CCNA (Cisco Certified Network Associate) Exams 2026 Practice Test – 188 Free Exam Questions with Answers

CCNA (Cisco Certified Network Associate) Exams 2026

188 questions · instant answer feedback · concise explanations · free

  1. Question 1 of 188How can you disable DTP on a switch port?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. Configure the switch port as a trunk.

    The correct answer proves that disabling DTP requires configuring the port as a static access or trunk. The trap is confusing the operational mode with the administrative mode that disables negotiation.

  2. Question 2 of 188What is the standard IP access list perform filtering?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: E. * Source IP address

    The correct answer proves that standard IP access lists can only filter by source IP address. The distractors are features of extended access lists or Layer 2 filtering.

  3. Question 3 of 188Which three statements about the features of SNMPv2 and SNMPv3 are true? (Choose three.)

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. SNMPv3 enhanced SNMPv2 security features. · B. SNMPv2 added the Inform protocol message to SNMP. · D. SNMPv2 added the GetBulk protocol message to SNMP.

    The correct answers prove the specific protocol message additions for each version. The trap is confusing which version added Inform and GetBulk messages.

  4. Question 4 of 188Which three elements must be used when you configure a router interface for VLAN trunking? (Choose three.)

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. one subinterface per VLAN · C. one IP network or subnetwork for each subinterface · F. subinterface encapsulation identifiers that match VLAN tags

    The correct answers prove the fundamental requirements for router-on-a-stick. The distractors misstate physical or configuration dependencies.

  5. Question 5 of 188Which component of a routing table entry represents the subnet mask?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. network mask

    The correct answer proves that the network mask is the component used for route matching. The distractors are other routing table fields.

  6. Question 6 of 188Which technology can enable multiple VLANs to communicate with one another?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. inter-VLAN routing using a Layer 3 switch

    The correct answer proves that inter-VLAN routing requires a Layer 3 function. The distractors incorrectly suggest Layer 2 solutions or misapply Layer 3 terms.

  7. Question 7 of 188Which IPv6 header field is equivalent to the TTL?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. Hop Limit

    The correct answer proves that Hop Limit is the TTL equivalent in IPv6. The distractors are other IPv6 header fields.

  8. Question 8 of 188Which of the following are control plane functions (Select all) * Encapsulation

    Select 4 answers.

    Show answer & explanation

    Correct answer: B. * ARP · C. * MAC address discovery · D. * NDP · E. * Routing protocol

    The correct answers prove that the control plane handles network intelligence. The distractor, QoS, is a data plane function.

  9. Question 9 of 188Which of the following are the correct descriptions for the bridge ID when using the extended system ID (select 3)

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. * Priority value is 4 bits · D. * Priority is a multiple of 4096 · F. * Extended system ID is 12 bits

    The correct answers prove the specific bit allocation and priority constraints of the extended system ID. The distractors provide incorrect bit values or priority ranges.

  10. Question 10 of 188What do Layer 2 switches use to determine the destination of the received frame?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: E. * Destination MAC address

    Layer 2 switches use the destination MAC address to forward frames. Source IP, default gateway, and IP addresses are incorrect.

  11. Question 11 of 188A network administrator needs to configure a serial link between the main office and a remote location. The router at the remote office is a non-Cisco router. How should the network administrator configure the serial interface of the main office router to make the connection?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. Main(config)# interface serial 0/0 Main(config-if)# ip address 172.16.1.1 255.255.255.252 Main(config-if)# encapsulation ppp Main(config-if)# no shut

    The correct answer proves that PPP encapsulation is required for interoperability with non-Cisco devices, unlike Cisco-proprietary HDLC. The distractor B lacks an encapsulation method, while C and D use incorrect or non-standard encryptions.

  12. Question 12 of 188Which of the following zones are involved in the firewall rule creation (select 3)

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. * External zone · B. * Internal zone · D. * Dmz

    The correct answers prove that firewalls use three primary zones: internal (trusted), external (untrusted), and DMZ (semi-trusted). The distractors use non-standard zone names or fail to represent the core firewall model.

  13. Question 13 of 188When connecting Cisco's AP1 to Cisco's SW using PoE, AP1 has been assigned an appropriate power class, but AP2 is assigned a power class higher than what was necessary. Which of the following is the cause of this?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: C. * Because CDP is used to assign the correct power classes

    The correct answer proves that CDP negotiates power classes for PoE, and a failure results in higher default power. The distractors incorrectly involve routing, cabling, or trunking protocols that do not affect power allocation.

  14. Question 14 of 188What will be the effect of executing the following command on port F0/1? switch(config-if)# switchport port-security mac-address 00C0.35F0.8301

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. The command statically defines the MAC address of 00c0.35F0.8301 as an allowed host on the switch port.

    The correct answer proves that the command statically allows a specific MAC address. The distractors incorrectly claim prohibition, ACL functionality, or encryption, which are not features of port-security MAC configuration.

  15. Question 15 of 188Which statement about native VLAN traffic is true?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. Traffic on the native VLAN is tagged with 1 by default

    The correct answer proves that native VLAN traffic is untagged by default. The distractor incorrectly claims CDP traffic uses it by default, while native VLANs are typically enabled for backward compatibility, not disabled for security.

  16. Question 16 of 188What are two characteristics of Frame Relay point-to-point subinterfaces? (Choose two.)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. They require a unique subnet within a routing domain. · C. They emulate leased lines.

    The correct answers prove that Frame Relay subinterfaces emulate leased lines and require unique subnets. The distractor 'full-mesh' is incorrect for point-to-point, while 'split-horizon' issues do not apply here.

  17. Question 17 of 188If primary and secondary root switches with priority 16384 both experience catastrophic losses, which tertiary switch can take over?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: C. a switch with priority 20480

    The correct answer proves that the lowest bridge ID (highest numerical priority) wins the root election among remaining switches. The distractor with priority 8192 is lower (higher priority) and would not be chosen.

  18. Question 18 of 188After you configure the Loopback0 interface, which command can you enter to verify the status of the interface and determine whether fast switching is enabled?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. Router#show ip interface loopback 0

    Correct answer verifies specific interface protocol status. Other commands show basic config or hardware details, not fast-switching capability.

  19. Question 19 of 188Which command can you execute to set the user inactivity timer to 10 seconds?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. SW1(config-line)#exec-timeout 0 10

    Correct answer shows proper syntax for minutes and seconds. The distractor lacks the zero minutes required for immediate timeout after seconds.

  20. Question 20 of 188Which of the following are the correct descriptions of the private address (select 2)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * Network administrators can allocate it freely · B. * 172.16.1.1 is a private address

    Private addresses are freely allocated in RFC 1918 ranges and are not routable on the internet. Other options incorrectly describe public addresses or routing behavior.

  21. Question 21 of 188You are working in a data center environment and are assigned the address range 10.188.31.0/23. You are asked to develop an IP addressing plan to allow the maximum number of subnets with as many as 30 hosts each. Which IP address range meets these requirements?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. 10.188.31.0/27

    /27 provides the maximum subnets while supporting 30 hosts. Larger masks don't support enough hosts, and smaller masks don't create enough subnets.

  22. Question 22 of 188Which of the following is a correct description of a TCP connection? (Select 3)

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. * Confirm that data has arrived by the ""ACK"" packet · D. * Establish a connection with ""SYN"", ""ACK + SYN"", ""ACK"" over three transactions · E. * TCP connection establishes before starting to send data

    TCP uses a three-way handshake to establish a connection before data transfer and confirms data receipt with ACK packets.

  23. Question 23 of 188Which command enables DHCP snooping?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. * (CONFIG) #IP DHCP Snooping

    The 'ip dhcp snooping' command globally enables DHCP snooping on a switch.

  24. Question 24 of 188Which command is used to enable RSTP?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: E. * Spanning-tree mode rapid-pvst

    The 'spanning-tree mode rapid-pvst' command enables Rapid PVST+, which is Cisco's implementation of RSTP.

  25. Question 25 of 188Which of the following subnet masks should you use when using a class B address and ensuring at least 300 subnets with 50 hosts per subnet? (select 2)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * 255.255.255.192 · E. * 255.255.255.128

    The correct answer demonstrates subnetting calculations for sufficient subnets and hosts. The distractor trap is confusing the subnet and host bit requirements for a given mask.

  26. Question 26 of 188Which routing protocol uses 'cost' as a metric?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: C. * OSPF

    The correct answer proves OSPF's use of cost as a metric. The distractor cue is eliminating EIGRP, which uses composite metrics, and RIP, which uses hop count.

  27. Question 27 of 188Which of the following are best practices when placing multiple APs in a Wireless LAN (select 2)?

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * Arrange them so as to have no gaps in coverage · E. * Channel assignment to avoid overlapping

    The correct answers prove coverage continuity and non-overlapping channels are best practices. The distractor trap is choosing channel reuse strategies that cause co-channel interference.

  28. Question 28 of 188Which device allows users to connect to the network using a single or double radio?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. access point

    The correct answer identifies an access point as the radio-frequency connection device. The elimination cue is distinguishing it from management and switching devices.

  29. Question 29 of 188Which of the following is the benefit of QoS?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. * Improves IP phone call quality

    The correct answer proves that QoS improves real-time application quality. The elimination cue is recognizing that other functions are provided by different protocols like NTP or FHRP.

  30. Question 30 of 188Which command should be used to start Negotiation themselves by LACP?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. * channel-group 1 mode active

    The correct answer confirms that 'active' mode initiates LACP negotiation. The trap is mistaking passive mode for initiating the process.

  31. Question 31 of 188Which command downloads iOS from the server to the router to replace the router's iOS?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: F. * copy tftp flash

    The copy tftp flash command downloads an IOS image from a TFTP server to the router's flash memory.

  32. Question 32 of 188RFC 1918 specifies what address range?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: E. * Private address

    Correct answer defines private address ranges. The distractors are clearly other public IANA address types, making this straightforward.

  33. Question 33 of 188What are two benefits of using a single OSPF area network design? (Choose two.)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. It reduces the types of LSAs that are generated. · C. It removes the need for virtual links.

    The correct answers prove that a single OSPF area minimizes link-state advertisement types and eliminates the need for virtual links. The trap is distractor B, as a single area reduces LSA processing time, and distractor D is incorrect because CPU load remains high for LSDB maintenance.

  34. Question 34 of 188At which layer of the OSI model is RSTP used to prevent loops?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. Data link

    The correct answer proves that RSTP operates at the data link layer. The trap is distractors B, C, and D, which are incorrect because RSTP is a Layer 2 protocol, not physical, network, or transport.

  35. Question 35 of 188Which type of EIGRP route entry describes a feasible successor?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. a backup route, stored in the topology table

    The correct answer proves that a feasible successor is a backup route in the topology table. Distractors B and C are eliminated because feasible successors are not in the routing table, only the topology table.

  36. Question 36 of 188A network administrator creates a layer 3 EtherChannel, bundling four interfaces into channel group 1. On what interface is the IP address configured?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. the port-channel 1 interface

    In a Layer 3 EtherChannel, the IP address is configured on the logical port-channel interface, not on the physical member interfaces.

  37. Question 37 of 188Switch ports operating in which two roles will forward traffic according to the IEEE 802.1w standard? (Choose two.)

    Select 2 answers.

    Show answer & explanation

    Correct answer: B. root · C. designated

    The root and designated port roles in Rapid PVST+ will always forward data traffic, while alternate and backup ports are in a blocking state.

  38. Question 38 of 188Which three statements are typical characteristics of VLAN arrangements? (Choose three.)

    Select 3 answers.

    Show answer & explanation

    Correct answer: D. A switch maintains a separate bridging table for each VLAN. · E. Each VLAN uses a separate address space. · F. Connectivity between VLANs requires a Layer 3 device.

    Each VLAN has a separate address space and bridging table. Inter-VLAN routing requires a Layer 3 device. VLANs can span multiple switches.

  39. Question 39 of 188A router receives information about network 192.168.10.0/24 from multiple sources. What will the router consider the most reliable information about the path to that network?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. a directly connected interface with an address of 192.168.10.254/24

    The correct answer proves that directly connected routes have the lowest administrative distance and are preferred over static or dynamic routes. The trap is confusing source reliability with router routing protocol preference.

  40. Question 40 of 188What is the best way to verify that a host has a path to other hosts in different networks?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. Ping the remote network.

    The correct answer proves that pinging a remote network verifies end-to-end IP connectivity across routers. The distractors only verify local connectivity or device-specific settings.

  41. Question 41 of 188Which of the following services use UDP? (Choose three.)

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. DNS · C. SNMP · E. TFTP

    UDP is a connectionless protocol used for DNS, SNMP, and TFTP. TCP-based services like Telnet, SMTP, and HTTP are distractors.

  42. Question 42 of 188Which two states are the port states when RSTP has converged? (Choose two.)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. Discarding · B. Forwarding

    RSTP converged ports are in Discarding or Forwarding states. Learning and Listening are transitional states.

  43. Question 43 of 188What is the default Syslog facility level?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. local7

    Local7 is the default facility level for user-defined messages. Other local levels are incorrect.

  44. Question 44 of 188Which command can check the router that is DR (select 2) * show running-config

    Select 2 answers.

    Show answer & explanation

    Correct answer: B. * show IP OSPF Interface Brief · D. * show ip ospf neighbor

    The correct answers prove that OSPF DR/BDR status is verified with neighbor or interface-specific commands. The distractor, 'show running-config', displays static configurations, not dynamic router states like DR/BDR roles.

  45. Question 45 of 188Which of the following descriptions are correct about the SDN controller (select 2) * It is security equipment used to prevent external attacks and unauthorized access

    Select 2 answers.

    Show answer & explanation

    Correct answer: B. * There are types such as APIC and APIC-EM · C. * It is software that centrally manages network devices

    The correct answers prove that SDN controllers are central management software, with Cisco examples like APIC and ACI. The distractor incorrectly describes a firewall, while 'no Cisco controller' is false.

  46. Question 46 of 188Which of the following are a correct description of CSMA / CD operations (select 2)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * While the cable is being used it will wait without sending data · E. * If a collision is detected, it will send the data after waiting for a random amount of time

    The correct answers prove that CSMA/CD involves waiting for idle medium and random backoff after collisions. The distractor incorrectly claims simultaneous transmission or prioritized retransmission, which violates CSMA/CD rules.

  47. Question 47 of 188A network administrator needs to configure port security on a switch. Which two statements are true?

    Select 2 answers.

    Show answer & explanation

    Correct answer: B. The sticky learning feature allows the addition of dynamically learned addresses to the running configuration. · C. When dynamic MAC address learning is enabled on an interface, the switch can learn new addresses, up to the maximum defined.

    Port security learns new MAC addresses up to the configured maximum. The sticky learning feature adds these addresses to the running configuration.

  48. Question 48 of 188What is the purpose of the POST operation on a router?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. determine whether additional hardware has been added

    Correct answer demonstrates understanding of router boot sequence. The trap is confusing boot sequence steps with hardware detection.

  49. Question 49 of 188Which standards-based First Hop Redundancy Protocol is a Cisco supported alternative to Hot Standby Router Protocol?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: C. VRRP

    VRRP is the industry standard alternative to Cisco proprietary HSRP. Other options are unrelated protocols, not FHRP alternatives.

  50. Question 50 of 188What are three advantages of VLANs? (Choose three.)

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. They establish broadcast domains in switched networks · B. They can simplify adding, moving, or changing hosts on the network. · C. They allow access to network services based on department, not physical location. They provide a method of conserving IP addresses in large networks.

    VLANs create broadcast domains and simplify moves. The distractor in D confuses them with routing, and E misstates their function.

  51. Question 51 of 188What are three reasons that an organization with multiple branch offices and roaming users might implement a Cisco VPN solution instead of point-to-point WAN links? (Choose three.)

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. reduced cost · B. increased security · D. scalability

    VPNs offer cost savings, security, and scalability. C and E are distractors that confuse VPNs with physical links.

  52. Question 52 of 188What command visualizes the general NetFlow data on the command line?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. show ip cache flow

    The show ip cache flow command provides a general overview of NetFlow data. Other options show specific subsets like top-talkers or sampling information.

  53. Question 53 of 188What is the function of the command switchport trunk native vlan 999 on a Cisco Catalyst switch?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. It designates VLAN 999 for untagged traffic.

    This command designates VLAN 999 for untagged traffic on the trunk. Option D confuses this with the default VLAN for unknown traffic, which is not how native VLANs operate.

  54. Question 54 of 188What information does a router running a link-state protocol use to build and maintain its topological database? (Choose two.)

    Select 2 answers.

    Show answer & explanation

    Correct answer: B. hello packets · F. LSAs from other routers

    Hello packets discover neighbors, and LSAs flood the topology database. Other options describe different protocols or concepts like SAP or TTL.

  55. Question 55 of 188A switch is configured with all ports assigned to VLAN 2 with full duplex FastEthernet to segment existing departmental traffic. What is the effect of adding switch ports to a new VLAN on the switch?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. An additional broadcast domain will be created.

    Each VLAN is a separate broadcast domain. Creating a new VLAN increases the total number of broadcast domains on the switch.

  56. Question 56 of 188Which of the following correctly detail FTP and TFTP? (Select 3)

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. * TFTP uses UDP port 69 · B. * TFTP does not require connection · C. * FTP uses TCP port 20 and 21

    TFTP uses UDP port 69 and is connectionless. FTP uses TCP ports 20 and 21.

  57. Question 57 of 188Which of the following are correct in regards to the comparisons between the IPv4 header and the IPv6 header (select 3)?

    Select 3 answers.

    Show answer & explanation

    Correct answer: B. * The size of the IPv6 header is larger · C. * Checksum field is not in the IPv6 header · E. * The IPv6 header has less fields and processes are easier than IPv4

    The correct answers verify that IPv6's header is larger, lacks a checksum, and is simpler. The ambiguity comes from the flawed original question text, which confuses 'Flora Bell' with 'Flow Label'.

  58. Question 58 of 188Which statement is correct regarding the operation of DHCP?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. If an address conflict is detected, the address is removed from the pool and an administrator must resolve the conflict.

    If a DHCP server detects an IP address conflict, it removes the address from the pool, requiring an administrator to resolve the issue.

  59. Question 59 of 188Refer to the exhibit. An attempt to deny web access to a subnet blocks all traffic from the subnet. Which interface command immediately removes the effect of ACL 102?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. no ip access-group 102 out

    The correct answer proves the specific syntax to remove an ACL applied to outbound traffic. The distractors fail because they use incorrect commands like 'access-class' instead of 'access-group'.

  60. Question 60 of 188The SERIAL0 interface of the router was shut down with the 'SHUTDOWN' command. If you execute the 'show interface serial 0' command, which of the following results is displayed?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. * Serial 0 is administratively down and line protocol is down

    The correct answer proves the output for an administratively shut-down interface. The distractors are traps for other states like link failure or protocol mismatch.

  61. Question 61 of 188Which of the following is used to obtain the host name from the IP address with DNS lookup?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. * Reverse lookup

    Reverse lookup converts an IP address to a hostname. The trap is confusing it with forward lookup, which maps names to IP addresses.

  62. Question 62 of 188Which two types of NAT addresses are used in a Cisco NAT device? (Choose two.)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. inside local · C. inside global

    Cisco NAT uses inside local and inside global address definitions. The other options are not standard NAT terminology.

  63. Question 63 of 188Which of the following is IPv6's Loopback address.

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. * :: 1/128

    ::1/128 is the IPv6 loopback address. The other options are different address types like unspecified or link-local.

  64. Question 64 of 188Which conversion method registered in advance to connect pre-converted local address with the post-converted local address in a 1-1 relationship?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. * Static NAT transformation

    Correct answer defines Static NAT as a manual, one-to-one IP mapping. The trap is confusing it with Dynamic NAT, which uses a pool of addresses.

  65. Question 65 of 188Which statement about access lists that are applied to an interface is true?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: C. You can configure one access list, per direction, per Layer 3 protocol.

    Correct answer states the ACL rule of one per protocol per direction. The trap is allowing unlimited or multiple lists, which violates this fundamental rule.

  66. Question 66 of 188Refer to the exhibit. The Bigtime router is unable to authenticate to the Littletime router. What is the cause of the problem?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. The passwords do not match on the two routers.

    Correct answer identifies CHAP authentication failure due to mismatched passwords. The trap is confusing the process as username or interface-specific.

  67. Question 67 of 188Syslog was configured with a level 3 trap. Which 4 types of logs would be generated (choose four)

    Select 4 answers.

    Show answer & explanation

    Correct answer: A. Emergencies · B. Alerts · C. Critical · D. Errors

    Correct answer identifies the severity levels included in level 3 (Errors). The distractors represent lower-severity levels that would not be captured by a level 3 trap.

  68. Question 68 of 188Which three statements about RSTP are true? (Choose three.)

    Select 3 answers.

    Show answer & explanation

    Correct answer: B. RSTP significantly reduces topology reconverging time after a link failure. · C. RSTP expands the STP port roles by adding the alternate and backup roles. · D. RSTP provides a faster transition to the forwarding state on point-to-point links than STP does.

    The correct answers prove that RSTP reduces convergence time, adds new port roles, and offers faster forwarding. The elimination cue is the fact that RSTP supersedes STP's timers and proposal process.

  69. Question 69 of 188Which of the following is correct for IPSec communication mode. (select 2)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * Transport mode encrypts only data sections of packets · B. * Tunnel mode encrypts the entire packet

    The correct answers prove that transport mode encrypts only the payload, while tunnel mode encrypts the entire packet. The trap is confusing the scope of encryption between the two modes.

  70. Question 70 of 188Which command can you enter to verify that a 128-bit address is live and responding?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. ping ipv6

    The correct answer proves that ping ipv6 tests IPv6 reachability. Distractor D is eliminated because it tests IPv4, and distractor C is for service connectivity, not basic reachability.

  71. Question 71 of 188Which two spanning-tree port states does RSTP combine to allow faster convergence? (Choose two.)

    Select 2 answers.

    Show answer & explanation

    Correct answer: B. blocking · D. listening

    The correct answers prove that RSTP merges blocking and listening into a single discarding state to speed up convergence. Distractor E is eliminated because learning is a distinct state in RSTP.

  72. Question 72 of 188Which of the following items can be confirmed by the command 'show snmp chassis'?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: C. * serial number

    The 'show snmp chassis' command displays hardware-specific information, including the device serial number. The other options are SNMP configuration or trap details, not chassis data.

  73. Question 73 of 188Which of the following are correct descriptions of IEEE 802.1Q? (Choose four.)

    Select 4 answers.

    Show answer & explanation

    Correct answer: A. * It inserts a 4-byte tag into a frame · C. * It can be used even when connecting a Cisco switch and other switches · E. * Supports native VLAN · F. * It is one of the VLAN encapsulation methods

    802.1Q inserts a 4-byte tag, supports native VLAN, is a standard encapsulation, and allows inter-switch communication with different vendors.

  74. Question 74 of 188Which two tasks does the Dynamic Host Configuration Protocol perform? (Choose two.)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. Configure IP address parameters from DHCP server to a host. · B. Assign and renew IP address from the default pool.

    DHCP assigns and renews IP addresses from a pool and delivers additional configuration parameters like IP addresses to hosts.

  75. Question 75 of 188What are two requirements for an HSRP group? (Choose two.)

    Select 2 answers.

    Show answer & explanation

    Correct answer: B. exactly one active router · C. one or more standby routers

    An HSRP group requires exactly one active router and one or more standby routers to maintain redundancy.

  76. Question 76 of 188When communicating between sites, which topology connects via a central point?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. * Hub and Spoke

    A hub and spoke topology uses a central hub to connect multiple spoke locations, unlike partial or full mesh topologies.

  77. Question 77 of 188Which three are characteristics of an IPv6 anycast address? (Choose three.)

    Select 3 answers.

    Show answer & explanation

    Correct answer: B. delivery of packets to the group interface that is closest to the sending device · C. the same address for multiple devices in the group · E. one-to-nearest communication model

    Anycast provides one-to-nearest delivery. The correct options prove this by defining the closest interface and the one-to-nearest model. The other options describe multicast, unicast, or incorrect models.

  78. Question 78 of 188What are two advantages of Layer 2 Ethernet switches over hubs? (Choose two.)

    Select 2 answers.

    Show answer & explanation

    Correct answer: D. allowing simultaneous frame transmissions · E. filtering frames based on MAC addresses

    Switches increase bandwidth by allowing simultaneous frame transmissions and filtering traffic by MAC address. The other options describe hub characteristics or are incorrect.

  79. Question 79 of 188Which of the following are endpoints? (Select 3)

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. * PC · C. * Server · D. * Smartphone

    Endpoints are end devices that send or receive data. The correct options identify user devices, while a switch is a network infrastructure device, not an endpoint.

  80. Question 80 of 188Which command allows you to verify the encapsulation type (CISCO or IETF) for a Frame Relay link?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. show frame-relay map

    The 'show frame-relay map' command displays the encapsulation type. Distractors verify LMI or PVC status, not the encapsulation method.

  81. Question 81 of 188Refer to the exhibit. The network administrator requires easy configuration options and minimal routing protocol traffic. What two options provide adequate routing table information for traffic that passes between the two routers and satisfy the requests of the network administrator? (Choose two.)

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. a static route on InternetRouter to direct traffic that is destined for 172.16.0.0/16 to CentralRouter.

    Static routes provide necessary connectivity without routing traffic. Distractors suggest dynamic protocols, which generate unwanted traffic.

  82. Question 82 of 188Refer to the exhibit. Hosts in network 192.168.2.0 are unable to reach hosts in network 192.168.3.0. Based on the output from RouterA, what are two possible reasons for the failure? (Choose two.)

    Select 2 answers.

    Show answer & explanation

    Correct answer: C. The encapsulation that is configured on S0/0 of RouterB does not match the encapsulation that is configured on S0/0 of RouterA · D. Interface S0/0 on RouterA is not receiving a clock signal from the CSU/DSU.

    A serial interface protocol down can be caused by mismatched encapsulation or a missing clock signal. Distractors suggest unrelated issues like wrong IP masks.

  83. Question 83 of 188The Company WAN is migrating from RIPv1 to RIPv2. Which three statements are correct about RIP version 2? (Choose three)

    Select 3 answers.

    Show answer & explanation

    Correct answer: B. It is a classless routing protocol. · D. It has the same maximum hop count as version 1. · E. It supports authentication.

    RIPv2 is classless, supports authentication, and has the same 15-hop limit as RIPv1. It uses multicast, not broadcast, and has the same administrative distance.

  84. Question 84 of 188What OSPF command, when configured, will include all interfaces into area 0?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. network 0.0.0.0 255.255.255.255 area 0

    The correct answer proves the OSPF network command syntax using a wildcard mask of all ones to match any IP address. The trap is the difference between the all-zeros network address and all-ones wildcard mask.

  85. Question 85 of 188How can an administrator determine if a router has been configured when it is first powered up?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. An unconfigured router goes into the setup dialog.

    The correct answer proves that an unconfigured router initiates the setup dialog. The distractors describe the state of a router after it has already been configured.

  86. Question 86 of 188A network engineer wants to allow a temporary entry for a remote user with a specific username and password so that the user can access the entire network over the Internet. Which ACL can be used?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. dynamic

    The correct answer proves that dynamic ACLs create temporary entries based on user authentication. The distractors describe different types of ACLs without user-based authentication.

  87. Question 87 of 188Of the following options, which are security measures (select 3)

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. * User Awareness · B. * Physical security measures · D. * Training

    User awareness, physical security, and training are proactive security measures. Spear fishing and Trojan horses are attacks, not defenses.

  88. Question 88 of 188Refer to the exhibit. An administrator pings the default gateway at 10.10.10.1 and sees the output as shown. At which OSI layer is the problem?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. network layer

    Ping uses ICMP, a Layer 3 protocol, so failures indicate network layer issues. Application layer and access layer are distractors.

  89. Question 89 of 188Which of the following describes the implementation method, owned by a cloud vendor, is aimed for general public so that anyone can use cloud computing resources. * Community Cloud

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. * Public cloud

    Public cloud is vendor-owned and accessible to the public. Community, hybrid, private, and IaaS are distractors.

  90. Question 90 of 188Which of the following options are characteristics of on-premises environment (select 2)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * You need to manage servers and networks in-house · C. * Initial expenses are high

    On-premises requires in-house management and has high initial costs. AWS and cloud models are incorrect.

  91. Question 91 of 188If the network address is "206.140.3.0" and the subnet mask is "255.255.255.224", which of the following is the correct notation?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. * 206.140.3.0/27

    A subnet mask of 255.255.255.224 has a CIDR prefix of /27, not /25. The other prefix values do not match the mask.

  92. Question 92 of 188On which type of device is every port in the same collision domain?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. a hub

    A hub operates at Layer 1, putting all ports in the same collision domain. Switches and routers create separate collision domains for each port.

  93. Question 93 of 188Which type of address is the public IP address of a NAT device?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. inside global

    The inside global address is the public IP address assigned to the NAT device that represents hosts on the private network.

  94. Question 94 of 188Which command displays CPU utilization?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. show process

    Correct answer confirms knowledge of IOS monitoring commands. The distractors are eliminated as they show different system information, not CPU usage.

  95. Question 95 of 188Which version of SNMP first allowed user-based access?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. SNMPv3

    SNMPv3 introduced user-based security models. SNMPv2C uses community strings and SNMPv1 has minimal security, making SNMPv3 the clear answer.

  96. Question 96 of 188Which of the following is used by the network to notify the Cisco DNA Center (select 2)?

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * SNMP · D. * Syslog

    SNMP and Syslog are standard notification methods. VPN and Netconf are not notification protocols.

  97. Question 97 of 188Which statement about MPLS is true?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: C. It operates between Layer 2 and Layer 3.

    MPLS operates between Layer 2 and Layer 3. The distractors incorrectly assign it to a single OSI layer.

  98. Question 98 of 188Refer to the exhibit. A network administrator configures a new router and enters the copy startup-config running-config command on the router. The network administrator powers down the router and sets it up at a remote location. When the router starts, it enters the system configuration dialog as shown below. The configuration register is set to 0x2102.

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. The network administrator failed to save the configuration.

    The configuration was not saved. The running-config was copied to an empty startup-config.

  99. Question 99 of 188Which of the following is done to establish a virtual communication path, while TCP is performed to ensure communication reliability?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. * 3 way hand shake

    TCP's three-way handshake establishes a virtual channel. Distractors like sequence numbers and FIN bits relate to data ordering and connection teardown, not establishment.

  100. Question 100 of 188Which of the following are correct descriptions of Message Integrity Check? (Select 2)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * Michael, CBC-MAC, GMAC in MIC algorithm · E. * Used to check if the data has not been tampered with

    Message Integrity Check verifies data has not been tampered with and uses algorithms like Michael and GMAC. Option B confuses MIC with Layer 2 addresses, and C confuses it with encryption.

  101. Question 101 of 188Which of the following is a correct description of IPv6's unique local address? (Select 3)

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. * Address starts with ""FD · B. * Global ID is 40 bits · C. * Subnet is 16 bits

    Unique local addresses start with 'FD', have a 40-bit Global ID, and a 16-bit Subnet ID. Option F describes link-local addresses, not unique local.

  102. Question 102 of 188Which of the following are downsides of using point-to-point connections? (Select 2)

    Select 2 answers.

    Show answer & explanation

    Correct answer: B. * Physical wiring is required between the points and this lacks flexibility · D. * A dedicated line using point-to-point connection is more expensive than VPN and other WAN services

    Point-to-point connections require physical wiring, which lacks flexibility, and are more expensive than WAN services like VPN. Options C and E incorrectly suggest low quality or reliability.

  103. Question 103 of 188Which of the following is a correct description of an IPv6 multicast address?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. * It is a destination addressed to a specific group

    An IPv6 multicast address is a destination address used to send packets to a specific group of nodes.

  104. Question 104 of 188Assuming a subnet mask of 255.255.248.0, three of the following addresses are valid host addresses. Which are these addresses? (Choose three.)

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. 172.16.31.0 · B. 172.16.20.0 · C. 172.16.9.0

    The correct answers demonstrate valid host address calculation within a /21 subnet. The distractor trap is confusing the network address with a usable host address.

  105. Question 105 of 188Which tab should be opened to manipulate WLC with a GUI and change QoS?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. * QoS tab

    The correct answer identifies the QoS tab for policy configuration. The distractor cue is distinguishing it from tabs for layer-specific or general settings.

  106. Question 106 of 188Refer to the exhibit. If the router Cisco returns the given output and has not had its router ID set manually, what value will OSPF use as its router ID?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. 2.2.2.2

    OSPF uses the highest active IP address on a loopback interface, or the highest active interface IP address if no loopbacks exist. The router's router ID is based on these IP addresses, not hostname or command output.

  107. Question 107 of 188Which of the following settings has the same meaning as 'Access-List 100 permit IP Any Host 192.168.1.1' (select all that apply)?

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * (Config) # Access-List 100 Permit IP 0.0.0.0 255.255.255.255 192.168.1.1 0.0.0.0 · C. * (Config) # Access-List 100 permit IP 0.0.0.0 255.255.255.255 Host 192.168.1.1

    'Any' is equivalent to '0.0.0.0 255.255.255.255' and 'Host' is equivalent to '0.0.0.0' for a specific destination IP.

  108. Question 108 of 188Which of the following are correct descriptions of a centralized wireless LAN network configuration (select 2)?

    Select 2 answers.

    Show answer & explanation

    Correct answer: B. * LAP and WLC send and receive data using CAPWAP tunnels · D. * LAP and switch connect with LAN cable

    In a centralized model, LAPs and WLCs communicate via CAPWAP tunnels, and LAPs connect to the wired network with a LAN cable.

  109. Question 109 of 188What is the purpose of Inverse ARP?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. to map a known DLCI to an IP address

    Inverse ARP maps a known DLCI to a remote device's IP address to dynamically populate a router's address-to-DLCI mapping table.

  110. Question 110 of 188When using PSK authentication on WPA or WPA2, which pre-shared key formats can be selected (select 2)?

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * ASCII · E. * Hex

    The standard PSK formats supported for configuration are ASCII and hexadecimal.

  111. Question 111 of 188Which of the following are correct descriptions of a subnet mask (select 3)?

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. * In binary notation, the number starting with ""1"" is lined up from left to right · B. * Numbers are used to distinguish the network parts and host parts · C. * In decimal notation, it is divided into decimal numbers, separated by dots every 8 bits.

    In binary, the network portion consists of consecutive 1s from the left. In decimal, it's represented as four 8-bit groups. CIDR notation indicates the prefix length.

  112. Question 112 of 188What are two benefits of private IPv4 IP addresses? (Choose two.)

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: E. They can be assigned to devices without Internet connections.

    The correct answer proves that private IPs allow device assignment without Internet access. The distractors are false because they claim elimination of NAT, conflicts, or identical routing to public addresses.

  113. Question 113 of 188What command disables 802.1x authentication on a port and permits traffic without authentication?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. dot1x port-control force-authorized

    The correct answer proves the command to set a port to bypass authentication. The distractors are traps for other 802.1x states or invalid syntax.

  114. Question 114 of 188What will happen if a private IP address is assigned to a public interface connected to an ISP?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. Addresses in a private range will not be routed on the Internet backbone.

    The correct answer proves the fundamental routing issue with private IP addresses on the internet. The distractors are traps that incorrectly invoke NAT or conflict states.

  115. Question 115 of 188What are the first 24 bits of the MAC address called?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. * OUI

    The first 24 bits of a MAC address are the OUI, which identifies the vendor. NIC is a hardware device, not a part of an address.

  116. Question 116 of 188Which command is used to enable port security?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: C. * (config-if) #switchport port-security

    The switchport port-security command enables port security on an interface. Other options enable different, unrelated features.

  117. Question 117 of 188Which of the following is the correct description of WLC's management access control. (select 2) * You can disable the SSH service and strengthen security

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * You can disable HTTP service and strengthen security · B. * You can disable the Telnet service and strengthen security

    Disabling unencrypted services like HTTP and Telnet strengthens security. Encrypted services like SSH and HTTPS should not be disabled for security.

  118. Question 118 of 188Which of the following are the correct descriptions of PSE and PD (select 2)? PD points to the side that supplies power.

    Select 2 answers.

    Show answer & explanation

    Correct answer: C. * The access points correspond to PD · D. * PSE points to the side that supplies power

    Correct answer identifies the Power Sourcing Equipment and Powered Device roles. The trap is confusing which device is which; remember PD receives power.

  119. Question 119 of 188Which of the following are the correct descriptions of syslog (select 2)? Time is automatically synchronized using syslog.

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * It records and displays information, such as timestamps, severity level and messages · B. * Used to collect logs

    Correct answer describes standard syslog functions. The question is ambiguous due to the inaccurate premise about automatic time synchronization; NTP is required for that.

  120. Question 120 of 188What is the purpose of introducing a DNS cache server? (select 2)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * To reduce the load on the authoritative DNS server · B. * In order to increase the response to the client

    Correct answer states the purpose of a caching server to reduce load and speed up responses. The distractors describe other network services like DHCP or Syslog.

  121. Question 121 of 188Which transport layer protocol supports VoIP?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. * UDP

    The correct answer proves that UDP is the transport protocol for VoIP due to its low overhead and connectionless nature. TCP is a distractor because its connection-oriented, reliable delivery unsuitable for real-time traffic.

  122. Question 122 of 188Which of the following are the correct descriptions of DHCP Snooping (select 3)

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. * Prevents attacks from an unauthorized client in which they send a large number of DHCP requests to the DHCP server · B. * Classifies each port as trusted port or untrusted ports · C. * Prevents an attack from an incorrect DHCP server

    The correct answers prove that DHCP snooping prevents rogue servers, classifies ports, and mitigates DHCP starvation attacks. The elimination cue is distinguishing it from port security, 802.1X, and SPAN features.

  123. Question 123 of 188The network administrator cannot connect to Switch 1 over a Telnet session, although the hosts attached to Switch1 can ping the interface Fa0/0 of the router. Given the information in the graphic and assuming that the router and Switch2 are configured properly, which of the following commands should be issued on Switch1 to correct this problem?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. Switch1(config)# ip default-gateway 192.168.24.1

    The correct answer proves that a default gateway is needed for Layer 3 access to the switch. The distractors are traps involving Layer 2 interface configuration or console access settings.

  124. Question 124 of 188In the communication path from the router to a destination, which command should be used to examine the point where the failure is occurring?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. * traceroute

    The correct answer proves that traceroute identifies failure points by probing the path. Distractor F is a Windows equivalent, and distractor D only checks reachability, not the specific failure location.

  125. Question 125 of 188Which three statements about Syslog utilization are true? (Choose three.)

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. A Syslog server provides the storage space necessary to store log files without using router disk space. · B. There are more Syslog messages available within Cisco IOS than there are comparable SNMP trap messages. · C. A Syslog server helps in aggregation of logs and alerts.

    Syslog servers provide centralized storage and log aggregation, which offers more messages than SNMP traps. Using Syslog does not inherently improve network performance or auto-notify administrators.

  126. Question 126 of 188When can it be said that a switched network where Spanning Tree Protocol is running has fully converged?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: E. * When all switch ports are either ""blocking"" or ""forwarding

    STP convergence is complete when all ports are in a stable forwarding or blocking state, which eliminates all listening and learning states.

  127. Question 127 of 188Which NAT function can map multiple inside addresses to a single outside address?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. PAT

    PAT allows multiple inside hosts to share a single public IP address. The other options are not NAT functions, making them easy eliminations.

  128. Question 128 of 188You want to start using the cloud service, but would like to emphasize QoS and security and also connect directly with the operator. Which connection method is appropriate?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. * Private WAN

    A Private WAN provides a direct, high-performance connection with guaranteed QoS and security. The distractors are either insecure, not a connection method, or offer indirect access.

  129. Question 129 of 188Which of the following is true about the ENABLE PASSWORD and ENABLE SECRET commands?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: F. * ""Enable Secret"" is encrypted by MD5 by default

    Enable Secret uses MD5 encryption for higher security. Enable Secret overrides Enable Password, not the reverse, and does not require both passwords.

  130. Question 130 of 188Which command can you use to set the hostname on a switch?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: C. switch-mdf-c1(config)#hostname switch-mdf1

    The 'hostname' command is used in global configuration mode. Distractors use incorrect modes like privileged or interface configuration.

  131. Question 131 of 188How to use the unused port to increase the security level of the switch (select 3)

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. * Change native VLAN · E. * Shutdown · F. * Access port

    Unused ports should be shut down, set as access ports, or have their native VLAN changed. Default native VLANs and trunk ports increase risk.

  132. Question 132 of 188In the network layer, what is the destination based on?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. * IP address

    The correct answer proves that Layer 3 routing decisions are made based on the destination IP address. The other options are attributes of other layers.

  133. Question 133 of 188Which network topology allows all traffic to flow through a central hub?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. star

    The correct answer proves that a star topology uses a central hub or switch as a single point of communication. The distractors describe different topologies.

  134. Question 134 of 188What Cisco IOS feature can be enabled to pinpoint an application that is causing slow network performance?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. Netflow

    The correct answer proves that NetFlow provides per-application traffic analysis. The distractors are other monitoring or optimization features with different primary functions.

  135. Question 135 of 188Router (config) #boot system flash c181x-advIpservicesk9-mz.124-15.t11.bin Which is the correct description of this command?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. * Specify where to search for iOS

    The correct answer proves the `boot system` command specifies the location for IOS image lookup. The distractors describe completely different router configuration commands.

  136. Question 136 of 188Which of the following is characteristic of DMVPN?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. * Dynamically establishes multiple VPN connections

    DMVPN dynamically establishes multiple VPN connections to reduce hub router load. SSL, encryption, and multi-vendor support are incorrect characteristics.

  137. Question 137 of 188Which of the following are the correct descriptions of SVI (select 3) * Router interface used by WAN connection

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. * Is a VLAN's default gateway · C. * SVI sets and uses IP addresses · D. * SVI is a virtual interface

    SVI is a virtual interface, a VLAN gateway, and uses IP addresses. STP and physical interfaces are incorrect.

  138. Question 138 of 188Which entity assigns IPv6 addresses to end users?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. RIR

    RIR assigns blocks to ISPs who then assign to end users. Option B is also technically correct as ISPs directly assign addresses, creating ambiguity.

  139. Question 139 of 188What parameter can be different on ports within an EtherChannel?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. DTP negotiation settings

    DTP negotiation is allowed to vary. The distractors are Layer 1/2 parameters that must match.

  140. Question 140 of 188Which of the following is the correct description about broadcast (select 2)?

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * Sends packets to all devices on the same network · B. * Has been discontinued on IPv6

    Broadcast is a one-to-all transmission method. The distractors describe unicast and multicast.

  141. Question 141 of 188Which two are the limitations of the service password-encryption command? (Choose two.)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. The algorithm used by this command cannot protect the configuration files against detailed analysis by attackers. · D. It uses the Vigenere cipher algorithm.

    This command uses a weak Vigenere cipher that can be cracked easily and cannot protect against detailed configuration analysis. Option B describes an advantage, not a limitation.

  142. Question 142 of 188Of the information displayed when using the 'show interfaces' command, which number does not increase if the interface is operating at full duplex?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: C. * COLLISIONS

    Collisions do not occur on a full-duplex interface, so the counter does not increase. The other options all increase with traffic or errors.

  143. Question 143 of 188Which of the following correctly explains Cisco DNA Center's SBI? (Select 2)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * Support for conventional access methods such as Telnet / SSH / SNMP · C. * Uses netconf / restconf for a relatively new device

    Cisco DNA Center uses both conventional access like Telnet/SSH and newer methods like NETCONF/RESTCONF. Option B incorrectly states Telnet is not supported.

  144. Question 144 of 188Which of the following are correct descriptions of STP role selection? (Select 2)

    Select 2 answers.

    Show answer & explanation

    Correct answer: C. * The switch with the smallest bridge ID in the L2 network becomes the root bridge · E. * In the segment, the port of the switch with the smallest route path cost is the specified port

    The root bridge is the switch with the lowest bridge ID. The designated port on a segment is the port with the lowest path cost to the root bridge.

  145. Question 145 of 188Which protocol is the Cisco proprietary implementation of FHRP?

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. HSRP · C. GLBP

    HSRP and GLBP are Cisco proprietary FHRPs. VRRP is an open standard.

  146. Question 146 of 188Which of the following are correct descriptions of ARP spoofing (select 2)?

    Select 2 answers.

    Show answer & explanation

    Correct answer: C. * Intermediate attack using ARP · D. * Can be prevented by DAI

    ARP spoofing is an attack that uses ARP to intercept traffic. DAI prevents it by validating ARP packets against a trusted database.

  147. Question 147 of 188Which type of device can be replaced by the use of subinterfaces for VLAN routing?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: C. Layer 3 switch

    Subinterfaces on a router perform inter-VLAN routing, a function also provided by a Layer 3 switch.

  148. Question 148 of 188What is the correct routing match for a packet destined for 172.16.1.5/32?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. 172.16.1.0/26

    The most specific longest prefix match in the routing table is used for forwarding. /26 is more specific than /25 or /24.

  149. Question 149 of 188Which of the following can be implemented by introducing Cisco DNA Center (select 2)?

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * Rapid development · D. * Control of network by the self-made program

    The correct answers prove Cisco DNA Center's role in automated network deployment and programmatic control. The distractors are traps claiming equipment reduction or security elimination.

  150. Question 150 of 188Which of the following are used to perform authentication in SNMPv2c?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: C. * Community string

    The correct answer proves SNMPv2c's use of community strings for authentication. The distractors are traps for advanced protocols available in SNMPv3.

  151. Question 151 of 188Which of the following requests an IP address from the host name in the DNS lookup?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: E. * Forward lookup

    The correct answer proves the definition of a forward lookup. The distractors are traps for reverse lookups or unrelated protocols.

  152. Question 152 of 188Select the highest priority item that is used to determine DR (representative router) in OSPF. * IP address

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. * Priority value

    Priority value is the first criterion for selecting an OSPF DR. Router ID is only used if priorities are equal, making it a secondary criterion.

  153. Question 153 of 188Which of the following are the correct descriptions about the router's config mode? (select 3)

    Select 3 answers.

    Show answer & explanation

    Correct answer: A. * If you disable CDP in this mode, CDP will be disabled for all interfaces · C. * Sets the router body in this mode · F. * Global configuration mode

    Correct answer identifies the global configuration mode. The trap is mistaking it for interface or router-specific configuration mode based on the prompt.

  154. Question 154 of 188Which of the following are the correct descriptions of unicast?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. * Sends a packet to a single partner

    The correct answer proves that unicast sends a packet to a single destination. The distractors incorrectly describe unicast as multicast, broadcast, or discontinued in IPv6.

  155. Question 155 of 188Where do you get global IP address from?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: C. * ISP

    The correct answer proves that ISPs assign public global IP addresses for Internet connectivity. The distractors are irrelevant entities; network administrators allocate private addresses, not public ones.

  156. Question 156 of 188In a situation where there is no default route in the routing table, which command should be used to achieve the advertisement of the default route by OSPF?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: C. * (Config-Router) # DEFAULT-INFORMATION ORIGINATE ALWAYS

    The correct answer proves that DEFAULT-INFORMATION ORIGINATE ALWAYS advertises a default route without one. The trap is distractor D, which requires the route to exist, and distractor A is a command to suppress updates.

  157. Question 157 of 188Which method is used to automatically build an enterprise campus LAN, provided by Cisco?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: E. * SD-ACCESS

    SD-Access uses intent-based networking for automated campus LAN deployment. This eliminates routing protocols like EIGRP and OSPF as potential answers.

  158. Question 158 of 188Which of the following is a description of "wide network access" as a feature of cloud computing? * The addition and extension of resources on demand

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. * Can be used without the need for a physical device or location

    Wide network access allows resource access without a physical device or location. The distractors describe other cloud features like on-demand self-service or resource sharing.

  159. Question 159 of 188Which is the correct description of the operations of a switch configured for VLANs?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. * If the destination MAC address is not registered in the MAC address table, it transfers to all ports (except for the receiving port) if the VLAN is not set.

    A switch floods an unknown destination MAC to all ports in the same VLAN. The distractors incorrectly describe trunk ports, inter-VLAN communication, and broadcast behavior.

  160. Question 160 of 188What are the correct descriptions of HDLC (select 2)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * A default encapsulation type of serial interface · D. * Cisco uses your own HDLC, with type fields added to ISO standard HDLC

    HDLC is a default Cisco serial encapsulation. Cisco's proprietary HDLC adds a type field, making it incompatible with non-Cisco devices.

  161. Question 161 of 188Which of the following can be implemented by SDN? (select 2)

    Select 2 answers.

    Show answer & explanation

    Correct answer: C. * You can dynamically change the network topology according to the status of traffic on the SDN controller · E. * Network can be virtualized using VTN with the SDN controller

    SDN enables dynamic topology changes and network virtualization. The distractors misplace SDN functions like per-device deployment or VM management.

  162. Question 162 of 188With a class C address and 13 subnets, which of the following subnet masks can prepare the most amount of hosts?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. * 255.255.255.240

    Four subnet bits support 16 subnets. The mask /240 maximizes hosts while meeting the subnet requirement. Distractors use insufficient or excessive subnet bits.

  163. Question 163 of 188From the following, select the correct explanation of FTP (select 2)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * Has the ability to authenticate · F. * It is a protocol used for file transfer

    FTP supports authentication and is a file transfer protocol. It is unencrypted and uses TCP, not UDP, ARP, or TFTP features.

  164. Question 164 of 188Show SNMP community Which item can be confirmed by the this command?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: C. * Community string

    The correct answer proves the `show snmp community` command displays configured community strings. The distractors are SNMP configuration parameters visible with different commands.

  165. Question 165 of 188In the cloud service model, which of the following is the name of a "platform provided in the form of service"?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: C. * PaaS

    PaaS provides a development platform for users, whereas SaaS is software and IaaS is infrastructure.

  166. Question 166 of 188Refer to the exhibit. Which address and mask combination represents a summary of the routes learned by EIGRP?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. 192.168.25.16 255.255.255.240

    The correct summary covers the 192.168.25.16/28 block. The distractor uses a network address that doesn't align with the route boundaries.

  167. Question 167 of 188What is the purpose of the client to make an IEEE 802.1X authentication request?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. * To connect to LAN

    The request grants LAN access. The distractors describe other IEEE standards' functions.

  168. Question 168 of 188Which two statements about IPv6 and routing protocols are true? (Choose two.)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. OSPFv3 was developed to support IPv6 routing. · B. Link-local addresses are used to form routing adjacencies.

    OSPFv3 supports IPv6. Link-local addresses are used for routing protocol adjacencies.

  169. Question 169 of 188Which of the following would you use if you want to filter packets for management interfaces?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: E. * Apply ACL to ""CPU Access Control Lists

    The correct answer proves the use of CPU Access Control Lists for filtering traffic to the controller itself. The distractors are traps for other WLAN features.

  170. Question 170 of 188Refer to the exhibit. What set of commands was configured on interface Fa0/3 to produce the given output?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. interface FastEthernet 0/3 channel-group 2 mode passive switchport trunk encapsulation dot1q switchport mode trunk

    Passive mode indicates the switch is not negotiating PAgP, but is ready to form a channel if the peer is active.

  171. Question 171 of 188A network administrator wants to add a line to an access list that will block only Telnet access by the hosts on subnet 192.168.1.128/28 to the server at 192.168.1.5. What command should be issued to accomplish this task?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. access-list 101 deny tcp 192.168.1.128 0.0.0.15 192.168.1.5 0.0.0.0 eq 23 access-list 101 permit ip any any

    Correct answer uses a standard numbered ACL for filtering. The trap is using an extended ACL number or the wrong wildcard mask for the /28 subnet.

  172. Question 172 of 188The following access list was applied outbound on the E0 interface connected to the 192.169.1.8/29 LAN: access-list 135 deny tcp 192.169.1.8 0.0.0.7 eq 20 any access-list 135 deny tcp 192.169.1.8 0.0.0.7 eq 21 any How will the above access lists affect traffic?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. All traffic exiting E0 will be denied

    The correct answer proves that an implicit deny at the end of an ACL blocks all unmatched traffic. The distractor fails to recognize the default action when no permit rules exist.

  173. Question 173 of 188Which is the most accurate description of DTP?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. * When connecting between ""Dynamic Desirable"", it becomes a trunk port

    The correct answer proves that two Dynamic Desirable ports negotiate to form a trunk. The distractors are incorrect due to misunderstandings about default modes, DTP on native VLANs, and the effect of connecting Dynamic AUTO to Desirable.

  174. Question 174 of 188Which statement about a router on a stick is true?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. It uses multiple subinterfaces of a single interface to encapsulate traffic for different VLANs.

    The correct answer proves that router on a stick uses subinterfaces to encapsulate traffic for different VLANs. Distractor D is eliminated because subinterfaces must be on different subnets, not the same.

  175. Question 175 of 188Which switch would STP choose to become the root bridge in the selection process?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: A. 32768: 11-22-33-44-55-66

    The root bridge is chosen based on the lowest Bridge ID, which is a combination of priority and MAC address. The lowest priority makes a switch the winner, regardless of MAC.

  176. Question 176 of 188Which of the following are the correct descriptions about FCS (select 2)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * It is used to confirm whether the received data is incorrect · F. * It is stored on the Ethernet trailer

    FCS is an error detection mechanism in Ethernet trailers that detects corruption. The distractors confuse FCS functions like data repair or SFD signaling.

  177. Question 177 of 188Which two commands can you enter to verify that a configured NetFlow data export is operational? (Choose two.)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. show ip cache flow · C. interface ethernet 0/0

    The correct answers prove that verification requires checking the flow cache. The distractors are configuration commands, not verification commands.

  178. Question 178 of 188Which of the options is the reason for the ERR-DISABLED state (select 2)?

    Select 2 answers.

    Show answer & explanation

    Correct answer: C. * Generation of security violation · D. * BPDU Guard Violation

    Security violations trigger the err-disabled state. The shutdown command is manual, not automatic, and port security is disabled by default.

  179. Question 179 of 188Which is the correct description of a site VPN and client VPN (select 2)?

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * The Client VPN connects to a VPN using TLS · D. * Within a site VPN, multiple terminals can use that one VPN

    Client VPNs use TLS for connections. Site VPNs connect entire networks, allowing multiple devices to communicate through the tunnel.

  180. Question 180 of 188Which of the following devices are appropriate for SOHO (select 2)?

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * Router with switch and firewall functions · E. * Autonomous AP

    SOHO networks use all-in-one devices like routers with switch/firewall features and simple, autonomous access points. Centralized and high-end devices are overkill.

  181. Question 181 of 188Which of the following is correct about SLAAC?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: D. * Automatically configures IPv6 address by interface ID generated by the received prefix and EUI-64

    SLAAC uses a router-advertised prefix and an EUI-64 generated interface ID to auto-configure an IPv6 address.

  182. Question 182 of 188Where are the responses to queries from DNS clients stored? (select 2)

    Select 2 answers.

    Show answer & explanation

    Correct answer: D. * Authority DNS server · E. * DNS cache server

    Authoritative DNS servers hold the primary data, and cache servers store temporary copies of responses to speed up future queries.

  183. Question 183 of 188You want to reduce the cost of IT-related equipment currently in operation. Which one should you consider adopting?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. * Cloud

    The cloud reduces on-premises costs. The distractors are LAN technologies, not cost reduction models.

  184. Question 184 of 188The Class B address of 172.16.0.0 is used in one network. Which subnet mask should you use to enable 985 hosts per subnet? 255.255.252.0

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: C. * 255.255.252.0

    The correct answer proves the host bit calculation needed for 985 hosts. The distractors are traps using masks for larger or smaller subnets.

  185. Question 185 of 188Refer to the exhibit. Which WAN protocol is being used PPP

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. Frame Relay

    Frame Relay is identified by LMI messages in the exhibit. PPP does not use LMI, which is the key cue for elimination.

  186. Question 186 of 188Which is "software delivered in the form of a service" in the cloud service model?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: C. * SaaS

    The correct answer proves that SaaS is the model for software as a service. The trap is confusing it with PaaS or IaaS, which deliver platforms and infrastructure, not ready-to-use software.

  187. Question 187 of 188Which of the following are the correct descriptions about a server?

    Tap an answer — you get instant feedback and the reasoning.

    Show answer & explanation

    Correct answer: B. * Equipment that provides a service

    A server provides services to clients. The distractors confuse server roles with clients, switches, or routers.

  188. Question 188 of 188Which are the characteristics of the distance vector type routing protocol? (select 3)

    Select 2 answers.

    Show answer & explanation

    Correct answer: A. * Uses a hop count as a metric · B. * Updates routing table based on routing update information received from adjacent routers

    Distance vector protocols use hop count and update based on neighbor information. The question asks for three options but only two are correct, and EIGRP has a topology table.

This test also exists as narrated videos — every answer explained out loud:

More free practice tests at certpunch.com and new video rounds on @CertPunch.

Scroll to Top