Maybe this is the configurations on Router and Switch (but notice that they are surely missing something):


no service password-encryption
enable password cisco
username ciscouser privilege 15 password 0 cisco
banner motd ^CWelcome! If you encountered any problem, please consult the administrator^C
line vty 0 4
password 4t&34rkf
login local
transport input telnet ssh


no service password-encryption
hostname switch1
enable password cisco
username ciscouser password 0 cisco
ip domain-name cisco.com

banner login ^c
************ welcome to Switch1. If you encountered any problem, please consult the administrator ************* ^c

line con 0
line vty 0 4
login local
transport input ssh
line vty 5 15
login local
transport input ssh

Note: This is just what we gather and guess. In the exam the configurations may be different so make sure you understand about “enable secret”, “enable password”, “login”, “login local”, “transport input”, “line vty”, “service password-encryption”, “bannder motd”, “privilege” before taking this exam!

This sim has 4 questions:

Question 1


There are 16 VTY lines (from 0 to 4 and 5 to 15) so there are more than 5 simutaneous remote connections can be made at the same time -> A is not correct.
There is no restriction on on the Switch so remote networks can connect to this switch -> C is not correct.
There is no config under “line con 0” so console access to this switch does not require a passowrd -> D is not correct.
All 16 VTY lines are configured to access via SSH only and all of them require a password. The difference is in the “line vty 0 4” configuration, the type of login is specified as “login local”. It means that the switch will not use the password configured under “line vty 0 4” (in this case none was set but it will use the user & password configured in “username ciscouser password 0 cisco” command -> B is correct.

Question 2


A is correct as we can telnet from line 0 to line 4 (line vty o 4).

We can use both telnet and SSH to connect to this router (transport input telnet ssh) -> B is not correct.

C is correct as we can telnet to it.

D is not correct because by default, the timeout is set to 10 minutes on both the console and the vty ports.

E is not correct as NAT can be used even DHCP is not used.

Question 3


Privilege mode on RouterA is protected with unencrypted password (via “enable password” command). Although this is a good choice but it is not the answer Cisco wants. Answer B is a correct answer instead. This can be explained by this way:

The wording in the banner is inappropriate as it “Welcomes” you to the network. If you are gaining unauthorised access to the device, the first thing you will see is a banner welcoming you. Apparently there has been a case (or cases) where a hacker has used this as a legal defence for gaining illegitimate access to the device. The banner should say something along the lines of “NO UNAUTHORISED ACCESS”.

The password of VTY lines is “4t&34rkf”. Although it is unencrypted but it is not a weak password because it has number & special characters inside -> C is not correct.

Although a password of “4t&34rkf” is configured but with the command “login local”, router will use the username of “ciscouser” & password of “cisco” (configured in “username ciscouser privilege 15 password 0 cisco” command) -> D is correct.

By checking the configuration of routerA with the “show run” command. To support web server access it must have the command “ip http server” but it does not -> E is not correct.

Question 4


The command “no service password-encryption” exists so the password to access privilege mode is not encrypted -> A is correct.

With the “login local” command the VTY lines will require both username and password -> C is not correct.

The username and password are easy to guess as they have common words like “cisco” and “user” -> D is correct.

In all VTY lines only SSH is allowed with the “transport input ssh” -> E is not correct.

To grant privilege level of 15 by default the following commands are required:

line vty 0 4
privilege level 15

or these lines:

username ciscouser privilege 15 password cisco


login local (in “line vty 0 4”)

but none can be found so F is not correct.

    I took exam today 8-31-2016 and I Passed ICND1 exam . 897/1000 .The Sim was similar to this one that shows here ( about router and Switch Secuirty) . so read it carefully . Another Sims had R1,R2,R3 with RIP configuration and then they had problem in DHCP scope , (which was configured wrong) ; they put ACL in one of the routers that was blocking the people to access Server ; and another Topic was in NAT ( the Interesting traffic was wrong) and another Concet of NTP . No need to do any configuration only show commands . It was time consuming and Had to use a lot of show run and Show ip int brief to find answer, I had two Sim with only show commands on ICND1 Exams. I studies old ICND1 exam PDF and I was able to pass it. Few Questions on Ip address , but some more question about NTP server.

    What are your thoughts on the questions below:

    Which option is a valid hostname for a switch?

    Which MTU size can cause a baby giant error?

    Which statement about native VLAN traffic is true?

    A.Cisco Discovery Protocol traffic travels on the native VLAN by default.
    B.Traffic on the native VLAN is tagged with 1 by default.
    C.Control plane traffic is blocked on the native VLAN.
    D.The native VLAN is typically disabled for security reasons.

    Which value is indicated by the next hop in a routing table?
    A.preference of the route source
    B.IP address of the remote router for forwarding the packets
    C.how the route was learned
    D.exit interface IP address for forwarding the packets

    Which RFC was created to alleviate the depletion of IPv4 public addresses

    A.RFC 4193
    B.RFC 1519
    C.RFC 1518
    D.RFC 1918

    Which NTP command configures the local device as an NTP reference clock source?
    A.ntp peer
    B.ntp broadcast
    C.ntp master
    D.ntp server

  14. Anonymous:
    November 19th, 2016

    1) Hostnames can’t start with a number, and can’t have special characters (bangs/exclamation) (but can have a dash). A) starts with a number. B) has a bang at the end. C) starts with a number. Only D) is correct.

    2) a standard frame is 1500 bytes. Baby Jumbo Frames are anything SLIGHTLY larger than 1500, up to 1600 bytes. Jumbo Frames are between 1600 and 9000 bytes. Super Jumbo frames are lager than 9000 bytes of payload. So, to answer this question: Just look at which MTU setting is slightly larger than 1500 MTUs, and that would be D) 1518.

    3) This question is about Native VLAN. The native VLAN is the VLAN that is configured for packets that don’t have a tag. The default native VLAN on all Cisco Switches is VLAN 1. It is always enabled by default. These settings can all be changed: That is: you can designate a different VLAN as the native VLAN, disable VLAN 1, etc. Knowing that, we can eliminate D) as the correct answer because it is enabled by default. We can also eliminate B) because Native VLAN packets don’t get tags by default (you can change this). Finally, Control Plane traffic is never blocked on Native VLAN 1, and even if you change the Native VLAN, the control plane traffic still comes across VLAN 1. That eliminated answer C) – leaving A) as the only answer.

    4) The next hop is the IP address of the next router that the packet has to be forwarded to, in order for it to eventually reach it’s destination. This pretty much leaves us with only one logical answer: B)

    RFC 4193 is about Unique Local IPv6 Unicast Addresses.
    RFC 1519: Classless Inter-Domain Routing (CIDR): an Address Assignment and Aggregation Strategy .
    RFC 1518: An Architecture for IP Address Allocation with CIDR.
    And RFC 1918: Address Allocation for Private Internets.

    Since we’re talking about Public, not private addresses, we can eliminate answer D. Since we’re talking about IPv4, we can also eliminate Answer A. Answer C can also be eliminated because the RFC is about the architecture for IP address allocation… leaving just Answer B as the correct choice.

    6) Last- NTP: NTP is the Network Time Protocol, which is how devices get time updates. A Master server (If you’re using public NTP, there are several of them) uses an atomic clock or GPS signal to keep itself on time. It also passes that time info down to properly configured NTP Peers. An NTP Server, is a router or other device that is authorized to pass on the time info to other devices. They can be several layers deep – meaning: The master passes time data to Router’s 1 and 2. Router 1 is a server, and passes that same data on to Router A and B. Router A passes the info onto a switch. and so on. All the servers, usually have several peers they refer to (other servers) to compare the times across the board. Any that are “insane” are rejected outright. Anyway the command to make a router a server is simply Answer D) which tells the router it is the source of NTP on it’s network. Note: It will have a master for NTP unless it is the master (meaning it has an atomic clock or GPS attached to it.)

