Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Cisco 200-301 Dumps Questions Answers

Page: 1 / 77
Total 1240 questions

Implementing and Administering Cisco Solutions (200-301 CCNA) v1.1 Questions and Answers

Question 1

Which group of channels in the 802.11b/g/n/ax 2.4 GHz frequency bands are non-overlapping channels?

Options:

A.

channels 1, 5, and 10

B.

channels 1, 5, and 11

C.

channels 1, 6, and 10

D.

channels 1, 6, and 11

Buy Now
Question 2

Refer to the exhibit. Of the routes learned with dynamic routing protocols, which has the least preferred metric?

Options:

A.

EIGRP

B.

OSPF

C.

Local

D.

RIP

Question 3

An on-site service desk technician must verify the IP addressss and DNS server information on a users Windows computer. Which command must the technician enter at the command prompt on the user ' s computer?

Options:

A.

ipconfig /all

B.

ifconfig -a

C.

show interface

D.

netstat -r

Question 4

What are two lacts that differentiate optical-fiber cabling from copper cabling? (Choose two.)

Options:

A.

It is less expensive when purchasing patch cables.

B.

It has a greater sensitivity to changes in temperature and moisture.

C.

It provides greater throughput options.

D.

It carries signals for longer distances.

E.

It carries electrical current further distances for PoE devices.

Question 5

What is a valid IPv6 addresss record in DNS?

Options:

A.

A

B.

MX

C.

AAAA

D.

CNAME

Question 6

Refer to the exhibit. Routers R1 and R2 have been configured with their respective LAN interfaces. The two circuits are operational and reachable across the WAN. Which command set establishes failover redundancy if the primary circuit goes down?

Options:

A.

Ri(config)#ip route 0.0.0.0 0.0.0.0 10.10.10.62R2(config)#ip route 0.0.0.0 0.0.0.0 10.10.10.5 2

B.

Ri(config)#ip route 10.10.13.10 255.255.255.255 10.10.10.6R2(config)#ip route 192.168.0.100 255.255.255.255 10.10.10.5

C.

Ri(config)#ip route 0.0.0.0 0.0.0.0 10.10.10.6R2(config)#ip route 0.0.0.0 0.0.0.0 10.10.10.5

D.

Ri(config)#ip route 10.10.13.10 255.255.255.255 10.10.10.2R2(config)#ip route 192.168.0.100 255.255.255.255 10.10.10.1

Question 7

A network security team noticed that an increasing number of employees are becoming victims of phishing attacks. Which security program should be implemented to mitigate the problem?

Options:

A.

Physical access control

B.

Software firewall enabled on all PCs

C.

Email system patches

D.

User awareness training

Question 8

Which interface is used to send traffic to the destination network?

10.249.210.56/25 [90/6144] via G0/15

10.249.210.56/25 [90/45053] via G0/13

10.249.210.56/25 [110/3693] via G0/16

10.249.210.56/25 [110/360] via G0/12

Options:

A.

G0/16

B.

G0/15

C.

G0/13

D.

G0/12

Question 9

Refer to the exhibit. What is the administrative distance for the advertised prefix that includes the host IP addressss 192.168.20.1?

Options:

A.

1

B.

24

C.

192.168.10.2

D.

0

Question 10

Refer to the exhibit. HQC needs to use a configuration that:

handles up to 150,000 concurrent connections

minimizes consumption of public IP addresssses

Options:

A.

ip nat pool NATPOOL 209.165.201.1 209.165.201.3 netmask 255.255.255.248  ip nat inside source list HQC pool NATPOOL overload

B.

ip nat pool NATPOOL 209.165.201.1 209.165.201.248 netmask 255.255.255.248  ip nat outside source list HQC pool NATPOOL overload

C.

ip nat pool NATPOOL 209.165.200.225 209.165.200.226 netmask 255.255.255.252  ip nat outside source list HQC pool NATPOOL overload

D.

ip nat pool NATPOOL 209.165.201.1 209.165.201.5 netmask 255.255.255.248  ip nat inside source list HQC interface gigabitEthernet0/0 overload

Question 11

Which action prevents debug messages from being sent via syslog while allowing other messages when an abnormally high number of syslog messages are generated by a device with the debug process turned on?

Options:

A.

Use an access list to filter out the syslog messages.

B.

Turn off the logging monitor in global configuration mode.

C.

Disable logging to the console.

D.

Set the logging trap severity level to informational.

Question 12

How are API keys used to enforce rate limiting?

Options:

A.

to specify the type of data format the client prefers to receive

B.

to define the network path the API request should take

C.

to encrypt data sent in the API request

D.

to uniquely identify each client application

Question 13

Refer to the exhibit. Which routes are configured with their default administrative distances?

Options:

A.

EIGRP

B.

OSPF

C.

RIP

D.

Local

Question 14

A manager asks a network engineer to recommend a cloud service model so that employees do not spend time installing, managing, and updating software that is only used occasionally. Which cloud service model does the engineer recommend?

Options:

A.

Infrastructure-as-a-service

B.

software-as-a-service

C.

business process as a service

D.

platform-as-a-service

Question 15

Drag and drop the characteristic from the left onto the IPv6 address type on the right.

Options:

Question 16

Refer to the exhibit. Which interface does a packet take to reach the destination addresss of 10.10.10.147?

Options:

A.

Serial 0/0

B.

FastEthernet 0/2

C.

FastEthernet 0/0

D.

FastEthernet 0/1

Question 17

What is a function of the core and distribution layers in a collapsed-core architecture?

Options:

A.

The router must use IPv4 and IPv6 addresses at Layer 3.

B.

The core and distribution layers are deployed on two different devices to enable failover.

C.

The router can support HSRP for Layer 2 redundancy in an IPv6 network.

D.

The router operates on a single device or a redundant pair.

Question 18

Which signal frequency appears 60 times per minute?

Options:

A.

1 Hz signal

B.

1 GHz signal

C.

60 Hz signal

D.

60 GHz signal

Question 19

Refer to the exhibit.

What is the subnet mask of the route to the 10.10.13.160 prefix?

Options:

A.

255.255.255.240

B.

255.255.255.128

C.

255.255.255.248

D.

255.255.248.0

Question 20

Which type of hypervisor operates without an underlying OS to host virtual machines?

Options:

A.

Type 1

B.

Type 2

C.

Type 3

D.

Type 12

Question 21

Which command creates a static NAT binding for a PC addresss of 10.1.1.1 to the public routable addresss 209.165.200.225 assigned to the PC?

Options:

A.

R1(config)#ip nat inside source static 10.1.1.1 209.165.200.225

B.

R1(config)#ip nat inside source static 209.165.200.225 10.1.1.1

C.

R1(config)#ip nat outside source static 10.1.1.1 209.165.200.225

D.

R1(config)#ip nat outside source static 209.165.200.225 10.1.1.1

Question 22

How does IPsec provide secure networking for applications within an organization?

Options:

A.

It takes advantage of FTP to secure file transfers between nodes on the network.

B.

It provides GRE tunnels to transmit traffic securely between network nodes.

C.

It enables sets of security associations between peers.

D.

It leverages TFTP providing secure file transfers among peers on the network.

Question 23

What is a function of Layer 3 switches?

Options:

A.

They route traffic between devices in different VLANs.

B.

They forward Ethernet frames between VLANs using only MAC addressses.

C.

They move frames between endpoints limited to IP addresssses.

D.

They transmit broadcast traffic when operating in Layer 3 mode exclusively.

Question 24

How does network automation help reduce network downtime?

Options:

A.

Changes can be implemented in parallel across multiple devices at once, which increases the speed of the change rate.

B.

By using automation platforms with intent-based configuration, all changes are checked for possible outages before being implemented.

C.

Emails can be generated based on when a network admin performs a network change, which increases visibility.

D.

Configuration templates and testing can be built into implementation, which increases the success rate of a network change.

Question 25

What is the temporary state that switch ports always enter immediately after the boot process when Rapid PVST+ is used?

Options:

A.

discarding

B.

listening

C.

forwarding

D.

learning

Question 26

Refer to the exhibit. IPv6 is being Implemented within the enterprise. The command Ipv6 unlcast-routing is configure. Interlace GlgO/0 on R1 must be configured to provide a dynamic assignment using the assigned IPv6 block Which command accomplishes this task?

Options:

A.

ipv6 addresss 2001:DB8:FFFF:FCF3::1/64

B.

ipv6 addresss autoconfig 2001:DB8:FFFF:FCF2::/64

C.

ipv6 addresss 2001:DB8:FFFF:FCF3::/64 eui-64

D.

ipv6 addresss 2001:DB8:FFFF:FCF3::/64 link-local

Question 27

Refer to the exhibit.

Switch AccSw2 has just been added to the network along with PC2. All VLANs have been implemented on AccSw2. How must the ports on AccSw2 be configured to establish Layer 2 connectivity between PC1 and PC2?

Options:

A.
B.

B.

C.

C.

D.

D.

Question 28

Which alternative to password authentication Is Implemented to allow enterprise devices to log in to the corporate network?

Options:

A.

magic links

B.

one-time passwords

C.

digital certificates

D.

90-day renewal policies

Question 29

Refer to the exhibit.

PC A is communicating with another device at IIP address 10.227.225.255. Through which router does router Y route the traffic?

Options:

A.

router A

B.

router B

C.

router C

D.

router D

Question 30

Which interface is used to send traffic to the destination network?

O 10.18.75.113/27 [110/6906] via GO/6

O 10.18.75.113/27 [110/23018] via GO/3

R 10.18.75.113/27 [120/16] via GO/16

R 10.18.75.113/27 [120/14] via GO/23

Options:

A.

G0/23

B.

G0/3

C.

G0/16

D.

G0/6

Question 31

Which technology is appropriate for communication between an SDN controller and applications running over the network?

Options:

A.

REST API

B.

OpenFlow

C.

Southbound API

D.

NETCONF

Question 32

Refer to the exhibit.

What does the host do when using the IPv4 Preferred function?

Options:

A.

It continues to use a statically assigned IPv4 addresss

B.

It forces the DNS server to provide the same IPv4 addresss at each renewal.

C.

It requests the same IPv4 addresss when it renews its lease with the DHCP server.

D.

It prefers a pool of addressses when renewing the IPv4 host IP addressss

Question 33

Refer to the exhibit.

What does route 10.0.1.3/32 represent in the routing table?

Options:

A.

a single destination addresss

B.

the source 10.0.1.100

C.

all hosts in the 10.0.1.0 subnet

D.

the 10.0.0.0 network

Question 34

Which security protocol is appropriate for a WPA3 implementation?

Options:

A.

CCMP

B.

MD5

C.

TKIP

D.

GCMP

Question 35

Which mechanism allows WPA3 to provide a higher degree of security than its predecessors?

Options:

A.

special-character support in pre-shared Keys

B.

SAE password-based key exchange

C.

automatic device pairing

D.

certificate-based authentication

Question 36

Which fact must the engineer consider when implementing syslog on a new network?

Options:

A.

Syslog defines the software or hardware component that triggered the message.

B.

There are 16 different logging levels (0-15).

C.

By default, all message levels are sent to the syslog server.

D.

The logging level defines the severity of a particular message.

Question 37

What describes the functionality of southbound APIs?

Options:

A.

They use HTTP messages to communicate.

B.

They enable communication between the controller and the network device.

C.

They convey information from the controller to the SDN applications.

D.

They communicate with the management plane.

Question 38

Refer to the exhibit. Traffic from R1 to the 10.10.2.0/24 subnet uses 192.168.1.2 as its next hop. A network engineer wants to update the R1 configuration so that traffic with destination 10.10.2.1 passes through router R3, and all other traffic to the 10.10.2.0/24 subnet passes through R2.

Which command must be used?

Options:

A.

ip route 10.10.2.0 255.255.255.0 192.168.1.4 100

B.

ip route 10.10.2.0 255.255.255.0 192.168.1.4 115

C.

ip route 10.10.2.1 255.255.255.255 192.168.1.4 100

D.

ip route 10.10.2.1 255.255.255.255 192.168.1.4 115

Question 39

What are two benefits of private IPv4 addresssing? (Choose two.)

Options:

A.

provides external internet network connectivity

B.

provides unlimited addresss ranges

C.

propagates routing information to WAN links

D.

reuses addressses at multiple sites

E.

conserves globally unique addresss space

Question 40

Which device separates networks by security domains?

Options:

A.

firewall

B.

access point

C.

intrusion protection system

D.

wireless controller

Question 41

Refer to the exhibit.

In which structure does the word " warning " directly reside?

Options:

A.

array

B.

object

C.

Boolean

D.

string

Question 42

Which authentication method requires the user to provide a physical attribute to authenticate successfully?

Options:

A.

password

B.

muftifactor

C.

biometric

D.

certificate

Question 43

In which way does a spine-and-leaf architecture allow for scalability in a network when additional access ports are required?

Options:

A.

A spine switch and a leaf switch are added with redundant connections between them.

B.

A spine switch is added with at least 40 GB uplinks.

C.

A leaf switch is added with a single connection to a core spine switch.

D.

A leaf switch is added with connections to every spine switch.

Question 44

A new DHCP server has been deployed in a corporate environment with lease time set to eight hours. Which CMD command on a Windows-based device allows the engineer to verify the DHCP lease expiration?

Options:

A.

ipconfig /renew

B.

ipconfig

C.

ipconfig /all

D.

ipconfig /displaydns

Question 45

What is represented by the word " LB13 " within this JSDN schema?

Options:

A.

value

B.

object

C.

array

D.

key

Question 46

It work security team noticed that an increasing number of employees are becoming victims of phishing attacks. Which security program should be implemented to mitigate the problem?

Options:

A.

email system patches

B.

physical access control

C.

software firewall enabled on all PCs

D.

user awareness training

Question 47

What is the RFC 4627 default encoding for JSDN text?

Options:

A.

UCS-2

B.

UTF-8

C.

Hex

D.

GB18030

Question 48

Refer to the exhibit.

Which IP route command created the best path for a packet destined for 10.10.10.3

Options:

A.

ip route 10.10.0.0 255.255.252.0 g0/0

B.

ip route 10.0.0.0 255.0.0.0 g0/0

C.

ip route 10.10.10.1 255.255.255.255 g0/0

D.

ip route 10.10.10.0 255.255.255.240 g0/0

Question 49

Which two principles must be considered when using per-hop behavior in QoS? (Choose two.)

Options:

A.

Policing is not supported on subinterfaces.

B.

Shaping and rate limiting have the same effect.

C.

Shaping drops excessive traffic without adding traffic delay.

D.

Shaping levels out traffic bursts by delaying excess traffic.

E.

Policing is performed in the inbound and outbound directions.

Question 50

Refer to the exhibit.

Packets are flowing from 192.168.10.1 to the destination at IP addressss 192.168.20.75. Which next hop will the router select for the packet?

Options:

A.

10.10.10.1

B.

10.10.10.11

C.

10.10.10.12

D.

10.10.10.14

Question 51

When deploying a new network that includes both Cisco and third-party network devices, which redundancy protocol avoids the interruption of network traffic if the default gateway router fails?

Options:

A.

FHRP

B.

HSRP

C.

GLBP

D.

VRRP

Question 52

Drag and drop the AAA terms from the left onto the descriptions on the right.

Options:

Question 53

Refer to the exhibit.

A network engineer is configuring a WLAN to connect with the 172.16.10.0/24 network on VLAN 20. The engineer wants to limit the number of devices that connect to the WLAN on the USERWL SSID to 125. Which configuration must the engineer perform on the WLC?

Options:

A.

In the Management Software activation configuration, set the Clients value to 125.

B.

In the Controller IPv6 configuration, set the Throttle value to 125.

C.

In the WLAN configuration, set the Maximum Allowed Clients value to 125.

D.

In the Advanced configuration, set the DTIM value to 125.

Question 54

Refer to the exhibit. After applying this configuration to router R1, a network engineer is verifying the implementation. If all links are operating normally, and the engineer sends a series of packets from PC1 to PC3. how are the packets routed?

Options:

A.

They are routed to 172.16.20.2.

B.

They are routed to 192.168.100.2.

C.

They are distributed sent round robin to interfaces SO/0/0 and SO/0/1.

D.

They are routed to 10.0.0.2.

Question 55

A network engineer is configuring a switch so that it is remotely reachable via SSH. The engineer has already configured the host name. Which additional command must the engineer configure before entering the command to generate the RSA key?

Options:

A.

ip domain-name domain

B.

password password

C.

crypto key generate rsa modulus 1024

D.

ip ssh authentication-retries 2

Question 56

Which action implements physical access control as part of the security program of an organization?

Options:

A.

configuring a password for the console port

B.

configuring enable passwords on network devices

C.

backing up syslogs at a remote location

D.

setting up IP cameras to monitor key infrastructure

Question 57

Refer to the exhibit.

The network engineer is configuring a new WLAN and is told to use a static password for authentication instead of the RADIUS servers. Which additional set of tasks must the engineer perform to complete the configuration?

Options:

A.

Crable PSKEnable iod 1s

B.

Select WPA2 PolicyDisable PMFEnable PSK

C.

Select WPA PolicyEnable PSK

D.

Select WPA PolicySelect WRAS Policy

Question 58

Refer to the exhibit.

A network engineer is updating the configuration on router R1 to connect a new branch office to the company network R2 has been configured correctly. Which command must the engineer configure so that devices at the new site communicate with the main office?

Options:

A.

ip route 172.25.25 0 255 255 255.0 192.168.2.1

B.

ip route 172.25.25 1 255 255 255 255 g0/1

C.

ip route 172.25.25.0.255.255.255.0.192.168.2.2

Question 59

Refer to the exhibit.

Router R1 is added to the network and configured with the 10.0.0.64/26 and 10.0.20.0/24 subnets. However, traffic destined for the LAN on R3 is not accessible. Which command when executed on R1 defines a static route to reach the R3 LAN?

Options:

A.

ip route 10.0.15.0 255.255.255.0 10.0.20.3

B.

ip route 10.0.15.0 255.255.255.0 10.0.20.1

C.

ip route 10.0.0.64 255.255.255.192 10.0.20.3

D.

ip route 10.0.15.0 255.255.255.192 10.0.20.1

Question 60

Drag and drop the characteristic from the left onto the IPv6 address type on the right.

Options:

Question 61

Company has decided to require multifactor authentication for all systems. Which set of parameters meets the requirement?

Options:

A.

personal 10-digit PIN and RSA certificate

B.

complex password and personal 10-digit PIN

C.

password of 8 to 15 characters and personal 12-digit PIN

D.

fingerprint scanning and facial recognition

Question 62

Refer to the exhibit. Drag and drop the learned prefixes from the left onto the preferred route methods from which they were learned on the right.

Options:

Question 63

What provides connection redundancy increased bandwidth and load sharing between a wireless LAN controller and a Layer 2 switch?

Options:

A.

VLAN trunking

B.

tunneling

C.

first hop redundancy

D.

link aggregation

Question 64

Refer to the exhibit.

Traffic from R1 to the 10.10.2.0/24 subnet uses 192.168.1.2 as its next hop. An network engineer wants to update the R1 configuration so that traffic with destination 10.10.2.1 passes through router R3, and all other traffic to the 10.10.20/24 subnet passes through r2. Which command must be used?

Options:

A.

ip route 10.10.2.1 255.255.255.255 192.168.1.4 115

B.

ip route 10.10.2.0 255.255.255.0 192.168.1.4 100

C.

ip route 10.10.2.0 255.255.255.0 192.168.1.4 115

D.

ip route 10.10.2.1 255.255.255.255 192.168.1.4 100

Question 65

Drag and drop the DNS commands from the left onto their effects on the right.

Options:

Question 66

Under which condition is TCP preferred over UDP?

Options:

A.

UDP is used when low latency is optimal, and TCP is used when latency is tolerable.

B.

TCP is used when dropped data is more acceptable, and UDP is used when data is accepted out- of-order.

C.

TCP is used when data reliability is critical, and UDP is used when missing packets are acceptable.

D.

UDP is used when data is highly interactive, and TCP is used when data is time-sensitive.

Question 67

What is a purpose of traffic shaping?

Options:

A.

It enables dynamic flow identification.

B.

It enables policy-based routing.

C.

It provide best-effort service.

D.

It limits bandwidth usage.

Question 68

An engineer must configure a core router with a floating static default route to the backup router at 10.200.0.2.

Options:

Question 69

Refer to the exhibit.

Which action by the router when a packet is sourced from 10.10.10.2 and destined 10.10.10.16?

Options:

A.

It queues the packets waiting for the route to be learned.

B.

It floods packets to all learned next hops.

C.

It discards the packets.

D.

It uses a route that is similar to the destination address.

Question 70

What is the role of community strings in SNMP operations?

Options:

A.

It serves as a sequence tag on SNMP traffic messages.

B.

It serves as a password to protect access to MIB objects.

C.

It passes the Active Directory username and password that are required for device access

D.

It translates alphanumeric MIB output values to numeric values.

Question 71

Which access point mode relies on a centralized controller for management, roaming, and SSID configuration?

Options:

A.

repeater mode

B.

autonomous mode

C.

bridge mode

D.

lightweight mode

Question 72

Refer to the exhibit.

How many objects are present in the given JSON-encoded data?

Options:

A.

one

B.

four

C.

seven

D.

nine

Question 73

Refer to the exhibit.

The EtherChannel is configured with a speed of 1000 and duplex as full on both ends of channel group 1. What is the next step to configure the channel on switch A to respond to but not initiate LACP communication?

Options:

A.

interface range gigabitethernet0/0/0-15 channel-group 1 mode on

B.

interface range gigabitethernet0/0/0-15 channel-group 1 mode desirable

C.

interface port-channel 1 channel-group 1 mode auto

D.

interface port-channel 1 channel-group 1 mode passive

Question 74

Refer to the exhibit.

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 75

Which IPsec transport mode encrypts the IP header and the payload?

Options:

A.

pipe

B.

control

C.

transport

D.

tunnel

Question 76

Why is TCP desired over UDP for application that require extensive error checking, such as HTTPS?

Options:

A.

UDP operates without acknowledgments, and TCP sends an acknowledgment for every packet received.

B.

UDP reliably guarantees delivery of all packets, and TCP drops packets under heavy load.

C.

UDP uses flow control mechanisms for the delivery of packets, and TCP uses congestion control for efficient packet delivery.

D.

UDP uses sequencing data tor packets to arrive in order, and TCP offers the capability to receive packets in random order.

Question 77

Refer to the exhibit.

Which configuration for RTR-1 denies SSH access from PC-1 to any RTR-1 interface and allows all other traffic?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 78

When a switch receives a frame for an unknown destination MAC address, how is the frame handled?

Options:

A.

broadcast to all ports on the switch

B.

flooded to all ports except the origination port

C.

forwarded to the first available port

D.

inspected and dropped by the switch

Question 79

When an access point is seeking to join wireless LAN controller, which message is sent to the AP- Manager interface?

Options:

A.

Discovery response

B.

DHCP request

C.

DHCP discover

D.

Discovery request

Question 80

Which action implements physical access control as part of the security program of an organization??

Options:

A.

backing up syslogs at a remote location

B.

configuring a password for the console port

C.

configuring enable passwords on network devices

D.

setting up IP cameras to monitor key infrastructure

Question 81

Drag and drop the virtualization concepts from the left onto the matching statements on the right.

Options:

Question 82

Which syslog severity level is considered the most severe and results in the system being considered unusable?

Options:

A.

Alert

B.

Error

C.

Emergency

D.

Critical

Question 83

Refer to the exhibit.

R1 has just received a packet from host A that is destined to host B. Which route in the routing table is used by R1 to reach host B?

Options:

A.

10.10.13.0/25 [108/0] via 10.10.10.10

B.

10.10.13.0/25 [110/2] via 10.10.10.2

C.

10.10.13.0/25 [110/2] via 10.10.10.6

D.

10.10.13.0/25 [1/0] via 10.10.10.2

Question 84

Refer to the exhibit.

An IPv6 address must be obtained automatically on the LAN interface on R1 Which command must be implemented to accomplish the task?

Options:

A.

Ipv6 address 2001:dbB:d8d2:1008:4343:61:0010::/64

B.

Ipv6 address autoconfig

C.

Ipv6 address fe80::/10

D.

Ipv6 address dhcp

Question 85

Which protocol is used in Software Defined Access (SDA) to provide a tunnel between two edge nodes in different fabrics?

Options:

A.

Generic Router Encapsulation (GRE)

B.

Virtual Local Area Network (VLAN)

C.

Virtual Extensible LAN (VXLAN)

D.

Point-to-Point Protocol

Question 86

Refer to the exhibit. Local access for R4 must be established and these requirements must be met:

• Only Telnet access is allowed.

• The enable password must be stored securely.

• The enable password must be applied in plain text.

• Full access to R4 must be permitted upon successful login.

Which configuration script meets the requirements?

A)

B)

C)

D)

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Question 87

Refer to the exhibit.

An administrator received a call from a branch office regarding poor application performance hosted at the headquarters. Ethernet 1 is connected between Router1 and the LAN switch. What identifies the issue?

Options:

A.

The QoS policy is dropping traffic.

B.

There is a duplex mismatch.

C.

The link is over utilized.

D.

The MTU is not set to the default value.

Question 88

Refer to the exhibit.

A network engineer executes the show ip route command on router D. What is the next hop to network 192.168.1.0/24 and why?

Options:

A.

The next hop is 10.0.2.1 because it uses distance vector routing

B.

The next hop is 10.0.2.1 because it is a link-state routing protocol

C.

The next hop is 10.0.0.1 because it has a better administrative distance

D.

The next hop is 10.0.0.1 because it has a higher metric.

Question 89

Refer to the exhibit.

An engineer must configure router R2 so it is elected as the DR on the WAN subnet. Which command sequence must be configured?

A)

B)

C)

D)

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Question 90

Refer to the exhibit.

A network engineer must configure NETCONF. After creating the configuration, the engineer gets output from the command show line but not from show running-config. Which command completes the configuration?

Options:

A.

Device(config)# netconf lock-time 500

B.

Device(config)# netconf max-message 1000

C.

Device(config)# no netconf ssh acl 1

D.

Device(config)# netconf max-sessions 100

Question 91

Which command implies the use of SNMPv3?

Options:

A.

snmp-server host

B.

snmp-server community

C.

snmp-server enable traps

D.

snmp-server user

Question 92

Drag and drop the Rapid PVST+ forwarding state actions from the left to the right. Not all actions are used.

Options:

Question 93

Drag and drop the steps in a standard DNS lookup operation from the left into the order on the right.

Options:

Question 94

A network engineer must configure an interface with IIP address 10.10.10.145 and a subnet mask equivalent to 11111111.11111111.11111111.11111000. Which subnet mask must the engineer use?

Options:

A.

/29

B.

/30

C.

/27

D.

/28

Question 95

Refer to the exhibit.

How does router R1 handle traffic to the 172.16.1.4/30 subnet?

Options:

A.

It sends all traffic over the path via 172.16.9.5 using 172.16.4.4 as a backup.

B.

It sends all traffic over the path via 10.0.1.100.

C.

It load-balances traffic over 172.16.9.5 and 172.16.4.4.

D.

It sends all traffic over the path via 172.16.4.4.

Question 96

What is the definition of backdoor malware?

Options:

A.

malicious code that is installed onto a computer to allow access by an unauthorized user

B.

malicious code with the main purpose of downloading other malicious code

C.

malicious program that is used to launch other malicious programs

D.

malicious code that infects a user machine and then uses that machine to send spam

Question 97

Refer to the exhibit.

An engineer is updating the management access configuration of switch SW1 to allow secured, encrypted remote configuration. Which two commands or command sequences must the engineer apply to the switch? (Choose two.)

Options:

A.

SW1(config)#enable secret ccnaTest123

B.

SW1(config)#username NEW secret R3mote123

C.

SW1(config)#line vty 0 15 SW1(config-line)#transport input ssh

D.

SW1(config)# crypto key generate rsa

E.

SW1(config)# interface f0/1 SW1(config-if)# switchport mode trunk

Question 98

Refer to the exhibit

.

After configuring a new static route on the CPE. the engineer entered this series of commands to verify that the new configuration is operating normally When is the static default route installed into the routing table?

Options:

A.

when 203 0 113.1 is no longer reachable as a next hop B. when the default route learned over external BGP becomes invalid

B.

when a route to 203.0 113 1 is learned via BGP

C.

when the default route over external BGP changes its next hop

Question 99

What is the function of northbound API?

Options:

A.

It upgrades software and restores files.

B.

It relies on global provisioning and configuration.

C.

It supports distributed processing for configuration.

D.

It provide a path between an SDN controller and network applications.

Question 100

Drag and drop the statements about networking from the left onto the corresponding networking types on the right

Options:

Question 101

Refer to the exhibit.

The network engineer is configuring router R2 as a replacement router on the network After the initial configuration is applied it is determined that R2 failed to show R1 as a neighbor Which configuration must be applied to R2 to complete the OSPF configuration and enable it to establish the neighbor relationship with R1?

A)

B)

C)

D)

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Question 102

Refer to the exhibit.

A packet sourced from 10.10.10.1 is destined for 10.10.8.14. What is the subnet mask of the destination route?

Options:

A.

255.255.254.0

B.

255.255.255.240

C.

255.255.255.248

D.

255.255.255.252

Question 103

Refer to the exhibit.

An engineer must configure a floating static route on an external EIGRP network. The destination subnet is the /29 on the LAN Interface of R86. Which command must be executed on R14?

Options:

A.

ip route 10.80.65.0.255.255.248.0.10.73.65.66.1

B.

ip route 10.80.65.0.255.255.255..240 fa0/1 89

C.

ip route 10.80.65.0.255.255.248.0.10.73.65.66.171

D.

ip route 10.80.65.0.0.0.224.10.80.65.0. 255

Question 104

NO: 346

What must a network administrator consider when deciding whether to configure a new wireless network with APs in autonomous mode or APs running in cloud-based mode?

Autonomous mode APs are less dependent on an underlay but more complex to maintain than APs in cloud-based mode.

Cloud-based mode APs rely on underlays and are more complex to maintain than APs in autonomous mode.

Options:

A.

Cloud-based mode APs are easy to deploy but harder to automate than APs in autonomous mode.

B.

Autonomous mode APs are easy to deploy and automate than APs in cloud-based mode.

Question 105

A router has two static routes to the same destination network under the same OSPF process. How does the router forward packets to the destination if the next-hop devices are different?

Options:

A.

The router chooses the route with the oldest age.

B.

The router load-balances traffic over all routes to the destination.

C.

The router chooses the next hop with the lowest MAC address.

D.

The router chooses the next hop with the lowest IP address.

Question 106

Refer to the exhibit. The router R1 is in the process of being configured. Routers R2 and R3 are configured correctly for the new environment. Which two commands must be configuredd on R1 for PC1 to communicate to all PCs on the 10.10.10.0/24 network? (Choose two.)

Options:

A.

ip route 10.10.10.0 255.255.255.0 192.168.2.3

B.

ip route 10.10.10.10 255.255.255.255 192.168.2.2

C.

ip route 10.10.10.10 255.255.255.255 g0/1

D.

ip route 10.10.10.8 255.255.255.248 g0/1

E.

ip route 10.10.10.0 255.255.255.248 192.168.2.2

Question 107

What are two examples of multifactor authentication? (Choose two.)

Options:

A.

single sign-on

B.

unique user knowledge

C.

passwords that expire

D.

soft tokens

E.

shared password responsibility

Question 108

What are two protocols within the IPsec suite? (Choose two)

Options:

A.

AH

B.

3DES

C.

ESP

D.

TLS

E.

AES

Question 109

Refer to the exhibit.

How must OSPF be configured on the GigabitEthernet0/0 interface of the neighbor device to achieve.

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 110

Which IPv6 address range is suitable for anycast addresses for distributed services such DHCP or DNS?

Options:

A.

FF00:1/12

B.

2001:db8:0234:ca3e::1/128

C.

2002:db84:3f37:ca98:be05:8/64

D.

FE80::1/10

Question 111

Drag and drop the IPv6 address types from the left onto their description on the right.

Options:

Question 112

By default, how long will the switch continue to know a workstation MAC address after the workstation stops sending traffic?

Options:

A.

200 seconds

B.

300 seconds

C.

600 seconds

D.

900 seconds

Question 113

Drag and drop the Ansible features from the left to the right Not all features are used.

Options:

Question 114

What is the put method within HTTP?

Options:

A.

It is a read-only operation.

B.

It is a nonldempotent operation.

C.

It replaces data at the destination.

D.

It displays a web site.

Question 115

Drag and drop the statement about AAA services from the left to the corresponding AAA services on the right.

Options:

Question 116

Drag and drop the characteristics of device-management technologies from the left onto the corresponding deployment types on the right.

Options:

Question 117

PC1 tries to send traffic to newly installed PC2. The PC2 MAC address is not listed in the MAC address table of the switch, so the switch sends the packet to all ports in the same VLAN Which switching concept does this describe?

Options:

A.

MAC address aging

B.

MAC address table

C.

frame flooding

D.

spanning-tree protocol

Question 118

Which property is shared by 10GBase-SR and 10GBase-LR interfaces?

Options:

A.

Both require fiber cable media for transmission.

B.

Both require UTP cable media for transmission.

C.

Both use the single-mode fiber type.

D.

Both use the multimode fiber type.

Question 119

Which device segregates a network into separate zones that have their own security policies?

Options:

A.

IPS

B.

firewall

C.

access point

D.

switch

Question 120

Refer to the exhibit.

A packet sourced from 172.18.33.2 is destined for 172.18.32.38. Where does the router forward the packet?

Options:

A.

GigabitEthernet0/0

B.

Loopback0

C.

10.1.1.1

D.

10.1.1.3

Question 121

Refer to the exhibit.

Which entry is the longest prefix match for host IP address 192.168.10.5?

Options:

A.

1

B.

2

C.

3

D.

4

Question 122

What is a reason to configure a trunk port that connects to a WLC distribution port?

Options:

A.

Eliminate redundancy with a link failure in the data path.

B.

Allow multiple VLAN to be used in the data path.

C.

Provide redundancy if there is a link failure for out-of-band management.

D.

Permit multiple VLANs to provide out-of-band management.

Question 123

Why is a first-hop redundancy protocol implemented?

Options:

A.

to protect against default gateway failures

B.

to prevent loops in a network

C.

to enable multiple switches to operate as a single unit

D.

to provide load-sharing for a multilink segment

Question 124

Refer to the exhibit.

What does route 10.0.1.3/32 represent in the routing table?

Options:

A.

the 10.0.0.0 network

B.

a single destination address

C.

the source 10.0.1.100

D.

all hosts in the 10.0.1.0 subnet

Question 125

IP connectivity and OSPF are preconfigured on all devices where necessary. Do not make any changes to the IP addressing or OSPF. The company policy uses connected interfaces and next hops when configuring static routes except for load balancing or redundancy without floating static. Connectivity must be established between subnet 172.20.20.128/25 on the Internet and the LAN at 192.168.0.0/24 connected to SW1:

1. Configure reachability to the switch SW1 LAN subnet in router R2.

2. Configure default reachability to the Internet subnet in router R1.

3. Configure a single static route in router R2 to reach to the Internet subnet considering both redundant links between routers R1 and R2. A default route is NOT allowed in router R2.

4. Configure a static route in router R1 toward the switch SW1 LAN subnet where the primary link must be through Ethernet0/1. and the backup link must be through Ethernet0/2 using a floating route. Use the minimal administrative distance value when required.

Options:

Question 126

All physical cabling is in place. Router R4 and PCI are fully configured and

inaccessible. R4 ' s WAN interfaces use .4 in the last octet for each subnet.

Configurations should ensure that connectivity is established end-to-end.

1 . Configure static routing to ensure RI prefers the path through R2 to

reach only PCI on R4 ' s LAN

2. Configure static routing that ensures traffic sourced from RI will take

an alternate path through R3 to PCI in the event of an outage along

the primary path

3. Configure default routes on RI and R3 to the Internet using the least number of hops

Guidelines

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using

the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Options:

Question 127

Configure IPv4 and IPv6 connectivity between two routers. For IPv4, use a /28 network from the 192.168.1.0/24 private range. For IPv6, use the first /64 subnet from the 2001:0db8:aaaa::/48 subnet.

1. Using Ethernet0/1 on routers R1 and R2, configure the next usable/28 from the 192.168.1.0/24 range. The network 192.168.1.0/28 is unavailable.

2. For the IPv4 /28 subnet, router R1 must be configured with the first usable host address.

3. For the IPv4 /28 subnet, router R2 must be configured with the last usable host address.

4. For the IPv6 /64 subnet, configure the routers with the IP addressing provided from the topology.

5. A ping must work between the routers on the IPv4 and IPv6 address ranges.

Options:

Question 128

All physical cabling is in place. A company plans to deploy 32 new sites.

The sites will utilize both IPv4 and IPv6 networks.

1 . Subnet 172.25.0.0/16 to meet the subnet requirements and maximize

the number of hosts

Using the second subnet

• Assign the first usable IP address to e0/0 on Sw1O1

• Assign the last usable IP address to e0/0 on Sw102

2. Subnet to meet the subnet requirements and maximize

the number of hosts

c Using the second subnet

• Assign an IPv6 GUA using a unique 64-Bit interface identifier

on e0/0 on Sw101

• Assign an IPv6 GUA using a unique 64-Bit interface identifier

on eO/O on swi02

Guidelines

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using

the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Options:

Question 129

IP connectivity between the three routers is configured. OSPF adjacencies must be established.

1. Configure R1 and R2 Router IDs using the interface IP addresses from the link that is shared between them.

2. Configure the R2 links with a max value facing R1 and R3. R2 must become the DR. R1 and R3 links facing R2 must remain with the default OSPF configuration for DR election. Verify the configuration after clearing the OSPF process.

3. Using a host wildcard mask, configure all three routers to advertise their respective Loopback1 networks.

4. Configure the link between R1 and R3 to disable their ability to add other OSPF routers.

Options:

Question 130

Connectivity between four routers has been established. IP connectivity must be configured in the order presented to complete the implementation. No dynamic routing protocols are included.

1. Configure static routing using host routes to establish connectivity from router R3 to the router R1 Loopback address using the source IP of 209.165.200.230.

2. Configure an IPv4 default route on router R2 destined for router R4.

3. Configure an IPv6 default router on router R2 destined for router R4.

Options:

Question 131

All physical cabling between the two switches is installed. Configure the network connectivity between the switches using the designated VLANs and interfaces.

1. Configure VLAN 100 named Compute and VLAN 200 named Telephony where required for each task.

2. Configure Ethernet0/1 on SW2 to use the existing VLAN named Available.

3. Configure the connection between the switches using access ports.

4. Configure Ethernet0/1 on SW1 using data and voice VLANs.

5. Configure Ethemet0/1 on SW2 so that the Cisco proprietary neighbor discovery protocol is turned off for the designated interface only.

Options:

Question 132

Connectivity between three routers has been established, and IP services must be configured jn the order presented to complete the implementation Tasks assigned include configuration of NAT, NTP, DHCP, and SSH services.

1. All traffic sent from R3 to the R1 Loopback address must be configured for NAT on R2. All source addresses must be translated from R3 to the IP address of Ethernet0/0 on R2, while using only a standard access list named NAT To verify, a ping must be successful to the R1 Loopback address sourced from R3. Do not use NVI NAT configuration.

2. Configure R1 as an NTP server and R2 as a client, not as a peer, using the IP address of the R1 Ethernet0/2 interface. Set the clock on the NTP server for midnight on January 1, 2019.

3. Configure R1 as a DHCP server for the network 10.1.3.0/24 in a pool named TEST. Using a single command, exclude addresses 1-10 from the range. Interface Ethernet0/2 on R3 must be issued the IP address of 10.1.3.11 via DHCP.

4. Configure SSH connectivity from R1 to R3, while excluding access via other remote connection protocols. Access for user root and password Cisco must be set on router R3 using RSA and 1024 bits. Verify connectivity using an SSH session from router R1 using a destination address of 10.1.3.11. Do NOT modify console access or line numbers to accomplish this task.

Options:

Question 133

Physical connectivity is implemented between the two Layer 2 switches, and the network connectivity between them must be configured

1. Configure an LACP EtherChannel and number it as 1; configure it between switches SW1 and SVV2 using interfaces Ethernet0/0 and Ethernet0/1 on both sides. The LACP mode must match on both ends

2 Configure the EtherChannel as a trunk link.

3. Configure the trunk link with 802.1 q tags.

4. Configure the native VLAN of the EtherChannel as VLAN 15.

Options:

Question 134

Physical connectivity is implemented between the two Layer 2 switches,

and the network connectivity between them must be configured.

I . Configure an LACP EtherChanneI and number it as 44; configure it

between switches SWI and SW2 using interfaces EthernetO/O and

Ethernet0/1 on both sides. The LACP mode must match on both ends.

2. Configure the EtherChanneI as a trunk link.

3. Configure the trunk link with 802. Iq tags.

4. Configure VLAN ' MONITORING ' as the untagged VLAN of the

EtherChannel.

==================

Guidelines

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using

the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Options:

Question 135

Three switches must be configured for Layer 2 connectivity. The company requires only the designated VLANs to be configured on their respective switches and permitted accross any links between switches for security purposes. Do not modify or delete VTP configurations.

The network needs two user-defined VLANs configured:

VLAN 110: MARKETING

VLAN 210: FINANCE

1. Configure the VLANs on the designated switches and assign them as access ports to the interfaces connected to the PCs.

2. Configure the e0/2 interfaces on Sw1 and Sw2 as 802.1q trunks with only the required VLANs permitted.

3. Configure the e0/3 interfaces on Sw2 and Sw3 as 802.1q trunks with only the required VLANs permitted.

Options:

Question 136

Drag and drop the threat-mitigation techniques from the left onto the types of threat or attack they mitigate on the right.

Options:

Question 137

What does a router do when configured with the default DNS lookup settings, and a URL is entered on the CLI?

Options:

A.

initiates a ping request to the URL

B.

prompts the user to specify the desired IP address

C.

continuously attempts to resolve the URL until the command is cancelled

D.

sends a broadcast message in an attempt to resolve the URL

Question 138

An email user has been lured into clicking a link in an email sent by their company ' s security organization. The webpage that opens reports that it was safe but the link could have contained malicious code. Which type of security program is in place?

Options:

A.

Physical access control

B.

Social engineering attack

C.

brute force attack

D.

user awareness

Question 139

How do TCP and UDP differ in the way they provide reliability for delivery of packets?

Options:

A.

TCP is a connectionless protocol that does not provide reliable delivery of data, UDP is a connection-oriented protocol that uses sequencing to provide reliable delivery.

B.

TCP does not guarantee delivery or error checking to ensure that there is no corruption of data UDP provides message acknowledgement and retransmits data if lost.

C.

TCP provides flow control to avoid overwhelming a receiver by sending too many packets at once, UDP sends packets to the receiver in a continuous stream without checking for sequencing

D.

TCP uses windowing to deliver packets reliably; UDP provides reliable message transfer between hosts by establishing a three-way handshake

Question 140

Which two minimum parameters must be configured on an active interface to enable OSPFv2 to operate? (Choose two)

Options:

A.

OSPF area

B.

OSPF MD5 authentication key

C.

IPv6 address

D.

OSPF process ID

E.

OSPF stub flag

Question 141

Which device tracks the state of active connections in order to make a decision to forward a packet through?

Options:

A.

wireless access point

B.

firewall

C.

wireless LAN controller

D.

router

Question 142

Refer to the exhibit.

Which switch becomes the root bridge?

Options:

A.

S1

B.

S2

C.

S3

D.

S4

Question 143

What are two functions of a server on a network? (Choose two)

Options:

A.

achieves redundancy by exclusively using virtual server clustering

B.

runs applications that send and retrieve data for workstations that make requests

C.

handles requests from multiple workstations at the same time

D.

runs the same operating system in order to communicate with other servers

E.

housed solely in a data center that is dedicated to a single client

Question 144

In which situation is private IPv4 addressing appropriate for a new subnet on the network of an organization?

Options:

A.

There is limited unique address space, and traffic on the new subnet will stay local within the organization.

B.

The network has multiple endpoint listeners, and it is desired to limit the number of broadcasts.

C.

Traffic on the subnet must traverse a site-to-site VPN to an outside organization.

D.

The ISP requires the new subnet to be advertised to the internet for web services.

Question 145

What is a DHCP client?

Options:

A.

a host that is configured to request an IP address automatically

B.

a server that dynamically assigns IP addresses to hosts

C.

a workstation that requests a domain name associated with its IP address

D.

a router that statically assigns IP addresses to hosts

Question 146

An engineer is asked to protect unused ports that are configured in the default VLAN on a switch.

Which two steps will fulfill the request? (Choose two)

Options:

A.

Configure the ports in an EtherChannel.

B.

Administratively shut down the ports

C.

Configure the port type as access and place in VLAN 99

D.

Configure the ports as trunk ports

E.

Enable the Cisco Discovery Protocol

Question 147

What is the function of a hub-and-spoke WAN topology?

Options:

A.

allows access restrictions to be implemented between subscriber sites.

B.

provides direct connections between subscribers

C.

supports Layer 2 VPNs

D.

supports application optimization

Question 148

Which MAC address is recognized as a VRRP virtual address?

Options:

A.

0000.5E00.010a

B.

0005.3711.0975

C.

0000.0C07.AC99

D.

0007.C070/AB01

Question 149

Where does the configuration reside when a helper address Is configured lo support DHCP?

Options:

A.

on the router closest to the server

B.

on the router closest to the client

C.

on every router along the path

D.

on the switch trunk interface

Question 150

What is an advantage of Cisco DNA Center versus traditional campus device management?

Options:

A.

It supports numerous extensibility options including cross-domain adapters and third-party SDKs.

B.

It supports high availability for management functions when operating in cluster mode.

C.

It enables easy autodiscovery of network elements m a brownfield deployment.

D.

It is designed primarily to provide network assurance.

Question 151

What is a practice that protects a network from VLAN hopping attacks?

Options:

A.

Enable dynamic ARP inspection

B.

Configure an ACL to prevent traffic from changing VLANs

C.

Change native VLAN to an unused VLAN ID

D.

Implement port security on internet-facing VLANs

Question 152

Which two WAN architecture options help a business improve scalability and reliability for the network? (Choose two.)

Options:

A.

asynchronous routing

B.

single-homed branches

C.

dual-homed branches

D.

static routing

E.

dynamic routing

Question 153

Drag and drop the 802.11 wireless standards from the left onto the matching statements on the right

Options:

Question 154

Refer to the exhibit.

After running the code in the exhibit, which step reduces the amount of data that the NETCONF server returns to the NETCONF client, to only the interface ' s configuration?

Options:

A.

Use the Ixml library to parse the data returned by the NETCONF server for the interface ' s configuration.

B.

Create an XML filter as a string and pass it to get_config() method as an argument.

C.

Create a JSON filter as a string and pass it to the get_config() method as an argument.

D.

Use the JSON library to parse the data returned by the NETCONF server for the interface ' s configuration.

Question 155

A frame that enters a switch fails the Frame Check Sequence. Which two interface counters are incremented? (Choose two)

Options:

A.

runts

B.

giants

C.

frame

D.

CRC

E.

input errors

Question 156

Router R1 must send all traffic without a matching routing-table entry to 192.168.1.1. Which configuration accomplishes this task?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 157

Which QoS Profile is selected in the GUI when configuring a voice over WLAN deployment?

Options:

A.

Bronze

B.

Platinum

C.

Silver

D.

Gold

Question 158

Which two capacities of Cisco DNA Center make it more extensible as compared to traditional campus device management? (Choose two)

Options:

A.

adapters that support all families of Cisco IOS software

B.

SDKs that support interaction with third-party network equipment

C.

customized versions for small, medium, and large enterprises

D.

REST APIs that allow for external applications to interact natively with Cisco DNA Center

E.

modular design that is upgradable as needed

Question 159

What is a similarity between OM3 and OM4 fiber optic cable?

Options:

A.

Both have a 50 micron core diameter

B.

Both have a 9 micron core diameter

C.

Both have a 62.5 micron core diameter

D.

Both have a 100 micron core diameter

Question 160

Several new coverage cells are required to improve the Wi-Fi network of an organization. Which two standard designs are recommended? (choose two.)

Options:

A.

5GHz provides increased network capacity with up to 23 nonoverlapping channels.

B.

For maximum throughput, the WLC is configured to dynamically set adjacent access points to the same channel.

C.

5GHz channel selection requires an autonomous access point.

D.

Adjacent cells with overlapping channels use a repeater access point.

E.

Cells that overlap one another are configured to use nonoverlapping channels.

Question 161

Which command entered on a switch configured with Rapid PVST+ listens and learns for a specific time period?

Options:

A.

switch(config)#spanning-tree vlan 1 max-age 6

B.

switch(config)#spanning-tree vlan 1 hello-time 10

C.

switch(config)#spanning-tree vlan 1 priority 4096

D.

switch(config)#spanning-tree vlan 1 forward-time 20

Question 162

How does a switch process a frame received on Fa0/1 with the destination MAC address of 0e38.7363.657b when the table is missing the address?

Options:

A.

lt drops the frame immediately.

B.

It forwards the frame back out of interface Fa0/1.

C.

It floods the frame to all interfaces except Fa0/1.

D.

It holds the frame until the MAC address timer expires and then drops the frame.

Question 163

Refer to the exhibit.

Which switch becomes the root of the spanning tree for VLAN 110?

Options:

A.

Switch 1

B.

Switch 2

C.

Switch 3

D.

Switch 4

Question 164

Refer to the exhibit.

The network administrator wants VLAN 67 traffic to be untagged between Switch 1 and Switch 2 while all other VLANs are to remain tagged.

Which command accomplishes this task?

Options:

A.

switchport access vlan 67

B.

switchport trunk allowed vlan 67

C.

switchport private-vlan association host 67

D.

switchport trunk native vlan 67

Question 165

What mechanism carries multicast traffic between remote sites and supports encryption?

Options:

A.

ISATAP

B.

GRE over IPsec

C.

IPsec over ISATAP

D.

GRE

Question 166

What are two improvements provided by automation for network management in an SDN environment? (Choose two)

Options:

A.

Data collection and analysis tools establish a baseline for the network

B.

Artificial intelligence identifies and prevents potential design failures.

C.

Machine learning minimizes the overall error rate when automating troubleshooting processes

D.

New devices are onboarded with minimal effort

E.

Proprietary Cisco APIs leverage multiple network management tools.

Question 167

Aside from discarding, which two states does the switch port transition through while using RSTP (802.1w)? (Choose two)

Options:

A.

listening

B.

blocking

C.

forwarding

D.

learning

E.

speaking

Question 168

Which type of security program is violated when a group of employees enters a building using the ID badge of only one person?

Options:

A.

intrusion detection

B.

user awareness

C.

physical access control

D.

network authorization

Question 169

Which security program element involves installing badge readers on data-center doors to allow workers to enter and exit based on their job roles?

Options:

A.

role-based access control

B.

biometrics

C.

multifactor authentication

D.

physical access control

Question 170

A network engineer is configuring an OSPFv2 neighbor adjacency Drag and drop the parameters from the left onto their required categories on the right. Not all parameters are used

Options:

Question 171

What are two benefits of controller-based networking compared to traditional networking?

Options:

A.

controller-based increases network bandwidth usage, while traditional lightens the load on the network.

B.

controller-based inflates software costs, while traditional decreases individual licensing costs

C.

Controller-based reduces network configuration complexity, while traditional increases the potential for errors

D.

Controller-based provides centralization of key IT functions. While traditional requires distributed management functions

E.

controller-based allows for fewer network failure, while traditional increases failure rates.

Question 172

What is a benefit of using a Cisco Wireless LAN Controller?

Options:

A.

Central AP management requires more complex configurations

B.

Unique SSIDs cannot use the same authentication method

C.

It supports autonomous and lightweight APs

D.

It eliminates the need to configure each access point individually

Question 173

Refer to Exhibit.

The loopback1 interface of the Atlanta router must reach the loopback3 interface of the Washington router. Which two static host routes must be configured on the New York router? (Choose two)

Options:

A.

ipv6 route 2000::1/128 2012::1

B.

ipv6 route 2000::3/128 2023::3

C.

ipv6 route 2000::3/128 s0/0/0

D.

ipv6 route 2000::1/128 2012::2

E.

ipv6 route 2000::1/128 s0/0/1

Question 174

A network engineer must back up 20 network router configurations globally within a customer environment. Which protocol allows the engineer to perform this function using the Cisco IOS MIB?

Options:

A.

CDP

B.

SNMP

C.

SMTP

D.

ARP

Question 175

Which access layer threat-mitigation technique provides security based on identity?

Options:

A.

Dynamic ARP Inspection

B.

using a non-default native VLAN

C.

802.1x

D.

DHCP snooping

Question 176

Drag and drop the characteristics of network architectures from the left onto the type of architecture on the right.

Options:

Question 177

Which device controls the forwarding of authentication requests for users when connecting to the network using a lightweight access point?

Options:

A.

TACACS server

B.

wireless access point

C.

RADIUS server

D.

wireless LAN controller

Question 178

Refer to exhibit.

Which statement explains the configuration error message that is received?

Options:

A.

It is a broadcast IP address

B.

The router does not support /28 mask.

C.

It belongs to a private IP address range.

D.

It is a network IP address.

Question 179

What criteria is used first during the root port selection process?

Options:

A.

local port ID

B.

lowest path cost to the root bridge

C.

lowest neighbor ' s bridge ID

D.

lowest neighbor ' s port ID

Question 180

Which CRUD operation corresponds to the HTTP GET method?

Options:

A.

read

B.

update

C.

create

D.

delete

Question 181

Which command on a port enters the forwarding state immediately when a PC is connected to it?

Options:

A.

switch(config)#spanning-tree portfast default

B.

switch(config)#spanning-tree portfast bpduguard default

C.

switch(config-if)#spanning-tree portfast trunk

D.

switch(config-if)#no spanning-tree portfast

Question 182

Refer to the exhibit.

Which type of route does R1 use to reach host 10.10.13.10/32?

Options:

A.

floating static route

B.

host route

C.

default route

D.

network route

Question 183

Which two protocols are supported on service-port interfaces? (Choose two.)

Options:

A.

RADIUS

B.

TACACS+

C.

SCP

D.

Telnet

E.

SSH

Question 184

Which two actions are performed by the Weighted Random Early Detection mechanism? (Choose two)

Options:

A.

It drops lower-priority packets before it drops higher-priority packets

B.

It can identify different flows with a high level of granularity

C.

It guarantees the delivery of high-priority packets

D.

It can mitigate congestion by preventing the queue from filling up

E.

It supports protocol discovery

Question 185

What is the primary purpose of a First Hop Redundancy Protocol?

Options:

A.

It allows directly connected neighbors to share configuration information.

B.

It allows a router to use bridge priorities to create multiple loop-free paths to a single destination.

C.

It reduces routing failures by allowing Layer 3 load balancing between OSPF neighbors that have the same link metric.

D.

It reduces routing failures by allowing more than one router to represent itself, as the default gateway of a network.

Question 186

Refer to the exhibit.

PC1 is trying to ping PC3 for the first time and sends out an ARP to S1 Which action is taken by S1?

Options:

A.

It forwards it out G0/3 only

B.

It is flooded out every port except G0/0.

C.

It drops the frame.

D.

It forwards it out interface G0/2 only.

Question 187

Why would VRRP be implemented when configuring a new subnet in a multivendor environment?

Options:

A.

when a gateway protocol is required that support more than two Cisco devices for redundancy

B.

to enable normal operations to continue after a member failure without requiring a change In a host ARP cache

C.

to ensure that the spanning-tree forwarding path to the gateway is loop-free

D.

to interoperate normally with all vendors and provide additional security features for Cisco devices

Question 188

Drag and drop the statements about networking from the left onto the corresponding networking types on the right

Options:

Question 189

Drag and drop the QoS terms from the left onto the descriptions on the right.

Options:

Question 190

What is a similarity between 1000BASE-LX and 1000BASE-T standards?

Options:

A.

Both use the same data-link header and trailer formats

B.

Both cable types support RJ-45 connectors

C.

Both cable types support Rj-45 connectors

D.

Both support up to 550 meters between nodes

Question 191

Refer to the exhibit.

A network engineer must update the configuration on Switch2 so that it sends LLDP packets every minute and the information sent via LLDP is refreshed every 3 minutes Which configuration must the engineer apply?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 192

Drag and drop the TCP or UDP details from the left onto their corresponding protocols on the right.

Options:

Question 193

Drag and drop the IPv6 addresses from the left onto the corresponding address types on the right.

Options:

Question 194

How does authentication differ from authorization?

Options:

A.

Authentication verifies the identity of a person accessing a network, and authorization determines what resource a user can access.

B.

Authentication is used to record what resource a user accesses, and authorization is used to determine what resources a user can access

C.

Authentication is used to determine what resources a user is allowed to access, and authorization is used to track what equipment is allowed access to the network

D.

Authentication is used to verify a person ' s identity, and authorization is used to create syslog messages for logins.

Question 195

Refer to the exhibit.

What is the next hop for traffic entering R1 with a destination of 10.1.2.126?

Options:

A.

10.165.20.126

B.

10.165.20.146

C.

10.165.20.166

D.

10.165.20.226

Question 196

Which QoS traffic handling technique retains excess packets in a queue and reschedules these packets for later transmission when the configured maximum bandwidth has been surpassed?

Options:

A.

weighted random early detection

B.

traffic policing

C.

traffic shaping

D.

traffic prioritization

Question 197

Refer to the exhibit.

What is the effect of this configuration?

Options:

A.

The switch port interface trust state becomes untrusted

B.

The switch port remains administratively down until the interface is connected to another switch

C.

Dynamic ARP inspection is disabled because the ARP ACL is missing

D.

The switch port remains down until it is configured to trust or untrust incoming packets

Question 198

Which PoE mode enables powered-device detection and guarantees power when the device is detected?

Options:

A.

dynamic

B.

static

C.

active

D.

auto

Question 199

An engineer is installing a new wireless printer with a static IP address on the Wi-Fi network. Which feature must be enabled and configured to prevent connection issues with the printer?

Options:

A.

client exclusion

B.

passive client

C.

DHCP address assignment

D.

static IP tunneling

Question 200

Refer to the exhibit.

Traffic sourced from the loopback0 Interface is trying to connect via ssh to the host at 10.0.1.15. What Is the next hop to the destination address?

Options:

A.

192.168.0.7

B.

192.168.0.4

C.

192.168.0.40

D.

192.168.3.5

Question 201

What is a function of Cisco Advanced Malware Protection for a Next-Generation IPS?

Options:

A.

authorizing potentially compromised wireless traffic

B.

inspecting specific files and file types for malware

C.

authenticating end users

D.

URL filtering

Question 202

Drag and drop the descriptions from the left onto the configuration-management technologies on the right.

Options:

Question 203

Refer to Exhibit.

Rotor to the exhibit. The IP address configurations must be completed on the DC-1 and HQ-1 routers based on these requirements:

DC-1 Gi1/0 must be the last usable address on a /30

DC-1 Gi1/1 must be the first usable address on a /29

DC-1 Gi1/2 must be the last usable address on a /28

HQ-1 Gil/3 must be the last usable address on a /29

Drag and drop the commands from the left onto the destination interfaces on the right. Not all commands are used

Options:

Question 204

Which two wireless security standards use Counter Mode with Cipher Block Chaining Message Authentication Code Protocol for encryption and data integrity ' ? (Choose two.)

Options:

A.

WPA2

B.

WPA3

C.

Wi-Fi 6

D.

WEP

E.

WPA

Question 205

Refer to the exhibit.

Which plan must be Implemented to ensure optimal QoS marking practices on this network?

Options:

A.

As traffic traverses MLS1 remark the traffic, but trust all markings at the access layer.

B.

Trust the IP phone markings on SW1 and mark traffic entering SW2 at SW2.

C.

Remark traffic as it traverses R1 and trust all markings at the access layer.

D.

As traffic enters from the access layer on SW1 and SW2. trust all traffic markings.

Question 206

Drag and drop the IPv6 address details from the left onto the corresponding types on the right.

Options:

Question 207

Refer to the exhibit.

Which configuration allows routers R14 and R86 to form an OSPFv2 adjacency while acting as a central point for exchanging OSPF information between routers?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 208

Which WLC management connection type is vulnerable to man-in-the-middle attacks?

Options:

A.

SSH

B.

HTTPS

C.

Telnet

D.

console

Question 209

Refer to the exhibit.

A network engineer is in the process of establishing IP connectivity between two sites. Routers R1 and R2 are partially configured with IP addressing. Both routers have the ability to access devices on their respective LANs. Which command set configures the IP connectivity between devices located on both LANs in each site?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 210

Refer to the exhibit.

Which command configures OSPF on the point-to-point link between routers R1 and R2?

Options:

A.

router-id 10.0.0.15

B.

neighbor 10.1.2.0 cost 180

C.

ipospf priority 100

D.

network 10.0.0.0 0.0.0.255 area 0

Question 211

Refer to the exhibit.

A company is configuring a failover plan and must implement the default routes in such a way that a floating static route will assume traffic forwarding when the primary link goes down. Which primary route configuration must be used?

Options:

A.

ip route 0.0.0.0 0.0.0.0 192.168.0.2 GigabitEthernet1/0

B.

ip route 0.0.0.0 0.0.0.0 192.168.0.2 tracked

C.

ip route 0.0.0.0 0.0.0.0 192.168.0.2 floating

D.

ip route 0.0.0.0 0.0.0.0 192.168.0.2

Question 212

Refer to the exhibit.

All traffic enters the CPE router from interface Serial0/3 with an IP address of 192 168 50 1 Web traffic from the WAN is destined for a LAN network where servers are load-balanced An IP packet with a destination address of the HTTP virtual IP of 192 1681 250 must be forwarded Which routing table entry does the router use?

Options:

A.

192.168.1.0/24 via 192.168.12.2

B.

192.168.1.128/25 via 192.168.13.3

C.

192.168.1.192/26 via 192.168.14.4

D.

192.168.1.224/27 via 192.168.15.5

Question 213

Refer to the exhibit.

Which two configurations must the engineer apply on this network so that R1 becomes the DR? (Choose two.)

A)

B)

C)

D)

E)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

E.

Option E

Question 214

What is a requirement for nonoverlapping Wi-Fi channels?

Options:

A.

different security settings

B.

discontinuous frequency ranges

C.

different transmission speeds

D.

unique SSIDs

Question 215

Refer to the exhibit.

Which switch becomes the root of a spanning tree for VLAN 20 if all links are of equal speed?

Options:

A.

SW1

B.

SW2

C.

SW3

D.

SW4

Question 216

Which type of API allows SDN controllers to dynamically make changes to the network?

Options:

A.

northbound API

B.

REST API

C.

SOAP API

D.

southbound API

Question 217

Which plane is centralized by an SDN controller?

Options:

A.

management-plane

B.

control-plane

C.

data-plane

D.

services-plane

Question 218

Drag and drop the HTTP methods used with REST-Based APIs from the left onto the descriptions on the right.

Options:

Question 219

Refer to the exhibit.

Which two commands when used together create port channel 10? (Choose two.)

Options:

A.

int range g0/0-1channel-group 10 mode active

B.

int range g0/0-1 channel-group 10 mode desirable

C.

int range g0/0-1channel-group 10 mode passive

D.

int range g0/0-1 channel-group 10 mode auto

E.

int range g0/0-1 channel-group 10 mode on

Question 220

Refer to the exhibit.

The given Windows PC is requesting the IP address of the host at To which IP address is the request sent?

Options:

A.

192.168.1.226

B.

192.168.1.100

C.

192.168.1.254

D.

192.168.1.253

Question 221

Refer to the exhibit.

Which minimum configuration items are needed to enable Secure Shell version 2 access to R15?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 222

Refer to the exhibit.

The DHCP server and clients are connected to the same switch. What is the next step to complete the DHCP configuration to allow clients on VLAN 1 to receive addresses from the DHCP server?

Options:

A.

Configure the ip dhcp snooping trust command on the interface that is connected to the DHCP client.

B.

Configure the ip dhcp relay information option command on the interface that is connected to the DHCP client.

C.

Configure the ip dhcp snooping trust command on the interface that is connected to the DHCP server.

D.

Configure the Ip dhcp relay information option command on the interface that is connected to the DHCP server.

Question 223

Refer to the exhibit.

Users need to connect to the wireless network with IEEE 802.11r-compatible devices. The connection must be maintained as users travel between floors or to other areas in the building What must be the configuration of the connection?

Options:

A.

Select the WPA Policy option with the CCKM option.

B.

Disable AES encryption.

C.

Enable Fast Transition and select the FT 802.1x option.

D.

Enable Fast Transition and select the FT PSK option.

Question 224

An engineer configures interface Gi1/0 on the company PE router to connect to an ISP Neighbor Discovery is disabled

Which action is necessary to complete the configuration if the ISP uses third-party network devices?

Options:

A.

Enable LLDP globally

B.

Disable autonegotiation

C.

Disable Cisco Discovery Protocol on the interface

D.

Enable LLDP-MED on the ISP device

Question 225

Refer to the exhibit.

The New York router is configured with static routes pointing to the Atlanta and Washington sites. Which two tasks must be performed so that the Serial0/0/0 interfaces on the Atlanta and Washington routers can reach one another?

(Choose two.)

Options:

A.

Configure the ipv6 route 2012::/126 2023::1 command on the Washington router.

B.

Configure the ipv6 route 2023::/126 2012::1 command on the Atlanta router.

C.

Configure the Ipv6 route 2012::/126 s0/0/0 command on the Atlanta router.

D.

Configure the ipv6 route 2023::/126 2012::2 command on the Atlanta router.

E.

Configure the ipv6 route 2012::/126 2023::2 command on the Washington router.

Question 226

Refer to the exhibit.

For security reasons, automatic Neighbor Discovery must be disabled on the R5 Gi0/1 interface. These tasks must be completed:

• Disable all Neighbor Discovery methods on R5 interface GiO/1.

• Permit Neighbor Discovery on R5 interface GiO/2.

• Verify there are no dynamically learned neighbors on R5 interface Gi0/1.

• Display the IP address of R6*s interface Gi0/2.

Which configuration must be used?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 227

An engineer is configuring switch SW1 to act an NTP server when all upstream NTP server connectivity fails. Which configuration must be used?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 228

Which protocol uses the SSL?

Options:

A.

HTTP

B.

SSH

C.

HTTPS

D.

Telnet

Question 229

Refer to the exhibit.

All VLANs are present in the VLAN database. Which command sequence must be applied to complete the configuration?

Options:

A.

Interface FastEthernet0/1 switchport trunk native vlan 10 switchport trunk allowed vlan 10,15

B.

Interface FastEthernet0/1 switchport mode trunk switchport trunk allowed vlan 10,15

C.

interface FastEthernet0/1 switchport mode access switchport voice vlan 10

D.

Interface FastEthernet0/1 switchport trunk allowed vlan add 10 vlan 10 private-vlan isolated

Question 230

What is a function performed by a web server?

Options:

A.

provide an application that is transmitted over HTTP

B.

send and retrieve email from client devices

C.

authenticate and authorize a user ' s identity

D.

securely store files for FTP access

Question 231

Refer to the exhibit.

An engineer is configuring an EtherChannel using LACP between Switches 1 and 2 Which configuration must be applied so that only Switch 1 sends LACP initiation packets?

Options:

A.

Switch 1 (config-if)#channel-group 1 mode onSwrtch2(config-if)#channel-group 1 mode passive

B.

Switch1(config-if)#channel-group 1 mode passiveSwitch2(config-if)#channel-group 1 mode active

C.

Switch1{config-if)£channel-group 1 mode activeSwitch2(config-if)#channel-group 1 mode passive

D.

Switch1(config-if)#channel-group 1 mode onSwitch2(config-if)#channel-group 1 mode active

Question 232

R1 has learned route 192.168.12.0/24 via IS-IS. OSPF, RIP. and Internal EIGRP Under normal operating conditions, which routing protocol is installed in the routing table?

Options:

A.

IS-IS

B.

RIP

C.

Internal EIGRP

D.

OSPF

Question 233

Refer to the exhibit.

Web traffic is coming in from the WAN interface. Which route takes precedence when the router is processing traffic destined for the LAN network at 10 0.10.0/24?

Options:

A.

via next-hop 10.0.1.5

B.

via next-hop 10 0 1.4

C.

via next-hop 10.0 1.50

D.

via next-hop 10.0 1 100

Question 234

Refer to the exhibit.

Switch A is newly configured. All VLANs are present in the VLAN database. The IP phone and PC A on Gi0/1 must be configured for the appropriate VLANs to establish connectivity between the PCs. Which command set fulfills the requirement?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 235

Refer to the exhibit.

What are two conclusions about this configuration? {Choose two.)

Options:

A.

The spanning-tree mode is Rapid PVST+.

B.

This is a root bridge.

C.

The root port is FastEthernet 2/1.

D.

The designated port is FastEthernet 2/1.

E.

The spanning-tree mode is PVST+.

Question 236

What is the default port-security behavior on a trunk link?

Options:

A.

It causes a network loop when a violation occurs.

B.

It disables the native VLAN configuration as soon as port security is enabled.

C.

It places the port in the err-disabled state if it learns more than one MAC address.

D.

It places the port in the err-disabled state after 10 MAC addresses are statically configured.

Question 237

What is a function of an endpoint on a network?

Options:

A.

forwards traffic between VLANs on a network

B.

connects server and client devices to a network

C.

allows users to record data and transmit to a tile server

D.

provides wireless services to users in a building

Question 238

Refer to the exhibit.

Which two commands must be configured on router R1 to enable the router to accept secure remote-access connections? (Choose two)

Options:

A.

transport input telnet

B.

crypto key generate rsa

C.

ip ssh pubkey-chain

D.

login console

E.

username cisco password 0 Cisco

Question 239

Drag and drop the threat-mitigation techniques from the left onto the types of threat or attack they mitigate on the right.

Options:

Question 240

Refer to the exhibit.

Which two commands were used to create port channel 10? (Choose two )

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

E.

Option E

Question 241

Refer to the exhibit.

Router R1 currently is configured to use R3 as the primary route to the Internet, and the route uses the default administrative distance settings. A network engineer must configure R1 so that it uses R2 as a backup, but only if R3 goes down. Which command must the engineer configure on R1 so that it correctly uses R2 as a backup route, without changing the administrative distance configuration on the link to R3?

Options:

A.

ip route 0.0.0.0 0.0.0.0 g0/1 1

B.

ip route 0.0.0.0 0.0.0.0 209.165.201.5 10

C.

ip route 0.0.0.0 0.0.0.0 209.165.200.226 1

D.

ip route 0,0.0.0 0.0.0.0 g0/1 6

Question 242

What is the function of " off-the-shelf " switches in a controller-based network?

Options:

A.

providing a central view of the deployed network

B.

forwarding packets

C.

making routing decisions

D.

setting packet-handling policies

Question 243

Refer to the exhibit. An engineer is asked to configure router R1 so that it forms an OSPF single-area neighbor relationship with R2. Which command sequence must be implemented to configure the router?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 244

Which QoS tool is used to optimize voice traffic on a network that is primarily intended for data traffic?

Options:

A.

FIFO

B.

WFQ

C.

PQ

D.

WRED

Question 245

Which characteristic differentiates the concept of authentication from authorization and accounting?

Options:

A.

user-activity logging

B.

service limitations

C.

consumption-based billing

D.

identity verification

Question 246

What is a function of Opportunistic Wireless Encryption in an environment?

Options:

A.

offer compression

B.

increase security by using a WEP connection

C.

provide authentication

D.

protect traffic on open networks

Question 247

What are two benefits of FHRPs? (Choose two.)

Options:

A.

They enable automatic failover of the default gateway.

B.

They allow multiple devices to serve as a single virtual gateway for clients in the network.

C.

They are able to bundle multiple ports to increase bandwidth.

D.

They prevent loops in the Layer 2 network.

E.

They allow encrypted traffic.

Question 248

Refer to the exhibit.

What is a reason for poor performance on the network interface?

Options:

A.

The interface is receiving excessive broadcast traffic.

B.

The cable connection between the two devices is faulty.

C.

The interface is operating at a different speed than the connected device.

D.

The bandwidth setting of the interface is misconfigured

Question 249

What is the same for both copper and fiber interfaces when using SFP modules?

Options:

A.

They support an inline optical attenuator to enhance signal strength

B.

They provide minimal interruption to services by being hot-swappable

C.

They offer reliable bandwidth up to 100 Mbps in half duplex mode

D.

They accommodate single-mode and multi-mode in a single module

Question 250

In software-defined architecture, which place handles switching for traffic through a Cisco router?

Options:

A.

Control

B.

Management

C.

Data

D.

application

Question 251

Which technology must be implemented to configure network device monitoring with the highest security?

Options:

A.

IP SLA

B.

syslog

C.

NetFlow

D.

SNMPv3

Question 252

Refer to the exhibit.

What does router R1 use as its OSPF router-ID?

Options:

A.

10.10.1.10

B.

10.10.10.20

C.

172.16.15.10

D.

192.168.0.1

Question 253

Refer to the exhibit.

A packet is being sent across router R1 to host 172.163.3.14. To which destination does the router send the packet?

Options:

A.

207.165.200.246 via Serial0/1/0

B.

207.165.200.254 via Serial0/0/1

C.

207.165.200.254 via Serial0/0/0

D.

207.165.200.250 via Serial/0/0/0

Question 254

Refer to the exhibit.

Drag and drop the networking parameters from the left onto the correct values on the right.

Options:

Question 255

Using direct sequence spread spectrum, which three 2.4-GHz channels are used to limit collisions?

Options:

A.

1,6,11

B.

1,5,10

C.

1,2,3

D.

5,6,7

Question 256

Refer to the exhibit.

A network engineer must block access for all computers on VLAN 20 to the web server via HTTP All other computers must be able to access the web server Which configuration when applied to switch A accomplishes this task?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 257

Refer to the exhibit.

With which metric was the route to host 172.16.0.202 learned?

Options:

A.

0

B.

110

C.

38443

D.

3184439

Question 258

An engineer must configure a WLAN using the strongest encryption type for WPA2- PSK. Which cipher fulfills the configuration requirement?

Options:

A.

WEP

B.

RC4

C.

AES

D.

TKIP

Question 259

Which action must be taken to assign a global unicast IPv6 address on an interface that is derived from the MAC address of that interface?

Options:

A.

configure a stateful DHCPv6 server on the network

B.

enable SLAAC on an interface

C.

disable the EUI-64 bit process

D.

explicitly assign a link-local address

Question 260

Which function does an SNMP agent perform?

Options:

A.

it sends information about MIB variables in response to requests from the NMS

B.

it requests information from remote network nodes about catastrophic system events.

C.

it manages routing between Layer 3 devices in a network

D.

it coordinates user authentication between a network device and a TACACS+ or RADIUS server

Question 261

Refer to the exhibit.

Router R1 is running three different routing protocols. Which route characteristic is used by the router to forward the packet that it receives for destination IP 172.16.32.1?

Options:

A.

longest prefix

B.

metric

C.

cost

D.

administrative distance

Question 262

Drag and drop to the characteristics of networking from the left onto the correct networking types on the right.

Options:

Question 263

Which unified access point mode continues to serve wireless clients after losing connectivity to the Cisco Wireless LAN Controller?

Options:

A.

sniffer

B.

mesh

C.

flexconnect

D.

local

Question 264

A Cisco IP phone receive untagged data traffic from an attached PC. Which action is taken by the phone?

Options:

A.

It allows the traffic to pass through unchanged

B.

It drops the traffic

C.

It tags the traffic with the default VLAN

D.

It tags the traffic with the native VLAN

Question 265

Refer to the exhibit.

Router R2 is configured with multiple routes to reach network 10 1.1 0/24 from router R1. What protocol is chosen by router R2 to reach the destination network 10.1 1 0/24?

Options:

A.

eBGP

B.

static

C.

OSPF

D.

EIGRP

Question 266

What are two benefits of FHRPs? (Choose two.)

Options:

A.

They prevent (loops in the Layer 2 network.

B.

They allow encrypted traffic.

C.

They are able to bundle multiple ports to increase bandwidth

D.

They enable automatic failover of the default gateway.

E.

They allow multiple devices to serve as a single virtual gateway for clients in the network

Question 267

Which two actions influence the EIGRP route selection process? (Choose two)

Options:

A.

The router calculates the reported distance by multiplying the delay on the exiting interface by 256.

B.

The router calculates the best backup path to the destination route and assigns it as the feasible successor.

C.

The router calculates the feasible distance of all paths to the destination route

D.

The advertised distance is calculated by a downstream neighbor to inform the local router of the bandwidth on the link

E.

The router must use the advertised distance as the metric for any given route

Question 268

What is the function of a server?

Options:

A.

It transmits packets between hosts in the same broadcast domain.

B.

It provides shared applications to end users.

C.

It routes traffic between Layer 3 devices.

D.

It Creates security zones between trusted and untrusted networks

Question 269

Drag and drop the TCP/IP protocols from the left onto the transmission protocols on the right

Options:

Question 270

An engineer must establish a trunk link between two switches. The neighboring switch is set to trunk or desirable mode. What action should be taken?

Options:

A.

configure switchport nonegotiate

B.

configure switchport mode dynamic desirable

C.

configure switchport mode dynamic auto

D.

configure switchport trunk dynamic desirable

Question 271

Refer to the exhibit.

Which action is taken by the router when a packet is sourced from 10.10.10.2 and destined for 10.10.10.16?

Options:

A.

It uses a route that is similar to the destination address

B.

It discards the packets.

C.

It floods packets to all learned next hops.

D.

It Queues the packets waiting for the route to be learned.

Question 272

Refer to the exhibit. After the configuration is applied, the two routers fail to establish an OSPF neighbor relationship. what is the reason for the problem?

Options:

A.

The OSPF router IDs are mismatched.

B.

Router2 is using the default helto timer.

C.

The network statement on Router1 is misconfigured.

D.

The OSPF process IDs are mismatched.

Question 273

How do AAA operations compare regarding user identification, user services and access control?

Options:

A.

Authorization provides access control and authentication tracks user services

B.

Authentication identifies users and accounting tracks user services

C.

Accounting tracks user services, and authentication provides access control

D.

Authorization identifies users and authentication provides access control

Question 274

Drag and drop the Cisco Wireless LAN Controller security settings from the left onto the correct security mechanism categories on the right.

Options:

Question 275

With REST API, which standard HTTP header tells a server which media type is expected by the client?

Options:

A.

Accept-Encoding: gzip. deflate

B.

Accept-Patch: text/example; charset=utf-8

C.

Content-Type: application/json; charset=utf-8

D.

Accept: application/json

Question 276

What is a characteristic of private IPv4 addressing?

Options:

A.

traverse the Internet when an outbound ACL is applied

B.

issued by IANA in conjunction with an autonomous system number

C.

composed of up to 65.536 available addresses

D.

used without tracking or registration

Question 277

Which two must be met before SSH can operate normally on a Cisco IOS switch? (Choose two)

Options:

A.

The switch must be running a k9 (crypto) IOS image

B.

The IP domain-name command must be configured on the switch

C.

IP routing must be enabled on the switch

D.

A console password must be configured on the switch

E.

Telnet must be disabled on the switch

Question 278

An engineer is configuring an encrypted password for the enable command on a router where the local user database has already been configured Drag and drop the configuration commands from the left into the correct sequence on the right Not all commands are used

Options:

Question 279

Which design element is a best practice when deploying an 802.11b wireless infrastructure?

Options:

A.

disabling TPC so that access points can negotiate signal levels with their attached wireless devices.

B.

setting the maximum data rate to 54 Mbps on the Cisco Wireless LAN Controller

C.

allocating nonoverlapping channels to access points that are in close physical proximity to one another

D.

configuring access points to provide clients with a maximum of 5 Mbps

Question 280

Which networking function occurs on the data plane?

Options:

A.

forwarding remote client/server traffic

B.

facilitates spanning-tree elections

C.

processing inbound SSH management traffic

D.

sending and receiving OSPF Helto packets

Question 281

How are VLAN hopping attacks mitigated?

Options:

A.

enable dynamic ARP inspection

B.

manually implement trunk ports and disable DTP

C.

activate all ports and place in the default VLAN

D.

configure extended VLANs

Question 282

Refer to the exhibit.

Which route type is configured to reach the internet?

Options:

A.

host route

B.

default route

C.

floating static route

D.

network route

Question 283

which IPv6 address block forwards packets to a multicast address rather than a unicast address?

Options:

A.

2000::/3

B.

FC00::/7

C.

FE80::/10

D.

FF00::/12

Question 284

Refer to the exhibit.

Which two commands, when configured on router R1, fulfill these requirements? (Choose two.)

Packets towards the entire network 2001:db8:2::/64 must be forwarded through router R2.

Packets toward host 2001:db8:23::14 preferably must be forwarded through R3.

Options:

A.

Ipv6 route 2001:db8:23::/128 fd00:12::2

B.

Ipv6 route 2001:db8:23::14/128 fd00:13::3

C.

Ipv6 route 2001:db8:23::14/64 fd00:12::2

D.

Ipv6 route 2001:db8:23::/64 fd00:12::2

E.

Ipv6 route 2001:db8:23::14/64 fd00:12::2 200

Question 285

When a WPA2-PSK WLAN is configured in the wireless LAN Controller, what is the minimum number of characters that in ASCII format?

Options:

A.

6

B.

8

C.

12

D.

18

Question 286

Refer to the exhibit.

If configuring a static default route on the router with the ip route 0.0.0.0 0.0.0.0 10.13.0.1 120 command how does the router respond?

Options:

A.

It ignores the new static route until the existing OSPF default route is removed

B.

It immediately replaces the existing OSPF route in the routing table with the newly configured static route

C.

It starts load-balancing traffic between the two default routes

D.

It starts sending traffic without a specific matching entry in the routing table to GigabitEthernet0/1

Question 287

Drag and drop the DNS lookup components from the left onto the functions on the right.

Options:

Question 288

Which action does the router take as it forwards a packet through the network?

Options:

A.

The router replaces the source and destination labels with the sending router interface label as a source and the next hop router label as a desbnabon

B.

The router encapsulates the source and destination IP addresses with the sending router P address as the source and the neighbor IP address as the destination

C.

The router replaces the original source and destination MAC addresses with the sending router MAC address as the source and neighbor MAC address as the destination

D.

The router encapsulates the original packet and then includes a tag that identifies the source router MAC address and transmit transparently to the destination

Question 289

Which goal is achieved by the implementation of private IPv4 addressing on a network?

Options:

A.

provides an added level of protection against Internet exposure

B.

provides a reduction in size of the forwarding table on network routers

C.

allows communication across the Internet to other private networks

D.

allows servers and workstations to communicate across public network boundaries

Question 290

Drag and drop the statement about networking from the left into the Corresponding networking types on the right. Not all statements are used.

Options:

Question 291

When a site-to-site VPN is configured, which IPsec mode provides encapsulation and encryption of the entire original IP packet?

Options:

A.

IPsec tunnel mode with AH

B.

IPsec transport mode with AH

C.

IPsec tunnel mode with ESP

D.

IPsec transport mode with ESP

Question 292

Which two values or settings must be entered when configuring a new WLAN in the Cisco Wireless LAN Controller GUI? (Choose two)

Options:

A.

management interface settings

B.

QoS settings

C.

Ip address of one or more access points

D.

SSID

E.

Profile name

Question 293

Refer to the exhibit.

R5 is the current DR on the network, and R4 is the BDR. Their interfaces are flapping, so a network engineer wants the OSPF network to elect a different DR and BDR. Which set of configurations must the engineer implement?

A)

B)

C)

D)

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Question 294

Which command must be entered to configure a DHCP relay?

Options:

A.

ip helper-address

B.

ip address dhcp

C.

ip dhcp pool

D.

ip dhcp relay

Question 295

How does a Cisco Unified Wireless network respond to Wi-Fi channel overlap?

Options:

A.

It alternates automatically between 2.4 GHz and 5 GHz on adjacent access points

B.

It allows the administrator to assign channels on a per-device or per-interface basis.

C.

It segregates devices from different manufacturers onto different channels.

D.

It analyzes client load and background noise and dynamically assigns a channel.

Question 296

What is the difference in data transmission delivery and reliability between TCP and UDP?

Options:

A.

TCP transmits data at a higher rate and ensures packet delivery. UDP retransmits lost data to ensure applications receive the data on the remote end.

B.

UDP sets up a connection between both devices before transmitting data. TCP uses the three-way handshake to transmit data with a reliable connection.

C.

UDP is used for multicast and broadcast communication. TCP is used for unicast communication and transmits data at a higher rate with error checking.

D.

TCP requires the connection to be established before transmitting data. UDP transmits data at a higher rate without ensuring packet delivery.

Question 297

Which 802.11 frame type is indicated by a probe response after a client sends a probe request?

Options:

A.

action

B.

management

C.

control

D.

data

Question 298

When deploying syslog, which severity level logs informational message?

Options:

A.

0

B.

2

C.

4

D.

6

Question 299

Which technology can prevent client devices from arbitrarily connecting to the network without state remediation?

Options:

A.

802.1x

B.

IP Source Guard

C.

MAC Authentication Bypass

D.

802.11n

Question 300

Refer to the exhibit.

The default-information originate command is configured under the R1 OSPF configuration After testing workstations on VLAN 20 at Site B cannot reach a DNS server on the Internet Which action corrects the configuration issue?

Options:

A.

Add the default-information originate command on R2

B.

Configure the ip route 0.0.0.0 0.0.0.0 10.10.10.18 command on R1

C.

Configure the ip route 0.0.0.0 0.0.0.0 10.10.10.2 command on R2

D.

Add the always keyword to the default-information originate command on R1

Question 301

Which IPv6 address type provides communication between subnets and is unable to route on the Internet?

Options:

A.

global unicast

B.

unique local

C.

link-local

D.

multicast

Question 302

Refer to the exhibit.

When PC-A sends traffic to PC-B, which network component is in charge of receiving the packet from PC-A verifying the IP addresses, and forwarding the packet to PC-B?

Options:

A.

Layer 2 switch

B.

Router

C.

Load balancer

D.

firewall

Question 303

Refer to Exhibit.

Which configuration must be applied to the router that configures PAT to translate all addresses in VLAN 200 while allowing devices on VLAN 100 to use their own IP addresses?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 304

What is a function of TFTP in network operations?

Options:

A.

transfers a backup configuration file from a server to a switch using a username and password

B.

transfers files between file systems on a router

C.

transfers a configuration files from a server to a router on a congested link

D.

transfers IOS images from a server to a router for firmware upgrades

Question 305

What are network endpoints?

Options:

A.

act as routers to connect a user to the service provider network

B.

a threat to the network if they are compromised

C.

support inter-VLAN connectivity

D.

enforce policies for campus-wide traffic going to the internet

Question 306

How does CAPWAP communicate between an access point in local mode and a WLC?

Options:

A.

The access point must directly connect to the WLC using a copper cable

B.

The access point must not be connected to the wired network, as it would create a loop

C.

The access point must be connected to the same switch as the WLC

D.

The access point has the ability to link to any switch in the network, assuming connectivity to the WLC

Question 307

What is a function of the Cisco DNA Center Overall Health Dashboard?

Options:

A.

It provides a summary of the top 10 global issues.

B.

It provides detailed activity logging for the 10 devices and users on the network.

C.

It summarizes the operational status of each wireless device on the network.

D.

It summarizes daily and weekly CPU usage for servers and workstations in the network.

Question 308

What is a syslog facility?

Options:

A.

Host that is configured for the system to send log messages

B.

password that authenticates a network management system to receive log messages

C.

group of log messages associated with the configured severity level

D.

set of values that represent the processes that can generate a log message

Question 309

Which level of severity must be set to get informational syslogs?

Options:

A.

alert

B.

critical

C.

notice

D.

debug

Exam Detail
Vendor: Cisco
Certification: CCNA
Exam Code: 200-301
Last Update: May 23, 2026
200-301 Question Answers
Page: 1 / 77
Total 1240 questions