Reinforce 300-410 concepts with active-recall study cards covering all 4 blueprint domains. Each card shows the question on the front and the correct answer with a full explanation on the back.
Flashcards work through active recall — the process of retrieving information from memory rather than passively re-reading it. Research consistently shows that active recall produces stronger, longer-lasting memory than re-reading study guides. For 300-410 preparation, this means flashcards are one of the highest-return study tools available.
Attempt recall first
Read the 300-410 question on each card, pause, and attempt to formulate the answer in your own words before revealing. This retrieval attempt — even if wrong — dramatically strengthens memory compared to immediately reading the answer.
Review wrong cards again
When you get a card wrong, note it and add it back to your review pile. Spaced repetition — seeing difficult cards more frequently — is the mechanism that makes flashcard study far more efficient than linear reading.
Study by domain
Group your 300-410 flashcard sessions by domain for the first 3–4 weeks. Master one domain before moving to the next. In the final week, shuffle all cards together to test cross-domain recall — which is what the real 300-410 exam requires.
Short sessions beat marathon reviews
20–30 flashcard cards per session, done daily, produces better retention than a single 200-card marathon session. Five short daily sessions per week over 4 weeks gives you over 400 total card reviews — enough to reliably pass 300-410.
Sample cards from the 300-410 flashcard bank. Read the question, think of the answer, then read the explanation below.
A network engineer is troubleshooting a DMVPN Phase 3 hub-and-spoke topology. Spoke routers are Cisco IOS devices running EIGRP as the routing protocol. The engineer wants to ensure that spoke-to-spoke traffic does not go through the hub after the initial path setup, and that spoke routers can dynamically form direct tunnels. Which NHRP command must be configured on the hub to enable this behavior?
ip nhrp redirect
For DMVPN Phase 3, the hub must be configured with 'ip nhrp redirect' to send redirect messages to spokes, allowing them to establish direct tunnels. Spokes must have 'ip nhrp shortcut' to act on those redirects. Without the hub redirect, spokes would continue sending traffic through the hub even after initial NHRP resolution.
A network engineer is configuring a static route on a Cisco IOS router to reach the network 192.168.2.0/24 via the next-hop address 10.1.1.2. The engineer enters the command 'ip route 192.168.2.0 255.255.255.0 10.1.1.2'. However, the route does not appear in the routing table. What is the most likely reason?
The next-hop address 10.1.1.2 is not reachable.
A static route is only installed in the routing table if its next-hop address is reachable. The next-hop 10.1.1.2 must be reachable via a directly connected interface or another route. If it is not reachable, the static route remains in the configuration but is not active. The subnet mask is correct, and no special keywords are needed for basic installation. Thus, the most likely reason is that the next-hop is unreachable.
A network engineer is configuring OSPFv3 on a Cisco router. The router has two interfaces in Area 0: GigabitEthernet0/0 (IPv6 address 2001:db8:1::1/64) and GigabitEthernet0/1 (IPv6 address 2001:db8:2::1/64). After enabling IPv6 unicast routing and configuring OSPFv3 with the router-id 1.1.1.1, the engineer notices that no OSPFv3 neighbors are forming. Which action is most likely to resolve the issue?
Enable OSPFv3 on the interfaces using the ipv6 ospf 1 area 0 command.
OSPFv3 requires enabling the protocol on each interface using the ipv6 ospf process-id area area-id command. Without this, the interface does not participate in OSPFv3, and no hellos are sent or received. The router ID and network type are secondary. Assigning IPv6 addresses from the same subnet is irrelevant because OSPFv3 uses link-local addresses for neighbor discovery.
A network engineer is configuring policy-based routing (PBR) on a Cisco IOS router. The engineer wants to route traffic from subnet 10.1.1.0/24 to a specific next-hop 192.168.1.1, while all other traffic uses the default route. The engineer configures a route map named PBR with a match statement for the subnet and a set statement for the next-hop, and applies it to the inbound interface of the subnet. However, traffic from 10.1.1.0/24 is still following the default route. What is the most likely reason?
The 'ip policy route-map' command is missing on the interface.
Policy-based routing requires the route map to be applied to an interface using the 'ip policy route-map' command. Without this command, the route map is not evaluated, and traffic follows the standard routing table. The engineer created the route map but likely did not apply it to the interface. Applying it to the inbound interface is correct for matching traffic from the subnet. The next-hop reachability is important but not the primary cause if PBR is not enabled.
A network engineer is configuring EIGRP on a Cisco router. The router has two interfaces: GigabitEthernet0/0 with IP address 10.1.1.1/24 and GigabitEthernet0/1 with IP address 10.2.2.1/24. The engineer wants to advertise both networks into EIGRP AS 100. Which configuration command is required to enable EIGRP on the interfaces?
network 10.1.1.0 0.0.0.255 and network 10.2.2.0 0.0.0.255
To enable EIGRP for IPv4 on interfaces, you use the network command under router eigrp with a wildcard mask. Each network statement specifies a range of addresses; the wildcard mask 0.0.0.255 matches a /24 subnet. Two statements are needed to cover both 10.1.1.0/24 and 10.2.2.0/24. The other options are either too broad, invalid syntax, or for IPv6.
A network administrator is troubleshooting an OSPFv3 network. Routers R1 and R2 are in the same area and on the same broadcast segment, but they are not forming an adjacency. The administrator verifies that the interfaces are up and IPv6 addresses are configured correctly. Which command should be used to check if OSPFv3 is enabled on the interfaces?
show ipv6 ospf interface
To verify OSPFv3 interface configuration, the 'show ipv6 ospf interface' command is used. It shows whether OSPFv3 is enabled on the interface, the area, network type, and other parameters. This is the most direct way to confirm OSPFv3 is active on the interfaces.
A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. Spokes are behind dynamic NAT and register with the hub using their public IP addresses. The engineer wants to ensure that spoke-to-spoke traffic can be established directly without traversing the hub. Which NHRP configuration is required on the hub to support this?
ip nhrp redirect
In DMVPN Phase 3, the hub uses NHRP redirect to inform spokes that a more optimal path exists directly to another spoke. The hub sends an NHRP redirect message to the source spoke, which then triggers an NHRP resolution for the destination spoke's NBMA address. The spoke then establishes a direct tunnel. The hub must have ip nhrp redirect enabled, while spokes typically have ip nhrp shortcut to act on the redirect.
A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco routers. The VPN tunnel is up, but traffic from the local LAN to the remote LAN is not passing. The administrator verifies that the crypto ACLs match on both peers and that routing is correct. Which of the following is the most likely cause?
NAT is translating the traffic before it is encrypted, causing the IPsec peer to drop the packets.
When NAT and IPsec are configured on the same router, outbound traffic may be translated by NAT before it is encrypted. If the translated source address does not match the crypto ACL, the remote peer will drop the packets because they do not match the interesting traffic. The tunnel remains up because Phase 1 and Phase 2 SAs are established, but data traffic fails. The fix is to configure a NAT exemption (deny statement) for the VPN traffic in the NAT ACL.
A network engineer is configuring a site-to-site DMVPN Phase 3 hub-and-spoke topology. The hub router is configured with tunnel mode gre multipoint. Spokes are unable to dynamically form tunnels with each other when the hub is reachable. Which additional configuration on the hub enables spoke-to-spoke direct tunnels in Phase 3?
Enable NHRP redirect on the hub tunnel interface.
In DMVPN Phase 3, the hub uses NHRP redirect to notify a spoke that a more optimal path exists to another spoke. The spoke then uses NHRP shortcut to resolve the destination and establish a direct tunnel. Configuring NHRP redirect on the hub is essential to enable spoke-to-spoke communication without traversing the hub for every packet.
A network administrator is configuring a Cisco IOS router to authenticate SSH users against an external TACACS+ server. The TACACS+ server is reachable at 10.10.10.5, and the shared secret is 'Cisco123'. The administrator wants to ensure that if the TACACS+ server is unreachable, a local user account 'backup' with privilege level 15 is used for authentication. Which configuration sequence correctly achieves this?
aaa new-model aaa authentication login default group tacacs+ local username backup privilege 15 secret Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123
The correct configuration must enable AAA, set the default login authentication to use TACACS+ first and then the local database, create a local user with privilege 15, and define the TACACS+ server with the correct IP and key. The fallback to local is essential for when the TACACS+ server is unreachable, and using 'secret' is best practice for storing the local password securely.
A network engineer configures a Cisco IOS router with the following commands: ip access-list extended BLOCK_TELNET deny tcp any any eq 23 permit ip any any ! interface GigabitEthernet0/0 ip access-group BLOCK_TELNET in After applying the configuration, the engineer notices that Telnet traffic from the local router to a remote device is still successful. What is the cause of this issue?
The access list is applied in the inbound direction, which only filters traffic entering the interface, not traffic originated by the router.
Access lists applied to an interface with the ip access-group command filter only traffic that passes through that interface in the specified direction. They do not filter traffic originated by the router itself. To control Telnet access to or from the router, an access-class must be applied under the VTY lines. Since the ACL is applied inbound on an interface, it does not affect locally generated Telnet packets, so the Telnet session succeeds.
A network administrator is configuring IPsec VPN on a Cisco IOS router. The administrator wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. The administrator has configured the crypto ACL as follows: 'access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255'. However, after applying the crypto map, the administrator notices that all traffic, including traffic to other destinations, is being dropped. What is the most likely cause?
The ACL 101 is also applied as an interface ACL in the outbound direction, and its implicit deny is dropping all other traffic.
The most likely cause is that the crypto ACL is also applied as an interface ACL, and its implicit deny is dropping all traffic that does not match the permit statement. Crypto ACLs are not meant to filter traffic; they only identify interesting traffic for encryption. If the same ACL is used for interface filtering, it will drop non-matching traffic.
A network engineer is deploying a DMVPN Phase 3 hub-and-spoke topology. The hub router must dynamically learn spoke-to-spoke routes and allow direct spoke-to-spoke tunnels. Which technology should be implemented on the hub to achieve this?
Enable NHRP redirect on the hub and NHRP shortcut on the spokes.
In DMVPN Phase 3, the hub uses NHRP redirect to inform spokes that a more optimal path exists directly to another spoke. Spokes then use NHRP shortcut to resolve the destination's NBMA address and establish a direct tunnel. This reduces hub transit and latency. The other options are valid DMVPN features but do not provide the dynamic spoke-to-spoke capability required.
A network engineer is configuring a Cisco IOS XE router to support a DMVPN Phase 3 hub-and-spoke topology. The hub router must be able to redirect spoke-to-spoke traffic without requiring the spokes to have a direct route to each other. Which technology should be implemented on the hub to enable the hub to inform the originating spoke of the optimal spoke-to-spoke path?
NHRP redirect
In DMVPN Phase 3, the hub uses NHRP redirect to notify the originating spoke that a better path exists directly to the destination spoke. The spoke then sends an NHRP resolution request for the destination spoke's NBMA address and, upon receiving a reply, establishes a direct tunnel. This optimizes traffic flow and reduces hub load. NHRP shortcut on the spoke caches the direct path, but the hub's redirect is the trigger.
A network administrator is troubleshooting an OSPFv3 network. Routers R1 and R2 are directly connected on a point-to-point link. R1 is configured with OSPFv3 area 0, and R2 is configured with OSPFv3 area 1. The administrator notices that no OSPFv3 adjacency forms between them. What is the most likely cause?
The OSPFv3 area numbers do not match on the link.
For OSPFv3 to form an adjacency, both routers on a common link must be configured in the same OSPF area. In this scenario, R1 is in area 0 and R2 is in area 1, which violates this requirement. The hello packets will be ignored, and no adjacency will form. Other potential issues like duplicate router IDs or interface configuration are not indicated by the symptoms.
A network engineer is configuring a DMVPN Phase 3 spoke router. The spoke must establish a direct tunnel to another spoke when traffic requires it. The hub is already configured with 'ip nhrp redirect'. Which additional command must be configured on the spoke to enable it to request and receive shortcut replies from the hub?
ip nhrp shortcut
In DMVPN Phase 3, the hub uses 'ip nhrp redirect' to notify spokes of a better path. The spoke must be configured with 'ip nhrp shortcut' to send NHRP resolution requests and install shortcut routes. This combination allows direct spoke-to-spoke tunnels, reducing latency and hub load. Other commands like 'ip nhrp map multicast dynamic' are hub-side multicast features and do not enable shortcut switching.
The 300-410 flashcard bank covers all 4 official blueprint domains published by Cisco. Cards are distributed proportionally, so domains with higher exam weight have more cards.
Domain Coverage
Layer 3 Technologies
VPN Technologies
Infrastructure Security
Infrastructure Services
Both flashcards and practice questions are evidence-based study tools. The difference is in what they train:
Flashcards — concept retention
Best for memorising definitions, acronyms, protocol behaviours, command syntax, and conceptual distinctions. Use flashcards to build the foundational vocabulary that 300-410 questions assume you know.
Best in: weeks 1–3
Practice tests — application
Best for applying concepts to realistic scenarios, eliminating distractors, and building exam stamina.300-410 questions test scenario reasoning — not just recall — so practice tests are essential.
Best in: weeks 3–6
The most effective 300-410 study plan combines both: use flashcards for the first 2–3 weeks to build conceptual foundations, then shift to practice tests and mock exams in the final 2–3 weeks to apply and benchmark that knowledge. Most candidates who pass on their first attempt use both tools.
Yes. Courseiva provides free 300-410 flashcards across all official exam domains. Every card includes the correct answer and a full explanation of why it is right and why the distractors are wrong. The platform also includes topic-based practice, mock exams, and readiness tracking — no account required.
Courseiva has 1401+ original 300-410 flashcards across all 4 exam blueprint domains. New cards are added regularly as the question bank grows. All cards are checked against the official Cisco exam objectives, with editorial oversight from an experienced network and security engineer.
Courseiva flashcards are purpose-built for IT certification exams. Unlike generic flashcard platforms where content quality varies, every Courseiva card is mapped to the official 300-410 exam blueprint, written by engineers who hold the certification, and includes a full explanation of the correct answer and why the distractors are wrong. This explanation quality is what separates genuine learning from rote memorisation.
Courseiva is a web platform — an internet connection is required. For offline study, we recommend creating free Courseiva account, using the platform in your browser, and using your device's offline capabilities if your browser supports offline web apps.
Save your results, see which domains need more work, and get spaced repetition recommendations — all free.
Sign Up FreeFree forever · Every certification included