Courseiva

CCNA Infrastructure Security Questions

75 of 77 questions · Page 1/2 · Infrastructure Security · Answers revealed

1
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using MD5. The engineer enters the following commands: interface GigabitEthernet0/0 ip ospf authentication message-digest ip ospf message-digest-key 1 md5 C1sco123 After applying the configuration, the OSPF neighbor relationship fails to form. Which action must the engineer take to resolve the issue?

A.Configure the ip ospf authentication-key command with the same password.
B.Change the key ID to 0 on both routers to match the default key.
C.Configure the same MD5 key and key ID on the neighboring router's interface.
D.Enable OSPF authentication globally using the area authentication command.
AnswerC

OSPF MD5 authentication requires that both neighbors use the same key ID and key string on their interfaces. The local configuration is correct, but without matching credentials on the neighbor, authentication fails and the adjacency will not form. Therefore, configuring the matching key on the neighboring router's interface resolves the issue.

Why this answer

OSPF MD5 authentication requires that both neighbors have the same key ID and key string configured on their interfaces. The local router is correctly configured for MD5, but the neighbor lacks the matching key, causing authentication to fail. Configuring the identical key on the neighbor's interface will allow the adjacency to form.

Exam trap

The trap here is assuming that enabling OSPF authentication on one side is sufficient, when in fact both neighbors must have matching credentials.

2
MCQmedium

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate IP spoofing. The router has two interfaces: GigabitEthernet0/0 connecting to the internet (untrusted) and GigabitEthernet0/1 connecting to the internal network (trusted). The engineer wants to enable strict uRPF on the untrusted interface. Which command should be applied to GigabitEthernet0/0?

A.ip verify unicast source reachable-via any
B.ip verify unicast source reachable-via rx
C.ip verify unicast reverse-path
D.ip verify unicast source reachable-via rx allow-default
AnswerB

The command ip verify unicast source reachable-via rx enables strict uRPF, which checks that the source IP address of incoming packets is reachable via the same interface the packet was received on. This is the correct configuration for the untrusted interface to prevent spoofed source addresses.

Why this answer

Strict uRPF is enabled with the command ip verify unicast source reachable-via rx on the interface. It ensures that the source IP address of incoming packets is reachable via the same interface, effectively dropping packets with spoofed source addresses that would not be routed back out that interface.

Exam trap

The trap here is confusing strict and loose uRPF modes, or using the deprecated command syntax, which may not be supported or may behave differently.

3
MCQmedium

A network engineer is implementing Zone-Based Policy Firewall (ZPFW) on a Cisco IOS router. The router has three interfaces: inside, outside, and DMZ. The engineer wants to allow HTTP traffic from the inside zone to the DMZ zone, and block all other traffic from inside to DMZ. Which configuration is required?

A.Configure a class-map that matches HTTP and apply it as an inspect action in the global policy.
B.Define a zone pair from inside to DMZ, apply a policy-map that inspects HTTP and drops all other traffic.
C.Apply an ACL on the inside interface permitting HTTP to the DMZ and denying all other traffic.
D.Create a zone pair from DMZ to inside and apply a policy-map that permits HTTP return traffic.
AnswerB

Zone-Based Policy Firewall uses zone pairs to define traffic flows between zones. To allow HTTP from inside to DMZ and block other traffic, a zone pair must be created from inside to DMZ, and a policy-map applied that permits HTTP and implicitly drops all other traffic. This meets the requirement.

Why this answer

In ZPFW, traffic between zones is controlled by zone pairs. A zone pair from inside to DMZ with a policy-map that inspects HTTP and implicitly drops other traffic will allow only HTTP and block the rest. Other options either do not use ZPFW correctly or apply the policy in the wrong direction.

Exam trap

The trap here is forgetting that ZPFW requires a zone pair to define the direction of traffic; applying a policy-map without a zone pair has no effect.

4
MCQhard

A network engineer is troubleshooting a Cisco IOS router that is configured for AAA authorization. The engineer notices that users are not being authorized for certain commands even though the TACACS+ server is reachable and the user is authenticated. The configuration includes 'aaa authorization exec default group tacacs+ local' and 'aaa authorization commands 15 default group tacacs+ local'. Which issue is most likely causing the problem?

A.The 'aaa new-model' command is not enabled.
B.The TACACS+ server is not configured to return the correct AV pairs for command authorization.
C.The local database does not have the necessary privilege level configured for the user.
D.The 'aaa authorization commands 15' command requires the 'if-authenticated' keyword to work.
AnswerB

For command authorization, the TACACS+ server must return authorization attributes that specify which commands are permitted. If the server does not have the correct command sets configured or returns an empty attribute, the router will deny the commands. The local fallback is only used if the server is unreachable, not if it returns a deny. Thus, the server configuration is the likely cause.

Why this answer

Command authorization relies on the TACACS+ server to provide authorization attributes that define which commands the user is allowed to execute. If the server is reachable and the user is authenticated but commands are denied, the server is likely not configured to return the proper AV pairs for command authorization. The local fallback is not used because the server is responding, so the issue is with the server's authorization configuration.

Exam trap

The trap here is assuming local fallback will occur for authorization failures when the server is reachable; fallback only happens if the server is unreachable.

5
MCQeasy

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The engineer wants to allow traffic from a multihomed customer that uses asymmetric routing. Which uRPF mode should the engineer configure?

A.Strict mode
B.VRF mode
C.Loose mode
D.Feasible path mode
AnswerC

Loose mode checks that the source IP address is reachable via any interface in the routing table, not necessarily the receiving interface. This allows packets from multihomed customers using asymmetric routing to pass, as long as the source is reachable. It still provides some anti-spoofing protection by verifying the source prefix exists in the routing table.

Why this answer

Loose mode uRPF verifies that the source IP address is reachable via any interface in the routing table, making it suitable for asymmetric routing scenarios. Strict mode would drop legitimate packets because it requires the source to be reachable via the receiving interface. Loose mode still provides anti-spoofing benefits by ensuring the source prefix exists in the routing table.

Exam trap

The trap here is assuming that strict mode is always the most secure choice, but it breaks asymmetric routing, which is common in multihomed environments.

6
MCQeasy

A network engineer is configuring AAA on a Cisco IOS router. The engineer wants to authenticate administrative users against a TACACS+ server and ensure that if the server is unreachable, a local username and password can be used as a fallback. Which configuration achieves this?

A.aaa authentication login default group tacacs+ local
B.aaa authentication login default local group tacacs+
C.aaa authentication login default group tacacs+ none
D.aaa authentication login default group tacacs+ enable
AnswerA

This command configures the default login authentication method list to first use TACACS+ and then fall back to the local username database if the TACACS+ server is unreachable. It meets the requirement of using TACACS+ with local fallback. The order of methods is critical: group tacacs+ is tried first, then local.

Why this answer

The correct command is aaa authentication login default group tacacs+ local. This method list attempts TACACS+ authentication first and, if the server is unreachable, falls back to the local username database. The order ensures TACACS+ is primary and local is used only when necessary.

Exam trap

The trap here is reversing the method order, which would cause local authentication to be used even when TACACS+ is available.

7
MCQmedium

A network administrator is configuring a router to authenticate with a TACACS+ server for administrative access. The administrator enters the command `aaa authentication login default group tacacs+ local` on the router. Which statement describes the authentication behavior when the TACACS+ server is reachable but rejects the user's credentials?

A.The router will deny access and will not attempt local authentication.
B.The router will attempt local authentication first, then TACACS+ if local fails.
C.The router will send the credentials to both TACACS+ and local simultaneously and grant access if either succeeds.
D.The router will fall back to the local database and authenticate the user if the local credentials are valid.
AnswerA

This is correct because with AAA authentication, methods are tried in order, but a failure response from a method (e.g., wrong password) stops the process. The local method is used only if the TACACS+ server is unreachable (timeout/error). When the server is reachable and rejects the credentials, the router denies access immediately. This behavior prevents unauthorized access via a less secure fallback.

Why this answer

With the command `aaa authentication login default group tacacs+ local`, the router first attempts authentication via the TACACS+ server group. If the server is reachable and returns a rejection (e.g., invalid credentials), the router treats that as a final denial and does not fall back to the local database. The local method is used only when the TACACS+ server is unreachable (timeout or error).

This ensures that a deliberate rejection by the central server is honored, preventing bypass via local accounts.

Exam trap

The trap here is assuming that the local method always serves as a fallback regardless of the server's response, when in fact it is only used when the server is unreachable.

8
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate login users against an external TACACS+ server. The engineer wants to ensure that if the TACACS+ server becomes unreachable, local authentication is used as a fallback. Which command set correctly configures this behavior on the router?

A.aaa authentication login default group tacacs+ local
B.aaa authentication login default group tacacs+ enable
C.aaa authentication login default group tacacs+ none
D.aaa authentication login default local group tacacs+
AnswerA

This command configures the default login authentication method list to first attempt TACACS+ and then fall back to the local username database if the server is unreachable. The 'group tacacs+' keyword specifies the TACACS+ server group, and 'local' provides the fallback. This meets the requirement exactly.

Why this answer

The correct configuration must specify TACACS+ as the primary authentication method and local as the fallback. The command 'aaa authentication login default group tacacs+ local' does exactly that: it attempts TACACS+ first, and if the server is unreachable, it uses the local username database. The other options either use the wrong fallback method, reverse the order, or disable authentication.

Exam trap

The trap here is confusing the 'enable' keyword with 'local' as a fallback method; 'enable' uses the enable password, not the local user database.

9
Multi-Selecthard

A network security engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS router to protect against denial-of-service attacks. The engineer wants to ensure that CoPP policies are applied correctly and that the router's control plane is protected. Which two statements about CoPP configuration are true? (Choose two.)

Select 2 answers
A.CoPP policies are applied globally to all interfaces using the service-policy command in global configuration mode.
B.CoPP policies are applied to the data plane to filter transit traffic.
C.CoPP can be configured to rate-limit specific types of traffic, such as OSPF and SSH, to protect the route processor.
D.CoPP uses a modular QoS CLI (MQC) framework with class maps and policy maps to classify and police control plane traffic.
E.CoPP requires that all control plane traffic be explicitly permitted in a class map, otherwise it is dropped by default.
AnswersC, D

CoPP allows the creation of class maps that match specific protocols or ports, such as OSPF or SSH, and policy maps that apply rate limiting (policing) to those classes. This protects the route processor from being overwhelmed by excessive control plane traffic. This statement is accurate.

Why this answer

CoPP uses the MQC framework to classify and police control plane traffic, allowing rate limiting of specific protocols like OSPF and SSH to protect the route processor. The policy is applied to the control plane, not globally or to the data plane. Unmatched traffic is not dropped by default; a class-default can be configured to manage it.

Therefore, the true statements are that CoPP uses MQC with class maps and policy maps, and that it can rate-limit specific traffic types.

Exam trap

The trap here is thinking that CoPP automatically drops all unmatched traffic, but actually it permits it unless a class-default with a police action is configured.

10
MCQmedium

A network engineer is configuring a Cisco IOS XE router to authenticate OSPFv3 neighbors. The engineer applies the following configuration under the OSPFv3 process: `area 0 authentication ipsec spi 256 sha1 0123456789ABCDEF0123456789ABCDEF01234567`. The engineer then verifies the neighbor relationship and sees that it remains in EXSTART state. Which action should the engineer take to resolve the issue?

A.Configure a key chain with the same key ID and key string on both routers.
B.Enable OSPFv3 authentication globally with the `ipv6 ospf authentication` command on all interfaces.
C.Configure the same IPsec SPI and key on the neighboring router under its OSPFv3 process.
D.Change the authentication algorithm to MD5 to match the neighbor's configuration.
AnswerC

OSPFv3 authentication uses IPsec AH or ESP with a manually configured SPI and key. Both neighbors must have matching SPI values and identical keys for the security association to be established. Without the same SPI and key on the peer, IPsec authentication fails, preventing OSPFv3 packets from being accepted and leaving the adjacency stuck in EXSTART.

Why this answer

OSPFv3 authentication uses IPsec to secure protocol packets. The configuration requires an SPI and a key to be manually set under the OSPFv3 process on both routers. When the peer lacks the matching SPI and key, authentication fails, and the adjacency cannot progress beyond EXSTART.

Configuring the identical IPsec parameters on the neighbor resolves the issue.

Exam trap

The trap here is assuming that OSPFv3 authentication can be configured per interface like OSPFv2, when it actually requires process-level IPsec parameters.

11
MCQeasy

A network administrator is configuring AAA on a Cisco IOS router. The administrator wants to authenticate administrative users against a TACACS+ server and ensure that if the TACACS+ server is unreachable, the router falls back to local authentication. The administrator has configured the TACACS+ server and local user accounts. Which additional configuration is required to achieve this?

A.Configure 'aaa authentication login default local group tacacs+'.
B.Configure 'aaa authentication login default group tacacs+ local'.
C.Configure 'aaa authentication login default group tacacs+ enable'.
D.Configure 'aaa authorization exec default group tacacs+ local'.
AnswerB

The 'aaa authentication login default group tacacs+ local' command configures the router to first attempt authentication via TACACS+ and then fall back to the local database if the TACACS+ server is unreachable. This meets the requirement for fallback authentication.

Why this answer

The correct command is 'aaa authentication login default group tacacs+ local', which specifies TACACS+ as the primary authentication method and local as the fallback. This ensures that if the TACACS+ server is unreachable, the router will use the local user database. Other options either reverse the order or use different methods that do not meet the fallback requirement.

Exam trap

The trap here is confusing the order of authentication methods or using 'enable' as a fallback instead of 'local', which does not provide local user authentication.

12
MCQmedium

A network administrator is configuring a Cisco IOS router to authenticate SSH users against an external TACACS+ server. The TACACS+ server is reachable at 10.10.10.5, and the shared secret is 'Cisco123'. The administrator wants to ensure that if the TACACS+ server is unreachable, a local user account 'backup' with privilege level 15 is used for authentication. Which configuration sequence correctly achieves this?

A.aaa new-model aaa authentication login default group tacacs+ username backup privilege 15 secret Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123
B.aaa new-model aaa authentication login default group tacacs+ local username backup privilege 15 password Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123
C.aaa new-model aaa authentication login default group tacacs+ enable username backup privilege 15 secret Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123
D.aaa new-model aaa authentication login default group tacacs+ local username backup privilege 15 secret Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123
AnswerD

This configuration enables AAA, sets the default login authentication method list to try TACACS+ first and then fall back to the local database, creates a local user with privilege 15, and defines the TACACS+ server with its IP and key. This exactly meets the requirement of using TACACS+ with local fallback and a local privileged account.

Why this answer

The correct configuration must enable AAA, set the default login authentication to use TACACS+ first and then the local database, create a local user with privilege 15, and define the TACACS+ server with the correct IP and key. The fallback to local is essential for when the TACACS+ server is unreachable, and using 'secret' is best practice for storing the local password securely.

Exam trap

The trap here is assuming that simply creating a local user account is enough for fallback, but the AAA method list must explicitly include 'local' after the TACACS+ group to enable fallback.

13
MCQhard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against route processor overload. The engineer creates a class map matching OSPF and BGP traffic and a policy map that polices this traffic to 1 Mbps with a burst of 2000 bytes. After applying the policy map to the control plane, the engineer notices that OSPF adjacencies flap intermittently. Which action should the engineer take to resolve the flapping?

A.Disable OSPF authentication to reduce packet size and processing overhead.
B.Configure a higher priority queue for OSPF traffic in the policy map.
C.Apply the policy map to all interfaces instead of the control plane.
D.Increase the policed rate and burst size to accommodate legitimate routing protocol traffic.
AnswerD

Intermittent OSPF adjacency flapping indicates that legitimate OSPF packets are being dropped due to the policer rate being too low. Increasing the rate and burst size allows the routing protocol traffic to pass without being policed, stabilizing the adjacencies. CoPP policies must be tuned to permit normal control plane traffic while still protecting against attacks.

Why this answer

CoPP policies that are too restrictive can drop legitimate control plane traffic, causing routing protocol adjacencies to flap. In this scenario, the policer rate of 1 Mbps is insufficient for OSPF and BGP traffic, leading to intermittent OSPF drops. Increasing the policed rate and burst size allows normal routing updates to pass while still providing protection against excessive traffic.

Exam trap

The trap here is assuming that any control plane policing is beneficial, without considering that overly aggressive rate limits can disrupt legitimate routing protocol operations.

14
MCQmedium

A network engineer is configuring a Cisco IOS XE router for Zone-Based Policy Firewall (ZPFW) to control traffic between a LAN zone and a WAN zone. The engineer wants to inspect all TCP and UDP traffic initiated from the LAN zone toward the WAN zone, while denying any traffic initiated from the WAN zone toward the LAN zone. The engineer has already created the zones and assigned interfaces. Which configuration step is required to achieve this?

A.Apply an access-list to the WAN interface inbound to block all traffic and an access-list to the LAN interface inbound to permit all traffic.
B.Configure a zone-pair from WAN to LAN and apply a policy-map that inspects all traffic, then configure a zone-pair from LAN to WAN with a policy-map that drops all traffic.
C.Enable Cisco IOS Firewall with the ip inspect command on the LAN interface and apply an inbound access-list on the WAN interface to deny all traffic.
D.Create a class-map that matches all TCP and UDP traffic, define a policy-map with inspect for that class, and apply the policy-map to the zone-pair from LAN to WAN using the service-policy command.
AnswerD

Zone-Based Policy Firewall requires a class-map to identify traffic, a policy-map to specify the action (inspect), and application of the policy-map to a zone-pair using the service-policy command. The zone-pair direction (LAN to WAN) determines the traffic flow to inspect, and by default, traffic not explicitly permitted is dropped, satisfying the requirement to deny WAN-initiated traffic.

Why this answer

To implement Zone-Based Policy Firewall, you must define class-maps to identify traffic, policy-maps to specify actions (such as inspect), and apply the policy-map to a zone-pair with the service-policy command. Inspecting traffic from LAN to WAN allows return traffic while denying unsolicited WAN-initiated traffic, as traffic not explicitly permitted between zones is dropped by default.

Exam trap

The trap here is assuming that a simple access-list can provide stateful inspection or that applying a policy-map in the wrong direction will still meet the requirement.

15
MCQmedium

A network administrator is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect against DoS attacks. The administrator wants to rate-limit ARP traffic destined to the route processor. Which configuration correctly applies a CoPP policy to ARP traffic?

A.class-map match-all ARP_CLASS match protocol arp ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! interface Control-Plane service-policy input COPP_POLICY
B.class-map match-all ARP_CLASS match protocol arp ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! control-plane host service-policy input COPP_POLICY
C.class-map match-all ARP_CLASS match protocol arp ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP_POLICY
D.class-map match-all ARP_CLASS match access-group name ARP_ACL ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! interface GigabitEthernet0/0 service-policy input COPP_POLICY
AnswerC

This configuration defines a class-map that matches ARP protocol traffic, a policy-map that applies policing to that class, and then attaches the policy to the control-plane interface using 'service-policy input'. The 'match protocol arp' command is valid for classifying ARP packets. This correctly implements CoPP for ARP.

Why this answer

Control Plane Policing (CoPP) is configured by defining class-maps to match traffic, policy-maps to define actions, and then attaching the policy to the control plane using the 'control-plane' global configuration mode with 'service-policy input'. The class-map must match ARP traffic using 'match protocol arp'. This setup rate-limits ARP packets destined to the route processor, protecting it from DoS attacks.

Exam trap

The trap here is applying the CoPP policy to a physical interface instead of the control plane.

16
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate SSH users against a TACACS+ server. The engineer wants to ensure that if the TACACS+ server is unreachable, the router will fall back to using the local username and password configured on the router. Which command set correctly configures this fallback behavior?

A.aaa authentication login default group tacacs+ local
B.aaa authentication login default group tacacs+ enable
C.aaa authentication login default local group tacacs+
D.aaa authentication login default group tacacs+ none
AnswerA

This command configures the default login authentication method list to first try TACACS+ and then fall back to the local username database if the server is unavailable. The 'local' keyword ensures local authentication is attempted only if the TACACS+ group fails or is unreachable, providing the desired fallback.

Why this answer

The correct command is 'aaa authentication login default group tacacs+ local'. The order of methods in the AAA authentication list is significant: the router tries each method in sequence until one succeeds. Placing 'group tacacs+' first ensures TACACS+ is preferred, and 'local' second ensures fallback to the local user database if the server is unreachable or rejects the credentials.

Exam trap

The trap here is assuming that the order of methods in the AAA authentication list does not matter or that 'local' must come first to be used as fallback.

17
MCQmedium

A network administrator is configuring a Cisco IOS router to authenticate login users against a TACACS+ server. The administrator wants to ensure that if the TACACS+ server is unreachable, the router falls back to the local username database for authentication. Which configuration should be applied?

A.aaa authentication login default group tacacs+
B.aaa authentication login default group tacacs+ local
C.aaa authentication login default local group tacacs+
D.aaa authentication login default group radius local
AnswerB

This command configures the default login authentication method list to first attempt TACACS+ and then fall back to the local database if the server is unreachable. The 'group tacacs+' keyword specifies the TACACS+ server group, and 'local' provides the backup. This meets the requirement of fallback to local authentication.

Why this answer

The correct configuration must specify TACACS+ as the primary authentication method and local as the fallback. The order of methods in the AAA authentication list determines the sequence: the router tries each method in turn until one succeeds or all fail. Placing 'group tacacs+' before 'local' ensures TACACS+ is attempted first, and if unreachable, local authentication is used.

Exam trap

The trap here is confusing the order of authentication methods in the AAA list, assuming that 'local' should come first to ensure fallback.

18
MCQmedium

A network engineer is configuring Zone-Based Policy Firewall on a Cisco IOS XE router. The company requires that all traffic from the internal LAN zone to the untrusted Internet zone be inspected, but traffic from the Internet to the internal LAN must be blocked unless it is return traffic. The engineer has already defined zone pairs with 'zone-pair security IN-TO-OUT source LAN destination INTERNET' and applied an inspect policy-map. What must the engineer do to complete the configuration?

A.Configure a class-map matching all traffic and apply it to the zone pair with the 'inspect' action.
B.Assign the interfaces to the LAN and INTERNET zones using the 'zone-member security' command.
C.Enable 'ip inspect' globally on the router to activate stateful inspection for all zones.
D.Apply the inspect policy-map directly to the inside interface using the 'service-policy type inspect' command.
AnswerB

Zone-Based Policy Firewall requires interfaces to be assigned to zones before any zone-pair policy takes effect. The 'zone-member security' interface command binds each interface to its zone, enabling the inspect policy-map to be applied to traffic traversing the LAN-to-INTERNET zone pair. Without this binding, the zone-pair policy is dormant and no inspection occurs.

Why this answer

Zone-Based Policy Firewall operates by grouping interfaces into security zones and defining policies between zone pairs. The inspect policy-map applied to the LAN-to-INTERNET zone pair only functions when the involved interfaces are assigned to their respective zones with 'zone-member security'. Until interfaces are bound to zones, the zone-pair policy remains inactive, so no stateful inspection or implicit return traffic handling occurs.

Exam trap

The trap here is assuming that applying a policy-map to a zone pair is sufficient, when interfaces must first be assigned to zones for the policy to take effect.

19
MCQeasy

A network technician is configuring a Cisco IOS router to authenticate administrative users via TACACS+ using a centralized server. The requirement is that if the TACACS+ server is unreachable, the router should use the local username database for authentication. Which command sequence correctly configures this fallback behavior?

A.aaa authentication login default group tacacs+ none
B.aaa authentication login default group tacacs+ local
C.aaa authentication login default group tacacs+ enable
D.aaa authentication login default local group tacacs+
AnswerB

This command configures AAA authentication for login to first use TACACS+ group and then fall back to the local database if the TACACS+ servers are unreachable. The order of methods is important: group tacacs+ is tried first, then local. This meets the requirement of fallback to local authentication.

Why this answer

The correct command is aaa authentication login default group tacacs+ local. This configures the router to attempt authentication via TACACS+ first, and if the TACACS+ server is unreachable, it falls back to the local username database. The order of methods is critical: the first method is tried, and subsequent methods are used only if the previous method fails or is unreachable.

Exam trap

The trap here is reversing the order of authentication methods, which would cause the router to use local authentication first and never query TACACS+ unless local fails.

20
MCQhard

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 192.168.1.0/24 subnet is encrypted and sent through the tunnel, while all other traffic is sent unencrypted. The engineer creates an extended ACL named VPN_TRAFFIC and applies it to the crypto map. However, after testing, the engineer finds that traffic from 192.168.1.0/24 is not being encrypted. Which action should the engineer take to correct the issue?

A.Apply the ACL to the outside interface with 'ip access-group VPN_TRAFFIC out'.
B.Ensure the ACL permits traffic from 192.168.1.0/24 to the remote subnet, and that the crypto map references this ACL.
C.Enable 'crypto ipsec transform-set' with the correct encapsulation mode.
D.Configure a route map to match the traffic and apply it to the crypto map.
AnswerB

For IPsec to encrypt traffic, the ACL used in the crypto map must permit the interesting traffic. If the ACL does not permit traffic from 192.168.1.0/24 to the remote subnet, the router will not encrypt it. The engineer must verify that the ACL entries match the source and destination subnets and that the crypto map correctly references the ACL.

Why this answer

The crypto map uses an extended ACL to identify interesting traffic that should be encrypted. If the ACL does not permit traffic from 192.168.1.0/24 to the remote subnet, that traffic will not be encrypted. The engineer must ensure the ACL entries match the desired source and destination and that the crypto map references the correct ACL.

This is a common misconfiguration when defining VPN traffic.

Exam trap

The trap here is confusing the ACL used for crypto map interesting traffic with an interface ACL, leading to applying the ACL to an interface instead of ensuring it is correctly referenced in the crypto map.

21
MCQhard

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. The engineer also wants to use a pre-shared key for authentication. Which configuration element is required to define the interesting traffic?

A.access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
B.crypto isakmp policy 10 authentication pre-share
C.crypto map MYMAP 10 ipsec-isakmp set peer 203.0.113.2 set transform-set MYSET match address 101
D.crypto ipsec transform-set MYSET esp-aes esp-sha-hmac
AnswerA

The extended ACL defines the interesting traffic that should be encrypted by the IPsec VPN. In this case, it permits IP traffic from 10.1.1.0/24 to 10.2.2.0/24. This ACL is then referenced in the crypto map with 'match address 101'. Without this ACL, the router would not know which traffic to encrypt, making it the essential element for defining interesting traffic.

Why this answer

The interesting traffic is defined by an extended ACL that matches the source and destination subnets. This ACL is then referenced in the crypto map using the 'match address' command. The ACL specifies which packets are encrypted and sent through the VPN tunnel, while all other traffic is sent unencrypted.

The other options are part of the IPsec configuration but do not define the traffic to be encrypted.

Exam trap

The trap here is confusing the crypto map's 'match address' command with the ACL itself; the ACL is the actual definition of interesting traffic.

22
MCQmedium

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The engineer wants to ensure that packets are dropped if the source IP address is not reachable via the same interface they arrived on. The engineer configures 'ip verify unicast source reachable-via rx' on interface GigabitEthernet0/0. However, some legitimate traffic from a secondary path is being dropped. What is the most likely cause?

A.The interface must be configured with 'ip verify unicast source reachable-via any' to allow asymmetric routing.
B.The uRPF feature requires CEF to be enabled, and CEF is not enabled on the router.
C.The router uses loose uRPF, which only checks if the source is reachable via any interface, so it should not drop legitimate traffic.
D.The router uses strict uRPF, which requires the source to be reachable via the same interface; asymmetric routing causes legitimate packets to be dropped.
AnswerD

The 'reachable-via rx' option enables strict uRPF, which checks that the source IP is reachable via the same interface the packet arrived on. In asymmetric routing scenarios, where return traffic takes a different path, legitimate packets can be dropped. This is the most likely cause of the dropped traffic.

Why this answer

The 'reachable-via rx' option enables strict uRPF, which drops packets if the source IP is not reachable via the ingress interface. In networks with asymmetric routing, legitimate traffic may arrive on an interface that is not the best path back to the source, causing drops. Switching to loose uRPF ('reachable-via any') would alleviate this but reduce spoofing protection.

CEF is typically enabled by default, so it is not the issue.

Exam trap

The trap here is confusing strict and loose uRPF modes; 'rx' means strict, which is sensitive to asymmetric routing, while 'any' means loose.

23
MCQhard

A network engineer is troubleshooting an IPsec VPN tunnel between two Cisco IOS routers. The tunnel fails to establish, and the engineer sees the debug output: 'ISAKMP: Unable to find a valid preshared key'. The engineer verifies that the preshared key is identical on both peers. Which additional configuration is most likely causing the issue?

A.The crypto isakmp key command is configured with the wrong peer address.
B.The crypto map is applied to the wrong interface.
C.The transform set is not configured with the correct encryption algorithm.
D.The ISAKMP policy priority numbers are different on the two peers.
AnswerA

If the preshared key is configured for a peer address that does not match the actual source IP of the remote peer, the router cannot find a valid key for that peer. This results in the 'Unable to find a valid preshared key' error even if the key string is correct. The engineer should verify that the peer address in the 'crypto isakmp key' command matches the remote peer's IP.

Why this answer

The error 'Unable to find a valid preshared key' typically occurs when the router cannot match the preshared key to the peer's IP address. This is often due to the 'crypto isakmp key' command specifying an incorrect peer address, even if the key string itself is correct.

Exam trap

The trap here is assuming that identical key strings are sufficient; the key must also be associated with the correct peer IP address.

24
MCQhard

A network engineer is implementing Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS XE router to mitigate spoofed source IP addresses. The router has two interfaces: GigabitEthernet0/0 (WAN, connected to ISP) and GigabitEthernet0/1 (LAN, connected to internal network). The engineer wants to apply strict uRPF on the WAN interface to drop packets with spoofed source addresses, but the internal network uses asymmetric routing, with some return traffic going out a different interface. The engineer applies the following configuration: interface GigabitEthernet0/0 ip address 203.0.113.1 255.255.255.0 ip verify unicast source reachable-via rx After applying this, the engineer notices that some legitimate traffic from the internal network is being dropped. Which action should the engineer take to resolve the issue while maintaining spoofing protection?

A.Configure uRPF with an access list to allow specific internal subnets that are subject to asymmetric routing, while keeping strict mode for other traffic.
B.Enable uRPF in loose mode with an access list that denies known spoofed prefixes, and apply it to the WAN interface.
C.Disable uRPF on the WAN interface and instead implement IP Source Guard on the LAN interfaces to prevent spoofing.
D.Change the uRPF mode to loose mode by using the ip verify unicast source reachable-via any command on the WAN interface.
AnswerA

Cisco IOS XE supports uRPF with an access list (ip verify unicast source reachable-via rx allow-self-ping acl) to exempt certain source addresses from the strict check. By creating an ACL that permits the internal subnets experiencing asymmetric routing, the engineer can maintain strict uRPF for all other traffic, preserving spoofing protection while allowing legitimate asymmetric flows. This is the recommended approach for handling exceptions without weakening overall security.

Why this answer

Strict uRPF drops packets if the source address is not reachable via the incoming interface. Asymmetric routing causes legitimate return traffic to arrive on an interface different from the one used to reach the source, triggering drops. Cisco IOS XE allows an access list with strict uRPF to exempt specific source addresses from the check.

By permitting the internal subnets that use asymmetric routing in the ACL, the engineer maintains strict uRPF for all other traffic, preserving spoofing protection while allowing legitimate flows.

Exam trap

The trap here is thinking that loose mode is the only way to handle asymmetric routing, when in fact strict mode with an exception ACL can maintain stronger security for most traffic.

25
MCQhard

A network administrator is configuring AAA on a Cisco IOS router using TACACS+. The requirement is that if the TACACS+ server is unreachable, the router should allow administrative access using the local username and password configured on the router. Which configuration accomplishes this?

A.aaa authentication login default group tacacs+ enable
B.aaa authentication login default group tacacs+ local
C.aaa authentication login default group tacacs+ if-needed
D.aaa authentication login default group tacacs+ none
AnswerB

This command configures the default method list for login authentication to first attempt TACACS+ and then fall back to the local username database if the TACACS+ server is unreachable. The 'local' keyword ensures that local authentication is used as a backup, satisfying the requirement.

Why this answer

To configure AAA authentication with TACACS+ and a fallback to the local username database, you use the 'aaa authentication login default group tacacs+ local' command. The 'local' keyword specifies that the router should use its local username and password configuration if the TACACS+ server does not respond. This provides a secure fallback method, ensuring administrative access is not lost during server outages.

Exam trap

The trap here is confusing the 'local' keyword with 'enable' or 'none' for fallback authentication.

26
Multi-Selectmedium

A network administrator is troubleshooting an 802.1X deployment on a Cisco switch. Users report that they cannot authenticate and are placed into a guest VLAN. The administrator suspects that the switch is not receiving EAPOL packets from the supplicants. Which two actions should the administrator take to verify that EAPOL packets are being received and processed on the switch? (Choose two.)

Select 2 answers
A.Use the 'show authentication sessions interface' command to view the session status and method.
B.Enable 'debug dot1x all' and observe the debug output for EAPOL packet reception.
C.Use the 'show dot1x interface' command to check the authentication status and EAPOL statistics.
D.Check the 'show mac address-table interface' command to see if the supplicant's MAC address is learned.
E.Use the 'show radius statistics' command to verify RADIUS server reachability.
AnswersB, C

The 'debug dot1x all' command provides real-time debugging information about 802.1X events, including EAPOL packet reception, authentication exchanges, and errors. It is a powerful tool to confirm whether EAPOL packets are being received and processed by the switch.

Why this answer

The two correct actions are using 'show dot1x interface' and enabling 'debug dot1x all'. These commands provide direct visibility into EAPOL packet reception and processing on the switch. The other options either show session information that doesn't confirm EAPOL reception or focus on RADIUS or MAC address tables, which are not specific to verifying EAPOL packets from the supplicant.

Exam trap

The trap here is assuming that seeing the MAC address in the MAC address table means EAPOL is working, but EAPOL frames are not learned in the MAC table.

27
MCQhard

A network engineer is configuring object tracking to influence a static default route on a Cisco IOS router. The engineer wants the default route to be removed from the routing table if the tracked object (a reachability test to 192.0.2.1) goes down. The engineer enters the following configuration: track 1 ip route 192.0.2.1 255.255.255.255 reachability ip route 0.0.0.0 0.0.0.0 203.0.113.1 track 1 After the link to 203.0.113.1 fails, the default route remains in the routing table. What is the most likely reason?

A.The tracked object uses a reachability test to 192.0.2.1, which may still be reachable via an alternate path, so the object remains up.
B.The static route must be configured with a administrative distance lower than the default to be removed by tracking.
C.The 'track 1 ip route' command requires a delay before the object goes down, so the route removal is delayed indefinitely.
D.The 'track' keyword on the static route must reference the track object by number, but the syntax requires 'track 1' to be placed before the route.
AnswerA

The track object tests reachability to 192.0.2.1, not the status of the 203.0.113.1 interface. If 192.0.2.1 remains reachable through another route (e.g., a backup link), the tracked object stays up and the static default route is not removed. This is the most likely reason the route persists despite the primary link failure.

Why this answer

Object tracking removes a static route only when the tracked object transitions to a down state. The reachability test to 192.0.2.1 may succeed via an alternate path even after the primary link fails, keeping the object up. The track keyword placement, administrative distance, and delay parameters do not explain the persistent route in this scenario.

Exam trap

The trap here is confusing interface line-protocol tracking with IP reachability tracking; a reachability probe can succeed over a backup path and keep the object up.

28
MCQhard

A network engineer is implementing 802.1X authentication on a Cisco Catalyst switch. The engineer wants to ensure that if the RADIUS server is unavailable, the switch will place the port in a restricted VLAN for guest access. Which command must be configured on the switch port?

A.authentication event no-response action authorize vlan 100
B.authentication event server dead action authorize vlan 100
C.authentication event fail action authorize vlan 100
D.authentication fallback vlan 100
AnswerB

This command configures the switch to authorize the port into VLAN 100 when the RADIUS server is detected as dead. This provides a fallback mechanism for guest access when the authentication server is unreachable, exactly as required. The VLAN must be configured and allowed on the port.

Why this answer

The correct command to place a port in a restricted VLAN when the RADIUS server is dead is 'authentication event server dead action authorize vlan 100'. This event is triggered when the switch determines the server is unresponsive after multiple retries. The 'fail' event is for authentication failures, and 'no-response' is for individual request timeouts, not the server being declared dead.

Exam trap

The trap here is confusing the 'server dead' event with 'no-response' or 'fail' events, which trigger under different conditions.

29
MCQeasy

A network administrator is configuring AAA on a Cisco IOS router to authenticate administrative SSH users against a TACACS+ server. The administrator wants to ensure that if the TACACS+ server is unreachable, a locally configured user account can still be used for authentication. Which configuration should the administrator apply?

A.aaa authentication login default group tacacs+ none
B.aaa authentication login default group tacacs+ local
C.aaa authentication login default local group tacacs+
D.aaa authentication login default group tacacs+ enable
AnswerB

The 'aaa authentication login default group tacacs+ local' command configures the default login authentication method list to first attempt TACACS+ and then fall back to the local user database if the TACACS+ server does not respond. This provides the required resilience, allowing administrative access even when the TACACS+ server is unreachable, as long as a local username is configured.

Why this answer

The 'aaa authentication login default group tacacs+ local' command creates a method list that tries TACACS+ first and then the local username database. This ensures that if the TACACS+ server is unreachable, administrators can still log in using locally configured credentials. The order of methods is critical: TACACS+ must be primary to maintain centralized authentication, with local as a backup for resiliency.

Exam trap

The trap here is reversing the order of authentication methods or using 'none' as a fallback, which either prioritizes local accounts over TACACS+ or bypasses authentication entirely.

30
MCQmedium

A network engineer is configuring an IPv6 First Hop Security feature on a Cisco Catalyst switch to prevent rogue devices from sending Router Advertisement messages with a prefix that conflicts with the legitimate prefix. The engineer wants to ensure that only authorized routers can advertise prefixes, while still allowing hosts to perform SLAAC. Which feature should be implemented?

A.IPv6 Source Guard
B.IPv6 DHCP Guard
C.IPv6 Destination Guard
D.IPv6 RA Guard
AnswerD

IPv6 RA Guard filters Router Advertisement and Redirect messages on ports where they are not expected. It can be configured to block RAs from unauthorized devices while allowing legitimate routers. This directly prevents rogue devices from advertising conflicting prefixes and is the correct solution for the stated requirement.

Why this answer

The requirement is to prevent rogue devices from sending Router Advertisement messages with conflicting prefixes while allowing legitimate routers and SLAAC. IPv6 RA Guard is designed specifically to filter RA and Redirect messages on untrusted ports, ensuring only authorized routers can advertise. The other features address different threats such as source spoofing, rogue DHCPv6 servers, or ND cache exhaustion.

Exam trap

The trap here is confusing RA Guard with other IPv6 First Hop Security features like DHCP Guard or Source Guard, which protect against different rogue device behaviors.

31
MCQhard

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The engineer wants to ensure that uRPF is applied in a way that allows asymmetric routing. Which uRPF mode should be configured?

A.VLAN mode
B.Feasible path mode
C.Strict mode
D.Loose mode
AnswerD

Loose mode uRPF checks that the source IP address is reachable via any interface in the routing table, not necessarily the incoming interface. This allows asymmetric routing because the return path can be different. It still provides spoofing mitigation by verifying the source is routable. This meets the requirement.

Why this answer

Loose mode uRPF verifies that the source IP address is present in the routing table, but does not require the packet to arrive on the same interface as the route to the source. This allows asymmetric routing while still providing anti-spoofing protection. Strict mode would drop packets in asymmetric environments.

VLAN mode and feasible path mode are not standard uRPF modes that allow asymmetric routing.

Exam trap

The trap here is assuming that strict mode uRPF can be used with asymmetric routing; strict mode requires the reverse path to match the incoming interface, which fails in asymmetric setups.

32
MCQmedium

A network administrator is configuring a Cisco IOS router to authenticate login users against an external TACACS+ server. The administrator wants to ensure that if the TACACS+ server becomes unreachable, local authentication is used as a fallback. The TACACS+ server has been configured with the IP address 10.1.1.100 and the shared secret key 'cisco123'. Which set of commands correctly implements this requirement?

A.aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key cisco123 aaa authentication login default group tacacs+ line vty 0 4 login authentication default
B.aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key cisco123 aaa authentication login default group tacacs+ enable line vty 0 4 login authentication default
C.aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key cisco123 aaa authentication login default group tacacs+ local line vty 0 4 login authentication default
D.aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key cisco123 aaa authentication login default group tacacs+ local line vty 0 4 login authentication TAC1
AnswerC

This configuration enables AAA, defines a TACACS+ server with the correct IP and key, and sets the default authentication method list to try TACACS+ first and then fall back to local. Applying the method list to the VTY lines ensures remote login uses this sequence. This meets the fallback requirement.

Why this answer

The correct configuration enables AAA, defines the TACACS+ server with the proper address and key, and sets the default authentication method list to use TACACS+ with local fallback. Applying this method list to the VTY lines ensures remote login attempts use the intended sequence. The 'local' keyword is essential for fallback when the server is unreachable.

Exam trap

The trap here is forgetting to include the 'local' keyword in the AAA authentication method list, which is required to enable local authentication as a fallback.

33
MCQmedium

A network engineer is deploying a new branch office router (Cisco IOS XE) and wants to protect the control plane from routing protocol floods. The router will run OSPF and EIGRP. The engineer must ensure that control plane packets are rate-limited and that the router logs when the rate is exceeded. Which of the following should be configured?

A.Management Plane Protection (MPP) with an ACL that permits only SSH and SNMP.
B.Control Plane Protection (CPPr) with a port-filter policy that drops all non-management traffic.
C.Control Plane Policing (CoPP) using a policy-map that classifies routing protocol traffic and applies police actions with exceeded-action logging.
D.uRPF strict mode on all interfaces facing the service provider.
AnswerC

CoPP allows granular rate-limiting of control plane traffic. By classifying OSPF and EIGRP packets and applying a policer with an exceeded action of transmit and log, the router will rate-limit and log when the rate is exceeded. This meets the requirement to protect the control plane and log violations.

Why this answer

Control Plane Policing (CoPP) is designed to protect the control plane by rate-limiting traffic destined to the router's CPU. By classifying OSPF and EIGRP packets and applying a policer with logging, the engineer can ensure that routing protocol floods are mitigated and that any excess is logged. Other options do not provide both rate-limiting and logging for control plane traffic.

Exam trap

The trap here is confusing Control Plane Policing with Control Plane Protection or Management Plane Protection, which have different purposes and do not provide rate-limiting with logging.

34
MCQmedium

A network administrator is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate IP spoofing. The router has two interfaces: GigabitEthernet0/0 connects to the internet, and GigabitEthernet0/1 connects to the internal network. The administrator wants to ensure that packets arriving on GigabitEthernet0/0 are dropped if their source address is not reachable via that interface. However, the administrator also wants to allow asymmetric routing where return traffic may use a different path. Which uRPF mode should be configured on GigabitEthernet0/0?

A.ip verify unicast source reachable-via rx
B.ip verify unicast source reachable-via any
C.ip verify unicast reverse-path
D.ip verify unicast source reachable-via tx
AnswerB

The any keyword enables loose uRPF, which checks that the source address is reachable via any interface in the routing table. This allows asymmetric routing because the return path can be different, while still dropping packets with spoofed source addresses that are not in the routing table. This meets the requirement.

Why this answer

Loose uRPF, configured with ip verify unicast source reachable-via any, checks the routing table for the source address but does not require the source to be reachable via the incoming interface. This allows asymmetric routing while still providing spoofing mitigation. Strict uRPF (rx) would drop packets in asymmetric scenarios, and the other options are either invalid or equivalent to strict mode.

Exam trap

The trap here is confusing strict and loose uRPF modes, or using outdated syntax, when the requirement to allow asymmetric routing points to loose mode.

35
MCQhard

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against a flood of OSPF hello packets. The engineer wants to ensure that OSPF hellos are rate-limited to 1000 packets per second (pps) with a burst of 2000 packets, while allowing all other traffic without policing. The engineer applies the following configuration: class-map match-any OSPF_HELLO match access-group name OSPF_HELLO_ACL ! policy-map COPP_POLICY class OSPF_HELLO police 1000 2000 conform-action transmit exceed-action drop class class-default police 1000000 2000000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP_POLICY After applying the policy, the engineer notices that OSPF adjacencies are flapping. Which action should the engineer take to resolve the issue?

A.Increase the police rate for the OSPF_HELLO class to 5000 pps to accommodate normal OSPF hello traffic.
B.Verify that the OSPF_HELLO_ACL matches OSPF hello packets by permitting IP protocol 89 and the correct multicast destination address, and adjust the ACL if necessary.
C.Modify the class-default policer to transmit all traffic without policing by using police 1000000 2000000 conform-action transmit exceed-action transmit.
D.Apply the CoPP policy to the control plane using the service-policy output command instead of input.
AnswerB

OSPF hellos are sent to multicast address 224.0.0.5 (AllSPFRouters) using IP protocol 89. If the ACL does not correctly match these parameters, OSPF hellos fall into class-default and may be dropped if the class-default policer is exceeded. Ensuring the ACL matches protocol 89 and destination 224.0.0.5 (and possibly source addresses) will correctly classify hellos into the OSPF_HELLO class, where they are policed at a higher rate, preventing flapping.

Why this answer

OSPF hellos are multicast to 224.0.0.5 with IP protocol 89. If the ACL used in the class-map does not match these specifics, hellos are classified into class-default and may be dropped when the class-default policer is exceeded, causing adjacencies to flap. The engineer must verify the ACL matches protocol 89 and the correct multicast destination, and adjust it so hellos are policed by the dedicated class with a higher rate.

Exam trap

The trap here is focusing on the police rate values while overlooking that the class-map may not actually match OSPF hellos due to an incorrect ACL, leading to hellos being policed by class-default and dropped.

36
MCQmedium

A network security engineer is configuring a Cisco IOS router to support Zone-Based Policy Firewall (ZPF). The engineer has created zones INSIDE and OUTSIDE, assigned interfaces to them, and now needs to allow HTTP traffic from INSIDE to OUTSIDE while inspecting return traffic. Which configuration step is required to achieve this?

A.Create a policy-map with inspect action for HTTP, apply it to both INSIDE and OUTSIDE interfaces using `service-policy type inspect` in the inbound direction.
B.Create an ACL that permits HTTP from INSIDE to OUTSIDE, apply it to the INSIDE interface with `ip access-group` in the outbound direction, and enable `ip inspect` on the OUTSIDE interface.
C.Create a zone-pair from INSIDE to OUTSIDE, define a policy-map with inspect action for HTTP, and apply the policy-map to the zone-pair using `service-policy type inspect`.
D.Create a class-map that matches HTTP traffic, define a policy-map with inspect action, and apply the policy-map to the INSIDE zone using `service-policy type inspect`.
AnswerC

This is correct because ZPF requires traffic policies to be applied to zone pairs. The zone-pair defines the direction (INSIDE to OUTSIDE). The policy-map, containing a class-map that matches HTTP and an inspect action, is applied to the zone-pair with `service-policy type inspect`. This allows HTTP traffic and inspects return traffic, creating a stateful firewall.

Why this answer

Zone-Based Policy Firewall (ZPF) uses zone pairs to apply traffic policies between zones. To allow HTTP from INSIDE to OUTSIDE and inspect return traffic, you must create a zone-pair from INSIDE to OUTSIDE, define a policy-map with an inspect action for HTTP, and apply that policy-map to the zone-pair using `service-policy type inspect`. This creates a stateful inspection allowing return traffic.

Applying policies directly to zones or interfaces is not correct for ZPF.

Exam trap

The trap here is applying the policy-map to a zone or interface instead of a zone-pair, which is the correct attachment point in ZPF.

37
MCQmedium

A network engineer configures a Cisco IOS router with the following commands: ip access-list extended BLOCK_TELNET deny tcp any any eq 23 permit ip any any ! interface GigabitEthernet0/0 ip access-group BLOCK_TELNET in After applying the configuration, the engineer notices that Telnet traffic from the local router to a remote device is still successful. What is the cause of this issue?

A.The access list is applied in the inbound direction, which only filters traffic entering the interface, not traffic originated by the router.
B.The implicit deny at the end of the access list is blocking the Telnet traffic, but the 'permit ip any any' statement overrides it.
C.The access list must be applied with the 'ip access-group BLOCK_TELNET out' command on the same interface to filter locally generated traffic.
D.The 'deny tcp any any eq 23' statement is incorrect because Telnet uses TCP port 22, not port 23.
AnswerA

The access list is applied inbound on GigabitEthernet0/0, so it filters only packets entering that interface. Locally generated Telnet traffic from the router does not pass through the inbound access-group; it is subject to outbound filtering on the egress interface or to a VTY access-class. Therefore, the Telnet session succeeds despite the deny statement.

Why this answer

Access lists applied to an interface with the ip access-group command filter only traffic that passes through that interface in the specified direction. They do not filter traffic originated by the router itself. To control Telnet access to or from the router, an access-class must be applied under the VTY lines.

Since the ACL is applied inbound on an interface, it does not affect locally generated Telnet packets, so the Telnet session succeeds.

Exam trap

The trap here is assuming that an interface ACL applied inbound will also filter traffic generated by the router itself.

38
MCQhard

A network administrator is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive traffic. The administrator wants to rate-limit ICMP echo requests destined to the router itself to 64 kbps, while allowing all other traffic to the control plane without restriction. Which configuration snippet correctly achieves this?

A.class-map match-any ICMP match access-group name ICMP_ACL ! policy-map COPP class ICMP police 64000 class class-default police 8000 ! control-plane service-policy input COPP
B.class-map match-any ICMP match access-group name ICMP_ACL ! policy-map COPP class ICMP police 64000 class class-default police 8000000 ! control-plane service-policy input COPP
C.class-map match-any ICMP match access-group name ICMP_ACL ! policy-map COPP class ICMP police 64000 conform-action transmit exceed-action drop class class-default police 64000 ! control-plane service-policy output COPP
D.class-map match-any ICMP match access-group name ICMP_ACL ! policy-map COPP class ICMP police 64000 class class-default ! control-plane service-policy input COPP
AnswerD

This configuration correctly applies a 64 kbps policer to ICMP traffic matching the ACL, while the class-default has no policer, allowing all other control plane traffic to pass without restriction. The control-plane service-policy applies the policy map to the control plane interface.

Why this answer

The correct configuration creates a class map matching ICMP traffic via an ACL, a policy map that polices that class to 64 kbps, and leaves the class-default without a policer. Applying the policy map to the control-plane in the input direction enforces the rate limit on ICMP traffic destined to the router while allowing all other control plane traffic unrestricted.

Exam trap

The trap here is assuming that class-default must always have a policer; in CoPP, if no policer is configured for class-default, traffic in that class is not rate-limited.

39
Multi-Selectmedium

A network engineer is implementing Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate IP spoofing. The router has two interfaces: GigabitEthernet0/0 (WAN) and GigabitEthernet0/1 (LAN). The engineer wants to apply strict mode uRPF on the WAN interface and loose mode uRPF on the LAN interface. Which two commands are required to accomplish this? (Choose two.)

Select 2 answers
A.interface GigabitEthernet0/0, then ip verify unicast source reachable-via rx
B.interface GigabitEthernet0/1, then ip verify unicast source reachable-via any
C.interface GigabitEthernet0/0, then ip verify unicast source reachable-via any
D.interface GigabitEthernet0/1, then ip verify unicast source reachable-via rx
E.ip verify unicast source reachable-via rx allow-default
AnswersA, B

This command enables strict mode uRPF on the WAN interface. Strict mode checks that the source IP address is reachable via the same interface the packet was received on. This is appropriate for WAN interfaces where symmetric routing is expected, and it helps prevent spoofed packets from entering the network.

Why this answer

The correct commands are to enable strict mode uRPF on the WAN interface with ip verify unicast source reachable-via rx, and loose mode uRPF on the LAN interface with ip verify unicast source reachable-via any. These configurations match the requirement of strict on WAN and loose on LAN, providing effective anti-spoofing while accommodating asymmetric routing on the LAN.

Exam trap

The trap here is mixing up the keywords rx and any, which correspond to strict and loose modes respectively.

40
MCQmedium

A network engineer is configuring a Cisco IOS XE router to send syslog messages to a remote server for security auditing. The engineer wants to ensure that the syslog messages are protected from eavesdropping and tampering. The router already has a CA trustpoint configured. Which command should the engineer use to enable secure syslog?

A.logging host 10.10.10.10 transport tcp port 6514
B.logging host 10.10.10.10 transport tls port 6514
C.logging host 10.10.10.10 transport udp port 514
D.logging host 10.10.10.10 transport tcp port 514
AnswerB

This command enables secure syslog over TLS by specifying the 'tls' transport and port 6514. The router will use the configured CA trustpoint to establish a TLS connection to the syslog server, ensuring confidentiality and integrity of the syslog messages. This meets the requirement for secure syslog.

Why this answer

The requirement is to protect syslog messages from eavesdropping and tampering, which necessitates encryption and integrity protection. Syslog over TLS (often called secure syslog) uses Transport Layer Security to encrypt and authenticate messages. The command 'logging host 10.10.10.10 transport tls port 6514' enables TLS transport, leveraging the existing CA trustpoint for certificate-based authentication.

Other transport methods like UDP or plain TCP do not provide encryption. Therefore, the correct configuration is to use the 'tls' transport option.

Exam trap

The trap here is assuming that specifying port 6514 alone enables TLS, but the transport must be explicitly set to 'tls' to activate encryption.

41
MCQhard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive traffic. The engineer has created a class map named 'CRITICAL' that matches BGP traffic and a policy map named 'COPP-POLICY' that applies a police rate of 1000000 bps with a conform-action transmit and exceed-action drop. After applying the policy map to the control plane, the engineer notices that BGP sessions are flapping. Which action should the engineer take to resolve the issue?

A.Increase the police rate in the policy map to accommodate the BGP traffic.
B.Change the exceed-action to transmit and set a lower conform-action rate.
C.Remove the class map from the policy map and rely on default CoPP settings.
D.Apply the policy map to the data plane interfaces instead of the control plane.
AnswerA

BGP sessions may flap if the police rate is too low and legitimate BGP traffic is being dropped. Increasing the police rate allows more BGP traffic to be transmitted, preventing session flaps. The engineer should monitor the actual BGP traffic rate and adjust the policer accordingly.

Why this answer

The BGP sessions are flapping because the CoPP policer is dropping legitimate BGP traffic due to a rate limit that is too low. Increasing the police rate allows the necessary BGP traffic to pass, stabilizing the sessions. The other options either disable policing, apply it incorrectly, or remove protection, none of which address the root cause.

Exam trap

The trap here is assuming that any BGP flap under CoPP is due to a misconfiguration, but often it is simply an insufficient policer rate for the actual traffic volume.

42
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate administrative SSH logins against an external TACACS+ server. The engineer wants to ensure that if the TACACS+ server becomes unreachable, a locally configured fallback account can still be used. The TACACS+ server IP is 10.1.1.100 and the shared key is 'Cisco123'. Which configuration snippet correctly implements this requirement?

A.aaa new-model aaa authentication login default group tacacs+ tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123
B.aaa new-model aaa authentication login default group tacacs+ local tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123
C.aaa new-model aaa authentication login default group tacacs+ local tacacs-server host 10.1.1.100 key Cisco123
D.aaa new-model aaa authentication login default local group tacacs+ tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123
AnswerB

This configuration enables AAA with 'aaa new-model', sets the default login authentication method list to try TACACS+ first and then fall back to the local user database, and defines the TACACS+ server with its IP and key. The 'local' keyword ensures that if the TACACS+ server is unreachable, the router will use local authentication, meeting the requirement.

Why this answer

The correct configuration enables AAA, defines a TACACS+ server, and sets the default login authentication method list to 'group tacacs+ local'. This ensures that the router first attempts to authenticate against the TACACS+ server and, if that server is unreachable, falls back to the local user database. The other options either omit the fallback, use deprecated commands, or reverse the authentication order.

Exam trap

The trap here is assuming that simply enabling AAA and configuring a TACACS+ server automatically provides local fallback, when the method list must explicitly include 'local' as a secondary method.

43
MCQmedium

A network engineer is configuring a site-to-site VPN between two Cisco IOS routers using IPsec. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet is encrypted and sent over the VPN, while all other traffic is sent unencrypted. Which configuration element defines the traffic to be encrypted?

A.crypto ACL
B.ISAKMP policy
C.crypto map
D.transform set
AnswerA

The crypto ACL (extended access list) defines which traffic is considered interesting and should be protected by IPsec. In this scenario, an ACL permitting IP traffic from 10.1.1.0/24 to the remote subnet would ensure that only that traffic is encrypted. The crypto map then references this ACL to match traffic that needs encryption.

Why this answer

The crypto ACL, an extended access list, is used to define interesting traffic that should be encrypted and sent through the IPsec tunnel. It specifies the source and destination subnets and protocols. The crypto map references this ACL to match packets that require IPsec protection.

Therefore, the crypto ACL is the configuration element that defines the traffic to be encrypted.

Exam trap

The trap here is confusing the role of the crypto map with the crypto ACL; the crypto map references the ACL but does not define the traffic itself.

44
MCQhard

A network administrator is deploying 802.1X on a Cisco Catalyst switch. The switch is configured as an authenticator, and a RADIUS server is used for authentication. The administrator wants to ensure that if the RADIUS server becomes unreachable, endpoints are placed into a guest VLAN with limited access. Which command must be configured on the switch to enable this behavior?

A.authentication host-mode multi-auth
B.authentication event fail action authorize vlan 100
C.authentication violation restrict
D.authentication event server dead action authorize vlan 100
AnswerD

This command, configured under interface configuration mode, instructs the switch to authorize the port into VLAN 100 when the RADIUS server is detected as dead. This provides the desired guest VLAN behavior, allowing limited access while the authentication server is unreachable.

Why this answer

To place endpoints into a guest VLAN when the RADIUS server is unreachable, the switch must be configured with the 'authentication event server dead action authorize vlan' command under the interface. This triggers the fallback VLAN assignment upon detecting the server as dead.

Exam trap

The trap here is confusing 'authentication event fail' with 'authentication event server dead'; the former handles bad credentials, while the latter handles server unavailability.

45
MCQmedium

A network administrator is configuring IPsec VPN on a Cisco IOS router. The administrator wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. The administrator has configured the crypto ACL as follows: 'access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255'. However, after applying the crypto map, the administrator notices that all traffic, including traffic to other destinations, is being dropped. What is the most likely cause?

A.The ACL 101 is also applied as an interface ACL in the outbound direction, and its implicit deny is dropping all other traffic.
B.The crypto map is applied to the wrong interface or in the wrong direction.
C.The crypto ACL is missing a deny statement for other traffic, causing all non-matching traffic to be dropped by the implicit deny at the end of the ACL.
D.The IPsec transform set is misconfigured, causing all traffic to be dropped.
AnswerA

If ACL 101 is applied as an interface ACL on the outbound interface, the implicit deny at the end will drop all traffic that does not match the permit statement. The crypto ACL itself does not drop traffic, but if it is reused as an interface ACL, it will filter traffic. This is a common misconfiguration.

Why this answer

The most likely cause is that the crypto ACL is also applied as an interface ACL, and its implicit deny is dropping all traffic that does not match the permit statement. Crypto ACLs are not meant to filter traffic; they only identify interesting traffic for encryption. If the same ACL is used for interface filtering, it will drop non-matching traffic.

Exam trap

The trap here is assuming that the crypto ACL itself causes all non-matching traffic to be dropped; in reality, crypto ACLs do not filter traffic, but if reused as an interface ACL, the implicit deny will drop traffic.

46
Multi-Selecthard

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS-XE router to protect the route processor from excessive traffic. The administrator creates a class-map to match all management traffic (SSH, SNMP, TACACS+) and a policy-map to police that traffic to 1 Mbps. After applying the service-policy to the control-plane, the administrator notices that some legitimate SNMP polling is being dropped. Which two actions can the administrator take to resolve this issue while maintaining protection against DoS attacks? (Choose two.)

Select 2 answers
A.Increase the police rate for the management class to accommodate the SNMP polling volume.
B.Remove the police action and use a bandwidth guarantee instead.
C.Apply the service-policy to the data plane interfaces instead of the control plane.
D.Enable SNMPv3 authentication to reduce the volume of SNMP traffic.
E.Configure a separate class-map for SNMP and assign a higher police rate to that class.
AnswersA, E

Increasing the policer rate allows more management traffic to pass while still enforcing a limit, providing protection against excessive traffic. This is a valid tuning step when legitimate traffic exceeds the configured rate. It maintains CoPP's protective function while reducing false positives. This action directly addresses the drops without disabling protection.

Why this answer

The legitimate SNMP polling is being dropped because the policer rate is too low for the combined management traffic. Increasing the overall rate or creating a separate class with a higher rate for SNMP will allow legitimate traffic while still policing excess. Both actions maintain protection against DoS by keeping policing in place.

Exam trap

The trap here is thinking that any change to CoPP must involve removing or disabling policing to stop drops.

47
MCQmedium

A network engineer is configuring uRPF on a Cisco IOS router. The router has two interfaces: GigabitEthernet0/0 (WAN) and GigabitEthernet0/1 (LAN). The engineer wants to prevent spoofed packets from entering the WAN interface while allowing asymmetric routing. Which uRPF mode should be configured on GigabitEthernet0/0?

A.Feasible path uRPF
B.VRF mode
C.Strict mode
D.Loose mode
AnswerD

Loose mode uRPF checks that the source address is reachable via any interface in the routing table, not necessarily the receiving interface. This allows asymmetric routing because the return path can be different. It still provides spoofing protection by ensuring the source is routable, making it the correct choice for this scenario.

Why this answer

Loose mode uRPF allows asymmetric routing because it only checks that the source address is present in the routing table, regardless of the incoming interface. Strict mode would require the source to be reachable via the same interface, which would break asymmetric routing. Therefore, loose mode is correct.

Exam trap

The trap here is assuming that strict mode is always better for spoofing prevention, but it can break legitimate asymmetric routing.

48
MCQeasy

A network engineer is configuring a Cisco IOS router to use IPsec VPN with IKEv2. The engineer wants to ensure that the router prefers a specific transform set that includes AES-256 encryption and SHA-256 hashing for integrity. Which command correctly defines the IKEv2 proposal with these parameters?

A.crypto ikev2 policy POLICY1 encryption aes-256 hash sha256 group 14
B.crypto isakmp policy 10 encryption aes 256 hash sha256 authentication pre-share group 14
C.crypto ikev2 proposal PROPOSAL1 encryption aes-cbc-256 integrity sha256 group 14
D.crypto ikev2 profile PROFILE1 encryption aes-cbc-256 integrity sha256 group 14
AnswerC

This command sequence correctly defines an IKEv2 proposal with AES-CBC-256 encryption, SHA-256 integrity, and Diffie-Hellman group 14. IKEv2 proposals are configured under crypto ikev2 proposal, and the syntax matches the required parameters. This is the correct way to specify encryption and integrity algorithms for IKEv2.

Why this answer

IKEv2 proposals define the encryption, integrity, and Diffie-Hellman group parameters. The correct command is crypto ikev2 proposal, followed by encryption aes-cbc-256, integrity sha256, and group 14. This proposal can then be referenced in an IKEv2 policy.

The other options use incorrect commands or syntax for IKEv2.

Exam trap

The trap here is confusing IKEv1 and IKEv2 configuration syntax, or misplacing algorithm definitions under a policy or profile instead of a proposal.

49
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate administrative SSH logins against an external TACACS+ server. The engineer wants to ensure that if the TACACS+ server becomes unreachable, local authentication is used as a fallback. Which configuration accomplishes this?

A.aaa authentication login default group tacacs+ local
B.aaa authentication login default group radius local
C.aaa authentication login default local group tacacs+
D.aaa authentication login default group tacacs+ none
AnswerA

This command configures the default method list to first attempt TACACS+ authentication and then fall back to the local username database if the TACACS+ server is unreachable. The 'group tacacs+' keyword specifies the TACACS+ server group, and 'local' provides the backup method. This is the correct way to ensure administrative access is not lost when the external server fails.

Why this answer

The correct command is 'aaa authentication login default group tacacs+ local'. It configures the default method list to try TACACS+ first and then the local database if the server is unreachable. This ensures administrative SSH logins are authenticated externally when possible, but local fallback maintains access during server outages.

The order of methods is critical: listing 'local' first would bypass the TACACS+ server.

Exam trap

The trap here is assuming that any fallback method is acceptable, but the order of methods in the AAA authentication command determines which is primary and which is backup.

50
MCQhard

A network administrator is deploying 802.1X on a Cisco Catalyst switch. The switch is configured as an authenticator, and the RADIUS server is reachable. However, some devices such as printers do not support 802.1X supplicant software. The administrator wants these devices to be automatically placed into a restricted VLAN with limited access. Which feature should be configured on the switch ports to achieve this?

A.MAB (MAC Authentication Bypass)
B.Critical VLAN
C.802.1X supplicant mode
D.Web Auth
AnswerA

MAB allows the switch to use the MAC address of the connecting device as the username and password for RADIUS authentication. When a device does not support 802.1X, the switch can fall back to MAB after a timeout. The RADIUS server can then assign the device to a specific VLAN based on its MAC address, such as a restricted VLAN. This is the standard method for non-802.1X devices.

Why this answer

MAC Authentication Bypass (MAB) enables the switch to authenticate devices that do not support 802.1X by using their MAC addresses as credentials. The RADIUS server can then authorize and assign a VLAN, such as a restricted VLAN, based on the MAC address. This is the correct feature to support printers and similar devices while maintaining network access control.

Exam trap

The trap here is confusing Critical VLAN with MAB; Critical VLAN is for when the RADIUS server is down, not for devices lacking supplicant support.

51
Multi-Selectmedium

A network administrator is configuring IPsec VPN on a Cisco IOS router using IKEv2. The administrator wants to ensure that the IKEv2 proposal includes encryption and integrity algorithms that are considered secure. Which two algorithms should be included in the IKEv2 proposal? (Choose two.)

Select 2 answers
A.3DES for encryption
B.SHA-256 for integrity
C.MD5 for integrity
D.DES for encryption
E.AES-CBC-256 for encryption
AnswersB, E

SHA-256 is a secure hash algorithm used for integrity protection in IKEv2. It provides strong authentication and is recommended over older algorithms like SHA-1. In Cisco IOS, it is configured using `integrity sha256` within the IKEv2 proposal. Including SHA-256 ensures that the integrity of IKEv2 messages is protected with a modern, secure algorithm.

Why this answer

For a secure IKEv2 proposal, encryption and integrity algorithms must be strong. AES-CBC-256 provides robust encryption, and SHA-256 offers secure integrity protection. These are both recommended in modern Cisco IOS configurations. 3DES and DES are weak encryption algorithms, and MD5 is an insecure integrity algorithm.

Therefore, the correct choices are AES-CBC-256 and SHA-256.

Exam trap

The trap here is selecting legacy algorithms like 3DES or MD5 due to familiarity, when they are considered insecure and not recommended for new deployments.

52
MCQhard

A network administrator is configuring a Cisco IOS router to use AAA authorization for administrative commands. The administrator wants to ensure that users are authorized for specific commands based on their user role. The TACACS+ server is configured with command authorization sets. Which AAA authorization method should the administrator configure to enforce command authorization?

A.aaa authorization auth-proxy default group tacacs+ local
B.aaa authorization network default group tacacs+ local
C.aaa authorization exec default group tacacs+ local
D.aaa authorization commands 15 default group tacacs+ local
AnswerD

This command enables authorization for commands at privilege level 15. When a user attempts to execute a command, the router sends an authorization request to the TACACS+ server, which checks the command against the configured command sets. This enforces per-command authorization based on the user's role. It is the correct method to achieve command authorization.

Why this answer

To enforce command authorization, the router must be configured to send authorization requests for each command entered by the user. The 'aaa authorization commands' command, specifying the privilege level (e.g., 15) and the method list (e.g., default) with TACACS+ as the first method, enables this functionality. The TACACS+ server must be configured with command sets that define which commands are permitted or denied.

Other authorization methods like exec, network, or auth-proxy serve different purposes and do not provide per-command authorization.

Exam trap

The trap here is confusing exec authorization, which controls session establishment and privilege level, with commands authorization, which controls individual command execution.

53
MCQmedium

A network administrator is configuring a Cisco IOS router to authenticate administrative logins using TACACS+ with a fallback to local authentication. The TACACS+ server is reachable, but the administrator wants to ensure that if the TACACS+ server becomes unreachable, local authentication is used. The router currently has the following configuration: aaa new-model aaa authentication login default group tacacs+ local tacacs server TAC1 address ipv4 10.1.1.1 key cisco What additional configuration is required to ensure that the router falls back to local authentication when the TACACS+ server does not respond?

A.Configure aaa authentication login default group tacacs+ local
B.Configure tacacs server TAC1 with the timeout 5 command
C.No additional configuration is required; the existing configuration already provides fallback to local authentication.
D.Configure aaa authentication login default group tacacs+ local-case
AnswerC

The existing AAA authentication list 'default' includes 'group tacacs+' followed by 'local'. In Cisco IOS, methods are attempted in order. If the TACACS+ servers are unreachable, the router will automatically fall back to the next method, which is local authentication. Therefore, the configuration already meets the requirement, and no further commands are needed.

Why this answer

The AAA authentication method list specifies the order of authentication methods. When 'group tacacs+' is followed by 'local', the router tries TACACS+ first. If the TACACS+ server does not respond (e.g., timeout), the router proceeds to the next method, local authentication.

Thus, the existing configuration already ensures fallback. The other options either do not enable fallback or are redundant.

Exam trap

The trap here is assuming that additional commands like 'local-case' or timeout settings are required to enable fallback, when the 'local' keyword already provides that behavior.

54
MCQeasy

A network administrator is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The administrator wants to ensure that uRPF is applied in strict mode on an interface that connects to an ISP. Which command correctly enables strict uRPF on the interface?

A.ip verify unicast source reachable-via tx
B.ip verify unicast reverse-path
C.ip verify unicast source reachable-via rx
D.ip verify unicast source reachable-via any
AnswerC

This command enables strict uRPF, which checks that the source IP address is reachable via the same interface the packet was received on. It is the correct syntax for strict mode on Cisco IOS and is suitable for ISP-facing interfaces where symmetric routing is expected.

Why this answer

Strict uRPF is enabled with the command 'ip verify unicast source reachable-via rx', which ensures the source address is reachable via the same interface the packet arrived on. This is the correct choice for an ISP-facing interface to prevent spoofed source addresses.

Exam trap

The trap here is confusing strict and loose uRPF modes: 'rx' enables strict mode, while 'any' enables loose mode.

55
MCQhard

A network engineer is implementing Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The router has two interfaces: GigabitEthernet0/0 connected to the Internet, and GigabitEthernet0/1 connected to the internal network. The engineer wants to ensure that packets coming from the Internet are dropped if their source IP address is not reachable via the same interface. However, the internal network uses asymmetric routing, so strict uRPF cannot be used on the internal interface. Which configuration should be applied to GigabitEthernet0/0 to achieve the goal?

A.ip verify unicast source reachable-via rx allow-default
B.ip verify unicast source reachable-via tx
C.ip verify unicast source reachable-via rx
D.ip verify unicast source reachable-via any
AnswerC

The 'ip verify unicast source reachable-via rx' command enables strict uRPF, which checks that the source IP address is reachable via the same interface the packet was received on. This is appropriate for the Internet-facing interface to drop spoofed packets. The internal interface would need a different mode due to asymmetric routing.

Why this answer

Strict uRPF is configured with the 'ip verify unicast source reachable-via rx' command, which verifies that the source IP address is reachable via the same interface the packet was received on. This is ideal for the Internet-facing interface to prevent spoofing. Loose mode ('any') would not meet the requirement, and the other options include modifiers or incorrect keywords.

Exam trap

The trap here is confusing strict and loose uRPF modes; strict mode uses 'rx' and checks the same interface, while loose mode uses 'any' and checks any interface.

56
MCQmedium

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 192.168.1.0/24 subnet is encrypted and sent through the tunnel, while other traffic is sent unencrypted. Which configuration element is required to define the interesting traffic?

A.transform set
B.crypto map
C.ISAKMP policy
D.access-list
AnswerD

An access list (ACL) is used to define which traffic is considered interesting and should be encrypted. For example, an ACL permitting IP traffic from 192.168.1.0/24 to the remote subnet will match that traffic for encryption. The crypto map references this ACL to determine what to protect.

Why this answer

In Cisco IOS IPsec configuration, an access list (ACL) is used to define interesting traffic that should be encrypted and sent through the VPN tunnel. The ACL specifies the source and destination subnets. The crypto map then references this ACL to apply IPsec to matching traffic.

Other components like transform set and ISAKMP policy handle encryption algorithms and key exchange, but not traffic selection.

Exam trap

The trap here is confusing the role of the crypto map with the ACL; the crypto map references the ACL but does not itself define the traffic.

57
MCQmedium

A network engineer is configuring a Cisco IOS XE router to mitigate spoofed source addresses on a WAN-facing interface using Unicast Reverse Path Forwarding. The WAN provider uses asymmetric routing, where return traffic from the provider occasionally arrives on a different interface than the one used for outbound traffic. The engineer wants to avoid dropping legitimate packets while still providing anti-spoofing protection. Which uRPF mode should the engineer configure on the WAN interface?

A.Loose mode
B.Strict mode
C.VRF-aware strict mode
D.Feasible path mode
AnswerA

Loose mode checks only that the source address is reachable via any route in the routing table, not necessarily the receiving interface. This preserves anti-spoofing protection for addresses that are completely unknown while allowing legitimate traffic that arrives over a different path than the outbound route. It is the appropriate choice when asymmetric routing exists on the WAN link.

Why this answer

Loose mode verifies that the source address exists in the routing table without requiring the packet to arrive on the same interface as the reverse route. This allows asymmetric traffic to pass while still dropping packets with completely unknown source addresses, providing useful anti-spoofing protection. Strict and feasible path modes would drop legitimate asymmetric traffic, and VRF-aware mode does not change the fundamental same-interface requirement.

Exam trap

The trap here is assuming that strict mode is always the best anti-spoofing choice, when asymmetric routing requires loose mode to avoid dropping legitimate traffic.

58
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate management users via TACACS+ against an ISE server. The engineer wants to ensure that if the TACACS+ server becomes unreachable, the router will fall back to using the local username database for authentication. The TACACS+ server is already configured with the address 10.1.1.100 and a shared secret. Which additional configuration is required on the router to achieve this fallback?

A.aaa authentication login default group tacacs+ local
B.aaa authentication login default group tacacs+ none
C.tacacs-server timeout 5
D.tacacs-server directed-request
AnswerA

This command configures the default login authentication method list to first use TACACS+ and then fall back to the local username database if the TACACS+ server is unreachable. The 'local' keyword at the end ensures that local authentication is attempted only if the TACACS+ group does not respond, which is exactly the desired behavior for failover.

Why this answer

The correct configuration is to define an AAA authentication method list that includes both TACACS+ and local. The command 'aaa authentication login default group tacacs+ local' ensures that the router first attempts authentication via TACACS+; if the server is unreachable, it then checks the local username database. This provides the required fallback and maintains security by not allowing unauthenticated access.

Exam trap

The trap here is confusing the 'none' keyword with fallback to local; 'none' means no authentication, not local database fallback.

59
Multi-Selecthard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against DoS attacks. The engineer has created a class-map to match malicious traffic and a policy-map to police it. Which two statements are true regarding the application and behavior of CoPP? (Choose two.)

Select 2 answers
A.CoPP automatically drops all traffic that exceeds the configured rate, regardless of the exceed-action specified in the policy.
B.The class-default class in a CoPP policy-map must always have a police action configured to drop all unmatched traffic.
C.CoPP uses a token bucket algorithm to enforce rate limits, where the first value is the committed information rate and the second is the burst size.
D.CoPP policies are applied to the control plane using the service-policy command under the control-plane configuration mode.
E.CoPP can be applied to a specific interface to police traffic entering that interface before it reaches the control plane.
AnswersC, D

CoPP, like other policing mechanisms, uses a token bucket algorithm. The police command specifies the committed information rate (CIR) and the burst size. The CIR is the average rate, and the burst size allows for temporary bursts above the CIR. Packets exceeding the burst are dropped or marked according to the exceed-action.

Why this answer

CoPP is applied to the control plane via the service-policy command under control-plane configuration mode, and it uses a token bucket algorithm with a committed information rate and burst size. The other statements are false: CoPP is not applied to interfaces, class-default does not require a police action, and the exceed-action determines the fate of excess traffic.

Exam trap

The trap here is assuming CoPP can be applied to interfaces or that class-default must be policed, or misunderstanding the token bucket parameters and exceed-action behavior.

60
MCQeasy

A network administrator is configuring a site-to-site VPN on a Cisco IOS router using IPsec. The administrator wants to ensure that only traffic from the 192.168.1.0/24 subnet is encrypted and sent over the VPN tunnel. Which configuration component is used to define the interesting traffic?

A.ISAKMP policy
B.transform set
C.access list
D.crypto map
AnswerC

An access list (ACL) is used to define interesting traffic for IPsec VPNs. The ACL specifies which source and destination IP addresses and protocols should be encrypted and sent through the tunnel. In this scenario, an ACL permitting traffic from 192.168.1.0/24 to the remote subnet would be referenced by the crypto map.

Why this answer

An access list is used to define interesting traffic for an IPsec VPN. It specifies the source and destination addresses and protocols that should be encrypted. The crypto map references this ACL to determine which packets to encrypt and send through the tunnel.

The transform set and ISAKMP policy define security parameters but do not select traffic.

Exam trap

The trap here is confusing the role of the crypto map with the ACL; the crypto map references the ACL but does not define the traffic itself.

61
MCQmedium

A network engineer is configuring a site-to-site IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which crypto ACL configuration achieves this?

A.access-list 100 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255 access-list 100 deny ip any any
B.access-list 100 permit ip any any
C.access-list 100 deny ip any any access-list 100 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
D.access-list 100 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
AnswerD

This ACL permits IP traffic from 10.1.1.0/24 to 10.2.2.0/24. In IPsec, the crypto ACL defines the traffic to be encrypted. By permitting only this specific traffic, all other traffic is implicitly denied and thus not encrypted, matching the requirement.

Why this answer

The correct crypto ACL is a single permit statement for the specific source and destination subnets. Because ACLs have an implicit deny at the end, all other traffic is not matched and therefore not encrypted. This precisely meets the requirement to encrypt only the specified traffic.

Exam trap

The trap here is adding an explicit deny any any or using permit any any, misunderstanding that the implicit deny already handles non-matching traffic and that permit any any would encrypt everything.

62
MCQhard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect against DoS attacks. The engineer wants to rate-limit ARP packets destined to the route processor to 1000 packets per second, with a burst of 2000 packets. Which CoPP policy configuration accomplishes this?

A.class-map match-all ARP-CLASS match protocol arp policy-map COPP-POLICY class ARP-CLASS police 1000 2000 conform-action transmit exceed-action drop control-plane service-policy input COPP-POLICY
B.class-map match-all ARP-CLASS match protocol arp policy-map COPP-POLICY class ARP-CLASS police 1000 2000 conform-action transmit exceed-action drop interface GigabitEthernet0/0 service-policy input COPP-POLICY
C.class-map match-all ARP-CLASS match access-group 101 access-list 101 permit arp any any policy-map COPP-POLICY class ARP-CLASS police 1000 2000 conform-action transmit exceed-action drop control-plane service-policy input COPP-POLICY
D.class-map match-any ARP-CLASS match protocol arp policy-map COPP-POLICY class ARP-CLASS police 1000 2000 conform-action transmit exceed-action drop control-plane service-policy output COPP-POLICY
AnswerA

This configuration correctly defines a class-map to match ARP protocol, a policy-map to police ARP traffic at 1000 pps with a burst of 2000, and applies it to the control plane using 'service-policy input' under 'control-plane' mode. This is the standard CoPP implementation to protect the route processor.

Why this answer

The correct configuration uses a class-map with 'match protocol arp', a policy-map with 'police 1000 2000', and applies the policy to the control plane with 'service-policy input COPP-POLICY'. This effectively rate-limits ARP packets destined to the route processor. The other options misapply the service policy to an interface, use an invalid access list for ARP, or apply it in the wrong direction.

Exam trap

The trap here is applying the CoPP service policy to an interface instead of the control plane, or using the wrong direction.

63
Multi-Selecthard

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive control-plane traffic. After applying the CoPP policy, the administrator notices that OSPF adjacencies are flapping and that SNMP polling from the management station is failing. The administrator wants to correct the CoPP policy without disabling protection entirely. Which two actions should the administrator take? (Choose two.)

Select 2 answers
A.Increase the rate limit or mark the OSPF and SNMP traffic as conforming in the class maps.
B.Apply the CoPP policy to all interfaces instead of the control plane.
C.Remove the CoPP policy from the control plane and rely on interface ACLs instead.
D.Verify that the class maps correctly match the OSPF and SNMP traffic using the proper access control lists or protocol keywords.
E.Disable CEF switching on the router to reduce control-plane load.
AnswersA, D

If OSPF and SNMP packets are being dropped or delayed, the policer rate for those classes is likely too low. Increasing the rate limit or adjusting the conform action to transmit allows legitimate control-plane traffic to pass while still policing other traffic. This directly addresses the flapping adjacencies and failed SNMP polls without removing CoPP protection.

Why this answer

CoPP failures for specific protocols usually stem from either incorrect classification or insufficient rate limits. Verifying that class maps match OSPF and SNMP traffic ensures they are placed in the correct class, and increasing the rate limit or adjusting the conform action for those classes allows legitimate traffic to pass. Together these correct the symptoms while preserving control-plane protection.

Exam trap

The trap here is assuming that removing CoPP or applying it elsewhere will fix protocol issues, when the real fix is correcting classification and rate limits.

64
Multi-Selectmedium

A network security engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect against denial-of-service attacks. The engineer wants to classify and police traffic destined to the route processor. Which two types of traffic should be considered for policing? (Choose two.)

Select 2 answers
A.ARP requests and replies
B.Management traffic (e.g., SSH, SNMP)
C.User data traffic transiting the router
D.IPsec encrypted traffic
E.Routing protocol updates (e.g., OSPF, EIGRP)
AnswersB, E

Management traffic such as SSH and SNMP is destined to the router itself and is essential for administration. However, it can also be exploited in DoS attacks. Policing this traffic ensures that a flood of management packets does not overwhelm the route processor, while still permitting legitimate administrative access. Therefore, it is a key consideration for CoPP.

Why this answer

CoPP is used to protect the route processor from excessive traffic that could cause high CPU utilization. The most critical types of traffic to police are those destined to the control plane, such as routing protocol updates and management traffic (SSH, SNMP, etc.). These are essential for network operation but can be exploited in DoS attacks.

Transit traffic, ARP, and IPsec data traffic are not primary control plane traffic and should be handled by other mechanisms.

Exam trap

The trap here is assuming that all traffic passing through the router should be policed by CoPP, but CoPP only applies to traffic destined to the route processor, not transit traffic.

65
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate management access using TACACS+. The TACACS+ server is reachable at 10.1.1.100. The engineer wants to ensure that if the TACACS+ server becomes unavailable, the router will fall back to using the local username database for authentication. Which command sequence correctly configures this fallback?

A.aaa authentication login default group tacacs+ local
B.aaa authentication login default group tacacs+ none
C.aaa authentication login default local group tacacs+
D.aaa authentication login default group tacacs+ enable
AnswerA

This command configures the default method list to first attempt TACACS+ authentication and then fall back to the local database if the server is unreachable. It meets the requirement by providing a backup authentication method, ensuring management access remains available even when the TACACS+ server fails.

Why this answer

The correct configuration uses the default method list with TACACS+ first and local second. This ensures that if the TACACS+ server is unreachable, the router will use the local username database for authentication, maintaining management access. The other options either use the wrong fallback method, reverse the order, or disable authentication entirely.

Exam trap

The trap here is assuming that any fallback method will work, but using 'enable' or 'none' changes the authentication behavior and does not provide local database fallback.

66
MCQmedium

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive traffic. The engineer wants to limit ICMP echo requests destined to the router to 100 packets per second, while allowing other traffic. Which configuration snippet correctly applies CoPP for this purpose?

A.class-map match-any ICMP match access-group 101 policy-map CoPP class ICMP police 100 conform-action transmit exceed-action drop interface GigabitEthernet0/0 service-policy input CoPP
B.access-list 101 permit icmp any any echo class-map match-any ICMP match access-group 101 policy-map CoPP class ICMP police 100 conform-action transmit exceed-action drop interface GigabitEthernet0/0 service-policy output CoPP
C.access-list 101 permit icmp any any echo class-map match-any ICMP match access-group 101 policy-map CoPP class ICMP police 100 conform-action transmit exceed-action drop control-plane service-policy input CoPP
D.access-list 101 permit icmp any any echo class-map match-any ICMP match access-group 101 policy-map CoPP class ICMP police 100 conform-action transmit exceed-action drop control-plane service-policy output CoPP
AnswerC

This configuration correctly defines an ACL to match ICMP echo requests, uses a class-map to reference the ACL, creates a policy-map to police the matched traffic at 100 pps, and applies the policy map to the control plane with 'service-policy input CoPP' under 'control-plane' mode. This is the proper way to implement CoPP.

Why this answer

CoPP is implemented by defining a class-map to match traffic, a policy-map to police it, and then applying the policy-map to the control plane with 'service-policy input' under the 'control-plane' configuration mode. The correct snippet uses an ACL to match ICMP echo requests, polices them at 100 pps, and applies the policy to the control plane. This protects the route processor from excessive ICMP traffic while allowing other traffic.

Exam trap

The trap here is applying the CoPP policy to an interface instead of the control plane, which would not protect the route processor.

67
MCQeasy

A network technician is configuring SSH access on a Cisco IOS router. The technician wants to ensure that only SSH version 2 is allowed and that the RSA key pair is generated with a modulus of 2048 bits. Which commands are required?

A.crypto key generate rsa general-keys modulus 2048 ip ssh version 1
B.ip ssh version 2 crypto key generate rsa modulus 4096
C.crypto key generate rsa modulus 1024 ip ssh version 2
D.crypto key generate rsa modulus 2048 ip ssh version 2
AnswerD

The 'crypto key generate rsa modulus 2048' command generates an RSA key pair with a 2048-bit modulus, which is required for SSH. The 'ip ssh version 2' command restricts SSH to version 2 only, enhancing security. Together, these commands meet the requirements. The key generation must be done before SSH can operate, and version 2 is preferred over version 1 due to vulnerabilities.

Why this answer

The correct answer generates a 2048-bit RSA key and sets SSH to version 2. This satisfies both the key size and protocol version requirements. The other options either use the wrong key size or configure SSH version 1, which is insecure.

It is important to generate the key before enabling SSH, and version 2 should be enforced for security.

Exam trap

The trap here is selecting a larger key size or forgetting to enforce SSH version 2; the requirement specifies exactly 2048 bits and version 2 only.

68
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate administrative SSH access using TACACS+ with a backup local user account. The TACACS+ server is reachable, but the engineer wants to ensure that if the TACACS+ server becomes unreachable, the router falls back to local authentication for users who are not defined on the TACACS+ server. Which AAA configuration accomplishes this?

A.aaa authentication login default group tacacs+ local
B.aaa authentication login default group tacacs+ none
C.aaa authentication login default group tacacs+ if-needed
D.aaa authentication login default group tacacs+ enable
AnswerA

The 'aaa authentication login default group tacacs+ local' command configures the default method list to try TACACS+ first, then fall back to the local username database if the TACACS+ server does not respond. This meets the requirement of using local authentication as a backup when the server is unreachable.

Why this answer

The correct configuration uses the 'group tacacs+ local' method list, which attempts TACACS+ authentication first and then falls back to the local username database if the TACACS+ server is unreachable. This ensures that administrators can still log in with locally defined credentials during a TACACS+ outage, maintaining access without compromising security.

Exam trap

The trap here is confusing the 'none' fallback method with 'local'; 'none' allows any user without authentication, while 'local' checks the local username database.

69
MCQmedium

A network administrator is configuring a Cisco IOS router for site-to-site VPN using DMVPN Phase 3. The administrator wants to ensure that spoke-to-spoke traffic flows directly between spokes without traversing the hub, and that the hub is only used for initial registration and route resolution. Which technology must be enabled on the spokes to achieve direct spoke-to-spoke communication?

A.IPsec tunnel protection on the hub only
B.NHRP redirect on the spokes and NHRP shortcut on the hub
C.NHRP redirect on the hub and NHRP shortcut on the spokes
D.OSPF broadcast network type on all spokes
AnswerC

In DMVPN Phase 3, the hub uses NHRP redirect to inform spokes of a more optimal path, and the spokes use NHRP shortcut to install a direct route to the destination spoke. This enables direct spoke-to-spoke tunnels without traversing the hub for data traffic.

Why this answer

DMVPN Phase 3 enables direct spoke-to-spoke communication through NHRP redirect on the hub and NHRP shortcut on the spokes. The hub sends NHRP redirect messages to spokes when it detects traffic that could be sent directly, and the spokes use NHRP shortcut to resolve the destination and build a direct tunnel. This reduces latency and hub load.

Exam trap

The trap here is confusing the roles of NHRP redirect and shortcut; redirect is on the hub, shortcut is on the spokes.

70
MCQeasy

A network engineer is configuring SSH access on a Cisco IOS router. The engineer wants to restrict SSH access to only the management subnet 192.168.1.0/24 and ensure that only SSH version 2 is used. Which set of commands accomplishes this?

A.ip ssh version 2 access-list 10 permit 192.168.1.0 0.0.0.255 line vty 0 4 transport input ssh access-class 10 out
B.ip ssh version 2 access-list 10 permit 192.168.1.0 0.0.0.255 line vty 0 4 transport input all access-class 10 in
C.ip ssh version 2 access-list 10 permit 192.168.1.0 0.0.0.255 line vty 0 4 transport input ssh access-class 10 in
D.ip ssh version 1 access-list 10 permit 192.168.1.0 0.0.0.255 line vty 0 4 transport input ssh access-class 10 in
AnswerC

This configuration sets SSH to version 2, creates an ACL permitting the management subnet, applies the ACL to inbound VTY lines, and restricts transport input to SSH only. This meets both requirements: restrict SSH access to the management subnet and use only SSH version 2.

Why this answer

The correct configuration must set SSH version 2, create an ACL for the management subnet, apply the ACL inbound on the VTY lines, and restrict transport input to SSH only. The other options either allow other protocols, use SSH version 1, or apply the ACL in the wrong direction.

Exam trap

The trap here is misapplying the access-class direction; it must be 'in' to filter incoming SSH connections, not 'out', and ensuring 'transport input ssh' restricts to SSH only.

71
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate management users via TACACS+ using the server at 10.1.1.100 with the shared key 'Cisco123'. The engineer wants to ensure that if the TACACS+ server becomes unreachable, the router will fall back to local authentication using the local username 'admin' with password 'AdminPass'. Which configuration correctly achieves this?

A.aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123 aaa authentication login default group tacacs+ aaa authorization exec default group tacacs+ line vty 0 4 login authentication default username admin privilege 15 secret AdminPass
B.aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123 aaa authentication login default group tacacs+ local aaa authorization exec default group tacacs+ local line vty 0 4 login authentication default username admin privilege 15 secret AdminPass
C.aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123 aaa authentication login default local group tacacs+ aaa authorization exec default local group tacacs+ line vty 0 4 login authentication default username admin privilege 15 secret AdminPass
D.aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123 aaa authentication login default group tacacs+ local aaa authorization exec default group tacacs+ local line vty 0 4 login authentication TAC1 username admin privilege 15 secret AdminPass
AnswerB

This configuration enables AAA with 'aaa new-model', defines a TACACS+ server, and sets authentication and authorization to use TACACS+ first, then local as fallback. The local username is created, and the VTY lines reference the default authentication list. This meets the requirement of falling back to local authentication if the server is unreachable.

Why this answer

The correct configuration enables AAA, defines the TACACS+ server, and configures the default authentication and authorization method lists to try TACACS+ first and then local. The VTY lines must reference the correct method list, and a local username must exist for fallback. The other options either omit fallback, reverse the order, or reference an invalid method list.

Exam trap

The trap here is confusing the TACACS+ server group name with an AAA method list name, leading to incorrect VTY line configuration.

72
MCQeasy

A network engineer is configuring AAA authorization on a Cisco IOS router. The engineer wants to limit which commands a user can execute after logging in via SSH. The user should be allowed to run show commands but not configuration commands. Which AAA authorization method should be used?

A.aaa authentication login default group tacacs+
B.aaa authorization network default group tacacs+
C.aaa authorization commands 15 default group tacacs+
D.aaa authorization exec default group tacacs+
AnswerC

Authorization for commands at privilege level 15 allows the AAA server to authorize each command the user attempts to execute at that privilege level. By configuring this, the engineer can define a command set on the TACACS+ server that permits show commands and denies configuration commands. This is the correct method to restrict specific commands.

Why this answer

AAA authorization for commands allows the network access server to consult the AAA server for each command entered by the user. By specifying privilege level 15, the engineer can restrict commands for users at that privilege level. The TACACS+ server can then be configured with a command set that permits show commands and denies configuration commands, achieving the desired restriction.

Exam trap

The trap here is confusing authentication with authorization, or thinking that exec authorization controls command execution, when actually command authorization is required to restrict specific CLI commands.

73
MCQeasy

A network technician is configuring a Cisco IOS router to use SSH for remote management. The technician generates an RSA key pair with 2048 bits, configures a local username and password, and enables SSH version 2. However, when attempting to connect via SSH, the connection is refused. Which additional configuration is required on the VTY lines to allow SSH access?

A.login local
B.transport input all
C.transport input ssh
D.exec-timeout 0 0
AnswerC

The 'transport input ssh' command on the VTY lines restricts incoming connections to SSH only, which is the secure method. If no transport input is configured, the router may not accept any remote connections, causing the SSH connection to be refused. This command explicitly enables SSH and disables Telnet, satisfying the requirement.

Why this answer

To enable SSH on a Cisco IOS router, you must generate an RSA key pair, configure a local username and password, enable SSH version 2, and apply 'transport input ssh' on the VTY lines. Without this transport command, the router may not accept SSH connections, resulting in a refused connection. The other options either enable insecure protocols or do not address the transport mechanism.

Exam trap

The trap here is assuming that generating RSA keys and enabling SSH version 2 automatically enables SSH on the VTY lines; you must explicitly allow SSH transport.

74
MCQmedium

A network engineer is configuring a Cisco IOS XE router to authenticate administrative SSH users against a TACACS+ server. The engineer wants to ensure that if the TACACS+ server is unreachable, a locally configured fallback account can still be used to log in. The engineer also wants to ensure that the fallback account is not used when the TACACS+ server is reachable but rejects the credentials. Which AAA configuration should the engineer apply?

A.aaa authentication login default group tacacs+ local
B.aaa authentication login default local group tacacs+
C.aaa authentication login default group tacacs+ none
D.aaa authentication login default group tacacs+ enable
AnswerA

This method list attempts TACACS+ first and falls back to the local database only if the TACACS+ server is unreachable. If the server is reachable and rejects the credentials, the local fallback is not tried, which matches the requirement. It is the standard way to provide a backup login method while preserving server-based authentication.

Why this answer

The method list order determines fallback behavior. Placing group tacacs+ before local ensures TACACS+ is tried first, and local is used only when the server is unreachable. If the server rejects credentials, the local method is not attempted, which satisfies both requirements.

The other options either reverse the order, allow unauthenticated access, or use the enable password, none of which meet the stated goals.

Exam trap

The trap here is thinking that local fallback is used on authentication rejection, when it is only used when the server is unreachable.

75
MCQeasy

A network administrator is configuring AAA on a Cisco IOS router. The administrator wants to use a RADIUS server for authentication and authorization, but wants to use local authentication as a fallback if the RADIUS server is unreachable. Which command should be used to configure the fallback?

A.aaa authentication login default group radius enable
B.aaa authentication login default local group radius
C.aaa authentication login default group radius none
D.aaa authentication login default group radius local
AnswerD

This command configures the default login authentication method list to use RADIUS first, then local authentication if RADIUS is unreachable. It provides the desired fallback to local authentication, ensuring administrative access is maintained even if the RADIUS server fails.

Why this answer

The command 'aaa authentication login default group radius local' sets RADIUS as the primary authentication method and local as the fallback. If the RADIUS server is unreachable, the router will use the local username database, ensuring continued administrative access.

Exam trap

The trap here is reversing the order of methods or using 'enable' or 'none' as fallback, which do not provide local authentication fallback.

Page 1 of 2 · 77 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Infrastructure Security questions.