New Question
Which two statements about IPv6 router advertisement messages are true? (Choose two.)

A. They use ICMPv6 type 134.
B. The advertised prefix length must be 64 bits.
C. The advertised prefix length must be 48 bits.
D. They are sourced from the configured IPv6 interface address.
E. Their destination is always the link-local address of the neighboring node.

Answer: AB

New Question
Which three statements about IPv6 prefixes are true? (Choose three.)

A. FF00:/8 is used for IPv6 multicast.
B. FE80::/10 is used for link-local unicast.
C. FC00::/7 is used in private networks.
D. 2001::1/127 is used for loopback addresses.
E. FE80::/8 is used for link-local unicast.
F. FEC0::/10 is used for IPv6 broadcast.

Answer: ABC

New Question
After you configure the Loopback0 interface, which command can you enter to verify the status of the interface and determine whether fast switching is enabled?

A. Router#show ip interface loopback 0
B. Router#show run
C. Router#show interface loopback 0
D. Router#show ip interface brief

Answer: A

New Question
Which three statements about link-state routing are true? (Choose three.)

A. Routes are updated when a change in topology occurs.
B. Updates are sent to a multicast address by default.
C. OSPF is a link-state protocol.
D. Updates are sent to a broadcast address.
E. RIP is a link-state protocol.
F. It uses split horizon.

Answer: ABC

New Question
Which NAT function can map multiple inside addresses to a single outside address?


Answer: A

New Question
What is the first step in the NAT configuration process?

A. Define inside and outside interfaces.
B. Define public and private IP addresses.
C. Define IP address pools.
D. Define global and local interfaces.

Answer: A

New Question
What are two requirements for an HSRP group? (Choose two.)

A. exactly one active router
B. one or more standby routers
C. one or more backup virtual routers
D. exactly one standby active router
E. exactly one backup virtual router

Answer: AD

New Question
Which two commands can you enter to verify that a configured NetFlow data export is operational? (Choose two.)

A. show ip flow export
B. show ip cache flow
C. ip flow ingress
D. ip flow egress
E. interface ethernet 0/0
F. ip flow-export destination

Answer: AB

New Question
What are three characteristics of satellite Internet connections? (Choose three.)

A. Their upload speed is about 10 percent of their download speed.
B. They are frequently used by rural users without access to other high-speed connections.
C. They are usually at least 10 times faster than analog modem connections.
D. They are usually faster than cable and DSL connections.
E. They require a WiMax tower within 30 miles of the user location.
F. They use radio waves to communicate with cellular phone towers.

Answer: ABC

New Question
Lab Simulation Question – ACL-5
A corporation wants to add security to its network. The requirements are:
– Host C should be able to use a web browser (HTTP) to access the Finance Web Server.
– Other types of access from host C to the Finance Web Server should be blocked.
– All access from hosts in the Core or local LAN to the Finance Web Server should be blocked.
– All hosts in the Core and on local LAN should be able to access the Public Web Server.
You have been tasked to create and apply a numbered access list to a single outbound interface. This access list can contain no more than three statements that meet these requirements.
Access to the router CLI can be gained by clicking on the appropriate host.
– All passwords have been temporarily set to “cisco”.
– The Core connection uses an IP address of
– The computers in the Hosts LAN have been assigned addresses of –
– host A
– host B
– host C
– host D
– The Finance Web Server has been assigned an address of
– The Public Web Server in the Server LAN has been assigned an address of

Please see below explanation part for details answer steps:
We should create an access-list and apply it to the interface that is connected to the Server LAN because it can filter out traffic from both S2 and Core networks.
To see which interface this is, use the “show ip int brief” command:

From this, we know that the servers are located on the fa0/1 interface, so we will place our numbered access list here in the outbound direction.
Corp1#configure terminal
Our access-list needs to allow host C – to the Finance Web Server via HTTP (port 80), so our first line is this:
Corp1(config)#access-list 100 permit tcp host host eq 80
Then, our next two instructions are these:
Other types of access from host C to the Finance Web Server should be blocked.
All access from hosts in the Core or local LAN to the Finance Web Server should be blocked.
This can be accomplished with one command (which we need to do as our ACL needs to be no more than 3 lines long), blocking all other access to the finance web server:
Corp1(config)#access-list 100 deny ip any host
Our last instruction is to allow all hosts in the Core and on the local LAN access to the Public Web Server (
Corp1(config)#access-list 100 permit ip host any
Finally, apply this access-list to Fa0/1 interface (outbound direction)
Corp1(config)#interface fa0/1
Corp1(config-if)#ip access-group 100 out
Notice: We have to apply the access-list to Fa0/1 interface (not Fa0/0 interface) so that the access-list can filter traffic coming from both the LAN and the Core networks.
To verify, just click on host C to open its web browser. In the address box type to check if you are allowed to access Finance Web Server or not. If your configuration is correct then you can access it.
Click on other hosts (A, B and D) and check to make sure you can’t access Finance Web Server from these hosts. Then, repeat to make sure they can reach the public server at Finally, save the configuration
Corp1#copy running-config startup-config

New Question
Which command sets and automatically encrypts the privileged enable mode password?

A. Enable password c1sc0
B. Secret enable c1sc0
C. Password enable c1sc0
D. Enable secret c1sc0

Answer: D

New Question
The enable secret command is used to secure access to which CLI mode?

A. global configuration mode
B. privileged EXEC mode
C. user EXEC mode
D. auxiliary setup mode

Answer: B

New Question
Which action can change the order of entries in a named access list?

A. opening the access list in Notepad.
B. resequencing
C. removing an entry
D. adding an entry

Answer: B

New Question
Refer to the exhibit. What is the result of setting the no login command?

A. Telnet access is denied.
B. Telnet access requires a new password at the first login.
C. Telnet access requires a new password.
D. no password is required for telnet access.

Answer: D

New Question
Which option describes a difference between EIGRP for IPv4 and IPv6?

A. Only EIGRP for IPv6 advertises all connected networks.
B. Only EIGRP for IPv6 requires a router ID to be configured under the routing process-
C. AS numbers are configured in EIGRP but not in EIGRPv3.
D. Only EIGRP for IPv6 is enabled in the global configuration mode.

Answer: B
Router ID – Both EIGRP for IPv4 and EIGRP for IPv6 use a 32-bit number for the EIGRP router ID. The 32-bit router ID is represented in dotted-decimal notation and is commonly referred to as an IPv4 address. If the EIGRP for IPv6 router has not been configured with an IPv4 address, the eigrp router-id command must be used to configure a 32-bit router ID. The process for determining the router ID is the same for both EIGRP for IPv4 and IPv6.

New Question
What is the best way to verify that a host has a path to other hosts in different networks?

A. Ping the loopback address.
B. Ping the default gateway.
C. Ping the local interface address.
D. Ping the remote network.

Answer: D
Ping is a tool that helps to verify IP-level connectivity; PathPing is a tool that detects packet loss over multiple-hop trips. When troubleshooting, the ping command is used to send an ICMP Echo Request to a target host name or IP address. Use Ping whenever you want to verify that a host computer can send IP packets to a destination host. You can also use the Ping tool to isolate network hardware problems and incompatible configurations. If you call ipconfig /all and receive a response, there is no need to ping the loopback address and your own IP address — Ipconfig has already done so in order to generate the report.
It is best to verify that a route exists between the local computer and a network host by first using ping and the IP address of the network host to which you want to connect. The command syntax is:
ping < IP address >
Perform the following steps when using Ping:
Ping the loopback address to verify that TCP/IP is installed and configured correctly on the local computer.
If the loopback step fails, the IP stack is not responding. This might be because the TCP drivers are corrupted, the network adapter might not be working, or another service is interfering with IP.
Ping the IP address of the local computer to verify that it was added to the network correctly. Note that if the routing table is correct, this simply forwards the packet to the loopback address of
ping < IP address of local host >
Ping the IP address of the default gateway to verify that the default gateway is functioning and that you can communicate with a local host on the local network.
ping < IP address of default gateway >
Ping the IP address of a remote host to verify that you can communicate through a router.
ping < IP address of remote host >
Ping the host name of a remote host to verify that you can resolve a remote host name.
ping < Host name of remote host >
Run a PathPing analysis to a remote host to verify that the routers on the way to the destination are operating correctly.
pathping < IP address of remote host >


