ECMS MS Switching and Network Segmentation 2 — Questions and Answers
Question 1: What Meraki MS capability provides automatic VLAN assignment based on 802.1X authentication results from a RADIUS server?
- Static VLAN configuration
- Dynamic VLAN assignment via RADIUS attributes (Correct answer)
- LLDP-based VLAN negotiation
- Auto-trunk VLAN learning
Correct answer: Dynamic VLAN assignment via RADIUS attributes
When 802.1X authentication succeeds, the RADIUS server can return a VLAN ID attribute that Meraki MS uses to dynamically place the port into the appropriate VLAN.
Question 2: What is the function of 'Link Aggregation (LAG)' on Meraki MS switches?
- It reduces the number of VLANs needed on uplink ports
- It combines multiple physical ports into a single logical link for increased bandwidth and redundancy (Correct answer)
- It automatically backs up switch configuration to the cloud
- It prioritizes voice traffic across aggregated uplinks
Correct answer: It combines multiple physical ports into a single logical link for increased bandwidth and redundancy
Link aggregation (IEEE 802.3ad LACP) combines multiple physical switch ports into one logical link, increasing bandwidth capacity and providing fault tolerance if one member link fails.
Question 3: Which Meraki dashboard feature provides a topology view showing how MS switches are interconnected with other Meraki devices?
- Organization > Inventory
- Monitor > Topology (Correct answer)
- Switch > Port schedule
- Network > Alerts
Correct answer: Monitor > Topology
The Meraki Monitor > Topology view automatically discovers and displays the physical connections between Meraki switches, APs, and MX appliances using LLDP data.
Question 4: What Meraki MS feature helps prevent rogue DHCP servers from distributing addresses on the network?
- DHCP relay agent configuration
- DHCP snooping (Correct answer)
- Static ARP entries
- Gratuitous ARP blocking
Correct answer: DHCP snooping
DHCP snooping on Meraki MS switches validates DHCP messages and only forwards DHCP offers/acknowledgments received on trusted (uplink) ports, blocking unauthorized DHCP servers.
Question 5: In Meraki switching, what does 'Dynamic ARP Inspection (DAI)' protect against?
- Spanning tree topology changes
- ARP poisoning/spoofing attacks where a malicious device sends falsified ARP replies (Correct answer)
- Unauthorized VLAN hopping attacks
- Broadcast storms from looped cables
Correct answer: ARP poisoning/spoofing attacks where a malicious device sends falsified ARP replies
DAI intercepts ARP packets and validates them against the DHCP snooping binding table, dropping ARP packets with IP-to-MAC mappings that don't match the binding database.
Question 6: What Meraki MS feature allows administrators to disable or enable switch ports on a time schedule?
- Port power scheduling
- Port scheduling (access control by time) (Correct answer)
- PoE time-based control
- MAC address time lockout
Correct answer: Port scheduling (access control by time)
Meraki port scheduling allows administrators to define time-based schedules that automatically enable or disable switch ports during specified hours or days.
What Meraki MS capability provides automatic VLAN assignment based on 802.1X authentication results from a RADIUS server?