Download New Updated (Spring 2015) Cisco 400-101 Actual Tests 61-70

Ensurepass

 

QUESTION 61

What is a key advantage of Cisco GET VPN over DMVPN?

 

A.

Cisco GET VPN provides zero-touch deployment of IPSEC VPNs.

B.

Cisco GET VPN supports certificate authentication for tunnel establishment.

C.

Cisco GET VPN has a better anti-replay mechanism.

D.

Cisco GET VPN does not require a secondary overlay routing infrastructure.

 

Correct Answer: D

 

 

QUESTION 62

Refer to the exhibit. What is wrong with the configuration of the tunnel interface of this DMVPN Phase II spoke router?

 

clip_image001

 

A.

The interface MTU is too high.

B.

The tunnel destination is missing.

C.

The NHRP NHS IP address is wrong.

D.

The tunnel mode is wrong.

 

Correct Answer: D

 

 

QUESTION 63

Which two statements are true about VPLS? (Choose two.)

 

A.

It can work over any transport that can forward IP packets.

B.

It provides integrated mechanisms to maintain First Hop Resiliency Protocols such as HSRP, VRRP, or GLBP.

C.

It includes automatic detection of multihoming.

D.

It relies on flooding to propagate MAC address reachability information.

E.

It can carry a single VLAN per VPLS instance.

 

Correct Answer: DE

 

 

 

 

 

 

 

QUESTION 64

Refer to the exhibit. What will be the extended community value of this route?

 

clip_image002

 

A.

RT:200:3000 RT:200:9999

B.

RT:200:9999 RT:200:3000

C.

RT:200:3000

D.

RT:200:9999

 

Correct Answer: D

 

 

QUESTION 65

Refer to the exhibit. Which statement is true?

 

clip_image004

 

A.

There is an MPLS network that is running 6PE, and the ingress PE router has no mpls ip propagate-ttl.

B.

There is an MPLS network that is running 6VPE, and the ingress PE router has no mpls ip propagate-ttl.

C.

There is an MPLS network that is running 6PE or 6VPE, and the ingress PE router has mpls ip propagate-ttl.

D.

There is an MPLS network that is running 6PE, and the ingress PE router has mpls ip propagate-ttl.

E.

There is an MPLS network that is running 6VPE, and the ingress PE router has mpls ip propagate-ttl.

Correct Answer: C

 

 

QUESTION 66

Refer to the exhibit. Which statement is true about a VPNv4 prefix that is present in the routing table of vrf one and is advertised from this router?

 

clip_image005

 

A.

The prefix is advertised only with route target 100:1.

B.

The prefix is advertised with route targets 100:1 and 100:2.

C.

The prefix is advertised only with route target 100:3.

D.

The prefix is not advertised.

E.

The prefix is advertised with route targets 100:1, 100:2, and 100:3.

 

Correct Answer: A

 

 

QUESTION 67

Which is the way to enable the control word in an L2 VPN dynamic pseudowire connection on router R1?

 

A.

R1(config)# pseudowire-class cw-enable

R1(
config-pw-class)# encapsulation mpls

R1(config-pw-class)# set control-word

B.

R1(config)# pseudowire-class cw-enable

R1(config-pw-class)# encapsulation mpls

R1(config-pw-class)# enable control-word

C.

R1(config)# pseudowire-class cw-enable

R1(config-pw-class)# encapsulation mpls

R1(config-pw-class)# default control-word

D.

R1(config)# pseudowire-class cw-enable

R1(config-pw-class)# encapsulation mpls

R1(config-pw-class)# control-word

 

Correct Answer: D

 

 

 

QUESTION 68

What is the goal of Unicast Reverse Path Forwarding?

 

A.

to verify the reachability of the destination address in forwarded packets

B.

to help control network congestion

C.

to verify the reachability of the destination address in multicast packets

D.

to verify the reachability of the source address in forwarded packets

 

Correct Answer: D

 

 

QUESTION 69

Which three features are considered part of the IPv6 first-hop security suite? (Choose three.)

 

A.

DNS guard

B.

destination guard

C.

DHCP guard

D.

ICMP guard

E.

RA guard

F.

DoS guard

 

Correct Answer: BCE

 

 

QUESTION 70

Refer to the exhibit. Why is the router not accessible via Telnet on the GigabitEthernet0 management interface?

 

clip_image006

 

A.

The wrong port is being used in the telnet-acl access list.

B.

The subnet mask is incorrect in the telnet-acl access list.

C.

The log keyword needs to be removed from the telnet-acl access list..

D.

The access class needs to have the vrf-also keyword added.

 

Correct Answer:
D

 

Free VCE & PDF File for Cisco 400-101 Real Exam

Instant Access to Free VCE Files: CCNA | CCNP | CCIE …
Instant Access to Free PDF Files: CCNA | CCNP | CCIE …