Question 1:

An access switch has been configured with an EtherChannel port. After configuring SPAN to monitor this port, the network administrator notices that not all traffic is being replicated to the management server. What is a cause for this issue?

A. VLAN filters are required to ensure traffic mirrors effectively.

B. SPAN encapsulation replication must be enabled to capture EtherChannel destination traffic.

C. The port channel can be used as a SPAN source, but not a destination.

D. RSPAN must be used to capture EtherChannel bidirectional traffic.

Correct Answer: C

Explanation: A source port or EtherChannel is a port or EtherChannel monitored for traffic analysis. You can configure both Layer 2 and Layer 3 ports and EtherChannels as SPAN sources. SPAN can monitor one or more source ports or EtherChannels in a single SPAN session. You can configure ports or EtherChannels in any VLAN as SPAN sources. Trunk ports or EtherChannels can be configured as sources and mixed with nontrunk sources. A port-channel interface (an EtherChannel) can be a SPAN source, but not a destination. Reference: http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ ios/12- 2SX/configuration/guide/book/ span.html#wp1040905

Question 2:

After reviewing UDLD status on switch ports, an engineer notices that the.” Which statement describes what this indicates about the status of the port?

A. The port is fully operational and no known issues are detected.

B. The bidirectional status of “unknown” indicates that the port will go into the disabled state because it stopped receiving UDLD packets from its neighbor.

C. UDLD moved into aggressive mode after inconsistent acknowledgements were detected.

D. The UDLD port is placed in the “unknown” state for 5 seconds until the next UDLD packet is received on the interface.

Correct Answer: A

By default, UDLD is disabled on all interfaces. We can enable UDLD globally on the device, or individually on specific interfaces with the command udld port. This enables UDLD in normal mode. It would be prohibitively difficult to coordinate

the configuration of UDLD on both ends of a link at the same time, so when UDLD is first enabled and does not detect a neighbor the link state is considered unknown, which is not necessarily an error condition. The port will remain

operational during this time. When UDLD is finally enabled on the other end, the status will transition to bidirectional.

Reference: http://packetlife.net/blog/2011/mar/7/udld/

Question 3:

Which option lists the information that is contained in a Cisco Discovery Protocol advertisement?

A. native VLAN IDs, port-duplex, hardware platform

B. native VLAN IDs, port-duplex, memory errors

C. native VLAN IDs, memory errors, hardware platform

D. port-duplex, hardware platform, memory errors

Correct Answer: A

Type-Length-Value fields (TLVs) are blocks of information embedded in CDP advertisements. Table 21 summarizes the TLV definitions for CDP advertisements. Table 21 Type-Length-Value Definitions for CDPv2

TLV Definition Device-ID TLV Identifies the device name in the form of a character string. Address TLV Contains a list of network addresses of both receiving and sending devices. Port-ID TLV Identifies the port on which the CDP packet is sent. Capabilities TLV Describes the functional capability for the device in the form of a de- vice type, for example, a switch. Version TLV Contains information about the software release version on which the device is running. Platform TLV Describes the hardware platform name of the device, for example, Cisco 4500. IP Network Prefix Contains a list of network prefixes to which the sending device can TLV forward IP packets. This information is in the form of the interface

protocol and port number, for example, Eth 1/0.

VTP Management Advertises the system\’s configured VTP management domain name- Domain TLV string. Used by network operators to verify VTP domain configuration in adjacent network nodes. Native VLAN TLV Indicates, per interface, the assumed VLAN for untagged packets on the interface. CDP learns the native VLAN for an interface. This fea- ture is

implemented only for interfaces that support the IEEE 802.1Q protocol.

Full/Half Duplex Indicates status (duplex configuration) of CDP broadcast interface. TLV Used by network operators to diagnose connectivity problems be- tween adjacent network elements. Reference:


Question 4:

Which statement about the use of PAgP link aggregation on a Cisco switch that is running Cisco IOS Software is true?

A. PAgP modes are off, auto, desirable, and on. Only the combinations auto-desirable, desirable- desirable, and on-on allow the formation of a channel.

B. PAgP modes are active, desirable, and on. Only the combinations active-desirable, desirable- desirable, and on-on allow the formation of a channel.

C. PAgP modes are active, desirable, and on. Only the combinations active-active, desirable- desirable, and on-on allow the formation of a channel.

D. PAgP modes are off, active, desirable, and on. Only the combinations auto-auto, desirable- desirable, and on-on allow the formation of a channel.

Correct Answer: A

PAgP modes are off, auto, desirable, and on. Only the combinations auto-desirable, desirable- desirable, and on-on will allow a channel to be formed.

The PAgP modes are explained below.

1.on: PAgP will not run. The channel is forced to come up. 2.off: PAgP will not run. The channel is forced to remain down. 3.auto: PAgP is running passively. The formation of a channel is desired; however, it is not initiated. 4.desirable: PAgP

is running actively. The formation of a channel is desired and ini- tiated. Only the combinations of auto-desirable, desirable-desirable, and on-on will allow a channel to be formed. If a device on one side of the channel does not support PAgP,

such as a router, the device on the other side must have PAgP set to on.


Reference: http://www.cisco.com/c/en/us/support/docs/switches/catalyst-2900-xl-series- switches/21041- 131.html

Question 5:

Which command creates a login authentication method named “login” that will primarily use RADIUS and fail over to the local user database?

A. (config)# aaa authentication login default radius local

B. (config)# aaa authentication login login radius local

C. (config)# aaa authentication login default local radius

D. (config)# aaa authentication login radius local

Correct Answer: B

In the command “aaa authentication login login radius local” the second login is the name of the AAA method. It also lists radius first then local, so it will primarily use RADIUS for authentication and fail over to the local user database only if the RADIUS server is unreachable.

Question 6:

A network engineer configures port security and 802.1x on the same interface. Which option describes what this configuration allows?

A. It allows port security to secure the MAC address that 802.1x authenticates.

B. It allows port security to secure the IP address that 802.1x authenticates.

C. It allows 802.1x to secure the MAC address that port security authenticates.

D. It allows 802.1x to secure the IP address that port security authenticates.

Correct Answer: A

Explanation: 802.1X and Port Security You can configure port security and 802.1X on the same interfaces. Port security secures the MAC addresses that 802.1X authenticates. 802.1X processes packets before port security processes them, so when you enable both on an interface, 802.1X is already preventing inbound traffic on the interface from unknown MAC addresses. Reference: http://www.cisco.com/c/en/us/ td/docs/switches/datacenter/sw/4_1/nx- os/security/ configuration/ guide/sec_nx-os-cfg/sec_portsec.html

Question 7:

Which gateway role is responsible for answering ARP requests for the virtual IP address in GLBP?

A. active virtual forwarder

B. active virtual router

C. active virtual gateway D. designated router

Correct Answer: C

GLBP Active Virtual Gateway Members of a GLBP group elect one gateway to be the active virtual gateway (AVG) for that group. Other group members provide backup for the AVG in the event that the AVG becomes unavailable. The AVG assigns a virtual MAC address to each member of the GLBP group. Each gateway assumes responsibility for forwarding packets sent to the virtual MAC address assigned to it by the AVG. These gateways are known as active virtual forwarders (AVFs) for their virtual MAC address. The AVG is responsible for answering Address Resolution Protocol (ARP) requests for the virtual IP address. Load sharing is achieved by the AVG replying to the ARP requests with different virtual MAC addresses. Reference: http://www.cisco.com/en/US/docs/ios/12_2t/12_2t15/feature/ guide/ft_glbp.html

Question 8:

Which statement about the MAC address sticky entries in the switch when the copy run start command is entered is true?

A. A sticky MAC address is retained when the switch reboots.

B. A sticky MAC address can be a unicast or multicast address.

C. A sticky MAC address is lost when the switch reboots.

D. A sticky MAC address ages out of the MAC address table after 600 seconds.

Correct Answer: A

Question 9:

Refer to the exhibit.

Which configuration ensures that the Cisco Discovery Protocol packet update frequency sent from DSW1 to ALS1 is half of the default value?

A. DSW1(config)#cdp timer 90

B. DSW1(config-if)#cdp holdtime 60

C. DSW1(config)#cdp timer 30

D. DSW1(config)#cdp holdtime 90

E. DSW1(config-if)#cdp holdtime 30

F. DSW1(config-if)#cdp timer 60

Correct Answer: C

Question 10:

When a Layer 2 trunking EtherChannel is configured.which two attributes must match across the member ports?(choose two)

A. Spanning-tree priority

B. Spanning-tree cost

C. Interface description

D. Trunk mode

E. allow VLANs

Correct Answer: DE

Author: CertBus