CCNA 3 Final Exam V4.0 Answers

Scaling Networks (Version 6.00) – ScaN Final Exam

1. Which security protocol or measure would provide the greatest protection for a wireless LAN?

cloaking SSIDs
shared WEP key
MAC address filtering

2Refer to the exhibit. All trunk links are operational and all VLANs are allowed on all trunk links. An ARP request is sent by computer 5. Which device or devices will receive this message?

only computer 4
computer 3 and RTR-A
computer 4 and RTR-A
computer 1, computer 2, computer 4, and RTR-A
computer 1, computer 2, computer 3, computer 4, and RTR-A
all of the computers and the router

3. Refer to the exhibit. Hosts A and B, connected to hub HB1, attempt to transmit a frame at the same time but a collision occurs. Which hosts will receive the collision jamming signal?

only hosts A and B
only hosts A, B, and C
only hosts A, B, C, and D
only hosts A, B, C, and E

4Refer to the exhibit. Router RA receives a packet with a source address of and a destination address of What will the router do with this packet?

The router will drop the packet.
The router will forward the packet out interface FastEthernet 0/1.1.
The router will forward the packet out interface FastEthernet 0/1.2.
The router will forward the packet out interface FastEthernet 0/1.3.
The router will forward the packet out interface FastEthernet 0/1.2 and interface FastEthernet 0/1.3.

5Refer to the exhibit. Which two settings show the default value of VTP configuration on a Cisco 2960 switch? (Choose two.)

revision number
existing VLANs
operating mode
domain name
pruning mode

6. Which value determines if a switch becomes the central point of reference in the spanning tree topology?

lowest bridge ID
highest revision number
lowest numeric IP address
highest numeric MAC address

7. What is the purpose of the Spanning Tree algorithm?

It propagates VLAN configurations to other switches.
It restricts broadcast packets to a single VLAN.
It segments a network into multiple broadcast domains.
It prevents loops in a switched network with redundant paths.

8. What are two benefits of the IEEE 802.11n standard over the IEEE 802.11G? (Choose two.)

requires less equipment
provides improved range
permits increased data rates
has a single-input and a single-output
needs no hardware upgrade for compatibility

9. Which configuration changes will increment the configuration revision number on the VTP server?

configuring trunk links on the VTP server
configuring or changing the VTP password
configuring or changing the VTP domain name
configuring or changing the VTP version number
configuring or deleting a VLAN or creating a VLAN name

10Refer to the exhibit. A company has acquired a new office in a campus environment. Switches in the existing office and the new office are directly connected by a trunk link. The VLANs and IP addressing are setup as shown in the exhibit. The computers in each office are not able to ping each other. What will fix the problem?

Use an access link between S2 and S3.
Connect S2 and S3 to a common router.
Set the subnet mask in the new office to /24.
Configure the new office default gateway to
Change the port assignments in the new office to a different VLAN.

11. What is a possible impact of setting too short an aging time in the MAC address table of a switch?

overly large address table
unnecessary flooding of packets
excessive timeouts of static addresses
impaired ability to dynamically learn new addresses

12Refer to the exhibit. The network administrator has just added VLAN 50 to Switch1 and Switch2. Hosts A, B, C, and D are correctly configured with IP addresses in the subnet range for VLAN 50. Host A can communicate with host B, but cannot communicate with host C or host D. What is the cause of this problem?

There is a native VLAN mismatch.
The Fa0/11 interface of Switch1 is not configured as a trunk.
The link between Switch1 and Switch2 is up but not trunked.
VLAN 50 is not allowed on the trunk link between Switch1 and Switch2.

13Refer to the exhibit. Users complain that they do not have connectivity to the web server that is connected to SW1. What should be done to remedy the problem?

Allow all VLANs on the trunk link.
Configure VLAN 100 as the native VLAN for SW1.
Configure the trunk port in trunk mode on SW1.
Attach the web server to a router and configure inter-VLAN routing.

14. What VLANs are allowed across a trunk when the range of allowed VLANs is set to the default value?

only the management VLAN
all VLANs except the extended range VLANs
all VLANs except 1 and 1002-1005
all VLANs

15Refer to the exhibit. A new host needs to be connected to VLAN 1. Which IP address should be assigned to this new host? /28 /28 /28 /28 /28

16. Using the command copy tftp:backup.cfg startup-config, an administrator downloaded a saved configuration from a TFTP server to a switch. Why does the administrator not detect any changes in the switch configuration after the download completes?

The command should have been copy startup-config tftp:backup.cfg.
A backup configuration from a TFTP server cannot be copied directly into the startup-config.
The command copy running-config startup-config should be used to save the changes on the switch.
Downloading to the startup-config requires the switch to be reloaded in order for the configuration to take effect.

17. What two methods can be used to remove MAC address table entries from a switch? (Choose two.)

Power cycle the switch to clear all dynamically learned addresses.
The clear switching-tables command will remove statically configured entries.
The clear mac-address-table command will remove statically and dynamically configured table entries.
The erase flash command will clear all statically configured table entries.
Statically configured MAC addresses will automatically be removed from the address table 300 minutes after the last activity on a switch port.

18. Which type of traffic can still be received on a switch interface that is in STP blocking mode?

BPDU frames
multicast frames
broadcast frames
Layer 3 packets

19. Which method establishes an administrative connection for configuring the Linksys WRT300N wireless access point?

Associate with the access point and then open a HyperTerminal session with the access point.
Physically connect to the access point and then reboot the computer to launch the configuration software.
From a computer in the same IP subnet as the access point, enter the default IP address of the access point in a web browser.
Modify the TCP/IP properties of the computer connected to the access point so that it exists on the same network, and then reboot your computer to establish a connection.

20Refer to the exhibit. All edge ports are configured with the spanning-tree portfast command. Host1 is recently connected to port Fa0/1 on switch SW1 . Which statement is true about the status of port Fa0/1?

The port will transition into blocking state.
The port will transition immediately into forwarding state.
The port will transition into blocking state and then immediately into forwarding state.
The port will transition into blocking state and immediately transition through the listening and learning states.

21Refer to the exhibit. What is true of the configuration of switch S1?

A Cisco proprietary protocol is in use for ports Fa0/1 and Fa0/3.
Switch ports Fa0/1 and Fa0/3 have been configured with the switchport mode access command.
Untagged frames received on ports Fa0/1 and Fa0/3 will be placed on VLAN 1.
Switch ports Fa0/1 and Fa0/3 are configured to carry data from multiple VLANs.

22Refer to the exhibit. The configuration steps that are listed in the exhibit have been entered in switch S1 via the console. Subsequent attempts to telnet to the switch are not successful. What is causing the problem?

The switch must be configured with SSH version 1.
The transport input command must specify Telnet access.
The RSA keys must be returned to zero before SSH will permit Telnet access.
The ip domain-name command must also be entered in line configuration mode for the vty lines.

23Refer to the exhibit. Which switch will be elected as the root bridge of the spanning tree topology?


24Refer to the exhibit. VTP has been configured with VTP pruning enabled on all switches. If HostA sends a broadcast frame to SW1, which devices will receive the frame?

SW1, SW3, HostF
SW1, HostB, HostC
SW1, SW2, SW3, SW4, HostF
SW1, SW2, SW3, SW4, all hosts

25Refer to the exhibit. Which two statements are true about the operation of the interfaces? (Choose two.)

Incoming traffic with VLAN ID 0 is processed by interface fa0/0.
Incoming traffic that has a VLAN ID of 2 is processed by subinterface fa0/0.2.
Both subinterfaces remain up with line protocol up, even if fa0/0 line protocol is down.
Subinterfaces use unique MAC addresses by adding the 802.1Q VLAN ID to the hardware address.
Traffic inbound on this router is processed by different subinterfaces, depending on the VLAN from which the traffic originated.

26. The network administrator wants to configure a switch to pass VLAN update information to other switches in the domain but not update its own local VLAN database. Which two steps should the administrator perform to achieve this? (Choose two.)

Reset the VTP counters.
Configure VTP version 1 on the switch.
Configure the VTP mode of the switch to transparent.
Verify that the switch has a higher configuration revision number.
Configure the switch with the same VTP domain name as other switches in the network.

27Refer to the exhibit. The devices in the network are operational and configured as indicated in the exhibit. However, hosts B and D cannot ping each other. What is the most likely cause of this problem?

The link between the switches is up but not trunked.
The Fa0/11 interface of Switch1 is not configured as a trunk.
Hosts B and D are configured with IP addresses from different subnets.
VLAN 20 and VLAN 30 are not allowed on the trunk between the switches.

28Refer to the exhibit. Users A and B are reporting intermittent connectivity problems. Pre-installation surveys showed strong signal strength from the AP locations to the client locations. Outside electrical interference has been eliminated. What will fix the problem?

Relocate the APs closer to each other.
Increase the distance between the clients.
Change the channel on AP-B to 6 or 11.
Place AP-A and AP-B on the same wireless channel.

29. Why is it advisable that a network administrator use SSH instead of Telnet when managing switches?

SSH uses TCP whereas Telnet does not.
SSH encrypts only the username and password when logging in.
SSH encrypts all remote management communications whereas Telnet does not.
SSH sends a clear text message steam which reduces the bandwidth use for management.

30Refer to the exhibit. The teacher host is connected to port Fa0/7 on switch STW. A student has decided to share access to the Internet by attaching a hub and laptop to STW as shown. What will be the result of the student making this connection?

The Fa0/7 port of STW will be shutdown.
The student will gain full access to the Internet.
Both the teacher and student will be able to receive data but only the teacher will be able to send.
The frames from the laptop will be dropped, but the teacher host will maintain connectivity with the network.

31. A network administrator configures a switch port with the command switchport mode dynamic auto. What is the resulting behavior of the switch port?

The switch port is able to trunk if the remote switch port is set to auto.
The switch port is able to trunk if the remote switch port is set to desirable.
The switch port will be disabled if it is unable to successfully negotiate trunking.
A successful trunk will be established if the remote switch is non-Cisco but the port is configured for trunking.

32. Which STP port type can only appear once on a segment, and must be present in order for traffic to flow on that segment?

non-root port
disabled port
designated port
non-designated port

33Refer to the exhibit. What would happen if the network administrator moved the network cable of Host A from interface Fa0/1 to Fa0/3 on switch SW1?

Host A remains a member of VLAN 10, because the router is routing traffic between VLANs.
Host A is no longer a member of VLAN 10, because port Fa0/3 has been manually assigned to VLAN 30.
Host A remains a member of VLAN 10, because the switch provides dynamic VLAN assignment for the port.
Host A maintains connectivity to all members of VLAN 10, because it is connected to the same physical network.
Host A is no longer a member of VLAN 10, but because port Fa0/3 was unused, it is now a member of VLAN 1.

34Refer to the exhibit. VLAN 10 has been configured on the VTP server. Users who are assigned to VLAN 10 are connected as shown in the exhibit. On the basis of the outputs that are provided, which group of users will be able to communicate with the users on VLAN 10 on SW1?

all the users who are connected only to SW2
users on VLAN 10 who are connected only to SW3
users on VLAN 10 who are connected only to SW4
users on VLAN 10 who are connected to both SW3 and SW4

35Refer to the exhibit. Which three options correctly identify information that could be associated with this output?(Choose three.)

Interface FastEthernet3/0/0 is subinterfaced.
A non-proprietary trunking protocol is in use.
The configuration is appropriate for a router-on-a-stick network design.
A shutdown command has been applied to interface FastEthernet3/0/0.
Interface FastEthernet3/0/0.3 is mapped to the default management VLAN.
An IP address should be applied to FastEthernet3/0/0 for correct data routing.

36Refer to the exhibit. The Layer 2 switching design that is shown has been implemented in a campus environment that is using Spanning Tree Protocol. All inter-switch links that are shown are trunks. Whenever an inter-switch link fails, the network takes nearly a minute to completely converge. How can the convergence time be reduced?

Increase the capacity of the distribution and core trunk links to 10 Gb/s.
Add a trunk link that directly connects D1 and D2.
Use Layer 3 switching on the core switch.
Implement Rapid Spanning Tree Protocol.

37Refer to the exhibit. Each switch is configured to participate in STP for VLANs 1, 10, 20, and 30. Which switch will become the root for VLAN 20?


38Refer to the exhibit. Switches S2 and S3 are properly connected using an ethernet cable. A network administrator has configured both switches with VTP, but S3 is unable to propagate VLANs to S2. What could be the reason for this?

The VTP configuration revision is different on both switches.
The VTP domains are different on both switches.
VTP pruning is disabled.
VTP v2 is disabled.

39. In a three-layer hierarchical network design, which distribution layer function delineates broadcast domains?

routing between VLANs
aggregating traffic flows
providing redundant links
reducing the network diameter

40. Which parameter is used to uniquely identify one wireless network from another?


41. What is one disadvantage that 802.11a wireless has compared to 802.11g?

Use of the 5GHz band requires much larger antennas.
The OFDM modulation technique results in a slower data rate.
There are fewer non-overlapping channels available to help reduce RF interference.
The use of higher frequencies means that signals are more likely to be obstructed.

42. Which three statements are correct concerning the default configuration of a new switch? (Choose three.)

It is configured in VTP server mode.
STP is automatically enabled.
The first VTY line is automatically configured to allow remote connections.
VLAN1 is configured with a management IP address.
All switch ports are assigned to VLAN1.
The enable password is configured as cisco.

43Refer to the exhibit. How is port Gi1/1 on SWT-A functioning in the spanning-tree topology?

It is sending and receiving data frames.
It is receiving BPDUs, but not sending data frames.
It is participating in the election process by forwarding the BPDUs it receives.
It is receiving BPDUs and populating the MAC address table, but not sending data.

44. While configuring a new switch, a network administrator configures the switch as an HTTP server. What benefits does this configuration provide?

This allows the switch to host web pages for the network.
This allows remote VPN connections to the switch over the Internet.
This is required if a web server or web farm is attached to the switch.
This allows web-based configuration tools to be used with the switch.

45. Which statement describes the use of voice VLANs in Cisco IP telephony?

The voice VLAN carries both tagged and untagged traffic.
The voice VLAN carries untagged traffic having special QoS markings.
The voice VLAN must be configured on the switch port to which the IP phone attaches.
Data and voice frames are tagged with same VLAN ID between the IP phone and the switch when a voice VLAN is configured.

46Refer to the exhibit. If switch SW1 is configured with the four VLANs as shown in the exhibit, how many physical interfaces are needed on router R1 to configure inter-VLAN routing using subinterfaces?


47Refer to the exhibit. What does the term DYNAMIC indicate in the output that is shown?

This entry can only be removed from the MAC address table by a network administrator.
When forwarding a frame to the device with address 0060.5c5b.cd23, the switch does not have to perform a lookup to determine the final destination port.
Only the device with MAC address 0060.5c5b.cd23 will be allowed to connect to port Fa0/18.
The switch learned this MAC address from the source address in a frame received on Fa0/18.

48Refer to the exhibit. The VTP domain has been configured as shown in the exhibit. The network technician accidentally configured the VTP server as a VTP client. After the technician reloaded the switches, all users in the VTP domain started to complain that they lost connectivity to the users on the same VLANs that are connected to other switches. What should be done in the future to prevent losing all VLAN configurations in a VTP domain?

Configure all switches in VTP transparent mode and copy the VLAN configuration into flash.
Configure all switches in the network as VTP clients and copy the VLAN configuration into NVRAM.
Create a new domain and configure a second switch as a VTP server to take over in case of a primary VTP server failure.
In the same domain, configure a second switch as a VTP server to take over in case of a primary VTP server failure.

49Refer to the exhibit. How does SW1 manage traffic coming from Host A?

SW1 drops the traffic because it is untagged.
SW1 leaves the traffic untagged and forwards it over the trunk.
SW1 tags the traffic with the lowest VLAN ID value and forwards it over the trunk link.
SW1 encapsulates the traffic with 802.1Q encapsulation and forwards it over the trunk link.

50. An administrator is troubleshooting a PC on the network which is suffering from slow and intermittent connectivity. The PC has a ping success rate to the default gateway of less than half the ping attempts. Other PCs on the switch can consistently ping the default gateway. The switch port is configured for auto duplex and the PC is configured for full duplex. What will commonly cause this problem?

The PC is set to full duplex. The switch port fails to autonegotiate the duplex setting and defaults to half duplex, which causes a duplex mismatch.
The switch traffic is exceeding available frame buffers. The result is that frames are being dropped.
The PC and the default gateway have different bandwidth Ethernet ports.
The default gateway is not on the same switch that the PC is.

51Refer to the exhibit. A network administrator has segmented the network into two VLANs and configured Router1 for inter-VLAN routing. A test of the network, however, shows that hosts on each VLAN can only access local resources and not resources on the other VLAN. What is the most likely cause of this problem?

Switch port Fa0/1 is not trunking.
Router interface Fa0/0 is possibly down.
No routing protocol is configured on Router1.
One of the router subinterfaces is possibly down.

52. What impact does the use of the mdix auto configuration command have on an Ethernet interface on a switch?

automatically detects duplex settings
automatically detects interface speed
automatically detects copper cable type
automatically assigns the first detected MAC address to an interface

————-New questions update 2011—————————–

53. Refer to the exhibit. A network administrator needs to add IP phones to the network. To which devices should the IP phones connect?

  • AS1 and AS2
  • DS1 and DS2
  • DS1, DS2, and CS1
  • AS1, AS2, DS1, and DS2

54. Which CLI mode allows users to access all device commands, such as those used for configuration, management, and troubleshooting?

user EXEC mode
privileged EXEC mode
global configuration mode
interface configuration mode

55. Refer to the exhibit. All hosts are in listen mode. Host 1 and Host 4 both transmit data at the same time. How do the hosts respond on the network? (Choose two.)

After the end of the jam signal, a backoff algorithm is invoked.
Hosts 1 and 4 are operating full duplex so no collision will exist.
The hub will block the port connected to Host 4 to prevent a collision.
Hosts 1 and 4 are assigned shorter backoff values to provide them priority to access the media.
If a host has data to transmit after the backoff period of that host, the host checks to determine if the line is idle before transmitting.

56. Refer to the exhibit. An administrator documented the output of a CAM table from an Ethernet switch as shown. What action will the switch take when it receives the frame shown at the bottom of the exhibit?

discard the frame
forward the frame out port 2
forward the frame out port 3
forward the frame out all ports
forward the frame out all ports except port 3
add station 00-00-3D-1F-11-05 to port 2 in the forwarding table

57What will be the effect of the command S1# copy system:running-config

The IOS will be copied to the TFTP server.
The configuration file named tokyo-config will overwrite the startup configuration file on S1.
The running configuration file on S1 will be saved via TFTP to a file named tokyo-config.
The contents of NVRAM on S1 will become the startup configuration file on the tokyo switch.

58. Company policy requires disabling the command history buffer on network devices. An administrator enters terminal no history size at the command prompt on a Cisco Catalyst switch and receives no error messages back, but the command history buffer is still available. What is the problem?

The command contained a syntax error.
The Cisco IOS version does not support disabling the command history buffer.
The command history can only be disabled on a router, not a switch.
The size parameter reset the default buffer size but did not disable access to the buffer.

59A network administrator is implementing VTP in a large campus LAN that contains one hundred switches. What are valid considerations for reliability and administration?

Using server mode on a single master switch and client mode on all other switches will provide the most fault tolerance for retaining VLAN information in all switches if power is lost on the network.
Using transparent mode on all switches will allow for efficient administration and prevent VLAN data loss from the loss of any single switch.
Configuring several switches in server mode will allow all VLANs to be entered from a single switch and preserve VLAN data if any of the switches or connections are lost.
Configuring one primary and one backup switch in server mode and all other switches in transparent mode will provide fault tolerance for the VLAN data and allow for efficient distribution of the VLAN configurations to all switches.

60. Refer to the exhibit. Switch SW-A is to be used as a temporary replacement for another switch in the VTP Student domain. What two pieces of information are indicated from the exhibited output? (Choose two.)

The other switches in the domain can be running either VTP version 1 or 2.
There is a risk that the switch may cause incorrect VLAN information to be sent through the domain.
VTP will block frame forwarding on at least one redundant trunk port that is configured on this switch.
VLAN configuration changes made on this switch will be sent to other devices in the VTP domain.
This switch will update its VLAN configuration when VLAN changes are made on a VTP server in the same domain.

61. What is the purpose of issuing the command switchport mode access on a switch interface?

disable port security
make the port operational
override the default port behavior
force the port to be a part of a single vlan

62. Refer to the exhibit. What happens when a frame from a source MAC address different from 00a8.d2e4.ba27 reaches switch port 0/5?

The frame is dropped.
The port is shut down.
An error message is displayed.
FastEthernet port 0/5 will show an err-disabled messag

63Refer to the exhibit. What will be the result of the commands that are shown in the exhibit?

Only clients on VLAN 2 will be able to use DHCP for addressing.
DHCP server responses will only be permitted on interface Fa0/2.
Only 100 clients are permitted to request DHCP addresses on VLAN 2.
Client requests for DHCP addresses will be filtered out if the requests are not received on interface Fa0/2.

64Why is it important that the network administrator consider the spanning-tree network diameter when choosing the root bridge?

The network diameter limitation is 9.
BPDUs may be discarded because of expiring timers.
The cabling distance between the switches is 100 meters.
The network diameter must be set to the number of meters of the cable between the root bridge and its farthest connected switch.

65. Refer to the exhibit. What is the result of issuing these commands?

The enable password will be set.
The password will be set for the first Telnet connection.
The password will be set for the console connection.
The password will be set for the auxiliary connection.

Add Comment