QA


Q&A

The questions and scenarios in this book are more difficult than what you should experience on the actual exam. The questions do not attempt to cover more breadth or depth than the exam; however, they are designed to make sure that you know the answers. Rather than allowing you to derive the answers from clues hidden inside the questions themselves, the questions challenge your understanding and recall of the subject. Hopefully, these questions will help limit the number of exam questions on which you narrow your choices to two options and then guess.

The answers to these questions can be found in Appendix A.

1.

What does the acronym AAA stand for?

2.

What external methods of authentication does a Catalyst switch support?

3.

A RADIUS server is located at IP address 192.168.199.10. What command configures a Catalyst switch to find the server?

4.

A Catalyst switch should be configured to authenticate users against RADIUS servers first, followed by TACACS+ servers. What command can define the authentication methods? Make sure users still can authenticate if none of the servers is available.

5.

What is the purpose of authorization? What happens if authorization is not used?

6.

Is it possible to use different methods to authorize users to run switch commands instead of making configuration changes?

7.

When might the command switchport port-security maximum 2 be used?

8.

After port-based authentication is configured and enabled, can any host connect as long as the user can authenticate?

9.

When the 802.1x force-authorized keyword is used, how does the switch react to users attempting to connect?

10.

Can more than one host be authenticated on a single switch port with port-based authentication?

11.

In DHCP spoofing and ARP poisoning attacks, what is the goal of the attacker? What Catalyst features can be used to mitigate the risk of these attacks?

12.

Which switch ports should be configured as trusted for DHCP snooping?

13.

What is the function of a trusted port in DAI?

14.

To inspect ARP information from a host that has received its IP address from a DHCP server, what must be enabled in addition to DAI?



CCNP Self-Study(c) CCNP BCMSN Exam Certification Guide
Red Hat Fedora 5 Unleashed
ISBN: N/A
EAN: 2147483647
Year: 2003
Pages: 177

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net