Tüm alıştırma soruları
1987 soru
Match each port security violation mode on the left with its corresponding switch behavior when an unauthorized MAC address is detected on an interface.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator needs to back up a Cisco IOS router's running configuration to a remote FTP server at IP address 10.1.1.50 using the username 'admin' and password 'Cisco123'. Which command correctly completes this file transfer in a single step?
A network administrator is monitoring an HSRP deployment on router R1 and executes the `show standby brief` command, obtaining the following output:
text
Interface Grp Pri P State Active Standby Virtual IP
Gi0/1 20 110 P Active local 192.168.20.3 192.168.20.1
Router R1 is configured to track interface GigabitEthernet0/0 with a priority decrement value of . Router R2 (currently the Standby router at ) has an HSRP priority of and has preemption enabled.
If interface GigabitEthernet0/0 on router R1 goes down, which operational change occurs on the local network segment?
A network engineer applies the following IPv4 extended named Access Control List (ACL) inbound on interface GigabitEthernet0/0 of a Cisco IOS router:
text
ip access-list extended SERVER_ACCESS
permit tcp 172.16.10.0 0.0.0.255 host 192.168.50.10 eq 443
permit tcp 172.16.10.0 0.0.0.255 host 192.168.50.10 eq 80
A workstation with IPv4 address 172.16.10.45 attempts to establish an SSH management session (TCP port 22) to the server at 192.168.50.10. Which result describes how the router processes this SSH traffic?
An administrator is configuring a secondary IPv4 static route on router R1 to reach network via next-hop . A primary static route to the same destination network via next-hop already exists in the active configuration with default settings. The secondary route must serve strictly as a backup and only enter the routing table if the primary path fails. Which Cisco IOS command should be configured on router R1?
A network administrator is auditing the infrastructure security measures for a newly constructed enterprise data center facility. Which two measures represent physical access controls specifically designed to protect physical hardware and prevent unauthorized physical entry? (Select two.)
Geçerli olan tümünü seçin
A network administrator is evaluating the operational parameters and default behaviors of First Hop Redundancy Protocols (FHRP) on Cisco IOS devices. Which two statements accurately describe default differences between VRRPv2 and HSRPv1?
Geçerli olan tümünü seçin
A network administrator is migrating a gateway configuration from VRRP to HSRP Group 1 on a Cisco router. Under the previous VRRP setup, the virtual IP address was configured to match the physical IPv4 address of router R1's GigabitEthernet0/1 interface (192.168.10.1/24). The administrator attempts to enter the command `standby 1 ip 192.168.10.1` under interface GigabitEthernet0/1 on R1. What is the outcome of executing this command on Cisco IOS?
A network administrator needs to configure an extended IPv4 ACL (ACL 101) on a Cisco router to control access from the User Subnet () to the Server Subnet () according to the following security requirements:
1. Host must be permitted SSH access (TCP port 22) to Server .
2. Host must be denied all other IP traffic to any destination on the Server Subnet ().
3. All other hosts on the User Subnet () must be permitted HTTP access (TCP port 80) to Server .
4. All other traffic from the User Subnet to the Server Subnet must be explicitly denied.
Arrange the given ACL statements in the correct top-down evaluation order (from first line processed to last line processed) to successfully enforce these security requirements.
Öğeleri doğru sıraya koymak için sürükleyin
A network administrator enables Dynamic ARP Inspection (DAI) on VLAN 20 of a Cisco Catalyst switch. DHCP Snooping is enabled on VLAN 20, but several legacy printers on untrusted access ports use static IPv4 addresses and are not recorded in the DHCP snooping binding database. Consequently, DAI drops legitimate ARP packets originating from these printers. Which two configuration actions must the administrator perform to allow ARP traffic from the static hosts while maintaining DAI inspection on those untrusted ports? (Select two.)
Geçerli olan tümünü seçin
A network administrator needs to configure and verify a floating static route for destination network via next-hop IP on a Cisco router. The primary path to this network is currently learned dynamically via EIGRP with an Administrative Distance of . Place the configuration and verification steps in the correct sequential order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
A network administrator is evaluating local password storage mechanisms on a Cisco IOS XE device to align with security hardening standards. Arrange the following Cisco IOS password storage types in order from WEAKEST security protection to STRONGEST security protection.
Öğeleri doğru sıraya koymak için sürükleyin
A network engineer is hardening an enterprise access layer switch using Cisco Layer 2 security features. Match each specific Layer 2 security feature configuration component on the left with its exact operational behavior or validation requirement on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network security administrator configures mutual certificate-based authentication (EAP-TLS) for remote access VPN endpoints. During initial validation testing, client endpoints successfully verify the identity of the VPN gateway. However, the VPN gateway fails to authenticate the client certificates. Detailed inspection reveals that the gateway is configured for mandatory certificate status checking using the Online Certificate Status Protocol (OCSP), but outbound HTTP requests sent to the Uniform Resource Identifier (URI) listed in the Authority Information Access (AIA) extension are being dropped by a perimeter security policy. Which statement correctly identifies the cause of the failure and the necessary resolution?
A network operations team switches from per-device manual command-line configuration to centralized template-based automation. Which primary operational advantage does this shift deliver?
Place the HSRP (Hot Standby Router Protocol) router states in the correct chronological order as a newly configured router transitions from initial startup to becoming the active gateway.
Öğeleri doğru sıraya koymak için sürükleyin
A network administrator needs to record and audit the specific CLI commands executed by engineers during their active management sessions on enterprise routers. Which component of the AAA framework provides this record-keeping functionality?
A network administrator is evaluating network file transfer protocols to manage router software images and configuration backups across an enterprise network. Which TWO statements correctly describe operational differences between TFTP and FTP in a Cisco IOS environment?
Geçerli olan tümünü seçin
A network engineer configures an inbound IPv4 extended Access Control List (ACL) on GigabitEthernet0/1 to filter traffic entering a corporate network segment:
text
ip access-list extended FILTER_WEB
permit tcp 172.16.10.0 0.0.0.255 host 192.168.1.50 eq 80
permit tcp 172.16.10.0 0.0.0.255 host 192.168.1.50 eq 443
A workstation at attempts to send ICMP echo request packets (ping) to the server at . What happens to these ICMP packets when processed by the router interface?
In enterprise Cisco switch implementations, Layer 2 security controls govern frame processing, metadata insertion, and hardware lookup behaviors. Match each Layer 2 security operation or feature context to its exact functional mechanism.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler