Cisco 350-601 Practice Test - Questions Answers, Page 23
List of questions
Related questions
An engineer must configure RBAC is Cisco UCS Manager in an existing data center environment. Which two roles can be used to configure LAN Connectivity policies? (Choose two.)
network-admin
server-profile
admin
enable
operations
An engineer has a primary fabric that is named UCS-A and a secondary fabric that is named UCS-B. A certificate request that has a subject name of sjc2016 for a keyring that is named kr2016 needs to be created. The cluster IP address is 10.68.68.68.
Which command set creates this certificate request?
UCS-A # scope keyring kr2016 UCS-A /keyring # create certreq 10.68.68.68 sjc2016 UCS-A /keyring* # commit-buffer
UCS-B # scope keyring kr2016 UCS-B /keyring # create certreq ip 10.68.68.68 subject-name sjc2016 UCS-B /keyring* # commit-both
UCS-B# scope security UCS-B /security # scope keyring kr2016 UCS-B /security/keyring # set certreq 10.68.68.68 sjc2016 UCS-B /security/keyring* # commit-both
UCS-A# scope security UCS-A /security # scope keyring kr2016 UCS-A /security/keyring # create certreq ip 10.68.68.68 subject-name sjc2016 UCS-A /security/keyring* # commit-buffer
Port security is enabled on a Cisco MDS 9000 series Switch. Which statement is true?
Cisco Fabric Services must be disabled before enabling port security.
Port security can be enabled only globally and affects all VSANs.
Auto-learning is always enabled automatically when port security is enabled.
Any devices currently logged in must be added manually to the device databased.
When a strict CoPP policy is implemented, which statement describes an event during which packets are dropped?
Fifteen SSH sessions remain connected to the switch.
A large system image is copied to a switch by using the default VRF.
A ping sweep is performed on a network that is connected through a switch.
A web server that is connected to a switch is affected by a DDoS attack.
Which two authentication types does Cisco UCS Manager support when configuration authentication? (Choose two.)
local
LDAP
802.1X
Kerberos
PAM
Refer to the exhibit.
What is the result of implementing this configuration?
The TACACS+ server uses the type-6 encrypted format.
The switch queries the TACACS+ server by using a clear text PAP login.
The timeout value on the TACACS+ server is 10 seconds.
The switch queries the TACACS+ server by using an encrypted text PAP login.
Refer to the exhibit.
Which setting must be configured to prevent reuse of passwords?
No Change Interval
Change Interval
History Count
Change Count
An engineer is configuring AAA authentication on an MDS 9000 switch. The LDAP server is located under the IP 10.10.2.2. The data sent to the LDAP server should be encrypted. Which command should be used to meet these requirements?
Idap-server host 10.10.2.2 enable-ssl
Idap-server 10.10.2.2 port 443
Idap server host 10.10.2.2 key SSL_KEY
Idap-server 10.10.2.2 key SSL_KEY
Refer to the exhibit.
Which action is taken to ensure that the relay agent forwards the DHCP BOOTREQUEST packet to a DHCP server?
Configure the interface of the DHCP server as untrusted.
Configure the IP address of the DHCP server.
Enable the DHCP relay agent.
Verify the DHCP snooping bindings.
A network administrator must perform a system upgrade on a Cisco MDS 9000 Series Switch. Due to the recent changes by the security team:
* The AAA server is unreachable.
* All TCP communication between the MDS 9000 Series Switch and AAA servers is disabled.
Which actions must be used to perform the upgrade?
Log in locally to the MDS 9000 Series Switch using a network-admin role and download the upgrade files from the remote TFTP server.
Log in locally to the MDS 9000 Series Switch using a server-admin role and download the upgrade files from the remote FTP server.
Log in to a server storing the upgrade files remotely using a server-admin role and download the files to the MDS 9000 Series Switch using SFTP.
Log in to a server storing the upgrade files remotely using a network-admin role and download the files to the MDS 9000 Series Switch using HTTP.
Question