Refer to the exhibits. Exhibit 1  Exhibit 2  A network administrator applies the ACL to Switch-2, as shown in the exhibit. Device-1, IP address 10.1.10.10/24, attempts to open an HTTP session with host 192.0.2.10 on the Internet. What happens with this attempt?
-
A
Switch-2 filters both the traffic from Device-1 and the return traffic with the ACL. The return traffic is dropped.
-
B
Switch-2 filters only the traffic from Device-1 with the ACL, and the session establishes successfully.
-
C
Switch-2 does not filter any of this traffic with the ACL, and the session establishes successfully
-
D
Switch-2 filters only the return traffic from the Internet with the ACL, and the ACL drops this traffic
Reveal answer details
Close answer details
Refer to the exhibit.  Endpoints in VLAN 2 connect directly to this switch. These devices should only be able to send DHCP, DNS, HTTP, and HTTPS traffic. However, they are able to send any traffic. Based on the exhibit, what is the issue?
-
A
The ACL lacks a deny ip any any statement at the end
-
B
The switch does not have an IP address on VLAN 2
-
C
The ACL is applied in the wrong direction
-
D
The name of the ACL applied to VLAN 2 is incorrect
Reveal answer details
Close answer details
Refer to the exhibit.  Switch-2, Switch-5, and Switch-6 currently have many OSPF routes to Area 1 networks. The network administrator wants to replace these routes with a single aggregated route to 10.1.0.0/16 on each switch. Where should the administrator specify the 10.1.0.0/16 range?
-
A
in the Switch-2 OSPF Area 2 configuration
-
B
in the Switch-1 OSPF Area 0 configuration
-
C
in the Switch-1 OSPF Area 1 configuration
-
D
in the Switch-2, Switch-5, and Switch-6 OSPF global configuration
Reveal answer details
Close answer details
Refer to the exhibit.  Network administrators want the network to use PIM-DM to route multicasts from Server 1 to receivers in VLAN 24. Which protocols should the administrators enable on which VLANs on Switch-1?
-
A
PIM-DM on VLAN 24; IGMP and PIM-DM on VLAN 10
-
B
IGMP on VLAN 24; IGMP on VLAN 10
-
C
IGMP on VLAN 24; PIM-DM on VLAN 10
-
D
IGMP and PIM-DM on VLAN 24; PIM-DM on VLAN 10
-
E
IGMP and PIM-DM on VLAN 24; PIM-DM on VLAN 10
Reveal answer details
Close answer details
A network administrator configures VSF settings on two Aruba 2930F switches. The switches form two separate VSF fabrics. What should the administrator check?
-
A
that the domain ID matches on both switches
-
B
that each switch is assigned a unique VSF priority
-
C
that LLDP MAD is configured on both members
-
D
that the switch with the lower priority has the lower member ID
Reveal answer details
Close answer details
A network administrator needs to set up an AOS-Switch to use port-based tunneled node for connected devices. However, the administrator wants the switch to forward traffic without tunneling if it cannot reach a tunneled-node server. What should the administrator do?
-
A
Apply the tunneled-node profile to ports, and set the local-switching-fallback option.
-
B
Make sure that the switch has an IP address on the untagged VLAN assigned to the ports.
-
C
Configure a local switching profile on the Mobility Controller that acts as tunneled-node server.
-
D
Set the switch to role-based tunneled node, and make sure it uses the default initial user role.
Reveal answer details
Close answer details
Refer to the exhibit.  A network administrator sets up prioritization for an application that runs between Device 1 and Device 2. However, the QoS for the application is not what the administrator expects. How can the administrator check if the network infrastructure prioritizes traffic from Device 1 and Device 2?
-
A
Run a packet capture on Device 2, run the application, and look in the packet capture for a high value DSCP in the IP header.
-
B
Set up RMON alarms on the switches that trigger when a high number of packets are dropped. Then, run the application and check for the alarm.
-
C
Clear interface statistics on the switches. Then, run the application and check the interface queue statistics for the switch-to-switch links.
-
D
Run a packet capture on Device 1, run the application, and look in the packet capture for a high value DSCP in the IP header.
Reveal answer details
Close answer details
A network uses MSTP and has AOS-Switches at the access layer. The company wants edge ports on the access layer switches to meet these criteria: They prevent all rogue switches that run STP, RSTP, or MSTP from connecting to the network. If a rogue switch connects and is then replaced by a proper endpoint, the port recovers automatically without IT staff involvement. How should the network administrator set up the edge ports to meet these requirements?
-
A
Enable loop protection with a timeout period.
-
B
-
C
Enable both root guard and BPDU protection.
-
D
Enable BPDU protection with a timeout period.
Reveal answer details
Close answer details
Refer to the exhibits. Exhibit 1  Exhibit 2  Switch-1 and Switch-2 lost IP connectivity with each other. They did not detect the issue for several seconds and caused a temporary traffic disruption. The administrations expected failover to the backup route through Switch-3 to occur in less than a second. The administrators restore the failed link and view the output on Switch-1, shown in the exhibit. What should they do to create the expected behavior if connectivity is lost again?
-
A
Lower the hello timer to a given range of times on each OSPF routing switch in VLAN 100
-
B
Enable BFD in asynchronous mode on each OSPF routing switch in VLAN 100
-
C
Manually configure the network type as point-to-point on each OPSF routing switch in VLAN 100
-
D
Set a BFD echo source IP address on each OSPF routing switch in VLAN 100
Reveal answer details
Close answer details
Question 10
Single choice
A company wants to implement role-based tunneled node on AOS-Switches. Which solution should be included in the plan to help apply the roles?
-
A
a RADIUS server, such as Aruba ClearPass
-
B
an SNMP server, such as Aruba AirWave
-
C
Aruba Mobility Manager (MM)
-
D
Reveal answer details
Close answer details
Question 11
Single choice
Refer to the exhibit.  An AOS-Switch has the ACL shown in the exhibit. A network administrator then enters these commands: Switch(config)# mac-access-list standard myACL Switch(config-std-macl)# 25 deny 007d.45cc.0000 0000.0000.ffff How does this ACL treat these frames: 1 = 007d.45cc.ffff 2 = 007d.45cc.0000
-
A
-
B
-
C
It denies frame 1 and permits frame 2.
-
D
It permits frame 1 and denies frame 2.
Reveal answer details
Close answer details
Question 12
Single choice
Refer to the exhibit.  The exhibit shows configurations for interface 5 and VLAN 20. Note that DHCP snooping and ARP protection are also enabled. A network administrator finds that interface 5 on an AOS-Switch is disabled. The administrator re-enables the interface, but it shuts down again. What should the administrator investigate?
-
A
a device that sends too much unicast traffic
-
B
-
C
-
D
a device that sends unauthorized ARP messages
Reveal answer details
Close answer details
Question 13
Single choice
 A network administrator applies the ACL shown in the exhibit. Which source IP address does the myList ACL deny?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 14
Single choice
Network administrators need to inspect all traffic that arrives on an AOS-Switch in VLAN 2 and is destined to TCP ports 50000-50010. They want to send the traffic to a protocol analyzer connected to the switch for deeper inspection. What else must they create to achieve their goal?
-
A
an extended IP ACL that selects the TCP traffic, apply the ACL to interfaces VLAN 2, and specify interfaces in VLAN 2 as monitor ports
-
B
a traffic class that selects the TCP traffic, map the class to the mirror session in a policy to VLAN 2
-
C
a traffic class that selects the TCP traffic, and apply the traffic class directly to the interface that connects to the protocol analyzer
-
D
a traffic class that selects the TCP traffic, and apply the traffic class directly to the interface that connects to the protocol analyzer
-
E
an extended IP ACL that selects the TCP traffic, apply the ACL to the mirror session, and specify interfaces in VLAN 2 as monitor ports
Reveal answer details
Close answer details
Question 15
Single choice
Refer to the exhibits. Exhibit 1  Exhibit 2  A company has attempted to implement OSPF without success. The devices in Area 1 need to be able to reach Area 2. Routes should be aggregated for advertisement in other areas. What must be changed to meet these requirements?
-
A
Change Area 3 to Area 0, remove Area 1 from Switch-2 and Area 2 from Switch-1
-
B
Move the 10.1.0.0/16 range to Area 2 on Switch-1 and the 10.2.0.0/16 range to Area 1 on Switch-2
-
C
Add Area 1 and Area 2 on VLAN 100 on both Switch-1 and Switch-2. Remove Area 3
-
D
Add the 10.2.0.0/16 range on Switch-1 and the 10.1.0.0/16 range on Switch-2
Reveal answer details
Close answer details
Question 16
Single choice
What is a primary use case for RPVST+ on AOS-Switches?
-
A
more granular load balancing than MSTP when access switches connect to two core switches
-
B
enhanced loop protection in an MSTP network
-
C
integration of AOS-Switches in a heterogeneous vendor network that uses the Cisco protocol
-
D
seamless integration with RSTP
Reveal answer details
Close answer details
Question 17
Single choice
Refer to the exhibits. Exhibit 1  Exhibit 2  Network administrators are alerted to high interface utilization on a switch by a management solution. They examine the utilization on the uplink interfaces several times an hour during problem times. The exhibit shows output typical of times of congestion. The administrators want to allocate bandwidth fairly and reduce congestion on the uplinks. What could help meet these requirements?
-
A
a per-queue rate limit on interfaces 1 and 2
-
B
an outbound rate limit on each edge port
-
C
a broadcast rate limit on each edge port
-
D
an outbound rate limit on interfaces 1 and 2
Reveal answer details
Close answer details
Question 18
Single choice
Refer to the exhibit.  The network administrator enables DHCP snooping globally and on VLAN 2. An additional step is mandatory for DHCP snooping to operate correctly and for clients to receive DHCP settings. What is the additional mandatory step?
-
A
Define trk1 as a trusted DHCP port.
-
B
Define an authorized DHCP server.
-
C
-
D
Define edge ports as untrusted DHCP ports.
Reveal answer details
Close answer details
Question 19
Single choice
The security plan for AOS-Switches calls for ARP protection. For ARP protection to function properly, which other feature should also be implemented?
-
A
-
B
-
C
-
D
connection-rate filtering
Reveal answer details
Close answer details
Question 20
Single choice
Refer to the exhibit.  A network administrator wants to add the protections of root guard to the network. Based on the spanning tree topology, on which ports should the network administrator implement root guard?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 21
Single choice
Refer to the exhibit.  Endpoints in VLAN 2 connect directly to this switch. These devices should only be able to send DHCP, DNS, HTTP, and HTTPS traffic. However, they are able to send any traffic. Based on the exhibit, what is the issue?
-
A
The switch does not have an IP address on VLAN 2.
-
B
The ACL lacks a deny ip any any statement at the end.
-
C
The ACL is applied in the wrong direction.
-
D
The name of the ACL applied to VLAN 2 is incorrect.
Reveal answer details
Close answer details
Question 22
Single choice
Refer to the exhibit.  Network administrators set up PIM-DM to route multicast traffic from Server 1 to clients in VLAN 24. The multicasts are not active now, but the administrators want to determine which path the multicasts will take. What should the administrators check to help them calculate this path?
-
A
If Switch-2 or Switch-3 has the highest IP address on a VLAN that runs PIM-DM.
-
B
If Switch-2 or Switch-3 is listed as an RP in the Switch-1 RP set
-
C
What the next hop is for the unicast route that Switch-1 uses to reach 10.2.2.2
-
D
If the Switch-2 DR priority on VLAN 10 is higher than the Switch-3 DR priority on VLAN 11
Reveal answer details
Close answer details
Question 23
Single choice
Refer to the exhibits. Exhibit 1  Exhibit 2  Exhibit 1 shows the topology for the network. The network administrator sees the log entries shown in Exhibit 2. Which type of failure is indicated?
-
A
A link between Switch-1 and Switch-2 went down. BFD detected the lost connectivity and behaved as expected.
-
B
Graceful restart helper was not enabled on Switvh-2, so BFD was unable to operate correctly, and the session was taken down.
-
C
A hardware issue caused a unidirectional link; BFD detected the issue at Layer 2 and prevented a broadcast storm.
-
D
BFD was set up incorrectly on Switch-2, so it caused Switch-2 to lose adjacency with Switch-1 rather than repair the session.
Reveal answer details
Close answer details
Question 24
Single choice
A company starts to have issues with too many rules in the dynamic ACLs applied to AOS-Switch ports. Administrators decide to remove some of the common rules from the dynamic ACLs and enforce them in an ACL applied to the users' VLAN instead. What is one rule that administrators should keep in mind to ensure that the new ACLs control traffic as they expect?
-
A
ACLs applied to VLANs cannot control ICMP traffic, do the dynamic ACLs must include the ICMP rules.
-
B
Administrators should add an explicit deny at the end of the dynamic ACLs, so traffic will hit VLAN ACL.
-
C
Traffic must be permitted by both the dynamic ACL and the VLAN ACL in order to be permitted.
-
D
If a port supports multiple clients, every dynamic ACL applied to one client filters traffic for all clients.
Reveal answer details
Close answer details
Question 25
Single choice
What is a reason to implement port security on an AOS-Switch?
-
A
to simplify provisioning for devices such as IP phones or printers
-
B
to enhance the security of an 802.1X solution
-
C
to filter traffic at the edge, based on multiple criteria in the MAC header
-
D
to control management access to the switch CLI based on device, as well as user credentials
Reveal answer details
Close answer details
Correct answerB
ExplanationReferences: http://h22208.www2.hpe.com/eginfolib/networking/docs/switches/WB/15-18/5998-8152_wb_2920_asg/content/ch14s02.html
Question 26
Single choice
Refer to the exhibits. Exhibit 1.  Exhibit 2.  The exhibits show the current operational state for routes on Switch-3. The company wants Switch-3 to prefer the link to Switch-1 over the link to Switch-2 for all intra-area, inter-area, and external traffic. What can the network administrator do to achieve this goal?
-
A
Set the OSPF cost on VLAN 108 higher than 1 on Switch-2 and Switch-3.
-
B
Set the OSPF administrative distance on Switch-2 higher than 110.
-
C
Set the OSPF area type to normal on all of the switches in Area 1.
-
D
Set the cost in the OSPF Area 1 stub command higher than 1 on Switch-2.
Reveal answer details
Close answer details
|