ports on AccSw2 be configured to establish Layer 2 connectivity between PC1 and PC2?

Options:

A.  

B.  

B.  

C.  

C.  

D.  

D.  

Discussion 0
Questions 165

Refer to the exhibit.

All routers in the network are configured correctly, and the expected routes are being exchanged among the routeis. Which set or routes are learned from neighbors and Installed on router 2?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 166

Which type of hypervisor operates without an underlying OS to host virtual machines?

Options:

A.  

Type 1

B.  

Type 2

C.  

Type 3

D.  

Type 12

Discussion 0
Questions 167

Which protocol is used in Software Defined Access (SDA) to provide a tunnel between two edge nodes in different fabrics?

Options:

A.  

Generic Router Encapsulation (GRE)

B.  

Virtual Local Area Network (VLAN)

C.  

Virtual Extensible LAN (VXLAN)

D.  

Point-to-Point Protocol

Discussion 0
Questions 168

Which cable type must be used when connecting a router and switch together using these criteria?

• Pins 1 and 2 are receivers and pins 3 and 6 are transmitters

• Auto detection MDi-X is unavailable

Options:

A.  

straight-through

B.  

rollover

C.  

crossover

D.  

console

Discussion 0
Questions 169

What is the benefit of using FHRP (First Hop Redundancy Protocol)?

Options:

A.  

Reduced ARP traffic on the network

B.  

Balancing traffic across multiple gateways in proportion to their loads

C.  

Reduced management overhead on network routers

D.  

Higher degree of availability

Discussion 0
Questions 170

What are two reasons lo configure PortFast on a switch port attached to an end host? (Choose two.)

Options:

A.  

to enable the number of MAC addresses learned on the port to l

B.  

to protect the operation of the port from topology change processes

C.  

to enable the pod to enter the forwarding state immediately when the host boots up

D.  

to prevent the port from participating in Spanning Tree Protocol operations

E.  

to block another switch or host from communicating through the port

Discussion 0
Questions 171

Drag and drop the management connection types from the left onto the definitions on the right.

Options:

Discussion 0
Questions 172

NO: 346

What must a network administrator consider when deciding whether to configure a new wireless network with APs in autonomous mode or APs running in cloud-based mode?

    Autonomous mode APs are less dependent on an underlay but more complex to maintain than APs in cloud-based mode.

Options:

A.  

Cloud-based mode APs relay on underlays and are more complex to maintain than APs in autonomous mode.

B.  

Cloud-based mode APs are easy to deploy but harder to automate than APs in autonomous mode.

C.  

Autonomous mode APs are easy to deploy and automate than APs in cloud-based mode.

Discussion 0
Questions 173

Which capability does TFTP provide?

Options:

A.  

loads configuration files on systems without data storage devices

B.  

provides authentication for data communications over a private data network

C.  

provides encryption mechanisms for file transfer across a WAN

D.  

provides secure file access within the LAN

Discussion 0
Questions 174

Which command do you enter so that a switch configured with Rapid PVST + listens and learns for a specific time period?

Options:

A.  

switch(config)#spanning-tree vlan 1 max-age 6

B.  

switch(config)#spanning-tree vlan 1 hello-time 10

C.  

switch(config)#spanning-tree vlan 1 priority 4096

D.  

switch(config)#spanning-tree vlan 1 forward-time 20

Discussion 0
Questions 175

When a WPA2-PSK WLAN is configured in the Wireless LAN Controller, what is the minimum number of characters that is required in ASCII format?

Options:

A.  

6

B.  

8

C.  

12

D.  

18

Discussion 0
Questions 176

What is an Ansible inventory?

Options:

A.  

file that defines the target devices upon which commands and tasks are executed

B.  

unit of Python code to be executed within Ansible

C.  

collection of actions to perform on target devices, expressed in YAML format

D.  

device with Ansible installed that manages target devices

Discussion 0
Questions 177

Under which condition is TCP preferred over UDP?

Options:

A.  

UDP is used when low latency is optimal, and TCP is used when latency is tolerable.

B.  

TCP is used when dropped data is more acceptable, and UDP is used when data is accepted out- of-order.

C.  

TCP is used when data reliability is critical, and UDP is used when missing packets are acceptable.

D.  

UDP is used when data is highly interactive, and TCP is used when data is time-sensitive.

Discussion 0
Questions 178

Refer to the exhibit.

A network engineer must provide configured IP addressing details to investigate a firewall rule Issue. Which subnet and mask Identify what is configured on the en0 interface?

Options:

A.  

10.8.0.0/16

B.  

10.8.64.0/18

C.  

10.8.128.0/19

D.  

10.8.138.0/24

Discussion 0
Questions 179

Refer to the exhibit.

A network engineer configures the Cisco WLC to authenticate local wireless clients against a RADIUS server Which task must be performed to complete the process?

Options:

A.  

Change the Server Status to Disabled

B.  

Select Enable next to Management

C.  

Select Enable next to Network User

D.  

Change the Support for CoA to Enabled.

Discussion 0
Questions 180

Refer to the exhibit.

What is the issue with the interface GigabitEthernet0/0/1?

Options:

A.  

Port security

B.  

High throughput

C.  

Cable disconnect

D.  

duplex mismatch

Discussion 0
Questions 181

Which component controls and distributes physical resources for each virtual machine?

Options:

A.  

OS

B.  

hypervisor

C.  

CPU

D.  

physical enclosure

Discussion 0
Questions 182

Drag and drop the statements about access-point modes from the left onto the corresponding modes on the right.

Options:

Discussion 0
Questions 183

Drag and drop the IPv6 address description from the left onto the IPv6 address types on the right. Not all options are used.

Options:

Discussion 0
Questions 184

Refer to the exhibit.

Wireless LAN access must be set up to force all clients from the NA WLAN to authenticate against the local database. The WLAN is configured for local EAP authentication. The time that users access the network must not be limited. Which action completes this configuration?

Options:

A.  

Uncheck the Guest User check box

B.  

Check the Guest User Role check box

C.  

Set the Lifetime (seconds) value to 0

D.  

Clear the Lifetime (seconds) value

Discussion 0
Questions 185

Which command creates a static NAT binding for a PC address of 10.1.1.1 to the public routable address 209.165.200.225 assigned to the PC?

Options:

A.  

R1(config)#ip nat inside source static 10.1.1.1 209.165.200.225

B.  

R1(config)#ip nat inside source static 209.165.200.225 10.1.1.1

C.  

R1(config)#ip nat outside source static 10.1.1.1 209.165.200.225

D.  

R1(config)#ip nat outside source static 209.165.200.225 10.1.1.1

Discussion 0
Questions 186

Which two wireless security stewards use Counter Mode Cipher Block Chaining Message Authentication Code Protocol for encryption and data integrity'? (Choose two.)

Options:

A.  

WPA2

B.  

WPA3

C.  

Wi-Fi 6

D.  

WEP

E.  

WPA

Discussion 0
Questions 187

What are two characteristics of a controller-based network? (Choose two.)

Options:

A.  

It uses Telnet to report system issues

B.  

It uses northbound and southbound APIs to communicate between architectural layers

C.  

It decentralizes the control plane, which allows each device to make its own forwarding decisions

D.  

It moves the control plane to a central point

E.  

The administrator can make configuration updates from the CLI

Discussion 0
Questions 188

What is the main difference between traditional networks and controller-based networking?

Options:

A.  

Controller-based networks increase TCO for the company, and traditional networks require less investment.

B.  

Controller-based networks provide a framework for Innovation, and traditional networks create efficiency.

C.  

Controller-based networks are open for application requests, and traditional networks operate manually.

D.  

Controller-based networks are a closed ecosystem, and traditional networks take advantage of programmability.

Discussion 0
Questions 189

What is the default port-security behavior on a trunk link?

Options:

A.  

It causes a network loop when a violation occurs.

B.  

It disables the native VLAN configuration as soon as port security is enabled.

C.  

It places the port in the err-disabled state if it learns more than one MAC address.

D.  

It places the port in the err-disabled slate after 10 MAC addresses are statically configured.

Discussion 0
Questions 190

When an access point is seeking to join wireless LAN controller, which message is sent to the AP- Manager interface?

Options:

A.  

Discovery response

B.  

DHCP request

C.  

DHCP discover

D.  

Discovery request

Discussion 0
Questions 191

What is the difference between an IPv6 link-local address and a unique local address?

Options:

A.  

The scope of an IPv6 link-local address is limited to a loopback address, and an IPv6 unique local address is limited to a directly attached interface.

B.  

The scope of an IPv6 link-local address can be used throughout a company site or network, but an IPv6 unique local address is limited to a loopback address.

C.  

The scope of an IPv6 link-local address is global, but the scope of an IPv6 unique local address is limited to a loopback address.

D.  

The scope of an IPv6 link-local address is limited to a directly attached interface, but an IPv6 unique local address is used throughout a company site or network.

Discussion 0
Questions 192

Drag and drop the descriptions of IP protocol transmissions from the left onto the IP traffic types on the right.

Options:

Discussion 0
Questions 193

What is the role of the root port in a switched network?

Options:

A.  

It replaces the designated port when the designated port fails

B.  

It is the best path to the root from a nonroot switch.

C.  

It replaces the designated port when the root port fails.

D.  

It is administratively disabled until a failover occurs.

Discussion 0
Questions 194

Refer to the exhibit. Drag and drop the learned prefixes from the left onto the preferred route methods from which they were learned on the right.

Options:

Discussion 0
Questions 195

Drag and drop the characteristic from the left onto the IPv6 address type on the right.

Options:

Discussion 0
Questions 196

Refer to the exhibit.

Refer to the exhibit. The IPv6 address for the LAN segment on router R1 must be configured using the EUI-64 format. When configured which ipv6 address is produced by the router?

Options:

A.  

2001:db8:1a44:41a4:C801:BEFF:FE4A:1

B.  

2001:db8:1a44:41a4:C081:BFFF:FE4A:1

C.  

2001:db8:1a44:41a4:4562:098F:FE36:1

D.  

2001:db8:1a44:41a4:C800:BAFE:FF00:1

Discussion 0
Questions 197

What does WPA3 provide in wireless networking?

Options:

A.  

safeguards against brute force attacks with SAE

B.  

optional Protected Management Frame negotiation

C.  

backward compatibility with WPAand WPA2

D.  

increased security and requirement of a complex configuration

Discussion 0
Questions 198

Which command enables HTTP access to the Cisco WLC?

Options:

A.  

config network secureweb enable

B.  

config certificate generate web admin

C.  

config network webmode enable

D.  

config network telnet enable

Discussion 0
Questions 199

Which WLC interface provides out-of-band management in the Cisco Unified Wireless Network Architecture?

Options:

A.  

service port

B.  

virtual

C.  

AP-Manager

D.  

dynamic

Discussion 0
Questions 200

Refer to the exhibit. Drag and drop the subnet masks from the left onto the corresponding subnets on the right. Not all subnet masks used.

Options:

Discussion 0
Questions 201

What is the put method within HTTP?

Options:

A.  

It is a read-only operation.

B.  

It is a nonldempotent operation.

C.  

It replaces data at the destination.

D.  

It displays a web site.

Discussion 0
Questions 202

Refer to the exhibit.

A network engineer must update the configuring on switch2 so that it sends LLDP packets.

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 203

Which port type does a lightweight AP use to connect to the wired network when it is configured in local mode?

Options:

A.  

EtherChannel

B.  

LAG

C.  

trunk

D.  

access

Discussion 0
Questions 204

Refer to the exhibit.

A new VLAN and switch are added to the network. A remote engineer configures OldSwitch and must ensure that the configuration meets these requirements:

• accommodates current configured VLANs

• expands the range to include VLAN 20

• allows for IEEE standard support for virtual LANs

Which configuration on the NewSwitch side of the link meets these requirements?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 205

Drag and drop the Ansible features from the left to the right Not all features are used.

Options:

Discussion 0
Questions 206

Refer to the exhibit. IPv6 is being Implemented within the enterprise. The command Ipv6 unlcast-routing is configure. Interlace GlgO/0 on R1 must be configured to provide a dynamic assignment using the assigned IPv6 block Which command accomplishes this task?

Options:

A.  

ipv6 address 2001:DB8:FFFF:FCF3::1/64

B.  

ipv6 address autoconfig 2001:DB8:FFFF:FCF2::/64

C.  

ipv6 address 2001:DB8:FFFF:FCF3::/64 eui-64

D.  

ipv6 address 2001:DB8:FFFF:FCF3::/64 link-local

Discussion 0
Questions 207

How does network automation help reduce network downtime?

Options:

A.  

Changes can be implemented in parallel across multiple devices at once, which increases the speed of the change rate.

B.  

By using automation platforms with intent-based configuration, all changes are checked for possible outages before being implemented.

C.  

Emails can be generated based on when a network admin performs a network change, which increases visibility.

D.  

Configuration templates and testing can be built into implementation, which increases the success rate of a network change.

Discussion 0
Questions 208

Refer to the exhibit.

After the election process what is the root bridge in the HQ LAN?

Options:

A.  

Switch 1

B.  

Switch 2

C.  

Switch 3

D.  

Switch 4

Discussion 0
Questions 209

Which WAN access technology is preferred for a small office / home office architecture?

Options:

A.  

broadband cable access

B.  

frame-relay packet switching

C.  

dedicated point-to-point leased line

D.  

Integrated Services Digital Network switching.

Discussion 0
Questions 210

Which WAN topology provides a combination of simplicity quality, and availability?

Options:

A.  

partial mesh

B.  

full mesh

C.  

point-to-point

D.  

hub-and-spoke

Discussion 0
Questions 211

What is a benefit of using a Cisco Wireless LAN Controller?

Options:

A.  

Central AP management requires more complex configurations

B.  

Unique SSIDs cannot use the same authentication method

C.  

It supports autonomous and lightweight APs

D.  

It eliminates the need to configure each access point individually

Discussion 0
Questions 212

Refer to the exhibit.

What commands are needed to add a subinterface to Ethernet0/0 on R1 to allow for VLAN 20, with IP address 10.20.20.1/24?

Options:

A.  

R1(config)#interface ethernet0/0R1(config)#encapsulation dot1q 20R1(config)#ip address 10.20.20.1 255.255.255.0

B.  

R1(config)#interface ethernet0/0.20R1(config)#encapsulation dot1q 20R1(config)#ip address 10.20.20.1 255.255.255.0

C.  

R1(config)#interface ethernet0/0.20R1(config)#ip address 10.20.20.1 255.255.255.0

D.  

R1(config)#interface ethernet0/0R1(config)#ip address 10.20.20.1 255.255.255.0

Discussion 0
Questions 213

Refer to the exhibit.

What is the metric of the route to the 192.168.10.33/28 subnet?

Options:

A.  

84

B.  

110

C.  

128

D.  

192

E.  

193

Discussion 0
Questions 214

Refer to the exhibit.

When PC-A sends traffic to PC-B, which network component is in charge of receiving the packet from PC-A verifying the IP addresses, and forwarding the packet to PC-B?

Options:

A.  

Layer 2 switch

B.  

Router

C.  

Load balancer

D.  

firewall

Discussion 0
Questions 215

Which level of severity must be set to get informational syslogs?

Options:

A.  

alert

B.  

critical

C.  

notice

D.  

debug

Discussion 0
Questions 216

Which resource is able to be shared among virtual machines deployed on the same physical server?

Options:

A.  

disk

B.  

applications

C.  

VM configuration file

D.  

operating system

Discussion 0
Questions 217

What is a function of a remote access VPN?

Options:

A.  

used cryptographic tunneling to protect the privacy of data for multiple users simultaneously

B.  

used exclusively when a user is connected to a company's internal network

C.  

establishes a secure tunnel between two branch sites

D.  

allows the users to access company internal network resources through a secure tunnel

Discussion 0
Questions 218

Which type of attack can be mitigated by dynamic ARP inspection?

Options:

A.  

worm

B.  

malware

C.  

DDoS

D.  

man-in-the-middle

Discussion 0
Questions 219

in Which way does a spine and-leaf architecture allow for scalability in a network when additional access ports are required?

Options:

A.  

A spine switch and a leaf switch can be added with redundant connections between them

B.  

A spine switch can be added with at least 40 GB uplinks

C.  

A leaf switch can be added with a single connection to a core spine switch.

D.  

A leaf switch can be added with connections to every spine switch

Discussion 0
Questions 220

Which CRUD operation modifies an existing table or view?

Options:

A.  

read

B.  

create

C.  

replace

D.  

update

Discussion 0
Questions 221

What does physical access control regulate?

Options:

A.  

access to spec fie networks based on business function

B.  

access to servers to prevent malicious activity

C.  

access to computer networks and file systems

D.  

access to networking equipment and facilities

Discussion 0
Questions 222

Refer to the exhibit.

What two conclusions should be made about this configuration? (Choose two )

Options:

A.  

The designated port is FastEthernet 2/1

B.  

This is a root bridge

C.  

The spanning-tree mode is Rapid PVST+

D.  

The spanning-tree mode is PVST+

E.  

The root port is FastEthernet 2/1

Discussion 0
Questions 223

What uses HTTP messages to transfer data to applications residing on different hosts?

Options:

A.  

OpenFlow

B.  

OpenStack

C.  

OpFlex

D.  

REST

Discussion 0
Questions 224

Which attribute does a router use to select the best path when two or more different routes to the same destination exist from two different routing protocols.

Options:

A.  

dual algorithm

B.  

metric

C.  

administrative distance

D.  

hop count

Discussion 0
Questions 225

Router R1 must send all traffic without a matching routing-table entry to 192.168.1.1. Which configuration accomplishes this task?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 226

What are two roles of the Dynamic Host Configuration Protocol (DHCP)? (Choose two)

Options:

A.  

The DHCP server offers the ability to exclude specific IP addresses from a pool of IP addresses

B.  

The DHCP client can request up to four DNS server addresses

C.  

The DHCP server assigns IP addresses without requiring the client to renew them

D.  

The DHCP server leases client IP addresses dynamically.

E.  

The DHCP client maintains a pool of IP addresses it can assign.

Discussion 0
Questions 227

Drag and drop the AAA functions from the left onto the correct AAA services on the right

Options:

Discussion 0
Questions 228

Drag and drop the threat-mitigation techniques from the left onto the types of threat or attack they mitigate on the right.

Options:

Discussion 0
Questions 229

Refer to the exhibit.

An extended ACL has been configured and applied to router R2 The configuration failed to work as intended Which two

changes stop outbound traffic on TCP ports 25 and 80 to 10.0.20 0 26 from the 10.0.10 0/26 subnet while still allowing all other traffic? (Choose

two )

Options:

A.  

Add a "permit ip any any" statement to the begining of ACL 101 for allowed traffic.

B.  

Add a "permit ip any any" statement at the end of ACL 101 for allowed traffic

C.  

The source and destination IPs must be swapped in ACL 101

D.  

The ACL must be configured the Gi0/2 interface inbound on R1

E.  

The ACL must be moved to the Gi0/1 interface outbound on R2

Discussion 0
Questions 230

An email user has been lured into clicking a link in an email sent by their company's security organization. The webpage that opens reports that it was safe but the link could have contained malicious code. Which type of security program is in place?

Options:

A.  

Physical access control

B.  

Social engineering attack

C.  

brute force attack

D.  

user awareness

Discussion 0
Questions 231

Which switch technology establishes a network connection immediately when it is plugged in?

Options:

A.  

PortFast

B.  

BPDU guard

C.  

UplinkFast

D.  

BackboneFast

Discussion 0
Questions 232

What are two functions of a Layer 2 switch? (Choose two)

Options:

A.  

acts as a central point for association and authentication servers

B.  

selects the best route between networks on a WAN

C.  

moves packets within a VLAN

D.  

moves packets between different VLANs

E.  

makes forwarding decisions based on the MAC address of a packet

Discussion 0
Questions 233

What is the benefit of using FHRP?

Options:

A.  

reduced management overhead on network routers

B.  

balancing traffic across multiple gateways in proportion to their loads

C.  

higher degree of availability

D.  

reduced ARP traffic on the network

Discussion 0
Questions 234

What is the role of a firewall in an enterprise network?

Options:

A.  

Forwards packets based on stateless packet inspection

B.  

Processes unauthorized packets and allows passage to less secure segments of the network

C.  

determines which packets are allowed to cross from unsecured to secured networks

D.  

explicitly denies all packets from entering an administrative domain

Discussion 0
Questions 235

Which CRUD operation corresponds to the HTTP GET method?

Options:

A.  

read

B.  

update

C.  

create

D.  

delete

Discussion 0
Questions 236

In software-defined architecture, which place handles switching for traffic through a Cisco router?

Options:

A.  

Control

B.  

Management

C.  

Data

D.  

application

Discussion 0
Questions 237

What software defined architecture plane assists network devices with making packet-forwarding decisions by providing Layer 2 reachability and Layer 3 routing information?

Options:

A.  

data plane

B.  

control plane

C.  

policy plane

D.  

management plane

Discussion 0
Questions 238

Which two encoding methods are supported by REST APIs? (Choose two)

Options:

A.  

YAML

B.  

JSON

C.  

EBCDIC

D.  

SGML

E.  

XML

Discussion 0
Questions 239

How are VLAN hopping attacks mitigated?

Options:

A.  

enable dynamic ARP inspection

B.  

manually implement trunk ports and disable DTP

C.  

activate all ports and place in the default VLAN

D.  

configure extended VLANs

Discussion 0
Questions 240

Refer to the exhibit.

Which command provides this output?

Options:

A.  

show ip route

B.  

show ip interface

C.  

show interface

D.  

show cdp neighbor

Discussion 0
Questions 241

Refer to the exhibit.

A router reserved these five routes from different routing information sources.

Which two routes does the router install in its routing table? (Choose two)

Options:

A.  

RIP route 10.0.0.0/30

B.  

iBGP route 10.0.0.0/30

C.  

OSPF route 10.0.0.0/30

D.  

EIGRP route 10.0.0.1/32

E.  

OSPF route 10.0.0.0/16

Discussion 0
Questions 242

Which two capacities of Cisco DNA Center make it more extensible as compared to traditional campus device management? (Choose two)

Options:

A.  

adapters that support all families of Cisco IOS software

B.  

SDKs that support interaction with third-party network equipment

C.  

customized versions for small, medium, and large enterprises

D.  

REST APIs that allow for external applications to interact natively with Cisco DNA Center

E.  

modular design that is upgradable as needed

Discussion 0
Questions 243

Aside from discarding, which two states does the switch port transition through while using RSTP (802.1w)? (Choose two)

Options:

A.  

listening

B.  

blocking

C.  

forwarding

D.  

learning

E.  

speaking

Discussion 0
Questions 244

Which type of address is the public IP address of a NAT device?

Options:

A.  

outside global

B.  

outsdwde local

C.  

inside global

D.  

insride local

E.  

outside public

F.  

inside public

Discussion 0
Questions 245

How will Link Aggregation be Implemented on a Cisco Wireless LAN Controller?

Options:

A.  

One functional physical port is needed to pass client traffic.

B.  

The EthernetChannel must be configured in "mode active".

C.  

When enabled, the WLC bandwidth drops to 500 Mbps.

D.  

To pass client traffic, two or more ports must be configured.

Discussion 0
Questions 246

Refer to the exhibit.

The network administrator wants VLAN 67 traffic to be untagged between Switch 1 and Switch 2 while all other VLANs are to remain tagged.

Which command accomplishes this task?

Options:

A.  

switchport access vlan 67

B.  

switchport trunk allowed vlan 67

C.  

switchport private-vlan association host 67

D.  

switchport trunk native vlan 67

Discussion 0
Questions 247

What is the purpose of a southbound API in a control based networking architecture?

Options:

A.  

Facilities communication between the controller and the applications

B.  

Facilities communication between the controller and the networking hardware

C.  

allows application developers to interact with the network

D.  

integrates a controller with other automation and orchestration tools.

Discussion 0
Questions 248

What is an advantage of Cisco DNA Center versus traditional campus device management?

Options:

A.  

It supports numerous extensibility options including cross-domain adapters and third-party SDKs.

B.  

It supports high availability for management functions when operating in cluster mode.

C.  

It enables easy autodiscovery of network elements m a brownfield deployment.

D.  

It is designed primarily to provide network assurance.

Discussion 0
Questions 249

Which option about JSON is true?

Options:

A.  

uses predefined tags or angle brackets () to delimit markup text

B.  

used to describe structured data that includes arrays

C.  

used for storing information

D.  

similar to HTML, it is more verbose than XML

Discussion 0
Questions 250

What are two southbound APIs? (Choose two )

Options:

A.  

OpenFlow

B.  

NETCONF

C.  

Thrift

D.  

CORBA

E.  

DSC

Discussion 0
Questions 251

Refer to the exhibit.

Which password must an engineer use to enter the enable mode?

Options:

A.  

adminadmin123

B.  

default

C.  

testing 1234

D.  

cisco123

Discussion 0
Questions 252

What is a recommended approach to avoid co-channel congestion while installing access points that use the 2.4 GHz frequency?

Options:

A.  

different nonoverlapping channels

B.  

different overlapping channels

C.  

one overlapping channel

D.  

one nonoverlapping channel

Discussion 0
Questions 253

What is the primary effect of the spanning-tree portfast command?

Options:

A.  

it enables BPDU messages

B.  

It minimizes spanning-tree convergence time

C.  

It immediately puts the port into the forwarding state when the switch is reloaded

D.  

It immediately enables the port in the listening state

Discussion 0
Questions 254

Refer to the exhibit.

An access list is required to permit traffic from any host on interface G0/0 and deny traffic from interface G/0/1. Which access list must be applied?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 255

What is a practice that protects a network from VLAN hopping attacks?

Options:

A.  

Enable dynamic ARP inspection

B.  

Configure an ACL to prevent traffic from changing VLANs

C.  

Change native VLAN to an unused VLAN ID

D.  

Implement port security on internet-facing VLANs

Discussion 0
Questions 256

Refer to the exhibit.

PC1 is trying to ping PC3 for the first time and sends out an ARP to S1 Which action is taken by S1?

Options:

A.  

It forwards it out G0/3 only

B.  

It is flooded out every port except G0/0.

C.  

It drops the frame.

D.  

It forwards it out interface G0/2 only.

Discussion 0
Questions 257

Which two functions are performed by the core layer in a three-tier architecture? (Choose two)

Options:

A.  

Provide uninterrupted forwarding service.

B.  

Police traffic that is sent to the edge of the network.

C.  

Provide direct connectivity for end user devices.

D.  

Ensure timely data transfer between layers.

E.  

Inspect packets for malicious activity.

Discussion 0
Questions 258

What is a characteristic of a SOHO network?

Options:

A.  

connects each switch to every other switch in the network

B.  

enables multiple users to share a single broadband connection

C.  

provides high throughput access for 1000 or more users

D.  

includes at least three tiers of devices to provide load balancing and redundancy

Discussion 0
Questions 259

Which two components are needed to create an Ansible script that configures a VLAN on a switch? (Choose two.)

Options:

A.  

cookbook

B.  

task

C.  

playbook

D.  

model

E.  

recipe

Discussion 0
Questions 260

Refer to the exhibit.

Which outcome is expected when PC_A sends data to PC_B?

Options:

A.  

The switch rewrites the source and destination MAC addresses with its own.

B.  

The source MAC address is changed.

C.  

The source and destination MAC addresses remain the same.

D.  

The destination MAC address is replaced with ffff.ffff.ffff.

Discussion 0
Questions 261

Refer to the exhibit Routers R1 and R2 have been configured with their respective LAN interfaces The two circuits are operational and reachable across WAN Which command set establishes failover redundancy if the primary circuit goes down?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 262

What is a similarity between OM3 and OM4 fiber optic cable?

Options:

A.  

Both have a 50 micron core diameter

B.  

Both have a 9 micron core diameter

C.  

Both have a 62.5 micron core diameter

D.  

Both have a 100 micron core diameter

Discussion 0
Questions 263

Refer to the exhibit.

R5 is the current DR on the network, and R4 is the BDR. Their interfaces are flapping, so a network engineer wants the OSPF network to elect a different DR and BDR. Which set of configurations must the engineer implement?

A)

B)

C)

D)

Options:

A.  

Option

B.  

Option

C.  

Option

D.  

Option

Discussion 0
Questions 264

Drag and drop the descriptions of file-transfer protocols from the left onto the correct protocols on the right.

Options:

Discussion 0
Questions 265

Which command enables a router to become a DHCP client?

Options:

A.  

ip address dhcp

B.  

ip helper-address

C.  

ip dhcp pool

D.  

ip dhcp client

Discussion 0
Questions 266

What is a difference between local AP mode and FiexConnet AP mode?

Options:

A.  

Local AP mode creates two CAPWAP tunnels per AP to the WLC

B.  

FiexConnect AP mode fails to function if the AP loses connectivity with the WLC

C.  

FlexConnect AP mode bridges the traffic from the AP to the WLC when local switching is configured

D.  

Local AP mode causes the AP to behave as if it were an autonomous AP

Discussion 0
Questions 267

Which feature on the Cisco Wireless LAN Controller when enabled restricts management access from specific networks?

Options:

A.  

CPU ACL

B.  

TACACS

C.  

Flex ACL

D.  

RADIUS

Discussion 0
Questions 268

Which mode must be used to configure EtherChannel between two switches without using a negotiation protocol?

Options:

A.  

on

B.  

auto

C.  

active

D.  

desirable

Discussion 0
Questions 269

What protocol allows an engineer to back up 20 network router configurations globally while using the copy function?

Options:

A.  

SMTP

B.  

SNMP

C.  

TCP

D.  

FTP

Discussion 0
Questions 270

Which function is performed by the collapsed core layer in a two-tier architecture?

Options:

A.  

enforcing routing policies

B.  

marking interesting traffic for data polices

C.  

attaching users to the edge of the network

D.  

applying security policies

Discussion 0
Questions 271

What is a network appliance that checks the state of a packet to determine whether the packet is legitimate?

Options:

A.  

Layer 2 switch

B.  

load balancer

C.  

firewall

D.  

LAN controller

Discussion 0
Questions 272

Drag and drop the functions of DHCP from the left onto any of the positions on the right Not all functions are used

Options:

Discussion 0
Questions 273

Refer to the exhibit.

Which configuration on RTR-1 denies SSH access from PC-1 to any RTR-1 interface and allows all other traffic?

Options:

A.  

access-list 100 deny tcp host 172.16.1.33 any eq 22 access-list 100 permit ip any anyinterface GigabitEthernet0/0 ip access-group 100 in

B.  

access-list 100 deny tcp host 172.16.1.33 any eq 22 access-list 100 permit ip any anyline vty 0 15 ip access-group 100 in

C.  

access-list 100 deny tcp host 172.16.1.33 any eq 23 access-list 100 permit ip any anyinterface GigabitEthernet0/0 ip access-group 100 in

D.  

access-list 100 deny tcp host 172.16.1.33 any eq 23 access-list 100 permit ip any anyline vty 0 15 ip access-group 100 in

Discussion 0
Questions 274

Refer to the exhibit.

Router R4 is dynamically learning the path to the server. If R4 is connected to R1 via OSPF Area 20, to R2 v2ia R2 BGP, and to R3 via EIGRP 777, which path is installed in the routing table of R4?

Options:

A.  

the path through R1, because the OSPF administrative distance is 110

B.  

the path through R2. because the IBGP administrative distance is 200

C.  

the path through R2 because the EBGP administrative distance is 20

D.  

the path through R3. because the EIGRP administrative distance is lower than OSPF and BGP

Discussion 0
Questions 275

What is the function of the controller in a software-defined network?

Options:

A.  

multicast replication at the hardware level

B.  

fragmenting and reassembling packets

C.  

making routing decisions

D.  

forwarding packets

Discussion 0
Questions 276

What describes the operation of virtual machines?

Options:

A.  

Virtual machines are responsible for managing and allocating host hardware resources

B.  

In a virtual machine environment, physical servers must run one operating system at a time.

C.  

Virtual machines are the physical hardware that support a virtual environment.

D.  

Virtual machines are operating system instances that are decoupled from server hardware

Discussion 0
Questions 277

Refer to the exhibit.

An engineer is configuring a new router on the network and applied this configuration. Which additional configuration allows the PC to obtain its IP address from a DHCP server?

Options:

A.  

Configure the ip dhcp relay information command under interface Gi0/1.

B.  

Configure the ip dhcp smart-relay command globally on the router

C.  

Configure the ip helper-address 172.16.2.2 command under interface Gi0/0

D.  

Configure the ip address dhcp command under interface Gi0/0

Discussion 0
Questions 278

Refer to the exhibit.

An engineer is asked to insert the new VLAN into the existing trunk without modifying anything previously configured Which command accomplishes this task?

Options:

A.  

switchport trunk allowed vlan 100-104

B.  

switchport trunk allowed vlan add 104

C.  

switchport trunk allowed vlan all

D.  

switchport trunk allowed vlan 104

Discussion 0
Questions 279

Drag and drop the threat-mitigation techniques from the left onto the types of threat or attack they mitigate on the right.

Options:

Discussion 0
Questions 280

Which WLC management connection type is vulnerable to man-in-the-middle attacks?

Options:

A.  

SSH

B.  

HTTPS

C.  

Telnet

D.  

console

Discussion 0
Questions 281

Which two network actions occur within the data plane? (Choose two.)

Options:

A.  

Add or remove an 802.1Q trunking header.

B.  

Make a configuration change from an incoming NETCONF RPC.

C.  

Run routing protocols.

D.  

Match the destination MAC address to the MAC address table.

E.  

Reply to an incoming ICMP echo request.

Discussion 0
Questions 282

Refer to the exhibit.

Users need to connect to the wireless network with IEEE 802. 11r-compatible devices. The connection must be maintained as users travel between floors or to other areas in the building What must be the configuration of the connection?

Options:

A.  

Select the WPA Policy option with the CCKM option.

B.  

Disable AES encryption.

C.  

Enable Fast Transition and select the FT 802.1x option.

D.  

Enable Fast Transition and select the FT PSK option.

Discussion 0
Questions 283

Refer to the exhibit.

Which two commands must be configured on router R1 to enable the router to accept secure remote-access connections? (Choose two)

Options:

A.  

transport input telnet

B.  

crypto key generate rsa

C.  

ip ssh pubkey-chain

D.  

login console

E.  

username cisco password 0 Cisco

Discussion 0
Questions 284

Refer to the exhibit.

Which plan must be Implemented to ensure optimal QoS marking practices on this network?

Options:

A.  

As traffic traverses MLS1 remark the traffic, but trust all markings at the access layer.

B.  

Trust the IP phone markings on SW1 and mark traffic entering SW2 at SW2.

C.  

Remark traffic as it traverses R1 and trust all markings at the access layer.

D.  

As traffic enters from the access layer on SW1 and SW2. trust all traffic markings.

Discussion 0
Questions 285

Refer to the exhibit.

The link between PC1 and the switch is up. but it is performing poorly. Which interface condition is causing the performance problem?

Options:

A.  

There is a duplex mismatch on the interface

B.  

There is an issue with the fiber on the switch interface.

C.  

There is a speed mismatch on the interface.

D.  

There is an interface type mismatch

Discussion 0
Questions 286

Refer to the exhibit.

Traffic sourced from the loopback0 Interface is trying to connect via ssh to the host at 10.0.1.15. What Is the next hop to the destination address?

Options:

A.  

192.168.0.7

B.  

192.168.0.4

C.  

192.168.0.40

D.  

192.168.3.5

Discussion 0
Questions 287

Which wireless security protocol relies on Perfect Forward Secrecy?

Options:

A.  

WPA3

B.  

WPA

C.  

WEP

D.  

WPA2

Discussion 0
Questions 288

Refer to the exhibit.

Which configuration enables DHCP addressing for hosts connected to interface FastEthernetO/1 on router R4?

Options:

A.  

interface FastEthernet0/0ip helper-address 10.0.1.1iaccess-list 100 permit udp host 10.0.1.1 eq bootps host 10.148.2.1

B.  

interface FastEthernot0/1ip helper-address 10.0.1.1!access-list 100 permit tcp host 10.0.1.1 eq 67 host 10.148.2.1

C.  

interface FastEthernetO/0ip helper-address 10.0.1.1Iaccess-list 100 permit host 10.0.1.1 host 10.148.2.1 eq bootps

D.  

interface FastEthernet0/1ip helper-address 10.0.1.1!access-list 100 permit udp host 10.0.1.1 eq bootps host 10.148.2.1

Discussion 0
Questions 289

Refer to the exhibit.

How should the configuration be updated to allow PC1 and PC2 access to the Internet?

Options:

A.  

Modify the configured number of the second access list.

B.  

Add either the ip nat {inside|outside} command under both interfaces.

C.  

Remove the overload keyword from the ip nat inside source command.

D.  

Change the ip nat inside source command to use interface GigabitEthernet0/0.

Discussion 0
Questions 290

Drag and drop the characteristics of networking from the left onto the networking types on the right.

Options:

Discussion 0
Questions 291

What is a function of a Next-Generation IPS?

Options:

A.  

makes forwarding decisions based on learned MAC addresses

B.  

serves as a controller within a controller-based network

C.  

integrates with a RADIUS server to enforce Layer 2 device authentication rules

D.  

correlates user activity with network events

Discussion 0
Questions 292

Refer to the exhibit.

Packets received by the router from BGP enter via a serial interface at 209.165.201.10. Each route is present within the routing table. Which interface is used to forward traffic with a destination IP of 10.10.10.24?

Options:

A.  

F0/10

B.  

F0/11

C.  

F0/12

D.  

F0/13

Discussion 0
Questions 293

Refer to the exhibit.

Which two configurations must the engineer apply on this network so that R1 becomes the DR? (Choose two.)

A)

B)

C)

D)

E)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

E.  

Option E

Discussion 0
Questions 294

Which protocol is used for secure remote CLI access?

Options:

A.  

HTTPS

B.  

HTTP

C.  

Telnet

D.  

SSH

Discussion 0
Questions 295

Which interface mode must be configured to connect the lightweight APs in a centralized architecture?

Options:

A.  

WLAN dynamic

B.  

management

C.  

trunk

D.  

access

Discussion 0
Questions 296

Refer to the exhibit.

The router has been configured with a supernet to accommodate the requirement for 380 users on a subnet The requirement already considers 30% future growth. Which configuration verifies the IP subnet on router R4?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 297

A network administrator is setting up a new IPv6 network using the 64-bit address 2001 0EB8 00C1 2200:0001 0000 0000 0331/64 To simplify the configuration the administrator has decided to compress the address Which IP address must the administrator configure?

Options:

A.  

ipv6 address 21:EB8:C1:2200:1::331/64

B.  

ipv6 address 2001:EB8:C1:22:1::331/64

C.  

ipv6 address 2001 :EB8:C 1:2200.1 ::331-64

D.  

ipv6 address 2001:EB8:C1:2200:1:0000:331/64

Discussion 0
Questions 298

How does Rapid PVST+ create a fast loop-free network topology?

Options:

A.  

lt requires multiple links between core switches

B.  

It generates one spanning-tree instance for each VLAN

C.  

It maps multiple VLANs into the same spanning-tree instance

D.  

It uses multiple active paths between end stations.

Discussion 0
Questions 299

Which field within the access-request packet is encrypted by RADIUS?

Options:

A.  

authorized services

B.  

authenticator

C.  

username

D.  

password

Discussion 0
Questions 300

Refer to the exhibit.

An IP subnet must be configured on each router that provides enough addresses for the number of assigned hosts and anticipates no more than 10% growth for now hosts. Which configuration script must be used?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 301

Refer to the exhibit.

A static route must be configured on R14 to forward traffic for the 172 21 34 0/25 network that resides on R86 Which command must be used to fulfill the request?

Options:

A.  

ip route 172.21.34.0 255.255.255.192 10.73.65.65

B.  

ip route 172.21.34.0 255.255.255.0 10.73.65.65

C.  

ip route 172.21.34.0 255.255.128.0 10.73.65.64

D.  

ip route 172.21.34.0 255.255.255.128 10.73.65.66

Discussion 0
Questions 302

Which Layer 2 switch function encapsulates packets for different VLANs so that the packets traverse the same port and maintain traffic separation between the VLANs?

Options:

A.  

VLAN numbering

B.  

VLAN DSCP

C.  

VLAN tagging

D.  

VLAN marking

Discussion 0
Questions 303

Refer to the exhibit.

Switch A is newly configured. All VLANs are present in the VLAN database. The IP phone and PC A on Gi0/1 must be configured for the appropriate VLANs to establish connectivity between the PCs. Which command set fulfills the requirement?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 304

Drag and drop the Rapid PVST+ forwarding slate actions from the loft to the right. Not all actions are used.

Options:

Discussion 0
Questions 305

Drag and drop the statements about networking from the left onto the corresponding networking types on the right.

Options:

Discussion 0
Questions 306

Refer to the exhibit.

An engineer assumes a configuration task from a peer Router A must establish an OSPF neighbor relationship with neighbor 172 1 1 1 The output displays the status of the adjacency after 2 hours. What is the next step in the configuration process for the routers to establish an adjacency?

Options:

A.  

Configure router A to use the same MTU size as router B.

B.  

Set the router B OSPF ID to a nonhost address.

C.  

Configure a point-to-point link between router A and router B.

D.  

Set the router B OSPF ID to the same value as its IP address

Discussion 0
Questions 307

Refer to the exhibit.

All traffic enters the CPE router from interface Serial0/3 with an IP address of 192 168 50 1 Web traffic from the WAN is destined for a LAN network where servers are load-balanced An IP packet with a destination address of the HTTP virtual IP of 192 1681 250 must be forwarded Which routing table entry does the router use?

Options:

A.  

192.168.1.0/24 via 192.168.12.2

B.  

192.168.1.128/25 via 192.168.13.3

C.  

192.168.1.192/26 via 192.168.14.4

D.  

192.168.1.224/27 via 192.168.15.5

Discussion 0
Questions 308

Which protocol uses the SSL?

Options:

A.  

HTTP

B.  

SSH

C.  

HTTPS

D.  

Telnet

Discussion 0
Questions 309

Refer to the exhibit.

An engineer is updating the R1 configuration to connect a new server to the management network. The PCs on the management network must be blocked from pinging the default gateway of the new server. Which command must be configured on R1 to complete the task?

Options:

A.  

R1(config)#lp route 172.16.2.2 255.255.255.248 gi0/1

B.  

R1(config)#jp route 172.16.2.2 255.255.255.255 gi0/0

C.  

R1(config>#ip route 172.16.2.0 255.255.255.0 192.168.1.15

D.  

R1(conflg)#ip route 172.16.2.0 255.255.255.0 192.168.1.5

Discussion 0
Questions 310

Which type of network attack overwhelms the target server by sending multiple packets to a port until the half-open TCP resources of the target are exhausted?

Options:

A.  

SYIM flood

B.  

reflection

C.  

teardrop

D.  

amplification

Discussion 0
Questions 311

Refer to the exhibit.

Which command must be issued to enable a floating static default route on router A?

Options:

A.  

lp route 0.0.0.0 0.0.0.0 192.168.1.2

B.  

ip default-gateway 192.168.2.1

C.  

ip route 0.0.0.0 0.0.0.0 192.168.2.1 10

D.  

ip route 0.0.0.0 0.0.0.0 192.168.1.2 10

Discussion 0
Questions 312

What is the purpose of the ip address dhcp command?

Options:

A.  

to configure an Interface as a DHCP server

B.  

to configure an interface as a DHCP helper

C.  

to configure an interface as a DHCP relay

D.  

to configure an interface as a DHCP client

Discussion 0
Questions 313

Drag and drop the TCP or UDP details from the left onto their corresponding protocols on the right.

Options:

Discussion 0
Questions 314

What is a requirement for nonoverlapping Wi-Fi channels?

Options:

A.  

different security settings

B.  

discontinuous frequency ranges

C.  

different transmission speeds

D.  

unique SSIDs

Discussion 0
Questions 315

Refer to the exhibit.

All VLANs are present in the VLAN database. Which command sequence must be applied to complete the configuration?

Options:

A.  

Interface FastEthernet0/1 switchport trunk native vlan 10 switchport trunk allowed vlan 10,15

B.  

Interface FastEthernet0/1 switchport mode trunk switchport trunk allowed vlan 10,15

C.  

interface FastEthernet0/1 switchport mode access switchport voice vlan 10

D.  

Interface FastEthernet0/1 switchport trunk allowed vlan add 10 vlan 10 private-vlan isolated

Discussion 0
Questions 316

Which two components comprise part of a PKI? (Choose two.)

Options:

A.  

preshared key that authenticates connections

B.  

RSA token

C.  

CA that grants certificates

D.  

clear-text password that authenticates connections

E.  

one or more CRLs

Discussion 0
Questions 317

Which two spanning-tree states are bypassed on an interface running PortFast? (Choose two.)

Options:

A.  

disabled

B.  

listening

C.  

forwarding

D.  

learning

E.  

blocking

Discussion 0
Questions 318

Refer to the exhibit.

R1 learns all routes via OSPF Which command configures a backup static route on R1 to reach the 192 168.20.0/24 network via R3?

Options:

A.  

R1(config)#ip route 192.168.20.0 255.255.0.0 192.168.30.2

B.  

R1(config)#ip route 192.168.20.0 255.255.255.0 192.168.30.2 90

C.  

R1(config)#ip route 192.168.20.0 255.255.255.0 192.168.30.2 111

D.  

R1(config)#ip route 192.168.20.0 255.255.255.0 192.168.30.2

Discussion 0
Questions 319

Refer to the exhibit.

Router R1 resides in OSPF Area 0. After updating the R1 configuration to influence the paths that it will use to direct traffic, an engineer verified that each of the four Gigabit interfaces has the same route to 10.10.0.0/16. Which interface will R1 choose to send traffic to reach the route?

Options:

A.  

GigabitEthernet0/0

B.  

GigabltEthornet0/1

C.  

GigabitEthernet0/2

D.  

GigabitEthernet0/3

Discussion 0
Questions 320

What is the difference between IPv6 unicast and anycast addressing?

Options:

A.  

IPv6 anycast nodes must be explicitly configured to recognize the anycast address, but IPv6 unicast nodes require no special configuration

B.  

IPv6 unicast nodes must be explicitly configured to recognize the unicast address, but IPv6 anycast nodes require no special configuration

C.  

An individual IPv6 unicast address is supported on a single interface on one node but an IPv6 anycast address is assigned to a group of interfaces on multiple nodes.

D.  

Unlike an IPv6 anycast address, an IPv6 unicast address is assigned to a group of interfaces on multiple nodes

Discussion 0
Questions 321

What are two benefits of FHRPs? (Choose two.)

Options:

A.  

They enable automatic failover of the default gateway.

B.  

They allow multiple devices to serve as a single virtual gateway for clients in the network.

C.  

They are able to bundle multiple ports to increase bandwidth.

D.  

They prevent loops in the Layer 2 network.

E.  

They allow encrypted traffic.

Discussion 0
Questions 322

Refer to the exhibit.

A company is configuring a failover plan and must implement the default routes in such a way that a floating static route will assume traffic forwarding when the primary link goes down. Which primary route configuration must be used?

Options:

A.  

ip route 0.0.0.0 0.0.0.0 192.168.0.2 GigabitEthernetl/0

B.  

ip route 0.0.0.0 0.0.0.0 192.168.0.2 tracked

C.  

ip route 0.0.0.0 0.0.0.0 192.168.0.2 floating

D.  

ip route 0.0.0.0 0.0.0.0 192.168.0.2

Discussion 0
Questions 323

Refer to the exhibit.

Which next-hop IP address does Routed use for packets destined to host 10 10.13.158?

Options:

A.  

10.10.10.5

B.  

10.10.11.2

C.  

10.10.12.2

D.  

10.10.10.9

Discussion 0
Questions 324

Which PoE mode enables powered-device detection and guarantees power when the device is detected?

Options:

A.  

dynamic

B.  

static

C.  

active

D.  

auto

Discussion 0
Questions 325

Refer to the exhibit.

Site A was recently connected to site B over a new single-mode fiber path. Users at site A report Intermittent connectivity Issues with applications hosted at site B. What is the reason for the problem?

Options:

A.  

Heavy usage is causing high latency.

B.  

An incorrect type of transceiver has been inserted into a device on the link.

C.  

physical network errors are being transmitted between the two sites.

D.  

The wrong cable type was used to make the connection.

Discussion 0
Questions 326

Which action implements physical access control as part of the security program of an organization?

Options:

A.  

configuring a password for the console port

B.  

backing up syslogs at a remote location

C.  

configuring enable passwords on network devices

D.  

setting up IP cameras to monitor key infrastructure

Discussion 0
Questions 327

What provides centralized control of authentication and roaming In an enterprise network?

Options:

A.  

a lightweight access point

B.  

a firewall

C.  

a wireless LAN controller

D.  

a LAN switch

Discussion 0
Questions 328

Refer to the exhibit.

Which minimum configuration items are needed to enable Secure Shell version 2 access to R15?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 329

Refer to the exhibit.

What is a reason for poor performance on the network interface?

Options:

A.  

The interface is receiving excessive broadcast traffic.

B.  

The cable connection between the two devices is faulty.

C.  

The interface is operating at a different speed than the connected device.

D.  

The bandwidth setting of the interface is misconfigured

Discussion 0
Questions 330

All physical cabling is in place. A company plans to deploy 32 new sites.

The sites will utilize both IPv4 and IPv6 networks.

1 . Subnet 172.25.0.0/16 to meet the subnet requirements and maximize

the number of hosts

Using the second subnet

• Assign the first usable IP address to e0/0 on Sw1O1

• Assign the last usable IP address to e0/0 on Sw102

2. Subnet to meet the subnet requirements and maximize

the number of hosts

c Using the second subnet

• Assign an IPv6 GUA using a unique 64-Bit interface identifier

on e0/0 on Sw101

• Assign an IPv6 GUA using a unique 64-Bit interface identifier

on eO/O on swi02

Guidelines

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using

the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Options:

Discussion 0
Questions 331

A network engineer must configure two new subnets using the address block 10 70 128 0/19 to meet these requirements:

• The first subnet must support 24 hosts

• The second subnet must support 472 hosts

• Both subnets must use the longest subnet mask possible from the address block

Which two configurations must be used to configure the new subnets and meet a requirement to use the first available address in each subnet for the router interfaces? (Choose two )

Options:

A.  

interface vlan 1234ip address 10.70.159.1 255.255.254.0

B.  

interface vlan 1148ip address 10.70.148.1 255.255.254.0

C.  

interface vlan 4722ip address 10.70.133.17 255.255.255.192

D.  

interface vlan 3002ip address 10.70.147.17 255.255.255.224

E.  

interface vlan 155ip address 10.70.155.65 255.255.255.224

Discussion 0
Questions 332

Which QoS per-hop behavior changes the value of the ToS field in the IPv4 packet header?

Options:

A.  

shaping

B.  

classification

C.  

policing

D.  

marking

Discussion 0
Questions 333

OSPF must be configured between routers R1 and R2. Which OSPF configuration must be applied to router R1 to avoid a DR/BDR election?

Options:

A.  

router ospf 1network 192.168.1.1 0.0.0.0 area 0interface e1/1ip address 192.168.1.1 255.255.255.252ip ospf network broadcast

B.  

router ospf 1network 192.168.1.1 0.0.0.0 area 0interface e1/1ip address 192.168.1.1 255.255.255.252ip ospf network point-to-point

C.  

router ospf 1network 192.168.1.1 0.0.0.0 area 0interface e1/1ip address 192.168.1.1 255.255.255.252ip ospf cost 0

D.  

router ospf 1network 192.168.1.1 0.0.0.0 area 0hello interval 15interface e1/1Ip address 192.168.1.1 255.255.255.252

Discussion 0
Questions 334

Refer to the exhibit.

Which network prefix was learned via EIGRP?

Options:

A.  

172.16.0.0/16

B.  

192.168.2.0/24

C.  

207.165.200.0/24

D.  

192.168.1.0/24

Discussion 0
Questions 335

Refer to the exhibit.

Host A sent a data frame destined for host D

What does the switch do when it receives the frame from host A?

Options:

A.  

It drops the frame from the switch CAM table.

B.  

It floods the frame out of all ports except port Fa0/1.

C.  

It shuts down the port Fa0/1 and places it in err-disable mode.

D.  

It experiences a broadcast storm.

Discussion 0
Questions 336

A network engineer must implement an IPv6 configuration on the vlan 2000 interface to create a routable locally-unique unicast address that is blocked from being advertised to the internet. Which configuration must the engineer apply?

Options:

A.  

interface vlan 2000ipv6 address ffc0:0000:aaaa::1234:2343/64

B.  

interface vlan 2000Ipv6 address fc00:0000:aaaa:a15d:1234:2343:8aca/64

C.  

interface vlan 2000ipv6 address fe80;0000:aaaa::1234:2343/64

D.  

interface vlan 2000ipv6 address fd00::1234:2343/64

Discussion 0
Questions 337

What is a requirement when configuring or removing LAG on a WLC?

Options:

A.  

The Incoming and outgoing ports for traffic flow must be specified If LAG Is enabled.

B.  

The controller must be rebooted after enabling or reconfiguring LAG.

C.  

The management interface must be reassigned if LAG disabled.

D.  

Multiple untagged interfaces on the same port must be supported.

Discussion 0
Questions 338

Refer to the exhibit.

Which two commands must be added to update the configuration of router R1 so that it accepts only encrypted connections? (Choose two )

Options:

A.  

username CNAC secret R!41!4319115@

B.  

ip ssh version 2

C.  

line vty 0 4

D.  

crypto key generate rsa 1024

E.  

transport input ssh

Discussion 0
Questions 339

Refer to the exhibit.

Routers R1 and R3 have the default configuration The router R2 priority is set to 99 Which commands on R3 configure it as the DR in the 10.0 4.0/24 network?

Options:

A.  

R3(config)#interface Gig0/1 R3(config-if)#ip ospf priority 100

B.  

R3(config)#interface Gig0/0 R3(config-if)#ip ospf priority 100

C.  

R3(config)#interface Gig0/0 R3(config-if)i=ip ospf priority 1

D.  

R3(config)#interface Gig0/1 R3(config-if)#ip ospf priority 0

Discussion 0
Questions 340

Refer to the exhibit.

A network engineer must update the configuration on Switch2 so that it sends LLDP packets every minute and the information sent via LLDP is refreshed every 3 minutes Which configuration must the engineer apply?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 341

An engineer is configuring remote access to a router from IP subnet 10.139.58.0/28. The domain name, crypto keys, and SSH have been configured. Which configuration enables the traffic on the destination router?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 342

Refer to the exhibit.

Web traffic is coming in from the WAN interface. Which route takes precedence when the router is processing traffic destined for the LAN network at 10 0.10.0/24?

Options:

A.  

via next-hop 10.0.1.5

B.  

via next-hop 10 0 1.4

C.  

via next-hop 10.0 1.50

D.  

via next-hop 10.0 1 100

Discussion 0
Questions 343

Drag and drop the facts about wireless architectures from the left onto the types of access point on the right. Not all options are used.

Options:

Discussion 0
Questions 344

Which QoS traffic handling technique retains excess packets in a queue and reschedules these packets for later transmission when the configured maximum bandwidth has been surpassed?

Options:

A.  

weighted random early detection

B.  

traffic policing

C.  

traffic shaping

D.  

traffic prioritization

Discussion 0
Questions 345

Refer to the exhibit.

An engineer has started to configure replacement switch SW1. To verify part of the configuration, the engineer issued the commands as shown and noticed that the entry for PC2 is missing. Which change must be applied to SW1 so that PC1 and PC2 communicate normally?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0