VLAN Management Flashcards
7 cards from real ICND1 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 VLAN Management flashcards as text
Which security threat exploits the default behavior of DTP to gain access to multiple VLANs?
Answer: VLAN hopping via switch spoofing
Switch spoofing is a VLAN hopping attack where a rogue device negotiates a trunk link using DTP, gaining access to all VLANs on the switch.
A network engineer configures 'switchport mode dynamic desirable' on a port. Under what condition will the port become a trunk?
Answer: Only when the other end is set to 'mode trunk' or 'dynamic desirable'
'dynamic desirable' actively initiates trunking and forms a trunk if the opposite side is set to trunk, dynamic desirable, or dynamic auto.
What is the result of a native VLAN mismatch on the two ends of an 802.1Q trunk?
Answer: Untagged frames are delivered to the wrong VLAN, causing traffic leakage
A native VLAN mismatch causes untagged frames from one switch to be placed in the wrong VLAN on the other switch, creating a traffic leakage security issue.
When configuring inter-VLAN routing on a Layer 3 switch, which command enables IP routing globally?
Answer: ip routing
The global configuration command 'ip routing' enables the Layer 3 switch to perform IP routing between VLAN interfaces (SVIs).
Which statement best describes a Switched Virtual Interface (SVI)?
Answer: A logical Layer 3 interface associated with a VLAN used for inter-VLAN routing or management
An SVI is a virtual Layer 3 interface on a multilayer switch tied to a VLAN, providing a gateway IP address for hosts in that VLAN.
An access port is assigned to VLAN 10, but VLAN 10 does not exist in the VLAN database. What is the port's operational state?
Answer: The port is inactive and will not forward frames
A port assigned to a non-existent VLAN becomes inactive; traffic will not be forwarded until the VLAN is created in the database.
Which command removes VLAN 20 from the list of VLANs allowed on a trunk port without affecting other VLANs?
Answer: switchport trunk allowed vlan remove 20
'switchport trunk allowed vlan remove 20' removes only VLAN 20 from the allowed list while leaving all other VLANs intact.