Selasa, 14 April 2009

CCNA Interview Questions #15/04/2009#

CCNA Interview Questions
Q: What must you do to enable IP routing on your router? (Choose all of the correct answers.)
A. Enable the routing protocol.
B. Set clocking on all serial interfaces.
C. Assign IP addresses to your router’s interfaces.
D. Assign the bandwidth parameter to your serial interfaces.
Ans: A & C
Q: What switching method examines the destination MAC address as the frame is being received and then begins forwarding the frame prior to receiving the entire frame?
A. Modified Cut Through
B. Store and Forward
C. Cut Through
D. Fragment Free
Ans: C
Q: What command activates the IP routing process?
A. router
B. enable
C. network
D. no shutdown
Ans: C
Q: RIP generates routing updates every _ _ _ _ seconds.
A. 15
B. 30
C. 60
D. 90
Ans: B
Q: Which routing protocol would allow a network administrator scalability, VLSM support and minimize overhead if the network administrator wants to merge different networks all using routers from multiple vendors?
A. VTP
B. RIP
C. IGRP
D. OSPF
Ans: D
Q: Host A is communicating with the server. What will be the source MAC address of the frames received by Host A from the server?
A. The MAC address of Host A.
B. The MAC address of router interface E0.
C. The MAC address of the server network interface.
D. MAC address of router interface E1.
Ans: B
Q: What does the concept route aggregation mean when one talks about using variable subnet masking?
A. Reclaiming unused space by means of changing the subnet size.
B. Calculating the available host addresses in the AS.
C. Combining routes to multiple networks into one supernet.
D. Deleting unusable addresses through the creation of many subnets.
Ans: C
Q: Which PPP authentication methods will you use when configuring PPP on an interface of a Cisco router? (Select two options.)
A. SSL
B. SLIP
C. PAP
D. CHAP
E. VNP
Ans: C, E

Senin, 13 April 2009

CCNA Interview Questions #14/04/2009#

CCNA Interview Questions #14/04/2009#
Q: Which of the following about Routing Protocols is correct? (choose all that apply)
A. RIP 2 is a Distance Vector Protocol
B. The RIP 1 uses bandwidth and delay as the metric
C. RIP 1 uses subnet mask
D. The Update timer value of IGRP is 90 sec.
Ans: A & E
Q: The switch port that is chosen to forward traffic for a segment is called a _ _ _ _
A. Root port
B. Alternate port
C. Backup port
D. Designated port
Ans: D
Q: Which of the following is false concerning VLANs?
A. A VLAN is a broadcast domain.
B. A VLAN is a logical group of users.
C. A VLAN is location-dependent.
D. A VLAN is a subnet.
Ans: C
Q: Which of the following trunking methods is/are proprietary to Cisco?
A. 802.1Q
B. 802.10
C. LANE
D. ISLbr
Ans: B & D
Q: What command is used to delete the configuration stored in NVRAM?
A. erase startup-config
B. erase running-config
C. delete nvram
D. erase nvram
Ans: A
Q: What is the maximum number of hops that OSPF allows before marking a network as unreachable?
A. 15
B. Unlimited
C. 16
D. 255
Ans: B
Q: Which one of the following is a reason to use a hardware address?
A. To transmit a packet from one local device to another local device.
B. To obtain a vendor code/serial number from the user.
C. To transmit a frame from one interface to another interface.
D. To contain logical information about a device to use an end-to-end transmission.
Ans: C
Q: Which VTP mode(s) will propagate VTP messages?
A. Client and server
B. Server
C. Client, server, and transparent
D. Transparent
Ans: C
Q: Which 2950 command enables trunking?
A. switchport mode trunk
B. trunking on
C. trunking enable
D. switchport trunk on
Ans: A

Rabu, 18 Maret 2009

CCNA Interview Questions #2

CCNA Interview Questions
Q: Which type of traffic is sent to a group of devices?
A. Multicast
B. Unicast
C. Broadcast
D. Groupcast
Ans: A
Q: Which of the following is a Network layer protocol for the TCP/IP protocol stack?
A. TCP
B. UDP
C. ICMP
D. None of these
Ans: D
Q: Which type of traffic is not flooded?
A. Multicast
B. Known unicast
C. Broadcast
D. Unknown unicast
Ans: B
Q: Put the following in the correct order, from high to low: session (a), presentation (b), physical (c), data link (d), network (e), application (f), transport (g).
A. c, d, e, g, a, b, f
B. f, a, b, g, d, e, c
C. f, b, g, a, e, d, c
D. f, b, a, g, e, d, c
Ans: D
Q: Which of the following standards or protocols are used by the session layer?
A. JPEG
B. NFS
C. TCP
D. Ethernet
Ans: B
Q: The _ _ _ _ layer provides for hardware addressing.
A. Transport
B. Network
C. Data link
D. Physical.
Ans: C
Q: A _ _ _ _ is basically all of the components, hardware and software, involved in connecting computers across small and large distances.
A. LAN
B. WAN
C. Network
D. SAN
Ans: C
Q: BPDU stands for _ _ _ _
A. Bridge Protocol Description Unicast
B. Bridge Protocol Data Unit
C. Bridge Protocol Description Unit
D. Bridge Protocol Data Unicast
Ans: B
Q: The root switch is the one elected with the _ _ _ _
A. Lowest MAC address
B. Highest MAC address
C. Lowest switch ID
D. Highest switch ID
Ans: C

CCNA Interview Questions #1

CCNA Interview Questions

Q: Which of the following is true concerning bridges?
A. They switch frames in hardware.
B. They support half- and full-duplexing.
C. They support one collision domain for the entire bridge.
D. They do only store-and-forward switching.
Ans: D
Q: With _ _ _ _ switching, the switch reads the destination MAC address of the frame and immediately starts forwarding the frame.
A. Store-and-forward
B. Cut-through
C. Fragment-free
D. Runtless
Ans: B
Q: When choosing a networking product, you should consider all of the following except_ _ _ _
A. Ease of installation and support
B. Product features and functions
C. Backplane capacity
D. Amount of memory
Ans: D
Q: When choosing a WAN solution, consider all of the following except _ _ _ _
A. Number of devices
B. Cost-effectiveness
C. Availability
D. Amount of bandwidth
Ans: A
Q: A 1924 has _ _ _ _ Ethernet interfaces.
A. 24
B. 26
C. 27
D. 28
Ans: C
Q: The TCP/IP protocol stack has _ _ _ _l ayers.
A. 4
B. 5
C. 6
D. 7.
Ans: B
Q: Which of the following is not true concerning TCP?
A. Provides for reliable connections
B. Uses windowing for flow control
C. Multiplexes applications
D. Is more efficient than UDP.
Ans: D
Q: Which of the following is true concerning full-duplexing?
A. It can either send or receive frames, but not both simultaneously.
B. It can be used with hubs.
C. It can be used with 10Base5 cabling.
D. It uses point-to-point connections.
Ans: D

Rabu, 11 Maret 2009

Networking Terminology.

Networking Terminology.

Data Network .

Data networks developed as a result of business applications that were written for microcomputers. 1 At that time microcomputers were not connected as mainframe computer terminals were, so there was no efficient way of sharing data among multiple microcomputers. 2 It became apparent that sharing data through the use of floppy disks was not an efficient or cost-effective manner in which to operate businesses. Sneakernet created multiple copies of the data. Each time a file was modified it would have to be shared again with all other people who needed that file. If two people modified the file and then tried to share it, one of the sets of changes would be lost. Businesses needed a solution that would successfully address the following three problems:

  • How to avoid duplication of equipment and resources
  • How to communicate efficiently
  • How to set up and manage a network

Businesses realized that networking technology could increase productivity while saving money. Networks were added and expanded almost as rapidly as new network technologies and products were introduced. In the early 1980s networking saw a tremendous expansion, even though the early development of networking was disorganized.

In the mid-1980s, the network technologies that had emerged had been created with a variety of different hardware and software implementations. Each company that created network hardware and software used its own company standards. These individual standards were developed because of competition with other companies. Consequently, many of the new network technologies were incompatible with each other. It became increasingly difficult for networks that used different specifications to communicate with each other. This often required the old network equipment to be removed to implement the new equipment.

One early solution was the creation of local-area network (LAN) standards. 3 Because LAN standards provided an open set of guidelines for creating network hardware and software, the equipment from different companies could then become compatible. This allowed for stability in LAN implementation.

In a LAN system, each department of the company is a kind of electronic island. As the use of computers in businesses grew, it soon became obvious that even LANs were not sufficient. 4

What was needed was a way for information to move efficiently and quickly, not only within a company, but also from one business to another. 5 The solution was the creation of metropolitan-area networks (MANs) and wide-area networks (WANs). Because WANs could connect user networks over large geographic areas, it was possible for businesses to communicate with each other across great distances. Figure 6 summarizes the relative sizes of LANs and WANs.

Selasa, 03 Maret 2009

Data Rate Converter

The following tool can be used to convert data rates. To use it, enter a number in the first box and choose your unit to convert, then click the "Convert" button.

note: This converter requires the use of a JavaScript enabled Browser.

Data Rate Converter

Access Control Lists (ACL)

Access lists are used to classify IP packets, the classification applied to these packets can then be used in a number of features:-

  • Security (Access Control)
  • Encryption
  • Policy Based Routing
  • Quality of Service (QoS), Queues
  • Network Access Translation (NAT)
  • Port Access Translation (PAT)
  • Dial on Demand Routing (Interesting Dial Traffic)

Access lists can be applied on Cisco IOS Routers and Switches, they are generally applied to interfaces or access ports in specific directions (e.g. incoming or outgoing).

Types of Access List

There are two types of Access List:

  • Standard ? Can only be used to look at the source IP of a packet.
  • Extended ? Can be used to look at source IP, destination IP, IP protocol, source TCP/UDP port and destination TCP/UDP port.

These two types of Access List are identified by the first argument of the ACL statement, an ID which is used to identify the list. This argument could fall within one of the following:

  • 1 ? 99 or 1300 ? 1999 Standard Access List
  • 100 ? 199 or 2000 ? 2699 Extended Access List
  • Name Named Access List

Specifying an Access List from 1 to 99 or 1300 to 1300 instructs the router that it is a Standard access list, or from 100 to 199 or 2000 to 2699 that it is an Extended Access List. Named Access Lists allow you to give an Access List an alphanumeric, more east to remember identification. Named Access lists also allow you to delete specific Access Lists lines.

Access List Components

The general components of an access list configuration are:

  • Access List Identification (used to identify list, you could have multiple lists)
  • Direction (e.g. in or out of router)
  • IP Address Pattern to Match (e.g. Source, Destination)
  • Action (e.g. Permit or Deny)

The structure of access lists is as follows:

Standard Access List -

access-list

Extended Access List -

access-list [Source Port] [Destination Port][

interface e1

ip access-group 1 in

access-list 1 permit 172.16.1.1 0.0.0.0

The configuration lines above demonstrate how a Standard Access List (you can tell it is a standard access list because it has an access list number identifier of 1). This access list has been applied to the e1 interface in the in direction. The access list is looking for packets matching a source IP address of 172.16.1.1, and permitting the packet to pass; all other packets which do not match this pattern will be discarded.

It is important to note that at the bottom of every access list there is an implicit ?deny all? which is not shown in the configuration. For this reason you should always have at least one permit statement in every Access List (unless you really do want to stop all traffic passing through an interface).

Access lists do not filter traffic that originates from the same router. You can only specify one ACL per protocol, per direction, per interface.


Access List Masks

Wildcard Masks are used to define how much of an IP Address is used in a match, all of it, or part of it? When performing an address filter, the mask identifies how much of an IP Address to check and ignore.

The mask works in a similar way to Subnet Masks, however they are the opposite way round, for this reason they are sometime known as ?inverted masks?. Take the following extended access list:

interface e1

ip access-group 1 out

access-list 101 deny ip 192.168.1.10 0.0.0.255 0.0.0.0 0.0.0.0


This extended access list (note extended because it has a identifier of 101), it is denying ALL traffic out of the e1 interface. The reason why it is blocking all addresses in the 192.168.1.X range is because of the Mask which follows it in the statement above (0.0.0.255). This mask is basically saying ?Match all 0?s and ignore 255?s), 255 it is kind of like the wildcard * or % used in file or database searches.

If we go into more detail around Access Lists masks we need to convert them, like subnet masks, into binary (0 means check value of corresponding bit in IP Address and 1 means ignore value of corresponding bit in IP Address):

Binary

Decimal

Action

00000000

0

Check All Address Bits (Match All)

00111111

63

Ignore Last 6 Address Bits

00001111

15

Ignore Last 4 Address Bits

11111100

252

Check Last 2 Address Bits

11111111

255

Do Not Check Address(Ignore All Bits)

In the following example Access List line permits traffic from a single host to anywhere:

access-list 102 permit ip 192.168.1.2 0.0.0.0 0.0.0.0 0.0.0.0

However the Access Lists Statement above could also be written in a shorter way:

access-list 102 permit ip host 192.168.1.2 any

The ?host? keyword is a short way of specifying a single host IP Address.
The ?any? keyword specifies any IP Address.

host 192.168.1.2 = 192.168.1.2 0.0.0.0

any = 0.0.0.0 0.0.0.0


Using Port Numbers in Access Lists

When using extended access lists, as well as IP Addresses, you can also match for TCP or UDP Port numbers. An example use for this may be of use when you want to specifically block Telnet access to everyone except a single IP Address.

access-list 102 permit tcp host 192.168.1.3 192.168.2.100 0.0.0.0 eq 23

The ?eq 23? at the end of the Access List line above specifies that only a single host, 192.168.1.3, is allowed to Telnet to 192.168.2.100. This Access List should be applied to the router interface nearest the 192.168.2.100 host and it should be applied in the outwards direction.

Here is a list of commonly known port TCP numbers:

Port Number

Service

20

FTP Data

21

FTP Control

22

SSH

23

Telnet

25

SMTP Email

80

HTTP Web

110

POP3 Email

If you can not remember these port numbers Cisco routers also allow you to enter the name of the service in place of the port number:

access-list 102 deny tcp host 192.168.1.4 192.168.2.99 0.0.0.0 eq ftp

WARNING! Be careful not to cut off your remote access when applying an input Access List.

Verifying Access Lists

When you have applied Access Lists to a routers interface, you can verify if it is working by issuing the ?sh access-list? command. This will show you the number of matches which an Access List has made:

Router#show access-list 101

Extended IP access list 101

permit tcp any host 192.168.1.4 eq 23 (1 matches)

permit tcp any host 192.168.1.5 eq ftp (7 matches)

permit ip any any (4867 matches)

 
 
Or if you enable the logging option in your access list, you could look at the routers log:
 
Dec  6 16:21:51.350: %SEC-6-IPACCESSLOGP: list 101 permitted tcp
192.168.0.1(35265) (FastEthernet3/0 0002.559c.f66e) -> 192.168.1.4(23), 1 packet