Font size
WorksheetsCCNA 2 final exam part 3
Total questions: 54
Worksheet time: 30mins
Refer to the exhibit. R1 was configured with the static route command ip route 209.165.200.224 255.255.255.224 S0/0/0 and consequently users on network 172.16.0.0/16 are unable to reach resources on the Internet. How should this static route be changed to allow user traffic from the LAN to reach the Internet?
Add an administrative distance of 254.
Change the destination network and mask to 0.0.0.0 0.0.0.0
Change the exit interface to S0/0/1.
Add the next-hop neighbor address of 209.165.200.226.
Refer to the exhibit. Which static route command can be entered on R1 to forward traffic to the LAN connected to R2?
ipv6 route 2001:db8:12:10::/64 S0/0/0
ipv6 route 2001:db8:12:10::/64 S0/0/1 fe80::2
ipv6 route 2001:db8:12:10::/64 S0/0/0 fe80::2
ipv6 route 2001:db8:12:10::/64 S0/0/1 2001:db8:12:10::1
Which option shows a correctly configured IPv4 default static route?
ip route 0.0.0.0 255.255.255.0 S0/0/0
ip route 0.0.0.0 0.0.0.0 S0/0/0
ip route 0.0.0.0 255.255.255.255 S0/0/0
ip route 0.0.0.0 255.0.0.0 S0/0/0
Refer to the exhibit. A network administrator is configuring a router as a DHCPv6 server. The administrator issues a show ipv6 dhcp pool command to verify the configuration. Which statement explains the reason that the number of active clients is 0?
The default gateway address is not provided in the pool.
No clients have communicated with the DHCPv6 server yet.
The IPv6 DHCP pool configuration has no IPv6 address range specified.
The state is not maintained by the DHCPv6 server under stateless DHCPv6 operation.
Refer to the exhibit. A network administrator configured routers R1 and R2 as part of HSRP group 1. After the routers have been reloaded, a user on Host1 complained of lack of connectivity to the Internet The network administrator issued the show standby brief command on both routers to verify the HSRP operations. In addition, the administrator observed the ARP table on Host1. Which entry should be seen in the ARP table on Host1 in order to gain connectivity to the Internet?
the virtual IP address and the virtual MAC address for the HSRP group 1
the virtual IP address of the HSRP group 1 and the MAC address of R1
the virtual IP address of the HSRP group 1 and the MAC address of R2
the IP address and the MAC address of R1
Which statement is correct about how a Layer 2 switch determines how to forward frames?
Frame forwarding decisions are based on MAC address and port mappings in the CAM table.
Only frames with a broadcast destination address are forwarded out all active switch ports.
Unicast frames are always forwarded regardless of the destination MAC address.
Cut-through frame forwarding ensures that invalid frames are always dropped.
Refer to the exhibit. In addition to static routes directing traffic to networks 10.10.0.0/16 and 10.20.0.0/16, Router HQ is also configured with the following command:
ip route 0.0.0.0 0.0.0.0 serial 0/1/1
|What is the purpose of this command?
Packets that are received from the Internet will be forwarded to one of the LANs connected to R1 or R2.
Packets with a destination network that is not 10.10.0.0/16 or is not 10.20.0.0/16 or is not a directly connected network will be forwarded to the Internet.
Packets from the 10.10.0.0/16 network will be forwarded to network 10.20.0.0/16, and packets from the 10.20.0.0/16 network will be forwarded to network 10.10.0.0/16.
Packets that are destined for networks that are not in the routing table of HQ will be dropped.
What protocol or technology disables redundant paths to eliminate Layer 2 loops?
VTP
STP
DTP
EtherChannel
Which two VTP modes allow for the creation, modification, and deletion of VLANs on the local switch? (Choose two.)
client
distribution
slave
server
transparent
Refer to the exhibit. Based on the exhibited configuration and output, why is VLAN 99 missing?
because VLAN 99 is not a valid management VLAN
because there is a cabling problem on VLAN 99
because VLAN 1 is up and there can only be one management VLAN on the switch
because VLAN 99 has not yet been created
Which three steps should be taken before moving a Cisco switch to a new VTP management domain? (Choose three.)
Configure the switch with the name of the new management domain.
Reset the VTP counters to allow the switch to synchronize with the other switches in the domain.
Download the VTP database from the VTP server in the new domain.
Select the correct VTP mode and version.
Reboot the switch.
A network administrator is preparing the implementation of Rapid PVST+ on a production network. How are the Rapid PVST+ link types determined on the switch interfaces?
Link types can only be configured on access ports configured with a single VLAN.
Link types can only be determined if PortFast has been configured.
Link types are determined automatically.
Link types must be configured with specific port configuration commands.
Refer to the exhibit. All the displayed switches are Cisco 2960 switches with the same default priority and operating at the same bandwidth. Which three ports will be STP designated ports? (Choose three.)
fa0/9
fa0/13
fa0/10
fa0/20
fa0/21
A network administrator is adding a new WLAN on a Cisco 3500 series WLC. Which tab should the administrator use to create a new VLAN interface to be used for the new WLAN?
CONTROLLER
WLANs
MANAGEMENT
WIRELESS
Which two functions are performed by a WLC when using split media access control (MAC)? (Choose two.)
association and re-association of roaming clients
frame translation to other protocols
frame queuing and packet prioritization
beacons and probe responses
packet acknowledgments and retransmissions
Why is DHCP snooping required when using the Dynamic ARP Inspection feature?
It relies on the settings of trusted and untrusted ports set by DHCP snooping.
It uses the MAC-address-to-IP-address binding database to validate an ARP packet.
It redirects ARP requests to the DHCP server for verification.
It uses the MAC address table to verify the default gateway IP address.
A network administrator is configuring a new Cisco switch for remote management access. Which three items must be configured on the switch for the task? (Choose three.)
default VLAN
vty lines
default gateway
IP address
A technician is troubleshooting a slow WLAN and decides to use the split-the-traffic approach. Which two parameters would have to be configured to do this? (Choose two.)
Configure the 5 GHz band for streaming multimedia and time sensitive traffic.
Configure the security mode to WPA Personal TKIP/AES for one network and WPA2 Personal AES for the other network
Configure the 2.4 GHz band for basic internet traffic that is not time sensitive.
MAN IM SO LAZY
Which information does a switch use to populate the MAC address table?
the destination MAC address and the incoming port
the source MAC address and the incoming port
the source and destination MAC addresses and the outgoing port
the destination MAC address and the outgoing port
The exhibit shows two PCs called PC A and PC B, two routes called R1 and R2, and two switches. PC A has the address 172.16.1.1/24 and is connected to a switch and into an interface on R1 that has the IP address 172.16.1.254. PC B has the address 172.16.2.1/24 and is connected to a switch that is connected to another interface on R1 with the IP address 172.16.2.254. The serial interface on R1 has the address 172.16.3.1 and is connected to the serial interface on R2 that has the address 172.16.3.2/24. R2 is connected to the internet cloud. Which command will create a static route on R2 in order to reach PC B?
R2(config)# ip route 172.16.2.0 255.255.255.0 172.16.3.1
R2(config)# ip route 172.16.3.0 255.255.255.0 172.16.2.254
R2(config)# ip route 172.16.2.0 255.255.255.0 172.16.2.254
R2(config)# ip route 172.16.2.1 255.255.255.0 172.16.3.1
Refer to the exhibit. Which three hosts will receive ARP requests from host A, assuming that port Fa0/4 on both switches is configured to carry traffic for multiple VLANs? (Choose three.)
host B
host F
host D
host C
What would be the primary reason an attacker would launch a MAC address overflow attack?
so that the attacker can see frames that are destined for other hosts
so that the attacker can execute arbitrary code on the switch
so that legitimate hosts cannot obtain a MAC address
so that the switch stops forwarding traffic
Which three Wi-Fi standards operate in the 2.4GHz range of frequencies? (Choose three.)
802.11n
802.11ac
802.11b
802.11g
802.11a
Which method of IPv6 prefix assignment relies on the prefix contained in RA messages?
EUI-64
stateful DHCPv6
SLAAC
static
A network administrator is configuring a WLAN. Why would the administrator disable the broadcast feature for the SSID?
to eliminate outsiders scanning for available SSIDs in the area
to provide privacy and integrity to wireless traffic by using encryption
to reduce the risk of unauthorized APs being added to the network
to reduce the risk of interference by external devices such as microwave ovens
What protocol or technology defines a group of routers, one of them defined as active and another one as standby?
HSRP
DTP
EtherChannel
VTP
A technician is configuring a router for a small company with multiple WLANs and doesn’t need the complexity of a dynamic routing protocol. What should be done or checked?
Create static routes to all internal networks and a default route to the internet.
Check the statistics on the default route for oversaturation.
Create extra static routes to the same location with an AD of 1.
Verify that there is not a default route in any of the edge router routing tables.
What mitigation plan is best for thwarting a DoS attack that is creating a MAC address table overflow?
Disable DTP.
Place unused ports in an unused VLAN.
Enable port security.
Disable STP.
A network engineer is troubleshooting a newly deployed wireless network that is using the latest 802.11 standards. When users access high bandwidth services such as streaming video, the wireless network performance is poor. To improve performance the network engineer decides to configure a 5 Ghz frequency band SSID and train users to use that SSID for streaming media services. Why might this solution improve the wireless network performance for that type of service?
The 5 GHz band has more channels and is less crowded than the 2.4 GHz band, which makes it more suited to streaming multimedia.
The only users that can switch to the 5 GHz band will be those with the latest wireless NICs, which will reduce usage.
The 5 GHz band has a greater range and is therefore likely to be interference-free.
Requiring the users to switch to the 5 GHz band for streaming media is inconvenient and will result in fewer users accessing these services.
Which protocol adds security to remote connections?
SSH
POP
HTTP
NetBEUI
Refer to the exhibit. A network administrator is configuring inter-VLAN routing on a network. For now, only one VLAN is being used, but more will be added soon. What is the missing parameter that is shown as the highlighted question mark in the graphic?
It identifies the VLAN number.
It identifies the type of encapsulation that is used.
It identifies the native VLAN number.
It identifies the subinterface
Refer to the exhibit. A network administrator has added a new subnet to the network and needs hosts on that subnet to receive IPv4 addresses from the DHCPv4 server.
What two commands will allow hosts on the new subnet to receive addresses from the DHCP4 server? (Choose two.)
R1(config-if)# ip helper-address 10.2.0.250
R2(config-if)# ip helper-address 10.2.0.250
R1(config)# interface G0/1
R1(config)# interface G0/0
What protocol or technology requires switches to be in server mode or client mode?
EtherChannel
STP
VTP
DTP
What are three techniques for mitigating VLAN attacks? (Choose three.)
Enable trunking manually
Disable DTP.
Enable Source Guard.
Set the native VLAN to an unused VLAN
What action does a DHCPv4 client take if it receives more than one DHCPOFFER from multiple DHCP servers?
It sends a DHCPREQUEST that identifies which lease offer the client is accepting.
It sends a DHCPNAK and begins the DHCP process over again.
It accepts both DHCPOFFER messages and sends a DHCPACK.
It discards both offers and sends a new DHCPDISCOVER.
Refer to the exhibit. Which two conclusions can be drawn from the output? (Choose two.)
The EtherChannel is down.
The port channel ID is 2.
The port channel is a Layer 3 channel.
The bundle is fully operational.
On a Cisco 3504 WLC Summary page ( Advanced > Summary ), which tab allows a network administrator to configure a particular WLAN with a WPA2 policy?
WLANs
SECURITY
WIRELESS
MANAGEMENT
What action takes place when the source MAC address of a frame entering a switch appears in the MAC address table associated with a different port?
The switch replaces the old entry and uses the more current port.
The switch forwards the frame out of the specified port.
The switch updates the refresh timer for the entry.
The switch purges the entire MAC address table.
Refer to the exhibit. A network administrator configures R1 for inter-VLAN routing between VLAN 10 and VLAN 20. However, the devices in VLAN 10 and VLAN 20 cannot communicate. Based on the configuration in the exhibit, what is a possible cause for the problem?
The port Gi0/0 should be configured as trunk port.
The encapsulation is misconfigured on a subinterface.
A no shutdown command should be added in each subinterface configuration.
The command interface gigabitEthernet 0/0.1 is wrong.
A network administrator uses the spanning-tree portfast bpduguard default global configuration command to enable BPDU guard on a switch. However, BPDU guard is not activated on all access ports. What is the cause of the issue?
BPDU guard needs to be activated in the interface configuration command mode.
Access ports configured with root guard cannot be configured with BPDU guard.
Access ports belong to different VLANs.
PortFast is not configured on all access ports.
Employees are unable to connect to servers on one of the internal networks. What should be done or checked?
Use the “show ip interface brief” command to see if an interface is down.
Verify that there is not a default route in any of the edge router routing tables.
Check the statistics on the default route for oversaturation.
Create static routes to all internal networks and a default route to the internet.
What is the effect of entering the ip dhcp snooping configuration command on a switch?
It enables DHCP snooping globally on a switch.
It enables PortFast globally on a switch.
It manually enables a trunk link.
It disables DTP negotiations on trunking ports.
What is the effect of entering the switchport port-security configuration command on a switch?
It dynamically learns the L2 address and copies it to the running configuration.
It enables port security on an interface.
It enables port security globally on the switch.
It restricts the number of discovery messages, per second, to be received on the interface.
Refer to the exhibit. PC-A and PC-B are both in VLAN 60. PC-A is unable to communicate with PC-B. What is the problem?
The VLAN that is used by PC-A is not in the list of allowed VLANs on the trunk.
The native VLAN should be VLAN 60.
The native VLAN is being pruned from the link.
The trunk has been configured with the switchport nonegotiate command.
What is the effect of entering the switchport mode access configuration command on a switch?
It enables BPDU guard on a specific port.
It manually enables a trunk link.
It disables an unused port.
It disables DTP on a non-trunking interface.
What is the effect of entering the ip arp inspection vlan 10 configuration command on a switch?
It enables DAI on specific switch interfaces previously configured with DHCP snooping.
It specifies the maximum number of L2 addresses allowed on a port.
It enables DHCP snooping globally on a switch.
It globally enables BPDU guard on all PortFast-enabled ports.
It globally enables BPDU guard on all PortFast-enabled ports.
What protocol or technology manages trunk negotiations between switches?
VTP
EtherChannel
DTP
STP
A network administrator is configuring a WLAN. Why would the administrator change the default DHCP IPv4 addresses on an AP?
to eliminate outsiders scanning for available SSIDs in the area
to reduce the risk of unauthorized APs being added to the network
to reduce outsiders intercepting data or accessing the wireless network by using a well-known address range
to reduce the risk of interference by external devices such as microwave ovens
What protocol or technology is a Cisco proprietary protocol that is automatically enabled on 2960 switches?
DTP
STP
VTP
EtherChannel
What are two characteristics of Cisco Express Forwarding (CEF)? (Choose two.)
When a packet arrives on a router interface, it is forwarded to the control plane where the CPU matches the destination address with a matching routing table entry.
This is the fastest forwarding mechanism on Cisco routers and multilayer switches.
Packets are forwarded based on information in the FIB and an adjacency table.
With this switching method, flow information for a packet is stored in the fast-switching cache to forward future packets to the same destination without CPU intervention
What is the effect of entering the show ip dhcp snooping binding configuration command on a switch?
It switches a trunk port to access mode.
It restricts the number of discovery messages, per second, to be received on the interface.
It displays the IP-to-MAC address associations for switch interfaces.
It checks the source L2 address in the Ethernet header against the sender L2 address in the ARP body.
A small publishing company has a network design such that when a broadcast is sent on the LAN, 200 devices receive the transmitted broadcast. How can the network administrator reduce the number of devices that receive broadcast traffic?
Add more switches so that fewer devices are on a particular switch.
Replace the switches with switches that have more ports per switch. This will allow more devices on a particular switch.
Segment the LAN into smaller LANs and route between them.*
Replace at least half of the switches with hubs to reduce the size of the broadcast domain.
Segment the LAN into smaller LANs and route between them.*
Replace the switches with switches that have more ports per switch. This will allow more devices on a particular switch.
What else is required when configuring an IPv6 static route using a next-hop link-local address?
administrative distance
ip address of the neighbor router
network number and subnet mask on the interface of the neighbor router
interface number and type
A PC has sent an RS message to an IPv6 router attached to the same network. Which two pieces of information will the router send to the client? (Choose two.)
prefix length
subnet mask in dotted
decimal notation
prefix
