Download CCNA 2 Final Exam 91 Questions with Complete Solutions. and more Exams Computer Science in PDF only on Docsity! CCNA 2 Final Exam 91 Questions with Complete Solutions. What are two features of a link-state routing protocol? (Choose two.) The database information for each router is obtained from the same source. Routers send triggered updates in response to a change. Routers create a topology of the network by using information from other routers. Paths are chosen based on the lowest number of hops to the designated router. Routers send periodic updates only to neighboring routers. - Correct Answer Routers send triggered updates in response to a change. Routers create a topology of the network by using information from other routers. Fill in the blank. In IPv6, all routes are level ___ ultimate routes. - Correct Answer 1 Which switching method drops frames that fail the FCS check? ingress port buffering cut-through switching store-and-forward switching borderless switching - Correct Answer store-and-forward switching Which summary IPv6 static route statement can be configured to summarize only the routes to networks 2001:db8:cafe::/58 through 2001:db8:cafe:c0::/58? ipv6 route 2001:db8:cafe::/54 S0/0/0 ipv6 route 2001:db8:cafe::/60 S0/0/0 ipv6 route 2001:db8:cafe::/62 S0/0/0 ipv6 route 2001:db8:cafe::/56 S0/0/0 - Correct Answer ipv6 route 2001:db8:cafe::/56 S0/0/0 When a Cisco switch receives untagged frames on a 802.1Q trunk port, which VLAN ID is the traffic switched to by default? data VLAN ID native VLAN ID unused VLAN ID management VLAN ID - Correct Answer native VLAN ID A college marketing department has a networked storage device that uses the IP address 10.18.7.5, TCP port 443 for encryption, and UDP port 4365 for video streaming. The college already uses PAT on the router that connects to the Internet. The router interface has the public IP address of 209.165.200.225/30. The IP NAT pool currently uses the IP addresses ranging from 209.165.200.228-236. Which configuration would the network administrator add to allow this device to be accessed by the marketing personnel from home? ip nat pool mktv 10.18.7.5 10.18.7.5 ip nat inside source static tcp 10.18.7.5 443 209.165.200.225 443 ip nat inside source static udp 10.18.7.5 4365 209.165.200.225 4365 ip nat inside source static tcp 209.165.200.225 443 10.18.7.5 443 ip nat inside source static udp 209.165.200.225 4365 10.18.7.5 4365 No additional configuration is necessary. ip nat outside source static 10.18.7.5 209.165.200.225 - Correct Answer ip nat inside source static tcp 10.18.7.5 443 209.165.200.225 443 ip nat inside source static udp 10.18.7.5 4365 209.165.200.225 4365 Which statement describes a route that has been learned dynamically? It is automatically updated and maintained by routing protocols. It is unaffected by changes in the topology of the network. It has an administrative distance of 1. It is identified by the prefix C in the routing table. - Correct Answer It is automatically updated and maintained by routing protocols. A network administrator is explaining to a junior colleague the use of the lt and gt keywords when filtering packets using an extended ACL. Where would the lt or gt keywords be used? Which two packet filters could a network administrator use on an IPv4 extended ACL? (Choose two.) computer type source TCP hello address ICMP message type destination UDP port number destination MAC address - Correct Answer ICMP message type destination UDP port number https://lh6.googleusercontent.com/- m0YrCpPdO1Y/UvwMKCwhxvI/AAAAAAAAAkg/ulKZo8mnIxU/w560-h220-no/15-final- ccna2.png Refer to the exhibit. R1 was configured with the static route command ip route 209.165.200.224 255.255.255.224 S0/0/0 and consequently users on network 172.16.0.0/16 are unable to reach resources on the Internet. How should this static route be changed to allow user traffic from the LAN to reach the Internet? Add an administrative distance of 254. Change the destination network and mask to 0.0.0.0 0.0.0.0 Change the exit interface to S0/0/1. Add the next-hop neighbor address of 209.165.200.226. - Correct Answer Change the destination network and mask to 0.0.0.0 0.0.0.0 How is the router ID for an OSPFv3 router determined? the highest IPv6 address on an active interface the highest EUI-64 ID on an active interface the highest IPv4 address on an active interface the lowest MAC address on an active interface - Correct Answer the highest IPv4 address on an active interface Two employees in the Sales department work different shifts with their laptop computers and share the same Ethernet port in the office. Which set of commands would allow only these two laptops to use the Ethernet port and create violation log entry without shutting down the port if a violation occurs? switchport mode access switchport port-security switchport mode access switchport port-security switchport port-security maximum 2 switchport port-security mac-address sticky switchport port-security violation restrict switchport mode access switchport port-security maximum 2 switchport port-security mac-address sticky switchport mode access switchport port-security maximum 2 switchport port-security mac-address sticky switchport port-security violation protect - Correct Answer switchport mode access switchport port-security switchport port-security maximum 2 switchport port-security mac-address sticky switchport port-security violation restrict Which two factors are important when deciding which interior gateway routing protocol to use? (Choose two.) speed of convergence scalability ISP selection the autonomous system that is used campus backbone architecture - Correct Answer speed of convergence scalability https://lh4.googleusercontent.com/-2huzHCgrK6M/UvwMKBTZg- I/AAAAAAAAAk0/Fb_LhbIEYJs/w529-h230-no/19-final-ccna2.png ultimate route child route default route level 1 parent route - Correct Answer level 1 parent route What caused the following error message to appear? 01:11:12: %PM-4-ERR_DISABLE: psecure-violation error detected on Fa0/8, putting Fa0/8 in err-disable state 01:11:12: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occurred, caused by MAC address 0011.a0d4.12a0 on port FastEthernet0/8. 01:11:13: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/8, changed state to down 01:11:14: %LINK-3-UPDOWN: Interface FastEthernet0/8, changed state to down An unauthorized user tried to telnet to the switch through switch port Fa0/8. NAT was enabled on a router, and a private IP address arrived on switch port Fa0/8. Port security was enabled on the switch port, and an unauthorized connection was made on switch port Fa0/8. Another switch was connected to this switch port with the wrong cable. A host with an invalid IP address was connected to a switch port that was previously unused. - Correct Answer Port security was enabled on the switch port, and an unauthorized connection was made on switch port Fa0/8. Which two statements are characteristics of routed ports on a multilayer switch? (Choose two.) In a switched network, they are mostly configured between switches at the core and distribution layers. They support subinterfaces, like interfaces on the Cisco IOS routers. The interface vlan command has to be entered to create a VLAN on routed ports. They are used for point-to-multipoint links. They are not associated with a particular VLAN. - Correct Answer In a switched network, they are mostly configured between switches at the core and distribution layers. interconnection of large-scale networks in wiring closets network access to the user fault isolation high-speed backbone connectivity - Correct Answer interconnection of large-scale networks in wiring closets A small-sized company has 20 workstations and 2 servers. The company has been assigned a group of IPv4 addresses 209.165.200.224/29 from its ISP. What technology should the company implement in order to allow the workstations to access the services over the Internet? static NAT dynamic NAT port address translation DHCP - Correct Answer dynamic NAT Which three requirements are necessary for two OSPFv2 routers to form an adjacency? (Choose three.) The link interface subnet masks must match. The two routers must include the inter-router link network in an OSPFv2 network command. The OSPFv2 process ID must be the same on each router. The OSPF hello or dead timers on each router must match. The OSPFv2 process is enabled on the interface by entering the ospf process area-id command. The link interface on each router must be configured with a link-local address. - Correct Answer The link interface subnet masks must match. The two routers must include the inter-router link network in an OSPFv2 network command. The OSPF hello or dead timers on each router must match. Which three pieces of information does a link-state routing protocol use initially as link- state information for locally connected links? (Choose three.) the cost of that link the type of network link the link bandwidth the link next-hop IP address the link router interface IP address and subnet mask - Correct Answer the cost of that link the type of network link the link router interface IP address and subnet mask What is a disadvantage of NAT? The internal hosts have to use a single public IPv4 address for external communication. There is no end-to-end addressing. The costs of readdressing hosts can be significant for a publicly addressed network. The router does not need to alter the checksum of the IPv4 packets. - Correct Answer There is no end-to-end addressing. https://lh3.googleusercontent.com/- oGhHS0mqtT0/UvwMLXF6h0I/AAAAAAAAAlM/c6zpr3Cv2Aw/w483-h333-no/33-final- ccna2.png Refer to the exhibit. The partial configuration that is shown was used to configure router on a stick for VLANS 10, 30, and 50. However, testing shows that there are some connectivity problems between the VLANs. Which configuration error is causing this problem? There is no IP address configured for the FastEthernet 0/0 interface. A configuration for the native VLAN is missing. The wrong VLAN has been configured on subinterface Fa0/0.50. The VLAN IP addresses should belong to the same subnet. - Correct Answer The wrong VLAN has been configured on subinterface Fa0/0.50. https://lh6.googleusercontent.com/-nrq_Fq7mPes/UvwMMjG- ANI/AAAAAAAAAlI/qbGSOu3YXtQ/w750-h330-no/34-final-ccna2.png Refer to the exhibit. R1 has been configured as shown. However, PC1 is not able to receive an IPv4 address. What is the problem? R1 is not configured as a DHCPv4 server. A DHCP server must be installed on the same LAN as the host that is receiving the IP address. The ip address dhcp command was not issued on the interface Gi0/1. The ip helper-address command was applied on the wrong interface. - Correct Answer The ip helper-address command was applied on the wrong interface. What best describes the operation of distance vector routing protocols? They use hop count as their only metric. They send their routing tables to directly connected neighbors. They flood the entire network with routing updates. They only send out updates when a new network is added. - Correct Answer They send their routing tables to directly connected neighbors. A network administrator is using the router-on-a-stick method to configure inter-VLAN routing. Switch port Gi1/1 is used to connect to the router. Which command should be entered to prepare this port for the task? Switch(config)# interface gigabitethernet 1/1 Switch(config-if)# spanning-tree vlan 1 Switch(config)# interface gigabitethernet 1/1 Switch(config-if)# spanning-tree portfast No router ID has been configured on the routers. The gigabit interfaces are passive. - Correct Answer The serial interfaces of the routers are in different subnets. https://lh6.googleusercontent.com/- rmcc79vOeBY/UvwMNMQIfrI/AAAAAAAAAlc/e1zIR2uKWyU/w543-h372-no/42-final- ccna2.png Which command will create a static route on R2 in order to reach PC B? R1(config)# ip route 172.16.2.0 255.255.255.0 172.16.2.254 R1(config)# ip route 172.16.2.0 255.255.255.0 172.16.3.1 R1(config)# ip route 172.16.2.1 255.255.255.0 172.16.3.1 R1(config)# ip route 172.16.3.0 255.255.255.0 172.16.2.254 - Correct Answer R1(config)# ip route 172.16.2.0 255.255.255.0 172.16.3.1 Which problem is evident if the show ip interface command shows that the interface is down and the line protocol is down? The no shutdown command has not been issued on the interface. There is an IP address conflict with the configured address on the interface. A cable has not been attached to the port. An encapsulation mismatch has occurred. - Correct Answer A cable has not been attached to the port. Which three values or sets of values are included when creating an extended access control list entry? (Choose three.) access list number between 100 and 199 source subnet mask and wildcard mask default gateway address and wildcard mask source address and wildcard mask destination subnet mask and wildcard mask access list number between 1 and 99 destination address and wildcard mask - Correct Answer access list number between 100 and 199 source address and wildcard mask destination address and wildcard mask A network administrator is designing an ACL. The networks 192.168.1.0/25, 192.168.0.0/25, 192.168.0.128/25, 192.168.1.128/26, and 192.168.1.192/26 are affected by the ACL. Which wildcard mask, if any, is the most efficient to use when specifying all of these networks in a single ACL permit entry? 0.0.0.127 0.0.0.255 0.0.1.255 0.0.255.255 A single ACL command and wildcard mask should not be used to specify these particular networks or other traffic will be permitted or denied and present a security risk. - Correct Answer 0.0.1.255 Which kind of message is sent by a DHCP client when its IP address lease has expired? a DHCPREQUEST unicast message a DHCPREQUEST broadcast message a DHCPDISCOVER broadcast message a DHCPDISCOVER unicast message - Correct Answer a DHCPREQUEST unicast message What happens immediately after two OSPF routers have exchanged hello packets and have formed a neighbor adjacency? They request more information about their databases. They negotiate the election process if they are on a multiaccess network. They exchange DBD packets in order to advertise parameters such as hello and dead intervals. They exchange abbreviated lists of their LSDBs - Correct Answer They exchange abbreviated lists of their LSDBs What benefit does NAT64 provide? It allows sites to use private IPv4 addresses, and thus hides the internal addressing structure from hosts on public IPv4 networks. It allows sites to connect multiple IPv4 hosts to the Internet via the use of a single public IPv4 address. It allows sites to connect IPv6 hosts to an IPv4 network by translating the IPv6 addresses to IPv4 addresses. It allows sites to use private IPv6 addresses and translates them to global IPv6 addresses. - Correct Answer It allows sites to connect IPv6 hosts to an IPv4 network by translating the IPv6 addresses to IPv4 addresses. What is the purpose of setting the native VLAN separate from data VLANs? The native VLAN is for routers and switches to exchange their management information, so it should be different from data VLANs. A separate VLAN should be used to carry uncommon untagged frames to avoid bandwidth contention on data VLANs. The native VLAN is for carrying VLAN management traffic only. The security of management frames that are carried in the native VLAN can be enhanced - Correct Answer A separate VLAN should be used to carry uncommon untagged frames to avoid bandwidth contention on data VLANs. Which command, when issued in the interface configuration mode of a router, enables the interface to acquire an IPv4 address automatically from an ISP, when that link to the ISP is enabled? ip helper-address https://lh6.googleusercontent.com/- cAFW81fa0TI/UvwMOgGX4wI/AAAAAAAAAlw/X20PLwf3AUg/w544-h295-no/57-final- ccna2.png Refer to the exhibit. What summary static address would be configured on R1 to advertise to R3? 192.168.0.0/24 192.168.0.0/23 192.168.0.0/22 192.168.0.0/21 - Correct Answer 192.168.0.0/22 Fill in the blank. Static routes are configured by the use of the ____________ global configuration command. - Correct Answer ip route Which three pairs of trunking modes will establish a functional trunk link between two Cisco switches? (Choose three.) dynamic desirable - dynamic auto dynamic auto - dynamic auto access - dynamic auto dynamic desirable - dynamic desirable access - trunk dynamic desirable - trunk - Correct Answer dynamic desirable - dynamic auto dynamic desirable - dynamic desirable dynamic desirable - trunk Fill in the blank. The OSPF Type 1 packet is the _________ packet. - Correct Answer hello Which value represents the "trustworthiness" of a route and is used to determine which route to install into the routing table when there are multiple routes toward the same destination? routing protocol outgoing interface metric administrative distance - Correct Answer administrative distance Fill in the blank. The default administrative distance for a static route is ________. - Correct Answer 1 Fill in the blank. Static routes are configured by the use of the global configuration command. - Correct Answer ip route Refer to the exhibit. If the switch reboots and all routers have to re-establish OSPF adjacencies, which routers will become the new DR and BDR? Router R3 will become the DR and router R1 will become the BDR. Router R1 will become the DR and router R2 will become the BDR. Router R4 will become the DR and router R3 will become the BDR. Router R1 will become the DR and router R2 will become the BDR. - Correct Answer Router R4 will become the DR and router R3 will become the BDR. What is the purpose of an access list that is created as part of configuring IP address translation? The access list permits or denies specific addresses from entering the device doing the translation. The access list defines the private IP addresses that are to be translated. The access list prevents external devices from being a part of the address translation. The access list defines the valid public addresses for the NAT or PAT pool. - Correct Answer The access list defines the private IP addresses that are to be translated. The computers used by the network administrators for a school are on the 10.7.0.0/27 network. Which two commands are needed at a minimum to apply an ACL that will ensure that only devices that are used by the network administrators will be allowed Telnet access to the routers? (Choose two.) -ip access-group 5 out -access-list standard VTY permit 10.7.0.0 0.0.0.127 -access-list 5 deny any -access-list 5 permit 10.7.0.0 0.0.0.31 -ip access-group 5 in -access-class 5 in - Correct Answer -access-list 5 permit 10.7.0.0 0.0.0.31 -access-class 5 in While analyzing log files, a network administrator notices reoccurring native VLAN mismatches. What is the effect of these reoccurring errors? The control and management traffic on the error-occurring trunk port is being misdirected or dropped. Unexpected traffic on the error-occurring trunk port is being received. All traffic on the error-occurring trunk port is being misdirected or dropped. All traffic on the error-occurring trunk port is being switched correctly regardless of the error. - Correct Answer The control and management traffic on the error-occurring trunk port is being misdirected or dropped. Which two characteristics describe the native VLAN? (Choose two.) This VLAN is necessary for remote management of a switch. router(config-router)# network 172.16.1.0 0.0.255.255 area 0 router(config-router)# network 172.16.0.0 0.0.15.255 area 0 router(config-router)# network 172.16.1.0 255.255.255.0 area 0 router(config-router)# network 172.16.1.0 0.0.0.0 area 0 - Correct Answer router(config- router)# network 172.16.1.0 0.0.255.255 area 0 https://lh6.googleusercontent.com/-WHr9kBVL-Ew/VQbF9wu- QTI/AAAAAAAAEBM/biy5xjhns5k/w509-h61-no/ccna1chap3%2Bnewquestion1.gif Refer to the exhibit. Which type of IPv6 static route is configured in the exhibit? fully specified static route recursive static route directly attached static route floating static route - Correct Answer recursive static route Which subnet mask would be used as the classful mask for the IP address 192.135.250.27? 255.0.0.0 255.255.0.0 255.255.255.0 255.255.255.224 - Correct Answer 255.255.255.0 Which subnet mask would be used as the classful mask for the IP address 128.107.52.27? 255.0.0.0 255.255.0.0 255.255.255.0 255.255.255.224 - Correct Answer 255.255.0.0 The buffers for packet processing and the running configuration file are temporarily stored in which type of router memory? Flash NVRAM RAM ROM - Correct Answer RAM A network technician is configuring port security on switches. The interfaces on the switches are configured in such a way that when a violation occurs, packets with unknown source address are dropped and no notification is sent. Which violation mode is configured on the interfaces? off restrict protect shutdown - Correct Answer protect A standard ACL has been configured on a router to allow only clients from the 10.11.110.0/24 network to telnet or to ssh to the VTY lines of the router. Which command will correctly apply this ACL? access-group 11 in access-class 11 in access-list 11 in access-list 110 in - Correct Answer access-group 11 in Refer to the exhibit. What address will summarize the LANs attached to routers 2-A and 3-A and can be configured in a summary static route to advertise them to an upstream neighbor? 10.0.0.0/24 10.0.0.0/23 10.0.0.0/22 10.0.0.0/21 - Correct Answer 10.0.0.0/21 A security specialist designs an ACL to deny access to a web server from all sales staff. The sales staff are assigned addressing from the IPv6 subnet 2001:db8:48:2c::/64. The web server is assigned the address 2001:db8:48:1c::50/64. Configuring the WebFilter ACL on the LAN interface for the sales staff will require which three commands? (Choose three.) permit tcp any host 2001:db8:48:1c::50 eq 80 deny tcp host 2001:db8:48:1c::50 any eq 80 deny tcp any host 2001:db8:48:1c::50 eq 80 permit ipv6 any any deny ipv6 any any ip access-group WebFilter in ipv6 traffic-filter WebFilter in - Correct Answer deny tcp host 2001:db8:48:1c::50 any eq 80 deny tcp any host 2001:db8:48:1c::50 eq 80 deny ipv6 any any To enable RIP routing for a specific subnet, the configuration command network 192.168.5.64 was entered by the network administrator. What address, if any, appears in the running configuration file to identify this network? 192.168.5.64 192.168.5.0 192.168.0.0