Escolar Documentos
Profissional Documentos
Cultura Documentos
(75 Questions)
Revised 1/27
New Question 1:
Refer to the following access list.
access-list 100 permit ip any any log
After applying the access list on a Cisco router, the network engineer notices that the router CPU utilization has risen to
99 percent. What is the reason for this?
A. A packet that matches access-list with the log keyword is Cisco Express Forwarding switched.
B. A packet that matches access-list with the log keyword is fast switched.
C. A packet that matches access-list with the log keyword is process switched.
D. A large amount of IP traffic is being permitted on the router.
Correct Answer: C
New Question 2:
What does the following access list, which is applied on the external interface FastEthernet 1/0 of the perimeter router,
accomplish?
router(config)#access-list 101 deny ip 10.0.0.0 0.255.255.255 any log
router (config)#access-list 101 deny ip 192.168.0.0 0.0.255.255 any log
router (config)#access-list 101 deny ip 172.16.0.0 0.15.255.255 any log
router (config)#access-list 101 permit ip any any
router (config)#interface fastEthernet 1/0
router (config-if)#ip access-group 101 in
A. It prevents incoming traffic from IP address ranges 10.0.0.0-10.0.0.255, 172.16.0.0-172.31.255.255, 192.168.0.0-
192.168.255.255 and logs any intrusion attempts.
B. It prevents the internal network from being used in spoofed denial of service attacks and logs any exit to the Internet.
C. It filters incoming traffic from private addresses in order to prevent spoofing and logs any intrusion attempts.
D. It prevents private internal addresses to be accessed directly from outside.
Correct Answer: C
New Question 3:
A network engineer is configuring a solution to allow failover of HSRP nodes during maintenance windows, as an
alternative to powering down the active router and letting the network respond accordingly. Which action will allow for
manual switching of HSRP nodes?
A. Track the up/down state of a loopback interface and shut down this interface during maintenance.
B. Adjust the HSRP priority without the use of preemption.
C. Disable and enable all active interfaces on the active HSRP node.
D. Enable HSRPv2 under global configuration, which allows for maintenance mode.
Correct Answer: A
New Question 4:
Which two commands would be used to troubleshoot high memory usage for a process? (Choose two.)
A. router#show memory allocating-process table
B. router#show memory summary
C. router#show memory dead
D. router#show memory events
E. router#show memory processor statistics
Correct Answer: A,B
New Question 6:
The enterprise network WAN link has been receiving several denial of service attacks from both IPv4 and IPv6 sources.
Which three elements can you use to identify an IPv6 packet via its header, in order to filter future attacks? (Choose
three.)
A. Traffic Class
B. Source address
C. Flow Label
D. Hop Limit
E. Destination Address
F. Fragment Offset
Correct Answer: Answer: A,C,D
New Question 7:
A network engineer has set up VRF-Lite on two routers where all the interfaces are in the same VRF. At a later time, a
new loopback is added to Router 1, but it cannot ping any of the existing interfaces. Which two configurations enable the
local or remote router to ping the loopback from any existing interface? (Choose two.)
A. adding a static route for the VRF that points to the global route table
B. adding the loopback to the VRF
C. adding dynamic routing between the two routers and advertising the loopback
D. adding the IP address of the loopback to the export route targets for the VRF
E. adding a static route for the VRF that points to the loopback interface
F. adding all interfaces to the global and VRF routing tables
Correct Answer: A,B
New Question 8:
Which three benefits does the Cisco Easy Virtual Network provide to an enterprise network? (Choose three.)
A. simplified Layer 3 network virtualization
B. improved shared services support
C. enhanced management, troubleshooting, and usability
D. reduced configuration and deployment time for dot1q trunking
E. increased network performance and throughput
F. decreased BGP neighbor configurations
Correct Answer: A,B,C
New Question 7:
Which PPP authentication method sends authentication information in cleartext?
A. MS CHAP
B. CDPCP
C. CHAP
D. PAP
Correct Answer: D
New Question 9:
On which two types of interface is Frame Relay switching supported? (Choose two.)
A. serial interfaces
B. Ethernet interfaces
C. fiber interfaces
D. ISDN interfaces
E. auxiliary interfaces
Correct Answer: A,D
B. (config)#ipcef
(config)#interface fa0/0
(config-if)#ip verify unicast source reachable-via rx
C. (config)#no ipcef
(config)#interface fa0/0
(config-if)#ip verify unicast source reachable-via rx
D. (config)#interface fa0/0
(config-if)#ip verify unicast source reachable-via any
Correct Answer: A
A. ABR
B. ASBR
C. Edge Router
D. Internal Router
Correct Answer: A
A network engineer has configured GRE between two IOS routers. The state of the tunnel interface is continuously
oscillating between up and down. What is the solution to this problem?
A. Create a more specific static route to define how to reach the remote router.
B. Create a more specific ARP entry to define how to reach the remote router.
C. Save the configuration and reload the router.
D. Check whether the internet service provider link is stable
Correct Answer: A
Correct Answer: C
A. Encapsulation is mismatched.
B. Frame Relay map is configured.
C. DLCI is active.
D. DLCI is inactive or deleted.
E. An access list is needed to allow ping.
Correct Answer: A,D
New Question 43
Which two functionalities are specific to stateless NAT64? (Choose two.)
A. No requirement exists for the characteristics of Ipv6 address assignment.
B. It does not conserve Ipv4 addresses.
C. It provides 1-to-1 translation.
D. It uses address overloading.
E. State or bindings are created on the translation.
Correct Answer: B,C
New Question 44
Other than a working EIGRP configuration, which option must be the same on all routers for EIGRP authentication key
rolleover to work correctly?
A. SMTP
B. SNMP
C. Passwords
D. Time
Correct Answer: D
New Question 45
Refer to the Exhibit
A network engineer is troubleshooting a DMVPN setup between the hub and the spoke. The engineer executes the
command show crypto isakmp sa and observes the output that is displayed. What is the problem?
A. That ISAKMP is not enabled
B. That ISAKMP is using default settings
C. An incompatible IP sec transform set
D. An incompatible ISAKMP policy
Corect Answer: B
New Question 46
In which form does PAP authentication send the username and password across the link?
A. Encrypted
B. Password protected
C. Clear text
D. Hashed
Correct Answer: C
Question 47:
An engineer is using a network sniffer to troubleshoot DHCPv6 between a router and hosts on the LAN with the
following configuration:
Interface Ethernet0
Ipv6 dhcp server DHCPSERVERPOOL rapid-commit
!
Which two DHCPv6 messages will appear in the sniffer logs?
A. reply
B. request
C. advertise
D. acknowledge
E. solicit
F. accept
Correct Answer: A,E
New Question 50
Which mode of uRPF causes a router interface to accept a packet, if the network to which the packets source IP address
belongs is found in the routers FIB?
A. Strict mode
B. Loose mode
C. Auto mode
D. Desirable mode
Correct Answer: B
New Question 51
Which of the following are characteristics of TACACS+? (Choose two.)
A. Uses UDP
B. Encrypts an entire packet
C. Offers robust accounting
D. Cisco-proprietary
Correct Answer: B,D
New Question 52
Which two options are causes of out-of-order packets? (Choose two.)
A. a routing loop
B. a router in the packet flow path that is intermittently dropping packets
C. high latency
D. packets in a flow traversing multiple paths through the network.
E. some packets in a flow being process-switched and others being interrupt-switched on a
transit Router.
Correct Answer: D,E
New Question 53
Your company uses Voice over IP (VoIP). The system sends UDP datagrams containing the voice data between
communicating hosts. When areas of the network become busy, some of the datagrams arrive at their destination out of
order. What happens when this occurs?
A. UDP will send an ICMP Information request message to the source host.
B. UDP will pass the information in the datagrams up to the next OSI layer in the order in
which they arrive.
C. UDP will drop the datagrams that arrive out of order.
D. UDP will use the sequence numbers in the datagram headers to reassemble the data
Correct Answer: B
New Question 58
A question about how ALWAYS block the outbound web traffic on Saturdays and Sunday between 1:00 AM to 23:59
AM.
Correct Answer: C
New Question 59
Which two phases of DMPVN allow the spoke site to create dynamic tunnels to one other (Choose 2)?
A. Phase 1
B. Phase 2
C. Phase 3
D. Phase 4
E. Phase 5
Correct Answer: B, C
New Question 60
A. Broadcast
B. Point to point
C. Non-Broadcast
D. Point-to-multipoint
New Question 61
Which command configures a PPPoE client and specifies dial-on-demand routing functionality?
A.pppoe-client dial-pool-number
B.PPPoE enable
C.interface dialer 1
D.encapsulation PPP
Correct Answer: A
New Question 62
A network engineer implemented Cisco EVN. Which feature implements shared services support?
A. edge interfacing
B. tunnel feedback
C. route replication
D. route redistribution.
Correct Answer: C
New Question 63
In regards to CEF (Cisco Express Forwarding) with a highlight of a configuration snippet valid punt adjacency.
Correct Answer: not supported in CEF, forward to the next switching layer
New Question 65
Eigrp is implemented in a frame relay network but there is no adjacency. Which options cause the adjacency to come up?
(choose 2)
New Question 66
What is uRPF checking first when the packet enters the interface?
Correct Answer: C
New Question 67
A network engineer applies the command ip tcp adjust-mss under interface configuration mode. What is the result?
Correct Answer: C
New Question 68
Which command instruct a PPPoE client to obtain its IP address from the PPPoE server?
A. Interface dialer
B. IP address negotiated
C. PPPOE enable
D. Not Sure
Correct Answer: B
New Question 69
A. Any packet that is received in the inside interface with a source IP port address of
172.16.10.8:80 is translated to 172.16.10.8:8080.
B. Any packet that is received in the inside interface with a source IP port address of
172.16.10.8:8080 is translated to 172.16.10.8:80
C. The router accepts only a TCP connection from port 8080 and port 80 on IP address
172.16.10.8.
D. Any packet that is received in the inside interface with a source IP address of 172.16.10.8
is redirected to port 8080 or port 80.
Correct Answer: B
New Question 70
Always block the outbound web traffic on Saturdays and Sunday between 1:00 to 23:59 with 4 options
Correct Answer: Absolute Saturday Sunday 01:00 to 11:59 (Do not confuse it with periodic Saturday Sunday 01:00 to
23:59)
New Question 71
Which two options are the causes for IP SLA tracking to fail? (Choose 2)
Correct Answer: A, C
New Question 72
A network engineer recently deployed Easy Virtual Networking in the enterprise network. Which feature improves the
service support??
A. edge interfacing,
B. tunnel feedback,
C. route replication
D. route distinguisher
Correct Answer: C
New Question 73
New Question 74
A network engineer enable OSPF on a Frame Relay WAN connection to various remote sites, but no OSPF adjacencies
come up. Which two action are possible solution for this issue (Choose 2)
Correct Answer: A, D
New Question 75
There is a question about applying an IPv6 access-list to block traffic INBOUND telnet and interface
Correct Answer: There are 5 answer options 3 being output and 2 being inbound. The two inbound options are the
correct answers