CCNA 200-301 Practice Questions & Answers
Q1. As a network administrator, you have a packet that needs to be routed to a specific
network. How does a router determine the appropriate interface to forward this packet?
Explana8on: Routers make packet forwarding decisions based on the packet's desKnaKon IP
address. The router checks its rouKng table to determine the appropriate interface (egress
interface) for forwarding packets to their desKnaKon network.
Q2. Imagine you are troubleshooKng a newly installed Ethernet switch. You noKce that frames
from a device are being flooded to all ports. What is the likely reason for this behavior?
Explana8on: When an Ethernet switch receives a frame with a desKnaKon MAC address it
hasn't learned yet, it floods the frame out all ports except the one it was received on. This
ensures the frame reaches its intended recipient. Once the switch learns the desKnaKon MAC
address from return traffic, it updates its MAC address table and no longer needs to flood such
frames.
Q3. What is the primary funcKon of an Intrusion PrevenKon System (IPS) sensor in network
security?
Q5. What is the key difference between client-server and peer-to-peer architectures?
Explana8on: The key difference is that in a client-server architecture, clients access resources
from a centralized server, whereas in a peer-to-peer architecture, clients themselves serve up
resources, such as shared printers or files.
Q6. You are designing a network using Cisco Catalyst Center. Which of the following tasks can
you perform with this tool?
Explana8on: Cisco Catalyst Center (formerly, Cisco DNA Center) provides a graphical interface to
design networks. It allows you to map out network topology, allocate IP addresses, add areas
Q7. You are se]ng up a virtual environment and need to choose a hypervisor. If you require
running the hypervisor directly on the server's hardware without a host operaKng system,
which type of hypervisor should you select?
Explana8on: A Type 1 hypervisor, also known as a NaKve or Bare Metal Hypervisor, runs directly
on the server's hardware. It does not require a host operaKng system, thus having direct access
to the machine's resources. An example is VMware ESXi, which is installed directly onto the
server hardware.
Q8. What is the purpose of the three-way handshake in the TCP protocol?
Explana8on: The three-way handshake in TCP is used to establish a connecKon between two
devices. This process involves three steps: a synchronizaKon message (SYN) from the iniKator, a
synchronizaKon and acknowledgement message (SYN-ACK) from the responder, and an
acknowledgement message (ACK) from the iniKator. This handshake ensures that both sides are
ready to communicate and establishes a reliable connecKon.
Q1. What is a primary advantage of using a three-@er architecture for interconnec@ng buildings
on a corporate campus?
A) It requires fewer physical connec@ons due to a full mesh design between buildings.
B) It enhances scalability by allowing easy addi@on of new buildings through a structured
hierarchy.
C) It reduces the need for high-end switches at the core layer by distribu@ng the load.
D) It simplifies network management by collapsing the core and distribu@on layers into a single
layer.
Explana5on: The three-@er architecture (access, distribu@on, and core layers) provides a
scalable way to interconnect buildings on a corporate or university campus. By structuring the
network into @ers, new buildings can be added by simply replica@ng the exis@ng structure and
connec@ng the building's distribu@on layer to the core layer. This structured approach avoids
the scalability issues of a full mesh architecture, where each building would need to connect to
every other building, significantly increasing the complexity and number of physical connec@ons
required.
Q2. What dis@nguishes Top-of-Rack (ToR) switches in a spine-leaf data center architecture?
Answer: C) They act as leaves, connec@ng both to servers within the rack and spine switches.
Explana5on: A point-to-point connec@on using the Point-to-Point Protocol (PPP) is the most
suitable choice for dedicated bandwidth and predictable latency between two sites. This is
because a point-to-point connec@on is exclusively reserved for use between these two sites,
ensuring that the bandwidth is not shared with others and that the latency remains consistent.
Unlike Frame Relay, ATM, or VPNs over the Internet, a point-to-point connec@on does not
involve traffic from other clients on the network, which could otherwise introduce variability in
bandwidth and latency.
Q4. You are seYng up a network for a small office with a mix of wired and wireless devices,
including laptops, smartphones, and a server. To ensure all devices can communicate internally
and access the Internet, which combina@on of network devices is most appropriate for your
SOHO environment?
A) A wireless router with built-in Ethernet ports, connected to an external cable modem
B) A cable modem and a standalone Ethernet switch without wireless capabili@es
C) Mul@ple wireless access points to form a mesh network without a router
D) A dedicated firewall device without integrated rou@ng or switching capabili@es
Answer: A) A wireless router with built-in Ethernet ports, connected to an external cable
modem
Explana5on: For a small office/home office (SOHO) environment that includes both wired and
wireless devices, a wireless router with built-in Ethernet ports connected to an external cable
modem (or other broadband technology) is the most suitable setup. This configura@on allows
wired devices to connect through Ethernet ports and wireless devices to connect via Wi-Fi,
ensuring all devices can communicate with each other and access the Internet. Unlike the other
op@ons, this setup provides a comprehensive solu@on for both internal networking and Internet
connec@vity, leveraging the versa@lity of a wireless router with Ethernet capabili@es.
A) Public Cloud
B) Private Cloud
C) Hybrid Cloud
D) Community Cloud
Explana5on: The Hybrid Cloud model is the op@mal choice for organiza@ons looking to blend
the scalability and elas@city of cloud services with the security and control of an on-premises
infrastructure. This model allows for cri@cal data and applica@ons to be managed on-premises
(private cloud) for security and compliance, while also leveraging the cloud (public cloud) for
scalable, on-demand resources. This approach provides a balanced solu@on that can adapt to
fluctua@ng demands and offers a phased migra@on pathway to the cloud.
Q1. You are configuring a home entertainment system and need to choose the appropriate
coaxial cable for connecCng to your television and also to your cable modem. Which of the
following cable types should you consider for opCmal performance given the electrical
characterisCcs menConed?
A) RG-58
B) RG-59
C) RG-6
D) RG-8/U
Answer: C) RG-6
Explana9on: RG-6 is recommended for home entertainment systems and for connecCons to
cable modems, as it has beier electrical characterisCcs than RG-59, which is an older standard.
RG-58 and RG-8/U are used for different applicaCons, such as networking in older 10BASE2 and
10BASE5 networks. Also, RG-58 and RG-8/U cables have a different impedance (i.e., 50 Ohms)
as compared to RG-59 and RG-6 cables (i.e., 75 Ohms).
Q2. You are installing a network in an office environment with a significant amount of
electromagneCc interference (EMI). Which type of twisted pair cabling should you choose to
ensure the best protecCon against EMI?
Explana9on: STP (Shielded Twisted Pair) is the correct choice for environments with significant
electromagneCc interference (EMI). STP cables have an addiConal layer of shielding, either foil
or braided metal, which provides superior protecCon against EMI compared to UTP (Unshielded
Twisted Pair) that relies solely on the twisCng of the wires. Plenum-rated cabling is concerned
with fire safety and the release of toxic fumes, not specifically with EMI protecCon.
A) Category 5
B) Category 6a
C) Category 3
D) Category 5e
Answer: D) Category 5e
Explana9on: Category 5e cabling is the appropriate choice for supporCng 1 gigabit per second
data transmission over distances up to 100 meters using the 1000BASE-T standard. While
Category 5 technically can support 1 gigabit per second, it's not recommended due to its
electrical characterisCcs. Category 3 is not suitable for 1 gigabit per second speeds, and while
Category 6a could also support 1 gigabit per second, however, it is more expensive that
Category 5e.
Q4. You are tasked with connecCng two PCs directly to facilitate a file transfer without using a
switch or router. What type of Ethernet cable should you use to ensure the PCs can
communicate effecCvely?
A) Crossover cable
B) Straight-through cable
C) Plenum-rated cable
D) Coaxial cable
Explana9on: A crossover cable is required when directly connecCng two devices with idenCcal
pinouts on their network interfaces, such as directly connecCng two PCs, to ensure proper
communicaCon. This cable type swaps transmit and receive leads, allowing the devices to
communicate effecCvely without needing an intermediary device like a switch.
A) Coaxial Fiber
B) Single Mode Fiber (SMF)
C) MulCmode Fiber (MMF)
D) Plenum-rated Fiber
Explana9on: Single Mode Fiber (SMF) is the ideal choice for long-distance installaCons because
it is designed to carry light directly down the fiber without mulCple modes of propagaCon. This
characterisCc minimizes modal dispersion, a common issue in MulCmode Fiber (MMF) where
different paths (modes) of light can lead to data corrupCon, especially over long distances. SMF
has a smaller core diameter, allowing only one path for the light, which prevents modal
dispersion and ensures data integrity.
Q6. In secng up a high-density fiber network panel, which connector would you choose to
maximize port density?
A) ST connector
B) LC connector
C) SC connector
D) MTRJ connector
Explana9on: The MTRJ connector is the best choice for maximizing port density in a high-
density fiber network panel due to its design, which incorporates two fibers (for transmicng
and receiving) within a single, very small connector. This allows for a higher density of cabling in
the same physical space compared to ST, LC, and SC connectors, which typically require a
separate connector for each fiber strand.
A) 100BASE-FX
B) 100BASE-SX
C) 1000BASE-SX
D) 10GBASE-LR
Answer: C) 1000BASE-SX
Explana9on: The 1000BASE-SX standard supports a 1 gigabit per second speed over 200m
(using mulCmode fiber with a core diameter of 62.5μm). However, the 100BASE-FX and
100BASE-SX standards support a maximum speed of 100 megabits per second. The 10GBASE-LR
standard supports a speed of 10 gigabits per second, but it uses single mode fiber, which is
more expensive than mulCmode fiber.
Q8. A network designer is planning to deploy IP cameras and wireless access points in a new
office building. To simplify the installaCon and reduce the need for addiConal power outlets,
which technology should be uClized to power these devices over the Ethernet infrastructure?
Explana9on: Power over Ethernet (PoE) is the correct technology to use for powering devices
like IP cameras and wireless access points over the Ethernet cabling. This technology allows
electrical power, along with data, to be transmiied over Ethernet cables, eliminaCng the need
for separate power supplies or electrical outlets close to the devices.
A) 202
B) 205
C) 210
D) 212
Answer: A) 202
A) 10011010
B) 10111100
C) 10011100
D) 11001100
Answer: C) 10011100
Explana3on: We begin by creaOng an eight-column table with column headings of: 128, 64, 32,
16, 8, 4, 2, and 1. Then, we ask if 156 greater than or equal to 128. Since the answer is, “yes,”
we place a “1” in the 128 column and find the remainder (i.e., 156 – 128 = 28). Next, we ask if
28 is greater than or equal to 64. Since the answer is “no,” we place a “0” in the 64 column.
Similarly, we ask if 28 is greater than or equal to “32,” and again the answer is no, so we place a
“0” in the 32 column. We then ask if 28 is greater than or equal to 16, and the answer is “yes.”
So, we place a 1 in the 16 column and find the remainder (i.e., 28 – 16 = 12). Then, we ask if 12
is greater than or equal to 8. Again, the answer is “yes.” That means we place a “1” in the 8
column and find the remainder (i.e., 12 – 8 = 4). Then, we ask if 4 is greater than or equal to 4.
Since the answer is “yes,” we place a “1” in the 4 column. InteresOngly, the remainder is now 0
(i.e., 4 – 4 = 0), meaning we’ll place a 0 in both the 2 column and 1 column. Pu_ng these values
together gives us a binary value of 10011100.
Q3. In an 8-bit binary number, which bit represents the highest value?
Explana3on: In binary, each bit represents a power of 2, with the leNmost bit in an 8-bit binary
number represenOng 2^7 or 128, which is the highest value.
Q4. What is the binary representaOon of the decimal number 255 in an 8-bit format?
A) 11111110
B) 11111111
C) 10101010
D) 11001100
Answer: B) 11111111
Explana3on: The number 255 in binary is the highest number that can be represented in 8 bits,
with all bits set to a 1 (i.e., 128 + 64 + 32 + 16 + 8 + 4 + 2 + 1 = 255).
Q1. You are configuring a network device and need to assign an IPv4 address. To ensure proper
address assignment, you must understand the structure of IPv4 addresses. Which of the
following best describes the total number of bits in an IPv4 address and how they are
commonly represented?
Explana4on: An IPv4 address is made up of 32 bits. These bits are commonly represented in a
doNed decimal format, where the 32 bits are divided into four 8-bit secWons. Each secWon is
converted to its decimal equivalent and separated by dots. This representaWon makes IPv4
addresses easier to read and understand compared to binary or other formats.
Q2. As a network engineer, you're tasked with designing a network for a small company. You
need to choose an appropriate IP address range that ensures devices within the network can
communicate internally but are not directly routable on the public Internet. Which of the
following IP address ranges would you select?
A) [Link] - [Link]
B) [Link] - [Link]
C) [Link] - [Link]
D) [Link] - [Link]
Explana4on: The [Link] - [Link] address range is designated for private networks,
allowing devices within the same network to communicate with each other without being
routable on the public Internet. The other opWons are not suitable: A and C are ranges reserved
for documentaWon and example purposes, and D is a publicly routable address range.
A) StaWc NAT
B) Dynamic NAT
C) Port Address TranslaWon (PAT)
D) Reverse NAT
Explana4on: Port Address TranslaWon (PAT) allows mulWple devices on a local network to be
mapped to a single public IP address but with different port numbers, which are used to
disWnguish between various communicaWon sessions. This is especially useful for home
networks or small offices where there is only one publicly routable IP address available, while
mulWple devices need to simultaneously access the Internet.
Q4. You're tasked with se]ng up a company-wide video broadcast of the CEO's announcement.
To minimize network load and ensure only interested parWes receive the stream, which IP
packet flow method should you employ?
A) MulWcast, sending a single stream to a group of PCs, which belong to interested users
B) Unicast, sending a separate stream to each interested user's PC
C) Broadcast, sending a single stream to all devices in the subnet
D) Anycast, sending from mulWple servers, in a round-robin fashion
Answer: A) MulWcast, sending a single stream to a group of PCs, which belong to interested
users
Explana4on: MulWcast is the opWmal soluWon for delivering video streams to a selecWve
audience without overloading the network. By using a mulWcast group idenWfied by a Class D IP
address, a video server can send a single stream that a network’s infrastructure replicates only
to the devices that have joined a specific mulWcast group. This method prevents unnecessary
load on both the video server and the network links, and it does not disturb devices not
interested in the stream, making it the most efficient choice.
Q1. In a small office, you are tasked with manually configuring the IPv4 address parameters of a
new server to ensure it can communicate within the local network and access the Internet.
Which of the following parameters would you NOT be manually configuring as part of your IPv4
configuraIon?
A) IPv4 address
B) subnet mask
C) default gateway
D) MAC address
Explana3on: For manual IPv4 address configuraIon, you must assign the IPv4 address, subnet
mask, and default gateway. An IPv4 address uniquely idenIfies the device on the network, a
subnet mask determines the network and host porIons of the address, and a default gateway is
the router on the local network that routes traffic to other networks, including the Internet. A
MAC address is a hardware idenIfier for a Network Interface Card (NIC) and is assigned by the
manufacturer. Therefore, a MAC address is not manually configured as part of a device’s IPv4
se]ngs.
Explana3on: The correct sequence of messages exchanged between a PC and a DHCP server
during the IP address assignment process is: Discover, Offer, Request, Acknowledgement. This
sequence is commonly referred to by the acronym DORA. The process starts with the client
broadcasIng a Discover message to locate available DHCP servers, followed by the server
responding with an Offer message. The client then sends a Request message to accept the offer,
and finally, the server sends an Acknowledgement message to confirm the assignment.
A) TXT
B) CNAME
C) MX
D) AAAA
Answer: B) CNAME
Explana3on: An A record maps a domain name to an IPv4 address, ensuring that the domain is
reachable on the Internet. CNAME records allow the domain to be aliased to another domain
(e.g., redirecIng [Link] to [Link]). TXT records are typically used for verificaIon
purposes, such as domain ownership or email sender policies. MX records are used for rouIng
email. Finally, AAAA records map a domain name to an IPv6 address.
Q1. You are a network administrator tasked with configuring a link between two sites,
connected by routers R1 and R2, within a Class C network of [Link] /24. Considering the
need to opImize IP address usage, which of the following subnet masks would allow you to
allocate IP addresses efficiently for this link, which requires only two IP addresses?
A) [Link]
B) [Link]
C) [Link]
D) [Link]
Answer: B) [Link]
Explana4on: The [Link] subnet mask allows for four IP addresses in the subnet, two
of which can be assigned to hosts (R1 and R2), plus one address for the network address and
one address for the broadcast address. This minimizes wasIng IP addresses, as a Class C
network with a default subnet mask ([Link]) would provide 254 usable IP addresses, far
more than necessary for a link requiring only two.
Q2. As a network engineer, you are planning to segment a Class C network into subnets to
accommodate 5 separate departments within your company. Each department requires its own
subnet. According to the subneWng formula: ”Number of Subnets = 2s, where s is the number
of borrowed bits,” how many bits must you borrow from the host porIon of the default subnet
mask to accommodate 5 subnets, without borrowing more host bits than necessary?
A) 2 bits
B) 3 bits
C) 4 bits
D) 5 bits
Answer: B) 3 bits
Explana4on: Using the formula: “Number of Subnets = 2s, where s is the number of borrowed
bits,” borrowing 3 bits results in 8 possible subnets, because 23 = 8. This saIsfies the
requirement of accommodaIng 5 separate departments, making it the most efficient choice.
A) 30
B) 62
C) 126
D) 254
Answer: A) 30
Explana4on: The subnet mask [Link] is a 27-bit subnet mask (i.e., a /27 mask), and
an IPv4 address has 32 bits. That leaves 5 bits for host addresses (since 32 total bits - 27
network = 5 host bits). Using the formula: “Number of Hosts = 2h – 2, where h represents the
number of host bits,” we calculate 25 – 2 = 30 usable host addresses. The subtracIon of 2
accounts for the network address and the directed broadcast address, which cannot be assigned
to hosts.
Q4. You are configuring a network that uIlizes the [Link] /24 address space. If you divide
this network into subnets with a subnet mask of [Link], what would be the first
usable IP address in the second subnet?
A) [Link]
B) [Link]
C) [Link]
D) [Link]
Answer: A) [Link]
Explana4on: With a subnet mask of [Link] (/29), each subnet has a 'block size' of 8
(i.e., The “interesIng octet” is the 4th octet, and the value in the 4th octet is 248. Therefore, the
block size is 256 – 248 = 8). The first subnet starts at [Link], making its range
[Link]-[Link] (where [Link] is the network address and [Link] is the
broadcast address). The second subnet starts at [Link] (the network address), which is
determined by adding 8 (i.e., the block size) to the current value (i.e., 0) in the interesIng octet
(i.e., the 4th octet). That makes the first usable IP address in the second subnet [Link],
which is determined by adding 1 to the network address of [Link].
A) [Link] /26
B) [Link] /26
C) [Link] /26
D) [Link] /26
Q1. You are a network engineer tasked with calcula>ng hexadecimal values for a new IPv6
deployment. Given the decimal number 157, what is its hexadecimal equivalent?
A) 0xC9
B) 0x9D
C) 0xCA
D) 0xAD
Answer: B) 0x9D
Explana4on: To convert a decimal number to its hexadecimal equivalent, you first convert it to
binary and then divide the binary number into two nibbles (i.e., groups of four bits). The binary
representa>on of 157 is 10011101. Breaking this into nibbles gives us 1001 (which is 9 in
decimal and 9 in hexadecimal) and 1101 (which is 13 in decimal and D in hexadecimal).
Therefore, the hexadecimal equivalent of 157 is 0x9D.
Q2. As a network architect, you're explaining the structure of IPv6 addresses to a group of new
engineers. How would you describe the total number of bits an IPv6 address comprises and its
representa>on in hexadecimal digits?
Explana4on: A hexadecimal digit has one of 16 possible values and can therefore be
represented as 4 binary bits. An IPv6 address is made up of 128 bits represented as 32
hexadecimal numbers (i.e., 32 hex digits * 4 bits/digit = 128 bits). In contrast, an IPv4 address is
made up of only 32 bits. An IPv6 address is commonly represented as 32 hexadecimal digits to
simplify nota>on, divided into eight groups of four hexadecimal digits (i.e., quartets), with each
group separated by colons.
Explana4on: According to IPv6 address shortening rules, when you encounter consecu>ve
quartets containing only zeros, you can replace them with a double colon. This method
significantly reduces the length of the address but can only be applied once in an address to
avoid ambiguity.
Q4. In the context of IPv6 traffic types, which of the following best describes the Anycast
communica>on model?
A) one-to-nearest
B) one-to-one
C) one-to-many
D) one-to-all
Answer: A) one-to-nearest
Explana4on: Anycast is a unique IPv6 traffic flow where a single address is assigned to mul>ple
devices, typically servers, distributed across different geographical loca>ons. When a client
sends a request to an Anycast address, the network directs the request to the nearest server,
op>mizing for lower latency and becer bandwidth u>liza>on. This one-to-nearest
communica>on flow is fundamentally different from Unicast, Mul>cast, and the nonexistent
Broadcast in IPv6.
Ques%ons
Q1. You are se9ng up an IPv6 network for your organizaDon and need to assign global unicast
addresses to your servers. Which of the following addresses is a valid IPv6 global unicast
address that could be assigned to a server?
A) FE80::1
B) FF02::1
C) 2001:DB8::1
D) ::1
Q2. Which of the following IPv6 addresses is used to represent all nodes in a link local scope for
mulDcast traffic?
A) FF02::1
B) FE80::1
C) 2001::1
D) FF01::1
Q3. While configuring an IPv6 network, you need to ensure local communicaDon on a single
network segment without involving routable addresses. Which type of IPv6 address would you
assign to the interfaces of devices on the same network segment to achieve this?
Q4. You are designing a private network for your organizaDon and decide to use IPv6 unique
local addresses. What prefix would you typically see at the beginning of these addresses?
A) FE80::/10
B) FF00::/8
C) 2001::/3
D) FC00::/7
A) ::1
B) FE80::1
C) 2001:DB8::1
D) FF02::1
Q6. When iniDalizing communicaDon without a specific IPv6 address, a device might use a
certain type of address to indicate that it does not yet have a defined IPv6 address. Which IPv6
address serves this purpose?
A) ::/128
B) FE80::/10
C) 2001::/3
D) FF02::1
Q7. When configuring an IPv6 network, how does the IPv6 solicited-node mulDcast address help
act as a replacement for IPv4’s use of ARP?
Q8. When manually configuring an IPv6 address for a device in a network, which of the
following steps is NOT part of the configuraDon process?
Q9. You are configuring an IPv6 network and need to generate interface IDs for devices using
their MAC addresses. Which of the following correctly describes the iniDal step in creaDng a 64-
bit interface ID using the EUI-64 format from a 48-bit MAC address?
A) Add the hexadecimal digits "FFFF" in the middle of the MAC address.
B) Divide the MAC address into two parts and insert "FFFE" in the middle.
C) Replace the first 24 bits of the MAC address with "FFFE".
D) Convert the enDre MAC address to binary and then add 16 bits of zeros.
Q1. You are se9ng up an IPv6 network for your organizaDon and need to assign global unicast
addresses to your servers. Which of the following addresses is a valid IPv6 global unicast
address that could be assigned to a server?
A) FE80::1
B) FF02::1
C) 2001:DB8::1
D) ::1
Answer: C) 2001:DB8::1
Explana:on: IPv6 global unicast addresses are publicly routable addresses that start with the
first three bits set to 001, which typically results in the first hexadecimal digit of the address
being 2 or 3. Therefore, 2001:DB8::1 is a valid global unicast address, as it starts with "2001",
indicaDng it falls within the 2000::/3 range. The other opDons are not IPv6 global unicast
addresses. Specifically, FE80::/10 is for link local addresses, and FF00::/8 is for mulDcast
addresses, and ::1 is the loopback address.
Q2. Which of the following IPv6 addresses is used to represent all nodes in a link local scope for
mulDcast traffic?
A) FF02::1
B) FE80::1
C) 2001::1
D) FF01::1
Answer: A) FF02::1
Explana:on: The address FF02::1 is a mulDcast address used to represent all nodes in a link
local scope, funcDoning similarly to a broadcast in IPv4. A typical use of this mulDcast address is
a router sending a Router AdverDsement (RA) to all nodes on a segment connected to a router
interface.
Explana:on: IPv6 link local addresses are specifically designed for local network segment
communicaDon and are not routable beyond their segment. A common use of these addresses
is a router sending out route adverDsements sourced from an interface’s link local address.
Global unicast addresses are routable and designed for Internet-wide communicaDon, making
them unsuitable for this scenario. Unique local addresses serve a different purpose, providing
local communicaDon within a broader scope but sDll potenDally routable within a private
network. MulDcast addresses are used for one-to-many communicaDon, not for the specified
requirement.
Q4. You are designing a private network for your organizaDon and decide to use IPv6 unique
local addresses. What prefix would you typically see at the beginning of these addresses?
A) FE80::/10
B) FF00::/8
C) 2001::/3
D) FC00::/7
Answer: D) FC00::/7
Explana:on: IPv6 unique local addresses are defined to start with the prefix FC00::/7 (although
the second hexadecimal digit is typically a D, due to the L-bit being set to 1), which allows for
local communicaDon within an organizaDon but is not routable on the public Internet. This
prefix ensures that the addresses are used within private networks, similar to the use of RFC
1918 addresses in IPv4.
A) ::1
B) FE80::1
C) 2001:DB8::1
D) FF02::1
Answer: A) ::1
Explana:on: The IPv6 address ::1 is the IPv6 loopback address, equivalent to [Link] in IPv4.
Pinging ::1 verifies that the IPv6 stack on the machine is operaDonal, ensuring that the network
interface card (NIC) can send and receive packets to itself without involving external network
interfaces.
Q6. When iniDalizing communicaDon without a specific IPv6 address, a device might use a
certain type of address to indicate that it does not yet have a defined IPv6 address. Which IPv6
address serves this purpose?
A) ::/128
B) FE80::/10
C) 2001::/3
D) FF02::1
Answer: A) ::/128
Explana:on: The IPv6 unspecified address, represented as ::/128, or simply ::, consists of all 128
bits set to zero and is used by devices indicaDng that they do not yet have a defined IPv6
address. This address is employed during iniDal communicaDon processes, such as when a
device is looking to obtain an IPv6 address through mechanisms like DHCPv6 or during the iniDal
stages of neighbor discovery.
Answer: C) By sending a mulDcast message to a group, expecDng a response from the device
with a matching IPv6 address
Explana:on: The IPv6 solicited-node mulDcast address replaces the ARP funcDonality of IPv4 by
sending a mulDcast message to a group of devices where only the device with the matching IPv6
address will respond. This method is efficient and limits the scope of address resoluDon traffic
to interested parDes only, unlike the IPv4 ARP broadcast method, which reaches all devices on a
local network segment.
Q8. When manually configuring an IPv6 address for a device in a network, which of the
following steps is NOT part of the configuraDon process?
Explana:on: A MAC address is a hardware idenDfier for network interfaces and is not manually
assigned as part of an IPv6 configuraDon. The steps involved typically include entering the IPv6
address, specifying the subnet prefix (ocen /64 for individual subnets), and se9ng a default
gateway for off-network communicaDon. The MAC address is used in the process of generaDng
a unique interface idenDfier for link local addresses and some types of global addresses but is
not directly assigned by network administrators during manual IPv6 address configuraDon.
A) Add the hexadecimal digits "FFFF" in the middle of the MAC address.
B) Divide the MAC address into two parts and insert "FFFE" in the middle.
C) Replace the first 24 bits of the MAC address with "FFFE".
D) Convert the enDre MAC address to binary and then add 16 bits of zeros.
Answer: B) Divide the MAC address into two parts and insert "FFFE" in the middle.
Explana:on: The EUI-64 format for generaDng a 64-bit interface ID from a 48-bit MAC address
involves dividing the MAC address into two equal parts and inserDng the hexadecimal digits
"FFFE" in the middle. This step extends the 48-bit MAC address to 64 bits, which is necessary for
creaDng the interface ID part of an IPv6 address. The addiDon of "FFFE" ensures that the
generated address remains unique and follows the structure required for IPv6 interface
idenDficaDon.
Q10. In an IPv6 network, which of the following describes the Stateless Address
AutoconfiguraDon (SLAAC) process?
Answer: B) A device uses a combinaDon of a router adverDsement and its MAC address to
generate its own IPv6 address.
Explana:on: SLAAC allows a device to automaDcally generate its own IPv6 address without
needing a DHCPv6 server. It uses the EUI-64 process to create the host porDon of the address
based on its MAC address and obtains the network prefix from a router adverDsement (RA),
enabling a device to autonomously configure its own IPv6 address.
Q1: You are a network engineer tasked with configuring a network to efficiently handle both
Layer 2 and Layer 3 forwarding decisions. Which type of switch would you choose to meet this
requirement?
Explana1on: A mulKlayer switch is designed to make forwarding decisions based on both Layer
2 (MAC address) and Layer 3 (IP address) informaKon, as opposed to a tradiKonal Layer 2 switch
that bases decisions solely on MAC addresses. MulKlayer switches can route packets between
VLANs, apply security rules, and perform quality of service operaKons, making them ideal for
handling complex networking requirements that involve both Layer 2 and Layer 3 forwarding.
Also, the term “mulKlayer” means that upper layer informaKon can also be considered when
making a forwarding decision (e.g., a configuraKon to block Telnet, using TCP port 23).
Q2: A network administrator is examining the MAC address table on a Cisco Catalyst switch.
They noKce several MAC addresses have the first six hexadecimal digits in common. What does
this indicate?
A) The devices with those MAC addresses belong to the same Layer 2 mulKcast group.
B) The devices with those MAC addresses have network interface cards manufactured by the
same manufacturer.
C) The vendor producing the network interfaces cards with those MAC addresses have
mistakenly duplicated bits that were supposed to be unique.
D) The switch is configured for IGMP Snooping on the ports associated with the MAC addresses
in quesKon.
Answer: B) The devices with those MAC addresses have network interface cards manufactured
by the same manufacturer.
Explana1on: A Media Access Control (MAC) address is a 48-bit address burned into a network
interface card by its manufacturer and is typically wri\en as a series of twelve hexadecimal
digits. A MAC address is divided into two parts: (1) The first 24 bits (i.e., the first 6 hexadecimal
digits) are called the OrganizaKonally Unique IdenKfier (OUI), which is assigned to a specific
manufacturer. (2) The last 24 bits are assigned by the manufacturer. Therefore, MAC addresses
having their first six hexadecimal digits in common were manufactured by the same
manufacturer, who has been assigned those six hexadecimal digits (i.e., 24 bits) as their OUI.
Q1: You are configuring a network and need to iden=fy adjacent Cisco devices, some of which
do not have IP addresses. Which protocol would you use to discover these Layer 2 adjacent
devices?
A) SNMP
B) CDP
C) LACP
D) OSPF
Answer: B) CDP
Explana3on: CDP (Cisco Discovery Protocol) is a Layer 2 protocol that allows Cisco devices to
discover informa=on about directly connected CDP-speaking devices without the need for IP
addressing. It enables network devices to share informa=on about themselves with other
directly connected devices on the network, facilita=ng the discovery of a network topology by
revealing details about adjacent CDP-speaking devices.
Q2: As a network administrator, you're tasked with enhancing the security of your network's
edge that connects to an Internet Service Provider (ISP). To prevent the ISP from gaining insights
regarding your edge router, what CDP command should you apply on the interface connected to
the ISP?
A) cdp enable
B) cdp run
C) no cdp run
D) no cdp enable
Explana3on: The `no cdp enable` command is used to selec=vely disable CDP on a specific
interface. This prevents the device on the other end of the link, such as an ISP, from receiving
CDP packets that contain informa=on about your network device, thus enhancing security by
limi=ng the amount of informa=on exposed.
A) LLDP
B) SNMP
C) CDP
D) BGP
Answer: A) LLDP
Explana3on: LLDP (Link Layer Discovery Protocol) is an IEEE standard (802.1AB) protocol
designed for discovering Layer 2 adjacent devices that are part of a network, irrespec=ve of
their vendor. Unlike CDP, which is proprietary to Cisco, LLDP offers a vendor-neutral solu=on,
allowing for interoperability across different network device manufacturers.
Q4: You're configuring a switch port and wish to stop sending LLDP packets to a directly
connected service provider in order to beWer protect your network details. Which command
allows you to achieve this without affec=ng your ability to receive LLDP packets from the service
provider?
A) no lldp run
B) lldp transmit
C) no lldp transmit
D) lldp receive
Explana3on: The `no lldp transmit` command disables the transmission of LLDP packets from a
switch port to other devices, such as a service provider, helping ensure that sensi=ve network
informa=on is not inadvertently shared. This command does not affect the switch port's ability
to receive LLDP packets, allowing it to s=ll learn details regarding a directly connected LLDP-
speaking device.
Q1. You are configuring a network for a company with several departments, and you need to
ensure that each department is on a separate broadcast domain to enhance security and
performance. Which of the following acEons best accomplishes this goal?
Explana5on: SegmenEng the network into different VLANs based on department ensures that
each department is on a separate broadcast domain. This setup enhances network security and
performance by isolaEng departmental traffic, reducing broadcast traffic, and limiEng the
visibility of devices across different departments.
Q2. You are tasked with seQng up VLANs for a company with two departments: Engineering
and Human Resources. AVer creaEng VLANs 10 and 20 for Engineering and HR respecEvely, you
need to assign interfaces to these VLANs. How would you most efficiently assign interfaces
GigabitEthernet0/1 and GigabitEthernet0/2 to the Engineering VLAN (VLAN 10)?
A) Use the `interface range gig 0/1-2` command followed by the `switchport access vlan 10`
command.
B) Individually configure each interface with `switchport access vlan 10` command.
C) Assign the interfaces to VLAN 10 using the `vlan database` command.
D) Apply the `switchport access vlan 10` command under the global configuraEon mode,
causing it to be inherited by interfaces without a VLAN assignment.
Answer: A) Use the `interface range gig 0/1-2` command followed by the `switchport access
vlan 10` command.
Explana5on: The `interface range` command allows you to configure mulEple interfaces at the
same Eme. By entering ` interface range gig 0/1-2` and then applying the `switchport access
vlan 10` command, both interfaces are assigned to the Engineering VLAN (VLAN 10). This
method is more efficient than individually configuring each interface, which is also a valid
method but not the best opEon given.
Answer: B) Subdivide the interface into two subinterfaces, each with its own VLAN idenEfier.
Q4. When configuring a Layer 3 switch to facilitate inter-VLAN rouEng without an external
router, what should be created for each VLAN to allow devices within those VLANs to
communicate with each other?
Explana5on: Switch Virtual Interfaces (SVIs) provide a means to route traffic between VLANs on
a Layer 3 switch without the need for an external router. By assigning an IP address to an SVI for
each VLAN, the switch can use these interfaces as the default gateways for devices in the
VLANs, allowing for inter-VLAN rouEng.
Answer: D) no switchport
Explana5on: The command `no switchport` is used to convert a Layer 2 switch port into a Layer
3 routed port. This command disables the switchport funcEonality, allowing the port to be
assigned an IP address and parEcipate in rouEng.
Q1. You are analyzing traffic flowing over an Ethernet trunk. For most of the frames, you see
four extra “tag” bytes that, among other funcJons, idenJfy the VLAN of the frame. However,
some frames do not have these tag bytes. What can you conclude about these untagged
frames?
Explana5on: An IEEE 802.1Q trunk can carry traffic for mulJple VLANs over a single link. Frames
for most VLANs are tagged with four addiJonal “tag” bytes. One of the fields in the tag bytes
idenJfies the VLAN of that frame. However, there is one excepJon. One VLAN, known as the
“NaJve VLAN,” is not tagged, meaning it does not have those four tag bytes added to its frames.
Therefore, it’s important that the ports at each end of a trunk be configured with an idenJcal
NaJve VLAN (which defaults to VLAN 1).
Q2. As a network administrator for the Sales division in your company, you have administraJve
privileges on switch SW1. This switch is connected via a single Ethernet link to switch SW2.
However, you do not have administraJve access to switch SW2, yet you have been assigned the
task of configuring an Ethernet trunk between those two switches. You happen to know the
default trunk mode for ports on switch SW2 is “dynamic auto.” Which of the following trunk
modes can you configure on the SW1 side of the link to form a trunk?
A) access
B) voice vlan
C) dynamic desirable
D) dynamic auto
Explana5on: The “dynamic desirable” mode acJvely adempts to negoJate a trunk link by
sending Dynamic Trunking Protocol (DTP) frames. When a port configured in “dynamic
desirable” mode connects to another switch port that is in “dynamic desirable,” “dynamic auto,”
or “trunk” mode, a trunk is formed. This mode is preferred when you want to ensure that a
trunk is established without manual configuraJon of a far-end switch.
Explana5on: The `switchport trunk allowed vlan 10,20,30` command is the correct syntax to
explicitly restrict the trunk link to carry only VLANs 10, 20, and 30. As another opJon, instead of
explicitly staJng which VLANs you wish to allow, you could tell the trunk to allow all VLANs,
except the ones you specify. For example, if you wished to permit all VLANs except 10, 20, and
30, you could use the command `switchport trunk allowed vlan except 10,20,30` in interface
configuraJon mode for your trunk port.
Q4. Under what circumstances might you opt for a single VLAN access port instead of a mulJ-
VLAN access port for your IP telephony deployment?
Answer: B) When using a third-party IP phone that does not support mulJ VLAN access ports
Explana5on: A single VLAN access port might be chosen over a mulJ-VLAN access port when
dealing with third-party IP phones that do not support the concept of mulJ-VLAN access ports.
In this case, the voice and data traffic share the same VLAN.
Q5. When configuring a mulJ-VLAN access port for a Cisco IP Phone, which command specifies
the VLAN for voice traffic?
Q1. You are configuring a network with mul>ple switches and need to ensure op>mal root
bridge selec>on for Spanning Tree Protocol opera>ons. Given the significance of the bridge ID in
this process, which component does NOT contribute to the bridge ID calcula>on?
Explana:on: The bridge ID, crucial for root bridge determina>on in STP, consists of a switch's
priority and its MAC address. The VLAN ID may influence the extended system ID in certain
spanning tree versions like PVST+, but the port priority does not directly contribute to the
bridge ID calcula>on.
Q2. Your network experienced a link failure between two switches. In the context of tradi>onal
Spanning Tree Protocol, how long does it take for a blocking port to transi>on to a Forwarding
state aUer the failure?
A) 50 seconds
B) 15 seconds
C) 20 seconds
D) 30 seconds
Answer: A) 50 seconds
Explana:on: In tradi>onal STP, a blocking port goes through 20 seconds of Blocking, 15 seconds
of Listening, and 15 seconds of Learning before it transi>ons to the Forwarding state, totaling 50
seconds. This process ensures a loop-free logical topology while adap>ng to topology changes.
Q3. You are configuring a network to op>mize traffic pa[erns for mul>ple VLANs using Cisco's
Per VLAN Spanning Tree Plus (PVST+). If VLAN 200 should have a different root bridge than
VLAN 100 to op>mize its traffic flow, how can you ensure this in a PVST+ environment?
Explana:on: PVST+ allows each VLAN to have its own spanning tree instance, meaning each
VLAN can have a different root bridge based on its traffic flow needs. By assigning different
bridge priori>es to VLANs on different switches, network administrators can influence which
switch becomes the root bridge for a par>cular VLAN, thereby op>mizing the traffic flow for
that VLAN.
Q4. You connect a printer to an access layer switch port in your network. To minimize
connec>vity delay, which STP feature should you enable on this port?
A) BPDU Guard
B) Root Guard
C) PortFast
D) UplinkFast
Answer: C) PortFast
Explana:on: PortFast is an STP feature designed to bypass the standard Listening and Learning
states for ports connected to end devices, like printers, enabling them to transi>on directly to
the Forwarding state and thus minimize connec>vity delays.
Q5. Imagine you are configuring a switch (SW1), which is ac>ng as a Root Bridge. You want to
ensure that an a[ached switch (SW2) does not assume the role of the Root Bridge, even if SW2
sends a superior BPDU to SW1. Which Spanning Tree Protocol (STP) enhancement would you
configure to meet this requirement?
A) BPDU Filter
B) Root Guard
C) Loop Guard
D) BPDU Guard
Explana:on: Root Guard is an STP enhancement that is configured on switch port, off of which
a superior BPDU should not be seen. This can help protect a network from an a[acker adding
their own switch and adver>sing a superior BPDU (i.e., a BPDU claiming the newly added switch
has the lowest Bridge ID (BID) in the network).
A) Root Guard
B) BPDU Filter
C) Loop Guard
D) BPDU Guard
Q7. As a network administrator, you are responsible for preven>ng Spanning Tree Protocol (STP)
informa>on from leaking between two dis>nct autonomous systems within your organiza>on.
To achieve this, you decide to implement an STP enhancement feature on a switch interface
connec>ng one autonomous system to the other autonomous system. Which feature should
you configure?
A) BPDU Guard
B) Root Guard
C) Loop Guard
D) BPDU Filter
Explana:on: BPDU Filter is the appropriate feature to use in this scenario. It prevents Bridge
Protocol Data Units (BPDUs) from being sent or received through a specified port. By filtering
out BPDUs on the interface connec>ng the switches of two different autonomous systems, you
can ensure that each system maintains its own Spanning Tree topology without interference or
integra>on with the other, thus preserving the autonomy and security of both network
segments.
A) BPDU Filter
B) Root Guard
C) Loop Guard
D) BPDU Guard
Explana:on: BPDU Guard is the correct feature to enable in this scenario. When BPDU Guard is
ac>ve on a PortFast-enabled port, it ensures that the port is moved into an Error-Disabled state
if any BPDU is received. This feature is crucial for preven>ng network loops or sub-op>mal
Spanning Tree topologies by immediately disabling the port upon detec>ng a BPDU, indica>ng
that a switch, rather than an end sta>on, has been connected to the port.
Q9. In a network with varying VLAN traffic pa[erns, you seek an STP op>miza>on strategy that
minimizes the number of spanning tree instances while ensuring op>mal paths for VLAN traffic.
Which STP variant meets these requirements?
A) PVST+
B) RSTP
C) MSTP
D) CST
Answer: C) MSTP
Explana:on: MSTP (Mul>ple Spanning Tree Protocol) allows for the crea>on of mul>ple
spanning tree instances that can be shared among VLANs, op>mizing path selec>on based on
traffic pa[erns while reducing the number of required instances.
A) Instantaneous recovery
B) Recovery within a few milliseconds to a maximum of about six seconds
C) Recovery within 30 seconds
D) Recovery within 50 seconds
Explana:on: Rapid Spanning Tree Protocol (RSTP) significantly reduces the default convergence
>me of tradi>onal STP from poten>ally 50 seconds to a range of a few milliseconds to a
maximum of about six seconds. This improvement is especially notable in the case of direct link
failures, where the convergence >me can be on the lower end of this range. The capability of
switches to quickly propagate Topology Change No>fica>ons (TCNs) contributes to this speed
increase, ensuring faster recovery and minimal network down>me.
Q11. You're in the process of configuring your network switches to use Rapid PVST. AUer
configuring the switches, you need to verify that a specific switch has successfully transi>oned
to Rapid PVST mode. Which command should you use to confirm the current Spanning Tree
Protocol mode on a Cisco switch?
Q1. Imagine you are configuring an EtherChannel between two switches to enhance bandwidth
and provide redundancy. What is an essenDal step to ensure the EtherChannel funcDons
correctly?
Answer: C) Configure all ports in the EtherChannel with the same speed and duplex seNngs.
Explana5on: For an EtherChannel to operate correctly, it is criDcal that all ports in the
EtherChannel bundle on both switches are configured with the same speed and duplex seNngs.
This ensures that the ports can communicate effecDvely and funcDon as a single, logical
connecDon. Mismatched seNngs could prevent the EtherChannel from forming or lead to
subopDmal performance.
Q2. When configuring an EtherChannel with PAgP, which mode combinaDon will successfully
establish an EtherChannel?
A) One side set to "auto" and the other side set to "desirable"
B) Both sides set to "auto"
C) One side set to "desirable" and the other to "on"
D) One side set to "auto" and the other side set to "on"
Answer: A) One side set to "auto" and the other side set to "desirable"
Explana5on: For an EtherChannel to form using PAgP, one side must be set to "desirable," which
acDvely sends PAgP frames to negoDate an EtherChannel, and the other side can be set to
either "auto" (which is willing to form an EtherChannel but will not iniDate it) or "desirable".
Answer: D) A network with mostly unicast traffic where source and desDnaDon pairs vary widely
Explana5on: The load balancing algorithm that considers both source and desDnaDon address
informaDon (either MAC address or IP address informaDon) is most effecDve in environments
where source-desDnaDon pairs vary widely. This method distributes traffic across the
EtherChannel links more evenly by adding an element of randomness and diversity to the path
selecDon process, opDmizing the use of available bandwidth.
Q4. As a network engineer, you're configuring a Layer 2 EtherChannel between switches SW1
and SW2. Which of the following commands correctly creates an EtherChannel using PAgP with
a mode that acDvely seeks to form an EtherChannel?
Explana5on: In PAgP (Port AggregaDon Protocol), which is Cisco proprietary, the "desirable"
mode acDvely sends PAgP frames to negoDate the formaDon of an EtherChannel. This mode
indicates that the port acDvely seeks to form an EtherChannel with the remote port if the
remote port is set to either "auto" or "desirable" mode. Therefore, "channel-group 1 mode
desirable" is the correct command for creaDng an EtherChannel that proacDvely aYempts to
form using PAgP.
A) Configuring the port channel with an IP address before assigning the physical interfaces to
the EtherChannel
B) Ensuring all ports in the EtherChannel are configured as access ports with the same VLAN ID
C) SeNng the EtherChannel mode to "desirable" to acDvely negoDate LACP packets
D) Assigning the port channel interface an IP address to enable Layer 3 rouDng capabiliDes
Answer: D) Assigning the port channel interface an IP address to enable Layer 3 rouDng
capabiliDes
Explana5on: For a Layer 3 EtherChannel, the crucial step is assigning the port channel interface
an IP address, which enables rouDng capabiliDes over the EtherChannel. This is because, in a
Layer 3 EtherChannel, the port channel interface acts as a routed interface instead of a
switchport, allowing it to facilitate inter-VLAN rouDng or rouDng between different IP networks.
The other opDons are not relevant to configuring a Layer 3 EtherChannel for rouDng purposes.
Q1. You are configuring a new network segment for your company, connecAng various devices
and servers. If a device in this new segment needs to communicate with a server located in a
different network segment, which piece of informaAon is criAcal for the device to send packets
to the server?
Explana4on: For a device to communicate with another device or server in a different network
segment, it needs to send the packets to its default gateway. The packets are then forwarded to
the desAnaAon by routers. The device uses ARP (Address ResoluAon Protocol) to determine the
MAC address of its default gateway, as this is the next hop for packets desAned for other
networks.
Q2. Your router has learned routes to a specific network from mulAple sources. Which criterion
will your router use to select the most authoritaAve route when mulAple routes to the same
desAnaAon exist?
Explana4on: The AdministraAve Distance (AD) is a value used by routers to choose the most
authoritaAve route when there are mulAple routes to the same desAnaAon. The lower the AD,
the more trustworthy the source of the route. Directly connected networks have an AD of 0,
making them the most reliable.
A) RIP – Link-State
B) EIGRP - Advanced Distance-Vector
C) OSPF – Distance-Vector
D) BGP - Interior Gateway Protocol
Q4. You are a network engineer analyzing the rouAng table of a Cisco router that parAcipates in
both OSPF and EIGRP rouAng protocols. You observe routes to the same desAnaAon network
adverAsed by both OSPF and EIGRP. Given the administraAve distance values commonly
associated with these protocols, under which condiAon would the router prefer the OSPF route
over the EIGRP route for forwarding packets?
A) When the OSPF route has a lower metric than the EIGRP route
B) When the EIGRP route's metric is arAficially inflated
C) When the OSPF route has a lower administraAve distance than the EIGRP route
D) When the EIGRP route has an administraAve distance adjustment to make it less preferred
than OSPF
Answer: D) When the EIGRP route has an administraAve distance adjustment to make it less
preferred than OSPF
Q1. You are a network administrator responsible for managing a remote sales office connected
to the headquarters (HQ) network. The remote office router (BR1) has a single connecLon to
the HQ router. Which of the following configuraLons would be most appropriate for enabling
Internet access from the remote office?
Explana4on: Since the remote office router (BR1) has a single connecLon to the HQ router and
there is no need for a complex rouLng protocol, configuring a staLc default route poinLng to
the HQ router is the most appropriate soluLon. This staLc default route will forward all Internet-
bound traffic from the remote office to the HQ router, which presumably has the necessary
rouLng informaLon to reach the Internet.
Q2. Imagine you're a network administrator in a small company that just expanded its network
with a new subnet of IP cameras. These cameras are on a separate subnet, [Link]/24,
and you need to ensure that traffic from the main office network, [Link]/24, can reach
this new subnet. You've decided to add a staLc route on the office's main router to handle this
traffic. Which of the following commands would correctly configure the staLc route if the next-
hop IP address is [Link]?
Explana4on: This command is correct because it configures a staLc route specifically for the
host with IP address [Link] (ServerA), direcLng traffic to the specified next-hop IP address
[Link] (RouterB). This is a staLc host route configuraLon, as indicated by the use of a 32-bit
subnet mask ([Link]), ensuring that only traffic to ServerA is affected.
Q4. You are a network administrator managing a network that uses OSPF for dynamic rouLng.
For redundancy, you've decided to configure a backup path through an alternate gateway
router, RouterB, with an IP address of [Link], in case the primary OSPF route to the
[Link]/24 network fails. The OSPF routes have an administraLve distance of 110. To configure
this backup route as a floaLng staLc route, which command could you issue on the network's
edge router?
Explana4on: This command is correct because it configures a staLc route to the [Link]/24
network through RouterB with an administraLve distance of 120. The administraLve distance is
higher than the OSPF routes' distance of 110, making this staLc route a floaLng staLc route. It
will only be used if the OSPF route becomes unavailable, thus providing the desired redundancy
without interfering with the primary OSPF-based rouLng during normal operaLons.
Q1. Which mul8cast address is used by OSPF routers to send hello messages and form neighbor
rela8onships?
A) [Link]
B) [Link]
C) FF02::A
D) FF02::9
Answer: B) [Link]
Explana7on: OSPF routers use the mul8cast address [Link] (IPv4) or FF02::5 (IPv6) to send
Hello messages to other OSPF-speaking routers on the same network segment. This allows
them to discover each other and form neighbor rela8onships.
Q2. In an OSPF network with mul8ple routers connected to the same Ethernet segment, what is
the primary reason for elec8ng a Designated Router (DR) and Backup Designated Router (BDR)?
Explana7on: The primary reason for elec8ng a DR and BDR in an OSPF network with mul8ple
routers on the same Ethernet segment is to reduce the number of adjacencies formed. In a full-
mesh topology, the number of adjacencies grows exponen8ally with the number of routers,
which can lead to scalability issues. By elec8ng a DR and BDR, other routers only need to form
adjacencies with these two routers, reducing the overall number of adjacencies, while s8ll
allowing for the efficient exchange of rou8ng informa8on.
Explana7on: If an interface is configured with an OSPF priority value of 0, it will not par8cipate
in the DR/BDR elec8on process, regardless of its Router ID. The priority value is a configurable
parameter that influences the elec8on of the DR and BDR. By sefng the priority to 0, you
prevent the router from becoming a DR or BDR on that specific interface. To resolve this issue
and allow the interface to par8cipate in the DR/BDR elec8on process based on its Router ID, you
could change the interface's OSPF priority to a non-zero value using the "ip ospf priority"
command in interface configura8on mode.
Q4. As an OSPF network grows, you no8ce that the number of entries in the Link-State Database
is becoming too large to manage effec8vely. Which of the following ac8ons can help mi8gate
this issue?
Explana7on: When an OSPF network grows large, the number of entries in the Link-State
Database (LSDB) can become difficult to manage. To mi8gate this issue, you can divide the
network into mul8ple OSPF areas. Each area maintains its own LSDB, containing detailed
topology informa8on for that specific area. Routers in one area do not have the full topology
informa8on of other areas, which helps to reduce the size of the LSDB and improve scalability.
This also helps administrators more easily interpret informa8on in the LSDB.
Explana7on: A Type 1 LSA, also known as a Router LSA, is generated by every router to
adver8se its directly connected networks within an area. For example, if router R1 had five
interfaces, each par8cipa8ng in the same OSPF rou8ng process, then R1 would adver8sed those
directly connected networks by sending five Type 1 LSAs (inside of Link State Update (LSU)
packets), one for each directly connected network.
Q6. You are configuring OSPFv2 on a router and need to ensure that interface GigabitEthernet
0/1, which connects to a network segment with end users and no OSPF routers, does not send
OSPF Hello messages. Which of the following router configura8on mode commands correctly
configures this requirement?
Explana7on: The command “passive-interface gig 0/1” is used within OSPF router configura8on
mode to specify that OSPF Hello messages should not be sent or received through the
GigabitEthernet 0/1 interface. This is suitable for interfaces that connect to networks where no
OSPF neighbors are expected, such as networks with end users only. This command prevents
OSPF neighbor rela8onships from forming on that interface while s8ll allowing the network
connected to that interface to be adver8sed via OSPF.
A) Intra-Area routes, indica8ng routes within the same area as the router
B) Inter-Area routes, indica8ng routes that come from a different area
C) Inaccessible routes, indica8ng routes that are not reachable
D) Interface-Aaached routes, indica8ng routes for directly connected networks
Answer: B) Inter-Area routes, indica8ng routes that come from a different area
Explana7on: The 'IA' code in an OSPF rou8ng table stands for Inter-Area, indica8ng routes
learned from an area other than the one in which a router resides. These Inter-Area routes were
adver8sed to this router by an Area Border Router (ABR) using Type 3 LSAs.
Q1. You are a network engineer configuring an HSRP setup with two routers, R1 and R2, where
R1 is the AcFve router and R2 is the Standby router. If R1 experiences an outage, how long will
R2 wait, by default, before assuming the AcFve role?
A) 3 seconds
B) 10 seconds
C) 1 second
D) 5 seconds
Answer: B) 10 seconds
Explana3on: In HSRP, a Standby router waits for a duraFon called the "Hold Time" before
assuming the AcFve role if the AcFve router fails. The default Hold Time is 10 seconds. This
interval allows the Standby router to ensure that the absence of communicaFon from the AcFve
router is due to a failure and not just lost messages due to network issues.
Q2. As a network administrator, you are tasked with choosing a First Hop Redundancy Protocol
(FHRP) that allows a router interface to share the same IP address as the Virtual Router’s IP
address. Which protocol would you use?
A) HSRP
B) GLBP
C) VRRP
D) OSPF
Answer: C) VRRP
Explana3on: VRRP, unlike HSRP and GLBP, supports configuring a router interface’s IP address to
be the same as the Virtual Router's IP address. This feature can prevent the Virtual Router from
using one of the available IP addresses in a subnet, although it might complicate
troubleshooFng.
Q3. You are seZng up a network using GLBP to opFmize both load balancing and redundancy.
Which of the following methods can GLBP use to distribute client traffic across mulFple routers?
A) Round-Robin DistribuFon
B) Weighted DistribuFon
C) Host-Dependent ConfiguraFon
D) All of the above
Explana3on: GLBP supports several load balancing methods, including Round-Robin, where
requests are distributed evenly across routers; Weighted DistribuFon, which allocates traffic
based on predefined weights; and Host-Dependent ConfiguraFon, which allows traffic from
specific hosts to consistently use the same router. This flexibility allows network administrators
to tailor traffic distribuFon based on network needs and device capabiliFes.
Q1. You are a network administrator for a small office. The office uses mulBple wireless access
points configured independently. Which of the following is a potenBal benefit or drawback
commonly associated this setup?
Explana6on: Configuring mulBple wireless access points independently can lead to an increased
risk of configuraBon errors due to the need to manually set each access point with the correct
SSID, channel, security se^ngs, etc. This approach does not scale well and increases
administraBve overhead, making it more error-prone compared to using a centralized Wireless
LAN Controller (WLC).
Q2. In which type of WLAN design do wireless clients communicate directly with each other
without the use of an Access Point (AP)?
A. Ad Hoc WLAN
B. Infrastructure WLAN
C. Mesh WLAN
D. Point-to-Point WLAN
Explana6on: An Ad Hoc WLAN design allows wireless clients to communicate directly with each
other without relying on any infrastructure such as APs or Ethernet switches. This setup is useful
for quick, temporary communicaBon needs.
Q3. In which access point mode does an AP solely perform background tasks (e.g., rogue AP
detecBon), without providing client connecBvity?
A. Local Mode
B. FlexConnect Mode
C. Monitor Mode
D. Bridge Mode
Q4. What term describes a unique MAC address on an access point that allows a wireless client
to idenBfy and communicate with it specifically?
A. BSSID
B. IBSS
C. SSID
D. ESSID
Answer: A. BSSID
Explana6on: A Basic Service Set IdenBfier (BSSID) is a MAC address on an access point, allowing
wireless clients to idenBfy and communicate with a specific access point within a network. Note
that some APs could have mulBple BSSIDs, where a different BSSID is associated with each SSID
configured on the AP.
Q5. Which of the following frequency bands is not commonly used in modern wireless
networks?
A. 2.4 GHz
B. 5 GHz
C. 6 GHz
D. 7 GHz
Answer: D. 7 GHz
Explana6on: The 2.4 GHz, 5 GHz, and 6 GHz bands are commonly used in modern wireless
networks. However, the 7 GHz band is not typically used for wireless networking.
Q6. Which of the following can cause interference in the 2.4 GHz wireless band?
Q1. Which Wi-Fi standard introduced the use of the 5 GHz frequency band and offered a
maximum theoreHcal bandwidth of 54 Mbps?
A. 802.11b
B. 802.11a
C. 802.11g
D. 802.11n
Answer: B. 802.11a
Explana5on: The 802.11a standard, introduced in 1999, was the first to use the 5 GHz
frequency band and offered a maximum theoreHcal bandwidth of 54 Mbps. This provided
higher data rates and less interference compared to the 2.4 GHz band used by earlier standards.
Q2. Which of the following describes the principle behind Orthogonal Frequency Division
MulHplexing (OFDM)?
Q3. Which technology allows an access point to communicate with mulHple clients
simultaneously by using mulHple spaHal streams?
A. Single-User MIMO
B. Frequency Hopping Spread Spectrum
C. MulH-User MIMO (MU-MIMO)
D. Direct Sequence Spread Spectrum
Q5. When configuring a new wireless LAN on a Cisco Wireless LAN Controller, what must be
done to ensure the wireless LAN’s SSID is visible to users?
Explana5on: To ensure a wireless LAN’s SSID is visible to users, SSID broadcasHng must be
enabled. This allows a wireless network name to be seen by devices searching for available
networks.
Q1. You are a network administrator tasked with configuring sta@c NAT on router R1 to allow
PC1 with an inside local address of [Link] to access the Internet using the inside global
address of [Link]. Which command correctly maps the inside local address to the inside
global address?
Explana3on: The command `ip nat inside source sta@c [Link] [Link]` is used to
configure sta@c NAT by mapping the inside local address ([Link]) to the inside global
address ([Link]). The keyword `sta@c` indicates this is a sta@c mapping.
Q2. You are configuring dynamic NAT on router R1. ARer defining the inside and outside
interfaces, what is the next step to allow inside local addresses to be translated to addresses in
a pool of inside global addresses?
Answer: B. Create an access control list (ACL) to match the inside local addresses
Explana3on: ARer defining which interfaces are considered to be “inside” and “outside” NAT
interfaces (which also enables NAT on those interfaces), the next step in configuring dynamic
NAT is to create an access control list (ACL) to match the inside local addresses that need to be
translated to inside global addresses. Note that in this context, the ACL is being used to match
traffic, rather than permit or deny traffic.
Q3. In a small office setup with a single public IP address, which NAT variant allows mul@ple
devices to share this single IP address using unique port numbers?
A. Sta@c NAT
B. Dynamic NAT
C. Network Address Port Transla@on (NAPT)
D. Port Address Transla@on (PAT)
Explana3on: Port Address Transla@on (PAT) allows mul@ple devices on a local network to be
mapped to a single public IP address but with a unique port number for each session. This is
also known as “NAT Overloading.”
Q1. During an audit, you discover that the digital cer=ficates used for secure communica=ons
are frequently being marked as expired even though they should s=ll be valid. What is the most
likely cause of this issue, and how can it be resolved?
Answer: B. Network devices are not synchronized with an NTP server. Ensure all devices are
configured to use an NTP server.
Explana2on: If network devices are not synchronized with an NTP server, the local =me on
devices might not match the actual =me, causing valid digital cer=ficates to be seen as expired.
Synchronizing all devices with an NTP server ensures consistent and accurate =me across the
network, helping prevent such issues.
Q2. ATer seRng up NTP on your network, you observe that synchroniza=on is not happening
immediately, and the Stratum values on your routers are higher than expected. What underlying
mechanism of NTP might be causing this delay, and how does it ensure accurate =me
synchroniza=on?
Answer: D. NTP uses a complex algorithm to gradually adjust the local clock to match the
reference clock, preven=ng sudden changes.
Explana2on: NTP uses a complex algorithm to gradually adjust a local clock to match a
reference clock. This process, known as “clock discipline,” prevents sudden changes to the
system clock, ensuring a smooth and accurate synchroniza=on. This gradual adjustment can
cause an ini=al delay before the clocks are fully synchronized and the stratum values reflect
accurate =me sources.
Q1. You are configuring a Cisco IOS router to act as a DHCP server. You want it to hand out IP
addresses in the range [Link] through [Link]. Which command do you use to
exclude the IP addresses outside this range?
Answer: C. “ip dhcp excluded-address [Link] [Link]” and “ip dhcp excluded-
address [Link] [Link]”
Explana2on: To exclude the IP addresses outside the desired range, you need to use the “ip
dhcp excluded-address” command twice. First, to exclude the addresses from [Link]
through [Link], and second, to exclude the addresses from [Link] through
[Link]. This ensures that only the addresses from the [Link] through
[Link] range are available for the DHCP pool.
Q2. You are a network administrator configuring Router R2 as a DHCP Relay Agent to forward
DHCP Discover messages from Router R1 to a DHCP server at IP address [Link]. Which
command would you use on Router R2 to correctly set up the DHCP relay agent on interface Gig
0/1?
A. ip helper-address [Link]
B. ip dhcp relay [Link]
C. ip relay address [Link]
D. ip dhcp forward [Link]
Explana2on: The “ip helper-address [Link]” command is used to configure a router interface
to forward DHCP Discover messages to a DHCP server with an IP address of [Link]. This
allows clients on a different subnet to receive IP address assignments from the DHCP server.
Q1. You are a network administrator tasked with accessing a Cisco router remotely for
configuraBon. Which of the following methods would provide an encrypted remote connecBon?
A. Telnet
B. HTTP
C. SSH
D. Console port with a USB cable
Answer: C. SSH
Explana7on: SSH (Secure Shell) provides a secure connecBon by encrypBng the traffic between
the client and the router, ensuring that sensiBve informaBon such as usernames and passwords
are protected from intercepBon. Telnet and HTTP do not provide encrypBon, making them
insecure opBons. The console port with a USB cable is used for direct, local access, not remote
access.
Q2. Which type of AI learning involves the system grouping data into categories without labeled
training data?
A. Supervised learning
B. Unsupervised learning
C. Semi-supervised learning
D. Reinforcement learning
Explana7on: Unsupervised learning involves the system analyzing unlabeled data to find natural
groupings or pa^erns. This method allows the AI to categorize the data without predefined
labels, making it useful for discovering underlying structures within the data.
Q3. What is the primary purpose of an SNMP agent's MIB (Management InformaBon Base)?
Q4. Which SNMP command is used to configure a read-only community string on a Cisco
router?
Explana7on: The “command snmp-server community [string] ro” is used to set up a read-only
community string on a Cisco router, allowing SNMP managers to read informaBon from the
device without making changes.
Answer: B. It helps with event correlaBon by collecBng log informaBon from mulBple devices in
one place.
Explana7on: A centralized syslog server collects log informaBon from mulBple devices, enabling
be^er event correlaBon. This helps network administrators idenBfy pa^erns and determine the
root causes of issues by analyzing logs from various sources at the same Bme.
Q6. Which command is used to generate an RSA key to support SSH on a Cisco router?
Explana7on: The command “crypto key generate rsa” is used to generate an RSA key to support
Secure Shell (SSH) on a Cisco router. This key is a requirement for establishing a secure SSH
connecBon.
Q7. Which Transport Layer protocol does TFTP use, and why is it less secure than FTP?
Explana7on: TFTP uses the UDP Transport Layer protocol and lacks authenBcaBon, making it
less secure than FTP. TFTP’s simplicity makes it faster but unsuitable for secure file transfers.
Q1. You are asked to configure a collec=on of QoS tools on a departmental network in your
company. These tools include: CB-WFQ, LLQ, WRED, and Class-Based Policing. These tools all fall
under which category of QoS tools?
A. FIFO
B. DiffServ
C. Best Effort
D. IntServ
Answer: B. DiffServ
Q2. In a network, which Layer 2 marking is used on a Dot1Q trunk to iden=fy the priority of
traffic, and how many different values can it represent?
A. CoS; 8 values
B. IP Precedence; 8 values
C. DSCP; 64 values
D. TOS; 64 values
Explana5on: Class of Service (CoS) is the Layer 2 marking used on a Dot1Q trunk. It uses three
bits, allowing for 8 different values (0-7), though typically only 0 – 5 are used for produc=on
traffic.
A. FIFO
B. CB-WFQ
C. LLQ
D. WFQ
Answer: C. LLQ
Explana5on: Low Latency Queuing (LLQ) should be configured to ensure that voice traffic is
priori=zed. LLQ adds a priority queue to Class-Based Weighted Fair Queuing (CB-WFQ)
configura=on, which can guarantee that high-priority traffic, like voice and/or video, is sent first.
Q4. You want to limit the bandwidth that a class of traffic uses on a WAN link. The link has a
rela=vely slow speed, and you want to delay excess traffic, rather than dropping it. Which traffic
condi=oner should you choose?
A. Policing
B. Weighted Random Early Detec=on
C. WFQ
D. Shaping
Answer: D. Shaping
Explana5on: Cisco routers support two types of traffic condi=oners: (1) Shaping and (2) Policing.
Shaping delays excess traffic rather than dropping it, and it is intended to be used on slower
speed interfaces. Policing, however, drops excess traffic rather than dropping it, and it is
intended to be used on higher speed interfaces.
A. Applying a Policy-Map
B. Crea=ng a Policy-Map
C. Matching traffic with a Class-Map
D. Verifying the configura=on
Explana5on: In the 3-step MQC configura=on process, the 1st step is to classify traffic using
Class-Maps. The 2nd step is to assign QoS policies (to the classes of traffic iden=fied in Step 1)
using Policy-Maps. The 3rd step is to apply the Policy-Maps, which are typically applied to an
interface, in either the inbound or outbound direc=on.
Q1. The CIA triad is a fundamental concept in informa@on security. Which of the following
describes the "Integrity" component of the CIA triad?
Explana:on: The "Integrity" component of the CIA triad focuses on preserving the accuracy and
consistency of data. It ensures that informa@on is not altered by unauthorized par@es and
remains trustworthy. This can be achieved through methods like hashing, which detects changes
in data.
Explana:on: A "zero-day aOack" occurs when aOackers exploit a vulnerability that has just been
discovered and for which no patch is yet available. This makes it par@cularly dangerous, because
defenses are not yet in place.
Answer: D. An email that asks you to update your bank details on a fake website
Explana:on: Phishing involves tricking individuals into disclosing sensi@ve informa@on such as
login creden@als or financial informa@on through decep@ve emails or websites. In this scenario,
the email asking for bank details is a classic example of phishing.
Explana:on: The primary goal of a Denial of Service (DoS) aOack is to make a service
unavailable to its intended users by overwhelming the target with excessive traffic, rendering it
unable to perform its regular func@ons.
Explana:on: An "evil twin" is a rogue access point set up by an aOacker to mimic a legi@mate
wireless network. Unsuspec@ng users connect to it, allowing the aOacker to intercept their data.
Q6. You need to ensure that passwords configured on a Cisco router are not stored in plain text.
Which command will you use to apply basic encryp@on to passwords?
Explana:on: Mul@-factor authen@ca@on (MFA) involves using more than one method of
verifica@on. Scanning a fingerprint and entering a password uses two different factors:
something the user is (fingerprint) and something the user knows (password).
Q9. Which of the following encryp@on methods uses the same key for both encryp@on and
decryp@on?
A. Asymmetric encryp@on
B. Public key encryp@on
C. Symmetric encryp@on
D. RSA encryp@on
Explana:on: Symmetric encryp@on uses the same key for both encryp@on and decryp@on,
making it faster but requiring a secure key exchange. Examples include DES, Triple DES, and AES.
A. Site-to-site VPN
B. Remote access VPN
C. SSH VPN
D. GRE VPN
Explana:on: A remote access VPN allows a traveling employee to securely connect back to their
corporate office network over the Internet, providing access to internal resources as if they
were physically present at their office.
Q11. Which of the following best describes a strong password according to current best
prac@ces?
Answer: D. A minimum of 12 characters, using a mix of upper and lowercase leOers, numbers,
and special characters
Explana:on: A strong password should have a minimum of 12 characters and include a mix of
upper and lowercase leOers, numbers, and special characters to provide greater security against
brute force and dic@onary aOacks.
Q12. Which wireless security protocol introduced the requirement that AES encryp@on be
supported?
A. WEP
B. WPA
C. WPA2
D. WPA3
Answer: C. WPA2
Q1. You are a network administrator configuring ACLs on your network. You need to ensure that
only Telnet traffic from a specific host can access a specific server while blocking all other traffic
from that host. Which type of ACL should you use?
A. standard ACL
B. extended ACL
C. class-based ACL
D. outbound ACL
Explana7on: An extended ACL allows you to specify both source and desZnaZon addresses as
well as a specific protocol and port number. In this case, you can permit Telnet traffic (TCP port
23) from a specific host to a specific server, which is not possible with a standard ACL that only
filters by source IP address.
Q2. You are configuring a numbered standard ACL to permit all IP traffic from the
[Link]/24 network. Which of the following access control entries would you use?
Explana7on: In a numbered standard ACL, the correct syntax to permit all IP traffic from a
network uses the network address followed by its wildcard mask. The wildcard mask for a /24
network is [Link]. Therefore, the correct ACE is “access-list 10 permit [Link]
[Link]”.
Q3. In configuring a numbered standard ACL, which of the following are the correct ranges for
the ACL number?
Q4. You are configuring a numbered extended ACL to deny Telnet (TCP port 23) traffic from the
[Link]/24 network to a server with an IP address of [Link]. Which of the following
access control entries would you use?
Explana7on: To deny Telnet traffic from the [Link]/24 network to a specific host, the
correct syntax specifies the protocol (TCP), the source network with its wildcard mask, the
desZnaZon host, and the TCP port number of 23. Therefore, the correct ACE is “access-list 100
deny tcp [Link] [Link] host [Link] eq 23”.
Q5. What is one major advantage of using named ACLs over numbered ACLs?
Answer: C. They are easier to understand and manage, because they can have descripZve
names.
Explana7on: Named ACLs can have descripZve names, which makes them easier to understand
and manage as compared to numbered ACLs. This helps administrators quickly idenZfy the
purpose of an ACL in a configuraZon.
Explana7on: To deny HTTP traffic from a specific network to any desZnaZon using a named
extended ACL, the correct syntax for an ACE specifies the protocol (TCP), the source network
with its wildcard mask, the desZnaZon (any), and the desZnaZon port number (80). Therefore,
the correct ACE is “deny tcp [Link] [Link] any eq 80”.
Q7. When troubleshooZng an ACL that is blocking more traffic than intended, what is a
common cause?
Answer: A. The implicit “deny any” rule at the end of the ACL
Explana7on: The implicit “deny any” rule at the end of an ACL blocks all traffic that is not
explicitly permi[ed by the preceding rules. If an ACL is not correctly configured to permit
necessary traffic before this implicit deny rule, it can block more traffic than intended.
Q1. Which DHCP message type involves the client sending a broadcast message to locate any
available DHCP servers?
A. Discover
B. Explore
C. Request
D. Query
Answer: A. Discover
Explana6on: A DHCP client uses the DORA process to obtain IP address informaTon from a
DHCP server. The DORA process involves four message types: Discover, Offer, Request, and
Acknowledgement. The Discover message type is a broadcast message sent out by a DHCP
client in an aQempt to find available DHCP servers.
Q2. You are configuring DHCP Snooping on a Cisco switch. Which command would you use to
trust a specific port connected to a corporate DHCP server?
Explana6on: The command `ip dhcp snooping trust` is used to designate a specific port as
trusted, allowing DHCP Offer messages to be received on that port.
Q3. What type of aQack does Dynamic ARP InspecTon (DAI) help protect against?
A. Zero-Day
B. ARP Poisoning
C. Social Engineering
D. SQL InjecTon
Explana6on: Dynamic ARP InspecTon (DAI) protects against ARP Poisoning aQacks, where an
aQacker sends unsolicited ARP replies in an aQempt to associate their MAC address with the IP
address of another device.
Explana6on: The command `ip arp inspecTon trust` is used to configure a port to trust ARP
messages, typically used on ports connected to switches, routers, or servers.
Q5. What is one method an aQacker might use to overflow a switch's MAC address table?
Explana6on: The `macof` (MAC Overflow) applicaTon can be used by an aQacker to send a large
number of frames, each with a different source MAC address, which results in an overflow of a
switch's MAC address table.
Q6. When configuring sTcky learning for port security, what must you do to ensure learned
MAC addresses are retained a`er a switch reboot?
Explana6on: To retain learned MAC addresses a`er a switch reboot, you must save the switch’s
running-configuraTon to its startup-configuraTon using the `copy running-config startup-config`
command.
Q1. You are explaining the concept of SDN to a team of junior network engineers. Which of the
following best describes the role of an SDN controller in relaHon to the network devices it
manages?
Explana5on: An SDN controller can provide a centralized control plane for the network. In
tradiHonal networking, each device has its own control plane, running protocols like OSPF or
STP. In an SDN architecture, these control plane funcHons can be centralized in an SDN
controller. The controller communicates with network devices through southbound interfaces
(SBIs) using protocols like OpenFlow, while applicaHons interact with the controller through
northbound interfaces (NBIs) using REST APIs.
Q2. You are designing a REST API for an SDN controller. Which HTTP verb would be most
appropriate for retrieving exisHng configuraHon data from the controller?
A. GET
B. POST
C. PUT
D. DELETE
Answer: A. GET
Explana5on: The GET HTTP verb is most appropriate for retrieving exisHng data from an SDN
controller using a REST API. In the CRUD (Create, Read, Update, Delete) model commonly used
in REST API design, GET corresponds to the "Read" operaHon. It is used to request data from a
specified resource without modifying any data on the controller. This makes GET ideal for
querying current configuraHons or state informaHon from the SDN controller without risking any
unintended changes to the network configuraHon.
Q4. You are a network architect designing a so]ware-defined soluHon for a large enterprise
with both data center and campus network components. Which Cisco SDN controllers would
you recommend for this environment?
Answer: D. Cisco APIC for data center and Cisco Catalyst Center for campus
Explana5on: For a large enterprise with both data center and campus network components, the
recommended Cisco SDN controllers would be Cisco APIC (ApplicaHon Policy Infrastructure
Controller) for the data center and Cisco Catalyst Center (formerly known as Cisco DNA Center)
for the campus network. Cisco APIC is specifically designed for Cisco's ApplicaHon Centric
Infrastructure (ACI) in data center environments, providing centralized policy-based automaHon
and management. Cisco Catalyst Center, on the other hand, is tailored for enterprise campus
and branch networks, offering intent-based networking capabiliHes, automated provisioning,
and advanced troubleshooHng features. This combinaHon allows for opHmized management of
both data center and campus network infrastructures using purpose-built controllers.
A. TradiHonal VLANs
B. VXLANs
C. GRE Tunnels
D. Collapsed Core Architecture
Answer: B. VXLANs
Explana5on: VXLANs (Virtual Extensible LANs) are the best soluHon for supporHng over 10,000
logical network segments in a data center environment. TradiHonal VLANs are limited to 4,096
segments due to their 12-bit VLAN ID field. VXLANs, on the other hand, use a 24-bit VNI (VXLAN
Network IdenHfier) field, allowing for over 16 million unique segments. This makes VXLANs ideal
for large-scale data center environments requiring numerous isolated network segments.
Q1. As a DevOps engineer, you're implemen?ng a new feature in your company's network
management soDware. During which phase of DevOps Lifecycle would you use a configura?on
management tool like Ansible to push code out to a device?
A. Plan
B. Code
C. Release
D. Deploy
Answer: D. Deploy
Explana3on: The Deploy phase occurs when the Network Opera?ons Team pushes new code
out to managed devices. Once deployed, the soDware is in the Operate phase, where it is
running on a produc?on network. Prior to the Deploy phase is the Release phase, where the
SoDware Development Team hands over the code to the Network Opera?ons Team, and the
code is staged for deployment.
Q2. Your company wants to implement a configura?on management tool that doesn't require
addi?onal soDware on managed devices. Which tool should you recommend?
A. Puppet
B. Chef
C. Ansible
D. SaltStack
Answer: C. Ansible
Explana3on: Ansible is the recommended tool in this scenario because it's always an agentless
configura?on management system. Unlike some other popular tools, Ansible doesn't require
any addi?onal soDware or agents to be installed on the managed devices, making it easier to
deploy and maintain across a large network of devices.
Q3. A startup is looking to automate its cloud infrastructure provisioning across mul?ple cloud
providers. Which tool would be most suitable for this task?
A. Terraform
B. Docker
C. Kubernetes
D. Jenkins
Explana3on: Terraform is the most suitable tool for automa?ng cloud infrastructure
provisioning across mul?ple cloud providers. It's designed specifically for infrastructure as code
(IaC) and supports a wide range of cloud providers, making it ideal for mul?-cloud environments
and automated provisioning of resources.
A) WSSID
B) IBSS
C) BSSID
D) ESSID
Answer: D
Explanation: An Extended Service Set Identifier (ESSID) is the collection of multiple Basic Service
Sets (BSS) that share the same SSID. It allows seamless roaming for clients within a network,
maintaining connectivity as they move between different access points.
Q2. For a data center requiring very high-speed connectivity between devices with a maximum
distance of 30 meters, which category of twisted pair cabling is most suitable to support data
transmission speeds up to 40 Gbps?
A) Category 6
B) Category 6A
C) Category 7
D) Category 8
Answer: D
Explanation: Category 8 twisted pair cabling is specifically designed for data center applications
requiring very high-speed connectivity between devices, supporting up to 25 or 40 Gbps with a
maximum distance of about 30 to 36 meters. This makes Category 8 the best choice for
environments that demand the highest data transmission speeds over short distances.
Q3. After attaching a new workstation to a switch configured with STP, you observe a delay
before the workstation can access the network. Assuming the port was not previously active,
what is the default delay before the port becomes active?
A) 15 seconds
B) 30 seconds
C) 50 seconds
D) 20 seconds
Explanation: For a port that was not previously active, the default STP delay before it goes
active is 30 seconds, bypassing the initial Blocking state and directly entering the Listening (15
seconds) and Learning (15 seconds) states, totaling 30 seconds. The PortFast feature can be
used to eliminate this delay.
Q4. In the context of wireless transmission, what does QAM stand for, and what is its function?
A) Quadrature Amplitude Modulation; it allows multiple bits of data to be sent per subchannel
by adjusting phase and amplitude
B) Quality Assurance Method; it ensures data integrity during transmission
C) Quick Access Mode; it prioritizes urgent data packets
D) Quantum Allocation Management; it manages bandwidth allocation using quantum
computing principles
Answer: A
Explanation: QAM stands for Quadrature Amplitude Modulation. It allows multiple bits of data
to be sent simultaneously per subchannel by adjusting the phase and amplitude of a signal and
comparing the phase and amplitude differences between that signal and a reference signal to
identify a point in a "constellation," which represents multiple bits.
Q5. You've set up a Layer 2 EtherChannel on your Cisco switch and wish to verify the load
balancing algorithm in use. Which command could you use to check the current load balancing
method?
Answer: C
Explanation: To verify the load balancing algorithm currently in use for EtherChannel on a Cisco
switch, the correct command is `show etherchannel load-balance`. This command provides
information about the basis on which the switch distributes outbound traffic among the ports in
the EtherChannel, such as source MAC address, destination MAC address, a combination of
source and destination IP addresses, or other options.
A) 1
B) 2
C) 3
D) 4
Answer: A
Explanation: A Type 2 Link State Advertisement (LSA) is known as a “Network LSA.” An area has
a Type 2 LSA for each network segment that meets two criteria: (1) The segment is a transit link
(i.e., it interconnects to OSPF-speaking routers), (2) The segment is one on which a DR would be
elected (e.g., on an OSPF Broadcast network type but not on an OSPF Point-to-Point network
type). In this example, router R2 is in Area 1, and only one network segment in Area 1 meets
both criteria. Specifically, the segment between routers R2 and R3 is an Ethernet segment, on
which a DR would be elected by default. Also, that segment is a transit link, interconnecting
routers R2 and R3. However, the segment between R3 and SW2 is not a transit link (i.e., it does
not interconnect two OSPF-speaking routers). Therefore, we would only have one Type 2 LSA in
router R3’s Link State Database.
Q7. Which routing protocol is described as being able to provide the entire path (sequence of
autonomous systems) a packet will traverse to reach its destination, distinguishing it from other
types of routing protocols?
A) OSPF
B) EIGRP
C) BGP
D) RIP
Answer: C
Q8. Your network includes a subnet that does not have a DHCP server locally available. What
solution allows PCs on this subnet to receive IP addresses from a DHCP server located on a
different subnet?
Answer: D
Explanation: The correct solution for allowing PCs on a subnet without a local DHCP server to
receive IP addresses from a DHCP server located on a different subnet is to configure a DHCP
relay agent on the subnet's next-hop router. A DHCP relay agent, sometimes referred to as an
"IP Helper," forwards DHCP Discover messages from clients across different subnets to a DHCP
server. This enables the DHCP server to allocate IP addresses to clients on subnets where it is
not directly present.
Q9. Which of the following is a valid private address range for a Class C address?
A) [Link] – [Link]
B) [Link] – [Link]
C) [Link] – [Link]
D) [Link] – [Link]
Answer: A
Explanation: The private IP address range [Link] – [Link] falls within the Class C
IPv4 address range. The default subnet mask for a Class C address is a /24 subnet mask, or
[Link].
Answer: D
Q11. In the EUI-64 method of generating an IPv6 address, why is the seventh bit of the original
MAC address inverted?
Answer: D
Explanation: The inversion of the seventh bit in the EUI-64 process indicates that the address
has been locally administered or modified from its original, universally administered state. This
bit manipulation is crucial for distinguishing between globally unique MAC addresses assigned
by manufacturers and those that have been locally modified or administered. It reflects a
change in the address's administration scope, ensuring that the newly generated interface ID
correctly represents its derivation from an altered MAC address.
Q12. What is the 48-bit address used by a switch to make frame forwarding decisions?
A) MAC address
B) CAM address
C) IP address
D) Link-local address
Answer: A
Answer: B
Explanation: The `snmp-server group` command in SNMPv3 is used to create a group that
defines allowable user permissions and encryption settings. This allows administrators to
manage SNMP users and their access levels securely.
Q14. Which command allows us to dynamically learn MAC addresses seen on an interface,
rather than using static assignments?
Answer: C
Explanation: This command allows the switch to dynamically learn MAC addresses seen on an
interface, which is much more scalable than static assignments. The MAC addresses are stored
in the switch security table and the running configuration.
Q15. Which command is used to enable PAT on router R1 to translate all inside local addresses
matched by ACL 1 to the IP address assigned to the outside interface (which is Gig 0/2)?
Explanation: The command `ip nat inside source list 1 interface gig0/2 overload` is used to
configure PAT by translating inside local addresses matched by ACL 1 to the IP address assigned
to the outside interface (Gig 0/2) with the `overload` keyword enabling multiple translations.
Q16. Given the 32-bit subnet mask 11111111 00000000 00000000 00000000, how many bits
represent the network bits?
A) 8
B) 16
C) 32
D) 24
Answer: A
Explanation: A 32-bit subnet mask separates IPv4 addresses into network bits and host bits. The
mask is made by setting the network bits to all binary 1s and setting the host bits to all binary 0s.
In this example, there are 8 binary 1s found, representing 8 network bits.
Q17. What is the range of assignable IP addresses for a subnet containing an IP address of
[Link] /19?
A) [Link] – [Link]
B) [Link] – [Link]
C) [Link] – [Link]
D) [Link] – [Link]
E) [Link] – [Link]
Answer: A
Explanation: To determine the subnets, assignable IP address ranges, and directed broadcast
addresses created by the 19-bit subnet mask we perform the following steps:
Step #1: Identify the interesting octet (i.e., the octet that contains the first zero in the binary
subnet mask).
In this question, we have a 19-bit subnet mask, which is written in binary as:
11111111 11111111 11100000 00000000
The interesting octet is the third octet, because the third octet (i.e., 11100000) is the first octet
to contain a 0 in the binary.
Step #3: Determine the block size by subtracting the decimal value of the interesting octet from
256.
Block Size = 256 – 224 = 32
Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at
0.
Placing a zero in the first interesting octet identifies the first subnet as:
[Link] /19
We then count by the block size (of 32) in the interesting octet (the third octet in this question)
to determine the remaining subnets:
[Link] /19
[Link] /19
[Link] /19
[Link] /19
[Link] /19
[Link] /19
[Link] /19
Step #5: Identify the subnet address, the directed broadcast address, and the usable range of
addresses.
Looking through the subnets created by the 19-bit subnet mask reveals that the IP address of
[Link] resides in the [Link] /19 subnet.
The directed broadcast address, where all host bits are set to a 1, is 1 less than the next subnet
address.
The next subnet address is [Link]. So, the directed broadcast address for the [Link]
/19 subnet is 1 less than [Link], which is: [Link]
The usable IP addresses are all the IP addresses between the subnet address and the directed
broadcast address. Therefore, in this example, the assignable IP address range for the
[Link] /19 network is: [Link] – [Link]
Answer: C
Explanation: The primary goal of continuous feedback and iteration in the DevOps lifecycle is to
improve both the quality and speed of application deployment. By constantly gathering
feedback and making iterative improvements, teams can more quickly address issues, enhance
features, and deliver better software more rapidly to meet business needs.
Q19. What is the decimal equivalent of the 8-bit binary number 01100101?
A) 100
B) 102
C) 110
D) 101
Answer: D
Explanation: The 8-bit binary number 01100101 converts to the decimal value 101. By knowing
our two-base numbers, we can see that the 1s in this binary number represent the values 1, 4,
32, and 64. Adding these values together (1 + 4 + 32 + 64) gives us the solution of 101.
Q20. Which Dynamic Trunking Protocol (DTP) mode actively generates messages on the
interface in an attempt to form a trunk with a remote switch?
A) Access Mode
B) Trunk Mode
C) Dynamic Desirable Mode
D) Dynamic Auto Mode
Answer: C
Explanation: A switch interface configured in Dynamic Desirable mode will generate Dynamic
Trunking Protocol (DTP) messages on the interface, actively trying to convert the remote switch
Q21. In a typical enterprise network, where would we most likely find Layer 2 switches?
Answer: B
Explanation: The Building Access Layer can be thought of as a wiring closet area. This area
would typically consist of Layer 2 switches, where no routing decisions would be made. This is
the area to which end user devices connect.
Q22. You are developing new security standards for a company. Which of the following factors
would NOT typically be used in a multi-factor authentication system?
Answer: D
Explanation: In multi-factor authentication (MFA), common factors include something the user
knows (password), something the user has (smartphone), and something the user is
(fingerprint). The user's beliefs are not typically used in MFA systems.
Q23. When determining the network and host portions of an IPv4 address, a specific value is
used to identify the boundary between these two segments. What is this value called, and how
does it function?
Explanation: A subnet mask is used to determine the dividing line between the network and
host portions of an IPv4 address. It is a 32-bit value, similar to an IP address, and its purpose is to
indicate which bits of the IP address refer to the network part and which refer to the host part.
This is done by matching the subnet mask bits with the IP address bits: where the mask has a '1'
bit corresponding to a bit in the IP address that is a network bit; and where the mask has a '0' bit
corresponding to a bit in the IP address that is a host bit.
Q24. Which EtherChannel protocol allows for the provisioning of 8 backup ports in a standby
configuration, which have the ability to take over if an individual port fails?
A) EtherChannel
B) LACP
C) PAgP
D) ISL
Answer: B
Explanation: Both Port Aggregation Protocol (PAgP) and Link Aggregation Control Protocol
(LACP) support a maximum of 8 active links in an EtherChannel. However, LACP can additionally
designate 8 redundant backup ports in a standby manner to take over in case of a failure.
Q25. Imagine your company operates in a large metropolitan area and requires high-speed
connectivity between multiple buildings within the city. You seek a solution that offers very high
bandwidth and redundancy, even in the event of a link failure. Based on these requirements,
which WAN/MAN technology is best suited for your needs?
A) MPLS
B) Metro Ethernet
C) VPN over the Internet
D) Frame Relay
Answer: B
Explanation: Of the options listed, Metro Ethernet is the optimal choice for high-speed
connectivity within a metropolitan area, providing very high bandwidth, often up to 100 gigabits
per second, depending on the service provider. It also offers redundancy, especially when
configured in a ring topology, ensuring that if any single link fails, connectivity between buildings
can be maintained through an alternate path. Unlike MPLS, VPNs, or Frame Relay, Metro
Answer: C
Explanation: OAuth 2.0 token-based authentication provides the highest level of security for
REST API authentication in an SDN controller. OAuth 2.0 is an industry-standard protocol for
authorization that allows third-party applications to obtain limited access to an HTTP service. It
generates short-lived tokens, reducing the risk of token compromise. Unlike basic
authentication or API keys, OAuth 2.0 doesn't require sending credentials with each request,
and it supports fine-grained access control. While digest authentication offers some advantages
over basic authentication, it doesn't provide the same level of security and flexibility as OAuth
2.0.
Q27. What is one advantage of using a cloud-managed solution for network management?
Answer: B
Explanation: A cloud-managed solution allows administrators to log into a single web portal to
manage devices across multiple locations, which simplifies the management process and
provides centralized control. This approach is more scalable and efficient than managing each
device individually.
Answer: B
Explanation: A switch interface configured in Dynamic Auto mode will not actively try to convert
the remote switch interface to form a trunk link. A Dynamic Auto mode interface becomes a
trunk interface only if the remote switch interface is configured to Trunk Mode or Dynamic
Desirable mode.
Q29. You are a network administrator setting up a server for a critical application. Which of the
following actions would best ensure "Availability" in the context of the CIA triad?
Answer: C
Explanation: "Availability" in the CIA triad ensures that information and resources are accessible
to authorized users when needed. Configuring redundant servers and load balancing helps
maintain service availability even if one server fails, thereby preventing downtime.
Q30. When examining a Power over Ethernet (PoE) topology, a wireless access point would be
considered what type of component?
A) PSE
B) WAP
C) AC
D) PD
Answer: D
Q31. A switch port in a traditional Spanning Tree Protocol environment transitions from blocking
to forwarding. Which of the following states does it NOT pass through during this transition?
A) Listening
B) Learning
C) Blocking
D) Filtering
Answer: D
Explanation: In traditional STP, a port transitions from Blocking to Listening, then to Learning,
and finally to Forwarding. There is no "Filtering" state in this process. The "Discarding" state is
synonymous with "Blocking" in terms of discarding user data.
Q32. You are assigning IP addresses to hosts in the [Link] /26 subnet. Which two of the
following IP addresses are assignable IP addresses that reside in that subnet?
A) [Link]
B) [Link]
C) [Link]
D) [Link]
E) [Link]
Answer: C and D
Explanation: To determine subnets and usable address ranges created by the 26-bit subnet
mask we perform the following steps:
Step #1: Identify the interesting octet (i.e., the octet that contains the first zero in the binary
subnet mask).
In this question, we have a 26-bit subnet mask, which is written in binary as:
11111111 11111111 11111111 11000000
The interesting octet is the fourth octet, because the fourth octet (i.e., 11000000) is the first
octet to contain a 0 in the binary.
Step #2: Identify the decimal value in the interesting octet of the subnet mask.
Step #3: Determine the block size by subtracting the decimal value of the interesting octet from
256.
Block Size = 256 – 192 = 64
Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at
0.
Placing a zero in the first interesting octet identifies the first subnet as:
[Link] /26
We then count by the block size (of 64) in the interesting octet (the fourth octet in this question)
to determine the remaining subnets:
[Link] /26
[Link] /26
[Link] /26
Step #5:
This question is asking about the [Link] /26 subnet. From the above list of subnets, we can
determine that the assignable range of IP addresses for this subnet is [Link] –
[Link]. We can also determine that [Link] is the network address, and [Link]
is the directed broadcast address.
From the assignable range of IP addresses we have calculated, we can determine that the two
assignable IP addresses given as options in this question are: [Link] and [Link].
Q33. Which access control entry would correctly permit traffic to an HTTPS server (with an IP
address of [Link]) from any host?
Answer: B
Explanation: To permit HTTPS traffic from any source to a specific host, the correct syntax
specifies the protocol (TCP), the source (any), the destination host (host [Link]), and the
destination port number (eq 443). Therefore, the correct ACE is `access-list 101 permit tcp any
host [Link] eq 443`.
Answer: C
Explanation: The aging time on a Catalyst switch is set as a value in seconds. Using this
command will set the aging time as desired, as 3600 seconds is equal to one hour.
A) Native
B) Hosted
C) Nested
D) Installed
Answer: B
Explanation: Also referred to as a client hypervisor, or Type-2 hypervisor, this runs within a host
operating system. The underlying hardware is managed by the host OS rather than the
hypervisor itself.
Q36. Which of the following reasons best explains why a company might want to implement
subnetting within its Class C network infrastructure?
Answer: C
A) Proxy firewall
B) Stateful firewall
C) Stateless firewall
D) Static firewall
Answer: C
Explanation: Stateless firewalls are not aware of the state of traffic or data patterns. They use
sets of static rules for packet filtering and do not keep track of the state of network connections.
These rules are known as access control lists (ALCs).
Q38. Which section of the Cisco DNA Center management dashboard allows us to graphically
allocate pools of IP addresses?
A) Design
B) Provision
C) Platform
D) Addressing
Answer: A
Explanation: In the Design area of Cisco DNA Center, we can graphically design networks. This
includes the ability to create campus maps, import floor plans, identify IP address allocation, and
more.
Q39. When configuring a subinterface for VLAN 10 in a router-on-a-stick setup, which command
correctly assigns the VLAN identifier using 802.1Q encapsulation?
Answer: C
Q40. Which command allows us to set the EtherChannel load-balancing algorithm to consider
source and destination IP addresses?
Answer: A
Explanation: This command will perform an Exclusive OR (XOR) operation to add randomness to
the physical links used in the EtherChannel. This will help distribute traffic more evenly over the
links.
Q41. In an effort to ensure continuous connectivity to the Internet, you are configuring a
floating static route as a failover for your primary Internet connection via RouterA (your default
gateway with an IP of [Link]). You've set up a secondary connection through RouterC, which
has an IP address of [Link]. Given that your dynamic routing protocol has an administrative
distance of 90, which of the following commands correctly configures the floating static route to
the Internet through RouterC with an appropriate administrative distance?
Answer: C
Explanation: This command is correct because it sets a default route through RouterC with an
administrative distance of 91, slightly higher than the primary routing protocol's administrative
distance of 90. This ensures the route through RouterC will be used as a backup if the primary
path via RouterA fails. The administrative distance is crucial in determining the preference of
routing information; in this case, the slightly higher value of 91 ensures the route serves as a
floating static route, acting as a failover route rather than overriding the primary route.
Answer: B
Explanation: A "logic bomb" is a piece of malicious code that remains dormant within a system
until it is triggered by a specific event or condition, such as a certain date or the removal of an
employee from a database.
Q43. In which scenario is the IPv6 unspecified address "::" most commonly used?
Answer: B
Explanation: The IPv6 unspecified address "::" is primarily used as a source address in the initial
packets when a device is undergoing the IPv6 address configuration process. This includes
scenarios such as sending Neighbor Solicitation messages or Router Solicitation messages when
the device does not yet have a configured IPv6 address.
Q44. How many available subnets are possible within the [Link] /26 network?
A) 4
B) 2
C) 8
D) 16
Answer: A
Explanation: We first determine the classful mask for the given network. This particular network
falls within the Class C address space, which has a default classful mask of /24 (or
[Link]). In order to determine the available subnets, we need to use the formula 2^s,
Q45. You need to automate network configuration tasks at your organization. Which Cisco
Catalyst Center feature would be most useful for this purpose?
Answer: C
Explanation: Cisco Catalyst Center's Application Programming Interfaces (APIs) are most useful
for automating network configuration tasks. These APIs allow network administrators to
programmatically configure a network, set policies, and gather troubleshooting information
using scripts, such as those written in Python.
Q46. You are configuring a router and want to gather detailed information about devices
directly connected to it via Layer 2. Which of the following commands provides detailed
information, including the IP address and device type of connected CDP-speaking devices?
A) show cdp
B) show cdp neighbors
C) show cdp interface
D) show cdp neighbors detail
Answer: D
Explanation: The `show cdp neighbors detail` command provides detailed information about
each directly connected CDP-speaking device, including device IDs, port identifiers, capabilities,
and IP addresses. This detailed view is crucial for administrators needing to map the network
topology or troubleshoot connectivity issues, offering insights beyond the basic connectivity and
device type information provided by summarized `show cdp neighbors` command output.
Answer: C
Q48. A host in your network has been assigned an IP address of [Link] /25. What is
the subnet to which the host belongs?
A) [Link] /25
B) [Link] /25
C) [Link] /25
D) [Link] /25
E) [Link] /25
Answer: A
Explanation: To determine subnets and usable address ranges created by the 25-bit subnet
mask we perform the following steps:
Step #1: Identify the interesting octet (i.e., the octet that contains the first zero in the binary
subnet mask).
In this question, we have a 25-bit subnet mask, which is written in binary as:
11111111 11111111 11111111 10000000
The interesting octet is the fourth octet, because the fourth octet (i.e., 10000000) is the first
octet to contain a 0 in the binary.
Step #2: Identify the decimal value in the interesting octet of the subnet mask.
A 25-bit subnet mask can be written in dotted decimal notation as:
[Link]
Since the fourth octet is the interesting octet, the decimal value in the interesting octet is 128.
Step #3: Determine the block size by subtracting the decimal value of the interesting octet from
256.
Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at
0.
Placing a zero in the first interesting octet identifies the first subnet as:
[Link] /25
We then count by the block size (of 128) in the interesting octet (the fourth octet in this
question) to determine the remaining subnets, or in this case just a single additional subnet.
[Link] /25
Now that we have our two subnets identified, we can determine the subnet in which the IP
address of [Link] resides.
Since the usable range of IP addresses for the [Link] /25 network is [Link]
– [Link] (because [Link] is the network address, and [Link] is
the directed broadcast address), and since [Link] is in that range, the subnet to which
[Link] /25 belongs is: [Link] /25
Q49. You are planning to deploy a subnet for a small office network that requires 28 devices to
be connected. Using IPv4 addressing, what is the subnet mask you should apply to ensure all
devices receive a unique IP address while minimizing the number of unused addresses?
A) [Link]
B) [Link]
C) [Link]
D) [Link]
Answer: A
Explanation: The [Link] subnet mask can be written in slash notation as /27, which
indicates 5 host bits (i.e., 32 - 27 = 5). According to the formula: "Available Hosts = (2^h - 2),
where h is the number of host bits," the number of available hosts in this instance = (2^5 - 2) =
32 - 2 = 30. (NOTE: Keep in mind that the order of operations says we need to perform
exponentiation before subtraction.) If we had used 4 host bits, the number of available hosts
would have only been 14. Therefore, 5 host bits (corresponding to a subnet mask of
[Link]) is the minimum number of host bits that can be used to meet the design
criteria.
Answer: D
Explanation: If one side of an EtherChannel is configured with PAgP Auto mode, the only way a
successful EtherChannel can be formed is when the other end is set to PAgP Desirable mode.
The auto option passively listens for PAgP frames, while the desirable option actively sends PAgP
frames in an attempt to form an EtherChannel.
Q51. During a planning session for digital transformation, your company decides it needs a cost-
effective solution for deploying web applications without the hassle of managing hardware.
Which cloud deployment model offers this capability, along with the benefit of paying only for
the resources you use?
A) Public Cloud
B) Private Cloud
C) Hybrid Cloud
D) On-Premises
Answer: A
Explanation: The Public Cloud deployment model is designed to deliver computing resources
over the Internet, provided by cloud service providers. This model enables organizations to
deploy web applications without the need to purchase, manage, or maintain any hardware, as
all the infrastructure is managed by their cloud provider. Additionally, it operates on a "pay-as-
you-go" basis, ensuring that organizations only pay for the resources they consume. This can
make the public cloud an exceptionally cost-effective and scalable solution for deploying web
applications.
A)
R1(config)# access-list 100 deny ip host [Link] eq 80 [Link] [Link]
R1(config)# access-list 100 permit ip any any
R1(config)# int gig 0/2
R1(config-if)# ip access-group 100 in
R1(config-if)#
B)
R1(config)# access-list 100 deny tcp host [Link] eq www [Link] [Link]
R1(config)# access-list 100 permit ip any any
R1(config)# int gig 0/2
R1(config-if)# ip access-group 100 in
R1(config-if)#
C)
R1(config)# access-list 100 deny tcp host [Link] eq www [Link] [Link]
R1(config)# access-list 100 permit ip any any
R1(config)# int gig 0/2
R1(config-if)# ip access-group 100 out
R1(config-if)#
D)
R1(config)# access-list 100 deny tcp host [Link] eq www [Link] [Link]
R1(config)# access-list 100 permit ip any any
R1(config)# int gig 0/2
R1(config-if)# ip access-group 100 in
R1(config-if)#
Explanation: In this example, we’re blocking traffic from the Server to the PCs. Therefore, the
source IP address is the Server’s IP address ([Link]), and the source port is TCP port 80 for
the HTTP traffic we wish to block. Also, since the traffic is traveling from the Server into
interface Gig 0/2 on router R1, the access list needs to be applied in the inbound direction on
interface Gig 0/2. Alternately, the ACL could have been applied in the outbound direction on
interface Gig 0/1, but in keeping with best practices, we’re applying the Extended ACL as close
to the source (i.e., the Server) as possible.
Option A is incorrect, because the first line is denying “ip” traffic rather than “tcp” traffic, and
will therefore not allow us to specify a port number.
Option B is incorrect, because a subnet mask ([Link]) is being used for the destination
network (i.e., the network on which the PCs reside) rather than a wildcard mask ([Link]).
Option C is incorrect, because the ACL is being applied outbound on interface Gig 0/2 rather
than inbound.
Option D, however, is correct. Specifically, it blocks TCP port 80 traffic (i.e., www traffic) from
the server (with a host IP address of [Link]) to PCs in the [Link] /24 network.
Q53. A network administrator needs to ensure accurate time synchronization across all network
devices to troubleshoot and correlate logs effectively. Which of the following protocols could be
implemented to achieve this?
A) NTP
B) SNMP
C) FTP
D) SMTP
Answer: A
Explanation: Network Time Protocol (NTP) is designed to synchronize the clocks of network
devices. Accurate time synchronization helps in correlating logs and troubleshooting network
issues effectively. SNMP is for network management, FTP is for file transfer, and SMTP is for
email communication.
A) 10100100
B) 1111100
C) 1111001
D) 1110000
Answer: D
Explanation: By knowing our two-base numbers, we can calculate the corresponding 8-bit
binary value as 01110000. The 1s in this binary number represent decimal values 16, 32, and 64.
Adding these values together (16 + 32 + 64) give us the decimal value 112.
Q55. Which Layer 2 neighbor discovery protocol sends information to the destination multicast
MAC address with an OUI of 01-80-c2-00-00-0E?
A) LLDP
B) CDP
C) ARP
D) STP
Answer: A
Explanation: Link Layer Discovery Protocol (LLDP) sends information to this address, known as
the LLDP Multicast address. This address is defined within a range of addresses reserved by the
IEEE for protocols that are to be constrained to an individual LAN.
Q56. A network administrator is tasked with implementing a solution that allows rapid
reconfiguration of network devices based on changing traffic patterns. Which of the following
SDN components would be most directly responsible for defining these network changes?
Answer: D
Explanation: Software Defined Networking (SDN) applications are most directly responsible for
defining network changes in an SDN environment. These applications communicate with the
Q57. Given the network [Link] /24, what is the usable IPv4 address range?
A) [Link] – [Link]
B) [Link] – [Link]
C) [Link] – [Link]
D) [Link] – [Link]
Answer: A
Explanation: Using the formulas to find the network and directed broadcast addresses, we can
determine that the network address is [Link] and the directed broadcast address is
[Link]. The usable IPv4 address range will fall inside here, with the first available host
address being one address higher than the network address, and the last being one address
lower than the directed broadcast address. This means the usable IPv4 address range is
[Link] – [Link]
Q58. Imagine you want Switch SW2 to serve as the primary root bridge for VLAN 1 in a PVST+
environment, ensuring optimal traffic flow for that VLAN. Which command correctly configures
this on SW2?
Answer: A
Explanation: The command `spanning-tree vlan 1 root primary` dynamically adjusts a switch's
bridge priority to ensure the switch becomes the primary root for VLAN 1. This command is part
of Cisco's PVST+ enhancements, allowing network administrators to directly influence which
switch serves as a root bridge for a specific VLAN, optimizing traffic flow.
A) ARP requests
B) Manual configuration by network administrators
C) Automatic configuration using DHCP
D) Dynamic routing protocols
Answer: D
Explanation: Routers can populate their IP routing tables through various methods, including
manual configuration (static routing) and dynamic routing protocols. Dynamic routing protocols
allow routers to automatically discover and maintain routes to different networks, providing
scalability and the ability to route around link failures. Examples of dynamic routing protocols
include OSPF and EIGRP.
Q60. You are configuring a VPN between two office locations. Which VPN setup should you use
to make the connection transparent to the end users?
Answer: C
Explanation: A site-to-site VPN connects two office locations, allowing routers to handle
encryption and decryption transparently. This makes the connection seamless for end users,
who do not need to initiate the VPN themselves.
Q61. If you have a route to a network that was learned via OSPF, and another route to the same
network learned via EIGRP, which route would a router typically prefer?
Answer: B
A) CAM Table
B) MAC Table
C) Routing Table
D) Memory Table
Answer: C
Explanation: A router maintains and references a routing table for packet forwarding decisions.
This table contains a list of its ports, along with the network that is connected to each port. This
allows the router to intelligently forward packets to their intended destination.
Q63. You are examining the OSPF database and notice that a transit network between two
routers is not being advertised via a Type 2 LSA. What could be the reason for this?
Answer: B
Explanation: For a network to be advertised via a Type 2 LSA (network LSA), two criteria must be
met. First, the network must be a transit network interconnecting OSPF neighbors. Second, a
Designated Router (DR) must be elected on that network segment. If no DR is elected, such as
on point-to-point network types, the network will not be advertised using a Type 2 LSA.
Answer: C
Explanation: Disallowing the reuse of previous passwords or slight variations of them helps
prevent employees from using the same passwords repeatedly, thereby enhancing security by
reducing the likelihood of compromised passwords being reused.
Q65. You are working with a Class B network with the private IP address of [Link] /16. You
need to maximize the number of broadcast domains, where each broadcast domain can
accommodate 1000 hosts. What subnet mask should you use?
A) /22
B) /23
C) /24
D) /25
E) /26
Answer: A
Explanation: In addition to testing your knowledge of subnetting, this question is also making
sure you understand that a subnet is a broadcast domain. This should not be confused with a
collision domain (i.e., each port on a switch is in its own collision domain).
To determine how many host bits are required to support 1000 hosts, we can create a table
from the following formula:
Number of Hosts = 2^h – 2, where h is the number of host bits
From this formula, we can create the following table:
This table tells us that a subnet with 10 host bits will accommodate the requirement of 1000
hosts. If we have 10 host bits, then we have a 22-bit subnet mask (i.e., 32 – 10 = 22). Also, by not
using more host bits than we need, we are maximizing the number of subnets that can be
created.
Q66. How many usable host addresses are found within the [Link] /18 network?
A) 16,382
B) 65,534
C) 32,766
D) 8,190
Answer: A
Explanation: To calculate the number of usable host addresses within a network, we use the
formula 2^h – 2, where h = the number of host bits in the subnet mask. Two is subtracted in
order to preserve a network address and a directed broadcast address. We know that subnet
masks are 32 bits in length, so given a /18 mask we can determine that there are 14 host bits (32
– 18 = 14). Inserting this into the formula gives us 2^14 – 2, which comes to 16,382. Therefore,
we have 16,382 usable host addresses in this network.
Q67. On a Cisco Discovery Protocol (CDP) capable device, which command will display Layer 2
neighbor information?
A) SW1#show ip cdp
B) SW1#show cdp table
C) SW1#show cdp neighbors
D) SW1#show neighbors
Answer: C
Explanation: This command displays information about Layer 2 adjacent neighbors that are also
running CDP. Information displayed includes the port ID on the neighboring device, the local
interface, and the type of neighboring device.
Answer: C
Explanation: When the "R" bit in an IPv6 multicast address is set to 1, it indicates that the
address includes an embedded IP address of a rendezvous point (RP). This feature is part of
multicast addressing that allows for efficient distribution of multicast traffic by directing it to a
specific router (rendezvous point) from which it can be sent out to all subscribing nodes.
Q69. Why is it recommended not to use the CoS values 6 and 7 for production traffic in a
network?
Answer: A
Explanation: CoS values 6 and 7 are reserved for network use, such as control traffic, and should
not be used for regular production traffic to avoid potential conflicts and ensure network
reliability.
Q70. What is the directed broadcast address for the IP address [Link] /8?
A) [Link]
B) [Link]
C) [Link]
D) [Link]
Answer: B
Explanation: With a /8 subnet mask (or [Link]), we know that there are 8 network bits and
24 host bits. In order to find the network address, we first convert the IP address into binary,
which in this case is 00001010.00001010.00000001.00110000. Since there are 8 network bits in
A) ACL
B) VLAN
C) STP
D) FastEthernet
Answer: B
Explanation: A virtual LAN (VLAN) allows for broadcast domain separation on a Layer 2 switch,
giving separation to sensitive traffic. It’s common to place different enterprise employee groups
on their own VLAN, such as separating the Sales department from the Engineering department.
Q72. In a Spanning Tree Protocol (STP) implementation, the root bridge is:
Answer: A
Explanation: The bridge ID (BID) is made up of the bridge priority (2 bytes) and the MAC address
(6 bytes). Combines, that created the BID value. By default, all Cisco Catalyst switches have a
priority value of 32768, so the MAC address value will be the tie breaker (lowest MAC wins).
Q73. Which IPv4 address class is represented by the classful mask [Link]?
A) Class A
B) Class B
C) Class C
D) Class D
Answer: B
Q74. In a CB-WFQ configuration, what is the maximum number of traffic classes Cisco
recommends creating in order to avoid excessive complexity?
A) No more than 5
B) No more than 8
C) No more than 11
D) No more than 15
Answer: C
Q75. In Wi-Fi 7, what is the maximum channel width that can be achieved through channel
bonding?
A) 160 MHz
B) 240 MHz
C) 320 MHz
D) 640 MHz
Answer: C
Explanation: In Wi-Fi 7 (802.11be), the maximum channel width that can be achieved through
channel bonding is 320 MHz. This is accomplished by combining two 160 MHz channels, allowing
for significantly higher data rates and improved performance, as compared with previous
standards.
A) When the campus is expected to expand rapidly, requiring the addition of many new
buildings
B) When each building requires a high degree of autonomy and separate network management
C) When there are a limited number of buildings, making the expense of a separate Core Layer
unjustifiable
D) When network scalability is the top priority
Answer: C
Explanation: A Collapsed Core architecture, where the Core and Distribution Layers are
combined, is most suitable for scenarios with a limited number of buildings. This is because the
complexity and expense of maintaining a separate Core Layer with high-end switches might not
be justified in smaller environments with only one to three buildings. In such cases, collapsing
the Core and Distribution Layers simplifies the network structure and can reduce costs, while
still meeting the network's performance and connectivity requirements. This choice focuses on
practicality and cost-effectiveness for smaller-scale networks.
Q77. In a Peer-to-Peer Architecture, which device is used to share resources on the network?
A) Server
B) Client
C) Proxy
D) Database
Answer: B
Explanation: In a Peer-to-Peer Architecture, the clients themselves are serving resources to the
network. This allows clients on the network to access local files or attached printers directly
from another client, without the use of a central server.
A) LLDP-VOIP
B) LLDP-MED
C) LLDP-CAP
D) LLDP-SEC
Answer: B
Q79. What type of error might indicate that a network cable is damaged or experiencing
interference?
Answer: C
Explanation: CRC (Cyclic Redundancy Check) errors often point to physical layer issues such as a
bad cable or electromagnetic interference (EMI) affecting traffic flowing over the cable. CRC is a
method used to detect errors in transmitted frames by comparing a calculated value to an
expected value. If these values don't match, it indicates that the data has been corrupted during
transmission.
A) The port remains in the same operational state until manually reset.
B) The port is disabled until the receipt of BPDUs resumes.
C) The port enters a loop-inconsistent state, preventing potential loops.
D) The port automatically resets itself after a predetermined timeout.
Answer: C
Explanation: When Loop Guard is enabled on a port, and that port stops receiving BPDUs
(potentially due to a unidirectional link failure), the port automatically transitions into a loop-
inconsistent state. This state helps prevent the port from moving into a Forwarding state, which
could cause a Layer 2 loop, particularly in scenarios like construction damage to cables. The port
remains in this state until it resumes receiving BPDUs, providing an effective safeguard against
network disruptions caused by physical link issues.
Q81. What is the network address for the IP address [Link] /16?
A) [Link]
B) [Link]
C) [Link]
D) [Link]
Answer: A
Explanation: With a /16 subnet mask (or [Link]), we know that there are 16 network bits
and 16 host bits. In order to find the network address, we first convert the IP address into
binary, which in this case is 10101100.00011101.00010100.00110010. Since there are 16
network bits in the subnet mask, this means we take the first 16 bits of this converted address
and keep them the same. The remaining 16 bits are set to a 0 value, giving us the binary value
10101100.00011101.00000000.00000000. Converting this back to decimal gives us the address
[Link], which is the network address for this IP address.
Answer: A and C
Explanation: Since the Bridge Priorities for VLAN 1 are all at their default value on the switches,
the lowest switch MAC address determines which switch is the Root Bridge. In this topology,
SW3 has the lowest MAC address and is therefore the Root Bridge.
SW2 has two connections to the Root Bridge. To prevent a loop, STP will cause one of those
ports to be blocking. Since both of SW2’s Gig 0/1 and Gig 0/2 ports connect to SW3, the deciding
factor for which port becomes the Root Port is which port is connected to the lowest far end
Port ID. The far end of the link connected to SW2’s Gig 0/1 interface is Gig 0/2 on SW3. The far
end of the link connected to SW2’s Gig 0/2 interface is Gig 0/1 on SW3. Therefore, the Root Port
on SW2 is Gig 0/2, because it connects to the lowest far end Port ID (i.e., Gig 0/1 on SW3 as
opposed to Gig 0/2 on SW3). And, to prevent a loop, Gig 0/1 on SW2 will be Blocking.
Q83. Which subnet mask can most efficiently represent all four networks listed below?
[Link] /24
[Link] /24
[Link] /24
[Link] /24
A) /21
B) /22
C) /4
D) /16
Answer: A
Explanation: If we convert all four IP addresses to binary, we will discover that they share the
same values in their first 21 bits. This tells us that we should use a /21 subnet mask, or
[Link] in dotted decimal.
Q84. As a network administrator, you have a switch port, Gig 0/3 on switch SW3, connected to
an end device that is expected to operate in full-duplex mode. You want this port to transition
immediately to the forwarding state upon connection without waiting for the usual STP
convergence times. How should you configure this port to meet the requirement?
Answer: A
Answer: D
Explanation: This command designates the interface as a switchport (rather than a trunk port)
and assigns the interface to VLAN 100. Interfaces can be added on an individual basis, or as a
group under interface-range configuration mode.
A) Multicast
B) Broadcast
C) Unicast
D) Transit
Answer: C
Explanation: Unicast is the term used to describe communication where data is sent from one
point to another point, with a single source and a single destination. This is the predominant
form of data transmission on LANs and the public Internet.
Q87. When converting the decimal number 241 to hexadecimal, which of the following
represents the correct process and result?
A) Convert to binary, divide into nibbles, convert nibbles to decimal, convert decimal to hex,
result is 0xF1
B) Convert directly to binary, result is 0xE1
C) Divide into nibbles, convert to binary, result is 0xF1
D) Convert to binary, divide into nibbles, convert nibbles to decimal, convert decimal to hex,
result is 0xE1
Explanation: The process involves converting a decimal number to binary (11110001 for 241),
dividing the binary number into nibbles (1111 and 0001), converting each nibble to its decimal
value (15 and 1), and then converting each decimal value into its corresponding hexadecimal
value (F and 1). Therefore, the correct hexadecimal representation of 241 is 0xF1. Recall that a
hexadecimal value is prepended with "0x" to identify the value as a hexadecimal value.
Q88. Which type of wireless LAN consists of clients sending and receiving radio waves directly
between themselves?
Answer: D
Explanation: An Ad Hoc Wireless LAN is a de-centralized type of network which does not rely on
devices such as wireless routers or access points. These networks are very limited, but still may
be useful in certain cases. The Apple iOS AirDrop feature is a modern example of an Ad Hoc
network, which creates a secure device-to-device connection for data transfer.
A) Infrastructure WLAN
B) Ad Hoc WLAN
C) Mesh WLAN
D) Peer-to-Peer WLAN
Answer: C
Explanation: A mesh WLAN design is ideal for extending wireless coverage to remote locations
where direct Ethernet connectivity is not available. Mesh nodes (access points) can receive and
regenerate wireless signals, allowing for broader coverage.
Q2. You are setting up a router that connects to the Internet but want to avoid maintaining a full
Internet routing table. Which of the following should you configure?
Answer: C
Explanation: To avoid maintaining a full Internet routing table, you should configure a default
route. This route (often listed as the "[Link]/0" network) directs packets with unknown
destinations out a specific interface (typically connected to the Internet) or to a specific next-
hop IP address (typically the IP address of the Internet Service Provider's router).
Q3. If a company wants to enable communication between a computer in the sales department
(VLAN 10) and a computer in the engineering department (VLAN 20), which of the following
components is essential?
Q4. Starting with which Wi-Fi standard can an access point both send and receive multiple
spatial streams at the same time?
A) Wi-Fi 4 (802.11n)
B) Wi-Fi 5 (802.11ac)
C) Wi-Fi 6 (802.11ax)
D) Wi-Fi 7 (802.11be)
Answer: C
Explanation: Starting with Wi-Fi 6 (802.11ax), an access point can both send and receive
multiple spatial streams at the same time. This advancement improves the overall capacity and
performance of wireless networks.
Q5. You are designing a network to include EtherChannel for higher bandwidth and redundancy.
Which of the following is a benefit of utilizing EtherChannel in your network design?
A) EtherChannel reduces the number of IP addresses needed for the links between switches.
B) EtherChannel can aggregate up to eight links, providing increased bandwidth and redundancy
without affecting the port channel port if a single link goes down.
C) EtherChannel allows for non-contiguous links to be logically bundled together, reducing
physical cabling.
D) EtherChannel eliminates the need for Spanning Tree Protocol, thereby simplifying network
configuration and management.
Answer: B
Explanation: One of the primary benefits of EtherChannel is its ability to logically bundle up to
eight links between switches. This aggregation increases overall bandwidth and provides
redundancy, as the failure of a single link does not bring down the entire port channel. This
capability enhances network performance and reliability without disabling Spanning Tree
Protocol.
Answer: D
Explanation: The Summary Net Link States section of the OSPF database, contains a listing of
networks in other areas. This section is constructed using Type 3 LSAs (Link-State
Advertisements), which an ABR (Area Border Router) generates to inform routers in one area
about networks located in other areas. This mechanism allows OSPF to efficiently advertise
routing information across different OSPF areas.
Q7. You need to configure a network device with an IP address within the subnet [Link] /23.
Which of the following IP addresses would be considered valid for a device within this subnet?
A) [Link]
B) [Link]
C) [Link]
D) All of the above
Answer: D
Explanation: The subnet mask /23 or [Link] allows for a range of IP addresses from
[Link] to [Link]. This includes the entire range of addresses within the 10.2.4.x and
10.2.5.x network ranges, making all the options listed valid IP addresses for devices within this
subnet. The network address would be [Link], and the broadcast address would be
[Link], with all addresses in between usable for host devices.
A) PVST
B) Rapid PVST+
C) RSTP
D) MSTP
Answer: D
Answer: A
Explanation: UDP is considered unreliable because it does not establish a session before data
transmission. Unlike TCP, which uses a three-way handshake to set up a connection and ensures
reliable delivery of data through acknowledgements, UDP follows a "fire and forget" approach.
It sends data without establishing a connection or confirming receipt, making it less reliable but
more suitable for applications where speed and low latency are more important than
guaranteed delivery, such as voice over IP (VoIP) or streaming media.
Q10. What purpose does the IPv6 solicited-node multicast address serve in the Duplicate
Address Detection (DAD) process?
Answer: D
Explanation: In the Duplicate Address Detection process, the IPv6 solicited-node multicast
address is used to ensure that a self-assigned IPv6 address is unique and not already in use on a
network. The device sends a multicast message to the solicited-node multicast address
corresponding to its potential IPv6 address. If no response is received, the address is considered
unique and safe to use. This process helps in preventing IP address conflicts within a network.
A) 1
B) 2
C) 3
D) 4
Answer: B
Explanation: A Type 3 Link State Advertisement (LSA) is known as a “Summary LSA.” By default,
an Area Border Router (ABR), which is router R2 in this topology, sends a single Type 3 LSA into
an area for each network it’s advertising from another area. In this example, router R3 is in Area
1, and router R2, acting as the ABR, advertises two networks from Area 0 into Area 1.
Specifically, it advertises networks [Link] /24 and [Link] /30. Router R2 send into Area 1 a
separate Type 3 LSA for each of these two networks. Therefore, router R3 will have two Type 3
LSAs in it’s Link State Database (LSDB), one for each network in Area 0.
Q12. In Cisco’s Collapsed Core architecture model, which two layers are combined?
Answer: D
Explanation: For smaller topologies where less complexity is needed, this model collapses the
Core and Distribution layers into a single layer. This creates a two-tier architecture with an
Access layer and a Collapsed Core layer. The Collapsed Core layer performs the combined
function of the Core and Distribution layers.
A) SNMPv1
B) SNMPv2c
C) SNMPv1c
D) SNMPv3
Answer: D
Q14. Which type of cabling issue can result in hearing part of a voice conversation from another
circuit?
A) Attenuation
B) Crosstalk
C) Jitter
D) Latency
Answer: B
A) Level 0 - Emergencies
B) Level 1 - Alerts
C) Level 2 - Critical
D) Level 3 - Errors
Answer: A
Explanation: Severity level 0, or Emergencies, is the most severe level in Syslog. It indicates a
condition that affects the entire system and requires immediate attention.
A) [Link]
B) [Link]
C) [Link]
D) [Link]
E) [Link]
Answer: B
Explanation: To determine the subnets, assignable IP address ranges, and directed broadcast
addresses created by the 19-bit subnet mask we perform the following steps:
Step #1: Identify the interesting octet (i.e., the octet that contains the first zero in the binary
subnet mask).
In this question, we have a 19-bit subnet mask, which is written in binary as:
11111111 11111111 11100000 00000000
The interesting octet is the third octet, because the third octet (i.e., 11100000) is the first octet
to contain a 0 in the binary.
Step #2: Identify the decimal value in the interesting octet of the subnet mask.
A 19-bit subnet mask can be written in dotted decimal notation as:
[Link]
Since the third octet is the interesting octet, the decimal value in the interesting octet is 224.
Step #3: Determine the block size by subtracting the decimal value of the interesting octet from
256.
Block Size = 256 – 224 = 32
Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at
0.
Placing a zero in the first interesting octet identifies the first subnet as:
[Link] /19
We then count by the block size (of 32) in the interesting octet (the third octet in this question)
to determine the remaining subnets:
[Link] /19
[Link] /19
[Link] /19
[Link] /19
[Link] /19
Step #5: Identify the subnet address, the directed broadcast address, and the usable range of
addresses.
Looking through the subnets created by the 19-bit subnet mask reveals that the IP address of
[Link] resides in the [Link] /19 subnet.
The directed broadcast address, where all host bits are set to a 1, is 1 less than the next subnet
address.
The next subnet address is [Link]. So, the directed broadcast address for the [Link]
/19 subnet is 1 less than [Link], which is:
[Link]
The usable IP addresses are all the IP addresses between the subnet address and the directed
broadcast address. Therefore, in this example, the assignable IP address range for the
[Link] /19 network is: [Link] – [Link]
Q17. When a client attempts to obtain network information through Dynamic Host
Configuration Protocol (DHCP), which unicast message from the client requests network
addressing information from the server?
A) REQUEST
B) DISCOVER
C) OFFER
D) ACKNOWLEDGEMENT
Answer: A
Explanation: After the OFFER message is sent from the server to the client, the client now
knows the IP address of the DHCP server and is able to communicate directly through unicast.
The REQUEST message requests that the DHCP server assign an IP address and other
configuration values to the client.
Q18. What is the primary advantage of using Infrastructure as Code (IaC) with tools like
Terraform?
Explanation: The primary advantage of using Infrastructure as Code (IaC) with tools like
Terraform is that it automates the creation and management of a virtual infrastructure. This
approach allows administrators to define their infrastructure using code, which can then be
version-controlled, replicated, and easily modified, leading to more consistent and efficient
infrastructure management.
Q19. With which category of routing protocol is the Dijkstra Algorithm used?
A) Link-State
B) Distance-Vector
C) Path-Vector
D) Route-Vector
Answer: A
Explanation: The Dijkstra Algorithm is used for finding the shortest path between nodes and is
used in the Open Shortest Path First (OSPF) routing protocol. This falls under the category of
link-state protocols, where every node constructs a map of the connectivity in the network.
Q20. Which type of Wide Area Network (WAN) has built-in redundancy due to the ring topology
used?
Answer: A
A) 64
B) 112
C) 107
D) 86
Answer: B
Explanation: The final 112 bits in an IPv6 multicast address are reserved for the multicast group
ID. This is the address that will be joined by devices desiring to receive a particular multicast
stream.
Q22. In the context of WPA2 wireless configuration, what does PSK stand for?
Answer: C
Explanation: PSK stands for Pre-Shared Key, which can be used in WPA2 wireless configurations
for user authentication by pre-configuring a key on both an access point and a client device.
Q23. In the context of Network Address Translation (NAT), what terminology is used to describe
the original, unaltered IP address of a device located inside the network, before any translation
has occurred?
A) Inside Local
B) Inside Global
C) Outside Local
D) Outside Global
Answer: A
Explanation: The term Inside Local refers to the original, unaltered IP address of a device on the
inside of the network, as seen from the inside network itself. It is the private IP address assigned
to a device, which is not routable on the public Internet. NAT modifies this address to an Inside
Global address for communication over the Internet.
A) Unshielded Twisted-Pair
B) Shielded Twisted-Pair
C) Plenum-Rated
D) RG-58/U
Answer: C
Explanation: Plenum-rated cable has a special insulation that has low smoke and low flame
characteristics. This is mandated for any situation where cabling needs to be ran through an air
handling space, such as below raised floors or inside drop-ceilings.
Q25. Which fiber optic connector is known for its straight tip design and utilizes a bayonet-style
attachment mechanism?
A) ST connector
B) LC connector
C) SC connector
D) MTRJ connector
Answer: A
Explanation: The ST connector, known for its straight tip design, uses a bayonet-style
attachment mechanism. To connect it, you push and twist it into a fiber receptacle, and the
tension in a spring holds the connector in place. This design makes it distinct from connectors
like the LC, SC, and MTRJ, with the LC connector being smaller and having a tab for release, the
SC connector being square-shaped, and the MTRJ connector incorporating two fibers into one
connector for increased port density.
Q26. A network administrator is implementing Cisco Catalyst Center in their enterprise network.
Which of the following is NOT a primary feature offered by this SDN controller?
Answer: D
Q27. Which QoS mechanism, by default, drops traffic that exceeds a configured bandwidth
limit?
A) Policing
B) Shaping
C) Queuing
D) Link Efficiency
Answer: A
Explanation: The two primary Quality of Service (QoS) mechanisms that can limit the amount of
bandwidth used are Policing and Shaping. These are known as "traffic conditioners." Policing is
more strict than Shaping and, by default, drops traffic exceeding a configured bandwidth limit
(the Committed Information Rate (CIR)). Shaping, however, delays excess traffic rather than
dropping it.
Q28. Which type of network connection is used in a switched network where devices are able to
communicate in full-duplex mode with one another?
A) Ethernet Bus
B) Shared Media Hub
C) Direct Connect
D) Point-to-Point
Answer: D
A) The rules can be in any order, because the router processes all rules simultaneously.
B) The more specific rules should be placed at the bottom of the list.
C) The order of rules is not important as there is no implicit deny at the end of the ACL.
D) The more specific rules should be placed at the top of the list to ensure they are evaluated
first.
Answer: D
Explanation: ACLs are processed in a top-down order, meaning that the first matching rule will
be applied. Therefore, more specific rules should be placed at the top to ensure they are
evaluated before any broader rules that might permit or deny traffic prematurely.
Q30. Which of the following represents the first two hexadecimal values of every IPv6 multicast
address?
A) FE
B) F0
C) 0E
D) FF
Answer: D
Explanation: The first 8 bits in every IPv6 multicast address are set to the all 1s value of 1111
1111. This converts to the hexadecimal value FF, which is how every IPv6 multicast address
begins.
Q31. Your network needs to support several link speeds. To support multiple link speeds greater
than 1 Gbps, you consider using STP's Long Path Cost method to determine port cost. Under the
Short Path Cost method, what is the port cost assigned to a 1 Gbps link?
A) 2
B) 4
C) 19
D) 100
Answer: B
Q32. A customer is using a Class C network of [Link] subnetted with a 28-bit subnet
mask. How many subnets can be created by using this subnet mask?
A) 32
B) 16
C) 30
D) 8
E) 14
Answer: B
Explanation: The subnet in this question is a Class C network, because there is a 192 in the first
octet. A class C network has a natural mask of 24 bits. However, this network has a 28-bit subnet
mask. Therefore, we have 4 borrowed bits, which are network bits added to a network’s natural
mask (i.e., 2^8 – 24 = 4). The number of subnets can be calculated as follows:
Number of Subnets = 2^s, where s is the number of borrowed bits.
Therefore, in this question, the number of created subnets is 16:
Number of Subnets = 2^4 = 16
Q33. Which Port Security violation mode will disable a port completely when a violation occurs?
A) Protect
B) Restrict
C) Shutdown
D) Monitor
Answer: C
Explanation: The "Shutdown" mode of Port Security will put a port into an error-disabled state
when a security violation occurs, preventing any traffic from passing through the port until the
port is either manually or automatically re-enabled.
A) Global Unicast
B) Loopback
C) Multicast
D) Link Local
Answer: D
Explanation: The link local address can only be used on the local network segment, similar to
the IPv4 APIPA address range. With IPv4, an APIPA typically indicates an issue with interface
communication, but this is not true with IPv6 link-local addresses. They are used by routing
protocols for neighborship formation, self-assignment of IPv6 addresses, and more.
A)
R1(config)# access-list 50 permit any
R1(config)# access-list 50 deny host [Link]
R1(config)# int gig 0/2
R1(config-if)# ip access-group 50 out
R1(config-if)#
B)
R1(config)# access-list 50 deny host [Link]
R1(config)# access-list 50 permit any
R1(config)# int gig 0/2
R1(config-if)# ip access-group 50 out
R1(config-if)#
C)
R1(config)# access-list 150 deny host [Link]
R1(config)# access-list 150 permit any
R1(config)# int gig 0/2
R1(config-if)# ip access-group 150 out
R1(config-if)#
D)
R1(config)# access-list 50 deny host [Link]
R1(config)# access-list 50 permit any
R1(config)# int gig 0/2
R1(config-if)# ip access-group 50 in
R1(config-if)#
Explanation: In this example, a Standard ACL is being used, because we’re not concerned about
a specific destination or a port number.
Option A is incorrect, because the first Access Control Entry (ACE) will permit both PCs, before
the second ACE has an opportunity to deny PC_A.
Option B is correct, because it blocks PC_A before permitting all other IP addresses. Also, the
ACL is applied outbound on R1’s Gig 0/2 interface. This follows the best practice of placing
Standard ACLs as close to the destination as possible.
Option C is incorrect, because the ACL number is 150, which is used for an Extended ACL, not a
Standard ACL.
Option D is incorrect, because the ACL is applied inbound on R1’s Gig 0/2 interface, rather than
outbound (i.e., going out to the Internet).
Q36. Which type of wireless access point (AP) is more common in large enterprise networks?
A) Autonomous
B) Standalone
C) Master
D) Lightweight
Answer: D
Explanation: Lightweight access points (APs) are controlled by a wireless LAN controller, which
can coordinate frequencies and signal strengths between all of the managed devices from a
central location.
Q37. You are diagnosing network issues in a newly set up office network and notice a device
with an IP address of [Link]. Understanding the nature of this IP address, what issue is
most likely present?
A) The device could not obtain an IP address from a DHCP server and assigned itself an IP
address.
B) The device is configured with a static IP address intended for public Internet use.
C) The device has successfully obtained an IP address from a DHCP server.
D) The device is using a private IP address, which is causing conflicts within the network.
Answer: A
Q38. Which command allows us to see which IP addresses have been assigned to the interfaces?
Answer: D
Explanation: From Privileged EXEC mode, the command show ip interface brief will show IP
assignments for all of the interfaces, along with the up/down status of the port.
Q39. With an IPv6 global unicast address, what is represented by the last 64 bits of the address?
Answer: C
Explanation: All global unicast addresses have a 64-bit interface ID, used to identify interfaces
on a link. These are typically composed of a portion of the interface MAC address.
Q40. In the context of emergency services, how can CDP be utilized to assist in identifying a
caller's location?
Explanation: CDP can be used to help identify the location of a caller in emergency situations by
communicating the phone's location based on the location of the switch to which the IP phone
is connected. This feature is particularly useful for calls to emergency services, where the
physical location of the caller can be crucial for a timely response.
A) MT-RJ
B) ST
C) LC
D) SC
Answer: A
Explanation: MT-RJ connectors carry two strands of fiber, which allows for a higher port density
by having transmit and receive strands in the same connector.
Q42. When examining a Cisco router's routing table, you notice routes with different codes such
as 'C', 'L', 'D', and 'O'. If your primary concern is identifying the next-hop for a packet destined
for an internal network that your router learned via dynamic routing, which code should you
look for?
A) C
B) L
C) S
D) O
Answer: D
Explanation: In Cisco routing tables, different codes are used to identify the source of the route
information. 'C' indicates a directly connected network, 'L' represents local routes (local IP
addresses of the router's interfaces), 'S' is used for statically configured routes, and 'O' identifies
routes learned via OSPF (Open Shortest Path First). If the primary concern is identifying the next-
hop for a packet learned via dynamic routing for an internal network, 'O' would be the correct
option of those listed.
A) RADIUS
B) TACACS+
C) LDAP
D) AD
Answer: B
Explanation: TACACS+ is considered more secure than RADIUS because it uses a two-way
challenge-response mechanism and encrypts the entire packet during transmission, whereas
RADIUS only encrypts the password.
Q44. When examining the structure of an IPv6 link local address, which of the following is true?
Answer: B
Explanation: An IPv6 link local address begins with FE80::/10, followed by 54 zeros. Therefore,
since the last 2 bits in the third hexadecimal digit and all 4 bits in the fourth hexadecimal digit
are zeros, we can conclude that all IPv6 link local addresses begin with FE80 in the first quartet.
The last half of a link local address (i.e., the last 64 bits) represent the interface ID and are often
calculated using the EUI-64 addressing process.
Q45. Which OSPF metric is used to determine Designated Router (DR) election?
A) Lowest Router ID
B) Highest Router ID
C) Lowest OSPF Priority
D) Highest OSPF Priority
Answer: D
Q46. For a data center requiring a fiber optic connection that supports 10 Gbps over a maximum
distance of 300 meters, which Ethernet standard and fiber type should be used?
Answer: A
Explanation: 10GBASE-SR with multimode fiber (50 micrometers core) is the best choice for a
data center requiring 10 Gbps connectivity over a distance of 300 meters. This standard is
designed for short-range applications and, when used with higher-grade multimode fiber with a
core diameter of 50 micrometers, can support distances up to 400 meters. 10GBASE-LR is
designed for long-range applications using single mode fiber and supports distances much
greater than 300 meters. 10GBASE-SR with a 62.5 micrometers core and 10GBASE-LX are not as
well-suited for this specific requirement.
Q47. As a network administrator, you want to selectively prevent the transmission of a device's
system name in LLDP advertisements to enhance privacy. Which command accomplishes this at
the global configuration level?
A) no lldp run
B) no lldp tlv-select system-name
C) lldp tlv-select system-name
D) no lldp tlv-select all
Answer: B
Explanation: The `no lldp tlv-select system-name` command at the global configuration level
specifically blocks a system name from being included in LLDP advertisements, enhancing
privacy by not disclosing the device's identity. This selective approach allows other LLDP
information to continue being transmitted, providing flexibility in controlling the scope of shared
network information.
A) Port Security
B) DHCP Snooping
C) VLAN Trunking
D) Spanning Tree Protocol
Answer: B
Explanation: DHCP Snooping must be enabled before configuring Dynamic ARP Inspection (DAI),
as DAI uses the DHCP Snooping binding table to validate ARP messages.
Q49. Given a subnet of [Link] /21, identify which of the following IP addresses belong to
this subnet. (Select 2.)
A) [Link]
B) [Link]
C) [Link]
D) [Link]
E) [Link]
Answer: B and C
Explanation: To determine subnets and usable address ranges created by the 21-bit subnet
mask we perform the following steps:
Step #1: Identify the interesting octet (i.e., the octet that contains the first zero in the binary
subnet mask).
In this question, we have a 21-bit subnet mask, which is written in binary as:
11111111 11111111 11111000 00000000
The interesting octet is the third octet, because the third octet (i.e., 11111000) is the first octet
to contain a 0 in the binary subnet mask.
Step #2: Identify the decimal value in the interesting octet of the subnet mask.
A 21-bit subnet mask can be written in dotted decimal notation as: [Link]
Since the third octet is the interesting octet, the decimal value in the interesting octet is 248.
Step #3: Determine the block size by subtracting the decimal value of the interesting octet from
256.
Block Size = 256 – 248 = 8
[Link] /21
[Link] /21
[Link] /21
[Link] /21
[Link] /21
[Link] /21
[Link] /21
[Link] /21
... SUBNETS OMITTED ...
We can stop counting after we pass the subnet we are being asked about. Specifically, in this
question, we’re being asked about [Link] /21.
Step #5: Identify the subnet address, the directed broadcast address, and the usable range of
addresses.
The subnet address, where all host bits are set to a 0, is given: [Link] /24
The directed broadcast address, where all host bits are set to a 1, is 1 less than the next subnet
address.
The next subnet address is [Link]. So, the directed broadcast address for the [Link]
/21 subnet is 1 less than [Link], which is: [Link]
The usable IP addresses are all the IP addresses between the subnet address and the directed
broadcast address. Therefore, in this example, the usable IP address range for the [Link]
/21 network is: [Link] – [Link]
The only IP addresses in this question that reside in this range are:
[Link]
[Link]
NOTE: Many CCNA candidates look at IP addresses like these and immediately assume they are
not usable IP addresses, because they have a 0 or a 255 in the fourth octet. They argue that
[Link] is a subnet address and that [Link] is a directed broadcast address.
While that would only be true of the subnet mask were 24-bits, remember that, by definition, a
subnet address has all of its host bits set to a 0, and a directed broadcast address has all of its
host bits set to a 1. In this question, we have 11 host bits (i.e., 32 – 21 = 11), not 8 host bits. So,
[Link] and [Link] are actually usable IP addresses.
A) A record
B) CNAME record
C) MX record
D) PTR record
Answer: A
Explanation: An Address (A) record is used by a DNS server to map a fully qualified domain
name (FQDN) to its corresponding IPv4 address, allowing devices on the Internet to locate each
other and communicate. CNAME records are used for aliases to other domain names. MX
records are used for mail exchange servers. PTR records are used for reverse DNS lookups,
mapping IP addresses back to their domain names.
Q51. Which part of the fiber optic cable is used to reflect light along the data path?
A) Dopant
B) Jacket
C) Cladding
D) Core
Answer: C
Explanation: The cladding layer surrounds the core and helps guide the light along the path of
the core. The cladding can be made of plastic or glass and is less transparent than the core. The
difference in the refraction index of the core and cladding is what causes a mirror-like surface,
which helps propagate the light through the cable.
Q52. A network administrator needs to ensure that a newly installed PoE switch can provide
adequate power for several devices, including VoIP phones and surveillance cameras. The
devices require up to 15.4 watts each to operate. Which IEEE standard for PoE should the
administrator ensure the switch supports to meet this requirement?
A) IEEE 802.3at
B) IEEE 802.3af
C) IEEE 802.3bt
D) IEEE 802.3ab
Explanation: The IEEE 802.3af standard for Power over Ethernet (PoE) supports delivery of up to
15.4 watts of power per port, which matches the requirement for the devices mentioned. The
802.3at and 802.3bt standards support higher power levels, while the 802.3ab standard pertains
to Gigabit Ethernet over twisted pair, not PoE.
Q53. What is the purpose of configuring the `transport input ssh` command on VTY lines?
Answer: A
Explanation: The `transport input ssh` command on VTY lines disables Telnet access and allows
only SSH connections, ensuring that remote access to the router is secure and encrypted.
Q54. Which routing protocol has a default administrative distance (AD) value of 90?
A) EIGRP
B) RIP
C) OSPF
D) BGP
Answer: A
Explanation: Enhanced Interior Gateway Routing Protocol (EIGRP) has a default AD value of 90.
This would be preferred by default over Open Shortest Path First (OSPF), which has a higher AD
value of 110.
Q55. Which value makes up the last 24 bits of an IPv6 solicited-node multicast address?
Explanation: The first 104 bits in an IPv6 solicited-node multicast are set to the hexadecimal
value FF02::1:FF. The remaining bits come from the last 24 bits of the IPv6 address to which this
multicast address is destined for. For example, if a solicited-node multicast message is destined
for a router at 3000::2, the complete solicited-node multicast address would be FF02::1:FF00:2.
Q56. A network architect is implementing a Software Defined Networking (SDN). Which of the
following best describes the relationship between the underlay and overlay networks in this
context?
Answer: B
Explanation: In the context of SDN, an underlay network represents the physical infrastructure,
including the actual switches, routers, and physical connections. An overlay network, on the
other hand, is a logical network created on top of the physical underlay. This overlay network is
defined in software and can contain virtual topologies that might not directly correspond to the
network's physical interconnections. This allows for greater flexibility in network design and
segmentation, enabling features like VXLANs (in a data center environment) to create logical
network segments that span across a physical infrastructure.
Q57. Which routing protocol has a default administrative distance (AD) value of 110?
A) EIGRP
B) RIP
C) OSPF
D) BGP
Answer: C
Explanation: Open Shortest Path First (OSPF) has a default AD value of 110. By default,
Enhanced Interior Gateway Routing Protocol (EIGRP) would be preferred over OSPF since it has
a lower AD value of 90.
A) Multicast
B) Unicast
C) Anycast
D) None of the above
Answer: A
Explanation: In IPv6, the absence of a broadcast traffic type is mitigated by the enhanced
functionality of Multicast. Multicast allows for one-to-many communication, where a single
packet can be sent to multiple destinations (members of a multicast group) efficiently. This
serves the purposes previously fulfilled by broadcasting in IPv4, such as discovering devices or
services on the network, but in a more controlled and efficient manner.
Q59. In a GLBP configuration, how does the Active Virtual Gateway (AVG) ensure that the traffic
load is distributed among different routers in a GLBP group?
Answer: B
Explanation: In GLBP (Gateway Load Balancing Protocol), the Active Virtual Gateway (AVG)
responds to ARP requests from different devices with one of multiple (as many as 4) MAC
addresses. These multiple MAC addresses belong to the different Active Virtual Forwarders
(AVFs) within a GLBP group, which can contain a maximum of 4 AVFs.
Q60. You are tasked with securing a server. Which of the following would you address as a
vulnerability?
Q61. What is the default OSPF network type for serial interfaces not configured for Frame
Relay?
A) Broadcast
B) Point-to-point
C) Non-broadcast
D) Point-to-multipoint
Answer: B
Explanation: Serial interfaces not configured for Frame Relay use the point-to-point OSPF
network type by default. This network type assumes that there are only two routers on the
network segment, which eliminates the need for electing a Designated Router (DR) and Backup
Designated Router (BDR).
Q62. What is the final step in a Transmission Control Protocol (TCP) 3-way handshake?
A) SYN/ACK
B) ARP
C) ACK
D) SYN
Answer: C
Explanation: The first step is when a client sends a SYN (synchronization) message to another
client or server as a request to begin the 3-way handshake process. The other end will respond
with a SYN-ACK (synchronization and acknowledgement) message if the SYN is accepted. The
final message is an ACK (acknowledgement) message sent from the original client, which
completes the establishment of the TCP session.
Answer: D
Explanation: To influence the DR (Designated Router) and BDR (Backup Designated Router)
election process, you can set the priority value for a router's interface using the `ip ospf priority
[value]` command in interface configuration mode. The router with the highest priority value
will be elected as the DR, and the router with the second-highest priority will become the BDR. If
you want to prevent a router interface from participating in the election process, you can set its
priority value to 0.
Q64. Which of the following access control entries would correctly deny all IP traffic from a host
with the IP address [Link]?
Answer: D
Explanation: To deny all IP traffic from a specific host in a numbered standard ACL, you should
use the `host` keyword followed by the host's IP address. Therefore, the correct ACE is `access-
list 20 deny host [Link]`. This syntax specifies the host to be denied.
Q65. What is the subnet address of the IP address [Link] with a subnet mask of
[Link]?
A) [Link] /27
B) [Link] /27
C) [Link] /27
D) [Link] /27
E) [Link] /27
Answer: C
Step #1: Identify the interesting octet (i.e., the octet that contains the first zero in the binary
subnet mask).
In this question, we have a 27-bit subnet mask, which is written in binary as:
11111111 11111111 11111111 11100000
The interesting octet is the fourth octet, because the fourth octet (i.e., 11100000) is the first
octet to contain a 0 in the binary.
Step #2: Identify the decimal value in the interesting octet of the subnet mask.
A 27-bit subnet mask can be written in dotted decimal notation as:
[Link]
Since the fourth octet is the interesting octet, the decimal value in the interesting octet is 224.
Step #3: Determine the block size by subtracting the decimal value of the interesting octet from
256.
Block Size = 256 – 224 = 32
Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at
0.
Placing a zero in the first interesting octet identifies the first subnet as: [Link] /27
We then count by the block size (of 32) in the interesting octet (the fourth octet in this question)
to determine the remaining subnets:
[Link] /27
[Link] /27
[Link] /27
[Link] /27
[Link] /27
[Link] /27
[Link] /27
Now that we have all of our subnets identified, we can determine the subnet in which the IP
address of [Link] resides.
Since the usable range of IP addresses for the [Link] /27 network is [Link] –
[Link] (because [Link] is the network address, and [Link] is the directed
broadcast address), and since [Link] is in that range, the subnet to which [Link]
/27 belongs is: [Link] /27
A) Global Unicast
B) Loopback
C) Multicast
D) Link Local
Answer: D
Explanation: A link-local address is valid only on the local network segment. When enabling IPv6
on an interface a link-local address is automatically assigned, but this can also be manually
configured.
Q67. Which IPv6 address is the equivalent of the IPv4 address [Link]?
A) ::0
B) 127:0:0:1
C) ::1
D) ::127
Answer: C
Explanation: This address is the specific IPv6 loopback address. The loopback interface has no
hardware associated with it, and it is not physically connected to a network. It is primarily used
for testing and troubleshooting.
Q68. You are reviewing an IPv6 address that has several quartets with leading zeros (but not all
zeros). What rule applies to the abbreviation of these quartets in the address?
Answer: D
Explanation: You are allowed to omit all leading zeros in each quartet, simplifying the address
and making it shorter and more readable. This technique can be used for any quartet within an
IPv6 address, regardless of its position or the hexadecimal digits that follow the leading zeros.
Answer: B
Explanation: A common use case for TFTP is downloading configuration files to network devices,
such as IP phones, during bootup. This allows devices to quickly obtain necessary configurations
without user intervention.
Q70. What multicast address is used by Open Shortest Path First to advertise Hello messages?
A) [Link]
B) [Link]
C) [Link]
D) [Link]
Answer: B
Q71. Given the MAC address 0014.2201.2345, which of the following will be the IPv6 link local
address?
A) fe80::14:22:01:2345
B) fe80:0014:22ff:fe01:2345
C) fe8::214:22ff:fe1:2345
D) fe80::214:22ff:fe01:2345
Answer: D
Q72. Which Spanning Tree Protocol (STP) port state is used to populate the CAM table during
convergence after a failure?
A) Listening
B) Learning
C) Blocking
D) Forwarding
Answer: B
Explanation: After the Blocking and Listening states, the Learning state ensures that the CAM
table is populated with MAC addresses of attached clients and their corresponding switch ports.
This state lasts for 15 seconds before transitioning the final operational state of Forwarding.
Q73. Which command configures a switch to takeover in the event that the primary root fails on
VLAN 1?
Answer: D
Explanation: This command configures switch SW2 to takeover in the event that the primary
root on VLAN 1 fails. Specifically, this command sets the Bridge Priority of a switch to 28672.
Answer: B
Explanation: Standard ACLs only filter based on source IP addresses. If they are placed too close
to the source, they might inadvertently block traffic that should be allowed to pass to other
parts of the network. Placing them close to the destination minimizes the risk of prematurely
dropping packets that need to traverse the network.
Q75. Which protocol is typically used to communicate between a wireless LAN controller and
lightweight access points?
A) CAPWAP
B) WPA3
C) SNMP
D) FTP
Answer: A
Q76. In an Ethernet switch, how does the switch learn where to forward frames for efficient
communication?
Answer: B
A) 2bcc:a1e:fb9c:d4c::7a0:76cd
B) 2bcc:0a1e:fb9c:0d4c::07a0:76cd
C) 2bcc:a1e:fb9c:d4c::7a:76cd
D) 2bcc:a1e:fb9c:d4c:0:7a0:76cd
Answer: A
Explanation: The rules for abbreviating an IPv6 address are as follows: (1) Leading zeros in a
quartet can be omitted. (2) Consecutive quartets containing all zeros can be represented with a
double colon. (3) Only one double colon can be used per address. Given these rules, the leading
zeros can be removed from the 2nd (0a1e), 4th (0d4c) and 7th (07a0) quartets. The 5th and 6th
quartets consecutively contain all zeros, which can be replaced with a double colon.
Q78. In the context of SVIs on a Layer 3 switch, what determines whether the virtual interface
for a VLAN is up and able to route traffic?
A) The physical interface connected to the switch's management port must be up.
B) There must be at least one active port in the VLAN associated with the SVI.
C) A routing protocol needs to be configured and operational on the switch.
D) The SVI must be manually enabled by an administrator each time the switch restarts.
Answer: B
Explanation: An SVI's operational status is contingent upon the existence of at least one active
port in the VLAN associated with it. If no ports in the VLAN are up, the SVI is considered down
and cannot route traffic. This design ensures that routing decisions are made only for VLANs
with active, connected devices.
Answer: B
Explanation: Virtual network interface cards (vNICs) can be effectively connected and organized
using a virtual switch, which you can create on the same hypervisor running your virtual
machines. This approach allows for the creation of different VLANs for various virtual NICs,
enabling sophisticated network configurations. The virtual switch can then connect to the
physical network interface card of the host running the hypervisor, in order to connect with an
external network.
Q80. Consider the following topology and output. What command produced the output shown?
Explanation: The `show interfaces trunk` command displays information for any trunks currently
active on a Cisco Catalyst switch. The output also includes such information the VLANs allowed
on the trunks and the VLANs that are active on the trunks.
Q81. You are tasked with enhancing network security by configuring features on your switches.
On switches SW1 and SW2, you configure the Root Guard feature on GigabitEthernet 0/1. What
happens if a superior BPDU is received on these interfaces?
Answer: C
Explanation: When a port configured with Root Guard receives a superior BPDU, the port does
not shut down or ignore the BPDU. Instead, it transitions into a "root-inconsistent" state. This
state is maintained until the port ceases to receive superior BPDUs, which prevents the switch
from being manipulated by potentially malicious users aiming to alter the root bridge
designation.
Q82. Which of the following is the correct command for creating a floating static route that will
be used as a backup to an OSPF route?
Answer: D
Explanation: The default administrative distance (AD) value for a static route is 1, meaning that
the route would be preferred over the OSPF route. If we want to make this a backup route, we
must change the AD value to something larger than the AD value of an OSPF route, which is 110.
A) Next-Hop Address
B) Default Gateway
C) Default Route
D) Unknown Route
Answer: C
Explanation: The default route is represented by an all-zero address. A static default route can
be manually configured using the command ip route [Link] [Link] followed by the IP address
for the router that will be the default route.
Q84. As a network engineer, you're tasked with identifying the correct port roles and states in a
RapidPVST+ enabled network. If a switch port is configured to connect to an end-user device
and should bypass the usual STP convergence times, what type of port and corresponding Cisco
switch feature should be applied?
Answer: C
Explanation: An edge port in RapidPVST+ terminology refers to a switch port that connects to an
end-user device, such as a laptop or a printer, and is not expected to contribute to network
loops. By enabling PortFast on these ports, the usual Spanning Tree Protocol (STP) convergence
times are bypassed, allowing the port to transition directly to the Forwarding state. This setup is
essential for ports where immediate network access is required upon connection, without
waiting through the usual STP Listening and Learning states.
Q85. When using Multiprotocol Label Switching (MPLS), what information is used to make frame
forwarding decisions?
A) IP Address
B) Shim Header
C) DLCI
D) MAC Address
Explanation: When using MPLS, a 32-but shim header is inserted into a frame between the
Layer 2 and Layer 3 headers. This label is used to determine the frame forwarding.
Q86. Which port state in Rapid Per-VLAN Spanning Tree (Rapid PVST+) is a combination of the
Listening and Learning port states found in traditional STP?
A) Learning
B) Discarding
C) Forwarding
D) Listening
Answer: A
Explanation: The Learning state performs the combined duties of the traditional STP Learning
and Listening states. When in this state, the switch is learning which MAC addresses are
available off the port. This state is seen when a port is transitioning to the Forwarding state.
Q87. What does the IPv6 loopback address "::1" primarily represent in network testing?
Answer: A
Explanation: The IPv6 loopback address "::1" represents a destination address used for a host to
send packets back to itself. This is similar to the IPv4 loopback address ([Link]) and is used
for testing and configuration purposes, ensuring that the IPv6 stack is functioning correctly on
the local machine. It is also commonly used by developers and network administrators to test
local network setups, applications, or services running on a device.
A) 1
B) 4
C) 8
D) 16
Answer: C
Explanation: There are 8 quartets found within an IPv6 address, each separated by a colon. Each
of the individual quartets contains four hexadecimal digits.
A) Silver
B) Bronze
C) Gold
D) Platinum
Answer: D
Explanation: The Platinum QoS access class is typically used for voice traffic in Wi-Fi networks. It
provides higher priority and better handling for voice packets, ensuring low latency and high
quality for voice communications.
Q2. How does Cisco's Application Centric Infrastructure (ACI) enhance the management of
spine-leaf architectures in data centers?
A) By enabling direct, physical connections between spine switches for a simplified topology
B) By reducing the number of uplink connections required from leaf switches to spine switches
C) By converting all inter-switch connections to Layer 2 to streamline data flow
D) By treating a collection of leaf and spine switches as if they are part of a single logical switch
Answer: D
Answer: B
Explanation: The most likely reason for a PortFast-enabled port that is also configured with
BPDU Guard to be in an Error Disabled state is because it has received a BPDU. BPDU Guard is
designed to shut down the port immediately upon detection of a BPDU to prevent potential
Layer 2 loops caused by connecting network devices that should not be present off those
specific ports. This safety mechanism helps ensure that a network's topology remains stable and
predictable by disabling a port in order to block unauthorized devices that might disrupt the
Spanning Tree topology.
Q4. Which Wi-Fi standard is known for having a maximum theoretical bandwidth of
approximately 10 Gbps and uses orthogonal frequency division multiple access (OFDMA)?
A) 802.11ac
B) 802.11n
C) 802.11ax
D) 802.11g
Answer: C
Explanation: The 802.11ax standard, also known as Wi-Fi 6, introduced in 2019, has a maximum
theoretical bandwidth approaching 10 Gbps. It uses orthogonal frequency division multiple
access (OFDMA) to improve efficiency and capacity.
Q5. You configure the BPDU Filter feature globally on a switch with ports configured for
PortFast. What will be the primary impact of this configuration on the network?
Explanation: While globally configuring BPDU Filter on PortFast ports can speed up the
activation of these ports by skipping STP processing times, the primary impact is that these ports
will neither send nor receive BPDUs. This could potentially lead to Layer 2 loops because the
STP's ability to detect and prevent loops depends on the continuous flow of BPDUs to monitor
network topology changes. Without BPDUs, the switch is unaware of the network structure
beyond its connected devices, increasing the risk of loops.
Q6. What is a primary purpose of the 5 GHz frequency band in wireless networks?
A) To provide higher data rates and less interference compared to 2.4 GHz
B) To offer longer range compared to 2.4 GHz
C) To support legacy wireless devices
D) To reduce power consumption of wireless devices
Answer: A
Explanation: The 5 GHz frequency band provides higher data rates and experiences less
interference compared to the 2.4 GHz band, making it suitable for high-performance wireless
networks.
Q7. When manually assigning an IPv4 address to a device, why is it important to also specify a
DNS server's address?
Answer: B
Explanation: DNS (Domain Name System) servers translate human-friendly domain names (like
[Link]) into their corresponding IP addresses, facilitating communication over the Internet
by allowing users to access websites using domain names instead of IP addresses.
A) 64-QAM
B) 1024-QAM
C) 256-QAM
D) 2048-QAM
Answer: B
Explanation: 802.11ax has a higher modulation scheme, moving from 256-QAM used by
802.11ac to 1024-QAM. This translates to better throughput and 25% higher data capacity,
where 10 bits are represented per symbol.
Q9. What might be a distinctive feature of a Next Generation Firewall, compared to a traditional
stateful firewall?
Answer: B
Explanation: While traditional stateful firewalls allow return traffic for sessions initiated on the
internal network, a Next Generation Firewall (NGFW) adds features like intrusion prevention
and deep packet inspection. Many NGFWs also have the ability to inspect encrypted traffic,
including the ability to recognize threats in that encrypted traffic.
Q10. When considering IPv6 terminology, what term is used to describe the network portion of
an address, differing from the IPv4 concept of a subnet mask?
A) 2
B) 4
C) 8
D) 16
Answer: C
Q11. Which of the following commands will allow interfaces with addresses in the [Link]/24
range to participate in OSPF area 0?
Answer: C
Explanation: Rather than using a subnet mask to designate interfaces participating in OSPF, we
instead use a wildcard mask. This can essentially be thought of as the inverse of the subnet
mask, where each octet value in the subnet mask is subtracted from the value 255.
Q12. You are configuring NTP on a router to synchronize its time with an Internet router acting
as an NTP master. The Internet router has a stratum value of 3. What stratum value will the
router you are configuring have after synchronization?
A) 1
B) 2
C) 3
D) 4
Answer: D
Explanation: NTP assigns stratum values to indicate the distance from the reference clock. A
stratum value increments by 1 for each hop away from the reference clock. Since the Internet
router is a stratum 3 clock, the router synchronizing with it will have a stratum value of 4.
A) WPA
B) WPA2
C) WPA3
D) TKIP
Answer: C
Explanation: Wi-Fi Protected Access version 3 is an update to the WPA standard that will
replace version 2 within the next few years. Among other enhancements, WPA3 will include a
192-bit AES security suite for use in Enterprise Mode.
Answer: C
Explanation: Predictive AI uses historical data to forecast future events or issues, allowing
network administrators to proactively address potential problems before they occur. This can
help in planning for capacity upgrades, load balancing, and preventing network congestion.
Q15. You are working for a company that will be using the [Link] /24 private IP address
space for IP addressing inside their organization. They have multiple geographical locations and
want to carve up the [Link] /24 address space into subnets. Their largest subnet will need
13 hosts. What subnet mask should you use to accommodate at least 13 hosts per subnet, while
maximizing the number of subnets that can be created?
A) [Link]
B) [Link]
C) [Link]
D) [Link]
E) [Link]
Answer: E
1 Host Bit: 21 – 2 = 0
2 Host Bits: 22 – 2 = 2
3 Host Bits: 23 – 2 = 6
4 Host Bits: 24 – 2 = 14
5 Host Bits: 25 – 2 = 30
6 Host Bits: 26 – 2 = 62
7 Host Bits: 27 – 2 = 126
8 Host Bits: 28 – 2 = 254
In this question, we’re asked to determine a subnet mask that accommodates at least 13 hosts
per subnet. By looking at the reference table we created, we can see that 4 host bits (which
support 14 hosts) would work, while 3 host bits (which supports only 6 hosts) would not be
enough.
So, we need a subnet with 4 host bits, which are enough host bits to meet the design goal, but
not more than we need. Using more host bits than we need would violate the requirement to
maximize the number of subnets.
A subnet mask with 4 host bits has 28 network bits (i.e., 3^2 – 4 = 28), and therefore a 28-bit
subnet mask. A 28-bit subnet mask can be written as: [Link]
Q16. Which piece of the AAA framework determines what a user is allowed to do?
A) Authentication
B) Authorization
C) Accounting
D) Access
Answer: B
Explanation: After a user has been authenticated, authorization is used to determine which
resources the user is allowed to affect, or which operations they can perform. This is distinct
Q17. A network engineer is reviewing a JSON-formatted configuration file and notices the
following structure: ["CCNA", "CCNP Enterprise", "CCIE Enterprise Infrastructure"] What type of
JSON data structure is this?
A) Object
B) Array
C) String
D) Number
Answer: B
Explanation: The structure shown in the question is a JSON array. In JSON, an array is an
ordered list of values enclosed in square brackets [ ]. Each value in an* array is separated by a
comma. Arrays can contain any valid JSON data type, including strings (as in this example),
numbers, booleans, objects, or even other arrays. In this specific case, the array contains three
string values representing different Cisco certifications. Arrays are useful for representing
collections of related data in a JSON document.
Q18. Where should more specific Access Control Entries (ACEs) be placed within an Access
Control List (ACL)?
Answer: D
Explanation: More specific Access Control Entries (ACEs) should be placed near the top of an
ACL. Since ACLs are processed in a top-down manner, more specific ACEs could potentially be
skipped if general ACEs find a traffic match first.
A) R1#syslog info
B) R1#show log local
C) R1#show logging
D) R1#show syslog
Answer: C
Explanation: This command will display the state of Syslog (including the configured logging
level) and the contents of the local system logging buffer.
Q20. Consider the following topology. How many Type 1 LSAs are present in router R3’s Link
State Database (LSDB)?
A) 1
B) 2
C) 3
D) 4
Answer: B
Explanation: A Type 1 Link State Advertisement (LSA) is known as a “Router LSA.” A router in an
area will have a Type 1 LSA entry for each network segment with that area. In this example,
router R3 belongs to Area 1, and Area 1 contains two network segments, specifically:
[Link] /30 and [Link] /24. Therefore, router R3’s LSDB contains two Type 1 LSAs, one for
each network segment in Area 1.
A) Static NAT
B) Dynamic NAT
C) Port Address Translation
D) NAT Pool
Answer: C
Q22. You receive a text message stating that your package has been shipped and asking you to
tap on a link to track it. What type of social engineering attack might this represent?
A) Phishing
B) Vishing
C) Smishing
D) Spear phishing
Answer: C
Explanation: Smishing is a type of social engineering attack that uses SMS (Short Message
Service) or text messages to deceive individuals. The text message asking the recipient to tap on
a link to track a package, might redirect the recipient to a malicious website.
Q23. During a network setup for selective video streaming, you consider the impact of each IP
packet flow type on network resources. Which method is least scalable for distributing a video
stream to a large number of recipients due to increased processor and bandwidth burden on the
video server?
A) Broadcast
B) Multicast
C) Anycast
D) Unicast
Answer: D
Q24. Within an IPv6 Type of Service (ToS) byte, which category of traffic does the highest
possible Differentiated Services Code Point (DSCP) binary value 101 110 indicate?
A) Default
B) Drop Traffic
C) Expedited Forwarding
D) Priority
Answer: C
Explanation: This high priority DSCP marking is referred to as Expedited Forwarding. Voice
packets would be marked with this DSCP value, since their sensitivity to latency requires high
priority treatment on the network.
Q25. As a network technician, you're tasked with setting up a network that requires protection
from electromagnetic interference (EMI). Which feature of coaxial cables is primarily
responsible for protecting the network signal from EMI?
Answer: C
Explanation: The braided metal shield in a coaxial cable is primarily responsible for protecting a
signal from electromagnetic interference (EMI). This shield encases the dielectric insulator that
surrounds the main copper conductor, effectively blocking EMI from corrupting the data signal.
The plastic jacket provides physical protection, the center conductor carries the signal, and the
insulator helps prevent signal loss but does not specifically protect against EMI.
A) Broadcast
B) Point-to-Point
C) Point-to-Multipoint
D) Shared
Answer: A
Explanation: The Broadcast network type is much more efficient for connecting a large number
of devices in an OSPF network, as opposed to point-to-point networks. DR and BDR election
allow for a multiaccess segment where full-mesh connectivity is not necessary.
Q27. What is the primary purpose of using static NAT in a network environment?
Answer: B
Explanation: Static NAT provides a fixed one-to-one mapping of an inside local address to an
inside global address. This allows devices inside the network to maintain a consistent public-
facing IP address for specific services.
Q28. Which file transfer protocol communicates using User Datagram Protocol (UDP)?
A) FTP
B) SFTP
C) FTPS
D) TFTP
Answer: D
Explanation: Trivial File Transfer Protocol (TFTP) is a much simpler version of FTP, but it lacks a
method for user authentication. This uses UDP communication, as opposed to the TCP
communication used by more complex file transfer protocols.
A) MD5
B) Scrypt
C) SHA-256
D) Vigenere Cipher
Answer: B
Explanation: Of the options listed, only MD5, SHA-256, and Scrypt are hashing algorithms, with
the Vigenere Cipher acting as an encryption algorithm. MD5 is the weakest of these three
hashing algorithms. While Scrypt and SHA-256 are similar, calculating an Scrypt hash is much
more time consuming compared to calculating a SHA-256 hash. Therefore, an enable secret
password is best protected from a brute-force attack by using an Scrypt hash.
Q30. Which of the following is not an advantage of Network Address Translation (NAT)?
Answer: D
Explanation: Because the nature of NAT is to modify a portion of the packet during translation,
and IPsec is designed to prevent the manipulation of data in transit, there are known issues with
using IPsec and NAT in conjunction. In order to completely avoid problems, IPsec tunnel
endpoints should always be located in the public address space.
Q31. After successfully configuring VLANs for your network, you decide to delete the HR VLAN
(VLAN 20). What is the impact on the interfaces assigned to VLAN 20?
A) The interfaces become unusable until they are reassigned to a different VLAN.
B) The interfaces automatically move to the default VLAN (VLAN 1).
C) You're prevented from deleting VLAN 20, because it has member ports.
D) The interfaces are deleted along with the VLAN.
Answer: A
Q32. A customer is using a Class C network of [Link] subnetted with a 28-bit subnet
mask. How many assignable addresses are available in each of the subnets?
A) 32
B) 16
C) 30
D) 8
E) 14
Answer: E
Explanation: An IPv4 address contains a total of 32 bits. Since, in this question, we have 28
subnet bits, the number of host bits is 4 (i.e., 32 – 28 = 4). The number of assignable IP
addresses in a subnet can be calculated as follows:
Number of Assignable IP Addresses = 2^h – 2, where h is the number of host bits.
Therefore, in this question, each subnet has 14 assignable IP addresses:
Number of Assignable IP Addresses = 2^4 – 2 = 16 – 2 = 14
Q33. What is the benefit of placing an extended ACL as close to the source as possible?
Answer: C
Explanation: Placing extended ACLs close to the source helps in dropping unwanted traffic early
in the network path, thereby conserving network resources and bandwidth that would
otherwise be used to transport packets across a network only to be dropped later.
A) LWAPP
B) CAPWAP
C) LDAP
D) Ad Hoc
Answer: B
Explanation: The Control and Provisioning of Wireless Access Points (CAPWAP) protocol is an
update to the original Lightweight Access Point Protocol (LWAPP) standard and is most
commonly used today by wireless LAN controllers for management of access points (APs).
Q35. Which file transfer protocol does not have a mechanism for authentication?
A) FTP
B) SFTP
C) FTPS
D) TFTP
Answer: D
Explanation: Trivial File Transfer Protocol (TFTP) is a much simpler version of FTP, but it lacks a
method for user authentication. This uses UDP communication, as opposed to the TCP
communication used by more complex file transfer protocols.
Q36. In a network setup, you're using the 1000BASE-T standard for connectivity. How many
wires are utilized in an Ethernet cable for this setup?
A) 2 pairs
B) 4 pairs
C) 6 wires
D) 4 wires
Answer: B
Explanation: The 1000BASE-T standard utilizes all 4 pairs (8 wires) in an Ethernet cable for
communication. This full utilization of wires is necessary to support the gigabit per second data
Q37. During Hot Standby Router Protocol (HSRP) active router election, what value can be
manually altered to influence the winner?
A) Router ID
B) HSRP Priority
C) HSRP Group Number
D) Loopback Address
Answer: B
Explanation: During HSRP active router election, the router with the highest priority will win the
election. By default, the HSRP priority value is set to 100. An active router can be manually
identified by assigning a priority value of more than 100 to the desired active router.
Q38. What is the highest believable stratum value in Network Time Protocol (NTP) hierarchy?
A) 8
B) 12
C) 15
D) 16
Answer: C
Explanation: The highest possible stratum value that is considered to be a believable time
source is Stratum 15. Any stratum number above 15 would be considered unreliable, and time
would not be learned from such a source.
Q39. When configuring the MAC address table aging time on a Cisco switch, a network engineer
decides to extend the aging time to reduce the frequency of MAC address relearning. What
command should they use to set the aging time to 3600 seconds?
Explanation: The correct command to set the aging time for MAC addresses in the switch's MAC
address table to 3600 seconds (1 hour) is `mac address-table aging-time 3600`. This command
adjusts the global aging time, which determines how long a dynamically learned MAC address
remains in the table without receiving traffic from that address before it is aged out and
removed. Extending the aging time can be beneficial in stable networks where MAC addresses
do not change frequently, reducing the overhead of the switch having to relearn MAC
addresses.
Q40. Which type of attack commonly attempts to appear as the default gateway of the network
in order to intercept traffic?
A) Ransomware
B) ARP Poisoning
C) DNS Poisoning
D) Phishing
Answer: B
Explanation: Address Resolution Protocol (ARP) Poisoning is when an attacker sends falsified
ARP messages over a LAN in order to link their own MAC address with the IP address of a
legitimate network resource, often the default gateway. This allows all traffic to flow through
their device, giving them an opportunity to intercept sensitive data.
Q41. When comparing OSPF neighborships and adjacencies, which statement is true?
Answer: C
Explanation: In OSPF, routers first become neighbors by exchanging Hello messages and
confirming that certain parameters match. Once they are neighbors, they can proceed to form
an adjacency, which involves exchanging link-state information to build the complete topology
database. Therefore, being a neighbor is a prerequisite for forming an adjacency.
Answer: B
Explanation: The command `switchport port-security` enables port security on a specific switch
port, allowing further configuration of port security parameters.
Q43. When using SLAAC for IPv6 address configuration, how does a device ensure the
uniqueness of its IPv6 address on the network?
Answer: A
Explanation: The IPv6 loopback address "::1" represents a destination address used for a host to
send packets back to itself. This is similar to the IPv4 loopback address ([Link]) and is used
for testing and configuration purposes, ensuring that the IPv6 stack is functioning correctly on
the local machine. It is also commonly used by developers and network administrators to test
local network setups, applications, or services running on a device.
Q44. When using REST APIs, which HTTP verb allows us to update something on the SDN
controller?
A) UPDATE
B) WRITE
C) CREATE
D) PUT
Answer: D
Explanation: The HTTP PUT verb is most often used for updating existing information on a
controller. PUT replaces the information with a newer version in its entirety.
Answer: A
Explanation: Servers in a network offer a more robust feature set and a granular level of
permissions control compared to peer-to-peer architectures. While peer-to-peer architectures
can be convenient for sharing certain resources, servers are designed to provide a wide range of
services and better manageability, especially in larger or more complex networks.
Q46. You are tasked with setting up an EtherChannel using LACP in an environment not
previously configured for either PAGP or LACP. Which mode should you preferentially configure
on your switches to form an LACP EtherChannel?
Answer: B
Explanation: When configuring an EtherChannel with LACP, setting both sides to "active"
ensures that both ends proactively send LACP packets to negotiate the formation of an
EtherChannel. This mode is recommended when you are not confined to using PAGP in your
environment, as LACP is an IEEE standard (802.3ad) and supports additional features like
standby ports. While a Link Aggregation Group (LAG) would be formed by setting both sides to
On, this configuration does not represent an LACP EtherChannel as required in the design
criterion.
A) DES
B) AES
C) RSA
D) 3DES
Answer: C
Explanation: RSA is an asymmetric encryption algorithm that uses a pair of keys (public and
private) for encryption and decryption, making it suitable for secure communications between a
client and a server. The other listed options are symmetric encryption algorithms.
A) [Link]
B) [Link]
C) [Link]
D) [Link]
E) [Link]
Answer: D
Explanation: To determine the subnets created by the 27-bit subnet mask we perform the
following steps:
Step #1: Identify the interesting octet (i.e., the octet that contains the first zero in the binary
subnet mask).
In this question, we have a 19-bit subnet mask, which is written in binary as:
11111111 11111111 11111111 11100000
The interesting octet is the fourth octet, because the fourth octet (i.e., 11100000) is the first
octet to contain a 0 in the binary.
Step #2: Identify the decimal value in the interesting octet of the subnet mask.
A 27-bit subnet mask can be written in dotted decimal notation as:
[Link]
Since the fourth octet is the interesting octet, the decimal value in the interesting octet is 224.
Step #3: Determine the block size by subtracting the decimal value of the interesting octet from
256.
Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at
0.
Placing a zero in the first interesting octet identifies the first subnet as:
[Link] /27
We then count by the block size (of 32) in the interesting octet (the fourth octet in this question)
to determine the remaining subnets:
[Link] /27
[Link] /27
[Link] /27
[Link] /27
[Link] /27
[Link] /27
[Link] /27
Step #5: Identify the subnet address of the IP address [Link] /27.
Looking through the subnets created by the 27-bit subnet mask reveals that the IP address of
[Link] resides in the [Link] subnet.
Q49. Given an IP address of [Link] with a subnet mask of [Link], which of the
following represents the subnet that this IP address belongs to?
A) [Link] /16
B) [Link] /24
C) [Link] /8
D) [Link] /24
Answer: B
Explanation: The subnet mask [Link] corresponds to a /24 prefix length, which means
the first three octets (10.1.15) define the network portion of the IP address, and the last octet
(0) is used for host addresses within the subnet. Therefore, the subnet that the IP address
[Link] belongs to is [Link] /24.
A) 12,000 bps
B) 750 bps
C) 48,000 bps
D) 6,000 bps
Answer: C
Explanation: The formula used to calculate the Committed Information Rate (CIR) is CIR = Bc/Tc.
Using the given numbers, the equation becomes CIR = 6,000 bits / 0.125 seconds, which is
48,000 bps.
Q51. When installing network cabling in a building's air return spaces, which type of cabling is
mandatory to prevent the emission of toxic fumes in case of a fire?
A) Plenum-rated cabling
B) UTP (Unshielded Twisted Pair)
C) STP (Shielded Twisted Pair)
D) Category 5e (or higher) twisted pair cabling
Answer: A
Explanation: Plenum-rated cabling is specifically designed for use in air return spaces of
buildings, such as above drop ceilings or below raised floors. These cables are made from
materials that do not emit toxic fumes when exposed to intense heat or flames, making them
the safe choice for these areas. UTP and STP cables might not have this fire-resistant
characteristic unless they are also specified as plenum-rated.
Q52. In the context of dynamic NAT, what is the role of the NAT pool?
Answer: C
Q53. Which of the following numbered Access Control Lists (ACLs) is a Standard ACL?
A) 1999
B) 101
C) 100
D) 2000
Answer: A
Explanation: Standard ACLs fall within the range of numbers 1 – 99, with an expanded range
identified as numbers 1300 – 1999.
Q54. Which channel combination is ideal when using the 2.4 Gigahertz (GHz) band in order to
avoid channel overlap?
A) 3,6,9,12
B) 1,7,14
C) 3,8,13
D) 1,6,11
Answer: D
Explanation: When selecting a 2.4 GHz wireless channel, channels 12 and 13 are allowed only
under low powered conditions, and channel 14 is banned completely in the United States. This
means that channels 1, 6, and 11 are the only non-overlapping channels in this range.
Answer: B
Q56. Consider the following topology and output. Which of the following commands produced
the output?
Answer: D
Explanation: The output shown is from the `show cdp neighbors` command, which shows
information about Layer 2 adjacent devices configured to run Cisco Discovery Protocol (CDP).
You can optionally add the keyword of `detail` to the end of the command to get more detailed
information about these neighbors. However, the output provided here only provides summary
information about router R1’s CDP neighbors.
A) Inventory
B) Playbook
C) YAML
D) Module
Answer: B
Explanation: Ordered lists of tasks are referred to as playbooks within Ansible. These playbooks
allow you to run tasks repeatedly and are written in the YAML syntax.
Q58. In an IPv6 address, what does the global routing prefix represent?
A) Broadcast length
B) Prefix length
C) Quartet count
D) Hexadecimal range
Answer: B
Explanation: Unlike IPv4, which uses a subnet mask to denote the network portion of an
address, IPv6 uses the term "prefix length" to indicate the number of bits allocated for the
network portion of an address. An IPv6 address has a total of 128 bits. Therefore, as an example,
if an IPv6 address had a prefix length of 96 bits, then we could conclude that the host portion of
the address is 32 bits in length (i.e., 96 + 32 = 128).
Q59. Consider you are implementing HSRP in a network environment requiring fast failover. Of
the following configuration options, which configuration would allow the shortest convergence
time if the active router fails?
Answer: B
Explanation: To achieve faster convergence in an HSRP setup, reducing the hello interval allows
quicker detection of router failures. By configuring the hello interval to 500 milliseconds, which
Q60. What type of attack does DHCP Snooping help to prevent by blocking rogue DHCP servers?
A) ARP Poisoning
B) DHCP Spoofing
C) Man-in-the-Middle
D) MAC Flooding
Answer: B
Explanation: DHCP Snooping helps prevent DHCP Spoofing attacks, where an attacker sets up a
rogue DHCP server to send incorrect information to clients, potentially redirecting them to
malicious servers.
Q61. If a master router in a VRRP configuration becomes unavailable, how is the master down
interval calculated by default?
Answer: A
Explanation: The master down interval in VRRP is calculated by taking three times the master
advertisement interval and adding the skew time. The skew time is derived from subtracting the
VRRP router's priority from 256 and then dividing by 256.
Q62. Which type of Link-State Advertisement (LSA) is created by each router in an OSPF
network, containing information about the directly attached networks?
A) Type 1
B) Type 2
C) Type 3
D) Type 4
Answer: A
Q63. At a branch office, you decide to use a static default route to simplify routing to the
headquarters (HQ) over a single connection. Which command correctly configures this on the
branch office router (BR1) to forward all unknown destinations to HQ (at an IP address of
[Link])?
Answer: A
Explanation: The `ip route [Link] [Link] [Link]` command is correct because it creates a
static default route, which matches all possible IPv4 addresses and forwards traffic for packets
that don't match a more specific route to a next-hop of [Link]. If a packet's destination IP
address matches an additional route in the IP routing table, that additional route will be used
instead of the static default route. This is due to the additional route having more specific route
information. This is an example of "The Longest Match Rule."
Q64. During an ARP poisoning attack, what kind of ARP messages does the attacker send to
inject themselves into the communication path?
A) DHCP Offers
B) Gratuitous ARP Replies
C) ARP Requests
D) Broadcast Frames
Answer: B
Explanation: During an ARP poisoning attack, an attacker sends unsolicited or gratuitous ARP
replies to associate their MAC address with the IP addresses of legitimate devices.
A) [Link]
B) [Link]
C) [Link]
D) [Link]
E) [Link]
Answer: C
Explanation: To meet the design requirements, four subnets must be created, and each subnet
must accommodate a maximum of 50 IP addresses.
We can begin by creating a listing of how many subnets are created from different numbers of
borrowed bits, using the formula:
Number of Subnets Created = 2^s, where s is the number of borrowed bits
Q66. You are tasked with configuring remote management access for a Cisco router in a highly
secure environment. Given the following requirements: encrypted communication, prevention
of password interception, and the ability to manage the device via the CLI and a web interface,
which combination of protocols should you use?
Answer: C
Explanation: In a highly secure environment, using SSH and HTTPS is the best combination for
remote management access. SSH provides encrypted communication for Command Line
Interface (CLI) access, preventing the interception of credentials and commands. HTTPS encrypts
the web interface traffic, ensuring that sensitive data transmitted between the client and the
router is secure. Telnet and HTTP do not provide encryption and are therefore not suitable for
secure environments.
Q67. How much space is found between channels 13 and 14 in the 2.4 Gigahertz (GHz) wireless
range?
A) 12 MHz
B) 5 MHz
C) 10 MHz
D) 1 MHz
Explanation: There are 14 channels designated in the 2.4 Gigahertz (GHz) wireless range.
Channels 1 through 13 have a space of 5 Megahertz (MHz) between them. The exception is the
space between channels 13 and 14, which is 12 MHz.
Q68. You have a Class C network with a default subnet mask of /24. If you apply a subnet mask
of /27 to this network, how many total subnets are created?
A) 2
B) 4
C) 8
D) 16
Answer: C
Explanation: By moving from a /24 to a /27 subnet mask, you are borrowing 3 bits for
subnetting (since 27 - 24 = 3). According to the formula: "Created Subnets = 2^s, where s is the
number of borrowed bits", the created subnets in this instance = 2^3 = 8.
Q69. Which command do you use in interface configuration mode a router to instruct the
interface to obtain its IP address via DHCP?
A) ip address dhcp
B) interface dhcp ip
C) ip address dynamic
D) interface dhcp
Answer: A
Explanation: The command `ip address dhcp` is used on a Cisco router to configure an interface
to obtain its IP address information dynamically from a DHCP server. This configuration is useful
for an interface that needs to learn its IP address from an Internet Service Provider (ISP).
A) Data Plane
B) Control Plane
C) Management Plane
D) Remote Plane
Answer: A
Explanation: The Data Plane is also referred to as the Forwarding Plane, responsible for
forwarding traffic to the next hop along the path to the destination based on control plane logic.
Q71. You are configuring a Cisco router to act as a DHCP server for a subnet with the network
address [Link] /24. You need to reserve the first 10 IP addresses for static assignments and
set the default gateway to [Link]. Which of the following correctly configures the DHCP
server?
A)
ip dhcp pool CLIENTS
network [Link] [Link]
default-router [Link]
B)
ip dhcp excluded-address [Link] [Link]
ip dhcp pool CLIENTS
network [Link] [Link]
default-router [Link]
C)
ip dhcp pool CLIENTS
network [Link] [Link]
excluded-address [Link] [Link]
default-router [Link]
D)
ip dhcp excluded-address [Link] [Link]
ip dhcp pool CLIENTS
network [Link] [Link]
default-router [Link]
Explanation: The correct configuration requires excluding the first 10 IP addresses from being
assigned by the DHCP server and setting the default gateway to [Link]. The command `ip
dhcp excluded-address [Link] [Link]` reserves the first 10 IP addresses for static
assignments, while the `ip dhcp pool CLIENTS` configuration sets up the DHCP pool for the
[Link] /24 subnet and specifies the default gateway as [Link]. Option B correctly
includes all necessary commands in the proper order.
Answer: B
Q73. As a network administrator, you are tasked with configuring your Cisco router to mitigate
Distributed Denial of Service (DDoS) attacks. Which of the following strategies might you
implement to better protect your network from DDoS attacks?
A) Enable and configure Access Control Lists (ACLs) to block traffic from known malicious IP
addresses.
B) Configure Network Address Translation (NAT) to hide internal IP addresses.
C) Set up DHCP snooping to prevent rogue DHCP servers.
D) Implement VLAN segmentation to separate different types of network traffic.
Answer: A
Explanation: To mitigate DDoS attacks, one effective strategy is to enable and configure Access
Control Lists (ACLs) to block traffic from known malicious IP addresses. ACLs can help filter out
unwanted traffic, reducing the impact of DDoS attacks on your network. While NAT, DHCP
Q74. Which best practice should be followed when placing a standard ACL in the network?
Answer: B
Explanation: Standard ACLs should be placed as close to the destination as possible to avoid
inadvertently blocking traffic that should be allowed to pass through the network. This helps
prevent premature packet drops and ensures that traffic can reach its intended destinations
before being filtered.
Q75. Which access point mode would you configure for access points at a remote office to keep
local data local, avoiding excessive WAN traffic?
A) Local Mode
B) FlexConnect Mode
C) Sniffer Mode
D) SE Connect Mode
Answer: B
Explanation: FlexConnect Mode allows access points (APs) at remote offices to keep local data
traffic local, reducing the need to send data over the WAN to a centralized WLAN controller.
This mode is beneficial in remote locations with limited WAN bandwidth. CAPWAP traffic sent
between a remote AP and a centralized WLAN controller, however, still crosses the WAN link.
Answer: D
Explanation: A Virtual Private Network (VPN) is crucial for ensuring secure communication
between a SOHO location and a main corporate office. VPN technology encrypts traffic between
these sites over the Internet, protecting sensitive information from eavesdropping. This secure
tunnel allows employees at the SOHO location to safely access corporate resources as if they
were directly connected to their main office network. The other options do not specifically
address the security of data communication between the SOHO location and a main corporate
office, making the VPN connection the most appropriate technology to implement for this
purpose.
Q77. Which first hop redundancy protocol makes use of all routers in the group, rather than
electing primary and secondary devices?
A) HSRP
B) GLBP
C) VRRP
D) MPLS
Answer: B
Explanation: Gateway Load Balancing Protocol (GLBP) is a Cisco proprietary protocol that offers
both redundancy and load balancing. This is performed by balancing traffic over multiple routers
using a single virtual IP address and multiple virtual MAC addresses.
Answer: B
Explanation: When a Layer 2 switch receives a frame destined for a MAC address that is not in
its MAC address table, it performs flooding. This means the switch forwards the frame out of all
ports except the one it was received on. This action ensures the frame has the best chance of
reaching its intended destination even when the switch does not yet know where that MAC
address resides. This process allows the switch to learn the location of MAC addresses over
time.
Q79. What phenomenon causes multimode delay distortion in Multimode Fiber (MMF) cabling,
potentially leading to data corruption over long distances?
Answer: D
Explanation: Multimode delay distortion in MMF cabling is caused by different paths (modes) of
light bouncing at varying angles within the core, leading to varying travel times for the light
signals. This can result in a situation where data bits arrive out of order, potentially corrupting
the data. This issue is specific to MMF due to its larger core diameter, which allows multiple
modes of light propagation, as opposed to Single-Mode Fiber (SMF), which only allows a single
mode (i.e., a single path of light), preventing this type of distortion.
Answer: C
Explanation: The command `switchport trunk allowed vlan 1,10,900` specifies which VLANs are
permitted to cross the trunk link, effectively pruning (excluding) all other VLANs. This ensures
that only traffic from VLANs 1, 10, and 900 is allowed, enhancing security by limiting access and
potentially improving network performance by reducing unnecessary traffic.
A) Bridge Priority
B) Hello Time
C) Port Cost
D) Aging Time
Answer: C
Explanation: From the topology, we can see that all of the links are Gigabit Ethernet links, which
have a default Port Cost of 4 (for the Short Path Cost method). From the output, we can see that
4 is the Port Cost of Gig 0/1 on SW1. However, the Port Cost for Gig 0/0 on SW1 has been
modified to have a value of 2, which is the default Port Cost for a Ten Gigabit Ethernet link.
A) Protect
B) Restrict
C) Shutdown
D) Drop
Explanation: The shutdown option is the default Port Security action taken during a violation.
This will put the interface into an error-disabled state and send an SNMP trap notification, if
configured for SNMP.
Q83. Which Cisco features allows us to mitigate CAM table overflow attacks?
A) STP
B) PortFast
C) ACL
D) Port Security
Answer: D
Explanation: In a CAM table overflow attack, frames are flooded into the network in an attempt
to fill up the CAM table with spoofed MAC addresses. The Port Security feature allows us to
specify the maximum number of MAC addresses that can be learned by a particular port.
Q84. In a network using IEEE 802.1Q trunking to interconnect switches, what happens to the
size of an Ethernet frame when VLAN tagging is applied?
A) It increases by 4 bytes.
B) It remains unchanged.
C) It decreases by 4 bytes.
D) The "frame" size is not impacted, because Tag bytes are applied at Layer 1.
Answer: A
Explanation: IEEE 802.1Q tagging adds an additional 4 bytes to the Ethernet frame to include
VLAN information, resulting in a slight increase in frame size. Despite this increase, such frames
are considered "baby giants" and are accepted by switches that support 802.1Q, thereby not
violating the typical MTU restrictions of Ethernet frames.
A) OID
B) Trap
C) MIB
D) Query
Answer: B
Explanation: SNMP trap messages are alert messages or notifications that are sent from a
remote SNMP-enabled device (referred to as an SNMP agent) to a central SNMP manager.
Q86. Which type of Access Control List (ACL) allows you to prioritize traffic by source port?
A) Standard
B) Extended
C) Named
D) Numbered
Answer: B
Explanation: A Standard ACL allows you to prioritize traffic by the source IP address only. An
Extended ACL provides greater control over which traffic is prioritized, using source and
destination IP addresses, source and destination TCP/UDP ports, and protocol ID.
Q87. In the context of IPv6 unique local addresses, what does the L bit signify when set to 1?
A) Multicast
B) Unicast
C) Anycast
D) None of the above
Answer: A
Explanation: In IPv6, the absence of a broadcast traffic type is mitigated by the enhanced
functionality of Multicast. Multicast allows for one-to-many communication, where a single
packet can be sent to multiple destinations (members of a multicast group) efficiently. This
serves the purposes previously fulfilled by broadcasting in IPv4, such as discovering devices or
services on the network, but in a more controlled and efficient manner.
A) 1 second
B) 3 seconds
C) 5 seconds
D) 10 seconds
Answer: A
Explanation: Instead of using a Hello message as HSRP does, this type of message in VRRP is
referred to as an Advertisement Interval. These advertisements are used to determine if the
master router is up and functioning and are sent every 1 second by default.
The prefix typically used for IPv6 unique local addresses is FC00::/7 . These addresses are intended for local communications within an organization and are not routable on the public Internet, providing a level of privacy similar to IPv4's RFC 1918 addresses .
A Switch Virtual Interface (SVI) is created on a Layer 3 switch to provide a routing interface for each VLAN. It is necessary for inter-VLAN communication because it allows the switch to route traffic between VLANs without the need for an external router, enabling devices in different VLANs to communicate .
EtherChannel aggregates multiple physical links into a single logical link, enhancing bandwidth and redundancy. It reduces the likelihood of network downtime since traffic can be rerouted through the remaining operational links if one fails. This setup optimizes load balancing and simplifies network management by reducing the number of IP addresses required for switches .
The IPv6 solicited-node multicast address functions as a replacement for IPv4's ARP by sending a multicast message to a group of devices, expecting a response only from the device with the matching IPv6 address. This method is efficient because it limits the traffic scope to only the relevant devices rather than broadcasting to all devices on the network, as ARP does .
A mesh WLAN design extends wireless coverage to remote areas by using mesh nodes that receive, regenerate, and transmit wireless signals. This setup allows the network to cover broader areas and reach places where laying Ethernet cables is impractical. The benefits include greater network flexibility, scalability, and potentially lower network setup costs .
The initial step in creating a 64-bit interface ID using the EUI-64 format from a 48-bit MAC address involves dividing the MAC address into two equal parts and inserting "FFFE" in the middle. This method is necessary because it extends the MAC address to 64 bits, ensuring uniqueness and compliance with IPv6 addressing standards .
IEEE 802.1Q VLAN tagging increases an Ethernet frame size by 4 bytes to include VLAN information. This means that when VLAN tagging is applied, switches must be capable of processing the increased frame size. The extra bytes allow for VLAN-specific traffic management and segregation, enhancing security and efficiency in network traffic handling .
Modifying the port cost in Spanning Tree Protocol (STP) can influence path selection decisions. Lowering the port cost makes a particular path more favorable for forwarding traffic, impacting how traffic flows through the network. Proper adjustment can optimize network efficiency, reduce congestion, and enhance redundancy in complex networks .
A link-local IPv6 address is automatically assigned to an interface and is only valid on the local network segment, making it useful for communication within a local link. In contrast, a global unicast IPv6 address is routable on the public Internet and is used for communication across different networks . Link-local addresses cannot be routed beyond the local link, while global unicast addresses can be used for broader internet communication.
The Stateless Address Autoconfiguration (SLAAC) process involves a device using its MAC address to generate a host identifier via the EUI-64 format, and a router advertisement provides the network prefix. This allows the device to independently configure its IPv6 address. SLAAC is beneficial because it doesn't require a DHCPv6 server, simplifying network configuration and management .