Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-501 Exam - Topic 1 Question 111 Discussion

Refer to the exhibit:Router 1 was experiencing a DDoS attack that was traced to interface gjgabitethernet0/1.Which statement about this configuration is true?
D) Router 1 accepts source addresses that have a match in the FIB that indicates it is reachable through a real interface
A) Router 1 drops all traffic that ingresses interface gigabitethernet0/1 that has a FIB entry that exits a different interface
B) Router 1 accepts source addresses on interface gigabitethemet0/1 that are private addresses
C) Router 1 accepts all traffic that ingresses and egresses interface gigabitethernet0/1

Cisco 350-501 Exam - Topic 1 Question 111 Discussion

Actual exam question for Cisco's 350-501 exam
Question #: 111
Topic #: 1
[All 350-501 Questions]

Refer to the exhibit:

Router 1 was experiencing a DDoS attack that was traced to interface gjgabitethernet0/1.

Which statement about this configuration is true?

Show Suggested Answer Hide Answer

Contribute your Thoughts:

0/2000 characters
Nickole
9 months ago
B seems off, private addresses shouldn't be accepted like that.
upvoted 0 times
...
Lettie
9 months ago
I think D is more accurate, it focuses on reachable addresses.
upvoted 0 times
...
Alfreda
9 months ago
C is incorrect, it wouldn't accept all traffic like that.
upvoted 0 times
...
Alise
9 months ago
Wait, can it really drop all that traffic? Sounds too strict!
upvoted 0 times
...
Fletcher
9 months ago
A is definitely true, it drops traffic not matching the FIB.
upvoted 0 times
...
Regenia
10 months ago
C seems too broad; I don't think all traffic would be accepted, especially during an attack.
upvoted 0 times
...
Jesse
10 months ago
I feel like B could be a trap answer. Private addresses are usually filtered, right?
upvoted 0 times
...
Onita
10 months ago
I remember practicing a question like this where the FIB entries were crucial. I might lean towards D, but I need to double-check.
upvoted 0 times
...
Ronald
10 months ago
I think option A sounds familiar, but I'm not entirely sure if it applies to DDoS scenarios specifically.
upvoted 0 times
...
Johnetta
11 months ago
This is a good opportunity to apply my knowledge of router access control and security features. I'll need to carefully consider each answer choice and how it aligns with best practices for mitigating DDoS attacks.
upvoted 0 times
...
Viki
11 months ago
Okay, the key seems to be understanding how Router 1 handles traffic that comes in on the gigabitethernet0/1 interface. I'll need to think through the different options and how they relate to the DDoS scenario.
upvoted 0 times
...
Tasia
11 months ago
Hmm, the question is asking about the behavior of Router 1 specifically. I'll need to focus on the information provided about that router and the interface experiencing the DDoS attack.
upvoted 0 times
...
Amie
11 months ago
This looks like a tricky one. I'll need to carefully read through the question and options to make sure I understand the key details about the DDoS attack and the router configuration.
upvoted 0 times
...
Yuriko
1 year ago
Can't we just unplug the router and call it a day? No wonder they're getting DDoS'd with these outdated configs.
upvoted 0 times
Tiara
1 year ago
Let's focus on implementing proper security measures instead of taking drastic actions.
upvoted 0 times
...
Elza
1 year ago
Unplugging the router won't solve the issue, we need to address the root cause.
upvoted 0 times
...
Breana
1 year ago
We need to update the configuration to prevent future attacks.
upvoted 0 times
...
...
Salina
1 year ago
Ha! I bet the routers just have a bunch of 'duct tape and bailing wire' holding them together. Option C is my pick.
upvoted 0 times
...
Lasandra
1 year ago
I'm leaning towards Option B. If this is a DDoS attack, the router should block private addresses to mitigate the issue.
upvoted 0 times
Diego
1 year ago
User 3: I'm not sure, but Option D also sounds plausible. It mentions accepting source addresses that are reachable through a real interface.
upvoted 0 times
...
Bette
1 year ago
User 2: I agree with Bette. Option A seems like the most logical choice.
upvoted 0 times
...
Katy
1 year ago
User 1: I think Option A is correct. The router drops traffic with FIB entries that exit a different interface.
upvoted 0 times
...
Dorthy
1 year ago
User 3: I'm not sure, but Option B does make sense. Blocking private addresses could help prevent the DDoS attack.
upvoted 0 times
...
Quentin
1 year ago
User 2: I disagree, I believe Option D is the right choice. The router only accepts source addresses that are reachable through a real interface.
upvoted 0 times
...
Helaine
1 year ago
User 1: I think Option A is correct. The router drops traffic with FIB entries that exit a different interface.
upvoted 0 times
...
...
Heike
1 year ago
Hmm, I think Option D is the correct answer. The router should only accept traffic with valid FIB entries, not just any private addresses.
upvoted 0 times
Wendell
1 year ago
Yeah, I see your point. Option D provides a more secure configuration for the router.
upvoted 0 times
...
Margot
1 year ago
I think Option D is still the best choice because it ensures that the source addresses are reachable through a real interface.
upvoted 0 times
...
Anissa
1 year ago
But what about Option A? It mentions dropping traffic with FIB entries that exit a different interface.
upvoted 0 times
...
Olene
1 year ago
I agree, Option D seems to be the most logical choice.
upvoted 0 times
...
...
Tammi
1 year ago
That's a good point, but I still think D is the correct answer based on the configuration provided in the exhibit.
upvoted 0 times
...
Daryl
1 year ago
I disagree, I believe the answer is A because dropping traffic with a FIB entry that exits a different interface would help prevent DDoS attacks.
upvoted 0 times
...
Fletcher
1 year ago
Option A sounds reasonable, but I'm not sure if it's the complete answer. We need more context on the DDoS attack and the router's configuration.
upvoted 0 times
...
Tammi
1 year ago
I think the answer is D because it makes sense to only accept traffic from a source address that is reachable through a real interface.
upvoted 0 times
...

Save Cancel