Configure and verify VLANs, 802.1Q trunks, EtherChannel, OSPF/EIGRP/BGP, HSRP, NAT, and NTP on IOS-XE, interpreting show commands like show ip ospf neighbor. The critical skill is correct Layer 2/Layer 3 forwarding and routing adjacency formation.
Start practicing
Infrastructure — choose a session length
Free · No account required
Domain overview
Infrastructure is 30% of ENCOR 350-401 and covers Layer 2 and Layer 3 forwarding on Cisco IOS-XE platforms. Expect scenario items on VLANs and trunking, STP variants, EtherChannel, OSPF, EIGRP, BGP, first-hop redundancy, NAT, and NTP, plus configuration-syntax and show-command interpretation rather than pure recall.
Exam objectives
Configuring 802.1Q trunk and access ports, native VLAN, and VTP modes on IOS switches
Comparing RSTP, MST, and PVST+ port roles, states, and root bridge election
Tuning OSPF neighbor adjacencies, network types, cost, and passive interfaces
Implementing HSRP, VRRP, or GLBP and verifying with show standby brief
Mixing up HSRP active/standby versus VRRP master/backup terminology, and forgetting HSRP's default priority of 100
Assuming DTP negotiates trunks on all platforms; some Catalyst switches default to dynamic auto or access
Configuring OSPF passive interfaces on links that must form adjacencies, silently blocking hello packets
Click any question to see the full explanation and answer options, or start a focused practice session above.
A network engineer is troubleshooting an EIGRP adjacency issue between two routers. The engineer verifies that both routers have the same K-values and autonomous system number. However, the adjacency does not form. Which configuration issue is most likely the cause?
2A company is implementing QoS in a campus network. Voice traffic must be prioritized over data traffic, and all traffic should be marked at Layer 2 and Layer 3. Which combination of marking values should be used on access ports to achieve this?
3An engineer needs to configure a switchport to carry traffic for multiple VLANs to a router using a single physical link. Which configuration should be applied on the switchport?
4A network engineer is deploying a new WLAN and needs to ensure that client traffic is encrypted using AES with a pre-shared key. Which security configuration should be applied to the wireless SSID?
5A network administrator is troubleshooting an issue where OSPF routes are not being learned from a neighbor. The administrator checks the OSPF configuration and sees that both routers are in the same area. The neighbor state is stuck in EXSTART. What is the most likely cause?
6An engineer is configuring a new VLAN 100 on a switch. Which command must be used to create the VLAN?
7A company has a requirement to provide redundancy for the default gateway on a subnet. Two switches are configured with HSRP. Which requirement must be met for the interfaces on the switches to form the HSRP group?
8A company has a campus network with two distribution switches (DSW1 and DSW2) connected via a Layer 2 trunk. Each distribution switch connects to two access switches. Spanning Tree Protocol (STP) is running with default settings. Recently, a network administrator added a new access switch (ASW3) and connected it to both distribution switches. After the connection, network performance degraded significantly, and users in VLAN 10 reported intermittent connectivity. The administrator checked the logs and saw multiple TCN notifications. What is the most likely cause of the issue?
9A multinational organization has a BGP-based MPLS VPN network. The CE router at a branch office is connected to two PE routers (PE1 and PE2) in the service provider network. The branch uses eBGP to exchange routes with the PEs. The network administrator notices that the branch can reach some destinations but not others. The BGP table on the CE shows routes with next-hop set to the PE loopback addresses, but those loopbacks are not reachable. The CE has a default route pointing to the PEs. What is the most likely cause of the issue?
10Refer to the exhibit. R1 has two equal-cost OSPF E2 routes to 10.1.1.0/24 via two different next hops. However, when tracing to 10.1.1.1, all traffic uses the path through 10.0.1.2. What is the most likely reason?
11A network engineer is configuring a new Cisco IOS switch that will be deployed in a data center. The switch must forward traffic for VLAN 10 while ensuring that the native VLAN for all trunk ports is not susceptible to VLAN hopping attacks. The engineer decides to change the native VLAN from the default to an unused VLAN 999. Which command sequence correctly configures the native VLAN on a trunk port?
12A network engineer is deploying a VXLAN EVPN fabric. The underlay is a routed Layer 3 network using OSPF. Hosts in the same subnet are attached to leaf switches that are not directly connected. The engineer must ensure that the fabric provides optimal forwarding for East-West traffic without tromboning through a centralized gateway. Which VXLAN component should be configured to accomplish this?
13A network engineer configured a router with the command `ip route 0.0.0.0 0.0.0.0 192.168.1.1` and also has a specific static route for 10.1.1.0/24 pointing to 192.168.1.1. A packet arrives destined for 10.1.1.5. Which route will the router use to forward the packet?
14A network engineer is deploying a new branch office switch and needs to configure a switched virtual interface (SVI) to act as the default gateway for VLAN 10. The VLAN has been created and ports have been assigned. Which additional step is required for the SVI to become operational and pass traffic?
15A network engineer is deploying a new branch office that uses a single switch stack with two member switches. The stack must forward traffic between access ports in different VLANs without involving an external router. Which feature should be configured to meet this requirement?
16A network administrator is configuring a Cisco IOS router to authenticate management users against a TACACS+ server. The administrator wants to ensure that if the TACACS+ server becomes unreachable, a local username and password can still be used to log in. Which configuration accomplishes this requirement?
17A network administrator is configuring a new Cisco IOS router and needs to enable OSPFv3 for IPv6 on an interface. The interface is already configured with an IPv6 address. Which command must be entered in interface configuration mode to enable OSPFv3 on that interface?
18A network engineer is configuring a Cisco IOS router to authenticate OSPF neighbors using MD5. The engineer enters the following commands under the OSPF process: area 0 authentication message-digest, and under the interface: ip ospf message-digest-key 1 md5 Cisco123. However, the neighbor relationship does not form. What is the most likely cause?
19A network administrator is deploying a new branch office that requires a dynamic routing protocol supporting unequal-cost load balancing and fast convergence. The topology includes Cisco routers only. Which routing protocol should be implemented?
20A network engineer is configuring a VXLAN EVPN fabric on Cisco Nexus switches. The fabric must support Layer 2 extension across multiple leaf switches while maintaining optimal forwarding for Layer 3 traffic. Which control plane component is responsible for advertising MAC and IP address bindings to all leaf switches?
21A network engineer is implementing VXLAN on a Cisco Nexus 9000 series switch running NX-OS. The underlay network uses OSPF and the loopback0 interface of each VTEP is advertised. The engineer wants to verify that the VXLAN tunnel endpoints can communicate. Which command should be used to check the VXLAN tunnel status?
22A network engineer needs to configure a switch port to authenticate end hosts against a RADIUS server. The requirement is that if the RADIUS server becomes unreachable, the port should place the host on a guest VLAN instead of shutting down. Which command must be added to the interface configuration?
23A network administrator is configuring a switch port to support a VoIP phone and a PC connected to the phone's internal switch. The phone must be placed in VLAN 50 and the PC in VLAN 60. Which configuration on the switch port achieves this?
24A network engineer is configuring a Cisco IOS router to authenticate OSPF neighbors using MD5 cryptographic authentication on an interface. The engineer enters the following commands: interface GigabitEthernet0/0, ip ospf authentication message-digest, ip ospf message-digest-key 1 md5 Cisco123. However, the OSPF adjacency with the neighbor router is not forming. Which additional configuration is required on the neighbor router to establish the adjacency?
25A network administrator is configuring a Cisco Catalyst 9000 switch to authenticate users via 802.1X. The authentication server is a Cisco Identity Services Engine (ISE). The administrator wants to ensure that if the ISE server becomes unreachable, the switch will allow devices to connect with limited access. Which feature should be configured?
26A network administrator is configuring a Cisco Catalyst switch to allow management access only from the subnet 10.10.10.0/24. The administrator wants to apply an ACL to the VTY lines. Which command correctly applies the ACL named MGMT to the VTY lines?
27A network engineer is configuring a Cisco Catalyst switch to authenticate users via 802.1X. The RADIUS server is reachable at 10.10.10.5 using the key 'Cisco123'. The switch must dynamically assign VLANs based on the RADIUS attributes returned. Which configuration is required on the switch to enable dynamic VLAN assignment?
28An engineer is implementing a QoS policy on a Cisco IOS XE router. The requirement is to prioritize voice traffic (marked DSCP EF) and ensure that it receives strict priority scheduling with a guaranteed bandwidth of 30% of the interface capacity. Which queuing mechanism should be configured on the interface?
29A network engineer is implementing VXLAN with a distributed anycast gateway in a Cisco SD-Access fabric. Hosts in the same subnet are attached to different edge nodes. The engineer must ensure that a host retains its default gateway IP and MAC address when it moves between edge nodes. Which technology should be configured on the edge nodes?
30A network engineer is configuring a Cisco IOS router to support VRF-lite for a customer. The engineer creates a VRF named CUST_A and assigns an interface to it using the command ip vrf forwarding CUST_A. After assigning the interface, the engineer notices that the interface IP address is removed. Which action must the engineer take to restore connectivity?
31A network administrator is configuring a Cisco IOS switch to authenticate users via 802.1X. The administrator wants to ensure that if the RADIUS server is unreachable, users are placed into a guest VLAN with limited access. Which feature should be configured to achieve this?
32A network engineer is configuring a Cisco IOS router to establish a site-to-site VPN using IPsec. The engineer wants to ensure that the VPN tunnel only carries traffic for the subnet 10.1.1.0/24 to 10.2.2.0/24. Which configuration element is required to define the interesting traffic?
33A network administrator is configuring a Cisco IOS router to authenticate management users against a centralized TACACS+ server. The administrator wants to ensure that if the TACACS+ server is unreachable, a locally configured user can still log in. Which command should be used to define the authentication method list for login?
34A network engineer is implementing VXLAN with a distributed anycast gateway in a Cisco SD-Access fabric. The fabric uses LISP for control plane and VXLAN for data plane. Which component is responsible for mapping endpoint IP addresses to fabric edge nodes?
35A network engineer is configuring a Cisco Wireless LAN Controller (WLC) to support a new WLAN that requires 802.1X authentication with EAP-TLS. The engineer must ensure that the WLC forwards authentication requests to an external RADIUS server. Which configuration is required on the WLC?
36A network engineer is configuring a new Cisco IOS router for OSPFv2 in a multi-area OSPF domain. The router will be an Area Border Router (ABR) connecting Area 0 and Area 10. The engineer must ensure that the router correctly summarizes routes from Area 10 into Area 0 and that it does not become a designated router (DR) on any broadcast network. Which two configuration steps are required to meet these requirements? (Choose two.)
37A network engineer is deploying a Cisco SD-WAN solution using vManage, vSmart, and vBond controllers. The engineer must ensure that the control plane and data plane are secure and that routers can authenticate to the controllers. Which two statements are true regarding the Cisco SD-WAN controller components? (Choose two.)
38A network engineer is configuring a Cisco Wireless LAN Controller (WLC) to authenticate corporate users using 802.1X with a RADIUS server. The requirement is to ensure that only users with valid credentials can access the wireless network, and that the RADIUS server is reachable. Which WLC configuration step is required to enable 802.1X authentication?
39A network administrator is configuring a new Cisco IOS switch. The administrator needs to assign switch port GigabitEthernet0/1 to VLAN 20 and ensure that the port is in access mode. Which command sequence is correct?
40A network administrator is deploying a Cisco SD-Access fabric and needs to ensure that the underlay network is properly configured. Which two statements about the underlay network in SD-Access are true? (Choose two.)
41A network engineer is configuring a Cisco IOS router to act as a DHCP server for a subnet. The engineer wants to exclude a range of addresses from being assigned dynamically. Which command should be used?
42A network engineer is configuring a Cisco IOS router for NAT overload (PAT) to allow internal hosts on the 10.1.1.0/24 network to access the internet using the router's outside interface IP address. The engineer wants to ensure that all internal hosts can initiate connections and that return traffic is correctly translated. Which configuration is required?
43A network engineer is configuring a Cisco IOS router to support a site-to-site VPN using IPsec. The engineer wants to ensure that traffic from the local subnet 10.1.1.0/24 to the remote subnet 10.2.2.0/24 is encrypted. Which configuration is required to define the interesting traffic?
44A network engineer is configuring a Cisco IOS router to support OSPFv3 for IPv6. The router must form adjacencies on its GigabitEthernet0/0 interface, which is assigned to area 0. Which command is required to enable OSPFv3 on the interface?
45A network engineer is deploying a new Cisco SD-WAN fabric using Cisco vManage, vSmart, and vBond controllers. The engineer must ensure that the control plane is secure and resilient. Which two statements are true regarding the roles of these controllers? (Choose two.)
46A network administrator is configuring a Cisco IOS router to use VRRP. The router should be the master for the virtual IP 192.168.1.1 on interface GigabitEthernet0/0. The administrator wants to ensure that if this router fails, another router takes over with minimal delay. Which command should be used to set the priority to 150?
47A network administrator is configuring a Cisco Catalyst switch to assign a voice VLAN to IP phones. The phones will tag voice traffic with VLAN 200, and data traffic from attached PCs should be untagged in VLAN 10. Which interface configuration correctly implements this?
48A network engineer is implementing VXLAN with an EVPN control plane. The underlay is a routed Layer 3 network. Which statement describes the role of the VXLAN Tunnel Endpoint (VTEP)?
49A network engineer at a large enterprise is deploying a new branch office. The branch has two Cisco Catalyst switches, SW1 and SW2, that must participate in the same Layer 2 domain. SW1 is configured as the VTP server with domain 'CORP' and version 2. SW2 is a new switch with a higher VTP revision number and the same domain and password, but it has an empty VLAN database. The engineer connects SW2 to SW1 via a trunk link. What will happen to the VLAN database on SW1?
50A network engineer is configuring a switch stack with two Catalyst 9300 switches. The engineer wants to ensure that if the active switch fails, the standby switch takes over with minimal disruption. Which statement accurately describes the stack MAC address behavior during a failover?
51A network engineer is configuring a Cisco IOS router to act as a DHCP relay agent for a remote subnet 10.10.10.0/24. The DHCP server is located at 172.16.1.100. The engineer issues the command 'ip helper-address 172.16.1.100' on interface GigabitEthernet0/0, which is the gateway for that subnet. However, clients on the subnet are not receiving IP addresses. What is the most likely cause?
52A network engineer is configuring a Cisco IOS router to act as a DHCP relay agent for a subnet that has no local DHCP server. The DHCP server is at 10.10.10.5, and the router interface facing the clients is GigabitEthernet0/1 with IP address 10.20.20.1. Which command must be applied to the interface so that client DHCP broadcasts are forwarded to the server?
53A network engineer is deploying a new Cisco Catalyst 9000 switch stack. The engineer wants to ensure that the stack uses the most efficient use of stack ports and provides the highest possible bandwidth between stack members. Which stacking technology and topology should be used?
54A network administrator is implementing VXLAN with a distributed anycast gateway in a Cisco SD-Access fabric. The fabric has two border nodes and four edge nodes. The administrator wants to ensure that traffic from a wired endpoint in VLAN 10 can reach a wireless endpoint in the same VLAN that is roaming between access points. Which component is responsible for mapping the endpoint's IP address to its location in the fabric?
55A network administrator is configuring a Cisco IOS router to authenticate management users via TACACS+. The requirement is to allow fallback to the local database if all TACACS+ servers are unreachable. Which AAA configuration achieves this?
56A network administrator is configuring a Cisco Catalyst switch and needs to assign a port to VLAN 20 as an access port. The port is currently in VLAN 1. Which command sequence correctly configures the interface?
57A network engineer is deploying VXLAN with an EVPN control plane in a data center. The underlay is a routed Layer 3 network using OSPF. The engineer must ensure that the VXLAN data plane and EVPN control plane operate correctly. Which two statements about this deployment are true? (Choose two.)
58A network engineer is implementing VXLAN with a Cisco Nexus 9000 series switch acting as a VTEP. The underlay network is OSPF, and the overlay uses BGP EVPN. The engineer notices that VM traffic between two hosts on different VTEPs is not being encapsulated. Which action should be taken to ensure VXLAN traffic is properly encapsulated and forwarded?
59A network engineer is implementing a VXLAN overlay over an existing Layer 3 campus network. The requirement is to carry Layer 2 frames across the Layer 3 underlay. Which protocol is used to encapsulate the original Layer 2 frame for transport across the IP network?
60A network engineer is troubleshooting a Cisco Wireless LAN Controller (WLC) deployment where clients cannot associate to an SSID. The SSID is configured with WPA2-Enterprise and uses a RADIUS server for authentication. The engineer verifies that the RADIUS server is reachable and the shared secret is correct. Which additional configuration on the WLC is required for clients to successfully authenticate?
61A network engineer is implementing VXLAN with a Layer 2 gateway on a Cisco Nexus 9000 series switch. The design uses a distributed anycast gateway to provide optimal forwarding for hosts in the same subnet across different leaf switches. The engineer needs to ensure that all leaf switches use the same virtual MAC address for the gateway. Which feature must be configured to achieve this?
62A network engineer is implementing VXLAN with Cisco SD-Access. The engineer must ensure that the underlay network provides the necessary transport for VXLAN traffic. Which two statements about VXLAN and its underlay are true? (Choose two.)
63A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using MD5. The engineer wants to ensure that only routers with the correct key can form adjacencies, and that the key is not sent in clear text. Which command sequence correctly enables MD5 authentication on an interface?
64A network administrator is configuring a Cisco IOS switch to support a new voice VLAN. The administrator wants to ensure that voice traffic is tagged with CoS 5 and data traffic is untagged. Which command should be applied to the interface connected to an IP phone?
65A network administrator is deploying a new Cisco Catalyst switch and wants to restrict management access to the switch. The requirement is that only hosts on the 10.10.10.0/24 subnet can access the switch via SSH, and all other SSH attempts must be denied. Which configuration achieves this?
66A network engineer is configuring a Cisco Catalyst switch to support a new wireless access point that will use 802.1X authentication with EAP-TLS. The switch port must be configured to allow multiple hosts, but only one host should be authenticated. Which command should be used to enable this behavior?
67A network administrator is configuring a Cisco IOS switch and needs to verify the current VLAN configuration, including VLAN IDs, names, and status. Which command should be used?
68A network engineer is deploying Cisco SD-Access and needs to provide fabric edge nodes with a mapping database for endpoint locations. The fabric uses LISP for control plane and VXLAN for data plane encapsulation. Which component is responsible for maintaining the endpoint-to-edge-node mapping and responding to map requests?
69A network engineer is deploying a new Cisco Catalyst 9000 switch stack and wants to protect the control plane from excessive ARP traffic that could overwhelm the CPU during a broadcast storm. The engineer needs to limit the rate of ARP packets sent to the CPU to 500 packets per second and drop the excess. Which feature should be configured on the switch?
70A network engineer is configuring a GRE tunnel between two Cisco IOS routers to transport multicast traffic and routing protocols across an IP network. Which two statements about GRE tunnel configuration and operation are true? (Choose two.)
71A network architect is designing a controller-based wireless deployment for a large campus. The requirement is to provide seamless roaming for voice clients across Layer 3 boundaries while keeping the client IP address unchanged. Which Cisco SD-Access fabric feature should be used to meet this requirement?
72A network engineer is configuring QoS on a Cisco IOS XE router. The router must mark all ingress traffic from a specific subnet with DSCP AF31 and ensure that this marking is trusted throughout the network. Which configuration step is required to achieve this?
73A network engineer is implementing VXLAN with an Ethernet VPN (EVPN) control plane in a data center. The underlay is a Layer 3 IP network. The engineer wants to ensure that the VXLAN tunnel endpoints (VTEPs) can discover each other and that the fabric supports multihoming with all-active forwarding. Which technology should be used?
74An engineer is configuring a new switch stack using Cisco StackWise technology. The stack must be resilient to the failure of the active switch, and the engineer wants to ensure that the standby switch takes over with minimal disruption. The engineer has four switches in the stack. Which statement describes the role of the standby switch in a StackWise stack?
75A network engineer is configuring a Cisco IOS XE router to support NETCONF over SSH. The requirement is to allow a remote management station to retrieve and modify the router's configuration using NETCONF. Which command must be used to enable the NETCONF subsystem on the router?
76A network engineer is implementing QoS on a Cisco IOS router. The engineer wants to ensure that VoIP traffic is marked with DSCP EF and that the router prioritizes this traffic during congestion. Which mechanism should be used to provide priority queuing for VoIP?
77A network engineer is implementing VXLAN on Cisco Nexus 9000 switches. The engineer needs to verify the configuration of the VXLAN data plane. Which two statements are true regarding VXLAN operation? (Choose two.)
78A network engineer is deploying a new branch office that must use dynamic ARP inspection (DAI) on its access switches. The engineer wants to minimize manual configuration while ensuring that only valid IP-to-MAC bindings are permitted. Which feature should be enabled on the switches to provide the required binding information to DAI?
79A network engineer is configuring a new Cisco Catalyst 9300 switch stack. The company requires that the native VLAN for all 802.1Q trunk ports be changed from the default to VLAN 99. The engineer enters the global configuration command vlan dot1q tag native and then configures the trunk ports with switchport trunk native vlan 99. After applying the configuration, the engineer notices that untagged frames received on the trunk are being dropped. What is the most likely cause?
80A network engineer is configuring a Cisco Catalyst switch to authenticate users via 802.1X. The switch must place authenticated users into a specific VLAN based on the RADIUS server's response, and unauthenticated users should have no network access. Which configuration element is required on the switch to support dynamic VLAN assignment?
81A network administrator is implementing a VXLAN EVPN fabric in a data center. The requirement is to provide Layer 2 connectivity between two leaf switches for a VLAN that must be stretched across the fabric. Which EVPN route type is used to advertise MAC address reachability information?
82A network administrator is configuring a new Cisco Catalyst switch and needs to assign a management IP address to VLAN 1. Which command is used to enter the interface configuration mode for VLAN 1?
83A network administrator is configuring a Cisco IOS router to provide DHCP services to a remote subnet. The router's interface on that subnet is configured with the address 10.1.1.1/24. Which command is required to exclude the router's own address from the DHCP pool?
84A network engineer is configuring a new Cisco Catalyst switch that will participate in a VTP domain. The switch must not be able to create, modify, or delete VLANs, but it must synchronize its VLAN database with the current VTP server. Which VTP mode should be configured on this switch?
85A network administrator is configuring a Cisco wireless LAN controller (WLC) to support a new employee SSID. The SSID must use WPA2-Enterprise with 802.1X authentication against an external RADIUS server. The administrator has already configured the RADIUS server on the WLC. Which additional step is required to complete the configuration?
86A network engineer is configuring a switch to support 802.1X authentication for wired clients. The requirement is to authenticate users against a centralized RADIUS server and assign dynamic VLANs based on the user's role. Which command must be configured on the switch to enable 802.1X authentication globally?
87A network engineer is configuring a new Cisco IOS switch and needs to ensure that the management VLAN is properly secured. The engineer wants to restrict management access to only the IT department subnet 10.10.10.0/24. Which configuration should be applied to the VTY lines?
88A network engineer is implementing QoS on a Cisco IOS router. The requirement is to classify traffic based on the DSCP value in the IP header and then mark it with a new DSCP value. Which QoS mechanism should be used to accomplish this?
89A network engineer is implementing VXLAN with a Cisco Nexus 9000 series switch acting as a VTEP. The engineer needs to ensure that the VXLAN overlay can carry traffic for multiple tenants while maintaining isolation. Which component is responsible for identifying the VXLAN segment and providing tenant isolation?
90A network engineer is deploying a new branch office with a single Cisco Catalyst 9300 switch. The branch has three VLANs: VLAN 10 (users), VLAN 20 (voice), and VLAN 30 (management). The engineer needs to route traffic between these VLANs directly on the switch without using an external router. Which feature should be configured on the switch to enable inter-VLAN routing?
91A network engineer is deploying a new branch office with a Cisco Catalyst 9300 switch. The switch must participate in the corporate OSPF domain but must not become a designated router (DR) or backup designated router (BDR) on any broadcast segment. Which configuration should the engineer apply to the switch's OSPF interface?
92A network engineer is implementing VXLAN on a Cisco Nexus switch. The engineer wants to ensure that the VXLAN tunnel endpoint (VTEP) can forward traffic between VLANs by mapping them to VNIs. Which component is responsible for the mapping of VLANs to VNIs on the VTEP?
93A network engineer is deploying a Cisco SD-WAN solution using vManage, vSmart, and vBond controllers. Which two statements accurately describe the roles of these controllers in the SD-WAN overlay? (Choose two.)
94A network engineer is deploying a new Cisco Catalyst switch and must ensure that the management VLAN 50 is the only VLAN allowed on the trunk link to the distribution switch, while also ensuring that the native VLAN matches on both ends. The distribution switch is already configured with switchport trunk native vlan 999 and switchport trunk allowed vlan 50. Which configuration on the new switch will satisfy these requirements?
95A network administrator is configuring a Cisco IOS router to act as a DHCP server for a subnet. The administrator wants to ensure that the router assigns IP addresses to clients and also provides them with the IP address of a TFTP server for configuration files. Which DHCP option should the administrator configure to provide the TFTP server address?
96A network engineer is configuring a Cisco IOS router to authenticate management users against a RADIUS server. The engineer wants to ensure that if the RADIUS server is unreachable, the router falls back to local authentication using the local username database. Which configuration should be applied?
97A network administrator is configuring a Cisco IOS router to authenticate management users via TACACS+. The TACACS+ server is reachable at 10.1.1.100. The administrator wants to ensure that if the TACACS+ server becomes unreachable, the router will fall back to local authentication using the local username 'admin' with password 'Cisco123'. Which configuration should be applied?
98A network engineer is configuring VXLAN on a Cisco Nexus 9000 series switch. The underlay network is a routed Layer 3 network using OSPF. The engineer needs to ensure that the VXLAN tunnel endpoint (VTEP) IP addresses are reachable across the underlay. Which statement describes the correct configuration for the VTEP source interface?
99A network engineer is implementing VXLAN with a Cisco Nexus 9000 series switch acting as a VTEP. The engineer wants to ensure that the VXLAN traffic is encapsulated and forwarded correctly over the underlay network. Which statement describes the VXLAN encapsulation and forwarding process?
100An engineer is implementing a VXLAN overlay network using Cisco Nexus switches. The engineer needs to ensure that the VXLAN tunnel endpoint (VTEP) can dynamically learn the mapping of remote VTEP IP addresses to MAC addresses. Which protocol should be used to achieve this dynamic learning?
101A network engineer is configuring a Cisco Catalyst switch to support a new wireless access point that will carry management traffic on VLAN 10 and client traffic on VLAN 20. The AP connects to a single switchport and requires both VLANs to be trunked with 802.1Q tagging, with VLAN 10 as the native VLAN. Which configuration on the switchport will meet these requirements?
102A network engineer is implementing a first-hop redundancy protocol on a pair of Cisco switches. The requirement is to provide sub-second failover for IPv4 hosts and to load-balance traffic between the two switches for different VLANs. Which protocol should be used to meet these requirements?
103A network engineer is configuring a Cisco Wireless LAN Controller (WLC) for a new wireless network. The engineer wants to ensure that client traffic is tunneled back to the WLC and that the WLC is the single point of management for the access points. Which mode should the access points be configured in?
104A network engineer is configuring a Cisco IOS router to support OSPFv3 for IPv6. The router is connected to two OSPFv3 areas: area 0 and area 1. The engineer wants to summarize the IPv6 routes from area 1 into area 0 using the prefix 2001:DB8:1::/48. Which command should be used on the area border router (ABR)?
105A network engineer is configuring QoS on a Cisco IOS switch. The engineer needs to mark packets coming from a specific server with DSCP EF (46) and ensure that this marking is trusted throughout the network. Which command should be used to trust the DSCP markings on the interface connected to the server?
106A network engineer is implementing QoS on a Cisco IOS router. The engineer wants to ensure that VoIP traffic is prioritized and that excess VoIP traffic is dropped when the interface is congested. Which QoS mechanism should be used?
107A network engineer is deploying a new branch office with a single Cisco Catalyst switch that will connect to the corporate network via a routed uplink. The switch must be able to forward traffic for VLANs 10, 20, and 30 over that single uplink to a router. The router interface is configured with subinterfaces and dot1Q encapsulation. Which switchport configuration should be applied to the uplink port?
108A network engineer is deploying a new branch office with a single Cisco Catalyst switch. The branch requires that all access ports automatically authenticate devices using 802.1X with RADIUS, but also allow unauthenticated devices to be placed into a guest VLAN. Which feature must be configured on the switch to meet this requirement?
109A network engineer is configuring a new switch stack using Cisco StackWise technology. The engineer wants to ensure that if the stack master fails, another switch takes over with minimal disruption. Which statement accurately describes the failover behavior in a StackWise stack?
110A network engineer is configuring a Cisco IOS router to support PIM Sparse Mode (PIM-SM) for multicast traffic. The engineer needs to ensure that the router can dynamically discover Rendezvous Points (RPs). Which two mechanisms can be used to achieve this? (Choose two.)
111A network administrator is configuring a Cisco IOS router to act as a DHCP server for the 10.10.10.0/24 subnet. The router interface GigabitEthernet0/0 is configured with IP address 10.10.10.1/24. Which command is required to specify the DNS server address that will be provided to DHCP clients?
112A network engineer is implementing VXLAN in a data center to support a large number of tenants. The engineer must ensure that the VXLAN overlay supports Layer 2 connectivity over a Layer 3 underlay. Which two statements are true about VXLAN? (Choose two.)
113A network administrator is configuring a Cisco switch to support a new wireless LAN controller (WLC) that requires the switch port to carry traffic for multiple VLANs. The WLC will be connected to a trunk port. Which command must be used to configure the switch port as a trunk?
114A network engineer is designing a new data center network using Cisco ACI. The engineer needs to ensure that traffic between two endpoints in different EPGs is allowed only if a contract permits it. Which ACI construct is used to define the rules that permit or deny traffic between EPGs?
115A network engineer is deploying Cisco SD-Access and wants to ensure that traffic from employee endpoints is tunneled to a fabric border node for external connectivity. Which component is responsible for encapsulating endpoint traffic into VXLAN and forwarding it to the border?
116A network engineer is configuring a Cisco Catalyst switch port that connects to an IP phone and a PC. The phone must tag its voice traffic with VLAN 200, and the PC must send untagged traffic that the switch places into VLAN 10. Which interface configuration accomplishes this?
117A network engineer is configuring a GRE tunnel between two sites to transport IPv6 traffic over an IPv4-only underlay. The engineer wants to ensure that the tunnel interface supports IPv6 and that traffic is encrypted. Which technology should be combined with GRE to provide encryption?
118A network administrator is configuring a Cisco IOS router to authenticate OSPF neighbors using MD5. The router must use key 1 with the password 'Cisco123' on interface GigabitEthernet0/0. Which configuration is correct?
119A network administrator is deploying a new Cisco Catalyst switch in a data center. The switch must support a protocol that allows multiple physical links to be bundled into a single logical link, providing increased bandwidth and redundancy. The administrator wants to ensure that the protocol can dynamically negotiate the bundle formation with the connected device. Which protocol should be configured?
120A network engineer is configuring a Cisco Catalyst switch to support 802.1X authentication for wired users. The company requires that if the RADIUS server becomes unreachable, devices on a critical VLAN should be allowed access to the network without authentication. Which feature should be configured on the switch to meet this requirement?
121A network engineer is configuring OSPF on a Cisco router. The router is connected to a broadcast network with multiple OSPF neighbors. The engineer wants to ensure that this router does not become the Designated Router (DR) or Backup Designated Router (BDR) on this network. Which configuration achieves this goal?
122A network engineer is configuring a VXLAN overlay. The underlay is an IP-routed network, and the engineer needs to ensure that the VXLAN tunnel endpoints can discover each other's VTEP IP addresses dynamically. Which technology should be used?
123A network engineer is deploying Cisco TrustSec in a campus network. The engineer needs to implement Security Group Tag (SGT) propagation and enforcement. Which two methods can be used to propagate SGTs? (Choose two.)
124A network engineer is deploying a new branch office router that must obtain its WAN interface IP address dynamically from the ISP while also advertising its LAN prefix into OSPF. The engineer configures the WAN interface with the ip address dhcp command. Which additional configuration is required on the router to ensure the LAN prefix is advertised into OSPF with the correct network statement when the WAN IP changes?
125A network engineer is configuring a Cisco IOS switch to use 802.1X authentication for endpoints connected to interface GigabitEthernet1/0/1. The engineer wants to ensure that if the RADIUS server is unreachable, the port will be placed in a restricted VLAN. Which command should be used?
126A network engineer is implementing a first-hop redundancy protocol on a pair of Cisco switches. The design requires that the virtual IP address be the same as one of the physical interface addresses, and that the standby group use a virtual MAC address of 0000.0c07.acXX. Which protocol meets these requirements?
127A network engineer is implementing a first-hop redundancy protocol on a pair of Cisco switches. The design requires that the standby router take over if the active router fails, and that the virtual MAC address be 0000.0c07.ac0a. Which protocol and group number are being used?
128A network engineer is configuring QoS on a Cisco IOS router. The engineer needs to ensure that packets marked with DSCP AF31 are placed into a queue that guarantees at least 30% of the interface bandwidth during congestion, while allowing other traffic to use any remaining bandwidth. Which configuration should be used?
129A network architect is designing a data center fabric that must support Layer 2 extension over a Layer 3 underlay while using a control-plane protocol that advertises MAC reachability. The design requires the use of a protocol that encapsulates Layer 2 frames in IP packets and uses an EVPN address family for MAC/IP advertisement. Which technology best meets these requirements?
130A network engineer is implementing a Cisco TrustSec solution. The engineer needs to classify traffic based on user identity and apply security policies accordingly. Which component is responsible for tagging packets with a Security Group Tag (SGT) at the ingress point?
131A network engineer is configuring a Cisco IOS switch with 802.1X authentication. The switch is connected to a Cisco IP phone, and a PC is connected to the phone's PC port. The engineer wants to authenticate both the phone and the PC using 802.1X. Which feature should be configured to allow both devices to authenticate on the same switch port?
132A network engineer at a branch office needs to configure a Cisco IOS router to obtain its WAN interface IPv4 address dynamically from the ISP using DHCP while also ensuring the ISP can reach a web server hosted on the internal LAN at 10.10.10.50. Which single command on the router's WAN interface accomplishes the address acquisition requirement?
133A network administrator is configuring a Cisco Catalyst switch to assign a voice VLAN to IP phones and a data VLAN to connected PCs on the same port. The phones are Cisco and use CDP to communicate VLAN information. Which configuration should be applied to the switch port?
134A network administrator is configuring a Cisco switch port that connects to an IP phone and a PC. The phone must tag voice traffic with VLAN 200, and the PC must send untagged traffic on VLAN 100. Which configuration is required on the switch port?
135A network engineer is configuring OSPF on a multiaccess segment. The design requires that the DR/BDR election be deterministic, with Router A always becoming the DR and Router B always becoming the BDR. Both routers are Cisco IOS devices. Which configuration on Router A ensures it wins the DR election?
136An engineer configures a VXLAN tunnel between two Nexus switches acting as VTEPs. The underlay is a routed Layer 3 network using OSPF, and the loopback interfaces of the VTEPs are reachable. However, hosts in the same VXLAN VNI on different VTEPs cannot communicate. Which action should the engineer take to resolve the issue?
137A network engineer is deploying a Cisco SD-Access fabric and needs to ensure that endpoints can communicate with devices outside the fabric. The engineer configures a fabric border node. Which functionality does the border node provide in this architecture?
138A network engineer is configuring a Cisco Catalyst switch port that connects to an IP phone. The phone must place voice traffic in VLAN 200 and data traffic from a daisy-chained PC in VLAN 100. The switch port is currently configured as a static access port in VLAN 100. Which configuration must the engineer apply to meet these requirements?
139A network engineer is deploying a new branch office and needs to assign IPv6 addresses to hosts on the LAN segment. The engineer wants hosts to automatically configure their own addresses using the MAC address and the network prefix, without relying on a DHCPv6 server. Which IPv6 address assignment method should be configured on the router interface?
140A network engineer is configuring a pair of Catalyst switches to run VRRP on VLAN 10 (10.10.10.0/24). The virtual IP must be 10.10.10.1 with a priority of 110 on the primary switch and 100 on the standby. The primary switch is currently active. Which configuration on the primary switch correctly sets the VRRP priority and virtual IP?
141An engineer is configuring a Cisco Catalyst switch with VXLAN to extend Layer 2 connectivity between two data centers. The switch will act as a VXLAN Tunnel Endpoint (VTEP) and must encapsulate traffic from VLAN 10 into VXLAN VNI 10010. Which command is required to map the VLAN to the VNI?
142A network engineer is configuring a new Cisco Catalyst switch that will participate in a VTP domain. The engineer wants to ensure the switch can create, modify, and delete VLANs for the domain while also receiving updates. The switch must not overwrite the existing VLAN database on other switches in the domain. Which VTP mode should be configured?
143A network administrator is configuring a new Cisco IOS switch and wants to ensure that the management VLAN is isolated from user traffic. The administrator needs to assign an IP address to VLAN 1 for management access. Which command should be used to enter the interface configuration mode for VLAN 1?
144A network administrator is configuring a new Cisco IOS router and needs to enable OSPFv2 on an interface with the correct area and network type. The interface is a broadcast multi-access network. Which command should be used to enable OSPF on the interface and set the area to 0?
145A network engineer is deploying a new branch office that uses Cisco SD-Access. The fabric must support both wired and wireless clients, with a single control plane that provides host tracking, location, and policy enforcement. Which fabric component is responsible for these functions?
146A network administrator is configuring a Cisco IOS router to support NAT overload for a small office. The inside network is 10.1.1.0/24, and the outside interface is GigabitEthernet0/1 with IP address 203.0.113.5. The administrator wants all inside hosts to share the outside interface address for internet access. Which command is required to define the NAT pool or interface used for translation?
147A network engineer is implementing VRF-Lite on a Cisco IOS router to separate traffic from two different departments. The router has two interfaces, GigabitEthernet0/0 and GigabitEthernet0/1, each assigned to a different VRF. The engineer wants to verify that the VRFs are properly configured and that routes are being populated. Which command displays the routing table for a specific VRF?
148A network engineer is configuring OSPF on a multiaccess network. The engineer wants to ensure that only two specific routers become DR and BDR, and that other routers do not participate in the election. Which OSPF interface setting should be configured on the routers that should not become DR or BDR?
149A network engineer is configuring a Cisco IOS router to support NAT overload (PAT) for a small office. The inside network is 192.168.1.0/24, and the outside interface is GigabitEthernet0/1 with IP address 203.0.113.5. The engineer wants to translate all inside addresses to the outside interface address. Which two commands are required to complete this configuration? (Choose two.)
150A network engineer is configuring a Cisco IOS XE router to support NETCONF over SSH for automated configuration. The management application requires that the router expose a standards-based data model and that configuration changes be applied as complete, atomic transactions. Which action must the engineer take?
151A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using SHA-256 HMAC cryptographic authentication on an interface. Which command sequence correctly enables this authentication?
152A network engineer is configuring VXLAN on a Cisco Nexus switch. The engineer needs to ensure that the VXLAN tunnel endpoint (VTEP) can forward traffic between hosts in the same VXLAN segment across the Layer 3 underlay. Which two statements are true about VXLAN operation? (Choose two.)
153A network engineer is configuring a Cisco IOS router to establish a site-to-site VPN with a remote peer using IKEv2. The engineer wants to ensure that the router uses a pre-shared key for authentication and that the IKEv2 proposal uses AES-256 for encryption and SHA-256 for integrity. Which configuration sequence correctly sets up the IKEv2 proposal and keyring?
154A network engineer is configuring a new Cisco IOS router and wants to ensure that OSPFv2 adjacencies form only on the interface that connects to the trusted internal network. The router has three interfaces: GigabitEthernet0/0 (internal), GigabitEthernet0/1 (DMZ), and GigabitEthernet0/2 (Internet). The engineer enables OSPF process 1 and wants to advertise the internal network 10.1.1.0/24 while preventing OSPF from sending or receiving hello packets on the other interfaces. Which configuration accomplishes this goal?
155A network engineer is implementing VXLAN with an EVPN control plane in a data center. The engineer must ensure that the underlay network supports the required traffic and that the overlay provides optimal forwarding. Which two statements are true regarding this implementation? (Choose two.)
156A network engineer is configuring a new Cisco Catalyst 9300 switch stack. The design requires that if the active switch fails, the standby switch takes over the active role, and the member switch that was formerly standby becomes the new standby. The engineer needs to verify and influence the election order. Which mechanism determines the active and standby switch election in a switch stack?
157A network engineer is configuring a Cisco IOS router to act as a DHCP server for a subnet that also contains a DHCP relay agent. The router must ensure that DHCP clients receive the correct default gateway address of 10.1.1.1, which is the router's own interface on that subnet. Which command is required to accomplish this?
158A network engineer is configuring a Cisco IOS router to act as a DHCP server for a subnet. The router must provide IP addresses, default gateway, and DNS server information to clients. Which configuration is required?
159A network engineer is deploying a new Cisco Catalyst switch and needs to implement a loop prevention mechanism that allows rapid convergence and supports multiple VLANs. The engineer decides to use Rapid PVST+. Which statement accurately describes a characteristic of Rapid PVST+ operation?
160An engineer is deploying VXLAN with a distributed anycast gateway in a Cisco SD-Access fabric. Hosts in the same subnet are attached to different edge nodes. Which mechanism ensures that a host's default gateway MAC address is identical on every edge node while still allowing local forwarding?
161A network engineer is implementing VXLAN with an EVPN control plane in a Cisco Nexus data center. The requirement is to provide Layer 2 extension over a Layer 3 underlay while maintaining optimal forwarding and avoiding unknown unicast flooding. Which statement describes the role of the EVPN control plane in this VXLAN fabric?
162A network engineer is configuring a Cisco IOS XE router to support a site-to-site VXLAN tunnel over an existing IP underlay. The engineer must configure the NVE interface and ensure that the underlay provides the necessary transport. Which two statements are true about this configuration? (Choose two.)
163A network engineer is implementing VXLAN with BGP EVPN on Cisco Nexus switches. The underlay network is OSPF, and the overlay uses MP-BGP EVPN. The engineer wants to ensure that the VXLAN tunnel endpoints (VTEPs) can discover each other and exchange MAC and IP address information. Which statement correctly describes the role of the BGP EVPN address family in this scenario?
164A network administrator is configuring a Cisco IOS router to authenticate management users via TACACS+. The router must use the TACACS+ server at 10.1.1.100 with the shared secret 'Cisco123'. The administrator wants to ensure that if the TACACS+ server is unreachable, authentication falls back to the local database. Which configuration is required?
165A network administrator needs to configure a Cisco IOS switch to authenticate users against a RADIUS server before granting access to a switchport. The requirement is that if the RADIUS server becomes unreachable, the port should fall back to the configured access VLAN and not shut down. Which set of commands accomplishes this?
166A network engineer is configuring a Cisco IOS router for QoS and wants to ensure that voice traffic is prioritized and that excess traffic is dropped rather than buffered when congestion occurs. The engineer decides to use Low Latency Queueing (LLQ). Which two statements accurately describe the behavior of LLQ? (Choose two.)
167A network engineer is implementing VXLAN with Cisco SD-Access. The engineer needs to ensure that the fabric supports Layer 2 and Layer 3 traffic between endpoints in different subnets. Which two components are required in the VXLAN data plane to achieve this? (Choose two.)
168A network engineer is implementing Cisco TrustSec in a campus network. The security team wants to assign a security group tag to traffic based on the identity of the user authenticated via 802.1X, and then enforce policy based on that tag in the data center. Which Cisco TrustSec component is responsible for classifying the traffic with the appropriate security group tag at the access layer?
169A network engineer is implementing Cisco SD-Access and needs to configure the fabric to support both wired and wireless clients. Which two components are required to enable wireless integration in a Cisco SD-Access fabric? (Choose two.)
170A network engineer is configuring a Cisco IOS router to support NAT for a small office. The inside network uses the 192.168.1.0/24 subnet, and the outside interface is GigabitEthernet0/0 with IP address 203.0.113.5. The engineer wants to translate all inside addresses to the outside interface address. Which command is required to define the NAT source list?
171A network engineer is configuring a Cisco IOS switch and needs to ensure that a port connected to a server is placed into the forwarding state immediately when the link comes up, without going through the listening and learning states. The engineer also wants to protect against accidental loops if a switch is connected to that port. Which feature should be configured on the port?
172A network engineer is troubleshooting a Cisco SD-WAN deployment where a branch router (vEdge) is not forming a control connection with the vSmart controller. The engineer verifies that the vEdge has IP reachability to the vSmart controller's public IP address on port 12346. Which additional step is required for the control connection to be established?
173A network engineer is implementing Cisco TrustSec in a campus network. The requirement is to classify traffic based on the identity of the user and the device, and to enforce policy across the network without relying on IP addresses. Which component assigns the Security Group Tag (SGT) to the packet at ingress?
174A network administrator is configuring a VXLAN EVPN fabric. The administrator wants to optimize the forwarding of broadcast, unknown unicast, and multicast (BUM) traffic by using a multicast group per VLAN. Which VXLAN feature should be configured on the VTEPs to achieve this?
175A network engineer is implementing a REST API script to retrieve interface statistics from a Cisco IOS XE device. The engineer wants to use the most efficient method that supports HTTP/2 and streaming telemetry. Which API should be used?
176A network technician is configuring a new Cisco switch and needs to assign the management IP address to VLAN 1. Which command sequence is correct?
177A network engineer is deploying a new Cisco SD-Access fabric. The design includes underlay and overlay networks. Which two statements accurately describe the underlay network in a Cisco SD-Access fabric? (Choose two.)
178A network engineer is configuring a GRE tunnel between two Cisco IOS routers to transport multicast traffic over an IP network that does not support multicast. The engineer must ensure the tunnel is operational and multicast is forwarded correctly. Which two statements are true about GRE tunnel configuration and operation? (Choose two.)
179A network engineer is deploying Cisco SD-Access and needs to integrate a new fabric site with an existing traditional network. The requirement is to allow endpoints in the fabric to communicate with external networks while preserving their fabric-assigned IP addresses and providing policy enforcement. Which component is responsible for this integration?
Configure and verify VLANs, 802.1Q trunks, EtherChannel, OSPF/EIGRP/BGP, HSRP, NAT, and NTP on IOS-XE, interpreting show commands like show ip ospf neighbor. The critical skill is correct Layer 2/Layer 3 forwarding and routing adjacency formation.
The Courseiva 350-401 question bank contains 179 questions in the Infrastructure domain, covering the 30% of the exam attributed to this domain in the official Cisco blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Infrastructure domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included