1.
A company is looking for a WAN solution to connect its headquarters site with four remote sites.
What advantage would dedicated leased lines provide to the customer compared to a shared
Frame Relay solution?
Correct Answer
B. Lower latency and jitter
Explanation
Dedicated leased lines provide a dedicated connection between the headquarters site and the remote sites, which means that the customer would have exclusive access to the bandwidth and resources of the connection. This results in lower latency and jitter, as there is no sharing of the connection with other users. In contrast, a shared Frame Relay solution would involve sharing the connection with other users, leading to potential congestion and higher latency and jitter.
2.
Refer to the exhibit. The network administrator is adding R1 to an existing network. As a part
of the corporate IT procedures, the administrator attempts to back up the router Cisco IOS
software of R1 and receives the output shown. The network administrator then attempts
unsuccessfully to ping the TFTP server from the console session. What should be done next to
isolate this problem?
Correct Answer
D. From the console session, make sure that R1 has a route to the network where the TFTPserver resides.
Explanation
To isolate the problem, the network administrator should check if R1 has a route to the network where the TFTP server resides. This is because if there is no route, R1 will not be able to reach the TFTP server, resulting in the unsuccessful ping attempt. By ensuring that there is a proper route, the administrator can establish connectivity between R1 and the TFTP server, allowing for successful backup of the router's Cisco IOS software.
3.
Which device encodes data for transmission across the WAN service provider transmission link?
Correct Answer
C. DCE
Explanation
The device that encodes data for transmission across the WAN service provider transmission link is the DCE (Data Circuit-terminating Equipment). DCE is responsible for converting the data from the DTE (Data Terminal Equipment) into a format suitable for transmission over the WAN link. It provides the necessary clocking and synchronization for the transmission and ensures that the data is properly encoded and decoded at both ends of the link.
4.
Refer to the exhibit. An administrator has added the exhibited commands to routers A and B,
but no routing updates are exchanged between the two routers. Based on the information that is
given, what is the likely cause of the problem?
.
Correct Answer
B. The authentication key strings do not match
Explanation
The likely cause of the problem is that the authentication key strings do not match between routers A and B. This is indicated by the fact that the exhibited commands include authentication key strings. If the key strings do not match, the routers will not be able to authenticate each other and therefore will not exchange routing updates.
5.
What are two characteristics of DSL technology? (Choose two.)
Correct Answer(s)
B. Service providers deploy DSL in the local loop of the telepHone network.
D. Filters and splitters allow POTS and DSL traffic to share the same medium.
Explanation
DSL technology is deployed by service providers in the local loop of the telephone network. This means that the DSL connection is established between the customer's location and the local telephone exchange. Additionally, filters and splitters are used to allow both POTS (Plain Old Telephone Service) voice traffic and DSL traffic to share the same medium, which is the telephone line. This enables users to use their telephone for voice calls while simultaneously using the same line for DSL internet access.
6.
An administrator is unable to receive e-mail. While troubleshooting the problem, the administrator is able to ping the local mail server IP address successfully from a remote network and can successfully resolve the mail server name to an IP address via the use of the nslookup command. At what layer of the OSI model is the problem most likely to be found?
Correct Answer
A. Application
Explanation
Based on the given information, the problem is most likely to be found at the application layer of the OSI model. This is because the administrator is unable to receive emails, which is a function of the email application. The fact that the administrator is able to ping the local mail server IP address and resolve the mail server name to an IP address indicates that the lower layers (transport and network) are functioning correctly. Therefore, the issue is likely specific to the application layer.
7.
While troubleshooting a problem with an e-mail server, an administrator observes that the switch port used by the server shows "up, line protocol up". The administrator cannot ping the server. At which layer of the OSI model is the problem most likely to be found?
Correct Answer
B. Network layer
Explanation
The problem is most likely to be found at the network layer. The fact that the switch port is showing as "up, line protocol up" indicates that the physical and data link layers are functioning properly. However, the inability to ping the server suggests that there may be an issue with network connectivity or routing at the network layer.
8.
Refer to the exhibit. An ACL called Managers already exists on this router. What happens if the network administrator issues the commands as shown in the exhibit?
Correct Answer
C. The existing ACL is modified to include the new command.
Explanation
The given exhibit shows a command that is being issued to modify an existing ACL called Managers on the router. The question asks what will happen as a result of this command. The correct answer states that the existing ACL will be modified to include the new command. This means that the command will be added to the existing ACL, rather than creating a new ACL or overwriting the existing one.
9.
Refer to the exhibit. Why are the routers unable to establish a PPP session?
Correct Answer
A. The usernames are misconfigured.
Explanation
The reason the routers are unable to establish a PPP session is because the usernames are misconfigured. PPP (Point-to-Point Protocol) requires both routers to have matching usernames in order to authenticate and establish a connection. Since the usernames are misconfigured, the authentication process fails and the PPP session cannot be established.
10.
A technician is talking to a colleague at a rival company and comparing DSL transfer rates between the two companies. Both companies are in the same city, use the same service provider, and have the same rate/service plan. What is the explanation for why Company A reports higher download speeds than Company B?
Correct Answer
D. Company A is closer to the service provider.
Explanation
The explanation for why Company A reports higher download speeds than Company B is that Company A is closer to the service provider. The proximity to the service provider allows for a shorter distance for the data to travel, resulting in faster download speeds.
11.
Refer to the exhibit. R1 is performing NAT overload for the 10.1.1.0/24 inside network. HostA has sent a packet to Web Server. What is the destination IP address of the return packet from Web Server when it is received at the NIC on HostA?
Correct Answer
A. 10.1.1.2:1234
Explanation
The destination IP address of the return packet from the Web Server, when received at the NIC on HostA, would be 10.1.1.2:1234. This is because R1 is performing NAT overload, which means it is translating the private IP address of HostA (10.1.1.2) to a public IP address and port number combination. The return packet from the Web Server would be sent back to the translated IP address and port number, which is 10.1.1.2:1234 in this case.
12.
Which protocol is implicitly denied at the end of an IPv4 access list?
Correct Answer
A. IP
Explanation
The protocol that is implicitly denied at the end of an IPv4 access list is IP. This means that any traffic using the IP protocol will be blocked by default.
13.
A network administrator is analyzing the data from a network performance baseline. Which condition will not be indicated in the baseline data?
Correct Answer
A. The IP addressing scheme of the network
Explanation
The IP addressing scheme of the network will not be indicated in the baseline data. The network performance baseline focuses on analyzing the performance and usage of the network, such as identifying the most heavily used parts of the network, congested areas, and error rates. The IP addressing scheme is a separate aspect of network configuration and is not directly related to network performance.
14.
Refer to the exhibit. An administrator is trying to connect Router1, a Cisco router, to a non-Cisco router using a serial connection. Why is the connection failing?
Correct Answer
C. The wrong encapsulation is being used.
Explanation
The connection is failing because the wrong encapsulation is being used. Different routers may require different encapsulation methods for serial connections. In this case, the Cisco router is being connected to a non-Cisco router, so it is likely that they require different encapsulation methods. To establish a successful connection, the administrator needs to ensure that the correct encapsulation method is used on both routers.
15.
Refer to the exhibit. Which statement is true about the WAN switch device?
Correct Answer
A. It uses a multiport internetworking device to switch traffic such as Frame Relay, ATM or X.25 over the WAN.
Explanation
The correct answer is that the WAN switch device uses a multiport internetworking device to switch traffic such as Frame Relay, ATM, or X.25 over the WAN. This means that the device is capable of handling multiple connections and can switch between different types of network protocols to transmit data over the wide area network. It acts as a central hub for routing and directing traffic between different networks and ensures efficient communication between different locations.
16.
Refer to the exhibit. Which statement is true about the status of the Frame Relay connection?
Correct Answer
C. Packets marked as FECN and BECN indicate that a congestion control mechanism is enabled on the Frame Relay PVC.
Explanation
The correct answer is that packets marked as FECN and BECN indicate that a congestion control mechanism is enabled on the Frame Relay PVC. This means that the network is actively monitoring and managing congestion on the connection, which helps to ensure smooth and efficient data transmission. The presence of FECN (Forward Explicit Congestion Notification) and BECN (Backward Explicit Congestion Notification) flags in the packets indicates that the network is proactively notifying the sender and receiver about the congestion status, allowing them to adjust their transmission rates accordingly.
17.
Refer to the exhibit. The hosts in network A all have static addresses that are assigned in the 192.168.2.0./24 network. The hosts in network B are DHCP clients in the 192.168.1.0/24 network. After router R1 has been configured with the statements as shown in the exhibit, the DHCP clients are reporting that they cannot access any network resources. The hosts with static addresses cannot access any resources outside network A. What is the problem?
Correct Answer
B. The interfaces on R1 are incorrectly addressed.
Explanation
The problem is that the interfaces on router R1 are incorrectly addressed. This means that the IP addresses assigned to the interfaces on R1 are not configured correctly, causing the DHCP clients to be unable to access network resources.
18.
Refer to the exhibit. Router1 and Router2 each support separate areas of a data center, and are connected via a crossover cable. Resources attached to Router1 are unable to connect to resources attached to Router2. What is the likely cause?
Correct Answer
B. The IP addressing is incorrect.
Explanation
The likely cause for the inability of resources attached to Router1 to connect to resources attached to Router2 is that the IP addressing is incorrect. IP addressing is crucial for devices to communicate with each other on a network. If the IP addresses assigned to the devices connected via the crossover cable are not in the same subnet or if there is an addressing conflict, communication between them will not be possible.
19.
-
At what physical location does the responsibility for a WAN connection change from the service provider to the user?
Correct Answer
D. Demarcation point
Explanation
The demarcation point is the physical location where the responsibility for a WAN connection changes from the service provider to the user. It is the point where the service provider's network ends and the user's network begins. At this point, the service provider is responsible for the connection up to the demarcation point, while the user is responsible for the connection from the demarcation point onwards.
20.
Because of a remote-procedure call failure, a user is unable to access an NFS server. At what layer of the TCP/IP model does this problem occur?
Correct Answer
D. Application layer
Explanation
The problem occurs at the application layer of the TCP/IP model because the user is unable to access the NFS server, which is an application-level service. The application layer is responsible for providing network services to applications and users, and in this case, the failure in the remote-procedure call is preventing the user from accessing the NFS server.
21.
-
Which two functions are provided by the Local Management Interface (LMI) that is used in Frame Relay networks? (Choose two.)
Correct Answer(s)
A. Flow control error
E. The sending of keepalive packets to verify operation of the PVC
Explanation
The Local Management Interface (LMI) in Frame Relay networks provides two functions: flow control error notification and the sending of keepalive packets to verify operation of the PVC. Flow control error notification helps in managing the flow of data by notifying the network devices about any errors or congestion in the network. The sending of keepalive packets ensures that the PVC is operational and helps in detecting any issues or failures in the connection.
22.
Which protocol is used to authenticate connections over serial links securely?
Correct Answer
A. CHAP
Explanation
CHAP (Challenge Handshake Authentication Protocol) is used to authenticate connections over serial links securely. It provides a more secure method of authentication compared to PAP (Password Authentication Protocol) by using a three-way handshake process. During the authentication process, the server challenges the client with a random value, and the client responds with a hash value generated using a shared secret and the challenge. The server then verifies the hash value received from the client. If the values match, the connection is authenticated. CHAP provides protection against replay attacks and does not send passwords in clear text, making it a more secure option for authentication.
23.
Refer to the exhibit. A packet is being sent from Host A to Host B through the VPN tunnel between R1 and R3. When the packet first arrives at R3, what are the source and destination IP addresses of the packet?
Correct Answer
C. Source 192.168.2.1 - Destination 192.168.3.2
24.
Refer to the exhibit. Branch A has a Cisco router and Branch B has a non-Cisco router that is using IETF encapsulation . After the commands that are shown are entered, R2 and R3 fail to establish the PVC. The R2 LMI is Cisco, and the R3 LMI is ANSI. The LMI is successfully established at both locations. Why is the PVC failing?
Correct Answer
D. The IETF parameter is missing from the frame-relay map ip 192.168.1.3 203 command.
Explanation
The PVC is failing because the IETF parameter is missing from the frame-relay map ip 192.168.1.3 203 command. This parameter is necessary for the non-Cisco router to understand the encapsulation type being used. Without it, the non-Cisco router is unable to establish the PVC with the Cisco router.
25.
Refer to the exhibit. A network administrator is trying to configure a router to use SDM, but the network administrator cannot access the SDM interface of the router. What is the cause of the problem?
Correct Answer
A. The VTY lines are misconfigured.
Explanation
The VTY lines are misconfigured. This means that the Virtual Terminal (VTY) lines on the router, which are used for remote management access, have not been properly configured. As a result, the network administrator is unable to access the SDM interface of the router.
26.
Refer to the exhibit. The SSH connections between the remote user and the server are failing. The correct configuration of NAT has been verified. What is the most likely cause of the problem?
Correct Answer
B. There are incorrect access control list entries.
Explanation
The most likely cause of the problem is that there are incorrect access control list entries. This means that the access control list is not properly configured to allow SSH connections to pass through. The correct configuration of NAT has already been verified, so the issue is likely with the access control list.
27.
What effect would the Router1(config-ext-nacl)# permit tcp 172.16.4.0 0.0.0.255 any eq www command have when implemented inbound on the f0/0 interface?
Correct Answer
D. Traffic originating from 172.16.4.0/24 is permitted to all TCP port 80 destinations.
Explanation
The command "permit tcp 172.16.4.0 0.0.0.255 any eq www" allows TCP traffic originating from the IP range 172.16.4.0/24 to be permitted to any destination with TCP port 80 (www). This means that any device within the 172.16.4.0/24 network will be able to access web servers (HTTP) on any destination that uses TCP port 80.
28.
While configuring a Frame Relay connection, when should a static Frame Relay map be used?
Correct Answer
C. Broadcast traffic and multicast traffic over the PVC must be controlled
Explanation
A static Frame Relay map should be used when there is a need to control broadcast traffic and multicast traffic over the PVC. This means that the network administrator wants to manage and limit the amount of broadcast and multicast traffic that is sent over the connection. By using a static Frame Relay map, the administrator can specify which traffic is allowed to pass through the PVC and which traffic should be dropped. This is especially useful in scenarios where the network has limited bandwidth or when certain types of traffic need to be prioritized over others.
29.
Where will a router operating system image be copied after the copy flash: tftp command is issued?
Correct Answer
D. Remote server
Explanation
When the "copy flash: tftp" command is executed, the router operating system image will be copied to a remote server. This means that the image will be transferred from the flash memory of the router to a server located remotely on the network. This allows for easy backup, storage, and distribution of the operating system image.
30.
Refer to the exhibit. You are a network administrator who has been tasked with completing the Frame Relay topology that interconnects two remote sites. How should the point-to-point subinterfaces be configured on HQ to complete the topology?
Correct Answer
B. HQ(config-subif)#frame-relay interface-dlci 301 on Serial 0/0/0.1 HQ(config-subif)# frame-relay interface-dlci 302 on Serial 0/0/0.2
Explanation
The point-to-point subinterfaces on HQ should be configured with DLCI 301 on Serial 0/0/0.1 and DLCI 302 on Serial 0/0/0.2. This is because the frame-relay map commands map the IP addresses 172.16.1.1 and 172.16.2.2 to DLCI 301 and DLCI 302 respectively, and these IP addresses are connected to the remote sites. By configuring the subinterfaces with the correct DLCIs, HQ will be able to establish a connection with the remote sites over the Frame Relay network.
31.
Refer to the exhibit. A host connected to Fa0/0 is unable to acquire an IP address from the DHCP server. The output of the debug ip dhcp server command shows "DHCPD: there is no address pool for 10.1.1.1". What is the problem?
Correct Answer
D. The pool of addresses for the 10Network pool is incorrect.
Explanation
The problem is that the pool of addresses for the 10Network pool is incorrect. This means that the DHCP server does not have a valid range of IP addresses to assign to the host connected to Fa0/0.
32.
Refer to the exhibit. Router1 is not able to communicate with its peer that is connected to this interface. Based on the output as shown, what is the most likely cause?
Correct Answer
C. Encapsulation failure
Explanation
The most likely cause for Router1 not being able to communicate with its peer is an encapsulation failure. This can be inferred from the output shown, which indicates that the interface is up and the line protocol is down. This typically occurs when there is a mismatch in the encapsulation type between the two devices connected to the interface.
33.
What will be the result of adding the command ip dhcp excluded-address 172.16.4.1 172.16.4.5 to the configuration of a local router that has been configured as a DHCP server?
Correct Answer
C. The DHCP server function of the router will not issue the addresses between 172.16.4.1 and 172.16.4.5
Explanation
By adding the command "ip dhcp excluded-address 172.16.4.1 172.16.4.5" to the configuration of the local router, the DHCP server function of the router will exclude the addresses between 172.16.4.1 and 172.16.4.5 from being issued to clients. This means that the DHCP server will not assign these addresses to any devices on the network.
34.
Refer to the exhibit. Which DHCP requests will R1 answer?
Correct Answer
D. Requests that are received on the FastEthernet 0/0 interface
Explanation
R1 will only answer DHCP requests that are received on the FastEthernet 0/0 interface.
35.
A router in a Frame Relay network needs to forward a message received from a host. What two methods does the router use to identify the correct VC to forward the message? (Choose two.)
Correct Answer(s)
C. The router searches Inverse ARP tables for maps of DLCIs to IP addresses
D. A table of static mappings can be searched
Explanation
The router in a Frame Relay network uses two methods to identify the correct VC to forward the message. First, it searches the Inverse ARP tables for maps of DLCIs to IP addresses. This allows the router to determine the correct VC based on the IP address of the destination host. Second, the router can search a table of static mappings. This table contains preconfigured mappings of DLCIs to IP addresses, allowing the router to determine the correct VC based on the destination IP address.
36.
An administrator is configuring a dual stack router with IPv6 and IPv4 using RIPng. The administrator receives an error message when trying to enter the IPv4 routes into RIPng. What is the cause of the problem?
Correct Answer
C. RIPv1 or RIPv2 needs to be configured in addition to RIPng to successfully use IPv4.
Explanation
The cause of the problem is that RIPv1 or RIPv2 needs to be configured in addition to RIPng to successfully use IPv4. RIPng is specifically designed for IPv6 routing and does not support IPv4 routes. Therefore, to enable IPv4 routing, RIPv1 or RIPv2 must be configured alongside RIPng.
37.
What are the symptoms when the s0/0/0 interface on a router is attached to an operational CSU/DSU that is generating a clock signal, but the far end router on the point-to-point link has not been activated?
Correct Answer
C. Show controllers indicates cable type DTE V.35. show interfaces s0/0/0 indicates serial up, line protocol down.
Explanation
The correct answer is "show controllers indicates cable type DTE V.35. show interfaces s0/0/0 indicates serial up, line protocol down." This answer suggests that the cable type is DTE V.35, which means that the router is acting as a data terminal equipment. The fact that the serial interface is up but the line protocol is down indicates that there is a physical connection between the router and the CSU/DSU, but the far end router on the point-to-point link has not been activated.
38.
What three statements describe the roles of devices in a WAN? (Choose three.)
Correct Answer(s)
A. A CSU/DSU terminates a digital local loop.
D. A modem terminates an analog local loop.
E. A router is commonly considered a DTE device.
Explanation
A CSU/DSU terminates a digital local loop means that a CSU/DSU device is used to connect a digital circuit from a customer's premises to a service provider's network.
A modem terminates an analog local loop means that a modem device is used to connect an analog circuit from a customer's premises to a service provider's network.
A router is commonly considered a DTE device means that a router is typically considered a Data Terminal Equipment (DTE) device, which is used to connect multiple networks together and direct traffic between them.
39.
Refer to the exhibit. Routers R1 and R2 are both configured for single area OSPF. Users who are connected to switch S1 are unable to access database applications that run on servers that are connected to S2. The network engineer is working remotely and only has the information that is shown in the exhibit to direct initial troubleshooting efforts. Based on the exhibit, which OSI layer is the most appropriate to start with for a divide-and-conquer approach?
Correct Answer
C. Data-link layer
Explanation
Based on the given exhibit, the most appropriate OSI layer to start with for a divide-and-conquer approach is the data-link layer. This layer is responsible for the reliable transmission of data between two directly connected devices. Since the issue is related to users being unable to access servers connected to S2, it indicates a problem in the local network. By starting with the data-link layer, the network engineer can check for any issues with the physical connections, network switches, or VLAN configurations that may be causing the problem.
40.
Refer to the exhibit. Partial results of the show access-list and show ip interface fastethernet 0/1 commands for router R3 are shown. There are no other ACLs in effect. Host A is unable to telnet to host B. Which action will correct the problem but still restrict other traffic between the two networks?
Correct Answer
B. Reverse the order of the TCP protocol statements in the ACL.
Explanation
Reversing the order of the TCP protocol statements in the ACL will correct the problem. By default, ACLs are evaluated in the order they are configured, and the first matching entry is applied. In this case, since the deny statement for any TCP traffic is listed before the permit statement for telnet traffic, all TCP traffic will be denied, including the telnet traffic between host A and host B. By reversing the order of the TCP protocol statements, the permit statement for telnet traffic will be evaluated first, allowing the telnet traffic between the two hosts.
41.
Refer to the exhibit. What is placed in the address field in the header of a frame that will travel from the DC office of ABC Company to the Orlando office?
Correct Answer
E. DLCI 200
Explanation
The DLCI 200 is placed in the address field in the header of the frame that will travel from the DC office of ABC Company to the Orlando office.
42.
When configuring remote access to a router, what is the significance of the no password command on a VTY line?
Correct Answer
A. Logins are prevented on that line.
Explanation
The significance of the "no password" command on a VTY line is that it prevents logins on that line. This means that users will not be able to access the router remotely through that specific line. By removing the requirement for a password, the line becomes inaccessible for remote access.
43.
Refer to the exhibit. The network administrator creates a standard access control list on Router1 to prohibit traffic from the 172.16.1.0/24 network from reaching the 172.16.2.0/24 network while still permitting Internet access for all networks. On which router interface and in which direction should it be applied?
Correct Answer
D. Interface Fa0/1, outbound
Explanation
The standard access control list should be applied on interface Fa0/1 in the outbound direction. This means that the access control list will be applied to traffic leaving the Fa0/1 interface. By applying it in the outbound direction on the interface connected to the 172.16.2.0/24 network, the access control list will prohibit traffic from the 172.16.1.0/24 network from reaching the 172.16.2.0/24 network while still allowing Internet access for all networks.
44.
Refer to the exhibit. Routers R1 and R2 have been configured with EIGRP in the same autonomous system. Computers PC1 and PC2 are not able to ping each other. Further investigation has revealed that the route to 192.168.10.0 is missing from the routing table on R2. What is the cause of the problem?
Correct Answer
B. The FastEthernet interfaces on R1 are configured as passive.
Explanation
The FastEthernet interfaces on R1 being configured as passive is the cause of the problem. When an interface is configured as passive in EIGRP, it means that the router will not send or receive EIGRP updates on that interface. As a result, the route to the 192.168.10.0 network is not being advertised from R1 to R2, causing it to be missing from the routing table on R2. This prevents PC1 and PC2 from being able to ping each other.
45.
Which three statements accurately describe attributes of a security policy? (Choose three.)
Correct Answer(s)
A. It creates a basis for legal action if necessary.
C. It defines a process for managing security violations.
E. It defines acceptable and unacceptable use of network resources.
Explanation
A security policy creates a basis for legal action if necessary by clearly outlining the rules and regulations that must be followed in order to ensure the security of the organization. It defines a process for managing security violations by providing guidelines on how to detect, respond to, and mitigate security incidents. It also defines acceptable and unacceptable use of network resources by specifying what actions are allowed and prohibited in order to maintain the security of the network.
46.
What is a major characteristic of a worm?
Correct Answer
D. Exploits vulnerabilities with the intent of propagating itself across a network
Explanation
A major characteristic of a worm is that it exploits vulnerabilities with the intent of propagating itself across a network. Unlike viruses, worms do not require a host program to attach themselves to. They can independently spread and infect multiple systems by taking advantage of security weaknesses. This characteristic allows worms to rapidly spread and cause widespread damage in a short amount of time.
47.
Refer to the exhibit. Which two statements correctly describe how Router1 processes an FTP request that enters interface S0/0/0 and is destined for an FTP server at IP address 192.168.1.5? (Choose two.)
Correct Answer(s)
C. The router matches the incoming packet to the statement that is created from the access-list 101 permit ip any 192.168.1.0 0.0.0.255 command.
E. The packet is allowed into Router1.
Explanation
The correct answer is that the router matches the incoming packet to the statement that is created from the access-list 101 permit ip any 192.168.1.0 0.0.0.255 command and the packet is allowed into Router1. This means that the router has an access list configured (access-list 101) that permits any IP traffic from any source to the IP address range 192.168.1.0/24. Therefore, any FTP request destined for the FTP server at IP address 192.168.1.5 will match this access list statement and be allowed into Router1.
48.
A technician has been asked to run the Cisco SDM one-step lockdown on the router of a customer. What will be the result of this process?
Correct Answer
D. The existing router configurations will be examined and all potential security-related configuration changes will be automatically implemented.
Explanation
Running the Cisco SDM one-step lockdown on the router will result in the existing router configurations being examined and any potential security-related configuration changes being automatically implemented. This process helps to enhance the security of the router by identifying and implementing necessary security configurations.
49.
Which statement is true about wildcard masks?
Correct Answer
D. When a "0" is encountered in a wildcard mask, the IP address bit must be checked.
Explanation
A wildcard mask is used in network addressing to identify the bits that are to be checked or ignored in an IP address. When a "0" is encountered in a wildcard mask, it means that the corresponding bit in the IP address must be checked. This allows for more flexibility in defining network or subnet boundaries. The other statements are incorrect. Inverting the subnet mask does not always create the wildcard mask, as the wildcard mask can have different values for different bits. The wildcard mask and subnet mask have different functions, as the subnet mask defines the network or subnet boundaries while the wildcard mask identifies the bits to be checked.
50.
What type of ACL can be used to force a user to authenticate to the router before accessing a network?
Correct Answer
B. Dynamic
Explanation
Dynamic ACLs can be used to force a user to authenticate to the router before accessing a network. Unlike standard ACLs, which are based on source and destination IP addresses, dynamic ACLs allow for more granular control by considering additional factors such as user authentication. By implementing dynamic ACLs, network administrators can ensure that only authenticated users are granted access to the network, enhancing security and preventing unauthorized access.