Question No: 10

A company needs to configure a new firewall and have only one public IP address to use in this firewall.

The engineer need to configure the firewall with NAT to handle inbound traffic to the mail server in addition to internet outbound traffic. Which options could he use ? (Choose Two)

A. Static NAT for inbound traffic on port 25

B. Dynamic NAT for outbound traffic

C. Static NAT for outbound traffic on port 25

D. Dynamic NAT for inbound traffic

E. NAT overload for outbound traffic

F. NAT overload for inboud traffic on port 25

Answer: A,E

Question No: 11

Which of these Layer 2 access designs does not support VLAN extensions?

A. FlexLinks

B. loop-free U

C. looped square

D. looped triangle

E. loop-free inverted U

Answer: B

Question No: 12

An engineer is designing a QoS architecture for a small organization and must meet these requirements:

*Guarantees resources for a new traffic flow prior to sending

*Polices traffic when the flow does not conform Which QoS architecture model will accomplish this?

A. auto quality of service

B. modular quality of service

C. differentiated services

D. integrated services

Answer: D

Question No: 13

What is an advantage of using the Cisco FabricPath feature in a data center environment?

A. VSS does not have to be configured.

B. Transparent Interconnection of Lots of Links can be configured simultaneously.

C. Equal-Cost Multipath can be used to choose the forwarding path.

D. The control plane and management plane remain separate.

Answer: C

Question No: 14

A network engineer must create a backup network connection between two corporate sites over the Internet using the existing ASA firewalls. Which VPN technology best satisfies this corporate need? (E)




D. IPSec



Answer: D

Question No: 15

What are the True regarding 802.1X. (Choose three)

A. Authenticates the user itself

B. Authenticates the device itself

C. If the device does not support, allow the access automatically

D. Cisco proprietary

E. Industry standard

Answer: A,B,E

Question No: 16

Refer to the exhibit.

Which recommended practice is applicable?

A. If no core layer is deployed, the design will be easier to scale.

B. A dedicated campus core layer should be deployed for connecting three or more buildings.

C. If no core layer is deployed, the distribution switches should not be fully meshed.

D. A dedicated campus core layer is not needed for connecting fewer than five buildings.

Answer: B

Question No: 17

Which statement about data center access layer design modes is correct?

A. The access layer is the first oversubscription point in a data center design.

B. The data center access layer provides the physical-level connections to the server resources and only operates at Layer 3.

C. When using a Layer 2 looped design, VLANs are not extended into the aggregation layer.

D. When using a Layer 3 design, stateful services requiring Layer 2 connectivity are provisioned from the aggregation layer.

Answer: A

Question No: 18

Which option is a benefit of the vPC+ feature?

A. Cisco FabricPath is not required in the network domain.

B. This feature provides fault domain separation.

C. Nonfabric devices, such as a server or a classic Ethernet switch, can be connected to two fabric switches that are configured with vPC.

D. The control plane and management plane are combined into one logical plane.

Answer: C

Question No: 19

Which two options improve BGP scalability in a large autonomous system? (Choose two.)

A. route reflectors

B. route redistribution

C. confederations

D. communities

Answer: A,C

