Q181. A network engineer is implementing virtualization into the enterprise network. Which system should be used to address policy enforcement at the distribution layer? 

A. Cisco IOS based firewall 

B. multilayer switches 

C. integrated firewall services 

D. identity services engine 

E. intrusion protection systems 

Answer: C 

Q182. A customer with a single Cisco Adaptive Security Appliance wants to separate multiple segments of the e-commerce network to allow for different security policies. What firewall technology accommodates these design requirements? 

A. virtual contexts 

B. private VLANs 

C. admission control 

D. virtual private network 

Answer: A 

Q183. In which multicast configuration is MSDP most useful? 

A. interdomain 

B. intradomain 

C. data center 

D. campus 

Answer: A 

Q184. The network designer needs to consider the number of multicast applications and sources in the network to provide the most robust network possible. Which of the following is a consideration the designer must also address? 

A. The IGPs should utilize authentication to avoid being the most vulnerable component 

B. With SSM source or receiver attacks are not possible 

C. With Shared Trees access control is always applied at the RP 

D. Limit the rate of Register messages to the RP to prevent specific hosts from being attacked on a PIM-SM network 

Answer: B 

Q185. Which command can you enter to inject BGP routes into an IGP? 

A. redistribute bgp 

B. redistribute static 

C. redistribute static subnet 

D. default-information originate 

Answer: A 

Q187. A e-commerce network has many devices that often need to be upgraded on a regular basis. What technology will ensure IP packets continue to be forwarded even during a device failover? 

A. stateful switchover 

B. nonstop forwarding 

C. route processor redundancy 

D. optimized edge routing 

E. enhanced object tracking 

Answer: B 

Q188. What is the recommended subnet between two sites that have a point-to-point connection to conserve IP addresses? 





Answer: C 

Q189. Refer to the exhibit. 

A network engineer manually reconfigures the BGP configuration on newly upgraded router R1. However, the BGP neighbor relationship does not come up with the directly connected neighbor router. What is causing the failure of the BGP neighbor relationship between routers R1 and R2? 

A. An incorrect neighbor IP address for router R2 is configured on router R1. 

B. An incorrect neighbor AS number is configured on router R1 for router R2. 

C. The wrong BGP authentication password is configured on router R1. 

D. Router R1 must configure the R2 loopback address as the neighbor IP address. 

Answer: C 

Q190. Which option is a benefit of the vPC+ feature? 

A. Cisco FabricPath is not required in the network domain. 

B. This feature provides fault domain separation. 

C. Nonfabric devices, such as a server or a classic Ethernet switch, can be connected to two fabric switches that are configured with vPC. 

D. The control plane and management plane are combined into one logical plane. 

Answer: C 


Q191. Which statement about IPS and IDS solutions is true? 

A. IDS and IPS read traffic only in inline mode. 

B. IDS and IPS read traffic only in promiscuous mode. 

C. An IDS reads traffic in inline mode, and an IPS reads traffic in promiscuous mode. 

D. An IDS reads traffic in promiscuous mode, and an IPS reads traffic in inline mode. 

Answer: D 

Q192. ACME corporation owns a single MDS. 

Which two SAN tools can be used to optimize the use and cost of the switching hardware? (Choose two.) 

A. zoning 




Answer: A,C 

Q193. Which of the following is true concerning best design practices at the switched Access layer of the traditional layer2 Enterprise Campus Network? 

A. Cisco NSF with SSO and redundant supervisors has the most impact on the campus in the Access layer 

B. Provide host-level redundancy by connecting each end device to 2 separate Access switches 

C. Offer default gateway redundancy by using dual connections from Access switches to redundant Distribution layer switches using a FHRP 

D. Include a link between two Access switches to support summarization of routing information from the Access to the Distribution layer 

Answer: A 

Q194. When an enterprise network is designed, which protocol provides redundancy for edge devices in the event of a first-hop failure? 





Answer: B 

Q195. A network engineer is building a LAN design that includes Cisco NAC. What two characteristics of an out-of-band NAC deployment are important to consider when evaluating it for the design? (Choose two.) 

A. supported by a limited number of switch models 

B. never in-line with user traffic 

C. aggregate client traffic is constrained to NAC server port speed 

D. recommended if sharing ports between IP phones and PCs 

E. supports real IP gateway (routed mode) 

Answer: A,D 

see more Designing Cisco Network Service Architectures