题目编号是根据6月12号的题库 U) B" d2 X8 |
QUESTION 127, K3 u6 j. U0 f& U
Onwhich interface can port security be configured?
& `/ c* ^, Z$ |5 h% T' i: AA. static trunk ports
& m6 x+ z- i8 g- Y$ E0 E4 p* _B. destination port for SPAN
/ A$ C, W5 j vC. EtherChannel port group
: g; ]5 F3 o: D9 r8 e, TD. dynamic access point! t1 Z5 D [! F5 u( m% O
CorrectAnswer: A. d+ m$ Q+ C3 Z' [' p: I6 m( W6 I
Section:part3" Q% m) D' y! _0 Q6 ^5 L# F
Explanation trunk ports确实可以实现port-security,但是port-channel下不能,及时打问号有这个命令,但是敲不出来。从文档来看A和C都不能用,所以我的认为答案选D Port SecurityGuidelines and Restrictions Follow theseguidelines when configuring port security: A secure portcannot be a trunk port. A secure portcannot be a destination port for Switch Port Analyzer (SPAN). A secure portcannot belong to an EtherChannel port-channel interface. A secure port andstatic MAC address configuration are mutually exclusive. QUESTION 194
9 G1 z* n. x7 HA physical switch port is part of an EtherChannelgroup.What happens while the same port is configured as a SPAN destination?6 m- f% T8 ?' p- @, c. {& l* t
A. The port forwards traffic in the EtherChannel groupand acts as a SPAN source simultaneously/ K. L. u2 b1 Y2 d, w+ O. G
B. The operation is not allowed as an EtherChannelmember cannot be a SPAN source port
& w8 U3 X: z: t1 {C. The port is put in the errdisabled state and canonly be reenabled manually
% y/ A" _$ H+ S+ D! S: yD. The port is removed from the EtherChannel! L- b8 Y; e8 f4 U
Correct Answer: B
, U3 y; m0 V/ _3 S- @: ]/ vSection:part4
4 W& ^% k0 n5 qExplanation
2 ~0 b- O( h+ b- zExplanation/Reference: A destination port can be a physical port that is assigned to anEtherChannel group, even if the EtherChannel group has been specified as a SPANsource. The port is removed from the group while it is configured as a SPANdestination port QUESTION 198
8 L. F- W* @% w& e( cWhat happens if you apply this command “vlan dot1q tag native” ? ' Z( V( r, S M& y% C y
A. packet will be dropped
5 P. Q% P7 V0 R7 O; S3 YB. packet go to defautl vlan + V; n- F; {2 f! M! `
C. packet go to native vlan ; Q: l1 E8 U# E( A5 E0 ?) w
D. http://bbs.hh010.com/
8 K/ S' S0 o/ m( x9 Q ?7 h y. WCorrect Answer: C 我认为答案是A 6 g: ^( \# G' h/ _) L% e
Section: part4 Explanation/Reference: Usage Guidelines Typically, youconfigure 802.1Q trunks with a native VLAN ID, which strips tagging from allpackets on that VLAN. To maintain thetagging on the native VLAN and drop untagged traffic, usethe vlan dot1q tag native command. The switch will tagthe traffic received on the native VLAN and admit only 802.1Q-tagged frames,dropping any untagged traffic, including untagged traffic in the native VLAN. Control trafficcontinues to be accepted as untagged on the native VLAN on a trunked port, evenwhen the vlan dot1q tag native command is enabled. QUESTION 215/ S! P1 Z/ q0 V" g
Which statements about RSPAN are true? (Choose two.)
8 d, D! w+ V* L, a( T/ nA. It supports MAC adress learning.6 X- W! W: Y* w2 T4 `7 A
B. RSPAN VLANS can carry RSPAN traffic only./ s+ G$ O9 e l6 Q7 @8 [2 _
C. only one RSPAN VLAN can be configured per device.
/ _$ P( M: v& y9 z$ D& [. m% z7 cD. RSPAN VLANs are exempt from VTP pruning.
9 I$ e! s+ O: T5 }4 [8 jE. MAC address learning is not supported.
% Y2 N$ R2 W# p" AF. RSPAN uses are GRE tunnel to transmit captured traffic.
) g1 H# | C e9 v+ E. N' V' BCorrect Answer: BC 我认为答案是BE# N3 ~, y9 @9 K6 `
Section: part5 Explanation/Reference: RSPAN VLAN The RSPAN VLANcarries SPAN traffic between RSPAN source and destination sessions. It hasthese special characteristics:
2 z' F/ K$ s$ J. H) _ - All traffic in the RSPAN VLAN is always flooded.
8 H# Q& w3 ^9 r X( Q, y: v - No MAC address learning occurs on the RSPAN VLAN.! O3 p% N* ~- K8 o) J; A3 H
- RSPAN VLAN traffic only flows on trunk ports.
, m# u7 u7 i) m' O - RSPAN VLANs must be configured in VLAN configuration mode by using the remote-span VLAN configuration mode command./ O$ R" U( x1 S0 G# x) n
- STP can run on RSPAN VLAN trunks but not on SPAN destination ports.- ~! z) v: z) V0 l C
For VLANs 1 to 1005that are visible to VLAN Trunking Protocol (VTP), the VLAN ID and itsassociated RSPAN characteristic are propagated by VTP. If you assign an RSPANVLAN ID in the extended VLAN range (1006 to 4094), you must manually configureall intermediate switches. It is normal tohave multiple RSPAN VLANs in a network at the same time with each RSPAN VLANdefining a network-wide RSPAN session. That is, multiple RSPAN source sessionsanywhere in the network can contribute packets to the RSPAN session. It is alsopossible to have multiple RSPAN destination sessions throughout the network,monitoring the same RSPAN VLAN and presenting traffic to the user. The RSPANVLAN ID separates the sessions. QUESTION 216
& S: C _2 l' q* Q* C4 xWhen a private VLAN is configured, which mode must be configured as a routerfacing port?# j9 U1 Z# S2 a# j9 \3 X
A. isolated
. |8 J* |2 F& y" x8 Y x! YB. promiscuous
! Z$ c4 z3 g0 `4 P( DC. community
$ o: N; t& h1 T0 oD. .host* f! X8 I E! D7 h
Correct Answer: C 我认为答案是B
# z- {4 }4 j; Q) H% {9 GSection: part5 QUESTION 240
8 R" R$ s/ B W! F% B: {6 IEtherChannel guard misconfig is configured on a switch, which technologysupports that
9 ^# }9 g& ~* Q0 ]A. LACP! a& U% Z# ^8 \/ Q0 z) g! t
B. PagP
1 u* L+ h4 k$ S3 v& j3 t2 mC. STP
# x5 |2 c( K1 M) B( |/ g& S) SD. Port Security
: `, }2 w j2 T7 MCorrect Answer: C 我认为答案是A.LACP
j* a7 X' g1 R) P: ^- ASection: part5 LACP可以避免由于错误配置而造成二层交换环路;开始LACP后,在两端没有成功沟通的情况下,EtherChannel是不会建立的。不过这样的沟通机制引入了更 大数据报头和更长初始化延时。配置‘On’可以消除延时,但是如果配置失误的话可能造成严重后果。 QUESTION 251 VMPS question – a dynamicaccess port is member of which VLAN by default? A. VLAN 1 is thedefault VLAN C. none until theport VLAN is determined Correct Answer: A Section: part6 Explanation Explanation/Reference: 如果在文件列表中找到MAC地址,交换机就将端口分配给列表中该MAC所对应的VLAN。所有列表中没有的话,交换机就会将该端口分配给默认VLAN(假设已经定义了默认VLAN)。如果在列表中没有MAC地址,而且也没有默认VLAN,端口将不会被激活。 本实例将述的就是基于MAC地址的动态VLAN。 其中(假设已经定义了默认VLAN)说明默认是没有定义“默认VLAN”所以我认为答案应该是C. none until the port VLAN is determined QUESTION 255
5 c/ D. c% y, p: ^question in regards to an EtherChannel misconfiguration.
# A- c7 e; h4 W- CA. LACP
% E: @4 \2 R5 x. _6 bB. PortFast/ a, C9 {. o: u$ s6 y0 D0 `
C. PAGP, q A: K( U/ b' Y/ X
D. STP
$ @* S3 S0 p8 A5 P) Y; @: [Correct Answer: D 我认为答案是A. LACP
# c: W/ E* j: |! D2 C+ K2 C9 p8 `. X+ W: I5 f
QUESTION 267
) x A. N8 G" ^& t( S) y: L6 nIf all devices on an EtherChannel are sending traffic to a single MAC address,which two methods of load
. _& n( f$ [+ O8 W1 \balancing on the EtherChannel are preferred? (Choose two.)- @/ J6 e' w: }' e9 N! F8 {. w
A. destination-MAC B.src-dst-MAC' r( F9 J* d3 z5 d0 G( { B4 B( D+ c
C. destination-IP! }& o5 b% i7 P$ C( R
D. source-MAC
% r0 ]: M: J& T. [& z5 K# hE. source-IP
( M) c3 }9 @6 bCorrect Answer: BD 我认为答案是D. source-MAC和E. source-IP
% b- K/ ~8 X. k& @; m5 V+ p$ u. N( dSection: part6 QUESTION 274) ^6 k5 M5 V! B6 h
Diagram is: with 1 core, 2 DSW connected with EtherChannel, 2 ALSW, 2 PCs perALSW. Per diagram" p8 E, F! ?2 [8 v7 V
current root for VLAN 10 is DSW2.& n$ e. b$ Z$ {# I# [9 W# h
Question is how to make DSW1 the primary root for VLAN 10. (Choose two.) A. DSW2: change bridge priority to 61440 (highest).6 x! L9 n- l) ]
B. DSW1: change bridge priority to 4096 (lowest).+ K1 [ S! [& Y5 x
C. DSW1: change port priority but in global configuration mode.7 g5 w2 m3 s# D( \1 M* t
D. DSW1: change bridge priority but value is 0.9 |8 y4 ~0 B: P" n
E. DSW1: change bridge priority but command is priority root.8 t- s; m: b2 _/ e3 D9 M4 C; x3 r
Correct Answer: BE 我认为答案是B和D$ {3 z1 C: ^" ?! G
Section: part6 QUESTION 290
* o6 k3 q6 e; A5 u+ ZWhat is the default mode for LACP EtherChannel when configured?
! ]0 \1 O O. D1 S' @3 d t% L dA. On3 R' C" J, O- ~& I/ \+ I
B. Active
3 U5 Y/ t% x. G7 K/ xC. Passive
8 f a9 G6 |- w5 w! n+ Q/ YD. Desirable
* ~1 g( b, v( F$ KE. Off
" x+ e: _5 a) A1 n) j* B# a0 ^Correct Answer: C 我认为答案是A. On
+ K8 G* r- {+ e8 E$ c! wSection: part6 QUESTION 300
( x' m6 {% }4 XWhich two operational attributes can be checked forEtherChannel ports
& R, e, m9 S# }; D& A. Lthat are in err-disabled state?
, F4 E4 z: Q& U \& Q# a# R3 bA. Port mode
! J9 I& }( a0 ?" p( vB. Port cost1 C: K1 q+ R" g: X/ v! \; Q6 m2 g
C. Duplex
# m& b" @* `+ h+ |4 VD. DTP
' J, E f' t5 A) D8 l9 a0 _E. VLAN8 [5 Y) C0 u6 ]+ I8 n% ^* D2 L. q
Correct Answer: AE 我认为答案是A和C
) |) A; a3 Q3 c6 b( S5 i9 mSection: part6 SW1(config)#spanning-treeetherchannel guard misconfig EtherChannel Guardis a way of finding out if one end of the EtherChannel is not configuredproperly. This could be that there are some parameters not matching up such asduplex and speed. Or it could be that one side is a trunk and the other isn’t. When there is amisconfiguration found, the switch will place the interfaces in error-disabledstate and an error will be displayed. QUESTION 303
7 r8 I% t, M, I- f/ l) E0 MWhatis the value of the TPID/tag protocol identifier of QinQ?# ^/ T9 i# f9 O. I8 u1 i
A. 0x8a88
: G1 U: e: X- O2 _2 QB. 0x8100# j/ ? X. b9 r* A# n8 t" E
C. 0x8b45% e! c* T+ M9 G Y4 G/ K6 `$ `; l; X
D. 0x82005 ~/ p: b+ v/ c+ v( F) ^6 P
CorrectAnswer: A
" a3 {4 q( \7 g; g3 x. Y3 uSection:part70 o7 n2 K9 l# Y" j: ?% A4 j) v
Explanation. |' a" U; x: [3 a" h
Explanation/Reference:
/ Y- q6 x- R0 q! IAns: A 在802.1Q中规定TPID(Tag Protocol Identifier)的EType的值为0x8100。在QinQ封装中,各个设备厂商的内层TPID的EType的值为0x8100,但是对于外层TPID的EType,各个厂商所使用的值不相同。 VLAN的标签也可以是上层嵌套的,这种VLAN方式一般在运营商的网络中采用。这种VLAN可以把多个客户的VLAN在划分在一个大的VLAN中以区别不同的业务。VLAN tag 从外到内逐步解析。此时外层的 VLAN TPID可以标记为9100、9200或者9300。根据802.1ad,由运营商的外层 VLAN TPID 被定义为88a8。 QUESTION 306
- N) e* F( r O sWhich two configurations cause the frames to be tagged? (Choose two.)
$ t2 @ S# V2 V+ E4 u3 eA. interface gi 0/1.116 encapsulation dot1q
2 `! ?, B/ d+ k- q- g' MB. trunk allowed vlan 1168 s2 w! m" C8 x
C. interface with access and voice VLAN configured to 116
7 t- x! I4 Z4 h! w* }5 L! gD. NA
, S7 p6 f3 O# L4 Z5 I1 XCorrect Answer: AB 我认为答案应该是A和D ,ISL( l. h l" m1 G" B* v/ l; X8 Q
Section: part7 QUESTION 308
' |. ~& U) D8 a6 o- f# g: \EtherChannel load balancing with an exhibit.. c+ f% |! u: F; N$ O' P% B
SERVER SERVER+ @$ S- M. B" p1 X8 R; h3 D5 a; _( v
| |# e! t. s! Z) i$ b( e
S W I T C H/ U: D/ w/ l& r b$ c' l
|||||||||||. {0 j& E6 C$ D9 D
S W I T C H
+ c8 p! s) G o# |. }|1 z7 p% G5 c0 I3 s$ L: t- [ K
HOST) L' D$ O$ g8 h {. @/ M
Which EtherChannel load balancing algorithm should be used to optimize theEtherChannel links9 }% A9 N/ T1 H) O/ R% V
between switches?
/ ?8 L6 m( u8 n0 y) e% M5 \/ g7 N# QA. Source MAC* C2 n/ |- r. b3 A7 t7 ~
B. Source-dest MAC: ?# o6 @, k$ i6 k7 j
C. Destination IP' Z: s7 w% A) y9 O6 Y
D. Destination MAC Correct Answer: A 我认为答案是D. Destination MAC
7 [' j8 q2 K7 A0 e+ a/ DSection: part7 QUESTION 317. v$ h7 c+ T1 `4 ?3 N
Aquestion about the port number and multicast address of VRRP.
7 o* S( h# ?# |" C# @, A(CONCEPT ONLY)
6 p4 s% X( r: \# C2 ?% ?2 {0 hA. VRRP uses multicast address 224.0.0.18 and uses UDPport 112.
8 |. k# o. P) k: {/ R. m0 RB. na
4 p+ O: v7 {# G n. C0 u9 tC. na4 i1 S& U0 [$ B' o* w9 R* V, N& L- E
D. na' I8 z& o- B: i
CorrectAnswer: A; E8 S m s* X8 W
Section:part7
* U! k, H/ I! R8 DExplanation/Reference: 1. HSRP——封装在UDP数据中,使用UDP端口号1985,多点广播地址为224.0.0.2 VRRP——使用IP报文作为传输协议,协议号为112,使用组播地址224.0.0.18 Advertisementprotocol—Uses a dedicated Internet Assigned Numbers Authority (IANA) standardmulticast address (224.0.0.18) for VRRP advertisements. This addressing schememinimizes the number of routers that must service the multicasts and allowstest equipment to accurately identify VRRP packets on a segment. IANA hasassigned the IP protocol number 112 to VRRP. QUESTION 333
" ?, u0 f- _+ ^- k/ RA question about EtherChannel compatibility modes. (Choose two.)
7 M7 A" m! V/ j- u1 G) ? RA. passive-passive
- ~" m' E: L: B g ?6 G. Q v' x& PB. active-active
; l/ z2 D4 t2 x1 n' ?3 tC. desirable-desirable
4 k/ C9 t$ l4 k5 sD. active-passive E. active-desirable
! B+ e( C+ C: Y0 L4 l4 }2 qCorrect Answer: CD 我认为答案ACD9 w$ O( Z/ [2 N% y! [3 M" t7 q
Section: part7 5 n6 H5 d+ w/ V
考试CCNP交换的朋友,大神,或者网络爱好者,欢迎吐槽、指点。
/ j0 W0 D2 C6 F' H% E' N4 | |