Q1. Which statement describes the result of configuring SPAN on a Cisco device?

A. If not carefully planned, SPAN can lead to loops between source and destination ports.

B. SPAN doubles traffic internally

C. SPAN blocks for normal use one additional port for each configured source port

D. SPAN halves the capacity of the source port.

Answer: A

Q2. What do subordinate switches in a switch stack keep?

A. Subordinate switches keep their own spanning trees for each VLAN that they support.

B. Subordinate switches keep entire VLAN database

C. Store running config all the switches

Answer: A

Q3. Which command do you enter so that the default authentication group on a device falls back to the case-sensitive local user database when the initial authentication fails?

A. aaa authentication login default group tacacs+ radius local

B. aaa authentication exec default group tacacs+ local if-authenticated

C. aaa authentication login default group tacacs+ local-case if-authenticated

D. aaa authentication exec default group tacacs+ if-authenticated local

Answer: C

Q4. Which two statements are true about recommended practices that are to be used in a local VLAN solution design where layer 2 traffic is to be kept to a minimum? (Choose two.)

A. Routing should occur at the access layer if voice VLANs are utilized. Otherwise, routing should occur at the distribution layer.

B. Routing may be performed at all layers but is most commonly done at the core and distribution layers.

C. Routing should not be performed between VLANs located on separate switches.

D. VLANs should be local to a switch.

E. VLANs should be localized to a single switch unless voice VLANs are being utilized.

Answer: B,D

Q5. Which security violation mode drops packets with unknown source addresses and increments the violation counter ?

A. Shutdown

B. Restrict

C. Protect

D. Drop

E. Inhibit

Answer: B

Q6. Refer to the exhibit.

When troubleshooting a network problem, a network analyzer is connected to Port f0/1 of a LAN switch. Which command can prevent BPDU transmission on this port?

A. spanning-tree portfast bpduguard enable

B. spanning-tree bpduguard default

C. spanning-tree portfast bpdufilter default

D. no spanning-tree link-type shared

Answer: C

Q7. Which two statements are true of root guard? (Choose two)

A. Configure root guard to automatically change a designated port to a root port. B. Configure uplinkfast on an enabled root guard interface to protect the root status a switch.

B. Configure root guard to ensure that root guard enabled ports become designated ports.

C. Configure root guard to prevent an unauthorized switch from becoming the root switch

D. Issue a no shutdown command to recover a port from the root-inconsistent state

Answer: C,D

Q8. An access switch at a remote location is connected to the spanning-tree root with redundant uplinks. A network engineer notices that there are issues with the physical cabling of the current root port. The engineer decides to force the secondary link to be the desired forwarding root port.

Which action accomplishes this task?

A. Change the link-type to point-to-point.

B. Enable Rapid Spanning Tree to converge using the secondary link.

C. Adjust the secondary link to have a lower priority than the primary link.

D. Apply a BPDU filter on the primary interface of the remote switches.

Answer: C

Q9. Which statement is true about RSTP topology changes?

A. Any change in the state of the port generates a TC BPDU.

B. Only nonedge ports moving to the forwarding state generate a TC BPDU.

C. If either an edge port or a nonedge port moves to a block state, then a TC BPDU is generated.

D. Only edge ports moving to the blocking state generate a TC BPDU.

E. Any loss of connectivity generates a TC BPDU.

Answer: B

Q10. Refer to the exhibit.

Which two statements about SW1 are true? (Choose two)

A. Interface Gi5/1 is using a Cisco proprietary trunking protocol

B. On Interface Gi5/1, all untagged traffic is tagged with VLAN 113

C. The device is configured with the default MST region

D. Interface Gi5/1 is using an industry-standard trunking protocol

E. Interface Gi6/2 is the root port for VLAN 36

F. On interface Gi6/2, all untagged traffic is tagged with VLAN 600

Answer: D,F

