Actualtests offers free demo for ccdp arch 300 320 exam. "Designing Cisco Network Service Architectures", also known as ccdp arch 300 320 exam, is a Cisco Certification. This set of posts, Passing the Cisco aerospatiale alenia atr 42 300 320 exam, will help you answer those questions. The ccdp arch 300 320 Questions & Answers covers all the knowledge points of the real exam. 100% real Cisco 320 300 exams and revised by experts!
Q111. Which two protocol characteristics should be most considered when designing a single unified fabric for the Data Center? (Choose two.)
A. FCIP or FCoE allow for easier integration by using the Fibre Channel Protocol (FCP) and Fibre Channel framing
B. iSCSI uses a special EtherType and an additional header containing additional control information
C. FCIP and iSCSI has higher overhead than FCoE owing to TCP/IP
D. FCoE was initially developed to be used as a switch-to-switch protocol, while FCIP is primarily meant to be used as an access layer protocol to connect hosts and storage to a Fibre Channel SAN
E. FCoE requires gateway functionality to integrate into an existing Fibre Channel network
Answer: A,C
Q112. Which option is a primary requirement for the deployment of an IPv6-enabled network via the native method (dual-stack model) within the enterprise campus environment?
A. hardware-based switching support for IPv6 forwarding on all campus switches
B. restriction of IPv6-enabled devices to the core layer
C. manual implementation of tunneling between IPv6-incompatible devices in an IPv4-over-IPv6 tunnel
D. disabling of multicast in the distribution layer prior to implementation of IPv6
Answer: A
Q113. Which network virtualization technology provides logical isolation of network traffic at Layer 3?
A. VSS
B. VLAN
C. VRF-Lite
D. MEC
Answer: C
Q114. Which of these Layer 2 access designs does not support VLAN extensions?
A. FlexLinks
B. loop-free U
C. looped square
D. looped triangle
E. loop-free inverted U
Answer: B
Q115. A VPN solution requires bulk traffic encryption, low OpEx to add new sites, and the ability to accommodate dynamic tunnels between branch locations. What VPN solution can fulfill these requirements?
A. GETVPN
B. SSL VPN
C. Easy VPN
D. DMVPN
Answer: D
Q116. When designing remote access to the Enterprise Campus network for teleworkers and mobile workers, which of the following should the designer consider?
A. It is recommended to place the VPN termination device in line with the Enterprise Edge firewall, with ingress traffic limited to SSL only
B. Maintaining access rules, based on the source IP of the client, on an internal firewall drawn from a headend RADIUS server is the most secure deployment
C. VPN Headend routing using Reverse Route Injection (RRI) with distribution is recommended when the remote user community is small and dedicated DHCP scopes are in place
D. Clientless SSL VPNs provide more granular access control than SSL VPN clients (thin or thick), including at Layer7
Answer: D
Q117. A network engineer is implementing virtualization into the enterprise network. Which system should be used to address policy enforcement at the distribution layer?
A. Cisco IOS based firewall
B. multilayer switches
C. integrated firewall services
D. identity services engine
E. intrusion protection systems
Answer: C
Q118. Port security supports which type of port?
A. SPAN destination port
B. EtherChannel port-channel port
C. nonnegotiating trunk port
D. DTP-enabled trunk port
Answer: C
Q119. Source traffic is sent to a VIP on an SLB device, which in turn is routed to the destination server. Return traffic is policy-based routed back to the SLB.
Which SLB design has been implemented?
A. router mode
B. inline bridge mode
C. one-armed mode
D. two-armed mode
Answer: D
Q120. Which option is the Cisco recommendation for data oversubscription for access ports on the access-to-distribution uplink?
A. 4 to 1
B. 20 to 1
C. 16 to 1
D. 10 to 1
Answer: B