Cisco · Free Practice Questions · Last reviewed May 2026
36real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
A network engineer is designing a campus network with high availability for critical services. Which Cisco technology enables traffic to be forwarded to an alternate next hop in the event of a first-hop router failure, without requiring any configuration changes on the hosts?
Static default route with a floating static
GLBP
VRRP
HSRP
HSRP is a Cisco proprietary FHRP that provides transparent failover without host configuration changes.
A company is deploying a wireless network in an office with high client density. Which Cisco architecture is best suited to handle client roaming without requiring a central controller for every roaming event?
Mesh networking
Autonomous APs
Centralized switching with a WLC
FlexConnect
FlexConnect allows local data switching and fast roaming with minimal controller interaction.
An enterprise is using OSPF in a multi-area design. Area 1 is a regular area, and Area 2 is a totally stubby area. Which LSA types are present in Area 2?
Type 1, Type 2, Type 3 (including default)
Totally stubby areas allow only Type 1, Type 2, and a default Type 3 LSA.
Type 1, Type 2, Type 3, Type 5
Type 1, Type 2, Type 4, Type 5
Type 1, Type 2, Type 3 (including default), Type 4
A network engineer is troubleshooting a routing loop in an EIGRP network. Which mechanism is designed to prevent routing loops by causing a router to reject routes that are learned from a neighbor that is not the successor?
Split horizon
Route poisoning
Hold-down timers
Feasibility condition
The feasibility condition ensures loop-free paths by verifying that the neighbor's reported distance is lower than the feasible distance.
A company is implementing QoS in a network where voice traffic must have strict priority over all other traffic. Which queuing mechanism should be used on the outbound interface of a router to ensure voice packets are always sent first?
Random Early Detection (RED)
Low Latency Queuing (LLQ)
LLQ combines a strict priority queue with CBWFQ, ensuring voice gets priority.
First In First Out (FIFO)
Class-Based Weighted Fair Queuing (CBWFQ)
A network administrator is configuring a new VLAN 100 on a switch and wants to ensure that the VLAN is created and active. Which command is required to create a VLAN in the VLAN database?
interface vlan 100
name VLAN100
vlan 100
This command creates VLAN 100 and enters VLAN configuration mode.
switchport access vlan 100
Want more Architecture practice?
Practice this domainA data center uses Cisco Nexus 9000 switches with VXLAN EVPN to provide network virtualization. The operations team notices that VLAN 100 (mapped to VNI 10100) is not reachable across the fabric, although other VLANs work fine. The NVE interface is up, and the EVPN address-family is configured. Which two actions should the engineer take to isolate the issue?
Check if EVPN type-3 routes are being advertised for VNI 10100.
Confirm that multicast group 239.1.1.1 is reachable across the underlay.
Verify that VLAN 100 is mapped to VNI 10100 consistently on all VTEPs.
Inconsistent mapping breaks VXLAN bridging.
Ensure that VNI 10100 is added under the NVE interface.
VNI must be member of NVE to forward traffic.
Check if the MTU on the underlay is set to at least 1550 bytes.
A network engineer is deploying a Cisco Catalyst 9300 switch as a virtual switch using StackWise Virtual. The switch will connect to two upstream routers for redundancy. What is the best practice for connecting the uplinks?
Bundle the uplinks into an EtherChannel that spans both stack members.
EtherChannel across members provides redundancy and load balancing.
Use two separate routed interfaces, each with a routing protocol.
Connect each uplink to the active switch member.
Configure the uplinks in active/standby mode using STP.
A cloud provider uses Cisco ACI to automate provisioning of tenant networks. A new tenant requires a Layer 2 bridge domain that extends to an external Layer 2 network via a VPC. The engineer creates a bridge domain with the settings: Type: Regular, L2 Unknown Unicast: Flood, L3 Unknown Multicast Flood: Flood, and Multi-Destination Flooding: Flood. The VPC is configured as a virtual port channel. The tenant reports that broadcast traffic is not reaching the external network. What is the most likely cause?
The VPC configuration does not support L2 extension.
The bridge domain is configured as proxy mode for L2 unknown unicast.
The L2Out is not configured to flood BUM traffic.
L2Out must be configured with flood settings to extend flooding.
The bridge domain type should be set to 'L2 Only'.
An enterprise uses VMware vSphere to host multiple virtual machines (VMs). The network team wants to implement a virtual firewall on the hypervisor to inspect traffic between VMs on the same ESXi host. Which technology should be used?
Use VXLAN to encapsulate traffic and send it to a firewall.
Deploy a virtual firewall on a vSphere Distributed Switch with a private VLAN.
Private VLAN can redirect traffic to the virtual firewall.
Use a vSphere Standard Switch and configure port mirroring.
Deploy a physical firewall and route all VM traffic through it.
A network engineer configured three interfaces on a switch as shown. A host connected to Ethernet1/2 sends an untagged frame. Which VLAN will this frame be placed into when it reaches Ethernet1/3?
VLAN 999
VLAN 1
The frame is dropped because VLAN 10 is not allowed.
Ethernet1/3 trunk does not allow VLAN 10.
VLAN 10
An engineer configures VXLAN EVPN on a Nexus 9000 switch. The configuration is shown. The switch does not advertise any EVPN routes for VNI 10100. Which configuration change is required to fix this issue?
Configure "evpn" and "vni 10100 l2" under the BGP address-family l2vpn evpn.
The VNI must be activated under evpn for route advertisement.
Remove the mcast-group from the NVE member, because EVPN uses BGP for control plane.
Change the source-interface to a physical interface.
Add an IP address to the VLAN 100 interface in the default VRF.
Want more Virtualization practice?
Practice this domainA network engineer is troubleshooting an EIGRP adjacency issue between two routers. The engineer verifies that both routers have the same K-values and autonomous system number. However, the adjacency does not form. Which configuration issue is most likely the cause?
Authentication is configured on one router but not on the other.
Mismatched authentication prevents EIGRP adjacency.
The network statement uses an incorrect subnet mask.
One router has a loopback interface that is not advertised.
The hello and hold timers do not match.
A company is implementing QoS in a campus network. Voice traffic must be prioritized over data traffic, and all traffic should be marked at Layer 2 and Layer 3. Which combination of marking values should be used on access ports to achieve this?
CoS 5, DSCP AF41
CoS 5, DSCP CS3
CoS 5, DSCP EF
CoS 5 and DSCP EF are the standard marks for voice.
CoS 4, DSCP EF
An engineer needs to configure a switchport to carry traffic for multiple VLANs to a router using a single physical link. Which configuration should be applied on the switchport?
Configure the port as a dynamic desirable port.
Configure the port as a trunk port.
Trunk ports carry multiple VLANs.
Configure the port as a routed port.
Configure the port as an access port.
A network engineer is deploying a new WLAN and needs to ensure that client traffic is encrypted using AES with a pre-shared key. Which security configuration should be applied to the wireless SSID?
WPA2-PSK with AES
WPA2-PSK with AES meets the requirements.
WPA3-PSK with AES
WPA2-PSK with TKIP
WEP with AES
A network administrator is troubleshooting an issue where OSPF routes are not being learned from a neighbor. The administrator checks the OSPF configuration and sees that both routers are in the same area. The neighbor state is stuck in EXSTART. What is the most likely cause?
The router ID is the same on both routers.
The area ID is different.
The hello timer is set to 30 seconds on one router.
The interface MTU does not match.
MTU mismatch causes EXSTART state.
An engineer is configuring a new VLAN 100 on a switch. Which command must be used to create the VLAN?
vlan 100
This creates VLAN 100.
switchport access vlan 100
vlan database
interface vlan 100
Want more Infrastructure practice?
Practice this domainA network administrator is troubleshooting high CPU utilization on a Catalyst 9300 switch. The output of 'show processes cpu sorted' shows the 'IP Input' process consuming 45% CPU. Which tool should be used to identify the specific packets causing the issue?
Use extended ping from the switch to generate traffic.
Configure a SPAN session to capture all traffic to the CPU.
Check CDP neighbors to see if any devices are flooding.
Enable IP traffic export (NetFlow) on the switch.
NetFlow (IP traffic export) exports flow records detailing source/destination IP, ports, and protocols. This allows pinpointing which flows are saturating the 'IP Input' process.
A network engineer is implementing QoS on a WAN link to prioritize voice traffic. Which queuing mechanism provides the lowest latency for real-time traffic?
Low Latency Queuing (LLQ)
LLQ is correct because it combines a strict priority queue with CBWFQ, ensuring that voice traffic is dequeued first, providing the lowest latency for real-time traffic.
Weighted Random Early Detection (WRED)
Class-Based Weighted Fair Queuing (CBWFQ)
First-In, First-Out (FIFO)
A network administrator is troubleshooting a BGP routing issue where routes from an eBGP neighbor are not being installed in the routing table. The 'show ip bgp' output shows the routes are received but not valid. What is the most likely cause?
The AS-path contains the local AS number.
The next-hop IP address is not reachable.
Correct. For a BGP route to be considered valid and installed in the routing table, the next-hop IP address must be reachable via an IGP or static route. If the next hop is not reachable, the route will appear in the 'show ip bgp' output but be marked as not valid.
BGP synchronization is enabled.
The maximum-prefix limit has been exceeded.
A network engineer is designing a multicast network for IPTV. Which protocol is used by routers to discover which multicast groups are of interest to directly connected hosts?
Rendezvous Point (RP)
Internet Group Management Protocol (IGMP)
Internet Group Management Protocol (IGMP) is the correct protocol. It allows hosts to signal their interest in multicast groups to their directly connected router.
Protocol Independent Multicast (PIM)
Multicast Source Discovery Protocol (MSDP)
Which TWO statements are true about IP SLA? (Choose two.)
IP SLA is only supported on ASR routers.
IP SLA can be used with tracking objects to trigger route changes.
IP SLA can be combined with tracking objects; when an SLA probe fails, the tracked object changes state, allowing dynamic route changes via static routes or PBR.
IP SLA can measure jitter between two devices.
IP SLA can measure various metrics including jitter between two devices by sending synthetic packets.
IP SLA uses actual user traffic for measurements.
IP SLA can only measure round-trip time, not one-way delay.
Refer to the exhibit. An engineer notices that interface resets have occurred. What is the most likely cause of the interface resets?
Cable or hardware issue causing link flapping
Interface resets occur when the interface goes down and comes back up, typically due to physical layer problems like faulty cables, damaged connectors, or hardware issues causing link flapping. This distinguishes resets from other errors.
CRC errors due to noise
Collisions on the link
Interface is administratively down
Want more Network Assurance practice?
Practice this domainA network engineer is configuring port security on a Cisco switch to prevent unauthorized devices from connecting. The requirement is to allow only the first two MAC addresses learned on an interface, and to disable the interface if a violation occurs. Which configuration achieves this?
switchport port-security maximum 2 switchport port-security violation err-disable
switchport port-security maximum 2 switchport port-security violation shutdown
Correct: sets max to 2 and violation shutdown disables interface.
switchport port-security maximum 2 switchport port-security violation protect
switchport port-security maximum 2 switchport port-security violation restrict
An organization wants to implement 802.1X authentication on its wired network using Cisco ISE as the authentication server. The switches are configured with the necessary RADIUS settings. Which additional configuration is required on the switch interfaces to enable 802.1X?
dot1x pae authenticator
authentication port-control auto
Correct: this command enables 802.1X authentication on the interface.
authentication port-control force-authorized
authentication port-control force-unauthorized
A security engineer is configuring CoPP (Control Plane Policing) on a Cisco router to protect the control plane from DoS attacks. The policy must rate-limit SSH traffic to 1 Mbps with a burst of 2000 bytes, and drop all other traffic destined to the control plane that exceeds a default rate. Which class-map and policy-map configuration is correct?
class-map match-all SSH match protocol ssh policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop
class-map match-all SSH match access-group name SSH_ACL policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop class class-default police 8000 conform-action transmit exceed-action drop
class-map match-all SSH match protocol ssh policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop class class-default police 8000 conform-action transmit exceed-action drop
Correct: matches SSH protocol, police rate 1Mbps burst 2000, and default police for all other traffic.
class-map match-all SSH match protocol ssh policy-map COPP class SSH police 2000 1000000 conform-action transmit exceed-action drop
A company has deployed a Cisco ASA firewall in transparent mode. The internal network uses VLAN 10 and the external network uses VLAN 20. The ASA is configured with two bridge groups: BVI 10 for inside and BVI 20 for outside. The security policy must allow HTTPS traffic from inside to outside. Which access-list entry is correct?
access-list INSIDE extended permit tcp 192.168.1.0 255.255.255.0 any eq 443 access-group INSIDE in interface inside
access-list GLOBAL extended permit ip 192.168.1.0 255.255.255.0 any
access-list GLOBAL extended permit tcp any any eq 443
access-list GLOBAL extended permit tcp 192.168.1.0 255.255.255.0 any eq 443
Correct: global access-list permits traffic from inside subnet to any on port 443.
A network administrator is troubleshooting a DHCP snooping issue on a Cisco switch. The switch is configured with DHCP snooping globally and on VLAN 10. The trusted interface is GigabitEthernet0/1 connected to the DHCP server. However, clients on VLAN 10 are not receiving IP addresses from the DHCP server. What is the most likely cause?
The switch has IP Source Guard enabled, blocking valid DHCP traffic.
The interface GigabitEthernet0/1 is not configured as a trusted port for DHCP snooping.
Correct: Untrusted ports drop DHCP server messages; the server port must be trusted.
The DHCP server is on a different subnet and the switch lacks an IP helper address.
The DHCP server is sending offers too quickly, exceeding the rate-limit on the switch.
Which TWO of the following are valid methods to mitigate VLAN hopping attacks?
Configure switchport mode dynamic auto on all ports.
Disable Dynamic Trunking Protocol (DTP) on all access ports.
Prevents trunk negotiation.
Set the native VLAN to VLAN 1 on all trunk ports.
Set the native VLAN to an unused VLAN ID on all trunk ports.
Mitigates double-tagging VLAN hopping.
Use 802.1Q trunking instead of ISL.
Want more Security practice?
Practice this domainA network engineer needs to automate the backup of running configurations from multiple Cisco IOS XE devices to a central TFTP server. Which tool is best suited for this task in a Python-based automation framework?
RESTCONF
Ansible
Paramiko
Paramiko provides SSH connectivity to network devices.
Netmiko
An organization uses Cisco DNA Center to automate network provisioning. A network engineer deploys a new access switch but finds that the switch does not receive the intended configuration template. The switch appears in DNA Center inventory with status 'Managed'. What is the most likely cause?
The switch has not been discovered by DNA Center
The switch is not in Plug and Play mode
The switch does not have a valid DNA license
The switch is not assigned to a site
Site assignment is required for template application.
A network team uses Ansible to automate VLAN configuration on Cisco IOS devices. The playbook fails with the error 'Failed to connect to the host via ssh: Permission denied (publickey)'. The control node runs Ubuntu, and the network devices are configured with SSH key authentication. Which solution should the engineer implement?
Set ansible_ssh_private_key_file in the inventory but omit the passphrase
Set ansible_user to the correct username in the inventory
Run ssh-add on the control node to add the private key to the SSH agent
The SSH agent must have the key loaded for authentication.
Enable keyboard-interactive authentication on the IOS devices
A company uses Cisco Catalyst Center (formerly DNA Center) for intent-based networking. After upgrading the Catalyst Center appliance, the engineer notices that some devices are unreachable via the network, but the Catalyst Center GUI shows them as 'Managed'. What is the most likely cause?
SNMP community strings are misconfigured
Devices were reassigned to different roles
Certificate trust between devices and Catalyst Center expired
The IP address of the Catalyst Center appliance changed after the upgrade
A changed IP address would break management connectivity.
A network engineer uses Netmiko to connect to multiple Cisco IOS XE devices and execute commands. The script runs correctly for most devices but fails for one device with the error: 'ValueError: SSH session not active'. The device is reachable and SSH credentials are correct. What is the most likely cause?
The connection timeout is set too low
The device has reached the maximum number of SSH sessions
The device's SSH server is not fully initialized
The device may still be booting or SSH service is not started.
The device requires an enable password but none was provided
A company uses Chef to automate network device configuration. The network devices are Cisco IOS XE running in a brownfield environment. Which Chef component is used to manage the state of the devices?
Ohai
Chef client
The client runs on each managed device to enforce desired state.
Chef workstation
Chef server
Want more Automation practice?
Practice this domainThe 350-401 exam has 90 questions and must be completed in 120 minutes. Cisco passing scores vary by exam version and are not always publicly listed. Check the official Cisco exam page before booking.
CLI output interpretation, network topology analysis, routing behaviour, switching concepts, troubleshooting, and configuration questions.
The exam covers 6 domains: Architecture, Virtualization, Infrastructure, Network Assurance, Security, Automation. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Cisco 350-401 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.