Font size
WorksheetsTest 301-400
Total questions: 100
Worksheet time: 52mins
Which unit of measure is used to measure wireless RF SNR?
dBm
dB
mW
dBi
What is the centralized control policy in a Cisco SD-WAN deployment?
set of statements that defines how routing is performed
list of enabled services for all nodes within the cloud
set of rules that governs nodes authentication within the cloud
list of ordered statements that define user access policies
In a Cisco SD-Access wireless architecture, which device manages endpoint ID to edge node bindings?
fabric edge node
fabric border node
fabric control plane node
fabric wireless controller
Refer to the exhibit. A network engineer issues the debug command while troubleshooting a network issue. What does the output confirm?
ACL100 is tracking ICMP traffic from Serial 1/0 destined for Serial3/0
ACL100 is tracking ICMP traffic from 1.1.1.1 destined for 10.1.1.1
ACL 100 is tracking all traffic from 10.1.1.1 destined for 1.1.1.1
ACL100 is tracking ICMP traffic from 10.1.1. 1 destined for 1.1.1.1
A network administrator applies the following configuration to an IOS device:
aaa new-model
aaa authentication login default local group tacacs+
What is the process of password checks when a login attempt is made to the device?
A local database is checked first. If that check fails, a TACACS+ server is checked.
A TACACS+ server is checked first. If that check fails, a RADIUS server is checked. If that check fails, a local database is checked.
A local database is checked first. If that check fails, a TACACS+ server is checked. If that check fails, a RADIUS server is checked
TACACS + sewer is checked first 15 that check fails a local database is checked
Refer to the exhibit: A client requests a new SSID that will use web-based authentication and extremal RADIUS servers. Which Layer 2 security mode must be selected?
WPA2+WPA3
Static WEP
None
WPA+WPA2
Refer to the exhibit. An engineer must deny Telnet traffic from the loopback interface of router R3 to the loopback interface of router R2 during the weekend hours. All other traffic between the loopback interfaces of routers R3 and R2 must be allowed at all times. Which command set accomplishes this task?
R1(config)#time-range WEEKEND
R1(config-time-range#periodic weekend 00:00 to 23:59
R1(config#access-list 150 deny tcp host 10.3.3.3 host 10.2.2.2 eq 23 time-range WEEKEND
R1(config)#access-list 150 permit ip any any.
R1(config)#interface G0/1
R1(config-if)#ip access-group 150 in
R1(config)#time-range WEEKEND
R1(config-time-range)#periodic Friday Sunday 00:00 to 00:00
R1(config)#access-list 150 deny tcp host 10.3.3.3 host 10.2.2.2 eq 23 time-range WEEKEND
R1(config#access-list 150 permit ip any any
R1(config)#interface G0/1
R1(config-if#ip access-group 150 in
R3(config#time-range WEEKEND
R3(config-time-range)#periodic weekend 00:00 to 23:59
R3(config)access-list 150 permit tep host 10.3.3.3 host 10.2.2.2 eq 23 time-range WEEKEND
R3(config)#access-list 150 permit ip any any time-range WEEKEND
R3(config)#interface G0/1
R3(config-if)#ip access-group 150 out
R3(config)#time-range WEEKEND
R3(config-time-range)#periodic Saturday Sunday 00:00 to 23:59
R3(config)#access-list 150 deny tcp host 10.3.3.3 host 10.2.2.2 eq 23 time-range WEEKEND
R3(confia)# access-list 150 permit ip anv any time-range WEEKEND
R3(config)#interface GO/1
R3(config-if)#ip access-group 150 out
What is one primary REST security design principle?
separation of privilege
password hashing
confidential algorithms
OAuth
What are two considerations when using SSO as a network redundancy feature? (Choose two.)
must be combined with NSF to support uninterrupted Layer 3 operations
the multicast state is preserved during switchover
both supervisors must be configured separately
requires synchronization between supervisors in order to guarantee continuous connectivity
must be combined with NSF to support uninterrupted Layer 2 operations
An engineer must construct an access list for a Cisco Catalyst 9800 Series WLC that will redirect wireless guest users to a splash page that is hosted on a Cisco ISE server. The CiscolSE servers are hosted at 10.9.11.141 and 10.1.11.141. Which access list meets the requirements?
ip access-list extended ACL_WEBAUTH_REDIRECT
70 permit ip any host 10.9.11.141
80 permit ip any host 10.1.1.141
500 deny top any any eq www
600 deny top any any eq 443
700 deny top any any eq 8443
800 deny udp any any eq domain
901 deny ip any any
ip access-list extended ACL_WEBAUTH_REDIRECT
50 deny ip host 10.9.11.44 any
60 deny ip any host 10.9.11.141
70 deny ip host 10.1.11.141 any
80 deny ip any host 10.1.11.141
500 permit tcp any any eq www
600 permittop any any eq 443
700 permit tcp any any eq 80
ip access-list extended ACL_WEBAUTH_REDIRECT
70 deny ip any host 10.9.11.141
80 deny ip any host 10.1.11.141
500 permit tcp any any eq www
600 permit tcp any any eq 443
700 permit tcp any any eq 8443
800 deny udp any any eq domain
ip access-list extended ACL_WEBAUTH_REDIRECT
70 permit ip any host 10.9.11.141
80 permit ip any host 10.1.11.141
500 permit tcp any any eq www
600 permit tcp any any eq 443
700 permit tcp any any eq 8443
800 deny udp any any eq domain
Refer to the exhibit. An engineer must update the existing configuration to achieve these results:
1. Only administrators from the 192.168.1.0/24 subnet can access the vty lines.
2. Access to the vtv lines using clear-text protocols is prohibited.
Which command set should be applied?
access-list 1 permit 192.168.1.0 0.0.0.255
line vty 0 15
access-class 1 in
transport input telnet ssh
access-list 1 permit 192.168.1.0 0.0.0.255
line vty 0 15
access-class 1 in
transport input none
access-list 1 permit 192. 168.1.0 255.255.255.0
line vty 0 15
access-class 1 in
transport input telnet rlogin
access-list 1 permit 192.168.1.0 0.0.0.255
line vty 0 15
access-class 1 in
transport input ssh
When a branch location loses connectivity, which Cisco FlexConnect state rejects new users but allows existing users to function normally?
Authentication-Down / Switching-Down
Authentication-Central / Switch-Local
Authentication-Local / Switch-Local
Authentication-Down / Switch-Local
Refer to the exhibit. The traceroute fails from R1 to R3. What is the cause of the failure?
Redistribution of connected routes into OSPF is not configured
The loopback on R3 is in a shutdown state
An ACL applied inbound on loopback0 of R2 is dropping the traffic
An ACL applied inbound on fal/1 of R3 is dropping the traffic
Which two components are supported by LISP? (Choose two.)
HMAC algorithm
spoke
proxy ETR
route reflector
egress tunnel router
Refer to the exhibit. Extended access-list 100 is configured on interface GigabitEthernet 0/0 in an inbound direction, but it does not have the expected behavior of allowing only packets to or from 192.168.0.0/16. Which command set properly configures the access list?
R1 (config)#no access-list 100 seq 10
R1(config)#access-list 100 seq 40 deny ip any any
R1(config)#ip access-list extended 100
R1 (config-ext-nacl)#5 permit ip any any
R1(config)#ip access-list extended 100
R1(config-ext-nacl)# no 10
R1(config)#no access-list 100 deny ip any any
Which component handles the orchestration plane of the Cisco SD-WAN?
vSmart
vBond
Manage
vEdge
Which action limits the total amount of memory and CPU that is used by a collection of VMs?
Place the collection of VMs in a vApp
Limit the amount of memory and CPU that is available to the cluster
Limit the amount of memory and CPU that is available to the individual VMs
Place the collection of VMs in a resource pool
To which category does a REST API that has been developed for IP address management integration belong?
westbound
eastbound
northbound
southbound
Which configuration creates a CoPP policy that provides unlimited SSH access from client 10.0.0.5 and denies access from all other SSH clients?
!
access-list 100 permit top host 10.0.0.5 any eq 22
access-list 100 deny tep any any eq 22
!
class-map match-all telnet_copp
match access-group 100
!
policy-map CoPP
class telnet_copp
drop
!
control-plane
service-policy input CoPP
!
!
access-list 100 deny tcp host 10.0.0.5 any eq 22
access-list 100 permit top any any eq 22
!
class-map match-all telnet_copp
match access-group 100
!
policy-map CoPP
class telnet_copp
drop
!
22.02.2024
control-plane
service-policy input CoPP
!
!
access-list 100 permit top host 10.0.0.5 any eq 22
access-list 100 deny tep any any eq 22
!
class-map matcn-all telnet_copp
match access-group 100
!
policy-map CoPP
class telnet_copp
police 8000
!
control-plane
service-policy input CoPP
!
!
access-list 100 permit top any any eq 22
access-list 100 deny top host 10.0.0.5 any eq 22
!
class-map match-all telnet_copp
match access-group 100
!
policy-map CoPP
class telnet_copp
police 8000
!
control-plane
service-policy input CoPP
!
An engineer configures a WLAN with fast transition enabled. Some legacy clients fail to connect to this WLAN. Which feature allows the legacy clients to connect while still allowing other clients to use fast transition based on their OUls?
adaptive R
802.11v
over the DS
802.11k
In a Cisco StackWise Virtual environment, which planes are virtually combined in the common logical switch?
control and data
control and management
control and forwarding
management and data
Which features does Cisco EDR use to provide threat detection and response protection?
containment, threat intelligence, and machine learning
cloud analysis and endpoint firewall controls
container-based agents
firewalling and intrusion prevention
What is the preferred QoS marking for delay-sensitive real-time protocols such as RTP?
ATM-CLP
AF
EF
CS1
How is traffic classified when using Cisco TrustSec technology?
with the IP address
with the VLAN
with the MAC address
with the security group tag
What is the purpose of an RP in PIM?
send join messages toward a multicast source SPT
receive IGMP joins from multicast receivers
secure the communication channel between the multicast sender and receiver
ensure the shortest path from the multicast source to the receiver
Refer to the exhibit. An engineer is troubleshooting a newly configured BGP peering that does not establish. What is the reason for the failure?
Mandatory BGP parameters between R1 and 10.255.255.3 are mismatched
BGP peer 10.255.255.3 is not configured for peering with R1
Both BGP peers are configured for passive TCP transport
A firewall is blocking access to TCP port 179 on the BGP peer 10.255.255.3
Refer to the exhibit. An engineer must configure HSRP for VLAN 1000 on SW2. The secondary switch must immediately take over the role of active router if the interlink with the primary switch fails. Which command set completes this task?
SW2(config-if)# standby version 2
SW2(config-if)# standby 1000 ip 10.23.87.1
SW2(config-if)# standby 1000 priority 95
SW2(config-if# standby 1000 track 1000
SW2(config-if)# standby version 2
SW2(config-if)# standby 1000 ip 10.23.87.1
SW2(config-if)# standby 1000 priority 95
SW2(config-if)# standby 1000 preempt
SW2(config-if)# standby 1000 track 1000
SW2(config-if)# standby 1000 ip 10.23.87.1
SW2(config-if)# standby 1000 priority 95
SW2(config-if)# standby 1000 preempt
SW2(config-if)# standby 1000 track 1000
SW2(config-if)# standby version 2
SW2(config-f# standby 1000 ip 10.23.87.13
SW2(config-if)# standby 1000 priority 95
SW2(config-if)# standby 1000 preempt
SW2(config-if)# standby 1000 track gigabitethernet0/0
What is a benefit of YANG?
t enables multiple leaf statements to exist within a leaf list
It collects statistical constraint analysis informations
It enforces the use of a specific encoding format for NETCONF
It enforces configuration semantics
In a wireless Cisco SD-Access deployment, which roaming method is used when a user moves from one AP to another on a different access switch using a single WLC?
Layer3
inter-xTR
fast roam
auto anchor
Refer to the exhibit. The existing configuration must be updated to terminate EXEC sessions after 20 minutes of idle time. Which command set should be applied?
line vty 0 15
session-timeout 20
line vty 0 15
exec-timeout 20
line vty 0 15
absolute-timeout 20
line vty 0 15
session-limit 20
1. Refer to the exhibit. A network engineer must configure a password expiry mechanism on the gateway router for all local passwords to expire after 60 days. What is required to complete this task?
username admin privilege 15 password 0 Cisco13579!
aaa new-model
!
aaa authentication login default local
aaa authentication enable default none
!
aaa common-criteria policy Administrators
min-length 1
max-length 127
char-changes 4
lifetime month 2
!
Add the username admin privilege 15 common-criteria-policy Administrators password Cisco 13579! command
No further action is required. The configuration is complete
Add the aaa authentication enable default Administrators command
The password expiry mechanism is on the AAA server and must be configured there
Refer to the exhibit. An engineer is configuring WebAuth on a Cisco Catalyst 9800 Series WLC. The engineer has purchased a third-party certificate using the FQDN of the WLC as the CN and intends to use it on the WebAuth splash page. What must be configured so that the clients do not receive a certificate error?
Virtual 1Pv4 Address must be set to a routable address
Virtual IPv4 Hostname must match the CN of the certificate
Web Auth Intercept HTTPs must be enabled
Trustpoint must be set to the management certificate of the WLC
What is a command-line tool for consuming REST APls?
Firefox
Python requests
Postman
cURL
Which technology uses network traffic telemetry, contextual information, and file reputation to provide insight into cyber threats?
security services
threat defense
security intelligence
segmentation
In a Cisco SD-Access solution, what is the role of a fabric edge node?
to connect the fusion router to the SD-Access fabric
to connect wired endpoints to the SD-Access fabric
to advertise fabric IP address space to external networks
to connect external Layer 3 networks to the SD-Access fabric
What is a client who is using 802.1X for authentication referred to as?
authenticator
supplicant
NAC device
policy enforcement point
What is the structure of a JSON web token?
header and payload
payload and signature
three parts separated by dots: header, payload, and signature
three parts separated by dots: version, header, and signature
Refer to the exhibit. What is the result when a technician adds the monitor session 1 destination remote vlan 223 command?
RSPAN traffic is sent to VLANS 222 and 223
RSPAN traffic is split between VLANs 222 and 223
An error is flagged for configuring two destinations.
The RSPAN VLAN is replaced by VLAN 223
What is a characteristic of a virtual machine?
It must be aware of other virtual machines, in order to allocate physical resources for them
It relies on hypervisors to allocate computing resources for it
It must run the same operating system as its host
It is deployable without a hypervisor to host it
Which A record type should be configured for access points to resolve the IP address of a wireless LAN controller using DNS?
CISCO-CAPWAP-CONTROLLER.localdomain
CISCO.CAPWAP.CONTROLLER.localdomain
CISCO.CONTROLLER.localdomain
CISCO-CONTROLLER.localdomain
Why is an AP joining a different WLC than the one specified through option 43?
The WLC is running a different software version
The AP multicast traffic is unable to reach the WLC through Layer 3
The AP is joining a primed WLC
The APs broadcast traffic is unable to reach the WLC through Layer 2
Refer to the exhibit. What does the snippet of code achieve?
It creates an SSH connection using the SSH key that is stored, and the password is ignored
It opens an ncclient connection to a Cisco Nexus device and maintains it for the duration of the context
It opens a tunnel and encapsulates the login information, if the host key is correct
It creates a temporary connection to a Cisco Nexus device and retrieves a token to be used for API calls
Refer to the exhibit. Which command must be applied to R2 for an OSPF neighborship to form?
network 20.0,0.2 0.0.0.3 area 0
network 20.1.1.2 0.0.0.0 area 0
network 20.1.1.0 0.0.0.0 area 0
network 20.0.0.2 0.0.0.0 area 0
In which two ways does TCAM differ from CAM? (Choose two.)
CAM is used by routers for IP address lookups, and TCAM is used to make Layer 2 forwarding decisions
CAM is used for software switching mechanisms, and TCAM is used for hardware switching mechanisms
The MAC address table is contained in CAM, and ACL and QOS information is stored in TCAM
CAM is used to make Layer 2 forwarding decisions, and TCAM is used for Layer 3 address lookups
The MAC address table is contained in TCAM, and ACL and QoS information is stored in CAM
An engineer is configuring a new SSID to present users with a splash page for authentication. Which WLAN Layer 3 setting must be configured to provide this functionality?
Local Policy
Web Policy
WPA2 Policy
CCKM
An engineer must configure a new WLAN that supports 802.11r and requires users to enter a passphrase. What must be configured to support this requirement?
FT PSK and SUITEB-1X
802.1X and SUITEB-1X
802.1X and Fast Transition
FT PSK and Fast Transition
Under which network conditions is an outbound QoS policy that is applied on a router WAN interface most beneficial?
under interface saturation conditions
under all network conditions
under traffic classification and marking conditions
under network convergence conditions
Refer to the exhibit. An engineer configures a new WLAN that will be used for secure communications; however, wireless clients report that they are able to communicate with each other. Which action resolves this issue?
Disable Aironet IE
Enable P2P Blocking
Enable Client Exclusions
Enable Wi-Fi Direct Client Policy
Refer to the exhibit. What is achieved by the XML code?
It adds the value of c1 to each of the access list statement sequence numbers
It configures an access list statement using the value of c1 as the sequence number that denies host c2 from reaching any destination
It adds statements to an access list by increasing each sequence number by the value of c1 until all hosts in the c2 list are included
It configures an access list statement that denies all hosts from reaching c2
A customer has two Cisco WLCs that manage separate APs throughout a building. Each WLC advertises the same SSID but terminates on different interfaces. Users report that they drop their connections and change IP addresses when roaming. Which action resolves this issue?
Enable client load balancing
Configure mobility groups
Enable fast roaming
Configure high availability
What is the function of a fabric border node in a Cisco SD-Access environment?
To collect traffic flow information toward external networks
To attach and register clients to the fabric
To connect the Cisco SD-Access fabric to another fabric or external Layer 3 networks
To handle an ordered list of IP addresses and locations for endpoints in the fabric
What does the LAP send when multiple WLCs respond to the CISCO-CAPWAP-CONTROLLER.localdomain hostname during the CAPWAP discovery and join process?
join request to all the WLCs
unicast discovery request to the first WLC that resolves the domain name
unicast discovery request to each WLC
multicast discovery Request
Refer to the exhibit. How should the script be completed so that each device configuration is saved into a JSON-formatted file under the device name?
Insert after the for loop:
with open(f"(Hostname}.json", "w") as OutFile:
OutFile.write(Response)
Insert immediately before the for loop
with open(f" (Hostname}.json", "w") as OutFile:
OutFile.write(json.load(Devices))
Append to the body of the for loop:
with open(f" {Hostname).json", "w") as OutFile:
OutFile.write(Response.text)
Insert after the for loop:
with open(f"(Hostname}.json", "w") as OutFile
OutFile.write(json.dumps(Response.text))
Refer to the exhibit. Running the script causes the output in the exhibit. What should be the first line of the script?
ncclient manager import
from ncclient import manager
from ncclient import *
import manager
Which device, in a LISP routing architecture, receives and de-encapsulates LISP traffic for endpoints within a LISP-capable site?
ETR
MR
MS
ITR
Refer to the exhibit. A customer asks an engineer to create a new secure WLAN to support only WPA3. Users must connect using a passphrase. Which encryption and key management configuration is required?
CCMP128 encryption with SAE key management
GCMP128 encryption with OWE key management
GCMP256 encryption with 802.1x key management
CCMP256 encryption with CCKM key management
An engineer must use IP SLA to measure the network performance and record statistics hop-by-hop. Which configuration must be used?
ip sla 1
path-echo 10.1.1.1
ip sla 1
echo 10.1.1.1-
historybuckets-kept 30
ip sla 1
icmp-echo 10.1.1.1
historybuckets-kept 30
ip sla 1
ip sla responder,
path-jitter 10.1.1.1
Which QoS component is used to share specific information about traffic to a downstream network device?
Shaping
Marking
Classification
Prioritization
Refer to the exhibit. An engineer must adjust the configuration so that Router A becomes the active router. Which two commands should be applied to Router A? (Choose two.)
vrrp 1 ip 10.1.0.11
vrrp 1 priority 120
ip address 10.1.0.11 255.0.0.0
vrrp 1 timers advertise 1
vrrp 1 priority 90
What is a benefit of a virtual machine when compared with a physical server?
Deploying a virtual machine is technically less complex than deploying a physical server
Multiple virtual servers can be deployed on the same physical server without having to buy additional hardware
Virtual machines increase server processing performance
The CPU and RAM resources on a virtual machine cannot be affected by other virtual machines
Refer to the exhibit. An engineer is investigating why guest users are able to access other guest user devices when the users are connected to the customer guest WLAN. What action resolves this issue?
implement Wi-Fi direct policy
implement MFP client protection
implement P2P blocking
implement split tunneling
What are two benefits of using Cisco TrustSec? (Choose two.)
advanced endpoint protection against malware
unknown file analysis using sandboxing
end-to-end traffic encryption
consistent network segmentation
simplified management of network Access
A company requires a wireless solution to support its main office and multiple branch locations. All sites have local Internet connections and a link to the main office for corporate connectivity. The branch offices are managed centrally. Which solution should the company choose?
Cisco Mobility Express
Cisco Unified Wireless Network
Cisco Catalyst switch with embedded controller
Cisco DNA Spaces
A network monitoring system uses SNMP polling to record the statistics of router interfaces. The SNMP queries work as expected until an engineer installs a new interface and reloads the router. After this action, all SNMP queries for the router fail. What is the cause of this issue?
The SNMP server traps are disabled for the link state
The SNMP server traps are disabled for the interface index
The SNMP interface index changed after reboot
The SNMP community is configured incorrectly
Which tool is used in Cisco DNA Center to build generic configurations that are able to be applied on devices with similar network settings?
Command Runner
Template Editor
Authentication Template
Application Policies
What is one difference between the RIB and the FIB?
The RIB keeps all routing information received from peers, and the FIB keeps the minimum information necessary to make a forwarding decision
The RIB works at the data plane, and the FIB works at the control plane
The RIB is known as the CEF table, and the FIB is known as the routing table
The FIB contains routing prefixes, and the RIB contains the Layer 2 and Layer 3 information necessary to make a forwarding decision
A network administrator is preparing a Python script to configure a Cisco IOS XE-based device on the network. The administrator is worried that colleagues will make changes to the device while the script is running. Which operation of the ncclient manager prevents colleagues from making changes to the devices while the script is running?
m.freeze(target='running'),
m.lock(config='running)'
m.freeze(config='running)
m.lock(target='running')
What are multicast RPs required?
RPs are required for protocol independent multicast sparse mode and dense mode
By default, the RP is needed only to start new sessions with sources and receivers
By default the RP is needed periodically to maintain sessions with sources and receivers
RPs are required only when using protocol independent multicast dense mode
Which port is required to allow APs to join a WLC when directed broadcasts are used on a Cisco IOS switch?
UDP 5247
TCP 5246
UDP 5246
TCP 5247
Refer to the exhibit. Which configuration enables password checking on the console line, using only a password?
router(config)# line con 0
router(config-line)# login
router (config)# line con 0
router (config-line)# exec-timeout 0 0
router(config)# line vty 0 4
router(config-line)# login
router(config)# line con 0
router(config-line)# login local
Which protocol is used to encrypt control plane traffic between SD-WAN controllers and SD-WAN endpoints?
DTLS
HTTPS
IPsec
PGP
1. Refer to the exhibit. An engineer attempts to use RESTCONF to configure GigabitEthenet2 on a remote router with IP address 192.168.159.10 but the configuration fails. Which configuration is required to complete the action?
response = requests.patch(
url = 'https://192.168.159.10/restconf/data/Cisco-IOS-XE-native: native/interface/GigabitEthernet2',
data = json dumps(l
'Cisco-IOS-XE-native: GigabitEthernet': {
ip': {
'address': {
interface': {
data = json.dumps(f
'Cisco-IOS-XE-native: GigabitEthernet2':{
Which technology enables a redundant supervisor engine to take over when the primary supervisor engine fails?
NSF
FHRP
graceful restart
SSO
When should the MAC authentication bypass feature be used on a switch port?
when authentication is required, but the attached host does not support 802.1X
when the attached host supports 802, 1X and must authenticate itself based on its MAC address instead of user credentials
when authentication should be bypassed for select hosts based on their MAC address
when the attached host supports limited 802.1X
Which action occurs during a Layer 3 roam?
Client traffic is tunneled back to the original controller after a Layer 3 roam occurs
The client receives a new IP address after authentication occurs
The client database entry is moved from the old controller to the new controller
The client is marked as "Foreign" on the original controller
Refer to the exhibit. Which two configurations enable R1 and R2 to advertise routes into OSPF? (Choose two.)
R2
router ospf 0
network 172.16.1.0 255.255.255.0 area 0
network 172.16.2.0 255.255.255.0 area 0
R2
router ospf 0
network 172.16.1.0 0.0.0.255 area 0
network 172. 16.2.0 0.0.0.255 area 0
R1
router ospf 0
network 192.168.1.0 0.0.0.255 area 0
network 192.168.2.0 0.0.0.255 area 0
R1
router ospf 0
network 192.168.1.0 255.255.255.0 area 0
network 192.168.2.0 255.255.255.0 area 0
R2
router ospf 0
network 172.16.1.0 0.0.0.255 area 0
network 172.16.2.0 255.255.255.0 area 0
In a wireless network environment what is calculated usina the numerical values of the transmitter nower level cable loss and antenna gaain?
EIRP
dBi
RSSI
SNR
Refer to the exhibit. Which router is the designated router on the segment 192.168.0.0/24?
Router Chicago because it has a lower router ID
This segment has no designated router because it is a p2p network type
Router NewYork because it has a higher router ID
This segment has no designated router because it is a nonbroadcast network type
Where is radio resource management performed in a cisco SD-access wireless solution?
wireless controller
Cisco CMX
DNA Center
control plane node
Refer to the exhibit. POSTMAN is showing an attempt to retrieve network device information from Cisco DNA Center API. What is the issue?
The URI string is incorrect
The token has expired
The JSON payload contains the incorrect UUID
Authentication has failed
Which two characteristics define the Intent API provided by Cisco DNA Center? (Choose two.)
northbound APl
procedural
device-oriented
business outcome oriented
southbound API
Refer to the exhibit.A network engineer configures OSPF and reviews the router configuration. Which interface or interfaces are able to establish OSPF adjacency?
only GigabitEthernet0/1
GigabitEthernet0/1 and GigabitEthernet0/1.40
GigabitEthernet0/0 and GigabitEthernet0/1
only GigabitEthernet0/0
How does SSO work with HSRP to minimize network disruptions?
It ensures fast failover in the case of link failure
It enables HSRP to elect another switch in the group as the active HSRP switch
It enables HSRP to failover to the standby RP on the same device
It enables data forwarding along known routes following a switchover, while the routing protocol reconverges
Refer to the exhibit. Which IP address becomes the active next hop for 192.168.102.0/24 when 192.168.101.2 fails?
192.168.101.6
192.168.101.10
192.168.101.14
192.168.101.18
Refer to the exhibit. Marketing users that are connected to Switch A are not able to communicate with Marketing users that are connected to Switch B. Which action will resolve the issue?
Configure the EtherChannel on Switch B to LACP
Configure the EtherChannel on Switch A to desirable mode
Configure the EtherChannel on Switch A to passive mode
Configure the EtherChannel on Switch B to active mode
Which configuration allows administrators to configure the device through the console port and use a network authentication server?
aaa new-model
aaa authentication login default group radius
aaa authorization console
aaa authorization config-commands
aaa new-model
aaa authentication login default line
aaa new-model
aaa authentication login default local
aaa authorization console
aaa authorization config-commands
aaa new-model
aaa authentication login default local
aaa authorization console
aaa authorization config-commands
username netadmin secret 9 1234567890
Refer to the exhibit. An engineer configured TACACS + to authenticate remote users, but the configuration is not working as expected. Which configuration must be applied to enable access?
R1(config)#tacacs server prod
R1 (config-server-tacacs)#port 1020
R1(config)#aaa authorization exec default group tacacs+ local
R1 (config)#ip tacacs source-interface Gig 0/0
R1 (config)#tacacs server prod
R1 (config-server-tacacs)#key cisco123
Which protocol is implemented to establish secure control plane adjacencies between Cisco SD-WAN nodes?
ESP
IKE
TLS
IPsec
What is a characteristic of MACsec?
802.1AE is negotiated using Cisco AnyConnect NAM and the SAP protocol
802.1AE is bult between the host and switch using the MKA protocol using keys generated via the Diffie-Hellman algorithm (anonymous encryption mode)
802.1AE provides encryption and authentication services
802.1AE is bult between the host and switch using the MKA protocol, which negotiates encryption keys based on the master session key from a successful 802.1X session
What is the process for moving a virtual machine from one host machine to another with no downtime?
live migration
high availability
multisite replication
disaster recovery
What is an advantage of utilizing data models in a multivendor environment?
Improving communication security with binary-encoded protocols
removing the distinction between configuration and runtime state data
lowering CPU load incurred to managed devices
facilitating a unified approach to configuration and management
Which command set configures RSPAN to capture outgoing traffic from from VLAN 3 on interface GigabitEthernet 0/3 while ignoring other VLAN traffic on the same interface?
monitor session 2 source interface gigabitethernet0/3 tx
monitor session 2 filter vlan 3
monitor session 2 source interface gigabitethernet0/3 rx
monitor session 2 filter vlan 1 - 2, 4 - 4094
monitor session 2 source interface gigabitethernet0/3 rx
monitor session 2 filter vlan 3
monitor session 2 source interface gigabitethernet0/3 tx
monitor session 2 filter vlan 1 - 2, 4 – 4094
What is the recommended minimum SNR for data applications on wireless networks?
20
10
25
15
How can an engineer prevent basic replay attacks from people who try to brute force a system via REST API?
Add a timestamp to the request in the API header
Use HTTPS
Add Auth to the request in the API header
Use a password hash
High bandwidth utilization is occurring on interface Gig0/1 of a router. An engineer must identify the flows that are consuming the most bandwidth. Cisco DNA Center is used as a flow exporter and is configured with the IP address 192.168.23.1 and UDP port 23000. Which configuration must be applied to set NetFlow data export and capture on the router?
R1 (config)#ip flow-export
R1 (config) # ip flow-export destination 192.168.23.1
R1 (config)# interface Gig0/1
R1 (contig-if)# collect counter bytes
R1 (config-if)# collect counter packets
R1 (config)# ip flow-export
R1(config)# ip flow-export destination 192.168.23.1 23000
R1(config)# interface Gig0/1
R1 (config-if)# ip flow monitor
R1 (config)# ip flow-export version 9
R1(config)# ip flow-export destination 192.168.23.1 23000
R1 (config)# interface Gig0/1
R1 (config-if)# ip flow ingress
R1 (config-if)# ip flow egress
R1(config)# ip flow-export version 9
R1 (config# ip flow export destination, 192. 168. 23.1.23000
R1(config)# interface Gig0/1
R1 (config-if)# ip flow-top-talkers
Refer to the exhibit. Which result does the Python code achieve?
The code converts time to the "year/month/day" time format
The code converts time to the Epoch LINUX time format
The code encrypts a base64 decrypted password
The code converts time to the yyyymmdd representation
Which mechanism can be used to enforce network access authentication against an AAA server if the endpoint does not support the 802.1X supplicant functionality?
MACsec
private VLANS
WebAuth
port security
Which method displays text directly into the active console with a synchronous EEM applet policy?
event manager applet boom
event syslog pattern 'UP'
action 1.0 puts ‘logging directly to console’
event manager applet boom
event syslog pattern 'UP'
action 1.0 string 'logging directly to console’
event manager applet boom
event syslog pattern 'UP'
action 1.0 gets 'logging directly to console'
event manager applet boom
event syslog pattern 'UP"
action 1.0 syslog priority direct msg "logging directly to console'
Refer to the exhibit. What is printed to the console when this script is run?
an error
a key-value pair in string type
a key-value pair in tuple type
a key-value pair in list type
In a Cisco DNA Center Plug and Play environment, why would a device be labeled unclaimed?
The device could not be added to the fabric
The device is from a third-party vendor
The device has not been assigned a workflow
The device had an error and could not be provisioned
