Persons experienced or maybe a newcomer to the particular Cisco vocation, is required to understand what ability get them to be popular with businesses. Organisations consider methods of decide upon probable personnel that have the particular solid foundation involving ability required for effective effectiveness. Along with the Cisco business gives you when using the best exercise and diet program to get fixing this sort of 400-101 checkups.
2021 Mar 400-101 exam
Q21. Refer to the exhibit.
Which two pieces of information in this Wireshark capture indicate that you are viewing EIGRP traffic? (Choose two.)
A. the header length
B. the protocol number
C. the destination address
D. the Class Selector
E. the source address
F. the header checksum
Answer: B,C
Explanation:
EIGRP uses protocol number 88, which shows as EIGRP in the capture. Also, we in the capture that the destination IP address is 224.0.0.10, which is the Enhanced Interior Gateway Routing Protocol (EIGRP) group address is used to send routing information to all EIGRP routers on a network segment.
Q22. Refer to the exhibit.
RIPv2 authentication is failing on a device with this configuration. Which two actions can you take to enable it? (Choose two.)
A. Set the RIP authentication mode to text.
B. Set the RIP authentication mode to MD5.
C. Configure the password encryption for the key.
D. Set the password encryption to AES.
Answer: A,B
Explanation:
See the reference link below for information on configuring RIPv2 authentication, including both test and MD5 modes.
Reference: http://www.cisco.com/c/en/us/support/docs/ip/routing-information-protocol-rip/13719-50.html#configuringplain
Q23. Which field is specific to the OPSFv3 packet header, as opposed to the OSPFv2 packet header?
A. checksum
B. router ID
C. AuType
D. instance ID
Answer: D
Explanation:
In OSPFv3, Instance ID is a new field that is used to have multiple OSPF process’ instance per link. By default it is 0 and for any additional instance it is increased, instance ID has local link significance only. OSPFv3 routers will only become neighbors if the instanceIDs match. It is thus possible to have multiple routers on a broadcast domain and all run Ospfv3 but not all of them becoming neighbors.
Reference: https://supportforums.cisco.com/document/97766/comparing-ospfv3-ospfv2-routing-protocol
Q24. Refer to the exhibit.
Which three statements about the device with this configuration are true? (Choose three.)
A. Multiple AFIs are configured on the device.
B. The authentication on 172.16.129.7 is configured incorrectly.
C. The device is configured to support MPLS VPNs.
D. This device is configured with a single AFI.
E. The authentication on 172.16.129.4 is configured incorrectly.
F. The device is configured to support L2VPNs.
Answer: A,B,C
Q25. Refer to the exhibit.
You are configuring the S1 switch for the switchport connecting to the client computer. Which option describes the effect of the command mls qos map cos-dscp 0 8 16 24 32 40 46 56?
A. Voice traffic is excluded from the default priority queue.
B. Voice packets are given a class selector of 5.
C. Video conferencing is marked CS3.
D. Voice packets are processed in the priority queue.
Answer: A
Explanation:
The default CoS to DSCP mappings are shown below:
Default CoS-to-DSCP Map
CoS Value
DSCP Value
0
0
1
8
2
16
3
24
4
32
5
40
6
48
7
56
In our example, we see that COS 6 is mapped to DSCP, not the default of DSCP 48 as shown above. DSCP 46 is Expedited Forwarding (EF), which is typically used for voice traffic, and this value has not been included in this class map.
Avant-garde 400-101 exam guide:
Q26. Which two protocols are not protected in an edge router by using control plane policing? (Choose two.)
A. SMTP
B. RPC
C. SSH
D. Telnet
Answer: A,B
Explanation:
A CoPP policy can limit a number of different packet types that are forwarded to the control plane. Traffic destined for the switch CPU includes:
. Address Resolution Protocol (ARP)
. First-hop redundancy protocol packets
. Layer 2 control packets
. Management packets (telnet, Secure Shell [SSH] Protocol, Simple Network Management Protocol [SNMP]) <--- C and D are not correct.
. Multicast control packets
. Routing protocol packets
. Packets with IP options
. Packets with time to live (TTL) set to 1
. Packets that require ACL logging
. Packets that require an initial lookup (first packet in a flow: FIB miss)
. Packets that have don't support hardware switching/routing
Reference: http://www.cisco.com/c/en/us/products/collateral/switches/catalyst-6500-series-switches/white_paper_c11_553261.html
Q27. DRAG DROP
Drag and drop each STP port role on the left to the matching statement on the right.
Answer:
Q28. Which three capabilities are provided by MLD snooping? (Choose three.)
A. dynamic port learning
B. IPv6 multicast router discovery
C. user-configured ports age out automatically
D. a 5-minute aging timer
E. flooding control packets to the egress VLAN
F. a 60-second aging timer
Answer: A,B,D
Explanation:
Like IGMP snooping, MLD snooping performs multicast router discovery, with these characteristics:
. Ports configured by a user never age out.
. Dynamic port learning results from MLDv1 snooping queries and IPv6 PIMv2 packets.
. If there are multiple routers on the same Layer 2 interface, MLD snooping tracks a single multicast router on the port (the router that most recently sent a router control packet).
. Dynamic multicast router port aging is based on a default timer of 5 minutes; the multicast router is deleted from the router port list if no control packet is received on the port for 5 minutes.
. IPv6 multicast router discovery only takes place when MLD snooping is enabled on the switch.
Reference: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3750/software/release/12-2_55_se/configuration/guide/scg3750/swv6mld.pdf
Q29. Which two statements about the default router settings for SSH connections are true? (Choose two.)
A. The default timeout value for the SSH negotiation phase is 120 seconds.
B. Data is exchanged in clear text by default unless AAA authentication is enabled on the console.
C. The default number of authentication retries is 3.
D. SSH is enabled by default when you configure the username command.
Answer: A,C
Explanation:
ip ssh {timeout seconds | authentication-retries number}
Configures the SSH control parameters:
. Specify the time-out value in seconds; the default is 120 seconds. The range is 0 to 120 seconds. This parameter applies to the SSH negotiation phase. After the connection is established, the Switch uses the default time-out values of the CLI-based sessions. By default, up to five simultaneous, encrypted SSH connections for multiple CLI-based sessions over the network are available (session 0 to session 4). After the execution shell starts, the CLI-based session time-out value returns to the default of 10 minutes.
. Specify the number of times that a client can re-authenticate to the server. The default is 3; the range is 0 to 5.
Reference: http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/3se/secur ity/configuration_guide/b_sec_3se_3850_cg/b_sec_3se_3850_cg_chapter_01000.html
Q30. Refer to the exhibit.
Router R2 is learning the 192.168.1.0/24 network from R1 via EIGRP and eBGP. R2 then redistributes EIGRP into OSPF as metric-type 2 with default metrics. Which metric of the route in the R3 routing table?
A. 20
B. 30
C. 110
D. The route is not present in the R3 routing table.
Answer: D