ETExamTower
Q13IP Services

R1, acting as an NTP server, must have the following: - NTP authentication enabled - NTP packets sourced from interface Loopback 0 - NTP stratum 2 - NTP packets permitted only to client IP `209.165.200.225` How should R1 be configured?

← → navigate · a answer
Community votes
C
80% (4)
D
20% (1)
A
0% (0)
B
0% (0)
Discussion · 24
21
C looks right, this is an acl question. 10 is a standard acl number so A and D are wrong because they are extended acls. NTP Master 2 makes the router an ntp server with stratum lvl 2.
C 7
Selected Answer: C It can't be D because stratum is not a valid command.
6
I just realized, its 100% C because access-list 10 is a standard access-list, so specifying the protocol (udp) and destination address as any with the eq port number wouldn't be allowed. C is the correct answer 100%
6
D has the command NTP stratum 2 (not a real command) it should be ntp master 2
5
Its not d, because access list 10 is standar and cannot configure ports on this
4
In my opinion, both C and D are correct answers, the only difference is that the access-list is more granular for D, meaning C is probably the better option. C. ntp authenticate ntp authentication-key 2 md5 CISCO123 ntp source Loopback0 ntp access-group server-only 10 ntp master 2 access-list 10 permit 209.165.200.225 D. ntp authenticate ntp authentication-key 2 md5 CISCO123 ntp source Loopback0 ntp access-group server-only 10 ntp stratum 2 access-list 10 permit udp host 209.165.200.225 any eq 123
C 4
Selected Answer: C explained below
3
Note ntp access-group serve-only is the correct command not server-only, but it's incorrect on every answer so it shouldn't matter. Source: https://www.cisco.com/c/en/us/td/docs/routers/crs/software/crs_r4-0/system_management/command/reference/yr40crs_chapter10.html#wp1797670550:~:text=Allows%20only%20time%20requests. A. Incorrect because sha1 isn't used for NTP authentication, must be MD5 ntp authenticate ntp authentication-key 2 sha1 CISCO123 ntp source Loopback0 ntp access-group server-only 10 ntp master 2 access-list 10 permit udp host 209.165.200.225 any eq 123
3
B. Incorrect because it isn't using the NTP source command (uses ntp interface Loopback0) instead ntp authenticate ntp authentication-key 2 md5 CISCO123 ntp interface Loopback0 ntp access-group server-only 10 ntp stratum 2 access-list 10 permit 209.165.200.225
3
Good Catch !
3
try to login to any router, i think we cannot insert any stratum 2 , only master 2 can. and for ntp access-group server-only 10,, i should serve-only 10.. anyway Answer is C. agree with MDK94
2
The ACL granularity shouldn't be required since the acl is being applied to "serve-only" aka only allow time requests Source: https://www.cisco.com/c/en/us/td/docs/routers/crs/software/crs_r4-0/system_management/command/reference/yr40crs_chapter10.html#wp1797670550:~:text=Allows%20only%20time%20requests.
2
you got a point but something pops up on my mind: the acl command is using standard numbered acl which ranges between 1 to 99 and as i studied the standard use only source ip so correct me if im wrong
2
Letter C ang sagot
2
C should be right
C 2
Selected Answer: C ntp master <stratum-level> global configuration command is the right way to set the stratum value.
2
C is correct. standard access lists do not specifically filter by protocol.
2
D is correct NTP uses UDP port 514
1
I thought the question is about NTP, but it's NOT.
D 1
Selected Answer: D Pretty sure it's D because it says Only NTP packets are allowed and on the access list command on D it specifies only allow traffic on port 123.
1
Also, since the NTP access group is set to server-only, time requests are allowed only from a device whose IP address meets the access list criteria.
1
But they missed the word "host" or the wildcard mask (0.0.0.0) in the ACL: access-list 10 permit 209.165.200.225
1
NTP stratus is NOT a valid cisco command. NTP master [stratum level]
1
C is the right answer. In D, the configuration of the startum value is wrong.