Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.
Start Scenario PracticeA network engineer is deploying Cisco SD-WAN in a hybrid cloud environment. The company requires secure segmentation between guest, employee, and IoT traffic across all branches. The engineer must ensure that traffic from each segment is isolated and that policies can be applied per segment. Which two components are used to achieve this segmentation? (Choose two.)
Explanation: In Cisco SD-WAN, segmentation is achieved by creating VPN segments in vManage and mapping them to VRF instances on the WAN Edge devices. The VPN segments define the logical separation, and the VRFs enforce it by maintaining separate routing and forwarding tables. Together, they provide end-to-end isolation and allow policies to be applied per segment. Other options like VLANs or IPsec tunnels do not provide fabric-wide segmentation, and application-aware routing policies are for path selection, not isolation.
Which two statements about Type 1 and Type 2 hypervisors are true? (Choose two.)
Explanation: Option A is correct because a Type 1 (bare-metal) hypervisor, such as VMware ESXi, Microsoft Hyper-V Server, or Citrix XenServer, installs and runs directly on the physical hardware and does not require an underlying host operating system. Option D is correct because VMware Workstation is a Type 2 (hosted) hypervisor that installs as an application on top of an existing host OS like Windows or Linux. Option B is incorrect because it describes a Type 1, not a Type 2, hypervisor — Type 2 hypervisors require a host operating system. Option C is incorrect because VMware ESXi is a Type 1 bare-metal hypervisor, not Type 2. Option E is incorrect because Type 1 hypervisors are typically deployed in data centers and server virtualization scenarios, whereas Type 2 hypervisors are more commonly used for desktop virtualization and testing.
Which three statements about BGP route reflectors are true? (Choose three.)
Explanation: Option A is correct because a route reflector relaxes the iBGP full-mesh requirement by reflecting routes learned from one iBGP peer to other iBGP peers (its clients and non-clients), so speakers no longer need direct sessions with every other iBGP speaker. Option C is correct because route reflectors can be arranged in a hierarchy: a route reflector can itself be a client of a higher-level route reflector, allowing large ASes to scale beyond a single cluster. Option D is correct because the CLUSTER_ID attribute (a 4-byte value, often derived from the router ID) identifies the cluster and lets a route reflector detect and drop routes that have already been reflected, preventing loops within the cluster. Option B is not correct because route reflector clients do not need to be fully meshed with each other; they only peer with the route reflector, which is the whole point of the design. Option E is not correct because loop prevention in route reflection is handled by ORIGINATOR_ID and CLUSTER_ID (and CLUSTER_LIST), not by modifying AS_PATH, which is used for inter-AS loop prevention in eBGP.
Which TWO statements are true about IP SLA? (Choose two.)
Explanation: IP SLA can be combined with tracking objects and the 'track' command to influence routing decisions. When an IP SLA probe fails or falls below a threshold, the tracked object changes state, which can trigger a route change (e.g., via a static route with a higher administrative distance or a PBR policy). This allows the network to react to network performance or reachability issues automatically.
Which three statements about VRF path isolation in a service provider network are true? (Choose three.)
Explanation: Option A is correct because a VRF (Virtual Routing and Forwarding) instance creates a separate routing table on the same physical router, so multiple customers can share the provider's physical infrastructure while their traffic and routing information remain logically isolated. Option B is correct because in MPLS L3VPN, each VRF is associated with route targets (extended BGP communities) that control which routes are exported from and imported into the VRF, thereby governing route distribution between PE routers. Option C is correct because VRF-aware features such as NAT, QoS, and ACLs can be configured within a specific VRF context, allowing per-VRF policy enforcement that maintains path isolation between customers. Option D is not correct because VRFs operate at Layer 3 by separating routing tables, whereas VLANs provide Layer 2 broadcast-domain isolation; VRF does not replace VLANs for Layer 2 segmentation. Option E is not correct because VRF-lite achieves isolation using separate routing/forwarding tables and interfaces (typically without MPLS), not by using MPLS labels.
+15 more scenario questions available
Practice all Select Two (Multi-Select) QuestionsMulti-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination. These appear throughout the 350-401 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-401. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-401 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Select Two (Multi-Select) Questions session with instant scoring and detailed explanations.
Start Scenario Practice →