Courseiva

CCNA Network Infrastructure and Connectivity Questions

8 of 308 questions · Page 5/5 · Network Infrastructure and Connectivity · Answers revealed

301
MCQhard

An administrator deploys a new WLAN on a Cisco 9800 WLC using WPA3-Personal (SAE) with AES encryption. A single 802.11ax laptop running Windows 10 fails to connect, displaying an authentication timeout despite entering the correct passphrase. Other clients, including legacy 802.11ac devices, connect without issue.

A.The WLC’s WLAN is misconfigured for WPA3-Enterprise, and the laptop lacks a supplicant for 802.1X authentication.
B.The laptop’s wireless adapter does not support Protected Management Frames, which are mandatory for WPA3-Personal.
C.The WLC has disabled 802.11ax OFDMA on the 5 GHz band, preventing the 802.11ax laptop from associating.
D.The laptop’s driver is configured for 160 MHz channel width, which is incompatible with the WLC’s channel plan, causing authentication to fail.
AnswerB

For WPA3-Personal, the client and access point must negotiate Protected Management Frames (PMF) as part of the RSN information element during association; PMF is not optional but mandatory in WPA3. If the laptop's wireless adapter does not advertise or enable the Management Frame Protection Capable bit, the WLC cannot complete the handshake, causing SAE authentication to time out. This explains why only this 802.11ax-capable device fails while others succeed—it reflects a client-side capability gap, not a network-wide configuration error.

Why this answer

WPA3-Personal (SAE) mandates the use of Protected Management Frames (PMF) as defined in IEEE 802.11w. If the laptop's wireless adapter or driver does not support PMF, it cannot complete the SAE handshake, resulting in an authentication timeout. Legacy 802.11ac clients can connect because they are using WPA2, which does not require PMF.

Exam trap

Cisco often tests the mandatory dependency of Protected Management Frames (802.11w) for WPA3-Personal, leading candidates to incorrectly attribute the failure to channel width or OFDMA incompatibility.

Why the other options are wrong

A

Misidentifying the WLAN security type: WPA3-Personal does not require an enterprise supplicant, so this is not the cause.

C

Confusing radio resource management with connection establishment: OFDMA settings do not block initial association, only data transmission efficiency.

D

Misattributing connection failures to channel bandwidth settings; these are negotiated after successful association and do not impact the 802.11 authentication and association phases.

302
MCQhard

Two routers, R1 and R2, are connected via a serial link. The interface on R1 shows 'Serial0/0 is up, line protocol is down' and no pings succeed across the link. You check the configuration and notice R1 has 'encapsulation ppp' but R2's serial interface was mistakenly left at the default encapsulation hdlc.

A.The IP addresses on the serial interfaces are in different subnets, so packets are dropped at Layer 3.
B.The mismatched encapsulation types prevent the routers from forming a Layer 2 connection, so the line protocol remains down.
C.The serial cable is faulty, causing physical layer issues that trigger the line protocol down state.
D.The routers are missing a routing protocol configuration, so they cannot route traffic across the link.
AnswerB

This is the correct diagnosis. The serial interfaces are configured with different encapsulations: one uses PPP and the other uses HDLC (or another incompatible type). Each encapsulation defines a distinct frame structure, and a router receiving a frame that does not match its configured format cannot interpret the contents or properly validate the keepalive messages. Consequently, the keepalive process fails, and the router marks the line protocol as 'down' even though the physical layer (carrier detect) remains active. This is a classic Layer 2 mismatch that prevents the routers from ever establishing a working data-link connection.

Why this answer

The line protocol on a serial interface requires both ends to agree on the Layer 2 encapsulation type. R1 is configured with PPP (encapsulation ppp), while R2 defaults to HDLC. Since these encapsulations are incompatible, the routers cannot establish a valid Layer 2 connection, causing the line protocol to remain down despite the physical layer being up.

Exam trap

Cisco often tests the distinction between 'line protocol is down' (Layer 2 issue) and 'Serial0/0 is down' (Layer 1 issue), and candidates mistakenly attribute a line protocol down state to physical problems or IP addressing errors rather than encapsulation mismatch.

Why the other options are wrong

A

The line protocol down state is a Layer 2 indicator, not a Layer 3 problem. It reflects the failure of the data link layer to establish a connection, independent of IP addressing.

C

The 'interface up' part of the status explicitly confirms that the physical layer (Layer 1) is operational. A faulty cable would cause both physical and line protocol to show down.

D

Line protocol down indicates a Layer 2 failure, which occurs before any routing decision. Even without a routing protocol, the line protocol would come up if Layer 2 were functional, because the interface status is independent of routing.

303
MCQhard

A technician is troubleshooting a connectivity issue where a workstation connected to a Cisco switch port cannot ping other hosts that are in the same VLAN 10 segment. The technician runs the show mac address-table command and notices that the workstation's MAC address is listed on VLAN 1, not VLAN 10. What is the most likely cause?

A.The switch port is not configured with the switchport access vlan 10 command.
B.The switch port is configured as a trunk with native VLAN 1.
C.The MAC address table contains a stale entry that must be cleared.
D.Spanning Tree Protocol has placed the port in a blocking state.
AnswerA

When an access port's VLAN is not explicitly set, the port defaults to VLAN 1. The workstation's MAC is learned on VLAN 1, causing connectivity failure with VLAN 10 hosts. Adding the switchport access vlan 10 command resolves the issue.

Why this answer

The workstation's MAC address appears in VLAN 1 instead of VLAN 10 because the switch port is operating in the default VLAN (VLAN 1). The most likely cause is that the port has not been explicitly assigned to VLAN 10 using the `switchport access vlan 10` command. Without this command, the port remains in its default access VLAN (VLAN 1), so all frames from the workstation are associated with VLAN 1, preventing communication with hosts in VLAN 10.

Exam trap

Cisco often tests the default VLAN behavior (VLAN 1) and the fact that an access port without an explicit VLAN assignment remains in VLAN 1, leading candidates to overlook the missing `switchport access vlan` command and instead blame trunking, STP, or MAC table aging.

Why the other options are wrong

B

Candidates often assume any VLAN mismatch with VLAN 1 indicates a trunk misconfiguration, but a missing access VLAN is the more common and direct cause.

C

Candidates might think that an outdated MAC record is causing the VLAN display, but the dynamic learning process reflects the actual port VLAN.

D

Tempting because a blocked port can disrupt connectivity, but the MAC address table entry would still appear on the correct VLAN, not default to VLAN 1.

304
MCQmedium

Exhibit: A host on VLAN 10 can ping the local SVI but not a server in VLAN 20. The Layer 3 switch has both VLAN interfaces up. What is the next item to verify first?

A.Whether the server in VLAN 20 has the correct default gateway
B.Whether the switch should disable IP routing
C.Whether VLAN 10 should be the native VLAN
D.Whether the host should use a /8 mask instead of /24
AnswerA

The most likely fault is that the server in VLAN 20 lacks a properly configured default gateway (or has a gateway that points to a different router/switch). When the VLAN 10 host pings the server, the ICMP echo request is routed by the switch's SVI to VLAN 20, but if the server cannot send the echo reply back through the correct next hop, the ping fails. This creates a one-way reachability issue that is a classic symptom of an end-host gateway misconfiguration, not a problem with the switch's routing table or trunking.

Why this answer

If the source host can reach its own default gateway, the local VLAN and access port are probably fine. The next practical check is whether the server in VLAN 20 has the correct IP address, mask, and default gateway configured.

Exam trap

A frequent exam trap is to overlook the remote device’s default gateway configuration and instead suspect the Layer 3 switch’s routing or VLAN setup. Candidates often assume that because the VLAN interfaces are up, routing must be functional. However, if the server in VLAN 20 lacks the correct default gateway pointing to its VLAN SVI, it cannot return traffic to the source host, causing failed pings.

This one-way communication failure can mislead candidates into troubleshooting switch settings unnecessarily, wasting time and missing the root cause.

Why the other options are wrong

B

Disabling IP routing on the Layer 3 switch would prevent inter-VLAN routing entirely. Since both VLAN interfaces are up and the host can ping its local SVI, IP routing is likely enabled, so this is not the first item to verify.

C

The native VLAN setting affects untagged traffic on trunk links but does not directly impact inter-VLAN routing or the ability of hosts to communicate across VLANs. It is not the primary cause of the described symptom.

D

Using a /8 mask instead of /24 would cause subnetting issues, but since the host can ping its own VLAN interface, the subnet mask is likely correct. This is not the first or most probable cause of the problem.

305
MCQhard

A host address is 10.10.10.14/29. Which address is the broadcast address for its subnet?

A.10.10.10.7
B.10.10.10.15
C.10.10.10.8
D.10.10.10.16
AnswerB

The /29 CIDR notation specifies that the first 29 bits define the network portion, leaving 3 bits for host addresses. For the 10.10.10.14/29 subnet, the network address is 10.10.10.8. The broadcast address is always the last address within a subnet, derived by setting all host bits to one. In this scenario, setting the three host bits of the 10.10.10.8 network to one results in 10.10.10.15, which functions as the broadcast address for this specific subnet, satisfying the constraint of the /29 mask.

Why this answer

A /29 subnet has a block size of 8. In practical terms, the fourth-octet ranges are 0–7, 8–15, 16–23, and so on. Since 14 falls in the 8–15 block, the broadcast address is the last address in that block, which is 10.10.10.15.

This is a classic subnetting question that checks whether you can find the block first and then identify the final address in that block.

Exam trap

Avoid confusing the network address or a host address with the broadcast address. Remember, the broadcast address is the last address in the subnet range.

Why the other options are wrong

A

Option A, 10.10.10.7, is incorrect because it does not represent the broadcast address for the subnet defined by 10.10.10.14/29. The correct broadcast address is 10.10.10.15, which is the highest address in the subnet range.

C

The address 10.10.10.8 is not the broadcast address for the subnet 10.10.10.14/29. The correct broadcast address is 10.10.10.15, which is the highest address in the subnet range from 10.10.10.8 to 10.10.10.15.

D

The address 10.10.10.16 is outside the subnet defined by 10.10.10.14/29, which includes addresses from 10.10.10.8 to 10.10.10.15. Therefore, it cannot be the broadcast address for this subnet.

306
MCQhard

A host with address 172.16.5.10/23 wants to determine whether 172.16.6.20 is on the same local network. What is the correct conclusion?

A.It is on the same local network because both addresses begin with 172.16.
B.It is on the same local network because /23 covers all addresses in 172.16.5.x and 172.16.6.x
C.It is on a different network, so the host should use the default gateway
D.It is on a different network, so ARP will resolve it across the router automatically
AnswerC

The host determines the network address by performing a bitwise AND operation between its IP address (172.16.5.10) and its /23 subnet mask (255.255.254.0), resulting in 172.16.4.0. It then applies the same subnet mask to the target IP (172.16.6.20), yielding 172.16.6.0. Since these calculated network addresses differ, the host concludes the target is on a different network. Consequently, it must forward traffic to its default gateway for routing.

Why this answer

A /23 prefix covers two consecutive /24 ranges. In plain language, that means the network boundaries move in blocks of 2 in the third octet. The address 172.16.5.10/23 belongs to the 172.16.4.0/23 network, which covers 172.16.4.x and 172.16.5.x. The destination 172.16.6.20 belongs to a different /23 block, so it is not on the same local network.

This question checks whether you can think beyond default /24 boundaries and understand how a broader prefix changes the local network range. The host would therefore need to use its default gateway to reach 172.16.6.20, because that destination is off-subnet relative to the /23 in use.

Exam trap

Don't assume addresses with the same initial octets are in the same subnet; always calculate based on the subnet mask.

Why the other options are wrong

A

This option is incorrect because the addresses 172.16.5.10 and 172.16.6.20 belong to different subnets; 172.16.6.20 is in the 172.16.6.0/23 subnet, while 172.16.5.10 is in the 172.16.5.0/23 subnet.

B

This option is incorrect because a /23 subnet mask allows for addresses in the range of 172.16.4.0 to 172.16.5.255, meaning 172.16.6.20 is outside this range and not on the same local network.

D

Option D is incorrect because ARP (Address Resolution Protocol) operates within the same local network and cannot resolve addresses across routers. Since 172.16.6.20 is on a different network than 172.16.5.10, ARP cannot automatically resolve it.

307
PBQmedium

You are connected to the console of R1. The network has a point-to-point serial link between R1 and R2. The link is down and the line protocol is down. The cable is a DCE/DTE crossover, and R1 is the DCE. The initial configuration shows the interface with an IP address but no clock rate set.

Network Topology
S0/0/0 .1/30S0/0/0 .2/30serial DCER1R2

Hints

  • •The DCE side must provide the clock rate.
  • •Check the cable type using 'show controllers'.
  • •Common clock rates are 64000, 128000, 256000, etc.
A.Configure the clock rate on R1's serial interface.
B.Configure the clock rate on R2's serial interface.
C.Replace the serial cable with a straight-through cable.
D.Set the encapsulation on both ends to PPP.
AnswerA
solution
! R1
interface Serial0/0/0
clock rate 128000

Why this answer

On a serial DCE cable, the DCE end must configure a clock rate to provide timing. Without it, the line protocol stays down. Setting 'clock rate 128000' on R1 resolved the issue.

Exam trap

Remember that 'down/down' indicates a Layer 1 issue. On serial links, the DCE must provide clocking. Do not confuse DCE/DTE roles or jump to Layer 2 solutions like encapsulation.

Why the other options are wrong

B

The DTE end does not set clock rate; only the DCE end does.

C

Serial cables are always DCE/DTE crossover; straight-through cables are for Ethernet.

D

Encapsulation mismatch causes protocol down, not line protocol down; the line protocol is down due to no clock.

308
MCQeasy

Which IPv6 address type is automatically created on an interface and used for link-local communication?

A.Unique local
B.Global unicast
C.Link-local
D.Anycast
AnswerC

Link-local IPv6 addresses are automatically created on every IPv6-enabled interface without any manual configuration or stateful protocol. They use the FE80::/10 prefix and are derived from the interface's MAC address (or a privacy-generated value) using EUI-64 or RFC 7217. Their scope is strictly the local link, enabling Neighbor Discovery Protocol, address resolution, and router discovery even before any other global address is present. Because they are always present, they are the correct answer to which IPv6 address type is auto-created.

Why this answer

IPv6 interfaces automatically generate a link-local address in FE80::/10 for local-segment functions such as neighbor discovery.

Exam trap

Be careful not to confuse link-local addresses with global or unique local addresses, which are not automatically generated and serve different purposes.

Why the other options are wrong

A

Unique local addresses (ULAs) are designed for local communications within a site and are not automatically created on an interface for local-link communication. They require manual configuration and are not used for link-local purposes.

B

Global unicast addresses are routable addresses used for communication over the internet and are not automatically created for local-link communication. They require configuration and are not limited to a single local network segment.

D

Anycast addresses are not automatically created on an interface for local-link communication; they are assigned to multiple interfaces to allow for routing to the nearest one. Therefore, they do not serve the same purpose as link-local addresses.

← PreviousPage 5 of 5 · 308 questions total

Ready to test yourself?

Try a timed practice session using only Network Infrastructure and Connectivity questions.