ExamGecko
Home Home / Cisco / 350-401

Cisco 350-401 Practice Test - Questions Answers, Page 22

Question list
Search
Search

Related questions











The login method is configured on the VTY lines of a router with these parameters The first method for authentication it TACACS If TACACS is unavailable login is allowed without any provided credentials Which configuration accomplishes this task?

A.

Option A

A.

Option A

Answers
B.

Option B

B.

Option B

Answers
C.

Option C

C.

Option C

Answers
D.

Option D

D.

Option D

Answers
Suggested answer: B

Which network devices secure API platform?

A.

next-generation intrusion detection systems

A.

next-generation intrusion detection systems

Answers
B.

Layer 3 transit network devices

B.

Layer 3 transit network devices

Answers
C.

content switches

C.

content switches

Answers
D.

web application firewalls

D.

web application firewalls

Answers
Suggested answer: D

Explanation:

Reference: https://www.cisco.com/c/en/us/products/collateral/security/advanced-waf-bot-aag.pdf

> Cisco® Secure Web Application Firewall (WAF) and bot protection defends your

> online presence and ensures that website, mobile applications, and APIs

> are secure, protected, and "always on."

Refer to the exhibit.

What is required to configure a second export destination for IP address 192.168.10.1?

A.

Specify a VRF.

A.

Specify a VRF.

Answers
B.

Specify a different UDP port.

B.

Specify a different UDP port.

Answers
C.

Specify a different flow ID

C.

Specify a different flow ID

Answers
D.

Configure a version 5 flow-export to the same destination.

D.

Configure a version 5 flow-export to the same destination.

Answers
E.

Specify a different TCP port.

E.

Specify a different TCP port.

Answers
Suggested answer: B

Explanation:

To configure multiple NetFlow export destinations to a router, use the following commands in global configuration mode:

Step 1: Router(config)# ip flow-export destination ip-address udp-port Step 2: Router(config)# ip flow-export destination ip-address udp-port The following example enables the exporting of information in NetFlow cache entries: ip flow-export destination 10.42.42.1 9991 ip flow-export destination 10.0.101.254 1999

Reference: https://www.cisco.com/c/en/us/td/docs/ios/12_0s/feature/guide/12s_mdnf.html

Which threat defence mechanism, when deployed at the network perimeter, protects against zeroday attacks?

A.

intrusion prevention

A.

intrusion prevention

Answers
B.

stateful inspection

B.

stateful inspection

Answers
C.

sandbox

C.

sandbox

Answers
D.

SSL decryption

D.

SSL decryption

Answers
Suggested answer: C

Explanation:

Reference: https://www.cisco.com/c/en/us/products/collateral/security/amp-appliances/datasheetc78-733182.html"File analysis and sandboxing: Secure Malware Analytics' highly secure environment helps youexecute, analyze, and test malware behavior to discover previously unknown ZERO-DAY threats. Theintegration of Secure Malware Analytics' sandboxing technology into Malware Defense results inmore dynamic analysis checked against a larger set of behavioral indicators. "

Refer to the exhibit.

A company requires that all wireless users authenticate using dynamic key generation. Which configuration must be applied?

A.

AP(config-if-ssid)# authentication open wep wep_methods

A.

AP(config-if-ssid)# authentication open wep wep_methods

Answers
B.

AP(config-if-ssid)# authentication dynamic wep wep_methods

B.

AP(config-if-ssid)# authentication dynamic wep wep_methods

Answers
C.

AP(config-if-ssid)# authentication dynamic open wep_dynamic

C.

AP(config-if-ssid)# authentication dynamic open wep_dynamic

Answers
D.

AP(config-if-ssid)# authentication open eap eap_methods

D.

AP(config-if-ssid)# authentication open eap eap_methods

Answers
Suggested answer: D

Which OSPF networks types are compatible and allow communication through the two peering devices?

A.

broadcast to nonbroadcast

A.

broadcast to nonbroadcast

Answers
B.

point-to-multipoint to nonbroadcast

B.

point-to-multipoint to nonbroadcast

Answers
C.

broadcast to point-to-point

C.

broadcast to point-to-point

Answers
D.

point-to-multipoint to broadcast

D.

point-to-multipoint to broadcast

Answers
Suggested answer: A

Explanation:

The following different OSPF types are compatible with each other:

+ Broadcast and Non-Broadcast (adjust hello/dead timers)

+ Point-to-Point and Point-to-Multipoint (adjust hello/dead timers)

Broadcast and Non-Broadcast networks elect DR/BDR so they are compatible. Point-topoint/ multipoint do not elect DR/BDR so they are compatible.

Refer to the exhibit.

An engineer must configure a SPAN session. What is the effect of the configuration?

A.

Traffic sent on VLANs 10, 11, and 12 is copied and sent to interface g0/1.

A.

Traffic sent on VLANs 10, 11, and 12 is copied and sent to interface g0/1.

Answers
B.

Traffic sent on VLANs 10 and 12 only is copied and sent to interface g0/1.

B.

Traffic sent on VLANs 10 and 12 only is copied and sent to interface g0/1.

Answers
C.

Traffic received on VLANs 10, 11, and 12 is copied and sent to Interface g0/1.

C.

Traffic received on VLANs 10, 11, and 12 is copied and sent to Interface g0/1.

Answers
D.

Traffic received on VLANs 10 and 12 only is copied and sent to interface g0/1.

D.

Traffic received on VLANs 10 and 12 only is copied and sent to interface g0/1.

Answers
Suggested answer: C

An engineer is configuring a GRE tunnel interface in the default mode. The engineer has assigned an IPv4 address on the tunnel and sourced the tunnel from an Ethernet interface. Which option also is required on the tunnel interface before it is operational?

A.

(config-if)#tunnel destination <ip address>

A.

(config-if)#tunnel destination <ip address>

Answers
B.

(config-if)#keepalive <seconds retries>

B.

(config-if)#keepalive <seconds retries>

Answers
C.

(config-if)#ip mtu <value>

C.

(config-if)#ip mtu <value>

Answers
D.

(config-if)#ip tcp adjust-mss <value>

D.

(config-if)#ip tcp adjust-mss <value>

Answers
Suggested answer: A

Explanation:

A GRE interface definition includes: + An IPv4 address on the tunnel + A tunnel source + A tunnel destination Below is an example of how to configure a basic GRE tunnel: interface Tunnel 0 ip address 10.10.10.1 255.255.255.0 tunnel source fa0/0 tunnel destination 172.16.0.2 In this case the “IPv4 address on the tunnel” is 10.10.10.1/24 and “sourced the tunnel from an Ethernet interface” is the command “tunnel source fa0/0”. Therefore it only needs a tunnel destination, which is 172.16.0.2.Note: A multiple GRE (mGRE) interface does not require a tunnel destination address.

Which solution do laaS service providers use to extend a Layer 2 segment across a Layer 3 network?

A.

VLAN

A.

VLAN

Answers
B.

VTEP

B.

VTEP

Answers
C.

VXLAN

C.

VXLAN

Answers
D.

VRF

D.

VRF

Answers
Suggested answer: C

Refer to the exhibit.

Which IP address becomes the active next hop for 192.168.102 0/24 when 192.168.101.2 fails?

A.

192.168.101.18

A.

192.168.101.18

Answers
B.

192.168.101.6

B.

192.168.101.6

Answers
C.

192.168.101.10

C.

192.168.101.10

Answers
D.

192.168.101.14

D.

192.168.101.14

Answers
Suggested answer: A

Explanation:

The '>' shown in the output above indicates that the path with a next hop of 192.168.101.2 is the current best path.

Path Selection Attributes: Weight > Local Preference > Originate > AS Path > Origin > MED > External > IGP Cost > eBGP Peering > Router ID BGP prefers the path with highest weight but the weights here are all 0 (which indicate all routes that are not originated by the local router) so we need to check the Local Preference. Answer '192.168.101.18' path without LOCAL_PREF (LocPrf column) means it has the default value of 100.

Therefore we can find the two next best paths with the next hop of 192.168.101.18 and 192.168.101.10.

We have to move to the next path selection attribute: Originate. BGP prefers the path that the local router originated (which is indicated with the "next hop 0.0.0.0"). But none of the two best paths is self-originated.

The AS Path of the next hop 192.168.101.18 is shorter than the AS Path of the next hop 192.168.101.10 then the next hop 192.168.101.18 will be chosen as the next best path.

Total 983 questions
Go to page: of 99