Soal Mtcna Pandu
Soal Mtcna Pandu
Soal Mtcna Pandu
You want to transfer existing '/ip firewall filter' configuration from one router to a new
system. Choose the best possible way to do:
A. Export only '/ip firewall filter'
B. Create backup only of '/ip firewall filter' rules
C. Create backup, edit backup file and restore on target
router
D. Export global configuration and remove everything
apart from '/ip firewall filter'
Jawab :a
Penjelasan : karena untuk menambahkan nama fitur
tersebut untuk export yang lebh spesifik
ssss
2.
A. Five
B. One
C. Two
D. Unlimited
Jawab : b
Penjelasan ; setiap interface hanya mendappat jatah 1
untuk setiap interface
Jawab : b
Penjelasan : karena dia termasuk dalam range yang
sama dan juga paling spesifik
Jawaban yang A dan c tidak termasuk karena mereka
kurang spesifik,
0 dst-address=10.0.0.0/24 gateway=10.1.5.126
1 dst-address=10.1.5.0/24 gateway=10.1.1.1
2 dst-address=10.1.0.0/24 gateway=25.1.1.1
3 dst-address=10.1.5.0/25 gateway=10.1.1.2
Which gateway will be used for a packet with destination address 10.1.5.126?
A. 10.1.5.126
B. 10.1.1.1
C. 10.1.1.2
D. 25.1.1.1
Jawab : c
Penjelasan : karena dia termasuk dalam range yang
sama dan juga paling spesifik
Jawaban yang A,B dan D tidak termasuk karena
mereka kurang spesifik
JAWAB :d
Penjelasan : karena port pptp berjalan pada tcp 1723
bukan udp
6. There are two wireless cards (wlan1 and wlan2) which are bridged together. On wlan1
card there is a setting "Forwarding=no". Choose the correct answer(s):
A. Stations on wlan2 will be able to communicate with
stations on wlan2
B. Stations on wlan2 will be able to communicate with
stations on wlan1
C. Stations on wlan1 will be able to communicate with
stations on wlan1
D. To prevent communication between wlan1 and
wlan2 one cannot use Bridge Filters
E. Stations on wlan1 will be able to communicate with
stations on wlan2
7. Consider a wireless access point with mode=ap-bridge. What is the maximum number of
concurrent clients that can connect to it?
A. 2007
B. 2012
C. 2048
D. 1024
8. Consider the following diagram. We want to communicate from a device on LAN1 to a
device on LAN2. Assuming that all necessary configurations are already included on R2,
which of the following configurations in R1 would enable this communication?
A. /ip route add dst-address=192.168.1.0/24 src-
address=192.168.0.0/24 gateway=192.168.99.2
B. /ip route add dst-address=0.0.0.0/0 gateway=Ether1
C. /ip route add dst-address=192.168.0.0/24
gateway=192.168.0.1
D. /ip route add dst-address=192.168.1.0/24
gateway=192.168.99.2
E. /ip route add dst-address=0.0.0.0/0
gateway=192.168.99.2
Jawab : B,D.E
Penjelasan: semuanya benar karena ,
B. bisa memakai interface,
D. konfigurasi static routing yang lengkap
E. bisa memakai efault route
Jawab : A,B,D
Penjelasan : ppp secret berfungsi untuk membuat user
an password untuk proses tunneling
Jawab : c
Penjelasan : karena untuk menjalankan fungsi diatas
mesti dipasang dibridge tersebut
Jawab : c
Penjelasan : karena total itu merupakan upload +
download
Jawab : D
Penjelasan : log itu fungsi mencatat, bukan memblok
ataupun mengijinkan data untuk leat
14. How many different priorities can be selected for queues in MikroTik RouterOS?
A. 1
B. 16
C. 0
D. 88
Jawab : d
Penjelasan : priority terbesar yang dapat diberikan pada
client adlah 8 semakin kecil angkanya semaikn I
prioritaskan
A. wireless
B. advanced-tools
C. dhcp
D. routing
E. System
Jawab : A dan E
Penjelasan : karena untuk sekedar menghubungkan ap-
stasion tidak dibutuhkan dhcp (untuk membagikan ip)
dan juga routing (karena bisa memakai satu network
yang sama)
17. For static routing functionality, additionally to the RouterOS 'system' package, you will
also need the following software package:
A. no extra package required
B. advanced-tools
C. dhcp
D. Routing
Jawab : A
Penjelasan :jika hanya static routing tidak memerlukan
paket tambahan/extra package
Jawab : B,C,D,F
Penjelasan :
H. Ssid
Jawab : g
Penjelasan : jika hanya sekedar terhubung kita hanya
mememrlukan band yang sama
21. What is the correct action for a NAT rule on a router that should intercept SMTP traffic
and send it over to a specified mail server?
A. redirect
B. passthrough
C. dst-nat
D. Tarpit
Jawab : c
Karena : paket ingin DIOPER ke mail server
22. PPPoE server only works within one Ethernet broadcast domain that it is connected to. If
there is a router between server and end-user host, it will not be able to create PPPoE tunnel
to that PPPoE server.
false
24. Where should you upload new MikroTik RouterOS version packages for upgrading
router?
A. FTP root directory or /files directory of the router
B. System Package menu
C. Any directory in /files
D. System Backup menu
Jawab : c
Penjelasan : karena setiap upgrade akan diletakan I
directory file
25. During a scan, in order to see all the available wireless frequencies that are supported by
the card, the following option must be selected in the wireless card's "Frequency Mode":
A. regulatory domain
B. superchannel
C. manual txpower
Jawab A
Penjelasan : karena memberi limit terhadap channel
yang tersedia dan maximum transit sesuai dengan
Negara masing2
2. When using routing option 'check-gateway=ping' after how many timeouts is gateway
considered unreachable:
A. 1
B. 3
C. 2
D. 4
Jawab : c
Penjelasan :
Jawab :b
Penjelasan : priority terbesar yang dapat diberikan pada client adlah 8 semakin kecil
angkanya semaikn I prioritaskan
A. Default Forward
B. Default Authenticate
C. Security Profile
D. Enable Access List
Jawab : b
Penjelasan : karena dengan default authenticate semua bisa connect ke ap tersebut
A. 192.168.0.1-192.168.0.255
B. 192.168.0.1-192.168.0.99,192.168.0.101-192.168.0.254
C. 192.168.0.1-192.168.0.14
D. 192.169.0.1-192.169.0.254
Jawab : b dan c
Penjelasan : karena untuk jawaban A dan D akan terjai overlap ip (ip gateway tidak
dipisah)
7. There can be more than one PPPoE server in a single broadcast domain:
true
Jawab : true
Penjelasa: karena dalam satu broadcast domain bisa menjalankan lebih dari satu point to
point dalam satu network
8. There are two wireless cards (wlan1 and wlan2) which are bridged together. On wlan1
card there is a setting "Forwarding=no". Choose the correct answer(s):
A. To prevent communication between wlan1 and wlan2 one cannot use Bridge Filters
B. Stations on wlan2 will be able to communicate with stations on wlan1
C. Stations on wlan1 will be able to communicate with stations on wlan2
D. Stations on wlan1 will be able to communicate with stations on wlan1
E. Stations on wlan2 will be able to communicate with stations on wlan2
9. When viewing the routes in Winbox, some routes will show "DAC" in the first column.
These flags mean:
10. For static routing functionality, additionally to the RouterOS 'system' package, you will
also need the following software package:
A. no extra package required
B. routing
C. advanced-tools
D. dhcp
Jawaban : a
Penjelasan :jika hanya static routing tidak memerlukan paket tambahan/extra package
Jawab : abc
Penjelsan : d tidak termasuk karena dia termasuk action dari firewall bukan status dari table
routing
Jawab true
penjelasan: karena dalam satu broadcast domain bisa menjalankan lebih dari satu point to
point dalam satu network
15. A client uses a RouterBOARD1000. The clock is configured in '/system clock'. The
clock resets to default after each reboot.
Select the best solution for the problem.
Jawab : b
Penjelasan : dengan memasang ntp client, maka ia akan mensingkronisasikan waktu
sesuai dengan yang ada di internet,
A, salah karna ketika reboot ia akan tetap kembali ke waktu sebelumnya
B salah karena dhcp server digunakan untuk memberikan waktu (dan bertindak sebagai
server) an ia tidak tersambung ke klien manapun
D. rb 1000 tidak memiliki battry cmos
16.
A. One
B. Unlimited
C. Five
D. Two
Jawaban : a
Penjelasan ; setiap interface hanya mendappat jatah 1 untuk setiap interface
17. A wireless interface 'wlan1' is added to a bridge interface 'br-lan'. To enable dhcp-server
for wireless interface 'wlan1', on which interface should dhcp-server be configured?
18. It is possible to have PPTP Client and PPTP server on one MikroTik router at the same
time.
true
Jawab : true
Penjelasa: karena d
19. Which firewall chain should be used for filters that protect your router interface?
A. post-routing
B. forward
C. pre-routing
D. input
20. What does the firewall action "Redirect" do? Select all true statements.
A. Redirects a packet to a specified port on a host in the network
B. Redirects a packet to a specified IP
C. Redirects a packet to a specified port on the router
D. Redirects a packet to the router
21. Which of the following would prevent unknown clients from connecting to your AP?
Choose the BEST answer.
A. Uncheck "Default Authenticate" in the wireless card configuration, and add each known
client's MAC address to your connect-list configuration
B. Configure the radius server under "/radius"
C. Add each known client's MAC address to your access-list configuration is the only step
needed
D. Uncheck "Default Authenticate" in the wireless card configuration, and add each known
client's MAC address to your access-list configuration ensuring that you enable
"authenticate" in the entry
E. Check the "Do not permit unknown client" box in the wireless configuration
Jawb
Penjelasan : karena dengan default authenticate semua bisa connect ke ap tersebut
Jawab : c
Penjelasan : Port yang dipakai pptp ialah 1723secara default
23. Which are necessary sections in /queue simple to set bandwidth limitation?
A. target-address, max-limit
B. max-limit
C. target-address, dst-address
D. target-address, dst-address, max-limit
Jawab : a
Penjelasan : karena untuk simple queue hanya membutuhkan target dan juga max limit nya
24. It is required to make a web server on a private LAN visible on the Public Internet. Only
the web server port should be visible to the public. Which of the following configuration
steps must be met. (select all that apply)
A. A route between the NAT Router and the webserver must exist
B. in ip firewall NAT there should be a dst-nat between the public ip of the router and the
private ip of the webserver
C. LAN address of the webserver should be routable on the internet
D. Public IP address of the webserver must be installed on the NAT Router
E. Connection Tracking must be enabled on NAT router
Jawab : c
Penjelasan ; port default dari winbox aalah 8291
1. A client uses a RouterBOARD1000. The clock is configured in '/system clock'. The clock
resets to default after each reboot.
Select the best solution for the problem.
Jawab: C
Penjelasan : dengan memasang ntp client, maka ia akan mensingkronisasikan waktu sesuai
dengan yang ada di internet,
A, salah karna ketika reboot ia akan tetap kembali ke waktu sebelumnya
B salah karena dhcp server digunakan untuk memberikan waktu (dan bertindak sebagai
server) an ia tidak tersambung ke klien manapun
D. rb 1000 tidak memiliki battry cmos
2. Which of the protocols below is used by Netinstall?
A. arp
B. bootp
C. dhcp
D. rarp
Jawab : b
Penjelasan : protocol yang digunakan adalah bootp untuk menginstalasi gn netinstall
Jawaban a salah karena dungsi ARP adalah memetakan layer2 dan 3
Jawaban c salah karena dhcp berfungsi untuk membagikan ip
Jawaban d salah karena adlh kebalikan dari ARP
Jawab : c
Penjelasan : jawaban A dan B salah karena dst addressnya tidak sesuai dengan yang diminta
Sedangkan yang D karena rangenya berbeda dengan 240
4. For a Simple Queue to apply a bandwidth restrictions on a bridged interface, following must
be done:
Jawab : a saja
Penjelasan : wirelesss access-list dapat menentukan mana yang boleh terhubung ke ap,
caranya dengan mendisable default authentication
Selainnya salah karena tidak sesuai
6. NAT rule is going to catch SMTP traffic and send it to a specific mail server.
What is the correct action for a NAT rule?
A. passthrough
B. dst-nat
C. redirect
D. tarpit
Jawab : b
Penjelasan : karena untuk membelokan smtp traffic kesuatu network ialah tugas dst nat
Untuk mengkonfigurasikannya ikuti command dibawah ini
7. When viewing the routes in Winbox, some routes will show "DAC" in the first column. These
flags mean:
Jawab : b
Penjelasan : bisa dilihat di bawah ini
Flags: X - disabled, A - active, D -dynamic,
C - connect, S -static, r - rip, b - bgp, o - ospf, m - mme,
B - blackhole, U - unreachable, P - prohibit
9. Action=redirect is applied in
A. chain=srcnat
B. chain=forward
C. chain=dstnat
Jawab : c
Penjelasan: karena redirect membutuhkan destination bukan source atau pun forward
10. MikroTik RouterOS commands can be run once a day by:
A. /system watchdog
B. /system cron
C. /system scheduler
Jawab: c
Pejelasan : karena scheduler mengatur jadwal kapan fitur tersebut dijalankan
11. Router has wireless and ethernet client interfaces, all client interfaces are bridged. To create
a DHCP service for all clients, DHCP server must be configured on:
A. Ethernet and wireless interfaces
B. DHCP service is not possible in this setup
C. Every bridge port
D. Only on the bridge interface
Jawab: D
Penjelasan : karena interface wireless dan ethernetnya sudah di bridge sehingga harus
dimasukan kedalam interface bridge
12. You want to use PCQ and allow 256k maximum download and upload for each client.
Choose correct argument values for the required queue.
A. kind=pcq pcq-rate=1256000 pcq-classifier=dst-address
B. kind=pcq pcq-rate=5000000 pcq-classifier=src-address
C. kind=pcq pcq-rate=256000 pcq-classifier=dst-address
D. kind=pcq pcq-rate=5000000 pcq-classifier=dst-address
E. kind=pcq pcq-rate=256000 pcq-classifier=src-address
Jawab : C dan E
Penjelasan :dalam PCQ untuk melimit Upload classifier yang diisi adalah Src-Address dan
untuk Download classfier yang diisi aalah dst-address
Jawaban :a
Penjelasan : karena default yang dipasang ke netinstall adalah 11520
A. 192.169.0.1-192.169.0.254
B. 192.168.0.1-192.168.0.255
C. 192.168.0.1-192.168.0.99,192.168.0.101-192.168.0.254
D. 192.168.0.1-192.168.0.14
Jawab : c an d
Penjelasan : karena untuk jawaban A dan B akan terjai overlap ip (ip gateway tidak dipisah)
15. There can be more than one PPPoE server in a single broadcast domain:
true
Jawab : true
Penjelasa: karena dalam satu broadcast domain bisa menjalankan lebih dari satu point to point
dalam satu network
16. Which wireless mode allows you to connect to any standard AP (not only MikroTik) and to
be able to bridge this wireless interface to an Ethernet?
A. station
B. station-wds
C. bridge
D. station-pseudobridge
Jawab : a
Penjelasan : karena untuk jawaban B dan D khusus mikrotik untuk melakukan wds
17. To block communications between wireless clients connected to the same access point
interface, you should set
A. 'default-forwarding=no'
B. 'max-station-count=1'
C. 'default-authentication=no'
D. 'default-authentication=no' and 'default-forwarding=no'
Jawab : a
Penjelasan : karena no default-forwarding akan men disable layer 2 dari client
18. PPPoE server only works within one Ethernet broadcast domain that it is connected to. If
there is a router between server and end-user host, it will not be able to create PPPoE tunnel to
that PPPoE server.
false
Jawaban : false
Penjelasan : karena PPPOE bisa berjalan meskipun beda IP network
/ip route
add disabled=no distance=10 dst-address=0.0.0.0/0 gateway=1.1.1.1
add disabled=no distance=5 dst-address=0.0.0.0/0 gateway=2.2.2.2
A. Route via gateway 2.2.2.2
B. Route via gateway 1.1.1.1
Jawab : a
Penjelasan :semakin kecil distance nya semakin di prioritaskan
Jawab : b
Penjelasan : karena untuk simple queue hanya membutuhkan target dan juga max limit nya
21. Which option in the configuration of a wireless card must be disabled to cause the router to
permit ONLY known clients listed in the access list to connect?
Jawab : c
Penjelasan : karena dengan default authenticate semua bisa onnect ke ap tersebut
22. For static routing functionality, additionally to the RouterOS 'system' package, you will also
need the following software package:
A. advanced-tools
B. routing
C. dhcp
D. no extra package required
Jawab : d
Penjelasan :jika hanya static routing tidak memerlukan paket tambahan/extra package
23. Which firewall chain should you use to filter clients HTTP traffic going through the router?
A. prerouting
B. forward
C. output
D. input
Jawab :b
Penjelasan : kata kuncinya adalah “through” atau melewati sehingga yang dibutuhkan untuk
“melewati” ialah chain=forward
Jawaban : b
Penjelasan : karena yang dibutuhkan untuk pppoe client interface akan dipakai
Jawab b
Penjelasan: karena redirect membutuhkan destination bukan source atau pun forward
Jawab : c
Penjelasan : karena port default dari winbox adalah tcp 8291
4. During a scan, in order to see all the available wireless frequencies that are supported by
the card, the following option must be selected in the wireless card's "Frequency Mode":
A. manual txpower
B. superchannel
C. regulatory domain
Jawab : c
Penjelasan : karena memberi limit terhadap channel yang tersedia dan maximum transit
sesuai dengan Negara masing2
Jawab :b
Penjelasan : karena untuk simple queue hanya membutuhkan target dan juga max limit nya
7. In order to use dynamic keys in your wireless security profile for an AP, you MUST set up
the dhcp server to provide the dynamic keys.
False
8. When viewing the routes in Winbox, some routes will show "DAC" in the first column.
These flags mean:
A. Dynamic, Active, Connected
B. Dynamic, Active, Console
C. Dynamic, Available, Created
D. Direct, Available, Connected
Jawab :a
Penjelasan : bisa dilihat di bawah ini
Flags: X - disabled, A - active, D -dynamic,
C - connect, S -static, r - rip, b - bgp, o - ospf, m - mme,
B - blackhole, U - unreachable, P - prohibit
9. Which wireless mode allows you to connect to any standard AP (not only MikroTik) and
to be able to bridge this wireless interface to an Ethernet?
A. station-pseudobridge
B. station
C. station-wds
D. bridge
Jawab : b
Penjelasan : karena untuk jawaban B dan D khusus mikrotik untuk melakukan wds
10. For static routing functionality, additionally to the RouterOS 'system' package, you will
also need the following software package:
A. no extra package required
B. advanced-tools
C. dhcp
D. routing
Jawab A
Penjelasan : Penjelasan :jika hanya static routing tidak memerlukan paket tambahan/extra
package
11. In RouterOS queue configurations the word "total" usually represents
A. download
B. upload + download
C. upload
D. download – upload
Jawab b
Penjelasan : karena total itu merupakan upload + download
12. PPPoE server only works within one Ethernet broadcast domain that it is connected to. If
there is a router between server and end-user host, it will not be able to create PPPoE tunnel
to that PPPoE server.
False
Penjelasan : Penjelasan : karena PPPOE bisa berjalan meskipun beda IP network
Jawab : A,E,F
Penjelasan : ppp secret berfungsi untuk membuat user an password untuk proses tunneling
14. When using routing option 'check-gateway=ping' after how many timeouts is gateway
considered unreachable:
A. 4
B. 3
C. 1
D. 2
15. Consider the following diagram. We want to communicate from a device on LAN1 to a
device on LAN2. Assuming that all necessary configurations are already included on R2,
which of the following configurations in R1 would enable this communication?
A. /ip route add dst-address=192.168.1.0/24 src-address=192.168.0.0/24
gateway=192.168.99.2
B. /ip route add dst-address=0.0.0.0/0 gateway=192.168.99.2
C. /ip route add dst-address=192.168.0.0/24 gateway=192.168.0.1
D. /ip route add dst-address=0.0.0.0/0 gateway=Ether1
E. /ip route add dst-address=192.168.1.0/24 gateway=192.168.99.2
Jawab :
Penjelasan: semuanya benar karena ,
D. bisa memakai interface,
E. konfigurasi static routing yang lengkap
B. bisa memakai Default route
17. If you wish to block user access to MSN messenger, which chain should the firewall rule
be placed in?
A. input
B. process
C. forward
D. output
Jawaban : C
Penjelasan : karena chain yang digunakan untuk data / paket dari luar router menuju luar
lainnya menggunakan Chain=Forward
Jawaban : A
Penjelasan : ARP=reply-only hanya membalas bagi yang IP dan MAC Addressnya sudah
tercantum
19. In WinBox when clicking the 'Backup' button in the Files window, the following happens
(select all that apply):
A. Backup file is created. Name contains the router identity, the date and time of its creation
B. Backup file is saved to the computer desktop
C. Backup file will contain usernames and passwords of the router
D. Optionally backup name and password can be specified
Jawaban : A
Penjelasan : Backup File berguna untuk membackup seluruh Konfigurasi termasuk Router
Ientity, tanggal dan waktu
Jawaban : C
Penjelasan : firewall nat akan membelokan traffic ari ether satu engan dst-port 3389 ke port
81.Jawaban A salah karena port yang dibelokkan salah, Jawaban A menjelaskan bahwa port
81 akan dibelokkan ke port 3389.
Jawaban : a
Penjelasan : karena yang dibutuhkan untuk pppoe client interface akan dipakai
23. Mark all the features that can be used for limiting client registrations to your access point:
A. access-list
B. wpa
C. WDS
D. registration-table
Jawaban : A
Penjelasan : untuk melimit client yang connect kita bisa menggunakan Access-List.
24. You want to use PCQ and allow 256k maximum download and upload for each client.
Choose correct argument values for the required queue.
A. kind=pcq pcq-rate=256000 pcq-classifier=dst-address
B. kind=pcq pcq-rate=1256000 pcq-classifier=dst-address
C. kind=pcq pcq-rate=5000000 pcq-classifier=src-address
D. kind=pcq pcq-rate=256000 pcq-classifier=src-address
E. kind=pcq pcq-rate=5000000 pcq-classifier=dst-address
Jawab : A dan D
Penjelasan :dalam PCQ untuk melimit Upload classifier yang diisi adalah Src-Address dan
untuk Download classfier yang diisi aalah dst-address
25. There can be more than one PPPoE server in a single broadcast domain:
True
Jawab : true
Penjelasa: karena dalam satu broadcast domain bisa menjalankan lebih dari satu point to
point dalam satu network
1. You want to transfer existing '/ip firewall filter' configuration from one router to a new
system. Choose the best possible way to do:
A. Export only '/ip firewall filter'
B. Create backup only of '/ip firewall filter' rules
C. Create backup, edit backup file and restore on target
router
D. Export global configuration and remove everything
apart from '/ip firewall filter'
Jawab :a
Penjelasan : karena untuk menambahkan nama fitur
tersebut untuk export yang lebh spesifik
2.
A. Five
B. One
C. Two
D. Unlimited
Jawab : b
Penjelasan ; setiap interface hanya mendappat jatah 1
untuk setiap interface
Jawab : b
Penjelasan : karena dia termasuk dalam range yang
sama dan juga paling spesifik
Jawaban yang A dan c tidak termasuk karena mereka
kurang spesifik,
0 dst-address=10.0.0.0/24 gateway=10.1.5.126
1 dst-address=10.1.5.0/24 gateway=10.1.1.1
2 dst-address=10.1.0.0/24 gateway=25.1.1.1
3 dst-address=10.1.5.0/25 gateway=10.1.1.2
Which gateway will be used for a packet with destination address 10.1.5.126?
A. 10.1.5.126
B. 10.1.1.1
C. 10.1.1.2
D. 25.1.1.1
Jawab : c
Penjelasan : karena dia termasuk dalam range yang
sama dan juga paling spesifik
Jawaban yang A,B dan D tidak termasuk karena
mereka kurang spesifik
JAWAB :d
Penjelasan : karena port pptp berjalan pada tcp 1723
bukan udp
6. There are two wireless cards (wlan1 and wlan2) which are bridged together. On wlan1
card there is a setting "Forwarding=no". Choose the correct answer(s):
A. Stations on wlan2 will be able to communicate with
stations on wlan2
B. Stations on wlan2 will be able to communicate with
stations on wlan1
C. Stations on wlan1 will be able to communicate with
stations on wlan1
D. To prevent communication between wlan1 and
wlan2 one cannot use Bridge Filters
E. Stations on wlan1 will be able to communicate with
stations on wlan2
7. Consider a wireless access point with mode=ap-bridge. What is the maximum number of
concurrent clients that can connect to it?
A. 2007
B. 2012
C. 2048
D. 1024
Jawab : A,B,D
Penjelasan : ppp secret berfungsi untuk membuat user
an password untuk proses tunneling
Jawab : c
Penjelasan : karena untuk menjalankan fungsi diatas
mesti dipasang dibridge tersebut
Jawab : c
Penjelasan : karena total itu merupakan upload +
download
Jawab : D
Penjelasan : log itu fungsi mencatat, bukan memblok
ataupun mengijinkan data untuk leat
14. How many different priorities can be selected for queues in MikroTik RouterOS?
A. 1
B. 16
C. 0
D. 8
Jawab : d
Penjelasan : priority terbesar yang dapat diberikan pada
client adlah 8 semakin kecil angkanya semaikn I
prioritaskan
A. wireless
B. advanced-tools
C. dhcp
D. routing
E. System
Jawab : A dan E
Penjelasan : karena untuk sekedar menghubungkan ap-
stasion tidak dibutuhkan dhcp (untuk membagikan ip)
dan juga routing (karena bisa memakai satu network
yang sama)
17. For static routing functionality, additionally to the RouterOS 'system' package, you will
also need the following software package:
A. no extra package required
B. advanced-tools
C. dhcp
D. Routing
Jawab : A
Penjelasan :jika hanya static routing tidak memerlukan
paket tambahan/extra package
Jawab : B,C,D,F
Penjelasan :
H. Ssid
Jawab : g
Penjelasan : jika hanya sekedar terhubung kita hanya
mememrlukan band yang sama
21. What is the correct action for a NAT rule on a router that should intercept SMTP traffic
and send it over to a specified mail server?
A. redirect
B. passthrough
C. dst-nat
D. Tarpit
Jawab : c
Karena : paket ingin DIOPER ke mail server
22. PPPoE server only works within one Ethernet broadcast domain that it is connected to. If
there is a router between server and end-user host, it will not be able to create PPPoE tunnel
to that PPPoE server.
false
24. Where should you upload new MikroTik RouterOS version packages for upgrading
router?
A. FTP root directory or /files directory of the router
B. System Package menu
C. Any directory in /files
D. System Backup menu
Jawab : c
Penjelasan : karena setiap upgrade akan diletakan I
directory file
25. During a scan, in order to see all the available wireless frequencies that are supported by
the card, the following option must be selected in the wireless card's "Frequency Mode":
A. regulatory domain
B. superchannel
C. manual txpower
Jawab A
Penjelasan : karena memberi limit terhadap channel
yang tersedia dan maximum transit sesuai dengan
Negara masing2
1. What can be used as ’target-address’ in the simple queue?
A. address list name
B. client’s MAC address
C. client’s address
D. server’s address
Jawab : c
Penjelasan : karena untuk simple queue menggunakan ip address si client
2. When using routing option 'check-gateway=ping' after how many timeouts is gateway
considered unreachable:
A. 1
B. 3
C. 2
D. 4
Jawab : c
Penjelasan :
Jawab :b
Penjelasan : priority terbesar yang dapat diberikan pada client adlah 8 semakin kecil
angkanya semaikn I prioritaskan
Jawab : a dan c
Penjelasan : fungsi dari access-list ialah membatasi mana saja yang bisa connect ke ap
tersebut
A. Default Forward
B. Default Authenticate
C. Security Profile
D. Enable Access List
Jawab : b
Penjelasan : karena dengan default authenticate semua bisa connect ke ap tersebut
A. 192.168.0.1-192.168.0.255
B. 192.168.0.1-192.168.0.99,192.168.0.101-192.168.0.254
C. 192.168.0.1-192.168.0.14
D. 192.169.0.1-192.169.0.254
Jawab : b dan c
Penjelasan : karena untuk jawaban A dan B akan terjai overlap ip (ip gateway tidak
dipisah)
7. There can be more than one PPPoE server in a single broadcast domain:
true
Jawab : true
Penjelasa: karena dalam satu broadcast domain bisa menjalankan lebih dari satu point to
point dalam satu network
8. There are two wireless cards (wlan1 and wlan2) which are bridged together. On wlan1
card there is a setting "Forwarding=no". Choose the correct answer(s):
A. To prevent communication between wlan1 and wlan2 one cannot use Bridge Filters
B. Stations on wlan2 will be able to communicate with stations on wlan1
C. Stations on wlan1 will be able to communicate with stations on wlan2
D. Stations on wlan1 will be able to communicate with stations on wlan1
E. Stations on wlan2 will be able to communicate with stations on wlan2
9. When viewing the routes in Winbox, some routes will show "DAC" in the first column.
These flags mean:
10. For static routing functionality, additionally to the RouterOS 'system' package, you will
also need the following software package:
A. no extra package required
B. routing
C. advanced-tools
D. dhcp
Jawaban : a
Penjelasan :jika hanya static routing tidak memerlukan paket tambahan/extra package
Jawab : abc
Penjelsan : d tidak termasuk karena dia termasuk action dari firewall bukan status dari table
routing
Jawab true
penjelasan: karena dalam satu broadcast domain bisa menjalankan lebih dari satu point to
point dalam satu network
Jawab : a dan c
Penjelasan : karena redirect yang terpasang di dm chain=dstnat ini berfungsi untuk
transparent http proxy dan juga transparent dns cache
15. A client uses a RouterBOARD1000. The clock is configured in '/system clock'. The
clock resets to default after each reboot.
Select the best solution for the problem.
Jawab : b
Penjelasan : dengan memasang ntp client, maka ia akan mensingkronisasikan waktu
sesuai dengan yang ada di internet,
A, salah karna ketika reboot ia akan tetap kembali ke waktu sebelumnya
B salah karena dhcp server digunakan untuk memberikan waktu (dan bertindak sebagai
server) an ia tidak tersambung ke klien manapun
D. rb 1000 tidak memiliki battry cmos
16.
A. One
B. Unlimited
C. Five
D. Two
Jawaban : a
Penjelasan ; setiap interface hanya mendappat jatah 1 untuk setiap interface
17. A wireless interface 'wlan1' is added to a bridge interface 'br-lan'. To enable dhcp-server
for wireless interface 'wlan1', on which interface should dhcp-server be configured?
Jawaban :D
Penjelasan tidak perlu lagi membuat ip address di wlan apabila sudah dimasukan kedalam
bridge
18. It is possible to have PPTP Client and PPTP server on one MikroTik router at the same
time.
true
Jawab : true
Penjelasa: karena d
19. Which firewall chain should be used for filters that protect your router interface?
A. post-routing
B. forward
C. pre-routing
D. input
20. What does the firewall action "Redirect" do? Select all true statements.
A. Redirects a packet to a specified port on a host in the network
B. Redirects a packet to a specified IP
C. Redirects a packet to a specified port on the router
D. Redirects a packet to the router
21. Which of the following would prevent unknown clients from connecting to your AP?
Choose the BEST answer.
A. Uncheck "Default Authenticate" in the wireless card configuration, and add each known
client's MAC address to your connect-list configuration
B. Configure the radius server under "/radius"
C. Add each known client's MAC address to your access-list configuration is the only step
needed
D. Uncheck "Default Authenticate" in the wireless card configuration, and add each known
client's MAC address to your access-list configuration ensuring that you enable
"authenticate" in the entry
E. Check the "Do not permit unknown client" box in the wireless configuration
Jawb
Penjelasan : karena dengan default authenticate semua bisa connect ke ap tersebut
Jawab : c
Penjelasan : Port yang dipakai pptp ialah 1723secara default
Jawab : a
Penjelasan : karena untuk simple queue hanya membutuhkan target dan juga max limit nya
24. It is required to make a web server on a private LAN visible on the Public Internet. Only
the web server port should be visible to the public. Which of the following configuration
steps must be met. (select all that apply)
A. A route between the NAT Router and the webserver must exist
B. in ip firewall NAT there should be a dst-nat between the public ip of the router and the
private ip of the webserver
C. LAN address of the webserver should be routable on the internet
D. Public IP address of the webserver must be installed on the NAT Router
E. Connection Tracking must be enabled on NAT router
Jawab : c
Penjelasan ; port default dari winbox aalah 8291
1. A client uses a RouterBOARD1000. The clock is configured in '/system clock'. The clock
resets to default after each reboot.
Select the best solution for the problem.
Jawab: C
Penjelasan : dengan memasang ntp client, maka ia akan mensingkronisasikan waktu sesuai
dengan yang ada di internet,
A, salah karna ketika reboot ia akan tetap kembali ke waktu sebelumnya
B salah karena dhcp server digunakan untuk memberikan waktu (dan bertindak sebagai
server) an ia tidak tersambung ke klien manapun
D. rb 1000 tidak memiliki battry cmos
Jawab : b
Penjelasan : protocol yang digunakan adalah bootp untuk menginstalasi gn netinstall
Jawaban a salah karena dungsi ARP adalah memetakan layer2 dan 3
Jawaban c salah karena dhcp berfungsi untuk membagikan ip
Jawaban d salah karena adlh kebalikan dari ARP
3. /ip route configuration on router,
Jawab : c
Penjelasan : jawaban A dan B salah karena dst addressnya tidak sesuai dengan yang diminta
Sedangkan yang D karena rangenya berbeda dengan 240
4. For a Simple Queue to apply a bandwidth restrictions on a bridged interface, following must
be done:
Jawab : a saja
Penjelasan : wirelesss access-list dapat menentukan mana yang boleh terhubung ke ap,
caranya dengan mendisable default authentication
Selainnya salah karena tidak sesuai
6. NAT rule is going to catch SMTP traffic and send it to a specific mail server.
What is the correct action for a NAT rule?
A. passthrough
B. dst-nat
C. redirect
D. tarpit
Jawab : b
Penjelasan : karena untuk membelokan smtp traffic kesuatu network ialah tugas dst nat
Untuk mengkonfigurasikannya ikuti command dibawah ini
7. When viewing the routes in Winbox, some routes will show "DAC" in the first column. These
flags mean:
Jawab : b
Penjelasan : bisa dilihat di bawah ini
Flags: X - disabled, A - active, D -dynamic,
C - connect, S -static, r - rip, b - bgp, o - ospf, m - mme,
B - blackhole, U - unreachable, P - prohibit
9. Action=redirect is applied in
A. chain=srcnat
B. chain=forward
C. chain=dstnat
Jawab : c
Penjelasan: karena redirect membutuhkan destination bukan source atau pun forward
Jawab: c
Pejelasan : karena scheduler mengatur jadwal kapan fitur tersebut dijalankan
11. Router has wireless and ethernet client interfaces, all client interfaces are bridged. To create
a DHCP service for all clients, DHCP server must be configured on:
A. Ethernet and wireless interfaces
B. DHCP service is not possible in this setup
C. Every bridge port
D. Only on the bridge interface
Jawab: D
Penjelasan : karena interface wireless dan ethernetnya sudah di bridge sehingga harus
dimasukan kedalam interface bridge
12. You want to use PCQ and allow 256k maximum download and upload for each client.
Choose correct argument values for the required queue.
A. kind=pcq pcq-rate=1256000 pcq-classifier=dst-address
B. kind=pcq pcq-rate=5000000 pcq-classifier=src-address
C. kind=pcq pcq-rate=256000 pcq-classifier=dst-address
D. kind=pcq pcq-rate=5000000 pcq-classifier=dst-address
E. kind=pcq pcq-rate=256000 pcq-classifier=src-address
Jawab : C dan E
Penjelasan :dalam PCQ untuk melimit Upload classifier yang diisi adalah Src-Address dan
untuk Download classfier yang diisi aalah dst-address
Jawaban :a
Penjelasan : karena default yang dipasang ke netinstall adalah 11520
A. 192.169.0.1-192.169.0.254
B. 192.168.0.1-192.168.0.255
C. 192.168.0.1-192.168.0.99,192.168.0.101-192.168.0.254
D. 192.168.0.1-192.168.0.14
Jawab : c an d
Penjelasan : karena untuk jawaban A dan B akan terjai overlap ip (ip gateway tidak dipisah)
15. There can be more than one PPPoE server in a single broadcast domain:
true
Jawab : true
Penjelasa: karena dalam satu broadcast domain bisa menjalankan lebih dari satu point to point
dalam satu network
16. Which wireless mode allows you to connect to any standard AP (not only MikroTik) and to
be able to bridge this wireless interface to an Ethernet?
A. station
B. station-wds
C. bridge
D. station-pseudobridge
Jawab : a
Penjelasan : karena untuk jawaban B dan D khusus mikrotik untuk melakukan wds
17. To block communications between wireless clients connected to the same access point
interface, you should set
A. 'default-forwarding=no'
B. 'max-station-count=1'
C. 'default-authentication=no'
D. 'default-authentication=no' and 'default-forwarding=no'
Jawab : a
Penjelasan : karena no default-forwarding akan men disable layer 2 dari client
18. PPPoE server only works within one Ethernet broadcast domain that it is connected to. If
there is a router between server and end-user host, it will not be able to create PPPoE tunnel to
that PPPoE server.
false
Jawaban : false
Penjelasan : karena PPPOE bisa berjalan meskipun beda IP network
/ip route
add disabled=no distance=10 dst-address=0.0.0.0/0 gateway=1.1.1.1
add disabled=no distance=5 dst-address=0.0.0.0/0 gateway=2.2.2.2
A. Route via gateway 2.2.2.2
B. Route via gateway 1.1.1.1
Jawab : a
Penjelasan :semakin kecil distance nya semakin di prioritaskan
Jawab : b
Penjelasan : karena untuk simple queue hanya membutuhkan target dan juga max limit nya
21. Which option in the configuration of a wireless card must be disabled to cause the router to
permit ONLY known clients listed in the access list to connect?
Jawab : c
Penjelasan : karena dengan default authenticate semua bisa onnect ke ap tersebut
22. For static routing functionality, additionally to the RouterOS 'system' package, you will also
need the following software package:
A. advanced-tools
B. routing
C. dhcp
D. no extra package required
Jawab : d
Penjelasan :jika hanya static routing tidak memerlukan paket tambahan/extra package
23. Which firewall chain should you use to filter clients HTTP traffic going through the router?
A. prerouting
B. forward
C. output
D. input
Jawab :b
Penjelasan : kata kuncinya adalah “through” atau melewati sehingga yang dibutuhkan untuk
“melewati” ialah chain=forward
Jawaban : b
Penjelasan : karena yang dibutuhkan untuk pppoe client interface akan dipakai
25. Action=redirect can be used in NAT chain src-nat
A. true
B. false
Jawab b
Penjelasan: karena redirect membutuhkan destination bukan source atau pun forward
Jawab : c
Penjelasan : karena port default dari winbox adalah tcp 8291
4. During a scan, in order to see all the available wireless frequencies that are supported by
the card, the following option must be selected in the wireless card's "Frequency Mode":
A. manual txpower
B. superchannel
C. regulatory domain
Jawab : c
Penjelasan : karena memberi limit terhadap channel yang tersedia dan maximum transit
sesuai dengan Negara masing2
Jawab :b
Penjelasan : karena untuk simple queue hanya membutuhkan target dan juga max limit nya
7. In order to use dynamic keys in your wireless security profile for an AP, you MUST set up
the dhcp server to provide the dynamic keys.
False
8. When viewing the routes in Winbox, some routes will show "DAC" in the first column.
These flags mean:
A. Dynamic, Active, Connected
B. Dynamic, Active, Console
C. Dynamic, Available, Created
D. Direct, Available, Connected
Jawab :a
Penjelasan : bisa dilihat di bawah ini
Flags: X - disabled, A - active, D -dynamic,
C - connect, S -static, r - rip, b - bgp, o - ospf, m - mme,
B - blackhole, U - unreachable, P - prohibit
9. Which wireless mode allows you to connect to any standard AP (not only MikroTik) and
to be able to bridge this wireless interface to an Ethernet?
A. station-pseudobridge
B. station
C. station-wds
D. bridge
Jawab : b
Penjelasan : karena untuk jawaban B dan D khusus mikrotik untuk melakukan wds
10. For static routing functionality, additionally to the RouterOS 'system' package, you will
also need the following software package:
A. no extra package required
B. advanced-tools
C. dhcp
D. routing
Jawab A
Penjelasan : Penjelasan :jika hanya static routing tidak memerlukan paket tambahan/extra
package
11. In RouterOS queue configurations the word "total" usually represents
A. download
B. upload + download
C. upload
D. download – upload
Jawab b
Penjelasan : karena total itu merupakan upload + download
12. PPPoE server only works within one Ethernet broadcast domain that it is connected to. If
there is a router between server and end-user host, it will not be able to create PPPoE tunnel
to that PPPoE server.
False
Penjelasan : Penjelasan : karena PPPOE bisa berjalan meskipun beda IP network
Jawab : A,E,F
Penjelasan : ppp secret berfungsi untuk membuat user an password untuk proses tunneling
14. When using routing option 'check-gateway=ping' after how many timeouts is gateway
considered unreachable:
A. 4
B. 3
C. 1
D. 2
15. Consider the following diagram. We want to communicate from a device on LAN1 to a
device on LAN2. Assuming that all necessary configurations are already included on R2,
which of the following configurations in R1 would enable this communication?
A. /ip route add dst-address=192.168.1.0/24 src-address=192.168.0.0/24
gateway=192.168.99.2
B. /ip route add dst-address=0.0.0.0/0 gateway=192.168.99.2
C. /ip route add dst-address=192.168.0.0/24 gateway=192.168.0.1
D. /ip route add dst-address=0.0.0.0/0 gateway=Ether1
E. /ip route add dst-address=192.168.1.0/24 gateway=192.168.99.2
Jawab :
Penjelasan: semuanya benar karena ,
D. bisa memakai interface,
E. konfigurasi static routing yang lengkap
B. bisa memakai Default route
17. If you wish to block user access to MSN messenger, which chain should the firewall rule
be placed in?
A. input
B. process
C. forward
D. output
Jawaban : C
Penjelasan : karena chain yang digunakan untuk data / paket dari luar router menuju luar
lainnya menggunakan Chain=Forward
Jawaban : A
Penjelasan : ARP=reply-only hanya membalas bagi yang IP dan MAC Addressnya sudah
tercantum
19. In WinBox when clicking the 'Backup' button in the Files window, the following happens
(select all that apply):
A. Backup file is created. Name contains the router identity, the date and time of its creation
B. Backup file is saved to the computer desktop
C. Backup file will contain usernames and passwords of the router
D. Optionally backup name and password can be specified
Jawaban : A
Penjelasan : Backup File berguna untuk membackup seluruh Konfigurasi termasuk Router
Ientity, tanggal dan waktu
Jawaban : C
Penjelasan : firewall nat akan membelokan traffic ari ether satu engan dst-port 3389 ke port
81.Jawaban A salah karena port yang dibelokkan salah, Jawaban A menjelaskan bahwa port
81 akan dibelokkan ke port 3389.
Jawaban : a
Penjelasan : karena yang dibutuhkan untuk pppoe client interface akan dipakai
23. Mark all the features that can be used for limiting client registrations to your access point:
A. access-list
B. wpa
C. WDS
D. registration-table
Jawaban : A
Penjelasan : untuk melimit client yang connect kita bisa menggunakan Access-List.
24. You want to use PCQ and allow 256k maximum download and upload for each client.
Choose correct argument values for the required queue.
A. kind=pcq pcq-rate=256000 pcq-classifier=dst-address
B. kind=pcq pcq-rate=1256000 pcq-classifier=dst-address
C. kind=pcq pcq-rate=5000000 pcq-classifier=src-address
D. kind=pcq pcq-rate=256000 pcq-classifier=src-address
E. kind=pcq pcq-rate=5000000 pcq-classifier=dst-address
Jawab : A dan D
Penjelasan :dalam PCQ untuk melimit Upload classifier yang diisi adalah Src-Address dan
untuk Download classfier yang diisi aalah dst-address
25. There can be more than one PPPoE server in a single broadcast domain:
True
Jawab : true
Penjelasa: karena dalam satu broadcast domain bisa menjalankan lebih dari satu point to
point dalam satu network
1. You want to transfer existing '/ip firewall filter' configuration from one router to a new
system. Choose the best possible way to do:
A. Export only '/ip firewall filter'
B. Create backup only of '/ip firewall filter' rules
C. Create backup, edit backup file and restore on target
router
D. Export global configuration and remove everything
apart from '/ip firewall filter'
Jawab :a
Penjelasan : karena untuk menambahkan nama fitur
tersebut untuk export yang lebh spesifik
2.
A. Five
B. One
C. Two
D. Unlimited
Jawab : b
Penjelasan ; setiap interface hanya mendappat jatah 1
untuk setiap interface
Jawab : b
Penjelasan : karena dia termasuk dalam range yang
sama dan juga paling spesifik
Jawaban yang A dan c tidak termasuk karena mereka
kurang spesifik,
0 dst-address=10.0.0.0/24 gateway=10.1.5.126
1 dst-address=10.1.5.0/24 gateway=10.1.1.1
2 dst-address=10.1.0.0/24 gateway=25.1.1.1
3 dst-address=10.1.5.0/25 gateway=10.1.1.2
Which gateway will be used for a packet with destination address 10.1.5.126?
A. 10.1.5.126
B. 10.1.1.1
C. 10.1.1.2
D. 25.1.1.1
Jawab : c
Penjelasan : karena dia termasuk dalam range yang
sama dan juga paling spesifik
Jawaban yang A,B dan D tidak termasuk karena
mereka kurang spesifik
JAWAB :d
Penjelasan : karena port pptp berjalan pada tcp 1723
bukan udp
6. There are two wireless cards (wlan1 and wlan2) which are bridged together. On wlan1
card there is a setting "Forwarding=no". Choose the correct answer(s):
A. Stations on wlan2 will be able to communicate with
stations on wlan2
B. Stations on wlan2 will be able to communicate with
stations on wlan1
C. Stations on wlan1 will be able to communicate with
stations on wlan1
D. To prevent communication between wlan1 and
wlan2 one cannot use Bridge Filters
E. Stations on wlan1 will be able to communicate with
stations on wlan2
7. Consider a wireless access point with mode=ap-bridge. What is the maximum number of
concurrent clients that can connect to it?
A. 2007
B. 2012
C. 2048
D. 1024
Jawab : B,D.E
Penjelasan: semuanya benar karena ,
B. bisa memakai interface,
D. konfigurasi static routing yang lengkap
E. bisa memakai efault route
9. PPP Secrets are used for
A. PPtP clients
B. L2TP clients
C. Router users
D. PPPoE clients
E. IPSec clients
F. PPP clients
Jawab : A,B,D
Penjelasan : ppp secret berfungsi untuk membuat user
an password untuk proses tunneling
Jawab : c
Penjelasan : karena untuk menjalankan fungsi diatas
mesti dipasang dibridge tersebut
Jawab : c
Penjelasan : karena total itu merupakan upload +
download
Jawab : D
Penjelasan : log itu fungsi mencatat, bukan memblok
ataupun mengijinkan data untuk leat
14. How many different priorities can be selected for queues in MikroTik RouterOS?
A. 1
B. 16
C. 0
D. 8
Jawab : d
Penjelasan : priority terbesar yang dapat diberikan pada
client adlah 8 semakin kecil angkanya semaikn I
prioritaskan
A. wireless
B. advanced-tools
C. dhcp
D. routing
E. System
Jawab : A dan E
Penjelasan : karena untuk sekedar menghubungkan ap-
stasion tidak dibutuhkan dhcp (untuk membagikan ip)
dan juga routing (karena bisa memakai satu network
yang sama)
17. For static routing functionality, additionally to the RouterOS 'system' package, you will
also need the following software package:
A. no extra package required
B. advanced-tools
C. dhcp
D. Routing
Jawab : A
Penjelasan :jika hanya static routing tidak memerlukan
paket tambahan/extra package
Jawab : B,C,D,F
Penjelasan :
H. Ssid
Jawab : g
Penjelasan : jika hanya sekedar terhubung kita hanya
mememrlukan band yang sama
21. What is the correct action for a NAT rule on a router that should intercept SMTP traffic
and send it over to a specified mail server?
A. redirect
B. passthrough
C. dst-nat
D. Tarpit
Jawab : c
Karena : paket ingin DIOPER ke mail server
22. PPPoE server only works within one Ethernet broadcast domain that it is connected to. If
there is a router between server and end-user host, it will not be able to create PPPoE tunnel
to that PPPoE server.
false
24. Where should you upload new MikroTik RouterOS version packages for upgrading
router?
A. FTP root directory or /files directory of the router
B. System Package menu
C. Any directory in /files
D. System Backup menu
Jawab : c
Penjelasan : karena setiap upgrade akan diletakan I
directory file
25. During a scan, in order to see all the available wireless frequencies that are supported by
the card, the following option must be selected in the wireless card's "Frequency Mode":
A. regulatory domain
B. superchannel
C. manual txpower
Jawab A
Penjelasan : karena memberi limit terhadap channel
yang tersedia dan maximum transit sesuai dengan
Negara masing2
2. When using routing option 'check-gateway=ping' after how many timeouts is gateway
considered unreachable:
A. 1
B. 3
C. 2
D. 4
Jawab : c
Penjelasan :
Jawab :b
Penjelasan : priority terbesar yang dapat diberikan pada client adlah 8 semakin kecil
angkanya semaikn I prioritaskan
Jawab : a dan c
Penjelasan : fungsi dari access-list ialah membatasi mana saja yang bisa connect ke ap
tersebut
A. Default Forward
B. Default Authenticate
C. Security Profile
D. Enable Access List
Jawab : b
Penjelasan : karena dengan default authenticate semua bisa connect ke ap tersebut
Jawab : b dan c
Penjelasan : karena untuk jawaban A dan B akan terjai overlap ip (ip gateway tidak
dipisah)
7. There can be more than one PPPoE server in a single broadcast domain:
true
Jawab : true
Penjelasa: karena dalam satu broadcast domain bisa menjalankan lebih dari satu point to
point dalam satu network
8. There are two wireless cards (wlan1 and wlan2) which are bridged together. On wlan1
card there is a setting "Forwarding=no". Choose the correct answer(s):
A. To prevent communication between wlan1 and wlan2 one cannot use Bridge Filters
B. Stations on wlan2 will be able to communicate with stations on wlan1
C. Stations on wlan1 will be able to communicate with stations on wlan2
D. Stations on wlan1 will be able to communicate with stations on wlan1
E. Stations on wlan2 will be able to communicate with stations on wlan2
9. When viewing the routes in Winbox, some routes will show "DAC" in the first column.
These flags mean:
10. For static routing functionality, additionally to the RouterOS 'system' package, you will
also need the following software package:
A. no extra package required
B. routing
C. advanced-tools
D. dhcp
Jawaban : a
Penjelasan :jika hanya static routing tidak memerlukan paket tambahan/extra package
Jawab : abc
Penjelsan : d tidak termasuk karena dia termasuk action dari firewall bukan status dari table
routing
Jawab true
penjelasan: karena dalam satu broadcast domain bisa menjalankan lebih dari satu point to
point dalam satu network
Jawab : a dan c
Penjelasan : karena redirect yang terpasang di dm chain=dstnat ini berfungsi untuk
transparent http proxy dan juga transparent dns cache
15. A client uses a RouterBOARD1000. The clock is configured in '/system clock'. The
clock resets to default after each reboot.
Select the best solution for the problem.
A. Write a script in '/system script' to set the clock
B. Configure '/system ntp client' and set a valid and reachable NTP server address.
C. Open the router and ensure the CMOS battery is fine.
D. Configure '/system ntp server' and set a valid and reachable NTP client address.
Jawab : b
Penjelasan : dengan memasang ntp client, maka ia akan mensingkronisasikan waktu
sesuai dengan yang ada di internet,
A, salah karna ketika reboot ia akan tetap kembali ke waktu sebelumnya
B salah karena dhcp server digunakan untuk memberikan waktu (dan bertindak sebagai
server) an ia tidak tersambung ke klien manapun
D. rb 1000 tidak memiliki battry cmos
16.
A. One
B. Unlimited
C. Five
D. Two
Jawaban : a
Penjelasan ; setiap interface hanya mendappat jatah 1 untuk setiap interface
17. A wireless interface 'wlan1' is added to a bridge interface 'br-lan'. To enable dhcp-server
for wireless interface 'wlan1', on which interface should dhcp-server be configured?
Jawaban :D
Penjelasan tidak perlu lagi membuat ip address di wlan apabila sudah dimasukan kedalam
bridge
18. It is possible to have PPTP Client and PPTP server on one MikroTik router at the same
time.
true
Jawab : true
Penjelasa: karena d
19. Which firewall chain should be used for filters that protect your router interface?
A. post-routing
B. forward
C. pre-routing
D. input
20. What does the firewall action "Redirect" do? Select all true statements.
A. Redirects a packet to a specified port on a host in the network
B. Redirects a packet to a specified IP
C. Redirects a packet to a specified port on the router
D. Redirects a packet to the router
21. Which of the following would prevent unknown clients from connecting to your AP?
Choose the BEST answer.
A. Uncheck "Default Authenticate" in the wireless card configuration, and add each known
client's MAC address to your connect-list configuration
B. Configure the radius server under "/radius"
C. Add each known client's MAC address to your access-list configuration is the only step
needed
D. Uncheck "Default Authenticate" in the wireless card configuration, and add each known
client's MAC address to your access-list configuration ensuring that you enable
"authenticate" in the entry
E. Check the "Do not permit unknown client" box in the wireless configuration
Jawb
Penjelasan : karena dengan default authenticate semua bisa connect ke ap tersebut
Jawab : c
Penjelasan : Port yang dipakai pptp ialah 1723secara default
Jawab : a
Penjelasan : karena untuk simple queue hanya membutuhkan target dan juga max limit nya
24. It is required to make a web server on a private LAN visible on the Public Internet. Only
the web server port should be visible to the public. Which of the following configuration
steps must be met. (select all that apply)
A. A route between the NAT Router and the webserver must exist
B. in ip firewall NAT there should be a dst-nat between the public ip of the router and the
private ip of the webserver
C. LAN address of the webserver should be routable on the internet
D. Public IP address of the webserver must be installed on the NAT Router
E. Connection Tracking must be enabled on NAT router
Jawab : c
Penjelasan ; port default dari winbox aalah 8291
1. A client uses a RouterBOARD1000. The clock is configured in '/system clock'. The clock
resets to default after each reboot.
Select the best solution for the problem.
Jawab: C
Penjelasan : dengan memasang ntp client, maka ia akan mensingkronisasikan waktu sesuai
dengan yang ada di internet,
A, salah karna ketika reboot ia akan tetap kembali ke waktu sebelumnya
B salah karena dhcp server digunakan untuk memberikan waktu (dan bertindak sebagai
server) an ia tidak tersambung ke klien manapun
D. rb 1000 tidak memiliki battry cmos
Jawab : b
Penjelasan : protocol yang digunakan adalah bootp untuk menginstalasi gn netinstall
Jawaban a salah karena dungsi ARP adalah memetakan layer2 dan 3
Jawaban c salah karena dhcp berfungsi untuk membagikan ip
Jawaban d salah karena adlh kebalikan dari ARP
Jawab : c
Penjelasan : jawaban A dan B salah karena dst addressnya tidak sesuai dengan yang diminta
Sedangkan yang D karena rangenya berbeda dengan 240
4. For a Simple Queue to apply a bandwidth restrictions on a bridged interface, following must
be done:
Jawab : a saja
Penjelasan : wirelesss access-list dapat menentukan mana yang boleh terhubung ke ap,
caranya dengan mendisable default authentication
Selainnya salah karena tidak sesuai
6. NAT rule is going to catch SMTP traffic and send it to a specific mail server.
What is the correct action for a NAT rule?
A. passthrough
B. dst-nat
C. redirect
D. tarpit
Jawab : b
Penjelasan : karena untuk membelokan smtp traffic kesuatu network ialah tugas dst nat
Untuk mengkonfigurasikannya ikuti command dibawah ini
Jawab : b
Penjelasan : bisa dilihat di bawah ini
Flags: X - disabled, A - active, D -dynamic,
C - connect, S -static, r - rip, b - bgp, o - ospf, m - mme,
B - blackhole, U - unreachable, P - prohibit
9. Action=redirect is applied in
A. chain=srcnat
B. chain=forward
C. chain=dstnat
Jawab : c
Penjelasan: karena redirect membutuhkan destination bukan source atau pun forward
Jawab: c
Pejelasan : karena scheduler mengatur jadwal kapan fitur tersebut dijalankan
11. Router has wireless and ethernet client interfaces, all client interfaces are bridged. To create
a DHCP service for all clients, DHCP server must be configured on:
A. Ethernet and wireless interfaces
B. DHCP service is not possible in this setup
C. Every bridge port
D. Only on the bridge interface
Jawab: D
Penjelasan : karena interface wireless dan ethernetnya sudah di bridge sehingga harus
dimasukan kedalam interface bridge
12. You want to use PCQ and allow 256k maximum download and upload for each client.
Choose correct argument values for the required queue.
A. kind=pcq pcq-rate=1256000 pcq-classifier=dst-address
B. kind=pcq pcq-rate=5000000 pcq-classifier=src-address
C. kind=pcq pcq-rate=256000 pcq-classifier=dst-address
D. kind=pcq pcq-rate=5000000 pcq-classifier=dst-address
E. kind=pcq pcq-rate=256000 pcq-classifier=src-address
Jawab : C dan E
Penjelasan :dalam PCQ untuk melimit Upload classifier yang diisi adalah Src-Address dan
untuk Download classfier yang diisi aalah dst-address
Jawaban :a
Penjelasan : karena default yang dipasang ke netinstall adalah 11520
A. 192.169.0.1-192.169.0.254
B. 192.168.0.1-192.168.0.255
C. 192.168.0.1-192.168.0.99,192.168.0.101-192.168.0.254
D. 192.168.0.1-192.168.0.14
Jawab : c an d
Penjelasan : karena untuk jawaban A dan B akan terjai overlap ip (ip gateway tidak dipisah)
15. There can be more than one PPPoE server in a single broadcast domain:
true
Jawab : true
Penjelasa: karena dalam satu broadcast domain bisa menjalankan lebih dari satu point to point
dalam satu network
16. Which wireless mode allows you to connect to any standard AP (not only MikroTik) and to
be able to bridge this wireless interface to an Ethernet?
A. station
B. station-wds
C. bridge
D. station-pseudobridge
Jawab : a
Penjelasan : karena untuk jawaban B dan D khusus mikrotik untuk melakukan wds
17. To block communications between wireless clients connected to the same access point
interface, you should set
A. 'default-forwarding=no'
B. 'max-station-count=1'
C. 'default-authentication=no'
D. 'default-authentication=no' and 'default-forwarding=no'
Jawab : a
Penjelasan : karena no default-forwarding akan men disable layer 2 dari client
18. PPPoE server only works within one Ethernet broadcast domain that it is connected to. If
there is a router between server and end-user host, it will not be able to create PPPoE tunnel to
that PPPoE server.
false
Jawaban : false
Penjelasan : karena PPPOE bisa berjalan meskipun beda IP network
/ip route
add disabled=no distance=10 dst-address=0.0.0.0/0 gateway=1.1.1.1
add disabled=no distance=5 dst-address=0.0.0.0/0 gateway=2.2.2.2
A. Route via gateway 2.2.2.2
B. Route via gateway 1.1.1.1
Jawab : a
Penjelasan :semakin kecil distance nya semakin di prioritaskan
Jawab : b
Penjelasan : karena untuk simple queue hanya membutuhkan target dan juga max limit nya
21. Which option in the configuration of a wireless card must be disabled to cause the router to
permit ONLY known clients listed in the access list to connect?
Jawab : c
Penjelasan : karena dengan default authenticate semua bisa onnect ke ap tersebut
22. For static routing functionality, additionally to the RouterOS 'system' package, you will also
need the following software package:
A. advanced-tools
B. routing
C. dhcp
D. no extra package required
Jawab : d
Penjelasan :jika hanya static routing tidak memerlukan paket tambahan/extra package
23. Which firewall chain should you use to filter clients HTTP traffic going through the router?
A. prerouting
B. forward
C. output
D. input
Jawab :b
Penjelasan : kata kuncinya adalah “through” atau melewati sehingga yang dibutuhkan untuk
“melewati” ialah chain=forward
Jawaban : b
Penjelasan : karena yang dibutuhkan untuk pppoe client interface akan dipakai
Jawab b
Penjelasan: karena redirect membutuhkan destination bukan source atau pun forward
Jawab : c
Penjelasan : karena port default dari winbox adalah tcp 8291
4. During a scan, in order to see all the available wireless frequencies that are supported by
the card, the following option must be selected in the wireless card's "Frequency Mode":
A. manual txpower
B. superchannel
C. regulatory domain
Jawab : c
Penjelasan : karena memberi limit terhadap channel yang tersedia dan maximum transit
sesuai dengan Negara masing2
Jawab :b
Penjelasan : karena untuk simple queue hanya membutuhkan target dan juga max limit nya
7. In order to use dynamic keys in your wireless security profile for an AP, you MUST set up
the dhcp server to provide the dynamic keys.
False
8. When viewing the routes in Winbox, some routes will show "DAC" in the first column.
These flags mean:
A. Dynamic, Active, Connected
B. Dynamic, Active, Console
C. Dynamic, Available, Created
D. Direct, Available, Connected
Jawab :a
Penjelasan : bisa dilihat di bawah ini
Flags: X - disabled, A - active, D -dynamic,
C - connect, S -static, r - rip, b - bgp, o - ospf, m - mme,
B - blackhole, U - unreachable, P - prohibit
9. Which wireless mode allows you to connect to any standard AP (not only MikroTik) and
to be able to bridge this wireless interface to an Ethernet?
A. station-pseudobridge
B. station
C. station-wds
D. bridge
Jawab : b
Penjelasan : karena untuk jawaban B dan D khusus mikrotik untuk melakukan wds
10. For static routing functionality, additionally to the RouterOS 'system' package, you will
also need the following software package:
A. no extra package required
B. advanced-tools
C. dhcp
D. routing
Jawab A
Penjelasan : Penjelasan :jika hanya static routing tidak memerlukan paket tambahan/extra
package
11. In RouterOS queue configurations the word "total" usually represents
A. download
B. upload + download
C. upload
D. download – upload
Jawab b
Penjelasan : karena total itu merupakan upload + download
12. PPPoE server only works within one Ethernet broadcast domain that it is connected to. If
there is a router between server and end-user host, it will not be able to create PPPoE tunnel
to that PPPoE server.
False
Penjelasan : Penjelasan : karena PPPOE bisa berjalan meskipun beda IP network
Jawab : A,E,F
Penjelasan : ppp secret berfungsi untuk membuat user an password untuk proses tunneling
14. When using routing option 'check-gateway=ping' after how many timeouts is gateway
considered unreachable:
A. 4
B. 3
C. 1
D. 2
15. Consider the following diagram. We want to communicate from a device on LAN1 to a
device on LAN2. Assuming that all necessary configurations are already included on R2,
which of the following configurations in R1 would enable this communication?
A. /ip route add dst-address=192.168.1.0/24 src-address=192.168.0.0/24
gateway=192.168.99.2
B. /ip route add dst-address=0.0.0.0/0 gateway=192.168.99.2
C. /ip route add dst-address=192.168.0.0/24 gateway=192.168.0.1
D. /ip route add dst-address=0.0.0.0/0 gateway=Ether1
E. /ip route add dst-address=192.168.1.0/24 gateway=192.168.99.2
Jawab :
Penjelasan: semuanya benar karena ,
D. bisa memakai interface,
E. konfigurasi static routing yang lengkap
B. bisa memakai Default route
17. If you wish to block user access to MSN messenger, which chain should the firewall rule
be placed in?
A. input
B. process
C. forward
D. output
Jawaban : C
Penjelasan : karena chain yang digunakan untuk data / paket dari luar router menuju luar
lainnya menggunakan Chain=Forward
Jawaban : A
Penjelasan : ARP=reply-only hanya membalas bagi yang IP dan MAC Addressnya sudah
tercantum
19. In WinBox when clicking the 'Backup' button in the Files window, the following happens
(select all that apply):
A. Backup file is created. Name contains the router identity, the date and time of its creation
B. Backup file is saved to the computer desktop
C. Backup file will contain usernames and passwords of the router
D. Optionally backup name and password can be specified
Jawaban : A
Penjelasan : Backup File berguna untuk membackup seluruh Konfigurasi termasuk Router
Ientity, tanggal dan waktu
Jawaban : C
Penjelasan : firewall nat akan membelokan traffic ari ether satu engan dst-port 3389 ke port
81.Jawaban A salah karena port yang dibelokkan salah, Jawaban A menjelaskan bahwa port
81 akan dibelokkan ke port 3389.
Jawaban : a
Penjelasan : karena yang dibutuhkan untuk pppoe client interface akan dipakai
23. Mark all the features that can be used for limiting client registrations to your access point:
A. access-list
B. wpa
C. WDS
D. registration-table
Jawaban : A
Penjelasan : untuk melimit client yang connect kita bisa menggunakan Access-List.
24. You want to use PCQ and allow 256k maximum download and upload for each client.
Choose correct argument values for the required queue.
A. kind=pcq pcq-rate=256000 pcq-classifier=dst-address
B. kind=pcq pcq-rate=1256000 pcq-classifier=dst-address
C. kind=pcq pcq-rate=5000000 pcq-classifier=src-address
D. kind=pcq pcq-rate=256000 pcq-classifier=src-address
E. kind=pcq pcq-rate=5000000 pcq-classifier=dst-address
Jawab : A dan D
Penjelasan :dalam PCQ untuk melimit Upload classifier yang diisi adalah Src-Address dan
untuk Download classfier yang diisi aalah dst-address
25. There can be more than one PPPoE server in a single broadcast domain:
True
Jawab : true
Penjelasa: karena dalam satu broadcast domain bisa menjalankan lebih dari satu point to
point dalam satu network