Which statement about the use of tunneling to migrate to IPv6 is true?

A.    Tunneling is less secure than dual stack or translation.
B.    Tunneling is more difficult to configure than dual stack or translation.
C.    Tunneling does not enable users of the new protocol to communicate with users of the old protocol without dual-stack hosts.
D.    Tunneling destinations are manually determined by the IPv4 address in the low-order 32 bits of IPv4-compatible IPv6 addresses.

Answer: C
Using the tunneling option, organizations build an overlay network that tunnels one protocol over the other by encapsulating IPv6 packets within IPv4 packets and IPv4 packets within IPv6 packets. The advantage of this approach is that the new protocol can work without disturbing the old protocol, thus providing connectivity between users of the new protocol. Tunneling has two disadvantages, as discussed in RFC 6144:
Users of the new architecture cannot use the services of the underlying infrastructure.
Tunneling does not enable users of the new protocol to communicate with users of the old protocol without dual-stack hosts, which negates interoperability.
http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/enterprise-ipv6- solution/white_paper_c11-676278.html

Refer to the exhibit. Which one statement is true?

A.    Traffic from the network will be blocked by the ACL.
B.    The network will not be advertised by Router B because the network statement for the network is missing from Router B.
C.    The network will not be in the routing table on Router B.
D.    Users on the network can successfully ping users on the network, but users on the cannot successfully ping users on the network.
E.    Router B will not advertise the network because it is blocked by the ACL.

Answer: E
You can filter what individual routes are sent (out) or received (in) to any interface within your EIGRP configuration.
One example is noted above. If you filter outbound, the next neighbor(s) will not know about anything except the route and therefore won’t send it to anyone else downstream. If you filter inbound, YOU won’t know about the route and therefore won’t send it to anyone else downstream.

Prior to enabling PPPoE in a virtual private dialup network group, which task must be completed?

A.    Disable CDP on the interface.
B.    Execute the vpdn enable command.
C.    Execute the no switchport command.
D.    Enable QoS FIFO for PPPoE support.

Answer: B

A network engineer is configuring a routed interface to forward broadcasts of UDP 69, 53, and 49 to Which command should be applied to the configuration to allow this?

A.    router(config-if)#ip helper-address
B.    router(config-if)#udp helper-address
C.    router(config-if)#ip udp helper-address
D.    router(config-if)#ip helper-address 69 53 49

Answer: A
To let a router forward broadcast packet the command ip helper-address can be used.
The broadcasts will be forwarded to the unicast address which is specified with the ip helper command.
ip helper-address {ip address}
When configuring the ip helper-address command, the following broadcast packets will be forwarded by the router by default:
TFTP — UDP port 69
Domain Name System (DNS) ?UDP port 53
Time service — port 37
NetBIOS Name Server — port 137
NetBIOS Datagram Server — port 138
Bootstrap Protocol (BOOTP) — port 67
TACACS UDP port 49

What is a function of NPTv6?

A.    It interferes with encryption of the full IP payload.
B.    It maintains a per-node state.
C.    It is checksum-neutral.
D.    It rewrites transport layer headers.

Answer: C
RFC 6296 describes a stateless Ipv6-to-Ipv6 Network Prefix Translation (NPTv6) function, designed to provide address independence to the edge network. It is transport-agnostic with respect to transports that do not checksum the IP header, such as SCTP, and to transports that use the TCP/UDP/DCCP (Datagram Congestion Control Protocol) pseudo-header and checksum NPTv6 provides a simple and compelling solution to meet the address-independence requirement in Ipv6. The address-independence benefit stems directly from the translation function of the network prefix translator. To avoid as many of the issues associated with NAPT44 as possible, NPTv6 is defined to include a two-way, checksum-neutral, algorithmic translation function, and nothing else.

IPv6 has just been deployed to all of the hosts within a network, but not to the servers. Which feature allows IPv6 devices to communicate with IPv4 servers?

A.    NAT
B.    NATng
C.    NAT64
D.    dual-stack NAT
E.    DNS64

Answer: C
NAT64 is a mechanism to allow Ipv6 hosts to communicate with Ipv4 servers. The NAT64 server is the endpoint for at least one Ipv4 address and an Ipv6 network segment of 32-bits (for instance
64:ff9b::/96, see RFC 6052, RFC 6146). The Ipv6 client embeds the Ipv4 address it wishes to communicate with using these bits, and sends its packets to the resulting address. The NAT64 server then creates a NAT-mapping between the Ipv6 and the Ipv4 address, allowing them to communicate.

A network engineer initiates the ip sla responder tcp-connect command in order to gather statistics for performance gauging. Which type of statistics does the engineer see?

A.    connectionless-oriented
B.    service-oriented
C.    connection-oriented
D.    application-oriented

Answer: C
Configuration Examples for IP SLAs TCP Connect Operations The following example shows how to configure a TCP Connection-oriented operation from Device B to the Telnet port (TCP port 23) of IP Host 1 (IP address, as shown in the "TCP Connect Operation" figure in the "Information About the IP SLAs TCP Connect Operation" section. The operation is scheduled to start immediately. In this example, the control protocol is disabled on the source (Device B). IP SLAs uses the control protocol to notify the IP SLAs responder to enable the target port temporarily. This action allows the responder to reply to the TCP Connect operation. In this example, because the target is not a Cisco device and a well-known TCP port is used, there is no need to send the control message.
Device A (target device) Configuration
configure terminal
ip sla responder tcp-connect ipaddress port 23

A network engineer executes the ipv6 flowset command. What is the result?

A.    Flow-label marking in 1280-byte or larger packets is enabled.
B.    Flow-set marking in 1280-byte or larger packets is enabled.
C.    IPv6 PMTU is enabled on the router.
D.    IPv6 flow control is enabled on the router.

Answer: A
Enabling Flow-Label Marking in Packets that Originate from the Device This feature allows the device to track destinations to which the device has sent packets that are 1280 bytes or larger.

A network engineer executes the show ip flow export command. Which line in the output indicates that the send queue is full and export packets are not being sent?

A.    output drops
B.    enqueuing for the RP
C.    fragmentation failures
D.    adjacency issues

Answer: A

A network engineer is asked to configure a "site-to-site" IPsec VPN tunnel. One of the last things that the engineer does is to configure an access list (access-list 1 permit any) along with the command ip nat inside source list 1 int s0/0 overload. Which functions do the two commands serve in this scenario?

A.    The command access-list 1 defines interesting traffic that is allowed through the tunnel.
B.    The command ip nat inside source list 1 int s0/0 overload disables "many-to-one" access for all devices on a defined segment to share a single IP address upon exiting the external interface.
C.    The command access-list 1 permit any defines only one machine that is allowed through the tunnel.
D.    The command ip nat inside source list 1 int s0/0 overload provides "many-to-one" access for all devices on a defined segment to share a single IP address upon exiting the external interface.

Answer: D

