Tüm alıştırma soruları
1987 soru
During a security audit of an enterprise network infrastructure, an engineer reviews several identified security vulnerabilities and proposed mitigation steps across administrative access, ACL filtering, and switchport security. Which of the following correctly pairs an identified security threat or vulnerability with its proper mitigation strategy?
Router R1 learns the destination network dynamically via internal EIGRP, which has a default Administrative Distance (AD) of 90. A network administrator wants to configure a floating static route pointing to next-hop to serve as a backup path when the EIGRP route fails. Which two conditions or behaviors apply to this floating static route implementation? (Select two.)
Geçerli olan tümünü seçin
A network administrator needs to secure remote administrative access to a Cisco IOS switch by requiring users to authenticate against the local user database. Which two steps are required to implement local user database authentication for remote VTY line access? (Select two.)
Geçerli olan tümünü seçin
A network engineer is configuring Quality of Service (QoS) mechanisms on a Cisco router interface to control bandwidth usage. Which two behaviors are characteristic of traffic policing rather than traffic shaping? (Select two.)
Geçerli olan tümünü seçin
A network security engineering team is analyzing threat vectors affecting enterprise switch and router infrastructure. Match each security threat scenario on the left with its primary technical mitigation mechanism on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator is configuring static routes on router R1 to reach two remote networks: Subnet A () connected across a point-to-point serial interface (Serial0/0/0), and Subnet B () connected across a multiaccess Ethernet interface (GigabitEthernet0/0, with next-hop IP address ). Which two static route configuration commands follow Cisco IOS best practices and prevent unnecessary ARP resolution overhead?
Geçerli olan tümünü seçin
Two Cisco routers, R1 and R2, are directly connected via their GigabitEthernet0/0 interfaces on the 192.168.12.0/24 network segment. OSPFv2 is initialized on both routers. R1 has its GigabitEthernet0/0 interface placed into OSPF Area 0, while R2 has its GigabitEthernet0/0 interface placed into OSPF Area 10. All other OSPF interface configurations use default settings. What will be the observed result when an administrator executes the command `show ip ospf neighbor` on R1?
A network administrator needs to restrict syslog messages sent to an external syslog server. The requirements specify that the remote server must receive only events with a severity level of Warning (level 4) and more critical events (levels 0 through 3), while excluding Notification (level 5), Informational (level 6), and Debugging (level 7) messages. Which Cisco IOS global configuration command meets this requirement?
Four routers (R1, R2, R3, and R4) are connected to a shared Ethernet switch in OSPFv2 Area 0. R1 (Router ID 1.1.1.1, interface priority 1) boots up first and completes initialization. Next, R2 (Router ID 2.2.2.2, interface priority 1) boots up and joins the network segment. Several minutes later, R3 (Router ID 3.3.3.3, interface priority 255) and R4 (Router ID 4.4.4.4, interface priority 0) are booted up and added to the OSPF segment. Assuming no OSPF processes are restarted or cleared, which router serves as the Designated Router (DR) on this multiaccess segment?
A network administrator configures an IPv4 extended access control list (ACL) on a Cisco router interface to allow web traffic using the following command:
`access-list 100 permit tcp host 192.168.1.50 any eq 80`
No other ACL entries are configured on the router. What happens when host 192.168.1.50 sends an ICMP echo request (ping) packet through the interface where this ACL is applied?
A network administrator is designing a high-availability default gateway architecture for VLAN 10 (subnet 10.1.10.0/24) using two Layer 3 distribution switches. Switch-1 is configured with physical interface IP address 10.1.10.2/24 and Switch-2 is configured with physical interface IP address 10.1.10.3/24. The administrator is evaluating protocol characteristics between HSRPv2 and VRRPv3. Which two statements correctly describe operational differences and IP addressing rules between these protocols? (Select two.)
Geçerli olan tümünü seçin
Match each Cisco Layer 2 security feature or interface trust state on the left with its correct operational behavior or dependency on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Network architects are evaluating packet encapsulation and routing mechanisms within a modern Cisco Software-Defined Access (SD-Access) fabric architecture. Which two statements correctly differentiate the operational capabilities and responsibilities of the underlay network versus the overlay network? (Select two.)
Geçerli olan tümünü seçin
An administrator configures the following extended IPv4 access control list on a Cisco IOS router to control traffic between subnets:
ip access-list extended SECURE_ACCESS
10 deny tcp host 192.168.10.15 host 10.1.20.10 eq 22
20 permit tcp host 192.168.10.15 10.1.20.0 0.0.0.255 eq 80
30 permit tcp host 192.168.10.15 10.1.20.0 0.0.0.255 eq 443
40 permit icmp 192.168.10.0 0.0.0.255 host 10.1.20.254 echo
The access list is applied inbound on the interface facing the 192.168.10.0/24 subnet. Which TWO statements accurately describe how traffic will be processed by this access control list?
Geçerli olan tümünü seçin
An engineer is configuring secure remote management on a central router named Edge-Rtr1. The device has a valid hostname, an IP domain name configured, a 1024-bit RSA key pair generated, and a local administrator user defined in global configuration mode. The virtual terminal lines are configured with transport input ssh. However, when connecting via SSH from a remote client, the router prompts only for a password instead of requesting a username, causing all login attempts to fail. Which configuration change on Edge-Rtr1 resolves this issue?
An administrator attempts to secure VLAN 20 on a Cisco Catalyst switch by executing the commands `ip dhcp snooping vlan 20` and `ip arp inspection vlan 20`. Access interface GigabitEthernet0/2 is in VLAN 20 and remains in its default untrusted state for both security features. Clients connected to GigabitEthernet0/2 are configured with static IP addresses, but all outgoing ARP packets from these clients are intercepted and dropped by the switch, preventing any network communication. Which root cause explains why Dynamic ARP Inspection (DAI) is dropping this ARP traffic?
An enterprise network engineer is using Cisco DNA Center Software Image Management (SWIM) to upgrade the Cisco IOS XE operating system across a cluster of access switches. The engineer imports the required software image into the Cisco DNA Center repository, marks it as the Golden Image for the switch family, and schedules the deployment. Cisco DNA Center successfully transfers the image file to the local flash storage of all target switches during the maintenance window. However, after the task finishes, all switches continue to run their previous operating system version and Cisco DNA Center flags the switches as non-compliant.
Which phase of the SWIM workflow was omitted or failed to execute?
An network engineer issues a REST API call to a Cisco DNA Center controller to retrieve information regarding managed network devices. The controller returns the following JSON response payload:
{
"response": [
{
"family": "Switches and Hubs",
"hostname": "Dist-Switch-01",
"managementIpAddress": "192.168.10.1",
"upTime": "12 days, 04:12:00",
"interfaceList": [
{
"portName": "GigabitEthernet1/0/1",
"vlan": 10,
"status": "up",
"speed": 1000
},
{
"portName": "GigabitEthernet1/0/2",
"vlan": 20,
"status": "down",
"speed": 1000
}
]
},
{
"family": "Routers",
"hostname": "Edge-Router-01",
"managementIpAddress": "10.1.1.1",
"upTime": "45 days, 11:05:22",
"interfaceList": [
{
"portName": "GigabitEthernet0/0/0",
"vlan": 1,
"status": "up",
"speed": 10000
}
]
}
],
"version": "1.0"
}
Assuming the variable `data` holds the parsed Python dictionary representation of this JSON payload, which Python expression correctly extracts the operating status (`"status"`) of the second interface on the distribution switch (`Dist-Switch-01`)?
A network engineering team implements an automated, controller-led management model to enforce baseline configurations across 200 edge routers. Instead of manually pushing changes via device-by-device CLI scripts, the team defines target configurations in centralized declarative state files. Which operational benefit is primarily realized by adopting this automated approach?
In Cisco DNA Center, Software Image Management (SWIM) simplifies the maintenance of device software binaries across enterprise networks. What is the primary purpose of designating a software image as a 'Golden Image' within SWIM?