Cisco · Free Practice Questions · Last reviewed May 2026
30real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
A data center engineer is troubleshooting intermittent connectivity between two servers in different VLANs. The servers are connected to different leaf switches in a VXLAN EVPN fabric. When checking the fabric, the engineer notices that the NVE interface on one leaf is up/up but the VNI for the server VLAN is not listed in 'show nve vni'. What is the most likely cause?
MTU mismatch on the underlay network
Anycast gateway is not configured on the leaf
BGP EVPN peers are not established
The VLAN-to-VNI mapping is missing under the VLAN configuration
A VNI appears in 'show nve vni' only when its VLAN is mapped to it under the VLAN configuration. Without that mapping, the NVE interface stays up/up but the VNI is never instantiated, breaking VXLAN bridging for that VLAN across leaf switches.
A network engineer is configuring OSPF on a Cisco Nexus switch for a data center network. The requirement is to ensure that the switch does not become the Designated Router (DR) on a multi-access segment. Which OSPF configuration achieves this?
Set OSPF priority to 255 on the interface
Set OSPF priority to 0 on the interface
OSPF priority determines DR election eligibility on multi-access segments; the highest priority wins, with ties broken by router ID. Setting priority to 0 makes the interface ineligible, so the Nexus switch never becomes DR or BDR, satisfying the stated requirement.
Change the OSPF network type to point-to-point
Configure the interface as passive under OSPF
During a maintenance window, a network engineer plans to upgrade the NX-OS software on a pair of Nexus 9000 switches configured as vPC peers. The engineer wants to minimize traffic disruption. Which upgrade sequence is recommended?
Upgrade both switches simultaneously using ISSU
Reload both switches to a previous version, then upgrade
Upgrade the primary vPC peer first, then the secondary
Upgrade the secondary vPC peer first, then the primary
Upgrading the secondary vPC peer first keeps the primary forwarding traffic throughout, so the vPC domain retains at least one active member and disruption is minimal. The primary is then upgraded while the secondary carries traffic, preserving the peer link and anycast behaviour.
Which TWO statements about VXLAN BGP EVPN control plane are true? (Choose two.)
The underlay network provides IP connectivity between VTEPs
Underlay routing (e.g., IS-IS, OSPF) enables VTEP-to-VTEP reachability.
BGP EVPN advertises MAC addresses and IP addresses as routes
EVPN Type-2 routes carry MAC/IP information.
VXLAN encapsulates Ethernet frames in IP packets using MPLS labels
VXLAN uses a 32-bit network identifier (VNI)
The control plane is responsible for actual data forwarding
Refer to the exhibit. An engineer is configuring a server-facing interface on a Nexus switch. The server is running VMware ESXi with multiple virtual machines in VLANs 10, 20, and 30. After applying the configuration, the ESXi host reports that it cannot communicate on VLAN 30. Which configuration change should be made?
Remove the 'spanning-tree port type edge trunk' command
Change the native VLAN to 30
Create VLAN 30 in the global VLAN database
VLAN 30 must exist in the Nexus global VLAN database before it can be assigned to the server-facing interface or carried in a trunk. Without it, the switch drops VLAN 30 traffic, so the ESXi host cannot communicate on that VLAN.
Configure the port as an access port in VLAN 30
Refer to the exhibit. A VXLAN VNI (10030) is operationally down. What is the most likely cause?
The source interface loopback0 is not up
The NVE mode should be L2VPN instead of L3VPN
The VLAN associated with VNI 10030 is not configured or mapped
The VNI must be mapped to a VLAN using 'vn-segment vlan-id' under the VLAN configuration; missing mapping causes operational down.
The multicast group 239.1.1.1 is not reachable
Want more Network practice?
Practice this domainAn engineer is configuring a Fibre Channel over Ethernet (FCoE) SAN. Which statement about FCoE Initialization Protocol (FIP) is true?
FIP operates only over lossless Ethernet.
FIP uses Ethernet MAC addresses for communication.
FIP operates at Layer 2, encapsulating its discovery, login and keepalive frames directly in Ethernet frames addressed by MAC addresses, since FCoE has no native Fibre Channel link layer before FIP establishes the virtual link. This distinguishes it from FC, which addresses ports by 24-bit N_Port IDs.
FIP is used only for FCoE initialization, not for maintenance.
FIP requires IP addresses to establish FCoE sessions.
A storage administrator needs to ensure that a Fibre Channel zone configuration is operationally effective without disrupting the current active zone set. Which approach should be used?
Create the new zone configuration in the defined configuration, then activate it as a new zone set.
Building the new configuration in the defined configuration and then activating it as a new zone set performs a non-disruptive change: the switch validates the new zone set before committing it, and traffic continues on the existing active zone set until activation completes.
Delete the active zone set and create a new one.
Edit the active zone set directly.
Use the 'commit' command to update the zone set.
A data center deployment uses NPV mode on a Cisco MDS switch to connect to a core Fibre Channel switch. After configuration, the NPV switch does not register with the core. What is the most likely cause?
Fibre Channel ports are in trunk mode.
The core switch has NPV mode enabled.
NPIV is not enabled on the core switch.
NPV switches register upstream as NPIV-capable nodes, so the core switch must have NPIV enabled on the relevant interface. Without NPIV on the core, the NPV switch's fabric login fails and it never registers, matching the reported symptom exactly.
The NPV switch has an incorrect domain ID.
An engineer is tuning performance for a storage network. Which two practices improve FC SAN performance?
Disabling flow control.
Using single-initiator zoning.
Single-initiator zoning isolates each host to its own target ports, preventing multiple initiators contending for the same target queue and reducing arbitration overhead. This limits interference between hosts, directly improving throughput and latency on the SAN fabric.
Ensuring adequate buffer credits.
Adequate buffer credits directly address the flow-control constraint in a Fibre Channel SAN: each credit represents a frame the receiving port can buffer, so insufficient credits stall transmission and throttle throughput. Provisioning enough credits sustains the link's full bandwidth over distance, satisfying the stem's performance-tuning requirement.
Enabling broadcast zoning.
Setting fabric login timeout to the maximum.
A SAN administrator notices intermittent connectivity issues between an initiator and target. The Fibre Channel link shows CRC errors. What is the most likely cause?
Incorrect domain ID.
Faulty SFP or fiber optic cable.
CRC errors indicate corrupted frames arriving at the receiver, which points to a physical-layer fault in the transmission path rather than zoning, login or congestion problems. A degraded SFP transceiver or damaged fibre optic cable corrupts the optical signal, producing exactly these intermittent CRC errors on the Fibre Channel link.
Buffer credit starvation.
Incorrect zone configuration.
In a Cisco UCS environment, which component provides the Fibre Channel connectivity to the SAN switches when using FCoE?
IOM (I/O Module)
Cisco VIC adapter
UCS Manager
UCS Fabric Interconnect
The Fabric Interconnect carries the FCoE traffic, converting Fibre Channel frames into Ethernet frames and presenting the uplinks to the SAN switches. This satisfies the requirement for FC connectivity to the SAN, since the blade VIC adapters connect through the FI rather than directly to the MDS fabric.
Want more Storage Network practice?
Practice this domainA network engineer wants to automate the deployment of a new VLAN across all Cisco Nexus switches in a data center using Python scripts. Which tool is most appropriate for this task?
Cisco NX-API with Python requests
NX-API exposes REST endpoints on Nexus switches, letting Python requests issue structured configuration calls directly over HTTPS. This satisfies the requirement to automate VLAN deployment across all switches, unlike screen-scraping CLI or agentless tools that lack native Nexus configuration semantics.
SSH CLI commands via Paramiko
Ansible playbook
SNMP SET commands
A data center team is troubleshooting an automation script that uses REST API to configure a Cisco Nexus 9000 switch. The script fails with a '401 Unauthorized' error. What is the most likely cause?
API rate limiting has been exceeded
Network connectivity issue between the script and the switch
The user account does not have admin privileges
Invalid or expired authentication token
A 401 response means the request lacked valid credentials, so the REST API rejected it before processing. An invalid or expired authentication token satisfies the stem's failure condition, since the script's structure and payload are irrelevant until the token is refreshed.
An engineer is designing an automation solution for a large data center with multiple Cisco UCS Manager domains. Which approach best ensures idempotent configuration operations?
Writing imperative Python scripts that execute CLI commands
Using a declarative automation tool like Ansible with idempotent modules
Ansible modules are declarative and idempotent: rerunning a playbook converges each Cisco UCS Manager domain to the desired state without duplicating changes. This satisfies the stem's requirement for idempotent operations across multiple domains, unlike imperative scripting that reapplies commands unconditionally.
Directly calling UCS Manager XML API using POST requests
Using SNMP to set configuration parameters
A network engineer is implementing automated configuration management using Cisco NSO (Network Services Orchestrator). The team wants to ensure that any configuration changes made directly on the devices (out-of-band) are detected and reconciled. Which NSO feature should be used?
Configuration Database (CDB) snapshots
Fast-map synchronization
Fast-map synchronisation reconciles NSO's CDB with live device configuration by reading the device and updating the CDB, detecting out-of-band changes. It satisfies the requirement to detect and reconcile direct device edits, unlike slow-map, which pushes NSO state to devices and would overwrite rather than detect those changes.
Service model templates
Rollback and recovery mechanism
Which TWO statements about Cisco NX-API are correct? (Choose two.)
NX-API uses SSH for transport.
NX-API only supports GET requests.
NX-API uses HTTP/HTTPS as the transport protocol.
NX-API transports requests over HTTP or HTTPS, satisfying the stem's requirement for a correct statement about its operation. HTTPS adds TLS encryption, while HTTP sends data in clear text. This distinguishes NX-API from CLI-only access methods such as SSH or Telnet, and enables browser-based and programmatic interaction with the switch.
NX-API is only available on Nexus 3000 series switches.
NX-API can output data in XML and JSON formats.
NX-API returns structured output in both XML and JSON, letting scripts parse responses without screen-scraping CLI text. This satisfies the stem's requirement for correct NX-API statements, since JSON suits modern automation tooling while XML supports legacy integrations, and both are natively produced by the HTTPS-based API.
Which THREE statements about Cisco UCS Manager automation using XML API are correct? (Choose three.)
Operations can be made idempotent by using the 'dn' (distinguished name) to specify the exact object.
Idempotency is achieved by targeting specific objects.
The XML API is based on a management information model (MIT) similar to ACI.
UCS Manager uses a MIT similar to ACI.
The API uses XML for both request and response payloads.
It is an XML-based API.
The API uses SNMP for configuration changes.
The UCS Manager XML API uses RESTful JSON format.
Want more Automation practice?
Practice this domainWhich TWO statements correctly describe the use of Cisco UCS Manager service profiles for server deployment?
Service profiles can only be applied to servers of the same model.
Service profiles decouple server identity from hardware, enabling rapid provisioning.
Service profiles abstract server identity, allowing quick redeployment.
A service profile can be associated with multiple servers simultaneously.
Service profiles are stored locally on the server's boot drive.
Service profiles include policies for firmware, BIOS, boot order, and network.
Service profiles encapsulate all server identity and policy settings.
A company is deploying a new Cisco UCS Mini with a single Fabric Interconnect 6324. They need to connect to an existing Fibre Channel SAN. Which action is required to enable Fibre Channel connectivity?
Enable NPV mode on the Fabric Interconnect to connect to the SAN.
Install a Fibre Channel module in the Fabric Interconnect.
Add a Cisco MDS 9148S Fibre Channel switch and connect it to the Fabric Interconnect via FC uplinks.
Configure the uplink Ethernet ports as unified ports to support Fibre Channel.
Correct. The unified ports on the 6324 must be configured as FC uplinks to provide Fibre Channel connectivity.
A UCS administrator needs to deploy 20 identical servers with the same firmware, BIOS, and boot order. Which approach is the most efficient?
Use a UUID suffix pool to auto-generate identities.
Use a Cisco UCS Central 'Gold' template to deploy the servers.
Create a service profile template and then generate service profiles from it.
A service profile template defines firmware, BIOS and boot order once, then generating service profiles from it applies those identical settings across all 20 servers. This satisfies the efficiency constraint by eliminating repeated manual configuration, ensuring consistency and reducing deployment effort.
Create a service profile for each server manually.
A company is deploying a Cisco UCS Mini in a remote office. They need to support both VMware vSphere and Microsoft Hyper-V on the same UCS domain. What is the best practice for deploying compute resources for both hypervisors?
Create separate service profile templates for each hypervisor
Separate service profile templates let each hypervisor receive its own BIOS policy, boot order and firmware package, since vSphere and Hyper-V demand different local disk and SAN boot settings. This satisfies the stem's requirement to run both hypervisors within one UCS domain without policy conflicts.
Use a single service profile but assign different VLANs for management traffic
Place each hypervisor in a separate UCS Organization within the same service profile template
Create a single service profile template and use different identity pools for each hypervisor
A Cisco UCS Manager administrator notices that a newly provisioned service profile is showing 'Config Error' for the vNIC. The vNIC is configured to use a dynamic MAC address from a pool that has no free addresses. What is the correct remediation?
Add more MAC addresses to the MAC pool used by the vNIC
Expanding the MAC pool directly resolves the exhaustion causing the 'Config Error'. UCS Manager allocates dynamic MAC addresses from the named pool at service profile association; with zero free addresses, allocation fails and the vNIC flags the error. Adding addresses restores available entries, allowing the next association or re-apply to succeed.
Upgrade the firmware on the Fabric Interconnect
Change the vNIC to use a static MAC address
Reassociate the service profile to a different blade
Which THREE are benefits of using Cisco UCS Manager to manage compute resources? (Choose three.)
Centralized management of multiple chassis
UCS Manager provides a single management domain spanning multiple chassis, so administrators configure and monitor all fabric interconnects, blades and service profiles from one interface. This eliminates per-chassis logins, directly satisfying the centralised management benefit the question requires.
Direct management of virtual machines
Policy-based provisioning to automate server deployment
Service profiles and templates let UCS Manager apply policy-based provisioning, so a server's identity, firmware and network settings deploy automatically from a single policy. This removes manual, per-blade configuration, directly delivering the automated server deployment benefit the question asks about.
Improved performance by disabling hardware features
Unified fabric for LAN and SAN traffic
Cisco UCS Manager consolidates LAN and SAN traffic onto a single unified fabric through FCoE and converged network adapters, eliminating separate switching paths. This satisfies the benefit of reduced cabling and adapter count while managing both traffic types under one management domain.
Want more Compute practice?
Practice this domainA customer is deploying Cisco ACI with a requirement to isolate tenant traffic in a multi-tenant environment. They want to ensure that a tenant admin can only manage their own tenant's objects. Which RBAC configuration should be implemented?
Assign the 'read-only' role to the user within the tenant.
Create a separate VRF for each tenant and assign admin to that VRF.
Create a security domain for each tenant and assign the 'tenant-admin' role to the user within that domain.
Security domains partition the fabric so a tenant admin's RBAC role applies only within their assigned domain. Scoping the tenant-admin role to a per-tenant domain restricts object management to that tenant, meeting the isolation requirement.
Assign the 'tenant-admin' role to the user globally.
A network administrator suspects that a rogue DHCP server is active on the data center network. The switches are Cisco Nexus 9000 series running NX-OS. Which configuration should be applied to prevent DHCP spoofing?
Enable dynamic ARP inspection on all VLANs.
Enable IP source guard on all access ports.
Enable DHCP snooping globally and configure uplink ports as trusted.
DHCP snooping globally filters server messages on untrusted ports, while marking uplink ports trusted permits legitimate replies from the real DHCP server. Rogue offers arriving on access ports are dropped, directly preventing DHCP spoofing on the Nexus 9000 fabric.
Enable MAC port security on all access ports.
An engineer is configuring Cisco ACI to secure inter-tenant traffic. Tenants 'TenantA' and 'TenantB' need to communicate via a shared service, such as a DNS server in TenantA. How should the contract be configured?
Create a contract in TenantA and apply it to the VRF shared between tenants.
Create a contract in TenantA. Set the DNS EPG as provider. In TenantB, create a consumer EPG and provide the contract from TenantA.
Contracts are unidirectional and defined in the provider's tenant. Placing the contract in TenantA with the DNS EPG as provider, then having TenantB consume it, permits the required cross-tenant communication while keeping the contract owned by the provider.
Create a contract in TenantB. Set the DNS EPG as consumer. In TenantA, create a provider EPG and provide the contract from TenantB.
Create a contract in TenantA. Set both DNS EPG and TenantB EPG as providers.
Which TWO of these are best practices for securing the Cisco ACI fabric?
Use security domains to control RBAC.
Security domains scope a user's RBAC permissions to specific tenants, fabrics or APIC resources, so an administrator cannot modify objects outside their assigned area. This limits blast radius from compromised or misused accounts, a core ACI fabric hardening practise.
Use in-band management for APIC connectivity.
Enable certificate-based authentication for APIC access.
Certificate-based authentication for APIC access replaces shared passwords with per-user X.509 credentials, satisfying the stem's requirement for fabric hardening. It enforces identity verification at the management plane, supports revocation, and integrates with Microsoft Entra ID via SAML or LDAP, reducing credential-theft risk across administrative sessions.
Leave default passwords for fabric discovery.
Place APIC controllers in a DMZ.
Which TWO of the following are required components for a Cisco ACI contract to allow communication between EPGs?
A filter that specifies the traffic parameters.
An ACI contract requires at least one subject, and each subject contains a filter defining the permitted traffic parameters such as EtherType, protocol, and port ranges. Without a filter, the contract cannot classify or permit any traffic between EPGs.
A subject that defines the filter.
A contract must contain at least one subject, which groups one or more filters and defines whether traffic is permitted or denied. The subject is the mandatory structural element that binds filters into an enforceable contract between EPGs.
A tenant.
A QoS class.
A VRF.
A large financial institution has a Cisco ACI fabric with multiple tenants. The security team requires that all management access to the APIC controllers be authenticated via multi-factor authentication (MFA) using a RADIUS server. The RADIUS server is configured to send a One-Time Password (OTP) challenge during authentication. The current configuration uses local authentication. The engineer needs to implement RADIUS authentication with MFA for APIC GUI and CLI access. The RADIUS server is reachable at 10.10.10.10, shared secret 'SecureSecret123'. The APIC is running software version 4.2(3). The engineer must ensure that local authentication is used as fallback if the RADIUS server is unreachable. Which of the following actions should the engineer take?
Configure TACACS+ as the authentication protocol and set the server IP and secret.
Enable local authentication only and require strong passwords.
Add a RADIUS provider with IP 10.10.10.10 and secret 'SecureSecret123', create a login domain with realm 'radius', set fallback to 'local', and assign the domain to users.
Adding the RADIUS provider, creating a login domain with realm radius, and setting fallback to local satisfies MFA via OTP challenge while preserving local authentication if the server is unreachable, covering both GUI and CLI access.
Configure LDAP authentication with the RADIUS server acting as an LDAP proxy.
Want more Security practice?
Practice this domainThe 350-601 exam has 90 questions and must be completed in 120 minutes. Cisco passing scores vary by exam version and are not always publicly listed. Check the official Cisco exam page before booking.
CLI output interpretation, network topology analysis, routing behaviour, switching concepts, troubleshooting, and configuration questions.
The exam covers 5 domains: Network, Storage Network, Automation, Compute, Security. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Cisco 350-601 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.