完全版200-301日本語練習テスト940特別な問題と解答が待ってます!
CCNA問題集で200-301日本語試験完全版問題で試験学習ガイド
質問 # 12
質問をドラッグアンドドロップ
関数を左側から右側の正しいネットワークコンポーネントにドラッグアンドドロップします。
正解:
解説:
質問 # 13
EtherChannel内のポートではどのパラメーターが異なる可能性がありますか?
- A. トランクのカプセル化
- B. DTPネゴシエーション設定
- C. 速度
- D. デュプレックス
正解:B
質問 # 14
デフォルトのDNSルックアップ設定で構成され、CLIにURLが入力された場合、ルーターは何をしますか?
- A. ユーザーに目的のIPアドレスを指定するように求めます
- B. URLへのpingリクエストを開始します
- C. コマンドがキャンセルされるまでURLの解決を継続的に試みます
- D. URLを解決するためにブロードキャストメッセージを送信します
正解:A
質問 # 15
展示を参照してください。
展示を参照してください。エンジニアは SW1 と SW2 の間に新しいレイヤ 2 LACP EtherChannel を構築しています。そして、指定された show コマンドを実行して作業を確認しました。スイッチが LACP ポート チャネルの 2 番目のメンバーを正常にバンドルするには、どの追加タスクを実行する必要がありますか?
- A. SW2 のインターフェイス FaO 2 で switchporttrunkallowtdvlanadd300 コマンドを設定します。
- B. SW1 ポートチャネル 1 で switchporttrunkallowtdvlanadd300 コマンドを設定します。
- C. SW1 のインターフェイス Fa0/2 で switchport train allowed vlan 300 コマンドを設定します。
- D. SW1 ポートチャネル 1 で switchport train allowed vlan 300 コマンドを設定します。
正解:C
質問 # 16
Cisco Wireless LAN Controllerのセキュリティ設定を左側から右側の適切なセキュリティメカニズムカテゴリにドラッグアンドドロップします。
正解:
解説:

質問 # 17
データセンターのドアにバッジ リーダーを設置して、従業員が職務に基づいて出入りできるようにするセキュリティ プログラム要素はどれですか?
- A. 物理アクセス制御
- B. 多要素認証
- C. ロールベースのアクセス制御
- D. バイオメトリクス
正解:A
質問 # 18
展示を参照してください。
管理者は、音声VLANを構成する必要があります。 Cisco電話がスイッチのGigabitEfriemet3 / 1/4ポートに接続されている場合に予想される結果は何ですか?
- A. 電話機はVLAN 50でデータを送受信しますが、電話機に接続されたワークステーションはVLAN 1でデータを送受信します
- B. 電話と電話に接続されているワークステーションは、VLAN 50でデータを送受信します。
- C. 電話はVLAN 50でデータを送受信しますが、電話に接続されたワークステーションはVLAN接続がありません
- D. 電話機と、その電話機に接続されているワークステーションにはVLAN接続がありません。
正解:A
質問 # 19
IPv6アドレスの詳細を左側から右側の対応するタイプにドラッグアンドドロップします。
正解:
解説:
質問 # 20
展示を参照してください。
10.10.10.32 から送信されたパケットは、インターネット宛てです。
- A. 0
- B. 1
- C. 2
- D. 3
正解:C
質問 # 21
展示を参照してください。
ルーター OldR は、OldR と R2 がルートを交換する目的で、ネットワーク上の別のルーターを置き換えています。エンジニアが最初の OSPF 構成を適用した後、ルートは両方のデバイスでまだ失われていました。ネイバー関係を有効にするために clear IP ospf process コマンドを入力する前に、どのコマンド シーケンスを発行する必要がありますか?
- A. オプション A
- B. オプション D
- C. オプション C
- D. オプション B
正解:C
質問 # 22
新しいインバウンドアクセス拳をルーターに適用し、HSRPグループへのUDPパケットをブロックします。
このアクションはHSRPグループプロセスにどの2つの影響を与えますか? (2つ選択してください。)
- A. HSRP冗長性は期待どおりに機能します
- B. アクティブルーターはすぐにスタンバイルーターになります。
- C. グループ内のルーターは重複IPアドレス警告を生成します
- D. アクティブとスタンバイの両方のルーターがアクティブになります。
- E. HSRP冗長性は失敗します
正解:D、E
質問 # 23
REST APIでは、どの標準HTTPヘッダーが、クライアントが予期するメディアタイプをサーバーに通知しますか?
- A. Accept-Encoding: gzip. deflate
- B. Content-Type: application/json; charset=utf-8
- C. Accept-Patch: text/example; charset=utf-8
- D. Accept: application/json
正解:D
解説:
Explanation
Accept header is a way for a client to specify the media type of the response content it is expecting and Content-type is a way to specify the media type of request being sent from the client to the server.
http://www.java-allan
dsundry.com/2012/08/accept-header-vs-content-type-header.html#:~:text=Accept%20and%20Content%2Dtype%
質問 # 24
すべての物理的なケーブル配線が適切に配置されています。ある企業は、32 の新しいサイトを展開する予定です。
これらのサイトは、IPv4 ネットワークと IPv6 ネットワークの両方を利用します。
1. サブネット要件を満たし、最大化するためのサブネット 172.25.0.0/16
ホストの数
2 番目のサブネットの使用
* 最初の使用可能な IP アドレスを Sw1O1 の e0/0 に割り当てます。
* 最後に使用可能な IP アドレスを Sw102 の e0/0 に割り当てます。
2. サブネット要件を満たし、最大化するためのサブネット
ホストの数
c 2 番目のサブネットの使用
* 一意の 64 ビット インターフェイス識別子を使用して IPv6 GUA を割り当てます
e0/0はSw101です
* 一意の 64 ビット インターフェイス識別子を使用して IPv6 GUA を割り当てます
eO/O 上 swi02
ガイドライン
これは、仮想デバイス上でタスクが実行されるラボ項目です。
* このラボ項目のタスクを表示するには、「タスク」タブを参照してください。
* デバイス コンソールにアクセスしてタスクを実行するには、[トポロジ] タブを参照してください。
* デバイス アイコンをクリックするか、次のコマンドを使用すると、必要なすべてのデバイスでコンソール アクセスが可能になります。
コンソール ウィンドウの上にあるタブ。
* 必要な事前構成はすべて適用されています。
* デバイスのイネーブル パスワードまたはホスト名は変更しないでください。
* 次の項目に進む前に、設定を NVRAM に保存してください。
* 画面の下部にある [次へ] をクリックしてこのラボを送信し、次の質問に進みます。
※「次へ」をクリックするとラボが閉じられ、再度開くことはできません。
正解:
解説:
解決策については説明を参照してください。
Explanation:
To subnet 172.25.0.0/16 to meet the subnet requirements and maximize the number of hosts, you need to determine how many bits you need to borrow from the host portion of the address to create enough subnets for 32 sites. Since 32 is 2^5, you need to borrow 5 bits, which means your new subnet mask will be /21 or 255.255.248.0. To find the second subnet, you need to add the value of the fifth bit (32) to the third octet of the network address (0), which gives you 172.25.32.0/21 as the second subnet. The first usable IP address in this subnet is 172.25.32.1, and the last usable IP address is 172.25.39.254.
To assign the first usable IP address to e0/0 on Sw101, you need to enter the following commands on the device console:
Sw101#configure terminal Sw101(config)#interface e0/0 Sw101(config-if)#ip address 172.25.32.1 255.255.248.0 Sw101(config-if)#no shutdown Sw101(config-if)#end
To assign the last usable IP address to e0/0 on Sw102, you need to enter the following commands on the device console:
Sw102#configure terminal Sw102(config)#interface e0/0 Sw102(config-if)#ip address 172.25.39.254 255.255.248.0 Sw102(config-if)#no shutdown Sw102(config-if)#end
To subnet an IPv6 GUA to meet the subnet requirements and maximize the number of hosts, you need to determine how many bits you need to borrow from the interface identifier portion of the address to create enough subnets for 32 sites. Since 32 is 2^5, you need to borrow 5 bits, which means your new prefix length will be /69 or ffff:ffff:ffff:fff8::/69 (assuming that your IPv6 GUA has a /64 prefix by default). To find the second subnet, you need to add the value of the fifth bit (32) to the fourth hextet of the network address (0000), which gives you xxxx:xxxx:xxxx:0020::/69 as the second subnet (where xxxx:xxxx:xxxx is your IPv6 GUA prefix). The first and last IPv6 addresses in this subnet are xxxx:xxxx:xxxx:0020::1 and xxxx:xxxx:xxxx:0027:ffff:ffff:ffff:fffe respectively.
To assign an IPv6 GUA using a unique 64-bit interface identifier on e0/0 on Sw101, you need to enter the following commands on the device console (assuming that your IPv6 GUA prefix is 2001:db8::/64):
Sw101#configure terminal Sw101(config)#interface e0/0 Sw101(config-if)#ipv6 address 2001:db8::20::1/69 Sw101(config-if)#no shutdown Sw101(config-if)#end
To assign an IPv6 GUA using a unique 64-bit interface identifier on e0/0 on Sw102, you need to enter the following commands on the device console (assuming that your IPv6 GUA prefix is 2001:db8::/64):
Sw102#configure terminal Sw102(config)#interface e0/0 Sw102(config-if)#ipv6 address 2001:db8::27::fffe/69 Sw102(config-if)#no shutdown Sw102(config-if)#end
質問 # 25
脅威を緩和する手法を左側から、脅威の種類または攻撃を軽減する攻撃の右側にドラッグアンドドロップします。
正解:
解説:
Explanation
Double-Tagging attack:In this attack, the attacking computer generates frames with two 802.1Q tags. The first tag matches the native VLAN of the trunk port (VLAN 10 in this case), and the second matches the VLAN of a host it wants to attack (VLAN 20).When the packet from the attacker reaches Switch A, Switch A only sees the first VLAN 10 and it matches with its native VLAN 10 so this VLAN tag is removed. Switch A forwards the frame out all links with the same native VLAN 10. Switch B receives the frame with an tag of VLAN 20 so it removes this tag and forwards out to the Victim computer.Note: This attack only works if the trunk (between two switches) has the same native VLAN as the attacker.To mitigate this type of attack, you can use VLAN access control lists (VACLs, which applies to all traffic within a VLAN. We can use VACL to drop attacker traffic to specific victims/servers) or implement Private VLANs.ARP attack (like ARP poisoning/spoofing) is a type of attack in which a malicious actor sends falsified ARP messages over a local area network as ARP allows a gratuitous reply from a host even if an ARP request was not received. This results in the linking of an attacker's MAC address with the IP address of a legitimate computer or server on the network. This is an attack based on ARP which is at Layer 2.Dynamic ARP inspection (DAI) is a security feature that validates ARP packets in a network which can be used to mitigate this type of attack.
質問 # 26
エンジニアは、2.4GHzチャネルでの使用率が高く、5GHzチャネルでの使用率が低いことを確認しています。クライアントが5GH2アクセスポイントを優先的に使用できるようにするには、何を設定する必要がありますか?
- A. OEAPスプリットトンネル
- B. ローミングされたクライアントを再アンカーする
- C. クライアントバンド選択
- D. 11ac MU-MIMO
正解:C
質問 # 27
オフィスには 8 つのフロアがあり、フロアごとに約 30 ~ 40 人のユーザーがいます アドレス空間を効率的に使用するためにルーターのスイッチ仮想インターフェイスで構成する必要があるコマンドはどれですか?
- A. IP アドレス 192.168.0.0 255.255.255.224
- B. IP アドレス 192.168.0.0 255.255.254.0
- C. IP アドレス 192.168.0.0 255.255.0.0
- D. IP アドレス 192.168.0.0 255.255.255.128
正解:B
質問 # 28
別紙を参照してください。
VLAN 100上のデバイスが独自のIPアドレスを使用できるようにしながら、VLAN 200内のすべてのアドレスを変換するようにPATを構成するルーターに、どの構成を適用する必要がありますか?
- A. オプションD
- B. オプションB
- C. オプションC
- D. オプションA
正解:A
質問 # 29
実行コンフィギュレーション内のすべてのパスワードを暗号化するグローバルコマンドはどれですか?
- A. パスワード暗号化を有効にする
- B. サービスパスワード暗号化
- C. パスワード暗号化
- D. シークレットを有効にする
正解:A
質問 # 30
JSONデータ表現を表示する出力はどれですか?
- A. オプションD
- B. オプションB
- C. オプションC
- D. オプションA
正解:B
質問 # 31
展示を参照してください。EtherChannel は、速度 1000 で構成され、チャネル グループ 1 の両端でデュプレックスが全二重に設定されています。LACP 通信に応答するが開始しないようにスイッチ A のチャネルを構成するには、次の手順を実行します。
- A. インターフェイス ポート チャネル 1 チャネル グループ 1 モード パッシブ
- B. インターフェイス範囲 gigabitethernet0/0/0-15 チャネル グループ 1 モード オン
- C. インターフェイス範囲 gigabitethernet0/0/0-15 channel-group 1 モードが望ましい
- D. インターフェイス ポート チャネル 1 チャネル グループ 1 モード自動
正解:A
質問 # 32
ネットワーク管理者は、ルーターで次のコマンドを入力します。logging trap 3. Syslog サーバーに送信される 3 つのメッセージ タイプは何ですか? (3つ選んでください。)
- A. 情報提供
- B. エラー
- C. デバッグ
- D. クリティカル
- E. 緊急事態
- F. 警告
正解:B、D、E
質問 # 33
ワイヤレス アクセス ポイントが必要で、次の要件を満たす必要があります。
* WLC によって展開および管理される「ゼロタッチ」
* リアルタイム MAC 機能のみを処理します
* 分割 MAC アーキテクチャで使用されます。どのタイプのアクセス ポイントを使用する必要がありますか?
- A. メッシュ
- B. 自律型
- C. クラウドベース
- D. 軽量
正解:D
解説:
https://www.cisco.com/c/en/us/support/docs/wireless/aironet-1200-series/70278-lap-faq.html
質問 # 34
MAC アドレスの最大数を超えたため、スイッチ ポートでポート セキュリティ違反が発生しました。
- A. スイッチポート セキュリティ違反のシャットダウン
- B. スイッチポート セキュリティ違反保護
- C. スイッチポートのポート セキュリティ違反を制限します。
- D. スイッチポート ポート セキュリティ違反アクセス
正解:C
解説:
Explanation
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/12-2/25ew/configuration/guide/conf/port_sec.h
質問 # 35
TCP / IPプロトコルを左側から右側の伝送プロトコルにドラッグアンドドロップします
正解:
解説:
質問 # 36
......
200-301日本語正真正銘のベスト資料、オンライン練習試験:https://www.jpntest.com/shiken/200-301J-mondaishu