300-135 Premium Bundle

300-135 Premium Bundle

Troubleshooting and Maintaining Cisco IP Networks (TSHOOT) Certification Exam

4.5 
(6285 ratings)
0 QuestionsPractice Tests
0 PDFPrint version
November 23, 2024Last update

Cisco 300-135 Free Practice Questions

Q1. - (Topic 2) 

A customer network engineer has made configuration changes that have resulted in some loss of connectivity. You have been called in to evaluate a switch network and suggest resolutions to the problems. 

Refer to the topology. 

SW1 Switch Management IP address is not pingable from SW4. What could be the issue? 

A. Management VLAN not allowed in the trunk links between SW1 and SW4 

B. Management VLAN not allowed in the trunk links between SW1 and SW2 

C. Management VLAN not allowed in the trunk link between SW2 and SW4 

D. Management VLAN ip address on SW4 is configured in wrong subnet 

E. Management VLAN interface is shutdown on SW4 

Answer:

Explanation: 

In the network, VLAN 300 is called the Management VLAN. Based on the configurations shown below, SW1 has VLAN 300 configured with the IP address of 192.168.10.1/24, while on SW4 VLAN 300 has an IP address of 192.168.100.4/24, which is not in the same subnet. 

Q2. - (Topic 4) 

Scenario: 

You have been asked by your customer to help resolve issues in their routed network. Their network engineer has deployed HSRP. On closer inspection HSRP doesn't appear to be operating properly and it appears there are other network problems as well. You are to provide solutions to all the network problems. 

Examine the configuration on R5. Router R5 do not see any route entries learned from R4; what could be the issue? 

A. HSRP issue between R5 and R4 

B. There is an OSPF issue between R5and R4 

C. There is a DHCP issue between R5 and R4 

D. The distribute-list configured on R5 is blocking route entries 

E. The ACL configured on R5 is blocking traffic for the subnets advertised from R4. 

Answer:

Explanation: 

If we issue the "show ip route" and "show ip ospf neighbor" commands on R5, we see that there are no learned OSPF routes and he has no OSPF neighbors. 

Q3. - (Topic 19) 

The implementation group has been using the test bed to do an IPv6 'proof-of-concept1.

After several changes to the network addressing and routing schemes, a trouble ticket has been opened indicating that the loopback address on R1 (2026::111:1) is not able to ping the loopback address on DSW2 (2026::102:1).

Use the supported commands to isolate the cause of this fault and answer the following question.

What is the solution to the fault condition?

A. Under the interface SerialO/0/0.23 configuration enter the ipv6 ospf 6 area 0 command.

B. Under the interface SerialO/0/0.12 configuration enter the ipv6 ospf 6 area 12 command.

C. Under ipv6 router ospf 6 configuration enter the network 2026::1:/122 area 0 command.

D. Under ipv6 router ospf 6 configuration enter the no passive-interface default command

Answer: A

Explanation:

As explained in question one of this ticket, we can then see that OSPFv3 has not been enabled on the interface to R3:

So the problem is with R2, related to IPV6 Routing, and the fix is to enable the "ipv6 ospf 6 area 0"command under the serial 0/0/0.23 interface. We need to enable this interface for area 0 according to the topology diagram.

Topic 20, Ticket 15: IPv6 Routing Issue 2

Topology Overview (Actual Troubleshooting lab design is for below network design)

-Client Should have IP 10.2.1.3

-EIGRP 100 is running between switch DSW1 & DSW2

-OSPF (Process ID 1) is running between R1, R2, R3, R4

-Network of OSPF is redistributed in EIGRP

-BGP 65001 is configured on R1 with Webserver cloud AS 65002

-HSRP is running between DSW1 & DSW2 Switches

The company has created the test bed shown in the layer 2 and layer 3 topology exhibits.

This network consists of four routers, two layer 3 switches and two layer 2 switches.

In the IPv4 layer 3 topology, R1, R2, R3, and R4 are running OSPF with an OSPF process number 1.

DSW1, DSW2 and R4 are running EIGRP with an AS of 10. Redistribution is enabled where necessary.

R1 is running a BGP AS with a number of 65001. This AS has an eBGP connection to AS 65002 in the ISP's network. Because the company's address space is in the private range.

R1 is also providing NAT translations between the inside (10.1.0.0/16 & 10.2.0.0/16) networks and outside (209.65.0.0/24) network.

ASW1 and ASW2 are layer 2 switches.

NTP is enabled on all devices with 209.65.200.226 serving as the master clock source.

The client workstations receive their IP address and default gateway via R4's DHCP server.

The default gateway address of 10.2.1.254 is the IP address of HSRP group 10 which is running on DSW1 and DSW2.

In the IPv6 layer 3 topology R1, R2, and R3 are running OSPFv3 with an OSPF process number 6.

DSW1, DSW2 and R4 are running RIPng process name RIP_ZONE.

The two IPv6 routing domains, OSPF 6 and RIPng are connected via GRE tunnel running over the underlying IPv4 OSPF domain. Redistrution is enabled where necessary.

Recently the implementation group has been using the test bed to do a ‘proof-of-concept' on several implementations. This involved changing the configuration on one or more of the devices.

You will be presented with a series of trouble tickets related to issues introduced during these configurations.

Note: Although trouble tickets have many similar fault indications, each ticket has its own issue and solution.

Each ticket has 3 sub questions that need to be answered & topology remains same.

Question-1 Fault is found on which device,

Question-2 Fault condition is related to,

Question-3 What exact problem is seen & what needs to be done for solution

===============================================================================

Q4. - (Topic 10) 

The implementations group has been using the test bed to do a ‘proof-of-concept' that requires both Client 1 and Client 2 to access the WEB Server at 209.65.200.241. After several changes to the network addressing, routing schemes, DHCP services, NTP services, layer 2 connectivity, FHRP services, and device security, a trouble ticket has been opened indicating that Client 1 cannot ping the 209.65.200.241 address. 

Use the supported commands to isolated the cause of this fault and answer the following questions. 

On which device is the fault condition located? 

A. R1 

B. R2 

C. R3 

D. R4 

E. DSW1 

F. DSW2 

G. ASW1 

Answer:

Explanation: 

On R1 we need to add the client IP address for reachability to server to the access list that is used to specify which hosts get NATed. 

Q5. - (Topic 4) 

Scenario: 

You have been asked by your customer to help resolve issues in their routed network. Their network engineer has deployed HSRP. On closer inspection HSRP doesn't appear to be operating properly and it appears there are other network problems as well. You are to provide solutions to all the network problems. 

You have received notification from network monitoring system that link between R1 and R5 is down and you noticed that the active router for HSRP group 1 has not failed over to the standby router for group 1. You are required to troubleshoot and identify the issue. 

A. There is an HSRP group track command misconfiguration 

B. There is an HSRP group priority misconfiguration 

C. There is an HSRP authentication misconfiguration 

D. There is an HSRP group number mismatch 

E. This is not an HSRP issue; this is routing issue. 

Answer:

Explanation: 

When looking at the HSRP configuration of R1, we see that tracking has been enabled, but that it is not tracking the link to R5, only the link to R2: 

R1 should be tracking the Eth 0/1 link, not 0/0 to achieve the desired affect/ 

Q6. - (Topic 5) 

Scenario: 

A customer network engineer has edited their OSPF network configuration and now your customer is experiencing network issues. They have contacted you to resolve the issues and return the network to full functionality. 

After resolving the issues between R3 and R4. Area 2 is still experiencing routing issues. Based on the current router configurations, what needs to be resolved for routes to the networks behind R5 to be seen in the company intranet? 

A. Configure R4 and R5 to use MD5 authentication on the Ethernet interfaces that connect to the common subnet. 

B. Configure Area 1 in both R4 and R5 to use MD5 authentication. 

C. Add ip ospf authentication-key 7 BEST to the R4 Ethernet interface that connects to R5 and ip ospf authentication-key 7 BEST to R5 Ethernet interface that connects to R4. 

D. Add ip ospf authentication-key CISCO to R4 Ethernet 0/1 and add area 2 authentication to the R4 OSPF routing process. 

Answer:

Explanation: 

Here, we see from the running configuration of R5 that OSPF authentication has been configured on the link to R4: 

However, this has not been done on the link to R5 on R4: 

Q7. - (Topic 6) 

The implementations group has been using the test bed to do a ‘proof-of-concept' that requires both Client 1 and Client 2 to access the WEB Server at 209.65.200.241. After several changes to the network addressing, routing scheme, DHCP services, NTP services, and FHRP services, a trouble ticket has been operated indicating that Client 1 cannot ping the 209.65.200.241 address. 

Use the supported commands to Isolated the cause of this fault and answer the following questions. 

On which device is the fault condition located? 

A. R1 

B. R2 

C. R3 

D. R4 

E. DSW1 

F. DSW2 

G. ASW1 

H. ASW2 

Answer:

Explanation: 

Since the Clients are getting an APIPA we know that DHCP is not working. However, upon closer examination of the ASW1 configuration we can see that the problem is not with DHCP, but the fact that the trunks on the port channels are only allowing VLANs 1-9, when the clients belong to VLAN 10. VLAN 10 is not traversing the trunk on ASW1, so the problem is with the trunk configuration on ASW1. 

Q8. - (Topic 12) 

The implementations group has been using the test bed to do a ‘proof-of-concept' that requires both Client 1 and Client 2 to access the WEB Server at 209.65.200.241. After several changes to the network addressing, routing scheme, DHCP services, NTP services, layer 2 connectivity, FHRP services, and device security, a trouble ticket has been opened indicating that Client 1 cannot ping the 209.65.200.241 

address. 

Use the supported commands to isolated the cause of this fault and answer the following questions. 

On which device is the fault condition located? 

A. R1 

B. R2 

C. R3 

D. R4 

E. DSW1 

F. DSW2 

G. ASW1 

H. ASW2 

Answer:

Explanation: 

port security needs is configured on ASW1. 

Q9. - (Topic 11) 

The implementations group has been using the test bed to do a ‘proof-of-concept' that requires both Client 1 and Client 2 to access the WEB Server at 209.65.200.241. After several changes to the network addressing, routing scheme, DHCP services, NTP services, layer 2 connectivity, FHRP services, and device security, a trouble ticket has been opened indicating that Client 1 cannot ping the 209.65.200.241 address. 

Use the supported commands to isolated the cause of this fault and answer the following questions. 

What is the solution to the fault condition? 

A. Under the interface Serial0/0/1 enter the ip access-group edge_security out command. 

B. Under the ip access-list extended edge_security configuration add the permit ip 

209.65.200.224 0.0.0.3 any command. 

C. Under the ip access-list extended edge_security configuration delete the deny ip 

10.0.0.0.0 0.255.255.255 any command. 

D. Under the interface Serial0/0/0 configuration delete the ip access-group edge_security in command and enter the ip access-group edge_security out command. 

Answer:

Explanation: 

On R1, we need to permit IP 209.65.200.222/30 under the access list. 

Topic 12, Ticket 7 : Port Security 

Topology Overview (Actual Troubleshooting lab design is for below network design) 

. Client Should have IP 10.2.1.3 

. EIGRP 100 is running between switch DSW1 & DSW2 

. OSPF (Process ID 1) is running between R1, R2, R3, R4 

. Network of OSPF is redistributed in EIGRP 

. BGP 65001 is configured on R1 with Webserver cloud AS 65002 

. HSRP is running between DSW1 & DSW2 Switches 

The company has created the test bed shown in the layer 2 and layer 3 topology exhibits. 

This network consists of four routers, two layer 3 switches and two layer 2 switches. 

In the IPv4 layer 3 topology, R1, R2, R3, and R4 are running OSPF with an OSPF process number 1. 

DSW1, DSW2 and R4 are running EIGRP with an AS of 10. Redistribution is enabled where necessary. 

R1 is running a BGP AS with a number of 65001. This AS has an eBGP connection to AS 65002 in the ISP's network. Because the company's address space is in the private range. 

R1 is also providing NAT translations between the inside (10.1.0.0/16 & 10.2.0.0/16) networks and outside (209.65.0.0/24) network. 

ASW1 and ASW2 are layer 2 switches. 

NTP is enabled on all devices with 209.65.200.226 serving as the master clock source. 

The client workstations receive their IP address and default gateway via R4's DHCP server. 

The default gateway address of 10.2.1.254 is the IP address of HSRP group 10 which is running on DSW1 and DSW2. 

In the IPv6 layer 3 topology R1, R2, and R3 are running OSPFv3 with an OSPF process number 6. 

DSW1, DSW2 and R4 are running RIPng process name RIP_ZONE. 

The two IPv6 routing domains, OSPF 6 and RIPng are connected via GRE tunnel running over the underlying IPv4 OSPF domain. Redistrution is enabled where necessary. 

Recently the implementation group has been using the test bed to do a ‘proof-of-concept' on several implementations. This involved changing the configuration on one or more of the devices. You will be presented with a series of trouble tickets related to issues introduced during these configurations. 

Note: Although trouble tickets have many similar fault indications, each ticket has its own issue and solution. 

Each ticket has 3 sub questions that need to be answered & topology remains same. 

Question-1 Fault is found on which device, 

Question-2 Fault condition is related to, 

Question-3 What exact problem is seen & what needs to be done for solution 

Client is unable to ping IP 209.65.200.241 

Solution 

Steps need to follow as below:-

. When we check on client 1 & Client 2 desktop we are not receiving DHCP address from R4 

ipconfig ----- Client will be getting 169.X.X.X 

. On ASW1 port Fa1/0/ 1 & Fa1/0/2 access port VLAN 10 was assigned but when we checked interface it was showing down 

Sh run ------- check for running config of int fa1/0/1 & fa1/0/2 (switchport access Vlan 10 will be there with switch port security command). Now check as below Sh int fa1/0/1 & sh int fa1/0/2 

. As seen on interface the port is in err-disable mode so need to clear port. 

. Change required: On ASW1, we need to remove port-security under interface fa1/0/1 & fa1/0/2. 

Q10. - (Topic 1)

Exhibit:

A network administrator is troubleshooting an EIGRP connection between RouterA, IP address 10.1.2.1, and RouterB, IP address 10.1.2.2. Given the debug output on RouterA, which two statements are true? (Choose two.)

A. RouterA received a hello packet with mismatched autonomous system numbers.

B. RouterA received a hello packet with mismatched hello timers.

C. RouterA received a hello packet with mismatched authentication parameters.

D. RouterA received a hello packet with mismatched metric-calculation mechanisms.

E. RouterA will form an adjacency with RouterB.

F. RouterA will not form an adjacency with RouterB.

Answer: D,F

Q11. - (Topic 17) 

The implementations group has been using the test bed to do a ‘proof-of-concept' that requires both Client 1 and Client 2 to access the WEB Server at 209.65.200.241. After several changes to the network addressing, routing schemes, DHCP services, NTP services, layer 2 connectivity, FHRP services, and device security, a trouble ticket has been opened DSW1 will not become the active router for HSRP group 10. 

Use the supported commands to isolated the cause of this fault and answer the following questions. 

What is the solution to the fault condition? 

A. Under the interface vlan 10 configuration enter standby 10 preempt command. 

B. Under the track 1 object configuration delete the threshold metric up 1 down 2 command and enter the threshold metric up 61 down 62 command. 

C. Under the track 10 object configuration delete the threshold metric up 61 down 62 command and enter the threshold metric up 1 down 2 command. 

D. Under the interface vlan 10 configuration delete the standby 10 track1 decrement 60 command and enter the standby 10 track 10 decrement 60 command. 

Answer:

Explanation: 

On DSW1, related to HSRP, under VLAN 10 change the given track 1 command to instead use the track 10 command. 

Q12. - (Topic 15) 

The implementations group has been using the test bed to do a ‘proof-of-concept' that requires both Client 1 and Client 2 to access the WEB Server at 209.65.200.241. After several changes to the network addressing, routing scheme, DHCP services, NTP services, layer 2 connectivity, FHRP services, and device security, a trouble ticket has been opened indicating that Client 1 cannot ping the 209.65.200.241 address. 

Use the supported commands to isolated the cause of this fault and answer the following questions. 

The fault condition is related to which technology? 

A. NTP 

B. IP DHCP Helper 

C. IPv4 EIGRP Routing 

D. IPv6 RIP Routing 

E. IPv4 layer 3 security 

F. Switch-to-Switch Connectivity 

G. Loop Prevention 

H. Access Vlans 

I. Port Security 

J. VLAN ACL / Port ACL 

K. Switch Virtual Interface 

Answer:

Explanation: 

On DSW1, VALN ACL, Need to delete the VLAN access-map test1 whose action is to drop access-list 10; specifically 10.2.1.3 

Q13. - (Topic 1)

Which IPsec mode will encrypt a GRE tunnel to provide multiprotocol support and reduced overhead?

A. 3DES

B. multipoint GRE

C. tunnel

D. transport

Answer: D

Q14. - (Topic 10) 

The implementations group has been using the test bed to do a ‘proof-of-concept' that requires both Client 1 and Client 2 to access the WEB Server at 209.65.200.241. After several changes to the network addressing, routing scheme, DHCP services, 

NTP services, layer 2 connectivity, FHRP services, and device security, a trouble ticket has been opened indicating that Client 1 cannot ping the 209.65.200.241 address. 

Use the supported commands to isolated the cause of this fault and answer the following questions. 

What is the solution to the fault condition? 

A. Under the interface Serial0/0/0 configuration enter the ip nat inside command. 

B. Under the interface Serial0/0/0 configuration enter the ip nat outside command. 

C. Under the ip access-list standard nat_trafic configuration enter the permit 10.2.0.0 

0.0.255.255 command. 

D. Under the ip access-list standard nat_trafic configuration enter the permit 209.65.200.0 

0.0.0.255 command. 

Answer:

Explanation: 

On R1 we need to add the client IP address for reachability to server to the access list that is used to specify which hosts get NATed. 

Q15. - (Topic 9) 

The implementations group has been using the test bed to do a ‘proof-of-concept' that requires both Client 1 and Client 2 to access the WEB Server at 209.65.200.241. After several changes to the network addressing, routing schemes, DHCP services, NTP services, layer 2 connectivity, FHRP services, and device security, a trouble ticket has been opened indicating that Client 1 cannot ping the 209.65.200.241 address. 

Use the supported commands to isolated the cause of this fault and answer the following questions. 

On which device is the fault condition located? 

A. R1 

B. R2 

C. R3 

D. R4 

E. DSW1 

F. DSW2 

G. ASW1 

Answer:

Explanation: 

The BGP neighbor statement is wrong on R1. 

Q16. - (Topic 5) 

Scenario: A customer network engineer has edited their OSPF network configuration and now your customer is experiencing network issues. They have contacted you to resolve the issues and return the network to full functionality. 

The 6.6.0.0 subnets are not reachable from R4. how should the problem be resolved? 

A. Edit access-list 46 in R6 to permit all the 6.6.0.0 subnets 

B. Apply access-list 46 in R6 to a different interface 

C. Apply access-list 1 as a distribute-list out under router ospf 100 in R4 

D. Remove distribute-list 64 out on R6 E. Remove distribute-list 1 in ethernet 0/1 in R4 

F. Remove distribute-list 1 in ethernet 0/0 in R4 

Answer:

Explanation: 

Here we see from the running configuration of R6 that distribute list 64 is being used in the outbound direction to all OSPF neighbors. 

However, no packets will match the 6.6.0.0 in this access list because the first line blocks all 6.0.0.0 networks, and since the 6.6.0.0 networks will also match the first line of this ACL, these OSPF networks will not be advertised because they are first denied in the first line of the ACL. 

Q17. - (Topic 1)

Refer to the exhibit.

How would you confirm on R1 that load balancing is actually occurring on the default-network (0.0.0.0)?

A. Use ping and the show ip route command to confirm the timers for each default network resets to 0.

B. Load balancing does not occur over default networks; the second route will only be used for failover.

C. Use an extended ping along with repeated show ip route commands to confirm the gateway of last resort address toggles back and forth.

D. Use the traceroute command to an address that is not explicitly in the routing table.

Answer: D

Q18. - (Topic 17) 

The implementations group has been using the test bed to do a ‘proof-of-concept' 

that requires both Client 1 and Client 2 to access the WEB Server at 209.65.200.241. After several changes to the network addressing, routing schemes, DHCP services, NTP services, layer 2 connectivity, FHRP services, and device security, a trouble ticket has been opened DSW1 will not become the active router for HSRP group 10. 

Use the supported commands to isolated the cause of this fault and answer the following questions. 

The fault condition is related to which technology? 

A. NTP 

B. HSRP 

C. IP DHCP Helper 

D. IPv4 EIGRP Routing 

E. IPv6 RIP Routing 

F. IPv4 layer 3 security 

G. Switch-to-Switch Connectivity 

H. Loop Prevention 

I. Access Vlans 

Answer:

Explanation: 

On DSW1, related to HSRP, under VLAN 10 change the given track 1 command to instead use the track 10 command. 

Q19. - (Topic 13) 

The implementations group has been using the test bed to do a ‘proof-of-concept' that requires both Client 1 and Client 2 to access the WEB Server at 209.65.200.241. After several changes to the network addressing, routing scheme, DHCP services, NTP services, layer 2 connectivity, FHRP services, and device security, a trouble ticket has been opened indicating that Client 1 cannot ping the 209.65.200.241 address. 

Use the supported commands to isolated the cause of this fault and answer the following questions. 

On which device is the fault condition located? 

A. R1 

B. R2 

C. R3 

D. R4 

E. DSW1 

F. DSW2 

G. ASW1 

H. ASW2 

Answer:

Explanation: 

On R4, in the redistribution of EIGRP routing protocol, we need to change name of route-map to resolve the issue. It references route-map OSPF_to_EIGRP but the actual route map is called OSPF->EIGRP. 

START 300-135 EXAM