Topic 01 Practice Test 2 covers Network Devices and Topology Architectures for Cisco Certified Network Associate 200-301 CCNA and maps to objectives 1.1–1.2. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps. Every option includes focused technical reasoning explaining both the networking concept and its fit to the scenario.
Question 1
A small campus has access switches connected directly to a redundant pair that performs both distribution and core functions. Which topology is this? Choose ONE.
- Two-tier campus architecture
- Three-tier campus architecture
- Spine-leaf architecture
- WAN architecture
Correct Answer: A
Correct Answer
Answer A is correct because There is no separate dedicated core layer, which defines the collapsed two-tier campus model. A two-tier campus collapses distribution and core functions into one layer above the access layer instead of deploying a separate core. The required outcome is a campus design with access plus collapsed distribution/core. The role matches.
Incorrect Answers
Answer B is incorrect because A three-tier campus separates access, distribution, and core functions into distinct architectural layers. Its proper use differs: It fits larger campuses that benefit from an independent core interconnecting several distribution blocks. This case needs a campus design with access plus collapsed distribution/core. There is no separate dedicated core layer, which defines the collapsed two-tier campus model. It therefore fails here.
Answer C is incorrect because In a classic spine-leaf fabric, each leaf connects to every spine and leaf-to-leaf traffic traverses a spine. It suits data centers that need scalable, predictable paths for substantial east-west traffic. Here, the task is a campus design with access plus collapsed distribution/core. There is no separate dedicated core layer, which defines the collapsed two-tier campus model. That option misses the required function.
Answer D is incorrect because Its scope is site-to-site transport across distance, not the local topology inside a single office. Wide-area networking extends connectivity beyond one local site, commonly joining branches, offices, or data centers through service-provider transport. The case instead needs a campus design with access plus collapsed distribution/core. There is no separate dedicated core layer, which defines the collapsed two-tier campus model. The roles differ.
Question 2
A large campus has access switches feeding distribution blocks, while a separate high-speed core interconnects those distribution blocks. Which topology is described? Choose ONE.
- SOHO architecture
- Three-tier campus architecture
- Two-tier campus architecture
- Spine-leaf architecture
Correct Answer: B
Correct Answer
Answer B is correct because Three-tier hierarchical design places a dedicated core above distribution blocks, which in turn aggregate access networks. The task requires separate access, distribution, and core layers. The architecture explicitly separates all three hierarchical campus layers. It is the appropriate choice.
Incorrect Answers
Answer C is incorrect because In a two-tier campus, access switches connect to a combined distribution/core tier, reducing the number of architectural layers. Choose it when a smaller campus needs hierarchy but can combine distribution and core functions. Here, the task is separate access, distribution, and core layers. The architecture explicitly separates all three hierarchical campus layers. That option misses the required function.
Answer D is incorrect because Choose it when server-to-server traffic and consistent fabric hop counts are central design goals. Spine-leaf data-center topology creates a consistent fabric by attaching every leaf switch to all spine switches. The case instead needs separate access, distribution, and core layers. The architecture explicitly separates all three hierarchical campus layers. The roles differ.
Answer A is incorrect because A small-office/home-office design favors simplicity and may combine routing, switching, firewalling, and Wi-Fi in only one or a few devices. Its proper use differs: It suits a small location where enterprise multi-tier architecture would be unnecessary. This case needs separate access, distribution, and core layers. The architecture explicitly separates all three hierarchical campus layers. It therefore fails here.
Question 3
A data center requires a fabric where every top-of-rack leaf switch connects to every spine so server-to-server traffic follows predictable paths. Which topology fits? Choose ONE.
- SOHO architecture
- Three-tier campus architecture
- Spine-leaf architecture
- WAN architecture
Correct Answer: C
Correct Answer
Answer C is correct because A two-tier spine-leaf fabric places endpoint-facing leaf switches below a spine layer, with full leaf-to-spine connectivity. The leaf-to-every-spine connectivity pattern identifies a spine-leaf fabric. Required outcome: a two-tier fabric optimized for east-west traffic. This option fits.
Incorrect Answers
Answer B is incorrect because It is appropriate where multiple distribution domains need a dedicated high-speed core layer. The traditional three-layer campus model uses separate access, distribution, and core tiers to improve modularity and scale. The case instead needs a two-tier fabric optimized for east-west traffic. The leaf-to-every-spine connectivity pattern identifies a spine-leaf fabric. The roles differ.
Answer D is incorrect because A wide area network connects LANs or sites across significant geographic distance using carrier, provider, or other long-haul connectivity. Its proper use differs: It fits communication between organizational sites in different geographic locations. This case needs a two-tier fabric optimized for east-west traffic. The leaf-to-every-spine connectivity pattern identifies a spine-leaf fabric. It therefore fails here.
Answer A is incorrect because SOHO networks serve a small user population with compact infrastructure instead of a multi-layer enterprise campus. Choose SOHO for a modest user count and simple local-network requirements. Here, the task is a two-tier fabric optimized for east-west traffic. The leaf-to-every-spine connectivity pattern identifies a spine-leaf fabric. That option misses the required function.
Question 4
A company must connect offices in Karachi and Lahore across a service-provider circuit. Which architecture category describes the inter-site network? Choose ONE.
- WAN architecture
- SOHO architecture
- Cloud infrastructure
- Two-tier campus architecture
Correct Answer: A
Correct Answer
Answer A is correct because The network spans distant locations rather than remaining within one local campus. WAN connectivity links separate geographic locations so their local networks can communicate across a metropolitan, regional, or global distance. The required outcome is geographically separated site connectivity. The role matches.
Incorrect Answers
Answer B is incorrect because Small office/home office architecture typically consolidates common edge and LAN functions to minimize cost and operational complexity. Its proper use differs: It fits homes or small offices that need basic integrated connectivity rather than large-scale campus hierarchy. This case needs geographically separated site connectivity. The network spans distant locations rather than remaining within one local campus. It therefore fails here.
Answer D is incorrect because Collapsed-core campus architecture uses two functional tiers: access and a combined distribution/core layer. It fits designs seeking a simpler campus hierarchy with access plus collapsed distribution/core. Here, the task is geographically separated site connectivity. The network spans distant locations rather than remaining within one local campus. That option misses the required function.
Answer C is incorrect because It is appropriate when the organization wants consumable infrastructure services rather than full responsibility for the physical platform. Cloud platforms let organizations deploy resources on demand in provider facilities instead of purchasing and operating every server and network device themselves. The case instead needs geographically separated site connectivity. The network spans distant locations rather than remaining within one local campus. The roles differ.
Question 5
A five-person consulting office uses one appliance for Internet routing, firewalling, Ethernet switching, and Wi-Fi. Which architecture best characterizes the site? Choose ONE.
- Spine-leaf architecture
- SOHO architecture
- Three-tier campus architecture
- WAN architecture
Correct Answer: B
Correct Answer
Answer B is correct because A small-office/home-office design favors simplicity and may combine routing, switching, firewalling, and Wi-Fi in only one or a few devices. The task requires a simple small-office network with integrated functions. The scale and consolidated device roles are typical of a SOHO design. It is the appropriate choice.
Incorrect Answers
Answer C is incorrect because A three-tier campus separates access, distribution, and core functions into distinct architectural layers. It fits larger campuses that benefit from an independent core interconnecting several distribution blocks. Here, the task is a simple small-office network with integrated functions. The scale and consolidated device roles are typical of a SOHO design. That option misses the required function.
Answer A is incorrect because It suits data centers that need scalable, predictable paths for substantial east-west traffic. In a classic spine-leaf fabric, each leaf connects to every spine and leaf-to-leaf traffic traverses a spine. The case instead needs a simple small-office network with integrated functions. The scale and consolidated device roles are typical of a SOHO design. The roles differ.
Answer D is incorrect because Wide-area networking extends connectivity beyond one local site, commonly joining branches, offices, or data centers through service-provider transport. Its proper use differs: Its scope is site-to-site transport across distance, not the local topology inside a single office. This case needs a simple small-office network with integrated functions. The scale and consolidated device roles are typical of a SOHO design. It therefore fails here.
Question 6
A regulated workload must run on servers physically installed in the company’s own data center, where its staff controls the hardware lifecycle. Which deployment model fits? Choose ONE.
- On-premises infrastructure
- WAN architecture
- Cloud infrastructure
- SOHO architecture
Correct Answer: A
Correct Answer
Answer A is correct because On-premises infrastructure runs on hardware in facilities controlled by the organization, which retains responsibility for the physical platform and much of its lifecycle. The requirement is direct ownership and operation of the underlying platform in company facilities. Required outcome: company-controlled local physical infrastructure. This option fits.
Incorrect Answers
Answer C is incorrect because It fits rapid scaling, on-demand service consumption, or reduced ownership of physical infrastructure. Cloud infrastructure supplies provider-hosted compute, storage, and networking resources that customers can provision without owning all underlying hardware. The case instead needs company-controlled local physical infrastructure. The requirement is direct ownership and operation of the underlying platform in company facilities. The roles differ.
Answer B is incorrect because A wide area network connects LANs or sites across significant geographic distance using carrier, provider, or other long-haul connectivity. Its proper use differs: It fits communication between organizational sites in different geographic locations. This case needs company-controlled local physical infrastructure. The requirement is direct ownership and operation of the underlying platform in company facilities. It therefore fails here.
Answer D is incorrect because SOHO networks serve a small user population with compact infrastructure instead of a multi-layer enterprise campus. Choose SOHO for a modest user count and simple local-network requirements. Here, the task is company-controlled local physical infrastructure. The requirement is direct ownership and operation of the underlying platform in company facilities. That option misses the required function.
Question 7
A development team wants to create dozens of temporary virtual machines for a test week and release them afterward without purchasing servers. Which model best fits? Choose ONE.
- Cloud infrastructure
- On-premises infrastructure
- Two-tier campus architecture
- WAN architecture
Correct Answer: A
Correct Answer
Answer A is correct because Rapid on-demand provisioning with no new customer-owned hardware is a cloud characteristic. A cloud model delivers infrastructure as provider-operated services, enabling elastic consumption and reducing direct responsibility for physical equipment. The required outcome is elastic provider-hosted compute without buying the physical platform. The role matches.
Incorrect Answers
Answer B is incorrect because With on-premises deployment, the organization owns or directly operates computing and networking resources at its own sites. Its proper use differs: Choose it when ownership and operation of the underlying physical platform are part of the requirement. This case needs elastic provider-hosted compute without buying the physical platform. Rapid on-demand provisioning with no new customer-owned hardware is a cloud characteristic. It therefore fails here.
Answer C is incorrect because A two-tier campus collapses distribution and core functions into one layer above the access layer instead of deploying a separate core. It is often appropriate for a campus whose scale does not justify a dedicated core layer. Here, the task is elastic provider-hosted compute without buying the physical platform. Rapid on-demand provisioning with no new customer-owned hardware is a cloud characteristic. That option misses the required function.
Answer D is incorrect because Choose WAN architecture when the main requirement is inter-site rather than within-building connectivity. WAN connectivity links separate geographic locations so their local networks can communicate across a metropolitan, regional, or global distance. The case instead needs elastic provider-hosted compute without buying the physical platform. Rapid on-demand provisioning with no new customer-owned hardware is a cloud characteristic. The roles differ.
Question 8
A medium campus uses access switches and a collapsed distribution/core pair. Which architecture keeps the hierarchy at two functional tiers? Choose ONE.
- Three-tier campus architecture
- Two-tier campus architecture
- Cloud infrastructure
- Spine-leaf architecture
Correct Answer: B
Correct Answer
Answer B is correct because In a two-tier campus, access switches connect to a combined distribution/core tier, reducing the number of architectural layers. The task requires collapsed distribution/core with no separate core tier. The design deliberately combines distribution and core responsibilities. It is the appropriate choice.
Incorrect Answers
Answer A is incorrect because Three-tier hierarchical design places a dedicated core above distribution blocks, which in turn aggregate access networks. Choose it when scale and modularity justify distinct access, distribution, and core roles. Here, the task is collapsed distribution/core with no separate core tier. The design deliberately combines distribution and core responsibilities. That option misses the required function.
Answer D is incorrect because Choose it when server-to-server traffic and consistent fabric hop counts are central design goals. Spine-leaf data-center topology creates a consistent fabric by attaching every leaf switch to all spine switches. The case instead needs collapsed distribution/core with no separate core tier. The design deliberately combines distribution and core responsibilities. The roles differ.
Answer C is incorrect because Cloud platforms let organizations deploy resources on demand in provider facilities instead of purchasing and operating every server and network device themselves. Its proper use differs: It is appropriate when the organization wants consumable infrastructure services rather than full responsibility for the physical platform. This case needs collapsed distribution/core with no separate core tier. The design deliberately combines distribution and core responsibilities. It therefore fails here.
Question 9
A university has many buildings and needs a dedicated high-speed backbone between several distribution blocks. Which campus model is the better fit? Choose ONE.
- Two-tier campus architecture
- Three-tier campus architecture
- SOHO architecture
- WAN architecture
Correct Answer: B
Correct Answer
Answer B is correct because The traditional three-layer campus model uses separate access, distribution, and core tiers to improve modularity and scale. A separate core is appropriate when multiple distribution blocks need a modular backbone. Required outcome: a scalable hierarchy with a dedicated core. This option fits.
Incorrect Answers
Answer A is incorrect because It fits designs seeking a simpler campus hierarchy with access plus collapsed distribution/core. Collapsed-core campus architecture uses two functional tiers: access and a combined distribution/core layer. The case instead needs a scalable hierarchy with a dedicated core. A separate core is appropriate when multiple distribution blocks need a modular backbone. The roles differ.
Answer C is incorrect because Small office/home office architecture typically consolidates common edge and LAN functions to minimize cost and operational complexity. Its proper use differs: It fits homes or small offices that need basic integrated connectivity rather than large-scale campus hierarchy. This case needs a scalable hierarchy with a dedicated core. A separate core is appropriate when multiple distribution blocks need a modular backbone. It therefore fails here.
Answer D is incorrect because Wide-area networking extends connectivity beyond one local site, commonly joining branches, offices, or data centers through service-provider transport. Its scope is site-to-site transport across distance, not the local topology inside a single office. Here, the task is a scalable hierarchy with a dedicated core. A separate core is appropriate when multiple distribution blocks need a modular backbone. That option misses the required function.
Question 10
A leaf switch in a data center should reach any other leaf through one of several equal-cost spine devices. Which architecture provides that regular connectivity pattern? Choose ONE.
- SOHO architecture
- Two-tier campus architecture
- Spine-leaf architecture
- Three-tier campus architecture
Correct Answer: C
Correct Answer
Answer C is correct because The characteristic path is leaf-to-spine-to-leaf rather than a traditional campus hierarchy. A two-tier spine-leaf fabric places endpoint-facing leaf switches below a spine layer, with full leaf-to-spine connectivity. The required outcome is consistent leaf-to-spine fabric paths. The role matches.
Incorrect Answers
Answer B is incorrect because A two-tier campus collapses distribution and core functions into one layer above the access layer instead of deploying a separate core. Its proper use differs: It is often appropriate for a campus whose scale does not justify a dedicated core layer. This case needs consistent leaf-to-spine fabric paths. The characteristic path is leaf-to-spine-to-leaf rather than a traditional campus hierarchy. It therefore fails here.
Answer D is incorrect because A three-tier campus separates access, distribution, and core functions into distinct architectural layers. It fits larger campuses that benefit from an independent core interconnecting several distribution blocks. Here, the task is consistent leaf-to-spine fabric paths. The characteristic path is leaf-to-spine-to-leaf rather than a traditional campus hierarchy. That option misses the required function.
Answer A is incorrect because It suits a small location where enterprise multi-tier architecture would be unnecessary. A small-office/home-office design favors simplicity and may combine routing, switching, firewalling, and Wi-Fi in only one or a few devices. The case instead needs consistent leaf-to-spine fabric paths. The characteristic path is leaf-to-spine-to-leaf rather than a traditional campus hierarchy. The roles differ.
Question 11
A retailer connects 200 stores to regional data centers over managed carrier services. What type of architecture is primarily involved between locations? Choose ONE.
- On-premises infrastructure
- Spine-leaf architecture
- WAN architecture
- SOHO architecture
Correct Answer: C
Correct Answer
Answer C is correct because A wide area network connects LANs or sites across significant geographic distance using carrier, provider, or other long-haul connectivity. The task requires wide-area interconnection of geographically dispersed sites. Carrier-based connectivity between distant sites is a WAN use case. It is the appropriate choice.
Incorrect Answers
Answer D is incorrect because SOHO networks serve a small user population with compact infrastructure instead of a multi-layer enterprise campus. Choose SOHO for a modest user count and simple local-network requirements. Here, the task is wide-area interconnection of geographically dispersed sites. Carrier-based connectivity between distant sites is a WAN use case. That option misses the required function.
Answer B is incorrect because It suits data centers that need scalable, predictable paths for substantial east-west traffic. In a classic spine-leaf fabric, each leaf connects to every spine and leaf-to-leaf traffic traverses a spine. The case instead needs wide-area interconnection of geographically dispersed sites. Carrier-based connectivity between distant sites is a WAN use case. The roles differ.
Answer A is incorrect because An on-premises model keeps the physical infrastructure under company control rather than consuming the entire platform from a cloud provider. Its proper use differs: It is appropriate where policy or design demands organization-controlled facilities and equipment. This case needs wide-area interconnection of geographically dispersed sites. Carrier-based connectivity between distant sites is a WAN use case. It therefore fails here.
Question 12
A remote employee’s home office has a broadband router, a small switch, and one wireless access point for a handful of devices. Which architecture label is most appropriate? Choose ONE.
- Spine-leaf architecture
- WAN architecture
- Three-tier campus architecture
- SOHO architecture
Correct Answer: D
Correct Answer
Answer D is correct because Small office/home office architecture typically consolidates common edge and LAN functions to minimize cost and operational complexity. The site is small and locally integrated rather than a multi-tier enterprise campus. Required outcome: small-scale office/home networking. This option fits.
Incorrect Answers
Answer C is incorrect because Choose it when scale and modularity justify distinct access, distribution, and core roles. Three-tier hierarchical design places a dedicated core above distribution blocks, which in turn aggregate access networks. The case instead needs small-scale office/home networking. The site is small and locally integrated rather than a multi-tier enterprise campus. The roles differ.
Answer A is incorrect because Spine-leaf data-center topology creates a consistent fabric by attaching every leaf switch to all spine switches. Its proper use differs: Choose it when server-to-server traffic and consistent fabric hop counts are central design goals. This case needs small-scale office/home networking. The site is small and locally integrated rather than a multi-tier enterprise campus. It therefore fails here.
Answer B is incorrect because WAN connectivity links separate geographic locations so their local networks can communicate across a metropolitan, regional, or global distance. Choose WAN architecture when the main requirement is inter-site rather than within-building connectivity. Here, the task is small-scale office/home networking. The site is small and locally integrated rather than a multi-tier enterprise campus. That option misses the required function.
Question 13
A factory keeps latency-sensitive controllers and application servers inside its own facility because it requires direct physical custody of the hardware. Which model is being used? Choose ONE.
- WAN architecture
- Two-tier campus architecture
- On-premises infrastructure
- Cloud infrastructure
Correct Answer: C
Correct Answer
Answer C is correct because The defining requirement is physical control of servers in the organization’s facility. On-premises infrastructure runs on hardware in facilities controlled by the organization, which retains responsibility for the physical platform and much of its lifecycle. The required outcome is locally controlled company infrastructure. The role matches.
Incorrect Answers
Answer D is incorrect because Cloud infrastructure supplies provider-hosted compute, storage, and networking resources that customers can provision without owning all underlying hardware. Its proper use differs: It fits rapid scaling, on-demand service consumption, or reduced ownership of physical infrastructure. This case needs locally controlled company infrastructure. The defining requirement is physical control of servers in the organization’s facility. It therefore fails here.
Answer A is incorrect because Wide-area networking extends connectivity beyond one local site, commonly joining branches, offices, or data centers through service-provider transport. Its scope is site-to-site transport across distance, not the local topology inside a single office. Here, the task is locally controlled company infrastructure. The defining requirement is physical control of servers in the organization’s facility. That option misses the required function.
Answer B is incorrect because Choose it when a smaller campus needs hierarchy but can combine distribution and core functions. In a two-tier campus, access switches connect to a combined distribution/core tier, reducing the number of architectural layers. The case instead needs locally controlled company infrastructure. The defining requirement is physical control of servers in the organization’s facility. The roles differ.
Question 14
An analytics team needs compute capacity that can expand automatically during a monthly batch window and shrink afterward. Which deployment model best supports that behavior? Choose ONE.
- Cloud infrastructure
- SOHO architecture
- On-premises infrastructure
- WAN architecture
Correct Answer: A
Correct Answer
Answer A is correct because A cloud model delivers infrastructure as provider-operated services, enabling elastic consumption and reducing direct responsibility for physical equipment. The task requires elastic consumption of provider-hosted resources. The requirement emphasizes rapid scale-out and scale-in without owning excess hardware. It is the appropriate choice.
Incorrect Answers
Answer C is incorrect because With on-premises deployment, the organization owns or directly operates computing and networking resources at its own sites. Choose it when ownership and operation of the underlying physical platform are part of the requirement. Here, the task is elastic consumption of provider-hosted resources. The requirement emphasizes rapid scale-out and scale-in without owning excess hardware. That option misses the required function.
Answer B is incorrect because It suits a small location where enterprise multi-tier architecture would be unnecessary. A small-office/home-office design favors simplicity and may combine routing, switching, firewalling, and Wi-Fi in only one or a few devices. The case instead needs elastic consumption of provider-hosted resources. The requirement emphasizes rapid scale-out and scale-in without owning excess hardware. The roles differ.
Answer D is incorrect because A wide area network connects LANs or sites across significant geographic distance using carrier, provider, or other long-haul connectivity. Its proper use differs: It fits communication between organizational sites in different geographic locations. This case needs elastic consumption of provider-hosted resources. The requirement emphasizes rapid scale-out and scale-in without owning excess hardware. It therefore fails here.
Question 15
A campus distribution device learns and forwards Layer 2 frames but must also route between user VLANs using SVIs. Which single component type provides both capabilities? Choose ONE.
- Wireless access point
- Layer 3 switch
- Layer 2 switch
- Router
Correct Answer: B
Correct Answer
Answer B is correct because A Layer 3 switch combines Ethernet switching with hardware-based IP routing, commonly using SVIs for inter-VLAN forwarding. A multilayer switch provides the switching function and SVI-based routing on one platform. Required outcome: combined switching and local Layer 3 routing. This option fits.
Incorrect Answers
Answer C is incorrect because Use it when endpoints need Ethernet forwarding within one VLAN or broadcast domain. Layer 2 switching is MAC-based forwarding within the local broadcast domain; it does not require IP route lookup. The case instead needs combined switching and local Layer 3 routing. A multilayer switch provides the switching function and SVI-based routing on one platform. The roles differ.
Answer D is incorrect because Routing operates across Layer 3 network boundaries; router interfaces normally separate broadcast domains and forward toward remote prefixes. Its proper use differs: Choose it when the needed function is inter-network IP forwarding rather than local Layer 2 switching. This case needs combined switching and local Layer 3 routing. A multilayer switch provides the switching function and SVI-based routing on one platform. It therefore fails here.
Answer A is incorrect because The AP is the edge radio device that lets nearby 802.11 clients join the WLAN and reach the wired network. Choose it to provide local wireless coverage and association rather than to coordinate many APs centrally. Here, the task is combined switching and local Layer 3 routing. A multilayer switch provides the switching function and SVI-based routing on one platform. That option misses the required function.
Question 16
A new Internet edge device must forward traffic from the enterprise LAN toward provider-learned or static external routes. Which component is most appropriate? Choose ONE.
- Endpoint
- Layer 2 switch
- Server
- Router
Correct Answer: D
Correct Answer
Answer D is correct because The role is Layer 3 path selection at a network boundary. Routers make Layer 3 forwarding decisions from IP routes and move packets between separate IP networks. The required outcome is routing between the enterprise and an external network. The role matches.
Incorrect Answers
Answer B is incorrect because An Ethernet switch at Layer 2 builds a forwarding table from learned MAC addresses and sends frames toward the matching switch port. Its proper use differs: Its role is local frame switching; a separate Layer 3 function is needed to cross subnet boundaries. This case needs routing between the enterprise and an external network. The role is Layer 3 path selection at a network boundary. It therefore fails here.
Answer A is incorrect because An endpoint is a client-side system such as a laptop, phone, scanner, or workstation that originates or consumes network application traffic. It fits a user or edge device that consumes services rather than hosting shared infrastructure. Here, the task is routing between the enterprise and an external network. The role is Layer 3 path selection at a network boundary. That option misses the required function.
Answer C is incorrect because It is appropriate when multiple clients depend on a hosted shared function. A server hosts shared applications, data, authentication, name resolution, or other services that network clients consume. The case instead needs routing between the enterprise and an external network. The role is Layer 3 path selection at a network boundary. The roles differ.
Question 17
An access switch receives a unicast frame whose destination MAC is already in the same VLAN’s MAC table. Which component behavior forwards it only to the mapped egress port? Choose ONE.
- Router
- Layer 2 switch
- Wireless/network controller
- Next-generation firewall
Correct Answer: B
Correct Answer
Answer B is correct because A Layer 2 switch learns source MAC addresses and uses its MAC table to forward Ethernet frames inside a VLAN. The task requires MAC-table-based Ethernet frame forwarding. Known-unicast forwarding is a Layer 2 switch function. It is the appropriate choice.
Incorrect Answers
Answer A is incorrect because A router connects distinct IP subnets, selecting a next hop from its routing information rather than forwarding only by MAC address. Its natural use is path selection between subnets or remote networks. Here, the task is MAC-table-based Ethernet frame forwarding. Known-unicast forwarding is a Layer 2 switch function. That option misses the required function.
Answer C is incorrect because It fits environments that need coordinated settings and operations across many access points. A wireless or network controller centralizes configuration, policy, monitoring, and often RF or lifecycle management for managed devices. The case instead needs MAC-table-based Ethernet frame forwarding. Known-unicast forwarding is a Layer 2 switch function. The roles differ.
Answer D is incorrect because NGFW policy can evaluate more than addresses and ports, adding application-aware and identity-aware inspection to stateful firewall controls. Its proper use differs: Choose it for perimeter or segmentation enforcement that needs richer context than a simple port-and-address rule. This case needs MAC-table-based Ethernet frame forwarding. Known-unicast forwarding is a Layer 2 switch function. It therefore fails here.
Question 18
A campus security policy must distinguish approved SaaS applications from unsanctioned ones and apply user-aware rules. Which device type should implement the policy? Choose ONE.
- Wireless access point
- Intrusion prevention system (IPS)
- Next-generation firewall
- Router
Correct Answer: C
Correct Answer
Answer C is correct because Next-generation firewalls enforce traffic policy with Layer 3/4 state plus deeper application, user, content, and threat context. The requirement goes beyond basic packet forwarding or signature-only prevention. Required outcome: identity- and application-aware traffic policy. This option fits.
Incorrect Answers
Answer B is incorrect because Choose IPS when the central task is active prevention of recognized malicious network behavior. IPS technology analyzes passing traffic for exploit indicators and can actively prevent matching malicious sessions before they reach a target. The case instead needs identity- and application-aware traffic policy. The requirement goes beyond basic packet forwarding or signature-only prevention. The roles differ.
Answer D is incorrect because Routing operates across Layer 3 network boundaries; router interfaces normally separate broadcast domains and forward toward remote prefixes. Its proper use differs: Choose it when the needed function is inter-network IP forwarding rather than local Layer 2 switching. This case needs identity- and application-aware traffic policy. The requirement goes beyond basic packet forwarding or signature-only prevention. It therefore fails here.
Answer A is incorrect because A wireless access point supplies the 802.11 radio interface that associates Wi-Fi clients and bridges their traffic into the wired LAN. Use an AP when the requirement is actual Wi-Fi client connectivity at a location. Here, the task is identity- and application-aware traffic policy. The requirement goes beyond basic packet forwarding or signature-only prevention. That option misses the required function.
Question 19
An inline appliance is dedicated to detecting exploit payloads and stopping attack flows. It is not the organization’s primary firewall. Which role is the best match? Choose ONE.
- Wireless/network controller
- Intrusion prevention system (IPS)
- Next-generation firewall
- Server
Correct Answer: B
Correct Answer
Answer B is correct because A dedicated IPS is designed around recognizing and preventing malicious traffic. An inline intrusion prevention sensor combines attack detection with an enforcement action such as blocking packets or terminating a suspicious flow. The required outcome is specialized inline intrusion detection and blocking. The role matches.
Incorrect Answers
Answer C is incorrect because A next-generation firewall extends stateful filtering with context such as application identity, user identity, URL categories, and often integrated threat prevention. Its proper use differs: It is suitable when security policy must distinguish applications, users, or content at a boundary. This case needs specialized inline intrusion detection and blocking. A dedicated IPS is designed around recognizing and preventing malicious traffic. It therefore fails here.
Answer A is incorrect because Controllers coordinate a fleet of managed access points or other network devices from a common management and policy plane. Use a controller when centralized policy or lifecycle management across a device fleet is the key need. Here, the task is specialized inline intrusion detection and blocking. A dedicated IPS is designed around recognizing and preventing malicious traffic. That option misses the required function.
Answer D is incorrect because Choose server when the primary responsibility is providing an application or infrastructure service to other systems. Servers provide resources or application functions to multiple client systems over the network. The case instead needs specialized inline intrusion detection and blocking. A dedicated IPS is designed around recognizing and preventing malicious traffic. The roles differ.
Question 20
A meeting-room device advertises an SSID and handles the radio association of nearby laptops. What is the device? Choose ONE.
- Wireless access point
- Router
- Wireless/network controller
- Endpoint
Correct Answer: A
Correct Answer
Answer A is correct because Access points provide the RF connection used by wireless stations, then connect those client frames to the distribution network. The task requires 802.11 client association and radio access. The described function occurs at the local wireless access point. It is the appropriate choice.
Incorrect Answers
Answer C is incorrect because Centralized controllers push consistent settings and collect operational state for multiple managed network devices instead of serving as the clients’ radio itself. Its role is fleet-wide coordination and control, not providing the individual endpoint’s Wi-Fi radio link. Here, the task is 802.11 client association and radio access. The described function occurs at the local wireless access point. That option misses the required function.
Answer B is incorrect because This is appropriate when traffic must cross from one IP network to another. Routers make Layer 3 forwarding decisions from IP routes and move packets between separate IP networks. The case instead needs 802.11 client association and radio access. The described function occurs at the local wireless access point. The roles differ.
Answer D is incorrect because Endpoints sit at the network edge and use services; common examples include user computers, mobile devices, printers, and scanners. Its proper use differs: Choose endpoint when the described system is the client itself, not a network intermediary or shared application host. This case needs 802.11 client association and radio access. The described function occurs at the local wireless access point. It therefore fails here.