Question No.41

A company needs to configure a new firewall and have only one public IP address to use in this firewall. The engineer need to configure the firewall with NAT to handle inbound traffic to the mail server in addition to internet outbound traffic. Which options could he use? (Choose two)


  1. Static NAT for inbound traffic on port 25

  2. Dynamic NAT for outbound traffic

  3. Static NAT for outbound traffic on port 25

  4. Dynamic NAT for inbound traffic

  5. NAT overload for outbound traffic

  6. NAT overload for inboud traffic on port 25

Correct Answer: AE

Question No.42

An engineering team must design a firewall solution with shared hardware resources but separation of features such as ACLs, NATs, and management between the external business partners of the organization. Which ASA deployment mode meets these requirements?

  1. clustering mode

  2. multicontext mode

  3. transparent mode

  4. routed mode

Correct Answer: B

Question No.43

Which option lists the EIGRP minimum timer settings for hello and dead timers in seconds?

  1. 4 and 6

  2. 2 and 4

  3. 2 and 6

  4. Both 6

Correct Answer: C

Question No.44

A network engineer wants to connect two sites via a WAN technology and to securely pass multicast traffic over this WAN technology. Which WAN technology should be configured?

  1. IPsec

  2. GRE

  3. Pure MPLS

  4. GRE over IPsec

Correct Answer: D

Question No.45

Which QoS mechanism uses PHBs?

  1. DiffServ

  2. IntServ

  3. CoS

  4. ToS

Correct Answer: A

Question No.46

You need to design a network with a summary segment that supports up to 15 IP segments and all segments must be /24?









Correct Answer: A

Question No.47

Which VPN technology supports dynamic creation of spoke-to-spoke VPN tunnels to provide a scalable design?

  1. IPsec

  2. GRE over IPsec

  3. DMVPN

  4. GRE

Correct Answer: C

Question No.48

What are two point-to-multipoint overlay tunneling strategies that are used in transitioning to IPv6 (choose two)?


  2. 6to4

  3. Nat64

  4. Dual-stack

Correct Answer: AB


https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/interface/configuration/xe-3s/ir-xe-3s-book/ip6- 6to4-tunlsxe.html

The key difference between automatic 6to4 tunnels and manually configured tunnels is that the tunnel is not point-to-point; it is point-to-multipoint.

https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/interface/configuration/xe-3s/ir-xe-3s-book/ip6- isatap-xe.html

ISATAP Point-to-multipoint tunnels that can be used to connect systems within a site.

Question No.49

Which two of these are recommended practices with trunks? (Choose two.)

  1. use ISL encapsulation

  2. use 802.1q encapsulation

  3. set ISL to desirable and auto with encapsulation negotiate to support ISL protocol negotiation

  4. use VTP server mode to support dynamic propagation of VLAN information across the network

  5. set DTP to desirable and desirable with encapsulation negotiate to support DTP protocol negotiation.

Correct Answer: BE


As a recommended practice, when configuring switch-to-switch interconnections to carry multiple VLANs,set Dynamic Trunking Protocol (DTP) to Desirable and Desirable with Encapsulation

Negotiate to support DTP negotiation.

Question No.50

Which protocol is required for end-to-end signaling in an IntServ QoS architecture?

  1. RSVP

  2. DSCP

  3. ToS

  4. LLQ

  5. DiffServ

Correct Answer: A

