exam questions

Exam 350-601 All Questions

View all questions & answers for the 350-601 exam

Exam 350-601 topic 1 question 404 discussion

Actual exam question from Cisco's 350-601
Question #: 404
Topic #: 1
[All 350-601 Questions]



Refer to the exhibit. An engineer must configure port security on the Cisco Nexus 5000 Series Switch that meets these requirements:

• Port security must be applied on VSAN 10 only.
• NWWN 20:10:10:10:10:10:10:10 to log in through SAN port-channel 2.
• Any WWN must be allowed to log in through interfaces fc1/1, fc1/2, fc1/3.
• Auto learning must be disabled.

Which command set satisfies these conditions?

  • A. Nexus5K(config)# port-security database vsan 10
    Nexus5K(config-port-security)# nwwn 20:10:10:10:10:10:10:10 interface san-port-channel 2
    Nexus5K(config-port-security)# any wwn interface fc1/1-3
    Nexus5K(config-port-security)# port-security commit vsan 10
  • B. Nexus5K(config)# port-security activate vsan 10 no auto-learn
    Nexus5K(config)# port-security database vsan 10
    Nexus5K(config-port-security)# nwwn 20:10:10:10:10:10:10:10 interface san-port-channel 2
    Nexus5K(config-port-security)# any wwn interface fc1/1-3
  • C. Nexus5K(config)# port-security database vsan 10
    Nexus5K(config-port-security)# nwwn 20:01:01:01:01:01:01:01 interface san port-channel 5
    Nexus5K(config-port-security)# any wwn interface fc1/1-3
    Nexus5K(config)# port-security database diff active vsan 10
  • D. Nexus5K(config)# port-security database vsan 10
    Nexus5K(config-port-security)# nwwn 20:01:01:01:01:01:01:01 interface port-channel 5
    Nexus5K(config-port-security)# any wwn interface fc1/1-3
    Nexus5K(config)# port-security database diff active vsan 10
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Scheldon
Highly Voted 2 years, 1 month ago
Selected Answer: A
C and D - wrong Adress B - there is no point of implementing "port-security activate vsan vsan-id no-auto-learn" as it is implemented before, beside it should be "no-auto-learn" not "no auto-learn" So after elimination process we have A on the table
upvoted 5 times
...
57ud3n7
Most Recent 7 months, 1 week ago
Selected Answer: A
pending database is not empty in B
upvoted 1 times
...
ed27
1 year, 1 month ago
Selected Answer: A
if you activate port security, follow up by disabling auto-learning, and finally commit the changes in the pending database, then the net result of your actions is the same as entering a port-security activate vsan vsan-id no-auto-learn command.
upvoted 3 times
...
elper
1 year, 2 months ago
Selected Answer: B
A seems to be missing the "no auto-learn". Or should we consider the exhibit as what was previously configured and we just need to complete it?
upvoted 2 times
...
asd248402
1 year, 3 months ago
Selected Answer: B
as per the pdf its b https://www.cisco.com/en/US/docs/storage/san_switches/mds9000/sw/rel_1_x/1_2_2a/san-os/configuration/guide/SecuPort.pdf#page2
upvoted 4 times
...
camelw
1 year, 3 months ago
This question has no correct answer and one of the requirements is Auto learning must be disabled and the correct command is port-security activate vsan 10 no-auto-learn. B is closest to the truth, maybe there was a typographical error.
upvoted 1 times
...
Lisgard
1 year, 8 months ago
It has to be the "B" option. Commit command is used when you are using "auto-learning configuration", that is not allowed here. C and D cannot be an option because have bad addresses
upvoted 1 times
ed27
1 year, 1 month ago
if you activate port security, follow up by disabling auto-learning, and finally commit the changes in the pending database, then the net result of your actions is the same as entering a port-security activate vsan vsan-id no-auto-learn command.
upvoted 1 times
...
...
VirtuaTech
2 years ago
I also Choose B
upvoted 1 times
...
bblauma
2 years ago
Selected Answer: C
I think "C" is right : I know PO 5 is wrong (misspilled word), but you see the link and the Tip We recommend that you issue the port-security database copy vsan command after disabling auto-learning. This action will ensure that the configuration database is in sync with the active database. If distribution is enabled, this command creates a temporary copy (and consequently a fabric lock) of the configuration database. If you lock the fabric, you need to commit the changes to the configuration databases in all the switches. https://www.cisco.com/c/en/us/td/docs/switches/datacenter/mds9000/sw/8_x/config/security/cisco_mds9000_security_config_guide_8x/configuring_port_security.html#task_1002579
upvoted 1 times
...
warCZert
2 years, 2 months ago
Selected Answer: B
C and D has wrong WWN. B is OK.Distribution is not required, so not A.
upvoted 2 times
...
[Removed]
2 years, 2 months ago
Answer is B, the following link explain it step by step: https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5000/sw/configuration/guide/cli_rel_4_0_1a/CLIConfigurationGuide/psec.html#92130
upvoted 1 times
...
paradigm88
2 years, 2 months ago
Selected Answer: A
https://www.cisco.com/en/US/docs/storage/san_switches/mds9000/sw/rel_3_x/configuration/guides/cli_3_2/psec.html#wp1298070
upvoted 2 times
FARHAMFAR
2 years, 2 months ago
switch is N5k , not mds9k
upvoted 1 times
FARHAMFAR
2 years, 2 months ago
question don't ask Port Security Configuration Distribution (commit) , so why not B is true answer?
upvoted 3 times
...
...
...
Rocky_Truth
2 years, 3 months ago
Selected Answer: A
The correct command set that satisfies the given requirements is option A. Option B does not include the "port-security database" command to define the port security database for the specific VSAN 10. Option C has the incorrect NWWN address specified and the "port-security database diff active" command is not needed. Option D has the incorrect interface type specified for the NWWN, it should be "san-port-channel 2" instead of "port-channel 5", and the "port-security database diff active" command is not needed.
upvoted 1 times
...
JesNet
2 years, 5 months ago
How can be C if WWN does not match and port.channel id either, correct it's B.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...