exam questions

Exam 200-301 All Questions

View all questions & answers for the 200-301 exam

Exam 200-301 topic 1 question 615 discussion

Actual exam question from Cisco's 200-301
Question #: 615
Topic #: 1
[All 200-301 Questions]

An engineer is asked to protect unused ports that are configured in the default VLAN on a switch. Which two steps will fulfill the request? (Choose two.)

  • A. Configure the ports as trunk ports.
  • B. Enable the Cisco Discovery Protocol.
  • C. Configure the port type as access and place in VLAN 99.
  • D. Administratively shut down the ports.
  • E. Configure the ports in an EtherChannel.
Show Suggested Answer Hide Answer
Suggested Answer: CD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ZayaB
Highly Voted 3 years, 8 months ago
The answer is trying to say is that put the ports into access vlan so that it does not get dtp traffic and put it under an unused vlan that is not in the network, for this example is 99...this is the best practice. Answers C & D is correct.
upvoted 12 times
ac89l
1 year, 6 months ago
what is dtp traffic?
upvoted 1 times
Aminoooo
1 year ago
Dynamic Trunking.
upvoted 1 times
...
ebachka
9 months, 2 weeks ago
If you enable DTP(Dynamic Trunking Protocol) aka Dynamic Auto Dynamic Desirable etc.. You are exposing yourself to Switch Spoofing attack.
upvoted 1 times
...
...
...
DoBronx
Highly Voted 2 years ago
Selected Answer: CD
never use the default vlan and shut it down.
upvoted 5 times
ebachka
9 months, 2 weeks ago
Don't do that because then not a single port will work unless you place them manually into a vlan. Its not a bad advice but if you are unaware of what I just mentioned, you wouldn't know why all of a sudden nothing is working.
upvoted 1 times
...
...
[Removed]
Most Recent 7 months, 2 weeks ago
Selected Answer: CD
C & D are correct
upvoted 2 times
...
picho707
1 year ago
Selected Answer: CD
Am I here to assume that VLAN 99 is not configured in the VLAN database? This is ridiculous.
upvoted 2 times
ebachka
9 months, 2 weeks ago
No brother, the question explicitly says secure port that is in vlan 1. If you change the vlan on the port that port will have no way of reaching anything on vlan aka securing the port. The vlan will be automatically created once you tell the port to join vlan 99.
upvoted 1 times
...
...
StingVN
1 year, 5 months ago
Selected Answer: CD
C. Configuring the port type as access and placing the unused ports in a specific VLAN (such as VLAN 99) ensures that any connected devices will not have access to the default VLAN, thereby protecting it. D. Administratively shutting down the unused ports completely disables them, preventing any traffic from passing through and enhancing security. The other options are not directly related to protecting unused ports in the default VLAN: A. Configuring the ports as trunk ports is used for carrying multiple VLANs across a single link. B. Enabling the Cisco Discovery Protocol (CDP) is a network protocol used by Cisco devices for discovering and sharing information about neighboring devices. E. Configuring the ports in an EtherChannel is a technique for bundling multiple physical links into a logical link for increased bandwidth and redundancy.
upvoted 3 times
...
cormorant
2 years ago
how i miss those questions from 2 years ago. the ccna used to be much easier back then
upvoted 1 times
...
DaBest
3 years, 1 month ago
and i thought vlan 99 is the cisco faivourit for vlan management guess i was wrong ~_~
upvoted 2 times
...
Acai
3 years, 6 months ago
I think they might be referring to a Black Hole Vlan as Maxiturne said.
upvoted 2 times
...
Nhan
3 years, 8 months ago
All port are in vlan 1 by default which everyone known. There for put in ina vlan 99 no body know what is that vlan for, also shit down it is one of the best practice
upvoted 2 times
...
GA24
3 years, 9 months ago
I assume Vlan 99 in the answer is a VLAN that is not used in production.
upvoted 2 times
...
uevenasdf
4 years, 1 month ago
C,D - I think it's good practice to change the vlan and shut it down.
upvoted 2 times
...
Goldsmate
4 years, 2 months ago
I don't understand how configuring the port as an access port and putting it in Vlan 99 (c), protects the port. I chose A and D as my answers.
upvoted 2 times
Maxiturne
4 years, 2 months ago
The answer C is not complete but the idea is to put the port in access mode in a "blackhole vlan" read an unused vlan without any "issue". Vlan 99 is not a special vlan available on switches for this application, you can use any vlan nummer you want
upvoted 4 times
...
I_Ninja
4 years, 2 months ago
putting them in access mode and assigning them to an unused vlan is one of the steps to mitigate vlan hopping attacks
upvoted 12 times
...
laurvy36
2 years, 9 months ago
all ports are by default in Vlan 1, that is why puting them in another vlan protect the port, not beeing so easy to guest it
upvoted 2 times
...
SanchezEldorado
4 years, 2 months ago
Additionally, setting up a Trunk port would not protect the port. An attacker could simply setup a switch with a trunk to access the rest of the network.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago