Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.
Start Scenario PracticeWhich TWO configuration steps are required to implement static NAT on a Cisco IOS router? (Choose TWO.)
Explanation: Option A is correct because static NAT is created with the global configuration command ip nat inside source static <inside-local> <inside-global>, which permanently maps one inside local address to one inside global address. Option B is correct because the router must know which interface is the internal side, and that is done by entering the interface configuration and issuing the ip nat inside command on the interface facing the internal network. Option C is wrong because ip nat outside must be applied to the external-facing interface, not the internal one. Option D is wrong because an access list is used for dynamic NAT or PAT with the pool/overload syntax, not for a static one-to-one mapping. Option E is wrong because there is no global ip nat service command required to activate NAT on Cisco IOS; NAT is enabled by the inside/outside interface designations and the translation statements themselves.
Which TWO statements about SNMPv3 security models are true? (Choose TWO.)
Explanation: SNMPv3 defines three security levels. The noAuthNoPriv level uses a community-string-like mechanism without authentication or encryption, making it the least secure option. This is correct because it matches the RFC 3414 definition where no authentication and no privacy (encryption) are applied.
Which TWO statements about IPv6 Neighbor Discovery (ND) Inspection are true? (Choose TWO.)
Explanation: Option A is correct because IPv6 ND Inspection builds a binding table (IPv6 address to MAC address mappings learned from DHCPv6 snooping or ND messages) and validates Neighbor Solicitation and Neighbor Advertisement messages against that table, dropping messages whose source link-layer address does not match the binding. Option B is correct because ND Inspection supports per-interface configuration, including the ability to rate-limit ND packets (using the ipv6 nd inspection limit rate command) to mitigate ND flooding and DoS attacks. Option C is not correct because blocking rogue DHCPv6 servers is the function of DHCPv6 Guard, not ND Inspection. Option D is not correct because ND Inspection relies on the IPv6 snooping binding table rather than a prefix list to validate addresses. Option E is not correct because ND Inspection is configured on a per-interface basis (with a global policy applied to interfaces), not globally only.
A network engineer is troubleshooting a DMVPN Phase 3 network using Cisco IOS XE routers. The hub router is configured with a multipoint GRE tunnel and NHRP. Spoke routers are unable to establish direct spoke-to-spoke tunnels. Which two statements describe the correct operation of DMVPN Phase 3 that could explain the issue? (Choose two.)
Explanation: In DMVPN Phase 3, the hub must be configured with ip nhrp redirect, and spokes must be configured with ip nhrp shortcut. The redirect command allows the hub to notify spokes of a better path, while the shortcut command enables spokes to act on those notifications and establish direct tunnels. Without these, spoke-to-spoke traffic will continue to traverse the hub, even if other NHRP settings are correct.
A network engineer is configuring a DMVPN Phase 3 network with mGRE and NHRP. The hub router must be able to dynamically learn spoke routes and advertise them to other spokes. Which two statements are true regarding the configuration of the hub to support spoke-to-spoke communication in DMVPN Phase 3? (Choose two.)
Explanation: In DMVPN Phase 3, the hub must be configured with 'ip nhrp redirect' to inform spokes of a better direct path, and it must have a route to all spoke networks to provide initial connectivity and forwarding. The spokes require 'ip nhrp shortcut' to act on redirects. The other options are either not specific to Phase 3 or are configured on spokes.
+15 more scenario questions available
Practice all Select Two (Multi-Select) QuestionsMulti-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination. These appear throughout the 300-410 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 300-410. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 300-410 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Select Two (Multi-Select) Questions session with instant scoring and detailed explanations.
Start Scenario Practice →