Q31. After port security is deployed throughout an enterprise campus, the network team has been overwhelmed with port reset requests. They decide to configure the network to automate the process of re-enabling user ports. Which command accomplishes this task?

A. switch(config)# errdisable recovery interval 180

B. switch(config)# errdisable recovery cause psecure-violation

C. switch(config)# switchport port-security protect

D. switch(config)# switchport port-security aging type inactivity

E. switch(config)# errdisable recovery cause security-violation

Answer: B

Q32. Which database is used to determine the validity of an ARP packet based on a valid IP-to- MAC address binding?

A. DHCP snooping database

B. dynamic ARP database

C. dynamic routing database

D. static ARP database

Answer: A

Q33.  a network engineer is extending a LAN segment between two geographically separated data centers. Which enhancement to a spanning-tree design prevents unnecessary traffic

from crossing the extended LAN segment?

A. Modify the spanning-tree priorities to dictate the traffic flow.

B. Create a Layer 3 transit VLAN to segment the traffic between the sites.

C. Use VTP pruning on the trunk interfaces.

D. Configure manual trunk pruning between the two locations.

Answer: C

Q34. Which portion of AAA looks at what a user has access to?

A. authorization

B. authentication

C. accounting

D. auditing

Answer: A

Q35. Which statement about Cisco devices learning about each other through Cisco Discovery Protocol is true?

A. Each device sends periodic advertisements to multicast address 01:00:0C:CC:CC:CC.

B. Each device broadcasts periodic advertisements to all of its neighbors.

C. Each device sends periodic advertisements to a central device that builds the network topology.

D. Each device sends periodic advertisements to all IP addresses in its ARP table.

Answer: A

Q36. Which technique automatically limits VLAN traffic to only the switches that require it?

A. access lists

B. DTP in nonegotiate

C. VTP pruning


Answer: C

Q37. Which type of information does the DHCP snooping binding database contain?

A. untrusted hosts with leased IP addresses

B. trusted hosts with leased IP addresses

C. untrusted hosts with available IP addresses

D. trusted hosts with available IP addresses

Answer: A

Q38. Which authentication service is needed to configure 802.1x?

A. RADIUS with EAP Extension


C. RADIUS with CoA


Answer: A

Q39. What is the maximum number of VLANs that can be assigned to an access switchport without a voice VLAN?

A. 0

B. 1

C. 2

D. 1024

Answer: B

Q40. What is the maximum number of 10 Gigabit Ethernet connections that can be utilized in an EtherChannel for the virtual switch link?

A. 4

B. 6

C. 8

D. 12

Answer: C

