background image
Q&A 499
Q&A
As mentioned in Chapter 1, "All About the Cisco Certified Network Associate Certification,"
the questions and scenarios in this book are more difficult than what you should experience on
the actual exam. The questions do not attempt to cover more breadth or depth than the exam;
however, they are designed to make sure that you know the answer. Rather than allowing you
to derive the answer from clues hidden inside the question itself, the questions challenge your
understanding and recall of the subject. Questions from the "Do I Know This Already?" quiz
from the beginning of the chapter are repeated here to ensure that you have mastered the
chapter's topic areas. Hopefully, these questions will help limit the number of exam questions
on which you narrow your choices to two options and then guess.
The answers to these questions can be found in Appendix A, on page 754.
1
Configure a numbered IP access list that would stop packets from subnet 134.141.7.0,
255.255.255.0, from exiting serial 0 on some router. Allow all other packets.
2
Configure an IP access list that allows only packets from subnet 193.7.6.0, 255.255.255.0,
going to hosts in network 128.1.0.0 and using a Web server in 128.1.0.0, to enter serial 0
on some router.
3
How would a user who does not have the enable password find out what access lists have
been configured and where they are enabled?
4
Configure and enable an IP access list that would stop packets from subnet 10.3.4.0/24
from getting out serial interface S0 and that would stop packets from 134.141.5.4 from
entering S0. Permit all other traffic.
5
Configure and enable an IP access list that would allow packets from subnet 10.3.4.0/24,
to any Web server, to get out serial interface S0. Also, allow packets from 134.141.5.4
going to all TCP-based servers using a well-known port to enter serial 0. Deny all other
traffic.
6
Create an IPX packet filter to prevent packets from entering Serial0, except for packets
from address 500.0000.0000.0001 destined for any node in network 4.
7
What services use IPX socket 4? What about Socket 7?
8
Create a configuration to add a SAP access list to filter all print services (SAP 7) from
being advertised out a router's serial 0 and serial1 interfaces.
9
Name all the items that a SAP access list can examine to make a match.
10
Can standard IP access lists be used to check the source IP address when enabled with the
ip access-group 1 in command, and can they check the destination IP addresses when
using the ip access-group 1 out command?
ch07.fm Page 499 Monday, March 20, 2000 5:14 PM