CCNA 2 CHAPTER 2 STUDYGUIDE
Which protocol or service sends broadcasts containing the Cisco IOS software version of the sending device, and the packets of which can be captured by malicious hosts on the network? DNS CDP DHCP SSH
CDP*
What is step 6 of the switch boot sequence description?
transfer switch control to the IOS
Match the Link State to the interface and protocol status. Layer 2 problem
up/disabled
Open the PT Activity. Perform the tasks in the activity instructions and then answer the question. Fill in the blank. Do not use abbreviations. What is the missing command on S1?
" ip address 192.168.99.2 255.255.255.0 " The ip address 192.168.99.2 255.255.255.0 command is missing on interface vlan 99, the management VLAN.
R1# show interfaces fastEthernet 0/0 <output omitted> MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec, reliability 255/255, txload 1/255, rxload 1/255 Encapsulation ARPA, loopback not set Keepalive set (10 sec) Full-duplex 100 Mb/s, media type is RJ45 Last clearing of "show interface" counters never Input queue: 0/75/0 (size/max/drops); Total output drops: 0 Output queue: 0/40 (size/max) 5 minute input rate 54 bits/sec, 0 packets/sec 5 minute output rate 54 bits/sec. 0 packets/sec 294 packets input, 20208 bytes, 0 no bugger 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort, Received 0 broadcasts, 0 runts, 50 giants, 0 throttles, 0 input packets with dribble condition detected 294 packets output, 20072 bytes, 0 underruns 0 output errors, 25 collisions, 1 interface resets, Refer to the exhibit. A network technician is troubleshooting connectivity issues in an Ethernet network with the command show interfaces fastEthernet 0/0. What conclusion can be drawn based on the partial output in the exhibit? All hosts on this network communicate in full-duplex mode. There are collisions in the network that cause frames to occur that are less than 64 bytes in length. A malfunctioning NIC can cause frames to be transmitted that are longer than the allowed maximum length. Some workstations might use an incorrect cabling type to connect to the network.
A malfunctioning NIC can cause frames to be transmitted that are longer than the allowed maximum length. *
What is step 3 of the switch boot sequence description?
CPU register intializations
Identify the third step to configure a switch for SSH
Configure a domain name
Identify the first step to configure a switch for SSH
Create a local user
In which type of attack does a malicious node request all available IP addresses in the address pool of a DHCP server in order to prevent legitimate hosts from obtaining network access? CAM table overflow DHCP starvation MAC address flooding DHCP snooping
DHCP starvation*
Which two statements are true regarding switch port security? (Choose two.) The three configurable violation modes all require user intervention to re-enable ports. The three configurable violation modes all log violations via SNMP. After entering the sticky parameter, only MAC addresses subsequently learned are converted to secure MAC addresses. Dynamically learned secure MAC addresses are lost when the switch reboots. If fewer than the maximum number of MAC addresses for a port are configured statically, dynamically learned addresses are added to CAM until the maximum number is reached.
Dynamically learned secure MAC addresses are lost when the switch reboots.* If fewer than the maximum number of MAC addresses for a port are configured statically, dynamically learned addresses are added to CAM until the maximum number is reached.*
What is step 1 of the switch boot sequence description?
Execute Post
__________________________ communication allows both ends of a connection to transmit and receive data simultaneously.
Full-Duplex Full-Duplex communication improves the performance of a switched LAN, increasing effective bandwidth by allowing both ends of a connection to transmit and receive data simultaneously
Identify the second step to configure a switch for SSH
Generate RSA keys
Which statement describes the port speed LED on the Cisco Catalyst 2960 switch? If the LED is off, the port is not operating. If the LED is blinking green, the port is operating at 10 Mb/s. If the LED is green, the port is operating at 100 Mb/s. If the LED is amber, the port is operating at 1000 Mb/s.
If the LED is green, the port is operating at 100 Mb/s.*
Which action will bring an error-disabled switch port back to an operational state? Issue the switchport mode access command on the interface. Remove and reconfigure port security on the interface. Clear the MAC address table on the switch. Issue the shutdown and then no shutdown interface commands.
Issue the shutdown and then no shutdown interface commands.*
Switch1 (config)# ip ssh version 2 Switch1 (config)# ip domain-name cisco.com Switch1 (config)# crypto key generate rsa Switch1 (config)# line vty 0-15 Switch1 (config-line)# transport input all Refer to the exhibit. The network administrator wants to configure Switch1 to allow SSH connections and prohibit Telnet connections. How should the network administrator change the displayed configuration to satisfy the requirement? Reconfigure the RSA key. Configure SSH on a different line. Use SSH version 1. Modify the transport input command.
Modify the transport input command.*
A production switch is reloaded and finishes with a Switch> prompt. What two facts can be determined? (Choose two.) There is not enough RAM or flash on this router. The switch did not locate the Cisco IOS in flash, so it defaulted to ROM. A full version of the Cisco IOS was located and loaded. The boot process was interrupted. POST occurred normally.
POST occurred normally.* A full version of the Cisco IOS was located and loaded.*
s1# show port-security: Secure Port: Fa0/1 MaxSecureAddr(count): 2 CurrAddr(Count): 0 SecurityViolation (Count): 0 Security Action: Protect Refer to the exhibit. Which event will take place if there is a port security violation on switch S1 interface Fa0/1? A notification is sent The interface will go into error-disabled state. A syslog message is logged. Packets with unknown source addresses will be dropped
Packets with unknown source addresses will be dropped
Which three statements are true about using full-duplex Fast Ethernet? (Choose three.) Performance is improved with bidirectional data flow. Performance is improved because the NIC is able to detect collisions. Latency is reduced because the NIC processes frames faster. Full-duplex Fast Ethernet offers 100 percent efficiency in both directions. Nodes operate in full-duplex with unidirectional data flow. Performance is improved because the collision detect function is disabled on the device.
Performance is improved with bidirectional data flow. Full-duplex Fast Ethernet offers 100 percent efficiency in both directions. Performance is improved because the collision detect function is disabled on the device.
Which two statements are true about using full-duplex Fast Ethernet? Performance is improved with bidirectional data flow. Latency is reduced because the NIC processes frames faster. Nodes operate in full-duplex with unidirectional data flow. Performance is improved because the NIC is able to detect collisions. Full-duplex Fast Ethernet offers 100 percent efficiency in both directions.
Performance is improved with bidirectional data flow.* Full-duplex Fast Ethernet offers 100 percent efficiency in both directions.*
Refer to the exhibit. Port Fa0/2 has already been configured appropriately. The IP phone and PC work properly. Which switch configuration would be most appropriate for port Fa0/2 if the network administrator has the following goals? No one is allowed to disconnect the IP phone or the PC and connect some other wired device. If a different device is connected, port Fa0/2 is shut down. The switch should automatically detect the MAC address of the IP phone and the PC and add those addresses to the running configuration. SWA(config-if)# switchport port-security SWA(config-if)# switchport port-security maximum 2 SWA(config-if)# switchport port-security mac-address sticky SWA(config-if)# switchport port-security SWA(config-if)# switchport port-security maximum 2 SWA(config-if)# switchport port-security mac-address sticky SWA(config-if)# switchport port-security violation restrict SWA(config-if)# switchport port-security mac-address sticky SWA(config-if)# switchport port-security maximum 2 SWA(config-if)# switchport port-security SWA(config-if)# switchport port-security mac-address sticky
SWA(config-if)# switchport port-security SWA(config-if)# switchport port-security maximum 2 SWA(config-if)# switchport port-security mac-address sticky
What is one difference between using Telnet or SSH to connect to a network device for management purposes? Telnet uses UDP as the transport protocol whereas SSH uses TCP. Telnet supports a host GUI whereas SSH only supports a host CLI. Telnet does not provide authentication whereas SSH provides authentication. Telnet sends a username and password in plain text, whereas SSH encrypts the username and password.
Telnet sends a username and password in plain text, whereas SSH encrypts the username and password.*
While troubleshooting a connectivity problem, a network administrator notices that a switch port status LED is alternating between green and amber. What could this LED indicate? A PC is using the wrong cable to connect to the port. The port has an active link with normal traffic activity. The port is administratively down. The port has no link. The port is experiencing errors.
The port is experiencing errors.*
ATC_S2# show port-security interface fastethernet 0/3 Port Security : Enabled Port Status : Secure-up Violation Mode : Shutdown Aging Time : 0 mins Aging Type : Absolute SecureStatic Address Aging : Disabled Maximum MAC Addresses : 2 Total MAC Addresses : 1 Configured MAC Addresses : 0 Sticky MAC Addresses :1 Last Source Address: Vlan 00D0: D3B6:C26B:10 Security Violation Count :044 Refer to the exhibit. What can be determined about port security from the information that is shown? The port has been shut down. The port has the maximum number of MAC addresses that is supported by a Layer 2 switch port which is configured for port security. The port violation mode is the default for any port that has port security enabled. The port has two attached devices.
The port violation mode is the default for any port that has port security enabled.*
Switch: Show interface fa0/1 FastEthernet0/1 is up, line protocol is up (connected) Hardware is Lance, address is 0050.0f29.2601 (bia 0050.0f29.2601) BW 100000 Kbit DLY 1000 usec, reliability 255/255. txload 1/255, rxload 1/255 <output omitted> Queueing strategy fifo Output queue: 0/40 (size/max) 5 minute input rate 0 bits/sec, 0 packets/sec 5 minute output rate 0 bits/sec, 0 packets/sec 956 packets input, 193351 bytes, 0 no buffer Received 956 broadcasts, 0 runts, 0 giants, 0 throttles 0 input errors, 15890 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort 0 watchdog, 0 multicast, 0 pause input 0 input packets with dribble condition detected 2357 packets output, 263570 bytes, 0 underruns Refer to the exhibit. What media issue might exist on the link connected to Fa0/1 based on the show interface command? The interface might be configured as half-duplex. The bandwidth parameter on the interface might be too high. There could be too much electrical interference and noise on the link. The cable attaching the host to port Fa0/1 might be too long. There could be an issue with a faulty NIC.
There could be too much electrical interference and noise on the link.*
Identify the fourth step needed to configure a switch for SSH
Use the login local command
Identify the last step needed to configure a switch for SSH
Use the transport input ssh command
The network administrator enters the following commands on a Cisco switch: Switch(config)# interface vlan1 Switch(config-if)# ip address 192.168.1.2 255.255.255.0 Switch(config-if)# no shutdown What is the effect of entering these commands? The address of the default gateway for this LAN is 192.168.1.2/24. Users on the 192.168.1.0/24 subnet are able to ping the switch at IP address 192.168.1.2. All devices attached to this switch must be in the 192.168.1.0/24 subnet to communicate. The switch is able to forward frames to remote networks.
Users on the 192.168.1.0/24 subnet are able to ping the switch at IP address 192.168.1.2.*
Which interface is the default location that would contain the IP address used to manage a 24-port Ethernet switch? VLAN 1 VLAN 99 Fa0/0 Fa0/1 interface connected to the default gateway
VLAN 1*
Which type of cable does a network administrator need to connect a PC to a switch to recover it after the Cisco IOS software fails to load? a coaxial cable a crossover cable a straight-through cable a console cable
a console cable*
Match the Link State to the interface and protocol status. disabled
administratively down
What impact does the use of the mdix auto configuration command have on an Ethernet interface on a switch? automatically assigns the first detected MAC address to an interface automatically detects duplex settings automatically detects copper cable type automatically detects interface speed
automatically detects copper cable type*
Which method would mitigate a MAC address flooding attack? using ACLs to filter broadcast traffic on the switch increasing the speed of switch ports increasing the size of the CAM table configuring port security
configuring port security*
Match the Link State to the interface and protocol status. Layer 1 problem
down/down
What is step 4 of the switch boot sequence description?
flash file system initialization
What is step 5 of the switch boot sequence description?
load the IOS
What is step 2 of the switch boot sequence description?
load the boot loader from ROM
Refer to the exhibit. Which S1 switch port interface or interfaces should be confgured with the ip dhcp snooping trust command if best practices are implemented? only the G0/1 and G0/24 ports only unused ports only the G0/2, G0/3, and G0/4 ports only the G0/1 port only the G0/1, G0/2, G0/3, and G0/4 ports
only the G0/1 and G0/24 ports*
Which two features on a Cisco Catalyst switch can be used to mitigate DHCP starvation and DHCP spoofing attacks? (Choose two.) port security DHCP snooping extended ACL strong password on DHCP servers DHCP server failover
port security* DHCP snooping*
A network administrator configures the port security feature on a switch. The security policy specifies that each access port should allow up to two MAC addresses. When the maximum number of MAC addresses is reached, a frame with the unknown source MAC address is dropped and a notification is sent to the syslog server. Which security violation mode should be configured for each access port? warning protect shutdown restrict
restrict*
Which two basic functions are performed by network security tools? (Choose two.) writing a security policy document for protecting networks controlling physical access to user devices revealing the type of information an attacker is able to gather from monitoring network traffic simulating attacks against the production network to determine any existing vulnerabilities educating employees about social engineering attacks
revealing the type of information an attacker is able to gather from monitoring network traffic* simulating attacks against the production network to determine any existing vulnerabilities*
Which command displays information about the auto-MDIX setting for a specific interface? show interfaces show processes show running-config show controllers
show controllers*
When port security is enabled, a switch port uses the default violation mode of " __________________ " until specifically configured to use a different violation mode.
shutdown If no violation mode is specified when port security is enabled on a switch port, then the security violation mode defaults to shutdown.
An administrator wants to use a network security auditing tool on a switch to verify which ports are not protected against a MAC flooding attack. For the audit to be successful, what important factor must the administrator consider? if the number of valid MAC addresses and spoofed MAC addresses is the same if the CAM table is empty before the audit is started if all the switch ports are operational at the same speed the aging-out period of the MAC address table
the aging-out period of the MAC address table
What is a function of the switch boot loader? to provide security for the vulnerable state when the switch is booting to control how much RAM is available to the switch during the boot process to speed up the boot process to provide an environment to operate in when the switch operating system cannot be found
to provide an environment to operate in when the switch operating system cannot be found*
Match the Link State to the interface and protocol status. operational
up/down
In which situation would a technician use the show interfaces switch command? when packets are being dropped from a particular directly attached host when an end device can reach local devices, but not remote devices to determine the MAC address of a directly attached network device on a particular interface to determine if remote access is enabled
when packets are being dropped from a particular directly attached host*