QUESTION 671
Drag the actions on the left to the correct order on the right when doing outside-to-inside NAT translation.
Correct Answer:
QUESTION 672
Drag the statements on the left to the correct OSPF network type on the right.
Correct Answer:
QUESTION 673
What is the purpose of an explicit “deny any” statement at the end of an ACL?
A. |
none, since it is implicit |
B. |
to enable Cisco lOS IPS to work properly; however, it is the deny all traffic entry that is actually required |
C. |
to enable Cisco lOS Firewall to work properly; however, it is the deny all traffic entry that is actually required |
D. |
to allow the log option to be used to log any matches |
E. |
to prevent sync flood attacks |
F. |
to prevent half-opened TCP connections |
Correct Answer: D
QUESTION 674
Which of these is mandatory when configuring Cisco IOS Firewall?
A. |
Cisco IOS IPS enabled on the untrusted interface |
B. |
NBAR enabled to perform protocol discovery and deep packet inspection |
C. |
a route map to define the trusted outgoing traffic |
D. |
a route map to define the application inspection rules |
E. |
an inbound extended ACL applied to the untrusted interface |
Correct Answer: E
QUESTION 675
Which statement correctly describes the disabling of IP TTL propagation in an MPLS network?
A. |
The TTL field from the IP packet is copied into the TTL field of the MPLS label header at the ingress edge LSR. |
B. |
TTL propagation cannot be disabled in an MPLS domain. |
C. |
TTL propagation is only disabled on the ingress edge LSR. |
D. |
The TTL field of the MPLS label header is set to 255. |
E. |
The TTL field of the IP packet is set to 0. |
Correct Answer: D
QUESTION 676
Two routers configured to run BGP have been connected to a firewall, one on the inside interface and one on the outside interface. BGP has been configured so the two routers should peer, including the correct BGP session endpoint addresses and the correct BGP session hop-count limit (EBGP multihop). What is a good first test to see if BGP will work across the firewall?
A. |
Attempt to TELNET from the router connected to the inside of the firewall to the router connected to the outside of the firewall. If telnet works, BGP will work, since telnet and BGP both use TCP to transport data. |
B. |
Ping from the router connected to the inside interface of the firewall to the router connected to the outside interface of the firewall. If you can ping between them, BGP should work, since BGP uses IP to transport packets. |
C. |
There is no way to make BGP work across a firewall without special configuration, so there is no simple test that will show you if BGP will work or not, other than trying to start the peering session. |
D. |
There is no way to make BGP work across a firewall. |
Correct Answer: C
QUESTION 677
Spanning Tree Protocol IEEE 802.1 s defines the ability to deploy which of these?
A. |
one global STP instance for all VLANs |
B. |
one STP instance for each VLAN |
C. |
one STP instance per set of VLANs |
D. |
one STP instance per set of bridges |
Correct Answer: C
QUESTION 678
Which two of these are used in the selection of a root bridge in a network utilizing Spanning Tree Protocol IEEE 802.1 D? (Choose two.)
A. |
Designated Root Cost |
B. |
bridge ID priority |
C. |
max age |
D. |
bridge ID MAC address |
E. |
Designated Root Priority |
F. |
forward delay |
Correct Answer: BD
QUESTION 679
If a port configured with STP loop guard stops receiving BPDUs, the port will be put into which state?
A. |
learning state |
B. |
listening state |
C. |
forwarding state |
D. |
loop-inconsistent state |
Correct Answer: D
QUESTION 680
What is the purpose of the STP PortFast BPDU guard feature?
A. |
enforce the placement of the root bridge in the network |
B. |
ensure that a port is transitioned to a forwarding state quickly if a BPDU is received |
C. |
enforce the borders of an STP domain |
D. |
ensure that any BPDUs received are forwarded into the STP domain |
Correct Answer: C
Free VCE & PDF File for Cisco 400-101 Real Exam
Instant Access to Free VCE Files: CCNA | CCNP | CCIE …
Instant Access to Free PDF Files: CCNA | CCNP | CCIE …
100-105 Dumps VCE PDF
200-105 Dumps VCE PDF
300-101 Dumps VCE PDF
300-115 Dumps VCE PDF
300-135 Dumps VCE PDF
300-320 Dumps VCE PDF
400-101 Dumps VCE PDF
640-911 Dumps VCE PDF
640-916 Dumps VCE PDF
70-410 Dumps VCE PDF
70-411 Dumps VCE PDF
70-412 Dumps VCE PDF
70-413 Dumps VCE PDF
70-414 Dumps VCE PDF
70-417 Dumps VCE PDF
70-461 Dumps VCE PDF
70-462 Dumps VCE PDF
70-463 Dumps VCE PDF
70-464 Dumps VCE PDF
70-465 Dumps VCE PDF
70-480 Dumps VCE PDF
70-483 Dumps VCE PDF
70-486 Dumps VCE PDF
70-487 Dumps VCE PDF
220-901 Dumps VCE PDF
220-902 Dumps VCE PDF
N10-006 Dumps VCE PDF
SY0-401 Dumps VCE PDF