RCNI Practice Questions
Prepare for RCNI with more than an answer.
- Exam fee
- $150 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 4
- Foundational Networking Concepts20%
- RUCKUS Products & Solutions20%
- ICX Solution Implementation45%
- ICX Solution Troubleshooting15%
- 1
When implementing Quality of Service (QoS) on a RUCKUS ICX switch to prioritize VoIP traffic, an administrator must map incoming traffic to an internal service queue. Which classification method uses the 6-bit field in the IP header to determine traffic priority?
Show answer details
Correct answer: B
Differentiated Services Code Point (DSCP) is a Layer 3 classification method that uses the 6-bit Differentiated Services field in the IP header. This allows for granular classification of traffic (up to 64 values). VoIP traffic is commonly marked with a DSCP value of EF (Expedited Forwarding, value 46) to ensure it receives the highest priority. CoS, on the other hand, is a Layer 2 method that uses a 3-bit field in the 802.1Q VLAN tag.
- 2
True or False: On an ICX switch, applying the
ip source-guardcommand to an interface is sufficient on its own to prevent IP spoofing attacks.Show answer details
Correct answer: B
This statement is false. IP Source Guard relies on the DHCP Snooping binding database to function effectively. DHCP Snooping must be enabled first to build a trusted database of MAC address, IP address, and port bindings. IP Source Guard then uses this database to filter traffic, dropping any packets that do not match a valid binding. Without DHCP Snooping, the binding database is empty, and IP Source Guard has no information to base its filtering decisions on.
- 3
An administrator is configuring a new ICX switch stack and needs to ensure that all switches in the stack synchronize their time with a central server. Which of the following are necessary steps to achieve this? (Select THREE).
Show answer details
Correct answer: A, B, C
This command specifies the IP address of the upstream NTP server that the switch will synchronize with.
This command activates the NTP client on the switch, allowing it to start the synchronization process.
NTP synchronizes to UTC. Setting the local time zone and daylight saving rules is essential for the switch to display the correct local time in logs and command outputs.
- 4
A member unit in an operational ICX stack has failed and needs to be replaced. A new, out-of-the-box switch of the same model is available. What is the most efficient process to replace the failed unit while minimizing manual configuration?
flowchart TD A[Stack Unit 3 Fails] --> B{Obtain new switch} B --> C{Power on new switch?} C --> D[Configure Stack ID & Priority] D --> E{Connect stack cables?} E --> F[System re-converges]Show answer details
Correct answer: A
RUCKUS ICX stacking supports a zero-touch replacement process. When a new, unconfigured switch is cabled into a live stack and powered on, the active controller detects it. The controller then automatically pushes the correct FastIron image (if necessary) and the stack configuration corresponding to that unit's ID to the new member. This eliminates the need for manual pre-configuration.
- 5
Case Study: Smart City IoT Deployment
Company Background:
A municipal government is deploying a Smart City initiative, which involves placing thousands of IoT sensors, HD cameras, and public Wi-Fi access points across the city. These devices will be connected to ruggedized ICX switches placed in outdoor enclosures.Current Situation:
The city's IT department is concerned about the security of the network edge, as the switches will be physically accessible. They need a robust mechanism to ensure that only authorized city-owned devices can connect to the network. Each type of device (sensor, camera, AP) needs to be placed into a separate, specific VLAN for security and traffic management.Technical Requirements:
- Implement a scalable and automated method for device authentication.
- Prevent unauthorized devices from gaining any network access.
- Automatically assign authenticated devices to their correct VLAN based on device type.
- Provide a fallback mechanism for devices that do not support 802.1X, such as older IoT sensors, using their hardware address for authentication.
Problem:
A senior network engineer is tasked with designing the port security solution for this deployment. Which combination of features on the RUCKUS ICX switches provides the most comprehensive solution to meet all stated requirements?Show answer details
Correct answer: D
This is the most complete solution. 802.1X provides robust, scalable authentication for devices that support it (like APs and modern cameras). MAC Authentication Bypass (MAB) serves as the necessary fallback for legacy or simple IoT devices that cannot act as an 802.1X supplicant. By using a central RADIUS server for both methods, the city can maintain a single database of authorized devices. Crucially, the RADIUS server can return specific attributes (Tunnel-Type, Tunnel-Private-Group-ID) to dynamically assign the authenticated device, regardless of method, to the correct VLAN.
- 6
A hospital is deploying a new ICX 7650 stack to support high-bandwidth medical imaging devices. The administrator needs to ensure that if the active stack controller fails, the standby controller takes over with minimal interruption. Which command is essential to configure this behavior?
Show answer details
Correct answer: D
The
stack standbycommand is used to explicitly designate a specific unit within the stack as the standby controller. This ensures a deterministic failover process, where the designated standby unit will take over the active controller role if the current active controller fails. This is crucial for environments requiring high availability, such as a hospital network. - 7
An engineer observes that an ICX 7150 switch, which was previously manageable, is no longer responding to SSH or web GUI requests after a recent configuration change. The only access available is via the console port. The
show running-configoutput reveals no obvious errors in the IP configuration. What is the most likely cause of the management access failure?Show answer details
Correct answer: B
A common cause for losing remote management access after a configuration change is the application of an ACL that does not explicitly permit management protocols like SSH (TCP port 22) or HTTP/S (TCP ports 80/443). If an ACL is applied to the management interface or globally without a permit statement for these protocols, the implicit 'deny all' at the end of the ACL will block access. The IP configuration might be correct, but the traffic is being filtered.
- 8
A financial services company requires that its ICX 7750 core switch be upgraded during a very short maintenance window. To minimize downtime, the network architect wants to pre-download the new FastIron image to the switch ahead of time. Which command should be used to copy the new firmware image from a TFTP server to the switch's secondary flash partition without immediately activating it?
Show answer details
Correct answer: C
The command
copy tftp flash secondarydownloads the specified firmware image from the TFTP server and places it into the secondary flash partition. This allows the administrator to pre-stage the new firmware without affecting the currently running primary image. The switch can then be rebooted into the secondary image during the maintenance window using theboot system flash secondarycommand. - 9
A network administrator at a university campus is trying to recover a forgotten enable password on a standalone ICX 7250 switch. They have console access and have rebooted the switch. What is the correct procedure to bypass the password check during the boot process?
Show answer details
Correct answer: A
The standard RUCKUS ICX password recovery procedure involves rebooting the switch and pressing 'b' when prompted to enter the boot monitor (ROMmon) mode. From the boot monitor prompt, the
no passwordcommand is entered. This command flags the system to skip the password check for the next boot only. After this, theresetcommand is used to continue the boot process, which will then provide access to the privileged EXEC mode without a password. - 10
True or False: When configuring a standard, static Link Aggregation Group (LAG) on an ICX switch, the LACP protocol is actively used to negotiate the link bundling with the connected device.
Show answer details
Correct answer: B
This statement is false. A standard, static LAG (configured with the
link-aggregate activecommand) does not use LACP. It unconditionally bundles the configured ports together. LACP (Link Aggregation Control Protocol) is used for dynamic LAGs, where devices actively negotiate the link bundle. Static LAGs are used when connecting to devices that do not support LACP or when dynamic negotiation is not desired.
