300-420 Sample Questions

300-420 Sample Questions & Answers

Addressing-plan and routing design for IS-IS and EIGRP ties with campus high-availability design for the top spot, alongside WAN connectivity and site-to-site VPN choices, end-to-end QoS strategy, and picking the right YANG data model.

Launch the full 300-420 simulator →

Showing 10 of 20 free samples.

  1. Question 1

    Which VLAN trunking protocol adds four bytes to the Ethernet frames?

    Show answer & explanation

    Correct answer: D

    Explanation:
    802.1Q adds 4 bytes to the Ethernet frame. The process is known as 802.1Q tagging, and inserts a four-byte field into the Ethernet frame header between the source address and the Len/Etype fields.
    This tag identifies the frame as an 802.1Q frame and includes bits used to identify both the priority and the VLAN ID. The VLAN ID field indicates which VLAN the frame belongs to. An 802.1q trunk can support 4096 different VLANs. After the new tag field is inserted into the frame, the frame's previous FCS field is recalculated and replaced. The following graphic shows both the ISL and 802.1Q frame formats as well as the original Ethernet frame: Inter switch link (ISL) is a Cisco proprietary trunking protocol that handles the frame in a different manner. It adds a 26- byte frame header and 4-byte trailer to the frame.
    LANE (LAN Emulation) is an IEEE standard for identifying VLANs on ATM networks. 802.10 is a Cisco proprietary method of identifying VLANs on FDDI media by writing VLAN information to the Security Association Identifier (SAID) of the 802.10 frame.
    Objective: Layer 2 Technologies Sub-Objective: Configure and verify trunking References: Cisco > Support > Technology Support > LAN Switching > Virtual LAN/VLAN Trunking Protocol (VLANS/VTP) > Design > Design Technotes > Inter-Switch Link and IEEE 802.1Q Frame Format

  2. Question 2

    The output displayed below is a result of what command?

    Interface Grp Fwd Pri State Address Active router
    Standby router VI10 10 - 254 Active 192.168.8.10 local unknown
    VI10 10 1 7 Active 0007.b400.0101 local -

    Show answer & explanation

    Correct answer: D

    Explanation:
    The output of the exhibit is provided with the command show glbp brief. This output includes the interface, priority, state, and address of GLBP interfaces on the switch. In this case, VLAN 10 is the active virtual gateway using IP address 192.168.8.10.
    The command show glbp displays detailed information about GLBP groups on the switch. This information includes the GLBP groups the switch is a member of, whether this is the active switch, the virtual IP address, and whether preemption is enabled.
    The command show standby brief is used to display a summary of the HSRP groups the switch is a member of. The summary information it provides includes the group number, priority, state, active device address, standby address, and group address. This command is for HSRP only.
    The command show standby can be used to display detailed information about HSRP groups a switch is a member of. This command is for HSRP only.
    Objective: Infrastructure Services Sub-Objective: Configure and verify first-hop redundancy protocols
    References: Cisco > Cisco IOS IP Application Services Command Reference > sctp through show ip sib vservers > show glbp Cisco > Cisco IOS IP Application Services Configuration Guide, Release 12.4 > Part 1: First Hop Redundancy Protocols > Configuring GLBP

  3. Question 3

    What attack technique attempts to fill a switching table so the attackers can capture traffic passing through a switch?

    Show answer & explanation

    Correct answer: D

    Explanation:
    MAC flooding is an attack technique in which frames with unique, but invalid, source MAC addresses flood the switch and exhaust the CAM table space. Eventually no more MAC addresses can be added because the table is full. When this occurs, any packets destined for a MAC address not in the table will be flooded to all other ports. This would allow the attacker to see the flooded traffic and capture information. The switch would be essentially functioning as a hub in this case.
    Two methods of mitigating these attacks are: • Implementing port security • Implementing VLAN access maps
    VLAN hopping is an attack that allows an attacker to access network resources on a different VLAN without passing through a router. The attacker can create a packet with two 802.1Q VLAN headers on it (called double tagging) and send it to a switch. The switch port will strip off the first header and leave the second. The second header will be seen as the originating VLAN, allowing the attacker access to a VLAN they are not connected to. Executing the switchport mode access command on all non-trunk ports can help prevent this attack. Pruning the native VLAN from a trunk link can also help.
    VLAN hopping is a security concern because it can be accomplished without the packet passing through a router and its security access lists. For this reason, private VLANs and VACLs should be used to secure access between VLANs. Techniques to prevent these attacks are: • Prevent automatic trunk configurations by explicitly turning off Dynamic Trunking Protocol on all unused ports • Place unused ports in a common unrouted VLAN
    MAC spoofing is an attack that allows an attacking device to receive frames intended for a different host by changing an assigned Media Access Control (MAC) address of a networked device to a different one. Changing the assigned MAC address may allow the device to bypass access control lists on servers or routers, either hiding a computer on a network or allowing it to impersonate another computer.
    A rogue device is a device attached to the network that is not under the control of the organization. This term is normally used to mean a wireless device, perhaps an access point that is not operating as a part of the company's infrastructure. Employees may bring their own access points and connect them to the network so they can use their computer wirelessly. This creates a security gap since the device is probably not secured to protect the traffic. An attacker could connect a rogue access point to a company's network and capture traffic from outside the company's premises.
    Objective: Layer 2 Technologies Sub-Objective: Configure and verify switch administration
    References: Cisco > Products and Services > Switches > Cisco Catalyst 6500 Series Switches > Product Literature > White Papers > Cisco Catalyst 6500 Series Switches > VLAN Security White Paper > MAC Flooding Attack

  4. Question 4

    In what mode does an LWAPP-enabled access point operate?

    Show answer & explanation

    Correct answer: A

    Explanation:
    Lightweight access point protocol (LWAPP)-enabled access points operate in lightweight mode. LWAPP is a protocol used to allow centralized management of APs. The management components are removed from the APs, and a WLAN controller provides a single point of management. This controller coordinates WLAN access, managing the load on the APs and user movement between APs.
    Upon starting, an LWAPP-enabled access point must obtain an IP address. It can then discover the controller using DHCP, DNS, or a subnet broadcast. When multiple wireless controllers are detected by an AP, it chooses to associate with the controller that has the fewest existing associated APs.
    Individually configured APs that operate without central management are operating in autonomous mode. This would be the opposite of lightweight mode, which is made possible by LWAPP.
    Autonomous access points can be upgraded to lightweight. If they are upgraded, they will only function in conjunction with a WLAN controller. Moreover, when an autonomous access point is upgraded to lightweight, the console port only provides read access to the unit.
    Characteristics that autonomous and lightweight access points have in common: . Both support Power over Ethernet (PoE) . Both can use a Cisco Secure Access Control server (ACS) for security
    A wireless gateway bridge (WGB) is used to connect a computer without a wireless network card to a wireless network, but not separate WLANs. The WGB can connect up to eight computers to a WLAN. The WGB connects to the root AP through a wireless interface.
    Ad hoc is a WLAN mode used for peer-to-peer connectivity. Ad hoc mode allows wireless-enabled computers to communicate with each other without having an AP involved.
    Objective: Layer 2 Technologies Sub-Objective: Configure and verify other LAN switching technologies
    References: Cisco > Support > Product Support > Wireless > Cisco Aironet 1200 Series > Reference Guides > Technical References > Upgrading Autonomous Cisco Aironet Access Points to Lightweight Mode Cisco > Support > Technology Support > Wireless/Mobility > Wireless, LAN (WLAN) > Design > Design Technotes > Cisco Wireless Devices Association Matrix

  5. Question 5Select 2

    Which PVLAN port types can send frames through a switch to community and promiscuous ports? (Choose two.)

    Show answer & explanation

    Correct answers: D, E

    In Private VLANs, community and promiscuous ports can send frames to community and promiscuous ports. Community ports within the same secondary VLAN can communicate with each other and with promiscuous ports, while promiscuous ports can communicate with all port types. Isolated ports can only communicate with promiscuous ports, and public/private are not valid PVLAN port types.

    In Private VLANs, community and promiscuous ports can send frames to community and promiscuous ports. Community ports within the same secondary VLAN can communicate with each other and with promiscuous ports, while promiscuous ports can communicate with all port types. Isolated ports can only communicate with promiscuous ports, and public/private are not valid PVLAN port types.

  6. Question 6

    How long does it take for a port to transition from the STP blocking state to the forwarding state by default?

    Show answer & explanation

    Correct answer: D

    Explanation:
    It usually takes 50 seconds for a port to transition from the blocking state to the forwarding state in STP. This delay is a function of the default settings for the forward-delay and max-age settings. The max-age delay is 20 seconds by default, and is used to transition from the blocking to the listening state. The forward-delay setting is 15 seconds by default. This timer is used in the transition from the listening to learning states, and again for the transition from the learning to the forwarding state. These timers give STP time to gather the correct information about the network topology. While they can be modified to make convergence more efficient, the default settings work for most networks. To change the timers on all switches in the VTP domain, change the timer settings on the root bridge and the changes will be forwarded to the other switches.
    To prevent switching loops, spanning tree transitions each port through several states whenever there is a change in the network topology. Each state is briefly defined as follows: . Blocking: In the blocking state, a port does not forward frames, learn information, or send information. A forwarding port is placed in the blocked state when the port senses an absence of BPDUs, which are sent in the interval defined by the hello timer (two seconds by default). If the blocked port does not detect a BPDU for the length of time defined in the max-age setting (20 seconds by default), the port will transition into the listening state. • Listening: In the listening state, a port receives traffic but does not send information. This is the first transitional state after the blocking state. No user data is forwarded at this time, but the switch is very busy. It is during this stage that the switch participates in the election of the root bridge, the designation of root ports on the non-root bridges, and the selection of designated ports on each segment. Ports that are designated or root ports will transition to the learning state after the time defined in the forward delay (15 seconds by default) has elapsed. • Learning: In the learning state, a switch port can add the MAC addresses that it has learned into its address table, but cannot forward user data. The switch port will remain in this state until the amount of time defined in the forward-delay setting has elapsed (15 seconds by default), at which time it will transition into the forwarding state. . Forwarding: In the forwarding state, a port is actively forwarding packets. It will remain in the forwarding state until it does not detect a BPDU within the defined hello time, at which time the port is placed in the blocking state and the process starts again.
    NOTE: One of the issues that can adversely affect the operation of STP is a duplex mismatch between the NICs on either end of a link between two switches. While this causes more of a performance problem than a loss of the link, the intermittent nature of the outage can cause one of the other links on the switch to transition into a forwarding state, as it may interpret this as a loss of connectivity. If one of the other links switches to forwarding and the link with the duplex mismatch comes back online (which could happen quickly), it can create a switching loop.
    Objective: Layer 2 Technologies Sub-Objective: Configure and verify spanning tree
    References: Cisco > Support > Technology Support > LAN Switching > Spanning Tree Protocol > Design > Design Technotes > Understanding and Tuning Spanning Tree Protocol Timers > Document ID: 19120 Cisco > Support > Technology Support > LAN Switching > Spanning Tree Protocol > Design > Design Technotes > Spanning Tree Protocol Problems and Related Design Considerations > Document ID: 10566

  7. Question 7

    What command displays detailed information about the GLBP groups to which the switch belongs?

    Show answer & explanation

    Correct answer: C

    Explanation:
    The command show glbp displays detailed information about GLBP groups on the switch. This information includes the GLBP groups the switch is a member of, whether this is the active switch, the virtual IP address, and whether preemption is enabled. Below is an example of the command output.
    The following can be learned from this output: • This router is the active virtual forwarder (AVF). In line 3, the output indicates the state is listen. This is the state of the active AVF. • As indicated in line 14, this router is configured with a weighting for tracking of 105. It also is configured with an upper limit of 100 and a lower limit of 90. When a tracked object goes down, the value of 105 will be reduced by the decrement value associated with that object. If this results in the weighting dropping below the lower limit (90), this router will give up its role as AVF. • The router is tracking two objects, and both have decrement values of 10. This means that ONLY if both objects go down will this router relinquish its role as AVF. As there is another router to take the role of AVF, there will be no disruption of traffic, even if hosts were using the tracked interface that went down.
    The show glbp state will only display the glbp state of the router (standby, listen etc). Detailed output is accomplished with the command show glbp.
    The command show standby can be used to display detailed information about HSRP groups to which a switch belongs. This command is for HSRP only.
    The command show standby detail provides the same output as show standby. It can be used to display detailed information about HSRP groups to which a switch belongs. This command is for HSRP only.
    Objective: Infrastructure Services Sub-Objective: Configure and verify first-hop redundancy protocols
    References: Cisco > Cisco IOS IP Application Services Configuration Guide, Release 12.4 > Part 1: First Hop Redundancy Protocols > Configuring GLBP

  8. Question 8

    With RSTP hello timers set to the default interval, how quickly can a non-edge port discover that its neighbor is down?

    Show answer & explanation

    Correct answer: C

    Explanation:
    With Rapid Spanning Tree Protocol (RSTP) hello timers set at the default interval, a non-edge port can discover that its neighbor is down in 6 seconds. One of the advantages of RSTP over STP is quicker convergence when changes occur in the topology. After a non-edge port fails to receive three Bridge Protocol Data Units (BPDUs) from its neighbor, it will assume the neighbor to be down and will age out all information regarding the neighbor. Since hellos are sent at 2-second intervals in RSTP, it will take only 6 seconds for this to occur, as compared to 20 seconds for STP.
    All other options are incorrect values for the default convergence time for RSTP.
    Objective: Layer 2 Technologies Sub-Objective: Configure and verify spanning tree
    References: Cisco > Home > Support > Technology Support > LAN Switching > Spanning Tree Protocol > Technology Information > Technology White Paper > Understanding Rapid Spanning Tree Protocol (802.1w)

  9. Question 9

    What is the first step STP performs to establish a loop-free spanning tree in a switched network?

    Show answer & explanation

    Correct answer: A

    Explanation:
    The first step taken by the Spanning-Tree Protocol (STP) is to elect a root bridge (switch). The root bridge keeps the STP database. The bridge ID is used to select the root bridge in the network. The bridge ID is a combination of the priority of the bridge (switch) and the MAC address. If two switches or bridges have the same priority value, the switch with the lowest MAC address will have the lowest priority and become the root bridge.
    Once the STP process is complete (after switches go through the learning and listening stages), STP disables redundant loops in the network.
    STP does not set a priority for each redundant link. The network administrator can manually set the priority of a switch. STP then uses the priority and the switch's MAC address to calculate the bridge ID, which is used to select the root bridge.
    STP does not first select a designated switch for each switched segment. The first goal of STP is to select a root bridge for a switched segment (VLAN).
    Objective: Layer 2 Technologies Sub-Objective: Configure and verify spanning tree
    References: Catalyst 6500 Release 12.2SXF and Rebuilds Software Configuration Guide > Configuring STP and IEEE 802.1s MST > Creating the Spanning Tree Topology Cisco > Support > Configuring Spanning Tree Protocol > How STP Works

  10. Question 10

    What protocol allows for centralized management of multiple wireless access points?

    Show answer & explanation

    Correct answer: D

    Explanation:
    Lightweight access point protocol (LWAPP) is a protocol used to allow centralized management of access points (APs). The management components are removed from the APs and centralized into a wireless LAN controller. This controller can coordinate WLAN access, managing the load on the APs and user movement between APs. A lightweight AP receives control and configuration from the WLAN controller.
    LWAPP defines the following activities: • Packet encapsulation, fragmentation, and formatting • Access point certification and software control • Access point discovery, information exchange, and configuration
    The processing of 802.11 data and the handling of management protocols and access point capabilities is distributed between the lightweight access point and the WLAN controller. For example, the AP handles the transmission of beacon frames and responses to probe request frames and the controller handles authentication. The WLC enhances:
    • Mobility • Authentication • Security management
    When lightweight APs are used, the data path from one wireless station to another includes the AP and its controller.
    Wi-Fi protected access (WPA) is an encryption and authentication protocol for wireless access. It supports 802.1x authentication and EAP on a wireless client. The AP would function as the authenticator.
    WEP is a wireless encryption protocol that uses static keys and no authentication.
    Ad hoc is a WLAN mode used for peer-to-peer connectivity. Ad hoc allows wireless-enabled computers to communicate with each other without having an AP involved.
    Objective: Layer 2 Technologies Sub-Objective: Configure and verify other LAN switching technologies
    References: Cisco > Support > Product Support > Wireless > Cisco Aironet 1200 Series > Product Literature > Solution Overviews > Cisco Unified Wireless Network Overview

Ready for the real thing?

The full 300-420 simulator has every exam-style question, timed mode, and instant scoring.