1. A wireless engineer configures an access point to use 40 MHz channel bonding in the 5 GHz band to increase throughput. What is a direct consequence of this configuration?
Network Fundamentals
A.The number of available non-overlapping channels decreases because pairs of 20 MHz channels are combined
B.The number of available non-overlapping channels in the deployment increases
C.The AP's transmit power automatically doubles to compensate for wider channels
D.The AP switches from 802.11ac to 802.11b to support the wider channel
Show answerAnswer
A. The number of available non-overlapping channels decreases because pairs of 20 MHz channels are combined
Channel bonding combines two adjacent 20 MHz channels into a single 40 MHz channel to increase throughput, but this reduces the total number of independent non-overlapping channels available in a given band, which can increase co-channel interference in dense deployments.
2. A router's routing table contains the following entries: 10.1.0.0/16, 10.1.1.0/24, and 10.1.1.128/25, each via a different next hop. A packet arrives destined for 10.1.1.130. Which route will the router use to forward this packet?
IP Connectivity
A.10.1.1.128/25, because it is the longest (most specific) matching prefix
B.10.1.1.0/24, because it has a lower administrative distance
C.The router will load-balance across all three routes
D.10.1.0.0/16, because it was learned first
Show answerAnswer
A. 10.1.1.128/25, because it is the longest (most specific) matching prefix
10.1.1.130 falls within all three ranges, but routers always use the longest prefix match first, before considering administrative distance. The /25 route (10.1.1.128-10.1.1.255) is the most specific match, so it is used.
3. A developer examines a JSON payload returned from a controller API and sees the following field:
"vlan_ids": [10, 20, 30]
What JSON data type is used to represent "vlan_ids"?
Automation and Programmability
A.String
B.Boolean
C.Object
D.Array
Show answerAnswer
D. Array
An array in JSON is an ordered list of values enclosed in square brackets [ ]. The three numeric values 10, 20, and 30 are elements of that ordered list, making it an array rather than an object (which uses curly braces and key-value pairs).
4. An automation engineer is writing a script that calls a REST API to update the description field on an existing interface object without replacing the entire resource. Which HTTP method is most appropriate for a partial update?
Automation and Programmability
A.POST
B.PUT
C.DELETE
D.PATCH
Show answerAnswer
D. PATCH
PATCH is designed for partial modifications to an existing resource, updating only the specified fields. PUT typically replaces the entire resource, POST creates a new resource, and DELETE removes one.
5. A network engineer wants a switch to remember which DHCP-assigned IP-to-MAC-to-VLAN-to-interface mappings are valid so that Dynamic ARP Inspection can validate future ARP packets. Where is this dynamically-learned information stored?
Security Fundamentals
A.In the DHCP snooping binding database
B.In the MAC address table
C.In the running-configuration as static entries
D.In the ARP cache of the switch's CPU
Show answerAnswer
A. In the DHCP snooping binding database
DHCP snooping builds and maintains a binding database (also called the DHCP snooping table) that records IP address, MAC address, lease time, VLAN, and interface for each client that receives an address via a trusted DHCP server. DAI uses this table to validate ARP packets on untrusted ports.
6. An engineer configures 'enable secret Cisco123' on a router that already has 'enable password Cisco123' configured. A colleague later runs 'show running-config' and notices the enable password line is still readable in plaintext even though 'service password-encryption' is enabled. Which statement explains this scenario?
Security Fundamentals
A.The enable secret uses a stronger one-way hash and takes precedence for login, while service password-encryption only applies a weak reversible Type 7 obfuscation to the enable password
B.The enable secret is ignored whenever an enable password also exists
C.Both passwords will always be identical, so this behavior is expected
D.service password-encryption failed because two passwords cannot coexist on the same device
Show answerAnswer
A. The enable secret uses a stronger one-way hash and takes precedence for login, while service password-encryption only applies a weak reversible Type 7 obfuscation to the enable password
When both are configured, the router uses the enable secret (a strong MD5/Type 5 or SHA hash) for authentication and ignores the enable password for login purposes. However, 'service password-encryption' only applies a weak, easily reversible Type 7 encoding to plaintext passwords like the enable password, not the already-hashed enable secret.
7. Two routers, R1 and R2, run HSRP for the 10.10.10.0/24 VLAN. R1 has priority 150 and is currently Active. R2 has priority 100 with default preempt settings. R1 experiences an interface failure and recovers a few minutes later. What will happen to the Active role after R1 recovers?
IP Connectivity
A.Both routers become Active simultaneously, causing a split-brain condition
B.R1 becomes the new Standby router and stays that way permanently
C.R2 remains Active because preempt is not enabled on R1 by default
D.R1 automatically becomes Active again immediately because it has higher priority
Show answerAnswer
C. R2 remains Active because preempt is not enabled on R1 by default
HSRP does not preempt by default; even though R1 has a higher priority, it will not reclaim the Active role automatically once R2 has taken over unless 'standby preempt' is explicitly configured on R1.
8. A company wants to automate configuration of 200 switches using a tool that does not require installing any agent software on the managed devices and instead connects over SSH to push changes. Which automation tool best fits this description?
Automation and Programmability
A.Chef
B.Ansible
C.SaltStack (using minions)
D.Puppet
Show answerAnswer
B. Ansible
Ansible is agentless, using SSH (or NETCONF/API for network devices) from a control node to push configuration changes to managed nodes without requiring installed agents. Puppet, Chef, and Salt (in minion mode) traditionally rely on agents installed on managed nodes.
9. An engineer runs an Ansible playbook containing the following task against Cisco IOS switches:
- name: Create VLAN 10
cisco.ios.ios_vlans:
config:
- vlan_id: 10
name: SALES
state: merged
What is the effect of setting 'state: merged' in this task?
Automation and Programmability
A.It replaces the entire VLAN database with only VLAN 10
B.It deletes all existing VLANs before applying VLAN 10
C.It causes the playbook to fail if VLAN 10 already exists
D.It combines the specified VLAN 10 configuration with existing VLANs, leaving others untouched
Show answerAnswer
D. It combines the specified VLAN 10 configuration with existing VLANs, leaving others untouched
The 'merged' state in Cisco IOS Ansible resource modules combines the specified configuration with the device's existing configuration, adding or updating only what is defined without removing unrelated existing settings. 'Replaced' or 'overridden' states would have more destructive effects on other VLANs.
10. A security team is comparing AAA protocols for network device administration. They require an option that encrypts the entire packet payload (not just the password) and uses TCP for reliable delivery. Which protocol meets this requirement?
Security Fundamentals
A.Kerberos
B.TACACS+
C.RADIUS
D.SNMPv2
Show answerAnswer
B. TACACS+
TACACS+ encrypts the entire packet body and uses TCP port 49, providing more robust confidentiality for device administration traffic, whereas RADIUS only encrypts the password field and uses UDP.
11. A switch port is configured with 'switchport port-security violation restrict' and a maximum of 2 MAC addresses. A third unauthorized device sends traffic on the port. What is the result?
Security Fundamentals
A.The frame from the unauthorized device is dropped, a syslog message is generated, and the violation counter increments, but the port stays up
B.The port is immediately placed into err-disabled state
C.The switch adds the new MAC address and removes the oldest learned address
D.The frame is silently dropped with no logging and no counter increment
Show answerAnswer
A. The frame from the unauthorized device is dropped, a syslog message is generated, and the violation counter increments, but the port stays up
The 'restrict' violation mode drops traffic from unauthorized MAC addresses, increments the security violation counter, and generates a log/SNMP trap, but unlike 'shutdown' mode it does not disable the port.
12. A syslog message '%CDP-4-NATIVE_VLAN_MISMATCH' appears on SW1's Gi0/1 trunk to SW2. CDP shows SW1's native VLAN as 1 while SW2's native VLAN on the matching port is 99. The trunk remains up and passes tagged traffic normally. What is the primary security/operational risk this mismatch creates?
Network Access
A.The trunk link will immediately be disabled by CDP
B.Both switches will fail to elect a spanning-tree root bridge
C.The EtherChannel bundle carrying this trunk will automatically shut down
D.Untagged frames from VLAN 1 on one switch could be received into VLAN 99 on the other switch, crossing VLAN boundaries
Show answerAnswer
D. Untagged frames from VLAN 1 on one switch could be received into VLAN 99 on the other switch, crossing VLAN boundaries
Untagged (native VLAN) frames are not tagged when sent across a trunk, so if the two ends disagree on which VLAN is native, an untagged frame sent as VLAN 1 by one switch will be interpreted as VLAN 99 by the other, effectively leaking traffic between VLANs. CDP only logs a warning; it does not disable the trunk.
13. Employees frequently travel and need secure encrypted access to internal company resources from any internet-connected location using a software client installed on their laptops. A permanent tunnel between fixed sites is not required. Which VPN type best meets this requirement?
Security Fundamentals
A.GRE tunnel without encryption
B.Client-based remote-access VPN
C.Site-to-site VPN
D.MPLS VPN
Show answerAnswer
B. Client-based remote-access VPN
A client-based remote-access VPN (such as Cisco AnyConnect) allows individual users to establish an encrypted tunnel from any internet connection to the corporate network using client software, ideal for traveling employees needing on-demand access rather than a permanent site-to-site link.
14. A host has the MAC address 00:1A:2B:3C:4D:5E and receives the IPv6 prefix 2001:DB8:ACAD:1::/64 via SLAAC. Using the EUI-64 process, what is the resulting IPv6 address?
Network Fundamentals
A.2001:DB8:ACAD:1::21A:2BFF:FE3C:4D5E
B.2001:DB8:ACAD:1::21A:2BFE:FF3C:4D5E
C.2001:DB8:ACAD:1::1A:2BFF:FE3C:4D5E
D.2001:DB8:ACAD:1::1A2B:3CFF:FE4D:5E00
Show answerAnswer
A. 2001:DB8:ACAD:1::21A:2BFF:FE3C:4D5E
EUI-64 splits the 48-bit MAC into two 24-bit halves (001A2B and 3C4D5E), inserts FFFE in the middle, and flips the 7th bit (universal/local bit) of the first byte. 00 (00000000) becomes 02 (00000010), yielding the interface ID 021A:2BFF:FE3C:4D5E, which with the leading zero dropped displays as 21A:2BFF:FE3C:4D5E appended to the prefix.
15. A network administrator configures a router so that multiple internal hosts share a single public IPv4 address for internet access, with each session distinguished by a unique source port number. Which technique is being used?
Network Fundamentals
A.Dynamic NAT
B.NAT64
C.Port Address Translation (PAT)
D.Static NAT
Show answerAnswer
C. Port Address Translation (PAT)
PAT, also known as NAT overload, allows many internal private addresses to share a single public IP address by tracking sessions using unique source port numbers. Static NAT maps one private address to one public address permanently, dynamic NAT maps from a pool without port sharing, and NAT64 translates between IPv6 and IPv4.
16. An administrator has enabled Dynamic ARP Inspection (DAI) on all access switches, using DHCP snooping bindings for validation. Several servers use statically configured IP addresses and never send DHCP requests, so their legitimate ARP replies are now being dropped by DAI. What should the administrator configure to permit these servers' ARP traffic while keeping DAI enforced for all DHCP clients?
Security Fundamentals
A.Disable DHCP snooping on the VLAN containing the servers
C.Configure the server switchports as DAI trusted interfaces
D.Create an ARP ACL that maps each server's static IP to its MAC address and apply it to the DAI configuration
Show answerAnswer
D. Create an ARP ACL that maps each server's static IP to its MAC address and apply it to the DAI configuration
Since DAI validates ARP packets against the DHCP snooping binding table, hosts with static IPs (never seen by DHCP snooping) will fail validation. An ARP ACL manually defines valid IP-to-MAC mappings for these static hosts and can be applied to DAI so their traffic is permitted, while DHCP clients are still validated dynamically against the snooping database.
17. A company implements GLBP for the 172.16.30.0/24 VLAN using four member routers. Which statement accurately describes how GLBP differs from HSRP and VRRP in this deployment?
IP Connectivity
A.GLBP allows only one router to actively forward traffic while the others remain in standby
B.GLBP requires a separate virtual IP address to be configured on each of the four routers
C.GLBP elects a single Active Virtual Gateway that also becomes the only Active Virtual Forwarder
D.GLBP allows all four routers to simultaneously forward traffic by assigning multiple virtual MAC addresses
Show answerAnswer
D. GLBP allows all four routers to simultaneously forward traffic by assigning multiple virtual MAC addresses
GLBP's key advantage over HSRP/VRRP is active load balancing: one router is elected Active Virtual Gateway (AVG) and assigns different virtual MAC addresses to each participating router, making them Active Virtual Forwarders (AVFs) that all actively forward traffic for different clients simultaneously.
18. A router's routing table shows two entries for destination network 192.168.50.0/24: one static route with administrative distance 1 and one OSPF-learned route with administrative distance 110. A separate OSPF route also exists for 192.168.50.0/25 learned via a different path. Which route does the router use to forward a packet destined for 192.168.50.10?
IP Connectivity
A.Both /24 routes are installed and load-balanced since they share the same prefix length
B.The OSPF route to 192.168.50.0/25, because it is the longest matching prefix
C.The OSPF route to 192.168.50.0/24, because OSPF is more scalable
D.The static route to 192.168.50.0/24, because static routes always win regardless of prefix length
Show answerAnswer
B. The OSPF route to 192.168.50.0/25, because it is the longest matching prefix
Longest prefix match takes priority over administrative distance. Even though the static /24 route has a lower AD than the competing /24 OSPF route, the separate /25 OSPF route is more specific for 192.168.50.10 and is chosen regardless of AD comparisons among the /24 entries.
19. A router's routing table contains two routes learned via OSPF for the same destination network 10.20.0.0/16: one as an intra-area route (O) with metric 20, and another as an external Type 2 route (O E2) with metric 15 redistributed from another protocol. Which route will the router install and use for forwarding?
IP Connectivity
A.The O E2 route, because external routes are always preferred over intra-area routes
B.Both routes will be installed and traffic will load balance between them
C.The intra-area O route with metric 20, because intra-area routes have a lower administrative distance than external OSPF routes
D.The O route with metric 20, because within OSPF, intra-area routes are always preferred over external routes regardless of the AD value assigned to each type
Show answerAnswer
D. The O route with metric 20, because within OSPF, intra-area routes are always preferred over external routes regardless of the AD value assigned to each type
OSPF has an internal route preference hierarchy independent of Cisco's overall AD table entry (which lists OSPF as AD 110 for all types): intra-area routes are always preferred over inter-area routes, which are preferred over external (E1/E2) routes, regardless of the numeric metric value. So the intra-area route wins even though its metric (20) is higher than the external route's metric (15).
20. A branch office has a single lightweight AP whose CAPWAP control connection to the central WLC traverses an unreliable WAN link. The design requirement is that wireless clients must still authenticate and pass traffic locally even if the WAN link to the WLC fails. Which AP mode meets this requirement?
Network Access
A.FlexConnect mode
B.Monitor mode
C.Sniffer mode
D.Local mode
Show answerAnswer
A. FlexConnect mode
FlexConnect mode allows an AP to switch client data locally and, in standalone mode, continue authenticating clients using locally stored credentials or open/PSK authentication even when the CAPWAP link to the WLC is down. Local mode fully depends on the WLC for control and typically tunnels all data, and monitor/sniffer modes don't serve clients at all.
21. Which extended ACL statement correctly permits only HTTPS traffic from any source to the server at 10.10.20.50?
Security Fundamentals
A.access-list 110 permit tcp host 10.10.20.50 any eq 443
B.access-list 110 permit ip any host 10.10.20.50 eq 443
C.access-list 110 permit tcp any 10.10.20.50 0.0.0.0 eq 80
D.access-list 110 permit tcp any host 10.10.20.50 eq 443
Show answerAnswer
D. access-list 110 permit tcp any host 10.10.20.50 eq 443
The correct syntax is 'permit tcp any host 10.10.20.50 eq 443', matching any source, the specific destination host, and TCP port 443 (HTTPS). Option B reverses source and destination, option C uses the 'ip' protocol which doesn't support port filtering, and option D uses port 80 (HTTP) instead of 443.
22. A technician runs 'show ip route' on a branch router and sees the following output:
C 10.1.1.0/24 is directly connected, GigabitEthernet0/1
L 10.1.1.1/32 is directly connected, GigabitEthernet0/1
O 10.2.2.0/24 [110/2] via 10.1.1.2, 00:01:12, GigabitEthernet0/1
S 0.0.0.0/0 [1/0] via 10.1.1.254
Which line represents a manually configured default route?
IP Connectivity
A.L 10.1.1.1/32 is directly connected, GigabitEthernet0/1
B.C 10.1.1.0/24 is directly connected, GigabitEthernet0/1
C.O 10.2.2.0/24 [110/2] via 10.1.1.2, 00:01:12, GigabitEthernet0/1
D.S 0.0.0.0/0 [1/0] via 10.1.1.254
Show answerAnswer
D. S 0.0.0.0/0 [1/0] via 10.1.1.254
The 'S' code identifies a static route, and 0.0.0.0/0 is the default route matching any destination not covered by a more specific entry. The [1/0] shows the default AD (1) for static routes and metric 0.
23. A campus network designer wants every core switch to have a direct physical connection to every other core switch, maximizing redundancy so a single link failure cannot isolate any device. Which topology describes this design?
Network Fundamentals
A.Star topology
B.Hub-and-spoke topology
C.Full mesh topology
D.Partial mesh topology
Show answerAnswer
C. Full mesh topology
In a full mesh topology, every node has a direct connection to every other node, providing maximum redundancy and eliminating single points of failure between core devices. Partial mesh only connects some nodes directly, while star and hub-and-spoke rely on a central device.
24. A company wants to run multiple isolated operating systems directly on server hardware for maximum performance, without installing a host operating system first. Which virtualization approach should be used?
Network Fundamentals
A.Type 1 hypervisor
B.Type 2 hypervisor
C.Application virtualization
D.Container-based virtualization
Show answerAnswer
A. Type 1 hypervisor
A Type 1 (bare-metal) hypervisor installs directly on the physical server hardware and manages guest virtual machines without needing an underlying host OS, providing better performance and resource efficiency than Type 2 hypervisors.
25. A network administrator receives documentation stating a subnet mask of /21 for a newly assigned network. Which subnet mask in dotted-decimal notation corresponds to this CIDR value?
Network Fundamentals
A.255.255.248.0
B.255.255.240.0
C.255.255.255.0
D.255.255.252.0
Show answerAnswer
A. 255.255.248.0
A /21 mask means 21 bits are network bits. The first three octets (24 bits) are all 1s, and the fourth octet has 24 total minus... actually the third octet needs 5 bits from it: 21 = 8+8+5, so the third octet is 11111000 = 248. Thus the mask is 255.255.248.0.
Channel bonding combines two or more adjacent 20 MHz channels (e.g., into 40, 80, or 160 MHz) to boost throughput at the cost of fewer available non-overlapping channels.
Increases throughput but increases interference risk
A JSON array is an ordered, comma-separated collection of values enclosed in square brackets [ ], which can hold numbers, strings, objects, or other arrays.
Denoted by square brackets [ ]
Values are ordered and accessed by index
Can contain mixed data types including nested objects/arrays
REST APIs use standard HTTP verbs to perform CRUD operations: GET (read), POST (create), PUT (full update/replace), PATCH (partial update), DELETE (remove).
GET is safe and idempotent
PUT is idempotent, replaces whole resource
PATCH modifies only specified fields, not necessarily idempotent
enable secret uses a strong one-way hash (Type 5/8/9) and takes precedence over enable password, which is stored in weaker, reversible Type 7 form when service password-encryption is enabled.
enable secret always overrides enable password for authentication
service password-encryption applies weak Type 7 to plaintext passwords
Type 7 is easily reversible; Type 5/8/9 hashes are much stronger
Ansible is a push-based, agentless automation tool that uses SSH (for Linux/network devices) to apply configurations defined in YAML playbooks from a control node.
Cisco IOS Ansible resource modules use a 'state' parameter (merged, replaced, overridden, deleted) to control how declared configuration interacts with existing device configuration.
merged: combines new config with existing, non-destructive
replaced: replaces only the specified config section
A VPN solution where individual users run client software (e.g., Cisco AnyConnect) to establish an encrypted tunnel to a corporate network from any internet connection, ideal for remote/traveling users.
Established on-demand by the user, not permanent
Commonly uses SSL/TLS or IPsec
Contrasts with site-to-site VPNs, which connect fixed locations permanently
EUI-64 generates a 64-bit interface ID from a 48-bit MAC address by splitting it, inserting FFFE in the middle, and flipping the 7th bit of the first byte.
Split MAC into two 24-bit halves
Insert FFFE between the halves
Flip the universal/local (U/L) bit of the first byte
PAT, or NAT overload, allows multiple private hosts to share a single public IP address by using unique source port numbers to differentiate simultaneous sessions.
An ARP access control list can be configured to manually define valid IP-to-MAC bindings for static IP hosts, allowing DAI to validate them without relying on the DHCP snooping binding table.
Used when hosts don't use DHCP (e.g., servers, printers)
Applied with 'ip arp inspection filter <acl-name> vlan <id>'
DHCP clients still validated against snooping bindings normally
Gateway Load Balancing Protocol allows multiple routers to actively forward traffic for a single virtual IP by assigning each router a distinct virtual MAC address as an Active Virtual Forwarder.
One router is elected AVG to manage virtual MAC assignment
Up to 4 AVFs can forward traffic simultaneously
Unlike HSRP/VRRP, GLBP uses all available bandwidth rather than one active path
Routers first select the most specific (longest) matching prefix for a destination; administrative distance is only used to break ties between sources advertising the identical prefix length.
Longest prefix match is evaluated first, always
AD comparison happens only among routes with the same prefix length
A /25 route always beats a /24 route for an address within the /25 range
Within OSPF, route selection follows a fixed hierarchy: intra-area > inter-area > external Type 1 > external Type 2, regardless of the numeric cost/metric.
Intra-area routes always beat inter-area and external routes
E1 costs include external+internal metric; E2 shows only external cost
This is separate from Administrative Distance which is 110 for all OSPF routes
Extended ACLs filter based on protocol, source, destination, and port number using the syntax: access-list <100-199> permit/deny protocol source destination [operator port].
A full mesh topology directly connects every network node to every other node, offering maximum redundancy at the cost of higher cabling and complexity.
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.