Refer to the exhibit. R1 and R2 are configured for EIGRP peering using authentication and the neighbors failed to come up. Which action resolves the issue?
A. Configure a matching key-id number on both routers. B. Configure a matching lowest key-id on both routers. C. Configure a matching key-chain name on both routers. D. Configure a matching authentication type on both routers.
B. Configure a matching lowest key-id on both routers.
Question 253:
Which NGFW mode block flows crossing the firewall?
A. Passive B. Tap C. Inline tap D. Inline
D. Inline
Explanation
Firepower Threat Defense (FTD) provides six interface modes which are: Routed, Switched, Inline Pair, Inline Pair with Tap, Passive, Passive (ERSPAN). When Inline Pair Mode is in use, packets can be blocked since they are processed inline When you use Inline Pair mode, the packet goes mainly through the FTD Snort engine When Tap Mode is enabled, a copy of the packet is inspected and dropped internally while the actual traffic goes through FTD unmodified
A network operator is attempting to configure an IS-IS adjacency between two routers, but the adjacency cannot be established. To troubleshoot the problem, the operator collects this debugging output. Which interfaces are misconfigured on these routers?
A. The peer router interface is configured as Level 1 only, and the R2 interface is configured as Level 2 only. B. The R2 interface is configured as Level 1 only, and the Peer router interface is configured as Level 2 only. C. The R2 interface is configured as point-to-point, and the peer router interface is configured as multipoint. D. The peer router interface is configured as point-as-point, and the R2 interface is configured as multipoint.
B. The R2 interface is configured as Level 1 only, and the Peer router interface is configured as Level 2 only.
Question 255:
SIMULATION
Guidelines
This is a lab item in which tasks will be performed on virtual devices.
1. Refer to the Tasks tab to view the tasks for this lab item.
2. Refer to the Topology tab to access the device console(s) and perform the tasks.
3. Console access is available for all required devices by clicking the device icon or using the tab(s) above the console window.
4. All necessary preconfigurations have been applied.
5. Do not change the enable password or hostname for any device.
6. Save your configurations to NVRAM before moving to the next item.
7. Click Next at the bottom of the screen to submit this lab and move to the next question.
8. When Next is clicked, the lab closes and cannot be reopened.
Topology
Tasks
A. See the solution below in Explanation. B. Place Holder C. Place Holder D. Place Holder
A. See the solution below in Explanation.
Explanation
Solution:
R30
show ip access-list
config t
ip access-list extended 120
5 permit eigrp any any
R20
config t
ip access-list extended 100
permit tcp 192.168.25.0 0.0.0.255 any eq 23
class-map match-any TELNET
match access-group 100
policy-map CoPP
class TELNET
police 10000 conform-action transmit exceed-action drop control-plane
service-policy input CoPP
Question 256:
Refer to the exhibit. The key value pairs must be extracted by iterating through a list of tuples. Which statement completes the snippet and prints each key value pair as a tuple?
A. for device, value In device_ip.items(): print(device) B. for device in device_ip.items(): print(device) C. for device in device_ip.values(): print(device) D. for device in deviceip: print(device)
A. for device, value In device_ip.items(): print(device)
Question 257:
Refer to the exhibit.
An engineer tries to log in to router R1. Which configuration enables a successful login?
A. R1#aaa new-modelaaa authorization exec default localenable aaa admin privilege 15 B. R1#username admin privilege 15aaa authorization exec default localnetconf-yang C. R1#netconf-yangusername admin privilege 15 secret cisco123aaa new-modelaaa authorization exec default local D. R1#username admin privilege 15aaa authorization exec default local
C. R1#netconf-yangusername admin privilege 15 secret cisco123aaa new-modelaaa authorization exec default local
A network engineer must simplify the IPsec configuration by enabling IPsec over GRE using IPsec profiles. Which two configuration changes accomplish this? (Choose two).
A. Create an IPsec profile, associate the transform-set ACL, and apply the profile to the tunnel interface. B. Apply the crypto map to the tunnel interface and change the tunnel mode to tunnel mode ipsec ipv4. C. Remove all configuration related to crypto map from R1 and R2 and eliminate the ACL. D. Create an IPsec profile, associate the transform-set, and apply the profile to the tunnel interface. E. Remove the crypto map and modify the ACL to allow traffic between 10.10.0.0/24 to 10.20.0.0/24.
C. Remove all configuration related to crypto map from R1 and R2 and eliminate the ACL. D. Create an IPsec profile, associate the transform-set, and apply the profile to the tunnel interface.
Explanation
A is wrong, you don't use a "transform-set ACL" B is wrong. question states use IPsec profiles. Crypto maps was the old way of doing ipsec tunnels before profiles.
C is correct, need to remove crypto map config or it will cause some confusion if the tunnel profile is applied. Didn't lab it up, but book references this. D is correct, all you need to do is create a profile and associate the transform-set to this profile, then apply it to the tunnel. If no transform set was created you would have to create one. E is wrong, i believe removing crypto map would cause the traffic to flow unencrypted over the tunnel. acl in this case is to match the interesting traffic to be encrypted. it's denying it.
Question 259:
Refer to the exhibit.
After running the code in the exhibit. Which step reduces the amount of data that NETCONF server returns to the NETCONF client, to only the interface's configuration?
A. Use the txml library to parse the data returned by the NETCONF server for the interface's configuration. B. Create an XML filter as a string and pass it to get_config() method as an argument. C. Create a JSON filter as a string and pass it to the get_config() method as an argument. D. Use the JSON library to parse the data returned by the NFTCONF server for the interface's configuration.
B. Create an XML filter as a string and pass it to get_config() method as an argument.
Explanation
"using the Pythonic approach with ncclient and its get_config() method, has a filter argument where you simply specify the filter type, in this case subtree, along with the XML RPC that you want to get a configuration rpc-reply."
A technician is assisting a user who cannot connect to a website. The technician attempts to ping the default gateway and DNS server of the workstation. According to troubleshooting methodology, this is an example of:
A. a divide-and-conquer approach. B. a bottom-up approach. C. a top-to-bottom approach. D. implementing a solution.
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Cisco exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your 350-401 exam preparations
and Cisco certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.