ExamGecko
Home Home / Cisco / 300-410

Cisco 300-410 Practice Test - Questions Answers, Page 18

Question list
Search
Search

List of questions

Search

Related questions











When configuring Control Plane Policing on a router to protect it from malicious traffic, an engineer observes that the configured routing protocols start flapping on that device. Which action in the Control Plane Policy prevents this problem in a production environment while achieving the security objective?

A.

Set the conform-action and exceed-action to transmit initially to test the ACLs and transmit rates and apply the Control Plane Policy in the output direction

A.

Set the conform-action and exceed-action to transmit initially to test the ACLs and transmit rates and apply the Control Plane Policy in the output direction

Answers
B.

Set the conform-action and exceed-action to transmit initially to test the ACLs and transmit rates and apply the Control Plane Policy in the input direction

B.

Set the conform-action and exceed-action to transmit initially to test the ACLs and transmit rates and apply the Control Plane Policy in the input direction

Answers
C.

Set the conform-action to transmit and exceed-action to drop to test the ACLs and transmit rates and apply the Control Plane Policy m the input direction

C.

Set the conform-action to transmit and exceed-action to drop to test the ACLs and transmit rates and apply the Control Plane Policy m the input direction

Answers
D.

Set the conform-action to transmit and exceed-action to drop to test the ACLs and transmit rates and apply the Control Plane Policy m the output direction

D.

Set the conform-action to transmit and exceed-action to drop to test the ACLs and transmit rates and apply the Control Plane Policy m the output direction

Answers
Suggested answer: B

Refer to Exhibit.

The network administrator configured the branch router for IPv6 on the E0/0 interface. The neighboring router is fully configured to meet requirements, but the neighbor relationship is not coming up. Which action fixes the problem on the branch router to bring the IPv6 neighbors up?

A.

Enable the IPv4 address family under the router ospfv3 4 process by using the address-family ipv4 unicast command

A.

Enable the IPv4 address family under the router ospfv3 4 process by using the address-family ipv4 unicast command

Answers
B.

Disable IPv6 on the E0/0 interface using the no ipv6 enable command

B.

Disable IPv6 on the E0/0 interface using the no ipv6 enable command

Answers
C.

Enable the IPv4 address family under the E0/0 interface by using the address-family ipv4 unicast command

C.

Enable the IPv4 address family under the E0/0 interface by using the address-family ipv4 unicast command

Answers
D.

Disable OSPF for IPv4 using the no ospfv3 4 area 0 ipv4 command under the E0/0 interface

D.

Disable OSPF for IPv4 using the no ospfv3 4 area 0 ipv4 command under the E0/0 interface

Answers
Suggested answer: A

Explanation:

Once again, Cisco changed the IOS configuration commands required for OSPFv3 configuration. The new OSPFv3 configuration uses the "ospfv3" keyword instead of the earlier "ipv6 router ospf" routing process command and "ipv6 ospf" interface commands.

The Open Shortest Path First version 3 (OSPFv3) address families feature enables both IPv4 and IPv6 unicast traffic to be supported. With this feature, users may have two processes per interface, but only one process per address family (AF).

An engineer is troubleshooting on the console session of a router and turns on multiple debug commands. The console screen is filled with scrolling debug messages that none of the commands can be verified if entered correctly or display any output. Which action allows the engineer to see entered console commands while still continuing the analysis of the debug messages?

A.

Configure the logging synchronous command

A.

Configure the logging synchronous command

Answers
B.

Configure the no logging console debugging command globally

B.

Configure the no logging console debugging command globally

Answers
C.

Configure the logging synchronous level all command

C.

Configure the logging synchronous level all command

Answers
D.

Configure the term no mon command globally

D.

Configure the term no mon command globally

Answers
Suggested answer: A

Explanation:

Let's see how the "logging synchronous" command affect the typing command:

Without this command, a message may pop up and you may not know what you typed if that message is too long. When trying to erase (backspace) your command, you realize you are erasing the message instead.

With this command enabled, when a message pops up you will be put to a new line with your typing command which is very

An engineer must configure a Cisco router to initiate secure connections from the router to other devices in the network but kept failing. Which two actions resolve the issue? (Choose two.)

A.

Configure a source port for the SSH connection to initiate

A.

Configure a source port for the SSH connection to initiate

Answers
B.

Configure a TACACS+ server and enable it

B.

Configure a TACACS+ server and enable it

Answers
C.

Configure transport input ssh command on the console

C.

Configure transport input ssh command on the console

Answers
D.

Configure a domain name

D.

Configure a domain name

Answers
E.

Configure a crypto key to be generated

E.

Configure a crypto key to be generated

Answers
Suggested answer: D, E

Explanation:

Follow these guidelines when configuring the switch as an SSH server or SSH client:

+ An RSA key pair generated by a SSHv1 server can be used by an SSHv2 server, and the reverse.+ If the SSH server is running on a stack master and the stack master fails, the new stack master uses the RSA key pair generated by the previous stack master + If you get CLI error messages after entering the crypto key generate rsa global configuration command, an RSA key pair has not been generated. Reconfigure thehostname and domain, and then enter the crypto key generate rsa command.+ When generating the RSA key pair, the message No host name specified might appear. If it does, you must configure a hostname by using the hostname globalconfiguration command.+ When generating the RSA key pair, the message No domain specified might appear. If it does, you must configure an IP domain name by using the ip domainnameglobal configuration command.+ When configuring the local authentication and authorization authentication method, make sure that AAA is disabled on the console.

Reference:https://www.cisco.com/en/US/docs/switches/lan/catalyst3850/software/release/3.2_0_se/multibook/configuration_guide/b_consolidated_config_guide_3850_chapter_01100

Exhibit:

Bangkok is using ECMP to reach to the 192.168.5.0/24 network. The administrator must configure Bangkok in such a way that Telnet traffic from 192.168.3.0/24 and192.168.4.0/24 networks uses the HongKong router as the preferred router.

Which set of configurations accomplishes this task?

A.

access-list 101 permit tcp 192.168.3.0 0.0.0.255 192.168.5.0 0.0.0.255 access-list 101 permit tcp 192.168.4.0 0.0.0.255 192.168.5.0 0.0.0.255 ! route-map PBR1 permit 10 match ip address 101 set ip next-hop 172.18.1.2 interface Ethernet0/3 ip policy route-map PBR1

A.

access-list 101 permit tcp 192.168.3.0 0.0.0.255 192.168.5.0 0.0.0.255 access-list 101 permit tcp 192.168.4.0 0.0.0.255 192.168.5.0 0.0.0.255 ! route-map PBR1 permit 10 match ip address 101 set ip next-hop 172.18.1.2 interface Ethernet0/3 ip policy route-map PBR1

Answers
B.

access-list 101 permit tcp 192.168.3.0 0.0.0.255 192.168.5.0 0.0.0.255 eq 23 access-list 101 permit tcp 192.168.4.0 0.0.0.255 192.168.5.0 0.0.0.255 eq 23 ! route-map PBR1 permit 10 match ip address 101 set ip next-hop 172.18.1.2 interface Ethernet0/1 ip policy route-map PBR1

B.

access-list 101 permit tcp 192.168.3.0 0.0.0.255 192.168.5.0 0.0.0.255 eq 23 access-list 101 permit tcp 192.168.4.0 0.0.0.255 192.168.5.0 0.0.0.255 eq 23 ! route-map PBR1 permit 10 match ip address 101 set ip next-hop 172.18.1.2 interface Ethernet0/1 ip policy route-map PBR1

Answers
C.

access-list 101 permit tcp 192.168.3.0 0.0.0.255 192.168.5.0 0.0.0.255 eq 23 access-list 101 permit tcp 192.168.4.0 0.0.0.255 192.168.5.0 0.0.0.255 eq 23 ! route-map PBR1 permit 10 match ip address 101 set ip next-hop 172.18.1.2 !i nterface Ethernet0/3 ip policy route-map PBR1

C.

access-list 101 permit tcp 192.168.3.0 0.0.0.255 192.168.5.0 0.0.0.255 eq 23 access-list 101 permit tcp 192.168.4.0 0.0.0.255 192.168.5.0 0.0.0.255 eq 23 ! route-map PBR1 permit 10 match ip address 101 set ip next-hop 172.18.1.2 !i nterface Ethernet0/3 ip policy route-map PBR1

Answers
D.

access-list 101 permit tcp 192.168.3.0 0.0.0.255 192.168.5.0 0.0.0.255 access-list 101 permit tcp 192.168.4.0 0.0.0.255 192.168.5.0 0.0.0.255 ! route-map PBR1 permit 10 match ip address 101 set ip next-hop 172.18.1.2 !i nterface Ethernet0/1 ip policy route-map PBR1

D.

access-list 101 permit tcp 192.168.3.0 0.0.0.255 192.168.5.0 0.0.0.255 access-list 101 permit tcp 192.168.4.0 0.0.0.255 192.168.5.0 0.0.0.255 ! route-map PBR1 permit 10 match ip address 101 set ip next-hop 172.18.1.2 !i nterface Ethernet0/1 ip policy route-map PBR1

Answers
Suggested answer: C

Explanation:

We need to use Policy Based Routing (PBR) here on Bangkok router to match the traffic from 192.168.3.0/24 & 192.168.4.0/24 and "set ip next-hop" to HongKong router(172.18.1.2 in this case).

Note: Please notice that we have to apply the PBR on incoming interface e0/3 to receive traffic from 192.168.3.0/24 and 192.168.4.0/24.

Exhibit:

Which action resolves the authentication problem?

A.

Configure the user name on the TACACS+ server

A.

Configure the user name on the TACACS+ server

Answers
B.

Configure the UDP port 1812 to be allowed on the TACACS+ server

B.

Configure the UDP port 1812 to be allowed on the TACACS+ server

Answers
C.

Configure the TCP port 49 to be reachable by the router

C.

Configure the TCP port 49 to be reachable by the router

Answers
D.

Configure the same password between the TACACS+ server and router.

D.

Configure the same password between the TACACS+ server and router.

Answers
Suggested answer: D

Explanation:

From the last line of the output, we notice that the result was "Invalid AUTHEN packet". Therefore something went wrong with the username or password.

Reference: https://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controlleraccess-control-system-tacacs-/200467-Troubleshoot-TACACS-Authentication-Issue.html

Refer to the exhibit.

The administrator successfully logs into R1 but cannot access privileged mode commands. What should be configured to resolve the issue?

A.

aaa authorization reverse-access

A.

aaa authorization reverse-access

Answers
B.

secret cisco123! at the end of the username command instead of password cisco123!

B.

secret cisco123! at the end of the username command instead of password cisco123!

Answers
C.

matching password on vty lines as cisco123!

C.

matching password on vty lines as cisco123!

Answers
D.

enable secret or enable password commands to enter into privileged mode

D.

enable secret or enable password commands to enter into privileged mode

Answers
Suggested answer: D

Which two protocols work in the control plane of P routers across the MPLS cloud? (choose two)

A.

LSP

A.

LSP

Answers
B.

RSVP

B.

RSVP

Answers
C.

ECMP

C.

ECMP

Answers
D.

LDP

D.

LDP

Answers
E.

MPLS OAM

E.

MPLS OAM

Answers
Suggested answer: B, D

Exhibit:

An engineer configured R2 and R5 as route reflectors and noticed that not all routes are sent to R1 to advertise to the eBGP peers. Which iBGP routers must be configured as route reflectors to advertise all routes to restore reachability across all networks?

A.

R1 and R4

A.

R1 and R4

Answers
B.

R1 and R5

B.

R1 and R5

Answers
C.

R4 and R5

C.

R4 and R5

Answers
D.

R2 and R5

D.

R2 and R5

Answers
Suggested answer: C

Explanation:

When R2 & R5 are route reflectors (RRs), routes from R4 & R8 are advertised to R5 and R5 advertises to R2. But R2 would drop them as R2 is also a RR. Therefore some routes are missing on R1 to advertise to eBGP peers.

Good reference:

https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2015/pdf/TECRST-2310.pdfRoute reflectors (RR) must be fully iBGP meshed so we cannot configure RR on both R1 andR5.

We should choose routers at the center of the topology RRs, in this case R4 & R5.

Refer to exhibit.

Routing protocols are mutually redistributed on R3 and R1. Users report intermittent connectivity to services hosted on the 10.1.1.0/24 prefix. Significant routing update changes are noticed on R3 when the show ip route profile command is run. How must the services be stabilized?

A.

The issue with using BGP must be resolved by using another protocol and redistributing it into EIGRP on R3

A.

The issue with using BGP must be resolved by using another protocol and redistributing it into EIGRP on R3

Answers
B.

The routing loop must be fixed by reducing the admin distance of iBGP from 200 to 100 on R3

B.

The routing loop must be fixed by reducing the admin distance of iBGP from 200 to 100 on R3

Answers
C.

The routing loop must be fixed by reducing the admin distance of OSPF from 110 to 80 on R3

C.

The routing loop must be fixed by reducing the admin distance of OSPF from 110 to 80 on R3

Answers
D.

The issue with using iBGP must be fixed by running eBGP between R3 and R4

D.

The issue with using iBGP must be fixed by running eBGP between R3 and R4

Answers
Suggested answer: B

Explanation:

After redistribution, R3 learns about network 10.1.1.0/24 via two paths:+ Internal BGP (IBGP): advertised from R4 with AD of 200 (and metric of 0)+ OSPF: advertised from R1 with AD of 110 (O E2) (and metric of 20)Therefore R3 will choose the path with the lower AD via OSPF But this is a looped path which is received from R3 -> R2 -> R1 -> R3. So when the advertised route from R4 is expired, the looped path is also expired soon and R3 willreinstall the main path from R4.

This is the cause of intermittent connectivity.In order to solve this issue, we can lower the AD of iBGP to a value which is lower than 110 so that it is preferred over OSPF-advertised route.

Total 570 questions
Go to page: of 57