371
116. B. The command
show port-security interface gi 2/13 will allow you to see a
detailed view of an individual port configured for port security. The command
show
running-configuration is incorrect; it will not show the status of a port, only the
configuration. The command
show port-security details interface gi 2/13 is
incorrect. The command
show port-security gi 2/13 is incorrect.
117. A. The command
switchport port-security violation shutdown puts the
interface into the err-disable state immediately and sends an SNMP trap notification to
a syslog server. The command
switchport port-security restrict is incorrect. The
command
switchport port-security violation protect is incorrect. The command
switchport port-security violation restrict is incorrect.
118. C. The command
switchport port-security violation protect will set the
violation mode to protect. This will drop frames over the maximum number of learned
MAC addresses but will not log security violations to the counters. The command
switchport port-security violation shutdown is incorrect. The command
switchport port-security restrict is incorrect. The command
switchport port-security violation restrict is incorrect.
119. C. The command
show port-security will show all ports that have logged port
security violations. The command
show violations is incorrect. The command
show port-security violations is incorrect. The command show psec violations
is incorrect.
120. C. When you configure sticky port security, the first MAC address seen by the switch will
become bound to the port. Any other MAC addresses will trip the access violation set.
Static port security will require you to enter the MAC address of each computer paired
with each port. Dynamic port security and time limit port security are not types of port
security that can be implemented.
121. B. The default configuration for port security results in an access violation of shutdown.
When a port security violation occurs, the port will be shut down in an err-disable
status. Because the port is in an err-disabled state, the exhibit does not support the
theory that a port has been administratively shut down. The exhibit also does not
support the theory that the port has bad wiring. You cannot tell from the output in the
exhibit that the port is configured as a trunk or access link, but neither will place the
port into an err-disabled state.
122. A. The command
switchport port-security mac-address sticky will configure
the port to learn the first MAC address and allow only the first MAC address to pass
traffic. The command
switchport port-security mac-address dynamic is incorrect.
The command
switchport port-security mac-address static is incorrect. The
command
switchport port-security mac-address learn is incorrect.
123. D. One way to clear an err-disable status is to issue the
shutdown command and then
the
no shutdown command on the port. This will reset the port so that traffic can flow
again. However, if the access violation still exists, then the port will enter an err-disable
status again. The command
no port-security is incorrect and will not clear the err-
disable state. The command
no shutdown is incorrect and will not clear the err-disable
state. The command
no switchport port-security is incorrect and will not clear the
err-disable state.
Do'stlaringiz bilan baham: |