Q121.  - (Topic 8)

Which option is a valid hostname for a switch?

A. Switch-Cisco

B. Switch-Cisco!

C. SwitchCisco

D. SwitchCisc0

Answer: C

Q122.  - (Topic 4)

What are three reasons that an organization with multiple branch offices and roaming users might implement a Cisco VPN solution instead of point-to-point WAN links? (Choose three.)

A. reduced cost

B. better throughput

C. broadband incompatibility

D. increased security

E. scalability

F. reduced latency

Answer: A,D,E


IPsec offer a number of advantages over point to point WAN links, particularly when multiple locations are involved. These include reduced cost, increased security since all traffic is encrypted, and increased scalability as s single WAN link can be used to connect to all locations in a VPN, where as a point to point link would need to be provisioned to each location.

Q123.  - (Topic 7)

What Cisco IOS feature can be enabled to pinpoint an application that is causing slow network performance?


B. Netflow



Answer: B


Netflow can be used to diagnose slow network performance, bandwidth hogs and bandwidth utilization quickly with command line interface or reporting tools.

Q124. DRAG DROP - (Topic 6)

Drag the security features on the left to the specific security risks they help protect against on the right. (Not all options are used.)


Q125.  - (Topic 8)

Which routing protocol has the smallest default administrative distance?






Answer: D


Default Distance Value TableThis table lists the administrative distance default values of the protocols that Cisco supports:

Route Source

Default Distance Values

Connected interface 0

Static route 1

Enhanced Interior Gateway Routing Protocol (EIGRP) summary route 5

External Border Gateway Protocol (BGP) 20

Internal EIGRP 90

IGRP 100 OSPF 110

Intermediate System-to-Intermediate System (IS-IS) 115

Routing Information Protocol (RIP) 120

Exterior Gateway Protocol (EGP) 140

On Demand Routing (ODR) 160

External EIGRP 170

Internal BGP 200

Unknown* 255

Q126.  - (Topic 8)

Which three circumstances can cause a GRE tunnel to be in an up/down state? (Choose three.)

A. The tunnel interface IP address is misconfigured.

B. The tunnel interface is down.

C. A valid route to the destination address is missing from the routing table.

D. The tunnel address is routed through the tunnel itself.

E. The ISP is blocking the traffic.

F. An ACL is blocking the outbound traffic.

Answer: B,C,D

Q127.  - (Topic 8)

Which HSRP feature was new in HSRPv2?

A. VLAN group numbers that are greater than 255

B. virtual MAC addresses

C. tracking

D. preemption

Answer: A

Q128.  - (Topic 3)

A network administrator needs to allow only one Telnet connection to a router. For anyone viewing the configuration and issuing the show run command, the password for Telnet access should be encrypted. Which set of commands will accomplish this task?

A. service password-encryption

access-list 1 permit

line vty 0 4 login

password cisco access-class 1

B. enable password secret line vty 0


password cisco

C. service password-encryption line vty 1


password cisco

D. service password-encryption line vty 0 4


password cisco

Answer: C


Only one VTY connection is allowed which is exactly what's requested. Incorrect Answer: command.

line vty0 4

would enable all 5 vty connections.

Topic 4, WAN Technologies

Q129.  - (Topic 5)

Refer to the exhibit.

Which address range efficiently summarizes the routing table of the addresses for router Main?





Answer: B


The network is the best option as it includes all networks from – and does it more efficiently than the /16 and /18 subnets. The /21 subnet will not include all the other subnets in this one single summarized address.

Q130.  - (Topic 3)

Refer to the exhibit.

What commands must be configured on the 2950 switch and the router to allow communication between host 1 and host 2? (Choose two.)

A. Router(config)# interface fastethernet 0/0 Router(config-if)# ip address Router(config-if)# no shut down

B. Router(config)# interface fastethernet 0/0 Router(config-if)# no shut down Router(config)# interface fastethernet 0/0.1 Router(config-subif)# encapsulation dot1q 10

Router(config-subif)# ip address Router(config)# interface fastethernet 0/0.2

Router(config-subif)# encapsulation dot1q 20

Router(config-subif)# ip address

C. Router(config)# router eigrp 100 Router(config-router)# network

Router(config-router)# network

D. Switch1(config)# vlan database Switch1(config-vlan)# vtp domain XYZ

Switch1(config-vlan)# vtp server

E. Switch1(config)# interface fastethernet 0/1 Switch1(config-if)# switchport mode trunk

F. Switch1(config)# interface vlan 1 Switch1(config-if)# ip default-gateway

Answer: B,E


The router will need to use subinterfaces, where each subinterface is assigned a VLAN and IP address for each VLAN. On the switch, the connection to the router need to be configured as a trunk using the switchport mode trunk command and it will need a default gateway for VLAN 1.