Pass the Cisco CCDE v3.0 400-007 Questions and answers with CertsForce

Viewing page 2 out of 11 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which issue poses a challenge for security architects who want end-to-end visibility of their networks?

Options:

A.

Too many overlapping controls


B.

Too many disparate solutions and technology silos


C.

An overabundance of manual processes


D.

A network security skills shortage


Expert Solution
Questions # 12:

An architect receives a functional requirement for a NAC system from a customer security policy stating that if a corporate Wi-Fi device does not meet current AV definitions, it cannot access the network until updated. Which component should be built into the NAC design?

Options:

A.

Posture assessment with remediation VLAN


B.

Quarantine SGTs


C.

dACLs with SGTs


D.

Quarantine VLAN


Expert Solution
Questions # 13:

Which design solution reduces the amount of IGMP state in the network?

Options:

A.

IGMP filtering


B.

IGMPv3 with PIM-SSM


C.

Multiple multicast domains


D.

One multicast group address throughout network regardless of IGMP version


Expert Solution
Questions # 14:

Which two features control multicast traffic in a VLAN environment? (Choose two)

Options:

A.

IGMP snooping


B.

MLD snooping


C.

RGMP


D.

PIM snooping


E.

pruning


Expert Solution
Questions # 15:

Company XYZ is designing the IS-IS deployment strategy for their multiarea IS-IS domain. They want IS-IS neighbor relationships minimized on each segment and the LSDB size optimized. Which design can be used?

Options:

A.

Design all routers as Level 2 routers. Set the links between the routers as Level 1 with the area


B.

Design the network so that the routers connecting to other areas are Level 2 routers and internal routers are Level 1


C.

Design the network so that all routers are Level 1 routers


D.

Design the network so that the routers connecting to other areas are Level 1/Level 2 routers and internal routers are Level 1


Expert Solution
Questions # 16:

Company XYZ runs OSPF in their network. A design engineer decides to implement hot-potato routing architecture. How can this implementation be achieved?

Options:

A.

Enable iBGP and apply prepend to ensure all prefixes will have the same length of the AS path attribute value.


B.

Redistribute the external prefixes onto OSPF and ensure the total metric calculation includes only the ext value and the value is the same in all ASBRs.


C.

Enable OSPF load-balancing over unequal cost path.


D.

Redistribute the external prefixes onto OSPF and ensure that the total metric calculation includes external internal values.


Expert Solution
Questions # 17:

The administrator of a small branch office wants to implement the Layer 2 network without running STP. The office has some redundant paths. Which mechanism can the administrator use to allow redundancy without creating Layer 2 loops?

Options:

A.

Use double-sided VPC on both switches


B.

Use two port channels as Flex links


C.

Use FabricPath with ECMP


D.

Use 802.3ad link bundling


Expert Solution
Questions # 18:

Which Interconnectivity method offers the fastest convergence in the event of a unidirectional issue between three Layer 3 switches connected together with routed links in the same rack in a data center?

Options:

A.

Copper Ethernet connectivity with BFD enabled


B.

Copper Ethernet connectivity with UDLD enabled


C.

Fiber Ethernet connectivity with BFD enabled


D.

Fiber Ethernet connectivity with UDLD enabled


Expert Solution
Questions # 19:

Which effect of using ingress filtering to prevent spoofed addresses on a network design is true?

Options:

A.

It reduces the effectiveness of DDoS attacks when associated with DSCP remarking to Scavenger.


B.

It protects the network infrastructure against spoofed DDoS attacks.


C.

It classifies bogon traffic and remarks it with DSCP bulk.


D.

It filters RFC 1918 IP addresses.


Expert Solution
Questions # 20:

Question # 20

Refer to the exhibit: A customer is migrating from a TDM-based Layer 2 VPN (L2VPN) to an MPLS Layer 3 VPN (L3VPN) in phases. The backbone OSPF connection between HUB A and HUB B will be replaced by eBGP. During the migration, some spokes (A2 and B1) are already moved to the L3VPN. The goal is to avoid routing loops during this hybrid transition.

Which design choice helps prevent routing loops during the backbone link migration?

Options:

A.

Enable route filtering on OSPF backbone routers for spoke traffic


B.

Advertise low AD value for transit traffic on hub sites


C.

OSPF backbone area advertises summarized routes to hub


D.

Redistribute EIGRP 200 and 300 with low cost into BGP


Expert Solution
Viewing page 2 out of 11 pages
Viewing questions 11-20 out of questions