Cisco CCNP Semester 7 Moduel 8

Published by Steve

Dec 12, 2009
During authentication initiation, what happens if an 802.1X-enabled client does not receive an EAP-request/identity frame after three attempts to start authentication?The client continues to send EAP-request/identity frames to the switch.The client refuses any further frames.The client sends frames as if the port is in the authorized state.The client determines that the port is switched to the unauthorized state.
Which statement is true when the
spanning-tree portfast bpduguard default
global configurationcommand is configured on a Catalyst 2950 switch?The command enables BPDU Guard on UplinkFast-enabled ports.This command limits the switch ports through which the root bridge may be negotiated.Any PortFast-enabled port that no longer receives BPDUs will automatically begin forwarding frames.Any PortFast-enabled port that receives a BPDU will go into an error-disabled state.
Which two statements regarding Loop Guard are true? (Choose two.)Loop Guard and UDLD can be enabled simultaneously.Loop Guard provides no protection against STP failures that occur because the designated switch is notsending BPDUs.Loop Guard provides protection against miswiring.Loop Guard works on shared links or on links have been unidirectional since initial setup.On an EtherChannel, Loop Guard will put the entire channel in a loop-inconsistent state if any physicallink in the bundle fails.
How should unused ports on a switch be configured in order to prevent VLAN hopping attacks?Configure them with the UDLD feature.Configure them with the PAgP protocol.Configure them as trunk ports for the native VLAN.Configure them as access ports.
The command
switchport port-security violation protect
performs which function?A trap notification is sent to the network management station.The interface will shut down upon a violation and must be manually re-enabled.The interface will shut down upon a violation and will be dynamically re-enabled.Packets from unknown sources are dropped until the maximum allowable MAC addresses drops below acertain value.
Which three global configuration commands are required for configuring port-based authentication?(Choose three.) 
dot1x system-auth-control
dot1x port-control auto
aaa new-model
aaa authentication dot1x {{default}}
aaa authorization network lucy group tacacs+
aaa authentication login host local
