CCNA(200-120)803题库V2.0(2014.10.08)-实验题

上传人:jiups****uk12 文档编号:41940276 上传时间:2018-05-31 格式:DOCX 页数:48 大小:2.08MB
返回 下载 相关 举报
CCNA(200-120)803题库V2.0(2014.10.08)-实验题_第1页
第1页 / 共48页
CCNA(200-120)803题库V2.0(2014.10.08)-实验题_第2页
第2页 / 共48页
CCNA(200-120)803题库V2.0(2014.10.08)-实验题_第3页
第3页 / 共48页
CCNA(200-120)803题库V2.0(2014.10.08)-实验题_第4页
第4页 / 共48页
CCNA(200-120)803题库V2.0(2014.10.08)-实验题_第5页
第5页 / 共48页
点击查看更多>>
资源描述

《CCNA(200-120)803题库V2.0(2014.10.08)-实验题》由会员分享,可在线阅读,更多相关《CCNA(200-120)803题库V2.0(2014.10.08)-实验题(48页珍藏版)》请在金锄头文库上搜索。

1、 1 / 481. EIGRPQuestion: After adding BLD-102 router, no routing updates are being exchanged between BLD-102 and the new location. All other inter connectivity and Internet access for the existing locations of the company are working properly. The task is to identify the fault(s) and correct the rou

2、ter configuration to provide full connectivity between the routers. Access to the router CLI can be gained by clicking on the appropriate host. All passwords on all routers are cisco. IP addresses are listed in the chart below.答案:EIGRP 实验题是一道排错题,通过 show run 找出拓扑中四台路由器 EIGRP 的配置错误改正做到内网全通即可,错误有两种类型,一

3、是网段宣告错误,二是 AS号错误。2 / 483 / 48注意:在 Cisco Packet Tracer 模拟器中可以双击路由器进入命令界面,在考试中需要点路由器 console(虚线)链接的 PC 进入命令界面,比如上图需要点 PC-D来进入 BLD-102 的命令界面。其他实验题也是如此。BLD-102enable (需要输入密码:cisco) BLD-102#show run(命令显示不全,需要多按几次空格键)(AS 号错误,需要删掉整个 eigrp,再重新宣告)BLD-102#configure terminal(可以简写为 conf t) BLD-102(config)#no ro

4、uter eigrp 22 BLD-102(config)#router eigrp 212 BLD-102(config-router)#network 192.168.22.0 BLD-102(config-router)#network 192.168.60.0 BLD-102(config-router)#no auto-summary(不要忘记关闭自动汇总) BLD-102(config-router)#end BLD-102#copy running-config startup-config (最后不要忘记保存,可以使用简写 copy run start,考试不支持 write)

5、Campusenable (需要输入密码:cisco) Campus#configure terminal Campus#show run(命令显示不全,需要多按几次空格键)4 / 485 / 48(宣告网段错误,路由中多了一个 192.168.22.0 的网段,却少了一个 192.168.60.0 的 网段) Campus(config)#router eigrp 212 Campus(config-router)#no network 192.168.22.0 Campus(config-router)#network 192.168.60.0 Campus(config-router)#

6、end Campus#copy running-config startup-config (不要忘记保存配置)此路由器有 passive-interface S1/0 的配置,这里没有错误,不用处理2 ACL-1An administrator is trying to ping and telnet from Switch to Router with the results shown below: Switch Switch ping 10.4.4.3 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 10

7、.4.4.3,timeout is 2 seconds: .U.U.U Success rate is 0 percent (0/5) Switch Switch telnet 10.4.4.3 Trying 10.4.4.3 % Destination unreachable; gateway or host down Switch Click the console connected to Router and issue the appropriate commands to answer the questions.6 / 487 / 48注意:此题对应的 PTK 文件,因为部分命令

8、模拟器不支持,所以配置和题库不一样,条目不够,路由器配置以 PDF 题库为准。Router enable (需要输入密码:cisco) Router# show running-config(命令显示不全,多按几次空格键即可)文件,因为部分命令模拟器不支持,所以配置和题库不一样,PKT 中中 ACL 条目8 / 489 / 4810 / 4811 / 4812 / 4813 / 48Question 1:Which will fix the issue and allow ONLY ping to work while keeping telnet disabled?ACorrectlyass

9、ignanIPaddresstointerfacefa0/1BChangetheipaccess-groupcommandonfa0/0from“in”to“out”C Remove access-group 106 in from interface fa0/0 and add access-group 115 in.D Remove access-group 102 out from interface s0/0/0 and add access-group 114 inE Remove access-group 106 in from interface fa0/0 and add ac

10、cess-group 104 inAnsw er:E14 / 4815 / 48Explanation:问:哪一个修改能只允许 ping,保持拒绝 telnet?我们来看一下 access list 104:题目没有问关于 FTP 的流量,所以不用关心第一条和第二条。第三条拒绝了所有 telent,第四条允许所有 ping 请求包,第五条拒绝所有 ping 回应包。要注意 access list 104 应用的 in 方向,路由器回应 ping 的包是 out 方向,所有第五条不会影响 ping 路由器的 ICMP流量,所以答案选 E。Question 2:What would be the

11、effect of issuing the command ip access-group 114 in to the fa0/0interface?AAttemptstotelnettotherouterwouldfailBItwouldallowalltrafficfromthe10.4.4.0networkC IP traffic would be passed through the interface but TCP and UDP traffic wouldnotD Routing protocol updates for the 10.4.4.0 network would no

12、t be accepted fromthe fa0/0 interfaceAnswer: BExplanation:问:把 ip access-group 114 in 设置在 F0/0 端口,会有什么影响?16 / 4817 / 48access-list 114: access-list 114 permit ip 10.4.4.0 0.0.0.255 any允许来自 10.4.4.0/24 网段的所有流量Question 3:What would be the effect of issuing the command ip access-group 115 in on thes0/0/

13、1 interface?ANohostcouldconnecttoRouterthroughs0/0/1BTelnetandpingwouldworkbutroutingupdateswouldfail.C FTP, FTP-DATA, echo, and www would work but telnet would failD Only traffic from the 10.4.4.0 network would pass through the interfaceAnswer: AExplanation:问:把命令 ip access-group 115 in 设置在设置在 S0/ 0

14、/ 1 端口,会有什么影响?首先 S0/0/1 端口已经配置了 ip access-group 102 in因为一个端口在一个方向只能设置一个 ACL,所以当我们设置 ip access-group 115 in,原 先的 ip access-group 102 in 就被覆盖了。access-list 115: access-list 114 permit ip 0.0.0.0 255.255.255.0 any允许来自 x.x.x.0 网络的流量。x.x.x.0 看上去像一个网络地址,所以选 A,因为网络地址不能作为 host 的 IP 地址。但是如果掩码小于 24 位,x.x.x.0 也

15、可能不是网络地址,比如 10.45.44.0/16,这样看来 A 也不是非常准确。BCD 是肯定不对,排除法,考试还要选 A。18 / 4819 / 483.ACL-2A network associate is adding security to the configuration of the Corp1 router. Theuser on host C should be able to use a web browser to access financial informationfrom the Finance Web Server. No other hosts from t

16、he LAN nor the Core should beable to use a web browser to access this server. Since there are multiple resources forthe corporation at this location including other resources on the Finance Web Server,all other traffic should be allowed.The task is to createand apply a numbered access-list with no more thanthreestatements that will allow ONLY host C web access to the Finance Web Server. Noother hosts will have web access to the Finance Web Server. All other traffic

展开阅读全文
相关资源
正为您匹配相似的精品文档
相关搜索

最新文档


当前位置:首页 > 行业资料 > 其它行业文档

电脑版 |金锄头文库版权所有
经营许可证:蜀ICP备13022795号 | 川公网安备 51140202000112号