Managing Industrial Networking for Manufacturing with Cisco Technologies

Question No: 31

Refer to the exhibit.

An expansion project added an E-Tap and Device Level Ring to interface FastEthernet1/1 of L2SW1. The administrator has looked at the logs of L2SW1 and found that FastEthernet1/1 was in an error-disabled state.Using command line access on L2SW1, the administrator issued the following commands in configuration mode:

L2SW1(config)# interface FastEthernet 1/1 L2SW1(config-if)# shutdown L2SW1(config-if)# no shutdown

The administrator checked the logs of L2SW1 and found the following:

Mar 30 02:23:17.588: %PM-4-ERR_DISABLE: bpduguard error detected on Fa1/1, putting Fa1/1 in err-disable state

The administrator checked the software configuration of the switch port and found the following:

interface FastEthernet1/1 switchport access vlan 310 switchport mode access speed 100

duplex full no mdix auto

spanning-tree portfast

spanning-tree bpduguard enable

Why has the port gone error-disabled?

  1. interface FastEthernet1/1 is configured as an access port on the wrong VLAN.

  2. There is a duplex mismatch between interface FastEthernet1/1 and the E-Tap.

  3. The E-Tap is not configured as a ring supervisor causing a loop on interface FastEthernet1/1.

  4. The E-Tap is configured at 10Mbps and the switch port is configured at 100Mbps.

  5. Automatic MDI Crossover detection is disabled.

Answer: C

Question No: 32

After commissioning several Stratix 5700 switches in a ring topology, you want to verify the installation against the network logical design. Specifically, you want to verify where the IGMP querier resides. What command can be issued in CLI to display the IP of the querier per VLAN?

  1. switch# show ip igmp snooping querier

  2. switch# show igmp snooping querier

  3. switch# show igmp querier

  4. switch# show ip igmp querier

Answer: A

Question No: 33

You have been tasked to design an Ethernet network capable of Motion control with cycle times not to exceed 1ms. In order to create a more deterministic network, what characteristic/s should you primarily focus on?

  1. Lattency and Jitter

  2. Redundancy and high availability

  3. Explicit and Implicit messaging

  4. This cycle time is not possible on an Ethernet network

  5. Gigabit port speed

Answer: A

Question No: 34

What is the reason that ProfiNET frames are discarded by default on Catalyst switches?

  1. ProfiNET uses a nonstandard Ethernet frame format

  2. The frames have an 802.1q tag with VLAN ID equal to 0 (zero)

  3. Catalyst switches do not support ProfiNET traffic

  4. A ProfiNET VLAN must be configured and enabled on a Catalyst switch

Answer: B

Question No: 35

Which best describes the difference between 802.11n and 802.11ac?

  1. 802.11ac offers more channels over more bands than 802.11n

  2. 802.11ac MCS 1 is about twice as fast as 802.11n MCS1

  3. 802.11ac offers more modulation schemes than 802.11n

  4. 802.11ac 1SS MCS 9 is allowed over a 20, 40, 80 and 160 MHz channel, while 802.11n 1SS MCS 9 is only allowed over a 20 or 40 MHz channel.

Answer: C

Question No: 36

What can be done to increase the security in depth in an industrial zone?

  1. Add additional disk storage to the IDS server

  2. Add specific SCADA signatures to the IDS server

  3. Create a high availability solution for the IDS server

  4. Place a #39;data diode#39; in front of the IDS server

Answer: B

Question No: 37

To ensure ProfiNET Layer 2 Class-of-Service markings from ProfiNET devices are trusted by the switch, which command must be entered on the interface attached to the device?

  1. switch(config-if)#mls qos trust cos

  2. switch(config-if)#qos trust cos

  3. switch(config-if)#profinet cos trust

  4. switch(config-if)#trust qos cos

Answer: A

Question No: 38

A ProfiNET management system operator is unable to add a ProfiNET Conformance Class B device to a SIMATIC management station. The device is connected to interface FastEthernet1/3. Based on the provided CLI output, which statement is correct?

switch#show profinet lldp Fa1/1 port-003-00000 On Fa1/2 port-004-00000 On Fa1/3 port-005-00000 Off Fa1/4 port-006-00000 Off Fa1/5 port-007-00000 On Fa1/6 port-008-00000 Off

Fa1/7 port-009-00000 On Fa1/8 port-010-00000 Off

  1. LLDP has been disabled on this switch

  2. The connected device is not sending LLDP packets with ProfiNET extensions

  3. The port label needs to be changed on interface FastEthernet 1/3 to quot;port-003-00000quot;

  4. ProfiNET is disabled on this switch

Answer: B

Question No: 39

Your controller has a high performance EtherNet/IP interface with port speed of gt;30,000 packets per second and 80% spare capacity. A new PowerFlex 753 drive will be added to the system with an RPI of 2ms and has been connected to a switch; you have been asked to set up the switch port. You open the EDS file and see that the drive will support 16 CIP connections and has transmit and receive capacity of 1,000 control packets per second.

What do you set as the storm control pps threshold limit for the port?

A. 16

B. 1,000

C. 2,500

D. 25,000

Answer: C

Question No: 40

Refer to the exhibit.

You are required to implement traffic segmentation in the network. See the table for relevant device details:

L2SW4, L2SW5, and L2SW6 are connected to L3SW1 with 802.1Q trunks with VLAN 191 and VLAN 398 allowed on the trunk.

You have the following information from L3SW1:

L3SW1# show run interfaces

interface Vlan1 no ip address shutdown


interface Vlan2

ip address


interface Vlan191

ip address


interface Vlan200

ip address


interface Vlan398

ip address

L3SW1# show ip route

*** Output Omitted *** is variably subnetted, 5 subnets, 3 masks C is directly connected, Vlan2

C is directly connected, Vlan191 C is directly connected, Vlan398 C is directly connected, Vlan200 S [1/0] via

S* [1/0] via

You are required to implement a configuration that will meet the following connectivity requirements:

  • The Administrator#39;s Station must have full access to PanelView

  • PanelView should have limited access, based on specific TCP ports, to PLC#1 and I/O#1

  • The Administrator#39;s Station should have no access to PLC#1 and I/O#1

  • PLC#1 and I/O#1 should be able to communicate with each other on any port

Which action will allow you to meet the connectivity requirements?

  1. Put interface VLAN 191 and interface VLAN 398 into different Virtual Routing and Forwarding (VRF) instances on L3SW1

  2. Deploy an inbound ACL on interface VLAN 191 to control the traffic from the Administrator#39;s Station and PanelView to PLC#1 and I/O#1

  3. No change is required, the traffic is already limited appropriately by the VLAN segmentation

  4. Implement an ACL on Firewall1 to control the traffic flow between VLAN 191 and VLAN 398

Answer: B

