Weekend Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Cisco 200-301 Dumps Questions Answers

Page: 1 / 86
Total 1191 questions

Cisco Certified Network Associate Questions and Answers

Question 1

Refer to the exhibit.

An engineer built a new L2 LACP EtherChannel between SW1 and SW2 and executed these show commands to verify the work. Which additional task allows the two switches to establish an LACP port channel?

Options:

A.

Change the channel-group mode on SW2 to auto

B.

Change the channel-group mode on SW1 to desirable.

C.

Configure the interface port-channel 1 command on both switches.

D.

Change the channel-group mode on SW1 to active or passive.

Buy Now
Question 2

Refer to the exhibit.

Traffic that is flowing over interface TenGigabitEthernet0/0 experiences slow transfer speeds. What is the reason for the issue?

Options:

A.

heavy traffic congestion

B.

a duplex incompatibility

C.

a speed conflict

D.

queuing drops

Question 3

What is a function of Opportunistic Wireless Encryption in an environment?

Options:

A.

offer compression

B.

increase security by using a WEP connection

C.

provide authentication

D.

protect traffic on open networks

Question 4

What is an expected outcome when network management automation is deployed?

Options:

A.

A distributed management plane must be used.

B.

Software upgrades are performed from a central controller

C.

Complexity increases when new device configurations are added

D.

Custom applications are needed to configure network devices

Question 5

What causes a port to be placed in the err-disabled state?

Options:

A.

nothing plugged into the port

B.

link flapping

C.

shutdown command issued on the port

D.

latency

Question 6

A network engineer is installing an IPv6-only capable device. The client has requested that the device IP address be reachable only from the internal network. Which type of IPv6 address must the engineer assign?

Options:

A.

unique local address

B.

link-local address

C.

aggregatable global address

D.

IPv4-compatible IPv6 address

Question 7

Which WLC management connection type is vulnerable to man-in-the-middle attacks?

Options:

A.

SSH

B.

HTTPS

C.

Telnet

D.

console

Question 8

Refer to the exhibit.

An engineer is configuring a new router on the network and applied this configuration. Which additional configuration allows the PC to obtain its IP address from a DHCP server?

Options:

A.

Configure the ip dhcp relay information command under interface Gi0/1.

B.

Configure the ip dhcp smart-relay command globally on the router

C.

Configure the ip helper-address 172.16.2.2 command under interface Gi0/0

D.

Configure the ip address dhcp command under interface Gi0/0

Question 9

Drag and drop the statements about networking from the left onto the corresponding networking types on the right.

Options:

Question 10

Which interface mode must be configured to connect the lightweight APs in a centralized architecture?

Options:

A.

WLAN dynamic

B.

management

C.

trunk

D.

access

Question 11

Refer to the exhibit.

Traffic sourced from the loopback0 Interface is trying to connect via ssh to the host at 10.0.1.15. What Is the next hop to the destination address?

Options:

A.

192.168.0.7

B.

192.168.0.4

C.

192.168.0.40

D.

192.168.3.5

Question 12

Drag and drop the TCP or UDP details from the left onto their corresponding protocols on the right.

Options:

Question 13

Which QoS per-hop behavior changes the value of the ToS field in the IPv4 packet header?

Options:

A.

shaping

B.

classification

C.

policing

D.

marking

Question 14

Refer to the exhibit.

Which two configurations must the engineer apply on this network so that R1 becomes the DR? (Choose two.)

A)

B)

C)

D)

E)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

E.

Option E

Question 15

Refer to the exhibit.

Which network prefix was learned via EIGRP?

Options:

A.

172.16.0.0/16

B.

192.168.2.0/24

C.

207.165.200.0/24

D.

192.168.1.0/24

Question 16

Refer to the exhibit.

The following must be considered:

• SW1 is fully configured for all traffic

• The SW4 and SW9 links to SW1 have been configured

• The SW4 interface Gi0/1 and Gi0/0 on SW9 have been configured

• The remaining switches have had all VLANs adde d to their VLAN database

Which configuration establishes a successful ping from PC2 to PC7 without interruption to traffic flow between other PCs?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 17

A Cisco engineer must configure a single switch interface to meet these requirements

• accept untagged frames and place them in VLAN 20

• accept tagged frames in VLAN 30 when CDP detects a Cisco IP phone

Which command set must the engineer apply?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 18

Refer to the exhibit.

Switch A is newly configured. All VLANs are present in the VLAN database. The IP phone and PC A on Gi0/1 must be configured for the appropriate VLANs to establish connectivity between the PCs. Which command set fulfills the requirement?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 19

Refer to the exhibit.

Which next-hop IP address does Routed use for packets destined to host 10 10.13.158?

Options:

A.

10.10.10.5

B.

10.10.11.2

C.

10.10.12.2

D.

10.10.10.9

Question 20

Refer to the exhibit.

A network engineer must update the configuration on Switch2 so that it sends LLDP packets every minute and the information sent via LLDP is refreshed every 3 minutes Which configuration must the engineer apply?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 21

Which type of network attack overwhelms the target server by sending multiple packets to a port until the half-open TCP resources of the target are exhausted?

Options:

A.

SYIM flood

B.

reflection

C.

teardrop

D.

amplification

Question 22

What are two benefits of FHRPs? (Choose two.)

Options:

A.

They enable automatic failover of the default gateway.

B.

They allow multiple devices to serve as a single virtual gateway for clients in the network.

C.

They are able to bundle multiple ports to increase bandwidth.

D.

They prevent loops in the Layer 2 network.

E.

They allow encrypted traffic.

Question 23

A Cisco engineer is configuring a factory-default router with these three passwords:

• The user EXEC password for console access is p4ssw0rd1

• The user EXEC password for Telnet access is s3cr3t2

• The password for privileged EXEC mode is pnv4t3p4ss Which command sequence must the engineer configured

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 24

Refer to the exhibit.

Which action must be taken to ensure that router A is elected as the DR for OSPF area 0?

Options:

A.

Configure the OSPF priority on router A with the lowest value between the three routers.

B.

Configure router B and router C as OSPF neighbors of router A.

C.

Configure the router A interfaces with the highest OSPF priority value within the area.

D.

Configure router A with a fixed OSPF router ID

Question 25

Refer to the exhibit.

An engineer is updating the R1 configuration to connect a new server to the management network. The PCs on the management network must be blocked from pinging the default gateway of the new server. Which command must be configured on R1 to complete the task?

Options:

A.

R1(config)#lp route 172.16.2.2 255.255.255.248 gi0/1

B.

R1(config)#jp route 172.16.2.2 255.255.255.255 gi0/0

C.

R1(config>#ip route 172.16.2.0 255.255.255.0 192.168.1.15

D.

R1(conflg)#ip route 172.16.2.0 255.255.255.0 192.168.1.5

Question 26

A network engineer must implement an IPv6 configuration on the vlan 2000 interface to create a routable locally-unique unicast address that is blocked from being advertised to the internet. Which configuration must the engineer apply?

Options:

A.

interface vlan 2000ipv6 address ffc0:0000:aaaa::1234:2343/64

B.

interface vlan 2000Ipv6 address fc00:0000:aaaa:a15d:1234:2343:8aca/64

C.

interface vlan 2000ipv6 address fe80;0000:aaaa::1234:2343/64

D.

interface vlan 2000ipv6 address fd00::1234:2343/64

Question 27

How does Rapid PVST+ create a fast loop-free network topology?

Options:

A.

lt requires multiple links between core switches

B.

It generates one spanning-tree instance for each VLAN

C.

It maps multiple VLANs into the same spanning-tree instance

D.

It uses multiple active paths between end stations.

Question 28

Refer to the exhibit.

Packets received by the router from BGP enter via a serial interface at 209 165 201 1 Each route is present within the routing table Which interface is used to forward traffic with a destination IP of 10.1.1.19?

Options:

A.

F0/4

B.

F0/0

C.

F0/1

D.

F0/3

Question 29

Refer to the exhibit.

The link between PC1 and the switch is up. but it is performing poorly. Which interface condition is causing the performance problem?

Options:

A.

There is a duplex mismatch on the interface

B.

There is an issue with the fiber on the switch interface.

C.

There is a speed mismatch on the interface.

D.

There is an interface type mismatch

Question 30

Refer to the exhibit.

Which two commands when used together create port channel 10? (Choose two.)

Options:

A.

int range g0/0-1channel-group 10 mode active

B.

int range g0/0-1 chanm.l-group 10 mode desirable

C.

int range g0/0-1channel-group 10 mode passive

D.

int range g0/0-1 channel-group 10 mode auto

E.

int range g0/0-1 channel-group 10 mode on

Question 31

Refer to the exhibit.

How should the configuration be updated to allow PC1 and PC2 access to the Internet?

Options:

A.

Modify the configured number of the second access list.

B.

Add either the ip nat {inside|outside} command under both interfaces.

C.

Remove the overload keyword from the ip nat inside source command.

D.

Change the ip nat inside source command to use interface GigabitEthernet0/0.

Question 32

What is the function of the controller in a software-defined network?

Options:

A.

multicast replication at the hardware level

B.

fragmenting and reassembling packets

C.

making routing decisions

D.

forwarding packets

Question 33

Which type of IPv6 address is similar to a unicast address but is assigned to multiple devices on the same network at the same time?

Options:

A.

global unicast address

B.

anycast address

C.

multicast address

D.

link-local address

Question 34

Refer to the exhibit.

Web traffic is coming in from the WAN interface. Which route takes precedence when the router is processing traffic destined for the LAN network at 10 0.10.0/24?

Options:

A.

via next-hop 10.0.1.5

B.

via next-hop 10 0 1.4

C.

via next-hop 10.0 1.50

D.

via next-hop 10.0 1 100

Question 35

Refer to the exhibit.

Router R1 currently is configured to use R3 as the primary route to the Internet, and the route uses the default administrative distance settings. A network engineer must configure R1 so that it uses R2 as a backup, but only if R3 goes down. Which command must the engineer configure on R1 so that it correctly uses R2 as a backup route, without changing the administrative distance configuration on the link to R3?

Options:

A.

ip route 0.0.0.0 0.0.0.0 g0/1 1

B.

ip route 0.0.0.0 0.0.0.0 209.165.201.5 10

C.

ip route 0.0.0.0 0.0.0.0 209.165.200.226 1

D.

ip route 0,0.0.0 0.0.0.0 g0/1 6

Question 36

What provides centralized control of authentication and roaming In an enterprise network?

Options:

A.

a lightweight access point

B.

a firewall

C.

a wireless LAN controller

D.

a LAN switch

Question 37

Drag and drop the threat-mitigation techniques from the left onto the types of threat or attack they mitigate on the right.

Options:

Question 38

Refer to the exhibit.

An IP subnet must be configured on each router that provides enough addresses for the number of assigned hosts and anticipates no more than 10% growth for now hosts. Which configuration script must be used?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 39

Which action is taken by the data plane within a network device?

Options:

A.

forwards traffic to the next hop

B.

constructs a routing table based on a routing protocol

C.

provides CLI access to the network device

D.

looks up an egress interface in the forwarding information base

Question 40

Refer to the exhibit.

R1 learns all routes via OSPF Which command configures a backup static route on R1 to reach the 192 168.20.0/24 network via R3?

Options:

A.

R1(config)#ip route 192.168.20.0 255.255.0.0 192.168.30.2

B.

R1(config)#ip route 192.168.20.0 255.255.255.0 192.168.30.2 90

C.

R1(config)#ip route 192.168.20.0 255.255.255.0 192.168.30.2 111

D.

R1(config)#ip route 192.168.20.0 255.255.255.0 192.168.30.2

Question 41

What is the purpose of the ip address dhcp command?

Options:

A.

to configure an Interface as a DHCP server

B.

to configure an interface as a DHCP helper

C.

to configure an interface as a DHCP relay

D.

to configure an interface as a DHCP client

Question 42

Which protocol is used for secure remote CLI access?

Options:

A.

HTTPS

B.

HTTP

C.

Telnet

D.

SSH

Question 43

Refer to the exhibit.

Host A sent a data frame destined for host D

What does the switch do when it receives the frame from host A?

Options:

A.

It drops the frame from the switch CAM table.

B.

It floods the frame out of all ports except port Fa0/1.

C.

It shuts down the port Fa0/1 and places it in err-disable mode.

D.

It experiences a broadcast storm.

Question 44

Which QoS traffic handling technique retains excess packets in a queue and reschedules these packets for later transmission when the configured maximum bandwidth has been surpassed?

Options:

A.

weighted random early detection

B.

traffic policing

C.

traffic shaping

D.

traffic prioritization

Question 45

OSPF must be configured between routers R1 and R2. Which OSPF configuration must be applied to router R1 to avoid a DR/BDR election?

Options:

A.

router ospf 1network 192.168.1.1 0.0.0.0 area 0interface e1/1ip address 192.168.1.1 255.255.255.252ip ospf network broadcast

B.

router ospf 1network 192.168.1.1 0.0.0.0 area 0interface e1/1ip address 192.168.1.1 255.255.255.252ip ospf network point-to-point

C.

router ospf 1network 192.168.1.1 0.0.0.0 area 0interface e1/1ip address 192.168.1.1 255.255.255.252ip ospf cost 0

D.

router ospf 1network 192.168.1.1 0.0.0.0 area 0hello interval 15interface e1/1Ip address 192.168.1.1 255.255.255.252

Question 46

Refer to the exhibit.

Packets received by the router from BGP enter via a serial interface at 209.165.201.10. Each route is present within the routing table. Which interface is used to forward traffic with a destination IP of 10.10.10.24?

Options:

A.

F0/10

B.

F0/11

C.

F0/12

D.

F0/13

Question 47

Drag and drop the Rapid PVST+ forwarding slate actions from the loft to the right. Not all actions are used.

Options:

Question 48

Refer to the exhibit.

A static route must be configured on R14 to forward traffic for the 172 21 34 0/25 network that resides on R86 Which command must be used to fulfill the request?

Options:

A.

ip route 172.21.34.0 255.255.255.192 10.73.65.65

B.

ip route 172.21.34.0 255.255.255.0 10.73.65.65

C.

ip route 172.21.34.0 255.255.128.0 10.73.65.64

D.

ip route 172.21.34.0 255.255.255.128 10.73.65.66

Question 49

Which action implements physical access control as part of the security program of an organization?

Options:

A.

configuring a password for the console port

B.

backing up syslogs at a remote location

C.

configuring enable passwords on network devices

D.

setting up IP cameras to monitor key infrastructure

Question 50

Refer to the exhibit.

All VLANs are present in the VLAN database. Which command sequence must be applied to complete the configuration?

Options:

A.

Interface FastEthernet0/1 switchport trunk native vlan 10 switchport trunk allowed vlan 10,15

B.

Interface FastEthernet0/1 switchport mode trunk switchport trunk allowed vlan 10,15

C.

interface FastEthernet0/1 switchport mode access switchport voice vlan 10

D.

Interface FastEthernet0/1 switchport trunk allowed vlan add 10 vlan 10 private-vlan isolated

Question 51

An engineer is tasked to configure a switch with port security to ensure devices that forward unicasts multicasts and broadcasts are unable to flood the port The port must be configured to permit only two random MAC addresses at a time Drag and drop the required configuration commands from the left onto the sequence on the right Not all commands are used.

Options:

Question 52

An engineer is configuring remote access to a router from IP subnet 10.139.58.0/28. The domain name, crypto keys, and SSH have been configured. Which configuration enables the traffic on the destination router?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 53

A network administrator is setting up a new IPv6 network using the 64-bit address 2001 0EB8 00C1 2200:0001 0000 0000 0331/64 To simplify the configuration the administrator has decided to compress the address Which IP address must the administrator configure?

Options:

A.

ipv6 address 21:EB8:C1:2200:1::331/64

B.

ipv6 address 2001:EB8:C1:22:1::331/64

C.

ipv6 address 2001 :EB8:C 1:2200.1 ::331-64

D.

ipv6 address 2001:EB8:C1:2200:1:0000:331/64

Question 54

What is a function of an endpoint on a network?

Options:

A.

forwards traffic between VLANs on a network

B.

connects server and client devices to a network

C.

allows users to record data and transmit to a tile server

D.

provides wireless services to users in a building

Question 55

Refer to the exhibit.

An engineer is asked to insert the new VLAN into the existing trunk without modifying anything previously configured Which command accomplishes this task?

Options:

A.

switchport trunk allowed vlan 100-104

B.

switchport trunk allowed vlan add 104

C.

switchport trunk allowed vlan all

D.

switchport trunk allowed vlan 104

Question 56

Refer to the exhibit.

Which minimum configuration items are needed to enable Secure Shell version 2 access to R15?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 57

Refer to the exhibit.

The router has been configured with a supernet to accommodate the requirement for 380 users on a subnet The requirement already considers 30% future growth. Which configuration verifies the IP subnet on router R4?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 58

A network engineer must configure two new subnets using the address block 10 70 128 0/19 to meet these requirements:

• The first subnet must support 24 hosts

• The second subnet must support 472 hosts

• Both subnets must use the longest subnet mask possible from the address block

Which two configurations must be used to configure the new subnets and meet a requirement to use the first available address in each subnet for the router interfaces? (Choose two )

Options:

A.

interface vlan 1234ip address 10.70.159.1 255.255.254.0

B.

interface vlan 1148ip address 10.70.148.1 255.255.254.0

C.

interface vlan 4722ip address 10.70.133.17 255.255.255.192

D.

interface vlan 3002ip address 10.70.147.17 255.255.255.224

E.

interface vlan 155ip address 10.70.155.65 255.255.255.224

Question 59

Refer to the exhibit.

Which plan must be Implemented to ensure optimal QoS marking practices on this network?

Options:

A.

As traffic traverses MLS1 remark the traffic, but trust all markings at the access layer.

B.

Trust the IP phone markings on SW1 and mark traffic entering SW2 at SW2.

C.

Remark traffic as it traverses R1 and trust all markings at the access layer.

D.

As traffic enters from the access layer on SW1 and SW2. trust all traffic markings.

Question 60

Refer to the exhibit.

An engineer is configuring the HO router. Which IPv6 address configuration must be applied to the router fa0'1 interface for the router to assign a unique 64-brt IPv6 address to Itself?

Options:

A.

ipv6 address 2001:DB8:0:1:C601:42FF:FE0F:7/64

B.

ipv6 address 2001:DB8:0:1:C601:42FE:800F:7/64

C.

ipv6 address 2001 :DB8:0:1:FFFF:C601:420F:7/64

D.

iov6 address 2001 :DB8:0:1:FE80:C601:420F:7/64

Question 61

Refer to the exhibit.

Routers R1 and R3 have the default configuration The router R2 priority is set to 99 Which commands on R3 configure it as the DR in the 10.0 4.0/24 network?

Options:

A.

R3(config)#interface Gig0/1 R3(config-if)#ip ospf priority 100

B.

R3(config)#interface Gig0/0 R3(config-if)#ip ospf priority 100

C.

R3(config)#interface Gig0/0 R3(config-if)i=ip ospf priority 1

D.

R3(config)#interface Gig0/1 R3(config-if)#ip ospf priority 0

Question 62

Refer to the exhibit.

An engineer has started to configure replacement switch SW1. To verify part of the configuration, the engineer issued the commands as shown and noticed that the entry for PC2 is missing. Which change must be applied to SW1 so that PC1 and PC2 communicate normally?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 63

R1 as an NTP server must have:

• NTP authentication enabled

• NTP packets sourced from Interface loopback 0

• NTP stratum 2

• NTP packets only permitted to client IP 209.165 200 225

How should R1 be configured?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 64

What is one reason to implement LAG on a Cisco WLC?

Options:

A.

to increase security and encrypt management frames

B.

to provide link redundancy and load balancing

C.

to allow for stateful and link-state failover

D.

to enable connected switch ports to failover and use different VLANs

Question 65

Refer to the exhibit.

Which command configures OSPF on the point-to-point link between routers R1 and R2?

Options:

A.

router-id 10.0.0.15

B.

neighbor 10.1.2.0 cost 180

C.

ipospf priority 100

D.

network 10.0.0.0 0.0.0.255 area 0

Question 66

Refer to the exhibit.

Which command must be issued to enable a floating static default route on router A?

Options:

A.

lp route 0.0.0.0 0.0.0.0 192.168.1.2

B.

ip default-gateway 192.168.2.1

C.

ip route 0.0.0.0 0.0.0.0 192.168.2.1 10

D.

ip route 0.0.0.0 0.0.0.0 192.168.1.2 10

Question 67

Refer to the exhibit.

An engineer is configuring an EtherChannel using LACP between Switches 1 and 2 Which configuration must be applied so that only Switch 1 sends LACP initiation packets?

Options:

A.

Switch 1 (config-if)#channel-group 1 mode onSwrtch2(config-if)#channel-group 1 mode passive

B.

Switch1(config-if)#channel-group 1 mode passiveSwitch2(config-if)#channel-group 1 mode active

C.

Switch1{config-if)£channel-group 1 mode activeSwitch2(config-if)#channel-group 1 mode passive

D.

Switch1(config-if)#channel-group 1 mode onSwitch2(config-if)#channel-group 1 mode active

Question 68

Which two components comprise part of a PKI? (Choose two.)

Options:

A.

preshared key that authenticates connections

B.

RSA token

C.

CA that grants certificates

D.

clear-text password that authenticates connections

E.

one or more CRLs

Question 69

Refer to the exhibit.

Which route must be configured on R1 so that OSPF routing is used when OSPF is up. but the server is still reachable when OSPF goes down?

Options:

A.

ip route 10.1.1.10 255.255.255.255 172.16.2.2 100

B.

ip route 10.1.1.0 255.255.255.0 gi0/1 125

C.

ip route 10.1.1.0 255.255.255.0 172.16.2.2 100

D.

ip route 10.1.1.10 255.255.255.255 gi0/0 125

Question 70

Which goal is achieved by the implementation of private IPv4 addressing on a network?

Options:

A.

provides an added level of protection against Internet exposure

B.

provides a reduction in size of the forwarding table on network routers

C.

allows communication across the Internet to other private networks

D.

allows servers and workstations to communicate across public network boundaries

Question 71

What role does a hypervisor provide for each virtual machine in server virtualization?

Options:

A.

infrastructure-as-a-service.

B.

Software-as-a-service

C.

control and distribution of physical resources

D.

services as a hardware controller.

Question 72

Refer to the exhibit.

For security reasons, automatic neighbor discovery must be disabled on the R5 Gi0/1 interface. These tasks must be completed:

• Disable all neighbor discovery methods on R5 interface GiO/1.

• Permit neighbor discovery on R5 interface GiO/2.

• Verify there are no dynamically learned neighbors on R5 interface Gi0/1.

• Display the IP address of R6*s interface Gi0/2.

Which configuration must be used?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 73

When the active router in an HSRP group fails, what router assumes the role and forwards packets?

Options:

A.

backup

B.

standby

C.

listening

D.

forwarding

Question 74

A corporate office uses four floors in a building

• Floor 1 has 24 users

• Floor 2 has 29 users

• Floor 3 has 28 users

•Floor 4 has 22 users

Which subnet summarizes and gives the most efficient distribution of IP addresses for the router configuration?

Options:

A.

192.168.0.0/26 as summary and 192.168.0.0/29 for each floor

B.

192.168.0.0.24 as summary and 192.168.0.0/28 for each floor

C.

192.168.0.0/23 as summary and 192.168.0.0/25 for each floor

D.

l92.168.0.0/25 as summary and 192.168.0.0/27 for each floor

Question 75

An engineer must configure a WLAN using the strongest encryption type for WPA2- PSK. Which cipher fulfills the configuration requirement?

Options:

A.

WEP

B.

RC4

C.

AES

D.

TKIP

Question 76

Which two primary drivers support the need for network automation? (Choose two.)

Options:

A.

Eliminating training needs

B.

Increasing reliance on self-diagnostic and self-healing

C.

Policy-derived provisioning of resources

D.

Providing a ship entry point for resource provisioning

E.

Reducing hardware footprint

Question 77

Refer to the exhibit.

What is the effect of this configuration?

Options:

A.

All ARP packets are dropped by the switch

B.

Egress traffic is passed only if the destination is a DHCP server.

C.

All ingress and egress traffic is dropped because the interface is untrusted

D.

The switch discard all ingress ARP traffic with invalid MAC-to-IP address bindings.

Question 78

Refer to the exhibit.

If R1 receives a packet destined to 172.161.1, to which IP address does it send the packet?

Options:

A.

192.168.12.2

B.

192.168.13.3

C.

192.168.14.4

D.

192.168.15.5

Question 79

Refer to the exhibit.

A network engineer is in the process of establishing IP connectivity between two sites. Routers R1 and R2 are partially configured with IP addressing. Both routers have the ability to access devices on their respective LANs. Which command set configures the IP connectivity between devices located on both LANs in each site?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 80

Which action is taken by a switch port enabled for PoE power classification override?

Options:

A.

When a powered device begins drawing power from a PoE switch port a syslog message is generated

B.

As power usage on a PoE switch port is checked data flow to the connected device is temporarily paused

C.

If a switch determines that a device is using less than the minimum configured power it assumes the device has failed and disconnects

D.

Should a monitored port exceeds the maximum administrative value for power, the port is shutdown and err-disabled

Question 81

Which communication interaction takes place when a southbound API Is used?

Options:

A.

between the SDN controller and PCs on the network

B.

between the SON controller and switches and routers on the network

C.

between the SON controller and services and applications on the network

D.

between network applications and switches and routers on the network

Question 82

Which two actions influence the EIGRP route selection process? (Choose two)

Options:

A.

The router calculates the reported distance by multiplying the delay on the exiting Interface by 256.

B.

The router calculates the best backup path to the destination route and assigns it as the feasible successor.

C.

The router calculates the feasible distance of all paths to the destination route

D.

The advertised distance is calculated by a downstream neighbor to inform the local router of the bandwidth on the link

E.

The router must use the advertised distance as the metric for any given route

Question 83

Which protocol requires authentication to transfer a backup configuration file from a router to a remote server?

Options:

A.

DTP

B.

FTP

C.

SMTP

D.

TFTP

Question 84

What is a similarly between 1000BASE-LX and 1000BASE-T standards?

Options:

A.

Both use the same data-link header and trailer formats

B.

Both cable types support LP connectors

C.

Both cable types support Rj-45 connectors

D.

Both support up to 550 meters between nodes

Question 85

Refer to the exhibit.

An administrator must configure interfaces Gi1/1 and Gi1/3 on switch SW11 PC-1 and PC-2 must be placed in the Data VLAN and Phone-1 must be placed in the Voice VLAN Which configuration meets these requirements?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 86

A network administrator must to configure SSH for remote access to router R1 The requirement is to use a public and private key pair to encrypt management traffic to and from the connecting client.

Which configuration, when applied, meets the requirements?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 87

Which 802.11 frame type is indicated by a probe response after a client sends a probe request?

Options:

A.

action

B.

management

C.

control

D.

data

Question 88

What are two benefits of FHRPs? (Choose two.)

Options:

A.

They prevent (oops in the Layer 2 network.

B.

They allow encrypted traffic.

C.

They are able to bundle muftlple ports to increase bandwidth

D.

They enable automatic failover of the default gateway.

E.

They allow multiple devices lo serve as a single virtual gateway for clients in the network

Question 89

Refer to the exhibit.

Which IPv6 configuration is required for R17 to successfully ping the WAN interface on R18?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 90

The SW1 interface g0/1 is in the down/down state. Which two configurations are valid reasons for the interface conditions?(choose two)

Options:

A.

There is a duplex mismatch

B.

There is a speed mismatch

C.

There is a protocol mismatch

D.

The interface is shut down

E.

The interface is error-disabled

Question 91

Refer to the exhibit.

An engineer deploys a topology in which R1 obtains its IP configuration from DHCP. If

the switch and DHCP server configurations are complete and correct. Which two sets of commands must be configured on R1 and R2 to complete the task? (Choose two)

Options:

A.

R1(config)# interface fa0/0R1(config-if)# ip helper-address 198.51.100.100

B.

R2(config)# interface gi0/0R2(config-if)# ip helper-address 198.51.100.100

C.

R1(config)# interface fa0/0R1(config-if)# ip address dhcpR1(config-if)# no shutdown

D.

R2(config)# interface gi0/0R2(config-if)# ip address dhcp

E.

R1(config)# interface fa0/0R1(config-if)# ip helper-address 192.0.2.2

Question 92

When a WLAN with WPA2 PSK is configured in the Wireless LAN Controller GUI which format is supported?

Options:

A.

Unicode

B.

base64

C.

decimal

D.

ASCII

Question 93

What is a capability of FTP in network management operations?

Options:

A.

encrypts data before sending between data resources

B.

devices are directly connected and use UDP to pass file information

C.

uses separate control and data connections to move files between server and client

D.

offers proprietary support at the session layer when transferring data

Question 94

Refer to the exhibit.

With which metric was the route to host 172.16.0.202 learned?

Options:

A.

0

B.

110

C.

38443

D.

3184439

Question 95

Which two protocols must be disabled to increase security for management connections to a Wireless LAN Controller? (Choose two.)

Options:

A.

Telnet

B.

SSH

C.

HTTP

D.

HTTPS

E.

TFTP

Question 96

Which statement correctly compares traditional networks and controller-based networks?

Options:

A.

Only traditional networks offer a centralized control plane

B.

Only traditional networks natively support centralized management

C.

Traditional and controller-based networks abstract policies from device configurations

D.

Only controller-based networks decouple the control plane and the data plane

Question 97

Which IPv6 address type provides communication between subnets and is unable to route on the Internet?

Options:

A.

global unicast

B.

unique local

C.

link-local

D.

multicast

Question 98

Refer to the exhibit.

A packet is being sent across router R1 to host 172.16.0.14. What is the destination route for the packet?

Options:

A.

209.165.200.254 via Serial0/0/1

B.

209.165.200.254 via Serial0/0/0

C.

209.165.200.246 via Serial0/1/0

D.

209.165.200.250 via Serial0/0/0

Question 99

An engineer requires a scratch interface to actively attempt to establish a trunk link with a neighbor switch. What command must be configured?

Options:

A.

switchport mode trunk

B.

switchport mode dynamic desirable

C.

switchport mode dynamic auto

D.

switchport nonegotiate

Question 100

Where does a switch maintain DHCP snooping information?

Options:

A.

in the MAC address table

B.

in the CAM table

C.

in the binding database

D.

in the frame forwarding database

Question 101

Refer to the exhibit.

Which prefix does Router 1 use for traffic to Host A?

Options:

A.

10.10.10.0/28

B.

10.10.13.0/25

C.

10.10.13.144/28

D.

10.10.13.208/29

Question 102

Refer to Exhibit.

An engineer is configuring the NEW York router to reach the Lo1 interface of the Atlanta router using interface Se0/0/0 as the primary path. Which two commands must be configured on the New York router so that it can reach the Lo1 interface of the Atlanta router via Washington when the link between New York and Atlanta goes down? (Choose two)

Options:

A.

ipv6 router 2000::1/128 2012::1

B.

ipv6 router 2000::1/128 2012::1 5

C.

ipv6 router 2000::1/128 2012::2

D.

ipv6 router 2000::1/128 2023::2 5

E.

ipv6 router 2000::1/128 2023::3 5

Question 103

Refer to the exhibit.

An engineer booted a new switch and applied this configuration via the console port. Which additional configuration must be applied to allow administrators to authenticate directly to enable privilege mode via Telnet using a local username and password?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 104

Which configuration management mechanism uses TCP port 22 by default when communicating with managed nodes?

Options:

A.

Ansible

B.

Python

C.

Puppet

D.

Chef

Question 105

An engineer needs to configure LLDP to send the port description time length value (TLV). What command sequence must be implemented?

Options:

A.

switch(config-line)#IIdp port-description

B.

switch(config)#IIdp port-description

C.

switch(config-if)#IIdp port-description

D.

switch#IIdp port-description

Question 106

Refer to the exhibit.

The entire contents of the MAC address table are shown. Sales-4 sends a data frame to Sales-1.

What does the switch do as it receives the frame from Sales-4?

Options:

A.

Perform a lookup in the MAC address table and discard the frame due to a missing entry.

B.

Insert the source MAC address and port into the forwarding table and forward the frame to Sales-1.

C.

Map the Layer 2 MAC address to the Layer 3 IP address and forward the frame.

D.

Flood the frame out of all ports except on the port where Sales-1 is connected.

Question 107

Which two QoS tools provides congestion management? ( Choose two )

Options:

A.

CAR

B.

CBWFQ

C.

PQ

D.

PBR

E.

FRTS

Question 108

Which QoS tool is used to optimize voice traffic on a network that is primarily intended for data traffic?

Options:

A.

FIFO

B.

WFQ

C.

PQ

D.

WRED

Question 109

While examining excessive traffic on the network, it is noted that all incoming packets on an interface appear to be allowed even though an IPv4 ACL is applied to the interface.

Which two misconfigurations cause this behavior? (Choose two)

Options:

A.

The packets fail to match any permit statement

B.

A matching permit statement is too high in the access test

C.

A matching permit statement is too broadly defined

D.

The ACL is empty

E.

A matching deny statement is too high in the access list

Question 110

Refer to the exhibit.

Which route type does the routing protocol Code D represent in the output?

Options:

A.

internal BGP route

B.

/24 route of a locally configured IP

C.

statically assigned route

D.

route learned through EIGRP

Question 111

When deploying syslog, which severity level logs informational message?

Options:

A.

0

B.

2

C.

4

D.

6

Question 112

Using direct sequence spread spectrum, which three 2.4-GHz channels are used to limit collisions?

Options:

A.

1,6,11

B.

1,5,10

C.

1,2,3

D.

5,6,7

Question 113

Refer to the exhibit.

An access list is created to deny Telnet access from host PC-1 to RTR-1 and allow access from all other hosts A Telnet attempt from PC-2 gives this message:"% Connection refused by remote host" Without allowing Telnet access from PC-1, which action must be taken to permit the traffic?

Options:

A.

Add the access-list 10 permit any command to the configuration

B.

Remove the access-class 10 in command from line vty 0.4.

C.

Add the ip access-group 10 out command to interface g0/0.

D.

Remove the password command from line vty 0 4.

Question 114

Which plane is centralized by an SDN controller?

Options:

A.

management-plane

B.

control-plane

C.

data-plane

D.

services-plane

Question 115

What is the benefit of configuring PortFast on an interface?

Options:

A.

After the cable is connected, the interface uses the fastest speed setting available for that cable type

B.

After the cable is connected, the interface is available faster to send and receive user data

C.

The frames entering the interface are marked with higher priority and then processed faster by a switch.

D.

Real-time voice and video frames entering the interface are processed faster

Question 116

What Is a syslog facility?

Options:

A.

Host that is configured for the system to send log messages

B.

password that authenticates a Network Management System to receive log messages

C.

group of log messages associated with the configured severity level

D.

set of values that represent the processes that can generate a log message

Question 117

R1 has learned route 10.10.10.0/24 via numerous routing protocols. Which route is installed?

Options:

A.

route with the lowest cost

B.

route with the next hop that has the highest IP

C.

route with the shortest prefix length

D.

route with the lowest administrative distance

Question 118

What is the primary function of a Layer 3 device?

Options:

A.

to analyze traffic and drop unauthorized traffic from the Internet

B.

to transmit wireless traffic between hosts

C.

to pass traffic between different networks

D.

forward traffic within the same broadcast domain

Question 119

Which type of traffic is sent with pure iPsec?

Options:

A.

broadcast packets from a switch that is attempting to locate a MAC address at one of several remote sites

B.

multicast traffic from a server at one site to hosts at another location

C.

spanning-tree updates between switches that are at two different sites

D.

unicast messages from a host at a remote site to a server at headquarters

Question 120

What benefit does controller-based networking provide versus traditional networking?

Options:

A.

moves from a two-tier to a three-tier network architecture to provide maximum redundancy

B.

provides an added layer of security to protect from DDoS attacks

C.

allows configuration and monitoring of the network from one centralized port

D.

combines control and data plane functionality on a single device to minimize latency

Question 121

Which design element is a best practice when deploying an 802.11b wireless infrastructure?

Options:

A.

disabling TPC so that access points can negotiate signal levels with their attached wireless devices.

B.

setting the maximum data rate to 54 Mbps on the Cisco Wireless LAN Controller

C.

allocating nonoverlapping channels to access points that are in close physical proximity to one another

D.

configuring access points to provide clients with a maximum of 5 Mbps

Question 122

Drag and drop the lightweight access point operation modes from the left onto the descriptions on the right

Options:

Question 123

Which function is performed by DHCP snooping?

Options:

A.

propagates VLAN information between switches

B.

listens to multicast traffic for packet forwarding

C.

provides DDoS mitigation

D.

rate-limits certain traffic

Question 124

A network engineer must create a diagram of a multivendor network. Which command must be configured on the Cisco devices so that the topology of the network can be mapped?

Options:

A.

Device(Config)#lldp run

B.

Device(Config)#cdp run

C.

Device(Config-if)#cdp enable

D.

Device(Config)#flow-sampler-map topology

Question 125

R1 has learned route 192.168.12.0/24 via IS-IS. OSPF, RIP. and Internal EIGRP Under normal operating conditions, which routing protocol is installed in the routing table?

Options:

A.

IS-IS

B.

RIP

C.

Internal EIGRP

D.

OSPF

Question 126

How do traditional campus device management and Cisco DNA Center device management differ in regards to deployment?

Options:

A.

Cisco DNA Center device management can deploy a network more quickly than traditional campus device management

B.

Traditional campus device management allows a network to scale more quickly than with Cisco DNA Center device management

C.

Cisco DNA Center device management can be implemented at a lower cost than most traditional campus device management options

D.

Traditional campus device management schemes can typically deploy patches and updates more quickly than Cisco DNA Center device management

Question 127

Refer to the exhibit.

If configuring a static default route on the router with the ip route 0.0.0.0 0.0.0.0 10.13.0.1 120 command how does the router respond?

Options:

A.

It ignores the new static route until the existing OSPF default route is removed

B.

It immediately replaces the existing OSPF route in the routing table with the newly configured static route

C.

It starts load-balancing traffic between the two default routes

D.

It starts sending traffic without a specific matching entry in the routing table to GigabitEthernet0/1

Question 128

What are two reasons for an engineer to configure a floating state route? (Choose two)

Options:

A.

to automatically route traffic on a secondary path when the primary path goes down

B.

to route traffic differently based on the source IP of the packet

C.

to enable fallback static routing when the dynamic routing protocol fails

D.

to support load balancing via static routing

E.

to control the return path of traffic that is sent from the router

Question 129

Refer to the exhibit.

Drag and drop the networking parameters from the left onto the correct values on the right.

Options:

Question 130

What is the function of a server?

Options:

A.

It transmits packets between hosts in the same broadcast domain.

B.

It provides shared applications to end users.

C.

It routes traffic between Layer 3 devices.

D.

It Creates security zones between trusted and untrusted networks

Question 131

Which technology must be implemented to configure network device monitoring with the highest security?

Options:

A.

IP SLA

B.

syslog

C.

NetFlow

D.

SNMPv3

Question 132

An engineer observes high usage on the 2.4GHz channels and lower usage on the 5GHz channels. What must be configured to allow clients to preferentially use 5GH2 access points?

Options:

A.

Re- Anchor Roamed Clients

B.

11ac MU-MIMO

C.

OEAP Split Tunnel

D.

Client Band Select

Question 133

What are two differences between optical-fiber cabling and copper cabling? (Choose two)

Options:

A.

Light is transmitted through the core of the fiber

B.

A BNC connector is used for fiber connections

C.

The glass core component is encased in a cladding

D.

Fiber connects to physical interfaces using Rj-45 connections

E.

The data can pass through the cladding

Question 134

A network engineer must configure the router R1 GigabitEthernet1/1 interface to connect to the router R2 GigabitEthernet1/1 interface. For the configuration to be applied the engineer must compress the address 2001:0db8:0000:0000:0500:000a:400F:583B. Which command must be issued on the interface?

Options:

A.

ipv6 address 2001:0db8::5: a: 4F 583B

B.

ipv6 address 2001:db8::500:a:400F:583B

C.

ipv6 address 2001 db8:0::500:a:4F:583B

D.

ipv6 address 2001::db8:0000::500:a:400F:583B

Question 135

What are two descriptions of three-tier network topologies? (Choose two)

Options:

A.

The core and distribution layers perform the same functions

B.

The access layer manages routing between devices in different domains

C.

The network core is designed to maintain continuous connectivity when devices fail.

D.

The core layer maintains wired connections for each host

E.

The distribution layer runs Layer 2 and Layer 3 technologies

Question 136

Which type of organization should use a collapsed-core architecture?

Options:

A.

large and requires a flexible, scalable network design

B.

large and must minimize downtime when hardware fails

C.

small and needs to reduce networking costs currently

D.

small but is expected to grow dramatically in the near future

Question 137

Refer to Exhibit.

Which action do the switches take on the trunk link?

Options:

A.

The trunk does not form and the ports go into an err-disabled status.

B.

The trunk forms but the mismatched native VLANs are merged into a single broadcast domain.

C.

The trunk does not form, but VLAN 99 and VLAN 999 are allowed to traverse the link.

D.

The trunk forms but VLAN 99 and VLAN 999 are in a shutdown state.

Question 138

Refer to the exhibit.

Between which zones do wireless users expect to experience intermittent connectivity?

Options:

A.

between zones 1 and 2

B.

between zones 2 and 5

C.

between zones 3 and 4

D.

between zones 3 and 6

Question 139

What event has occurred if a router sends a notice level message to a syslog server?

Options:

A.

A TCP connection has been torn down

B.

An ICMP connection has been built

C.

An interface line has changed status

D.

A certificate has expired.

Question 140

Which two minimum parameters must be configured on an active interface to enable OSPFv2 to operate? (Choose two)

Options:

A.

OSPF area

B.

OSPF MD5 authentication key

C.

iPv6 address

D.

OSPf process ID

E.

OSPf stub flag

Question 141

Two switches are connected and using Cisco Dynamic Trunking Protocol SW1 is set to Dynamic Desirable

What is the result of this configuration?

Options:

A.

The link is in a down state.

B.

The link is in an error disables state

C.

The link is becomes an access port.

D.

The link becomes a trunk port.

Question 142

Drag and drop the IPv6 address type characteristics from the left to the right.

Options:

Question 143

Drag and drop the functions of DHCP from the left onto any of the positions on the right Not all functions are used

Options:

Question 144

Refer to the exhibit.

Which switch becomes the root bridge?

Options:

A.

S1

B.

S2

C.

S3

D.

S4

Question 145

What is the function of a hub-and-spoke WAN topology?

Options:

A.

allows access restrictions to be implemented between subscriber sites.

B.

provides direct connections between subscribers

C.

supports Layer 2 VPNs

D.

supports application optimization

Question 146

Drag and drop the threat-mitigation techniques from the left onto the types of threat or attack they mitigate on the right.

Options:

Question 147

An engineer must configure the IPv6 address 2001:0db8:0000:0000:0700:0003:400F:572B on the serial0/0 interface of the HQ router and wants to compress it for easier configuration. Which command must be issued on the router interface?

Options:

A.

ipv6 address 2001:db8::700:3:400F:572B

B.

ipv6 address 2001:db8:0::700:3:4F:572B

C.

ipv6 address 2001:Odb8::7:3:4F:572B

D.

ipv6 address 2001::db8:0000::700:3:400F:572B

Question 148

What is the default behavior of a Layer 2 switch when a frame with an unknown destination MAC address is received?

Options:

A.

The Layer 2 switch drops the received frame

B.

The Layer 2 switch floods packets to all ports except the receiving port in the given VLAN.

C.

The Layer 2 switch sends a copy of a packet to CPU for destination MAC address learning.

D.

The Layer 2 switch forwards the packet and adds the destination MAC address to its MAC address table

Question 149

Refer to the exhibit.

A network engineer must configured communication between PC A and the File Server. To prevent interruption for any other communications, which command must be configured?

Options:

A.

Switch trunk allowed vlan 12

B.

Switchport trunk allowed vlan none

C.

Switchport trunk allowed vlan add 13

D.

Switchport trunk allowed vlan remove 10-11

Question 150

A network engineer must back up 20 network router configurations globally within a customer environment. Which protocol allows the engineer to perform this function using the Cisco IOS MIB?

Options:

A.

CDP

B.

SNMP

C.

SMTP

D.

ARP

Question 151

Refer to the exhibit.

What commands are needed to add a subinterface to Ethernet0/0 on R1 to allow for VLAN 20, with IP address 10.20.20.1/24?

Options:

A.

R1(config)#interface ethernet0/0R1(config)#encapsulation dot1q 20R1(config)#ip address 10.20.20.1 255.255.255.0

B.

R1(config)#interface ethernet0/0.20R1(config)#encapsulation dot1q 20R1(config)#ip address 10.20.20.1 255.255.255.0

C.

R1(config)#interface ethernet0/0.20R1(config)#ip address 10.20.20.1 255.255.255.0

D.

R1(config)#interface ethernet0/0R1(config)#ip address 10.20.20.1 255.255.255.0

Question 152

A frame that enters a switch fails the Frame Check Sequence. Which two interface counters are incremented? (Choose two)

Options:

A.

runts

B.

giants

C.

frame

D.

CRC

E.

input errors

Question 153

Which device performs stateful inspection of traffic?

Options:

A.

firewall

B.

switch

C.

access point

D.

wireless controller

Question 154

Which IPv6 address block sends packets to a group address rather than a single address?

Options:

A.

2000::/3

B.

FC00::/7

C.

FE80::/10

D.

FF00::/8

Question 155

Refer to the exhibit.

Which password must an engineer use to enter the enable mode?

Options:

A.

adminadmin123

B.

default

C.

testing 1234

D.

cisco123

Question 156

Refer to the exhibit.

PC1 is trying to ping PC3 for the first time and sends out an ARP to S1 Which action is taken by S1?

Options:

A.

It forwards it out G0/3 only

B.

It is flooded out every port except G0/0.

C.

It drops the frame.

D.

It forwards it out interface G0/2 only.

Question 157

On workstations running Microsoft Windows, which protocol provides the default gateway for the device?

Options:

A.

DHCP

B.

STP

C.

SNMP

D.

DNS

Question 158

Which command entered on a switch configured with Rapid PVST* listens and learns for a specific time period?

Options:

A.

switch(config)#spanning-tree vlan 1 max-age 6

B.

switch(config)#spanning-tree vlan 1 hello-time 10

C.

switch(config)#spanning-tree vlan 1 priority 4096

D.

switch(config)#spanning-tree vlan 1 forward-time 20

Question 159

Drag and drop the characteristics of network architectures from the left onto the type of architecture on the right.

Options:

Question 160

Refer to the exhibit.

What is the result if Gig1/11 receives an STP BPDU?

Options:

A.

The port transitions to STP blocking

B.

The port transitions to the root port

C.

The port immediately transitions to STP forwarding.

D.

The port goes into error-disable state

Question 161

What facilitates a Telnet connection between devices by entering the device name?

Options:

A.

SNMP

B.

DNS lookup

C.

syslog

D.

NTP

Question 162

Refer to the exhibit.

Which switch in this configuration will be elected as the root bridge?

Options:

A.

SW1

B.

SW2

C.

SW3

D.

SW4

Question 163

After installing a new Cisco ISE server, which task must the engineer perform on the Cisco WLC to connect wireless clients on a specific VLAN based on their credentials?

Options:

A.

Enable the allow AAA Override

B.

Enable the Even: Driven RRM.

C.

Disable the LAG Mode or Next Reboot.

D.

Enable the Authorized MIC APs against auth-list or AAA.

Question 164

What is a benefit of VRRP?

Options:

A.

It provides traffic load balancing to destinations that are more than two hops from the source.

B.

It provides the default gateway redundancy on a LAN using two or more routers.

C.

It allows neighbors to share routing table information between each other.

D.

It prevents loops in a Layer 2 LAN by forwarding all traffic to a root bridge, which then makes the final forwarding decision.

Question 165

How are VLAN hopping attacks mitigated?

Options:

A.

enable dynamic ARP inspection

B.

manually implement trunk ports and disable DTP

C.

activate all ports and place in the default VLAN

D.

configure extended VLANs

Question 166

Aside from discarding, which two states does the switch port transition through while using RSTP (802.1w)? (Choose two)

Options:

A.

listening

B.

blocking

C.

forwarding

D.

learning

E.

speaking

Question 167

Refer to the exhibit Routers R1 and R2 have been configured with their respective LAN interfaces The two circuits are operational and reachable across WAN Which command set establishes failover redundancy if the primary circuit goes down?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 168

What are network endpoints?

Options:

A.

act as routers to connect a user to the service prowler network

B.

a threat to the network if they are compromised

C.

support inter-VLAN connectivity

D.

enforce policies for campus-wide traffic going to the internet

Question 169

Drag and drop the AAA functions from the left onto the correct AAA services on the right

Options:

Question 170

Which two actions are performed by the Weighted Random Early Detection mechanism? (Choose two)

Options:

A.

It drops lower-priority packets before it drops higher-priority packets

B.

It can identify different flows with a high level of granularity

C.

It guarantees the delivery of high-priority packets

D.

It can mitigate congestion by preventing the queue from filling up

E.

it supports protocol discovery

Question 171

Drag drop the descriptions from the left onto the correct configuration-management technologies on the right.

Options:

Question 172

How do TCP and UDP differ in the way that they establish a connection between two endpoints?

Options:

A.

TCP uses synchronization packets, and UDP uses acknowledgment packets.

B.

UDP uses SYN, SYN ACK and FIN bits in the frame header while TCP uses SYN, SYN ACK and ACK bits

C.

UDP provides reliable message transfer and TCP is a connectionless protocol

D.

TCP uses the three-way handshake and UDP does not guarantee message delivery

Question 173

What are two roles of the Dynamic Host Configuration Protocol (DHCP)? (Choose two)

Options:

A.

The DHCP server offers the ability to exclude specific IP addresses from a pool of IP addresses

B.

The DHCP client can request up to four DNS server addresses

C.

The DHCP server assigns IP addresses without requiring the client to renew them

D.

The DHCP server leases client IP addresses dynamically.

E.

The DHCP client maintains a pool of IP addresses it can assign.

Question 174

Drag and drop the QoS congestion management terms from the left onto the description on the right.

Options:

Question 175

Which WAN access technology is preferred for a small office / home office architecture?

Options:

A.

broadband cable access

B.

frame-relay packet switching

C.

dedicated point-to-point leased line

D.

Integrated Services Digital Network switching.

Question 176

Which API is used in controller-based architectures to interact with edge devices?

Options:

A.

overlay

B.

northbound

C.

underlay

D.

southbound

Question 177

Refer to the exhibit.

The network administrator wants VLAN 67 traffic to be untagged between Switch 1 and Switch 2 while all other VLANs are to remain tagged.

Which command accomplishes this task?

Options:

A.

switchport access vlan 67

B.

switchport trunk allowed vlan 67

C.

switchport private-vlan association host 67

D.

switchport trunk native vlan 67

Question 178

What is a recommended approach to avoid co-channel congestion while installing access points that use the 2.4 GHz frequency?

Options:

A.

different nonoverlapping channels

B.

different overlapping channels

C.

one overlapping channel

D.

one nonoverlapping channel

Question 179

Refer to the exhibit.

When PC-A sends traffic to PC-B, which network component is in charge of receiving the packet from PC-A verifying the IP addresses, and forwarding the packet to PC-B?

Options:

A.

Layer 2 switch

B.

Router

C.

Load balancer

D.

firewall

Question 180

Drag and drop the IPv4 network subnets from the left onto the correct usable host ranges on the right

Options:

Question 181

How does QoS optimize voice traffic?

Options:

A.

reducing bandwidth usage

B.

by reducing packet loss

C.

by differentiating voice and video traffic

D.

by increasing jitter

Question 182

which purpose does a northbound API serve in a controller-based networking architecture?

Options:

A.

communicates between the controller and the physical network hardware

B.

reports device errors to a controller

C.

generates statistics for network hardware and traffic

D.

facilitates communication between the controller and the applications

Question 183

Which command on a port enters the forwarding state immediately when a PC is connected to it?

Options:

A.

switch(config)#spanning-tree portfast default

B.

switch(config)#spanning-tree portfast bpduguard default

C.

switch(config-if)#spanning-tree portfast trunk

D.

switch(config-if)#no spanning-tree portfast

Question 184

What are two fundamentals of virtualization? (choose two)

Options:

A.

The environment must be configured with one hypervisor that serves solely as a network manager to monitor SNMP traffic

B.

It allows logical network devices to move traffic between virtual machines and the rest of the physical network

C.

It allows multiple operating systems and applications to run independently on one physical server.

D.

It allows a physical router to directly connect NICs from each virtual machine into the network

E.

It requires that some servers, virtual machines and network gear reside on the Internet

Question 185

How will Link Aggregation be Implemented on a Cisco Wireless LAN Controller?

Options:

A.

One functional physical port is needed to pass client traffic.

B.

The EthernetChannel must be configured in "mode active".

C.

When enabled, the WLC bandwidth drops to 500 Mbps.

D.

To pass client traffic, two or more ports must be configured.

Question 186

Which mode must be used to configure EtherChannel between two switches without using a negotiation protocol?

Options:

A.

on

B.

auto

C.

active

D.

desirable

Question 187

What is an advantage of Cisco DNA Center versus traditional campus device management?

Options:

A.

It supports numerous extensibility options including cross-domain adapters and third-party SDKs.

B.

It supports high availability for management functions when operating in cluster mode.

C.

It enables easy autodiscovery of network elements m a brownfield deployment.

D.

It is designed primarily to provide network assurance.

Question 188

Refer to the exhibit Router R1 Fa0/0 is unable to ping router R3 Fa0'1. Which action must be taken in router R1 to help resolve the configuration issue?

Options:

A.

set the default network as 20.20.20.0/24

B.

set the default gateway as 20.20.20.2

C.

configure a static route with Fa0/1 as the egress interface to reach the 20.20.20.0/24 network

D.

configure a static route with 10.10.10.2 as the next hop to reach the 20.20.20.0/24 network

Question 189

What is an appropriate use for private IPv4 addressing?

Options:

A.

on the public-facing interface of a firewall

B.

to allow hosts inside to communicate in both directions with hosts outside the organization

C.

on internal hosts that stream data solely to external resources

D.

on hosts that communicates only with other internal hosts

Question 190

Which resource is able to be shared among virtual machines deployed on the same physical server?

Options:

A.

disk

B.

applications

C.

VM configuration file

D.

operating system

Question 191

Which command prevents passwords from being stored in the configuration as plain text on a router or switch?

Options:

A.

enable secret

B.

service password-encryption

C.

username Cisco password encrypt

D.

enable password

Question 192

In software-defined architecture, which place handles switching for traffic through a Cisco router?

Options:

A.

Control

B.

Management

C.

Data

D.

application

Question 193

Which attribute does a router use to select the best path when two or more different routes to the same destination exist from two different routing protocols.

Options:

A.

dual algorithm

B.

metric

C.

administrative distance

D.

hop count

Question 194

Refer to Exhibit.

The loopback1 interface of the Atlanta router must reach the loopback3 interface of the Washington router. Which two static host routes must be configured on the NEW York router? (Choose two)

Options:

A.

ipv6 route 2000::1/128 2012::1

B.

ipv6 route 2000::3/128 2023::3

C.

ipv6 route 2000::3/128 s0/0/0

D.

ipv6 route 2000::1/128 2012::2

E.

ipv6 route 2000::1/128 s0/0/1

Question 195

Which function does the range of private IPv4 addresses perform?

Options:

A.

allows multiple companies to each use the same addresses without conflicts

B.

provides a direct connection for hosts from outside of the enterprise network

C.

ensures that NAT is not required to reach the internet with private range addressing

D.

enables secure communications to the internet for all external hosts

Question 196

How do TCP and UDP differ in the way they provide reliability for delivery of packets?

Options:

A.

TCP is a connectionless protocol that does not provide reliable delivery of data, UDP is a connection-oriented protocol that uses sequencing to provide reliable delivery.

B.

TCP does not guarantee delivery or error checking to ensure that there is no corruption of data UDP provides message acknowledgement and retransmits data if lost.

C.

TCP provides flow control to avoid overwhelming a receiver by sending too many packets at once, UDP sends packets to the receiver in a continuous stream without checking for sequencing

D.

TCP uses windowing to deliver packets reliably; UDP provides reliable message transfer between hosts by establishing a three-way handshake

Question 197

What is a similarity between OM3 and OM4 fiber optic cable?

Options:

A.

Both have a 50 micron core diameter

B.

Both have a 9 micron core diameter

C.

Both have a 62.5 micron core diameter

D.

Both have a 100 micron core diameter

Question 198

Refer to the exhibit.

How must router A be configured so that it only sends Cisco Discovery Protocol Information to router C?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 199

Which CRUD operation modifies an existing table or view?

Options:

A.

read

B.

create

C.

replace

D.

update

Question 200

Several new coverage cells are required to improve the Wi-Fi network of an organization. Which two standard designs are recommended? (choose two.)

Options:

A.

5GHz provides increased network capacity with up to 23 nonoveriapping channels.

B.

For maximum throughput, the WLC is configured to dynamically set adjacent access points to the same channel.

C.

5GHz channel selection requires an autonomous access point.

D.

Adjacent cells with overlapping channels use a repeater access point.

E.

Cells that overlap one another are configured to use nonoveriapping channels.

Question 201

What is a DNS lookup operation?

Options:

A.

DNS server pings the destination to verify that it is available

B.

serves requests over destination port 53

C.

DNS server forwards the client to an alternate IP address when the primary IP is down

D.

responds to a request for IP address to domain name resolution to the DNS server

Question 202

What is a function of Wireless LAN Controller?

Options:

A.

register with a single access point that controls traffic between wired and wireless endpoints.

B.

use SSIDs to distinguish between wireless clients.

C.

send LWAPP packets to access points.

D.

monitor activity on wireless and wired LANs

Question 203

What is a function of the Cisco DNA Center Overall Health Dashboard?

Options:

A.

It provides a summary of the top 10 global issues.

B.

It provides detailed activity logging for the 10 devices and users on the network.

C.

It summarizes the operational status of each wireless devise on the network.

D.

It summarizes daily and weekly CPU usage for servers and workstations in the network.

Question 204

Which WAN topology provides a combination of simplicity quality, and availability?

Options:

A.

partial mesh

B.

full mesh

C.

point-to-point

D.

hub-and-spoke

Question 205

Which technology allows for multiple operating systems to be run on a single host computer?

Options:

A.

virtual routing and forwarding

B.

network port ID visualization

C.

virtual device contexts

D.

server visualization

Question 206

When implementing a router as a DHCP server, which two features must be configured'? (Choose two)

Options:

A.

relay agent information

B.

database agent

C.

address pool

D.

smart-relay

E.

manual bindings

Question 207

How does HSRP provide first hop redundancy?

Options:

A.

It load-balances traffic by assigning the same metric value to more than one route to the same destination m the IP routing table.

B.

It load-balances Layer 2 traffic along the path by flooding traffic out all interfaces configured with the same VLAN.

C.

It forwards multiple packets to the same destination over different routed links n the data path

D.

It uses a shared virtual MAC and a virtual IP address to a group of routers that serve as the default gateway for hosts on a LAN

Question 208

Why choose Cisco DNA Center for automated lifecycle management?

Options:

A.

To perform upgrades without service interruption

B.

To provide fast and accurate deployment of patches and updates

C.

To allow SSH access to all nodes in the network.

D.

To provide software redundancy in the network.

Question 209

Drag and drop the TCP or UDP details from the left onto their corresponding protocols on the right.

Options:

Question 210

Refer to the exhibit.

Which configuration establishes a Layer 2 LACP EtherChannel when applied to both switches?

Options:

A.

Interface range G1/1 – 1/3 switchport mode trunk channel-group 1 mode active no shutdown

B.

Interface range G1/1 – 1/3 switchport mode access channel-group 1 mode passive no shutdown

C.

Interface range G1/1 – 1/3 switchport mode trunkchannel-group 1 mode desirableno shutdown

D.

Interface range G1/1 – 1/3 switchport mode access channel-group 1 mode on no shutdown

Question 211

Refer to the exhibit Routers R1 R2 and R3 use a protocol to identify their neighbors' IP addresses hardware platforms, and software versions. A network engineer must configure R2 to avoid sharing any neighbor information with R3, and maintain its relationship with R1. What action meets this requirement?

Options:

A.

Configure the no cdp enable command on gO/2.

B.

Configure the no cdp run command globally.

C.

Configure the no lldp run command globally.

D.

Configure the no lldp receive command on gQV1.

Question 212

It work security team noticed that an increasing number of employees are becoming victims of phishing attacks. Which security program should be implemented to mitigate the problem?

Options:

A.

email system patches

B.

physical access control

C.

software firewall enabled on all PCs

D.

user awareness training

Question 213

Refer to the exhibit.

An engineer must configure a floating static route on an external EIGRP network. The destination subnet is the /29 on the LAN Interface of R86. Which command must be executed on R14?

Options:

A.

ip route 10.80.65.0.255.255.248.0.10.73.65.66.1

B.

ip route 10.80.65.0.255.255.255..240 fa0/1 89

C.

ip route 10.80.65.0.255.255.248.0.10.73.65.66.171

D.

ip route 10.80.65.0.0.0.224.10.80.65.0. 255

Question 214

Which is a fact related to FTP?

Options:

A.

It uses block numbers to identify and mitigate data-transfer errors

B.

It always operates without user authentication

C.

It relies on the well-known UDP port 69.

D.

It uses two separate connections for control and data traffic

Question 215

Which interface is used for out-of-band management on a WLC?

Options:

A.

dynamic

B.

service port

C.

virtual

D.

management

Question 216

What are two characteristics of a controller-based network? (Choose two.)

Options:

A.

It uses Telnet to report system issues

B.

It uses northbound and southbound APIs to communicate between architectural layers

C.

It decentralizes the control plane, which allows each device to make its own forwarding decisions

D.

It moves the control plane to a central point

E.

The administrator can make configuration updates from the CLI

Question 217

Which group of channels in the 802.1ib/g/n/ac/ax 2.4 GHz frequency Bands are nonoverlapping channels?

Options:

A.

channels 1, 5, and 10

B.

channels 1,6, and 11

C.

channels 1,5, and 11

D.

channels 1,6, and 10

Question 218

Which two wireless security stewards use Counter Mode Cipher Block Chaining Message Authentication Code Protocol for encryption and data integrity'? (Choose two.)

Options:

A.

WPA2

B.

WPA3

C.

Wi-Fi 6

D.

WEP

E.

WPA

Question 219

Refer to the exhibit.

Refer to the exhibit. The IPv6 address for the LAN segment on router R1 must be configured using the EUI-64 format. When configured which ipv6 address is produced by the router?

Options:

A.

2001:db8:1a44:41a4:C801:BEFF:FE4A:1

B.

2001:db8:1a44:41a4:C081:BFFF:FE4A:1

C.

2001:db8:1a44:41a4:4562:098F:FE36:1

D.

2001:db8:1a44:41a4:C800:BAFE:FF00:1

Question 220

Drag and drop the characteristic from the left onto the IPv6 address type on the right.

Options:

Question 221

Refer to the exhibit. All routers in the network are configured conrectly, and the expected routes are being exchanged among the routers. Which set of routes are leamed from neighbors and installed on router 2?

Options:

A.

10.129.9.0/2310.139.2.0/3010.2.191.0/3010.129.9.0/25

B.

10.129.9.0/2310.40.1.0/3010.2.191.0/3010.129.9.0/25

C.

10.40.1.0/3010.139.2.0/3010.2.191.0/3010.129.9.0/25

D.

10.129.9.0/2310.139.2.0/3010.129.9.0/2510.22.1.0/24

Question 222

Why would a network administrator choose to implement automation in a network environment?

Options:

A.

To simplify the process of maintaining a consistent configuration state across all devices

B.

To centralize device information storage

C.

To implement centralized user account management

D.

To deploy the management plane separately from the rest of the network Answer: A

Question 223

Refer to the exhibit.

What is the issue with the interface GigabitEthernet0/0/1?

Options:

A.

Port security

B.

High throughput

C.

Cable disconnect

D.

duplex mismatch

Question 224

Refer to the exhibit.

What does route 10.0.1.3/32 represent in the routing table?

Options:

A.

the 10.0.0.0 network

B.

a single destination address

C.

the source 10.0.1.100

D.

all hosts in the 10.0.1.0 subnet

Question 225

Refer to the exhibit.

Switch AccSw2 has just been added to the network along with PC2. All VLANs have been implemented on AccSw2. How must the ports on AccSw2 be configured to establish Layer 2 connectivity between PC1 and PC2?

Options:

A.

B.

B.

C.

C.

D.

D.

Question 226

Two switches have been implemented and all interfaces are at the default configuration level. A trunk link must be implemented between two switches with these requirements:

• using an industry-standard trunking protocol

• permitting VLANs 1 -10 and denying other VLANs

How must the interconnecting ports be configured?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 227

Drag and drop the IPv6 address description from the left onto the IPv6 address types on the right. Not all options are used.

Options:

Question 228

What is a reason to configure a trunk port that connects to a WLC distribution port?

Options:

A.

Eliminate redundancy with a link failure in the data path.

B.

Allow multiple VLAN to be used in the data path.

C.

Provide redundancy if there is a link failure for out-of-band management.

D.

Permit multiple VLANs to provide out-of-band management.

Question 229

A switch is a forwarding a frame out of an interfaces except the interface that received the frame. What is the technical term for this process?

Options:

A.

ARP

B.

CDP

C.

flooding

D.

multicast

Question 230

How do traditional campus device management and Cisco DNA Center device management differ in regards to deployment?

Options:

A.

Traditional campus device management schemes typically deploy patches and updates quicker than Cisco DNA Center device management.

B.

Cisco DNA Center device management is implemented at a lower cost than most traditional campus device management options.

C.

Traditional campus device management allows a network to scale quicker than using Cisco DNA Center device management.

D.

Cisco DNA Center device management deploys a network faster than traditional campus device management.

Question 231

A network engineer is configuring a new router at a branch office. The router is connected to an upstream WAN network that allows the branch to communicate with the head office. The central time server with IP address 172.24.54.8 is located behind a firewall at the head office. Which command must the engineer configure so that the software clock of the new router synchronizes with the time server?

Options:

A.

ntp master 172.24.54.8

B.

ntp client 172.24.54.8

C.

ntp peer 172.24.54.8

D.

ntp server 172.24.54.8

Question 232

Refer to the exhibit. With a reference bandwidth of 100 Gb on all routers, which path does router Y use to get to network 192.168.1.0/24?

Options:

A.

router C > D > A > B > F

B.

router C > D > A > F

C.

router E > F

D.

router E > B > F

Question 233

An engineer has configured the domain name, user name, and password on the local router. What is the next step to complete the configuration tor a Secure Shell access RSA key?

Options:

A.

crypto key Import rsa pem

B.

crypto key pubkey-chain rsa

C.

crypto key generate rsa

D.

crypto key zeroize rsa

Question 234

What is the function of northbound API?

Options:

A.

It upgrades software and restores files.

B.

It relies on global provisioning and configuration.

C.

It supports distributed processing for configuration.

D.

It provides a path between an SDN controller and network applications.

Question 235

What is a functionality of the control plane in the network?

Options:

A.

It exchanges topology information with other routers.

B.

It forwards traffic to the next hop.

C.

It looks up an egress interface in the forwarding information base.

D.

It provides CLI access to the network device.

Question 236

A network analyst is tasked with configuring the date and time on a router using EXEC mode. The date must be set to January 1. 2020 and the time must be set to 12:00 am. Which command should be used?

Options:

A.

clock summer-time recurring

B.

clock timezone

C.

clock summer-time date

D.

clock set

Question 237

Refer to the exhibit.

Router R14 is in the process of being configured. Which configuration must be used to establish a host route to PC 10?

Options:

A.

ip route 10.80.65.10 255.255.255.254 10.80.65.1

B.

ip route 10.8065.10 255.255.255.255 10.73.65.66

C.

ip route 1073.65.65 255.0.0.0 10.80.65.10

D.

ip route 10.73.65.66 0.0.0.255 10.80.65.10

Question 238

Which channel-group mode must be configured when multiple distribution interfaces connected to a WLC are bundled?

Options:

A.

Channel-group mode passive.

B.

Channel-group mode on.

C.

Channel-group mode desirable.

D.

Channel-group mode active.

Question 239

Refer to the exhibit. Company A wants to use a RADIUS server to service all user and device authentication attempts with a more secure and granular authentication approach. Not all client devices support dot1x authentication. Which two configuration changes must be made to accomplish the task? (Choose two.)

Options:

A.

Enable AutoConfig IPSK under the Layer 2 tab.

B.

Select Authentication server under the AAA servers tab.

C.

Configure Enterprise Security type under the Layer 2 tab.

D.

Set Authentication under the Layer 3 tab.

E.

Enable WPA2 Policy under the Layer 2 tab.

Question 240

Refer to the exhibit.

An engineer is checking the routing table in the main router to identify the path to a server on the network. Which route does the router use to reach the server at 192.168.2.2?

Options:

A.

S 192.168.0.0/20 [1/0] via 10.1.1.1

B.

S 192.168.2.0/29 [1/0] via 10.1.1.1

C.

S 192.168.2.0/28 [1/0] via 10.1.1.1

D.

S 192.168.1.0/30 [1/0] via 10.1.1.1

Question 241

Refer to the exhibit.

Which action must be taken so that neighbofing devices rapidly discover switch Cat9300?

Options:

A.

Configure the cdp timer 10 command on switch Cat9300.

B.

Enable portfast on the ports that connect to neighboring devices.

C.

Configure the cdp holdtime 10 command on switch Cat9300.

D.

Configure the cdp timer 10 command on the neighbors of switch Cat9300.

Question 242

What are two advantages of implementing a controller-based architecture instead of a traditional network architecture? (Choose two.)

Options:

A.

It allows for seamless connectivity to virtual machines.

B.

It supports complex and high-scale IP addressing schemes.

C.

It enables configuration task automation.

D.

It provides increased scalability and management options.

E.

It increases security against denial-of-service attacks.

Question 243

Refer to the exhibit.

How many objects are present in the given JSON-encoded data?

Options:

A.

one

B.

four

C.

seven

D.

nine

Question 244

What is the benefit of using FHRP (First Hop Redundancy Protocol)?

Options:

A.

Reduced ARP traffic on the network

B.

Balancing traffic across multiple gateways in proportion to their loads

C.

Reduced management overhead on network routers

D.

Higher degree of availability

Question 245

Refer to the exhibit. Four load-balancing servers are reachable through this router; however, the company is removing all static and default routes on the router.

Server 1 - 10.12.14.14

Server 2 - 192.168.4.4

Server 3 - 209.165.200.5

Server 4 - 209.165.201.26

Which server will handle all traffic after the policy changes take effect?

Options:

A.

Server 1 - 10.12.14.14

B.

Server 2 - 192.168.4.4

C.

Server 3 - 209.165.200.5

D.

Server 4 - 209.165.201.26

Question 246

Refer to the exhibit.

The loopback1 interface of the Atlanta router must reach the lookback3 interface of the Washington router.

Options:

A.

ipv6 route 2000::1/128 2012::2

B.

ipv6 route 2000::1/128 2012::1

C.

ipv6 route 2000:3 123 s0/0/0

D.

ipv6 route 2000::3/128 2023::3

E.

ipv6 route 2000::1/128 s0/0/1

Question 247

Refer to the exhibit.

A network engineer must provide configured IP addressing details to investigate a firewall rule Issue. Which subnet and mask Identify what is configured on the en0 interface?

Options:

A.

10.8.0.0/16

B.

10.8.64.0/18

C.

10.8.128.0/19

D.

10.8.138.0/24

Question 248

A Cisco engineer notices thai two OSPF neighbors are connected using a crossover Ethernet cable. The neighbors are taking too long to become fully adjacent. Which command must be issued under the interface configuration on each router to reduce the time required for the adjacency to reach the FULL state?

Options:

A.

ip ospf network broadcast

B.

ip ospf dead-interval 40

C.

ip ospf network point-to-point

D.

ip ospf priority 0

Question 249

Which enhancements were implemented as part of WPA3?

Options:

A.

802.1x authentication and AES-128 encryption

B.

TKIP encryption improving WEP and per-packet keying

C.

AES-64 m personal mode and AES-128 in enterprise mode

D.

forward secrecy and SAE in personal mode for secure initial key exchange

Question 250

Refer to the exhibit.

What is the prefix length for the route that router1 will use to reach host A?

Options:

A.

/25

B.

/27

C.

/28

D.

/29

Question 251

Why is TCP desired over UDP for application that require extensive error checking, such as HTTPS?

Options:

A.

UDP operates without acknowledgments, and TCP sends an acknowledgment for every packet received.

B.

UDP reliably guarantees delivery of all packets, and TCP drops packets under heavy load.

C.

UDP uses flow control mechanisms for the delivery of packets, and TCP uses congestion control for efficient packet delivery.

D.

UDP uses sequencing data tor packets to arrive in order, and TCP offers trie capability to receive packets in random order.

Question 252

Refer to Itie exhibit

A network engineer started to configure port security on a new switch. These requirements must be met:

* MAC addresses must be learned dynamically

* Log messages must be generated without disabling the interface when unwanted traffic is seen

Which two commands must be configured to complete this task"? (Choose two)

Options:

A.

SW(ccnfig-if)=switchport port-security mac-address sticky

B.

SW(confKj-if)=switchport port-security violation restrict

C.

SW(config.if)sswitchport port-security mac-address 0010.7B84.45E6

D.

SW(config-if)aswitchport port-security maximum 2

E.

SW(ccnfig-if)=switchport port-security violation shutdown

Question 253

Refer to the exhibit.

In which structure does the word "warning" directly reside?

Options:

A.

array

B.

object

C.

Boolean

D.

string

Question 254

What is used as a solution for protecting an individual network endpoint from attack?

Options:

A.

Router

B.

Wireless controller

C.

Anti software

D.

Cisco DNA Center

Question 255

Drag and drop the characteristic from the left onto the IPv6 address type on the right.

Options:

Question 256

What is the role of SNMP in the network?

Options:

A.

to monitor network devices and functions using a TCP underlay that operates on the presentation layer

B.

to collect data directly from network devices using an SSL underlay that operates on the transport layer

C.

to monitor and manage network devices using a UDP underlay that operates on the application layer

D.

to collect telemetry and critical information from network devices using an SSH underlay that operates on the network layer

Question 257

Which event has occurred if a router sends a notice level message to a syslog server?

Options:

A.

An ICMP connection has been built

B.

A certificate has expired

C.

An interface line has changed status

D.

A TCP connection has been torn down

Question 258

What are two benefits for using private IPv4 addressing? (Choose two.)

Options:

A.

They alleviate the shortage of public IPv4 addresses.

B.

They supply redundancy in the case of failure.

C.

They offer Internet connectivity to endpoints on private networks.

D.

They allow for Internet access from IoT devices.

E.

They provide a layer of security from Internet threats.

Question 259

What is a DHCP client?

Options:

A.

a server that dynamically assigns IP addresses to hosts

B.

a router that statically assigns IP addresses to hosts

C.

a host that is configured to request an IP address automatically

D.

a workstation that requests a domain name associated with its IP address

Question 260

Refer to the exhibit. Drag and drop the subnet masks from the left onto the corresponding subnets on the right. Not all subnet masks used.

Options:

Question 261

An engineer must configure a core router with a floating static default route to the backup router at 10.200.0.2.

Options:

Question 262

An engineer must configure neighbor discovery between the company router and an ISP

What is the next step to complete the configuration if the ISP uses a third-party router?

Options:

A.

Enable LLDP globally.

B.

Disable CDP on gi0/0.

C.

Enable LLDP TLVs on the ISP router.

D.

Disable auto-negotiation.

Question 263

How does network automation help reduce network downtime?

Options:

A.

Changes can be implemented in parallel across multiple devices at once, which increases the speed of the change rate.

B.

By using automation platforms with intent-based configuration, all changes are checked for possible outages before being implemented.

C.

Emails can be generated based on when a network admin performs a network change, which increases visibility.

D.

Configuration templates and testing can be built into implementation, which increases the success rate of a network change.

Question 264

SW1 supports connectivity for a lobby conference room and must be secured. The engineer must limit the connectivity from PCI lo ma SW1 and SW2 network. The MAC addresses allowed must be Limited to two. Which configuration secures the conference room connectivity?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 265

An engineer is configuring switch SW1 to act an NTP server when all upstream NTP server connectivity fails. Which configuration must be used?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 266

Refer to the exhibit.

A network engineer configures the CCNA WLAN so that clients must authenticate hourly and to limit the number of simultaneous connections to the WLAN to Which two actions complete this configuration? (Choose two.)

Options:

A.

Enable the Enable Session Timeout option and set the value to 3600.

B.

Set the Maximum Allowed Clients value to 10.

C.

Enable the Client Exclusion option and set the value to 3600.

D.

Enable the Wi-Fi Direct Clients Policy option.

E.

Set the Maximum Allowed Clients Per AP Radio value to 10.

Question 267

What provides connection redundancy increased bandwidth and load sharing between a wireless LAN controller and a Layer 2 switch?

Options:

A.

VLAN trunking

B.

tunneling

C.

first hop redundancy

D.

link aggregation

Question 268

When should an engineer implement a collapsed-core architecture?

Options:

A.

for small networks with minimal need for growth

B.

the access and distribution layers must be on the same device

C.

for large networks that are connected to multiple remote sites

D.

only when using VSS technology

Question 269

What are two reasons a switch experiences frame flooding? (Choose two.)

Options:

A.

A defective patch cable is connected to the switch port

B.

Topology changes are occurring within spanning-tree

C.

An aged MAC (able entry is causing excessive updates

D.

Port-security is configured globally

E.

The forwarding table has overflowed

Question 270

Options:

Question 271

Drag and drop the characteristic from the left onto the IPv6 address type on the right.

Options:

Question 272

What is the purpose of classifying network traffic in QoS?

Options:

A.

services traffic according to its class

B.

identifies the type of traffic that will receive a particular treatment

C.

writes the class identifier of a packet to a dedicated field in the packet header

D.

configures traffic-matching rules on network devices

Question 273

Which IPv6 address range is suitable for anycast addresses for distributed services such DHCP or DNS?

Options:

A.

FF00:1/12

B.

2001:db8:0234:ca3e::1/128

C.

2002:db84:3f37:ca98:be05:8/64

D.

FE80::1/10

Question 274

Refer to the exhibit.

A packet sourced from 10.10.10.1 is destined for 10.10.8.14. What is the subnet mask of the destination route?

Options:

A.

255.255.254.0

B.

255.255.255.240

C.

255.255.255.248

D.

255.255.255.252

Question 275

Which interface enables communication between a program on the controller and a program on the networking devices?

Options:

A.

northbound interface

B.

software virtual interface

C.

southbound interface

D.

tunnel Interface

Question 276

Drag and drop the statements about access-point modes from the left onto the corresponding modes on the right.

Options:

Question 277

Which action prevents debug messages from being sent via syslog while allowing other messages when an abnormally high number of syslog messages are generated by a device with the debug process turned on?

Options:

A.

Use an access list to filter out the syslog messages.

B.

Turn off the logging monitor in global configuration mode.

C.

Disable logging to the console.

D.

Set the logging trap severity level to informational.

Question 278

Refer to the exhibit. A secondary route is required on router R1 to pass traffic to the LAN network on R2 if the primary link fails. Which command must be entered to configure the router?

Options:

A.

ip route 10.0.2.0 255.255.255.240 10.0.0.7 92

B.

ip route 10.0.2.0 255.255.255.248 10.0.0.6 91

C.

ip route 10.0.2.0 256.255.255.240 10.0.0.6 91

D.

ip route 10.0.2.0 255.255.255.248 null0 93

Question 279

Refer to the exhibit. VLAN 23 is being implemented between SW1 and SW2. The command show interface ethernet0/0 switchport has been issued on SW1. Ethernet0/0 on SW1 is the uplink to SW2. Which command when entered on the uplink interface allows PC 1 and PC 2 to communicate without impact to the communication between PC 11 and PC 12?

Options:

A.

switchport trunk allowed vlan 2-1001

B.

switchport trunk allowed vlan add 23

C.

switchport trunk allowed vlan 23

D.

switchport trunk allowed vlan 22-23

Question 280

Which technology allows for logical Layer 3 separation on physical network equipment?

Options:

A.

Virtual Route Forwarding

B.

Virtual Switch System

C.

IPsec Transport Mode

D.

Time Division Multiplexer

Question 281

Which AP mode wirelessly connects two separate network segments each set up within a different campus building?

Options:

A.

mesh

B.

local

C.

bridge

D.

point-to-point

Question 282

Why are API keys used to enforce rate limiting?

Options:

A.

to uniquely identify clients to monitor their usage patterns

B.

to encrypt data to prevent excessive usage

C.

to contain embedded permissions that automatically expire

D.

to track the geographical location of each request

Question 283

IP connectivity between the three routers is configured. OSPF adjacencies must be established.

1. Configure R1 and R2 Router IDs using the interface IP addresses from the link that is shared between them.

2. Configure the R2 links with a max value facing R1 and R3. R2 must become the DR. R1 and R3 links facing R2 must remain with the default OSPF configuration for DR election. Verify the configuration after clearing the OSPF process.

3. Using a host wildcard mask, configure all three routers to advertise their respective Loopback1 networks.

4. Configure the link between R1 and R3 to disable their ability to add other OSPF routers.

Options:

Question 284

Which default condition must be considered when an encrypted mobility tunnel is used between two Cisco WLCs?

Options:

A.

TCP port 443 and UDP 21 are used.

B.

Control and data traffic encryption are enabled.

C.

The tunnel uses the IPsec protocol for encapsulation.

D.

The tunnel uses the EolP protocol to transmit data traffic.

Question 285

Which interface condition is occurring in this output?

Options:

A.

duplex mismatch

B.

queueing

C.

bad NIC

D.

broadcast storm

Question 286

Refer to the exhibit. During initial configuration testing, the Windows workstation PC1 cannot connect with the 172.16.2.0/24 network.

Which set of actions corrects the configuration?

Options:

A.

Change the IP address to 172.16.1.6 and change the subnet mask to 255.255.255.248.

B.

Change the IP address to 172.16.1.6 and change the DNS servers to 172.16.1.12 and 172.16.1.13.

C.

Change the IP address to 172.16.1.9 and change the default gateway to 172.16.1.7.

D.

Change the IP address to 172.16.1.9 and change the DNS server to 172.16.1.12 only.

Question 287

Refer to the exhibit. What is the administrative distance for the advertised prefix that includes the host IP address 10.30.0.1?

Options:

A.

10.0.0.2

B.

110

C.

30

D.

2

Question 288

Refer to the exhibit. What is the administrative distance for the advertised prefix that includes the host IP address 192.168.20.1?

Options:

A.

0

B.

192.168.10.2

C.

24

D.

1

Question 289

Which key function is provided by the data plane?

Options:

A.

Making routing decisions

B.

Originating packets

C.

Forwarding traffic to the next hop

D.

Exchanging routing table data

Question 290

Aswitch receives a frame with the destination MAC address 3C:5D: 7E:9F: 1A:2B.

Switch# show ethernet-frame-and-mac-address-table

How does the switch handle the frame?

Options:

A.

It ages out the frame until the MAC address becomes known.

B.

It drops the frame to avoid unnecessary network congestion.

C.

It switches the frame to a predetermined port based on settings.

D.

It floods the frame to all ports except the incoming port.

Question 291

Which fact must the engineer consider when implementing syslog on a new network?

Options:

A.

Syslog defines the software or hardware component that triggered the message.

B.

There are 16 different logging levels (0-15).

C.

By default, all message levels are sent to the syslog server.

D.

The logging level defines the severity of a particular message.

Question 292

Refer to the exhibit.

Which configuration is needed to configure a WLAN with WPA2 only and with a password that is 63 characters long?

Options:

A.

Disable WPA Policy and WPA Encryption and then enable PSK using ASCII.

B.

Enable PSK and FT PSK and then disable WPA Policy.

C.

Disable WPA Encryption and then enable FT PSK.

D.

Enable PSK using Hex format and then disable WPA Policy.

Question 293

What is a characteristic of private IPv4 addressing?

Options:

A.

alleviates the shortage of IPv4 addresses

B.

reduces the forwarding table on network routers

C.

enables secure connectivity over the internet

D.

used as the NAT outside global IP address

Question 294

Which two QoS tools provide congestion management? (Choose two.)

Options:

A.

PBR

B.

FRTS

C.

PQ

D.

CBWFQ

E.

CAR

Question 295

An engineer must update the configuration on two PCs in two different subnets to communicate locally with each other. One PC is configured with IP address 192.168.25.128/25 and the other with 192.168.25.100/25. Which network mask must the engineer configure on both PCs to enable the communication?

Options:

A.

255.255.255.224

B.

255.255.255.248

C.

255.255.255.0

D.

255.255.255.252

Question 296

Which two features are provided by Ansible in network automation? (Choose two.)

Options:

A.

supplying network credentials

B.

role-based access control

C.

agentless deployment

D.

manual playbook runs

E.

launching job templates using version control

Question 297

Which interface is used to send traffic to the destination network?

O 10.76.170 161/26 |110/102] via FO/17

O 10.76.170 161/26[110/27e31] via FO/20

R 10.76.170.161/261120/15] via FO/8

R 10.76.170.161/26 [120/10] via FO/12

Options:

A.

F0/8

B.

FO/20

C.

FO/12

D.

FO/17

Question 298

Which two principles must be considered when using per-hop behavior in QoS? (Choose two.)

Options:

A.

Policing is not supported on subinterfaces.

B.

Shaping and rate limiting have the same effect.

C.

Shaping drops excessive traffic without adding traffic delay.

D.

Shaping levels out traffic bursts by delaying excess traffic.

E.

Policing is performed in the inbound and outbound directions.

Question 299

What is a function of a northbound API in an SDN environment?

Options:

A.

It supports distributed processing for configuration.

B.

It relies on global provisioning and configuration.

C.

It upgrades software and restores files.

D.

It provides orchestration and network automation services.

Question 300

What are two behaviors of a point-to-point WAN topology? (Choose two.)

Options:

A.

It uses a single router to route traffic between sites.

B.

It leverages a dedicated connection.

C.

It connects remote networks through a single line.

D.

t delivers redundancy between the central office and branch offices.

E.

It provides direct connections between each router in the topology.

Question 301

How is Al used to identify issues within network traffic?

Options:

A.

II exclusively predicts device malfunctions.

B.

It enhances data packet delivery speeds.

C.

It simplifies traffic route mapping.

D.

It analyzes patterns for anomaly detection.

Question 302

Refer to the exhibit. Configurations for the switch and PCs are complete.

Which configuration must be applied so that VLANs 2 and 3 communicate back and forth?

Options:

A.

interface GigabitEthernet0/0 ip address 10.10.2.10 255.255.252.0

B.

interface GigabitEthernet0/0.3 encapsulation dot1Q 3 native ip address 10.10.2.10 255.255.252.0

C.

interface GigabitEthernet0/0.10 encapsulation dot1Q 3

D.

interface GigabitEthernet0/0.3 encapsulation dot1Q 10 ip address 10.10.2.10 255.255.252.0

Question 303

What are two benefits of private IPv4 addressing? (Choose two.)

Options:

A.

provides external internet network connectivity

B.

provides unlimited address ranges

C.

propagates routing information to WAN links

D.

reuses addresses at multiple sites

E.

conserves globally unique address space

Question 304

All physical cabling is in place. Router R4 and PCI are fully configured and

inaccessible. R4's WAN interfaces use .4 in the last octet for each subnet.

Configurations should ensure that connectivity is established end-to-end.

1 . Configure static routing to ensure RI prefers the path through R2 to

reach only PCI on R4's LAN

2. Configure static routing that ensures traffic sourced from RI will take

an alternate path through R3 to PCI in the event of an outage along

the primary path

3. Configure default routes on RI and R3 to the Internet using the least number of hops

Guidelines

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using

the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Options:

Question 305

Why would a network administrator choose to implement RFC 1918 address space?

Options:

A.

to route traffic on the internet

B.

to provide flexibility in the IP network design

C.

to provide overlapping address space with another network

D.

to limit the number of hosts on the network

Question 306

Physical connectivity is implemented between the two Layer 2 switches, and the network connectivity between them must be configured

1. Configure an LACP EtherChannel and number it as 1; configure it between switches SW1 and SVV2 using interfaces Ethernet0/0 and Ethernet0/1 on both sides. The LACP mode must match on both ends

2 Configure the EtherChannel as a trunk link.

3. Configure the trunk link with 802.1 q tags.

4. Configure the native VLAN of the EtherChannel as VLAN 15.

Options:

Question 307

How does MAC learning function?

Options:

A.

inserts MAC addresses dynamically into the CAM table

B.

restricts ports to a maximum of 10 dynamically-learned addresses

C.

protects against denial of service attacks

D.

rewrites the source and destination MAC address

Question 308

Refer to the exhibit. An LACP EtherChannel between two directly connected switches is in the configuration process.

Which command must be configured on switch SW2’s Gi0/1-2 interfaces to establish the channel to SW1?

Options:

A.

channel-group 1 mode desirable

B.

channel-group 1 mode on

C.

channel-group 1 mode auto

D.

channel-group 1 mode active

Question 309

Refer to the exhibit. Which configuration enables SW2 to establish an LACP EtherChannel?

Options:

A.

B.

B.

C.

C.

D.

D.

Question 310

IP connectivity and OSPF are preconfigured on all devices where necessary. Do not make any changes to the IP addressing or OSPF. The company policy uses connected interfaces and next hops when configuring static routes except for load balancing or redundancy without floating static. Connectivity must be established between subnet 172.20.20.128/25 on the Internet and the LAN at 192.168.0.0/24 connected to SW1:

1. Configure reachability to the switch SW1 LAN subnet in router R2.

2. Configure default reachability to the Internet subnet in router R1.

3. Configure a single static route in router R2 to reach to the Internet subnet considering both redundant links between routers R1 and R2. A default route is NOT allowed in router R2.

4. Configure a static route in router R1 toward the switch SW1 LAN subnet where the primary link must be through Ethernet0/1. and the backup link must be through Ethernet0/2 using a floating route. Use the minimal administrative distance value when required.

Options:

Question 311

All physical cabling between the two switches is installed. Configure the network connectivity between the switches using the designated VLANs and interfaces.

1. Configure VLAN 100 named Compute and VLAN 200 named Telephony where required for each task.

2. Configure Ethernet0/1 on SW2 to use the existing VLAN named Available.

3. Configure the connection between the switches using access ports.

4. Configure Ethernet0/1 on SW1 using data and voice VLANs.

5. Configure Ethemet0/1 on SW2 so that the Cisco proprietary neighbor discovery protocol is turned off for the designated interface only.

Options:

Question 312

How does automation affect network management processes?

Options:

A.

It interoperates with ISE to define and manage patch and update schedules.

B.

It performs configuration updates based on user profiles.

C.

It improves the efficiency of system lifecycle management.

D.

It provides a reactive support model.

Question 313

How does automation leverage data models to reduce the operational complexity of a managed network?

Options:

A.

Reduces the response time for specific requests to devices with many interfaces

B.

Categorizes traffic and provides insights

C.

Allows the controller to be vendor-agnostic

D.

Streamlines monitoring using SNMP and other polling tools

Question 314

Refer to the exhibit.

Users will be using a preconfigured secret key and SSID and must have a secured key hashing algorithm configured. The AAA server must not be used for the user authentication method. Which action completes the task?

Options:

A.

Enable AutoConfig iPSK.

B.

SetCCMP128(AES).

C.

Configure PSK Format HEX with key string.

D.

Configure PSK-SHA2.

Question 315

Refer to the exhibit. An administrator is configuring a new WLAN for a wireless network that has these requirements:

    Dual-band clients that connect to the WLAN must be directed to the 5-GHz spectrum.

    Wireless clients on this WLAN must be able to apply VLAN settings from RADIUS attributes.

Which two actions meet these requirements? (Choose two.)

Options:

A.

Enable the Aironet IE option.

B.

Enable the Coverage Hole Detection option.

C.

Set the MFP Client Protection option to Required

D.

Enable the client band select option.

E.

Enable the allow AAA Override option

Question 316

Three switches must be configured for Layer 2 connectivity. The company requires only the designated VLANs to be configured on their respective switches and permitted accross any links between switches for security purposes. Do not modify or delete VTP configurations.

The network needs two user-defined VLANs configured:

VLAN 110: MARKETING

VLAN 210: FINANCE

1. Configure the VLANs on the designated switches and assign them as access ports to the interfaces connected to the PCs.

2. Configure the e0/2 interfaces on Sw1 and Sw2 as 802.1q trunks with only the required VLANs permitted.

3. Configure the e0/3 interfaces on Sw2 and Sw3 as 802.1q trunks with only the required VLANs permitted.

Options:

Question 317

Refer to the exhibit. A network engineer is adding another physical interface as a new member to the existing Port-Channel1 bundle.

Which command set must be configured on the new interface to complete the process?

Options:

A.

switchport mode trunk channel-group 1 mode active

B.

no switchport channel-group 1 mode active

C.

no switchport channel-group 1 mode on

D.

switchport switchport mode trunk

Question 318

Which header must be included in a REST request from an application that requires JSON-formatted content?

Options:

A.

Content-Type: application/json

B.

Accept-Encoding: application/json

C.

Accept: application/json

D.

Accept-Language: application/json

Question 319

What is the difference between the TCP and UDP protocols?

Options:

A.

TCP ensures ordered, reliable data delivery, and UDP offers low latency and high throughput.

B.

TCP is used for transmitting data over the internet, and UDP is used for transmitting data over a local network.

C.

TCP manages multicast and broadcast data transfers, and UDP only handles unicast communications.

D.

TCP is used to ensure data integrity in a file transfer, and UDP is used to broadcast a message to multiple recipients.

Question 320

Refer to the exhibit. Which two commands, when configured on router R1. fulfill these requirements? (Choose two.) ' Packets toward the entire network 2001:db8:23: :/64 must be forwarded through router R2. ' Packets toward host 2001: db8:23::14 preferably must be forwarded through R3.

Options:

A.

ipv6 route 2001:db8:23: :/128 fd00:12::2

B.

Ipv6 route 2001:db8:23::14/128 fd00:13::3

C.

ipv6 route 2001:db8:23::14/64 fd00:12::2 200

D.

ipv6 route 2001:db8:23: l4/64 fd00:12::2

E.

ipv6 route 2001:db8:23: :/64 fd00:12::2

Question 321

What is represented by the word "LB13" within this JSON schema?

Options:

A.

value

B.

object

C.

array

D.

key

Question 322

Refer to the exhibit.

The LACP EtherChannel is configured, and the last change is to modify the interfaces on SwitchA to respond to packets received, but not to initiate negotiation. The interface range gigabitethernet0/0-15 command is entered. What must be configured next?

Options:

A.

SwitchA(config-if-range) #channel-group 1 mode desirable

B.

SwitchA(config-if-range) #channel-group 1 mode auto

C.

SwitchA(config-if-range) #channel-group 1 mode active

D.

SwitchA(config-if-range) #channel-group 1 mode passive

Question 323

Refer to the exhibit. The routers R1-LAB and R2-LAB are configured with link-local addresses. What command must be applied to interface Gi0/0 on R1-LAB for an automated address self-assignment on the IPv6 network?

Options:

A.

ipv6 address 2001:db8:1:0FFA:0::/64

B.

ipv6 address 2001:db8:0:0FFA::1/64

C.

ipv6 address 2001:db8:0:0FFA::/64 eui-64

D.

ipv6 address 2001:db8:0:0FFA::/64 anycast

Question 324

Which technology allows multiple operating systems lo run a single physical server?

Options:

A.

cloud computing

B.

virtualization

C.

application hosting

D.

containers

Question 325

Drag and drop the characteristic from the left onto the IPv6 address type on the right.

Options:

Question 326

Refer to the exhibit. The static routes were implemented on the border router. What is the next hop IP address for a ping sent to 172.16.153.154 from the border router?

Options:

A.

10.56.65.56

B.

10.56.65.65

C.

10.65.56.56

D.

10.65.65.65

Question 327

All physical cabling is in place. A company plans to deploy 32 new sites.

The sites will utilize both IPv4 and IPv6 networks.

1 . Subnet 172.25.0.0/16 to meet the subnet requirements and maximize

the number of hosts

Using the second subnet

• Assign the first usable IP address to e0/0 on Sw1O1

• Assign the last usable IP address to e0/0 on Sw102

2. Subnet to meet the subnet requirements and maximize

the number of hosts

c Using the second subnet

• Assign an IPv6 GUA using a unique 64-Bit interface identifier

on e0/0 on Sw101

• Assign an IPv6 GUA using a unique 64-Bit interface identifier

on eO/O on swi02

Guidelines

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using

the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Options:

Question 328

How does a network administrator securely manage an AP in lightweight mode?

Options:

A.

using the CLI via an out-of-band connection

B.

using the WLC GUI via HTTPS

C.

using the AP GUI via an in-band SSH connection

D.

using the CLI via a virtual interface with SSH

Question 329

Why does an administrator choose to implement a remote access IPsec VPN?

Options:

A.

to establish an encrypted tunnel between a remote user and a private network over the internet

B.

to allow access to an enterprise network using any internet-enabled location via a web browser using SSL

C.

to provide a secure link between an HTTPS server, authentication subsystem, and an end-user

D.

to use cryptography for authentication between a device and user over a negotiated VPN gateway

Question 330

How does MAC learning function?

Options:

A.

Enabled by default on all VLANs and interfaces

B.

Forwards frames to a neighbor port using CDP

C.

Overwrites the known source MAC address in the address table

D.

Protects against denial of service attacks

Question 331

What is the function of generative AI in network operations?

Options:

A.

It disables unused services.

B.

It deploys network firmware updates.

C.

It creates synthetic network configurations.

D.

It computes optimal data storage solutions.

Question 332

An engineer requires a switch interface to actively attempt to establish a trunk link with a neighbor switch. What command must be configured?

Options:

A.

switchport mode dynamic desirable

B.

switchport mode trunk

C.

switchport nonegotiate

D.

switchport mode dynamic auto

Question 333

Refer to the exhibit. Which tasks must be performed on the Download File tab to install new software using TCP port 22?)

Options:

A.

Set the File Type to Code, set the Transfer Mode to SFTP, and specify the IP address of the WLC.

B.

Set the File Type to Configuration, set the Transfer Mode to FTP, and specify the IP address of the file server.

C.

Set the File Type to Code, set the Transfer Mode to SFTP, and specify the IP address of the file server.

D.

Set the File Type to Configuration, set the Transfer Mode to SFTP, and specify the IP address of the WLC.

Question 334

What is a similarity between global and unique local IPv6 addresses?

Options:

A.

They are allocated by the same organization.

B.

They are routable on the global internet.

C.

They use the same process for subnetting.

D.

They are part of the multicast IPv6 group type.

Question 335

Refer to the exhibit. A packet sourced from 10.10.10.1 is destined for 172.16.3.254. What is the subnet mask of the destination route?

Options:

A.

0.0.0.0

B.

255.255.254.0

C.

255.255.255.0

D.

255.255.255.255

Question 336

What is the main purpose of SSH management access?

Options:

A.

To support DES 56-bit and 3DES (168-bit) ciphers

B.

To enable secured access to the inbound management interface

C.

To validate management access with username and domain name only

D.

To allow passwords protected with HTTPS encryption to be sent

Question 337

An organization developed new security policies and decided to print the policies and distribute them to all personnel so that employees review and apply the policies. Which element of a security program is the organization implementing?

Options:

A.

Asset identification

B.

User training

C.

Physical access control

D.

Vulnerability control

Question 338

Physical connectivity is implemented between the two Layer 2 switches,

and the network connectivity between them must be configured.

I . Configure an LACP EtherChanneI and number it as 44; configure it

between switches SWI and SW2 using interfaces EthernetO/O and

Ethernet0/1 on both sides. The LACP mode must match on both ends.

2. Configure the EtherChanneI as a trunk link.

3. Configure the trunk link with 802. Iq tags.

4. Configure VLAN 'MONITORING' as the untagged VLAN of the

EtherChannel.

==================

Guidelines

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using

the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Options:

Question 339

Which security element uses a combination of one-time passwords, a login name, and a personal smartphone?

Options:

A.

software-defined segmentation

B.

multifactor authentication

C.

attribute-based access control

D.

rule-based access control

Question 340

What is the total number of users permitted to simultaneously browse the controller management pages when using the AireOS GUI?

Options:

A.

2

B.

5

C.

8

D.

9

Question 341

Configure IPv4 and IPv6 connectivity between two routers. For IPv4, use a /28 network from the 192.168.1.0/24 private range. For IPv6, use the first /64 subnet from the 2001:0db8:aaaa::/48 subnet.

1. Using Ethernet0/1 on routers R1 and R2, configure the next usable/28 from the 192.168.1.0/24 range. The network 192.168.1.0/28 is unavailable.

2. For the IPv4 /28 subnet, router R1 must be configured with the first usable host address.

3. For the IPv4 /28 subnet, router R2 must be configured with the last usable host address.

4. For the IPv6 /64 subnet, configure the routers with the IP addressing provided from the topology.

5. A ping must work between the routers on the IPv4 and IPv6 address ranges.

Options:

Question 342

What is a characteristic of a Layer 2 switch?

Options:

A.

Uses routers to create collision domains

B.

Responsible for sending data in a particular sequence

C.

Avoids MAC address storage for faster transmission

D.

Uses the data link layer for communications

Question 343

Drag and drop the IPv6 address from the left onto the type on the right.

Options:

Question 344

What is the purpose of the service-set identifier?

Options:

A.

It identifies the wired network to which a network device is connected.

B.

It identifies a wireless network for a mobile device to connect.

C.

It identifies the wireless network to which an application must connect.

D.

It identifies the wired network to which a user device is connected.

Question 345

Refer to the exhibit.

How does router R1 forward packets destined to 10.0.4.10?

Options:

A.

via 10.0.4.2

B.

via 10.0.0.2

C.

via FastEthernet0/1

D.

via FastEthernet1/1

Exam Detail
Vendor: Cisco
Certification: CCNA
Exam Code: 200-301
Last Update: Sep 14, 2025
200-301 Question Answers
Page: 1 / 86
Total 1191 questions