CCNA 2 v7.0 Final Exam Answers – Switching, Routing and Wireless Essentials
SRWE Course Final Exam. This comprehensive study guide covers the entire CCNA2 Switching, Routing, and Wireless Essentials v7.0 curriculum, including switching concepts, VLANs, STP, EtherChannel, routing, DHCP, HSRP, and wireless essentials.
1. Refer to the exhibit. What will router R1 do with a packet that has a destination IPv6 address of 2001:db8:cafe:5::1?
Explanation: Topic 14.4.9 – The route ::/0 is the compressed form of the default route. The default route is used if a more specific route is not found in the routing table.
2. Refer to the exhibit. Currently router R1 uses an EIGRP route learned from Branch2 to reach the 10.10.0.0/16 network. Which floating static route would create a backup route to the 10.10.0.0/16 network in the event that the link between R1 and Branch2 goes down?
Explanation: Topic 15.4.1 – A floating static route needs to have an administrative distance that is greater than the administrative distance of the active route in the routing table. Router R1 is using an EIGRP route which has an administrative distance of 90 to reach the 10.10.0.0/16 network. To be a backup route the floating static route must have an administrative distance greater than 90 and have a next hop address corresponding to the serial interface IP address of Branch1.
3. Refer to the exhibit. R1 was configured with the static route command ip route 209.165.200.224 255.255.255.224 S0/0/0 and consequently users on network 172.16.0.0/16 are unable to reach resources on the Internet. How should this static route be changed to allow user traffic from the LAN to reach the Internet?
Explanation: Topic 15.3.1 – The static route has the wrong destination network and mask. The correct destination is 0.0.0.0 0.0.0.0 for a default route.
4. Which option shows a correctly configured IPv4 default static route?
Explanation: Topic 15.3.1 – The default static route uses 0.0.0.0 0.0.0.0 as the destination network and mask.
5. Refer to the exhibit. Which static route command can be entered on R1 to forward traffic to the LAN connected to R2?
Explanation: Topic 15.2.6 – When using a link-local next-hop, the exit interface must be specified.
6. What is a method to launch a VLAN hopping attack?
Explanation: Topic 10.5.2 – VLAN hopping can be launched by introducing a rogue switch and enabling trunking.
7. A cybersecurity analyst is using the macof tool to evaluate configurations of switches deployed in the backbone network of an organization. Which type of LAN attack is the analyst targeting during this evaluation?
Explanation: Topic 10.4.2 – Macof is a tool used to flood LAN switches with MAC addresses, causing a MAC address table overflow.
8. Refer to the exhibit. A network administrator is configuring a router as a DHCPv6 server. The administrator issues a show ipv6 dhcp pool command to verify the configuration. Which statement explains the reason that the number of active clients is 0?
Explanation: Topic 8.3.2 – Under the stateless DHCPv6 configuration, indicated by the command ipv6 nd other-config-flag, the DHCPv6 server does not maintain the state information, because client IPv6 addresses are not managed by the DHCP server. Because the clients will configure their IPv6 addresses by combining the prefix/prefix-length and a self-generated interface ID, the ipv6 dhcp pool configuration does not need to specify the valid IPv6 address range. And because clients will use the link-local address of the router interface as the default gateway address, the default gateway address is not necessary.
9. Refer to the exhibit. A network administrator configured routers R1 and R2 as part of HSRP group 1. After the routers have been reloaded, a user on Host1 complained of lack of connectivity to the Internet. The network administrator issued the show standby brief command on both routers to verify the HSRP operations. In addition, the administrator observed the ARP table on Host1. Which entry should be seen in the ARP table on Host1 in order to gain connectivity to the Internet?
Explanation: Topic 9.1.2 – Hosts will send an ARP request to the default gateway which is the virtual IP address. ARP replies from the HSRP routers contain the virtual MAC address. The host ARP tables will contain a mapping of the virtual IP to the virtual MAC.
10. Match the forwarding characteristic to its type. (Not all options are used.)
Explanation: Topic 2.1.5 – Store-and-forward: full frame received, error checking. Cut-through: fast-forward and fragment-free.
11. Which statement is correct about how a Layer 2 switch determines how to forward frames?
Explanation: Topic 2.1.2 – Cut-through frame forwarding reads up to only the first 22 bytes of a frame, which excludes the frame check sequence and thus invalid frames may be forwarded. In addition to broadcast frames, frames with a destination MAC address that is not in the CAM are also flooded out all active ports. Unicast frames are not always forwarded. Received frames with a destination MAC address that is associated with the switch port on which it is received are not forwarded because the destination exists on the network segment connected to that port.
12. Which statement describes a result after multiple Cisco LAN switches are interconnected?
Explanation: Topic 2.2.2 – In Cisco LAN switches, the microsegmentation makes it possible for each port to represent a separate segment and thus each switch port represents a separate collision domain. This fact will not change when multiple switches are interconnected. However, LAN switches do not filter broadcast frames. A broadcast frame is flooded to all ports. Interconnected switches form one big broadcast domain.
13. Match the link state to the interface and protocol status. (Not all options are used.)
Explanation: Topic 1.2.6
| Problem | Status |
|---|---|
| Layer 1 problem | down/down |
| Layer 2 problem | up/down |
| Disabled | administratively down |
| Operational | up/up |
14. Refer to the exhibit. How is a frame sent from PCA forwarded to PCC if the MAC address table on switch SW1 is empty?
Explanation: Topic 2.1.3 – When a switch powers on, the MAC address table is empty. The switch builds the MAC address table by examining the source MAC address of incoming frames. The switch forwards based on the destination MAC address found in the frame header. If a switch has no entries in the MAC address table or if the destination MAC address is not in the switch table, the switch will forward the frame out all ports except the port that brought the frame into the switch.
15. An administrator is trying to remove configurations from a switch. After using the command erase startup-config and reloading the switch, the administrator finds that VLANs 10 and 100 still exist on the switch. Why were these VLANs not removed?
Explanation: Topic 3.3.10 – Standard range VLANs (1-1005) are stored in a file that is called vlan.dat that is located in flash memory. Erasing the startup configuration and reloading a switch does not automatically remove these VLANs. The vlan.dat file must be manually deleted from flash memory and then the switch must be reloaded.
16. Match the description to the correct VLAN type. (Not all options are used.)
Explanation: Topic 3.1.3 - A data VLAN is configured to carry user-generated traffic. A default VLAN is the VLAN where all switch ports belong after the initial boot up of a switch loading the default configuration. A native VLAN is assigned to an 802.1Q trunk port, and untagged traffic is placed on it. A management VLAN is any VLAN that is configured to access the management capabilities of a switch. An IP address and subnet mask are assigned to it, allowing the switch to be managed via HTTP, Telnet, SSH, or SNMP.
| VLAN Type | Description |
|---|---|
| Native VLAN | Carries untagged traffic |
| Management VLAN | An IP address and subnet mask are assigned to this VLAN, allowing the switch to be accessed by HTTP, Telnet, SSH, or SNMP |
| Default VLAN | All switch ports are assigned to this VLAN after initial bootup of the switch |
| Data VLANs | Configured to carry user generated traffic |
17. Refer to the exhibit. A network administrator has connected two switches together using EtherChannel technology. If STP is running, what will be the end result?
Explanation: Topic 6.1.3 – Cisco switches support two protocols for negotiating a channel between two switches: LACP and PAgP. PAgP is Cisco-proprietary. In the topology shown, the switches are connected to each other using redundant links. By default, STP is enabled on switch devices. STP will block redundant links to prevent loops.
18. What is a secure configuration option for remote access to a network device?
Explanation: Topic 1.3.2 – SSH provides secure encrypted remote access.
19. Which wireless encryption method is the most secure?
Explanation: Topic 12.7.4 – WPA2 with AES is the most secure wireless encryption method.
20. After attaching four PCs to the switch ports, configuring the SSID and setting authentication properties for a small office network, a technician successfully tests the connectivity of all PCs that are connected to the switch and WLAN. A firewall is then configured on the device prior to connecting it to the Internet. What type of network device includes all of the described features?
Explanation: Topic 12.2.3 – A wireless router combines switching, wireless access, and firewall functionality.
21. Refer to the exhibit. Host A has sent a packet to host B. What will be the source MAC and IP addresses on the packet when it arrives at host B?
Explanation: Topic 14.2.2 – As a packet traverses the network, the Layer 2 addresses will change at every hop as the packet is de-encapsulated and re-encapsulated, but the Layer 3 addresses will remain the same.
23. Refer to the exhibit. In addition to static routes directing traffic to networks 10.10.0.0/16 and 10.20.0.0/16, Router HQ is also configured with the following command: ip route 0.0.0.0 0.0.0.0 serial 0/1/1. What is the purpose of this command?
Explanation: Topic 15.3.1 – The default route forwards packets to the Internet for destinations not in the routing table.
24. What protocol or technology disables redundant paths to eliminate Layer 2 loops?
Explanation: Topic 5.1.2 – Spanning Tree Protocol (STP) eliminates Layer 2 loops by blocking redundant paths.
25. Refer to the exhibit. Based on the exhibited configuration and output, why is VLAN 99 missing?
Explanation: Topic 4.4.3 – VLAN 99 is missing because it has not been created on the switch.
26. Which two VTP modes allow for the creation, modification, and deletion of VLANs on the local switch? (Choose two.)
Explanation: Topic 3.3.1 – Server and transparent modes allow VLAN creation, modification, and deletion.
27. Which three steps should be taken before moving a Cisco switch to a new VTP management domain? (Choose three.)
Explanation: Topic 3.3.1 – When adding a new switch to a VTP domain, it is critical to configure the switch with a new domain name, the correct VTP mode, VTP version number, and password. A switch with a higher revision number can propagate invalid VLANs and erase valid VLANs thus preventing connectivity for multiple devices on the valid VLANs.
28. A network administrator is preparing the implementation of Rapid PVST+ on a production network. How are the Rapid PVST+ link types determined on the switch interfaces?
Explanation: Topic 5.3.2 – When Rapid PVST+ is being implemented, link types are automatically determined but can be specified manually. Link types can be either point-to-point, shared, or edge.
29. Refer to the exhibit. All the displayed switches are Cisco 2960 switches with the same default priority and operating at the same bandwidth. Which three ports will be STP designated ports? (Choose three.)
Explanation: Topic 5.2.6 – Given that all the switches have the same default priority and are operating at the same bandwidth, the switch with the lowest MAC address will become the root bridge. This would be SW3 and all its ports would be designated ports. SW1 has a lower MAC address than SW2 has and therefore port fa0/10 will become the designated port on that link.
30. How will a router handle static routing differently if Cisco Express Forwarding is disabled?
Explanation: Topic 15.2.5 – In most platforms running IOS 12.0 or later, Cisco Express Forwarding is enabled by default. Cisco Express Forwarding eliminates the need for the recursive lookup. If Cisco Express Forwarding is disabled, multiaccess network interfaces require fully specified static routes in order to avoid inconsistencies in their routing tables. Point-to-point interfaces do not have this problem, because multiple end points are not present. With or without Cisco Express Forwarding enabled, using an exit interface when configuring a static route is a viable option.
31. Compared with dynamic routes, what are two advantages of using static routes on a router? (Choose two.)
Explanation: Topic 14.5.1 – Static routes are manually configured on a router. Static routes are not automatically updated and must be manually reconfigured if the network topology changes. Thus static routing improves network security because it does not make route updates among neighboring routers. Static routes also improve resource efficiency by using less bandwidth, and no CPU cycles are used to calculate and communicate routes.
32. Refer to the exhibit. Which route was configured as a static route to a specific network using the next-hop address?
Explanation: Topic 15.2.1 – The C in a routing table indicates an interface that is up and has an IP address assigned. The S in a routing table signifies that a route was installed using the ip route command. Two of the routing table entries shown are static routes to a specific destination (the 192.168.2.0 network). The entry that has the S denoting a static route and [1/0] was configured using the next-hop address. The other entry (S 192.168.2.0/24 is directly connected, Serial 0/0/0) is a static route configured using the exit interface. The entry with the 0.0.0.0 route is a default static route which is used to send packets to any destination network that is not specifically listed in the routing table.
33. What is the effect of entering the spanning-tree portfast configuration command on a switch?
Explanation: Topic 11.5.2 – PortFast enables a port to transition directly to forwarding state.
34. What is the IPv6 prefix that is used for link-local addresses?
Explanation: Topic 1.5.3 – IPv6 link-local addresses use the FE80::/10 prefix.
35. Which two statements are characteristics of routed ports on a multilayer switch? (Choose two.)
Explanation: Topic 4.3.1 – Routed ports are physical ports that act similarly to a router interface. They are not associated with a particular VLAN, they do not support subinterfaces, and they are used for point-to-point links. In a switched network, they are mostly configured between switches at the core and distribution layers. To configure routed ports, the no switchport interface command has to be used on the appropriate ports.
36. Successful inter-VLAN routing has been operating on a network with multiple VLANs across multiple switches for some time. When an inter-switch trunk link fails and Spanning Tree Protocol brings up a backup trunk link, it is reported that hosts on two VLANs can access some, but not all the network resources that could be accessed previously. Hosts on all other VLANS do not have this problem. What is the most likely cause of this problem?
Explanation: Topic 4.4.1 – The backup trunk likely does not have all VLANs allowed on it.
37. Which command will start the process to bundle two physical interfaces to create an EtherChannel group via LACP?
Explanation: Topic 6.2.2 – The interface range command selects the interfaces to be bundled into an EtherChannel.
38. What action takes place when a frame entering a switch has a multicast destination MAC address?
Explanation: Topic 2.1.3 – If the destination MAC address is a broadcast or a multicast, the frame is also flooded out all ports except the incoming port.
39. A junior technician was adding a route to a LAN router. A traceroute to a device on the new network revealed a wrong path and unreachable status. What should be done or checked?
Explanation: Topic 15.2.3 – The exit interface on the static route may be misconfigured.
40. Select the three PAgP channel establishment modes. (Choose three.)
Explanation: Topic 6.1.6 – PAgP uses auto, desirable, and on modes.
41. A static route has been configured on a router. However, the destination network no longer exists. What should an administrator do to remove the static route from the routing table?
Explanation: Topic 15.2 – When the destination network specified in a static route does not exist anymore, the static route stays in the routing table until it is manually removed by using the no ip route command.
42. Refer to the exhibit. What can be concluded about the configuration shown on R1?
Explanation: Topic 7.2.8 – The ip helper-address command configures a router as a DHCP relay agent.
43. Match the step to each switch boot sequence description. (Not all options are used.)
Explanation: Topic 1.1.1 – Steps: execute POST → load boot loader from ROM → CPU register initializations → flash file system initialization → load IOS → transfer control to IOS.
44. Refer to the exhibit. R1 has been configured as shown. However, PC1 is not able to receive an IPv4 address. What is the problem?
Explanation: Topic 7.2.8 – The ip helper-address command has to be applied on interface Gi0/0. This command must be present on the interface of the LAN that contains the DHCPv4 client PC1 and must be directed to the correct DHCPv4 server.
45. What two default wireless router settings can affect network security? (Choose two.)
Explanation: Topic 13.1.3 – Default settings on wireless routers often include broadcasting the SSID and using a well-known administrative password. Both of these pose a security risk to wireless networks. WEP encryption and MAC address filtering are not set by default. The automatic selection of the wireless channel poses no security risks.
46. What is the common term given to SNMP log messages that are generated by network devices and sent to the SNMP server?
Explanation: Topic 13.3.2 – SNMP traps are messages sent from devices to the SNMP server.
47. A network administrator is adding a new WLAN on a Cisco 3500 series WLC. Which tab should the administrator use to create a new VLAN interface to be used for the new WLAN?
Explanation: Topic 13.3.7 – The CONTROLLER tab is used to create VLAN interfaces on a Cisco WLC.
48. A network administrator is configuring a WLAN. Why would the administrator change the default DHCP IPv4 addresses on an AP?
Explanation: Topic 13.1.3 – Changing default DHCP address ranges reduces the risk of unauthorized access.
49. Which two functions are performed by a WLC when using split media access control (MAC)? (Choose two.)
Explanation: Topic 12.4.3 – Split MAC allows the WLC to handle frame translation and client association/roaming.
50. On what switch ports should BPDU guard be enabled to enhance STP stability?
Explanation: Topic 11.5.3 – BPDU guard should be enabled on all PortFast-enabled ports.
51. Which network attack is mitigated by enabling BPDU guard?
Explanation: Topic 10.5.9 – BPDU guard prevents rogue switches from being added to the network.
52. Why is DHCP snooping required when using the Dynamic ARP Inspection feature?
Explanation: Topic 11.4.1 – DAI relies on DHCP snooping. DHCP snooping listens to DHCP message exchanges and builds a bindings database of valid tuples (MAC address, IP address, VLAN interface). When DAI is enabled, the switch drops ARP packet if the sender MAC address and sender IP address do not match an entry in the DHCP snooping bindings database. However, it can be overcome through static mappings. Static mappings are useful when hosts configure static IP addresses, DHCP snooping cannot be run, or other switches in the network do not run dynamic ARP inspection. A static mapping associates an IP address to a MAC address on a VLAN.
53. Refer to the exhibit. Router R1 has an OSPF neighbor relationship with the ISP router over the 192.168.0.32 network. The 192.168.0.36 network link should serve as a backup when the OSPF link goes down. The floating static route command ip route 0.0.0.0 0.0.0.0 S0/0/1 100 was issued on R1 and now traffic is using the backup link even when the OSPF link is up and functioning. Which change should be made to the static route command so that traffic will only use the OSPF link when it is up?
Explanation: Topic 15.4.1 – The problem with the current floating static route is that the administrative distance is set too low. The administrative distance will need to be higher than that of OSPF, which is 110, so that the router will only use the OSPF link when it is up.
54. Refer to the exhibit. What is the metric to forward a data packet with the IPv6 destination address 2001:DB8:ACAD:E:240:BFF:FED4:9DD2?
Explanation: Topic 14.4.3 – The destination address belongs to the 2001:DB8:ACAD:E::/64 network, which has a metric of 2682112 via Serial 0/0/1.
55. A network administrator is configuring a new Cisco switch for remote management access. Which three items must be configured on the switch for the task? (Choose three.)
Explanation: Topic 1.1.5 – To enable the remote management access, the Cisco switch must be configured with an IP address and a default gateway. In addition, vty lines must configured to enable either Telnet or SSH connections. A loopback address, default VLAN, and VTP domain configurations are not necessary for the purpose of remote switch management.
56. Refer to the exhibit. Which statement shown in the output allows router R1 to respond to stateless DHCPv6 requests?
Explanation: Topic 8.3.3 – The interface command ipv6 nd other-config-flag allows RA messages to be sent on this interface, indicating that additional information is available from a stateless DHCPv6 server.
57. Refer to the exhibit. A Layer 3 switch routes for three VLANs and connects to a router for Internet connectivity. Which two configurations would be applied to the switch? (Choose two.)
Explanation: Topic 4.3.7 – A Layer 3 switch requires ip routing and routed ports configured with no switchport.
58. A technician is troubleshooting a slow WLAN and decides to use the split-the-traffic approach. Which two parameters would have to be configured to do this? (Choose two.)
Explanation: Topic 13.4.3 – Splitting traffic between 5 GHz (streaming) and 2.4 GHz (basic) improves performance.
59. A company has just switched to a new ISP. The ISP has completed and checked the connection from its site to the company. However, employees at the company are not able to access the internet. What should be done or checked?
Explanation: Topic 15.3 – The old default route may still be present and causing issues.
60. Which information does a switch use to populate the MAC address table?
Explanation: Topic 2.1.3 – To maintain the MAC address table, the switch uses the source MAC address of the incoming packets and the port that the packets enter. The destination address is used to select the outgoing port.
61. Refer to the exhibit. A network administrator is reviewing the configuration of switch S1. Which protocol has been implemented to group multiple physical ports into one logical link?
Explanation: Topic 6.1.6 – The EtherChannel protocol PAgP provides the grouping of physical interfaces and utilizes the modes of auto and desirable. The EtherChannel protocol LACP provides the grouping of physical interfaces and utilizes the modes of passive and active. DTP and STP are not utilized to group multiple physical interfaces into a single logical link.
62. Which type of static route is configured with a greater administrative distance to provide a backup route to a route learned from a dynamic routing protocol?
Explanation: Topic 15.4.1 – There are four basic types of static routes. Floating static routes are backup routes that are placed into the routing table if a primary route is lost. A summary static route aggregates several routes into one, reducing the of the routing table. Standard static routes are manually entered routes into the routing table. Default static routes create a gateway of last resort.
63. What action takes place when a frame entering a switch has a unicast destination MAC address appearing in the MAC address table?
Explanation: Topic 2.1.3 – If the destination MAC is in the CAM table, the switch forwards the frame to the associated port.
64. The exhibit shows two PCs called PC A and PC B, two routes called R1 and R2, and two switches. PC A has the address 172.16.1.1/24 and is connected to a switch and into an interface on R1 that has the IP address 172.16.1.254. PC B has the address 172.16.2.1/24 and is connected to a switch that is connected to another interface on R1 with the IP address 172.16.2.254. The serial interface on R1 has the address 172.16.3.1 and is connected to the serial interface on R2 that has the address 172.16.3.2/24. R2 is connected to the internet cloud. Which command will create a static route on R2 in order to reach PC B?
Explanation: Topic 15.2.1 – The correct syntax is: router(config)# ip route destination-network destination-mask {next-hop-ip-address | exit-interface} If the local exit interface instead of the next-hop IP address is used then the route will be displayed as a directly connected route instead of a static route in the routing table. Because the network to be reached is 172.16.2.0 and the next-hop IP address is 172.16.3.1, the command is R2(config)# ip route 172.16.2.0 255.255.255.0 172.16.3.1
65. What protocol or technology allows data to transmit over redundant switch links?
Explanation: Topic 6.1.1 – EtherChannel allows multiple physical links to be aggregated into one logical link.
66. Refer to the exhibit. Which three hosts will receive ARP requests from host A, assuming that port Fa0/4 on both switches is configured to carry traffic for multiple VLANs? (Choose three.)
Explanation: Topic 3.1.1 – ARP requests are sent out as broadcasts. That means the ARP request is sent only throughout a specific VLAN. VLAN 1 hosts will only hear ARP requests from hosts on VLAN 1. VLAN 2 hosts will only hear ARP requests from hosts on VLAN 2.
67. Refer to the exhibit. The network administrator configures both switches as displayed. However, host C is unable to ping host D and host E is unable to ping host F. What action should the administrator take to enable this communication?
Explanation: Topic 3.5.3 – Both ports are in dynamic auto mode; one side must be set to dynamic desirable or trunk to form a trunk.
68. What is the effect of entering the shutdown configuration command on a switch?
Explanation: Topic 11.1.1 – The shutdown command administratively disables a port.
69. What would be the primary reason an attacker would launch a MAC address overflow attack?
Explanation: Topic 10.4.2 – A MAC overflow attack floods the CAM table, causing the switch to flood frames, allowing the attacker to see traffic destined for other hosts.
70. During the AAA process, when will authorization be implemented?
Explanation: Topic 10.2.4 – AAA authorization is implemented immediately after the user is authenticated against a specific AAA data source.
71. A company security policy requires that all MAC addressing be dynamically learned and added to both the MAC address table and the running configuration on each switch. Which port security configuration will accomplish this?
Explanation: Topic 11.1.4 – With sticky secure MAC addressing, the MAC addresses can be either dynamically learned or manually configured and then stored in the address table and added to the running configuration file. In contrast, dynamic secure MAC addressing provides for dynamically learned MAC addressing that is stored only in the address table.
72. Which three Wi-Fi standards operate in the 2.4GHz range of frequencies? (Choose three.)
Explanation: Topic 12.1.4 – 802.11b and 802.11g operate in the 2.4GHz range, and 802.11n can operate in either the 2.4GHz or the 5GHz range. 802.11a and 802.11ac operate only in the 5GHz range of frequencies.
73. To obtain an overview of the spanning tree status of a switched network, a network engineer issues the show spanning-tree command on a switch. Which two items of information will this command display? (Choose two.)
Explanation: Topic 5.2 – show spanning-tree displays the root bridge BID and port roles.
74. Refer to the exhibit. Which trunk link will not forward any traffic after the root bridge election process is complete?
Explanation: Topic 5.2 – The root bridge election will block the redundant trunk link.
75. Which method of IPv6 prefix assignment relies on the prefix contained in RA messages?
Explanation: Topic 8.2.1 – Stateless Address Autoconfiguration (SLAAC) relies on information received in router advertisement (RA) messages in order to automatically create an IPv6 address. The RA messages contain information such as the network prefix and prefix length, which the host combines with an interface ID in order to make a unique IPv6 unicast address.
76. Which two protocols are used to provide server-based AAA authentication? (Choose two.)
Explanation: Topic 10.2.3 – Server-based AAA authentication uses an external TACACS or RADIUS authentication server to maintain a username and password database. When a client establishes a connection with an AAA enabled device, the device authenticates the client by querying the authentication servers.
77. A network administrator is configuring a WLAN. Why would the administrator disable the broadcast feature for the SSID?
Explanation: Topic 12.7.2 – Disabling SSID broadcast prevents casual discovery of the network.
78. Which mitigation technique would prevent rogue servers from providing false IP configuration parameters to clients?
Explanation: Topic 11.3.2 – Like Dynamic ARP Inspection (DAI), IP Source Guard (IPSG) needs to determine the validity of MAC-address-to-IP-address bindings. To do this IPSG uses the bindings database built by DHCP snooping.
79. A network administrator configures the port security feature on a switch. The security policy specifies that each access port should allow up to two MAC addresses. When the maximum number of MAC addresses is reached, a frame with the unknown source MAC address is dropped and a notification is sent to the syslog server. Which security violation mode should be configured for each access port?
Explanation: Topic 11.1.6 – Restrict mode drops unknown packets and sends a notification.
80. What protocol or technology defines a group of routers, one of them defined as active and another one as standby?
Explanation: Topic 9.2.1 – HSRP defines active and standby routers for gateway redundancy.
81. Refer to the exhibit. After attempting to enter the configuration that is shown in router RTA, an administrator receives an error and users on VLAN 20 report that they are unable to reach users on VLAN 30. What is causing the problem?
Explanation: Topic 4.2.4 – VLAN 20 and VLAN 30 are on the same subnet, which prevents inter-VLAN routing.
82. Which three pairs of trunking modes will establish a functional trunk link between two Cisco switches? (Choose three.)
Explanation: Topic 3.5.3 – Trunking modes that establish a trunk: dynamic desirable/trunk, dynamic desirable/dynamic desirable, dynamic desirable/dynamic auto.
83. A technician is configuring a router for a small company with multiple WLANs and doesn't need the complexity of a dynamic routing protocol. What should be done or checked?
Explanation: Topic 14.4.5 – For small networks, static routes to internal networks and a default route are sufficient.
84. A company is deploying a wireless network in the distribution facility in a Boston suburb. The warehouse is quite large and it requires multiple access points to be used. Because some of the company devices still operate at 2.4GHz, the network administrator decides to deploy the 802.11g standard. Which channel assignments on the multiple access points will make sure that the wireless channels are not overlapping?
Explanation: Topic 12.5.2 – In the North America domain, 11 channels are allowed for 2.4GHz wireless networking. Among these 11 channels, the combination of channels 1, 6, and 11 are the only non-overlapping channel combination.
85. A network administrator of a small advertising company is configuring WLAN security by using the WPA2 PSK method. Which credential do office users need in order to connect their laptops to the WLAN?
Explanation: Topic 12.7.5 – WPA2 PSK requires a pre-shared key that matches the one on the AP.
86. Refer to the exhibit. What are the possible port roles for ports A, B, C, and D in this RSTP-enabled network?
Explanation: Topic 5.2.1 – Because S1 is the root bridge, B is a designated port, and C and D root ports. RSTP supports a new port type, alternate port in discarding state, that can be port A in this scenario.
87. Refer to the exhibit. Which static route would an IT technician enter to create a backup route to the 172.16.1.0 network that is only used if the primary RIP learned route fails?
Explanation: Topic 15.4.1 – A backup static route is called a floating static route. A floating static route has an administrative distance greater than the administrative distance of another static route or dynamic route.
88. What mitigation plan is best for thwarting a DoS attack that is creating a MAC address table overflow?
Explanation: Topic 11.1.2 – A MAC address (CAM) table overflow attack, buffer overflow, and MAC address spoofing can all be mitigated by configuring port security. A network administrator would typically not want to disable STP because it prevents Layer 2 loops. DTP is disabled to prevent VLAN hopping. Placing unused ports in an unused VLAN prevents unauthorized wired connectivity.
89. A network engineer is troubleshooting a newly deployed wireless network that is using the latest 802.11 standards. When users access high bandwidth services such as streaming video, the wireless network performance is poor. To improve performance the network engineer decides to configure a 5 Ghz frequency band SSID and train users to use that SSID for streaming media services. Why might this solution improve the wireless network performance for that type of service?
Explanation: Topic 13.4.3 – Wireless range is determined by the access point antenna and output power, not the frequency band that is used. In this scenario it is stated that all users have wireless NICs that comply with the latest standard, and so all can access the 5 GHz band. Although some users may find it inconvenient to switch to the 5 Ghz band to access streaming services, it is the greater number of channels, not just fewer users, that will improve network performance.
90. Which DHCPv4 message will a client send to accept an IPv4 address that is offered by a DHCP server?
Explanation: Topic 7.1.3 – When a DHCP client receives DHCPOFFER messages, it will send a broadcast DHCPREQUEST message for two purposes. First, it indicates to the offering DHCP server that it would like to accept the offer and bind the IP address. Second, it notifies any other responding DHCP servers that their offers are declined.
91. Refer to the exhibit. Which destination MAC address is used when frames are sent from the workstation to the default gateway?
Explanation: Topic 9.1.2 – The IP address of the virtual router acts as the default gateway for all the workstations. Therefore, the MAC address that is returned by the Address Resolution Protocol to the workstation will be the MAC address of the virtual router.
92. After a host has generated an IPv6 address by using the DHCPv6 or SLAAC process, how does the host verify that the address is unique and therefore usable?
Explanation: Topic 8.2.6 – Before a host can actually configure and use an IPv6 address learned through SLAAC or DHCP, the host must verify that no other host is already using that address. To verify that the address is indeed unique, the host sends an ICMPv6 neighbor solicitation to the address. If no neighbor advertisement is returned, the host considers the address to be unique and configures it on the interface.
93. Match the purpose with its DHCP message type. (Not all options are used.)
Explanation: Topic 7.1.3
| Purpose | Message Type |
|---|---|
| locate any available DHCP server | DHCPDISCOVER |
| identify the explicit server and lease offer to accept | DHCPREQUEST |
| acknowledge that the lease is successful | DHCPACK |
| suggest a lease to a client | DHCPOFFER |
94. Which protocol adds security to remote connections?
Explanation: Topic 1.3.2 – SSH allows a technician to securely connect to a remote network device for monitoring and troubleshooting. HTTP establishes web page requests. FTP manages file transfer. NetBEUI is not routed on the Internet. POP downloads email messages from email servers.
95. Refer to the exhibit. A network administrator is verifying the configuration of inter-VLAN routing. Users complain that PC2 cannot communicate with PC1. Based on the output, what is the possible cause of the problem?
Explanation: Topic 4.4.6 – The encapsulation dot1Q command must match the VLAN ID (should be 10, not 5).
96. Refer to the exhibit. A network administrator is configuring inter-VLAN routing on a network. For now, only one VLAN is being used, but more will be added soon. What is the missing parameter that is shown as the highlighted question mark in the graphic?
Explanation: Topic 4.2.4 – The parameter after dot1Q is the VLAN number.
97. Match each DHCP message type with its description. (Not all options are used.)
Explanation: Topic 7.1.3
- client initiating a message to find a DHCP server → DHCPDISCOVER
- DHCP server responding to the initial request by a client → DHCPOFFER
- the client accepting the IP address provided by the DHCP server → DHCPREQUEST
- the DHCP server confirming that the lease has been accepted → DHCPACK
98. What network attack seeks to create a DoS for clients by preventing them from being able to obtain a DHCP lease?
Explanation: Topic 10.5.5 – DCHP starvation attacks are launched by an attacker with the intent to create a DoS for DHCP clients. To accomplish this goal, the attacker uses a tool that sends many DHCPDISCOVER messages in order to lease the entire pool of available IP addresses, thus denying them to legitimate hosts.
99. Refer to the exhibit. If the IP addresses of the default gateway router and the DNS server are correct, what is the configuration problem?
Explanation: Topic 7.2.2 – In this configuration, the excluded address list should include the address that is assigned to the default gateway router. So the command should be ip dhcp excluded-address 192.168.10.1 192.168.10.9.
100. Refer to the exhibit. A network administrator has added a new subnet to the network and needs hosts on that subnet to receive IPv4 addresses from the DHCPv4 server. What two commands will allow hosts on the new subnet to receive addresses from the DHCP4 server? (Choose two.)
Explanation: Topic 7.2.8 – You need the router interface that is connected to the new subnet and the dhcp server address. The ip helper-address command is used to configure a router to be a DHCPv4 relay. The command should be placed on the interface facing the DHCPv4 clients. When the command is applied on the router interface, the interface will receive DHCPv4 broadcast messages and forward them as unicast to the IP address of the DHCPv4 server.
101. What protocol or technology uses source IP to destination IP as a load-balancing mechanism?
Explanation: Topic 6.1.3 – EtherChannel uses source/destination IP or MAC for load balancing.
102. What protocol should be disabled to help mitigate VLAN attacks?
Explanation: Topic 11.2.2 – Disabling DTP helps prevent VLAN hopping attacks.
103. What protocol or technology requires switches to be in server mode or client mode?
Explanation: Topic 3.3.1 – VTP uses server, client, and transparent modes.
104. What are two reasons a network administrator would segment a network with a Layer 2 switch? (Choose two.)
Explanation: Topic 2.2.3 – A switch has the ability of creating temporary point-to-point connections between the directly-attached transmitting and receiving network devices. The two devices have full-bandwidth full-duplex connectivity during the transmission.
105. What command will enable a router to begin sending messages that allow it to configure a link-local address without using an IPv6 DHCP server?
Explanation: Topic 8.2.2 – To enable IPv6 on a router you must use the ipv6 unicast-routing global configuration command or use the ipv6 enable interface configuration command. This is equivalent to entering ip routing to enable IPv4 routing on a router when it has been turned off. Keep in mind that IPv4 is enabled on a router by default. IPv6 is not enabled by default.
106. A network administrator is using the router-on-a-stick model to configure a switch and a router for inter-VLAN routing. What configuration should be made on the switch port that connects to the router?
Explanation: Topic 4.1.3 – The port on the switch that connects to the router interface should be configured as a trunk port. Once it becomes a trunk port, it does not belong to any particular VLAN and will forward traffic from various VLANs.
107. What are three techniques for mitigating VLAN attacks? (Choose three.)
Explanation: Topic 11.2.2 – Mitigating a VLAN attack can be done by disabling Dynamic Trunking Protocol (DTP), manually setting ports to trunking mode, and by setting the native VLAN of trunk links to VLANs not in use.
108. Match the DHCP message types to the order of the DHCPv4 process. (Not all options are used.)
Explanation: Topic 7.1.3 - The broadcast DHCPDISCOVER message finds DHCPv4 servers on the network. When the DHCPv4 server receives a DHCPDISCOVER message, it reserves an available IPv4 address to lease to the client and sends the unicast DHCPOFFER message to the requesting client. When the client receives the DHCPOFFER from the server, it sends back a DHCPREQUEST. On receiving the DHCPREQUEST message the server replies with a unicast DHCPACK message. DHCPREPLY and DHCPINFORMATION-REQUEST are DHCPv6 messages.
| Step | Message |
|---|---|
| Step 1 | DHCPDISCOVER |
| Step 2 | DHCPOFFER |
| Step 3 | DHCPREQUEST |
| Step 4 | DHCPACK |
109. In which situation would a technician use the show interfaces switch command?
Explanation: Topic 1.2.6 – The show interfaces command is useful to detect media errors, to see if packets are being sent and received, and to determine if any runts, giants, CRCs, interface resets, or other errors have occurred. Problems with reachability to a remote network would likely be caused by a misconfigured default gateway or other routing issue, not a switch issue. The show mac address-table command shows the MAC address of a directly attached device.
110. What is a drawback of the local database method of securing device access that can be solved by using AAA with centralized servers?
Explanation: Topic 10.2.1 – The local database method of securing device access utilizes usernames and passwords that are configured locally on the router. This allows administrators to keep track of who logged in to the device and when. The passwords can also be encrypted in the configuration. However, the account information must be configured on each device where that account should have access, making this solution very difficult to scale.
111. What action does a DHCPv4 client take if it receives more than one DHCPOFFER from multiple DHCP servers?
Explanation: Topic 7.1.3 – The client sends a DHCPREQUEST to accept one offer and decline others.
112. Refer to the exhibit. The network administrator is configuring the port security feature on switch SWC. The administrator issued the command show port-security interface fa 0/2 to verify the configuration. What can be concluded from the output that is shown? (Choose three.)
Explanation: Topic 11.1.3 – Because the security violation count is at 0, no violation has occurred. The system shows that 3 MAC addresses are allowed on port fa0/2, but only one has been configured and no sticky MAC addresses have been learned. The port is up because of the port status of secure-up. The violation mode is what happens when an unauthorized device is attached to the port. A port must be in access mode in order to activate and use port security.
113. What method of wireless authentication is dependent on a RADIUS authentication server?
Explanation: Topic 12.7.7 – WPA2 Enterprise uses RADIUS for authentication.
114. A network administrator has found a user sending a double-tagged 802.1Q frame to a switch. What is the best solution to prevent this type of attack?
Explanation: Topic 10.5.3 – Using different VLANs for user access and native VLAN prevents double-tagging attacks.
115. Refer to the exhibit. Which two conclusions can be drawn from the output? (Choose two.)
Explanation: Topic 6.3.1 – The output shows the EtherChannel is down and the port channel ID is 2.
116. Match the step number to the sequence of stages that occur during the HSRP failover process. (Not all options are used.)
Explanation: Topic 9.1.3 - Hot Standby Router Protocol (HSRP) is a Cisco-proprietary protocol that is designed to allow for transparent failover of a first-hop IPv4 device.
| Step | Description |
|---|---|
| Step 1 | The forwarding router fails. |
| Step 2 | The standby router stops seeing hello messages from the forwarding router. |
| Step 3 | The standby router assumes the role of the forwarding router using both the IP and MAC addresses of the virtual router. |
117. On a Cisco 3504 WLC Summary page (Advanced > Summary), which tab allows a network administrator to configure a particular WLAN with a WPA2 policy?
Explanation: Topic 13.2.6 – The WLANs tab in the Cisco 3504 WLC advanced Summary page allows a user to access the configuration of WLANs including security, QoS, and policy-mapping.
118. Refer to the exhibit. A network engineer is configuring IPv6 routing on the network. Which command issued on router HQ will configure a default route to the Internet to forward packets to an IPv6 destination network that is not listed in the routing table?
Explanation: Topic 15.3.1 – The IPv6 default route uses ::/0 as the destination.
119. Users are complaining of sporadic access to the internet every afternoon. What should be done or checked?
Explanation: Topic 16.2.1 – Sporadic access may indicate oversaturation of the default route.
120. What action takes place when the source MAC address of a frame entering a switch appears in the MAC address table associated with a different port?
Explanation: Topic 2.1.3 – The switch updates the CAM table with the new port mapping.
121. A network administrator is configuring a WLAN. Why would the administrator use a WLAN controller?
Explanation: Topic 12.4.2 – A WLC centralizes management of multiple WLANs.
122. A new Layer 3 switch is connected to a router and is being configured for interVLAN routing. What are three of the five steps required for the configuration? (Choose three.)
Explanation: Topic 4.3.3 – Steps: configure routed port, enable routing, configure routing, verify, verify connectivity.
Case 7 (NEW): creating SVI interfaces, enabling IP routing, assigning ports to VLANs
Case 1: entering "no switchport" on the port connected to the router, assigning ports to VLANs, enabling IP routing
Case 2: assigning ports to VLANs, creating SVI interfaces, creating VLANs
Case 3: assigning ports to VLANs, enabling IP routing, entering "no switchport" on the port connected to the router
Case 4: enabling IP routing, assigning ports to VLANs, creating SVI interfaces
Case 5: assigning ports to VLANs, enabling IP routing, creating SVI interfaces
Case 6: enabling IP routing, entering "no switchport" on the port connected to the router, assigning ports to VLANs
123. Which three statements accurately describe duplex and speed settings on Cisco 2960 switches? (Choose three.)
Explanation: Topic 1.2.2 – Autonegotiation failures cause issues; 1000 Mb/s ports are full-duplex; speed/duplex can be manually configured.
124. Refer to the exhibit. A network administrator configures R1 for inter-VLAN routing between VLAN 10 and VLAN 20. However, the devices in VLAN 10 and VLAN 20 cannot communicate. Based on the configuration in the exhibit, what is a possible cause for the problem?
Explanation: Topic 4.2.4 – The encapsulation dot1Q command must match the correct VLAN.
125. A network administrator uses the spanning-tree portfast bpduguard default global configuration command to enable BPDU guard on a switch. However, BPDU guard is not activated on all access ports. What is the cause of the issue?
Explanation: Topic 11.5.3 – BPDU guard only activates on PortFast-enabled ports.
126. Which two types of spanning tree protocols can cause suboptimal traffic flows because they assume only one spanning-tree instance for the entire bridged network? (Choose two.)
Explanation: Topic 5.3.1 – STP and RSTP use a single spanning-tree instance for the entire network.
127. Refer to the exhibit. A network administrator is configuring the router R1 for IPv6 address assignment. Based on the partial configuration, which IPv6 global unicast address assignment scheme does the administrator intend to implement?
Explanation: Topic 8.3.5 – The configuration indicates stateful DHCPv6.
128. A WLAN engineer deploys a WLC and five wireless APs using the CAPWAP protocol with the DTLS feature to secure the control plane of the network devices. While testing the wireless network, the WLAN engineer notices that data traffic is being exchanged between the WLC and the APs in plain-text and is not being encrypted. What is the most likely reason for this?
Explanation: Topic 12.4.4 – DTLS is enabled for the control channel but disabled by default for the data channel.
129. A new switch is to be added to an existing network in a remote office. The network administrator does not want the technicians in the remote office to be able to add new VLANs to the switch, but the switch should receive VLAN updates from the VTP domain. Which two steps must be performed to configure VTP on the new switch to meet these conditions? (Choose two.)
Explanation: Topic 3.3.1 – Before the switch is put in the correct VTP domain and in client mode, the switch must be connected to any other switch in the VTP domain through a trunk in order to receive/transmit VTP information.
130. Refer to the exhibit. Consider that the main power has just been restored. PC3 issues a broadcast IPv4 DHCP request. To which port will SW1 forward this request?
Explanation: Topic 2.1.3 – Broadcast frames are flooded to all ports except the ingress port.
131. What action takes place when the source MAC address of a frame entering a switch is not in the MAC address table?
Explanation: Topic 2.1.3 – The switch learns MAC addresses by adding the source MAC and incoming port to the table.
132. Employees are unable to connect to servers on one of the internal networks. What should be done or checked?
Explanation: Topic 1.5.2 – show ip interface brief quickly identifies down interfaces.
133. What is the effect of entering the ip dhcp snooping configuration command on a switch?
Explanation: Topic 11.3.3 – The ip dhcp snooping command enables DHCP snooping globally.
134. An administrator notices that large numbers of packets are being dropped on one of the branch routers. What should be done or checked?
Explanation: Topic 16.2.1 – Packet drops may indicate a missing static route.
135. What are two switch characteristics that could help alleviate network congestion? (Choose two.)
Explanation: Topic 2.2.3 – Fast internal switching and large frame buffers help alleviate congestion.
136. What is a result of connecting two or more switches together?
Explanation: Topic 2.2.2 – When two or more switches are connected together, the size of the broadcast domain is increased and so is the number of collision domains. The number of broadcast domains is increased only when routers are added.
138. Branch users were able to access a site in the morning but have had no connectivity with the site since lunch time. What should be done or checked?
Explanation: Topic 16.2.3 – The static route to the server may have been removed or changed.
139. What is the effect of entering the switchport port-security configuration command on a switch?
Explanation: Topic 11.1.3 – switchport port-security enables port security on the interface.
140. A network administrator is configuring a WLAN. Why would the administrator use multiple lightweight APs?
Explanation: Topic 13.2.2 – Lightweight APs are managed centrally by a WLC.
141. Refer to the exhibit. PC-A and PC-B are both in VLAN 60. PC-A is unable to communicate with PC-B. What is the problem?
Explanation: Topic 3.4.1 – Because PC-A and PC-B are connected to different switches, traffic between them must flow over the trunk link. Trunks can be configured so that they only allow traffic for particular VLANs to cross the link. In this scenario, VLAN 60, the VLAN that is associated with PC-A and PC-B, has not been allowed across the link, as shown by the output of show interfaces trunk.
142. A network administrator is configuring a WLAN. Why would the administrator use RADIUS servers on the network?
Explanation: Topic 12.7.7 – RADIUS servers provide authentication for wireless users.
143. What is the effect of entering the switchport mode access configuration command on a switch?
Explanation: Topic 11.2.2 – switchport mode access disables DTP and forces the port into access mode.
144. A network administrator has configured a router for stateless DHCPv6 operation. However, users report that workstations are not receiving DNS server information. Which two router configuration lines should be verified to ensure that stateless DHCPv6 service is properly configured? (Choose two.)
Explanation: Topic 8.3.3 – To use the stateless DHCPv6 method, the router must inform DHCPv6 clients to configure a SLAAC IPv6 address and contact the DHCPv6 server for additional configuration parameters, such as the DNS server address. This is done through the command ipv6 nd other-config-flag entered at the interface configuration mode. The DNS server address is indicated in the ipv6 dhcp pool configuration.
145. A network administrator is configuring a WLAN. Why would the administrator disable the broadcast feature for the SSID?
Explanation: Topic 12.7.2 – Disabling SSID broadcast prevents casual scanning.
146. Refer to the exhibit. An administrator is attempting to install an IPv6 static route on router R1 to reach the network attached to router R2. After the static route command is entered, connectivity to the network is still failing. What error has been made in the static route configuration?
Explanation: Topic 15.1.2 – In this example the interface in the static route is incorrect. The interface should be the exit interface on R1, which is s0/0/0.
147. What action takes place when a frame entering a switch has a unicast destination MAC address that is not in the MAC address table?
Explanation: Topic 2.1.3 – Unknown unicast frames are flooded to all ports except the ingress port.
148. A junior technician was adding a route to a LAN router. A traceroute to a device on the new network revealed a wrong path and unreachable status. What should be done or checked?
Explanation: Topic 16.2.1 – The exit interface on the static route may be misconfigured.
149. What is the effect of entering the ip arp inspection vlan 10 configuration command on a switch?
Explanation: Topic 11.4.2 – ip arp inspection vlan 10 enables Dynamic ARP Inspection on VLAN 10.
150. What protocol or technology manages trunk negotiations between switches?
Explanation: Topic 3.5.1 – DTP (Dynamic Trunking Protocol) manages trunk negotiations.
151. A network administrator is configuring a WLAN. Why would the administrator apply WPA2 with AES to the WLAN?
Explanation: Topic 12.7.6 – WPA2 with AES provides encryption for wireless traffic.
152. Users on a LAN are unable to get to a company web server but are able to get elsewhere. What should be done or checked?
Explanation: Topic 16.2.3 – The static route to the web server may be missing.
153. What IPv6 prefix is designed for link-local communication?
Explanation: Topic 1.5.3 – IPv6 link-local addresses use the FE80::/10 prefix.
154. What is the effect of entering the ip dhcp snooping limit rate 6 configuration command on a switch?
Explanation: Topic 11.3.3 – The ip dhcp snooping limit rate command rate-limits DHCP discovery messages.
155. A network administrator is configuring a WLAN. Why would the administrator change the default DHCP IPv4 addresses on an AP?
Explanation: Topic 13.1.3 – Changing default DHCP address ranges reduces the risk of unauthorized access.
156. What is the effect of entering the ip arp inspection validate src-mac configuration command on a switch?
Explanation: Topic 11.4.3 – DAI validate src-mac checks source MAC against sender MAC in ARP body.
157. What protocol or technology is a Cisco proprietary protocol that is automatically enabled on 2960 switches?
Explanation: Topic 3.5.1 – DTP is a Cisco proprietary protocol enabled by default on 2960 switches.
158. What address and prefix length is used when configuring an IPv6 default static route?
Explanation: Topic 15.3.1 – IPv6 default route uses ::/0.
159. What are two characteristics of Cisco Express Forwarding (CEF)? (Choose two.)
Explanation: Topic 14.2.3 – CEF is the fastest forwarding mechanism and uses FIB and adjacency tables.
160. Which term describes the role of a Cisco switch in the 802.1X port-based access control?
Explanation: Topic 10.2.6 – The switch acts as the authenticator in 802.1X.
161. Which Cisco solution helps prevent ARP spoofing and ARP poisoning attacks?
Explanation: Topic 10.3.3 – Dynamic ARP Inspection (DAI) prevents ARP spoofing and poisoning.
162. What is an advantage of PVST+?
Explanation: Topic 5.3.1 – PVST+ results in optimum load balancing. However, this is accomplished by manually configuring switches to be elected as root bridges for different VLANs on the network. The root bridges are not automatically selected. Furthermore, having spanning-tree instances for each VLAN actually consumes more bandwidth and it increases the CPU cycles for all the switches in the network.
163. What protocol or technology uses a standby router to assume packet-forwarding responsibility if the active router fails?
Explanation: Topic 9.2.1 – HSRP provides gateway redundancy with active and standby routers.
164. What is the effect of entering the show ip dhcp snooping binding configuration command on a switch?
Explanation: Topic 11.3.4 – show ip dhcp snooping binding displays the DHCP snooping binding database.
165. What action takes place when the source MAC address of a frame entering a switch is in the MAC address table?
Explanation: Topic 2.1.3 – The switch updates the aging timer for the MAC address entry.
166. A small publishing company has a network design such that when a broadcast is sent on the LAN, 200 devices receive the transmitted broadcast. How can the network administrator reduce the number of devices that receive broadcast traffic?
Explanation: Topic 3.1.2 – By dividing the one big network into two smaller network, the network administrator has created two smaller broadcast domains. When a broadcast is sent on the network now, the broadcast will only be sent to the devices on the same Ethernet LAN. The other LAN will not receive the broadcast.
167. What defines a host route on a Cisco router?
Explanation: Topic 15.5.1 – By dividing the one big network into two smaller network, the network administrator has created two smaller broadcast domains. When a broadcast is sent on the network now, the broadcast will only be sent to the devices on the same Ethernet LAN. The other LAN will not receive the broadcast.
168. What else is required when configuring an IPv6 static route using a next-hop link-local address?
Explanation: Topic 15.2.6 – When using a link-local next-hop, the exit interface must be specified.
169. A technician is configuring a wireless network for a small business using a SOHO wireless router. Which two authentication methods are used, if the router is configured with WPA2? (Choose two.)
Explanation: Topic 12.7.5 – WPA2 supports both Personal (PSK) and Enterprise (RADIUS) authentication.
170. Which mitigation technique would prevent rogue servers from providing false IPv6 configuration parameters to clients?
Explanation: Topic 11.6.2 – By dividing the one big network into two smaller network, the network administrator has created two smaller broadcast domains. When a broadcast is sent on the network now, the broadcast will only be sent to the devices on the same Ethernet LAN. The other LAN will not receive the broadcast.
171. A PC has sent an RS message to an IPv6 router attached to the same network. Which two pieces of information will the router send to the client? (Choose two.)
Explanation: Topic 8.2.4 – By dividing the one big network into two smaller network, the network administrator has created two smaller broadcast domains. When a broadcast is sent on the network now, the broadcast will only be sent to the devices on the same Ethernet LAN. The other LAN will not receive the broadcast.
172. While attending a conference, participants are using laptops for network connectivity. When a guest speaker attempts to connect to the network, the laptop fails to display any available wireless networks. The access point must be operating in which mode?
Explanation: Topic 12.3.7 – Active is a mode used to configure an access point so that clients must know the SSID to connect to the access point. APs and wireless routers can operate in a mixed mode meaning that that multiple wireless standards are supported. Open is an authentication mode for an access point that has no impact on the listing of available wireless networks for a client. When an access point is configured in passive mode, the SSID is broadcast so that the name of wireless network will appear in the listing of available networks for clients.
173. Which three components are combined to form a bridge ID?
Explanation: Topic 5.2.1 – The three components that are combined to form a bridge ID are bridge priority, extended system ID, and MAC address.
174. On a Cisco 3504 WLC Summary page (Advanced > Summary), which tab allows a network administrator to configure a particular WLAN with a WPA2 policy?
Explanation: Topic 13.2.6 – The WLANs tab allows configuration of WLAN security policies.
🚀 Ace Your CCNA Exam - Complete Study Pack!
Get 500+ exam-realistic questions, Packet Tracer labs, and detailed explanations.
Understanding the CCNA 2 v7.0 Final Exam – Switching, Routing and Wireless Essentials
Passing the CCNA 2 v7.0 Final Exam requires a comprehensive understanding of switching, routing, VLANs, STP, EtherChannel, DHCP, HSRP, and wireless essentials. This exam covers the entire SRWE (Switching, Routing, and Wireless Essentials) curriculum and tests your ability to configure, verify, and troubleshoot network devices.
Why This Exam Matters for Your Networking Career
The CCNA 2 v7.0 Final Exam validates your knowledge of Layer 2 switching, VLANs, inter-VLAN routing, spanning tree protocol, EtherChannel, DHCP, FHRP (HSRP), and wireless LANs. Employers expect CCNA-certified professionals to understand switching concepts, routing fundamentals, and wireless configuration. Mastering these topics prepares you for advanced networking roles and the full CCNA certification.
Key Topics Covered in the Exam
- Switching Concepts: MAC address tables, frame forwarding, collision/broadcast domains.
- VLANs and Trunking: VLAN configuration, trunking (802.1Q, DTP), VTP.
- STP and EtherChannel: STP/RSTP operation, root bridge election, port roles, EtherChannel (PAgP, LACP).
- Inter-VLAN Routing: Router-on-a-stick, Layer 3 switching, SVI configuration.
- Dynamic Host Configuration Protocol (DHCP): DHCPv4 and DHCPv6, relay agents, stateless/stateful DHCPv6.
- First Hop Redundancy Protocols: HSRP, active/standby routers, virtual IP and MAC.
- Wireless Essentials: WLAN standards (802.11a/b/g/n/ac), security (WPA2, AES), WLC configuration.
- Network Security: Port security, DHCP snooping, Dynamic ARP Inspection (DAI), AAA, 802.1X.
Study Strategies That Work
To retain this material long-term, combine our exam answers with hands-on practice. Use Packet Tracer to configure VLANs, trunking, STP, EtherChannel, inter-VLAN routing, DHCP, HSRP, and wireless networks. Practice troubleshooting scenarios and verify configurations with show commands. This practical approach cements the theory from the SRWE curriculum.
We also recommend creating flashcards for key terms: STP, RSTP, PVST+, EtherChannel, PAgP, LACP, DTP, VTP, HSRP, DHCP snooping, DAI, 802.1X, and the different wireless standards. Quiz yourself daily until you can define each term without hesitation.
Final Tips for Exam Day
- Get a good night's sleep – fatigue leads to misreading questions.
- Read each question twice. Some ask "Which two statements are correct?" – don't just pick one answer.
- Manage your time. You typically have 60-90 minutes for 60-80 questions. Skip difficult ones and return later.
- Look for keywords like "not", "except", or "only". One word changes the entire meaning.
- Trust your first instinct unless you find clear evidence you misread.
Remember: The CCNA v7 curriculum emphasizes practical troubleshooting. If you can explain why a port goes into error-disable or why a DHCP starvation attack succeeds, you're ready. Use our answers to verify your thinking, then reinforce with simulation tools. Good luck on your exam – and on your journey to networking expertise.