WorksheetsCCNA 3 Final Exam 52-100
Total questions: 50
Worksheet time: 28mins
What is a characteristic of the two-tier spine-leaf topology of the Cisco ACI fabric architecture?
The leaf switches always attach to the spines, but they never attach to each other.
The leaf switches always attach to the spines and they are interlinked through a trunk line.
The spine switches attach to the leaf switches and attach to each other for redundancy.
The spine and leaf switches are always linked through core switches.
Which two scenarios would result in a duplex mismatch? (Choose two.)
connecting a device with autonegotiation to another that is manually set to full-duplex
manually setting the two connected devices to different duplex modes
starting and stopping a router interface during a normal operation
connecting a device with an interface running at 100 Mbps to another with an interface running at 1000 Mbps
configuring dynamic routing incorrectly
A network technician is configuring SNMPv3 and has set a security level of auth . What is the effect of this setting?
authenticates a packet by using either the HMAC with MD5 method or the SHA method
authenticates a packet by a string match of the username or community string
authenticates a packet by using either the HMAC MD5 or 3.HMAC SHA algorithms and encrypts the packet with either the DES, 3DES or AES algorithms
authenticates a packet by using the SHA algorithm only
What are two types of attacks used on DNS open resolvers? (Choose two.)
amplification and reflection
resource utilization
fast flux
ARP poisoning
cushioning
An ACL is applied inbound on a router interface. The ACL consists of a single entry:
access-list 101 permit udp 192.168.100.0 0.0.2.255 64.100.40.0 0.0.0.15 eq telnet .
If a packet with a source address of 192.168.101.45, a destination address of 64.100.40.4, and a protocol of 23 is received on the interface, is the packet permitted or denied?
denied
permitted
An ACL is applied inbound on a router interface. The ACL consists of a single entry:
access-list 101 permit udp 192.168.100.0 0.0.2.255 64.100.40.0 0.0.0.0.15 eq telnet .
If a packet with a source address of 192.168.100.219, a destination address of 64.100.40.10, and a protocol of 54 is received on the interface, is the packet permitted or denied?
denied
permitted
Which type of resources are required for a Type 1 hypervisor?
a management console
a host operating system
a dedicated VLAN
In JSON, what is held within square brackets [ ]?
an array
an object
key/value pairs
nested values
What are three components used in the query portion of a typical RESTful API request? (Choose three.)
format
key
parameters
API server
protocol
A user reports that when the corporate web page URL is entered on a web browser, an error message indicates that the page cannot be displayed. The help-desk technician asks the user to enter the IP address of the web server to see if the page can be displayed. Which troubleshooting method is being used by the technician?
divide-and-conquer
substitution
bottom-up
top-down
Which protocol provides authentication, integrity, and confidentiality services and is a type of VPN?
IPsec
AES
MD5
ESP
Which statement describes a characteristic of Cisco Catalyst 2960 switches?
New Cisco Catalyst 2960-C switches support PoE pass-through.
They are best used as distribution layer switches.
They are modular switches.
They do not support an active switched virtual interface (SVI) with IOS versions prior to 15.x.
Which component of the ACI architecture translates application policies into network programming?
the Application Policy Infrastructure Controller
the hypervisor
the Nexus 9000 switch
the Application Network Profile endpoints
Which two pieces of information should be included in a logical topology diagram of a network? (Choose two.)
interface identifier
connection type
OS/IOS version
cable specification
cable type and identifier
Refer to the exhibit. A PC at address 10.1.1.45 is unable to access the Internet. What is the most likely cause of the problem?
The NAT pool has been exhausted.
The wrong netmask was used on the NAT pool.
Access-list 1 has not been configured properly.
The inside and outside interfaces have been configured backwards.
What are two benefits of using SNMP traps? (Choose two.)
They eliminate the need for some periodic polling requests.
They reduce the load on network and agent resources.
They limit access for management systems only.
They can provide statistics on TCP/IP packets that flow through Cisco devices.
They can passively listen for exported NetFlow datagrams.
Which statement accurately describes a characteristic of IPsec?
IPsec is a framework of open standards that relies on existing algorithms.
IPsec works at the transport layer and protects data at the network layer.
IPsec is a framework of proprietary standards that depend on Cisco specific algorithms.
IPsec is a framework of standards developed by Cisco that relies on OSI algorithms.
IPsec works at the application layer and protects all application data.
In a large enterprise network, which two functions are performed by routers at the distribution layer? (Choose two.)
connect remote networks
provide data traffic security
provide Power over Ethernet to devices
provide a high-speed network backbone
connect users to the network
Which two statements describe the use of asymmetric algorithms? (Choose two.)
If a private key is used to encrypt the data, a public key must be used to decrypt the data.
If a public key is used to encrypt the data, a private key must be used to decrypt the data.
If a private key is used to encrypt the data, a private key must be used to decrypt the data.
If a public key is used to encrypt the data, a public key must be used to decrypt the data.
Public and private keys may be used interchangeably.
Refer to the exhibit. A network administrator has deployed QoS and has configured the network to mark traffic on the VoIP phones as well as the Layer 2 and Layer 3 switches. Where should initial marking occur to establish the trust boundary?
Trust Boundary 1
Trust Boundary 3
Trust Boundary 4
Trust Boundary 2
What are two benefits of extending access layer connectivity to users through a wireless medium? (Choose two.)
reduced costs
increased flexibility
decreased number of critical points of failure
increased bandwidth availability
increased network management options
What are two purposes of launching a reconnaissance attack on a network? (Choose two.)
to scan for accessibility
to gather information about the network and devices
to retrieve and modify data
to prevent other users from accessing the system
to escalate access privileges
A group of users on the same network are all complaining about their computers running slowly. After investigating, the technician determines that these computers are part of a zombie network. Which type of malware is used to control these computers?
botnet
spyware
virus
rootkit
An ACL is applied inbound on a router interface. The ACL consists of a single entry:
access-list 101 permit tcp 10.1.1.0 0.0.0.255 host 192.31.7.45 eq dns .
If a packet with a source address of 10.1.1.201, a destination address of 192.31.7.45, and a protocol of 23 is received on the interface, is the packet permitted or denied?
permitted
denied
Refer to the exhibit. From which location did this router load the IOS?
flash memory
NVRAM?
RAM
ROM
a TFTP server?
Refer to the exhibit. Which data format is used to represent the data for network automation applications?
JSON
HTML
YAML
XML
What QoS step must occur before packets can be marked?
classifying
shaping
queuing
policing
What is the main function of a hypervisor?
It is used to create and manage multiple VM instances on a host machine.
It is a device that filters and checks security credentials.
It is a device that synchronizes a group of sensors.
It is software used to coordinate and prepare data for analysis.
It is used by ISPs to monitor cloud computing resources.
A company needs to interconnect several branch offices across a metropolitan area. The network engineer is seeking a solution that provides high-speed converged traffic, including voice, video, and data on the same network infrastructure. The company also wants easy integration to their existing LAN infrastructure in their office locations. Which technology should be recommended?
Ethernet WAN
Frame Relay
VSAT
ISDN
Refer to the exhibit. As traffic is forwarded out an egress interface with QoS treatment, which congestion avoidance technique is used?
traffic policing
classification and marking
weighted random early detection
traffic shaping
An ACL is applied inbound on a router interface. The ACL consists of a single entry:
access-list 101 permit tcp 10.1.1.0 0.0.0.255 host 10.1.3.8 eq dns .
If a packet with a source address of 10.1.3.8, a destination address of 10.10.3.8, and a protocol of 53 is received on the interface, is the packet permitted or denied?
denied
permitted
Refer to the exhibit. What is the purpose of the command marked with an arrow shown in the partial configuration output of a Cisco broadband router?
defines which addresses can be translated
defines which addresses are allowed into the router
defines which addresses are assigned to a NAT pool
defines which addresses are allowed out of the router
If a router has two interfaces and is routing both IPv4 and IPv6 traffic, how many ACLs could be created and applied to it?
8
12
4
16
6
Refer to the exhibit. An administrator first configured an extended ACL as shown by the output of the show access-lists command. The administrator then edited this access-list by issuing the commands below.
Router(config)# ip access-list extended 101
Router(config-ext-nacl)# no 20
Router(config-ext-nacl)# 5 permit tcp any any eq 22
Router(config-ext-nacl)# 20 deny udp any any
Which two conclusions can be drawn from this new configuration? (Choose two.)
Ping packets will be permitted.
SSH packets will be permitted.
TFTP packets will be permitted.
Telnet packets will be permitted.
All TCP and UDP packets will be denied.
Which troubleshooting approach is more appropriate for a seasoned network administrator rather than a less-experienced network administrator?
a less-structured approach based on an educated guess
an approach comparing working and nonworking components to spot significant differences
a structured approach starting with the physical layer and moving up through the layers of the OSI model until the cause of the problem is identified
an approach that starts with the end-user applications and moves down through the layers of the OSI model until the cause of the problem has been identified
Refer to the exhibit. Many employees are wasting company time accessing social media on their work computers. The company wants to stop this access. What is the best ACL type and placement to use in this situation?
extended ACLs inbound on R1 G0/0 and G0/1
standard ACL outbound on R2 S0/0/0
standard ACL outbound on R2 WAN interface towards the internet
extended ACL outbound on R2 WAN interface towards the internet
Refer to the exhibit. An administrator is trying to configure PAT on R1, but PC-A is unable to access the Internet. The administrator tries to ping a server on the Internet from PC-A and collects the debugs that are shown in the exhibit. Based on this output, what is most likely the cause of the problem?
The inside global address is not on the same subnet as the ISP
The inside and outside NAT interlaces have been configured backwards
The address on Fa0/0 should be 64.100.0.1.
The NAT source access list matches the wrong address range.
Why is QoS an important issue in a converged network that combines voice, video, and data communications?
Voice and video communications are more sensitive to latency.
Data communications must be given the first priority.
Legacy equipment is unable to transmit voice and video without QoS.
Data communications are sensitive to jitter.
Which statement describes a VPN?
VPNs use virtual connections to create a private network through a public network.
VPNs use dedicated physical connections to transfer data between remote users.
VPNs use open source virtualization software to create the tunnel through the Internet.
VPNs use logical connections to create public networks through the Internet.
In which OSPF state is the DR/BDR election conducted?
Two-Way
Exchange
Init
ExStart
Two corporations have just completed a merger. The network engineer has been asked to connect the two corporate networks without the expense of leased lines. Which solution would be the most cost effective method of providing a proper and secure connection between the two corporate networks?
site-to-site VPN
Cisco AnyConnect Secure Mobility Client with SSL
remote access VPN using IPsec
Frame Relay
Cisco Secure Mobility Clientless SSL VPN
What is the final operational state that will form between an OSPF DR and a DROTHER once the routers reach convergence?
full
established
loading
two-way
Refer to the exhibit. If the switch reboots and all routers have to re-establish OSPF adjacencies, which routers will become the new DR and BDR?
Router R3 will become the DR and router R1 will become the BDR.
Router R4 will become the DR and router R3 will become the BDR.
Router R1 will become the DR and router R2 will become the BDR.
Router R3 will become the DR and router R2 will become the BDR.
Which type of server would be used to keep a historical record of messages from monitored network devices?
syslog
authentication
DHCP
DNS
When QoS is implemented in a converged network, which two factors can be controlled to improve network performance for real-time traffic? (Choose two.)
delay
jitter
packet addressing
packet routing
link speed
In which step of gathering symptoms does the network engineer determine if the problem is at the core, distribution, or access layer of the network?
Narrow the scope.
Determine the symptoms.
Determine ownership.
Document the symptoms.
Gather information.
What protocol sends periodic advertisements between connected Cisco devices in order to learn device name, IOS version, and the number and type of interfaces?
CDP
SNMP
NTP
LLDP
An administrator is configuring single-area OSPF on a router. One of the networks that must be advertised is 192.168.0.0 255.255.252.0. What wildcard mask would the administrator use in the OSPF network statement?
0.0.3.255
0.0.0.63
0.0.0.31
0.0.0.127
Refer to the exhibit. An administrator configures the following ACL in order to prevent devices on the 192.168.1.0 subnet from accessing the server at 10.1.1.5:
access-list 100 deny ip 192.168.1.0 0.0.0.255 host 10.1.1.5
access-list 100 permit ip any any
Where should the administrator place this ACL for the most efficient use of network resources?
inbound on router A Fa0/0
outbound on router B Fa0/0
outbound on router A Fa0/1
inbound on router B Fa0/1
Which type of OSPFv2 packet is used to forward OSPF link change information?
link-state update
link-state acknowledgment
hello
database description
