CCNA 4 V6 Final Exam
CCNA 4 V6 Final Exam
CCNA 4 V6 Final Exam
2. Connecting offices at different locations using the Internet can be economical for a
business. What are two important business policy issues that should be addressed
when using the Internet for this purpose? (Choose two.)addressingbandwidth
privacy*
security*
WAN technology
higher latency*
4. A company is considering updating the campus WAN connection. Which two WAN
options are examples of the private WAN architecture? (Choose two.)cableleased
line*
Ethernet WAN*
municipal Wi-Fi
6. Which WAN technology can serve as the underlying network to carry multiple
types of network traffic such as IP, ATM, Ethernet, and DSL?ISDNMPLS*
Frame Relay
Ethernet WAN
7. Which two WAN technologies are more likely to be used by a business than by
teleworkers or home users? (Choose two.)cableDSL
Frame Relay*
MetroE*
VPN
8. The security policy in a company specifies that the staff in the sales department
must use a VPN to connect to the corporate network to access the sales data when
they travel to meet customers. What component is needed by the sales staff to
establish a remote VPN connection?VPN gatewayVPN appliance
VPN concentrator
creating one logical link between two LAN switches via the use of multiple physical
links
11. Refer to the exhibit. A network administrator is configuring the PPP link between
the routers R1 and R2. However, the link cannot be established. Based on the
partial output of the show running-config command, what is the cause of the
problem? The
usernames do not match each other.
The usernames do not match the host names.*
The passwords for CHAP should be in lowercase.
The username r1 should be configured on the router R1 and the username r2 should be
configured on the router R2.
12. Refer to the exhibit. A network administrator has configured routers RTA and
RTB, but cannot ping from serial interface to serial interface. Which layer of the
OSI model is the most likely cause of the problem?
application
transport
network
data link*
physical
13. What advantage does DSL have compared to cable technology?DSL upload and
download speeds are always the same.DSL is faster.
DSL has no distance limitations.
16. Refer to the exhibit. What is the network administrator verifying when issuing the
show ip interface brief command on R1 in respect to the PPPoE connection to R2?
that the Dialer1 interface has been manually assigned an IP address
that the Dialer1 interface is up and up
that the Dialer1 interface has been assigned an IP address by the ISP router*
that the IP address on R1 G0/1 is in the same network range as the DSL modem
17. Which technology creates a mapping of public IP addresses for remote tunnel
spokes in a DMVPN configuration?ARPNHRP*
NAT
IPsec
18. What is the purpose of the generic routing encapsulation tunneling protocol?to
provide packet level encryption of IP traffic between remote sitesto manage the
transportation of IP multicast and multiprotocol traffic between remote sites*
to support basic unencrypted IP tunneling using multivendor routers between remote
sites
19. Refer to the exhibit. What is used to exchange routing information between routers
within each AS?
static routing
IGP routing protocols*
EGP routing protocols
default routing
20. Which IPv4 address range covers all IP addresses that match the ACL filter
specified by 172.16.2.0 with wildcard mask 0.0.1.255?172.16.2.0 to
172.16.2.255172.16.2.1 to 172.16.3.254
172.16.2.0 to 172.16.3.255*
172.16.2.1 to 172.16.255.255
21. Refer to the exhibit. A named access list called chemistry_block has been written to
prevent users on the Chemistry Network and public Internet from access to
Records Server. All other users within the school should have access to this server.
The list contains the following statements:deny 172.16.102.0 0.0.0.255
172.16.104.252 0.0.0.0permit 172.16.0.0 0.0.255.255 172.16.104.252 0.0.0.0Which
command sequence will place this list to meet these requirements?
Hera(config)# interface fa0/0
Hera(config-if)# ip access-group chemistry_block in
23. In the creation of an IPv6 ACL, what is the purpose of the implicit final command
entries, permit icmp any any nd-na and permit icmp any any nd-ns?to allow IPv6 to
MAC address resolution*to allow forwarding of IPv6 multicast packets
to allow automatic address configuration
ARP
28. Which term describes the role of a Cisco switch in the 802.1X port-based access
control?agentsupplicant
authenticator*
authentication server
29. What two protocols are supported on Cisco devices for AAA communications?
(Choose two.)
VTPLLDPHSRP
RADIUS*
TACACS+*
30. In configuring SNMPv3, what is the purpose of creating an ACL?to define the
source traffic that is allowed to create a VPN tunnelto define the type of traffic that is
allowed on the management network
to specify the source addresses allowed to access the SNMP agent*
to define the protocols allowed to be used for authentication and encryption
31. Refer to the exhibit. What feature does an SNMP manager need in order to be able
to set a parameter on switch ACSw1?
a
manager who is using an SNMP string of K44p0ut
a manager who is using an Inform Request MIB
32. Which Cisco feature sends copies of frames entering one port to a different port on
the same switch in order to perform traffic analysis?CSAHIPS
SPAN*
VLAN
33. What are two characteristics of video traffic? (Choose two.)Video traffic is more
resilient to loss than voice traffic is.Video traffic is unpredictable and inconsistent.*
Video traffic latency should not exceed 400 ms.*
Video traffic requires a minimum of 30 kbs of bandwidth.
Video traffic consumes less network resources than voice traffic consumes.
34. Which QoS mechanism allows delay-sensitive data, such as voice, to be sent first
before packets in other queues are sent?CBWFQFIFO
LLQ*
FCFS
35. Refer to the exhibit. As traffic is forwarded out an egress interface with QoS
treatment, which congestion avoidance technique is used?
traffic shaping*
weighted random early detection
traffic policing
IP precedence
37. What is the function of a QoS trust boundary?A trust boundary identifies the location
where traffic cannot be remarked.A trust boundary identifies which devices trust the
marking on packets that enter a network.*
A trust boundary only allows traffic to enter if it has previously been marked.
A trust boundary only allows traffic from trusted endpoints to enter the network.
people-to-machine
39. Which pillar of the Cisco IoT System allows data to be analyzed and managed at
the location where it is generated?data analyticsfog computing*
network connectivity
40. Which Cloud computing service would be best for a new organization that cannot
afford physical servers and networking equipment and must purchase network
services on-demand?PaaSSaaS
ITaaS
IaaS*
41. A data center has recently updated a physical server to host multiple operating
systems on a single CPU. The data center can now provide each customer with a
separate web server without having to allocate an actual discrete server for each
customer. What is the networking trend that is being implemented by the data
center in this situation?BYODvirtualization*
maintaining communication integrity
online collaboration
42. What is used to pre-populate the adjacency table on Cisco devices that use CEF to
process packets?the ARP table*the routing table
the FIB
the DSP
43. Which component of the ACI architecture translates application policies into
network programming?the Nexus 9000 switchthe Application Network Profile
endpoints
the Application Policy Infrastructure Controller*
the hypervisor
44. Which two pieces of information should be included in a logical topology diagram
of a network? (Choose two.)device typeOS/IOS version
connection type*
interface identifier*
cable specification
45. Which network performance statistics should be measured in order to verify SLA
compliance?NAT translation statisticsdevice CPU and memory utilization
latency, jitter, and packet loss*
the number of error messages that are logged on the syslog server
46. Which feature sends simulated data across the network and measures performance
between multiple network locations?LLDPIP SLA*
syslog
SPAN
47. Which troubleshooting tool would a network administrator use to check the Layer
2 header of frames that are leaving a particular host?protocol analyzer*baselining
tool
knowledge base
CiscoView
48. Refer to the exhibit. A network administrator is troubleshooting the OSPF network.
The 10.10.0.0/16 network is not showing up in the routing table of Router1. What is
the probable cause of this problem?
CCNA4 v6.0 Final Exam 011
The serial interface on Router2 is down.
51. What are two types of WAN providers? (Choose two.)DNS serverssatellite service*
web hosting service
telephone company*
Internet search engine service
52. Which two types of devices are specific to WAN environments and are not found on
a LAN? (Choose two.)access layer switchbroadband modem*
core switch
CSU/DSU*
distribution layer router
55. Which WAN solution uses labels to identify the path in sending packets through a
provider network?cableDSLFrame Relay
MPLS*
VSAT
56. An intercity bus company wants to offer constant Internet connectivity to the users
traveling on the buses. Which two types of WAN infrastructure would meet the
requirements? (Choose two.)private infrastructurepublic infrastructure*
dedicated
circuit-switched
cellular*
57. What device is needed at a central office to aggregate many digital subscriber lines
from customers?CMTSDSLAM*
CSU/DSU
access server
58. A corporation is searching for an easy and low cost solution to provide teleworkers
with a secure connection to headquarters. Which solution should be selected?dial-up
connectionleased line connection
site-to-site VPN over the Internet
60. Refer to the exhibit. What type of Layer 2 encapsulation will be used for RtrA
connection D if it is left to the default and the router is a Cisco router?
Ethernet
Frame Relay
HDLC*
PPP
61. Which two functions are provided by the NCP during a PPP connection? (Choose
two.)identifying fault conditions for the PPP linkproviding multilink capabilities over the
PPP linkbringing the network layer protocol or protocols up and down*
enhancing security by providing callback over PPP
62. What PPP information will be displayed if a network engineer issues the show ppp
multilink command on Cisco router?the link LCP and NCP statusthe queuing type on
the link
the IP addresses of the link interfaces
Only the
link-establishment phase completed successfully.
Only the network-layer phase completed successfully.
The PPP link will not be established if more than 30 percent of options cannot be
accepted.
65. How does virtualization help with disaster recovery within a data center?Power is
always provided.Less energy is consumed.
Server provisioning is faster.
ADSL
67. What is the protocol that provides ISPs the ability to send PPP frames over DSL
networks?PPPoE*CHAP
ADSL
LTE
68. In software defined network architecture, what function is removed from network
devices and performed by an SDN controller?control plane*data plane
security
application policies
69. What would a network administrator expect the routing table of stub router R1 to
look like if connectivity to the ISP was established via a PPPoE
configuration?192.168.1.0/32 is subnetted, 2 subnetted
C 192.168.1.1 is directly connected, Dialer1
C 192.168.1.2 is directly connected, Dialer2S* 0.0.0.0/0 is directly connected,
Dialer1192.168.1.0/32 is subnetted, 2 subnetted
C 192.168.1.1 is directly connected, Dialer
S* 0.0.0.0/0 is directly connected, Dialer1
192.168.1.0/32 is subnetted, 2 subnetted
C 192.168.1.1 is directly connected, Dialer1
C 192.168.1.2 is directly connected, Dialer1*
70. What is a benefit of implementing a Dynamic Multipoint VPN network design?A
DMVPN will use an encrypted session and does not require IPsec.A DMVPN uses a
Layer 3 protocol, NHRP, to dynamically establish tunnels.
A DMVPN will support remote peers by providing a mapping database of public IP
addresses to each one.*
A DMVPN uses mGRE to create multiple GRE interfaces that each support a single
VPN tunnel.
71. Which remote access implementation scenario will support the use of generic
routing encapsulation tunneling?a mobile user who connects to a router ata central
sitea branch office that connects securely to a central site
a mobile user who connects to a SOHO site
4*
5
They can be configured to filter traffic based on both source IP addresses and source
ports.
74. Which three values or sets of values are included when creating an extended access
control list entry? (Choose three.)access list number between 1 and 99access list
number between 100 and 199*
default gateway address and wildcard mask
75. Refer to the exhibit. A router has an existing ACL that permits all traffic from the
172.16.0.0 network. The administrator attempts to add a new ACE to the ACL that
denies packets from host 172.16.0.1 and receives the error message that is shown in
the exhibit. What action can the administrator take to block packets from host
172.16.0.1 while still permitting all other traffic from the 172.16.0.0 network?
Manually add the new deny ACE with a sequence number of 5.*
Manually add the new deny ACE with a sequence number of 15.
Create a second access list denying the host and apply it to the same interface.
76. Which three implicit access control entries are automatically added to the end of an
IPv6 ACL? (Choose three.)deny ip any anydeny ipv6 any any*
permit ipv6 any any
ip access-group 5 in
79. What would be the primary reason an attacker would launch a MAC address
overflow attack?so that the switch stops forwarding trafficso that legitimate hosts
cannot obtain a MAC address
so that the attacker can see frames that are destined for other hosts*
so that the attacker can execute arbitrary code on the switch
80. What are three of the six core components in the Cisco IoT system? (Choose
three.)fog computing*wearable technologies
data analytics*
robot guides
81. What security countermeasure is effective for preventing CAM table overflow
attacks?
port security*DHCP snoopingIP source guard
Dynamic ARP Inspection
82. Which SNMP feature provides a solution to the main disadvantage of SNMP
polling?SNMP set messagesSNMP trap messages*
SNMP get messages
83. When SNMPv1 or SNMPv2 is being used, which feature provides secure access to
MIB objects?packet encryptionmessage integrity
community strings*
source validation
features
84. What two are added in SNMPv3 to address the weaknesses of previous versions of
SNMP? (Choose two.)bulk MIB objects retrievalencryption*
authorization with community string priority
authentication*
ACL management filtering
FCFS
86. Which field is used to mark Layer 2 Ethernet frames for QoS treatment?Type of
Service fieldTraffic Class field
Priority field*
Version field
89. A network technician made a configuration change on the core router in order to
solve a problem. However, the problem is not solved. Which step should the
technician take next?Gather symptoms.Isolate the problem.
Restore the previous configuration.*
Implement the next possible corrective action.
90. A user reports that when the corporate web page URL is entered on a web browser,
an error message indicates that the page cannot be displayed. The help-desk
technician asks the user to enter the IP address of the web server to see if the page
can be displayed. Which troubleshooting method is being used by the
technician?top-downbottom-up
substitution
divide-and-conquer*
91. What is a primary function of the Cisco IOS IP Service Level Agreements feature?
to detect potential network attacksto provide network connectivity for customersto adjust
network device configurations to avoid congestion
to measure network performance and discover a network failure as early as
possible*
92. Which IOS log message level indicates the highest severity level?level 0*level 1
level 4
level 7
94. Refer to the exhibit. H1 can only ping H2, H3, and the Fa0/0 interface of router R1.
H2 and H3 can ping H4 and H5. Why might H1 not be able to successfully ping H4
and H5?
Router R1 does not have a route to the destination network.
Switch S1 does not have an IP address configured.
95. Refer to the exhibit. On the basis of the output, which two statements about
network connectivity are correct? (Choose two.)
There is
connectivity between this device and the device at 192.168.100.1.*
The connectivity between these two hosts allows for videoconferencing calls.
There are 4 hops between this device and the device at 192.168.100.1.*
The average transmission time between the two hosts is 2 milliseconds.
96. Fill in the blanks. Use dotted decimal format.The wildcard mask that is associated
with 128.165.216.0/23 is 0.0.1.255
97. Match the characteristic to the appropriate authentication protocol. (Not all options
are used.)
98. Match the term to the description. (Not all options are used.)
99. What is a primary difference between a company LAN and the WAN services that
it uses?The company must subscribe to an external WAN service provider.*The
company has direct control over its WAN links but not over its LAN.
Each LAN has a specified demarcation point to clearly separate access layer and
distribution layer equipment.
The LAN may use a number of different network access layer standards whereas the
WAN will use only one standard.
100. To which two layers of the OSI model do WAN technologies provide services?
(Choose two.)network layersession layerphysical layer*
transport layer
101. Which two technologies are private WAN technologies? (Choose two.)cableFrame
Relay*
DSL
ATM*
cellular
102. Which WAN technology can switch any type of payload based on labels?PSTNDSL
MPLS*
T1/E1
103. What technology can be used to create a private WAN via satellite
communications?VPN3G/4G cellular
dialup
VSAT*
WiMAX
104. Which public WAN access technology utilizes copper telephone lines to provide
access to subscribers that are multiplexed into a single T3 link
connection?ISDNDSL*
dialup
cable
105. How many DS0 channels are bounded to produce a 1.544 Mb/s DS1 line?
21224*
28
106. Refer to the exhibit. Communication between two peers has failed. Based on the
output that is shown, what is the most likely cause?
interface reset
unplugged cable
PPP issue*
107. Refer to the exhibit. Which type of Layer 2 encapsulation used for connection D
requires Cisco routers?
Ethernet
PPPoE
HDLC*
PPP
108. Which three statements are true about PPP? (Choose three.)PPP can use
synchronous and asynchronous circuits.*PPP can only be used between two Cisco
devices.
PPP carries packets from several network layer protocols in LCPs.
PPP uses LCPs to establish, configure, and test the data-link connection.*
PPP uses LCPs to agree on format options such as authentication, compression, and
error detection.*
109. A network administrator is evaluating authentication protocols for a PPP link.
Which three factors might lead to the selection of CHAP over PAP as the
authentication protocol? (Choose three.)establishes identities with a two-way
handshakeuses a three-way authentication periodically during the session to
reconfirm identities*
control by the remote host of the frequency and timing of login events
UMTS
111. A company is looking for the least expensive broadband solution that provides at
least 10 Mb/s download speed. The company is located 5 miles from the nearest
provider. Which broadband solution would be appropriate?satelliteDSL
WiMax
cable*
112. Which technology can ISPs use to periodically challenge broadband customers
over DSL networks with PPPoE?PAPCHAP*
HDLC
Frame Relay
113. What are the three core components of the Cisco ACI architecture? (Choose
three.)Application Network Profile*Application Policy Infrastructure Controller*
Cisco Nexus Switches*
Microsoft hypervisor
115. What are three features of a GRE tunnel? (Choose three.)creates nonsecure
tunnels between remote sites*transports multiple Layer 3 protocols*
creates additional packet overhead*
uses RSA signatures to authenticate peeers
supports hosts as GRE tunnel endpoints by installing Cisco VPN client software
116. Refer to the exhibit. What two commands are needed to complete the GRE tunnel
configuration on router R1? (Choose two.)
117. What does BGP use to exchange routing updates with neighbors?TCP
connections*area numbers
group identification numbers
hellos
118. Refer to the exhibit. The network administrator that has the IP address of
10.0.70.23/25 needs to have access to the corporate FTP server (10.0.54.5/28). The
FTP server is also a web server that is accessible to all internal employees on
networks within the 10.x.x.x address. No other traffic should be allowed to this
server. Which extended ACL would be used to filter this traffic, and how would this
ACL be applied? (Choose two.)
119. Refer to the exhibit. A router has an existing ACL that permits all traffic from the
172.16.0.0 network. The administrator attempts to add a new statement to the ACL
that denies packets from host 172.16.0.1 and receives the error message that is
shown in the exhibit. What action can the administrator take to block packets from
host 172.16.0.1 while still permitting all other traffic from the 172.16.0.0 network?
Create a second access list denying the host and apply it to the same interface.
120. Refer to the exhibit. What can be determined from this output?
The ACL is only monitoring traffic destined for 10.23.77.101 from three specific hosts.
The router has not had any Telnet packets from 10.35.80.22 that are destined for
10.23.77.101.*
121. What is the only type of ACL available for IPv6?named standardnamed extended*
numbered standard
numbered extended
122. Which IPv6 ACL command entry will permit traffic from any host to an SMTP
server on network 2001:DB8:10:10::/64?permit tcp any host 2001:DB8:10:10::100
eq 25*permit tcp host 2001:DB8:10:10::100 any eq 25
permit tcp any host 2001:DB8:10:10::100 eq 23
123. Refer to the exhibit. Considering how packets are processed on a router that is
configured with ACLs, what is the correct order of the statements?
C-B-A-
D
A-B-C-D
C-B-D-A*
B-A-D-C
D-A-C-B
124. Which two hypervisors are suitable to support virtual machines in a data center?
(Choose two.)Virtual PCVMware FusionVMware ESX/ESXi*
Oracle VM VirtualBox
125. How can DHCP spoofing attacks be mitigated?by disabling DTP negotiations on
nontrunking portsby implementing DHCP snooping on trusted ports*
by implementing port security
126. What action can a network administrator take to help mitigate the threat of
VLAN attacks?Disable VTP.Configure all switch ports to be members of VLAN 1.
Disable automatic trunking negotiation.*
Enable PortFast on all switch ports.
127. Which SNMP message type informs the network management system (NMS)
immediately of certain specified events?
GET requestSET requestGET response
Trap*
128. Refer to the exhibit. A SNMP manager is using the community string of
snmpenable and is configured with the IP address 172.16.10.1. The SNMP manager
is unable to read configuration variables on the R1 SNMP agent. What could be the
problem?
129. Refer to the exhibit. Which SNMP authentication password must be used by the
member of the ADMIN group that is configured on router R1?
cisco54321
cisco98765
cisco123456*
cisco654321
130. A network administrator has noticed an unusual amount of traffic being received
on a switch port that is connected to a college classroom computer. Which tool
would the administrator use to make the suspicious traffic available for analysis at
the college data center?RSPAN*TACACS+
802.1X
DHCP snooping
SNMP
131. What network monitoring tool copies traffic moving through one switch port, and
sends the copied traffic to another switch port for analysis?802.1XSNMP
SPAN*
syslog
132. Voice packets are being received in a continuous stream by an IP phone, but
because of network congestion the delay between each packet varies and is causing
broken conversations. What term describes the cause of this condition?
bufferinglatencyqueuing
jitter*
133. What mechanism compensates for jitter in an audio stream by buffering packets
and then replaying them outbound in a steady stream?digital signal
processorplayout delay buffer*
voice codec
WFQ
134. Which type of network traffic cannot be managed using congestion avoidance
tools?TCPUDP*
IP
ICMP
135. A network administrator has moved the company intranet web server from a
switch port to a dedicated router interface. How can the administrator determine
how this change has affected performance and availability on the company
intranet?Conduct a performance test and compare with the baseline that was
established previously.*Determine performance on the intranet by monitoring load
times of company web pages from remote sites.
Interview departmental administrative assistants to determine if web pages are loading
more quickly.
Compare the hit counts on the company web server for the current week to the values
that were recorded in previous weeks.
136. In which stage of the troubleshooting process would ownership be researched and
documented?Gather symptoms.*Implement corrective action.
Isolate the problem.
an approach that starts with the end-user applications and moves down through the layers
of the OSI model until the cause of the problem has been identified
138. A router has been configured to use simulated network traffic in order to monitor
the network performance between the router and a distant network device. Which
command would display the results of this analysis?show ip routeshowip protocols
show ip sla statistics*
show monitor
139. Which type of tool would an administrator use to capture packets that are going to
and from a particular device?NMS toolknowledge base
baselining tool
protocol analyzer*
140. Refer to the exhibit. Which two statements describe the results of entering these