Cisco · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
35% of exam · 6 sample questions below
A network engineer is troubleshooting a DMVPN Phase 3 hub-and-spoke topology. Spoke routers are Cisco IOS devices running EIGRP as the routing protocol. The engineer wants to ensure that spoke-to-spoke traffic does not go through the hub after the initial path setup, and that spoke routers can dynamically form direct tunnels. Which NHRP command must be configured on the hub to enable this behavior?
ip nhrp map multicast dynamic
ip nhrp redirect
The 'ip nhrp redirect' command on the hub enables NHRP redirect messages, which inform spokes of a better direct path to another spoke. This allows spoke-to-spoke communication without traversing the hub after initial resolution. It is essential for DMVPN Phase 3 and works with 'ip nhrp shortcut' on spokes.
ip nhrp network-id 1
ip nhrp shortcut
A network engineer is configuring a static route on a Cisco IOS router to reach the network 192.168.2.0/24 via the next-hop address 10.1.1.2. The engineer enters the command 'ip route 192.168.2.0 255.255.255.0 10.1.1.2'. However, the route does not appear in the routing table. What is the most likely reason?
The next-hop address 10.1.1.2 is not reachable.
For a static route to be installed in the routing table, the next-hop address must be reachable via a directly connected interface or another route. If 10.1.1.2 is not reachable, the static route remains inactive and does not appear in the routing table. This is a common issue when the next-hop is not on a directly connected subnet or lacks a route.
The static route requires the 'permanent' keyword to be installed.
The subnet mask is incorrect; it should be 255.255.255.0.
The router needs a default route to install any static route.
A network engineer is configuring OSPFv3 on a Cisco router. The router has two interfaces in Area 0: GigabitEthernet0/0 (IPv6 address 2001:db8:1::1/64) and GigabitEthernet0/1 (IPv6 address 2001:db8:2::1/64). After enabling IPv6 unicast routing and configuring OSPFv3 with the router-id 1.1.1.1, the engineer notices that no OSPFv3 neighbors are forming. Which action is most likely to resolve the issue?
Assign IPv6 addresses from the same subnet to both interfaces.
Enable OSPFv3 on the interfaces using the ipv6 ospf 1 area 0 command.
OSPFv3 is enabled per interface, unlike OSPFv2 which can be enabled under router configuration. Without the ipv6 ospf 1 area 0 interface command, the interfaces do not participate in OSPFv3, so no hellos are sent or received. This command activates OSPFv3 on the interface and associates it with Area 0. Thus, neighbors will form once the interfaces are enabled.
Set the OSPFv3 network type to point-to-point on both interfaces.
Configure a 64-bit router ID using the router-id command under the OSPFv3 process.
A network engineer is configuring policy-based routing (PBR) on a Cisco IOS router. The engineer wants to route traffic from subnet 10.1.1.0/24 to a specific next-hop 192.168.1.1, while all other traffic uses the default route. The engineer configures a route map named PBR with a match statement for the subnet and a set statement for the next-hop, and applies it to the inbound interface of the subnet. However, traffic from 10.1.1.0/24 is still following the default route. What is the most likely reason?
The next-hop 192.168.1.1 is not reachable, so PBR is ignored.
The route map must be applied to the outbound interface instead of the inbound interface.
The route map is missing a 'permit' statement, causing all traffic to be denied.
The 'ip policy route-map' command is missing on the interface.
To enable PBR, the route map must be applied to the interface using the 'ip policy route-map' command. Without this command, the route map is not used, and traffic follows the normal routing table. The engineer configured the route map but may have forgotten to apply it to the interface, which is a common oversight.
A network engineer is configuring MPLS Layer 3 VPN on a Cisco IOS XR router. The engineer needs to ensure that customer routes are properly propagated across the MPLS core. Which two of the following are required to establish the VPNv4 peering between PE routers? (Choose two.)
Configure OSPF as the IGP for the MPLS core.
Enable BGP address-family vpnv4 unicast on the PE routers.
To exchange VPNv4 routes between PE routers, BGP must be configured with the VPNv4 address family. This allows the PE routers to carry customer routes with route distinguishers and route targets. Without enabling the VPNv4 address family, the PE routers cannot exchange VPN routing information, and MPLS L3VPN would not function.
Enable LDP for label distribution on the core interfaces.
Enable BGP address-family ipv4 unicast for customer routes.
Configure a route reflector or full mesh of iBGP sessions between PE routers.
VPNv4 routes are exchanged via iBGP between PE routers. To scale, a route reflector is often used to avoid a full mesh. Without either a full mesh of iBGP sessions or a route reflector, PE routers cannot propagate VPNv4 routes to each other, preventing end-to-end VPN connectivity.
A network engineer is configuring EIGRP on a Cisco router. The router has two interfaces: GigabitEthernet0/0 with IP address 10.1.1.1/24 and GigabitEthernet0/1 with IP address 10.2.2.1/24. The engineer wants to advertise both networks into EIGRP AS 100. Which configuration command is required to enable EIGRP on the interfaces?
network 10.1.1.0 0.0.0.255 and network 10.2.2.0 0.0.0.255
EIGRP uses the network command with a wildcard mask to specify which interfaces participate in EIGRP. To advertise both 10.1.1.0/24 and 10.2.2.0/24, you need two network statements: one for each subnet. The wildcard mask 0.0.0.255 matches the /24 subnet. This configuration enables EIGRP on both interfaces and advertises the connected networks. This is the correct and specific way to achieve the goal.
network 10.0.0.0
ipv6 eigrp 100 on each interface
network 10.0.0.0 0.255.255.255
Want more Layer 3 Technologies practice?
Practice this domainA network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. Spokes are behind dynamic NAT and register with the hub using their public IP addresses. The engineer wants to ensure that spoke-to-spoke traffic can be established directly without traversing the hub. Which NHRP configuration is required on the hub to support this?
ip nhrp network-id 1
ip nhrp shortcut
ip nhrp redirect
The ip nhrp redirect command on the hub enables the hub to send a redirect message to the originating spoke when it detects that traffic is being routed through the hub to another spoke. This allows the spoke to initiate a direct NHRP resolution for the destination spoke's NBMA address, enabling spoke-to-spoke tunnels. Without redirect, spokes would continue to use the hub for all inter-spoke traffic.
ip nhrp map multicast dynamic
A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco routers. The VPN tunnel is up, but traffic from the local LAN to the remote LAN is not passing. The administrator verifies that the crypto ACLs match on both peers and that routing is correct. Which of the following is the most likely cause?
The transform set is misconfigured with mismatched encryption algorithms.
The crypto map is applied to the wrong interface.
The IPsec SA lifetime is set to a lower value than the ISAKMP SA lifetime.
NAT is translating the traffic before it is encrypted, causing the IPsec peer to drop the packets.
If NAT is applied to the outbound interface before the crypto map, the source IP of the packets may be translated to the router's public IP, which does not match the crypto ACL. The IPsec peer will then drop the packets because they do not match the expected source subnet. This is a common issue when NAT and IPsec are configured on the same interface. The solution is to configure NAT exemption for the VPN traffic.
A network engineer is configuring a site-to-site DMVPN Phase 3 hub-and-spoke topology. The hub router is configured with tunnel mode gre multipoint. Spokes are unable to dynamically form tunnels with each other when the hub is reachable. Which additional configuration on the hub enables spoke-to-spoke direct tunnels in Phase 3?
Enable NHRP shortcut on the hub tunnel interface.
Set the tunnel interface to multipoint GRE on all spokes.
Enable NHRP redirect on the hub tunnel interface.
NHRP redirect is a Phase 3 feature that allows the hub to inform spokes of a better path to another spoke. When the hub receives a packet from one spoke destined to another, it sends an NHRP redirect message to the originating spoke, which then resolves the destination NBMA address and builds a direct tunnel. Without NHRP redirect, spokes continue to route through the hub, defeating the purpose of Phase 3.
Configure a unique NHRP network ID on each spoke.
A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. Spoke routers are behind dynamic NAT and cannot be reached directly. The engineer wants spoke-to-spoke traffic to bypass the hub after initial resolution. Which NHRP command on the spoke routers enables this behavior?
ip nhrp redirect
ip nhrp map multicast dynamic
ip nhrp network-id 1
ip nhrp shortcut
The ip nhrp shortcut command is configured on spoke routers in a DMVPN Phase 3 topology. When a spoke receives an NHRP redirect from the hub, the shortcut command allows it to dynamically create a direct mGRE tunnel to the destination spoke, bypassing the hub for subsequent packets. Without this command, the spoke would continue sending traffic through the hub even after receiving the redirect.
A network administrator is deploying DMVPN Phase 3 with IKEv2 between a hub and two spokes. The hub is configured with a dynamic multipoint VPN tunnel and uses NHRP. Spoke1 can reach Spoke2 via the hub, but direct spoke-to-spoke communication fails. The administrator verifies that NHRP registrations are successful and that the hub has routes to both spokes. Which action is most likely to enable direct spoke-to-spoke communication?
Configure the hub as a route reflector for BGP.
Disable split horizon on the hub's tunnel interface.
Enable NHRP redirect on the hub and NHRP shortcut on the spokes.
DMVPN Phase 3 requires NHRP redirect on the hub to inform spokes of a better path, and NHRP shortcut on the spokes to dynamically create direct tunnels. Without these, spokes continue to route through the hub. Enabling both features allows the spoke to resolve the remote spoke's NBMA address and build a direct GRE tunnel.
Configure the spokes to use the hub as the next-hop for all routes.
A network engineer is configuring a GRE tunnel between two Cisco routers. The tunnel source is a physical interface, and the tunnel destination is a loopback interface on the remote router. The engineer notices that the tunnel interface is up, but line protocol is down. What is the most likely cause?
The tunnel key is mismatched.
The tunnel destination is not reachable.
For a GRE tunnel to come up, the tunnel destination must be reachable via the underlay network. If the destination is not reachable, the tunnel interface will show up, but line protocol will be down. The engineer should verify routing to the tunnel destination and ensure that the loopback interface is advertised and reachable. This is a common issue when the underlay routing is misconfigured.
The tunnel mode is set to GRE multipoint.
The tunnel source and destination are reversed.
Want more VPN Technologies practice?
Practice this domain20% of exam · 6 sample questions below
A network administrator is configuring a Cisco IOS router to authenticate SSH users against an external TACACS+ server. The TACACS+ server is reachable at 10.10.10.5, and the shared secret is 'Cisco123'. The administrator wants to ensure that if the TACACS+ server is unreachable, a local user account 'backup' with privilege level 15 is used for authentication. Which configuration sequence correctly achieves this?
aaa new-model aaa authentication login default group tacacs+ username backup privilege 15 secret Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123
aaa new-model aaa authentication login default group tacacs+ local username backup privilege 15 password Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123
aaa new-model aaa authentication login default group tacacs+ enable username backup privilege 15 secret Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123
aaa new-model aaa authentication login default group tacacs+ local username backup privilege 15 secret Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123
This configuration enables AAA, sets the default login authentication method list to try TACACS+ first and then fall back to the local database, creates a local user with privilege 15, and defines the TACACS+ server with its IP and key. This exactly meets the requirement of using TACACS+ with local fallback and a local privileged account.
A network engineer configures a Cisco IOS router with the following commands:
ip access-list extended BLOCK_TELNET deny tcp any any eq 23 permit ip any any
!
interface GigabitEthernet0/0 ip access-group BLOCK_TELNET in
After applying the configuration, the engineer notices that Telnet traffic from the local router to a remote device is still successful. What is the cause of this issue?
The access list is applied in the inbound direction, which only filters traffic entering the interface, not traffic originated by the router.
The access list is applied inbound on GigabitEthernet0/0, so it filters only packets entering that interface. Locally generated Telnet traffic from the router does not pass through the inbound access-group; it is subject to outbound filtering on the egress interface or to a VTY access-class. Therefore, the Telnet session succeeds despite the deny statement.
The implicit deny at the end of the access list is blocking the Telnet traffic, but the 'permit ip any any' statement overrides it.
The access list must be applied with the 'ip access-group BLOCK_TELNET out' command on the same interface to filter locally generated traffic.
The 'deny tcp any any eq 23' statement is incorrect because Telnet uses TCP port 22, not port 23.
A network administrator is configuring IPsec VPN on a Cisco IOS router. The administrator wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. The administrator has configured the crypto ACL as follows: 'access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255'. However, after applying the crypto map, the administrator notices that all traffic, including traffic to other destinations, is being dropped. What is the most likely cause?
The ACL 101 is also applied as an interface ACL in the outbound direction, and its implicit deny is dropping all other traffic.
If ACL 101 is applied as an interface ACL on the outbound interface, the implicit deny at the end will drop all traffic that does not match the permit statement. The crypto ACL itself does not drop traffic, but if it is reused as an interface ACL, it will filter traffic. This is a common misconfiguration.
The crypto map is applied to the wrong interface or in the wrong direction.
The crypto ACL is missing a deny statement for other traffic, causing all non-matching traffic to be dropped by the implicit deny at the end of the ACL.
The IPsec transform set is misconfigured, causing all traffic to be dropped.
A network administrator is configuring AAA on a Cisco IOS router using TACACS+. The requirement is that if the TACACS+ server is unreachable, the router should allow administrative access using the local username and password configured on the router. Which configuration accomplishes this?
aaa authentication login default group tacacs+ enable
aaa authentication login default group tacacs+ local
This command configures the default method list for login authentication to first attempt TACACS+ and then fall back to the local username database if the TACACS+ server is unreachable. The 'local' keyword ensures that local authentication is used as a backup, satisfying the requirement.
aaa authentication login default group tacacs+ if-needed
aaa authentication login default group tacacs+ none
A network administrator is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect against DoS attacks. The administrator wants to rate-limit ARP traffic destined to the route processor. Which configuration correctly applies a CoPP policy to ARP traffic?
class-map match-all ARP_CLASS match protocol arp ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! interface Control-Plane service-policy input COPP_POLICY
class-map match-all ARP_CLASS match protocol arp ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! control-plane host service-policy input COPP_POLICY
class-map match-all ARP_CLASS match protocol arp ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP_POLICY
This configuration defines a class-map that matches ARP protocol traffic, a policy-map that applies policing to that class, and then attaches the policy to the control-plane interface using 'service-policy input'. The 'match protocol arp' command is valid for classifying ARP packets. This correctly implements CoPP for ARP.
class-map match-all ARP_CLASS match access-group name ARP_ACL ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! interface GigabitEthernet0/0 service-policy input COPP_POLICY
A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using MD5. The engineer enters the following commands:
interface GigabitEthernet0/0 ip ospf authentication message-digest ip ospf message-digest-key 1 md5 C1sco123
After applying the configuration, the OSPF neighbor relationship fails to form. Which action must the engineer take to resolve the issue?
Configure the ip ospf authentication-key command with the same password.
Change the key ID to 0 on both routers to match the default key.
Configure the same MD5 key and key ID on the neighboring router's interface.
OSPF MD5 authentication requires that both neighbors use the same key ID and key string on their interfaces. The local configuration is correct, but without matching credentials on the neighbor, authentication fails and the adjacency will not form. Therefore, configuring the matching key on the neighboring router's interface resolves the issue.
Enable OSPF authentication globally using the area authentication command.
Want more Infrastructure Security practice?
Practice this domain25% of exam · 6 sample questions below
A network engineer is deploying a DMVPN Phase 3 hub-and-spoke topology. The hub router must dynamically learn spoke-to-spoke routes and allow direct spoke-to-spoke tunnels. Which technology should be implemented on the hub to achieve this?
Configure NHRP authentication and NHRP map entries on all routers.
Implement IPsec tunnel protection with IKEv2 and enable QoS pre-classify.
Use OSPF broadcast network type on all tunnel interfaces and enable split horizon.
Enable NHRP redirect on the hub and NHRP shortcut on the spokes.
NHRP redirect on the hub and NHRP shortcut on the spokes enable Phase 3 DMVPN. The hub sends NHRP redirect messages to spokes when it receives traffic that could go directly between them, and spokes use NHRP shortcut to resolve the destination spoke's NBMA address and build a direct tunnel, reducing hub load and latency.
A network engineer is configuring a Cisco IOS XE router to support a DMVPN Phase 3 hub-and-spoke topology. The hub router must be able to redirect spoke-to-spoke traffic without requiring the spokes to have a direct route to each other. Which technology should be implemented on the hub to enable the hub to inform the originating spoke of the optimal spoke-to-spoke path?
Multipoint GRE (mGRE)
NHRP redirect
NHRP redirect is a DMVPN Phase 3 feature that enables the hub to send an NHRP redirect message to the originating spoke when it detects traffic being routed through the hub to another spoke. The redirect instructs the spoke to initiate an NHRP resolution request for the destination spoke's NBMA address, allowing the spoke to build a direct tunnel. This reduces latency and hub load, and it is the correct mechanism for the hub to inform the spoke of the optimal path.
IPsec tunnel protection
Next Hop Resolution Protocol (NHRP) shortcut
A network administrator is troubleshooting an OSPFv3 network. Routers R1 and R2 are directly connected on a point-to-point link. R1 is configured with OSPFv3 area 0, and R2 is configured with OSPFv3 area 1. The administrator notices that no OSPFv3 adjacency forms between them. What is the most likely cause?
The OSPFv3 area numbers do not match on the link.
OSPFv3, like OSPFv2, requires that routers on the same link be in the same area to form an adjacency. Since R1 is in area 0 and R2 is in area 1, the hello packets will not be accepted, and the adjacency will not form. This is the most likely cause of the problem described.
The OSPFv3 router IDs are not unique.
The OSPFv3 process is not enabled on the interfaces.
The OSPFv3 network type is mismatched.
A network engineer is configuring a DMVPN Phase 3 spoke router. The spoke must establish a direct tunnel to another spoke when traffic requires it. The hub is already configured with 'ip nhrp redirect'. Which additional command must be configured on the spoke to enable it to request and receive shortcut replies from the hub?
ip nhrp shortcut
On a DMVPN Phase 3 spoke, 'ip nhrp shortcut' enables the spoke to intercept traffic and send an NHRP resolution request to the hub for a remote spoke. The hub replies with a redirect, and the spoke installs a shortcut route, allowing direct spoke-to-spoke communication. Without this command, the spoke continues to forward traffic through the hub even if the hub is configured with 'ip nhrp redirect'.
ip nhrp redirect
ip nhrp network-id 100
ip nhrp map multicast dynamic
A network administrator is deploying MPLS Layer 3 VPNs with Cisco IOS XE routers. The administrator wants to ensure that customer routes are not leaked into the global routing table and that each VPN instance maintains separate routing and forwarding tables. Which of the following must be configured on the PE routers to achieve this isolation?
BGP route reflectors with confederation
OSPF sham links with domain ID
MPLS LDP with explicit-null and penultimate hop popping
VRF definition with route distinguisher (RD) and route target (RT) import/export policies
A VRF (Virtual Routing and Forwarding) instance creates separate routing and forwarding tables per VPN. The route distinguisher (RD) makes the customer prefix unique within the MPLS domain, while route targets (RTs) control import and export of routes between VRFs. This combination ensures isolation and proper route leaking only where intended. Without VRFs, customer routes would mix with the global table or with other customers' routes, violating the isolation requirement.
A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using MD5. The engineer wants to ensure that the authentication key is not sent in clear text and that the key can be changed without disrupting the adjacency. Which command should be used to configure the key on the interface?
area 0 authentication message-digest
ip ospf authentication message-digest
ip ospf message-digest-key <key-id> md5 <key>
The 'ip ospf message-digest-key' command with the 'md5' keyword configures an MD5 key for OSPFv2 authentication on an interface. The key is not sent in clear text; instead, an MD5 hash is used. Multiple keys can be configured with different key IDs, allowing for graceful key rollover without disrupting the adjacency. This meets both requirements.
ip ospf authentication-key <key>
Want more Infrastructure Services practice?
Practice this domainThe 300-410 exam has 90 questions and must be completed in 120 minutes. Cisco passing scores vary by exam version and are not always publicly listed. Check the official Cisco exam page before booking.
CLI output interpretation, network topology analysis, routing behaviour, switching concepts, troubleshooting, and configuration questions.
The exam covers 4 domains: Layer 3 Technologies, VPN Technologies, Infrastructure Security, Infrastructure Services. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Cisco 300-410 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.