+ All Categories
Home > Documents > 2º Exam

2º Exam

Date post: 27-Nov-2014
Category:
Upload: serg911
View: 7,690 times
Download: 0 times
Share this document with a friend
58
2º Exam (+ solutions): 1 What are two limitations of an ad hoc troubleshooting approach? (Choose two.) x inefficient use of time and resources only applicable to physical layer problems x difficult to transfer the job to someone else can only be used after a structured approach has failed requires more technical knowledge than a structured approach 2 What are two facts regarding the information that is collected for baseline creation? (Choose two.) The information is the same for all networks. x It can be used for capacity planning. It should be limited to only a few key performance statistics. x It can be collected using tools such as NBAR, NetFlow, and SNMP. It should be collected only once and then archived for future reference. 3 After a proposed solution has been implemented, the network administrator realizes that new problems have been introduced by the changes. What is the next step in the troubleshooting process? Propose a hypothesis. x Execute the rollback plan. Determine an appropriate workaround. Escalate the problem to another department. 4 A network engineer initially uses the ping command to help troubleshoot a connection problem. Which troubleshooting approach best describes this scenario? bottom-up approach x divide-and-conquer approach follow-the-path approach
Transcript
Page 1: 2º Exam

2º Exam (+ solutions):

1 What are two limitations of an ad hoc troubleshooting approach? (Choose two.)x inefficient use of time and resourcesonly applicable to physical layer problemsx difficult to transfer the job to someone elsecan only be used after a structured approach has failedrequires more technical knowledge than a structured approach

2 What are two facts regarding the information that is collected for baseline creation? (Choose two.)The information is the same for all networks.x It can be used for capacity planning.It should be limited to only a few key performance statistics.x It can be collected using tools such as NBAR, NetFlow, and SNMP.It should be collected only once and then archived for future reference.

3 After a proposed solution has been implemented, the network administrator realizes that new problems have been introduced by the changes. What is the next step in the troubleshooting process?Propose a hypothesis.x Execute the rollback plan.Determine an appropriate workaround.Escalate the problem to another department.

4 A network engineer initially uses the ping command to help troubleshoot a connection problem. Which troubleshooting approach best describes this scenario?bottom-up approachx divide-and-conquer approachfollow-the-path approachmove-the-problem approachspot-the-difference approachtop-down approach

5 What is a situation where escalation of an issue is inadvisable?Management has not been consulted.x Escalation will slow the procedure.The problem is actually a set of problems.The problem has an impact on the performance of the entire network.

Page 2: 2º Exam

Solving the problem would showcase the skills and knowledge of the troubleshooter.

6 To correct an issue that was discovered a few days earlier, an administrator makes a change during a regularly scheduled maintenance window. After making the change, the administrator discovers that a new problem has occurred. What should the administrator do next?x Rollback the change and resume the troubleshooting process.Continue making changes until the symptoms disappear.Leave the change in place and troubleshoot the new problems at a later time.Gather information about the new problem and form a new hypothesis.

7 Which three types of data are useful for creating a baseline? (Choose three.)number of infrastructure routers and switchesx Remote Monitoring (RMON), Network Based Application Recognition (NBAR), and NetFlow statisticsDHCP and NAT translation statisticsx network performance characteristicsswitch interface statistics of all access portsx basic performance statistics like the interface load for critical network links and the CPU load and memory usage of routers and switches

8 After a network change that occurred during a scheduled maintenance window, users were complaining about not being able to access a local file server. Upon investigation, the administrator determined that the problem was with the recently entered routing configurations. Because of company policy, the administrator is not allowed to correct the routing configuration outside of a scheduled maintenance window. Instead, the administrator moved the file server to an accessible subnet. Which statement describes what the administrator did?The administrator determined a solution to the problem.x The administrator determined a workaround for the problem.The administrator applied the "move the problem" troubleshooting approach.The administrator applied the "spot the difference" troubleshooting approach.

9 Which three IOS features can be used to keep the network documentation accurate? (Choose three.)x rollback featurepolicy compliancex configuration archiveperformance monitoringbasic performance statisticsx Embedded Event Manager

Page 3: 2º Exam

10 A network administrator executes the show processes cpu command on a production router and notices that the average CPU load over the past 5 seconds was 97% and over the last one minute was around 39%. What should the administrator do next?Nothing. This is normal behavior for an ISR router.Contact the service provider because the contract is not being fulfilled as specified in the SLA.x Compare the result to the baseline for an accurate assessment.Replace the router as soon as possible because it has reached capacity.

11 Which two procedures can be implemented to ensure that current backups of all device configurations are maintained? (Choose two.)x Log all configuration change events to a syslog server.Password protect all devices to prevent configuration changes.x Implement a system to create automatic configuration backups.Update configuration backups only after major network outages.Create configuration backups as soon as an issue is reported with network performance.

12 A user creates a trouble ticket indicating that the Internet is inaccessible. The network administrator receives the ticket and determines that this user is the only one having problems. A ping command issued from the administrative PC to the user PC is successful. What should the administrator do next?x Escalate the issue to the desktop support group.Contact the ISP to determine if there is an issue on the ISP side.View the route table on the core router to determine if there is a routing issue.Swap out the patch cable between the user PC and the switch to determine if that solves the problem.

13 What is a symptom of an incorrectly applied network command when issued under the routing process?a down status on an interfacex a timeout message when attempting to ping a device on another networka routing protocol that is not runninga user who is unable to connect to machines that are located on the same subnet

14 Which two components are normally considered part of change control? (Choose two.)the cost of network changesx the time when changes can be madethe technology that is used to implement changesx the authorization that is required to make changesthe staff changes that are required to carry out repairs

Page 4: 2º Exam

15 In which phase of the structured troubleshooting process should a network administrator clearly communicate to the affected network users what is going to be done and why it is being done?the analysis of informationthe definition of the problemthe elimination of possibilitiesthe gathering of factsx the proposal and testing of a hypothesis

16 What is a benefit of change control during the processes of regular network maintenance?simplification of the process for creating a network baselinex reduction in the frequency and duration of unplanned outageselimination of the need to troubleshoot planned outageselimination of the need to perform a regular network backup

17 In which structured troubleshooting process phase would a network engineer ask questions such as "When did it last work?" or "Has it ever worked?"analyze information phasex define the problem phaseeliminate possibilities phasegather facts phasepropose a hypothesis phasesolve the problem phase

18 What is an important element of troubleshooting, regardless of the method used?using a single troubleshooting processexecuting the steps in the same order every timex following a structured and systematic processspending a significant amount of time analyzing the information

19 The help desk receives several calls on Monday morning stating that users cannot connect to a local print server that was working on Friday. Which statement about the problem would be correct?x The inability to connect to the print server is a symptom of a problem.The inability to connect to the print server is the problem.The connectivity problem occurred Monday morning.The inability to connect to the print server caused the problem.

20

Page 5: 2º Exam

What type of information can be gathered by using SNMP during the process of collecting baseline information?basic performance statistics via the use of show commandsbasic performance statistics for Layer 2 and Layer 3 protocolsx basic performance statistics about the interface load for critical network linksbasic performance statistics to profile different types of traffic on the network

-- Chapter 5º -------------------------------------------------------------------------------------------------------------------------------------------------

5º Exam (+ solutions):(Pictures posted on the comment secction)

1 Refer to the exhibit. A network administrator wants to load-balance the traffic that is coming from the LAN that is attached to router R1 and going to the 10.10.10.0/24 network. The output from the routing table on R1 reveals that the traffic is flowing through router R3 only. What is the reason for this traffic behavior?x RIP redistribution into the EIGRP routing process is not performed on R4.EIGRP does not load-balance automatically over equal-cost paths.A variance command is missing under the EIGRP configuration on R3 and R4.The seed metrics should be configured with the default metrics command under the EIGRP process on R3.The passive-interface default command on R4 is blocking the RIP updates that are being propagated into the EIGRP routing domain.

2 Refer to the exhibit. A network administrator first issued the show ip route command and then decided to filter the output of the routing table via the show ip route 128.0.0.0 128.0.0.0 longer-prefixes command. Which prefixes will be displayed in the output?all IP prefixesIP prefixes 10.10.1.0 and 10.134.2.0x IP prefixes 172.16.30.0 and 172.30.40.0IP prefixes 10.10.1.0, 10.129.30.0, 10.134.2.0, and 10.230.40.0

3 What occurs immediately following the encapsulation of data into IP packets during the transmission of data between source and destination hosts?

Page 6: 2º Exam

The source host sends the packet to the default gateway address.An ARP request is made to determine the MAC address of the destination host.x The source host determines if the destination network is the same or different from its own local subnet.The sending host encapsulates the data into a frame addressed to the MAC address of the destination host.The routing table is consulted to determine which interface to forward the packet through based on the longest prefix match.

4 [Picture 8º]Refer to the exhibit. A network administrator uses the output of the show ip cef exact-route command to verify the routing operations. Which statement represents the information that the network administrator will gather from the output?Traffic that is sourced from 172.17.249.252 will use 192.168.49.252 as a next hop.The destination 172.17.249.252 can be reached via the next hop address 10.10.10.1.The destination 10.10.10.1 can be reached via the next hop address 172.17.249.252.x Traffic that is sourced from 10.10.10.1 and destined to 172.17.249.252 will go out the FastEthernet1/0 interface.

5 Which data structure does an EIGRP enabled router use to track devices from which it receives EIGRP hello packets?Forwarding Information Baseinterface tablex neighbor tablerouting tabletopology table

6 [Picture 9º]Refer to the exhibit. A network administrator is troubleshooting a routing related problem. Which two facts can be concluded based on the generated output of the show logging command? (Choose two.)Interface Serial 0/1 has been incorrectly configured with IP address 192.168.2.2.x Interface Serial 0/1 is flapping.Router R1 has established a stable IBGP peering relationship with the neighbor at IP address 192.168.2.2.Router R1 has established a stable EBGP peering relationship with the neighbor at IP address 192.168.2.2.x Router R1 is unable to establish a stable BGP peering relationship with the neighbor at IP address 192.168.2.2.The BGP-5-ADJCHANGE message indicates an error with the subnet mask for the specified prefix.

Page 7: 2º Exam

7 Which two data structures are used by Cisco Express Forwarding to improve the performance of IP packet switching processes on routers? (Choose two.)x adjacency tablex Forwarding Information Baseinterface tableneighbor tablerouting tabletopology table

8 [Picture 5º]Refer to the exhibit. Mutual redistribution has been configured on router R7 between the OSPF and EIGRP routing processes. What could be the reason that EIGRP routes are not being properly redistributed into the OSPF process?The OSPF metric configuration is missing for the EIGRP routes that are redistributed into OSPF.x The subnets keyword configuration is missing for the EIGRP routes that are redistributed into OSPF.There is an incorrect EIGRP metric configuration for the OSPF routes that are redistributed into EIGRPThere is an incorrect external route type configuration for the EIGRP routes that are redistributed into OSPF.

9 [Picture 11º]Refer to the exhibit. In the show ip route output, what is the source of the 72.163.4.0 /24 route?It comes from a stub area router.It comes from a normal area router.x It comes from an area border router (ABR).It comes from an autonomous system border router (ASBR).

10 Which three pieces of information are found in the BGP neighbor table? (Choose three.)x the BGP router ID of any peerthe routes that are redistributed into BGPthe peer synchronization configurationx the number of exchanged prefixes with a neighborx the AS number of the peerthe IGP that is configured on the BGP peer

11 When route redistribution is being configured from another routing protocol into EIGRP, what value is used when no seed metric is configured?

Page 8: 2º Exam

a value equal to the minimum possible valuex a value equal to the maximum possible valuea value equal to the cost of a directly connected segmenta value equal to the redistributing protocol

12 [Picture 1º]Refer to the exhibit. Router RTA and router RTB have been configured to exchange routing information using OSPF. However, both routers never transition beyond 2WAY state. What is the cause of this problem?An access list on one side is blocking OSPF Hellos.Authentication is enabled on only one side.There is a switch problem and multicast capabilities are broken.x A priority of 0 has been configured on RTA and RTB interfaces.There is a misconfigured neighbor statement on RTA or RTB.

13 [Picture 3º]Refer to the exhibit. A network administrator is unable to have two BGP peers exchange routing information. Which solution would correct this problem?Router R1 should be configured with the neighbor 2.2.2.2 ebgp-multihop 1 command and R2 with the neighbor 1.1.1.1 ebgp-multihop 1 command.Router R1 should be configured with the neighbor 2.2.2.2 ebgp-multihop 3 command and R2 with the neighbor 1.1.1.1 ebgp-multihop 3 command.x Router R1 should be configured with the neighbor 2.2.2.2 remote-as 300 command.The loopback interfaces on each router should be removed.

14 A network administrator is adding a new router into an existing OSPF network and notices that the router is stuck in the INIT state. What is a possible cause of this problem?There is a mismatched interface MTU.x An access list is blocking OSPF hellos.Duplicate Router IDs are configured on the new router.Layer 2 switches between the two routers are not multicast aware.

15 A network administrator issued the show ip cef command to verify the routing operations on the device. Which table entries will be present in the output?the topology table entriesthe routing table entriesthe Routing Information Base (RIB) entriesx the Forwarding Information Base (FIB) entries

Page 9: 2º Exam

16 [Picture 2º]Refer to the exhibit. Based on the shown output, what is the resulting effect on the routing table?A route to the network 172.16.0.0 /30 will not be added to the routing table.A route to the network 172.16.0.0 /30 will be added to the routing table and have a metric of 1310720.A route to the network 172.16.0.0 /30 will be added to the routing table and have an administrative distance of 90.x A route to the network 172.16.0.0 /30 will be added to the routing table with an outbound interface of FastEthernet0/0.

17 [Picture 6º]Refer to the exhibit. What can be determined about the origin of the route to the 172.16.0.0 network?The route is manually entered.The route is directly connected to RouterHQ2.x The route is learned via redistribution into EIGRP.The route is summarized by EIGRP at the advertising router.

18 [Picture 4º]Refer to the exhibit. What is a possible reason that Router2 is not receiving OSPF routing updates on interface FastEthernet0/1?Interface FastEthernet0/1 is configured as passive for OSPF.The OSPF priority of interface FastEthernet0/1 is set to zero.OSPF is not enabled on the neighboring router that is connected to FastEthernet0/1.There is no OSPF network statement for the network to which interface FastEthernet0/1 belongs.

19 [Picture 10º]Refer to the exhibit. A network administrator is replacing an existing router and configuring EIGRP authentication on the Serial 0/0/0 port. When viewing the routing table, the administrator notices that the entries for the remote networks are not listed. The administrator enters the debug eigrp packet command and notices this output:R1# *Nov 17 01:26:31.935: EIGRP: Serial0/0/0: ignored packet from 172.20.1.2, opcode = 5 (authentication off or key-chain missing)Based on the information in the running configuration and the output from the debug command, what is a possible reason for the missing routes?Automatic summarization must be disabled.EIGRP is not enabled on the correct interface.An incorrect keychain name has been entered under the serial interface.x The EIGRP autonomous system does not match the interface authentication autonomous system.

Page 10: 2º Exam

20 What is the result of issuing the ip route profile command on a router?The router will log each route redistribution entry to the configured syslog server.x The router will track the number of routing table changes that occur over 5 second sampling intervals.The router will send console messages each time a route is installed or removed from the routing table.Until the buffer is full, the router will archive a copy of the routing table each time the topology changes.

---------------------------------------------------------------------------------- Chapter 6º -------------------------------------------------------------------------------------------------------------------------------------------------

6º Exam (+/- solutions):(Pictures posted on the comment secction)

1 Which statement is true about 6to4 tunneling and OSPF?The neighbor command must be specified within OSPF router configuration mode to establish the tunnel.The neighbor address must be specified on the tunnel interface.OSPF will automatically send out its link state database to the destination of the tunnel.x OSPF cannot be used when establishing a 6to4 tunnel.

2 [Picture X]Refer to the exhibit. Users on the LAN complained that they cannot access the resources on the network. A network administrator issued the debug ip udp command on R2 to verify the DHCP server operation. On the basis of the provided output, what could be the possible cause of the problem?x The ip dhcp pool command is missing from the R2 configuration.The ip helper-address command is missing from the R2 configuration.The ip dhcp excluded-addresses command is missing from the R2 configuration.The domain-name command is missing from the R3 configuration.

3 Which three UDP ports are associated with messages that are forwarded by default by a DHCP relay agent? (Choose three.)x 3751x 5359

Page 11: 2º Exam

x 6980

4 [Picture X]Refer to the exhibit. R2 is a branch router and accesses all nonlocal networks via R1. The network administrator is troubleshooting why router R2 cannot access any external networks. Based on the output of the commands, what is the likely issue?The default router for R1 is invalid.The IPv6 address configured for R1 is invalid.IPv6 unicast routing has not been enabled on R1.R2 has not been configured for autoconfiguration.

5 The network administrator changed the DHCP address pool from 10.10.0.0/16 to 10.20.0.0/16 and is now receiving complaints from users that they are unable to connect to the Internet. The administrator issues the command show ip nat translations on the border router and observes that there are no active translations present. The administrator then verifies that connectivity to the Internet from the border router is present. What should the administrator do next?Increase the size of the existing NAT pool.Create a new NAT pool using the 10.20.0.0/16 address space.Change from dynamic to static NAT for all outbound connections.x Verify that the ACL is selecting the correct addresses for translation.

6 [Picture X]Refer to the exhibit. A network administrator has configured a static NAT entry on router R1 for the internal web server. However, external users still cannot connect to the web server. Which procedure would resolve this problem?Delete the current static entry and issue the ip nat outside source static 10.0.0.10 209.165.200.226 command.x Delete the current static entry and issue the ip nat inside source static 10.1.1.10 209.165.200.226 command.For security reasons, an outside address cannot be mapped to an internal private address and therefore the web server should be configured with a valid public address.Remove the overload keyword from the ip nat inside source list command.

7 [Picture X]Refer to the exhibit. A network administrator created a static NAT translation. The purpose of the translation is to allow outside users to use the IP address 209.165.201.1 to connect to a server that is located on the internal network at IP address 172.16.6.3. However, users are unable to connect to the

Page 12: 2º Exam

server by using the supplied address. What is the most probable cause of the problem?There is no outside global address specified.The 172.16.0.0/16 network has not been advertised to the outside world.Dynamic NAT must be used to allow an outside user to connect to the server.x The network administrator reversed the addresses in the mapping command.No access list has been configured to select the traffic that is allowed to connect to the server.

8 Which statement correctly describes the problem when NAT and IPsec implementation coexist in the network?NAT changes the encryption keys that are used by IPsec during the key negotiation processes.x NAT changes the IP header fields, and those changes can conflict with the integrity of IPsec protocols.NAT changes the source and destination IP addresses that are encapsulated inside the IPsec packets.NAT changes the TCP and UDP transport protocols that are embedded in the payload of the IPsec packets.

9 [Picture X]Refer to the exhibit. Users on LAN_1 complained that they cannot communicate with the other users on the network. A network administrator issued show ip dhcp conflict command to verify the DHCP server operation on the router. Based on the provided outputs, what could be done to remedy the problem?Configure the DHCP pool for a larger scope of IP addresses.Issue the dhcp services command on router R2.Issue the ip helper-address command under the Fa0/1 interface.Configure the IP addresses that must be excluded from the DHCP pool.

10 [Picture X]Refer to the exhibit. Routers R1 and R2 cannot get DHCP addresses from router R3, which is configured as a DHCP server. After issuing the show ip socket command and troubleshooting the problem, a network administrator verifies that the R1 and R2 interfaces are up and operational. Based on the provided output, what could be the possible cause of the problem?x The DHCP services are disabled on R3.The IP helper address is missing from the R3 configuration.The IP addresses from the DHCP pool have been exhausted.Illegal addresses have been assigned to the interfaces of routers R1 and R2.

11 [Picture X]Refer to the exhibit. Which two statements are true about DHCP snooping on Switch2? (Choose two.)DHCP snooping is enabled for interface FastEthernet0/13 and interface FastEthernet0/14.x DHCP snooping is not enabled for interface FastEthernet0/15 and interface FastEthernet0/16.

Page 13: 2º Exam

x DHCP snooping is configured for VLAN 10.DHCP snooping is configured for VLAN 2.Any interface assigned to VLAN 10 could host a DHCP server.

12 [Picture X]Refer to the exhibit. A network administrator has configured NAT on router R1. However, R1 does not translate addresses when hosts from the 10.0.0.0 /24 LAN attempt to access the Internet. Which configuration change would correct this situation?Append the overload keyword to the ip nat inside source list 1 pool NATPOOL command.Change the NAT pool to be in the same subnet as the IP address of s0/0/0.Change the netmask of the NATPOOL to 255.255.255.224.Enter the no ip nat inside source static 10.0.0.10 209.165.200.226 command.x Make interface Fa0/0 the inside NAT interface and S0/0/0 the outside NAT interface.

13 [Picture X]Refer to the exhibit. Which statement accurately describes the IPv6 routing configuration?The command ipv6 route 5432::/48 null0 was entered on the router.The network 4000::2/128 was learned via a routing protocol.The command ipv6 route 5000::/64 null0 was entered on the router.The network 4001::1/128 is unreachable.

14 [Picture X]Refer to the exhibit. A network administrator configured an OSPF neighbor to correct a reachability issue in a network that is using OSPF over a 6to4 tunnel. The configuration did not solve the issue, and an error message was displayed. What should the administrator do to correct the problem?Change the version of OSPF to version 3.Add the ipv6 ospf network broadcast command to tunnel interface 0.Configure an OSPF neighbor on R2 that points to the tunnel endpoint of R1.x Configure static routes on both R1 and R2 to the IPv6 address of the tunnel endpoint of the neighbor.

15 [Picture X]Refer to the exhibit. Users on the LAN complained that they cannot access the Internet. Based on the provided output, what could be the possible cause of the problem?Too few addresses are assigned to the NAT pool.The NAT pool is configured with the wrong netmask.An incorrect ACL is referenced during the NAT translation process.The configurations for the inside and outside interfaces are reversed.

Page 14: 2º Exam

16 [Picture X]Refer to the exhibit. A network technician is having issues setting up router R4 in a IPv6 network. What problem is indicated from the router output?x IPv6 routing needs to be enabled.The interface also requires an IPv4 address.A routing protocol for IPv6 must be enabled.IPv4 routes should be redistributed into IPv6.

17 What are the three roles a router may assume with respect to DHCP? (Choose three.)x serverforwarderx clientremote agentx relay agentsupplicant

18 What are two things to be taken into consideration when NAT is configured in the network? (Choose two.)x the protocols that are used in the networkx the port numbers that are used by the applicationsthe type of interface that is configured for NATthe scope of the IP addresses that are configured in the NAT poolthe type of ACLs that are filtering the traffic from source to destination

19 [Picture X]Refer to the exhibit. A network administrator has implemented Network Address Translation (NAT) on router R1. However, hosts on the inside LAN cannot connect to addresses outside of the corporate network. Which option correctly identifies the problem?Interface Fa0/0 should be configured as the outside NAT interface and S0/0/0 as the inside NAT interface.NAT cannot use named access control lists.x The ACL is referring to the wrong internal network.The NAT-POOL should have included the S0/0/0 interface IP address.The overload keyword has not been appended to the ip nat inside source command.The static NAT entry IP address is not included in the NAT-POOL.

20 Which IPv6 address is used by OSPFv3 as a next hop?

Page 15: 2º Exam

x the link-local address of the neighborthe loopback address of the neighborthe global unicast address of the neighborthe default gateway of the neighbor

---------------------------------------------------------------------------------- Chapter 7º -------------------------------------------------------------------------------------------------------------------------------------------------

7º Exam (+/- solutions):(Pictures posted on the comment secction)

1A network administrator plans to implement QoS in the network by using the Cisco AutoQoS tool. What should be done in the first phase of the automation process? In order to apply QoS policies, each interface should be configured with the auto qos command. Cisco Express Forwarding should be disabled on each target interface by the use of the no ip cef command. x The network device should be configured to capture network traffic statistics via the use of the auto discovery qos interface configuration command. Via the use of the ip nbar protocol-discovery command, each interface should be configured to gather information about the applications that are known to NBAR.

2A network administrator has configured a Cisco IOS device to provide server load balancing (SLB) for the corporate web server. What is required on the client side to ensure proper load balancing? x Clients should initiate connections to the virtual IP address (VIP). Clients should initiate connections to the IP address of the predictor. Port numbers should be added to each client request in order to get routed to the correct server. Clients must be readdressed so that they are equally distributed throughout the network address space.

3What must a system administrator do to allow NBAR to recognize a new protocol without having to upgrade the Cisco IOS image? Enable the autodiscovery feature on the interface. Upgrade the version of NBAR that is running on the device. Because NBAR will automatically discover new applications, the administrator does not need to do anything. x Load an appropriate Packet Description Language Module (PDLM).

Page 16: 2º Exam

4Refer to the exhibit. A network administrator has noticed that the IP SLA probe did not run as expected. What should the administrator do to correct this problem? Adjust the clock frequency on R1. Configure the router as a stratum 1 time source. Remove the forever keyword from the configuration. x Configure NTP on the router to point to a different time source.

5Refer to the exhibit. A network administrator enables AutoQoS on a PPP link that is currently active. Once AutoQoS is enabled the link goes down. What should the administrator do to correct this problem? Disable multilink on the PPP connection. Decrease the multilink threshold value to allow AutoQoS to run. Change the encapsulation to HDLC because AutoQoS does not support PPP. x Investigate the configured bandwidth on the PPP link to ensure it is sufficient, then remove and reapply the AutoQoS configuration.

6Refer to the exhibit. A network administrator is investigating performance issues of the access switch. On the basis of the provided outputs, what conclusion can be made about the switch performance? The ratio between the FCS errors and the number of received errors is normal and does not require further investigation. The ratio between the FCS errors and the number of giant frames that are received on the switch is excessively high and requires further investigation. The ratio between the FCS errors and the number of broadcast and multicast traffic frames that are received on the switch is normal and does not require further investigation. x The ratio between the FCS errors and the number of unicast, broadcast, and multicast traffic frames that are received on the switch is excessively high and requires further investigation.

7A network is experiencing performance degradation on an access switch where user traffic is subject to granular QoS policy and security inspection. Which switch component or components should be inspected by the network administrator to help determine the issue? the ingress interfaces only the egress interfaces only the forwarding plane only the control plane only the forwarding plane and the control plane x the ingress and egress interfaces, the forwarding plane, and the control plane

Page 17: 2º Exam

8Refer to the exhibit. Users on the network are complaining that transferring large files to the SRV1 server takes hours. A network administrator runs a few tests on both switches to investigate the problem. On the basis of the provided outputs, what could be the possible reason for problem? High CPU utilization is causing excessive FCS errors on ASW_1. x A duplex mismatch is causing a high volume of late collisions on DSW_1. Slow STP convergence is causing a high volume of single collisions on DSW_1. An unsupported Auto-MDIX feature on both switches is causing a high volume of multi collisions.

9Which three hardware components are common in the architectures of all Catalyst switch families? (Choose three.) route processors modules x interfaces x forwarding hardware x control plane hardware content-addressable memory

10What reported error counter describes frames that do not end with an integral number of octets and have a bad cyclic redundancy check (CRC)? FCS-Err Xmit-Err x Align-Err Rcv-Err undersize runt

11What are three indicators of a cabling issue on a switch? (Choose three.) x alignment error excessive collisions giant frames x invalid frame size x late collisions transmit error

12Refer to the exhibit. What can be determined about the operation of interface FastEthernet 0/2? It is connected to a hub.

Page 18: 2º Exam

x It is operating within acceptable limits. It is carrying 802.1Q formatted frames. It has a duplex mismatch with the connected device.

13What can cause a memory leak on a router? x an IOS bug incorrect configuration registry code buffer overflow too many remote users logged into the router

14How can an administrator determine if a memory leak is present in a router? The show interface command will show that the input queue has reached the maximum capacity. The show buffers command will show no free buffers. x The show memory allocating-process totals command will show low free space. The show diagnostics command will show that the DRAM size has reached maximum capacity.

15Which three Cisco packet switching methods must a network administrator be familiar with in order to troubleshoot a router performance issue that is related to the switching path? (Choose three.) autonomous switching x Cisco Express Forwarding (CEF) x fast switching optimum switching x process switching silicon switching

16A network administrator wishes to use debug commands to observe how a router processes each individual packet on an interface. Which packet switching solution should be implemented on the interface to accomplish this task? Enable Cisco Express Forwarding (CEF) using the ip cef comand. Enable Cisco Express Forwarding (CEF) using the no ip cef command. Enable fast switching using the ip route-cache command. Enable fast switching using the no ip route-cache command. Enable process switching using the ip route-cache command. x Enable process switching using the no ip route-cache command.

17A network administrator wishes to use debug commands to observe how a router processes each individual packet on an interface. Which packet switching solution should be implemented on the

Page 19: 2º Exam

interface to accomplish this task? Enable Cisco Express Forwarding (CEF) using the ip cef comand. Enable Cisco Express Forwarding (CEF) using the no ip cef command. Enable fast switching using the ip route-cache command. Enable fast switching using the no ip route-cache command. Enable process switching using the ip route-cache command. x Enable process switching using the no ip route-cache command.

18Refer to the exhibit. A network administrator is troubleshooting the switching path on a router. Based on the exhibited output, what can be concluded? Cisco Express Forwarding (CEF) has been implemented. x Fast switching has been enabled. Process switching has been enabled. Switching has been disabled.

19A network administrator keeps receiving "%SYS-2-MALLOCFAIL" console messages. Further investigation reveals that the buffer pool continues to grow. The CCO knowledge base identified the cause of the problem as a result of a buffer memory leak due to an IOS software bug. What should the administrator do to rectify this problem? Reload the router. Reinstall older Cisco IOS software. x Upgrade the Cisco IOS software to a version that fixes the issue. Power down the router and wait a few minutes before reloading it. Change the configuration register settings to bypass the loading of the IOS. Change the configuration register settings to bypass the loading of the startup configuration file.

20Refer to the exhibit. Based on the output of the show interfaces command, which two statements are true? (Choose two.)

The interface is currently shutdown. x The interface is displaying symptoms of a buffer leak. x This is an example of a wedged interface. The interface has been configured with the no ip route-cache command. The serial interface is being subjected to a denial of service (DoS) attack.

8º Exam (+/- solutions):

Page 20: 2º Exam

(Pictures posted on the comment secction)

TSHOOT v6.0 Chapter 8

1A network technician is adding a wireless access point to an existing network. However, the wireless clients will not associate with the AP. What action can be taken to isolate the root cause? Enable encryption on the AP. Remove the IP address from the AP. x Temporarily disable ACLs on the AP. Shut down the LAN interface on the AP.

2Refer to the exhibit. An administrator is troubleshooting why host CL1 cannot communicate with the other hosts in the network. What appears to be the problem? Port Gi0/1 of ASw1 is disabled. x VLAN 104 is not being permitted on the trunk. The native VLAN on the trunk should be VLAN 1. Port Gi0/2 of ASw1 should be configured as a trunk.

3Which protocol does a Lightweight AP use to communicate with the Wireless LAN Controller? 802.1Q IPsec x LWAPP TCP

4Refer to the exhibit. Wireless network users are complaining that they are not able to register with the Wireless LAN Controller. Wireless clients use DHCP to obtain their IP configuration information from R1. Based on the output that is shown, what is the reason that the wireless clients are unable to register with the controller? x The DHCP configuration is missing option 43. The DCHP pool should be specified as 10.10.0.0/16 to include both VLANs. The DHCP default-router command must specify the IP address of the WLC. The DHCP configuration should specify the 10.10.20.0/24 pool, as this is where the WLC is located.

5How does a Cisco IP phone discover which VLAN to use for voice traffic? x CDP

Page 21: 2º Exam

DHCP TFTP POST

6Refer to the exhibit. A network administrator needs to connect an IP phone to FastEthernet 0/22, which is currently configured to support a workstation. What three configuration commands are recommended to accommodate the addition of the phone? (Choose three.) no cdp enable x mls qos trust cos ip dhcp client request switchport port-security x switchport voice vlan 10 x mls qos trust device cisco-phone switchport port-security mac-address sticky

7IP phones are unable to register with the router and download their firmware and configuration files. A colleague advises that you should check to ensure that the protocols required for this process are not blocked by the IOS firewall. What two lines should you look for in the ACL? (Choose two.) permit tcp any any eq 22 permit tcp any any eq 23 permit tcp any any eq ftp x permit udp any any eq 69 permit tcp any any eq http permit udp any any eq https permit tcp any any eq www x permit tcp any any eq 2000

8What value does a Cisco IP phone receive in DHCP option 150? x IP address of TFTP server IP address of DHCP server IP address of NTP server PoE value setting Voice VLAN setting CDP neighbor list

9Refer to the exhibit. A user has a PC that connects to a VoIP phone and the phone connects to port Fa0/1 on the switch. The user is complaining about not being able to access the network. The user cannot access any local print servers and cannot ping any neighboring devices. The administrator

Page 22: 2º Exam

attempts to ping the PC of the user but is unsuccessful. Based on the output of the show port-security command, what could be the issue? The switch port has not been able to detect any devices connected to it. x The switch port detected more than one MAC address. The switch port detected a bridging loop. The switch port detected a MAC address that belongs to a different VLAN.

10Refer to the exhibit. Which statement is true about the debug ephone register command? x The router was able to successfully register the phone. There is an IP address mismatch that is detected on the phone. The IP address that is detected for the phone is 10.1.0.6. The phone is in Voice VLAN 7.

11Users complain that voice calls are choppy and of poor quality. A network administrator verifies the settings on the interface and discovers that no QoS has been configured. Which priority level should be applied to the voice traffic in order to improve the quality of voice calls? normal priority x highest priority medium priority lowest priority

12Refer to the exhibit. A user is not able to use a VoIP phone. Based on the output, what could be the problem? The phone is in the wrong VLAN. The switchport mode is incorrect. QoS is missing. x CDP is disabled.

13If an ACL is used on a port that connects to an Cisco IP phone, which two protocols must be allowed in the ACL for the Cisco IP phone to work? (Choose two.) x SCCP SMTP SNMP Telnet x TFTP WWW

14

Page 23: 2º Exam

Refer to the exhibit. An administrator is troubleshooting a video multicast problem on router R1. Users on the FastEthernet 0/1 are not receiving multicast traffic over the Serial 0/0/0 WAN link. Which statement correctly identifies the problem? Router R1 has not been configured with the ip multicast-routing command. The Fa0/1 interface has not been configured with the ip pim sparse-dense-mode command. x The S0/0/0 interface has not been configured with the ip pim sparse-dense-mode command. The S0/0/0 interface should be configured with the ip pim version 1 command. The S0/0/0 interface should be configured with the ip pim version 2 command.

15A network administrator is troubleshooting an IP multicast problem. After the administrator alters an IGMP configuration, which command should be used to verify the multicast routing table entries? show ip igmp interface show ip igmp membership x show ip mroute show ip pim interface show ip pim neighbor show ip route

16Refer to the exhibit. After a major network upgrade, network users complain about poor video application performance. A network administrator verified that all trunk links are up and operational and the EtherChannel configuration is correct. The output of the show interfaces port-channel command reveals that there is a 0 packet output rate over the last 5 minutes on the Po2 uplink. What could be done to correct the issue? Configure switch A_SW1 to be the root bridge for the network for all VLANs. x Configure switch D_SW1 to be the STP root for VLANs 10 and 20, and D_SW2 to be the root for VLANs 30 and 40. Remove the EtherChannel trunk uplinks from the access switch A_SW1 to the distribution switches. Remove the EtherChannel trunk uplinks from the access switch A_SW1 to the distribution switch D_SW2

17Refer to the exhibit. Users who are connected to SW1 are part of the multicast group 224.1.1.1, and they are complaining that they do not receive a video stream from the source. Based on the provided output, what could be done to remedy the problem? Apply the ip pim sparse-dense-mode command to interface Fa0/1 on router R1. x Apply the ip pim sparse-dense-mode command to interface S0/0/0 on router R2. Apply the ip igmp join-group command to interface Fa0/0 on router R1. Apply the ip igmp join-group command to interface Fa0/1 on router R2.

18

Page 24: 2º Exam

Refer to the exhibit. Users complained that they have experienced performance degradation for all video applications that are coming from the video server. Based on the provided outputs, what could be the possible cause of the problem? STP is blocking the redundant links that are bundled in both channels, thus causing the video traffic to be dropped. STP is blocking the redundant links that are bundled in the Po2 channel, thus causing half of the video traffic to be dropped. STP is alternating between channels when forwarding video traffic over the redundant links, thus causing a loss of video traffic. x STP is blocking the redundant links that are bundled in the Po2 channel, thus causing the video traffic to be forwarded over the Po1 channel only.

19Refer to the exhibit. The network security auditing team has added access lists to the network configurations in an attempt to improve network security. Users of the wireless network are now complaining that they can no longer associate to the wireless LAN. Based on the output shown, what must be added to the access list to restore connectivity? permit tcp any any range 12222 12223 x permit udp host 10.10.10.4 host 10.10.20.5 range 12222 12223 permit udp host 10.10.20.5 host 10.10.10.4 range 12222 12223 permit tcp host 10.10.20.5 host 10.10.10.4 range 12222 12223

20Which video application has the strictest latency requirement? video collaboration x video conferencing video surveillance video signaling

---------------------------------------------------------------------------------- Chapter 9º -------------------------------------------------------------------------------------------------------------------------------------------------

9º Exam (+/- solutions):(Pictures posted on the comment secction)

1 When audit trails are enabled with the ip inspect audit-trail command, which messages will appear in the syslog?

Page 25: 2º Exam

all packets that enter the specified interfaceall TCP packetsall stateful inspection sessionsall packets that match an ACL

2 [Picture X]Refer to the exhibit. An administrator has implemented a stateful IOS firewall configuration that allows internal users access to Internet websites. However, users have reported that they cannot do so. Based on the configuration in the exhibit, what change should be made to allow the firewall to function as planned?R1(config)# interface Fa0/1R1(config-if)# no ip access-group DENY outR1(config-if)# ip access-group DENY inR1(config)# no ip inspect name FWALL httpR1(config)# ip inspect name DENY httpx R1(config)# interface Fa0/1R1(config-if)# no ip inspect FWALL outR1(config-if)# ip inspect FWALL inR1(config)# no ip access-list extended DENYR1(config)# ip access-list extended DENYR1(config-ext-nacl)# permit ip any any

3 Which two security features could be implemented in the network control plane? (Choose two.)x which devices will exchange routing updateswho can alter the configuration of a network devicewhich locations can alter the configuration of network devicesx which device will become the root device in an STP selection processwho can access network device operational logs and interface statistics

4 [Picture X]Refer to the exhibit. Router R1 no longer receives routing updates from other EIGRP neighbors. Based on the output in the exhibit, what could be the cause of this problem?Interface FastEthernet 0/0 has been configured as a passive interface.Interface FastEthernet 0/0 has not been configured to support authentication.Interface FastEthernet 0/0 is administratively shut down.The EIGRP peer has not been configured to support authentication.There are no valid EIGRP neighbors connected to interface FastEthernet 0/0.

5

Page 26: 2º Exam

[Picture X]Refer to the exhibit. A legitimate user experienced a problem while attempting to gain access to the router EXEC shell. To investigate the situation, a network administrator issued debug tacacs and debug aaa authentication commands on the router. Based on the provided output, what could be the problem?The user credentials are rejected by the TACACS+ server.The user credentials stored in the local database do not match the credentials on the TACACS+ server.The user fails the authentication because the TACAS+ server does not have a profile set up to authorize CHAP.The user fails the authentication because router R1 cannot connect to the TACACS+ server.

6 [Picture X]Refer to the exhibit. Which statement about the debug radius authentication output is correct?The RADIUS server is unreachable.The user raduser has been authenticated.The IP address of the RADIUS server is 10.1.50.252.The user raduser is on a device with the IP address of 10.1.50.1.

7 [Picture X]Refer to the exhibit. Based on the debug aaa authentication and debug tacacs outputs, which statement is true?The authentication process verifies the user credentials to the local database.The first method defined by the default authentication method list is TACACS+.The user with the IP address 172.31.60.15 has been authorized to use privileged EXEC mode.The attempt of a remote user with the IP address 172.31.60.15 to log in to the router is unsuccessful.

8 [Picture X]Refer to the exhibit. The network administrator has decided to create an IPsec tunnel between the HQ and BRANCH routers. What two changes must be made to the existing ACL in order to allow the formation of the tunnel? (Choose two.)ICMP must be denied.UDP port 500 must be permitted.TCP ports 50 and 51 must be permitted.The ESP and AH protocols must be permitted.IP must be permitted between the two ends of the tunnel.The established keyword must be removed from statement 10.

9 [Picture X]

Page 27: 2º Exam

Refer to the exhibit. A network administrator is attempting to connect a branch office to headquarters through a VPN tunnel. The tunnel is reported as being active at both ends, but the 10.2.2.0/24 network is not appearing in the routing table at the branch end. The administrator has determined that the problem is with the branch office configuration. Based on the output as shown, why is the 10.2.2.0/24 network not appearing in the routing table?The tunnel protocol is improperly set.The tunnel key has been improperly configured.The tunnel encapsulation is improperly configured.The tunnel bandwidth is insufficient for EIGRP updates.The tunnel destination end point has been improperly configured.

10 What is the first step in troubleshooting connectivity issues in a secured network environment?Determine when the connectivity problem first appeared.Determine if the connectivity problem is affecting all users.Determine if disabling all security features on the network re-establishes connectivity.Determine if any access lists were added or modified immediately prior to the reporting of the connectivity problems.Determine if the user should have connectivity based on the security policy of the organization and the type of traffic being generated.

11 [Picture X]Refer to the exhibit. Based on the provided debug aaa authorization and debug tacacs command output, which statement is true?x The authorization method used for user Admin was TACACS+.The user Admin attempted to gain Telnet access to the device.The AAA security server authorized the user Admin to perform the requested command.The AAA security server has authorized the user Admin to use privilege level 15 EXEC commands.

12 A network administrator has received a report from a user about being unable to access the server that houses employee records. The server is on a restricted VLAN and the user workstation is not assigned to this VLAN. What step should the administrator take next?Move the workstation to a port that is configured for the VLAN.Add the port connected to the workstation to the VLAN and test connectivity.Move the server to a trunk link so that multiple VLANs can access the records.Review the security policy to determine if the user should have access to the VLAN.

13 [Picture X]Refer to the exhibit. What is the expected behavior of the configured firewall when internal hosts

Page 28: 2º Exam

attempt to access web sites on the Internet?The rule FWALL will inspect all HTTP traffic for viruses before allowing the traffic through.Hosts from the Internet will be allowed to initiate sessions with internal hosts that are using HTTP.Because all IP traffic is blocked by the access-list DENY, internal hosts cannot reach Internet hosts.HTTP sessions that are initiated from internal hosts to Internet hosts will be tracked and allowed, until closed or when the idle timer expires.

14 What would be the outcome of the no service password-recovery command enabled on the router?The secret password can be recovered but not the original configuration.The original configuration of the device can be recovered but not the secret password.The original configuration and passwords of the device can be recovered using the password recovery procedure.The original configuration and passwords of the device cannot be recovered using the password recovery procedure.

15 [Picture X]Refer to the exhibit. A network administrator issued the show ip inspect sessions command on R1 to investigate the status of the firewall. What two facts can be determined from the output? (Choose two.)The limit of one HTTP session has been reached.The firewall has been configured to monitor SIS traffic.The session will be blocked because of the NAT configuration on R1.The firewall is tracking an HTTP session that was initiated by an internal trusted host.Return traffic from the untrusted Internet host on port 80 will be permitted.

16 What is considered a control plane issue?x A wrong key is used by OSPF.An ACL is blocking TCP traffic to a server.SSH is not enabled on the VTY lines of a switch.The network administrator account is disabled on the RADIUS server.

17 Which three control plane protocols influence the data structures used by the data plane to forward unicast packets in the core network? (Choose three.)Dynamic Host Configuration Protocol (DHCP)First Hop Redundancy Protocols (FHRP)x Address Resolution Protocol (ARP)multicast routing protocolsx unicast routing protocolsx Spanning Tree Protocol (STP)

Page 29: 2º Exam

18 Which technology prevents CPU overloading of infrastructure devices?Simple Network Management ProtocolCisco Express Forwardingx Control Plane PolicingAccess Control Lists

19 [Picture X]Refer to the exhibit. A network technician has just configured router East to establish a tunnel to router West. After the configuration is applied, tunnel 1 is flapping. What needs to be done to stop this flapping?Make tunnel 1 on router East an EIGRP passive interface.Set the default gateway of Computer1 to 128.107.229.50.Add a static route on router East out S0/0/0 to 198.133.219.25.Change the configuration on router East such that the destination of tunnel 1 is 192.168.0.2.

20 Which two features should be enabled to secure DHCP and ARP? (Choose two.)DHCP SnoopingBPDU GuardPrivate VLANsBPDU FilteringIP Source GuardDynamic ARP Inspection

1Which two advantages does scheduled maintenance offer over interrupt-driven events? (Choose two.)reduced network downtimefaster time to resolution of problemssimplified troubleshooting processespredictable lead times for change requestsmaintenance windows during regular business hours

Page 30: 2º Exam

2RSPAN depends on which type of VLAN?native VLANmanagement VLANdefault VLANRSPAN VLANblack hole VLANprivate VLAN

3Refer to the exhibit. What information can be deduced from the provided debug aaa accounting command output?The user successfully gained access to the router EXEC shell.The user attempts to gain access to a local security server were unsuccessful.The user credentials were rejected by the default authentication method.The user access to the services was stopped because of the improper protocol that was used for the session.

4Refer to the exhibit. A network administrator issues the show interfaces s0/0/0 command on a router to determine the cause for a recent decrease in device performance. Based on the output shown, what is a possible cause of the observed performance issues?high CPU usage on the routerinsufficient RAM in the routerincorrect or outdated version of the Cisco IOSunrecognized Layer 2 encapsulation formats on the network

5In which three situations will traffic be handed off (punted) to the CPU for processing? (Choose three.)any traffic that is going through a GRE tunnelany traffic that is explicitly blocked by an ACLany traffic that is destined for any of the switch IP addressesany traffic that is assigned to a particular VLAN that is not allowed on a trunkany traffic that is coming to an inbound port that is in the spanning-tree blocking stateany multicast and broadcast traffic that is coming from the Spanning Tree Protocol (STP) or routing protocols

6An administrator has just implemented two-way route redistribution between an OSPF and EIGRP domain. However, network performance between domains quickly degraded and an investigation revealed routing loops. What action could be used to solve this issue?

Page 31: 2º Exam

Change the seed metric of the routes being redistributed.Filter the routes being redistributed between the protocols.Redistribute all subnets in both EIGRP and OSPF domains.Configure an additional router to be a secondary point of route redistribution.

7What content can be found in the show ip eigrp topology network mask output?minimum delaycumulative costhop countvariancemetric weights

8Refer to the exhibit. BPDU guard and PortFast have been configured on all edge ports on the access switches. A junior network administrator tested a new switch in the lab and verified that the bridge ID is 32887. What would happen when the administrator plugs this switch into port Fa0/20 on ASW_1 in an attempt to extend the LAN?Port Fa0/20 will be shut down.Port Fa0/20 will become a root port.Port Fa0/20 will start forwarding traffic immediately.Port Fa0/20 will transition from blocking to forwarding state after the spanning tree convergence.

9What is a characteristic of network maintenance?Network maintenance typically excludes consideration of network changes.Proper network maintenance will eliminate network downtime.Maintaining network documentation is an important element of network maintenance.The amount of resources expended on network maintenance is consistent across all companies.

10Refer to the exhibit. A network administrator is troubleshooting a connectivity issue between LAN clients on routers R1 and R3. Connectivity tests from R2 to the R1 and R3 LAN segments are successful. The administrator issues the debug ip icmp command for R1 and confirms that a routing issue exists. Based on the information that is presented in the exhibit, which configuration command would correct the problem?R1(config)# ip route 0.0.0.0 0.0.0.0 172.16.7.1R1(config)# ip route 172.16.6.0 255.255.255.0 172.16.7.10R2(config)# ip route 172.16.6.0 255.255.255.0 172.16.7.9R2(config)# ip route 0.0.0.0 0.0.0.0 172.16.7.9R3(config)# ip route 0.0.0.0 0.0.0.0 172.16.7.9R3(config)# ip route 172.16.6.0 255.255.255.0 172.16.7.10

Page 32: 2º Exam

11What is the final task in a structured troubleshooting process?gathering informationtesting the hypothesisdocumenting the changeseliminating possible causes

12Syslogs reveal malicious activity originating from an internal host that is located at IP address 10.10.10.251. From the local gateway router, the administrator successfully pings the host IP address and populates the ARP cache of the router. The administrator then issues the show ip arp 10.10.10.251 command and discovers that the MAC address of the host is 0011.9254.e2a0. What could the administrator do next to discover the physical location of the malicious host?Issue the show mac address-table address 0011.9254.e2a0 command on various switches and follow the path to the host.Issue the show vlan command on various switches and follow the path to the host.Issue the traceroute 0011.9254.e2a0 command and follow the path to the host.Issue the traceroute 10.10.10.251 command and follow the path to the host.

13Which two pieces of information are displayed by the debug ip bgp command? (Choose two.)BGP updatesroute redistribution informationBGP related eventsphases of BGP peering relationshipsinternal metrics of IBGP routes

14Refer to the exhibit. What could be concluded about the TACACS+ failure based on the exhibited command output from debug tacacsand debug aaa authentication?The TACACS+ server is not operational.The TACACS+ server IP address has been incorrectly configured on the router.The TACACS+ server key of the router does not match that of the TACACS+ server.The username and password that were supplied by the user were rejected by the TACACS+ server.

15Refer to the exhibit. A network administrator issued the debug dhcp detail command to verify the operations of DHCP on router R2. Which statement is correct about the active DHCP processes on R2?The DHCP server sends a DHCPOFFER message with the full set of configuration parameters to the client.The DHCP client sends out a DHCPDISCOVER broadcast message to find its local DHCP server.The DHCP server sends a DHCPACK message with the full set of configuration parameters to the client.

Page 33: 2º Exam

The DHCP client sends out a DHCPREQUEST broadcast message to the DHCP server to accept the offered parameters.

16Which two benefits do the use of templates provide in the troubleshooting process? (Choose two.)provide an effective method of maintaining network documentationensure that all individuals carry out similar tasks in a consistent mannerdocument the solution to specific problems eliminating the requirement for troubleshootingallow each technician to select the best troubleshooting process to use for a particular problemensure that the problem is located and corrected regardless of the knowledge level of the technician

17Which VTP mode is configured on a switch in the implementation of private VLANs?clientservertransparentclient or serverclient or transparenttransparent or server

18A network administrator notices frames are received on a different port than expected on a switch. What are two plausible causes of the problem? (Choose two.)a routing erroran access list errorduplicate MAC addressesVLAN trunk misconfigurationa Spanning Tree Protocol related issue

19What are the three private VLAN (PVLAN) port types? (Choose three.)communityedgeisolatedpoint-to-pointpromiscuousprotected

20Refer to the exhibit. Based on the information that is provided, which two NetFlow statements are correct? (Choose two.)All NetFlow packets sent from R1 to the traffic collector will be sourced from IP address 1.1.1.1.

Page 34: 2º Exam

Interfaces Fa0/0 and Fa0/1 must also be included as flow-export source interfaces.NetFlow version 5 should be configured if the infrastructure includes non-Cisco devices.NetFlow will track all ingress traffic for interfaces Fa0/0 and Fa0/1.NetFlow will forward the traffic statistics and packet payload content of interfaces Fa0/0 and Fa0/1 to IP address 10.10.10.1.The UDP value 9996 is optional because it is the default NetFlow destination port number.

21Refer to the exhibit. A network administrator is troubleshooting a NAT translation issue on router R2. The IP addresses of hosts on the R2 LAN are not being translated by R2. Based on the information in the exhibit, what is the issue?The NAT pool is exhausted.The static translation prevents any new dynamic translations.The ACL is using a wrong pool reference.The R2 LAN is not configured as an inside interface.

22Refer to the exhibit. An administrator has configured VRRP on routers R1 and R2. However, no output is generated using the show vrrp brief command on router R1. The administrator then verifies the VRRP interface and key chain configurations. Based on the output in the exhibit, what is the cause of the problem?Interface FastEthernet 0/0 on router R1 requires the vrrp 1 ip 10.1.1.254 command to be issued.Interface FastEthernet 0/0 on router R1 requires the vrrp 1 preempt command to be issued.Interface FastEthernet 0/0 on router R1 requires the vrrp 1 priority 100 command to be issued.Router R1 is configured to use text authentication, while R2 is configured to use MD5 authentication.Router R1 should be configured to use text authentication.

23Refer to the exhibit. A network administrator is investigating a possible network congestion problem. Which information is indicative of network congestion?The EIGRP neighbor has not sent any hello packets in the last 14 seconds.The EIGRP neighbor is redistributing routes from OSPF with invalid seed metrics.The EIGRP neighbor is offline and unreachable.The Q Cnt field should be at zero.The Seq Num field should be much higher.The values of the SRTT and RTO fields should be much lower.

24Which DHCP message is sent by the server to the client and contains the DHCP configuration parameters?DHCP DISCOVERDHCP OFFER

Page 35: 2º Exam

DHCP REQUESTDHCP ACKDHCP NAKDHCP INFORM

25Which statement is true based on the show ip ospf neighbor command output that is shown in the exhibit?RTB did not see its router ID in the hello packet that was received from RTA.RTB did not receive a hello packet from RTA.RTB is able to exchange routing updates with RTA.RTB has established an adjacency with RTA.

26Refer to the exhibit. A network administrator is troubleshooting a connectivity issue between R1 and R2. The routers are failing to create a neighbor relationship and no OSPF HELLO packets are traversing the Frame Relay link. Based on the output, what does the administrator need to do on R1 to correct the issue?Map the DLCI to the link local address of R2.Change the OSPF neighbor to point to the global unicast address of R2.Change the IPv6 address on Serial 0/0/0 to be in the same segment as the Serial 0/0/0 interface of R2.Remove the broadcast keyword from the frame-relay map statement.

27Refer to the exhibit. You have been asked to troubleshoot a connectivity issue between R3 and R1. From the partial output of theshow running-config command on both routers, what configuration change is required?A static route should be added to R3 to point to the 192.168.1.0/24 network.A static route should be added to R1 to point to the 192.168.1.0/24 network.The tunnel source for Tunnel0 on R3 should be the IP address of Serial0/0/1 on R1.The tunnel source for Tunnel0 on R1 should be the IP address of Loopback0 on R3.The tunnel destination for Tunnel0 on R1 should be the IP address of Serial0/0/1 on R3.The tunnel destination for Tunnel0 on R3 should be the IP address of Loopback0 on R1.

28Which type of spanning tree failure is the most disruptive?The STP reaches its maximum diameter.Ports that should be blocked start forwarding.The TTL field in the Ethernet frames decrements to 0 on all frames.Frames with matching entries in the MAC address table are not forwarded.

29

Page 36: 2º Exam

Refer to the exhibit. Wireless network users are complaining about performance issues, especially when using Voice over WLAN. Based on the output that is shown, what could be the problem?QoS is not supported in Lightweight mode.The trunk between R1 and SW1 does not support QoS.SW1 is resetting the DSCP values supplied by the Lightweight AP.The Wireless LAN Controller has not been configured to support voice traffic.QoS has not been enabled between the Lightweight AP and the Wireless LAN Controller.

30Which backup mechanism presents the highest security risk?FTPHTTPSSCPTFTP

31An administrator notices that CDP is disabled on a port that connects to an IP phone. What effect will this have?The phone will experience intermittent connectivity.The phone will be placed into the default VLAN.The phone will not be able to discover auxiliary VLAN information, QoS settings, or automatically negotiate power settings.The phone will be able to make calls but will not be able to receive calls.

32Which two conditions could cause two routers to have trouble establishing a neighbor relationship in an OSPF network? (Choose two.)The interfaces have different network types.Hello packets are not sent from either neighbor.One of the routers is redistributing the OSPF routes into EIGRP.Slow network connections cause OSPF advertisements to time out.The network command has put the connected interfaces into the same OSPF area.

33Refer to the exhibit. A port channel link between a branch site and the main site experiences an outage after a hardware upgrade at the branch site. The network administrator at the main site checks the log and sees a “%SPANTREE-2-CHNL_MISCFG” message. What is a likely cause of this message?The branch site has been configured for the Spanning Tree Protocol, but the main site has not.The main site has been configured to bundle links into an EtherChannel and the branch site has not.The branch site is running a newer, incompatible version of the Spanning Tree Protocol.The main site has inconsistencies in the physical ports that are members of the channel.

Page 37: 2º Exam

34Refer to the exhibit. Based on the output of the debug ip nat command in the exhibit, which two statements are true? (Choose two.)Packets were not translated for the return path from source 192.168.1.95.Packets that are destined for 172.31.2.132 from source 192.168.1.95 are translated into 172.31.233.209.Entries that are indicated with NAT* have been translated via the fast path.The IP address 172.31.233.209 is the configured IP address on the remote PC.Entries with NAT* have the ToS value 5.

35When configuring private VLANs, how many isolated VLANs can be mapped to a primary VLAN?0124platform dependent

36Which switch error is indicative of a duplex mismatch on the full-duplex side of a link?Xmit-ErrRcv-ErrFCS-ErrGiants

37Refer to the exhibit. Users are complaining that they are unable to access the web server that is located at 172.16.1.101. Based on the partial syslog output that is exhibited, what is causing this problem?The web server is denying the client request.There is no logical path from the client to the web server location.A Java applet reset option is configured on the zone-based policy firewall.The zone-based policy firewall has been configured to block all HTTP traffic to the server location.The classic IOS firewall has not been properly configured to allow HTTP traffic in response to an internal request.

38Which action occurs immediately following POST in the boot process of a Cisco IP phone?The IP phone sends DHCP broadcasts.The IP phone initializes the IP stack.The IP phone uses CDP to learn the voice VLAN.The IP phone requests a configuration file from a TFTP server.

39

Page 38: 2º Exam

What occurs when the no service password-recovery command is entered on the router?Passwords will not be encrypted.Executive passwords can be retrieved and viewed in the running configuration.Executive passwords can be changed in ROMMON mode.The original configuration and passwords cannot be retrieved.All passwords are encrypted to level 7.

40Which anti-spoofing mechanism will filter packets that enter a multilayer switch through an interface that does not provide the best path back to the source of the packet?spanning treeprivate VLANintrusion preventionVLAN access control listsUnicast Reverse Path Forwarding

41Which DSCP value should be applied to voice traffic?AF11AF31CS1EF

42Which command would a network administrator use to verify which VLANs are allowed on a trunk?show vlanshow interfaces trunkshow vlan interfaceshow mac address-table

43Refer to the exhibit. An administrator is troubleshooting an HSRP implementation on routers R1 and R2. Based on the output in the exhibit, what is the probable cause of the problem?Router R1 requires the standby 1 ip 10.1.1.254 command to be issued on interface FastEthernet 0/0.Router R2 requires the standby 1 ip 10.1.1.254 command to be issued on interface FastEthernet 0/0.Router R1 is configured to support MD5 authentication while router R2 is configured to support text authentication.Router R1 is configured to support text authentication while router R2 is configured to support MD5 authentication.Routers R1 and R2 have different MD5 authentication strings configured.Routers R1 and R2 have different text authentication strings configured.

Page 39: 2º Exam

44What are two problems that can occur when routes are redistributed in two directions? (Choose two.)suboptimal routingrouting loopslost seed metricsroute filteringlost external routes

45Refer to the exhibit. Which two FTP-related statements are true? (Choose two.)The Configuration Rollback feature was preconfigured on router R1 via the archive command.The configuration was copied using a method that is less secure than HTTPS.The ip ftp username and ip ftp password commands were issued on router R1.The login credentials were sent to the FTP server in an encrypted format.The R1-test.cfg configuration was successfully copied from the FTP server to the running configuration file of router R1.The R1-test.cfg configuration was successfully copied from the FTP server to the startup configuration file of router R1.

46Refer to the exhibit. Users are complaining that they are unable to connect to resources outside of their corporate network during peak hours. What action should the administrator take to correct this problem?Remove the ACL because it is blocking connections.Change the FastEthernet 0/1 interface to an inside NAT interface.Disable CEF because it is sending packets to the CPU for processing.Disable static NAT because it is interfering with the dynamic translations.Increase the size of the NAT pool to provide more IP addresses for translation.

47Refer to the exhibit. A network administrator is trying to secure the remote administration of the router by enabling the use of the SSH protocol. Which changes should be made on the partial configuration as shown in the graphic?The enable password must be encrypted.The commands listed under the VTY line should be listed under the Console line.The transport input telnet command should be changed to transport input ssh.The transport input telnet command should be changed to transport input none.

48Users at a branch office are complaining that they are unable to connect to resources at the head office. The network administrator issues the show ip route command and verifies that the correct next hop IP address and egress interface are listed. What should the administrator do next?

Page 40: 2º Exam

Verify that CEF is running on the router.Verify the Layer 3 to Layer 2 mappings.Verify end-to-end connectivity via the use of the ping command.Verify that the information in the CEF FIB is correct.Verify that the interface is active and participating in the routing process.

49Refer to the exhibit. In a converged spanning tree, how many blocked ports will there be in VLAN 1 for the pictured topology?1234

50Refer to the exhibit. Users are complaining that they are receiving duplicate address error messages when they start their machines. What should the administrator do to correct this problem?Change the address assigned to the default router and dns server.Decrease the DHCP lease time to make more addresses available at one time.Change the netmask to 255.0.0.0 to agree with the class A network that is used in the DHCP pool.Use the ip dhcp excluded-address command to exclude any statically assigned addresses from the DHCP pool.

51What is a characteristic of network maintenance toolkits?are vendor specificmay be both GUI and CLIrequire expensive investmentssupport only real-time monitoring

52What can be inferred from the fact that a switch is receiving BPDUs on a port but not transmitting BPDUs?The port is a designated port.The port is a root port.The port is disabled.The port is in listening state.

53A newly configured switch is connected to an existing network. The instant the trunk link is brought up to the rest of the network, the entire network goes down. What could have caused this problem?The switch was inserted into the network using an incorrect VTP domain name.

Page 41: 2º Exam

The VTP password entered on the new switch did not match that of the existing VTP domain.The switch should have been placed into VTP Transparent Mode prior to being inserted into the network.The configuration revision number of the inserted switch was higher than the configuration revision of the VTP domain.The configuration revision number of the inserted switch was lower than the configuration revision of the VTP domain.

54Refer to the exhibit. A network engineer is investigating a reported issue of Computer1 not receiving its IP configuration from the DHCP server. Computer2 is receiving its configuration from the DHCP server. What is a plausible reason for this issue?An ACL is blocking broadcasts into the F0/0 interface of router North .The DHCP server does not have a DHCP pool for 192.168.0.0 /24 network.The WAN segment between routers East and North should be replaced with a LAN.The S0/0/0 interface of router East should be configured to provide DHCP relay.

55Refer to the exhibit. Based on the output that is generated, which two statements are true? (Choose two.)The archive path is the only mandatory archive parameter that must be configured.Every time the running configuration file is saved to NVRAM, it will also be automatically archived.The $h and $t parameters will automatically add the device hostname and version number to the archive filename.Use the archive config privileged EXEC mode command to replace the running configuration file with the most recent archived file.The time-period parameter must be configured to enable the automatic archiving of the running-configuration file everytime it is saved to NVRAM.

56What are two limitations of using buffered logging? (Choose two.)Only high severity messages can be captured.Messages are lost when there is a connectivity issue.Log messages are removed when a device is powered down.Message services may have messages filtered through a firewall.Oldest messages are overwritten when allocated memory is exceeded.

57Refer to the exhibit. You have been asked to correct the configuration on R1 so that the Tunnel 0 interface does not flap and R3 can be consistently reached from R1. What command would you issue on R1 to accomplish this?ip route 10.3.3.3 255.255.255.255 Tunnel0

Page 42: 2º Exam

ip route 10.3.3.3 255.255.255.255 Serial0/0/0ip route 172.16.25.3 255.255.255.0 Serial0/0/0ip route 172.16.25.0 255.255.255.0 Serial0/0/0ip route 172.16.25.3 255.255.255.255 Tunnel0ip route 172.16.15.2 255.255.255.255 Tunnel0

58What type of BGP message precedes the successful formation of a BGP peering session?updatekeepaliveestablishedwithdrawopen

59Refer to the exhibit. A network administrator is unable to have two BGP peers exchange routing information. Which solution would correct this problem?Change the neighbor peer IP addresses on R1 and R2 to the loopback interface IP address of the other router.Change the neighborx.x.x.xupdate-source command on R1 and R2 to refer to the FastEthernet interfaces.Enter the neighborx.x.x.xebgp-multihop 1 command on R1 and R2.Remove the loopback interfaces on each router.

60Refer to the exhibit. Based on the partial configuration that is shown, which traffic will be inspected by the zone-based policy firewall?all TCP traffic that is destined for the public networkall TCP traffic that is destined for the private networkTelnet, SMTP, and HTTP traffic that is destined for the public networkTelnet, SMTP, and HTTP traffic that is destined for the private network


Recommended