Cisco Certified Network Associate (CCNA) Practice Exam

Disable ads (and more) with a membership for a one time $2.99 payment

Study for the Cisco Certified Network Associate (CCNA) exam with our comprehensive quiz featuring multiple-choice questions and detailed explanations. Prepare effectively and enhance your understanding of networking concepts!

Practice this question and more.


Which three statements about HSRP operation are true?

  1. The virtual IP address and virtual MAC address are active on the HSRP Master router.

  2. HSRP supports only clear-text authentication.

  3. HSRP supports up to 255 groups per interface.

  4. The HSRP virtual IP address must be on a different subnet than the routers' interfaces on the same LAN.

The correct answer is: The virtual IP address and virtual MAC address are active on the HSRP Master router.

The statement about the virtual IP address and virtual MAC address being active on the HSRP Master router is accurate. In the Hot Standby Router Protocol (HSRP) operation, there is one active router, known as the Master router, which handles all traffic destined for the virtual IP address. This Master router's use of the virtual IP address allows clients to send their packets to a single address, which is not tied to any single physical router, thus providing redundancy and failover capabilities. The virtual MAC address, associated with the virtual IP, will also be used by this Master router to forward packets, ensuring seamless communication for network devices. While HSRP does offer some authentication mechanisms, it does not only support clear-text authentication. In fact, it also supports MD5 authentication, which adds an additional layer of security between the routers involved in HSRP. The limitation of HSRP to 255 groups per interface is incorrect as it can support much more under certain configurations depending on the network architecture and the equipment used. Finally, the assertion regarding the HSRP virtual IP address being on a different subnet than the routers' interfaces is misleading. The virtual IP address should be in the same subnet as the routers' interface addresses to allow devices