Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.
Start Scenario PracticeRefer to the exhibit. A network administrator configured IP Source Guard and DHCP Snooping on a switch. A host connected to GigabitEthernet0/2 with MAC address 0050.7966.6801 has been assigned IP 192.168.1.10 via DHCP. The host now tries to use IP 192.168.1.20. What will happen?
Explanation: IP Source Guard uses DHCP snooping binding table to enforce IP-to-port mapping. When the host at GigabitEthernet0/2 with MAC 0050.7966.6801 attempts to use IP 192.168.1.20 instead of its DHCP-assigned IP 192.168.1.10, the switch compares the source IP of the packet against the binding table. Since 192.168.1.20 is not bound to that port and MAC, the switch drops all traffic from that host with source IP 192.168.1.20, preventing IP spoofing.
Refer to the exhibit. The tunnel is established but no traffic is encrypted. What is the most likely issue?
Explanation: The most likely issue is that the crypto map is not applied to the external interface. In IPsec VPN configuration, the crypto map must be applied to the interface that sends and receives encrypted traffic (typically the outside/public-facing interface). Without this application, the router does not know which traffic to protect or how to negotiate the IPsec tunnel, even if the tunnel is established (e.g., IKE Phase 1 completes). The tunnel may show as up due to successful ISAKMP negotiation, but no traffic will be encrypted because the crypto map's policy (including the access-list and transform set) is never enforced on the interface.
Refer to the exhibit. A network engineer applies a zone-based firewall policy to a router. Users in the INSIDE zone report they can access HTTP servers on the OUTSIDE zone but cannot resolve DNS names or access MS-SQL servers. What does the policy do to DNS and MS-SQL traffic?
Explanation: The zone-based firewall policy explicitly defines a class map (BAD_TRAFFIC) that matches DNS (UDP/53) and MS-SQL (TCP/1433) traffic and applies the 'drop' action. Since the policy-map uses a 'class-default' action of 'inspect' for GOOD_TRAFFIC, any traffic not matching GOOD_TRAFFIC but matching BAD_TRAFFIC is dropped before inspection can occur. The users' symptoms confirm that DNS and MS-SQL are being dropped, while HTTP (matched by GOOD_TRAFFIC) is inspected and allowed.
An administrator reviewed the log entry from the Cisco ESA exhibit. The DLP policy is set to 'Continue (with disclaimer)' for credit card matches. How should the policy be changed to prevent this data leakage?
Explanation: The current DLP policy action 'Continue (with disclaimer)' allows the email to be delivered after appending a disclaimer, which does not prevent data leakage. Changing the action to 'Drop' will block the email entirely, preventing the credit card data from leaving the organization. This directly addresses the requirement to stop the data leakage.
Refer to the exhibit. A switch port is configured for 802.1X with MAB. The switch has reached its maximum number of authentication sessions (platform limit). When a new device attempts to connect, what happens?
Explanation: When the switch reaches its platform-specific limit for authentication sessions (e.g., 256 sessions on a Catalyst 3850), no new 802.1X or MAB sessions can be initiated. The new device remains in an unauthorized state (typically in the 'critical' or 'auth-fail' VLAN, or simply blocked) because the switch cannot allocate a new session context. There is no automatic fallback or CoA action to free a session; the port stays in the unauthorized state until an existing session expires or is manually cleared.
+10 more scenario questions available
Practice all Refer to the Exhibit Practice QuestionsPractise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer. These appear throughout the 350-701 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-701. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-701 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Refer to the Exhibit Practice Questions session with instant scoring and detailed explanations.
Start Scenario Practice →