Rabu, 22 Juli 2009
CCNA Discovery 4 - Module 8 Exam Answers V.4 #6-10
• BECN
• DE
• FECN
• FCS
7. Refer to the exhibit. The complete configuration of a Frame Relay interface on the Chicago router is shown. How does the Chicago router know which DLCI is mapped to the IP address of the remote router?
• DE
• CIR
• FECN
• Inverse ARP
8. What statement correctly defines the purpose of the split horizon rule?
• marks the route unreachable in a routing update that is sent to other routers
• prevents routers from advertising a network through the interface from which the update came
• prevents routers from accepting higher cost routes to networks previously marked as inaccessible before the timer expires
• limits the number of hops a packet can traverse through the network before it should be discarded
9. Which PVC status suggests that the router recognizes the DLCI configured on its interface as being present on the Frame Relay switch, but the PVC associated with the DLCI is not capable of end-to-end communication?
• active
• deleted
• inactive
• idle
10. Refer to the exhibit. Which router command is used to associate a Layer 2 address with the corresponding Layer 3 address?
• Miller(config-if)#frame-relay map ip 172.16.150.1 110
• Miller(config-if)#frame-relay map ip 172.16.150.1 112
• Miller(config-if)#frame-relay map ip 172.16.150.2 110
• Miller(config-if)#frame-relay map ip 172.16.150.2 112
Rabu, 01 Juli 2009
CCNA Discovery 4 - Module 8 Exam Answers V.4 #1-5
• administrative distance
• cost
• hop count
• passive interface
2. IPSec operates at which layer of the OSI model?
• application
• network
• datalink
• transport
3. Which is true regarding Frame Relay LMI?
• There are three LMI types standardized by ANSI, ITU-T, and Cisco.
• Routers at each end of a Frame Relay virtual circuit must always use the same LMI type.
• The LMI type must be manually configured.
• The only function of LMI is to verify the connection between the router and the Frame Relay switch.
4. Which statement identifies the IP address design for subinterfaces that are configured for a Frame Relay network?
• Multipoint configurations require the IP address of each subinterface on each router to be in its own subnet.
• Multipoint configurations require IP addresses for each subinterface on each router to be a part of the same subnet.
• Point-to-point configurations require IP addresses for each subinterface on each router to be a part of the same subnet.
• Point-to-point configurations do not require IP addresses on each subinterface on each router.
• Multipoint configurations do not require IP addresses on each subinterface on each router.
5. Which three algorithms can be used to encrypt user data in an IPSec VPN framework? (Choose three.)
• 3DES
• AES
• Diffie-Hellman
• DES
• ESP
• SHA
CCNA Discovery 4 - Module 8 Exam Answers V.4 #1-5
• administrative distance
• cost
• hop count
• passive interface
2. IPSec operates at which layer of the OSI model?
• application
• network
• datalink
• transport
3. Which is true regarding Frame Relay LMI?
• There are three LMI types standardized by ANSI, ITU-T, and Cisco.
• Routers at each end of a Frame Relay virtual circuit must always use the same LMI type.
• The LMI type must be manually configured.
• The only function of LMI is to verify the connection between the router and the Frame Relay switch.
4. Which statement identifies the IP address design for subinterfaces that are configured for a Frame Relay network?
• Multipoint configurations require the IP address of each subinterface on each router to be in its own subnet.
• Multipoint configurations require IP addresses for each subinterface on each router to be a part of the same subnet.
• Point-to-point configurations require IP addresses for each subinterface on each router to be a part of the same subnet.
• Point-to-point configurations do not require IP addresses on each subinterface on each router.
• Multipoint configurations do not require IP addresses on each subinterface on each router.
5. Which three algorithms can be used to encrypt user data in an IPSec VPN framework? (Choose three.)
• 3DES
• AES
• Diffie-Hellman
• DES
• ESP
• SHA
Senin, 09 Februari 2009
CCNA Discovery 3 - Module 2 Exam Answers Version 4.0
CCNA Discovery 3 - Module 2 Exam Answers Version 4.0
1. What type of connection point is a point of presence (POP)?• between a client and a host
• between two local networks
• between a computer and a switch
• between an ISP and an Enterprise network
2. A network administrator needs to configure Telnet access to a router. Which group of commandsenable Telnet access to the router?
• Router(config)# enable password class
Router(config)# line con 0
Router(config-line)# login
Router(config-line)# password cisco
• Router(config)# ip host 192.168.1.1 NewYork
Router(config)# enable password cisco
• Router(config)# line aux 0
Router(config-line)# login
Router(config-line)# password cisco
• Router(config)# enable password class
Router(config)# line vty 0 4
Router(config-line)# login
Router(config-line)# password cisco
3. Which two types of information should be included in a business continuity plan? (Choose two.)
• maintenance time periods
• intrusion monitoring records
• offsite data storage procedures
• alternate IT processing locations*
• problem resolution escalation steps
4. Which two router parameters can be set from interface configuration mode? (Choose two.)
• IP address
• Telnet password
• hostname
• console password
• subnet mask
• enable secret password
5. Which two devices protect a corporate network against malicious attacks at the enterprise edge ?(Choose two.)
• demarc
• IP security (IPSec)
• Data Service Unit (DSU)
• intrusion prevention system (IPS)
• intrusion detection system (IDS)
6. Which three steps must be performed to remove all VLAN information from a switch but retain therest of the configuration? (Choose three.)
• Remove all VLAN associations from the interfaces.
• Remove the 802.1q encapsulation from the interfac
• Issue the command copy start run.
• Issue the command delete flash:vlan.dat.
• Issue the command erase start.
• Reload the switch.
7. What is the demarcation?
• physical point where the ISP responsibilty ends and the customer responsibilty begins
• physical location where all server farm connections meet before being distributed into the Core
• point of entry for outside attacks and is often vulnerable
• point of entry for all Access Layer connections from the Distribution Layer devices
8. Which device is responsible for moving packets between multiple network segments?
• router
• switch
• CSU/DSU
• IDS device
10. What information can an administrator learn using the show version command?
• Cisco IOS filename
• configured routing protocol
• status of each interface
• IP addresses of all interfaces
11. Which two situations require a network administrator to use out-of-band management to change arouter configuration? (Choose two.)
• Network links to the router are down.
• No Telnet password has been configured on the router.
• The administrator can only connect to the router using SSH.
• The network interfaces of the router are not configured with IP addresses.
• Company security policy requires that only HTTPS be used to connect to routers.
12. It is crucial that network administrators be able to examine and configure network devices fromtheir homes. Which two approaches allow this connectivity without increasing vulnerability to externalattacks? (Choose two.)
• Configure a special link at the POP to allow external entry from the home computer.
• Set up VPN access between the home computer and the network.
• Install a cable modem in the home to link to the network.
• Configure ACLs on the edge routers that allow only authorized users to access management portson network devices.
• Configure a server in the DMZ with a special username and password to allow external access.
13. A network administrator must define specific business processes to implement if a catastrophicdisaster prevents a company from performing daily business routines. Which portion of the networkdocumentation is the administrator defining?
• business security plan
• business continuity plan
• network solvency plan
• service level agreement
• network maintenance plan
14. A DoS attack crippled the daily operations of a large company for 8 hours. Which two optionscould be implemented by the network administrator to possibly prevent such an attack in the future?(Choose two.)
• install security devices with IDS and IPS at the enterprise edge
• reset all user passwords every 30 days
• filter packets based on IP address, traffic pattern, and protocol
• deny external workers VPN access to internal resources
• ensure critical devices are physically secure and placed behind the demarc
15. A network manager wants to have processes in place to ensure that network upgrades do not affectbusiness operations. What will the network manager create for this purpose?
• business security plan
• business continuity plan
• service level agreement
• network maintenance plan
16. An investment company has multiple servers that hold mission critical datThey are worried that ifsomething happens to these servers, they will lose this valuable information. Which type of plan isneeded for this company to help minimize loss in the event of a server crash?
• business security
• business continuity
• network maintenance
• service level agreement
17. When searching for information about authentication methods and usernames of companypersonnel, where can a network administrator look?
• Business Continuity Plan
• Business Security Plan
• Network Maintenance Plan
• Service Level Agreement
18. Refer to the exhibit. Which statement is true about port Fa5/1?
• When a violation is detected, the port will log the information to a syslog server.
• When a violation is detected, the port will go into err-disable mod
• There have been 11 security violations since the last reloa
• The port is currently in the shutdown state.
Minggu, 08 Februari 2009
CCNA Discovery 3 - Module 1 Exam Answers Version 4.0
CCNA Discovery 3 - Module 1 Exam Answers Version 4.0
1. What can be found at the enterprise edge?• Internet, VPN, and WAN modules
• Internet, PSTN, and WAN services
• server farms and network management
• campus infrastructure, including access layer devices
2. In which functional area of the Cisco Enterprise Architecture should IDS and IPS be located to detect
• and prevent services from accessing hosts?
• Enterprise Campus
• Edge Distribution
• Enterprise Edge
• Service Provider Edge
3. A business consultant must use Internet websites to research a report on the e-business strategies of several firms and then electronically deliver the report to a group of clients in cities throughout the world. Which two teleworker tools can the consultant use to accomplish this project? (Choose two.)
• VoIP
• VPN
• HTTP
• Telnet
4. Which two measures help ensure that a hardware problem does not cause an outage in an enterprise LAN that supports mission critical services? (Choose two.)
• providing failover capability
• installing redundant power supplies
• purchasing more bandwidth from the ISP
• implementing broadcast containment with VLANs
• installing routers that can handle a greater amount of throughput
5. Which task would typically only require services located at the access layer of the hierarchical design model?
• connecting to the corporate web server to update sales figures
• using a VPN from home to send data to the main office servers
• printing a meeting agenda on a local departmental network printer
• placing a VoIP call to a business associate in another country
• responding to an e-mail from a co-worker in another department
6. How does a VPN work to support remote user productivity?
• It uses SSL to encrypt remote user logins to the corporate intranet.
• It uses secure Telnet for remote user connections to internal network devices.
• It creates a virtual circuit that allows real-time communications between any two Internet endpoints.
• It uses encapsulation to create a secure tunnel for transmission of data across non-secure networks.****
7. A remote user needs to access a networking device on the internal network of the company. The transactions between the remote user and the device must be secure. Which protocol enables this to happen securely?
• HTTP
• SSH
• Telnet
• FTP
8. What does VoIP provide to telecommuters?
• high-quality, live-video presentations
• real-time voice communications over the Internet
• ability to share desktop applications simultaneously
• secure, encrypted data transmissions through the Internet
9. Which functional component of the Cisco Enterprise Architecture is responsible for hosting internal servers?
• enterprise campus
• enterprise edge
• service provider edge
• building distribution
10. What is the purpose of the Cisco Enterprise Architecture?
• remove the three-layer hierarchical model and use a flat network approach
• divide the network into functional components while still maintaining the concept of Core, Distribution, and Access Layers
• provide services and functionality to the core layer by grouping various components into a single
• component located in the access layer
• reduce overall network traffic by grouping server farms, the management server, corporate intranet, and e-commerce routers in the same layer
11. Which two solutions would an enterprise IT department use to facilitate secure intranet access for remote workers? (Choose two.)
• VPN
• NAT
• user authentication
• client firewall software
• packet sniffing
12. Which statement describes the difference between an enterprise WAN and an enterprise extranet?
• An enterprise WAN is designed to interconnect local LANs, while an enterprise extranet is designed to interconnect remote branch offices.
• An enterprise WAN is designed to interconnect branch offices, while an enterprise extranet is designed to give access to external business partners.
• An enterprise WAN is designed to provide remote access for its teleworkers, while an enterprise extranet is designed to provide Internet connectivity for the enterprise.
• An enterprise WAN is designed to provide Internet connectivity for the enterprise, while an enterprise extranet is designed to provide remote access to the enterprise network for teleworkers.
13. Why would a network administrator want to limit the size of failure domains when designing a network?
• reduces the effect of Ethernet collisions
• reduces the impact of a key device or service failure
• reduces the impact of Internet congestion on critical traffic
• reduces the impact of blocking broadcast packets at the edge of the local network
14. What is the main purpose of the Access Layer in a hierarchically designed network?
• performs routing and packet manipulation
• supplies redundancy and failover protection
• provides a high-speed, low-latency backbone
• serves as a network connection point for end-user devices
15. Which three functions are performed at the Distribution Layer of the hierarchical network model? (Choose three.)
• forwards traffic that is destined for other networks
• isolates network problems to prevent them from affecting the Core Layer
• allows end users to access the local network
• provides a connection point for separate local networks
• transports large amounts of data between different geographic sites
• forwards traffic to other hosts on the same logical network
16. What is a benefit of having an extranet?
• It provides web-like access to company information for employees only.
• It limits access to corporate information to secure VPN or remote access connections only.
• It allows customers and partners to access company information by connecting to a public web server.
• It allows suppliers and contractors to access confidential internal information using controlled external connections.
17. What are two important characteristics or functions of devices at the Enterprise Edge? (Choose two.)
• providing Internet, telephone, and WAN services to the enterprise network
• providing a connection point for end-user devices to the enterprise network
• providing high-speed backbone connectivity with redundant connections
• providing intrusion detection and intrusion prevention to protect the network against malicious activity
• providing packet inspection to determine if incoming packets should be allowed on the enterprise network
18. Why is TCP the preferred Layer 4 protocol for transmitting data files?
• TCP is more reliable than UDP because it requires lost packets to be retransmitted.
• TCP requires less processing by the source and destination hosts than UDP.
• UDP introduces delays that degrade the quality of the data applications.
• TCP ensures fast delivery because it does not require sequencing or acknowlegements.
19. The ABC Corporation implements the network for its new headquarters using the Cisco Enterprise Architecture. The network administrator wants to filter the traffic from and to the outside world. Where should the administrator deploy a firewall device?
• server farm
• enterprise edge
• enterprise campus
• service provider edge
20. Which two statements are reasons why UDP is used for voice and video traffic instead of TCP?(Choose two.)
• TCP requires all data packets to be delivered for the data to be usable.
• The acknowledgment process of TCP introduces delays that break the streams of data.
• UDP does not have mechanisms for retransmitting lost packets.
• UDP tolerates delays and compensates for them.
• TCP is a connectionless protocol that provides end-to-end reliability.
• UDP is a connection-oriented protocol that provides end-to-end reliability.
Jumat, 09 Januari 2009
Networking for Home and Small Businesses - Lab 3.1.5 Building a Peer-to-Peer Network
Objectives
• Design and build a simple peer-to-peer network using a crossover cable supplied by the instructor.
• Verify connectivity between the peers using the ping command.
Background / Preparation
In this hands-on lab, you will plan and build a simple peer-to-peer network using two PCs and an Ethernet
crossover cable.
The following resources are required:
• Two Window XP Professional PCs, each with an installed and functional Network Interface Card
(NIC)
• An Ethernet crossover cable
Step 1: Diagram the network
a. A network diagram is a map of the logical topology of the network. In the space below, sketch a
simple peer-to-peer network connecting two PCs. Label one PC with IP address 192.168.1.1 and the other PC with IP address 192.168.1.2. Use labels to indicate connecting media and any necessary network devices.
b. A simple network like the one you designed can use a hub or switch as a central connecting device, or the PCs may be directly connected. Which kind of cable is required for a direct Ethernet connection between the two PCs? _________________________________________________________
Ethernet crossover cable
Step 2: Document the PCs
a. Check the computer name settings for each PC and make adjustments as necessary. For each PC, select Start and Control Panel. Double-click the System icon, then click the Computer Name tab.
Write down the computer name that is displayed following Full computer name:
| PC1 Nam
e: | | |
| PC2 Name: |
b. Check to see if the two PCs have the same name. If they do, change the name of one PC by clicking the Change button, typing a new name in the Computer name field, then clicking OK.
c. Click OK to close the System Properties window.
d. Why is it important that each PC on a network have a unique name?
____________________________________________________________________________
Answers will vary. Example: Each PC represents a unique network resource. The name is used along with the IP address to identify it on the network, so the name must be unique
Step 3: Connect the Ethernet cable
a. Use the Ethernet crossover cable provided by the instructor. Plug one end of the cable into the
Ethernet NIC of PC1.
b. Plug the other end of the cable into the Ethernet NIC of PC2. As you insert the cable, you should hear a click which indicates that the cable connector is properly inserted into the port.
Step 4: Verify physical connectivity
a. After the Ethernet crossover cable is connected to both PCs, take a close look at each Ethernet port. A light (usually green or amber) indicates that physical connectivity has been established between the two NICs. Try unplugging the cable from one PC then reconnecting it to verify that the light goes off then back on.
b. Go to the Control Panel, double click the Network Connections icon, and confirm that the local area connection is established. The following figure shows an active local area connection. If physical connectivity problems exist, you will see a red X over the Local Area Connection icon with the words Network cable unplugged.
c. If the Local Area Connection does not indicate that it is connected, troubleshoot by repeating Steps 3 and 4. You may also want to ask your instructor to confirm that you are using an Ethernet crossover cable.
Step 5: Configure IP settings
a. Configure the logical addresses for the two PCs so that they are able to communicate using TCP/IP. On one of the PCs, go to the Control Panel, double click the Network Connections icon, and then right click the connected Local Area Connection icon. Choose Properties from the pull-down menu.
b. Using the scroll bar in the Local Area Connection Properties window, scroll down to highlight
Internet Protocol (TCP/IP). Click the Properties button.
c. Select the Use the following IP address radio button and enter the following information:
| IP Address | 192.168.1.1 |
| Subnet Mask | 255.255.255.0 |
d. Click OK, which will close the Internet Protocol (TCP/IP) Properties window. Click the Close button to exit the Local Area Connection Properties window.
e. Repeat steps 5a – 5d for the second PC using the following information:
| IP Address | 192.168.1.2 |
| Subnet Mask | 255.255.255.0 |
Step 6: Verify IP connectivity between the two PCs
NOTE: To test TCP/IP connectivity between the PCs, Windows Firewall must be disabled temporarily on both PCs. Windows Firewall should be re-enabled after the tests have been completed.
a. On PC1, on the Windows XP desktop, click Start. From the Start menu, select Control Panel, and double-click Network Connections.
b. Right-click the Local Area Connection icon and select Properties. Click the Advanced tab. Locate and click the Settings button.
c. Make a note of whether the firewall settings are ENABLED (ON) for the Ethernet port or DISABLED (OFF) for the Ethernet port. ____________________________________________________
d. If the firewall settings are enabled, click the Off (not recommended) radio button to disable the firewall. The setting will be re-enabled in a later step. Click OK in this dialog box and the following to apply this setting.
e. Now that the two PCs are physically connected and configured correctly with IP addresses, we need to make sure they communicate with each other. The ping command is a simple way to accomplish this task. The ping command is included with the Windows XP operating system.
f. On PC1, go to Start, then Run. Type cmd, and then click OK. A Windows command prompt window will appear as shown in the figure below.
g. At the > prompt, type ping 192.168.1.2 and press Enter. A successful ping will verify the IP
connectivity. It should produce results similar to those shown in here.
h. Repeat Steps 6a-6c on the second PC. The second PC will ping 192.168.1.1.
i. Close the Windows command prompt window on both PCs.
Step 7: Verify connectivity using My Network Places
x
b. Do you see an icon for the other PC in your peer-to-peer network? ___________________ Yes
c. What is the name of the other PC? _________________________________ Answers will vary
d. Is it the same name you recorded in Step 2? ____________________________________ Yes
e. Perform Step 7a on the second PC.
f. Close any open windows.
Step 8: (Optional – Use only if the Firewall was originally ENABLED) Re-enable the firewall
a. If you disabled the Windows Firewall in Step 6, click Start, select Control Panel, and open the Network Connections control panel.
b. Right-click the Ethernet network connection icon and select Properties. Click the Advanced tab. Locate and click Settings.
c. If the firewall settings are disabled (and they were enabled before this lab began), click the On radio button to enable the firewall. Click OK in this dialog box and the following one to apply this setting.