These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.
Start Scenario PracticeA network engineer runs the following command on Switch SW5: SW5# show monitor session 5 Session 5 --------- Type : Remote Source Session Source Ports : Both : Gi1/0/1-3 Destination Ports : Gi1/0/24 Encapsulation : Replicate Based on this output, what can be concluded?
Explanation: The output shows a Remote Source SPAN (RSPAN) session. The 'Type: Remote Source Session' indicates that traffic from source ports Gi1/0/1-3 is mirrored and sent to a remote VLAN (the RSPAN VLAN) via the destination port Gi1/0/24, which acts as a reflector port. The 'Encapsulation: Replicate' means the destination port replicates the original frames without adding an extra VLAN tag, forwarding them onto the RSPAN VLAN for transport to a remote switch.
A network engineer is troubleshooting an STP issue in a network that uses Rapid PVST+. The network has a root bridge (SW1) and a secondary root bridge (SW2). The engineer notices that after a link failure between SW1 and SW2, the network takes longer than expected to converge. The engineer checks the configuration and finds that SW2 has the 'spanning-tree uplinkfast' command enabled. The engineer also notices that SW2 has a lower priority than SW1. What is the most likely cause of the slow convergence?
Explanation: UplinkFast is a legacy STP feature that is incompatible with Rapid PVST+. When enabled on a switch running Rapid PVST+, it forces the switch to revert to 802.1D STP convergence behavior on the affected ports, disabling the rapid transition mechanisms (such as proposal/agreement and sync). This causes the network to take longer to converge after a link failure, as the switch falls back to the slower listening and learning states.
A network engineer is configuring EIGRP on a router that connects to a service provider network. The engineer wants to advertise a default route to internal routers. The engineer configures 'ip default-network 0.0.0.0' and redistributes a static default route into EIGRP. However, internal routers are not receiving the default route. The engineer checks the EIGRP topology table and sees the default route with a metric of 1. What is the most likely reason?
Explanation: The engineer's configuration includes both 'ip default-network 0.0.0.0' (which is an IGRP command, not EIGRP) and redistribution of a static default route. The appearance of the default route in the EIGRP topology table with metric 1 indicates that redistribution occurred, but the route is not being advertised to internal routers. The most likely reason is that the static default route itself is not correctly configured. For EIGRP redistribution to succeed, the static route must point to a valid next-hop IP address using the syntax 'ip route 0.0.0.0 0.0.0.0 <next-hop>'. If the engineer used an interface instead of a next-hop, or the next-hop is unreachable, the static route may be invalid or not installed in the routing table, preventing its advertisement to EIGRP neighbors.
Which three statements about Cisco SD-Access policy enforcement are true? (Choose three.)
Explanation: Option A is correct because Scalable Group Tags (SGTs) are the fundamental mechanism for micro-segmentation in Cisco SD-Access, allowing group-based policy enforcement rather than traditional IP-based ACLs. Option D is correct because Cisco Identity Services Engine (ISE) serves as the policy plane in SD-Access, defining and managing group-based policies, SGT assignments, and TrustSec matrix rules. Option E is correct because the fabric edge node enforces policy by inspecting the SGT carried in the VXLAN-GPO header (Group Policy Option) of encapsulated traffic, applying the appropriate SGACL or contract. Option B is incorrect because SGTs can be assigned dynamically via ISE using 802.1X, MAC authentication bypass, or static mapping, not based on IP address alone. Option C is incorrect because policy enforcement in SD-Access occurs primarily at the fabric edge nodes (and fabric border for external traffic), not exclusively at the border node for all intra-fabric traffic.
Drag and drop each RESTCONF method on the left to its equivalent NETCONF operation on the right.
Explanation: Correct pairings: GET retrieves data (like get-config); POST creates a resource (like edit-config with operation create); PUT replaces a resource (like edit-config with operation replace); PATCH partially updates (like edit-config with operation merge); DELETE removes a resource (like edit-config with operation delete).
+15 more scenario questions available
Practice all Hard Difficulty QuestionsThese are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam. These appear throughout the 350-401 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-401. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-401 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Hard Difficulty Questions session with instant scoring and detailed explanations.
Start Scenario Practice →