Free 300-420 sample questions
Real questions from the Designing Cisco Enterprise Networks (ENSLD) practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Showing 10 of 20 free sample questions.
Which are valid configurable VLAN ID numbers for 802.1Q networks?
Correct answer: 1-4094
Explanation: IEEE 802.1Q supports configuring VLAN IDs 1 through 4094. The 802.1Q standard specifies support for a maximum of 4,094 VLANs. (IDs 0 and 4095 are reserved.) Therefore, ID values of 1-4094 are assignable. In contrast, the valid range of configurable ISL VLANs is 1-1001. The following is a summary of VLAN IDs: .0 and 4095: Reserved . 1: Cisco default management .2-1001: Available for Ethernet VLANs .1002-1005: Defaults for FDDI and Token Ring VLANs .1006-4094: Extended range available for Ethernet VLANs (802.1Q only) Recognizing the differences between supported VLAN ID ranges highlights several issues in constructing a network of both ISL and 802.1Q VLAN networks. Ethernet VLAN IDs above the supported ISL range must be mapped to IDs within the range supported by ISL. Among other limitations, you are limited to eight mappings. This process of mapping 802.1Q to ISL VLAN IDs will further restrict and define which IDs are available to be used. Objective: Layer 2 Technologies Sub-Objective: Configure and verify VLANs References: Cisco Nexus 5000 Series Switch CLI Software Configuration Guide > Configuring Access and Trunk Interfaces
Inter-VLAN routing has been operating successfully for several months. Users who connect to a newly installed switch report that they are unable to communicate with the rest of the company's networks. You decide to ensure that the switch is properly connected to the VTP domain before taking any other troubleshooting steps. What command would be best used to verify this?
Correct answer: switch# show vtp status
Explanation: The command show vtp status would be the best command to verify the switch's connection to the company's VTP domain. This command displays the version of VTP, the VTP domain the switch is a member of, the VTP mode of the switch, and other configuration settings relating to VTP. The command show vlan will display the VLANs that exist and the ports that are members of the VLANs, but will not identify whether switch is a member of the VTP domain. If the VLANs that are displayed with this command are the same as those in the VTP domain, it does not necessarily mean the switch is a member of the domain. This data needs to be verified with the show vtp status command. The command show ip route is used to verify the routing table, but it does not provide any VTP information. This command is used to verify routes to other networks discovered or configured on the switch. It will display the routing protocol used to discover each route, and the next hop used to forward traffic to the destination network. The command show interfaces trunk is used to verify which VLANs are being forwarded to another device, but does not indicate whether the switch is a member of the VTP domain. The command show interfaces would not allow you to verify the switch's connection to the company's VTP domain. This command would allow you to determine the following features of the switch: • Port state . Port speed . Input errors • Collisions Objective: Layer 2 Technologies Sub-Objective: Configure and verify trunking References: Catalyst 4500 Series Switch Cisco IOS Software Configuration Guide, 12.1(13)EW > Understanding and Configuring VTP Cisco > Cisco IOS LAN Switching Command Reference > show vlan through ssl-proxy module allowed-vlan > show vtp
What Cisco switch features are designed to work together to mitigate ARP spoofing attacks? (Choose two.)
Correct answers: DHCP snooping; DAI
DHCP snooping and Dynamic ARP Inspection (DAI) are Cisco features designed to work together to mitigate ARP spoofing attacks. DHCP snooping builds a trusted database of IP-to-MAC address bindings by monitoring DHCP transactions, while DAI validates ARP packets against this database to prevent ARP cache poisoning. Port security controls MAC addresses on switch ports but does not prevent ARP spoofing, and 802.1x provides network access control but does not validate ARP packets.
DHCP snooping and Dynamic ARP Inspection (DAI) are Cisco features designed to work together to mitigate ARP spoofing attacks. DHCP snooping builds a trusted database of IP-to-MAC address bindings by monitoring DHCP transactions, while DAI validates ARP packets against this database to prevent ARP cache poisoning. Port security controls MAC addresses on switch ports but does not prevent ARP spoofing, and 802.1x provides network access control but does not validate ARP packets.
Which next-hop router redundancy protocol provides backup for an assigned real IP address?
Correct answer: VRRP
Explanation: Using VRRP, the shared address of the next-hop router redundancy group can be the real address of a router interface. Virtual Router Redundancy Protocol (VRRP) is defined in RFC 2338. VRRP enables a group of routers to form a single virtual router, known as a VRRP group. Routers are configured in VRRP groups to provide redundancy for an IP address shared among members of the VRRP group. This address can be the real address of a router interface or a virtual address (or addresses) shared by the group. Each group is comprised of a master and one or more backup routers. If the shared address is the real IP address of a router, that router will always be the master when the address is available. The master router is responsible for forwarding packets sent to the virtual router. The backup routers provide redundancy and stand ready to assume the role of the master router in the event that it is unable to forward packets. The master virtual router owns the VRRP IP address and is responsible for handling all packets sent to the VRRP IP address. Backup VRRP routers monitor for hello activity from the master virtual router. The master router will advertise using IP 224.0.0.18 and MAC 0000.0c00.01xx (xx is the VRRP Group ID). The advertisements by default will be sent every second, and the master down interval is three seconds. If the VRRP IP address is NOT the physical address of one of the VRRP routers, then the router with the highest priority will assume the role of the master. The configurable priority range is from 0 to 255, and the default value is 100. The higher the value is, the higher the priority is. If activity stops for the duration of the master router's down interval, the backup router with the highest priority will become the master router. When the old master router comes back online, it will assume the master role again if it still has the highest priority among all routers. In the configuration shown below, Router A will be the master router unless it goes down, in which case B will take over. If A comes back up it will assume the master role again. routerA(config-if)# vrrp 3 priority 130 routerB(config-if)# vrrp 3 priority 110 Hot Standby Router Protocol (HSRP) defines a set of routers that work together to represent one virtual, fault-tolerant router. Thus, redundancy is provided in the event that any one of the routers fails. The shared address of the next-hop router redundancy group is not the real address of a router interface. Gateway Load Balancing Protocol GLBP) is a Cisco-designed protocol that provides for the dynamic utilization of redundant routers in a broadcast network. The shared address of the next-hop router redundancy group is not the real address of a router interface. A virtual group address is used. Objective: Infrastructure Services Sub-Objective: Configure and verify first-hop redundancy protocols References: Cisco > Cisco IOS IP Application Services Configuration Guide, Release 12.4 > Part 1: First Hop Redundancy Protocols > Configuring VRRP
Which VLAN trunking protocol adds four bytes to the Ethernet frames?
Correct answer: 802.1Q
Explanation: 802.1Q adds 4 bytes to the Ethernet frame. The process is known as 802.1Q tagging, and inserts a four-byte field into the Ethernet frame header between the source address and the Len/Etype fields. This tag identifies the frame as an 802.1Q frame and includes bits used to identify both the priority and the VLAN ID. The VLAN ID field indicates which VLAN the frame belongs to. An 802.1q trunk can support 4096 different VLANs. After the new tag field is inserted into the frame, the frame's previous FCS field is recalculated and replaced. The following graphic shows both the ISL and 802.1Q frame formats as well as the original Ethernet frame: Inter switch link (ISL) is a Cisco proprietary trunking protocol that handles the frame in a different manner. It adds a 26- byte frame header and 4-byte trailer to the frame. LANE (LAN Emulation) is an IEEE standard for identifying VLANs on ATM networks. 802.10 is a Cisco proprietary method of identifying VLANs on FDDI media by writing VLAN information to the Security Association Identifier (SAID) of the 802.10 frame. Objective: Layer 2 Technologies Sub-Objective: Configure and verify trunking References: Cisco > Support > Technology Support > LAN Switching > Virtual LAN/VLAN Trunking Protocol (VLANS/VTP) > Design > Design Technotes > Inter-Switch Link and IEEE 802.1Q Frame Format
The output displayed below is a result of what command? Interface Grp Fwd Pri State Address Active router Standby router VI10 10 - 254 Active 192.168.8.10 local unknown VI10 10 1 7 Active 0007.b400.0101 local -
Correct answer: switch# show glbp brief
Explanation: The output of the exhibit is provided with the command show glbp brief. This output includes the interface, priority, state, and address of GLBP interfaces on the switch. In this case, VLAN 10 is the active virtual gateway using IP address 192.168.8.10. The command show glbp displays detailed information about GLBP groups on the switch. This information includes the GLBP groups the switch is a member of, whether this is the active switch, the virtual IP address, and whether preemption is enabled. The command show standby brief is used to display a summary of the HSRP groups the switch is a member of. The summary information it provides includes the group number, priority, state, active device address, standby address, and group address. This command is for HSRP only. The command show standby can be used to display detailed information about HSRP groups a switch is a member of. This command is for HSRP only. Objective: Infrastructure Services Sub-Objective: Configure and verify first-hop redundancy protocols References: Cisco > Cisco IOS IP Application Services Command Reference > sctp through show ip sib vservers > show glbp Cisco > Cisco IOS IP Application Services Configuration Guide, Release 12.4 > Part 1: First Hop Redundancy Protocols > Configuring GLBP
What attack technique attempts to fill a switching table so the attackers can capture traffic passing through a switch?
Correct answer: MAC flooding
Explanation: MAC flooding is an attack technique in which frames with unique, but invalid, source MAC addresses flood the switch and exhaust the CAM table space. Eventually no more MAC addresses can be added because the table is full. When this occurs, any packets destined for a MAC address not in the table will be flooded to all other ports. This would allow the attacker to see the flooded traffic and capture information. The switch would be essentially functioning as a hub in this case. Two methods of mitigating these attacks are: • Implementing port security • Implementing VLAN access maps VLAN hopping is an attack that allows an attacker to access network resources on a different VLAN without passing through a router. The attacker can create a packet with two 802.1Q VLAN headers on it (called double tagging) and send it to a switch. The switch port will strip off the first header and leave the second. The second header will be seen as the originating VLAN, allowing the attacker access to a VLAN they are not connected to. Executing the switchport mode access command on all non-trunk ports can help prevent this attack. Pruning the native VLAN from a trunk link can also help. VLAN hopping is a security concern because it can be accomplished without the packet passing through a router and its security access lists. For this reason, private VLANs and VACLs should be used to secure access between VLANs. Techniques to prevent these attacks are: • Prevent automatic trunk configurations by explicitly turning off Dynamic Trunking Protocol on all unused ports • Place unused ports in a common unrouted VLAN MAC spoofing is an attack that allows an attacking device to receive frames intended for a different host by changing an assigned Media Access Control (MAC) address of a networked device to a different one. Changing the assigned MAC address may allow the device to bypass access control lists on servers or routers, either hiding a computer on a network or allowing it to impersonate another computer. A rogue device is a device attached to the network that is not under the control of the organization. This term is normally used to mean a wireless device, perhaps an access point that is not operating as a part of the company's infrastructure. Employees may bring their own access points and connect them to the network so they can use their computer wirelessly. This creates a security gap since the device is probably not secured to protect the traffic. An attacker could connect a rogue access point to a company's network and capture traffic from outside the company's premises. Objective: Layer 2 Technologies Sub-Objective: Configure and verify switch administration References: Cisco > Products and Services > Switches > Cisco Catalyst 6500 Series Switches > Product Literature > White Papers > Cisco Catalyst 6500 Series Switches > VLAN Security White Paper > MAC Flooding Attack
In what mode does an LWAPP-enabled access point operate?
Correct answer: lightweight mode
Explanation: Lightweight access point protocol (LWAPP)-enabled access points operate in lightweight mode. LWAPP is a protocol used to allow centralized management of APs. The management components are removed from the APs, and a WLAN controller provides a single point of management. This controller coordinates WLAN access, managing the load on the APs and user movement between APs. Upon starting, an LWAPP-enabled access point must obtain an IP address. It can then discover the controller using DHCP, DNS, or a subnet broadcast. When multiple wireless controllers are detected by an AP, it chooses to associate with the controller that has the fewest existing associated APs. Individually configured APs that operate without central management are operating in autonomous mode. This would be the opposite of lightweight mode, which is made possible by LWAPP. Autonomous access points can be upgraded to lightweight. If they are upgraded, they will only function in conjunction with a WLAN controller. Moreover, when an autonomous access point is upgraded to lightweight, the console port only provides read access to the unit. Characteristics that autonomous and lightweight access points have in common: . Both support Power over Ethernet (PoE) . Both can use a Cisco Secure Access Control server (ACS) for security A wireless gateway bridge (WGB) is used to connect a computer without a wireless network card to a wireless network, but not separate WLANs. The WGB can connect up to eight computers to a WLAN. The WGB connects to the root AP through a wireless interface. Ad hoc is a WLAN mode used for peer-to-peer connectivity. Ad hoc mode allows wireless-enabled computers to communicate with each other without having an AP involved. Objective: Layer 2 Technologies Sub-Objective: Configure and verify other LAN switching technologies References: Cisco > Support > Product Support > Wireless > Cisco Aironet 1200 Series > Reference Guides > Technical References > Upgrading Autonomous Cisco Aironet Access Points to Lightweight Mode Cisco > Support > Technology Support > Wireless/Mobility > Wireless, LAN (WLAN) > Design > Design Technotes > Cisco Wireless Devices Association Matrix
Which PVLAN port types can send frames through a switch to community and promiscuous ports? (Choose two.)
Correct answers: community; promiscuous
In Private VLANs, community and promiscuous ports can send frames to community and promiscuous ports. Community ports within the same secondary VLAN can communicate with each other and with promiscuous ports, while promiscuous ports can communicate with all port types. Isolated ports can only communicate with promiscuous ports, and public/private are not valid PVLAN port types.
In Private VLANs, community and promiscuous ports can send frames to community and promiscuous ports. Community ports within the same secondary VLAN can communicate with each other and with promiscuous ports, while promiscuous ports can communicate with all port types. Isolated ports can only communicate with promiscuous ports, and public/private are not valid PVLAN port types.
10 more free samples are waiting
Create a free account to unlock the whole 300-420 sample bank, or get full access to all 372 practice questions in the simulator.