Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.
Start Scenario PracticeWhich THREE are benefits of using Cisco UCS Manager to manage compute resources? (Choose three.)
Explanation: Cisco UCS Manager provides a single pane of glass for the entire UCS domain, so option A (Centralized management of multiple chassis) is correct because one UCS Manager instance can manage up to 20 chassis and hundreds of blades from a single interface. Option C (Policy-based provisioning to automate server deployment) is correct because UCS Manager uses service profiles and pools (UUID, MAC, WWN, BIOS, boot policy) to abstract hardware and automate consistent, repeatable server deployment. Option E (Unified fabric for LAN and SAN traffic) is correct because UCS Manager manages the fabric interconnects that carry both Ethernet LAN and Fibre Channel SAN traffic over a unified fabric (FCoE), reducing cabling and adapters. Option B is not a UCS Manager benefit because UCS Manager manages physical compute, network, and storage-access resources, not guest VMs, which are managed by hypervisors such as vCenter or Hyper-V. Option D is incorrect because UCS Manager does not improve performance by disabling hardware features; it enables features and applies BIOS/firmware policies, and disabling hardware would generally reduce capability rather than improve performance.
Which THREE are best practices for securing a data center network? (Choose three.)
Explanation: Device hardening, such as disabling unused services, is a fundamental best practice for securing a data center network. By reducing the attack surface, you eliminate potential entry points for exploits, which is a core principle of Cisco's secure network design. This aligns with the Cisco Nexus and IOS-XE hardening guidelines, where services like HTTP, Telnet, or CDP are disabled to prevent unauthorized access or reconnaissance.
A network engineer is deploying a VXLAN EVPN fabric using Cisco Nexus 9000 switches. The engineer must configure the underlay to support load balancing of VXLAN traffic across multiple equal-cost paths. Which two actions are required to achieve this? (Choose two.)
Explanation: To load-balance VXLAN traffic across multiple equal-cost paths, the underlay must have multiple equal-cost routes installed in the routing table, and the switch must hash traffic using fields that vary per flow. Including Layer 4 information, especially the source UDP port, provides the necessary entropy. The routing protocol must support ECMP and be configured to install multiple paths. Together, these actions enable effective distribution of VXLAN traffic.
Which three features are used on Nexus switches to mitigate Layer 2 attacks? (Choose three.)
Explanation: DHCP Snooping (A) is correct because it builds a trusted binding table of MAC-to-IP-to-port mappings by inspecting DHCP traffic, which prevents rogue DHCP servers and serves as the foundation for other Layer 2 protections. IP Source Guard (C) is correct because it uses the DHCP Snooping binding table to filter out frames with spoofed source IP or MAC addresses on untrusted ports, blocking IP/MAC spoofing attacks. Dynamic ARP Inspection (D) is correct because it validates ARP packets against the DHCP Snooping binding database, dropping ARP spoofing/poisoning attempts used for man-in-the-middle attacks. RBAC (B) is not a Layer 2 attack mitigation but an access-control mechanism for managing user privileges on the switch, and CoPP (E) is a control-plane policing feature that rate-limits traffic destined to the CPU, protecting the control plane rather than mitigating Layer 2 attacks like spoofing or DHCP/ARP abuse.
A UCS administrator is planning to deploy stateless computing using service profiles. Which three components are abstracted from the physical hardware and defined in the service profile? (Choose three.)
Explanation: In Cisco UCS stateless computing, the service profile holds all identity and configuration data that can follow a server across hardware. Option A (Boot order) is correct because the boot policy, including boot order, is defined in the service profile and applied to the server. Option B (MAC addresses for vNICs) is correct because MAC addresses are pool-derived identities assigned to vNICs in the service profile, enabling consistent network identity. Option D (Server UUID) is correct because the server UUID is a logical identity defined in the service profile and presented to the OS. Option C (Physical disk serial numbers) is not abstracted; disk serial numbers are physical hardware identifiers tied to the actual drives. Option E (CPU model) is not abstracted; the CPU model is a physical hardware attribute of the server and cannot be defined in a service profile.
+15 more scenario questions available
Practice all Select Two (Multi-Select) QuestionsMulti-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination. These appear throughout the 350-601 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-601. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-601 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Select Two (Multi-Select) Questions session with instant scoring and detailed explanations.
Start Scenario Practice →