Unauthorized users have used Telnet to gain access to a company router. The network administrator wants to configure and apply an access list to allow Telnet access to the router, but only from the network administrator’s computer. Which group of commands would be the best choice to allow only the IP address to have Telnet access to the router?

A.    access-list 101 permit tcp any host eq telnet
interface s0/0
ip access-group 101 in
B.    access-list 3 permit host
line vty 0 4
access-class 3 in
C.    access-list 101 permit tcp any host eq telnet
access-list 101 permit ip any any
interface s0/0
ip access-group 101 in
D.    access-list 3 permit host
line vty 0 4
ip access-group 3 in

Answer: B

Refer to the exhibit. What command sequence will enable PAT from the inside to outside network?

A.    (config) ip nat pool isp-net netmask overload
B.    (config-if) ip nat outside overload
C.    (config) ip nat inside source list 1 interface ethernet1 overload
D.    (config-if) ip nat inside overload

Answer: C

Which two statements about static NAT translations are true? (Choose two.)

A.    They allow connections to be initiated from the outside.
B.    They require no inside or outside interface markings because addresses are statically defined.
C.    They are always present in the NAT table.
D.    They can be configured with access lists, to allow two or more connections to be initiated from the

Answer: AC

A network administrator wants to ensure that only the server can connect to port Fa0/1 on a Catalyst switch. The server is plugged into the switch Fa0/1 port and the network administrator is about to bring the server online. What can the administrator do to ensure that only the MAC address of the server is allowed by switch port Fa0/1? (Choose two.)

A.    Configure port Fa0/1 to accept connections only from the static IP address of the server.
B.    Employ a proprietary connector type on Fa0/1 that is incompatible with other host connectors.
C.    Configure the MAC address of the server as a static entry associated with port Fa0/1.
D.    Bind the IP address of the server to its MAC address on the switch to prevent other hosts from spoofing
the server IP address.
E.    Configure port security on Fa0/1 to reject traffic with a source MAC address other than that of the server.
F.    Configure an access list on the switch to deny server traffic from entering any port other than Fa0/1.

Answer: CE

The company internetwork is subnetted using 29 bits. Which wildcard mask should be used to configure an extended access list to permit or deny access to an entire subnetwork?


Answer: E

A router has been configured to provide the nine users on the branch office LAN with Internet access, as shown in the diagram. It is found that some of the users on the LAN cannot reach the Internet. Based on the topology and router output shown, which command should be issued on the router to correct the problem?

A.    Branch(config-if)# no shutdown
B.    Branch(config-if)# duplex full
C.    Branch(config-if)# no keepalive
D.    Branch(config-if)# ip address
E.    Branch(config-if)# bandwidth 100
F.    Branch(config-if)# encapsulation 802.3

Answer: D

What are three valid reasons to assign ports to VLANs on a switch? (Choose three.)

A.    to make VTP easier to implement
B.    to isolate broadcast traffic
C.    to increase the size of the collision domain
D.    to allow more devices to connect to the network
E.    to logically group hosts according to function
F.    to increase network security

Answer: BEF

Which protocol provides a method of sharing VLAN configuration information between switches?

A.    VTP
B.    STP
C.    ISL
D.    802.1Q
E.    VLSM

Answer: A
Understanding VLAN Trunk Protocol (VTP)
VLAN Trunk Protocol (VTP) reduces administration in a switched network. When you configure a new VLAN on one VTP server, the VLAN is distributed through all switches in the domain. This reduces the need to configure the same VLAN everywhere. VTP is a Cisco-proprietary protocol that is available on most of the Cisco Catalyst series products.

Refer to the exhibit. To what does the 128 refer in the router output O 168.12.240/30 [110/128] via,00:35:36, Serial 0?

A.    OSPF cost
B.    OSPF priority
C.    OSPF hop count
D.    OSPF ID number
E.    OSPF administrative distance

Answer: A

Assuming the default switch configuration, which VLAN range can be added, modified, and removed on a Cisco switch?

A.    1 through 1001
B.    2 through 1001
C.    1 through 1002
D.    2 through 1005

Answer: B

The ROUTE company has a small network. The network consists of one switch and one router. The switch has been configured with two VLANs. The router has been configured as a router-on- a-stick to allow inter-VLAN routing. A trunk is configured to connect the switch to the router. What
is the minimum number of router subinterfaces that are required for all the VLANs to communicate?

A.    zero
B.    one
C.    two
D.    three

Answer: C

Identify the four valid IPv6 addresses. (Choose four.)

A.    ::
B.    ::192:168:0:1
C.    2000::
D.    2001:3452:4952:2837::
E.    2002:c0a8:101::42
F.    2003:dead:beef:4dad:23:46:bb:101

Answer: ABEF

A network administrator receives an error message while trying to configure the Ethernet interface of a router with IP address Which statement explains the reason for this issue?

A.    VLSM-capable routing protocols must be enabled first on the router.
B.    This address is a network address.
C.    This address is a broadcast address.
D.    The Ethernet interface is faulty.

Answer: B

You are working in a data center environment and are assigned the address range You are asked to develop an IP addressing plan to allow the maximum number of subnets with as many as 30 hosts each. Which IP address range meets these requirements?


Answer: D

Which IPv6 address is valid?

A.    2001:0db8:0000:130F:0000:0000:08GC:140B
B.    2001:0db8:0:130H::87C:140B
C.    2031::130F::9C0:876A:130B
D.    2031:0:130F::9C0:876A:130B

Answer: D

Which protocol should be used to establish a secure terminal connection to a remote network device?

A.    ARP
B.    SSH
C.    Telnet
D.    WEP
E.    SNMPv1
F.    SNMPv2

Answer: B

What three pieces of information can be used in an extended access list to filter traffic? (Choose three.)

A.    protocol
B.    VLAN number
C.    TCP or UDP port numbers
D.    source switch port number
E.    source IP address and destination IP address
F.    source MAC address and destination MAC address

Answer: ACE

Refer to the topology and partial router configurations shown in the exhibit. The network is fully operational and all routing tables are converged. Which route will appear in the output of the show ip route command issued on the Branch router?

A.    S* [1/0] via
B.    R [120/1] via, 00:00:22, Serial0/0
C.    R [120/0] via, 00:00:22, Serial0/0
D.    R [120/1] via, 00:00:22, Serial0/0
E.    C is directly connected, FastEthernet0/0

Answer: A

Which router command can be used to verify the type of cable connected to interface serial 0/0?

A.    show running-config
B.    show controllers serial 0/0
C.    show interfaces serial 0/0
D.    show ip interface serial 0/0

Answer: B

Which command is necessary to permit SSH or Telnet access to a Cisco switch that is otherwise configured for these vty line protocols?

A.    transport output all
B.    transport preferred all
C.    transport type all
D.    transport input all

Answer: D

