Question 1:

Refer to the exhibit.

Which set of configurations will result in all ports on both switches successfully bundling into an EtherChannel?

A. switch1 channel-group 1 mode active switch2 channel-group 1 mode auto

B. switch1 channel-group 1 mode desirable switch2 channel-group 1 mode passive

C. switch1 channel-group 1 mode on switch2 channel-group 1 mode auto

D. switch1 channel-group 1 mode desirable switch2 channel-group 1 mode auto

Correct Answer: D

The different etherchannel modes are described in the table below:

Mode Description active Places an interface into an active negotiating state, in which the interface starts negotiations with other interfaces by sending LACP packets. auto Places an interface into a passive negotiating state, in which the interface re- sponds to PAgP packets it receives but does not start PAgP packet negotia- tion.

This setting minimizes the transmission of PAgP packets.

desirable Places an interface into an active negotiating state, in which the interface starts negotiations with other interfaces by sending PAgP packets.

on Forces the interface into an EtherChannel without PAgP or LACP. With the on mode, a usable EtherChannel exists only when an interface group in the on mode is connected to another interface group in the on mode.

passive Places an interface into a passive negotiating state, in which the interface re- sponds to LACP packets that it receives, but does not start LACP packet ne- gotiation. This setting minimizes the transmission of LACP packets.

Both the auto and desirable PAgP modes allow interfaces to negotiate with partner interfaces to determine if they can form an EtherChannel based on criteria such as interface speed and, for Layer 2 EtherChannels, trunking state and VLAN

numbers. Interfaces can form an EtherChannel when they are in different PAgP modes as long as the modes are compatible. For example:

An interface in the desirable mode can form an EtherChannel with another interface that is in the desirable or auto mode.

An interface in the auto mode can form an EtherChannel with another interface in the desirable mode. An interface in the auto mode cannot form an EtherChannel with another interface that is also in the auto mode because neither interface

starts PAgP negotiation. An interface in the on mode that is added to a port channel is forced to have the same characteristics as the already existing on mode interfaces in the channel.

Reference: http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3550/software/release/12- 1_13_ea1/configuration/guide/3550scg/swethchl.html

Question 2:

Refer to the exhibit.

How can the traffic that is mirrored out the GigabitEthernet0/48 port be limited to only traffic that is received or transmitted in VLAN 10 on the GigabitEthernet0/1 port?

A. Change the configuration for GigabitEthernet0/48 so that it is a member of VLAN 10.

B. Add an access list to GigabitEthernet0/48 to filter out traffic that is not in VLAN 10.

C. Apply the monitor session filter globally to allow only traffic from VLAN 10.

D. Change the monitor session source to VLAN 10 instead of the physical interface.

Correct Answer: C

To start a new flow-based SPAN (FSPAN) session or flow-based RSPAN (FRSPAN) source or destination session, or to limit (filter) SPAN source traffic to specific VLANs, use the monitor session filter global configuration command.

Usage Guidelines You can set a combined maximum of two local SPAN sessions and RSPAN source sessions. You can have a total of 66 SPAN and RSPAN sessions on a switch or switch stack. You can monitor traffic on a single VLAN or on a series or range of ports or VLANs. You select a series or range of VLANs by using the [ , | -] options. If you specify a series of VLANs, you must enter a space before and after the comma. If you specify a range of VLANs, you must enter a space before and after the hyphen ( -). VLAN filtering refers to analyzing network traffic on a selected set of VLANs on trunk source ports. By default, all VLANs are monitored on trunk source ports. You can use the monitor session session_number filter vlan vlan-id command to limit SPAN traffic on trunk source ports to only the specified VLANs. VLAN monitoring and VLAN filtering are mutually exclusive. If a VLAN is a source, VLAN filtering cannot be enabled. If VLAN filtering is configured, a VLAN cannot become a source. Reference: http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/3se/network_m anagement/command_reference/b_nm_3se_3850_cr/ b_nm_3se_3850_cr_chapter_010.html#wp3 875419997

Question 3:

After the implementation of several different types of switches from different vendors, a network engineer notices that directly connected devices that use Cisco Discovery Protocol are not visible. Which vendor- neutral protocol could be used to resolve this issue?

A. Local Area Mobility

B. Link Layer Discovery Protocol

C. NetFlow

D. Directed Response Protocol

Correct Answer: B

The Link Layer Discovery Protocol (LLDP) is a vendor-neutral link layer protocol in the Internet Protocol Suite used by network devices for advertising their identity, capabilities, and neighbors on an IEEE 802 local area network, principally wired Ethernet. LLDP performs functions similar to several proprietary protocols, such as the Cisco Discovery Protocol (CDP). Reference: http://en.wikipedia.org/wiki/ Link_Layer_Discovery_Protocol

Question 4:

After configuring new data VLANs 1020 through 1030 on the VTP server, a network engineer notices that none of the VTP clients are receiving the updates. What is the problem?

A. The VTP server must be reloaded.

B. The VTP version number must be set to version 3.

C. After each update to the VTP server, it takes up to 4 hours propagate.

D. VTP must be stopped and restarted on the server.

E. Another switch in the domain has a higher revision number than the server.

Correct Answer: B

VTP version 3 supports these features that are not supported in version 1 or version 2: Enhanced authentication–You can configure the authentication as hidden or secret. When hidden, the secret key from the password string is saved in the VLAN database file, but it does not appear in plain text in the configuration. Instead, the key associated with the password is saved in hexadecimal format in the running configuration. You must reenter the password if you enter a takeover command in the domain. When you enter the secret keyword, you can directly configure the password secret key. Support for extended range VLAN (VLANs 1006 to 4094) database propagation. VTP versions 1 and 2 propagate only VLANs 1 to 1005. If extended VLANs are configured, you cannot convert from VTP version 3 to version 1 or 2. Reference: http://www.cisco.com/en/US/docs/switches/lan/catalyst3560/ software/ release/12.2_52_se/config uration/guide/swvtp.html#wp1316856

Question 5:

Which option lists the information that is contained in a Cisco Discovery Protocol advertisement?

A. native VLAN IDs, port-duplex, hardware platform

B. native VLAN IDs, port-duplex, memory errors

C. native VLAN IDs, memory errors, hardware platform

D. port-duplex, hardware platform, memory errors

Correct Answer: A

Type-Length-Value fields (TLVs) are blocks of information embedded in CDP advertisements. Table 21 summarizes the TLV definitions for CDP advertisements. Table 21 Type-Length-Value Definitions for CDPv2

TLV Definition Device-ID TLV Identifies the device name in the form of a character string. Address TLV Contains a list of network addresses of both receiving and sending devices. Port-ID TLV Identifies the port on which the CDP packet is sent. Capabilities TLV Describes the functional capability for the device in the form of a de- vice type, for example, a switch. Version TLV Contains information about the software release version on which the device is running. Platform TLV Describes the hardware platform name of the device, for example, Cisco 4500. IP Network Prefix Contains a list of network prefixes to which the sending device can TLV forward IP packets. This information is in the form of the interface

protocol and port number, for example, Eth 1/0.

VTP Management Advertises the system\’s configured VTP management domain name- Domain TLV string. Used by network operators to verify VTP domain configuration in adjacent network nodes. Native VLAN TLV Indicates, per interface, the assumed VLAN for untagged packets on the interface. CDP learns the native VLAN for an interface. This fea- ture is

implemented only for interfaces that support the IEEE 802.1Q protocol.

Full/Half Duplex Indicates status (duplex configuration) of CDP broadcast interface. TLV Used by network operators to diagnose connectivity problems be- tween adjacent network elements. Reference:


Question 6:

Which VTP mode is needed to configure an extended VLAN, when a switch is configured to use VTP versions 1 or 2?

A. transparent

B. client

C. server

D. Extended VLANs are only supported in version 3 and not in versions 1 or 2.

Correct Answer: A

Question 7:

Which authentication service is needed to configure 802.1x?

A. RADIUS with EAP Extension


C. RADIUS with CoA


Correct Answer: A

Explanation: With 802.1x, the authentication server–performs the actual authentication of the client. The authentication server validates the identity of the client and notifies the switch whether or not the client is authorized to access the LAN and switch services. Because the switch acts as the proxy, the authentication service is transparent to the client. The Remote Authentication Dial-In User Service (RADIUS) security system with Extensible Authentication Protocol (EAP) extensions is the only supported authentication server. Reference: http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2940/ software/release/12- 1_19_ea1/configuration/guide/2940scg_1/sw8021x.pdf

Question 8:

Which command would a network engineer apply to error-disable a switchport when a packet- storm is detected?

A. router(config-if)#storm-control action shutdown

B. router(config-if)#storm-control action trap

C. router(config-if)#storm-control action error

D. router(config-if)#storm-control action enable

Correct Answer: A

Configuring the Traffic Storm Control Shutdown Mode To configure the traffic storm control shutdown mode on an interface, perform this task: Command Purpose

Step 1 Router(config)# interface {{type1 Selects an interface to configure. slot/port} | {port-channel num-ber}}

Step 2 Router(config-if)# storm-control (Optional) Configures traffic storm control to action shutdown error- disable ports when a traffic storm occurs.

?Enter the no storm-control action shut-down command to revert to the default action (drop).

?Use the error disable detection and recov-ery feature, or the shutdown and no shut-down commands to reenable ports.

Reference: http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/12- 2SX/configuration/ guide/book/storm.html

Question 9:

What is the default HSRP priority?

A. 50

B. 100

C. 120

D. 1024

Correct Answer: B

standby [group-num- Set a priority value used in choosing the active router. The ber] priority priority range is 1 to 255; the default priority is 100. The highest [preempt [delay delay]] number represents the highest priority.

(Optional) group-number–The group number to which

the command applies.


preempt–Select so that when the local router has a higher priority than the active router, it assumes control as the active router.


delay–Set to cause the local router to post- pone taking over the active role for the shown number of sec- onds. The range is 0 to 36000 (1 hour); the default is 0 (no de- lay before taking over). Use the no form of the command to restore the

default values.


http://www.cisco.com/en/US/docs/switches/lan/catalyst3550/software/release/12.1_19_ea1/confi guration/ guide/swhsrp.html#wp1044327

Question 10:

An engineer is configuring an EtherChannel between two switches using LACP. If the EtherChannel mode on switch 1 is configured to active, which two modes on switch 2 establish an operational EtherChannel? (Choose two.)

A. active

B. auto

C. desirable

D. on

E. passive

Correct Answer: AE

