wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Platonus test

Total questions: 60

Worksheet time: 30mins

Name
Class
Date
1.

Which address does a DHCPv4 server target when sending a DHCPOFFER message to a client that makes an address request? 

a)

Client hardware address 

b)

Broadcast MAC address 

c)

Client IP address 

d)

Gateway IP address 

2.

What command is used to view port security information for all interfaces? 

a)

 show running-config 

b)

show interface 

c)

show mac address-table 

d)

show port-security 

3.

Which feature immediately places a port into the forwarding state? 

a)

PortFast 

b)

BPDU Guard 

c)

DAI 

d)

VLAN Trunking 

4.

Where are dynamically learned MAC addresses stored when sticky learning is enabled with the switchport port-security mac-address sticky comman 

a)

Flash 

b)

ROM 

c)

boot 

d)

RAM 

5.

A network administrator is configuring DAI on a switch with the command ip arp inspection validate dst-mac. What is the purpose of this configuration command? 

a)

 To check the destination MAC address in the Ethernet header against the user-configured ARP ACLs 

b)

To check the destination MAC address in the Ethernet header against the target MAC address in the ARP body 

c)

To check the destination MAC address in the Ethernet header against the source MAC address in the ARP body 

d)

To check the destination MAC address in the Ethernet header against the MAC address table 

6.

On what switch ports should PortFast be enabled to enhance STP stability? 

a)

All trunk ports that are not root ports 

b)

Only ports that are elected as designated ports 

c)

Only ports that attach to a neighboring switch 

d)

All end-user ports 

7.

Which command is recommended to secure unused switch ports? 

a)

no shutdown 

b)

ip dhcp snooping 

c)

shutdown 

d)

switchport port-security 

8.

What is an advantage of using dynamic routing protocols instead of static routing? 

a)

fewer router resource overhead requirements 

b)

more secure in controlling routing updates 

c)

ability to actively search for new routes if the current path becomes unavailable 

d)

easier to implement 

9.

Which security feature should be enabled in order to prevent an attacker from overflowing the MAC address table of a switch? 

a)

BPDU filter 

b)

Port security 

c)

Storm control 

d)

Root guard 

10.

Which command displays the overall status of the aggregated channel interface?  

a)

show interfaces port-channel 

b)

show etherchannel port-channel 

c)

show vlan 

d)

show interfaces 

11.

Where are dynamically learned sticky MAC addresses stored while the switch is running? 

a)

all is correct answers 

b)

ROM 

c)

RAM 

d)

Flash 

12.

What is a characteristic of a floating static route? 

a)

It is simply a static route with 0.0.0.0/0 as the destination IPv4 address. 

b)

When it is configured, it creates a gateway of last resort. 

c)

It is used to provide load balancing between static routes. 

d)

It is configured with a higher administrative distance than the original dynamic routing protocol has. 

13.

Which statement describes the characteristics of EtherChannel? 

a)

It can combine mixed Ethernet speeds of 100 Mbps and 1 Gbps. 

b)

It combines multiple physical links into one logical link between two switches. 

c)

It consists of several parallel links between a switch and a router. 

d)

It can combine up to four physical links. 

14.

What is a recommended best practice when dealing with the native VLAN?  

a)

Assign the same VLAN number as the management VLAN. 

b)

Turn off DTP. 

c)

Assign it to an unused VLAN. 

d)

Use port security. 

15.

What Layer 2 attack is mitigated by disabling Dynamic Trunking Protocol? 

a)

ARP poisoning 

b)

ARP spoofing 

c)

VLAN hopping 

d)

DHCP spoofing 

16.

Which type of VLAN-hopping attack may be prevented by designating an unused VLAN as the native VLAN? 

a)

DHCP starvation 

b)

VLAN double-tagging 

c)

DTP spoofing 

d)

DHCP spoofing 

17.

Which protocol should be used to mitigate the vulnerability of using Telnet to remotely manage network devices? 

a)

SNMP 

b)

SCP 

c)

TFTP 

d)

SSH 

18.

Which Layer 2 attack will result in legitimate users not getting valid IP addresses? 

a)

DHCP starvation 

b)

ARP spoofing 

c)

IP address spoofing 

d)

MAC address flooding 

19.

Which mode must be configured on an interface before enabling port security?  

a)

switchport mode dynamic desirable 

b)

switchport mode access 

c)

switchport mode trunk 

d)

switchport mode dynamic auto 

20.

If more than one DHCP server is available on the local network, in which order will DHCP messages be sent between a host and a DHCP server?  

a)

Request, acknowledgment, discover, offer 

b)

Discover, offer, request, acknowledgment 

c)

Request, discover, offer, acknowledgment 

d)

Acknowledgment, request, offer, discover 

21.

What mitigation plan is best for thwarting a DoS attack that is creating a MAC address table overflow? 

a)

Enable port security. 

b)

Disable STP. 

c)

Place unused ports in an unused VLAN. 

d)

Disable DTP. 

22.

What is the default port-security maximum number of MAC addresses on a port? 

a)

8192 

b)

c)

d)

23.

Which type of wireless network often makes use of devices mounted on buildings? 

a)

 wireless metropolitan-area network 

b)

wireless local-area network 

c)

wireless personal-area network 

d)

wireless wide-area network 

24.

A network administrator is configuring DHCP snooping on a switch. Which configuration command should be used first? 

a)

ip dhcp snooping trust 

b)

ip dhcp snooping 

c)

ip dhcp snooping vlan 

d)

ip dhcp snooping limit rate 

25.

Which procedure is recommended to mitigate the chances of ARP spoofing? 

a)

Enable port security globally. 

b)

Enable DAI on the management VLAN. 

c)

Enable IP Source Guard on trusted ports. 

d)

Enable DHCP snooping on selected VLANs. 

26.

Which type of wireless network is suitable for use in a home or office?  

a)

wireless personal-area network 

b)

wireless metropolitan-area network 

c)

wireless local-area network 

d)

wireless wide-area network 

27.

Which type of wireless network uses transmitters to cover a medium-sized network, usually up to 300 feet (91.4 meters)?  

a)

wireless local-area network 

b)

wireless metropolitan-area network 

c)

wireless personal-area network 

d)

wireless wide-area network 

28.

A network administrator has configured an EtherChannel with three interfaces between two switches. What happens if one of the three interfaces fails? 

a)

The EtherChannel fails. 

b)

The remaining two interfaces become separate links between switches. 

c)

The remaining two interfaces continue to share traffic load. 

d)

One interface becomes active and another becomes standby. 

29.

An IT security specialist enables port security on a switch port of a Cisco switch. What is the default violation mode in use until the switch port is configured to use a different violation mode? 

a)

disabled 

b)

shutdown 

c)

protect 

d)

restrict

30.

Which access control component, implementation, or protocol controls what users can do on the network? 

a)

802.1X 

b)

authentication 

c)

authorization 

d)

accounting 

31.

Which port-security learning method saves MAC addresses to the running configuration? 

a)

sticky 

b)

dynamic 

c)

static 

d)

manual 

32.

Which command is recommended to secure unused switch ports? 

a)

ip dhcp snooping 

b)

no shutdown 

c)

switchport port-security 

d)

shutdown 

33.

Which port-security violation mode shuts the port down? 

a)

restrict 

b)

none 

c)

shutdown 

d)

protect

34.

 An IT security specialist enables port security on a switch port of a Cisco switch. What is the default violation mode in use until the switch port is configured to use a different violation mode? 

a)

restrict 

b)

disabled 

c)

protect 

d)

shutdown 

35.

A network administrator of a college is configuring the WLAN user authentication process. Wireless users are required to enter username and password credentials that will be verified by a server. Which server would provide such service? 

a)

NAT 

b)

ААА 

c)

RADIUS 

d)

SNMP 

36.

What command is used to view port security information for all interfaces?  

a)

show interface 

b)

show mac address-table 

c)

show running-config 

d)

show port-security 

37.

On what switch ports should PortFast be enabled to enhance STP stability?  

a)

Only ports that are elected as designated ports 

b)

Only ports that attach to a neighboring switch 

c)

All trunk ports that are not root ports 

d)

All end-user ports 

38.

What is a recommended best practice when dealing with the native VLAN? 

a)

Turn off DTP. 

b)

Assign the same VLAN number as the management VLAN. 

c)

Assign it to an unused VLAN. 

d)

Use port security. 

39.

A network administrator is configuring DAI on a switch. Which command should be used on the uplink interface that connects to a router? 

a)

spanning-tree portfast 

b)

ip arp inspection trust 

c)

ip dhcp snooping 

d)

ip arp inspection vlan 

40.

Which type of VLAN-hopping attack may be prevented by designating an unused VLAN as the native VLAN? 

a)

VLAN double-tagging 

b)

DHCP spoofing 

c)

DHCP starvation 

d)

DTP spoofing 

41.

Which command would be best to use on an unused switch port if a company adheres to the best practices as recommended by Cisco? 

a)

 switchport port-security mac-address sticky mac-address 

b)

ip dhcp snooping 

c)

shutdown 

d)

switchport port-security mac-address sticky 

42.

Which access control component, implementation, or protocol controls what users can do on the network? 

a)

802.1X 

b)

authorization 

c)

authentication 

d)

accounting

43.

Which feature filters DHCP messages on untrusted ports? 

a)

DAI 

b)

Port Security 

c)

DHCP Snooping 

d)

BPDU Guard 

44.

A network administrator is configuring DHCP snooping on a switch. Which configuration command should be used first? 

a)

ip dhcp snooping vlan 

b)

ip dhcp snooping trust 

c)

ip dhcp snooping 

d)

ip dhcp snooping limit rate ip dhcp snooping limit rate 

45.

Which procedure is recommended to mitigate the chances of ARP spoofing?  

a)

Enable IP Source Guard on trusted ports. 

b)

Enable DAI on the management VLAN. 

c)

Enable DHCP snooping on selected VLANs. 

d)

Enable port security globally. 

46.

Which command enables DAI on a VLAN? 

a)

ip dhcp snooping vlan 

b)

spanning-tree portfast 

c)

ip arp inspection vlan 

d)

switchport port-security 

47.

A network administrator is configuring DAI on a switch with the command ip arp inspection validate dst-mac. What is the purpose of this configuration command?  

a)

To check the destination MAC address in the Ethernet header against the user-configured ARP ACLS 

b)

To check the destination MAC address in the Ethernet header against the target MAC address in the ARP body 

c)

To check the destination MAC address in the Ethernet header against the source MAC address in the ARP body 

d)

To check the destination MAC address in the Ethernet header against the MAC address table 

48.

Where are dynamically learned sticky MAC addresses stored while the switch is running? 

a)

ROM 

b)

RAM 

c)

Flash 

d)

all is correct answers 

49.

What is the default port-security maximum number of MAC addresses on a port? 

a)

4

b)

1

c)

8192

d)

2

50.

Which component of AAA allows an administrator to track individuals who access network resources and any changes that are made to those resources? 

a)

accessibility 

b)

accounting 

c)

authorization 

d)

authentication 

51.

What feature prevents MAC address table overflow attacks? 

a)

BPDU Guard 

b)

Port security 

c)

DHCP Snooping 

d)

DAI 

52.

What attack is mitigated by disabling DTP on access ports? 

a)

DHCP starvation 

b)

ARP spoofing 

c)

STP manipulation 

d)

VLAN hopping 

53.

Which feature on a Cisco Catalyst switch can be used to mitigate DHCP spoofing attacks?  

a)

DHCP snooping 

b)

DHCP server failover 

c)

Extended ACL 

d)

Strong password on DHCP servers 

54.

What device is considered a supplicant during the 802.1X authentication process?  

a)

the authentication server that is performing client authentication 

b)

the client that is requesting authentication 

c)

the switch that is controlling network access 

d)

the router that is serving as the default gateway 

55.

What Layer 2 attack is mitigated by disabling Dynamic Trunking Protocol? 

a)

ARP spoofing 

b)

ARP poisoning 

c)

DHCP spoofing 

d)

VLAN hopping 

56.

An administrator who is troubleshooting connectivity issues on a switch notices that a switch port configured for port security is in the err-disabled state. After verifying the cause of the violation, how should the administrator re-enable the port without disrupting network operation? 

a)

Reboot the switch. 

b)

Issue the shutdown command followed by the no shutdown command on the interface. 

c)

Issue the no switchport port-security command, then re-enable port security. 

d)

Issue the no switchport port-security violation shutdown command on the interface. 

57.

What are two types of switch ports that are used on Cisco switches as part of the defense against DHCP spoofing attacks?  

a)

Unknown port and Unauthorized port 

b)

Trusted DHCP port and Untrusted port 

c)

Authorized DHCP port and Established DHCP port 

d)

Untrusted port and Unknown port 

58.

Which security feature should be enabled in order to prevent an attacker from overflowing the MAC address table of a switch? 

a)

Port security 

b)

Storm control 

c)

Root guard 

d)

BPDU filter 

59.

Which authentication method stores usernames and passwords in the router and is ideal for small networks? 

a)

local AAA over RADIUS 

b)

local AAA 

c)

server-based AAA 

d)

server-based AAA over TACACS+ 

60.

What command marks an interface as trusted for DHCP Snooping?  

a)

ip dhcp snooping trust 

b)

switchport mode access 

c)

ip dhcp snooping limit rate 

d)

ip arp inspection trust