These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.
Start Scenario PracticeDuring an FCoE deployment, the server team reports that hosts can reach the storage array but performance is intermittent with periodic timeouts. The network team sees no errors on the FCoE VLAN. The DCB configuration on the upstream switch shows that PFC is enabled for CoS 3. What should the engineer check next?
Explanation: D is correct because PFC (Priority Flow Control) must be consistently configured on both ends of an FCoE link to prevent frame loss. If PFC is enabled for CoS 3 on the upstream switch but not on the server's vNIC or the FCoE VLAN interfaces, the lack of lossless behavior causes intermittent timeouts and performance degradation, even if the FCoE VLAN shows no errors.
In a Cisco ACI fabric, a tenant has multiple bridge domains in the same VRF all with 'Unicast Routing' enabled and hardware proxy mode. However, endpoints in different BDs within the same VRF cannot communicate even with a contract. What is a possible reason?
Explanation: When 'Unicast Routing' is enabled on a bridge domain (BD) in hardware proxy mode, the ACI fabric relies on hardware proxy for forwarding. In this mode, ARP flooding should be disabled to prevent excessive flooding and allow the fabric to properly resolve ARP via the COOP database. If 'ARP Flooding' is enabled, the fabric floods ARP requests across all BDs, which can cause ARP resolution to fail for endpoints in different BDs because the hardware proxy expects ARP to be handled differently. This prevents inter-BD communication even with a contract in place. Therefore, having 'ARP Flooding' enabled is a possible reason for the communication failure.
Which TWO statements about Cisco TrustSec in a data center are true?
Explanation: SXP (SGT Exchange Protocol) is specifically designed to propagate Security Group Tag (SGT) information between network devices that do not support hardware-based inline tagging (e.g., older switches or routers). SXP allows these devices to participate in TrustSec policy enforcement by exchanging SGT-to-IP bindings over TCP, enabling consistent access control across heterogeneous environments.
Refer to the exhibit. A server connected to Ethernet1/1 is experiencing intermittent connectivity. The server sends BPDUs, causing the switch to place the port into a blocking state. Which configuration change should be made to prevent this while maintaining rapid convergence?
Explanation: Enabling BPDU filter on the interface prevents the switch from processing BPDUs received from the server, which stops the port from being placed into a blocking state due to BPDU reception. This maintains rapid convergence because the port remains configured as an edge port (spanning-tree port type edge trunk), allowing it to transition directly to forwarding without spanning-tree negotiation.
A large financial institution has a Cisco ACI fabric with multiple tenants. The security team requires that all management access to the APIC controllers be authenticated via multi-factor authentication (MFA) using a RADIUS server. The RADIUS server is configured to send a One-Time Password (OTP) challenge during authentication. The current configuration uses local authentication. The engineer needs to implement RADIUS authentication with MFA for APIC GUI and CLI access. The RADIUS server is reachable at 10.10.10.10, shared secret 'SecureSecret123'. The APIC is running software version 4.2(3). The engineer must ensure that local authentication is used as fallback if the RADIUS server is unreachable. Which of the following actions should the engineer take?
Explanation: It follows the required steps to configure RADIUS authentication with MFA on Cisco APIC: adding a RADIUS provider with the correct IP and shared secret, creating a login domain with realm 'radius', setting fallback to 'local', and assigning the domain to users. This ensures that the APIC sends authentication requests to the RADIUS server, which can issue an OTP challenge for MFA, and falls back to local authentication if the RADIUS server is unreachable.
+15 more scenario questions available
Practice all Hard Difficulty QuestionsThese are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam. These appear throughout the 350-601 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-601. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-601 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Hard Difficulty Questions session with instant scoring and detailed explanations.
Start Scenario Practice →