ccna 2 PT.2
Although DTLS is enabled by default to secure the CAPWAP control channel, it is disabled by default for the data channel.
A WLAN engineer deploys a WLC and five wireless APs using the CAPWAP protocol with the DTLS feature to secure the control plane of the network devices. While testing the wireless network, the WLAN engineer notices that data traffic is being exchanged between the WLC and the APs in plain-text and is not being encrypted. What is the most likely reason for this? DTLS only provides data security through authentication and does not provide encryption for data moving between a wireless LAN controller (WLC) and an access point (AP). Although DTLS is enabled by default to secure the CAPWAP control channel, it is disabled by default for the data channel. DTLS is a protocol that only provides security between the access point (AP) and the wireless client. Data encryption requires a DTLS license to be installed on each access point (AP) prior to being enabled on the wireless LAN controller (WLC).
channels 1, 6, and 11
A company is deploying a wireless network in the distribution facility in a Boston suburb. The warehouse is quite large and it requires multiple access points to be used. Because some of the company devices still operate at 2.4GHz, the network administrator decides to deploy the 802.11g standard. Which channel assignments on the multiple access points will make sure that the wireless channels are not overlapping? channels 1, 5, and 9 channels 1, 6, and 11 channels 1, 7, and 13 channels 2, 6, and 10
Check the configuration of the exit interface on the new static route.
A junior technician was adding a route to a LAN router. A traceroute to a device on the new network revealed a wrong path and unreachable status. What should be done or checked? Create a floating static route to that network. Check the configuration on the floating static route and adjust the AD. Check the configuration of the exit interface on the new static route. Verify that the static route to the server is present in the routing table.
The VLANs for user access ports should be different VLANs than any native VLANs used on trunk ports.
A network administrator has found a user sending a double-tagged 802.1Q frame to a switch. What is the best solution to prevent this type of attack? The native VLAN number used on any trunk should be one of the active data VLANs. The VLANs for user access ports should be different VLANs than any native VLANs used on trunk ports. Trunk ports should be configured with port security. Trunk ports should use the default VLAN as the native VLAN number.
to provide privacy and integrity to wireless traffic by using encryption
A network administrator is configuring a WLAN. Why would the administrator apply WPA2 with AES to the WLAN? to reduce the risk of unauthorized APs being added to the network to centralize management of multiple WLANs to provide prioritized service for time-sensitive applications to provide privacy and integrity to wireless traffic by using encryption
to reduce outsiders intercepting data or accessing the wireless network by using a well-known address range
A network administrator is configuring a WLAN. Why would the administrator change the default DHCP IPv4 addresses on an AP? to eliminate outsiders scanning for available SSIDs in the area to reduce the risk of unauthorized APs being added to the network to reduce outsiders intercepting data or accessing the wireless network by using a well-known address range to reduce the risk of interference by external devices such as microwave ovens
to restrict access to the WLAN by authorized, authenticated users only
A network administrator is configuring a WLAN. Why would the administrator use RADIUS servers on the network? to centralize management of multiple WLANs to restrict access to the WLAN by authorized, authenticated users only to facilitate group configuration and management of multiple WLANs through a WLC to monitor the operation of the wireless network
to facilitate group configuration and management of multiple WLANs through a WLC
A network administrator is configuring a WLAN. Why would the administrator use a WLAN controller? to centralize management of multiple WLANs to provide privacy and integrity to wireless traffic by using encryption to facilitate group configuration and management of multiple WLANs through a WLC to provide prioritized service for time-sensitive applications
Configure the port as an 802.1q trunk port.
A network administrator is using the router-on-a-stick model to configure a switch and a router for inter-VLAN routing. What configuration should be made on the switch port that connects to the router? Configure it as a trunk port and allow only untagged traffic. Configure the port as an access port and a member of VLAN1. Configure the port as an 802.1q trunk port. Configure the port as a trunk port and assign it to VLAN1.
a user passphrase
A network administrator of a small advertising company is configuring WLAN security by using the WPA2 PSK method. Which credential do office users need in order to connect their laptops to the WLAN? the company username and password through Active Directory service a key that matches the key on the AP a user passphrase a username and password configured on the AP
PortFast is not configured on all access ports.
A network administrator uses the spanning-tree portfast bpduguard default global configuration command to enable BPDU guard on a switch. However, BPDU guard is not activated on all access ports. What is the cause of the issue? BPDU guard needs to be activated in the interface configuration command mode. Access ports configured with root guard cannot be configured with BPDU guard. Access ports belong to different VLANs. PortFast is not configured on all access ports.
The 5 GHz band has more channels and is less crowded than the 2.4 GHz band, which makes it more suited to streaming multimedia.
A network engineer is troubleshooting a newly deployed wireless network that is using the latest 802.11 standards. When users access high bandwidth services such as streaming video, the wireless network performance is poor. To improve performance the network engineer decides to configure a 5 Ghz frequency band SSID and train users to use that SSID for streaming media services. Why might this solution improve the wireless network performance for that type of service? Requiring the users to switch to the 5 GHz band for streaming media is inconvenient and will result in fewer users accessing these services. The 5 GHz band has more channels and is less crowded than the 2.4 GHz band, which makes it more suited to streaming multimedia. The 5 GHz band has a greater range and is therefore likely to be interference-free. The only users that can switch to the 5 GHz band will be those with the latest wireless NICs, which will reduce usage.
Configure the new switch as a VTP client. Configure the existing VTP domain name on the new switch.
A new switch is to be added to an existing network in a remote office. The network administrator does not want the technicians in the remote office to be able to add new VLANs to the switch, but the switch should receive VLAN updates from the VTP domain. Which two steps must be performed to configure VTP on the new switch to meet these conditions? (Choose two.) Configure the new switch as a VTP client. Configure the existing VTP domain name on the new switch. Configure an IP address on the new switch. Configure all ports of both switches to access mode. Enable VTP pruning.
Segment the LAN into smaller LANs and route between them.*
A small publishing company has a network design such that when a broadcast is sent on the LAN, 200 devices receive the transmitted broadcast. How can the network administrator reduce the number of devices that receive broadcast traffic? Add more switches so that fewer devices are on a particular switch. Replace the switches with switches that have more ports per switch. This will allow more devices on a particular switch. Segment the LAN into smaller LANs and route between them.* Replace at least half of the switches with hubs to reduce the size of the broadcast domain.
Create static routes to all internal networks and a default route to the internet.
A technician is configuring a router for a small company with multiple WLANs and doesn't need the complexity of a dynamic routing protocol. What should be done or checked? Verify that there is not a default route in any of the edge router routing tables. Create static routes to all internal networks and a default route to the internet. Create extra static routes to the same location with an AD of 1. Check the statistics on the default route for oversaturation.
The host sends an ICMPv6 neighbor solicitation message to the DHCP or SLAAC-learned address and if no neighbor advertisement is returned, the address is considered unique.
After a host has generated an IPv6 address by using the DHCPv6 or SLAAC process, how does the host verify that the address is unique and therefore usable? The host sends an ICMPv6 echo request message to the DHCPv6 or SLAAC-learned address and if no reply is returned, the address is considered unique. The host sends an ICMPv6 neighbor solicitation message to the DHCP or SLAAC-learned address and if no neighbor advertisement is returned, the address is considered unique. The host checks the local neighbor cache for the learned address and if the address is not cached, it it considered unique. The host sends an ARP broadcast to the local link and if no hosts send a reply, the address is considered unique.
Check the routing table for a missing static route.
An administrator notices that large numbers of packets are being dropped on one of the branch routers. What should be done or checked? Create static routes to all internal networks and a default route to the internet. Create extra static routes to the same location with an AD of 1. Check the statistics on the default route for oversaturation. Check the routing table for a missing static route.
Use the "show ip interface brief" command to see if an interface is down.
Employees are unable to connect to servers on one of the internal networks. What should be done or checked? Use the "show ip interface brief" command to see if an interface is down. Verify that there is not a default route in any of the edge router routing tables. Create static routes to all internal networks and a default route to the internet. Check the statistics on the default route for oversaturation.
when packets are being dropped from a particular directly attached host
In which situation would a technician use the show interfaces switch command? to determine if remote access is enabled when packets are being dropped from a particular directly attached host when an end device can reach local devices, but not remote devices to determine the MAC address of a directly attached network device on a particular interface
WLANs
On a Cisco 3504 WLC Summary page ( Advanced > Summary ), which tab allows a network administrator to configure a particular WLAN with a WPA2 policy? WLANs SECURITY WIRELESS MANAGEMENT
Check the statistics on the default route for oversaturation.
Users are complaining of sporadic access to the internet every afternoon. What should be done or checked? Create static routes to all internal networks and a default route to the internet. Verify that there is not a default route in any of the edge router routing tables. Create a floating static route to that network. Check the statistics on the default route for oversaturation.
Verify that the static route to the server is present in the routing table.
Users on a LAN are unable to get to a company web server but are able to get elsewhere. What should be done or checked? Ensure that the old default route has been removed from the company edge routers. Verify that the static route to the server is present in the routing table. Check the configuration on the floating static route and adjust the AD. Create a floating static route to that network.
It sends a DHCPREQUEST that identifies which lease offer the client is accepting.
What action does a DHCPv4 client take if it receives more than one DHCPOFFER from multiple DHCP servers? It sends a DHCPREQUEST that identifies which lease offer the client is accepting. It sends a DHCPNAK and begins the DHCP process over again. It discards both offers and sends a new DHCPDISCOVER. It accepts both DHCPOFFER messages and sends a DHCPACK.
The switch will forward the frame out all ports except the incoming port.
What action takes place when a frame entering a switch has a unicast destination MAC address that is not in the MAC address table? The switch updates the refresh timer for the entry. The switch resets the refresh timer on all MAC address table entries. The switch replaces the old entry and uses the more current port. The switch will forward the frame out all ports except the incoming port.
The switch replaces the old entry and uses the more current port.
What action takes place when the source MAC address of a frame entering a switch appears in the MAC address table associated with a different port? The switch purges the entire MAC address table. The switch replaces the old entry and uses the more current port. The switch updates the refresh timer for the entry. The switch forwards the frame out of the specified port.
The switch updates the refresh timer for the entry.
What action takes place when the source MAC address of a frame entering a switch is in the MAC address table? The switch forwards the frame out of the specified port. The switch updates the refresh timer for the entry. The switch replaces the old entry and uses the more current port. The switch adds a MAC address table entry for the destination MAC address and the egress port.
The switch adds the MAC address and incoming port number to the table.
What action takes place when the source MAC address of a frame entering a switch is not in the MAC address table? The switch adds a MAC address table entry for the destination MAC address and the egress port. The switch adds the MAC address and incoming port number to the table. The switch replaces the old entry and uses the more current port. The switch updates the refresh timer for the entry.
Enable trunking manually Disable DTP. Set the native VLAN to an unused VLAN.
What are three techniques for mitigating VLAN attacks? (Choose three.) Use private VLANs. Enable BPDU guard. Enable trunking manually Enable Source Guard. Disable DTP. Set the native VLAN to an unused VLAN.
- to enhance user bandwidth - to isolate traffic between segments
What are two reasons a network administrator would segment a network with a Layer 2 switch? (Choose two.) to create fewer collision domains to enhance user bandwidth to create more broadcast domains to eliminate virtual circuits to isolate traffic between segments to isolate ARP request messages from the rest of the network
fast internal switching large frame buffers
What are two switch characteristics that could help alleviate network congestion? (Choose two.) fast internal switching large frame buffers store-and-forward switching low port density frame check sequence (FCS) check
the ipv6 unicast-routing command
What command will enable a router to begin sending messages that allow it to configure a link-local address without using an IPv6 DHCP server? a static route the ipv6 route ::/0 command the ipv6 unicast-routing command the ip routing command
An IPv4 static host route configuration uses a destination IP address of a specific device and a /32 subnet mask.
What defines a host route on a Cisco router? The link-local address is added automatically to the routing table as an IPv6 host route. An IPv4 static host route configuration uses a destination IP address of a specific device and a /32 subnet mask. A host route is designated with a C in the routing table. A static IPv6 host route must include the interface type and the interface number of the next hop router.
interface number and type
What else is required when configuring an IPv6 static route using a next-hop link-local address? administrative distance ip address of the neighbor router network number and subnet mask on the interface of the neighbor router interface number and type
User accounts must be configured locally on each device, which is an unscalable authentication solution.
What is a drawback of the local database method of securing device access that can be solved by using AAA with centralized servers? There is no ability to provide accountability. User accounts must be configured locally on each device, which is an unscalable authentication solution. It is very susceptible to brute-force attacks because there is no username. The passwords can only be stored in plain text in the running configuration.
The size of the broadcast domain is increased.
What is a result of connecting two or more switches together? The number of broadcast domains is increased. The size of the broadcast domain is increased. The number of collision domains is reduced. The size of the collision domain is increased.
PVST+ optimizes performance on the network through load sharing.
What is an advantage of PVST+? PVST+ optimizes performance on the network through autoselection of the root bridge. PVST+ reduces bandwidth consumption compared to traditional implementations of STP that use CST. PVST+ requires fewer CPU cycles for all the switches in the network. PVST+ optimizes performance on the network through load sharing.
It checks the source L2 address in the Ethernet header against the sender L2 address in the ARP body.
What is the effect of entering the ip arp inspection validate src-mac configuration command on a switch? It checks the source L2 address in the Ethernet header against the sender L2 address in the ARP body. It disables all trunk ports. It displays the IP-to-MAC address associations for switch interfaces. It enables portfast on a specific switch interface.
It enables DAI on specific switch interfaces previously configured with DHCP snooping.
What is the effect of entering the ip arp inspection vlan 10 configuration command on a switch? It specifies the maximum number of L2 addresses allowed on a port. It enables DAI on specific switch interfaces previously configured with DHCP snooping. It enables DHCP snooping globally on a switch. It globally enables BPDU guard on all PortFast-enabled ports.
It enables DHCP snooping globally on a switch.
What is the effect of entering the ip dhcp snooping configuration command on a switch? It enables DHCP snooping globally on a switch. It enables PortFast globally on a switch. It disables DTP negotiations on trunking ports. It manually enables a trunk link.
It displays the IP-to-MAC address associations for switch interfaces.
What is the effect of entering the show ip dhcp snooping binding configuration command on a switch? It switches a trunk port to access mode. It checks the source L2 address in the Ethernet header against the sender L2 address in the ARP body. It restricts the number of discovery messages, per second, to be received on the interface. It displays the IP-to-MAC address associations for switch interfaces.
It disables DTP on a non-trunking interface.
What is the effect of entering the switchport mode access configuration command on a switch? It enables BPDU guard on a specific port. It manually enables a trunk link. It disables an unused port. It disables DTP on a non-trunking interface.
It enables port security on an interface.
What is the effect of entering the switchport port-security configuration command on a switch? It dynamically learns the L2 address and copies it to the running configuration. It enables port security on an interface. It enables port security globally on the switch. It restricts the number of discovery messages, per second, to be received on the interface.
WPA2 Enterprise
What method of wireless authentication is dependent on a RADIUS authentication server? WEP WPA Personal WPA2 Personal WPA2 Enterprise
Enable port security.
What mitigation plan is best for thwarting a DoS attack that is creating a MAC address table overflow? Disable DTP. Disable STP. Enable port security. Place unused ports in an unused VLAN.
DHCP starvation
What network attack seeks to create a DoS for clients by preventing them from being able to obtain a DHCP lease? IP address spoofing DHCP starvation CAM table attack DHCP spoofing
VTP
What protocol or technology requires switches to be in server mode or client mode? EtherChannel STP VTP DTP
EtherChannel
What protocol or technology uses source IP to destination IP as a load-balancing mechanism? VTP EtherChannel DTP STP
DTP
What protocol should be disabled to help mitigate VLAN attacks? CDP ARP STP DTP
Dynamic ARP Inspection
Which Cisco solution helps prevent ARP spoofing and ARP poisoning attacks? Dynamic ARP Inspection IP Source Guard DHCP Snooping Port Security
broadcast DHCPREQUEST
Which DHCPv4 message will a client send to accept an IPv4 address that is offered by a DHCP server? broadcast DHCPACK broadcast DHCPREQUEST unicast DHCPACK unicast DHCPREQUEST
enabling DHCPv6 Guard
Which mitigation technique would prevent rogue servers from providing false IPv6 configuration parameters to clients? enabling DHCPv6 Guard enabling RA Guard implementing port security on edge ports disabling CDP on edge ports
SSH
Which protocol adds security to remote connections? FTP HTTP NetBEUI POP SSH
authenticator
Which term describes the role of a Cisco switch in the 802.1X port-based access control? agent supplicant authenticator authentication server
dynamic desirable - dynamic desirable dynamic desirable - trunk dynamic desirable - dynamic auto
Which three pairs of trunking modes will establish a functional trunk link between two Cisco switches? (Choose three.) dynamic desirable - dynamic desirable dynamic desirable - trunk dynamic auto - dynamic auto access - dynamic auto dynamic desirable - dynamic auto access - trunk
An autonegotiation failure can result in connectivity issues. When the speed is set to 1000 Mb/s, the switch ports will operate in full-duplex mode. The duplex and speed settings of each switch port can be manually configured.
Which three statements accurately describe duplex and speed settings on Cisco 2960 switches? (Choose three.) An autonegotiation failure can result in connectivity issues. When the speed is set to 1000 Mb/s, the switch ports will operate in full-duplex mode. The duplex and speed settings of each switch port can be manually configured. Enabling autonegotiation on a hub will prevent mismatched port speeds when connecting the hub to the switch.
RSTP STP
Which two types of spanning tree protocols can cause suboptimal traffic flows because they assume only one spanning-tree instance for the entire bridged network? (Choose two.) MSTP RSTP Rapid PVST+ PVST+ STP