Free preview mode
Enjoy the free questions and consider upgrading to gain full access!
300-101
Free trial
Verified
Question 76
Refer to the exhibit. A new TAC engineer came to you for advice. A GRE over IPsec tunnel was configured, but the tunnel is not coming up.
What did the TAC engineer configure incorrectly?
- A: The crypto isakmp configuration is not correct.
- B: The crypto map configuration is not correct.
- C: The network 172.16.1.0 is not included in the OSPF process.
- D: The interface tunnel configuration is not correct.
Question 77
What two features are benefits of using GRE tunnels with IPsec over using an IPsec tunnel alone in building-to-building site-to-site VPNs? (Choose two.)
- A: Allows dynamic routing securely over the tunnel
- B: IKE keepalives are unidirectional and sent every ten seconds
- C: Reduces IPsec headers overhead since tunnel mode is used
- D: Supports non-IP traffic over the tunnel
- E: uses Virtual Tunnel Interface (VTI) to simplify the IPsec VPN configuration AD
Question 78
Which two statement about GRE tunnel interface are true? (Choose two.)
- A: A tunnel can be established when a source the source interface is in the up/down state
- B: A tunnel Destination must be Routable, but it can be unreachable
- C: To establish a tunnel the source interface must be a loopback
- D: To Establish a tunnel the source interface must be up/up state
- E: A tunnel destination must be a physical interface that is on up/up state BD
Question 79
Which two statements about EVN are true? (Choose two.)
- A: Virtual network tags are assigned per-VRF.
- B: It is supported only on access ports.
- C: Virtual network tags are assigned globally.
- D: Routing metrics can be manipulated only from directly within the routing-context configuration.
- E: The VLAN ID in the 802.1q frame carries the virtual network tag.
- F: The VLAN ID is the ISL frame carries the virtual network tag. AE
Question 80
Which three problems result from application mixing of UDP and TCP streams within a network with no QoS? (Choose three.)
- A: starvation
- B: jitter
- C: latency
- D: windowing
- E: lower throughput
Question 81
When unicast reverse path forwarding is configured on an interface, which action does the interface take first when it receives a packet?
- A: It verifies that the source has a valid CEF adjacency.
- B: It checks the egress access lists.
- C: It verifies a reverse path via the FIB to the source.
- D: It checks the ingress access lists.
Question 82
Other than a working EIGRP configuration, which components must be the same on all routers for EIGRP authentication key rollover to work correctly?
- A: SMTP
- B: time
- C: SNMP
- D: passwords B
Question 83
Which access list used to filter upper layer protocol?
- A: Extended acl
- B: Standart acl
- C: Reflexive acl
- D: Time based acl
- E: Dynamic acl A
Question 84
Which option is one way to mitigate symmetric routing on an active/active firewall setup for TCP-based connections?
- A: Performing packet captures
- B: Disabling asr-group commands on interfaces that are likely to receive asymmetric traffic
- C: Replacing them with redundant routers and allowing load balancing
- D: Disabling stateful TCP checks
Question 85
Which configuration is applied to a device so that it blocks outbound web traffic on Saturdays and Sundays between the hours of 1:00 AM and 11:59 PM?
- A: time-range SATSUN absolute Saturday Sunday 1:00 to 23:59 access-list 102 deny tcp any any eq 80 time-range SATSUN access-list 102 deny tcp any any eq 443 time-range SATSUN interface Vlan303 ip address 10.9.5.3 255.255.255.0 ip access-group 102 in
- B: time-range SATSUN periodic Saturday Sunday 1:00 to 23:59 access-list 102 deny tcp any any eq 80 time-range SATSUN access-list 102 deny tcp any any eq 443 time-range SATSUN interface VLAN303 ip address 10.9.5.3 255.255.255.0 ip access-group 102 in
- C: time-range SATSUN periodic Saturday Sunday 1:00 to 11:59 access-list 102 deny tcp any any eq 80 time-range SATSUN access-list 102 deny tcp any any eq 443 time-range SATSUN interface Vlan303 ip address 10.9.5.3 255.255.255.0 ip access-group 102 in
- D: time-range SATSUN periodic Saturday Sunday 1:00 to 23:59 access-list 102 deny udp any any eq 80 time-range SATSUN access-list 102 deny tcp any any eq 443 time-range SATSUN interface Vlan303 ip address 10.9.5.3 255.255.255.0 ip access-group 102 out
Question 86
Which two different configurations can you apply to a device to block incoming SSH access? (Choose two.)
A.
B.
C.
D.
E.
Question 87
Refer to Exhibit.
Which two reasons for IP SLA tracking failure are likely true? (Choose two.)
- A: The source-interface is configured incorrectly.
- B: The destination must be 172.30.30.2 for icmp-echo.
- C: A route back to the R1 LAN network is missing in R2.
- D: The default route has wrong next hop IP address.
- E: The threshold value is wrong. AC
Question 88
Which option is a prerequisite for stateful NAT64?
- A: IPsec for IPv6
- B: DNS64
- C: Application Layer Gateway
- D: ICMP64
That’s the end of your free questions
You’ve reached the preview limit for 300-101Consider upgrading to gain full access!
Free preview mode
Enjoy the free questions and consider upgrading to gain full access!