Question 1
Question
Refer to the exhibit. Which type of ISP connectivity to the service provider edge is being used by company A?
Answer
-
multihomed
-
dual-multihomed
-
dual-homed
-
single-homed
Question 2
Question
Refer to the exhibit. Which Cisco Enterprise Architecture module is shown?
Answer
-
remote
-
campus infrastructure
-
service provider edge
-
enterprise campus
-
enterprise edge
Question 3
Question
The network design for a college with users at five sites is being developed. Where in the campus network architecture would servers used by all users be located?
Answer
-
data center
-
services
-
enterprise edge
-
access-distribution
Question 4
Question
Which network architecture functions through a combination of technologies that include wired, wireless, security, and more?
Answer
-
Cisco Borderless
-
Cisco Enterprise Edge
-
Cisco Enterprise Branch
-
Cisco Enterprise Campus
Question 5
Question
Which network module is the fundamental component of a campus design?
Question 6
Question
What is one advantage to designing networks in building block fashion for large companies?
Question 7
Question
A network engineer wants to redesign the wireless network and make use of wireless network controllers that manage the many deployed wireless access points. In which network design module of the campus network architecture would the centralized wireless network controllers be found?
Answer
-
access-distribution
-
data center
-
services
-
enterprise edge
Question 8
Question
Refer to the exhibit. Which type of Cisco hierarchical LAN design model is used at school site 1?
Answer
-
three-tier
-
7 layer
-
two-tier collapsed core
-
3 layer
Question 9
Question
Which layer of the Cisco Collaboration Architecture contains unified communications and conference software such as Cisco WebEx Meetings, WebEx Social, Cisco Jabber, and TelePresence?
Answer
-
applications and devices
-
services module
-
enterprise WAN
-
service provider edge
Question 10
Question
Why would a company want network engineers to adhere to structured engineering principles when designing networks?
Answer
-
The resiliency of a network depends on being able to modify portions of the network, add services, or increase network capacity without adding new hardware devices.
-
A hierarchical network model is a useful high-level tool for designing a reliable network infrastructure, although it increases the complexity of network design
-
The network can be easily designed because of the separation of the various functions that exist on a network into modules.
-
The network is not expected to remain available under abnormal conditions such as extreme traffic loads or denial-of-service events.
Question 11
Question
What is creating a new challenge for IT departments by changing the border of the enterprise network?
Answer
-
energy costs
-
tablets
-
access layer switching
-
company-owned desktops
Question 12
Question
Which approach in networking allows for network changes, upgrades, or the introduction of new services in a controlled and staged fashion?
Answer
-
modular
-
static
-
borderless
-
network module
Question 13
Question
Which Cisco technology allows diverse network devices to connect securely, reliably, and seamlessly to enterprise network resources?
Answer
-
service provider edge
-
building distribution
-
Cisco AnyConnect
-
enterprise edge
Question 14
Question
In which layer of the hierarchical enterprise LAN design model would PoE for VoIP phones and access points be considered?
Answer
-
data link
-
physical
-
distribution
-
access
-
core
Question 15
Question
Which network architecture combines individual components to provide a comprehensive solution allowing people to cooperate and contribute to the production of something?
Answer
-
Cisco Enterprise Branch Architecture
-
Cisco Borderless Network Architecture
-
Cisco Enterprise Campus Architecture
-
Cisco Collaboration Architecture
Question 16
Question
What feature is more important at the core layer than at any other hierarchical network design layer?
Answer
-
aggregation of network links
-
QoS classification and marking
-
easy access of end devices
-
packet switching speed
-
data security
Question 17
Question
What are two of the top trends that affect network architecture design? (Choose two.)
Question 18
Question
Which three network architectures have been introduced by Cisco to address the emerging technology challenges created by the evolving business models? (Choose three.)
Answer
-
Cisco Borderless
-
Cisco Collaboration
-
Cisco Data Center
-
Cisco Enterprise Campus
-
Cisco Enterprise Edge
-
Cisco Enterprise Branch
Question 19
Question
What are two structured engineering principles necessary for successful implementation of a network design? (Choose two.)
Answer
-
modularity
-
resiliency
-
availability
-
security
-
quality of service
Question 20
Question
What is the recommended technology to use over a public WAN infrastructure when a branch office is connected to the corporate site?
Answer
-
VPN
-
ATM
-
ISDN
-
municipal Wi-Fi
Question 21
Question
Which statement describes cable?
Answer
-
Delivering services over a cable network requires downstream frequencies in the 50 to 860 MHz range, and upstream frequencies in the 5 to 42 MHz range
-
Cable subscribers may expect up to 27 Mbps of bandwidth on the upload path.
-
Each cable subscriber has dedicated upstream and downstream bandwidth
-
The cable subscriber must purchase a cable modem termination system (CMTS).
Question 22
Question
A home user lives within 10 miles (16 kilometers) of the Internet provider network. Which type of technology provides high-speed broadband service with wireless access for this home user?
Answer
-
WiMAX
-
municipal Wi-Fi
-
802.11
-
DSL
Question 23
Question
Which feature is used when connecting to the Internet using DSL?
Answer
-
DSLAM
-
CMTS
-
IEEE 802.16
-
LTE
Question 24
Question
Which wireless technology provides Internet access through cellular networks?
Answer
-
LTE
-
municipal WiFi
-
WiMAX
-
satellite
Question 25
Question
Which connectivity method would be best for a corporate employee who works from home two days a week, but needs secure access to internal corporate databases?
Question 26
Question
A corporation is looking for a solution to connect multiple, newly established remote branch offices. Which consideration is important when selecting a private WAN connection rather than a public WAN connection?
Answer
-
data security and confidentiality during transmission
-
higher data transmission rate
-
lower cost
-
website and file exchange service support
Question 27
Question
Which statement describes a characteristic of a WAN?
Answer
-
WAN networks are owned by service providers
-
A WAN provides end-user network connectivity to the campus backbone
-
All serial links are considered WAN connections
-
A WAN operates within the same geographic scope of a LAN, but has serial links
Question 28
Question
Which two devices are needed when a digital leased line is used to provide a connection between the customer and the service provider? (Choose two.)
Answer
-
CSU
-
DSU
-
dialup modem
-
access server
-
Layer 2 switch
Question 29
Question
A new corporation needs a data network that must meet certain requirements. The network must provide a low cost connection to sales people dispersed over a large geographical area. Which two types of WAN infrastructure would meet the requirements? (Choose two.)
Answer
-
public infrastructure
-
Internet
-
satellite
-
dedicated
-
private infrastructure
Question 30
Question
A small company with 10 employees uses a single LAN to share information between computers. Which type of connection to the Internet would be appropriate for this company?
Answer
-
a broadband service, such as DSL, through their local service provider
-
a dialup connection that is supplied by their local telephone service provider
-
private dedicated lines through their local service provider
-
Virtual Private Networks that would enable the company to connect easily and securely with employees
Question 31
Question
Which WAN technology establishes a dedicated constant point-to-point connection between two sites?
Answer
-
leased lines
-
ISDN
-
Frame Relay
-
ATM
Question 32
Question
What is a long distance fiber-optic media technology that supports both SONET and SDH, and assigns incoming optical signals to specific wavelengths of light?
Question 33
Question
A customer needs a WAN virtual connection that provides high-speed, dedicated bandwidth between two sites. Which type of WAN connection would best fulfill this need?
Answer
-
Ethernet WAN
-
packet-switched network
-
circuit-switched network
-
MPLS
Question 34
Question
Which WAN technology is cell-based and well suited to carry voice and video traffic?
Answer
-
ATM
-
Frame Relay
-
VSAT
-
ISDN
Question 35
Question
Which equipment is needed for an ISP to provide Internet connections through cable service?
Answer
-
CMTS
-
DSLAM
-
access server
-
CSU/DSU
Question 36
Question
Which solution can provide Internet access to remote locations where no regular WAN services are available?
Answer
-
VSAT
-
WiMAX
-
municipal Wi-Fi
-
Ethernet
Question 37
Question
Which network scenario will require the use of a WAN?
Answer
-
Employees need to connect to the corporate email server through a VPN while traveling.
-
Employees need to access web pages that are hosted on the corporate web servers in the DMZ within their building
-
Employees in the branch office need to share files with the headquarters office that is located in a separate building on the same campus network
-
Employee workstations need to obtain dynamically assigned IP addresses
Question 38
Question
Which geographic scope requirement would be considered a distributed WAN scope?
Answer
-
many-to-many
-
local
-
one-to-one
-
regional
-
global
-
one-to-many
Question 39
Question
What is an advantage of packet-switched technology over circuit-switched technology?
Answer
-
Packet-switched networks can efficiently use multiple routes inside a service provider network.
-
Packet-switched networks are less susceptible to jitter than circuit-switched networks are
-
Packet-switched networks usually experience lower latency than circuit-switched networks experience
-
Packet-switched networks do not require an expensive permanent connection to each endpoint
Question 40
Question
What are two common high-bandwidth fiber-optic media standards? (Choose two.)
Question 41
Question
What is a requirement of a connectionless packet-switched network?
Answer
-
Full addressing information must be carried in each data packet
-
Each packet has to carry only an identifier
-
A virtual circuit is created for the duration of the packet delivery
-
The network predetermines the route for a packet
Question 42
Question
What PPP information will be displayed if a network engineer issues the show ppp multilink command on Cisco router?
Answer
-
the serial interfaces participating in the multilink
-
the IP addresses of the link interfaces
-
the link LCP and NCP status
-
the queuing type on the link
Question 43
Question
In which situation would the use of PAP be preferable to the use of CHAP?
Answer
-
when plain text passwords are needed to simulate login at the remote host
-
when a network administrator prefers it because of ease of configuration
-
when multilink PPP is used
-
when router resources are limited
Question 44
Question
Refer to the exhibit. Which statement describes the status of the PPP connection?
Answer
-
Neither the link-establishment phase nor the network-layer phase completed successfully.
-
Only the link-establishment phase completed successfully.
-
Both the link-establishment and network-layer phase completed successfully.
-
Only the network-layer phase completed successfully.
Question 45
Question
Which serial 0/0/0 interface state will be shown if no serial cable is attached to the router, but everything else has been correctly configured and turned on?
Answer
-
Serial 0/0/0 is down, line protocol is down
-
Serial 0/0/0 is administratively down, line protocol is down
-
Serial 0/0/0 is up, line protocol is up
-
Serial 0/0/0 is up, line protocol is down
-
Serial 0/0/0 is up (looped)
-
Serial 0/0/0 is up (disabled)
Question 46
Question
A network engineer is monitoring an essential, but poor quality, PPP WAN link that periodically shuts down. An examination of the interface configurations shows that the ppp quality 90 command has been issued. What action could the engineer take to reduce the frequency with which the link shuts down?
Answer
-
Issue the command ppp quality 70.
-
Issue the command ppp quality 100
-
Set the DCE interface to a lower clock rate
-
Use the bandwidth command to increase the bandwidth of the link
Question 47
Question
Which three are types of LCP frames used with PPP? (Choose three.)
Question 48
Question
Which command can be used to view the cable type that is attached to a serial interface?
Answer
-
Router(config)# show controllers
-
Router(config)# show ip interface
-
Router(config)# show ip interface brief
-
Router(config)# show interfaces
Question 49
Question
How does PPP interface with different network layer protocols?
Answer
-
by using separate NCPs
-
by specifying the protocol during link establishment through LCP
-
by encoding the information field in the PPP frame
-
by negotiating with the network layer handler
Question 50
Question
Which protocol will terminate the PPP link after the exchange of data is complete?
Question 51
Question
Which is an advantage of using PPP on a serial link instead of HDLC?
Answer
-
option for authentication
-
option for session establishment
-
fixed-size frames
-
higher speed transmission
Question 52
Question
At which layer of the OSI model does multiplexing take place?
Answer
-
Layer 3
-
Layer 4
-
Layer 2
-
Layer 1
Question 53
Question
During a PPP session establishment phase, which two messages are sent by the requested party if the options are not acceptable? (Choose two.)
Answer
-
Configure-Reject
-
Configure-Nak
-
Protocol-Reject
-
Code-Reject
-
Discard-Request
Question 54
Question
A network engineer is troubleshooting the loss of MPEG video viewing quality as MPEG video files cross a PPP WAN link. What could be causing this loss of quality?
Answer
-
The compress command was used when PPP was configured on the interfaces
-
Link Quality Monitoring was not configured correctly on each interface.
-
The clock rates configured on each serial interface do not match
-
PAP authentication was misconfigured on the link interfaces
Question 55
Question
Which address is used in the Address field of a PPP frame?
Answer
-
a single byte of binary 11111111
-
a single byte of binary 10101010
-
the IP address of the serial interface
-
a single byte of binary 00000000
Question 56
Question
Which three physical layer interfaces support PPP? (Choose three.)
Answer
-
HSSI
-
asynchronous serial
-
synchronous serial
-
FastEthernet
-
GigabitEthernet
-
Ethernet
Question 57
Question
Refer to the exhibit. A network administrator is configuring the PPP link between the two routers. However, the PPP link cannot be established. Based on the partial output of the show running-config command, what is the cause of the problem?
Answer
-
The passwords do not match
-
The interface IP addresses are in different subnets
-
The usernames do not match
-
The passwords should be longer than 8 characters
Question 58
Question
Refer to the exhibit. Based on the debug command output that is shown, which statement is true of the operation of PPP.
Answer
-
A PPP session was successfully established.
-
Both PAP and CHAP authentication were attempted
-
CHAP authentication failed because of an unknown hostname.
-
The debug output is from router R2.
Question 59
Question
Which three statements are true about PPP? (Choose three.)
Answer
-
PPP uses LCPs to establish, configure, and test the data link connection.
-
PPP can use synchronous and asynchronous circuits
-
PPP uses LCPs to agree on format options such as authentication, compression, and error detection.
-
PPP can only be used between two Cisco devices.
-
PPP carries packets from several network layer protocols in LCPs.
Question 60
Question
Refer to the exhibit. What type of Layer 2 encapsulation will be used for connection D on the basis of this configuration on a newly installed router:
RtrA(config)# interface serial0/0/0
RtrA(config-if)# ip address 128.107.0.2 255.255.255.252
RtrA(config-if)# no shutdown
Answer
-
HDLC
-
PPP
-
Frame Relay
-
Ethernet
Question 61
Question
Which two functions are provided by the Local Management Interface (LMI) that is used in Frame Relay networks? (Choose two.)
Question 62
Question
Refer to the exhibit. A network administrator is configuring Frame Relay subinterfaces on R1. A distance vector routing protocol has also been configured. Data is routing successfully from R1 to networks that are connected to R2, R3, and R4, but routing updates between R2 and R3 are failing. What is the possible cause of this failure?
Answer
-
Split horizon is preventing successful routing table updates on the multipoint link
-
Subinterfaces cannot be used on multipoint Frame Relay links
-
Multipoint Frame Relay networks cannot be used with this IP addressing scheme
-
Two DLCI identifiers cannot be configured on one subinterface
Question 63
Question
What are the two major criteria that constitute the cost of a Frame Relay circuit? (Choose two.)
Answer
-
local loop
-
required bandwidth
-
QoS
-
end-to-end connectivity
-
circuit management fees
Question 64
Question
A network administrator uses the following command to configure a Frame Relay connection on a router towards the service provider:
R1(config-if)# frame-relay map ip 209.165.200.225 102 broadcast
What is the purpose of using the broadcast keyword?
Answer
-
to support dynamic routing protocol updates across the link
-
to enable dynamic IP address-to-DLCI mapping
-
to support IP address to MAC address resolution for the interface in the service provider site
-
to enable VoIP packet transmission across the link
Question 65
Question
Refer to the exhibit. A network administrator issues the show frame-relay map command to troubleshoot the Frame Relay connection problem. Based on the output, what is the possible cause of the problem?
Answer
-
The Frame Relay map statement on the R3 router for the PVC to R2 is configured with an incorrect DLCI number.
-
Inverse ARP is providing false information to the R1 router.
-
The IP address on S0/0/1 of R3 is configured incorrectly.
-
The S0/0/1 interface of the R2 router has been configured with the encapsulation frame relay ietf command
-
The S0/0/1 interface of the R2 router is down.
Question 66
Question
Which two Frame Relay router reachability issues are resolved by configuring logical subinterfaces? (Choose two.)
Answer
-
Link-state routing protocols are unable to complete neighbor discovery
-
Distance vector routing protocols are unable to forward routing updates back out the incoming interface to other remote routers
-
Frame Relay is unable to map a remote IP address to a DLCI
-
LMI status inquiry messages sent to the network are not received
-
Inverse ARP fails to associate all IP addresses to the correct DLCIs
Question 67
Question
Refer to the exhibit. Which two statements are correct? (Choose two.)
Answer
-
The IPv4 address of interface S0/1/1 on RB is 192.168.1.2
-
The DLCI that is attached to the VC on RA to RB is 62.
-
The Frame Relay map was set by using the command frame-relay map.
-
The IPv4 address of interface S0/1/0 on RA is 192.168.1.2.
-
The DLCI that is attached to the VC on RB to RA is 62.
Question 68
Question
The show frame-relay pvc command is best utilized to display the number for which type of packets that are received by the router?
Question 69
Question
Why would a customer request a Frame Relay circuit with a CIR of zero?
Answer
-
to have a link with reduced costs
-
to have a backup circuit for critical data transmissions
-
to have a circuit used for voice traffic
-
to have better QoS
-
to have a circuit used for network management traffic
Question 70
Question
Which three notification mechanisms are used when congestion is present in a Frame Relay network? (Choose three.)
Answer
-
BECN
-
DE
-
FECN
-
inverse ARP
-
DLCI
-
CIR
Question 71
Question
A router interface connects to a Frame Relay network over a preconfigured logical circuit that does not have a direct electrical connection from end to end. Which type of circuit is being used?
Answer
-
PVC
-
SVC
-
full mesh
-
hub and spoke
-
dedicated leased line
Question 72
Question
What is an advantage of Frame Relay WAN technology compared with leased lines?
Answer
-
It uses one interface to connect to several remote sites
-
It supports both voice and data traffic
-
It provides permanent dedicated capacity to the customers
-
It offers a guaranteed direct electrical circuit from end to end
Question 73
Question
Which three actions can be taken to solve Layer 3 routing protocol router reachability issues when using Frame Relay? (Choose three.)
Question 74
Question
A network administrator has statically configured the LMI type on the interface of a Cisco router that is running Cisco IOS Release 11.2. If the service provider modifies its own LMI type in the future, what step must the network administrator take?
Answer
-
The network administrator must statically set the LMI type to be compatible with the service provider
-
The network administrator simply has to verify connectivity with the provider, because the router has an LMI autosensing feature that automatically detects the LMI type
-
The network administrator does not have to do anything, because all LMI types are compatible with one another.
-
The network administrator must modify the keepalive time interval to maintain connectivity with the LMI type of the service provider.
Question 75
Question
Which technology allows a Layer 3 IPv4 address to be dynamically obtained from a Layer 2 DLCI?
Answer
-
Inverse Address Resolution Protocol
-
Address Resolution Protocol
-
Neighbor Discovery
-
Inverse Neighbor Discovery
Question 76
Question
When would the multipoint keyword be used in Frame Relay PVCs configuration?
Answer
-
when participating routers are in the same subnet
-
when using physical interfaces
-
when global DLCIs are in use
-
when multicasts must be supported
Question 77
Question
A network administrator of a large organization is designing a Frame Relay network. The organization needs redundancy between some key sites but not all. What WAN topology should the administrator choose to meet their needs?
Answer
-
partial mesh
-
star
-
extended star
-
full mesh
Question 78
Question
A network engineer has issued the interface serial 0/0/1.102 point-to-point command on a router that will be communicating with another router over a Frame Relay virtual circuit that is identified by the DLCI 102. Which two commands would be appropriate for the network engineer to issue next? (Choose two.)
Answer
-
frame-relay interface-dlci 102
-
ip address 10.1.1.10 255.255.255.252
-
no ip address
-
encapsulation frame relay
-
no shutdown
Question 79
Question
Refer to the exhibit. Based on the output that is shown, what type of NAT has been implemented?
Answer
-
PAT using an external interface
-
dynamic NAT with a pool of two public IP addresses
-
static NAT with a NAT pool
-
static NAT with one entry
Question 80
Question
Refer to the exhibit. What is the purpose of the command marked with an arrow shown in the partial configuration output of a Cisco broadband router?
Answer
-
defines which addresses can be translated
-
defines which addresses are allowed into the router
-
defines which addresses are allowed out of the router
-
defines which addresses are assigned to a NAT pool
Question 81
Question
What is the purpose of port forwarding?
Answer
-
Port forwarding allows an external user to reach a service on a private IPv4 address that is located inside a LAN.
-
Port forwarding allows users to reach servers on the Internet that are not using standard port numbers.
-
Port forwarding allows an internal user to reach a service on a public IPv4 address that is located outside a LAN.
-
Port forwarding allows for translating inside local IP addresses to outside local addresses
Question 82
Question
Which statement accurately describes dynamic NAT?
Answer
-
It provides an automated mapping of inside local to inside global IP addresses.
-
It dynamically provides IP addressing to internal hosts
-
It always maps a private IP address to a public IP address
-
It provides a mapping of internal host names to IP addresses.
Question 83
Question
Which version of NAT allows many hosts inside a private network to simultaneously use a single inside global address for connecting to the Internet?
Answer
-
PAT
-
port forwarding
-
dynamic NAT
-
static NAT
Question 84
Question
Refer to the exhibit. R1 is configured for NAT as displayed. What is wrong with the configuration?
Answer
-
NAT-POOL2 is not bound to ACL 1.
-
Interface Fa0/0 should be identified as an outside NAT interface.
-
The NAT pool is incorrect
-
Access-list 1 is misconfigured
Question 85
Question
What is a disadvantage of NAT?
Answer
-
There is no end-to-end addressing
-
The internal hosts have to use a single public IPv4 address for external communication
-
The router does not need to alter the checksum of the IPv4 packets.
-
The costs of readdressing hosts can be significant for a publicly addressed network.
Question 86
Question
Which prefix is used for IPv6 ULAs?
Answer
-
FC00::/7
-
2001:7F8::/29
-
FF02::1:FF00:0/104
-
2001:DB8:1:2::/64
Question 87
Question
How does NAT complicate the use of IPsec?
Answer
-
Header values are modified which causes issues with integrity checks.
-
End-to-end IPv4 traceability is lost.
-
Troubleshooting is made impossible
-
Network performance is degraded even more than with just NAT.
Question 88
Question
A network administrator configures the border router with the command
R1(config)# ip nat inside source list 4 pool corp
What is required to be configured in order for this particular command to be functional?
Answer
-
a NAT pool named corp that defines the starting and ending public IP addresses
-
ip nat outside to be enabled on the interface that connects to the LAN affected by the NAT
-
an access list numbered 4 that defines the starting and ending public IP addresses
-
an access list named corp that defines the private addresses that are affected by NAT
-
a VLAN named corp to be enabled and active and routed by R1
Question 89
Question
What is the group of public IPv4 addresses used on a NAT-enabled router known as?
Answer
-
inside global addresses
-
outside local addresses
-
outside global addresses
-
inside local addresses
Question 90
Question
Refer to the exhibit. The NAT configuration applied to the router is as follows:
ERtr(config)# access-list 1 permit 10.0.0.0 0.255.255.255
ERtr(config)# ip nat pool corp 209.165.201.6 209.165.201.30 netmask 255.255.255.224
ERtr(config)# ip nat inside source list 1 pool corp overload
ERtr(config)# ip nat inside source static 10.10.10.55 209.165.201.4
ERtr(config)# interface gigabitethernet 0/0
ERtr(config-if)# ip nat inside
ERtr(config-if)# interface serial 0/0/0
ERtr(config-if)# ip nat outside
Based on the configuration and the output shown, what can be determined about the NAT status within the organization?
Answer
-
Not enough information is given to determine if both static and dynamic NAT are working.
-
NAT is working
-
Static NAT is working, but dynamic NAT is not.
-
Dynamic NAT is working, but static NAT is not.
Question 91
Question
Which configuration would be appropriate for a small business that has the public IP address of 209.165.200.225/30 assigned to the external interface on the router that connects to the Internet?
Answer
-
access-list 1 permit 10.0.0.0 0.255.255.255
ip nat inside source list 1 interface serial 0/0/0 overload
-
access-list 1 permit 10.0.0.0 0.255.255.255
ip nat pool comp 192.168.2.1 192.168.2.8 netmask 255.255.255.240
ip nat inside source list 1 pool comp overload
ip nat inside source static 10.0.0.5 209.165.200.225
-
access-list 1 permit 10.0.0.0 0.255.255.255
ip nat pool comp 192.168.2.1 192.168.2.8 netmask 255.255.255.240
ip nat inside source list 1 pool comp
-
access-list 1 permit 10.0.0.0 0.255.255.255
ip nat pool comp 192.168.2.1 192.168.2.8 netmask 255.255.255.240
ip nat inside source list 1 pool comp overload
Question 92
Question
When NAT is employed in a small office, which address type is typically used for hosts on the local LAN?
Answer
-
private IP addresses
-
Internet-routable addresses
-
both private and public IP addresses
-
global public IP addresses
Question 93
Question
When dynamic NAT without overloading is being used, what happens if seven users attempt to access a public server on the Internet when only six addresses are available in the NAT pool?
Answer
-
The request to the server for the seventh user fails
-
All users can access the server
-
No users can access the server.
-
The first user gets disconnected when the seventh user makes the request
Question 94
Question
Which technology would be used on a router that is running both IPv4 and IPv6?
Answer
-
dual stack
-
NAT for IPv6
-
dynamic NAT
-
static NAT
Question 95
Question
What is a characteristic of unique local addresses?
Answer
-
They allow sites to be combined without creating any address conflicts
-
They are defined in RFC 3927.
-
Their implementation depends on ISPs providing the service.
-
They are designed to improve the security of IPv6 networks
Question 96
Question
What are two of the required steps to configure PAT? (Choose two.)
Answer
-
Identify the inside interface
-
Define a pool of global addresses to be used for overload translation
-
Create a standard access list to define applications that should be translated
-
Define the hello and interval timers to match the adjacent neighbor router
-
Define the range of source ports to be used
Question 97
Question
Which type of NAT maps a single inside local address to a single inside global address?
Answer
-
static
-
dynamic
-
overloading
-
port address translation
Question 98
Question
Typically, which network device would be used to perform NAT for a corporate environment?
Answer
-
router
-
switch
-
server
-
host device
-
DHCP server
Question 99
Question
Which DSL technology provides higher downstream bandwidth to the user than upstream bandwidth?
Question 100
Question
What two layers of the OSI model are defined by DOCSIS? (Choose two.)
Answer
-
Layer 1
-
Layer 2
-
Layer 3
-
Layer 4
-
Layer 5
-
Layer 6
-
Layer 7
Question 101
Question
What are two features of wavelengths in the electromagnetic spectrum? (Choose two.)
Answer
-
They are the distance from the peak of one radio wave to the peak of the next radio wave
-
They are calculated by the speed of propagation of the electromagnetic signal divided by its frequency in cycles per second
-
They are the distance from the peak of one radio wave to the trough of the next radio wave
-
They are the rate at which current or voltage cycles occur
-
They are calculated by the number of waves per second
Question 102
Question
Which two network components does a teleworker require to connect remotely and securely from home to the corporate network? (Choose two.)
Answer
-
VPN client software or VPN-enabled router
-
broadband Internet connection
-
VPN server or concentrator
-
authentication server
-
multifunction security appliance
Question 103
Question
What are two Layer 2 WAN technologies that can provide secure remote connections between corporate branch offices? (Choose two.)
Answer
-
Frame Relay
-
leased lines
-
QoS
-
LTE
-
IPsec
Question 104
Question
What are two characteristics of a PPPoE configuration on a Cisco customer router? (Choose two.)
Answer
-
The Ethernet interface does not have an IP address
-
The PPP configuration is on the dialer interface
-
The customer router CHAP username and password are independent of what is configured on the ISP router
-
The dialer pool command is applied to the Ethernet interface to link it to the dialer interface
-
An MTU size of 1492 bytes is configured on the Ethernet interface
Question 105
Question
Which cable network communication technology is secure, extremely resistant to noise, and employs spread-spectrum technology?
Question 106
Question
Which standard specifies the channel frequencies and the deterministic access method of cable networks?
Question 107
Question
Which technology provides a secure connection between a SOHO and the headquarters office?
Question 108
Question
What mobile broadband communication Layer 2 technology uses a special coding scheme to assign each transmitter a specific code?
Question 109
Question
Which type of long distance telecommunication technology provides point-to-point connections and cellular access?
Answer
-
WiMax
-
satellite
-
municipal Wi-Fi
-
mobile broadband
Question 110
Question
Which medium is used for delivering data via DSL technology through PSTN?
Answer
-
fiber
-
copper
-
wireless
-
radio frequency
Question 111
Question
What technology provides service providers the capability to use authentication, accounting, and link management features to customers over Ethernet networks?
Question 112
Question
Which broadband wireless technology is based on the 802.11 standard?
Answer
-
municipal Wi-Fi
-
UMTS
-
CDMA
-
WiMAX
Question 113
Question
Which broadband technology would be best for a user that needs remote access when traveling in mountains and at sea?
Answer
-
satellite
-
Wi-Fi Mesh
-
mobile broadband
-
WiMax
Question 114
Question
What are two disadvantages of employing teleworkers in an organization? (Choose two.)
Answer
-
the need to implement a new management style
-
increased difficulty of tracking task progress
-
slower customer service response times
-
increase in office expenses
-
increased usage of sick or vacation days
Question 115
Question
A company is looking for the least expensive broadband solution that provides at least 10 Mb/s download speed. The company is located 5 miles from the nearest provider. Which broadband solution would be appropriate?
Answer
-
cable
-
DSL
-
satellite
-
WiMax
Question 116
Question
What functionality is required on routers to provide remote workers with VoIP and videoconferencing capabilities?
Question 117
Question
How is voice traffic affected when the customer uses ADSL technology?
Answer
-
ADSL signals can distort voice transmissions
-
No special equipment is needed to separate voice and data signals
-
Voice signals are on a separate wire pair from ADSL signals
-
Voice traffic is interrupted if the ADSL service fails
Question 118
Question
What advantage does DSL have compared to cable technology?
Answer
-
DSL is not a shared medium
-
DSL has no distance limitations
-
DSL is faster
-
DSL upload and download speeds are always the same
Question 119
Question
Which two OSI Layer 1 specifications does DOCSIS define for a cable Internet connection? (Choose two.)
Answer
-
modulation technique
-
channel bandwidth
-
the separation of the voice and data transmissions
-
VPN tunneling requirements
-
a deterministic media access method
Question 120
Question
Why is the MTU for a PPPoE DSL configuration reduced from 1500 bytes to 1492?
Answer
-
to accommodate the PPPoE headers
-
to establish a secure tunnel with less overhead
-
to reduce congestion on the DSL link
-
to enable CHAP authentication
Question 121
Question
When PPPoE is configured on a customer router, which two commands must have the same value for the configuration to work? (Choose two.)
Question 122
Question
Two corporations have just completed a merger. The network engineer has been asked to connect the two corporate networks without the expense of leased lines. Which solution would be the most cost effective method of providing a proper and secure connection between the two corporate networks?
Answer
-
site-to-site VPN
-
Cisco Secure Mobility Clientless SSL VPN
-
Cisco AnyConnect Secure Mobility Client with SSL
-
Frame Relay
-
remote access VPN using IPsec
Question 123
Question
How can the use of VPNs in the workplace contribute to lower operating costs?
Answer
-
VPNs can be used across broadband connections rather than dedicated WAN links.
-
High-speed broadband technology can be replaced with leased lines
-
VPNs require a subscription from a specific Internet service provider that specializes in secure connections.
-
VPNs prevents connectivity to SOHO users
Question 124
Question
A network design engineer is planning the implementation of an IPsec VPN. Which hashing algorithm would provide the strongest level of message integrity?
Answer
-
512-bit SHA
-
SHA-1
-
AES
-
MD5
Question 125
Question
Refer to the exhibit. A tunnel was implemented between routers R1 and R2. Which two conclusions can be drawn from the R1 command output? (Choose two.)
Answer
-
A GRE tunnel is being used.
-
The data that is sent across this tunnel is not secure.
-
This tunnel mode provides encryption
-
This tunnel mode does not support IP multicast tunneling.
-
This tunnel mode is not the default tunnel interface mode for Cisco IOS software.
Question 126
Question
Which two characteristics describe IPsec VPNs? (Choose two.)
Answer
-
Specific PC client configuration is required to connect to the VPN.
-
IPsec authenticates by using shared secrets or digital certificates.
-
IPsec authentication is one-way or two-way
-
IPsec is specifically designed for web-enabled applications
-
Key lengths range from 40 bits to 256 bits
Question 127
Question
How is "tunneling" accomplished in a VPN?
Answer
-
New headers from one or more VPN protocols encapsulate the original packets.
-
Packets are disguised to look like other types of traffic so that they will be ignored by potential attackers
-
All packets between two hosts are assigned to a single physical medium to ensure that the packets are kept private.
-
A dedicated circuit is established between the source and destination devices for the duration of the connection.
Question 128
Question
Which service of IPsec verifies that secure connections are formed with the intended sources of data?
Answer
-
authentication
-
confidentiality
-
data integrity
-
encryption
Question 129
Question
Which two scenarios are examples of remote access VPNs? (Choose two.)
Answer
-
A mobile sales agent is connecting to the company network via the Internet connection at a hotel.
-
An employee who is working from home uses VPN client software on a laptop in order to connect to the company network.
-
A toy manufacturer has a permanent VPN connection to one of its parts suppliers.
-
All users at a large branch office can access company resources through a single VPN connection
-
A small branch office with three employees has a Cisco ASA that is used to create a VPN connection to the HQ
Question 130
Question
What is an advantage of using the Cisco Secure Mobility Clientless SSL VPN?
Answer
-
Clients do not require special software.
-
Any device can connect to the network without authentication
-
Security is provided by prohibiting network access through a browser
-
Clients use SSH to access network resources
Question 131
Question
Which critical function that is provided by IPsec ensures that data has not been changed in transit between the source and destination?
Answer
-
integrity
-
confidentiality
-
authentication
-
anti-replay protection
Question 132
Question
Which statement describes a feature of site-to-site VPNs?
Answer
-
Internal hosts send normal, unencapsulated packets.
-
The VPN connection is not statically defined.
-
VPN client software is installed on each host
-
Individual hosts can enable and disable the VPN connection
Question 133
Question
What is an IPsec protocol that provides data confidentiality and authentication for IP packets?
Question 134
Question
What is the purpose of utilizing Diffie-Hellman (DH) algorithms as part of the IPsec standard?
Answer
-
DH algorithms allow two parties to establish a shared secret key that is used by encryption and hash algorithms.
-
DH algorithms allow two parties to establish a shared public key that is used by encryption and hash algorithms.
-
DH algorithms allow unlimited parties to establish a shared secret key that is used by encryption and hash algorithms.
-
DH algorithms allow unlimited parties to establish a shared public key that is used by encryption and hash algorithms.
Question 135
Question
Which statement correctly describes IPsec?
Answer
-
IPsec works at Layer 3, but can protect traffic from Layer 4 through Layer 7.
-
IPsec uses algorithms that were developed specifically for that protocol
-
IPsec implements its own method of authentication
-
IPsec is a Cisco proprietary standard
Question 136
Question
Which two algorithms use Hash-based Message Authentication Code for message authentication? (Choose two.)
Question 137
Question
What key question would help determine whether an organization should use an SSL VPN or an IPsec VPN for the remote access solution of the organization?
Answer
-
Do users need to be able to connect without requiring special VPN software?
-
What applications or network resources do the users need for access?
-
Are both encryption and authentication required?
-
Is a Cisco router used at the destination of the remote access tunnel?
Question 138
Question
What is the purpose of a message hash in a VPN connection?
Answer
-
It ensures that the data has not changed while in transit.
-
It ensures that the data is coming from the correct source.
-
It ensures that the data cannot be read in plain text.
-
It ensures that the data cannot be duplicated and replayed to the destination.
Question 139
Question
Which remote access implementation scenario will support the use of generic routing encapsulation tunneling?
Answer
-
a central site that connects to a SOHO site without encryption
-
a mobile user who connects to a router at a central site
-
a mobile user who connects to a SOHO site
-
a branch office that connects securely to a central site
Question 140
Question
A network design engineer is planning the implementation of a cost-effective method to interconnect multiple networks securely over the Internet. Which type of technology is required?
Answer
-
a VPN gateway
-
a GRE IP tunnel
-
a leased line
-
a dedicated ISP
Question 141
Question
Refer to the exhibit. Which IP address would be configured on the tunnel interface of the destination router?
Answer
-
172.16.1.2
-
209.165.200.225
-
172.16.1.1
-
209.165.200.226
Question 142
Question
Which algorithm is an asymmetrical key cryptosystem?
Question 143
Question
Refer to the exhibit. From what location have the syslog messages been retrieved?
Answer
-
router RAM
-
router NVRAM
-
syslog client
-
syslog server
Question 144
Question
Which syslog message type is accessible only to an administrator and only via the Cisco CLI?
Answer
-
debugging
-
alerts
-
errors
-
emergency
Question 145
Question
The command ntp server 10.1.1.1 is issued on a router. What impact does this command have?
Answer
-
synchronizes the clock of the device to the timeserver that is located at IP address 10.1.1.1
-
determines which server to send system log files to
-
ensures that all logging will have a time stamp associated with it
-
identifies the server on which to store backup configurations
Question 146
Question
A network administrator has issued the logging trap 4 global configuration mode command. What is the result of this command?
Answer
-
The syslog client will send to the syslog server any event message that has a severity level of 4 and lower.
-
After four events, the syslog client will send an event message to the syslog server.
-
The syslog client will send to the syslog server event messages with an identification trap level of only 4.
-
The syslog client will send to the syslog server any event message that has a severity level of 4 and higher.
Question 147
Question
Which protocol is used by network administrators to track and gather statistics on TCP/IP packets that are entering or exiting network devices?
Question 148
Question
Which SNMP version uses weak community string-based access control and supports bulk retrieval?
Answer
-
SNMPv2c
-
SNMPv3
-
SNMPv1
-
SNMPv2Classic
Question 149
Question
A network administrator issues two commands on a router:
R1(config)# snmp-server host 10.10.50.25 version 2c campus
R1(config)# snmp-server enable traps
What can be concluded after the commands are entered?
Answer
-
If an interface comes up, a trap is sent to the server
-
No traps are sent, because the notification-types argument was not specified yet.
-
The snmp-server enable traps command needs to be used repeatedly if a particular subset of trap types is desired
-
Traps are sent with the source IP address as 10.10.50.25.
Question 150
Question
Refer to the exhibit. While planning an upgrade, a network administrator uses the Cisco NetFlow utility to analyze data flow in the current network. Which protocol used the greatest amount of network time?
Answer
-
UDP-other
-
TCP-Telnet
-
TCP-FTP
-
UDP-DNS
-
TCP-other
Question 151
Question
When SNMPv1 or SNMPv2 is being used, which feature provides secure access to MIB objects?
Answer
-
community strings
-
message integrity
-
packet encryption
-
source validation
Question 152
Question
Which type of information can an administrator obtain with the show ip cache flow command?
Answer
-
the protocol that uses the largest volume of traffic
-
the configuration of the export parameters
-
the NetFlow version that is enabled
-
whether NetFlow is configured on the correct interface and in the correct direction
Question 153
Question
A network administrator has issued the snmp-server user admin1 admin v3 encrypted auth md5 abc789 priv des 256 key99 command. What are two features of this command? (Choose two.)
Answer
-
It uses the MD5 authentication of the SNMP messages.
-
It adds a new user to the SNMP group.
-
It forces the network manager to log into the agent to retrieve the SNMP messages.
-
It allows a network administrator to configure a secret encrypted password on the SNMP server.
-
It restricts SNMP access to defined SNMP managers.
Question 154
Question
Which two statements describe items to be considered in configuring NetFlow? (Choose two.)
Answer
-
Netflow can only be used in a unidirectional flow
-
NetFlow consumes additional memory
-
Netflow requires both management and agent software.
-
NetFlow can only be used if all devices on the network support it
-
Netflow requires UDP port 514 for notification messages
Question 155
Question
What are the most common syslog messages?
Answer
-
link up and link down messages
-
output messages that are generated from debug output
-
those that occur when a packet matches a parameter condition in an access control list
-
error messages about hardware or software malfunctions
Question 156
Question
Which destination do Cisco routers and switches use by default when sending syslog messages for all severity levels?
Answer
-
console
-
nearest syslog server
-
NVRAM
-
RAM
Question 157
Question
Refer to the exhibit. What does the number 17:46:26.143 represent?
Answer
-
the time when the syslog message was issued
-
the time passed since the syslog server has been started
-
the time on the router when the show logging command was issued
-
the time passed since the interfaces have been up
Question 158
Question
Refer to the exhibit. What can be concluded from the produced output?
Answer
-
An ACL was configured to restrict SNMP access to an SNMP manager.
-
This is the output of the show snmp command without any parameters.
-
The location of the device was not configured with the snmp-server location command.
-
The system contact was not configured with the snmp-server contact command.
Question 159
Question
Which protocol or service can be configured to send unsolicited messages to alert the network administrator about a network event such as an extremely high CPU utilization on a router?
Question 160
Question
When logging is used, which severity level indicates that a device is unusable?
Answer
-
Emergency - Level 0
-
Critical - Level 2
-
Alert - Level 1
-
Error - Level 3
Question 161
Question
Which protocol or service allows network administrators to receive system messages that are provided by network devices?
Question 162
Question
What is the most common purpose of implementing NetFlow in a networked environment?
Answer
-
to support accounting and monitoring with consumer applications
-
to passively capture changing events that occur in the network and to perform after-the-fact-analysis
-
to actively capture traffic from networked devices
-
to monitor live data usage and to control traffic flow with set messages
Question 163
Question
Which statement describes SNMP operation?
Answer
-
A set request is used by the NMS to change configuration variables in the agent device.
-
An SNMP agent that resides on a managed device collects information about the device and stores that information remotely in the MIB that is located on the NMS
-
An NMS periodically polls the SNMP agents that are residing on managed devices by using traps to query the devices for data
-
A get request is used by the SNMP agent to query the device for data
Question 164
Question
How does NetFlow function on a Cisco router or multilayer switch?
Answer
-
One user connection to an application exists as two NetFlow flows.
-
Netflow captures and analyzes traffic
-
NetFlow does not consume any additional memory.
-
On 2960 switches, Netlow allows for data export
Question 165
Question
Which SNMP feature provides a solution to the main disadvantage of SNMP polling?
Answer
-
SNMP trap messages
-
SNMP community strings
-
SNMP set messages
-
SNMP get messages
Question 166
Question
A user in a large office calls technical support to complain that a PC has suddenly lost connectivity to the network. The technician asks the caller to talk to nearby users to see if other machines are affected. The caller reports that several immediate neighbors in the same department have a similar problem and that they cannot ping each other. Those who are seated in other departments have connectivity. What should the technician check as the first step in troubleshooting the issue?
Answer
-
the status of the departmental workgroup switch in the wiring closet
-
the cable connection between a PC and a network outlet that is used by a neighbor
-
the cable that connects the PC of the caller to the network jack
-
the trunks between switches in the wiring closet
-
the power outlet to the PC that is used by the caller
Question 167
Question
When should a network performance baseline be measured?
Answer
-
during normal work hours of an organization
-
immediately after the main network devices restarted
-
after normal work hours to reduce possible interruptions
-
when a denial of service attack to the network is detected and blocked
Question 168
Question
What is a purpose of establishing a network baseline?
Answer
-
It creates a point of reference for future network evaluations.
-
It manages the performance of network devices
-
It provides a statistical average for network performance
-
It checks the security configuration of network devices
Question 169
Question
A network technician is troubleshooting an email connection problem. Which question to the end-user will provide clear information to better define the problem?
Answer
-
When did you first notice your email problem?
-
What kind of equipment are you using to send emails?
-
How big are the emails you tried to send?
-
Is your email working now?
Question 170
Question
In which step of gathering symptoms does the network engineer determine if the problem is at the core, distribution, or access layer of the network?
Answer
-
Narrow the scope
-
Determine the symptoms
-
Document the symptoms
-
Gather information
-
Determine ownership
Question 171
Question
Which number represents the most severe level of syslog logging?
Question 172
Question
A team of engineers has identified a solution to a significant network problem. The proposed solution is likely to affect critical network infrastructure components. What should the team follow while implementing the solution to avoid interfering with other processes and infrastructure?
Answer
-
change-control procedures
-
knowledge base guidelines
-
one of the layered troubleshooting approaches
-
syslog messages and reports
Question 173
Question
After which step in the network troubleshooting process would one of the layered troubleshooting methods be used?
Question 174
Question
Which type of tool would an administrator use to capture packets that are going to and from a particular device?
Answer
-
protocol analyzer
-
baselining tool
-
NMS tool
-
knowledge base
Question 175
Question
Which troubleshooting method begins by examining cable connections and wiring issues?
Answer
-
bottom-up
-
top-down
-
divide-and-conquer
-
substitution
Question 176
Question
An administrator is troubleshooting an Internet connectivity problem on a router. The output of the show interfaces gigabitethernet 0/0 command reveals higher than normal framing errors on the interface that connects to the Internet. At what layer of the OSI model is the problem likely occurring?
Answer
-
Layer 2
-
Layer 1
-
Layer 3
-
Layer 4
-
Layer 7
Question 177
Question
A company is setting up a web site with SSL technology to protect the authentication credentials required to access the web site. A network engineer needs to verify that the setup is correct and that the authentication is indeed encrypted. Which tool should be used?
Answer
-
protocol analyzer
-
baselining tool
-
fault-management tool
-
cable analyzer
Question 178
Question
Which statement describes the physical topology for a LAN?
Answer
-
It defines how hosts and network devices connect to the LAN.
-
It shows the order in which hosts access the network
-
It describes whether the LAN is a broadcast or token-passing network.
-
It depicts the addressing scheme that is employed in the LAN.
Question 179
Question
A network engineer is troubleshooting a network problem and can successfully ping between two devices. However, Telnet between the same two devices does not work. Which OSI layers should the administrator investigate next?
Question 180
Question
The newly configured ASBR that connects a company to the Internet has a default route configured and has the default-information originate command entered. Devices connected through this router can access the Internet. The problem is that no other OSPF routers have a default route in the routing table and no other users throughout the organization can access the Internet. What could be the problem?
Answer
-
The ASBR does not have an OSPF neighbor.
-
The ASBR does not have OSPF configured
-
The other routers are not configured to accept LSA type 4s.
-
The ASBR should use the exit_interface argument instead of next-hop on the default route.
Question 181
Question
Users report that the new web site http://www.company1.biz cannot be accessed. The helpdesk technician checks and verifies that the web site can be accessed with http://www.company1.biz:90. Which layer in the TCP/IP model is involved in troubleshooting this issue?
Answer
-
transport
-
application
-
internet
-
network access
Question 182
Question
A user reports that after an OS patch of the networking subsystem has been applied to a workstation, it performs very slowly when connecting to network resources. A network technician tests the link with a cable analyzer and notices that the workstation sends an excessive number of frames smaller than 64 bytes and also other meaningless frames. What is the possible cause of the problem?
Question 183
Question
Which two specialized troubleshooting tools can monitor the amount of traffic that passes through a switch? (Choose two.)
Question 184
Question
A group of Windows PCs in a new subnet has been added to an Ethernet network. When testing the connectivity, a technician finds that these PCs can access local network resources but not the Internet resources. To troubleshoot the problem, the technician wants to initially confirm the IP address and DNS configurations on the PCs, and also verify connectivity to the local router. Which three Windows CLI commands and utilities will provide the necessary information? (Choose three.)
Question 185
Question
A networked PC is having trouble accessing the Internet, but can print to a local printer and ping other computers in the area. Other computers on the same network are not having any issues. What is the problem?
Answer
-
The PC has a missing or incorrect default gateway
-
The link between the switch to which the PC connects and the default gateway router is down
-
The default gateway router does not have a default route
-
The switch port to which the PC connects has an incorrect VLAN configured
Question 186
Question
An internal corporate server can be accessed by internal PCs, but not by external Internet users that should have access. What could be the issue?
Answer
-
Static NAT has not been configured properly or at all.
-
The default gateway router for the server does not have a default route
-
The server does not have a private IP address assigned
-
The switch port to which the server connects has an incorrect VLAN configured