CCNP Switch Final Exam Questions with Correct Answers |New Update 100%
Verified By Experts
Refer to the exhibit. The indicated configuration was established on the HSRP standby router
RTB. However, the console message %IP-4-DUPADDR started appearing almost immediately on
the RTB router. Given the output of the show standby brief command on RTA, what is the cause
of the problem?
a. The command standby preempt should only be applied on the active router
b. The subnet mask is missing from the standby ip 10.1.1.1 command
c. The group number 50 is missing in the Router RTB configuration command
d. The priority number 150 is missing in the Router RTB configuration commands
e. The virtual IP address should be the same as the active router
f. The ports on the switch must be configured with the spanning-tree PortFast feature c. The
group number 50 is missing in the Router RTB configuration commands.
Which statement correctly explains the process of mitigating ARP attacks on a switch where
dynamic ARP inspection (DAI) has been configured?
a. All intercepted packets that come from untrusted ports are dropped
b. All intercepted packets that come from trusted ports are sent to untrusted ports only
c. The intercepted packets are verified against the DHCP snooping binding table for valid IP-to-
MAC bindings
d. For all intercepted packets, an ARP request is sent to the DHCP server for IP-to-MAC address
resolution c. The intercepted packets are verified against the DHCP snooping binding table
for valid IP-to-MAC bindings.
Refer to the exhibit. What feature does an SNMP manager need to be able to set a parameter
on ACSw1?
a. a manager who is using an SNMP string of K44p0ut
,b. a manager who is using an Inform Request MIB
c. a manager who is using host 192.168.0.5
d. a manager who is using authPriv c. a manager who is using host 192.168.0.5
Which statement is true concerning the core layer within the hierarchical design model?
a. Remote users are granted access to the network through the core
b. Routing should be configured without traffic filtering, address translation, or other packet
manipulation at the core
c. The core, which acts as the front door to a network, is designed to prevent unauthorized
users from gaining entry
d. The core provides an optimized and reliable transport structure by using a combination of
route summaries, distribution lists, and route maps b. Routing should be configured without
traffic filtering, address translation, or other packet manipulation at the core.
When a port security violation occurs on a switch port, the switch sends a syslog message but
does not shut down the port. What port security mode is in effect?
a. sticky
b. shutdown
c. restrict
d. protect c. restrict
Which three steps are required to configure interfaces as routed ports on a multilayer Catalyst
switch? (Choose three.)
1. Enable IP routing globally
2. Assign IP addresses to routed ports.
3. Configure SVI for each VLAN in the network
, 4. Configure 802.1 Q encapsulation on routed ports
5. Disable Power over Ethernet (PoE) on the physical Layer 3 interfaces
6. Disable Layer 2 functionality on interfaces that will be configured as routed ports 1.
Enable IP routing globally.
2. Assign IP addresses to routed ports.
6. Disable Layer 2 functionality on interfaces that will be configured as routed ports.
A bridging loop occurs in a network and disrupts user connectivity. What action should be taken
by a network administrator to restore connectivity?
a. Disable ports that should be in the blocking state
b. Disable ports that should be in the forwarding state
c. Disable and re-enable all ports on the distribution switches
d. Disable all ports on the distribution switches and replace with new switches a. Disable
ports that should be in the blocking state.
Which three actions can cause problems with a VTP implementation? (Choose three.)
1. using a non-trunk link to connect switches
2. using non-Cisco switches
3. configuring all switches to be in VTP server mode
4. not using any VTP passwords on any switches
5. using lowercase on one switch and uppercase on another switch for domain names
6. having a VTP transparent switch in between a VTP server switch and a VTP client switch (all
switches in the same VTP domain) 1. using a non-trunk link to connect switches
2. using non-Cisco switches
5. using lowercase on one switch and uppercase on another switch for domain names
Verified By Experts
Refer to the exhibit. The indicated configuration was established on the HSRP standby router
RTB. However, the console message %IP-4-DUPADDR started appearing almost immediately on
the RTB router. Given the output of the show standby brief command on RTA, what is the cause
of the problem?
a. The command standby preempt should only be applied on the active router
b. The subnet mask is missing from the standby ip 10.1.1.1 command
c. The group number 50 is missing in the Router RTB configuration command
d. The priority number 150 is missing in the Router RTB configuration commands
e. The virtual IP address should be the same as the active router
f. The ports on the switch must be configured with the spanning-tree PortFast feature c. The
group number 50 is missing in the Router RTB configuration commands.
Which statement correctly explains the process of mitigating ARP attacks on a switch where
dynamic ARP inspection (DAI) has been configured?
a. All intercepted packets that come from untrusted ports are dropped
b. All intercepted packets that come from trusted ports are sent to untrusted ports only
c. The intercepted packets are verified against the DHCP snooping binding table for valid IP-to-
MAC bindings
d. For all intercepted packets, an ARP request is sent to the DHCP server for IP-to-MAC address
resolution c. The intercepted packets are verified against the DHCP snooping binding table
for valid IP-to-MAC bindings.
Refer to the exhibit. What feature does an SNMP manager need to be able to set a parameter
on ACSw1?
a. a manager who is using an SNMP string of K44p0ut
,b. a manager who is using an Inform Request MIB
c. a manager who is using host 192.168.0.5
d. a manager who is using authPriv c. a manager who is using host 192.168.0.5
Which statement is true concerning the core layer within the hierarchical design model?
a. Remote users are granted access to the network through the core
b. Routing should be configured without traffic filtering, address translation, or other packet
manipulation at the core
c. The core, which acts as the front door to a network, is designed to prevent unauthorized
users from gaining entry
d. The core provides an optimized and reliable transport structure by using a combination of
route summaries, distribution lists, and route maps b. Routing should be configured without
traffic filtering, address translation, or other packet manipulation at the core.
When a port security violation occurs on a switch port, the switch sends a syslog message but
does not shut down the port. What port security mode is in effect?
a. sticky
b. shutdown
c. restrict
d. protect c. restrict
Which three steps are required to configure interfaces as routed ports on a multilayer Catalyst
switch? (Choose three.)
1. Enable IP routing globally
2. Assign IP addresses to routed ports.
3. Configure SVI for each VLAN in the network
, 4. Configure 802.1 Q encapsulation on routed ports
5. Disable Power over Ethernet (PoE) on the physical Layer 3 interfaces
6. Disable Layer 2 functionality on interfaces that will be configured as routed ports 1.
Enable IP routing globally.
2. Assign IP addresses to routed ports.
6. Disable Layer 2 functionality on interfaces that will be configured as routed ports.
A bridging loop occurs in a network and disrupts user connectivity. What action should be taken
by a network administrator to restore connectivity?
a. Disable ports that should be in the blocking state
b. Disable ports that should be in the forwarding state
c. Disable and re-enable all ports on the distribution switches
d. Disable all ports on the distribution switches and replace with new switches a. Disable
ports that should be in the blocking state.
Which three actions can cause problems with a VTP implementation? (Choose three.)
1. using a non-trunk link to connect switches
2. using non-Cisco switches
3. configuring all switches to be in VTP server mode
4. not using any VTP passwords on any switches
5. using lowercase on one switch and uppercase on another switch for domain names
6. having a VTP transparent switch in between a VTP server switch and a VTP client switch (all
switches in the same VTP domain) 1. using a non-trunk link to connect switches
2. using non-Cisco switches
5. using lowercase on one switch and uppercase on another switch for domain names