nerdexam
Cisco

350-601 · Question #177

An engineer configures a storage environment for a customer with high-security standards. The secure environment is configured in VSAN 50. The customer wants to maintain a configuration and active…

The correct answer is C. fabric-binding activate vsan 50 force E. port-security enable. Two requirements are stated: (1) Prevent unauthorized switches from joining the fabric by maintaining a configuration and active database - this is addressed by Fabric Binding. Option C ('fabric-binding activate vsan 50 force') activates the fabric binding database for VSAN 50…

Storage Network

Question

An engineer configures a storage environment for a customer with high-security standards. The secure environment is configured in VSAN 50. The customer wants to maintain a configuration and active databases and prevent unauthorized switches from joining the fabric. Additionally, the switches must prevent rogue device from connecting to their ports by automatically learning the WWPNs of the ports connected to them for the first time. Which configuration sets must be used to meet these requirements? (Choose two.)

Options

  • Afcsp enable
  • Bfcsp dhchap hash md5 sha1
  • Cfabric-binding activate vsan 50 force
  • Dclear fabric-binding activate vsan 50
  • Eport-security enable

How the community answered

(37 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    81% (30)
  • D
    11% (4)

Explanation

Two requirements are stated: (1) Prevent unauthorized switches from joining the fabric by maintaining a configuration and active database - this is addressed by Fabric Binding. Option C ('fabric-binding activate vsan 50 force') activates the fabric binding database for VSAN 50, enforcing that only listed switches can join the fabric. The 'force' keyword is needed when activating if there are discrepancies. (2) Prevent rogue devices from connecting to switch ports by automatically learning WWPNs - this is addressed by Port Security. Option E ('port-security enable') enables port security, which auto-learns connected device WWPNs on first connection and blocks any subsequent unauthorized devices. FCSP (Options A/B) provides authentication between switches but does not auto-learn WWPNs or restrict fabric membership by database. Option D clears the fabric binding database, which is the opposite of what is needed.

Topics

#Fabric Binding#Port Security#Fibre Channel#SAN security

Community Discussion

No community discussion yet for this question.

Full 350-601 Practice