These questions describe a network symptom and ask you to identify the root cause or the correct fix. They appear across all certification exams and reward systematic thinking over memorisation. The best candidates follow a consistent troubleshooting framework even under time pressure.
Start Scenario PracticeA network engineer is configuring MPLS L3VPN on a Cisco IOS-XE router. The VRF CUSTOMER_C has route-target import 300:1 and export 300:1. The PE receives VPNv4 routes from the route reflector, but the CE router connected to the PE cannot ping any remote site IP addresses. The PE can ping the remote site IP addresses from the VRF. What is the most likely cause?
Explanation: The PE can ping remote site IP addresses from within the VRF, confirming that the VRF has the correct route-target import/export configuration and that VPNv4 routes are being received and installed in the VRF routing table. However, the CE router cannot ping remote sites, which indicates that the CE does not have a route pointing to the PE’s VRF interface as its next hop. Without a default route or a specific route pointing to the PE’s VRF-facing interface, the CE has no path to forward traffic to remote VPN destinations, even though the PE can reach them.
A network engineer is troubleshooting an STP issue in a network that uses Rapid PVST+. The network has a root bridge (SW1) and a secondary root bridge (SW2). The engineer notices that after a link failure between SW1 and SW2, the network takes longer than expected to converge. The engineer checks the configuration and finds that SW2 has the 'spanning-tree uplinkfast' command enabled. The engineer also notices that SW2 has a lower priority than SW1. What is the most likely cause of the slow convergence?
Explanation: UplinkFast is a legacy STP feature that is incompatible with Rapid PVST+. When enabled on a switch running Rapid PVST+, it forces the switch to revert to 802.1D STP convergence behavior on the affected ports, disabling the rapid transition mechanisms (such as proposal/agreement and sync). This causes the network to take longer to converge after a link failure, as the switch falls back to the slower listening and learning states.
A company is deploying a new Cisco wireless LAN controller (WLC) and wants to use RADIUS for authenticating wireless users. The WLC is configured with the RADIUS server IP, shared secret, and authentication port 1812. However, users are unable to authenticate. The network engineer checks the RADIUS server logs and sees that the server is receiving authentication requests from the WLC but is responding with an 'Access-Reject' message. The WLC logs show 'RADIUS server not responding' for the same server. What is the most likely cause?
Explanation: The RADIUS server is receiving authentication requests and sending 'Access-Reject' responses, but the WLC logs show 'RADIUS server not responding'. This indicates the WLC is not receiving the responses. The most likely cause is a source IP mismatch: the RADIUS server sends responses from a different IP address than the one configured on the WLC. The WLC drops these responses because they do not match the expected source IP, making it appear as if the server is not responding.
A network administrator is troubleshooting a BGP routing issue where routes from an eBGP neighbor are not being installed in the routing table. The 'show ip bgp' output shows the routes are received but not valid. What is the most likely cause?
Explanation: For a BGP route to be considered valid and installed in the routing table, the next-hop IP address must be reachable via an IGP or a static route. If the next hop is not reachable, the route will appear in the 'show ip bgp' output but will be marked as not valid (often with a 'r' for received but not valid). This is the most common cause when routes are received from an eBGP neighbor but not installed.
A network engineer is troubleshooting a DHCP issue where a client is not receiving an IP address from a Cisco router configured as a DHCP server. The engineer checks the DHCP pool configuration and sees that the network command is configured with the correct subnet. The engineer also verifies that the ip dhcp excluded-address command is not blocking any addresses. However, the client's DHCP discover message is not reaching the router. What is the most likely cause?
Explanation: If the client and the router's DHCP server interface are on different VLANs (i.e., different subnets), the DHCP discover broadcast will not cross the Layer 3 boundary unless the router interface has an ip helper-address configured. The ip helper-address command enables the router to convert the broadcast DHCP discover into a unicast and forward it to the DHCP server. Without it, the client's broadcast never reaches the server, even if the DHCP pool is correctly defined.
+10 more scenario questions available
Practice all Troubleshooting Scenario QuestionsThese questions describe a network symptom and ask you to identify the root cause or the correct fix. They appear across all certification exams and reward systematic thinking over memorisation. The best candidates follow a consistent troubleshooting framework even under time pressure. These appear throughout the 350-401 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-401. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-401 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Troubleshooting Scenario Questions session with instant scoring and detailed explanations.
Start Scenario Practice →