Free 300-410 Exam Braindumps (page: 41)

Page 41 of 156

Refer to the exhibit. A network administrator successfully logs in to a switch using SSH from a RADIUS server. When the network administrator uses a console port to access the switch, the RADIUS server returns shell:priv-lvl=15" and the switch asks to enter the enable command. When the command is entered, it gets rejected.


Which command set is used to troubleshoot and resolve this issue?


  1. line con 0
    aaa authorization console privl5
    !
    linevty 0 4
    authorization exec

  2. line con 0
    aaa authorization console
    !
    linevty 0 4
    authorization exec

  3. line con 0
    aaa authorization console
    authorization priv15
    !
    linevty 0 4
    transport input ssh

  4. line con 0
    aaa authorization console
    authorization exec
    !
    linevty 0 4
    transport input ssh

Answer(s): D


Reference:

https://flylib.com/books/en/1.233.1.74/1/



Refer to the exhibit. An engineer is troubleshooting a TACACS problem.

Which action resolves the issue?

  1. Configure a matching TACACS server IP.
  2. Configure a matching preshared key.
  3. Generate authentication from a relative source interface.
  4. Apply a configured AAA profile to the VTY.

Answer(s): B


Reference:

https://community.cisco.com/t5/network-access-control/issues-with-tacacs-authentication/td-p/3412001



The network administrator configured CoPP so that all HTTP and HTTPS traffic from the administrator device located at 172.16 1.99 toward the router CPU is limited to 500 kbps. Any traffic that exceeds this limit must be dropped.

access-list 100 permit ip host 172.16.1.99 any
!
class-map CM-ADMIN
match access-group 100
!
policy-map PM-COPP
class CM-ADMIN
police 500000 conform-action transmit
!
interface E0/0
service-policy input PM-COPP

CoPP failed to capture the desired traffic and the CPU load is getting higher.

Which two configurations resolve the issue? (Choose two.)


  1. interface E0/0
    no service-policy input PM-COPP
    !
    control-plane
    service-policy input PM-COPP

  2. policy-map PM-COPP
    class CM-ADMIN
    no police 500000 conform-action transmit
    police 500 conform-action transmit
    !
    control-plane
    service-policy input PM-COPP

  3. no access-list 100
    access-list 100 permit tcp host 172.16.1.99 any eq 80

  4. no access-list 100
    access-list 100 permit tcp host 172.16.1.99 any eq 80
    access-list 100 permit tcp host 172.16.1.99 any eq 443

  5. policy-map PM-COPP
    class CM-ADMIN
    no police 500000 conform-action transmit
    police 500 conform-action transmit

Answer(s): D



Refer to the exhibit. While monitoring VTY access to a router, an engineer notices that the router does not have any filter and anyone can access the router with username and password even though an ACL is configured.


Which command resolves this issue?

  1. access-class INTERNET in
  2. ip access-group INTERNET in
  3. ipv6 traffic-filter INTERNET in
  4. ipv6 access-class INTERNET in

Answer(s): D



Page 41 of 156



Post your Comments and Discuss Cisco® 300-410 exam with other Community members:

Ramu commented on February 24, 2024
I really do not like relying on these exam dumps questions, but this exam has left me no choice. So I purchased this exam dumps and now I feel much relieved and confident preparing for my exam.
Anonymous
upvote

Loren commented on August 06, 2021
I really do not like relying on these exam dumps questions, but this exam has left me no choice. So I purchased this exam dumps and now I feel much relieved and confident preparing for my exam.
UNITED STATES
upvote

Asaya commented on August 04, 2021
It is looking good. I just made my download. Study begins tomorrow.
BRAZIL
upvote

Kalib commented on April 12, 2021
With my busy schedule this is the best source of studying to pass my exam.
AUSTRALIA
upvote