Question No. 1

You want to configure port security on an interface. Which two tasks must you perform? (Choose two)

Answer: C, D

Question No. 2

Which command enables you to determine the spanning-tree guard features that are enabled globally?

Answer: B, D

Question No. 3

SIMULATION is an IT company that has an existing enterprise network comprised of two layer 2 only switches; DSW1 and ASW1. The topology diagram indicates their layer 2 mapping. VLAN 20 is a new VLAN that will be used to provide the shipping personnel access to the server. Corporate polices do not allow layer 3 functionality to be enabled on the switches. For security reasons, it is necessary to restrict access to VLAN 20 in the following manner:

* Users connecting to VLAN 20 via portfO/1 on ASW1 must be authenticated before they are given access to the network. Authentication is to be done via a Radius server:

* Radius server host:

* Radius key: rad123

* Authentication should be implemented as close to the host as possible.

* Devices on VLAN 20 are restricted to the subnet of

* Packets from devices in the subnet of should be allowed on VLAN 20.

* Packets from devices in any other address range should be dropped on VLAN 20.

* Filtering should be implemented as close to the serverfarm as possible.

The Radius server and application servers will be installed at a future date. You have been tasked with implementing the above access control as a pre-condition to installing the servers. You must use the available IOS switch features.

Answer: A

Question No. 4

A network engineer is installing a switch for temporary workers to connect to. The engineer does not want this switch participating in Spanning Tree with the rest of the network; however, end user connectivity is still required. Which spanning-tree feature accomplishes this?

Answer: B

Question No. 5

Your company wants to connect an internal switch to the uplink provider switch.

What method / feature / functions you need to enable to prevent initial / potential

broadcast of internal information/topology?

Answer: A

Question No. 6

Which configuration do you apply to an interface so that a host can be placed into VLAN 593?

Answer: A

Question No. 7

An engineer is configuring an EtherChannel between two switches using LACP. If the EtherChannel mode on switch 1 is configured to active, which two modes on switch 2 establish an operational EtherChannel? (Choose two.)

Answer: A, E

Question No. 8

Refer to the exhibit.

A single server in Company ABC is connected via EtherChannel to a single upstream Layer 2 switch. Which EtherChannel load balancing methods on the switch make optimal use of the redundant links as traffic flows from the router that is the default gateway to the server?

Answer: C

Question No. 9

When a private VLAN is configured, which mode must be configured as a router facing port?

Answer: B

Question No. 10

Which VLAN range is eligible to be pruned when a network engineer enables VTP pruning on a switch?

Answer: C

Question No. 11

Which statement about Layer 2 protocol participation of ports involved m a SPAN session is true?

Answer: C

Question No. 12

Which two statements about VTP modes are true? (Choose two )

Answer: A, B

Question No. 13

An access switch at a remote location is connected to the spanning-tree root with redundant uplinks. A network engineer notices that there are issues with the physical cabling of the current root port. The engineer decides to force the secondary link to be the desired forwarding root port.

Which action accomplishes this task?

Answer: C

Question No. 14

Which option is a benefit of configuring UDLD on a link between two switches?

Answer: B

