Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cisco CCDE v3.0 400-007 Questions and answers with CertsForce

Viewing page 1 out of 15 pages
Viewing questions 1-10 out of questions
Questions # 1:

You were tasked to enhance the security of a network with these characteristics:

A pool of servers is accessed by numerous data centers and remote sites

The servers are accessed via a cluster of firewalls

The firewalls are configured properly and are not dropping traffic

The firewalls occasionally cause asymmetric routing of traffic within the server data center.

Which technology should you recommend to enhance security by limiting traffic that could originate from a hacker compromising a workstation and redirecting flows at the servers?

Options:

A.

Poison certain subnets by adding static routes to Null0 on the core switches connected to the pool of servers.


B.

Deploy uRPF strict mode.


C.

Limit sources of traffic that exit the server-facing interface of the firewall cluster with ACLs.


D.

Deploy uRPF loose mode.


Expert Solution
Questions # 2:

Indicate the nature of automation and orchestration tasks by dragging the tasks on the left to the corresponding category on the right in no particular order.

Question # 2


Expert Solution
Questions # 3:

An enterprise that runs numerous proprietary applications has major issues with its on-premises server estate hardware, to the point where business-critical functions are compromised. The enterprise accelerates plans to migrate services to the cloud. Which cloud service should be used if the enterprise wants to avoid hardware issues yet have control of its applications and operating system?

Options:

A.

SaaS


B.

PaaS


C.

IaaS


D.

hybrid cloud


Expert Solution
Questions # 4:

Your network operations team is deploying Access Control Lists (ACLs) across your Internet gateways. They wish to place an ACL inbound on the Internet gateway interface facing the core network (the " trusted " interface). Which IP address would the ACL need for traffic sourced from the inside interface, to match the source address of the traffic?

Options:

A.

inside global


B.

outside global


C.

inside local


D.

outside local


Expert Solution
Questions # 5:

Refer to the exhibit.

Question # 5

A customer runs OSPF with Area 5 between its aggregation router and an internal router. When a network change occurs in the backbone, Area 5 starts having connectivity issues due to the SPF algorithm recalculating an abnormal number of times in Area 5. You are tasked to redesign this network to increase resiliency on the customer network with the caveat that Router B does not support the stub area. How can you accomplish this task?

Options:

A.

Increase the bandwidth on the connection between Router A and Router B


B.

Implement LSA filtering on the ABR, allowing summary routes and preventing more specific routes into Area 5


C.

Create a virtual link to Area 0 from Router B to the ABR


D.

Turn on LSA throttling on all devices in Area 5


E.

Set Area 5 to stubby at the ABR anyway


Expert Solution
Questions # 6:

Company XYZ asks for design recommendations for Layer 2 redundancy. The company wants to prioritize fast convergence and resiliency elements. In the design, which two technologies are recommended? (Choose two.)

Options:

A.

Design MLAG/MC-LAG into the network wherever possible.


B.

Configure DHCP snooping on the switches.


C.

Use root guard.


D.

Use BPDU guard.


E.

Use UniDirectional Link Detection.


Expert Solution
Questions # 7:

Question # 7

Refer to the exhibit After a network audit a network engineer must optimize the current network convergence time The proposed solution must consider link layer and control plane failures Which solution meets the requirements?

Options:

A.

Configure denounce timers


B.

Increase fast hello timers.


C.

Implement BFD


D.

Enable LSP fast flood


Expert Solution
Questions # 8:

You are designing a large-scale DMVPN network with more than 500 spokes using EIGRP as the IGP protocol. Which design option eliminates potential tunnel down events on the spoke routers due to the holding time expiration?

Options:

A.

Increase the hold queue on the physical interface of the hub router


B.

Increase the hold queue on the tunnel interface of the spoke routers


C.

Increase the hold queue on the tunnel interface of the hub router


D.

Apply QoS for pak_priority class


E.

Increase the hold queue on the physical interface of the spoke routers


Expert Solution
Questions # 9:

Which two features control multicast traffic in a VLAN environment? (Choose two)

Options:

A.

IGMP snooping


B.

MLD snooping


C.

RGMP


D.

PIM snooping


E.

pruning


Expert Solution
Questions # 10:

How many fully established neighbour relationships exist on an Ethernet with five routers running OSPF as network type broadcast?

Options:

A.

5


B.

6


C.

7


D.

10


E.

20


Expert Solution
Viewing page 1 out of 15 pages
Viewing questions 1-10 out of questions