Font size
WorksheetsCCNA 2 v7 Practice Test (Pt. 2)
Total questions: 60
Worksheet time: 5hrs 0mins
Refer to the exhibit. Which three hosts will receive ARP requests from host A, assuming that port Fa0/4 on both switches is configured to carry traffic for multiple VLANs? (Choose three.)
Host B
Host C
Host D
Host E
Host F
Refer to the exhibit. The network administrator configures both switches as displayed. However, host C is unable to ping host D and host E is unable to ping host F. What action should the administrator take to enable this communication?
Associate hosts A and B with VLAN 10 instead of VLAN 1.
Configure either trunk port in the dynamic desirable mode.
Include a router in the topology.
Remove the native VLAN from the trunk.
Add the switchport nonegotiate command to the configuration of SW2.
What is the effect of entering the shutdown configuration command on a switch?
It enables BPDU guard on a specific port.
It disables an unused port.
It enables portfast on a specific switch interface.
It disables DTP on a non-trunking interface.
What would be the primary reason an attacker would launch a MAC address overflow attack?
so that the switch stops forwarding traffic
so that legitimate hosts cannot obtain a MAC address
so that the attacker can see frames that are destined for other hosts
so that the attacker can execute arbitrary code on the switch
During the AAA process, when will authorization be implemented?
Immediately after successful authentication against an AAA data source
Immediately after AAA accounting and auditing receives detailed reports
Immediately after an AAA client sends authentication information to a centralized server
Immediately after the determination of which resources a user can access
A company security policy requires that all MAC addressing be dynamically learned and added to both the MAC address table and the running configuration on each switch. Which port security configuration will accomplish this?
auto secure MAC addresses
dynamic secure MAC addresses
static secure MAC addresses
sticky secure MAC addresses
Which three Wi-Fi standards operate in the 2.4GHz range of frequencies? (Choose three.)
802.11a
802.11b
802.11g
802.11n
802.11ac
To obtain an overview of the spanning tree status of a switched network, a network engineer issues the show spanning-tree command on a switch. Which two items of information will this command display? (Choose two.)
The root bridge BID.
The role of the ports in all VLANs.
The status of native VLAN ports.
The number of broadcasts received on each root port.
The IP address of the management VLAN interface.
Refer to the exhibit. Which trunk link will not forward any traffic after the root bridge election process is complete?
Trunk1
Trunk2
Trunk3
Trunk4
Which method of IPv6 prefix assignment relies on the prefix contained in RA messages?
EUI-64
SLAAC
static
stateful DHCPv6
Which two protocols are used to provide server-based AAA authentication? (Choose two.)
802.1x
SSH
SNMP
TACAS+
RADIUS
A network administrator is configuring a WLAN. Why would the administrator disable the broadcast feature for the SSID?
to eliminate outsiders scanning for available SSIDs in the area
to reduce the risk of interference by external devices such as microwave ovens
to reduce the risk of unauthorized APs being added to the network
to provide privacy and integrity to wireless traffic by using encryption
Which mitigation technique would prevent rogue servers from providing false IP configuration parameters to clients?
implementing port security
turning on DHCP snooping
disabling CDP on edge ports
implementing port-security on edge ports
A network administrator configures the port security feature on a switch. The security policy specifies that each access port should allow up to two MAC addresses. When the maximum number of MAC addresses is reached, a frame with the unknown source MAC address is dropped and a notification is sent to the syslog server. Which security violation mode should be configured for each access port?
Shutdown
Restrict
Warning
Protect
What protocol or technology defines a group of routers, one of them defined as active and another one as standby?
EtherChannel
VTP
HSRP
DTP
Refer to the exhibit. After attempting to enter the configuration that is shown in router RTA, an administrator receives an error and users on VLAN 20 report that they are unable to reach users on VLAN 30. What is causing the problem?
There is no address on Fa0/0 to use as a default gateway.
RTA is using the same subnet for VLAN 20 and VLAN 30.
Dot1q does not support subinterfaces.
The no shutdown command should have been issued on Fa0/0.20 and Fa0/0.30.
Which three pairs of trunking modes will establish a functional trunk link between two Cisco switches? (Choose three.)
dynamic auto - dynamic auto
dynamic desirable - trunk
access - dynamic auto
dynamic desirable - dynamic desirable
dynamic desirable - dynamic auto
A technician is configuring a router for a small company with multiple WLANs and doesn’t need the complexity of a dynamic routing protocol. What should be done or checked?
Verify that there is not a default route in any of the edge router routing tables.
Create static routes to all internal networks and a default route to the internet.
Create extra static routes to the same location with an AD of 1.
Check the statistics on the default route for oversaturation.
A company is deploying a wireless network in the distribution facility in a Boston suburb. The warehouse is quite large and it requires multiple access points to be used. Because some of the company devices still operate at 2.4GHz, the network administrator decides to deploy the 802.11g standard. Which channel assignments on the multiple access points will make sure that the wireless channels are not overlapping?
channels 1, 5, and 9
channels 1, 6, and 11
channels 1, 7, and 13
channels 2, 6, and 10
A network administrator of a small advertising company is configuring WLAN security by using the WPA2 PSK method. Which credential do office users need in order to connect their laptops to the WLAN?
the company username and password through Active Directory service
a key that matches the key on the AP
a user passphrase
a username and password configured on the AP
Refer to the exhibit. What are the possible port roles for ports A, B, C, and D in this RSTP-enabled network?
alternate, designated, root, root
designated, alternate, root, root
alternate, root, designated, root
designated, root, alternate, root
Refer to the exhibit. Which static route would an IT technician enter to create a backup route to the 172.16.1.0 network that is only used if the primary RIP learned route fails?
ip route 172.16.1.0 255.255.255.0 s0/0/0
ip route 172.16.1.0 255.255.255.0 s0/0/0 121
ip route 172.16.1.0 255.255.255.0 s0/0/0 111
ip route 172.16.1.0 255.255.255.0 s0/0/0 91
What mitigation plan is best for thwarting a DoS attack that is creating a MAC address table overflow?
Disable DTP.
Disable STP.
Enable port security.
Place unused ports in an unused VLAN.
A network engineer is troubleshooting a newly deployed wireless network that is using the latest 802.11 standards. When users access high bandwidth services such as streaming video, the wireless network performance is poor. To improve performance the network engineer decides to configure a 5 Ghz frequency band SSID and train users to use that SSID for streaming media services. Why might this solution improve the wireless network performance for that type of service?
Requiring the users to switch to the 5 GHz band for streaming media is inconvenient and will result in fewer users accessing these services.
The 5 GHz band has more channels and is less crowded than the 2.4 GHz band, which makes it more suited to streaming multimedia.
The 5 GHz band has a greater range and is therefore likely to be interference-free.
The only users that can switch to the 5 GHz band will be those with the latest wireless NICs, which will reduce usage.
Which DHCPv4 message will a client send to accept an IPv4 address that is offered by a DHCP server?
broadcast DHCPACK
broadcast DHCPREQUEST
unicast DHCPACK
unicast DHCPREQUEST
Refer to the exhibit. Which destination MAC address is used when frames are sent from the workstation to the default gateway?
MAC address of the virtual router
MAC address of the standby router
MAC addresses of both the forwarding and standby routers
MAC address of the forwarding router
After a host has generated an IPv6 address by using the DHCPv6 or SLAAC process, how does the host verify that the address is unique and therefore usable?
The host sends an ICMPv6 echo request message to the DHCPv6 or SLAAC-learned address and if no reply is returned, the address is considered unique.
The host sends an ICMPv6 neighbor solicitation message to the DHCP or SLAAC-learned address and if no neighbor advertisement is returned, the address is considered unique.
The host checks the local neighbor cache for the learned address and if the address is not cached, it it considered unique.
The host sends an ARP broadcast to the local link and if no hosts send a reply, the address is considered unique.
Which protocol adds security to remote connections?
FTP
HTTP
NetBEUI
POP
SSH
Refer to the exhibit. A network administrator is verifying the configuration of inter-VLAN routing. Users complain that PC2 cannot communicate with PC1. Based on the output, what is the possible cause of the problem?
Gi0/0 is not configured as a trunk port.
The command interface GigabitEthernet0/0.5 was entered incorrectly.
There is no IP address configured on the interface Gi0/0.
The no shutdown command is not entered on subinterfaces.
The encapsulation dot1Q 5 command contains the wrong VLAN.
Refer to the exhibit. A network administrator is configuring inter-VLAN routing on a network. For now, only one VLAN is being used, but more will be added soon. What is the missing parameter that is shown as the highlighted question mark in the graphic?
It identifies the subinterface.
It identifies the VLAN number.
It identifies the native VLAN number.
It identifies the type of encapsulation that is used.
It identifies the number of hosts that are allowed on the interface.
What network attack seeks to create a DoS for clients by preventing them from being able to obtain a DHCP lease?
IP address spoofing
DHCP starvation
CAM table attack
DHCP spoofing
Refer to the exhibit. If the IP addresses of the default gateway router and the DNS server are correct, what is the configuration problem?
he DNS server and the default gateway router should be in the same subnet.
The IP address of the default gateway router is not contained in the excluded address list.
The default-router and dns-server commands need to be configured with subnet masks.
The IP address of the DNS server is not contained in the excluded address list.
Refer to the exhibit. A network administrator has added a new subnet to the network and needs hosts on that subnet to receive IPv4 addresses from the DHCPv4 server.What two commands will allow hosts on the new subnet to receive addresses from the DHCP4 server? (Choose two.)
R1(config-if)# ip helper-address 10.2.0.250
R1(config)# interface G0/1
R1(config)# interface G0/0
R2(config-if)# ip helper-address 10.2.0.250
R2(config)# interface G0/0
What protocol or technology uses source IP to destination IP as a load-balancing mechanism?
VTP
EtherChannel
DTP
STP
What protocol should be disabled to help mitigate VLAN attacks?
CDP
ARP
STP
DTP
What protocol or technology requires switches to be in server mode or client mode?
EtherChannel
STP
VTP
DTP
What are two reasons a network administrator would segment a network with a Layer 2 switch? (Choose two.)
to create fewer collision domains
to enhance user bandwidth
to create more broadcast domains
to eliminate virtual circuits
to isolate traffic between segments
What command will enable a router to begin sending messages that allow it to configure a link-local address without using an IPv6 DHCP server?
a static route
the ipv6 route ::/0 command
the ipv6 unicast-routing command
the ip routing command
A network administrator is using the router-on-a-stick model to configure a switch and a router for inter-VLAN routing. What configuration should be made on the switch port that connects to the router?
Configure it as a trunk port and allow only untagged traffic.
Configure the port as an access port and a member of VLAN1.
Configure the port as an 802.1q trunk port.
Configure the port as a trunk port and assign it to VLAN1.
What are three techniques for mitigating VLAN attacks? (Choose three.)
Set the native VLAN to an unused VLAN.
Disable DTP.
Use private VLANs.
Enable BPDU guard.
Enable trunking manually
In which situation would a technician use the show interfaces switch command?
to determine if remote access is enabled
when packets are being dropped from a particular directly attached host
when an end device can reach local devices, but not remote devices
to determine the MAC address of a directly attached network device on a particular interface
What is a drawback of the local database method of securing device access that can be solved by using AAA with centralized servers?
There is no ability to provide accountability.
User accounts must be configured locally on each device, which is an unscalable authentication solution.
It is very susceptible to brute-force attacks because there is no username.
The passwords can only be stored in plain text in the running configuration.
What action does a DHCPv4 client take if it receives more than one DHCPOFFER from multiple DHCP servers?
It sends a DHCPREQUEST that identifies which lease offer the client is accepting.
It sends a DHCPNAK and begins the DHCP process over again.
It discards both offers and sends a new DHCPDISCOVER.
It accepts both DHCPOFFER messages and sends a DHCPACK.
Refer to the exhibit. The network administrator is configuring the port security feature on switch SWC. The administrator issued the command show port-security interface fa 0/2 to verify the configuration. What can be concluded from the output that is shown? (Choose three.)
Three security violations have been detected on this interface.
This port is currently up.
Security violations will cause this port to shut down immediately.
There is no device currently connected to this port.
The switch port mode for this interface is access mode.
What method of wireless authentication is dependent on a RADIUS authentication server?
WEP
WPA Personal
WPA2 Personal
WPA2 Enterprise
A network administrator has found a user sending a double-tagged 802.1Q frame to a switch. What is the best solution to prevent this type of attack?
The native VLAN number used on any trunk should be one of the active data VLANs.
The VLANs for user access ports should be different VLANs than any native VLANs used on trunk ports.
Trunk ports should be configured with port security.
Trunk ports should use the default VLAN as the native VLAN number.
Refer to the exhibit. Which two conclusions can be drawn from the output? (Choose two.)
The EtherChannel is down
The port channel ID is 2
The port channel is a Layer 3 channel.
The bundle is fully operational.
The load-balancing method used is source port to destination port.
On a Cisco 3504 WLC Summary page ( Advanced > Summary ), which tab allows a network administrator to configure a particular WLAN with a WPA2 policy?
WLANs
SECURITY
WIRELESS
MANAGEMENT
Refer to the exhibit. A network engineer is configuring IPv6 routing on the network. Which command issued on router HQ will configure a default route to the Internet to forward packets to an IPv6 destination network that is not listed in the routing table?
ipv6 route ::/0 serial 0/0/0
ip route 0.0.0.0 0.0.0.0 serial 0/1/1
ipv6 route ::1/0 serial 0/1/1
ipv6 route ::/0 serial 0/1/1
Users are complaining of sporadic access to the internet every afternoon. What should be done or checked?
Create static routes to all internal networks and a default route to the internet.
Verify that there is not a default route in any of the edge router routing tables.
Create a floating static route to that network.
Check the statistics on the default route for oversaturation.
What action takes place when the source MAC address of a frame entering a switch appears in the MAC address table associated with a different port?
The switch purges the entire MAC address table.
The switch replaces the old entry and uses the more current port.
The switch updates the refresh timer for the entry.
The switch forwards the frame out of the specified port.
A network administrator is configuring a WLAN. Why would the administrator use a WLAN controller?
to centralize management of multiple WLANs
to provide privacy and integrity to wireless traffic by using encryption
to facilitate group configuration and management of multiple WLANs through a WLC
to provide prioritized service for time-sensitive applications
A new Layer 3 switch is connected to a router and is being configured for interVLAN routing. What are three of the five steps required for the configuration? (Choose three.)Case 1:
installing a static route
entering “no switchport” on the port connected to the router
modifying the default VLAN
assigning ports to VLANs
enabling IP routing
Which three statements accurately describe duplex and speed settings on Cisco 2960 switches? (Choose three.)
An autonegotiation failure can result in connectivity issues.
When the speed is set to 1000 Mb/s, the switch ports will operate in full-duplex mode.
The duplex and speed settings of each switch port can be manually configured.
Enabling autonegotiation on a hub will prevent mismatched port speeds when connecting the hub to the switch.
By default, the speed is set to 100 Mb/s and the duplex mode is set to autonegotiation.
Refer to the exhibit. A network administrator configures R1 for inter-VLAN routing between VLAN 10 and VLAN 20. However, the devices in VLAN 10 and VLAN 20 cannot communicate. Based on the configuration in the exhibit, what is a possible cause for the problem?
The port Gi0/0 should be configured as trunk port.
The encapsulation is misconfigured on a subinterface.
A no shutdown command should be added in each subinterface configuration.
The command interface gigabitEthernet 0/0.1 is wrong.
A network administrator uses the spanning-tree portfast bpduguard default global configuration command to enable BPDU guard on a switch. However, BPDU guard is not activated on all access ports. What is the cause of the issue?
BPDU guard needs to be activated in the interface configuration command mode.
Access ports configured with root guard cannot be configured with BPDU guard.
Access ports belong to different VLANs.
PortFast is not configured on all access ports.
Which two types of spanning tree protocols can cause suboptimal traffic flows because they assume only one spanning-tree instance for the entire bridged network? (Choose two.)
MSTP
RSTP
Rapid PVST+
PVST+
STP
Refer to the exhibit. A network administrator is configuring the router R1 for IPv6 address assignment. Based on the partial configuration, which IPv6 global unicast address assignment scheme does the administrator intend to implement?
stateful
stateless
manual configuration
SLAAC
A WLAN engineer deploys a WLC and five wireless APs using the CAPWAP protocol with the DTLS feature to secure the control plane of the network devices. While testing the wireless network, the WLAN engineer notices that data traffic is being exchanged between the WLC and the APs in plain-text and is not being encrypted. What is the most likely reason for this?
DTLS only provides data security through authentication and does not provide encryption for data moving between a wireless LAN controller (WLC) and an access point (AP).
Although DTLS is enabled by default to secure the CAPWAP control channel, it is disabled by default for the data channel.
DTLS is a protocol that only provides security between the access point (AP) and the wireless client.
Data encryption requires a DTLS license to be installed on each access point (AP) prior to being enabled on the wireless LAN controller (WLC).
A new switch is to be added to an existing network in a remote office. The network administrator does not want the technicians in the remote office to be able to add new VLANs to the switch, but the switch should receive VLAN updates from the VTP domain. Which two steps must be performed to configure VTP on the new switch to meet these conditions? (Choose two.)
Configure the new switch as a VTP client.
Configure the existing VTP domain name on the new switch.
Configure an IP address on the new switch.
Configure all ports of both switches to access mode.
Enable VTP pruning.
