· 8 years ago · Jul 09, 2018, 03:20 PM
1CCNA 4 – Final by ijaa.wordpress.com
2
31. A technician has been asked to run Cisco SDM one-step lockdown on the router of a customer. What will be the result of this process?
4Traffic is only forwarded from SDM-trusted Cisco routers.
5Security testing is performed and the results are saved as a text file stored in NVRAM.
6The router is tested for potential security problems and any necessary changes are made.
7All traffic entering the router is quarantined and checked for viruses before being forwarded.
8
92. Refer to the exhibit. A network administrator is trying to configure a router to use SDM but it is not functioning correctly. What could be the problem?
10The username and password are not configured correctly.
11The authentication method is not configured correctly.
12The HTTP timeout policy is not configured correctly.
13The vtys are not configured correctly.
14
153. Refer to the exhibit. How is the TCP/IP configuration information specified by the default-router and dns-server commands made available?
16The TCP/IP information is forwarded to a 10.0.1.3 to be supplied to DHCP clients.
17The TCP/IP information is used by DHCP clients that are configured to request a configuration from R1.
18The TCP/IP information is supplied to any DHCP client on the network connected to the FastEthernet 0/0 interface of R1.
19The TCP/IP information is applied to each packet that enters R1 through the FastEthernet 0/0 interface that are hosts on the 10.0.1.0 /24 network except packets from addresses 10.0.1.2, 10.0.1.16, and 10.0.1.254.
20
214. What is a major characteristic of a worm?
22malicious software that copies itself into other executable programs
23tricks users into running the infected software
24a set of computer instructions that lies dormant until triggered by a specific event
25exploits vulnerabilities with the intent of propagating itself across a network
26
275. Refer to the exhibit. What can be concluded from the exhibited output of the debug ip nat command?
28The 10.1.1.225 host is exchanging packets with the 192.168.0.10 host.
29The native 10.1.200.254 address is being translated to 192.168.0.10.
30The 192.168.0.0/24 network is the inside network.
31Port address translation is in effect.
32
336. A technician is talking to a colleague at a rival company and comparing DSL transfer rates between the two companies. Both companies are in the same city, use the same service provider, and have the same rate/service plan. What is the explanation for why Company A reports higher download speeds than Company B?
34Company B has a higher volume of POTS voice traffic than Company A.
35Company B shares the conection to the DSLAM with more clients than Company A.
36Company A only uses microfilters on branch locations.
37Company A is closer to the service provider.
38
397. Refer to the exhibit. Which statement correctly describes how Router1 processes an FTP request entering interface s0/0/0, destined for an FTP server at IP address 192.168.1.5?
40It matches the incoming packet to the access-list 201 permit any any statement and allows the packet into the router.
41It reaches the end of ACL 101 without matching a condition and drops the packet because there is no access-list 101 permit any any statement.
42It matches the incoming packet to the access-list 101 permit ip any 192.168.1.0 0.0.0.255 statement, ignores the remaining statements in ACL 101, and allows the packet into the router.
43It matches the incoming packet to the access-list 201 deny icmp 192.168.1.0 0.0.0.255 any statement, continues comparing the packet to the remaining statements in ACL 201 to ensure that no subsequent statements allow FTP, and then drops the packet.
44
458. Refer to the exhibit. Which two conclusions can be drawn from the output shown? (Choose two.)
46This network is experiencing congestion.
47The Frame Relay connection is in the process of negotiation.
48Data is not flowing in this network.
49The network is discarding eligible packets.
50The DLCI is globally significant.
51
529. A system administrator must provide Internet connectivity for ten hosts in a small remote office. The ISP has assigned two public IP addresses to this remote office. How can the system administrator configure the router to provide Internet access to all ten users at the same time?
53Configure DHCP and static NAT.
54Configure dynamic NAT for ten users.
55Configure static NAT for all ten users.
56Configure dynamic NAT with overload.
57
5810. Refer to the exhibit. Company ABC expanded its business and recently opened a new branch office in another country. IPv6 addresses have been used for the company network. The data servers Server1 and Server2 run applications which require end-to-end functionality, with unmodified packets that are forwarded from the source to the destination. The edge routers R1 and R2 support dual stack configuration. What solution should be deployed at the edge of the company network in order to successfully interconnect both offices?
59a new WAN service supporting only IPv6
60NAT overload to map inside IPv6 addresses to outside IPv4 address
61a manually configured IPv6 tunnel between the edge routers R1 and R2
62static NAT to map inside IPv6 addresses of the servers to an outside IPv4 address and dynamic NAT for the rest of the inside IPv6 addresses
63
6411. Refer to the exhibit. You are a network administrator who has been tasked with completing the Frame Relay topology that interconnects two remote sites. How should the point-to-point subinterfaces be configured on HQ to complete the topology?
65HQ(config-subif)#frame-relay interface-dlci 103 on Serial 0/0/0.1
66HQ(config-subif)#frame-relay interface-dlci 203 on Serial 0/0/0.2
67HQ(config-subif)#frame-relay interface-dlci 301 on Serial 0/0/0.1
68HQ(config-subif)# frame-relay interface-dlci 302 on Serial 0/0/0.2
69HQ(config-subif)#frame-relay map ip 172.16.1.1 103 broadcast on Serial 0/0/0.1
70HQ(config-subif)#frame-relay map ip 172.16.2.2 203 broadcast on Serial 0/0/0.2
71HQ(config-subif)#frame-relay map ip 172.16.1.1 301 broadcast on Serial 0/0/0.1
72HQ(config-subif)#frame-relay map ip 172.16.2.2 302 broadcast on Serial 0/0/0.2
73
7412. An established company has recently transitioned from outsourced LAN support to a completely in-house staff. The outsourcing company is no longer in business, so no records are available. There are many user complaints about application speed and availability. What two considerations apply to this situation? (Choose two.)
75A network utilization baseline should quickly reveal application availability.
76A period of 24 to 48 hours should provide a sufficient baseline to track normal network activity.
77It is easier to start with monitoring all available data inputs on application servers, and then fine-tune to fewer variables along the way.
78The initial baseline results have little relevance to current values after the network has been modified or grown in usage.
79When it is practical, network administrators should attempt to automate the collection of performance data and stay away from manual collection.
80Creating a network baseline data helps determine device thresholds for alerting.
81
8213. Which combination of Layer 2 protocol and authentication should be used to establish a link without sending authentication information in plain text between a Cisco and a non-Cisco router?
83PPP with PAP
84PPP with CHAP
85HDLC with PAP
86HDLC with CHAP
87
8814. An administrator is unable to receive e-mail. While troubleshooting the problem, the administrator is able to ping the local mail server IP address successfully from a remote network and can successfully resolve the mail server name to an IP address via the use of the nslookup command. At what OSI layer is the problem most likely to be found?
89physical layer
90data link layer
91network layer
92application layer
93
9415. When configuring a Frame Relay connection, what are two instances when a static Frame Relay map should be used? (Choose two.)
95when the remote router is a non-Cisco router
96when the remote router does not support Inverse ARP
97when the local router is using IOS Release 11.1 or earlier
98when broadcast traffic and multicast traffic over the PVC must be controlled
99when globally significant rather than locally significant DLCIs are being used
100
10116. Which three statements are true about creating and applying access lists? (Choose three.)
102Access list entries should filter in the order from general to specific.
103One access list per port per protocol per direction is permitted.
104Standard ACLs should be applied closest to the source while extended ACLs should be applied closest to the destination.
105There is an implicit deny at the end of all access lists.
106Statements are processed sequentially from top to bottom until a match is found.
107The inbound keyword refers to traffic entering the network from the router interface where the ACL is applied.
108
10917. Which technology would provide the highest bandwidth connections between company sites at the lowest cost?
110broadband Internet site-to-site VPN connections
111satellite based network connections
112dedicated point-to-point circuits
113Frame Relay PVCs
114
115
116
11718. Refer to the exhibit. This serial interface is not functioning correctly. Based on the output shown, what is the most likely cause?
118improper LMI type
119interface reset
120PPP negotiation failure
121unplugged cable
122
12319. What three statements describe the roles of devices in a WAN? (Choose three.)
124A CSU/DSU terminates a digital local loop.
125A modem terminates a digital local loop.
126A CSU/DSU terminates an analog local loop.
127A modem terminates an analog local loop.
128A router is commonly considered a DTE device.
129A router is commonly considered a DCE device.
130
13120. A network administrator is instructing a technician on best practices for applying ACLs. Which suggestion should the administrator provide?
132Named ACLs are less efficient than numbered ACLs.
133Standard ACLs should be applied closest to the core layer.
134ACLs applied to outbound interfaces are the most efficient.
135Extended ACLs should be applied closest to the source that is specified by the ACL.
136
13721. Refer to the exhibit. Branch A has a Cisco router. Branch B has a non-Cisco router set for IETF encapsulation. After the commands shown are entered, R2 and R3 fail to establish the PVC. The R2 LMI is Cisco, and the R3 LMI is ANSI. The LMI is successfully established at both locations. Why is the PVC failing?
138The PVC to R3 must be point-to-point.
139LMI types must match on each end of a PVC.
140The ietf parameter is missing from the frame-relay map ip 10.10.10.3 203 command.
141The PVCs at R2 use different encapsulation types. A single port can only support one encapsulation type.
142
14322. Which statement is true regarding wildcard masks?
144The wildcard mask and subnet mask perform the same function.
145The wildcard mask is always the inverse of the subnet mask.
146A "0" in the wildcard mask identifies IP address bits that must be checked.
147A "1" in the wildcard mask identifies a network or subnet bit.
148
14923. Refer to the exhibit. What is placed in the address field in the header of a frame that will travel from the DC office of ABC Company to the Orlando office?
150MAC address of the Orlando router
151MAC address of the DC router
152192.168.1.25
153192.168.1.26
154DLCI 100
155DLCI 200
156
15724 .A company is looking for a WAN solution to connect its headquarters site with four remote sites. What advantage would dedicated leased lines provide to the customer compared to a shared Frame Relay solution?
158lower cost
159lower latency and jitter
160variable bandwidth capacity
161fewer physical router interfaces
162
16325. Refer to the exhibit. RIPv2 has been configured on all routers in the network. Routers R1 and R3 do not receive RIP routing updates. On the basis of the provided configuration, what should be enabled on router R2 to remedy the problem?
164proxy ARP
165CDP updates
166SNMP services
167RIP authentication
168
16926. What are the symptoms when the s0/0/0 interface on a router is attached to an operational CSU/DSU that is generating a clock signal, but the far end router on the point-to-point link has not been activated?
170show controllers indicates cable type DCE V.35. show interfaces s0/0/0 indicates serial down, line protocol down.
171show controllers indicates cable type DCE V.35. show interfaces s0/0/0 indicates serial up, line protocol down.
172show controllers indicates cable type DTE V.35. show interfaces s0/0/0 indicates serial up, line protocol down.
173show controllers indicates cable type DTE V.35. show interfaces s0/0/0 indicates serial down, line protocol down.
174
17527. Which statement about a VPN is true?
176VPN link establishment and maintenance is provided by LCP.
177DLCI addresses are used to identify each end of the VPN tunnel.
178VPNs use virtual Layer 3 connections that are routed through the Internet.
179Only IP packets can be encapsulated by a VPN for tunneling through the Internet.
180
18128. Refer to the exhibit. Partial results of the show access-lists and show ip interface FastEthernet 0/1 commands for router R3 are shown. There are no other ACLs in effect. Host A is unable to telnet to host B. Which action will correct the problem but still restrict other traffic between the two networks?
182Apply the ACL in the inbound direction.
183Apply the ACL on the FastEthernet 0/0 interface.
184Reverse the order of the TCP protocol statements in the ACL.
185Modify the second entry in the list to permit tcp host 192.168.10.10 any eq telnet .
186
18729. Refer to the exhibit. What happens if the network administrator issues the commands shown when an ACL called Managers already exists on the router?
188The commands overwrite the existing Managers ACL.
189The commands are added at the end of the existing Managers ACL.
190The network administrator receives an error stating that the ACL already exists.
191The commands will create a duplicate Managers ACL containing only the new commands being entered.
192
19330. Which three statements accurately describe a security policy? (Choose three.)
194It creates a basis for legal action if necessary.
195It defines a process for managing security violations.
196It defines acceptable and unacceptable use of network resources.
197The remote access policy is a component of the security policy that governs acceptable use of e-mail systems.
198It is kept private from users to prevent the possibility of circumventing security measures.
199It provides step-by-step procedures to harden routers and other network devices.
200
20131. Refer to the exhibit. The link between the CTRL and BR_1 routers is configured as shown in the exhibit. Why are the routers unable to establish a PPP session?
202The clock rate must be 56000.
203The usernames are misconfigured.
204The IP addresses are on different subnets.
205The clock rate is configured on the wrong end of the link.
206The CHAP passwords must be different on the two routers.
207Interface serial 0/0/0 on CTRL must connect to interface serial 0/0/1 on BR_1.
208
20932. What effect would the Router1(config-ext-nacl)# permit tcp 172.16.4.0 0.0.0.255 any eq www command have when implemented inbound on the f0/0 interface?
210All TCP traffic is permitted, and all other traffic is denied.
211The command is rejected by the router because it is incomplete.
212All traffic from 172.16.4.0/24 is permitted anywhere on any port.
213Traffic originating from 172.16.4.0/24 is permitted to all TCP port 80 destinations.
214
21533. What can a network administrator do to recover from a lost router password?
216use the copy tftp: flash: command
217boot the router to bootROM mode and enter the b command to load the IOS manually
218telnet from another router and issue the show running-config command to view the password
219boot the router to ROM monitor mode and configure the router to ignore the startup configuration when it initializes
220
22134. A router in a Frame Relay network needs to forward a message received from a host. What two methods does the router use to identify the correct VC to forward the message? (Choose two.)
222The router forwards the frame to all ports in the network and learns the address from the reply frame.
223The destination host IP address is embedded in the DLCI.
224The router searches Inverse ARP tables for maps of DLCIs to IP addresses.
225A table of static mappings can be searched.
226The router broadcasts a request for the required IP address.
227
22835. Refer to the exhibit. From the output of the show interface commands, at which OSI layer is a fault indicated?
229application
230transport
231network
232data link
233physical
234
23536. Refer to the exhibit. The network administrator creates a standard access control list to prohibit traffic from the 192.168.1.0/24 network from reaching the 192.168.2.0/24 network while still permitting Internet access for all networks. On which router interface and in which direction should it be applied?
236interface fa0/0/0, inbound
237interface fa0/0/0, outbound
238interface fa0/0/1, inbound
239interface fa0/0/1, outbound
240
24137. Refer to the exhibit. The SSH connections between the remote user and the server are failing. The correct configuration of NAT has been verified. What is the most likely cause of the problem?
242SSH is unable to pass through NAT.
243There are incorrect access control list entries.
244The access list has the incorrect port number for SSH.
245The ip helper command is required on S0/0/0 to allow inbound connections.
246
24738. Refer to the exhibit. A technician issues the show interface s0/0/0 command on R1 while troubleshooting a network problem. What two conclusions can be determined by from the output shown? (Choose two.)
248The bandwidth has been set to the value of a T1 line.
249Encapsulation should of this inteface be changed to PPP.
250There is no failure indicated in an OSI Layer 1 or Layer 2.
251The physical connection between the two routers has failed.
252The IP address of S0/0 is invalid, given the subnet mask being used.
253
25439. Refer to the exhibit. A packet is being sent from Host A to Host B through the VPN tunnel between R1 and R3. When the packet first arrives at R3, what are the source and destination IP addresses of the packet?
255Source 192.168.1.2 - Destination 192.168.4.2
256Source 192.168.3.1 - Destination 192.168.3.2
257Source 192.168.2.1 - Destination 192.168.3.2
258Source 192.168.3.1 - Destination 192.168.4.2
259
26040. An administrator is configuring a dual stack router with IPv6 and IPv4 using RIPng. The administrator receives an error message when trying to enter the IPv4 routes into RIPng. What is the cause of the problem?
261RIPng is incompatible with dual-stack technology.
262All interfaces have been configured with the incorrect IPv4 addresses.
263RIPv1 or RIPv2 needs to be configured in addition to RIPng to successfully use IPv4.
264When IPv4 and IPv6 are configured on the same interface, all IPv4 addresses are shut down in favor of the newer technology.
265
26641. Which wireless solution can provide mobile users with non line-of-sight broadband Internet access at speeds comparable to DSL or cable?
267Wi-Fi
268WiMAX
269satellite
270Metro Ethernet
271
27242. A network administrator added two switches and a new VLAN over the past weekend. How can the administrator determine if the additions and changes improved performance and availability on the company intranet?
273Perform a baseline test and compare the current values to values that were obtained in previous weeks.
274Interview departmental secretaries and determine if they think load time for web pages is improved.
275Compare the hit counts on the company web server for the current week to the values that were recorded from previous weeks.
276Performance on the intranet can be determined by monitoring load times of company web pages from remote sites.
277
278
27943. Refer to the exhibit. The network administrator is adding R1 to an existing network. As a part of the corporate IT procedures, the administrator attempts to back up the router Cisco IOS software of R1 and receives the output shown. The network administrator then attempts unsuccessfully to ping the TFTP server from the console session. What should be done next to isolate this problem?
280From R2, validate that interface Fa0/0 is operational.
281From the TFTP server, verify that the software on the TFTP server is operational.
282From the TFTP server, confirm there is enough room on the TFTP server for the Cisco IOS software.
283From the console session, make sure that R1 has a route to the network where the TFTP server resides.
284
28544. What functionality do access control lists provide when implementing dynamic NAT on a Cisco router?
286defines which addresses can be translated
287defines which addresses are assigned to a NAT pool
288defines which addresses are allowed out of the router
289defines which addresses can be accessed from the inside network
290
29145. A network administrator is working with an applications team to fix a problem that a server based application is having with response time. The administrator has examined the network portions of the data path and identified several possible problem areas. The applications team has simultaneously identified potential issues with the current release of software. The network administrator begins addressing the network issues while the applications team implements software patches.
292Which statement applies to this situation?
293Changes to the network will reveal problems that are caused by the new patches.
294Scheduling will be more difficult if the network and software teams work independently.
295It will be difficult to isolate the problem if two teams are implementing changes independently.
296Results from changes will be easier to reconcile and document if each team works in isolation.
297
29846. Refer to the exhibit. R1 is performing NAT overload for the 10.1.1.0/24 inside network. Host A has sent a packet to the web server. What is the destination IP address of the return packet from the web server?
29910.1.1.2:1234
300172.30.20.1:1234
301172.30.20.1:3333
302192.168.1.2:80
303
30447. Which three guidelines would help contribute to creating a strong password policy? (Choose three.)
305Once a good password is created, do not change it.
306Deliberately misspell words when creating passwords.
307Create passwords that are at least 8 characters in length.
308Use combinations of upper case, lower case, and special characters.
309Write passwords in locations that can be easily retrieved to avoid being locked out.
310Use long words found in the dictionary to make passwords that are easy to remember.
311
31248. What will be the result of adding the command ip dhcp excluded-address 172.16.4.1 172.16.4.5 to the configuration of a local router that has been configured as a DHCP server?
313Traffic that is destined for 172.16.4.1 and 172.16.4.5 will be dropped by the router.
314Traffic will not be routed from clients with addresses between 172.16.4.1 and 172.16.4.5.
315The DHCP server function of the router will not issue the addresses between 172.16.4.1 and 172.16.4.5.
316The router will ignore all traffic that comes from the DHCP servers with addresses 172.16.4.1 and 172.16.4.5.
317
31849. Which two statements are true about IPv6? (Choose two.)
319Security options are build into IPv6.
320IPv6 addresses require less router overhead to process.
321IPv6 can only be configured on an interface that does not have IPv4 on it.
322There is no way to translate between IPv4 addresses and IPv6 addresses.
323When enabled on a router, IPv6 can automatically configure link-local IPv6 addresses on all interfaces.
324
32550. Refer to the exhibit. A network administrator has issued the commands that are shown on Router1 and Router2. A later review of the routing tables reveals that neither router is learning the LAN network of the neighbor router. What is most likely the problem with the RIPng configuration?
326The serial interfaces are in different subnets.
327The RIPng process is not enabled on interfaces.
328The RIPng network command is not configured.
329The RIPng processes do not match between Router1 and Router2.
330
33151. At what physical location does the responsibilty for a WAN connection change from the user to the service provider?
332demilitarized zone (DMZ)
333demarcation point
334local loop
335cloud
336
33752. Refer to the exhibit. A host connected to Fa0/0 is unable to acquire an IP address from this DHCP server. The output of the debug ip dhcp server command shows "DHCPD: there is no address pool for 192.168.1.1". What is the problem?
338The 192.168.1.1 address has not been excluded from the DHCP pool.
339The pool of addresses for the 192Network pool is incorrect.
340The default router for the 192Network pool is incorrect.
341The 192.168.1.1 address is already configured on Fa0/0.
342
34353. Which three functions are provided by the Local Management Interface used in Frame Relay networks? (Choose three.)
344exchange information about the status of virtual circuits
345map DLCIs to network addresses
346provide flow control
347provide error notification
348provide congestion notification
349send keepalive packets to verify operation of the PVC
350
35154. Which three items are LCP options that can be configured for PPP? (Choose three.)
352CHAP
353Stacker
354IPCP
355CDPCP
356Multilink
357
35855. What are two main components of data confidentiality? (Choose two.)
359checksum
360digital certificates
361encapsulation
362encryption