Sunteți pe pagina 1din 3

EWAN Final Exam

1 What is the function of an intrusion detection system on a network? to restrict access to only authorized users to detect attacks against a network and send logs to a management console to prevents attack against the network and provide active defense mechanisms to detect and prevent most viruses and many Trojan horse applications from spreading in the network 2

Refer to the exhibit. A network administrator is trying to connect R1 remotely to make configuration changes. Based on the exhibited command output, what will be the result when attempting to connect to R1? failure to connect due to Telnet not being enabled failure to connect due to incomplete configuration for Telnet a successful connection and ability to make configuration changes a successful connection but inability to make configuration changes because of the absence of an enable secret password 3 A company is looking for a WAN solution to connect its headquarters site to four remote sites. What are two advantages that dedicated leased lines provide compared to a shared Frame Relay solution? (Choose two.) reduced jitter reduced costs reduced latency the ability to burst above guaranteed bandwidth the ability to borrow unused bandwidth from the leased lines of other customers 4 What is the result when the command permit tcp 10.25.132.0 0.0.0.255 any eq smtp is added to a named access control list and applied on the inbound interface of a router? TCP traffic with a destination to the 10.25.132.0/24 is permitted. Only Telnet traffic is permitted to the 10.24.132.0/24 network Ttraffic from 10.25.132.0/24 is permitted to anywhere on using any port. Traffic using port 25 from the 10.25.132.0/24 is permitted to all destinations. 5 While troubleshooting a PPP link that uses PAP authentication, a network administrator notices an incorrectly configured password in the running configuration. The administrator corrects the error by entering the command ppp pap sent-username ROUTER_NAME password NEW_PASSWORD, but the link still does not come up.

Assuming that the rest of the configuration is correct and that the link has no physical layer problems, what should the administrator do? Save the configuration to NVRAM. Shut down the interface then re-enable it. Generate traffic by pinging the remote router. Use CHAP to ensure compatibility with the remote router. 6

Refer to the exhibit. Branch A has a non-Cisco router that is using IETF encapsulation and Branch B has a Cisco router. After the commands that are shown are entered, R1 and R2 fail to establish the PVC. The R2 LMI is Cisco, and the R1 LMI is ANSI. The LMI is successfully established at both locations. Why is the PVC failing? The PVC to R1 must be point-to-point. LMI types must match on each end of a PVC. The frame relay PVCs cannot be established between Cisco and non-Cisco routers. The IETF parameter is missing from the frame-relay map ip 10.10.10.1 201 command. 7 What major benefit does Cisco HDLC provide that ISO standard HDLC lacks? flow control error control multiprotocol support cyclic redundancy checks 8.3.4 WAN Topology Considerations 8 A company has its headquarters office in Dallas and five branch offices located in New York, Chicago, Los Angeles, Seattle, and Atlanta. WAN links are used for communications among offices in six sites. In planning the WAN links, the network designer is given two requirements: (1) minimize cost and (2) provide a certain level of WAN link reliability with redundant links. Which topology should the network designer recommend? star full mesh hierarchical partial mesh 9

Refer to the exhibit. Which statement correctly describes how Router1 processes an FTP request that enters interface s0/0/0 and is destined for an FTP server at IP address 192.168.1.5? The router matches the incoming packet to the statement that was created by the access-list 201 deny icmp 192.168.1.0 0.0.0.255 any command, continues comparing the packet to the remaining statements in ACL 201 to ensure that no subsequent statements allow FTP, and then the router drops the packet. The router reaches the end of ACL 101 without matching a condition and drops the packet because there is no statement that was created by the access-list 101 permit ip any any command. The router matches the incoming packet to the statement that was created by the access-list 101 permit ip any 192.168.1.0 0.0.0.255 command and allows the packet into the router. It matches the incoming packet to the statement that was created by the access-list 201 permit ip any any command and allows the packet into the router. 10

Refer to the exhibit. The corporate network that is shown has been assigned network 172.16.128.0/19 for use at branch office LANs. If VLSM is used, what mask should be used for addressing hosts at Branch4 with minimal waste from unused addresses? /19 /20 /21 /22 /23 /24

S-ar putea să vă placă și