Cisco 350-701 Practice Test - Questions Answers, Page 11
List of questions
Question 103
(0)
Question 106
(0)
Related questions
A malicious user gained network access by spoofing printer connections that were authorized using MAB on four different switch ports at the same time. What two catalyst switch security features will prevent further violations? (Choose two)
DHCP Snooping
802.1AE MacSec
Port security
IP Device track
Dynamic ARP inspection
Private VLANs
Which command enables 802.1X globally on a Cisco switch?
dot1x system-auth-control
dot1x pae authenticator
authentication port-control aut
aaa new-model
Which RADIUS attribute can you use to filter MAB requests in an 802.1 x deployment?
1
2
6
31
A network administrator configures Dynamic ARP Inspection on a switch. After Dynamic ARP Inspection is applied, all users on that switch are unable to communicate with any destination. The network administrator checks the interface status of all interfaces, and there is no err-disabled interface. What is causing this problem?
DHCP snooping has not been enabled on all VLANs.
The ip arp inspection limit command is applied on all interfaces and is blocking the traffic of all users.
Dynamic ARP Inspection has not been enabled on all VLANs
The no ip arp inspection trust command is applied on all user host interfaces
Refer to the exhibit.
An engineer configured wired 802.1x on the network and is unable to get a laptop to authenticate.
Which port configuration is missing?
authentication open
dotlx reauthentication
cisp enable
dot1x pae authenticator
Which SNMPv3 configuration must be used to support the strongest security possible?
asa-host(config)#snmp-server group myv3 v3 priv asa-host(config)#snmp-server user andy myv3 auth sha cisco priv des ciscXXXXXXXX asa-host(config)#snmp-server host inside 10.255.254.1 version 3 andy
asa-host(config)#snmp-server group myv3 v3 noauth asa-host(config)#snmp-server user andy myv3 auth sha cisco priv aes 256 ciscXXXXXXXX asa-host(config)#snmp-server host inside 10.255.254.1 version 3 andy
asa-host(config)#snmpserver group myv3 v3 noauth asa-host(config)#snmp-server user andy myv3 auth sha cisco priv 3des ciscXXXXXXXX asa-host(config)#snmp-server host inside 10.255.254.1 version 3 andy
asa-host(config)#snmp-server group myv3 v3 priv asa-host(config)#snmp-server user andy myv3 auth sha cisco priv aes 256 ciscXXXXXXXX asa-host(config)#snmp-server host inside 10.255.254.1 version 3 andy
Refer to the exhibit.
Which command was used to generate this output and to show which ports are authenticating with dot1x or mab?
show authentication registrations
show authentication method
show dot1x all
show authentication sessions
What Cisco command shows you the status of an 802.1X connection on interface gi0/1?
show authorization status
show authen sess int gi0/1
show connection status gi0/1
show ver gi0/1
Refer to the exhibit.
What does the number 15 represent in this configuration?
privilege level for an authorized user to this router
access list that identifies the SNMP devices that can access the router
interval in seconds between SNMPv3 authentication attempts
number of possible failed attempts until the SNMPv3 user is locked out
Under which two circumstances is a CoA issued? (Choose two)
A new authentication rule was added to the policy on the Policy Service node.
An endpoint is deleted on the Identity Service Engine server.
A new Identity Source Sequence is created and referenced in the authentication policy.
An endpoint is profiled for the first time.
A new Identity Service Engine server is added to the deployment with the Administration persona
Question