wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CCNA Day 4

Total questions: 50

Worksheet time: 29mins

Name
Class
Date
1.

By default, how does EIGRP determine the metric of a route for the routing table?

a)

It counts the number of hops between the receiving and destination routers and uses that value as the metric.

b)

It uses a reference bandwidth and the actual bandwidth of the connected link to calculate the route metric.

c)

It uses the bandwidth and delay values of the path to calculate the route metric.

d)

It uses a default metric of 10 for all routes that are learned by the router.

2.

Which type of IPv6 address is publicly routable in the same way as IPv4 public addresses?

a)

unique local

b)

link-local

c)

multicast

d)

global unicast

3.

Which WPA3 enhancement protects against hackers viewing traffic on the \M-Fi network?

a)

AES encryption

b)

SAE encryption

c)

TKIP encryption

d)

scrambled encryption key

4.

Refer to the exhibit. Which two commands were used to create port channel 10? (Choose two.)

a)

int range g0/0-1

channel-group 10 mode active

b)

int range g0/0-1

channel-group 10 mode desirable

c)

int range g0/0-1

channel-group 10 mode passive

d)

int range g0/0-1

channel-group 10 mode on

e)

int range g0/0-1

channel-group 10 mode auto

5.

What are two fundamentals of virtualization? (Choose two.)

a)

The environment must be configured with one hypervisor that serves solely las a network manager to monitor SNMP traffic.

b)

It requires that some servers, virtual machines, and network gear reside on the Internet.

c)

It allows logical network devices to move traffic between virtual machines and the rest of the physical network.

d)

It allows a physical router to directly connect Nle from each virtual machine into the network.

e)

It allows multiple operating systems and applications to run independently on one physical server.

6.

Refer to the exhibit. What is the next hop address for traffic that is destined to host 10.0.1.5?

a)

10.0.1.3

b)

10.0.1.4

c)

Loopback 0

d)

10.0.1.50

7.

When configuring a WLAN with WPA2 PSK in the Cisco Wireless LAN Controller. GUI, which two formats are available to select? (Choose two.)

a)

base64

b)

hexadecimal

c)

binary

d)

decimal

e)

ASCII

8.

Refer to the exhibit. Which path is used by the router for internet traffic?

a)

0.0.0.0/0

b)

10.10.10.0/28

c)

10.10.13.0/24

d)

209.165.200.0/27

9.

Which two encoding methods are supported by REST APls? (Choose two.)

a)

XML

b)

YAML

c)

SGML

d)

EBCDIC

e)

JSON

10.

What is an advantage of Cisco DNA Center versus traditional campus device management?

a)

It enables easy autodiscovery of network elements in a brownfield deployment.

b)

It is designed primarily to provide network assurance.

c)

It supports numerous extensibility options, including cross-domain adapters and third-party SDKs.

d)

It supports high availability for management functions when operating in cluster mode.

11.

When a WPA2-PSK WLAN is configured in the Wireless LAN Controller, what is the minimum number of characters that is required in ASCII format?

a)

8

b)

6

c)

12

d)

18

12.

Which two conditions must be met before SSH can operate normally on a Cisco IOS switch? (Choose two.)

a)

IP routing must be enabled on the switch.

b)

Telnet mustbe disabled on the switch

c)

The ip domain-name command must be configured on the switch.

d)

A console password must be configured on the switch.

e)

The switch must be running a k9 (crypto) IOS image.

13.

Refer to the exhibit. What two conclusions should be made about this configuration? (Choose two.)

a)

The spanning-tree mode is Rapid PVST+.

b)

The spanning-tree mode is PVST+

c)

This is a root bridge.

d)

The designated port is FastEthernet 2/1

e)

The root port is FastEthernet 2/ 1

14.

What is a difference between RADIUS and TACACS+?

a)

TACACS+ separates authentication and authorization, and RADIUS merges them.

b)

TACACS+ encrypts only password information, and RADIUS encrypts the entire payload.

c)

RADIUS logs all commands that are entered by the administrator, but TACACS+ logs only start, stop, and interim commands.

d)

RADIUS is most appropriate for dial authentication, bUt TACACS+ can be used for multiple types of authentication.

15.

What are two benefits of network automation? (Choose two.)

a)

faster changes with more reliable results

b)

fewer network failures

c)

reduced hardware footprint

d)

reduced operational costs

e)

increased network security

16.

Refer to the exhibit. How does the router manage traffic to 192.168.12.16?

a)

It chooses the EIGRP route because it has the lowest administrative distance

b)

It load-balances traffic between all three routes

c)

It selects the RIP route because it has the longest prefix inclusive of the destination address.

d)

It chooses the OSPF route because it has the longest prefix inclusive of the destination address.

17.

Which two capabilities of Cisco DNA Center make it more extensible? (Choose two-)

a)

customized versions for small, medium, and large enterprises

b)

REST APIS that allow for external applications to interact natively with Cisco DNA Center

c)

SDKs that support interaction with third-party network equipment

d)

adapters that support all families of Cisco IOS software

e)

modular design that is upgradable as needed

18.

When configuring IPv6 on an interface, which two IPv6 multicast groups are joined? (Choose two.)

a)

FF02::2

b)

FC00::/7

c)

FF02::1

d)

2002::5

e)

2000::/3

19.

An engineer must configure a WLAN using the strongest encryption type for WPA2-PSK Which cipher fulfills the configuration requirement?

a)

WEP

b)

TKIP

c)

RC4

d)

AES

20.

Which goal is achieved by the implementation of private IPv4 addressing on a network?

a)

allows servers and workstations to communicate across public network boundaries

b)

allows communication across the Internet to other private networks

c)

provides a reduction in size of the forwarding table on network routers

d)

provides an added level of protection against Internet exposure

21.

Which type of attack is mitigated by dynamic ARP inspection?

a)

man-in-the-middle

b)

DDoS

c)

Worm

d)

Malware

22.

A device detects two stations transmitting frames at the same time. This condition occurs after the first 64 bytes of the frame is received. Which interface counter increments?

a)

late collision

b)

Runt

c)

CRC

d)

Collision

23.

How does Cisco DNA Center gather data from the network?

a)

The Cisco CLI Analyzer tool gathers data from each licensed network device and streams it to the controller.

b)

Network devices use different services like SNMP, syslog, and streaming telemetry to send data to the controller.

c)

Devices use the call-home protocol to periodically send data to the controller

d)

Devices establish an IPsec tunnel to exchange data with the controller.

24.

How does CAPWAP communicate between an access point in local mode and a WLC?

a)

The access point has the ability to link to any switch in the network, assuming connectivity to the WLC.

b)

The access point must be connected to the same switch as the WLC.

c)

The access point must directly connect to the WLC using a copper cable.

d)

The access point must not be connected to the wired network, as it would create a loop.

25.

An engineer is configuring NAT to translate the source subnet of 10.10.0.0/24 to any one of three addresses:192.168.3.1, 192.168.3.2, or 192.168.3.3. Which configuration should be used?

a)

enable

configure terminal

ip nat pool mypool 192168.3.1 192.168.3.3 prefix-length30

access-list 1 permit 10.10.0.0 0.0.0.255

ip nat inside source list 1 pool mypool

interface g1/1

ip nat inside

interface g1/2

ip nat outside

b)

enable

configure terminal

ip nat pool mypool 192,168.3.1 192.168.3.3 prefix-length 30

access-list 1 permit 10.10.0.0 0.0.0.255

ip nat outside destination list 1 pool mypool

interface g1/1

ip nat inside

interface g1/2

ip nat outside

c)

enable

configure terminal

ip nat pool mypool 192,168.3.1 192.168.3.3 prefix-length 30

access-list 1 permit 10.10.0.0 0.0.0.255

ip nat outside destination list 1 pool mypool

interface g1/1

ip nat inside

interface g1/2

ip nat outside

d)

enable

configure terminal

ip nat pool mypool 192.168.3.1 192.168.3.3 prefix-length 30

route-map permit 10.10.0.0 255.255.255.0

ip nat outside destination list 1 pool mypool

interface g1/1

ip nat inside

interface g1/2

ip nat outside

e)

enable

configure terminal

ip nat pool mypool 192.168.3.1 192.168.3.3 prefix-length 30

access-list 1 permit 10.10.0.0 0.0.0.254

ip nat inside source list 1 pool mypool

interface g1/1

ip nat inside

interface g1/2

ip nat outside .

26.

Refer to the exhibit. An engineer deploys a topology in which R1 obtains its IP configuration from DHCP. If the switch and DHCP server configurations are complete and correct, which two sets of commands must be configured on R1 and R2 to complete the task? (Choose two.)

a)

R1 (config)# interface fa0/0

R1 (config-if)# ip address dhcp

R1 (config-if)# no shutdown

b)

R1 (config)# interface fa0/0

R1 (config-if)# ip helper-address 192.0.2.2

c)

R2(config)# interface gi0/0

R2(config-if)# ip helper-address 198.51.10

d)

R2(config)# interface gi0/0

R2(config-if)# ip address dhcp

e)

R1 (confi9)# interface fa0/0

R1 (config-if)# ip helper-address 198.51.100.100

27.

Which command must be entered when a device is configured as an NTP server?

a)

ntp peer

b)

ntp server

c)

ntp master

d)

ntp authenticate

28.

What mechanism carries multicast traffic between remote sites and supports encryption?

a)

GRE

b)

GRE over IPsec

c)

ISATAP

d)

IPsec over ISATAP

29.

Which 802.11 frame type is Association Response?

a)

control

b)

protected frame

c)

management

d)

action

30.

The service password-encryption command is entered on a router. What is the effect of this configuration?

a)

protects the VLAN database from unauthorized PC connections on the switch

b)

encrypts the password exchange when a VPN tunnel is established

c)

prevents network administrators from configuring clear-text passwords

d)

restricts unauthorized users from viewing clear-text passwords in the running configuration

31.

Refer to the exhibit. Which outcome is expected when PC_A sends data to PC_B?

a)

The source MAC address is changed.

b)

The source and destination MAC addresses remain the same.

c)

The destination MAC address is replaced with ffff.ffff.ffff

d)

The switch rewrites the source and destination MAC addresses with its own.

32.

What is a characteristic of spine-and-Ieaf architecture?

a)

Each link between leaf switches allows for higher bandwidth.

b)

Each device is separated by the same number of hops.

c)

It provides variable latency.

d)

It provides greater predictability on STP blocked ports.

33.

A packet is destined for 10.10.1.22. Which static route does the router choose to forward the packet?

a)

ip route 10.10.1.0 255.255.255.240 10.10.255.1

b)

ip route 10.10.1.16 255.255.255.252 10.10.255.1

c)

ip route 10.10.1.20 255.255.255.252 10.10.255.1

d)

ip route 10.10.1.20 255.255.255.254 10.10.255.1

34.

How do AAA operations compare regarding user identification, user services, and access control?

a)

Authorization identifies users, and authentication provides access control.

b)

Authorization provides access control, and authentication tracks user services

c)

Authentication identifies users, and accounting tracks user services.

d)

Accounting tracks user services, and authentication provides access control.

35.

Refer to the exhibit Which configuration issue is preventing the OSPF neighbor relationship from being established between the two routers?

a)

R1 interface Gi1/0 has a larger MTU size.

b)

R1 has an incorrect network command for interface Gi1/0.

c)

R2 should have its network command in area 1.

d)

R2 is using the passive-interface default command.

36.

Which feature on the Cisco Wireless LAN Controller when enabled restricts management access from specific networks?

a)

RADIUS

b)

Flex ACL

c)

CPU ACL

d)

TACACS

37.

What are two reasons for an engineer to configure a floating static route? (Choose two.)

a)

to enable fallback static routing when the dynamic routing protocol fails

b)

to support load balancing via static routing

c)

to route traffic differently based on the source IP of the packet

d)

to automatically route traffic on a secondary path when the primary path goes down

e)

to control the return path of traffic that is sent from the router

38.

What is the expected outcome when an EUl-64 address is generated?

a)

The seventh bit of the original MAC address of the interface is inverted,

b)

The MAC address of the interface is used as the interface ID without modification.

c)

The characters FE80 are inserted at the beginning of the MAC address of the interface.

d)

The interface ID is configured as a random 64-bit value.

39.

What are two reasons that cause late collisions to increment on an Ethernet interface? (Choose two.)

a)

when one side of the connection is configured for half-duplex

b)

When the cable length limits are exceeded

c)

when Carrier Sense Multiple Access/Collision Detection is used

d)

when a collision occurs after the 32nd byte of a frame has been transmitted

e)

sending

40.

Referto the exhibit. What is the effect of this configuration?

a)

The switch port interface trust state becomes untrusted

b)

The switch port remains administratively down until the interface is connected to another switch

c)

The switch port remains down until it is configured to trust or untrust incoming packets

d)

Dynamic ARP Inspection is disabled because the ARP ACL is missing

41.

Refer to the exhibit. What commands are needed to add a subinterface to Ethernet0/0 on R1 to allow for VLAN 20, with IP address 10.20.20.1/24?

a)

R1 (config)# interface ethernet0/0

R1(config)# ip address 10.20.20.1 255.255.255.0

b)

R1 (config)# interface ethernet0/0.20

R1(config)# encapsulation dot1q 20

R1(config)# ip address 10.20.20.1 255.255.255.0

c)

R1 (config)# interface ethernet0/0.20

R1(config)# ip address 10.20.20.1 255.255.255.0

d)

R1 (config)# interface ethernet0/0

R1(config)# encapsulation dot1q 20

R1(config)# ip address 10.20.20.1 255.255.255.0

42.

What are two benefits of controller-based networking compared to traditional networking? (Choose two.)

a)

controller-based allows for fewer network failures, while traditional increases failure rates

b)

controller-based increases network bandwidth usage. while traditional lightens the load on the network

c)

controller-based inflates software costs, while traditional decreases individual licensing costs

d)

controller-based reduces network configuration complexity, while traditional increases the potential for errors

e)

controller-based provides centralization of key IT functions, while traditional requires distributed management functions

43.

Refer to the exhibit. An engineer booted a new switch and applied this configuration via the console port. Which additional configuration must be applied to allow administrators to authenticate directly to enable privilege mode via Telnet using a local username and password?

a)

R1(confi9)#username admin .

R1 (config-if)#line vty 0 4

R1(config-line)#password p@ss1234

b)

R1(config)#usemame admin

R1 (config-if)#line vty 0 4

R1 (config-line)#password p@ss1234

R1 (config-Iine)#transport input telnet

c)

R1 (config)#usemame admin secret p@ss1234

R1 (config-if)#line vty 0 4

R1 (config-line)#login local

R1(config)#enable secret p@ss1234

d)

R1(config)#usemame admin privilege 15 secret p@ss1234

R1(config-if)#line vty 0 4

R1 (config-Iine)#login local

44.

Refer to the exhibit. Which switch becomes the root bridge?

a)

S3

b)

S4

c)

S1

d)

S2

45.

Refer to the exhibit. Which route type does the‘routing protocol Code D represent in the output?

a)

/24 route of a locally configured IP

b)

statically assigned route

c)

internal BGP route

d)

route learned through EIGRP

46.

Which two values or settings must be entered when configuring a new WLAN in the Cisco Wireless LAN Controller GUI? (Choose two.)

a)

QoS settings

b)

management interface settings

c)

SSID

d)

IP address of one or more access points

e)

profile name

47.

Which configuration is needed to generate an RSA key for SSH on a router?

a)

Create a user with a password.

b)

Configure the version of SSH

c)

Configure VTY access.

d)

Assign a DNS domain name

48.

Refer to the exhibit. An administrator is tasked with configuring a voice VLAN. What is the expected outcome when a Cisco phone is connected to the GigabitEthernet3/1/4 port on a switch?

a)

The phone sends and receives data in VLAN 50, but a workstation connected to the phone sends and receives data in VLAN 1.

b)

The phone sends and receives data in VLAN 50, but a workstation connected to the phone has no VLAN connectivity.

c)

The phone and a workstation that is connected to the phone do not have VLAN connectivity.

d)

The phone and a workstation that is connected to the phone send and receive data in VLAN 50.

49.

Refer to the exhibit. Which action is expected from SW1 when the untagged frame is received on the GigabitEthernet0/1 interface?

a)

The frame is processed in VLAN 1.

b)

The frame is processed in VLAN 11.

c)

The frame is dropped.

d)

The frame is processed in VLAN 5.

50.

What are two descriptions of three-tier network topologies? (Choose two.)

a)

The core layer maintains wired connections for each host.

b)

The distribution layer runs Layer 2 and Layer 3 technologies.

c)

The core and distribution layers perform the same functions.

d)

The access layer manages routing between devices in different domains.

e)

The network core is designed to maintain continuous connectivity when devices fail.