Cisco Certified Network Associate (200-301 CCNA) – Question691

What is the default port-security behavior on a trunk link?

A.
It places the port in the err-disabled state if it learns more than one MAC address.
B. It causes a network loop when a violation occurs.
C. It disables the native VLAN configuration as soon as port security is enabled.
D. It places the port in the err-disabled state after 10 MAC addresses are statically configured.

Correct Answer: A

Cisco Certified Network Associate (200-301 CCNA) – Question687

What is a function of a Next-Generation IPS?

A.
correlates user activity with network events
B. serves as a controller within a controller-based network
C. integrates with a RADIUS server to enforce Layer 2 device authentication rules
D. makes forwarding decisions based on learned MAC addresses

Correct Answer: A

Cisco Certified Network Associate (200-301 CCNA) – Question685

Which two practices are recommended for an acceptable security posture in a network? (Choose two.)

A.
Use a cryptographic keychain to authenticate to network devices.
B. Place internal email and file servers in a designated DMZ.
C. Back up device configurations to encrypted USB drives for secure retrieval.
D. Disable unused or unnecessary ports, interfaces, and services.
E. Maintain network equipment in a secure location.

Correct Answer: DE