Sponsor

CCNA 4 v5.0 Practice Final Exam Connecting Networks 2014

Thứ Ba, 15 tháng 4, 2014

CCNA 4 Practice Final Exam – Connecting Networks (Version 5.0) 2014



Which is a clientless VPN solution for mobile workers?
GRE
SSL*
SSH
IPsec

For a VPN, which technology provides secure remote access over broadband?
ADSL
QoS
IPsec*
LTE

A technician is talking to a colleague at a rival company and comparing DSL transfer rates between the two companies. Both companies are in the same city, use the same service provider, and have the same rate/service plan. What is the explanation for why Company A reports higher download speeds than Company B?
Company B shares the conection to the DSLAM with more clients than Company A.
Company A only uses microfilters on branch locations.
Company A is closer to the service provider.*
Company B has a higher volume of POTS voice traffic than Company A.

How does an SNMP trap aid network monitoring and management?
It flags attempts to begin a DoS attack on the network.
It collects information for the management station by using polling devices.
It reports to the management station by responding to polls.
It sends an alert message to the management station when a threshold is reached.*
5

Refer to the exhibit. A PC at address 10.1.1.45 is unable to access the Internet. What is the most likely cause of the problem?
The inside and outside interfaces have been configured backwards.
The wrong netmask was used on the NAT pool.
The NAT pool has been exhausted.*
Access-list 1 has not been configured properly.
6

Refer to the exhibit. A network administrator has configured routers RTA and RTB, but cannot ping from serial interface to serial interface. Which layer of the OSI model is the most likely cause of the problem?
network
physical
application
data link*
transport

A user is unable to connect to the Internet. The network administrator decides to use the top-down troubleshooting approach. Which action should the administrator perform first?
Check the patch cable connection from the PC to the wall.
Run the tracert command to identify the faulty device.
Enter an IP address in the address bar of the web browser to determine if DNS has failed.*
Run the ipconfig command to verify the IP address, subnet mask, and gateway on the PC.
8

Refer to the exhibit. A network administrator has configured router Edge_Router as shown in the output. Connectivity is failing between Edge_Router and a non-Cisco router running Frame Relay. What should be done to repair this Layer 2 connectivity?
Modify the OSPF process-id from 10 to 1.
Issue the frame-relay lmi-type ansi command on interface serial 0/1/0.
Issue the ietf keyword when enabling Frame Relay on interface serial 0/1/0.*
Issue the broadcast keyword when performing static mapping on interface serial 0/1/0.
Correct the IP address used in the frame-relay map command.

What is an advantage of packet-switched technology over circuit-switched technology?
Packet-switched networks do not require an expensive permanent connection to each endpoint.
Packet-switched networks can efficiently use multiple routes inside a service provider network.*
Packet-switched networks usually experience lower latency than circuit-switched networks experience.
Packet-switched networks are less susceptible to jitter than circuit-switched networks are.
10 
A network administrator has moved the company intranet web server from a switch port to a dedicated router interface. How can the administrator determine how this change has affected performance and availability on the company intranet?
Interview departmental administrative assistants and determine if they think load time for web pages has improved.
Compare the hit counts on the company web server for the current week to the values that were recorded in previous weeks.
Determine performance on the intranet by monitoring load times of company web pages from remote sites.
Conduct a performance test and compare with the baseline that was established previously.*
11 
Which statement describes cable?
The cable subscriber must purchase a cable modem termination system (CMTS)
Delivering services over a cable network requires downstream frequencies in the 50 to 860 MHz range, and upstream frequencies in the 5 to 42 MHz range.*
Each cable subscriber has dedicated upstream and downstream bandwidth.
Cable subscribers may expect up to 27 Mbps of bandwidth on the upload path.
12 
Which syslog entry has a severity code that indicates the most serious situation?
Mar 17 06:42:22: 10.1.1.1 %LINK-3-UPDOWN: Interface FastEthernet0/3, changed state to down*
Mar 17 06:43:02: 10.1.1.1 %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/3, changed state to up
Mar 17 06:42:21: 10.1.1.1 %CDP-4-DUPLEX_MISMATCH: duplex mismatch discovered on FastEthernet0/3 (not half duplex), with NA-1.30.foo.com FastEthernet0/24 (half duplex).
Mar 17 06:03:21: 10.1.1.1 %SYS-6-BOOTTIME: Time taken to reboot after reload = 551932 seconds
Mar 17 06:42:20: 10.1.1.1 %SYS-5-CONFIG_I: Configured from console by mwmwm on vty0 (192.168.254.5)
Mar 17 06:42:22: 10.1.1.1 %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/3, changed state to down
13

Refer to the exhibit. R3 has the following configuration:
R3# show running-config
–some output text omitted–
interface serial0
bandwidth 128
ip address 192.168.11.2 255.255.255.0
encapsulation frame-relay
frame-relay map ip 192.168.11.2 30 broadcast
After the command R3# debug frame-relay packet is executed, a ping is issued from R3 to R1 but is unsuccessful. Based on the output of the debug command shown in the graphic and the router configuration, what is the problem?
An incorrect IP address exists in the map statement.*
No clock rate has been configured on interface s0.
The encapsulation frame-relay command is missing the broadcast keyword.
There is an incorrect DLCI number in the map statement
14 
A technician has been asked to configure a broadband connection for a teleworker. The technician has been instructed that all uploads and downloads for the connection must use existing phone lines. Which broadband technology should be used?
cable
ISDN
DSL*
POTS
15 
Which WAN technology uses a fixed payload of 48 bytes and is transported across both switched and permanent virtual circuits?
ISDN
metro Ethernet
Frame Relay
ATM*
16 
Which two statements about NetFlow are true? (Choose two.)
NetFlow can be used to collect performance indicators such as interface errors, CPU usage, and memory usage.
NetFlow traffic collectors use a “pull” based model to acquire traffic statistics from ports of interest.
NetFlow can be used to monitor traffic statistics, including packet payload content.
NetFlow is a Cisco-specific feature that enables the collection of detailed traffic profiles.*
NetFlow can be used to create baseline documentation.*
NetFlow is a network monitoring and event reporting tool.
17 
Which three items are normally included when a log message is generated by a syslog client and forwarded to a syslog server? (Choose three.)
community ID
checksum field
date and time of message*
ID of sending device*
length of message
message ID*
18 
Which statement is true about NCP?
NCP establishes the initial link between PPP devices.
NCP tests the link to ensure that the link quality is sufficient.
Each network protocol has a corresponding NCP.*
Link termination is the responsibility of NCP.
19 
What is IPsec?
a protocol that is used to create a VPN at Layer 2 of the OSI model
a 56-bit authentication and encryption method that must be used to create VPN tunnels
a means by which routers and VPN gateways read and forward packets with encrypted packet headers
a specification for the way in which a group of protocols and algorithms combine to create VPNs*
20
Launch PT Hide and Save PT
Open the PT Activity. Perform the tasks in the activity instructions and then answer the question.
Which message is displayed on the web browser?
PPP is working!*
Configured correctly!
PPP configured!
Well done!
21 
Which statement is true about the operation of a site-to-site VPN connection?
The data is encrypted by the VPN gateway at the sending side and decrypted by the target host.
The data is encrypted by the sending host and decrypted by the VPN gateway at the receiving side.
The data is encrypted and decrypted by VPN gateways at both the sending and receiving sides.*
The data is encrypted and decrypted by the sending and target hosts.
22

Refer to the exhibit. What type of Layer 2 encapsulation will be used for connection D on the basis of this configuration on a newly installed router:
RtrA(config)# interface serial0/0/0
RtrA(config-if)# ip address 128.107.0.2 255.255.255.252
RtrA(config-if)# no shutdown
PPP
HDLC*
Ethernet
Frame Relay
23 
What are two characteristics of DSL technology? (Choose two.)
Filters and splitters allow POTS and DSL traffic to share the same medium.*
DSL download rates are reduced by large volumes of POTS voice traffic.
Service providers deploy DSL in the local loop of the telephone network.*
DSL is a shared medium that allows many users to share bandwidth available from the DSLAM.
Uploads typically offer larger transfer rates than downloads.
24

Refer to the exhibit. A small office uses an ISR to provide connectivity for both wired and wireless computers. One day, a sales person who is using a laptop cannot connect to Server1 through the wireless network. A network technician attempts to determine if the problem is on the wireless or the wired network. The technician pings successfully from the wireless laptop to the default gateway IP address on the ISR. What should be the next troubleshooting step?
Ping from Server1 to its gateway IP address.*
Ping from Server1 to PC1.
Ping from the laptop to the Ethernet port on the cable modem.
Ping from the laptop to PC1
25 
What are two WAN connection enhancements that are achieved by implementing PPPoE? (Choose two.)
Encapsulating Ethernet frames within PPP frames is an efficient use of bandwidth.
DSL CHAP features are included in PPPoE.
PPP enables the ISP to assign an IP address to the customer WAN interface.*
An Ethernet link supports a number of data link protocols.
CHAP enables customer authentication and accounting.*
26 
A company has been assigned the 203.0.113.0/27 block of IP addresses by the ISP. The company has over 6000 internal devices. What type of NAT would be most appropriate for the employee workstations of the company?
dynamic NAT
dynamic NAT overload using the pool of addresses*
static NAT
port forwarding
PAT off the external router interface
27 
What are two significant benefits that are provided by IPsec? (Choose two.)
encapsulation*
encryption*
automatic creation of a private network
automatic creation of a public network
authentication
28 
What makes the Cisco EasyVPN application a useful tool for VPN implementation?
It ensures that remote workers actually use the VPN for connectivity.
It simplifies the configuration tasks for the device that is used as the VPN server.*
It allows a greater variety of network devices to be used for VPN connections.
It provides encryption algorithms unavailable in other systems.
29 
What is the purpose of the Cisco Enterprise Architecture?
It provides services and functionality to the core layer by grouping various components into a single component that is located in the access layer.
It replaces the three-layer hierarchical model with a flat network approach.
It reduces overall network traffic by grouping server farms, the management server, corporate intranet, and e-commerce routers in the same layer.
It provides an enterprise-wide system network architecture that helps protect, optimize, and grow the network infrastructure that supports the business processes of a company.*
30 
Which basic network module of the Enterprise Architecture is the fundamental component of a campus design?
services module
data center
enterprise edge
access-distribution*
31

Refer to the exhibit. An administrator is trying to configure PAT on R1, but PC-A is unable to access the Internet. The administrator tries to ping a server on the Internet from PC-A and collects the debugs that are shown in the exhibit. Based on this output, what is most likely the cause of the problem?
The inside and outside NAT interfaces have been configured backwards.
The NAT source access list matches the wrong address range.
The address on Fa0/0 should be 64.100.0.1.
The inside global address is not on the same subnet as the ISP.*
32 
Which statement best describes a WAN?
WAN is another name for the Internet.
A WAN is a public utility that enables access to the Internet.
A WAN interconnects LANs over long distances.*
A WAN is a LAN that is extended to provide secure remote network access.
33

Refer to the exhibit. A ping from R1 to 10.1.1.2 is successful, but a ping from R1 to any address in the 192.168.2.0 network fails. What is the cause of this problem?
There is no gateway of last resort at R1.
The serial interface between the two routers is down.
The static route for 192.168.2.0 is incorrectly configured.*
A default route is not configured on R1.
34

Refer to the exhibit. Based on the configuration of R1, which device is the inside host and what is the inside local address of this host?
PC-B with address 64.100.0.100
PC-A with address 64.100.0.100
PC-B with address 209.165.200.225*
PC-A with address 209.165.200.225
35 
Which three statements are true regarding the Frame Relay LMI? (Choose three.)
The LMI types supported by Cisco routers are CISCO and IETF.
The LMI uses reserved DLCIs to exchange messages between the DTE and DCE.*
The LMI type must always be manually configured.
The available LMI types are CHAP and PAP.
The LMI provides a virtual circuit (VC) status mechanism.*
The LMI type configured on the router must match the one used on the Frame Relay switch.*
36 
What type of installation is needed to view syslog messages?
A syslog client must be installed on a workstation.
Because any network equipment can interpret syslog messages, nothing special is needed to view them.
A syslog server must be installed on a router.
A syslog server must be installed on a workstation.*
37 
What are three Frame Relay congestion management mechanisms? (Choose three.)
BECN*
FECN*
DE*
DLCI
Inverse ARP
LMI
38 
What is the relationship between the DE and the CIR in Frame Relay?
The DE bit will indicate when the CIR committed burst size should be applied.
When the CIR on a given DLCI is exceeded, the DE bit of frames above the CIR is set.*
When the CIR is exceeded, an Inverse ARP DE message notifies the source to reduce frame transmission speed.
The XON/XOFF flow control mechanism sets the DE bit when the CIR is exceeded.
39 
What can cause a reduction in available bandwidth on a cable broadband connection?
distance from the central office of the provider
committed information rate
smaller cells
number of subscribers*
40 
The output of the show ip interface brief command indicates that Serial0 is up but the line protocol is down. What are two possible causes for the line protocol being in the down state? (Choose two.)
An incorrect default gateway is set on the router.
Keepalives are not being sent by the remote device.*
A network is missing from the routing protocol configuration.
The clock rate is not set on the DTE.
The encapsulation on the Serial0 interface is incorrect.*
41
Launch PT Hide and Save PT
Open the PT activity. Perform the tasks in the activity instructions and then answer the question.
What is the IP address or range of IP addresses that are used as the inside global address for packets that originate from PC1 and are going to the server?​
209.165.200.231 – 209.165.200.239
192.168.10.21
209.165.200.225 – 200.165.200.229*
192.168.10.1 – 192.168.10.254
209.165.200.231
42 
Which three algorithms can be used to encrypt user data in an IPSec VPN framework? (Choose three.)
AES*
SHA
Diffie-Hellman
DES*
ESP
3DES*
43 
An administrator needs to configure a router so that internal network servers are accessible from the Internet. Each server is configured with a private IPv4 address. What type of NAT should the administrator configure?
dynamic NAT
PAT
NAT overloading
static NAT*
44 
Which two Layer 1 requirements are outlined in the Data-over-Cable Service Interface Specification (DOCSIS)? (Choose two.)
channel widths*
modulation techniques*
maximum data rate
access method
compression techniques
45 
What are three parameters that are used by NetFlow to classify traffic? (Choose three.)
TOS field*
number of packets
port number*
ingress interface*
egress interface
number of bytes
46 
Which two products are part of the Cisco Collaboration Architecture? (Choose two.)
Cisco Unified Computing
Cisco Unified Communications*
Cisco Borderless End Point​
Cisco TelePresence​*
Cisco Virtual Private Network
47 
How many addresses will be available for dynamic NAT translation when a router is configured with the following commands?
Router(config)#ip nat pool TAME 209.165.201.23 209.165.201.30 netmask 255.255.255.224 
Router(config)#ip nat inside source list 9 pool TAME
31
24
9
10
8*
7
48 
In the Cisco Enterprise Architectures network design approach what is the purpose of the enterprise edge module?
to provide high-speed connectivity and protection for servers
to provide Internet, VPN, and WAN connections*
to forward traffic from one local network to another
to provide access to IP telephony services, wireless controller services, and unified services
49 
How does STDM allocate bandwidth on a serial connection?
It ensures that bandwidth is allocated to each channel or time slot regardless of whether the station using the channel has data to transmit.
It ensures each of the time slices are assigned to individual conversations.
It keeps track of conversations that require extra bandwidth. It then dynamically reassigns unused time slices on an as-needed basis.*
It statically assigns bandwidth based upon pre-assigned time slots.
50
Refer to the exhibit. While planning an upgrade, a network administrator uses the Cisco NetFlow utility to analyze data flow in the current network. What generated the most packets?
TCP-other*
UDP-DNS
TCP-Telnet
UDP-other
ICMP
Read more ...

CCNA 4 R&S Connecting Networks Chapter 9 v5.0 Exam Answers 2014

Thứ Ba, 15 tháng 4, 2014

CCNA 4 R&S Connecting Networks Chapter 9 v5.0 Exam Answers 2014

1. Users are reporting longer delays in authentication and in accessing network resources during certain time periods of the week. What kind of information should network engineers check to find out if this situation is part of a normal network behavior?
syslog records and messages
the network performance baseline
debug output and packet captures
network configuration files

2. A team of engineers has identified a solution to a significant network problem. The proposed solution is likely to affect critical network infrastructure components. What should the team follow while implementing the solution to avoid interfering with other processes and infrastructure?
change-control procedures
one of the layered troubleshooting approaches
knowledge base guidelines
syslog messages and reports

3. After which step in the network troubleshooting process would one of the layered troubleshooting methods be used?
documenting symptoms
determining ownership
narrowing the scope
gathering symptoms from suspect devices

4. A user reports that the workstation cannot connect to a networked printer in the office in order to print a report created with word processing software. Which troubleshooting action by the helpdesk technician would follow the divide-and-conquer approach?
Ask the user to launch the web browser.
Ask the user to save the working document.
Ask the user to issue the ipconfig command.
Ask the user to unplug and reattach the network cable.

5. A network engineer is troubleshooting a network problem and can successfully ping between two devices. However, Telnet between the same two devices does not work. Which OSI layers should the administrator investigate next?
all of the layers
from the network layer to the application layer
from the network layer to the physical layer
only the network layer

6. Which troubleshooting method begins by examining cable connections and wiring issues?
top-down
bottom-up
substitution
divide-and-conquer

7.

Refer to the exhibit. Which two statements describe the results of entering these commands?(Choose two.)
R1 will send system messages of levels 0 (emergencies) to level 4 (warnings) to a server.
R1 will not send critical system messages to the server until the command debug all is entered.
R1 will reset all the warnings to clear the log.
R1 will output the system messages to the local RAM.
The syslog server has the IPv4 address 192.168.10.10.

8. An administrator is troubleshooting an Internet connectivity problem on a router. The output of the show interfaces gigabitethernet 0/0 command reveals higher than normal framing errors on the interface that connects to the Internet. At what layer of the OSI model is the problem likely occurring?
Layer 1
Layer 2
Layer 3
Layer 4
Layer 7

9. Users report that the new web site http://www.company1.biz cannot be accessed. The helpdesk technician checks and verifies that the web site can be accessed with http://www.company1.biz:90. Which layer in the TCP/IP model is involved in troubleshooting this issue?
application
transport
internet
network access

10. A user reports that after an OS patch of the networking subsystem has been applied to a workstation, it performs very slowly when connecting to network resources. A network technician tests the link with a cable analyzer and notices that the workstation sends an excessive number of frames smaller than 64 bytes and also other meaningless frames. What is the possible cause of the problem?
cabling faults
corrupted NIC driver
Ethernet signal attenuation
corrupted application installation

11. A network administrator is configuring SSH on a router. When verifying the configuration, the administrator notices that the SSH connection requests fail, but the Telnet connection requests from the same workstation are successful. Which two parts of the router configuration should be checked to try to locate the problem? (Choose two.)
The ip access-class command is missing.
The password is misconfigured on the console line.
The transport input command is incorrect on the vty lines.
A standard ACL is possibly blocking the workstation from access to the router.
An extended ACL that is referencing the port argument for SSH is misconfigured.

12. A user in a large office calls technical support to complain that a PC has suddenly lost connectivity to the network. The technician asks the caller to talk to nearby users to see if other machines are affected. The caller reports that several immediate neighbors in the same department have a similar problem and that they cannot ping each other. Those who are seated in other departments have connectivity. What should the technician check as the first step in troubleshooting the issue?
the power outlet to the PC that is used by the caller
the trunks between switches in the wiring closet
the status of the departmental workgroup switch in the wiring closet
the cable that connects the PC of the caller to the network jack
the cable connection between a PC and a network outlet that is used by a neighbor

13. After cables were reconnected to a switch in a wiring closet, several PCs that had been previously configured manually can no longer access resources outside the local network. The PC configurations were not altered in the process and resources on the local network can still be accessed. What is a possible cause of the problem?
The cabling to the PCs is faulty.
The PCs are no longer on the correct VLAN.
The DHCP server has been misconfigured.
The DNS configuration on the PCs is incorrect.

14.

Refer to the exhibit. On the basis of the output, which two statements about network connectivity are correct? (Choose two.)
There is connectivity between this device and the device at 192.168.100.1.
The connectivity between these two hosts allows for videoconferencing calls.
There are 4 hops between this device and the device at 192.168.100.1.
The average transmission time between the two hosts is 2 miliseconds.
This host does not have a default gateway configured.

15. Fill in the blank.
Use the “ ARP   ” cache to verify IPv4 address to Layer 2 Ethernet address mappings on a host computer.

16. Which two specialized troubleshooting tools can monitor the amount of traffic that passes through a switch? (Choose two.)
digital multimeter
TDR
NAM
portable network analyzer
DTX cable analyzer

17. A group of Windows PCs in a new subnet has been added to an Ethernet network. When testing the connectivity, a technician finds that these PCs can access local network resources but not the Internet resources. To troubleshoot the problem, the technician wants to initially confirm the IP address and DNS configurations on the PCs, and also verify connectivity to the local router. Which three Windows CLI commands and utilities will provide the necessary information? (Choose three.)
ipconfig
telnet
ping
arp -a
nslookup
tracert
netsh interface ipv6 show neighbor

18. A company is setting up a web site with SSL technology to protect the authentication credentials required to access the web site. A network engineer needs to verify that the setup is correct and that the authentication is indeed encrypted. Which tool should be used?
baselining tool
cable analyzer
protocol analyzer
fault-management tool

19. In which step of gathering symptoms does the network engineer determine if the problem is at the core, distribution, or access layer of the network?
Determine ownership.
Narrow the scope.
Gather information.
Document the symptoms.
Determine the symptoms.

20. A network technician is troubleshooting an email connection problem. Which question to the end-user will provide clear information to better define the problem?
How big are the emails you tried to send?
When did you first notice your email problem?
Is your email working now?
What kind of equipment are you using to send emails?

21. A network engineer issues the show cdp neighbor command on several network devices during the process of network documentation. What is the purpose of performing this command?
to obtain information about directly connected Cisco devices 
to check the networks that are advertised by the neighboring routers
to verify the network addresses that are attached to the network devices
to check the connectivity of PCs that are connected to the network devices

22.

Refer to exhibit. A network engineer is troubleshooting a WAN connectivity problem. A ping to a remote router is successful and an attempt to telnet to the same router displays the exhibited output. What does the output verify?
A Telnet password has not been configured on the remote router.
The transport layer is connecting successfully.
The web server service is password protected.
The remote router IPv6 address is incorrect.

23. When should a network performance baseline be measured?
after normal work hours to reduce possible interruptions
during normal work hours of an organization 
when a denial of service attack to the network is detected and blocked
immediately after the main network devices restarted

24. Which number represents the most severe level of syslog logging?
7
0
1
10

25.
Place the options in the following order: 
[+] CiscoView 
[+] What’s Up Gold 
[+] HP OpenviewBTO 
[#] SolarWinds LAN surveyor 
[#] CyberGauge software 
[*] Internet search engines 
[*] Cisco Tools & Resources web site
[+] Order does not matter within this group.
[#] Order does not matter within this group.
[*] Order does not matter within this group.
Read more ...

CCNA 4 R&S Connecting Networks Chapter 8 v5.0 Exam Answers 2014

Thứ Ba, 15 tháng 4, 2014

CCNA 4 R&S: Connecting Networks Chapter 8 v5.0 Exam Answers 2014


1.

Refer to the exhibit. Which two conclusions can be drawn from the syslog message that was generated by the router? (Choose two.)
This message resulted from an unusual error requiring reconfiguration of the interface.
This message indicates that the interface should be replaced.
This message is a level 5 notification message.
This message indicates that service timestamps have been configured.
This message indicates that the interface changed state five times.

2. A network technician has issued the service timestamps log datetime command in the configuration of the branch router. Which additional command is required to include the date and time in logged events?
Branch1(config)# service timestamps log uptime
Branch1# clock set 08:00:00 05 AUG 2013
Branch1(config)# service timestamps debug datetime
Branch1# copy running-config startup-config

3.

Refer to the exhibit. From what location have the syslog messages been retrieved?
syslog server
syslog client
router RAM
router NVRAM

4.

Refer to the exhibit. What does the number 17:46:26.143 represent?
the time passed since the syslog server has been started
the time when the syslog message was issued
the time passed since the interfaces have been up
the time on the router when the show logging command was issued

5. What are SNMP trap messages?
messages that are used by the NMS to query the device for data
unsolicited messages that are sent by the SNMP agent and alert the NMS to a condition on the network
messages that are used by the NMS to change configuration variables in the agent device
messages that are sent periodically by the NMS to the SNMP agents that reside on managed devices to query the device for
data

6. How can SNMP access be restricted to a specific SNMP manager?
Use the snmp-server community command to configure the community string with no access level.
Specify the IP address of the SNMP manager by using the snmp-server host command.
Use the snmp-server traps command to enable traps on an SNMP manager.
Define an ACL and reference it by using the snmp-server community command.

7. A network administrator issues two commands on a router:
R1(config)# snmp-server host 10.10.50.25 version 2c campus
R1(config)# snmp-server enable traps
What can be concluded after the commands are entered?
No traps are sent, because the notification-types argument was not specified yet.
Traps are sent with the source IP address as 10.10.50.25.
If an interface comes up, a trap is sent to the server.
The snmp-server enable traps command needs to be used repeatedly if a particular subset of trap types is desired.

8. What is a difference between SNMP and NetFlow?
Unlike NetFlow, SNMP uses a “push”-based model.
NetFlow collects more detailed traffic statistics on IP networks than SNMP does.
SNMP only gathers traffic statistics, whereas NetFlow can also collect many other performance indicators, such as interface
errors and CPU usage.
Unlike NetFlow, SNMP may be used to provide IP accounting for billing purposes.

9. How does NetFlow function on a Cisco router or multilayer switch?
Netflow captures and analyzes traffic.
One user connection to an application exists as two NetFlow flows.
On 2960 switches, Netlow allows for data export.
NetFlow does not consume any additional memory.

10. Which type of information can an administrator obtain with the show ip cache flow command?
the NetFlow version that is enabled
whether NetFlow is configured on the correct interface and in the correct direction
the configuration of the export parameters
the protocol that uses the largest volume of traffic
11. What is the most common purpose of implementing NetFlow in a networked environment?
to support accounting and monitoring with consumer applications
to actively capture traffic from networked devices
to monitor live data usage and to control traffic flow with set messages
to passively capture changing events that occur in the network and to perform after-the-fact-analysis

12. Which destination do Cisco routers and switches use by default when sending syslog messages for all severity levels?
RAM
NVRAM
nearest syslog server
console

13. Which SNMP feature provides a solution to the main disadvantage of SNMP polling?
SNMP community strings
SNMP set messages
SNMP get messages
SNMP trap messages

14. Which statement describes SNMP operation?
A get request is used by the SNMP agent to query the device for data.
A set request is used by the NMS to change configuration variables in the agent device.
An NMS periodically polls the SNMP agents that are residing on managed devices by using traps to query the devices for data.
An SNMP agent that resides on a managed device collects information about the device and stores that information remotely in the MIB that is located on the NMS.

15. A network administrator has issued the logging trap 4 global configuration mode command. What is the result of this command?
After four events, the syslog client will send an event message to the syslog server.
The syslog client will send to the syslog server any event message that has a severity level of 4 and higher.
The syslog client will send to the syslog server event messages with an identification trap level of only 4.
The syslog client will send to the syslog server any event message that has a severity level of 4 and lower.

16. When logging is used, which severity level indicates that a device is unusable?
Critical – Level 2
Alert – Level 1
Emergency-Level 0 
Error-Level 3
17.

Refer to the exhibit. While planning an upgrade, a network administrator uses the Cisco NetFlow utility to analyze data flow in the current network. Which protocol used the greatest amount of network time?
TCP-FTP
TCP-Telnet
UDP-DNS
TCP-other
UDP-other

18. Which two statements describe items to be considered in configuring NetFlow? (Choose two.)
Netflow requires both management and agent software.
NetFlow can only be used if all devices on the network support it.
Netflow can only be used in a unidirectional flow.
Netflow requires UDP port 514 for notification messages.
Netflow consumes additional memory.

19. When SNMPvl or SNMPv2 is being used, which feature provides secure access to MIB objects?
message integrity
source validation
community strings
packet encryption

20.

Refer to the exhibit. What can be concluded from the produced output?
An ACL was configured to restrict SNMP access to an SNMP manager.
This is the output of the show snmp command without any parameters.
The system contact was not configured with the snmp server contact command

21. What are the most common syslog messages?
output messages that are generated from debug output
linkup and link down messages
those that occur when a packet matches a parameter condition in an access control list
error messages about hardware or software malfunctions

22. A network administrator has issued the snmp-server user adminl admin v3 encrypted auth md5 abc789 priv des 256 key99 command. What are two features of this command? (Choose two.)
It forces the network manager to log into the agent to retrieve the SNMP messages.
It restricts SNMP access to defined SNMP managers.
It uses the MD5 authentication of the SNMP messages.
It allows a network administrator to configure a secret encrypted password on the SNMP server.
It adds a new user to the SNMP group.

23. Fill in the blank.
The   “syslog”   protocol uses UDP port 514 and is the most common method to access system messages provided by networking devices.
24 When SNMPv1 or SNMPv2 is being used, which feature provides secure access to MIB objects?
packet encryption
source validation
community strings 
message integrity
25  A network administrator has issued the snmp-server user admin1 admin v3 encrypted auth md5 abc789 priv des 256 key99 command. What are two features of this command? (Choose two.)
It uses the MD5 authentication of the SNMP messages. 
It allows a network administrator to configure a secret encrypted password on the SNMP server.
It adds a new user to the SNMP group. 
It restricts SNMP access to defined SNMP managers.
It forces the network manager to log into the agent to retrieve the SNMP messages.
Read more ...

CCNA 4 R&S Connecting Networks Chapter 7 v5.0 Exam Answers 2014

Thứ Ba, 15 tháng 4, 2014

CCNA 4 R&S Connecting Networks Chapter 7 v5.0 Exam Answers 2014


1. How is “tunneling” accomplished in a VPN?
New headers from one or more VPN protocols encapsulate the original packets.
All packets between two hosts are assigned to a single physical medium to ensure that the packets are kept private.
Packets are disguised to look like other types of traffic so that they will be ignored by potential attackers.
A dedicated circuit is established between the source and destination devices for the duration of the connection.
2. Which two scenarios are examples of remote access VPNs? (Choose two.)
A toy manufacturer has a permanent VPN connection to one of its parts suppliers.
All users at a large branch office can access company resources through a single VPN connection.
A mobile sales agent is connecting to the company network via the Internet connection at a hotel.
A small branch office with three employees has a Cisco ASA that is used to create a VPN connection to the HQ.
An employee who is working from home uses VPN client software on a laptop in order to connect to the company network.
3.

Refer to the exhibit. Which IP address would be configured on the tunnel interface of the destination router?
172.16.1.1
172.16.1.2
209.165.200.225
209.165.200.226
4. Which statement correctly describes IPsec?
IPsec works at Layer 3, but can protect traffic from Layer 4 through Layer 7.
IPsec uses algorithms that were developed specifically for that protocol.
IPsec implements its own method of authentication.
IPsec is a Cisco proprietary standard.
5. What is an IPsec protocol that provides data confidentiality and authentication for IP packets?
AH
ESP
RSA
IKE
6. Which three statements describe the building blocks that make up the IPsec protocol framework? (Choose three.)
IPsec uses encryption algorithms and keys to provide secure transfer of data.
IPsec uses Diffie-Hellman algorithms to encrypt data that is transferred through the VPN.
IPsec uses 3DES algorithms to provide the highest level of security for data that is transferred through a VPN.
IPsec uses secret key cryptography to encrypt messages that are sent through a VPN.
IPsec uses Diffie-Hellman as a hash algorithm to ensure integrity of data that is transmitted through a VPN.
IPsec uses ESP to provide confidential transfer of data by encrypting IP packets.
7. What key question would help determine whether an organization should use an SSL VPN or an IPsec VPN for the remote access solution of the organization?
Is a Cisco router used at the destination of the remote access tunnel?
What applications or network resources do the users need for access?
Are both encryption and authentication required?
Do users need to be able to connect without requiring special VPN software?
8. What is the purpose of a message hash in a VPN connection?
It ensures that the data cannot be duplicated and replayed to the destination.
It ensures that the data is coming from the correct source.
It ensures that the data has not changed while in transit.
It ensures that the data cannot be read in plain text.
9. A network design engineer is planning the implementation of a cost-effective method to interconnect multiple networks securely over the Internet. Which type of technology is required?
a dedicated ISP
a VPN gateway
a leased line
a GRE IP tunnel
10. What is one benefit of using VPNs for remote access?
lower protocol overhead
potential for reduced connectivity costs 
increased quality of service
ease of troubleshooting
11. Which statement describes a characteristic of IPsec VPNs?
IPsec can secure traffic at Layers 1 through 3.
IPsec works with all Layer 2 protocols.
IPsec encryption causes problems with routing.
IPsec is a framework of Cisco proprietary protocols
12. What is the purpose of the generic routing encapsulation tunneling protocol?
to support basic unencrypted IP tunneling using multivendor routers between remote sites
to provide fixed flow-control mechanisms with IP tunneling between remote sites
to manage the transportation of IP multicast and multiprotocol traffic between remote sites
to provide packet level encryption of IP traffic between remote sites
13. Which algorithm is an asymmetrical key cryptosystem?
3DES
DES
AES
RSA
14. A network design engineer is planning the implementation of an IPsec VPN. Which hashing algorithm would provide the strongest level of message integrity?
512-bit SHA
AES
SHA-1
MD5
15. What two encryption algorithms are used in IPsec VPNs? (Choose two.)
IKE
DH
PSK
3DES
AES
16. Which statement describes a feature of site-to-site VPNs?
Internal hosts send normal, unencapsulated packets.
VPN client software is installed on each host.
The VPN connection is not statically defined.
Individual hosts can enable and disable the VPN connection.
17. Which Cisco VPN solution provides limited access to internal network resources by utilizing a Cisco ASA and provides browser-based access only?
clientless SSL VPN 
IPsec
SSL
client-based SSL VPN
18. Which two algorithms use Hash-based Message Authentication Code for message authentication? (Choose two.)
AES
DES
3DES
MD5
SHA
19. Which function of IPsec security services allows the receiver to verify that the data was transmitted without being changed or altered in any way?
confidentiality
anti-replay protection
data integrity
authentication
20.

Open the PT Activity. Perform the tasks in the activity instructions and then answer the question. What problem is preventing the hosts from communicating across the VPN tunnel?
The EIGRP configuration is incorrect.
The tunnel destinations addresses are incorrect.
The tunnel IP addresses are incorrect.
The tunnel source interfaces are incorrect
21. What is the purpose of utilizing Diffie-Hellman (DH) algorithms as part of the IPsec standard?
DH algorithms allow unlimited parties to establish a shared public key that is used by encryption and hash algorithms.
DH algorithms allow two parties to establish a shared public key that is used by encryption and hash algorithms.
DH algorithms allow two parties to establish a shared secret key that is used by encryption and hash algorithms.
DH algorithms allow unlimited parties to establish a shared secret key that is used by encryption and hash algorithms.
22.
Refer to the exhibit. A tunnel was implemented between routers R1 and R2. Which two conclusions can be drawn from the R1 command output? (Choose two.)
The data that is sent across this tunnel is not secure.
This tunnel mode provides encryption.
This tunnel mode does not support IP multicast tunneling.
A GRE tunnel is being used. 
This tunnel mode is not the default tunnel interface mode for Cisco IOS software.
23. Two corporations have just completed a merger. The network engineer has been asked to connect the two corporate networks without the expense of leased lines. Which solution would be the most cost effective method of providing a proper and secure connection between the two corporate networks?
Cisco AnyConnect Secure Mobility Client with SSL
Frame Relay
remote access VPN using IPsec
Cisco Secure Mobility Clientless SSL VPN
site-to-site VPN
24. Which remote access implementation scenario will support the use of generic routing encapsulation tunneling?
a mobile user who connects to a SOHO site
a central site that connects to a SOHO site without encryption 
a branch office that connects securely to a central site
a mobile user who connects to a router at a central site
Read more ...

CCNA 4 R&S Connecting Networks Chapter 6 v5.0 Exam Answers 2014

Thứ Ba, 15 tháng 4, 2014

CCNA 4 R&S Connecting Networks Chapter 6 v5.0 Exam Answers 2014


1. What are two Layer 2 WAN technologies that can provide secure remote connections between corporate branch offices? (Choose two.)
LTE
Frame Relay
leased lines
QoS
IPsec
2. Which two OSI Layer 1 specifications does DOCSIS define for a cable Internet connection? (Choose two.)
a deterministic media access method
channel bandwidth
modulation technique
VPN tunneling requirements
the separation of the voice and data transmissions
3. Which medium is used for delivering data via DSL technology through PSTN?
fiber
copper
radifrequency
wireless
4. A company is looking for the least expensive broadband solution that provides at least 10 Mb/s download speed. The company is located 5 miles from the nearest provider. Which broadband solution would be appropriate?
satellite
DSL
WiMax
cable
5. What are twcharacteristics of a PPPoE configuration on a Cisccustomer router? (Choose two.)
The PPP configuration is on the dialer interface.
An MTU size of 1492 bytes is configured on the Ethernet interface.
The Ethernet interface does not have an IP address.
The customer router CHAP username and password are independent of what is configured on the ISP router.
The dialer pool command is applied tthe Ethernet interface tlink it tthe dialer interface.
6. Fill in the blank.
DOCSIS specifies the  ”MAC“  sub-layer as a Layer 2 requirement that defines either a deterministic access method, TDMA, or S-CDMA.
7. Fill in the blank. Use only an acronym.
PPPoE”   creates a PPP tunnel through the DSL connection for the purpose of sending PPP frames.
8. What functionality is required on routers tprovide remote workers with VoIP and videoconferencing capabilities?
PPPoE
QoS
VPN
IPsec
9. Which broadband wireless technology is based on the 802.11 standard?
CDMA
municipal Wi-Fi
UMTS
WiMAX
10. Why is the MTU for a PPPoE DSL configuration reduced from 1500 bytes t1492?
to enable CHAP authentication
to accommodate the PPPoE headers
to reduce congestion on the DSL link
to establish a secure tunnel with less overhead
11. Which standard specifies the channel frequencies and the deterministic access method of cable networks?
DOCSIS
802.16
LTE
WIMAX
12. Which two network components does a teleworker require to connect remotely and securely from home to the corporate network? (Choose two.)
VPN client software or VPN-enabled router
broadband Internet connection
VPN server or concentrator
authentication server
multifunction security appliance
13. In which layer of the TCP/IP protocol model does IPsec apply security to network data?
application
transport
internet
network
access
14. Which cable network communication technology is secure, extremely resistant to noise, and employs spread-spectrum technology?
CDMA
S-CDMA
FDMA
TDMA
15. How is voice traffic affected when the customer uses ADSL technology?
No special equipment is needed to separate voice and data signals.
Voice traffic is interrupted if the ADSL service fails.
Voice signals are on a separate wire pair from ADSL signals.
ADSL signals can distortvoice transmissions.
16. Which technology provides a secure connection between a SOHO and the headquarters office?
PPPoE
QoS
WiMax
VPN
17. What are two characteristics of a PPPoE configuration on a Cisco customer router? (Choose two.)
The customer router CHAP username and password are independent of what is configured on the ISP router.
The PPP configuration is on the dialer interface.
An MTU size of 1492 bytes is configured on the Ethernet interface.
The Ethernet interface does not have an IP address.
The dialer pool command is applied to the Ethernet interface to link it to the dialer interface.
18. What advantage does DSL have compared to cable technology?
DSL upload and download speeds are always the same.
DSL is not a shared medium.
DSL is faster.
DSL has no distance limitations.
19. What are two disadvantages of employing teleworkers in an organization? (Choose two.)
slower customer service response times
increased usage of sick or vacation days
increased difficulty of tracking task progress
increase in office expenses
the need to implement a new management style
20. 
Place the options in the following order: 
WiMax 
Cellular/Mobile 
Satellite 
– not scored -

21. Which DSL technology provides higher downstream bandwidth to the user than upstream bandwidth?
SDSL
TDMA
CDMA
ADSL
22. Which networking technology will ensure reliable and secure remote access when a teleworker connects to a corporate network?
an encrypted VPN tunnel 
routers with QoS capability
broadband (cable or DSL) access to the corporate network
a VoIP and videoconferencing capable connection
23. Which broadband technology would be best for a user that needs remote access when traveling in mountains and at sea?
satellite 
Wi-Fi Mesh
mobile broadband
WiMax
24. Which type of long distance telecommunication technology provides point-to-point connections and cellular access?
WiMax
satellite
mobile broadband
municipal Wi-Fi
25. What functionality is required on routers to provide remote workers with VoIP and videoconferencing capabilities?
QoS
VPN
PPPoE
IPsec
26
A company is looking for the least expensive broadband solution that provides at least 10 Mb/s download speed. The company is located 5 miles from the nearest provider. Which broadband solution would be appropriate?
satellite
DSL
WiMax
cable
Read more ...

Advertisment