Cisco · Free Practice Questions · Last reviewed May 2026
36real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
A company is deploying a wireless network in an office with high client density. Which Cisco architecture is best suited to handle client roaming without requiring a central controller for every roaming event?
Mesh networking
Autonomous APs
Centralized switching with a WLC
FlexConnect
FlexConnect is correct because it separates the control plane (which remains with the WLC) from the data plane (which is switched locally at the AP). This allows client traffic to be forwarded directly to the wired network at each access point, avoiding unnecessary latency and controller bottlenecks, which is ideal for high-bandwidth, high-density indoor environments. Furthermore, FlexConnect supports IEEE 802.11r fast roaming and can perform client-based or AP-based neighbor discovery when connected to a WLC, ensuring seamless and fast handoffs as users move across the office. Its design balances centralized management with localized forwarding, offering both the operational consistency of a controller and the performance of distributed switching.
An enterprise is using OSPF in a multi-area design. Area 1 is a regular area, and Area 2 is a totally stubby area. Which LSA types are present in Area 2?
Type 1, Type 2, Type 3 (including default)
In a totally stubby area, the ABR suppresses Type 4 (ASBR-summary) and Type 5 (AS-external) LSAs, and also replaces all Type 3 inter-area summaries with a single default route. This leaves only Type 1 (router) and Type 2 (network) LSAs for intra-area topology, plus the injected Type 3 default LSA for any traffic leaving the area. Therefore, the allowed LSA set is exactly Type 1, Type 2, and the default Type 3.
Type 1, Type 2, Type 3, Type 5
Type 1, Type 2, Type 4, Type 5
Type 1, Type 2, Type 3 (including default), Type 4
A network engineer is troubleshooting a routing loop in an EIGRP network. Which mechanism is designed to prevent routing loops by causing a router to reject routes that are learned from a neighbor that is not the successor?
Split horizon
Route poisoning
Hold-down timers
Feasibility condition
The feasibility condition is EIGRP's loop-free guarantee: a neighbor advertises a reported distance (RD) that is strictly lower than the current feasible distance (FD) to a destination. This proves the neighbor's path does not pass back through the local router, so the path can safely be used as a feasible successor. If no such neighbor exists, DUAL goes active and queries neighbors, but the feasibility condition remains the core mechanism ensuring that any selected path is genuinely loop-free.
A company is implementing QoS in a network where voice traffic must have strict priority over all other traffic. Which queuing mechanism should be used on the outbound interface of a router to ensure voice packets are always sent first?
Random Early Detection (RED)
Low Latency Queuing (LLQ)
LLQ (Low Latency Queuing) combines a strict-priority queue with CBWFQ: the priority queue is serviced first on every scheduling cycle, before any CBWFQ class queues, so voice is dequeued with minimal and deterministic delay. The priority queue can be policed to a configured rate to prevent a flood of priority traffic from starving the non-priority classes, but within the committed rate voice effectively experiences 'express lane' treatment. This strict-priority scheduling is exactly what makes LLQ the standard QoS queueing strategy for real-time voice traffic in an enterprise.
First In First Out (FIFO)
Class-Based Weighted Fair Queuing (CBWFQ)
A network administrator is configuring a new VLAN 100 on a switch and wants to ensure that the VLAN is created and active. Which command is required to create a VLAN in the VLAN database?
interface vlan 100
name VLAN100
vlan 100
vlan 100 is the global configuration command that creates a new VLAN with ID 100 and immediately enters VLAN configuration mode. This is the required first step when establishing a new VLAN, as it adds the VLAN to the switch's local VLAN database. From this mode, you can set optional parameters such as the VLAN name, MTU, or other interface-specific settings. Issuing this command makes the VLAN available for subsequent operations like assigning access ports or creating an SVI.
switchport access vlan 100
An engineer is troubleshooting a network where OSPF neighbors are stuck in the EXSTART state. What is the most likely cause?
Dead timer mismatch
Authentication misconfiguration
Mismatched OSPF area IDs
MTU mismatch between the routers
During the EXSTART/EXCHANGE phase, OSPF routers exchange database description (DBD) packets that can be as large as the interface MTU; if one router's MTU is lower, the larger DBD packet will be dropped or fragmented, and the neighbor will never leave EXSTART because it keeps waiting for a valid DBD sequence. The interface MTU mismatch is a classic cause of OSPF adjacencies stuck in EXSTART, as the router with the smaller MTU silently discards the oversized multicast packets. This can be diagnosed by checking the 'show ip ospf neighbor' state and by ensuring both ends have the same MTU or by enabling 'ip ospf mtu-ignore' as a workaround.
Want more Architecture practice?
Practice this domainA cloud provider uses Cisco ACI to automate provisioning of tenant networks. A new tenant requires a Layer 2 bridge domain that extends to an external Layer 2 network via a VPC. The engineer creates a bridge domain with the settings: Type: Regular, L2 Unknown Unicast: Flood, L3 Unknown Multicast Flood: Flood, and Multi-Destination Flooding: Flood. The VPC is configured as a virtual port channel. The tenant reports that broadcast traffic is not reaching the external network. What is the most likely cause?
The VPC configuration does not support L2 extension.
The bridge domain is configured as proxy mode for L2 unknown unicast.
The L2Out is not configured to flood BUM traffic.
An L2Out connects the ACI fabric to an external Layer 2 network, but by default BUM (broadcast, unknown unicast, multicast) traffic is not automatically flooded through every L2Out. The 'flood on' setting under the L2Out must be explicitly enabled so that BUM frames received in the BD are also sent to the external network; without it, BUM traffic is dropped or handled only locally. Since this L2Out lacks that flood configuration, the L2 extension does not actually extend L2 flooding, which explains the connectivity problem.
The bridge domain type should be set to 'L2 Only'.
An engineer configures VXLAN EVPN on a Nexus 9000 switch. The configuration is shown. The switch does not advertise any EVPN routes for VNI 10100. Which configuration change is required to fix this issue?
Configure "evpn" and "vni 10100 l2" under the BGP address-family l2vpn evpn.
The VNI must be explicitly activated under BGP EVPN. Without the 'vni 10100 l2' configuration inside address-family l2vpn evpn, BGP has no awareness of this L2 VNI and will not originate or import the type-2 (MAC/IP) and type-3 (inclusive multicast) routes needed for remote VTEPs to learn MAC addresses. Adding that command, along with 'evpn' as the address family, is what makes the control plane advertise the VNI. This is the missing configuration causing the issue.
Remove the mcast-group from the NVE member, because EVPN uses BGP for control plane.
Change the source-interface to a physical interface.
Add an IP address to the VLAN 100 interface in the default VRF.
Which TWO of the following are benefits of using network virtualization with VXLAN? (Choose two.)
Enables Layer 2 extension across Layer 3 boundaries.
VXLAN tunnels Layer 2 over Layer 3.
Eliminates the need for STP by using a centralized controller.
Uses only multicast for control plane learning.
Supports up to 16 million logical networks.
VNI provides 16M segments.
Provides native encryption for data in transit.
Which THREE of the following are components of a Cisco ACI fabric? (Choose three.)
Firewall
Spine switch
Spine switches form the fabric backbone.
Router
APIC controller
APIC manages the ACI fabric.
Leaf switch
Leaf switches connect to endpoints.
A financial services company has deployed Cisco UCS servers with VMware vSphere 7.0 to host critical trading applications. The network uses Cisco Nexus 9000 switches in a VXLAN EVPN fabric with BGP as the underlay. The environment includes 50 ESXi hosts, each connected via two 40G interfaces to two different leaf switches in a VPC. The VMs are spread across multiple hosts and communicate over VXLAN. Recently, the operations team migrated a set of VMs from an old VLAN-based network to a new VXLAN segment (VNI 50000). After the migration, users report intermittent connectivity issues and packet loss. The engineering team captures traffic and notices that some VMs send ARP requests that are not being replied to, even though the target VM is active. Further analysis shows that the ARP requests are being flooded to all VTEPs, but the replies are not reaching the source. The team checks the underlay and finds no issues with BGP or routing. The NVE interfaces are up, and the VNI is configured. Which of the following is the most likely cause of the issue?
The ingress replication list is missing some VTEPs.
The symmetric routing configuration is missing on the leaf switches.
The VPC configuration between the leaf switches and ESXi hosts is incorrect.
The MAC address of the target VM is not being advertised in EVPN type-2 routes because the VM's MAC is learned on a different leaf switch than expected.
In EVPN, each leaf switch advertises locally learned MAC addresses via MP-BGP Type-2 routes. If the target VM's MAC is learned on a leaf different from the one the source leaf expects, or if that leaf has not advertised the route, the source leaf has no EVPN entry for that MAC. It floods the ARP request as BUM, but the reply is sent as unicast, and without a Type-2 route the source cannot properly deliver or cache the reply, leading to unidirectional communication failure.
A network engineer is troubleshooting connectivity issues in a multi-tenant environment where each tenant's traffic is isolated using VRF-Lite. The engineer notices that tenants in the same VRF cannot communicate with each other across different access switches. Which design change should be implemented to enable inter-switch VRF communication?
Use the same VLAN for all tenants and rely on VLAN ACLs.
Create trunk links with 802.1Q subinterfaces on each switch and assign each subinterface to the appropriate VRF.
Creating an 802.1Q trunk with subinterfaces lets each switch or router terminate multiple VLANs on a single physical link, and each subinterface can be explicitly bound to a tenant's VRF. This gives each tenant an isolated routing table; the switch will route packets received on a subinterface using only the routes in that subinterface's assigned VRF. The trunk carries tagged frames for all tenants, but the VRF association ensures that traffic from tenant A's VLAN never enters tenant B's routing path, even though they share the same physical ports and trunk. This is a standard VRF-lite design for inter-switch VRF connectivity.
Configure static routes on each switch pointing to the next-hop IP in the global routing table.
Enable OSPF with a single area on all switches and redistribute between VRFs.
Want more Virtualization practice?
Practice this domainA network engineer is troubleshooting an EIGRP adjacency issue between two routers. The engineer verifies that both routers have the same K-values and autonomous system number. However, the adjacency does not form. Which configuration issue is most likely the cause?
Authentication is configured on one router but not on the other.
EIGRP authenticates each hello packet and every routing update using a configured key, typically MD5 or SHA-2. If one router has authentication enabled (e.g., 'ip authentication mode eigrp' and 'ip authentication key-chain eigrp') while the peer does not, the receiving router fails the authentication check and silently discards the hello, so no adjacency can ever form. Even a key mismatch or different key-chain name on both sides produces the same failure, making this a classic common cause of missing EIGRP neighbor relationships.
The network statement uses an incorrect subnet mask.
One router has a loopback interface that is not advertised.
The hello and hold timers do not match.
A company is implementing QoS in a campus network. Voice traffic must be prioritized over data traffic, and all traffic should be marked at Layer 2 and Layer 3. Which combination of marking values should be used on access ports to achieve this?
CoS 5, DSCP AF41
CoS 5, DSCP CS3
CoS 5, DSCP EF
CoS 5 combined with DSCP EF (Expedited Forwarding, DSCP 46) is the industry-standard marking for voice bearer traffic in a campus network. This dual marking ensures that voice frames are placed in the strict-priority queue at both Layer 2 and Layer 3, providing the low latency, low jitter, and minimal packet loss that real-time audio requires. The EF PHB (Per-Hop Behavior) is designed to guarantee a configured bandwidth and queue service, while CoS 5 aligns with the Cisco-recommended voice VLAN and switch port trust settings, making this the only correct answer.
CoS 4, DSCP EF
An engineer needs to configure a switchport to carry traffic for multiple VLANs to a router using a single physical link. Which configuration should be applied on the switchport?
Configure the port as a dynamic desirable port.
Configure the port as a trunk port.
A trunk port tags frames with 802.1Q VLAN identifiers, allowing multiple VLANs to traverse one physical link to the router. Access ports carry only a single untagged VLAN, so they cannot satisfy the multi-VLAN requirement.
Configure the port as a routed port.
Configure the port as an access port.
A network engineer is deploying a new WLAN and needs to ensure that client traffic is encrypted using AES with a pre-shared key. Which security configuration should be applied to the wireless SSID?
WPA2-PSK with AES
WPA2-PSK with AES-CCMP is the appropriate choice because it offers robust wireless encryption (AES in counter mode with CBC-MAC) and uses a pre-shared key for straightforward authentication. This configuration is widely supported, passes PCI DSS requirements for strong encryption, and fulfills the stated requirement of using AES-based security. It balances compatibility with strong protection.
WPA3-PSK with AES
WPA2-PSK with TKIP
WEP with AES
A network administrator is troubleshooting an issue where OSPF routes are not being learned from a neighbor. The administrator checks the OSPF configuration and sees that both routers are in the same area. The neighbor state is stuck in EXSTART. What is the most likely cause?
The router ID is the same on both routers.
The area ID is different.
The hello timer is set to 30 seconds on one router.
The interface MTU does not match.
An MTU mismatch is the classic cause of an OSPF neighbor being stuck in EXSTART; during the Database Description exchange, each router advertises its outgoing interface MTU in the DBD packet header. If one router's interface has a lower MTU, it discards DBD packets that declare a larger MTU, so the neighboring router never receives a valid acknowledgment and remains in EXSTART. Because OSPF does not initialize the DBD exchange until both MTUs are verified equal, the adjacency stalls at the point where the Master/Slave election occurs, exactly matching the reported symptom.
An engineer is configuring a new VLAN 100 on a switch. Which command must be used to create the VLAN?
vlan 100
The global configuration command 'vlan 100' creates VLAN 100 and enters VLAN configuration mode, allowing optional parameters such as a name or MTU to be applied. This is the standard and correct method to create a VLAN on modern Cisco IOS switches, as it directly adds the VLAN to the switch's VLAN database and running configuration. Without this command, other VLAN-related commands have no VLAN to act upon.
switchport access vlan 100
vlan database
interface vlan 100
Want more Infrastructure practice?
Practice this domainA network administrator is troubleshooting high CPU utilization on a Catalyst 9300 switch. The output of 'show processes cpu sorted' shows the 'IP Input' process consuming 45% CPU. Which tool should be used to identify the specific packets causing the issue?
Use extended ping from the switch to generate traffic.
Configure a SPAN session to capture all traffic to the CPU.
Check CDP neighbors to see if any devices are flooding.
Enable IP traffic export (NetFlow) on the switch.
NetFlow (IP traffic export) samples and exports flow records containing source/destination IP addresses, Layer 4 ports, protocol numbers, and packet/byte counts to a NetFlow collector. By analyzing these exported records, the administrator can pinpoint exactly which flows are contributing to the saturated 'IP Input' process, such as specific hosts generating large volumes of routed traffic. This local, low-overhead mechanism is specifically designed for flow-level visibility and is the correct tool for this troubleshooting scenario.
A network engineer is implementing QoS on a WAN link to prioritize voice traffic. Which queuing mechanism provides the lowest latency for real-time traffic?
Low Latency Queuing (LLQ)
Low Latency Queuing (LLQ) is correct because it integrates a strict priority queue (PQ) with CBWFQ. The LLQ scheduler always empties the priority class before servicing any other CBWFQ class, which guarantees that real-time packets like voice are dequeued first and experience minimal, jitter-free delay. To prevent the PQ from starving other classes, LLQ applies a policer to priority-class traffic, dropping or shaping excess packets while still meeting the latency objective for admitted real-time flows.
Weighted Random Early Detection (WRED)
Class-Based Weighted Fair Queuing (CBWFQ)
First-In, First-Out (FIFO)
A network administrator is troubleshooting a BGP routing issue where routes from an eBGP neighbor are not being installed in the routing table. The 'show ip bgp' output shows the routes are received but not valid. What is the most likely cause?
The AS-path contains the local AS number.
The next-hop IP address is not reachable.
Correct. For a BGP route to be considered valid and installed in the routing table, the next-hop IP address must be reachable via an IGP or static route. If the next hop is not reachable, the route will appear in the 'show ip bgp' output but be marked as not valid.
BGP synchronization is enabled.
The maximum-prefix limit has been exceeded.
A network engineer is designing a multicast network for IPTV. Which protocol is used by routers to discover which multicast groups are of interest to directly connected hosts?
Rendezvous Point (RP)
Internet Group Management Protocol (IGMP)
IGMP is the end-system to router protocol that lets hosts on a directly connected subnet announce their interest in a specific multicast group, which is exactly what an IPTV receiver must do to request a channel. Routers send general queries and process membership reports to maintain an active group list on each interface. IGMPv3 further supports source-specific joins (S,G), enabling explicit control over which IPTV streams are received. Without IGMP, the first-hop router would have no way to know that a host wants multicast traffic.
Protocol Independent Multicast (PIM)
Multicast Source Discovery Protocol (MSDP)
Which TWO statements are true about IP SLA? (Choose two.)
IP SLA is only supported on ASR routers.
IP SLA can be used with tracking objects to trigger route changes.
IP SLA operations can be tied to Cisco tracking objects using the 'track' command, where the tracked object state changes based on probe reachability or response-time thresholds. When the probe fails consecutive times, the tracking object transitions to 'down', which can trigger a floating static route, policy-based routing, or other route manipulation to redirect traffic. This creates a dynamic failover or convergence mechanism driven by synthetic traffic rather than solely by physical link state.
IP SLA can measure jitter between two devices.
IP SLA supports a UDP jitter operation that sends a series of synthetic UDP packets at a predetermined rate and interval between a source and destination running the IP SLA Responder. By embedding sequence numbers and timestamps in the packets, the operation calculates jitter (inter-packet delay variance), one-way delay, and packet loss. This provides a quantitative measure of network QoE, which is especially useful for VoIP and video traffic, and it does not rely on actual user data.
IP SLA uses actual user traffic for measurements.
IP SLA can only measure round-trip time, not one-way delay.
Which THREE are common causes of high CPU utilization on a Cisco Catalyst switch? (Choose three.)
Broadcast storms
A broadcast storm floods every port with endlessly circulating frames, forcing the switch CPU to process enormous volumes of broadcast traffic and replicate frames across the broadcast domain. This software-path processing load, rather than normal hardware switching, is what drives control-plane CPU utilisation upward.
Excessive hardware switching of packets
Low memory conditions
Frequent STP topology changes
Each STP topology change triggers recalculation, flushing MAC address tables and generating TCN BPDUs processed by the CPU. Frequent flapping or unstable links therefore cause repeated reconvergence, a well-known driver of high CPU on Catalyst switches.
ACL logging with 'log' keyword
ACL logging with the log keyword punts matching packets to the switch's CPU for syslog generation, so high traffic volumes hitting logged entries drive CPU utilisation up sharply. This is a recognised control-plane cause of elevated Catalyst switch CPU.
Want more Network Assurance practice?
Practice this domainA network engineer is configuring port security on a Cisco switch to prevent unauthorized devices from connecting. The requirement is to allow only the first two MAC addresses learned on an interface, and to disable the interface if a violation occurs. Which configuration achieves this?
switchport port-security maximum 2 switchport port-security violation err-disable
switchport port-security maximum 2 switchport port-security violation shutdown
This is the correct configuration. It sets the maximum number of secure MAC addresses to 2 and also specifies the violation action as 'shutdown'. When a third MAC address attempts to use the port, the switch places the interface in an err-disabled state, which completely disables the port and blocks all traffic, satisfying the requirement to disable the interface upon a violation.
switchport port-security maximum 2 switchport port-security violation protect
switchport port-security maximum 2 switchport port-security violation restrict
An organization wants to implement 802.1X authentication on its wired network using Cisco ISE as the authentication server. The switches are configured with the necessary RADIUS settings. Which additional configuration is required on the switch interfaces to enable 802.1X?
dot1x pae authenticator
authentication port-control auto
This command sets the port's authentication mode to auto, meaning the port will be unauthorized until the client successfully authenticates via 802.1X. It triggers the authentication process and is the required command to enable 802.1X on an interface. This is the correct answer because it directly controls the port's state based on authentication.
authentication port-control force-authorized
authentication port-control force-unauthorized
A security engineer is configuring CoPP (Control Plane Policing) on a Cisco router to protect the control plane from DoS attacks. The policy must rate-limit SSH traffic to 1 Mbps with a burst of 2000 bytes, and drop all other traffic destined to the control plane that exceeds a default rate. Which class-map and policy-map configuration is correct?
class-map match-all SSH match protocol ssh policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop
class-map match-all SSH match access-group name SSH_ACL policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop class class-default police 8000 conform-action transmit exceed-action drop
class-map match-all SSH match protocol ssh policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop class class-default police 8000 conform-action transmit exceed-action drop
This is the correct CoPP configuration: `class-map match-all SSH` with `match protocol ssh` classifies SSH control-plane traffic, and the policy map `COPP` applies a police rate of 1,000,000 bps with a burst of 2000 bytes, dropping exceeding traffic. The `class-default` then polices all other control-plane traffic at 8000 bps, ensuring that no unclassified protocol can flood the CPU. The syntax and parameters are correctly ordered (rate in bps, burst in bytes), providing comprehensive control-plane protection.
class-map match-all SSH match protocol ssh policy-map COPP class SSH police 2000 1000000 conform-action transmit exceed-action drop
A company has deployed a Cisco ASA firewall in transparent mode. The internal network uses VLAN 10 and the external network uses VLAN 20. The ASA is configured with two bridge groups: BVI 10 for inside and BVI 20 for outside. The security policy must allow HTTPS traffic from inside to outside. Which access-list entry is correct?
access-list INSIDE extended permit tcp 192.168.1.0 255.255.255.0 any eq 443 access-group INSIDE in interface inside
access-list GLOBAL extended permit ip 192.168.1.0 255.255.255.0 any
access-list GLOBAL extended permit tcp any any eq 443
access-list GLOBAL extended permit tcp 192.168.1.0 255.255.255.0 any eq 443
This is the correct configuration for transparent mode. The global access-list is the only ACL applied to a transparent ASA, and it evaluates all traffic crossing the Layer 2 bridge. The rule precisely matches the requirement: source is the inside subnet 192.168.1.0/24, destination is any, and service is TCP 443 (HTTPS), thus permitting only outbound HTTPS from the inside network while implicitly denying everything else. This adheres to least-privilege access control and is applied globally so that traffic from any interface, including the inside, is filtered consistently.
Which TWO of the following are valid methods to mitigate VLAN hopping attacks?
Configure switchport mode dynamic auto on all ports.
Disable Dynamic Trunking Protocol (DTP) on all access ports.
Prevents trunk negotiation.
Set the native VLAN to VLAN 1 on all trunk ports.
Set the native VLAN to an unused VLAN ID on all trunk ports.
Mitigates double-tagging VLAN hopping.
Use 802.1Q trunking instead of ISL.
Which THREE of the following are characteristics of Cisco TrustSec (CTS) security architecture?
It uses IPsec to encrypt traffic between network devices.
It uses VLANs to segment traffic based on security roles.
It uses Security Group Tags (SGTs) to classify traffic.
SGTs are used for classification.
It provides data confidentiality using IEEE 802.1AE (MACsec) encryption.
MACsec provides link-layer encryption.
It uses Security Group Access Control Lists (SGACLs) to enforce policies.
SGACLs are enforced based on SGTs.
Want more Security practice?
Practice this domainAn organization uses Cisco DNA Center to automate network provisioning. A network engineer deploys a new access switch but finds that the switch does not receive the intended configuration template. The switch appears in DNA Center inventory with status 'Managed'. What is the most likely cause?
The switch has not been discovered by DNA Center
The switch is not in Plug and Play mode
The switch does not have a valid DNA license
The switch is not assigned to a site
In DNA Center, CLI templates are created and then associated with a site, and devices that are not assigned to a site cannot be targeted by the provisioning workflow that applies those templates. Template configuration via the 'Provision' workflow only operates on devices that belong to a selected site in the network hierarchy. Thus the correct fix is to assign the switch to a site, after which the templates and compliance checks become applicable.
A network team uses Ansible to automate VLAN configuration on Cisco IOS devices. The playbook fails with the error 'Failed to connect to the host via ssh: Permission denied (publickey)'. The control node runs Ubuntu, and the network devices are configured with SSH key authentication. Which solution should the engineer implement?
Set ansible_ssh_private_key_file in the inventory but omit the passphrase
Set ansible_user to the correct username in the inventory
Run ssh-add on the control node to add the private key to the SSH agent
Running ssh-add on the control node is the correct solution because it loads the passphrase-protected private key into the running SSH agent, where its decrypted form is retained for the duration of the agent session. Once the key is in the agent, Ansible's SSH connections can use it transparently without prompting for the passphrase, since the agent responds to authentication requests. This directly addresses the root cause: the key must be pre-authenticated to the SSH agent before Ansible attempts to connect, and ssh-add is the standard way to do that in an automated, non-interactive workflow.
Enable keyboard-interactive authentication on the IOS devices
A company uses Cisco Catalyst Center (formerly DNA Center) for intent-based networking. After upgrading the Catalyst Center appliance, the engineer notices that some devices are unreachable via the network, but the Catalyst Center GUI shows them as 'Managed'. What is the most likely cause?
SNMP community strings are misconfigured
Devices were reassigned to different roles
Certificate trust between devices and Catalyst Center expired
The IP address of the Catalyst Center appliance changed after the upgrade
If the Catalyst Center appliance's IP address is changed after an upgrade, the management network's routing and ARP entries are disrupted. Devices that are configured to send telemetry or accept management commands to/from the old IP address will no longer be reachable, because their ARP caches, DHCP reservations, or static routes still reference the previous address. Additionally, any access control lists on the devices that permit management traffic from the appliance's old IP will silently drop the new source address. This directly explains why all devices become unreachable after the upgrade, even though the appliance itself is up.
A network engineer uses Netmiko to connect to multiple Cisco IOS XE devices and execute commands. The script runs correctly for most devices but fails for one device with the error: 'ValueError: SSH session not active'. The device is reachable and SSH credentials are correct. What is the most likely cause?
The connection timeout is set too low
The device has reached the maximum number of SSH sessions
The device's SSH server is not fully initialized
This error from Netmiko/Paramiko means the SSHTransport object is not in an active state when invoke_shell() is called. On Cisco devices, this commonly occurs when the device is still booting and the SSH server has not fully initialized—for example, RSA keys are still being generated—so the server accepts TCP but aborts the SSH protocol handshake, leaving the client transport inactive.
The device requires an enable password but none was provided
A company uses Chef to automate network device configuration. The network devices are Cisco IOS XE running in a brownfield environment. Which Chef component is used to manage the state of the devices?
Ohai
Chef client
The Chef client is the enforcement agent that runs directly on each managed device, including network infrastructure such as IOS XE, NX-OS, or IOS XR when Cisco devices are integrated with Chef. It performs the convergence loop by querying the Chef server for the node's run list, evaluating the current state using Ohai, and then executing resources to bring the device to the desired configuration. This on-device agent is precisely the component that applies the automated configuration, making it the correct answer.
Chef workstation
Chef server
Which TWO statements are true about Cisco DNA Center automation? (Choose two.)
DNA Center primarily uses SNMP to manage devices.
DNA Center only supports greenfield deployments.
DNA Center uses a declarative model for network configuration.
DNA Center's intent-based declarative model lets engineers define the desired end state, and the controller computes and applies device configuration to reach it. This contrasts with imperative per-device CLI configuration, and is a defining characteristic of DNA Center automation.
DNA Center provides a single dashboard for network management.
DNA Center consolidates assurance, design, policy, and provisioning into one management interface, giving visibility across the entire campus fabric rather than per-device views. This single-pane-of-glass dashboard is a core automation and management characteristic of the platform.
DNA Center uses an imperative model for network configuration.
Want more Automation practice?
Practice this domainThe 350-401 exam has 90 questions and must be completed in 120 minutes. Cisco passing scores vary by exam version and are not always publicly listed. Check the official Cisco exam page before booking.
CLI output interpretation, network topology analysis, routing behaviour, switching concepts, troubleshooting, and configuration questions.
The exam covers 6 domains: Architecture, Virtualization, Infrastructure, Network Assurance, Security, Automation. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Cisco 350-401 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.