New Questions 2

Which option describes a limitation of LLDP?

A. LLDP cannot provide information about VTP.

B. LLDP does not support TLVs.

C. LLDP can discover only Windows servers.

D. LLDP can discover up to two devices per port.

Answer: A

New Questions 3

Which private VLAN access port belongs to the primary VLAN and can communicate with all interfaces, including the community and isolated host ports?

A. promiscuous port

B. isolated port

C. community port

D. trunk port

Answer: A

New Questions 4

Which command is needed to enable DHCP snooping if a switchport is connected to a DHCP server?

A. ip dhcp snooping trust

B. ip dhcp snooping

C. ip dhcp trust

D. ip dhcp snooping information

Answer: A

New Questions 5

Refer to the exhibit.

Which EtherChannel negotiation protocol is configured on the interface f0/13 u2013 f0/15?

A. Link Combination Control Protocol

B. Port Aggregation Protocol

C. Port Combination Protocol

D. Link Aggregation Control Protocol

Answer: B

102.Which feature describes MAC addresses that are dynamically learned or manually configured, stored in the address table, and added to the running configuration?

A. sticky

B. dynamic

C. static

D. secure

Answer: A

New Questions 6

Refer to the exhibit.

Which set of configurations will result in all ports on both switches successfully bundling into an EtherChannel?

A. switch1

channel-group 1 mode active switch2

channel-group 1 mode auto

B. switch1

channel-group 1 mode desirable switch2

channel-group 1 mode passive

C. switch1

channel-group 1 mode on switch2

channel-group 1 mode auto

D. switch1

channel-group 1 mode desirable switch2

channel-group 1 mode auto

Answer: D

New Questions 7

CORRECT TEXTSWITCH.com is an IT company that has an existing enterprise network comprised of two layer 2 only switches; DSW1 and ASW1. The topology diagram indicates their layer 2 mapping. VLAN 20 is a new VLAN that will be used to provide the shipping personnel access to the server. Corporate polices do not allow layer 3 functionality to be enabled on the switches. For security reasons, it is necessary to restrict access to VLAN 20 in the following manner:

u2022 Users connecting to VLAN 20 via portfO/1 on ASW1 must be authenticated before they are given access to the network. Authentication is to be done via a Radius server:

u2022 Radius server host:

u2022 Radius key: rad123

u2022 Authentication should be implemented as close to the host as possible.

u2022 Devices on VLAN 20 are restricted to the subnet of

u2022 Packets from devices in the subnet of should be allowed on VLAN 20.

u2022 Packets from devices in any other address range should be dropped on VLAN 20.

u2022 Filtering should be implemented as close to the serverfarm as possible.

The Radius server and application servers will be installed at a future date. You have been tasked with implementing the above access control as a pre-condition to installing the servers. You must use the available IOS switch features.


The configuration:

Step1: Console to ASW1 from PC console 1 ASW1(config)#aaa new-model

ASW1(config)#radius-server host key rad123 ASW1(config)#aaa authentication dot1x default group radius ASW1(config)#dot1x system-auth-control ASW1(config)#inter fastEthernet 0/1

ASW1(config-if)#switchport mode access ASW1(config-if)#dot1x port-control auto ASW1(config-if)#exit

ASW1#copy run start

Step2: Console to DSW1 from PC console 2 DSW1(config)#ip access-list standard 10 DSW1(config-ext-nacl)#permit DSW1(config-ext-nacl)#exit

DSW1(config)#vlan access-map PASS 10 DSW1(config-access-map)#match ip address 10 DSW1(config-access-map)#action forward DSW1(config-access-map)#exit DSW1(config)#vlan access-map PASS 20 DSW1(config-access-map)#action drop DSW1(config-access-map)#exit DSW1(config)#vlan filter PASS vlan-list 20

DSW1#copy run start

New Questions 8

Which switch is chosen as the stack master during a stack master election or re-election?

A. the switch with the highest stack member ID

B. the switch with the lowest stack member ID

C. the switch with the lowest stack member priority value

D. the switch with the highest stack member priority value

Answer: D

New Questions 9

Which feature must be enabled to eliminate the broadcasting of all unknown traffic to switches that are not participating in the specific VLAN?

A. VTP pruning

B. port-security

C. storm control

D. bpdguard

Answer: A

New Questions 10

What is the function of NSF?

A. forward traffic simultaneously using both supervisors

B. forward traffic based on Cisco Express Forwarding

C. provide automatic failover to back up supervisor in VSS mode

D. provide nonstop forwarding in the event of failure of one of the member supervisors

Answer: D

New Questions 11

After reviewing UDLD status on switch ports, an engineer notices that the." Which statement describes what this indicates about the status of the port?

A. The port is fully operational and no known issues are detected.

B. The bidirectional status of "unknown" indicates that the port will go into the disabled state because it stopped receiving UDLD packets from its neighbor.

C. UDLD moved into aggressive mode after inconsistent acknowledgements were detected.

D. The UDLD port is placed in the "unknown" state for 5 seconds until the next UDLD packet is received on the interface.

Answer: A

New Questions 12

Which statement about the MAC address sticky entries in the switch when the copy run start command is entered is true?

A. A sticky MAC address is retained when the switch reboots.

B. A sticky MAC address can be a unicast or multicast address.

C. A sticky MAC address is lost when the switch reboots.

D. A sticky MAC address ages out of the MAC address table after 600 seconds.

Answer: A

