You are responsible for increasing the security within the Company LAN. Of the following choices listed below,
which is true regarding layer 2 security and mitigation techniques? ()
A. Enable root guard to mitigate ARP address spoofing attacks.
B. Configure DHCP spoofing to mitigate ARP address spoofing attacks.
C. Configure PVLANs to mitigate MAC address flooding attacks.
D. Enable root guard to mitigate DHCP spoofing attacks.
E. Configure dynamic APR inspection (DAI) to mitigate IP address spoofing on DHCP untrusted ports.
F. Configure port security to mitigate MAC address flooding
G. None of the other alternatives apply
您可能感興趣的試卷
你可能感興趣的試題
Refer to the exhibit. An attacker is connected to interface Fa0/11 on switch A-SW2 and attempts to establish a DHCP server for a man-in-middle attack.
Which recommendation, if followed, would mitigate this type of attack?()
A. All switch ports in the Building Access block should be configured as DHCP untrusted ports.
B. All switch ports in the Building Access block should be configured as DHCP trusted ports.
C. All switch ports connecting to servers in the Server Farm block should be configured as DHCP untrusted ports.
D. All switch ports connecting to hosts in the Building Access block should be configured as DHCP trusted ports.
E. All switch ports in the Server Farm block should be configured as DHCP untrusted ports.
F. All switch ports connecting to hosts in the Building Access block should be configured as DHCP untrusted ports.
Refer to the exhibit. On the basis of the output generated by the show commands,
which two statements are true?()
A. Because it is configured as a trunk interface, interface gigabitethernet 0/1 does not appear in the show vlan output.
B. VLAN 1 will not be encapsulated with an 802.1q header.
C. There are no native VLANs configured on the trunk.
D. VLAN 2 will not be encapsulated with an 802.1q header.
E. All interfaces on the switch have been configured as access ports.
F. Because it has not been assigned to any VLAN, interface gigabitethernet 0/1 does not appear in the show vlan output.
Refer to the exhibit. Based upon the output of show vlan on switch CAT2,
what can we conclude about interfaces Fa0/13 and Fa0/14? ()
A. that interfaces Fa0/13 and Fa0/14 are in VLAN 1
B. that interfaces Fa0/13 and Fa0/14 are down
C. that interfaces Fa0/13 and Fa0/14 are trunk interfaces
D. that interfaces Fa0/13 and Fa0/14have a domain mismatch with another switch
E. that interfaces Fa0/13 and Fa0/14have a duplex mismatch with another switch
Refer to the exhibit. Switch P1S1 is not applying VLAN updates from switch P2S1.
What are three reasons why this is not occurring?()
A. Switch P2S1 is in server mode.
B. Switch P1S1 is in transparent mode.
C. The MD5 digests do not match.
D. The passwords do not match.
E. The VTP domains are different.
F. VTP trap generation is disabled on both switches.
Refer to the show interface Gi0/1 switchport command output shown in the exhibit.
Which two statements are true about this interface?()
A. This interface is a member of a voice VLAN.
B. This interface is configured for access mode.
C. This interface is a dot1q trunk passing all configured VLANs.
D. This interface is a member of VLAN7.
E. This interface is a member of VLAN1.
You’re a network administer and you issue the command (show port 3/1) on an Ethernet port. To your surprise you notice a non-zero entry in the ’Giants’ column.
What could be the cause of this? ()
A. IEEE 802.1Q
B. IEEE 802.10
C. Misconfigured NIC
D. User configuration
E. All of the above
The Company administrator has issue the "show vlan id 5" command.
What will this command display? ()
A. Ports in VLAN 5
B. Utilization
C. VLAN information on port 0/5
D. Filters
E. MTU and type
Which of the following should you enable to prevent a switch from forwarding packets with source addresses that are outside an administratively defined group? ()
A. DAI
B. STP
C. PVLAN
D. port security
Refer to the exhibit. The switchport output in Figure 1 displays the default settings of interface FastEthernet 0/13 on switch SW1. Figure 2 displays the desired interface settings.
Which command sequence would configure interface FastEthernet 0/13 as displayed in Figure 2? ()
A. SW1(config-if)# switchport trunk encapsulation dot1q SW1(config-if)# switchport mode trunk SW1(config-if)# switchport trunk native DATA SW1(config-if)# switchport trunk allowed vlan 1,10,20
B. SW1(config-if)# switchport trunk encapsulation dot1q SW1(config-if)# switchport mode dynamic auto SW1(config-if)# switchport trunk native DATA SW1(config-if)# witchport trunk allowed vlan add 1,10,20
C. SW1(config-if)# switchport trunk encapsulation dot1q SW1(config-if)# switchport mode dynamic desirable SW1(config-if)# switchport trunk native vlan DATA SW1(config-if)# switchport trunk allowed vlan 1,10,20
D. SW1(config-if)# switchport trunk encapsulation dot1q SW1(config-if)# switchport mode dynamic desirable SW1(config-if)# switchport trunk native vlan 10 SW1(config-if)# switchport trunk allowed vlan 1,10,20
E. SW1(config-if)# switchport trunk encapsulation dot1q SW1(config-if)# switchport mode dynamic Desirable SW1(config-if)# switchport trunk native vlan 10
You need make configuration changes to an existing layer 3 switch in the Company network. On a multilayer Catalyst switch,
which interface command is used to convert a Layer 3 interface to a Layer 2 interface?()
A. switchport access vlan vlan-id
B. switchport
C. switchport mode access
D. no switchport
E. None of the other alternatives apply
最新試題
If G1/0/1 on DS1 is shutdown, what will be the current priority value of the Vlan105’s group on DS1 ?()
Which two statements are true when the extended system ID feature is enabled? ()
Refer to the exhibit and the partial configuration of switch SW_A and SW_B. STP is configured on all switches in the network. SW_B receives this error message on the console port:00:06:34: %CDP-4-DUPLEX_MISMATCH: duplex mismatch discovered on FastEthernet0/5 (not half duplex), with SW_A FastEthernet0/4 (half duplex) , with TBA05071417(Cat6K-B) 0/4 (half duplex). What would be the possible outcome of the problem?()
Refer to the exhibit. For what purpose is the command show ip cef used?()
Refer to the exhibit. Based on the output of the show spanning-tree command, which statement is true? ()
Which two statements are true about BPDU port-guard and BPDU filtering?()
Refer to the exhibit. On the basis of the output of the show spanning-tree inconsistentports command, which statement about interfaces FastEthernet 0/1 and FastEthernet 0/2 is true?()
Which router redundancy protocol cannot be configured for interface tracking?()
Refer to the exhibit. Initially, LinkA is connected and forwarding traffic. A new LinkB is then attached between SwitchA and HubA. Which two statements are true about the possible result of attaching the second link?()
Which three statements are true of the Link Aggregation Control Protocol (LACP)?()