300-420 Designing Cisco Enterprise Networks (ENSLD) Practice Questions
Prepare for 300-420 with more than an answer.
- Exam fee
- $300 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 5
- Advanced Addressing and Routing Solutions25%
- Advanced Enterprise Campus Networks25%
- WAN for Enterprise Networks20%
- Network Services20%
- Automation10%
- 1
Which IOS commands do you enter in interface configuration mode to configure a switch port to actively negotiate to be an ISL trunk port if possible? (Choose two.)
Show answer details
Correct answer: D, E
To configure a switch port to actively negotiate to be an ISL trunk port, you need both "switchport mode dynamic desirable" and "switchport trunk encapsulation isl" commands. The dynamic desirable mode actively initiates DTP negotiations to form a trunk, while the encapsulation command specifies ISL as the trunking protocol. Dynamic auto mode waits for the other side to initiate trunking, and the other options do not enable active trunk negotiation.
To configure a switch port to actively negotiate to be an ISL trunk port, you need both "switchport mode dynamic desirable" and "switchport trunk encapsulation isl" commands. The dynamic desirable mode actively initiates DTP negotiations to form a trunk, while the encapsulation command specifies ISL as the trunking protocol. Dynamic auto mode waits for the other side to initiate trunking, and the other options do not enable active trunk negotiation.
- 2
As the network administrator, you have enabled port security on the FaO/1 port of a switch. FaO/1 is not a trunk port. You have configured the port security so that the MAC addresses 1111.1111.1111 and 2222.2222.2222 are allowed to connect to the switch port.
Which of the following commands were required to configure the port security so that only the MAC addresses 1111.1111.1111 and 2222.2222.2222 are allowed to connect to the switch port.? (Choose all that apply.)
Show answer details
Correct answer: B, C, D
To enable port security allowing exactly two specific MAC addresses on a non-trunk port, you need "switchport port-security", "switchport mode access", and "switchport port-security maximum 2" commands. The port-security command enables the feature, mode access ensures it operates as an access port (not trunk), and maximum 2 allows exactly two MAC addresses. The trunk mode command would conflict with port security on access ports.
To enable port security allowing exactly two specific MAC addresses on a non-trunk port, you need "switchport port-security", "switchport mode access", and "switchport port-security maximum 2" commands. The port-security command enables the feature, mode access ensures it operates as an access port (not trunk), and maximum 2 allows exactly two MAC addresses. The trunk mode command would conflict with port security on access ports.
To enable port security allowing exactly two specific MAC addresses on a non-trunk port, you need "switchport port-security", "switchport mode access", and "switchport port-security maximum 2" commands. The port-security command enables the feature, mode access ensures it operates as an access port (not trunk), and maximum 2 allows exactly two MAC addresses. The trunk mode command would conflict with port security on access ports.
- 3
During a CEF packet rewrite, which of the following changes are NOT made to the packet?
Show answer details
Correct answer: D
Explanation:
There is no Layer 2 TTL in the packet, so the Layer 2 time to live (TTL) cannot be decremented by one. All other options are correct. The following changes will be made when the Cisco Express Forwarding (CEF) packet rewrite process occurs: • The source MAC address is changed to the MAC address of the outbound Layer 3 switch interface. • The destination MAC address is changed to the MAC address of the next hop routers MAC address • The Layer 3 IP TTL is decremented by one • The Layer 3 IP checksum is recalculated • The Layer 2 frame checksum is recalculated
Objective: Layer 2 Technologies Sub-Objective: Configure and verify switch administration
References: Cisco > Catalyst 6500 Series Cisco IOS Software Configuration Guide, 12.1 E > Configuring IP Unicast Layer 3 Switching on Supervisor Engine 2 > Understanding How IP Multicast Layer 3 Switching Works - 4
What command should you use to quickly view the HSRP state of the switch for all HSRP groups of which the switch is a member?
Show answer details
Correct answer: A
Explanation:
The command show standby brief should be used to quickly view the HSRP state of a switch for all HSRP groups of which it is a member. The summary information it provides includes the group number, priority, state, active device address, standby address, and group address.
The command show standby can be used to display detailed information about HSRP groups of which a switch is a member. This command would not provide a quick view. This command displays information about HSRP on all configured interfaces and for all HSRP groups. It also displays hello timer information and the expiration timer for the standby switch.
The command show ip interface brief is useful in that lists the interfaces and displays the basic IP configuration of each. This output would include the IP address of the interface and the state of the interface, but now HSRP information.
The command show hsrp is not a valid command due to incorrect syntax.
Objective: Infrastructure Services Sub-Objective: Configure and verify first-hop redundancy protocols
References: Cisco > Cisco IOS IP Application Services Command Reference > show standby Cisco > Cisco IOS IP Application Services Configuration Guide, Release 12.4 > Part 1: First Hop Redundancy Protocols > Configuring HSRP - 5
A network architect is reviewing the following diagram, which illustrates a common WAN service. The diagram shows customer (CE) routers connecting to provider edge (PE) routers. The provider network uses MP-BGP to exchange VPN routes between PE routers, and each customer is isolated into a separate VRF. Which WAN connectivity option does this diagram represent?
graph TD subgraph Customer A CE1_A[CE 1] CE2_A[CE 2] end subgraph Customer B CE1_B[CE 1] end subgraph Provider Cloud PE1[PE 1] PE2[PE 2] P1[P Router] P2[P Router] PE1 --- P1 --o P2 --- PE2 end CE1_A -- VRF_A --- PE1 CE2_A -- VRF_A --- PE2 CE1_B -- VRF_B --- PE1 linkStyle 4 stroke:#ff0000,stroke-width:2px,fill:none; linkStyle 6 stroke:#0000ff,stroke-width:2px,fill:none; linkStyle 7 stroke:#ff0000,stroke-width:2px,fill:none;Show answer details
Correct answer: B
The diagram shows the classic architecture of an MPLS Layer 3 VPN. Key identifiers include: the distinction between Customer Edge (CE) and Provider Edge (PE) routers, the use of VRFs on the PE routers to create separate routing tables for each customer, and the implied use of MP-BGP within the provider cloud to exchange customer routes securely. This service provides customers with Layer 3 IP connectivity between their sites over a shared provider backbone.
- 6
Which of the following is required to allow load balancing between three HSRP routers connected to the same LAN?
Show answer details
Correct answer: E
To enable load balancing between three HSRP routers on the same LAN, you must configure three separate HSRP groups, with each router serving as the active router for one group and standby for the others. This approach distributes traffic across all three routers by allowing different subnets or clients to use different virtual gateways. A single HSRP group can only have one active router at a time, while two groups would not utilize all three routers effectively for load balancing.
- 7
Which are valid configurable VLAN ID numbers for 802.1Q networks?
Show answer details
Correct answer: B
Explanation:
IEEE 802.1Q supports configuring VLAN IDs 1 through 4094.
The 802.1Q standard specifies support for a maximum of 4,094 VLANs. (IDs 0 and 4095 are reserved.) Therefore, ID values of 1-4094 are assignable. In contrast, the valid range of configurable ISL VLANs is 1-1001. The following is a summary of VLAN IDs: .0 and 4095: Reserved . 1: Cisco default management .2-1001: Available for Ethernet VLANs .1002-1005: Defaults for FDDI and Token Ring VLANs .1006-4094: Extended range available for Ethernet VLANs (802.1Q only)
Recognizing the differences between supported VLAN ID ranges highlights several issues in constructing a network of both ISL and 802.1Q VLAN networks. Ethernet VLAN IDs above the supported ISL range must be mapped to IDs within the range supported by ISL. Among other limitations, you are limited to eight mappings. This process of mapping 802.1Q to ISL VLAN IDs will further restrict and define which IDs are available to be used.
Objective: Layer 2 Technologies Sub-Objective: Configure and verify VLANs References: Cisco Nexus 5000 Series Switch CLI Software Configuration Guide > Configuring Access and Trunk Interfaces - 8
Inter-VLAN routing has been operating successfully for several months. Users who connect to a newly installed switch report that they are unable to communicate with the rest of the company's networks. You decide to ensure that the switch is properly connected to the VTP domain before taking any other troubleshooting steps.
What command would be best used to verify this?
Show answer details
Correct answer: D
Explanation:
The command show vtp status would be the best command to verify the switch's connection to the company's VTP domain. This command displays the version of VTP, the VTP domain the switch is a member of, the VTP mode of the switch, and other configuration settings relating to VTP.
The command show vlan will display the VLANs that exist and the ports that are members of the VLANs, but will not identify whether switch is a member of the VTP domain. If the VLANs that are displayed with this command are the same as those in the VTP domain, it does not necessarily mean the switch is a member of the domain. This data needs to be verified with the show vtp status command.
The command show ip route is used to verify the routing table, but it does not provide any VTP information. This command is used to verify routes to other networks discovered or configured on the switch. It will display the routing protocol used to discover each route, and the next hop used to forward traffic to the destination network.
The command show interfaces trunk is used to verify which VLANs are being forwarded to another device, but does not indicate whether the switch is a member of the VTP domain.
The command show interfaces would not allow you to verify the switch's connection to the company's VTP domain. This command would allow you to determine the following features of the switch:
• Port state . Port speed . Input errors • Collisions
Objective: Layer 2 Technologies Sub-Objective: Configure and verify trunking References: Catalyst 4500 Series Switch Cisco IOS Software Configuration Guide, 12.1(13)EW > Understanding and Configuring VTP Cisco > Cisco IOS LAN Switching Command Reference > show vlan through ssl-proxy module allowed-vlan > show vtp - 9
What Cisco switch features are designed to work together to mitigate ARP spoofing attacks? (Choose two.)
Show answer details
Correct answer: A, D
DHCP snooping and Dynamic ARP Inspection (DAI) are Cisco features designed to work together to mitigate ARP spoofing attacks. DHCP snooping builds a trusted database of IP-to-MAC address bindings by monitoring DHCP transactions, while DAI validates ARP packets against this database to prevent ARP cache poisoning. Port security controls MAC addresses on switch ports but does not prevent ARP spoofing, and 802.1x provides network access control but does not validate ARP packets.
DHCP snooping and Dynamic ARP Inspection (DAI) are Cisco features designed to work together to mitigate ARP spoofing attacks. DHCP snooping builds a trusted database of IP-to-MAC address bindings by monitoring DHCP transactions, while DAI validates ARP packets against this database to prevent ARP cache poisoning. Port security controls MAC addresses on switch ports but does not prevent ARP spoofing, and 802.1x provides network access control but does not validate ARP packets.
- 10
Which next-hop router redundancy protocol provides backup for an assigned real IP address?
Show answer details
Correct answer: C
Explanation:
Using VRRP, the shared address of the next-hop router redundancy group can be the real address of a router interface.
Virtual Router Redundancy Protocol (VRRP) is defined in RFC 2338. VRRP enables a group of routers to form a single virtual router, known as a VRRP group. Routers are configured in VRRP groups to provide redundancy for an IP address shared among members of the VRRP group. This address can be the real address of a router interface or a virtual address (or addresses) shared by the group.
Each group is comprised of a master and one or more backup routers. If the shared address is the real IP address of a router, that router will always be the master when the address is available. The master router is responsible for forwarding packets sent to the virtual router. The backup routers provide redundancy and stand ready to assume the role of the master router in the event that it is unable to forward packets.
The master virtual router owns the VRRP IP address and is responsible for handling all packets sent to the VRRP IP address. Backup VRRP routers monitor for hello activity from the master virtual router. The master router will advertise using IP 224.0.0.18 and MAC 0000.0c00.01xx (xx is the VRRP Group ID). The advertisements by default will be sent every second, and the master down interval is three seconds.
If the VRRP IP address is NOT the physical address of one of the VRRP routers, then the router with the highest priority will assume the role of the master. The configurable priority range is from 0 to 255, and the default value is 100. The higher the value is, the higher the priority is. If activity stops for the duration of the master router's down interval, the backup router with the highest priority will become the master router. When the old master router comes back online, it will assume the master role again if it still has the highest priority among all routers.
In the configuration shown below, Router A will be the master router unless it goes down, in which case B will take over. If A comes back up it will assume the master role again.
routerA(config-if)# vrrp 3 priority 130 routerB(config-if)# vrrp 3 priority 110
Hot Standby Router Protocol (HSRP) defines a set of routers that work together to represent one virtual, fault-tolerant router. Thus, redundancy is provided in the event that any one of the routers fails.
The shared address of the next-hop router redundancy group is not the real address of a router interface.
Gateway Load Balancing Protocol GLBP) is a Cisco-designed protocol that provides for the dynamic utilization of redundant routers in a broadcast network. The shared address of the next-hop router redundancy group is not the real address of a router interface. A virtual group address is used.
Objective: Infrastructure Services Sub-Objective: Configure and verify first-hop redundancy protocols
References: Cisco > Cisco IOS IP Application Services Configuration Guide, Release 12.4 > Part 1: First Hop Redundancy Protocols > Configuring VRRP
