WorksheetsPlatonus test
Total questions: 60
Worksheet time: 30mins
Which address does a DHCPv4 server target when sending a DHCPOFFER message to a client that makes an address request?
Client hardware address
Broadcast MAC address
Client IP address
Gateway IP address
What command is used to view port security information for all interfaces?
show running-config
show interface
show mac address-table
show port-security
Which feature immediately places a port into the forwarding state?
PortFast
BPDU Guard
DAI
VLAN Trunking
Where are dynamically learned MAC addresses stored when sticky learning is enabled with the switchport port-security mac-address sticky comman
Flash
ROM
boot
RAM
A network administrator is configuring DAI on a switch with the command ip arp inspection validate dst-mac. What is the purpose of this configuration command?
To check the destination MAC address in the Ethernet header against the user-configured ARP ACLs
To check the destination MAC address in the Ethernet header against the target MAC address in the ARP body
To check the destination MAC address in the Ethernet header against the source MAC address in the ARP body
To check the destination MAC address in the Ethernet header against the MAC address table
On what switch ports should PortFast be enabled to enhance STP stability?
All trunk ports that are not root ports
Only ports that are elected as designated ports
Only ports that attach to a neighboring switch
All end-user ports
Which command is recommended to secure unused switch ports?
no shutdown
ip dhcp snooping
shutdown
switchport port-security
What is an advantage of using dynamic routing protocols instead of static routing?
fewer router resource overhead requirements
more secure in controlling routing updates
ability to actively search for new routes if the current path becomes unavailable
easier to implement
Which security feature should be enabled in order to prevent an attacker from overflowing the MAC address table of a switch?
BPDU filter
Port security
Storm control
Root guard
Which command displays the overall status of the aggregated channel interface?
show interfaces port-channel
show etherchannel port-channel
show vlan
show interfaces
Where are dynamically learned sticky MAC addresses stored while the switch is running?
all is correct answers
ROM
RAM
Flash
What is a characteristic of a floating static route?
It is simply a static route with 0.0.0.0/0 as the destination IPv4 address.
When it is configured, it creates a gateway of last resort.
It is used to provide load balancing between static routes.
It is configured with a higher administrative distance than the original dynamic routing protocol has.
Which statement describes the characteristics of EtherChannel?
It can combine mixed Ethernet speeds of 100 Mbps and 1 Gbps.
It combines multiple physical links into one logical link between two switches.
It consists of several parallel links between a switch and a router.
It can combine up to four physical links.
What is a recommended best practice when dealing with the native VLAN?
Assign the same VLAN number as the management VLAN.
Turn off DTP.
Assign it to an unused VLAN.
Use port security.
What Layer 2 attack is mitigated by disabling Dynamic Trunking Protocol?
ARP poisoning
ARP spoofing
VLAN hopping
DHCP spoofing
Which type of VLAN-hopping attack may be prevented by designating an unused VLAN as the native VLAN?
DHCP starvation
VLAN double-tagging
DTP spoofing
DHCP spoofing
Which protocol should be used to mitigate the vulnerability of using Telnet to remotely manage network devices?
SNMP
SCP
TFTP
SSH
Which Layer 2 attack will result in legitimate users not getting valid IP addresses?
DHCP starvation
ARP spoofing
IP address spoofing
MAC address flooding
Which mode must be configured on an interface before enabling port security?
switchport mode dynamic desirable
switchport mode access
switchport mode trunk
switchport mode dynamic auto
If more than one DHCP server is available on the local network, in which order will DHCP messages be sent between a host and a DHCP server?
Request, acknowledgment, discover, offer
Discover, offer, request, acknowledgment
Request, discover, offer, acknowledgment
Acknowledgment, request, offer, discover
What mitigation plan is best for thwarting a DoS attack that is creating a MAC address table overflow?
Enable port security.
Disable STP.
Place unused ports in an unused VLAN.
Disable DTP.
What is the default port-security maximum number of MAC addresses on a port?
8192
1
2
4
Which type of wireless network often makes use of devices mounted on buildings?
wireless metropolitan-area network
wireless local-area network
wireless personal-area network
wireless wide-area network
A network administrator is configuring DHCP snooping on a switch. Which configuration command should be used first?
ip dhcp snooping trust
ip dhcp snooping
ip dhcp snooping vlan
ip dhcp snooping limit rate
Which procedure is recommended to mitigate the chances of ARP spoofing?
Enable port security globally.
Enable DAI on the management VLAN.
Enable IP Source Guard on trusted ports.
Enable DHCP snooping on selected VLANs.
Which type of wireless network is suitable for use in a home or office?
wireless personal-area network
wireless metropolitan-area network
wireless local-area network
wireless wide-area network
Which type of wireless network uses transmitters to cover a medium-sized network, usually up to 300 feet (91.4 meters)?
wireless local-area network
wireless metropolitan-area network
wireless personal-area network
wireless wide-area network
A network administrator has configured an EtherChannel with three interfaces between two switches. What happens if one of the three interfaces fails?
The EtherChannel fails.
The remaining two interfaces become separate links between switches.
The remaining two interfaces continue to share traffic load.
One interface becomes active and another becomes standby.
An IT security specialist enables port security on a switch port of a Cisco switch. What is the default violation mode in use until the switch port is configured to use a different violation mode?
disabled
shutdown
protect
restrict
Which access control component, implementation, or protocol controls what users can do on the network?
802.1X
authentication
authorization
accounting
Which port-security learning method saves MAC addresses to the running configuration?
sticky
dynamic
static
manual
Which command is recommended to secure unused switch ports?
ip dhcp snooping
no shutdown
switchport port-security
shutdown
Which port-security violation mode shuts the port down?
restrict
none
shutdown
protect
An IT security specialist enables port security on a switch port of a Cisco switch. What is the default violation mode in use until the switch port is configured to use a different violation mode?
restrict
disabled
protect
shutdown
A network administrator of a college is configuring the WLAN user authentication process. Wireless users are required to enter username and password credentials that will be verified by a server. Which server would provide such service?
NAT
ААА
RADIUS
SNMP
What command is used to view port security information for all interfaces?
show interface
show mac address-table
show running-config
show port-security
On what switch ports should PortFast be enabled to enhance STP stability?
Only ports that are elected as designated ports
Only ports that attach to a neighboring switch
All trunk ports that are not root ports
All end-user ports
What is a recommended best practice when dealing with the native VLAN?
Turn off DTP.
Assign the same VLAN number as the management VLAN.
Assign it to an unused VLAN.
Use port security.
A network administrator is configuring DAI on a switch. Which command should be used on the uplink interface that connects to a router?
spanning-tree portfast
ip arp inspection trust
ip dhcp snooping
ip arp inspection vlan
Which type of VLAN-hopping attack may be prevented by designating an unused VLAN as the native VLAN?
VLAN double-tagging
DHCP spoofing
DHCP starvation
DTP spoofing
Which command would be best to use on an unused switch port if a company adheres to the best practices as recommended by Cisco?
switchport port-security mac-address sticky mac-address
ip dhcp snooping
shutdown
switchport port-security mac-address sticky
Which access control component, implementation, or protocol controls what users can do on the network?
802.1X
authorization
authentication
accounting
Which feature filters DHCP messages on untrusted ports?
DAI
Port Security
DHCP Snooping
BPDU Guard
A network administrator is configuring DHCP snooping on a switch. Which configuration command should be used first?
ip dhcp snooping vlan
ip dhcp snooping trust
ip dhcp snooping
ip dhcp snooping limit rate ip dhcp snooping limit rate
Which procedure is recommended to mitigate the chances of ARP spoofing?
Enable IP Source Guard on trusted ports.
Enable DAI on the management VLAN.
Enable DHCP snooping on selected VLANs.
Enable port security globally.
Which command enables DAI on a VLAN?
ip dhcp snooping vlan
spanning-tree portfast
ip arp inspection vlan
switchport port-security
A network administrator is configuring DAI on a switch with the command ip arp inspection validate dst-mac. What is the purpose of this configuration command?
To check the destination MAC address in the Ethernet header against the user-configured ARP ACLS
To check the destination MAC address in the Ethernet header against the target MAC address in the ARP body
To check the destination MAC address in the Ethernet header against the source MAC address in the ARP body
To check the destination MAC address in the Ethernet header against the MAC address table
Where are dynamically learned sticky MAC addresses stored while the switch is running?
ROM
RAM
Flash
all is correct answers
What is the default port-security maximum number of MAC addresses on a port?
4
1
8192
2
Which component of AAA allows an administrator to track individuals who access network resources and any changes that are made to those resources?
accessibility
accounting
authorization
authentication
What feature prevents MAC address table overflow attacks?
BPDU Guard
Port security
DHCP Snooping
DAI
What attack is mitigated by disabling DTP on access ports?
DHCP starvation
ARP spoofing
STP manipulation
VLAN hopping
Which feature on a Cisco Catalyst switch can be used to mitigate DHCP spoofing attacks?
DHCP snooping
DHCP server failover
Extended ACL
Strong password on DHCP servers
What device is considered a supplicant during the 802.1X authentication process?
the authentication server that is performing client authentication
the client that is requesting authentication
the switch that is controlling network access
the router that is serving as the default gateway
What Layer 2 attack is mitigated by disabling Dynamic Trunking Protocol?
ARP spoofing
ARP poisoning
DHCP spoofing
VLAN hopping
An administrator who is troubleshooting connectivity issues on a switch notices that a switch port configured for port security is in the err-disabled state. After verifying the cause of the violation, how should the administrator re-enable the port without disrupting network operation?
Reboot the switch.
Issue the shutdown command followed by the no shutdown command on the interface.
Issue the no switchport port-security command, then re-enable port security.
Issue the no switchport port-security violation shutdown command on the interface.
What are two types of switch ports that are used on Cisco switches as part of the defense against DHCP spoofing attacks?
Unknown port and Unauthorized port
Trusted DHCP port and Untrusted port
Authorized DHCP port and Established DHCP port
Untrusted port and Unknown port
Which security feature should be enabled in order to prevent an attacker from overflowing the MAC address table of a switch?
Port security
Storm control
Root guard
BPDU filter
Which authentication method stores usernames and passwords in the router and is ideal for small networks?
local AAA over RADIUS
local AAA
server-based AAA
server-based AAA over TACACS+
What command marks an interface as trusted for DHCP Snooping?
ip dhcp snooping trust
switchport mode access
ip dhcp snooping limit rate
ip arp inspection trust
