πŸ”

200-301 β€” questions

Page 31 of 60 Β· 1182 total questions.

Topic 1 Β· Question 654

When a WPA2-PSK WLAN is configured in the Wireless LAN Controller, what is the minimum number of characters that is required in ASCII format?

  • A6
  • B8 (correct answer)
  • C12
  • D18
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: 8

Topic 1 Β· Question 655

What mechanism carries multicast traffic between remote sites and supports encryption?

  • AISATAP
  • BIPsec over ISATAP
  • CGRE
  • DGRE over IPsec (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: GRE over IPsec This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 656

Refer to the exhibit. An access-list is required to permit traffic from any host on interface Gi0/0 and deny traffic from interface Gi0/1. Which access list must be applied?

Exhibit 1 for question 656
  • Aip access-list standard 99 permit 10.100.100.0 0.0.0.255 deny 192.168.0.0 0.0.255.255 (correct answer)
  • Bip access-list standard 99 permit 10.100.100.0 0.0.0.255 deny 192.168.0.0 0.255.255.255
  • Cip access-list standard 199 permit 10.100.100.0 0.0.0.255 deny 192.168.0.0 0.255.255.255
  • Dip access-list standard 199 permit 10.100.100.0 0.0.0.255 deny 192.168.0.0 0.0.255.255
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: ip access-list standard 99 permit 10.100.100.0 0.0.0.255 deny 192.168.0.0 0.0.255.255

Topic 1 Β· Question 657 Β· Select all that apply

Refer to the exhibit. Which two commands must be configured on router R1 to enable the router to accept secure remote-access connections? (Choose two.)

Exhibit 1 for question 657
  • Aip ssh pubkey-chain (correct answer)
  • Busername cisco password 0 cisco
  • Ccrypto key generate rsa (correct answer)
  • Dtransport input telnet
  • Elogin console
Reveal answer & explanation
Correct answer: A, C

The correct answer is A, C. Option A: ip ssh pubkey-chain Option C: crypto key generate rsa

Explanation

SSH provides encrypted remote CLI administration and should replace insecure Telnet. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 658

Which service is missing when RADIUS is selected to provide management access to the WLC?

  • Aauthorization
  • Bauthentication
  • Caccounting
  • Dconfidentiality (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: confidentiality

Topic 1 Β· Question 659

Which action implements physical access control as part of the security program of an organization?

  • Asetting up IP cameras to monitor key infrastructure (correct answer)
  • Bconfiguring a password for the console port
  • Cbacking up syslogs at a remote location
  • Dconfiguring enable passwords on network devices
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: setting up IP cameras to monitor key infrastructure This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 660

Which field within the access-request packet is encrypted by RADIUS?

  • Aauthorized services
  • Bpassword (correct answer)
  • Cauthenticator
  • Dusername
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: password This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 661

A Cisco engineer is configuring a factory-default router with these three passwords: β€’ The user EXEC password for console access is p4ssw0rd1. β€’ The user EXEC password for Telnet access is s3cr3t2. β€’ The password for privileged EXEC mode is priv4t3p4ss. Which command sequence must the engineer configure?

  • Aenable secret priv4t3p4ss ! line con 0 password p4ssw0rd1 ! line vty 0 15 password s3cr3t2
  • Benable secret priv4t3p4ss ! line con 0 password p4ssw0rd1 login ! line vty 0 15 password s3cr3t2 login (correct answer)
  • Cenable secret priv4t3p4ss ! line con 0 password login p4ssw0rd1 ! line vty 0 15 password login s3cr3t2 login
  • Denable secret privilege 15 priv4t3p4ss ! line con 0 password p4ssw0rd1 login ! line vty 0 15 password s3cr3t2 login
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: enable secret priv4t3p4ss ! line con 0 password p4ssw0rd1 login ! line vty 0 15 password s3cr3t2 login

Topic 1 Β· Question 662

How does MAC learning function?

  • Asends the frame back to the source to verify availably
  • Brewrites the source and destination MAC address
  • Cdrops received MAC addresses not listed in the address table
  • Dadds unknown source MAC addresses to the CAM table (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: adds unknown source MAC addresses to the CAM table

Explanation

OSPF elects a designated router on multiaccess networks to reduce adjacency and LSA exchange overhead.

Topic 1 Β· Question 664

What is a function of Opportunistic Wireless Encryption in an environment?

  • Aprovide authentication
  • Bprotect traffic on open networks (correct answer)
  • Coffer compression
  • Dincrease security by using a WEP connection
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: protect traffic on open networks This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 666

Refer to the exhibit. Clients on the WLAN are required to use 802.11r. What action must be taken to meet the requirement?

Exhibit 1 for question 666
  • AUnder Protected Management Frames, set the PMF option to Required.
  • BEnable CCKM under Authentication Key Management.
  • CSet the Fast Transition option and the WPA gtk-randomize State to disable.
  • DSet the Fast Transition option to Enable and enable FT 802.1X under Authentication Key Management. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Set the Fast Transition option to Enable and enable FT 802.1X under Authentication Key Management.

Topic 1 Β· Question 667

Refer to the exhibit. What must be configured to enable 802.11w on the WLAN?

Exhibit 1 for question 667
  • ASet Fast Transition to Enabled.
  • BEnable WPA Policy.
  • CSet PMF to Required. (correct answer)
  • DEnable MAC Filtering.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Set PMF to Required.

Topic 1 Β· Question 668

Which encryption method is used by WPA3?

  • ATKIP
  • BAES (correct answer)
  • CSAE
  • DPSK
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: AES This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 669

Which type of traffic is sent with pure IPsec?

  • Amulticast traffic from a server at one site to hosts at another location
  • Bbroadcast packets from a switch that is attempting to locate a MAC address at one of several remote sites
  • Cunicast messages from a host at a remote site to a server at headquarters (correct answer)
  • Dspanning-tree updates between switches that are at two different sites
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: unicast messages from a host at a remote site to a server at headquarters

Topic 1 Β· Question 670

How does authentication differ from authorization?

  • AAuthentication is used to record what resource a user accesses, and authorization is used to determine what resources a user can access.
  • BAuthentication verifies the identity of a person accessing a network, and authorization determines what resource a user can access. (correct answer)
  • CAuthentication is used to determine what resources a user is allowed to access, and authorization is used to track what equipment is allowed access to the network.
  • DAuthentication is used to verify a person's identity, and authorization is used to create syslog messages for logins.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Authentication verifies the identity of a person accessing a network, and authorization determines what resource a user can access.

Topic 1 Β· Question 671

An engineer has configured the domain name, user name, and password on the local router. What is the next step to complete the configuration for a Secure Shell access RSA key?

  • Acrypto key import rsa pem
  • Bcrypto key generate rsa (correct answer)
  • Ccrypto key zeroize rsa
  • Dcrypto key pubkey-chain rsa
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: crypto key generate rsa This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 672

Which type if network attack overwhelms the target server by sending multiple packets to a port until the half-open TCP resources of the target are exhausted?

  • ASYN flood (correct answer)
  • Breflection
  • Cteardrop
  • Damplification
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: SYN flood

Topic 1 Β· Question 673 Β· Select all that apply

Which two components comprise part of a PKI? (Choose two.)

  • Apreshared key that authenticates connections
  • Bone or more CRLs (correct answer)
  • CRSA token
  • DCA that grants certificates (correct answer)
  • Eclear-text password that authenticates connections
Reveal answer & explanation
Correct answer: B, D

The correct answer is B, D. Option B: one or more CRLs Option D: CA that grants certificates

Topic 1 Β· Question 675

After a recent security breach and a RADIUS failure, an engineer must secure the console port of each enterprise router with a local username and password. Which configuration must the engineer apply to accomplish this task?

  • Aaaa new-model line con 0 password plaintextpassword privilege level 15
  • Baaa new-model aaa authorization exec default local aaa authentication login default radius username localuser privilege 15 secret plaintextpassword
  • Cusername localuser secret plaintextpassword line con 0 no login local privilege level 15
  • Dusername localuser secret plaintextpassword line con 0 login authentication default privilege level 15 (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: username localuser secret plaintextpassword line con 0 login authentication default privilege level 15 This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 676

Which wireless security protocol relies on Perfect Forward Secrecy?

  • AWEP
  • BWPA2
  • CWPA
  • DWPA3 (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: WPA3

Explanation

WPA3 strengthens wireless authentication, including SAE for personal networks. This option keeps traffic private / properly secured as required.

Showing questions 601–620 of 1182 Β· Page 31 of 60