Cisco chapter 2

¡Supera tus tareas y exámenes ahora con Quizwiz!

restrict

. A network administrator configures the port security feature on a switch. The security policy specifies that each access port should allow up to two MAC addresses. When the maximum number of MAC addresses is reached, a frame with the unknown source MAC address is dropped and a notification is sent to the syslog server. Which security violation mode should be configured for each access port?

A full version of the Cisco IOS was located and loaded.* POST occurred normally.*

A production switch is reloaded and finishes with a Switch> prompt. What two facts can be determined? (Choose two.)

the aging-out period of the MAC address table*

An administrator wants to use a network security auditing tool on a switch to verify which ports are not protected against a MAC flooding attack. For the audit to be successful, what important factor must the administrator consider?

Full duplex

Fill in the blank. " ____________" communication allows both ends of a connection to transmit and receive data simultaneously. Full-duplex communication improves the performance of a switched LAN, increasing effective bandwidth by allowing both ends of a connection to transmit and receive data simultaneously.

[+] Create a local user. [+] Generate RSA keys. [+] Configure a domain name. [+] Use the login local command. [+] Use the transport input ssh command. [+] Order does not matter within this group.

Identify the steps needed to configure a switch for SSH. Place the options in the following order:

when packets are being dropped from a particular directly attached host*

In which situation would a technician use the show interfaces switch command?

DHCP starvation

In which type of attack does a malicious node request all available IP addresses in the address pool of a DHCP server in order to prevent legitimate hosts from obtaining network access?​

ip address 192.168.99.2 255.255.255.0 "

Open the PT Activity. Perform the tasks in the activity instructions and then answer the question. Do not use abbreviations.What is the missing command on S1?

A malfunctioning NIC can cause frames to be transmitted that are longer than the allowed maximum length. *

Refer to the exhibit. A network technician is troubleshooting connectivity issues in an Ethernet network with the command show interfaces fastEthernet 0/0. What conclusion can be drawn based on the partial output in the exhibit?

SWA(config-if)# switchport port-security SWA(config-if)# switchport port-security maximum 2 SWA(config-if)# switchport port-security mac-address sticky********

Refer to the exhibit. Port Fa0/2 has already been configured appropriately. The IP phone and PC work properly. Which switch configuration would be most appropriate for port Fa0/2 if the network administrator has the following goals? No one is allowed to disconnect the IP phone or the PC and connect some other wired device. If a different device is connected, port Fa0/2 is shut down. The switch should automatically detect the MAC address of the IP phone and the PC and add those addresses to the running configuration.

Modify the transport input command.

Refer to the exhibit. The network administrator wants to configure Switch1 to allow SSH connections and prohibit Telnet connections. How should the network administrator change the displayed configuration to satisfy the requirement?

The port violation mode is the default for any port that has port security enabled.*

Refer to the exhibit. What can be determined about port security from the information that is shown?

There could be too much electrical interference and noise on the link.*

Refer to the exhibit. What media issue might exist on the link connected to Fa0/1 based on the show interface command?

only the G0/1 and G0/24 ports*

Refer to the exhibit. Which S1 switch port interface or interfaces should be configured with the ip dhcp snooping trust command if best practices are implemented?

Packets with unknown source addresses will be dropped

Refer to the exhibit. Which event will take place if there is a port security violation on switch S1 interface Fa0/1?

Users on the 192.168.1.0/24 subnet are able to ping the switch at IP address 192.168.1.2.*

The network administrator enters the following commands on a Cisco switch: Switch(config)# interface vlan1 Switch(config-if)# ip address 192.168.1.2 255.255.255.0 Switch(config-if)# no shutdown What is the effect of entering these commands?

automatically detects copper cable type*

What impact does the use of the mdix auto configuration command have on an Ethernet interface on a switch?

to provide an environment to operate in when the switch operating system cannot be found*

What is a function of the switch boot loader?

Telnet sends a username and password in plain text, whereas SSH encrypts the username and password.

What is one difference between using Telnet or SSH to connect to a network device for management purposes?

Shutdown

When port security is enabled, a switch port uses the default violation mode of " ________ " until specifically configured to use a different violation mode. If no violation mode is specified when port security is enabled on a switch port, then the security violation mode defaults to shutdown.

Issue the shutdown and then no shutdown interface commands.*

Which action will bring an error-disabled switch port back to an operational state?

show controllers*

Which command displays information about the auto-MDIX setting for a specific interface?​

VLAN 1*

Which interface is the default location that would contain the IP address used to manage a 24-port Ethernet switch?

configuring port security

Which method would mitigate a MAC address flooding attack?

CDP

Which protocol or service sends broadcasts containing the Cisco IOS software version of the sending device, and the packets of which can be captured by malicious hosts on the network?

If the LED is green, the port is operating at 100 Mb/s.*

Which statement describes the port speed LED on the Cisco Catalyst 2960 switch?

Performance is improved with bidirectional data flow.* Full-duplex Fast Ethernet offers 100 percent efficiency in both directions. Performance is improved because the collision detect function is disabled on the device.*

Which three statements are true about using full-duplex Fast Ethernet? (Choose three.)

revealing the type of information an attacker is able to gather from monitoring network traffic simulating attacks against the production network to determine any existing vulnerabilities

Which two basic functions are performed by network security tools? (Choose two.)

port security* DHCP snooping*

Which two features on a Cisco Catalyst switch can be used to mitigate DHCP starvation and DHCP spoofing attacks? (Choose two.)

Performance is improved with bidirectional data flow Full-duplex Fast Ethernet offers 100 percent efficiency in both directions.

Which two statements are true about using full-duplex Fast Ethernet?

Dynamically learned secure MAC addresses are lost when the switch reboots.* If fewer than the maximum number of MAC addresses for a port are configured statically, dynamically learned addresses are added to CAM until the maximum number is reached.*

Which two statements are true regarding switch port security? (Choose two.)

a console cable

Which type of cable does a network administrator need to connect a PC to a switch to recover it after the Cisco IOS software fails to load?

The port is experiencing errors

While troubleshooting a connectivity problem, a network administrator notices that a switch port status LED is alternating between green and amber. What could this LED indicate?


Conjuntos de estudio relacionados

Intro to Business Bonus Exam Part 1 (Most Missed Question/Exam Questions)

View Set

implementation ch 14 coursepoint

View Set

Chapter 5 Integumentary systemSudoriferous (sweat) glands are categorized as two distinct types. Which of the following are the two types of sweat glands?

View Set

Chapter: 10 Florida Statutes, Rules, and Regulations Common to All Lines

View Set

Ch. 24: Measuring the cost of Living

View Set

Practice of Real Estate (Fair Housing)

View Set