CCNA 3 (Version 7.00) ENSA Practice Final Exam Answers
Enterprise Networking, Security, and Automation (Version 7.00) – ENSA Practice Final Exam. This comprehensive study guide covers all topics from the CCNA 3 ENSA curriculum, including OSPF, ACLs, NAT, VPNs, QoS, and network automation.
1. Which QoS mechanism allows delay-sensitive data, such as voice, to be sent first before packets in other queues are sent?
Explanation: Low latency queuing (LLQ) adds a priority queue to CBWFQ from which delay-sensitive traffic, such as voice traffic, can be transmitted ahead of packets in other queues.
2. Which QoS technique retains excess packets in a separate queue for later transmission?
Explanation: As network traffic exits an interface it is queued and then shaped to smooth out the packet output rate. Classification and marking should occur early on to identify traffic and classify how the traffic should be treated.
3. What term describes adding a value to the packet header, as close to the source as possible, so that the packet matches a defined policy?
Explanation: Traffic marking adds a value to the packet header to identify traffic for policy enforcement.
4. What is a characteristic of the distribution layer in the three layer hierarchical model?
Explanation: One of the functions of the distribution layer is aggregating large-scale wiring closet networks. Providing access to end users is a function of the access layer, which is the network edge. Acting as a backbone is a function of the core layer.
5. Which two methods help to prevent the disruption of network services? (Choose two.)
Explanation: Using duplicate equipment and using redundant paths are two methods to help prevent network disruptions. The use of VLANs would not affect network availability. Changing the routing protocol could actually reduce availability during convergence. Loops, which are created by the provision of redundant paths, are managed by protocols without removing devices.
6. Which technology provides laptops the ability to function on a cellular network?
Explanation: Mobile hotspots allow a laptop to connect to a cellular network and gain WAN access. Bluetooth and infrared wireless work for short distances. 802.11 Wi-Fi technology provides laptops with access to a local network.
7. Which two types of devices are specific to WAN environments and are not found on a LAN? (Choose two.)
Explanation: Broadband modems and CSU/DSUs are examples of WAN devices. Core switches can be found on both WANs and LANs. Access layer switches and distribution layer routers are found only on LANs.
8. Which three traffic-related factors would influence selecting a particular WAN link type? (Choose three.)
Explanation: The traffic-related factors that influence selecting a particular WAN link type include the type of traffic, amount of traffic, quality requirements, and security requirements. Quality requirements include ensuring that traffic that cannot tolerate delay gets priority treatment as well as important business transactional traffic.
9. Which type of NAT maps a single inside local address to a single inside global address?
Explanation: A one-to-one mapping of an inside local address to an inside global address is accomplished through static NAT.
10. Refer to the exhibit. What has to be done in order to complete the static NAT configuration on R1?
Explanation: In order for NAT translations to work properly, both an inside and outside interface must be configured for NAT translation on the router.
11. Refer to the exhibit. R1 is configured for static NAT. What IP address will Internet hosts use to reach PC1?
Explanation: In static NAT a single inside local address, in this case 192.168.0.10, will be mapped to a single inside global address, in this case 209.165.200.225. Internet hosts will send packets to PC1 and use as a destination address the inside global address 209.165.200.225.
12. A network administrator is troubleshooting the dynamic NAT that is configured on router R2. Which command can the administrator use to see the total number of active NAT translations and the number of addresses that are allocated from the NAT pool?
Explanation: R2# show ip nat statistics will display information about the total number of active translations, NAT configuration parameters, the number of addresses in the pool, and the number that have been allocated.
13. What is correct in relation to NAT for IPv6?
Explanation: NAT for IPv6 is a temporary measure to aid in the move from IPv4 to IPv6. NAT64 is replacing NAT-PT. Dual stack is a method for running IPv4 and IPv6 on the same network.
14. Which three statements are generally considered to be best practices in the placement of ACLs? (Choose three.)
Explanation: Extended ACLs should be placed as close as possible to the source IP address, so that traffic that needs to be filtered does not cross the network and use network resources. Because standard ACLs do not specify a destination address, they should be placed as close to the destination as possible. Placing a standard ACL close to the source may have the effect of filtering all traffic, and limiting services to other hosts. Filtering unwanted traffic before it enters low-bandwidth links preserves bandwidth and supports network functionality. Decisions on placing ACLs inbound or outbound are dependent on the requirements to be met.
15. Refer to the exhibit. The Gigabit interfaces on both routers have been configured with subinterface numbers that match the VLAN numbers connected to them. PCs on VLAN 10 should be able to print to the P1 printer on VLAN 12. PCs on VLAN 20 should print to the printers on VLAN 22. What interface and in what direction should you place a standard ACL that allows printing to P1 from data VLAN 10, but stops the PCs on VLAN 20 from using the P1 printer? (Choose two.)
Explanation: A standard access list is commonly placed as close to the destination network as possible because access control expressions in a standard ACL do not include information about the destination network. The destination in this example is printer VLAN 12 which has router R1 Gigabit subinterface 0/1/.12 as its gateway. A sample standard ACL that only allows printing from data VLAN 10 (192.168.10.0/24), for example, and no other VLAN would be:
R1(config)# access-list 1 permit 192.168.10.0 0.0.0.255 R1(config)# access-list 1 deny any R1(config)# interface gigabitethernet 0/1.12 R1(config-if)# ip access-group 1 out
16. If a router has two interfaces and is routing both IPv4 and IPv6 traffic, how many ACLs could be created and applied to it?
Explanation: In calculating how many ACLs can be configured, use the rule of “three Ps”: one ACL per protocol, per direction, per interface. In this case, 2 interfaces x 2 protocols x 2 directions yields 8 possible ACLs.
17. Which type of Hypervisor is implemented when a user with a laptop running the Mac OS installs a Windows virtual OS instance?
Explanation: Type 2 hypervisors, also know as hosted hypervisors, are installed on top of an existing operating system, such as Mac OS, Windows, or Linux.
18. Which two layers of the OSI model are associated with SDN network control plane functions that make forwarding decisions? (Choose two.)
Explanation: The SDN control plane uses the Layer 2 ARP table and the Layer 3 routing table to make decisions about forwarding traffic.
19. What defines a two-tier spine-leaf topology?
Explanation: In this two-tier topology, everything is one hop from everything else. The leaf switches (Cisco Nexus 9300) always attach to the spines (Cisco Nexus 9500), but never to each other. Similarly, the spine switches only attach to the leaf and core switches. The Cisco APICs and all other devices in the network physically attach to leaf switches. When compared to SDN, the APIC controller does not manipulate the data path directly.
20. Which SNMP message type informs the network management system (NMS) immediately of certain specified events?
Explanation: A GET request retrieves the value of a specific MIB variable. A SET request modifies the value of an MIB variable. A GET response contains the value of the requested variable. A Trap transmits an unsolicited alarm condition immediately after the event occurs.
21. Which number represents the most severe level of syslog logging?
Explanation: Syslog levels are numbered 0 through 7, with 0 being the most severe and 7 being the least severe.
22. Which command will backup the configuration that is stored in NVRAM to a TFTP server?
Explanation: The startup configuration file is stored in NVRAM, and the running configuration is stored in RAM. The copy command is followed by the source, then the destination.
23. Which statement describes a feature of site-to-site VPNs?
Explanation: Site-to-site VPNs are statically defined VPN connections between two sites that use VPN gateways. The internal hosts do not require VPN client software and send normal, unencapsulated packets onto the network where they are encapsulated by the VPN gateway.
24. Which VPN solution allows the use of a web browser to establish a secure, remote-access VPN tunnel to the ASA?
Explanation: When a web browser is used to securely access the corporate network, the browser must use a secure version of HTTP to provide SSL encryption. A VPN client is not required to be installed on the remote host, so a clientless SSL connection is used.
25. Which two types of VPNs are examples of enterprise-managed remote access VPNs? (Choose two.)
Explanation: Enterprise managed VPNs can be deployed in two configurations: Remote Access VPNs (client-based IPsec and clientless SSL) and Site-to-site VPNs (IPsec, GRE over IPsec, DMVPN, VTI).
26. When JSON data format is being used, what characters are used to hold objects?
Explanation: A JavaScript Object Notation (JSON) object is a key-value data format that is typically rendered in curly braces { }.
27. Which two statements describe remote access VPNs? (Choose two.)
Explanation: Remote access VPNs are designed to provide for the needs of telecommuters and mobile users through the use of software that is installed on the client to encrypt and encapsulate the data. Remote access VPNs can be used across a variety of WAN connections. Users must access the client software to initiate the VPN connection.
28. Refer to the exhibit. If the switch reboots and all routers have to re-establish OSPF adjacencies, which routers will become the new DR and BDR?
Explanation: OSPF elections of a DR are based on the following in order of precedence: highest priority (1-255), highest router ID, highest IP address of a loopback or active interface. In this case routers R4 and R1 have the highest router priority. Between the two, R3 has the higher router ID. Therefore, R4 will become the DR and R1 will become the BDR.
29. Refer to the exhibit. A network administrator has configured OSPFv2 on the two Cisco routers as shown. The routers are unable to form a neighbor adjacency. What should be done to fix the problem?
Explanation: In order to form OSPFv2 neighbor adjacencies, two connected router interfaces must share the same subnet. Router R2 is shown in the topology with an IP address of 192.168.20.5 and does not exist on the same subnet as the 192.168.20.1 /30 IP address of S0/0 on router R1.
30. What are the two purposes of an OSPF router ID? (Choose two.)
Explanation: OSPF router ID does not contribute to SPF algorithm calculations, nor does it facilitate the transition of the OSPF neighbor state to Full. Although the router ID is contained within OSPF messages when router adjacencies are being established, it has no bearing on the actual convergence process.
31. Which command will a network engineer issue to verify the configured hello and dead timer intervals on a point-to-point WAN link between two routers that are running OSPFv2?
Explanation: The show ip ospf interface serial 0/0/0 command will display the configured hello and dead timer intervals on a point-to-point serial WAN link between two OSPFv2 routers.
32. Refer to the exhibit. What is the OSPF cost to reach the router A LAN 172.16.1.0/24 from B?
Explanation: The formula used to calculate the OSPF cost is: Cost = reference bandwidth / interface bandwidth. Default reference bandwidth is 10^8 (100,000,000). Serial link (1544 Kbps) cost = 100,000,000 / 1,544,000 = 64. Gigabit Ethernet cost = 100,000,000 / 1,000,000,000 = 1. Total cost to reach 172.16.1.0/24 = 64 + 1 = 65.
33. Refer to the exhibit. Which data format is used to represent the data for network automation applications?
Explanation: YAML uses indentation to define its structure, without the use of brackets or commas. Common data formats include JSON (key/value pairs in braces), XML (tags), and YAML (indentation).
34. A user is reading a book from the website https://www.books-info.com/author1a/book2.html#page100 . Which part of the web link is called a fragment?
Explanation: In the URI, the fragment is indicated by the hash (#) and refers to a specific part of the resource. Components: Protocol/scheme (https://), hostname (www.books-info.com), path/file (/author1a/book2.html), fragment (#page100).
35. Refer to the exhibit. Why are routers R1 and R2 not able to establish an OSPF adjacency?
Explanation: On router R1, the network 192.168.10.0/30 is defined in the wrong area (area 1). It has to be defined in area 0 in order to establish adjacency with router R2, which has the network 192.168.10.0/30 defined in area 0.
36. A network technician has used the access-list 1 permit 172.16.0.0 0.0.0.255 command to configure NAT on an edge router to translate only four networks, 172.16.0.0 /24, 172.16.1.0 /24, 172.16.2.0 /24, and 172.16.3.0 /24. After receiving complaints about limited access to the Internet, issuing the show ip nat translations command reveals that some networks are missing from the output. Which change will resolve the problem?
Explanation: The ACL in the original configuration will only permit the first subnet, 172.16.0.0, to be translated. The correct wildcard mask to cover 172.16.0.0 – 172.16.3.0 is 0.0.3.255. The option with 0.0.3.255 will allow translation of just the four subnets.
37. Which type of tool would an administrator use to capture packets that are going to and from a particular device?
Explanation: Protocol analyzers capture packets as they enter or leave a device and can display those packets in real time. An NMS tool is used to monitor and configure network devices. A knowledge base is a repository of information that pertains to the operation and troubleshooting of a specific device or service. A baselining tool is used to measure network or device performance during normal operations, so that abnormal conditions can be easily spotted.
38. A user reports that the workstation cannot connect to a networked printer in the office in order to print a report created with word processing software. Which troubleshooting action by the helpdesk technician would follow the divide-and-conquer approach?
Explanation: The ipconfig command can be used to check the IP settings of the workstation, an internet layer issue, so this is the divide-and-conquer approach. Based on the result, the technician can further investigate either from the lower layer (for example, looking for a network connectivity issue) or the upper layer (for example, checking whether the application is working properly). To ask the user to unplug and reattach the network cable is the bottom-up approach. Asking the user to launch a web browser (to check if an application can start normally) and to save the document (to check that the application is performing normally and to preserve the working document) is the top-down approach.
39. Match the OSPF state with the order in which it occurs. (Not all options are used.)
Explanation: The active and passive states are used by EIGRP. The correct order:
| Order | State |
|---|---|
| first state | Down state |
| second state | Init state |
| third state | Two-way state |
| fourth state | Exstart state |
| fifth state | Exchange state |
| sixth state | Loading state |
| seventh state | Full state |
40. When an OSPF network is converged and no network topology change has been detected by a router, how often will LSU packets be sent to neighboring routers?
Explanation: After all LSRs have been satisfied for a given router, the adjacent routers are considered synchronized and in a full state. Updates (LSUs) are sent to neighbors only when a network topology change is detected (incremental updates) or every 30 minutes.
41. Which type of OSPFv2 packet contains an abbreviated list of the LSDB of a sending router and is used by receiving routers to check against the local LSDB?
Explanation: The database description (DBD) packet contains an abbreviated list of the LSDB sent by a neighboring router and is used by receiving routers to check against the local LSDB.
42. Which step in the link-state routing process is described by a router building a link-state database based on received LSAs?
Explanation: Building the topology table is the process of constructing the link-state database from received LSAs.
43. Refer to the exhibit. A network administrator has configured ACL 9 as shown. Users on the 172.31.1.0 /24 network cannot forward traffic through router CiscoVille. What is the most likely cause of the traffic failure?
Explanation: When verifying an ACL, the statements are always listed in a sequential order. Even though there is an explicit permit for the traffic that is sourced from network 172.31.1.0 /24, it is being denied due to the previously implemented ACE of CiscoVille(config)# access-list 9 deny 172.31.0.0 0.0.255.255. The sequence of the ACEs must be modified to permit the specific traffic that is sourced from network 172.31.1.0 /24 and then to deny 172.31.0.0 /16.
44. A technician is tasked with using ACLs to secure a router. When would the technician use the access-class 20 in configuration option or command?
Explanation: The access-class command is used to restrict VTY (telnet/SSH) access to the router based on an ACL, thus securing administrative access.
45. Refer to the exhibit. A network administrator is configuring a standard IPv4 ACL. What is the effect after the command no access-list 10 is entered?
Explanation: The R1(config)# no access-list
46. An administrator has configured an access list on R1 to allow SSH administrative access from host 172.16.1.100. Which command correctly applies the ACL?
Explanation: Administrative access over SSH to the router is through the vty lines. Therefore, the ACL must be applied to those lines in the inbound direction. This is accomplished by entering line configuration mode and issuing the access-class command.
47. Refer to the exhibit. The network administrator that has the IP address of 10.0.70.23/25 needs to have access to the corporate FTP server (10.0.54.5/28). The FTP server is also a web server that is accessible to all internal employees on networks within the 10.x.x.x address. No other traffic should be allowed to this server. Which extended ACL would be used to filter this traffic, and how would this ACL be applied? (Choose two.)
Explanation: The first two lines of the ACL allow host 10.0.70.23 FTP access to the server that has the IP address of 10.0.54.5. The next line of the ACL allows HTTP access to the server from any host that has an IP address that starts with the number 10. The fourth line of the ACL denies any other type of traffic to the server from any source IP address. The last line of the ACL permits anything else in case there are other servers or devices added to the 10.0.54.0/28 network. Because traffic is being filtered from all other locations and for the 10.0.70.23 host device, the best place to put this ACL is closest to the server.
48. What is a feature of an IPS?
Explanation: An advantage of an intrusion prevention systems (IPS) is that it can identify and stop malicious packets. However, because an IPS is deployed inline, it can add latency to the network.
49. Which type of security threat can be described as software that attaches itself to another program to execute a specific unwanted function?
Explanation: Viruses can be malicious and destructive or simply change something about the computer, such as words or images, and not necessarily cause the computer to malfunction. Viruses can be spread through shared media such as CDs or memory sticks, but can also be delivered via the Internet and email.
50. What is the significant characteristic of worm malware?
Explanation: Worm malware can execute and copy itself without being triggered by a host program. It is a significant network and Internet security threat.
51. What is the best description of Trojan horse malware?
Explanation: The best description of Trojan horse malware, and what distinguishes it from viruses and worms, is that it appears as useful software but hides malicious code. Trojan horse malware may cause annoying computer problems, but can also cause fatal problems. Some Trojan horses may be distributed over the Internet, but they can also be distributed by USB memory sticks and other means. Specifically targeted Trojan horse malware can be some of the most difficult malware to detect.
52. What is the function of ASICs in a multilayer switch?
Explanation: ASICs are application-specific integrated circuits and they allow a multilayer switch to forward IP packets without calling on the CPU to make routing decisions. By using ASICs a switch can forward IP packets almost as fast as it can forward Layer 2 frames.
53. What is the port density of a switch?
Explanation: Port density refers to the number of available ports on a switch. Bandwidth is the wire speed of a single port on a switch. The combined bandwidth of all ports on a switch is the forwarding rate.
54. What is a difference between the functions of Cloud computing and virtualization?
Explanation: Cloud computing separates the application from the hardware. Virtualization separates the OS from the underlying hardware. Virtualization is a typical component within cloud computing. Virtualization is also widely used in data centers. Although the implementation of virtualization facilitates an easy server fault tolerance setup, it is not a fault tolerance technology by design. The Internet connection from a data center or service provider needs redundant physical WAN connections to ISPs.
55. Why would a network administrator use the config-register 0x2102 command on a Cisco network device?
Explanation: Password Recovery Procedures involve setting config-register to 0x2142 to ignore startup-config. After changing passwords, set config-register back to 0x2102 to load startup-config normally. Therefore, 0x2102 ensures the device loads the startup configuration file during startup.
56. Refer to the exhibit. The network administrator that has the IP address of 10.0.70.23/25 needs to have access to the corporate FTP server (10.0.54.5/28). The FTP server is also a web server that is accessible to all internal employees on networks within the 10.x.x.x address. No other traffic should be allowed to this server. Which extended ACL would be used to filter this traffic, and how would this ACL be applied? (Choose two.)
Explanation: Same as question 47. The correct ACL and placement allow FTP from the specific host, HTTP from internal network, and deny everything else to the server, applied outbound on R1 Gi0/0.
🚀 Ace Your CCNA Exam - Complete Study Pack!
Get 500+ exam-realistic questions, Packet Tracer labs, and detailed explanations.
Understanding the ENSA Practice Final Exam
Passing the CCNA 3 ENSA Practice Final Exam is a crucial step toward mastering enterprise networking, security, and automation. This comprehensive exam covers a wide range of topics from OSPF routing and ACLs to NAT, VPNs, QoS, and network programmability.
Why the Practice Final Matters
The ENSA Practice Final Exam is designed to test your knowledge of the entire CCNA 3 curriculum. It bridges the gap between theoretical concepts and real-world application. Employers expect CCNA-certified professionals to understand advanced routing protocols, network security policies, WAN technologies, and automation principles. Mastering these topics prepares you for the final certification exam and a successful networking career.
Key Topics Covered in the Exam
- OSPF: Single-area and multi-area OSPFv2/v3, DR/BDR election, router IDs, neighbor states, and cost calculation.
- ACLs: Standard and extended ACLs, placement best practices, and filtering traffic for security.
- NAT: Static NAT, dynamic NAT, PAT, and NAT for IPv6.
- VPNs and IPsec: Site-to-site and remote access VPNs, IPsec components (AES, SHA, DH), and tunneling.
- QoS: Queuing, shaping, policing, and LLQ for real-time traffic.
- Network Management: SNMP, syslog, and configuration backup.
- Virtualization and Automation: Hypervisors, SDN, JSON/YAML/XML data formats, and automation tools.
- Network Security: Malware types (virus, worm, Trojan), IPS, and secure access.
Study Strategies That Work
To retain this material long-term, combine our exam answers with hands-on practice. Use Packet Tracer or real equipment to configure OSPF, ACLs, NAT, and VPNs. Experiment with different scenarios and verify with show commands. This practical approach cements the theory from the curriculum.
We also recommend creating flashcards for key terms: OSPF states, ACL types, NAT terminology, IPsec protocols, QoS mechanisms, and data formats. Quiz yourself daily until you can define each term without hesitation.
How to Use This Answer Page Effectively
Our goal at CoursMooc.com is to provide accurate, up-to-date answers for the latest CCNA v7 curriculum. For each question, we include an explanation—not just the correct choice. Read those explanations carefully. If you find a concept unclear, refer to the official Cisco NetAcad course materials or our additional tutorials linked below.
We regularly update this page to match any changes in the exam. If you notice discrepancies, please let us know through the comments. Your feedback helps other learners succeed.
Final Tips for Exam Day
- Get a good night's sleep – fatigue leads to misreading questions.
- Read each question twice. Some ask "Which two statements are correct?" – don't just pick one answer.
- Manage your time. You typically have 50-60 minutes for 40-50 questions. Skip difficult ones and return later.
- Look for keywords like "not", "except", or "only". One word changes the entire meaning.
- Trust your first instinct unless you find clear evidence you misread.
Remember: The CCNA v7 curriculum emphasizes practical troubleshooting. If you can explain why an OSPF adjacency fails or why a NAT translation isn't working, you're ready. Use our answers to verify your thinking, then reinforce with simulation tools. Good luck on your exam – and on your journey to networking expertise.