网友您好, 请在下方输入框内输入要搜索的题目:

题目内容 (请给出正确答案)
多选题
Which three statements about the DHCP snooping feature on Cisco Nexus switches are true? ()
A

DHCP snooping commands are not available until the feature is enabled with the feature dhcp- snooping command.

B

When you enable the DHCP snooping feature, the switch begins building and maintaining the DHCP snooping binding database.

C

The switch will not validate DHCP messages received or use the DHCP snooping binding database to validate subsequent requests from untrusted hosts until DHCP snooping is enabled globally and for each specific VLAN.

D

Globally disabling DHCP snooping removes all DHCP snooping configuration on the switch.

E

Globally disabling DHCP snooping does not remove any DHCP snooping configuration or the configuration of other features that are dependent upon the DHCP snooping feature.


参考答案

参考解析
解析: 暂无解析
更多 “多选题Which three statements about the DHCP snooping feature on Cisco Nexus switches are true? ()ADHCP snooping commands are not available until the feature is enabled with the feature dhcp- snooping command.BWhen you enable the DHCP snooping feature, the switch begins building and maintaining the DHCP snooping binding database.CThe switch will not validate DHCP messages received or use the DHCP snooping binding database to validate subsequent requests from untrusted hosts until DHCP snooping is enabled globally and for each specific VLAN.DGlobally disabling DHCP snooping removes all DHCP snooping configuration on the switch.EGlobally disabling DHCP snooping does not remove any DHCP snooping configuration or the configuration of other features that are dependent upon the DHCP snooping feature.” 相关考题
考题 As a network administrator, you issue the interface auto qos voip cisco-phone command on a port in an edge network. It is possible for a Cisco Catalyst switch to check if a Cisco IP Phone is directly attached to that port by:()A. using DHCP snoopingB. snooping the incoming 802.1Q VLAN tagC. using CDPD. snooping the CoS marking on the incoming frames

考题 Which two statements are true about Internet Group Management Protocol (IGMP) snooping?() A. IGMP snooping and Cisco Group Membership Protocol (CGMP) can be used simultaneously on a switch.B. IGMP snooping a nd Cisco Group Membership Protocol (CGMP) were developed to help Layer 3 switches make intelligent forwarding decisions on their own.C. IGMP snooping examines IGMP join/leave messages so that multicast traffic is forwarded only to hosts that sent an IG MP message toward the router.D. IGMP snooping is an IP multicast constraining mechanism for Layer 2 switches.E. IGMP snooping is enabled with the ip multicast - routing global configuration command.

考题 DHCP Snooping是一种DHCP的安全特性,关于DHCP Snooping的说法,以下正确的是()。 A.DHCP Snooping绑定表分为动态绑定表和静态绑定表B.DHCP Snooping区分信任端口和非信任端口,对非信任端口,不处理DHCP Reply报文C.静态绑定表在报文入端口手工输入,也可以手工设置表项老化时间D.在二层上应用DHCP Snooping时,不配置Option82功能也可以获得绑定表所需的接口信息

考题 The Cisco AutoQoS feature is being used throughout the Company VOIP network.  Which three  statements about this feature are true?()A、The "mls qos" global configuration command must be entered before configuring AutoQoS.B、CEF must be enabled.C、The "no auto qos voip" command is used to disable Cisco AutoQos and revoke all  configurations generated by Cisco AutoQos.D、CDP must be enabled.E、SNMP must be enabled.

考题 As the network technician at Company, you need to configure DHCP snooping on a new switch.   Which three steps are required? ()A、 Configure the switch to insert and remove DHCP relay information (option-82 field) in forwarded  DHCP request messages.B、 Configure DHCP snooping globally.C、 Configure the switch as a DHCP server.D、 Configure DHCP snooping on an interface.E、 Configure all interfaces as DHCP snooping trusted interfaces.F、 Configure DHCP snooping on a VLAN or range of VLANs.

考题 Nexus# sh ip igmp snooping vlan 120   IGMP Snooping information for vlan 120   IGMP snooping disabled   Optimised Multicast Flood (OMF) disabled   IGMP querier none  Switch-querier enabled, address 1.1.1.1, currently not running  IGMPv3 Explicit tracking enabled  IGMPv2 Fast leave disabled  IGMPv1/v2 Report suppression enabled  IGMPv3 Report suppression disabled  Link Local Groups suppression enabled  Router port detection using PIM Hellos, IGMP Queries  Number of router-ports: 0  Number of groups: 0   Active ports: Po100 Po111  Which statement best describes what is depicted in the show command output?()A、 IGMP snooping is not active for VLAN 120 because the IGMP feature has not been enabled on the switch with the feature igmp command.B、 The IGMP snooping querier for VLAN 120 is not in a running state because the Loopback interface configured with 1.1.1.1/32 is currently in a down state.C、 IGMP snooping has been disabled on the VLAN 120 SVI.D、 IGMP snooping has been disabled for VLAN 120 in VLAN configuration mode.E、 IGMP snooping is not active for VLAN 120 because VLAN 120 does not exist in the VLAN database.

考题 Which three statements best describe multicast operation on Cisco Nexus switches in a data center?()A、 Cisco NX-OS Software does not support PIM dense mode.B、 The command ip multicast-routing must be enabled in Cisco NX-OS Software before any multicast configuration is possible on the switch.C、 PIM CLI configuration and verification commands are not available until you enable the PIM feature with the feature pim command.D、 Cisco NX-OS Software supports multicast routing per Layer 3 VRF instance.E、 The default PIM operational mode on the Cisco Nexus 7000 switch is SSM.

考题 The Company is concerned about Layer 2 security threats.  Which statement is true about these  threats? ()A、 MAC spoofing attacks allow an attacking device to receive frames intended for a different  network host.B、 Port scanners are the most effective defense against dynamic ARP inspection.C、 MAC spoofing, in conjunction with ARP snooping, is the most effective counter-measure against reconnaissance attacks that use dynamic ARP inspection (DAI) to determine vulnerable  attack points.D、 Dynamic ARP inspection in conjunction with ARP spoofing can be used to counter DHCP  snooping attacks.E、 DHCP snooping sends unauthorized replies to DHCP queries.F、 ARP spoofing can be used to redirect traffic to counter dynamic ARP inspection.G、 None of the other alternatives apply.

考题 Which statement best describes what is depicted in the show command output?()A、 IGMP snooping is not active for VLAN 120 because the IGMP feature has not been enabled on the switch with the feature igmp command.B、 The IGMP snooping querier for VLAN 120 is not in a running state because the Loopback interface configured with 1.1.1.1/32 is currently in a down state.C、 IGMP snooping has been disabled on the VLAN 120 SVI.D、 IGMP snooping has been disabled for VLAN 120 in VLAN configuration mode.E、 IGMP snooping is not active for VLAN 120 because VLAN 120 does not exist in the VLAN database.

考题 he Cisco Nexus 1000V Series Switches are virtual machine access switches that are an intelligent software switch implementation for VMware vSphere environments running the Cisco NX-OS Software operating system. Together with the VMware ESX hypervisor, the Nexus 1000V supports Cisco VN-Link server virtualization technology, which provides mobile virtual machine security and network policy for VMware View components, including the DHCP snooping feature. DHCP snooping is disabled on the Nexus 1000V by default. When the DHCP snooping feature is enabled on the Nexus 1000V, what are the default trust settings for the vEthernet and uplink ports?() A、 All vEthernet ports are trusted, and all Ethernet ports such as uplinks and port channels are trusted.B、 All vEthernet ports are not trusted, and all Ethernet ports such as uplinks and port channels are not trusted.C、 All vEthernet ports are trusted and all Ethernet ports such as uplinks and port channels are not trusted.D、 All vEthernet ports are not trusted and all Ethernet ports such as uplinks and port channels are trusted.

考题 Which two statements are true about Internet Group Management Protocol (IGMP) snooping?()A、IGMP snooping and Cisco Group Membership Protocol (CGMP) can be used simultaneously on a switch.B、IGMP snooping a nd Cisco Group Membership Protocol (CGMP) were developed to help Layer 3 switches make intelligent forwarding decisions on their own.C、IGMP snooping examines IGMP join/leave messages so that multicast traffic is forwarded only to hosts that sent an IG MP message toward the router.D、IGMP snooping is an IP multicast constraining mechanism for Layer 2 switches.E、IGMP snooping is enabled with the ip multicast - routing global configuration command.

考题 As a network administrator, you issue the interface auto qos voip cisco-phone command on a port in an edge network. It is possible for a Cisco Catalyst switch to check if a Cisco IP Phone is directly attached to that port by:()A、using DHCP snoopingB、snooping the incoming 802.1Q VLAN tagC、using CDPD、snooping the CoS marking on the incoming frames

考题 Which three statements are true about DAI?()A、DAI intercept all ARP packets on untrusted portsB、DAI determines the validity of an ARP packet based on the valid MAC address-to-IP address bindings stored in the DHCP Snooping database.C、DAI is used to prevent against a DHCP Snooping attack.D、DAI forwards all ARP packets received on a trusted interface without any checks.E、DAI forwards all ARP packets on untrusted ports.F、DAI determines the validity of an ARP packet based on the valid MAC address-to-IP address bindings stored in the CAM table.

考题 In the event that two devices need access to a common server, but they cannot communicate witheach other, which security feature should be configured to mitigate attacks between thesedevices?()A、private VLANsB、port securityC、BPDU guardD、dynamic ARP inspectionE、DHCP snooping

考题 Which three statements about the DHCP snooping feature on Cisco Nexus switches are true? ()A、 DHCP snooping commands are not available until the feature is enabled with the feature dhcp- snooping command.B、 When you enable the DHCP snooping feature, the switch begins building and maintaining the DHCP snooping binding database.C、 The switch will not validate DHCP messages received or use the DHCP snooping binding database to validate subsequent requests from untrusted hosts until DHCP snooping is enabled globally and for each specific VLAN.D、 Globally disabling DHCP snooping removes all DHCP snooping configuration on the switch.E、 Globally disabling DHCP snooping does not remove any DHCP snooping configuration or the configuration of other features that are dependent upon the DHCP snooping feature.

考题 DHCP snooping on Cisco Nexus 1000V Series Switches acts like a firewall between untrusted hosts and trusted DHCP servers by doing which of these? ()A、 validates DHCP messages received from untrusted sources and filters out invalid response messages from DHCP serversB、 intercepts all ARP requests and responses on untrusted portsC、 builds and maintains the DHCP snooping binding database, which contains information about untrusted hosts with leased IP addressesD、 uses the DHCP snooping binding database to validate subsequent requests from untrusted hostsE、 limits IP traffic on an interface to only those sources that have an IP-MAC address binding table entry or static IP source entry

考题 多选题As the network technician at Company, you need to configure DHCP snooping on a new switch.   Which three steps are required? ()AConfigure the switch to insert and remove DHCP relay information (option-82 field) in forwarded  DHCP request messages.BConfigure DHCP snooping globally.CConfigure the switch as a DHCP server.DConfigure DHCP snooping on an interface.EConfigure all interfaces as DHCP snooping trusted interfaces.FConfigure DHCP snooping on a VLAN or range of VLANs.

考题 多选题DHCP Snooping是一种DHCP的安全特性,关于DHCP Snooping的说法,以下正确的是()。ADHCP Snooping绑定表分为动态绑定表和静态绑定表BDHCP Snooping区分信任端口和非信任端口,对非信任端口,不处理DHCP Reply报文C静态绑定表在报文入端口手工输入,也可以手工设置表项老化时间D在二层上应用DHCP Snooping时,不配置Option82功能也可以获得绑定表所需的接口信息

考题 单选题In the event that two devices need access to a common server, but they cannot communicate witheach other, which security feature should be configured to mitigate attacks between thesedevices?()A private VLANsB port securityC BPDU guardD dynamic ARP inspectionE DHCP snooping

考题 单选题DHCP Snooping是一种DHCP的安全特性,关于DHCP Snooping的说法,下列描述错误的是()A DHCP Snooping绑定表分为动态绑定表和静态绑定表B DHCP Snooping区分信任端口和非信任端口,对非信任端口,不处理DHCPReply报文C 静态绑定表在报文入端口手工输入,也可以手工设置表项老化时间D 在二层上应用DHCP Snooping,不配置Option82功能也可以获得绑定表所需的接门信息

考题 多选题DHCP snooping on Cisco Nexus 1000V Series Switches acts like a firewall between untrusted hosts and trusted DHCP servers by doing which of these? ()Avalidates DHCP messages received from untrusted sources and filters out invalid response messages from DHCP serversBintercepts all ARP requests and responses on untrusted portsCbuilds and maintains the DHCP snooping binding database, which contains information about untrusted hosts with leased IP addressesDuses the DHCP snooping binding database to validate subsequent requests from untrusted hostsElimits IP traffic on an interface to only those sources that have an IP-MAC address binding table entry or static IP source entry

考题 多选题Which three statements are true about DAI?()ADAI intercept all ARP packets on untrusted portsBDAI determines the validity of an ARP packet based on the valid MAC address-to-IP address bindings stored in the DHCP Snooping database.CDAI is used to prevent against a DHCP Snooping attack.DDAI forwards all ARP packets received on a trusted interface without any checks.EDAI forwards all ARP packets on untrusted ports.FDAI determines the validity of an ARP packet based on the valid MAC address-to-IP address bindings stored in the CAM table.

考题 多选题Which two statements are true about Internet Group Management Protocol (IGMP) snooping?()AIGMP snooping and Cisco Group Membership Protocol (CGMP) can be used simultaneously on a switch.BIGMP snooping a nd Cisco Group Membership Protocol (CGMP) were developed to help Layer 3 switches make intelligent forwarding decisions on their own.CIGMP snooping examines IGMP join/leave messages so that multicast traffic is forwarded only to hosts that sent an IG MP message toward the router.DIGMP snooping is an IP multicast constraining mechanism for Layer 2 switches.EIGMP snooping is enabled with the ip multicast - routing global configuration command.

考题 多选题The Cisco AutoQoS feature is being used throughout the Company VOIP network.  Which three  statements about this feature are true?()AThe mls qos global configuration command must be entered before configuring AutoQoS.BCEF must be enabled.CThe no auto qos voip command is used to disable Cisco AutoQos and revoke all  configurations generated by Cisco AutoQos.DCDP must be enabled.ESNMP must be enabled.

考题 多选题Which three statements best describe multicast operation on Cisco Nexus switches in a data center?()ACisco NX-OS Software does not support PIM dense mode.BThe command ip multicast-routing must be enabled in Cisco NX-OS Software before any multicast configuration is possible on the switch.CPIM CLI configuration and verification commands are not available until you enable the PIM feature with the feature pim command.DCisco NX-OS Software supports multicast routing per Layer 3 VRF instance.EThe default PIM operational mode on the Cisco Nexus 7000 switch is SSM.

考题 单选题Nexus# sh ip igmp snooping vlan 120   IGMP Snooping information for vlan 120   IGMP snooping disabled   Optimised Multicast Flood (OMF) disabled   IGMP querier none  Switch-querier enabled, address 1.1.1.1, currently not running  IGMPv3 Explicit tracking enabled  IGMPv2 Fast leave disabled  IGMPv1/v2 Report suppression enabled  IGMPv3 Report suppression disabled  Link Local Groups suppression enabled  Router port detection using PIM Hellos, IGMP Queries  Number of router-ports: 0  Number of groups: 0   Active ports: Po100 Po111  Which statement best describes what is depicted in the show command output?()A  IGMP snooping is not active for VLAN 120 because the IGMP feature has not been enabled on the switch with the feature igmp command.B  The IGMP snooping querier for VLAN 120 is not in a running state because the Loopback interface configured with 1.1.1.1/32 is currently in a down state.C  IGMP snooping has been disabled on the VLAN 120 SVI.D  IGMP snooping has been disabled for VLAN 120 in VLAN configuration mode.E  IGMP snooping is not active for VLAN 120 because VLAN 120 does not exist in the VLAN database.

考题 单选题Which statement best describes what is depicted in the show command output?()A  IGMP snooping is not active for VLAN 120 because the IGMP feature has not been enabled on the switch with the feature igmp command.B  The IGMP snooping querier for VLAN 120 is not in a running state because the Loopback interface configured with 1.1.1.1/32 is currently in a down state.C  IGMP snooping has been disabled on the VLAN 120 SVI.D  IGMP snooping has been disabled for VLAN 120 in VLAN configuration mode.E  IGMP snooping is not active for VLAN 120 because VLAN 120 does not exist in the VLAN database.