Which security feature is only supported on the Cisco Nexus 7000 Series Switch?

  • A. Dynamic ARP Inspection
  • B. NAC
  • C. CoPP
  • D. IP source guard

Answer: B

Which statement is true if password-strength checking is enabled?

  • A. Short, easy-to-decipher passwords will be rejected.
  • B. The strength of existing passwords will be checked.
  • C. Special characters, such as the dollar sign ($) or the percent sign (%), will not be allowed.
  • D. Passwords become case-sensitiv

Answer: A

Explanation: If a password is trivial (such as a short, easy-to-decipher password), the cisco NX_OS software will reject your password configuration if password-strength checking is enabled. Be sure to configure a strong password. Passwords are case sensitive.
Reference: http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus9000/sw/7- x/security/configuration/guide/b_Cisco_Nexus_9000_Series_NXOS_ Security_Configuration_Guide_7x/b_Cisco_Nexus_9000_Series_NXOS_ Security_Configuration_Guide_7x_chapter_01000.pdf

Which two options should you consider when you configure a SAN zone set? (Choose two.)

  • A. VSANs can be activated by using enhanced zoning.
  • B. A SAN zone set consists of one or more SAN zones.
  • C. A SAN zone set must be activated manually on all of the fabric nodes.
  • D. Only the SAN zone set can be activated simultaneously.
  • E. One SAN zone can be the member of only one zone se

Answer: BC

What can be identified by running the switch# show install all impact kickstart bootflash:n5000-uk9- kickstart.4.2.1.N.1.1a.bin system bootflash:n5000-uk9.4.2.1.N1.1a.bin command?

  • A. the impact of the specified kickstart image on the specified system image
  • B. whether the specified system image supports the kickstart image
  • C. whether bootflash is supported for the specified Cisco NX-OS images
  • D. whether ISSU is supported for the specified Cisco NX-OS images

Answer: D

Refer to the exhibit.
300-165 dumps exhibit
What is the consequence of configuring peer-gateway on the two vPC peers N7K-1 and N7K-2?

  • A. Nothing, this is the standard vPC configuration to make the feature work.
  • B. The downstream device detects only one of the vPC peers as its gateway.
  • C. The downstream device can use DMAC of N7K-1 on the link to N7K-2, and N7K-2 forwards the packet.
  • D. This configuration enables the downstream device to use DHCP to obtain its default gatewa

Answer: C

Explanation: Beginning with Cisco NX-OS 4.2(1), you can configure vPC peer devices to act as the gateway even for packets that are destined to the vPC peer device's MAC address. Use the peer-gateway command to configure this feature.
Some network-attached storage (NAS) devices or load-balancers may have features aimed to optimize the performances of particular applications. Essentially these features avoid performing a routing-table lookup when responding to a request that originated form a host not locally attached to the same subnet. Such devices may reply to traffic using the MAC address of the sender Cisco Nexus 7000 device rather than the common HSRP gateway. Such behavior is non-complaint with some basic Ethernet RFC standards. Packets reaching a vPC device for the non-local router MAC address are sent across the peer-link and could be dropped by the built in vPC loop avoidance mechanism if the final destination is behind another vPC.
The vPC peer-gateway capability allows a vPC switch to act as the active gateway for packets that are addressed to the router MAC address of the vPC peer. This feature enables local forwarding of such packets without the need to cross the vPC peer-link. In this scenario, the feature optimizes use of the peer-link and avoids potential traffic loss.
Configuring the peer-gateway feature needs to be done on both primary and secondary vPC peers and is non-disruptive to the operations of the device or to the vPC traffic. The vPC peer-gateway feature can be configured globally under the vPC domain submode.
When enabling this feature it is also required to disable IP redirects on all interface VLANs mapped over a vPC VLAN to avoid generation of IP redirect messages for packets switched through the peer gateway router. When the feature is enabled in the vPC domain, the user is notified of such a requirement through an appropriate message.
Packets arriving at the peer-gateway vPC device will have their TTL decremented, so packets carrying TTL = 1 may be dropped in transit due to TTL expire. This needs to be taken into account when the peer-gateway feature is enabled and particular network protocols sourcing packets with TTL = 1 operate on a vPC VLAN.
Reference: http://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/4_2/nxos/ interfaces/configuration/guide/if_nxos/if_vPC.html

When connecting Cisco Nexus 5000 Series Switches to the VMware vCenter Server, which item must be configured before installing the extension keys?

  • A. configure vPC
  • B. configure DirectPath I/O support in vCenter
  • C. configure PTS on the VSM
  • D. configure dynamic vNICs

Answer: A

Which two features are required to implement a Layer 3 VXLAN gateway on the Cisco Nexus 5600 Series platform? (Choose two.)

  • A. feature mpls
  • B. feature nv overlay
  • C. feature lldp
  • D. feature eigrp
  • E. feature vn-segment-vlan-based

Answer: BE

What are two requirements for configuring SAN device aliases? (Choose two.)

  • A. The aliases are independent between fabric nodes.
  • B. The aliases can be assigned to WWPN and WWNN.
  • C. The aliases can be assigned to WWNN only.
  • D. The aliases can be assigned to WWPN only.
  • E. The aliases must be 64 characters or les

Answer: DE

Refer to the exhibit.
300-165 dumps exhibit
Which result does the configuration show?

  • A. border spine
  • B. tenant interface
  • C. SVI configuration
  • D. border leaf

Answer: D

After enabling strong, reversible 128-bit Advanced Encryption Standard password type-6 encryption on a Cisco Nexus 7000, which command would convert existing plain or weakly encrypted passwords to type-6 encrypted passwords?

  • A. switch# key config-key ascii
  • B. switch(config)# feature password encryption aes
  • C. switch# encryption re-encrypt obfuscated
  • D. switch# encryption decrypt type6

Answer: C

Explanation: This command converts existing plain or weakly encrypted passwords to type-6 encrypted passwords.
http://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/5_x/nxos/security/configuration/guide/b_Cisco_Nexus_7000_NXOS_ Security_Configuration_Guide Release_5-x/b_Cisco_Nexus_7000_NXOS_ Security_Configuration_Guide Release_5-x_chapter_010101.html

Which statement about electronic programmable logic device image upgrades is true?

  • A. EPLD and ISSU image upgrades are nondisruptive.
  • B. An EPLD upgrade must be performed during an ISSU system or kickstart upgrade.
  • C. Whether the module being upgraded is online or offline, only the EPLD images that have different current and new versions are upgraded.
  • D. You can execute an upgrade or downgrade only from the active supervisor modul

Answer: D

Explanation: You can upgrade (or downgrade) EPLDs using CLI commands on the Nexus 7000 Series device. Follow these guidelines when you upgrade or downgrade EPLDs:
• You can execute an upgrade from the active supervisor module only. All the modules, including the active supervisor module, can be updated individually.
• You can individually update each module whether it is online or offline as follows:
– If you upgrade EPLD images on an online module, only the EPLD images with version numbers that differ from the new EPLD images are upgraded.
– If you upgrade EPLD images on an offline module, all of the EPLD images are upgraded.
• On a system that has two supervisor modules, upgrade the EPLDs for the standby supervisor and then switch the active supervisor to standby mode to upgrade its EPLDs. On a system that has only one supervisor module, you can upgrade the active supervisor, but this will disrupt its operations during the upgrade.
• If you interrupt an upgrade, you must upgrade the module that is being upgraded again.
• The upgrade process disrupts traffic on the targeted module.
• Do not insert or remove any modules while an EPLD upgrade is in progress. Reference:
http://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/4_0/epld/release/notes/epld_rn.ht ml

Refer to the exhibit.
300-165 dumps exhibit
Which result of implementing the configuration is true?

  • A. The maximum message size is 2500000.
  • B. An alert is sent for a Major condition.
  • C. Email is used as the transport.
  • D. The minimum message seventy level is 9.

Answer: A

What mode is required on a Cisco Nexus 7000 32-port 10-GB module port group to allow equal access to the 10-GB port controller?

  • A. dedicated
  • B. assigned
  • C. shared
  • D. community

Answer: C

Explanation: You can share 10 Gb of bandwidth among a group of ports (four ports) on a 32-port 10-Gigabit Ethernet module. To share the bandwidth, you must bring the dedicated port administratively down, specify the ports that are to share the bandwidth, change the rate mode to shared, and then bring the ports administratively up.
Reference: http://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/5_x/nxos/ interfaces/configuration/guide/if_cli/if_basic.html#70242

Which statement accurately describes an EPLD upgrade on supervisor modules?

  • A. It is disruptive in dual supervisor configurations.
  • B. It is disruptive in single supervisor configurations.
  • C. It can be performed during an ISSU.
  • D. It requires an NX-OS image upgrad

Answer: B

The following four questions concern the Nexus 7010’ s which are configured as a vPC pair at the core of a Data Center network. You can utilize all the available show commands to answer the Questions Access to the running-configuration is not allowed.
Enter NX-OS commands on 7K-3 and 7K-4 to verity network operation and answer four multiplechoice questions
Click on the switch to gain access to the console of the switch. No console or enable passwords are required.
To access the multiple-choice questions, click on the numbered boxes on the loft of the top panel. There are four multiple-choice questions with this task Be sure to answer all four questions before selecting the Next button
300-165 dumps exhibit
300-165 dumps exhibit
300-165 dumps exhibit
Within the vpc configuration of the 7K’s. the command peer-gateway is configured as confirmed with the command show vpc. What is the result of enabling this command?

  • A. Enables 7K-3 to act as the active gateway for packets received on VLAN 101 that are addressed to the MAC address of 7K-4
  • B. Enables 7K-4 to use of the vpc peer link for forwarding packets received on VLAN 100 that are addressed to the MAC address of 7K-3
  • C. Generates IP redirect messages for packets switched through the peer-gateway router
  • D. Causes the HSRP active router to update the ARP table on the standby router for faster convergence after the vPC peer link has flapped
  • E. Allows the vpc peers to coordinate the LACP ID which must be the same on all links on the portchannel

Answer: A

Refer to the exhibit.
300-165 dumps exhibit
Which corrective action is taken to resolve the problem?

  • A. Trunk four VLANs on interface ethernet 199/1/1.
  • B. Use the shut and no shut interface ethernet 199/1/1so that the VLANs come up.
  • C. Place interface ethernet 199/1/1 in VLAN 4 in the N5K-2 configuration.
  • D. Prune all but four VLANs from vPC 199.
  • E. Add VLAN 4 to vPC 199.

Answer: C

Explanation: Place interface ethernet 199/1/1 in VLAN 4 in the N5K-2 configuration.

Refer to the exhibit.
300-165 dumps exhibit
Which two outcomes occur when the state is Other? (Choose two.)

  • A. The VSAN on each end of the connection does not match.
  • B. The interface is not an E Port.
  • C. The interface is not an F Port.
  • D. The interface is administratively shut down.
  • E. Cisco Fabric Services is not enabled.
  • F. NPIV should be disabled.
  • G. The interface is functioning, but may have errors.
  • H. Encryption is not enable

Answer: CD

