ccna 4 discovery chapter 7

14
1 What OSI model Layer 2 security measure can a network engineer implement when prototyping network security? a firewall at the network edge port security at the access design layer port security at the distribution design layer IP access control lists at the access design layer 2 Refer to the exhibit. The redundant paths are of equal bandwidth and EIGRP is the routing protocol in use. Which statement describes the data flow from Server to PC2? EIGRP load balances across the R3 to R1 and R3 to R2 links. EIGRP load balances across the R1 to Switch3 and R2 to Switch3 paths. EIGRP load balances across the Switch1 to Switch3 and Switch1 to Switch2 paths. EIGRP does not load balance in this topology.

Upload: steve

Post on 10-Apr-2015

30.566 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: CCNA 4 Discovery Chapter 7

1

WhatOSImodelLayer2securitymeasurecananetworkengineerimplementwhenprototypingnetworksecurity?

afirewallatthenetworkedge

portsecurityattheaccessdesignlayer

portsecurityatthedistributiondesignlayer

IPaccesscontrollistsattheaccessdesignlayer

2

Refertotheexhibit.TheredundantpathsareofequalbandwidthandEIGRPistheroutingprotocolinuse.WhichstatementdescribesthedataflowfromServertoPC2?

EIGRPloadbalancesacrosstheR3toR1andR3toR2links.

EIGRPloadbalancesacrosstheR1toSwitch3andR2toSwitch3paths.

EIGRPloadbalancesacrosstheSwitch1toSwitch3andSwitch1toSwitch2paths.

EIGRPdoesnotloadbalanceinthistopology.

Page 2: CCNA 4 Discovery Chapter 7

3

SwitchportFa0/24waspreviouslyconfiguredasatrunk,butnowitistobeusedtoconnectahosttothenetwork.HowshouldthenetworkadministratorreconfigureswitchportFa0/24?

Usetheswitchportmodeaccesscommandfrominterfaceconfigurationmode.

Entertheswitchportnonegotiatecommandfrominterfaceconfigurationmode.

Administrativelyshutdownandre‐enabletheinterfacetoreturnittothedefault.

UsetheswitchportaccessvlanvlannumbercommandfrominterfaceconfigurationmodetoremovetheportfromthetrunkandaddittoaspecificVLAN.

4

Anetworkdesignermustprovidearationaletoacustomerforadesignwhichwillmoveanenterprisefromaflatnetworktopologytoahierarchicalnetworktopology.Whichtwofeaturesofthehierarchicaldesignmakeitthebetterchoice?(Choosetwo.)

lowerbandwidthrequirements

reducedcostforequipmentandusertraining

easiertoprovideredundantlinkstoensurehigheravailability

lessrequiredequipmenttoprovidethesameperformancelevels

abilitytoaddaccesslayermoduleswithoutaffectingexistingusers

Page 3: CCNA 4 Discovery Chapter 7

5

Whenaswitchportisrecoveringfromafailure,whichprotocolallowstheporttotransitiondirectlytotheforwardingstate?

BGP

HSRP

RSTP

VPN

VTP

6

Whichisthenextstepinevaluatingtheperformanceofanetworkoncetheprototypeisconfiguredandbasicconnectivityisverified?

Generatedifferenttraffictypestoseetheeffectsonperformance.

StarttestingatLayer2byverifyinglinkfailurerecovery.

Createanetworkbaseline.

Tracethepacketroutethroughthenetwork.

Page 4: CCNA 4 Discovery Chapter 7

7

Refertotheexhibit.Theusersonthe192.168.10.192networkarenotallowedInternetaccess.ThenetworkdesigncallsforanextendedACLtobedevelopedandtested.WhereshouldtheACLbeplacedfortheleasteffectonothernetworktraffic?

inboundonFa0/0ofR3

outboundonFa0/0ofR3

inboundonFa0/1ofR3

outboundonFa0/1ofR3

inboundonFa0/1ofR2

outboundonS0/0ofR2

8

Page 5: CCNA 4 Discovery Chapter 7

Refertotheexhibit.WhyareinterfacesFa0/11,Fa0/23,andFa0/24notshowninthisswitchoutput?

InterfacesFa0/11,Fa0/23,andFa0/24aretrunkports.

InterfacesFa0/11,Fa0/23,andFa0/24areshutdown.

InterfacesFa0/11,Fa0/23,andFa0/24areblocking.

InterfacesFa0/11,Fa0/23,andFa0/24faileddiagnostics.

9

WhenimplementingRSTP,whatisthedesignationforaportonanonrootswitchthatblockstheportfromforwarding?

alternate

backup

designated

root

Page 6: CCNA 4 Discovery Chapter 7

10

AnetworkdesignerneedstodetermineifaproposedIPaddressingschemeallowsefficientroutesummarizationandprovidestheappropriateamountofscalabilitytoadesign.WhatisusefulforvalidatingaproposedhierarchicalIPaddressingscheme?

NBAR

apilotnetwork

aroutesummary

anetworksimulator

aphysicaltopologymap

11

Refertotheexhibit.Anetworkadministratorhasbeengiventhetaskofcreatingadesignforatemporaryclassroombuildingthatistobesetupoutsideanovercrowdedschool.Intestingtheprototype,itisfoundthatthestudentPCcannotpingtheteacherPC.Alltheswitchinterfacesareactiveandconnectedproperly,asisinterfaceFa0/0oftherouter.Giventhatonlythecommandsshownhavebeenaddedtotherouterconfiguration,whatisthesourceoftheproblem?

TheIPsettingsonthestudentPCareincorrect.

ThedefaultgatewayontheteacherPCismisconfigured.

TherouterFa0/0interfacehasnotbeenconfiguredasaVLANtrunk.

TheFa0/0physicalinterfacehasnotbeenconfiguredwithanIPaddressandsubnetmask.

TheadministratorforgottoconfigurearoutingprotocoltoallowthepingpacketstoreachtheteacherPCsubnet.

Page 7: CCNA 4 Discovery Chapter 7

12

Whyisitimportanttorecordbaselinemeasurementsofaprototypenetwork?

Testresultsshowsecurityweaknessesafterthebaselinetestsarerun.

Thebaselineisthepointatwhichthenetworkisoperatingatitsfullestpotential.

Baselinemeasurementsdefineapointatwhichnetworktraffichasexceededthedesignedcapabilitiesofthenetwork.

Testresultsarecomparedtothebaselinetoseehowthetestconditionsincreaseprocessoruseordecreaseavailablebandwidth.

13

ForthemultipleteststhatarerequiredtocompleteaLANdesigntestplan,whichactionshouldbetakenasacomponentofeverytest?

VerifyphysicalandIPconnectivity.

DemonstratemultipleVLANs.

Documenttheoperation.

DemonstrateroutingoftrafficbetweenseparateVLANs.

Demonstrate802.1qtrunklinkoperation.

Page 8: CCNA 4 Discovery Chapter 7

14

Refertotheexhibit.Afteralltheinterfaceshavestabilized,whatisthespanning‐treestateofalltheenabledinterfacesofSW11?

discarding

forwarding

learning

listening

15

Anetworkengineerhasdecidedtopilottestaportionofanewnetworkdesignratherthanrelyonaprototypeforproof‐of‐concept.Whataretwoadvantagesofpilottestingadesignconcept?(Choosetwo.)

Thetestnetworkexperiencesreal‐worldnetworktraffic.

Userswithintheenterprisearenotaffectedbythetest.

Networkresponsecanbetestedinunplannedandunpredictablesituations.

Unlikelyfailureconditionscanbeconvenientlytested.

Networkresponsecanbetestedinahighlycontrolledsimulatedenvironment.

Page 9: CCNA 4 Discovery Chapter 7

16

Refertotheexhibit.Intheroutercommandencapsulationdot1q10,whatdoesthenumber10represent?

themetricthatisusedforaparticularroute

thenumberthatmustmatchtheFastEthernetsubinterfacenumber

theprioritynumberthatisgiventothedevicefortheelectionprocess

theidentifieroftheVLANthatisassociatedwiththeencapsulatedsubinterface

thenumberthatisusedtoprogramtherouterforunequal‐costpathloadbalancing

17

Whilepreparinganetworktestplandocument,anetworkdesignerrecordsallinitialandmodifieddeviceconfigurations.Whichsectionofthedocumenttypicallycontainsthisinformation?

Appendix

TestProcedures

TestDescription

ActualResultsandConclusions

AnticipatedResultsandSuccessCriteria

Page 10: CCNA 4 Discovery Chapter 7

18

WhatRapidSpanningTreeProtocol(RSTP)stateisgiventotheforwardingportelectedforeveryswitchedEthernetLANsegment?

root

backup

alternate

designated

19

Howdodesignersdecidewhichnetworkfunctionsneedtobeincludedintheprototypetest?

Theyselectthefunctionsthatalignwiththebusinessgoals.

Theyselectthefunctionsthatoccuratthenetworkcore.

Theyselectthefunctionsthatdonotexistintheexistingnetwork.

Theyselectthefunctionsfromalistofgenericnetworkoperation

Page 11: CCNA 4 Discovery Chapter 7

20

Refertotheexhibit.Duringprototyping,Layer2functionalityisbeingtested.Basedontheoutputshown,whichtwopiecesofinformationcanbedetermined?(Choosetwo.)

Switch1istherootbridge.

InterfaceFa0/2onSwitch1hasnoroleintheoperationofspanningtree.

InterfaceFa0/2onSwitch1isthealternateportusedtoreachtherootbridge.

Basedontheentriesinthe"Role"column,itcanbeconcludedthatRSTPhasbeenimplemented.

InterfaceFa0/1onSwitch1istheforwardingportselectedfortheentirespanning‐treetopology.

Page 12: CCNA 4 Discovery Chapter 7

21

Refertotheexhibit.Whattwomeasurescanbetakentoaddresstheareasofweaknesscircledinthenetworkdesign?(Choosetwo.)

Provideredundantconnectionstoallendusers.

Addanothercoreswitchtoincreaseredundancy.

Addaswitchintheserverblockconnectingtheserverfarmtoeachcoreswitch.

AddanadditionalswitchtotheDMZanddirectlinksfromthenewswitchtothecoreswitches.

ProvidearedundantfirewallrouterconnectingtoasecondISP,thecoreswitches,andtheDMZ.

Page 13: CCNA 4 Discovery Chapter 7

22

Refertotheexhibit.Anetworkdesignercreatesatestplanthatincludesthespecificationshown.Inwhichsectionofthetestplanwouldthisspecificationbefound?

TestDescription

TestProcedures

DesignandTopologyDiagram

ActualResultsandConclusions

AnticipatedResultsandSuccessCriteria

23

Refertotheexhibit.DuringprototypetestingoftheCisconetworkshown,connectivitymustbeverified.AssumingallconnectionsareworkingandCDPisenabledonalldevicesandinterfaces,onwhichdevicewasthecommandissued?

R1

S1

R3

S2

R5

S3

Page 14: CCNA 4 Discovery Chapter 7

24

Refertotheexhibit.Anetworktechnicianisperforminganinitialinstallationofanewswitchintheeastwing.Thetechnicianremovestheswitchfromthebox,makestheconnectionstothenetwork,andaddstheconfigurationshown.Thetechniciannotifiesthenetworkadministratorthattheswitchhasbeeninstalled.Whenthenetworkadministratoratthehomeofficeattemptstotelnettotheswitchfromhost192.168.0.1,theconnectionfails.Whatactionshouldthenetworktechniciantake?

Addanenablepasswordtotheswitch.

Addadefaultgatewaytotheswitchconfiguration.

ConfiguretheswitchwithanIPaccesslisttopermitthehostconnection.

Enablethephysicalinterfacesoftheswitchwiththenoshutdowncommand.