Courseiva

CCNA 200-301 v2 (200-301) — Questions 676–750

1450 questions total · 20pages · All types, answers revealed

Page 9

Page 10 of 20

Page 11
676
Drag & Dropmedium

What is the correct order of steps to capture and analyze traffic on IOS-XE using the embedded packet capture feature, and in Wireshark to isolate a Layer 2 or Layer 3 fault?

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order for embedded packet capture on IOS-XE is to first define the capture point with the desired interface and optional filter, then start the capture, stop it after capturing the needed traffic, and finally export the file for analysis in Wireshark. Option A accurately reflects this sequence. Option B fails because the capture must be defined before starting.

Option C fails because exporting should occur after stopping the capture. Option D fails because analysis is performed externally, not on the router.

Exam trap

Do not confuse the order of operations: you must define the capture point before starting, and you must stop the capture before exporting. Also, remember that analysis is done externally, not on the router itself.

Why candidates pick the wrong answer

B

Candidates might think that starting the capture is the first step, similar to enabling a debug, but EPC requires configuration first.

C

Candidates may think exporting is just copying a buffer that can be done anytime, but the capture must be stopped to finalize the file.

D

Candidates might assume that since the router has the capture, it can also analyze it, but IOS-XE lacks a full packet analyzer.

677
MCQmedium

Exhibit: A laptop has IP address 10.20.30.44/27. Which address is its directed broadcast for that subnet?

A.10.20.30.31
B.10.20.30.32
C.10.20.30.63
D.10.20.30.64
AnswerC

With a /27 prefix, the subnet block size is 32 addresses. The host address 10.20.30.44 falls inside 10.20.30.32/27, whose range extends from .32 through .63. The directed broadcast address is the final address in that range, 10.20.30.63, with all five host bits set to 1. It is valid only as a broadcast target and cannot be assigned to an interface.

Why this answer

A /27 gives a block size of 32 addresses. The host 10.20.30.44 falls in the 10.20.30.32 to 10.20.30.63 subnet, so the broadcast address is 10.20.30.63.

Exam trap

Avoid confusing the network address or a host address with the broadcast address. Remember, the broadcast address is the last address in the subnet.

Why the other options are wrong

A

10.20.30.31 is the broadcast address of the previous /27 subnet (10.20.30.0/27), not the subnet containing 10.20.30.44. The host 10.20.30.44 belongs to the 10.20.30.32/27 subnet, so its broadcast is 10.20.30.63.

B

10.20.30.32 is the network address (subnet ID) of the subnet 10.20.30.32/27, not the broadcast address. The network address is the first address in the subnet and is used to identify the subnet itself.

D

10.20.30.64 is the network address of the next /27 subnet (10.20.30.64/27), not the broadcast of the current subnet. The broadcast address for 10.20.30.32/27 is 10.20.30.63.

When would these options actually be correct?

A

This option would be correct if the question asked for the directed broadcast address of the subnet containing 10.20.30.44 with a /26 mask (block size 64), where the subnet would be 10.20.30.0/26 and the broadcast would be 10.20.30.63.

B

If the question asked for the network address of the subnet containing 10.20.30.44/27, then 10.20.30.32 would be correct. For example: 'Which address is the network address for the subnet of 10.20.30.44/27?'

D

If the question asked for the network address of the next subnet after 10.20.30.32/27, then 10.20.30.64 would be correct. For example: 'What is the network address of the subnet following 10.20.30.32/27?'

Why candidates pick the wrong answer

A

Students often miscalculate the subnet boundaries or confuse the broadcast address with the network address. The number 31 might appear as a common broadcast address in smaller subnets, but here it is incorrect.

B

Some students mistakenly think the network address or the first usable address is the broadcast address. The network address is often confused with the broadcast because both are special addresses within the subnet.

D

Students may incorrectly add the subnet size (32) to the network address to get the broadcast, but the broadcast is one less than the next network address. 10.20.30.64 is the next subnet boundary, not the broadcast.

678
Multi-Selectmedium

Which two statements accurately describe software-defined networking and network virtualization concepts at a basic CCNA level?

Select 2 answers
A.SDN is associated with more centralized or programmable control of network behavior.
B.NFV is associated with delivering network functions in software or virtualized form.
C.Both terms are just new names for subnet masks.
D.Both terms replace the need for routing protocols completely.
E.Both terms refer only to wireless client roaming.
AnswersA, B

SDN decouples the network control plane from the forwarding plane, centralizing intelligence in a software controller that programs flows into switches and routers. This controller provides a global, vendor-neutral view of the network and exposes APIs (e.g., OpenFlow) that allow operators to dynamically adjust policies and traffic paths via software. As a result, SDN is accurately described as enabling more centralized or programmable control of network behavior, which is the core of the technology.

Why this answer

At a basic level, these concepts point toward more abstracted, software-driven ways of controlling or delivering networking capabilities. SDN is associated with more centralized or programmable control behavior. NFV is associated with delivering network functions in virtualized software form instead of relying only on fixed-purpose hardware.

The goal here is conceptual recognition, not deep architectural implementation detail.

Exam trap

A frequent exam trap is mistaking SDN and NFV for basic network addressing concepts like subnet masks or for wireless client roaming features. Candidates might also incorrectly believe these technologies replace routing protocols entirely. However, SDN and NFV focus on centralized control and virtualized network functions, respectively, and do not eliminate the need for routing logic or relate directly to subnetting or wireless roaming.

Misunderstanding these distinctions can lead to selecting incorrect options that describe unrelated networking concepts.

Why the other options are wrong

C

Option C is incorrect because subnet masks are related to IP addressing and have no connection to SDN or NFV concepts, which focus on network control and virtualization.

D

Option D is wrong since SDN and NFV do not eliminate routing protocols; routing remains necessary for path determination and packet forwarding in networks.

E

Option E is incorrect because SDN and NFV are broad network architecture concepts and do not exclusively refer to wireless client roaming or mobility management.

When would these options actually be correct?

C

In a question that asks about basic networking terminology and definitions, if the context was specifically about how modern networking concepts are merely rebranding of traditional terms, then stating that SDN and NFV are just new names for subnet masks could be correct if the question was misleadingly framed to suggest that all networking terms evolve in this manner.

D

If the exam question asked whether SDN and NFV can operate in environments where traditional routing protocols are not necessary, such as in certain isolated or specialized networks, then this option could be correct, as it might focus on specific scenarios where alternative methods are used.

E

If the exam question specifically asked about technologies that enhance wireless networks or focused solely on wireless client management, this option could be correct, as it would then align with the context of wireless roaming capabilities.

Why candidates pick the wrong answer

C

Students may confuse the term 'virtualization' in NFV with virtual LANs (VLANs) or subnetting, leading them to incorrectly associate these concepts with subnet masks.

D

The centralized control in SDN might suggest that routing logic is entirely moved to the controller, but in practice, routing protocols often still run on devices or are integrated with the SDN controller.

E

The term 'network virtualization' might be mistakenly associated with virtual wireless networks or SSIDs, leading students to think these concepts only apply to wireless roaming.

679
MCQhard

An ACL permits only tcp 10.10.10.0/24 host 192.0.2.10 eq 443 and has no other permit entries. What happens to an ICMP echo request from 10.10.10.5 to 192.0.2.10?

A.It is permitted because the destination matches
B.It is denied by the implicit deny
C.It is permitted because the packet matches the source network stated in the ACE.
D.It is permitted only if the source port is 443
AnswerB

An ACL ends with an implicit deny all rule, so any packet not explicitly permitted by a preceding ACE is dropped. An ICMP packet is not TCP and therefore does not match the permit tcp statement, regardless of its source or destination. Thus, it falls through to the implicit deny and is denied.

Why this answer

ACLs end with an implicit deny. Since the only explicit permit is for HTTPS traffic, the ICMP packet is denied.

Exam trap

Remember that ACLs have an implicit deny all rule. Just because a source or destination is specified doesn't mean all traffic types are allowed.

Why the other options are wrong

A

The ACL only permits TCP traffic from 10.10.10.0/24 to host 192.0.2.10 on port 443. ICMP is not TCP, so even though the destination matches, the protocol does not match, and the packet is not permitted.

C

Although the source IP matches the ACE's source network, the ACE only permits TCP traffic; ICMP is a different protocol, so the packet is denied by the implicit deny.

D

ICMP does not use TCP ports; it uses ICMP type and code. The ACL entry specifies TCP port 443, which is irrelevant for ICMP traffic. Even if the source port were 443, ICMP packets do not have TCP ports.

When would these options actually be correct?

A

In a different exam scenario where an ACL permits ICMP traffic from a specific source to a specific destination, such as 'permit icmp 10.10.10.0/24 host 192.0.2.10', this option would be correct as the ICMP echo request would match the permit statement.

C

In a different scenario where an ACL permits both TCP and ICMP traffic, a question might ask about the behavior of an ICMP packet under those conditions. If the ACL included rules for ICMP, then translating ICMP to TCP could be a valid consideration.

D

In a different scenario, if the ACL specified a rule that allowed ICMP traffic from any source to a specific destination, and the question asked about ICMP traffic, then this option could be correct if the source port was relevant to the rule being applied.

Why candidates pick the wrong answer

A

Students might think that matching the destination IP address is sufficient for permit, but ACLs require matching all specified fields (protocol, source, destination, and port).

C

Some students may confuse ACLs with NAT or other features that can modify packets, but ACLs only filter based on existing packet headers.

D

Students might think that matching the source port 443 could permit the traffic, but they overlook that the protocol must also match TCP.

680
Multi-Selectmedium

Which three statements about IPv6 routing are correct? (Choose three.)

Select 3 answers
.IPv6 static routes can be configured using the 'ipv6 route' command.
.The next-hop address for a directly attached IPv6 static route can be a link-local address.
.OSPFv3 uses the same basic algorithm as OSPFv2 but is designed for IPv6.
.IPv6 routing is enabled by default on all Cisco routers.
.The default route in IPv6 is represented as ::/128.
.EIGRP for IPv6 uses the same autonomous system number as EIGRP for IPv4 and shares the same routing table.

Why this answer

All three statements are correct. The 'ipv6 route' command is used to configure static routes in IPv6, similar to 'ip route' in IPv4. A directly attached IPv6 static route can indeed use a link-local address as the next hop, which is common for point-to-point interfaces.

OSPFv3 (OSPF for IPv6) uses the same fundamental SPF algorithm and link-state concepts as OSPFv2 but is designed to support IPv6 addressing and runs per-link rather than per-subnet.

Exam trap

Cisco often tests the nuance that a link-local address can be used as a next hop for a directly attached IPv6 static route only if the exit interface is explicitly specified, leading candidates to incorrectly think link-local addresses are never valid next hops.

681
MCQhard

Exhibit: Clients can see the corporate SSID but fail authentication after entering valid usernames and passwords. Which issue is the best explanation?

A.The AP is using the wrong RF channel
B.The RADIUS path or shared secret is failing
C.The SSID must be hidden for enterprise authentication
D.The clients need a voice VLAN assignment first
AnswerB

In WPA2-Enterprise, the access point acts as an 802.1X authenticator and forwards EAP credentials to a RADIUS server. If the shared secret is misconfigured or the RADIUS server is unreachable, the authentication exchange fails after the client associates, precisely matching the symptom of seeing the SSID but being unable to connect. This is the only option that directly impacts the authentication stage rather than association or RF visibility.

Why this answer

WPA2-Enterprise relies on 802.1X with a RADIUS server. If the RADIUS server is unreachable or the shared secret is wrong, users can see the SSID and attempt to authenticate, but the login process fails. Option A is incorrect because RF channel issues would cause connectivity problems, not authentication failures after association.

Option C is incorrect because hiding the SSID is irrelevant to enterprise authentication; the issue is server-side. Option D is incorrect because a voice VLAN is not required for standard client authentication and would not cause login failure.

Exam trap

Remember that WPA2-Enterprise relies on a RADIUS server. Authentication issues often stem from server communication problems, not client-side settings.

Why the other options are wrong

A

RF channel issues cause connectivity or performance problems, not authentication failures after a successful association.

C

Hiding the SSID does not affect the 802.1X authentication process; the failure is likely due to RADIUS communication.

D

Voice VLAN assignment is unrelated to client authentication; clients do not need a voice VLAN to authenticate.

When would these options actually be correct?

A

In a different scenario, if a question asks why clients are unable to connect to an SSID despite being in range, and mentions issues like poor signal strength or interference, then stating that the AP is using the wrong RF channel could be a valid explanation for connectivity problems.

C

In a scenario where a question states that clients are unable to connect to the network because the SSID is not visible, and the context involves a security policy requiring hidden SSIDs for enterprise authentication, this option would be correct.

D

In a different scenario where the question states that clients are required to connect to a voice VLAN for specific services, and they fail to authenticate until they are assigned to that VLAN, this option would be correct. For instance, if the question specifies that voice traffic must be prioritized and VLANs are configured accordingly, then this option would be valid.

Why candidates pick the wrong answer

A

Students often associate wireless problems with RF interference or channel overlap, but authentication failures point to higher-layer issues like RADIUS or credentials.

C

Some believe hiding the SSID adds security, but it is unrelated to authentication success and can actually cause client connectivity issues.

D

Students may confuse VLAN assignment with authentication, thinking a specific VLAN is required before authentication, but VLANs are applied after successful authentication.

682
Multi-Selectmedium

Which three of the following statements about Network Address Translation (NAT) are correct? (Choose three.)

Select 3 answers
.Static NAT provides a one-to-one mapping between a private IP and a public IP.
.Dynamic NAT uses a pool of public IP addresses assigned on a first-come, first-served basis.
.PAT (Port Address Translation) allows multiple internal hosts to share a single public IP address.
.NAT eliminates the need for any routing in a network.
.Dynamic NAT always assigns the same public IP to a given internal host.
.PAT requires a unique public IP for every concurrent session.

Why this answer

Static NAT provides a one-to-one mapping between a private IP and a public IP, ensuring that a specific internal host always uses the same public address. Dynamic NAT uses a pool of public IP addresses assigned on a first-come, first-served basis, so internal hosts compete for available addresses. PAT (Port Address Translation) allows multiple internal hosts to share a single public IP by differentiating sessions via unique port numbers, which is the most common form of NAT used in home and small office routers.

Exam trap

Cisco often tests the misconception that dynamic NAT provides a fixed mapping like static NAT, or that PAT requires multiple public IPs, when in fact PAT is designed to share a single public IP among many hosts.

683
MCQhard

A network administrator is configuring a site-to-site IPsec VPN between two Cisco routers. The administrator wants to ensure that the encryption and integrity of the data traffic are provided separately, using ESP. Which statement correctly describes how ESP provides these services?

A.ESP encrypts only the TCP or UDP header, leaving application data in clear text.
B.ESP provides encryption but not integrity, so AH must be added for integrity.
C.ESP authenticates the entire packet including the outer IP header, but provides no encryption.
D.ESP encrypts the payload and can also authenticate it, but it does not protect the outer IP header.
AnswerD

ESP encrypts and optionally authenticates the payload and part of the ESP header, but in transport mode the original IP header is not protected, and in tunnel mode a new outer IP header is added that is not authenticated by ESP. This matches ESP's design, unlike AH, which authenticates more of the packet including the outer IP header.

Why this answer

ESP is designed to provide confidentiality through encryption and can also provide integrity and authentication for the payload and ESP header. It does not authenticate the outer IP header, which is why AH is sometimes described as offering broader header protection. In a site-to-site VPN, ESP with encryption and authentication meets the requirement of separate encryption and integrity services.

Exam trap

The trap here is mixing up ESP and AH responsibilities, since AH is the protocol that authenticates the outer IP header while ESP is the one that encrypts the payload.

684
MCQmedium

Why is NTP especially useful when devices send logs to a centralized Syslog server?

A.It helps align device clocks so centralized log timestamps can be correlated more accurately.
B.It assigns the Syslog server an IP address.
C.It replaces the need for a Syslog server.
D.It encrypts every Syslog message automatically.
AnswerA

Network Time Protocol synchronizes the system clocks of routers, switches, and servers, so each device reports the same timestamp for concurrent events. When centralized log correlation combines Syslog outputs from multiple devices, consistent time references enable security analysts to reconstruct the exact sequence of actions and pinpoint root causes. Without NTP alignment, clock drift would cause misleading log ordering and obscure real threats.

Why this answer

NTP is especially useful because synchronized clocks make the log timestamps more meaningful and easier to correlate. In plain language, if each device thinks the current time is different, the sequence of events in the centralized log becomes confusing. NTP helps align time across devices so the logs tell a more accurate story.

This is an operational best practice. Syslog collects the messages, and NTP makes their timing consistent. The correct answer is the one focused on timestamp correlation.

Exam trap

Avoid confusing NTP's function with security or data optimization features; focus on its role in time synchronization.

Why the other options are wrong

B

NTP is a protocol for clock synchronization, not for IP address assignment. IP addresses are assigned via DHCP or static configuration, and NTP operates at the application layer to synchronize time over the network. Therefore, NTP does not assign IP addresses to any device, including Syslog servers.

C

NTP and Syslog serve entirely different purposes. NTP synchronizes clocks, while Syslog is a protocol for sending log messages to a centralized server. NTP cannot replace Syslog because it does not collect, store, or forward log messages.

Both are often used together but are independent services.

D

NTP does not provide encryption for Syslog messages or any other data. NTP is solely responsible for time synchronization and does not include security features like encryption. Syslog messages are typically sent in clear text unless additional security measures like TLS or SSH are implemented.

When would these options actually be correct?

B

In a different question asking about the initial setup of a Syslog server, an option stating that NTP assigns an IP address could be correct if the question is framed around the need for devices to communicate with the Syslog server, implying that IP assignment is part of the configuration process.

C

In a question asking about the role of NTP in a network where logging is handled entirely by a different protocol or system that does not require a Syslog server, this option could be correct. For example, if the question states that all logging is done locally on devices without centralization, then NTP could be seen as sufficient without a Syslog server.

D

If the exam question asked about a protocol that provides both time synchronization and encryption for log messages, such as TLS (Transport Layer Security) applied to Syslog, then this option could be correct.

Why candidates pick the wrong answer

B

Students might confuse NTP with DHCP or other protocols that provide network configuration parameters. Since NTP involves network communication, some may incorrectly assume it also handles IP addressing, especially when they see NTP configured with server IP addresses.

C

A test-taker with partial knowledge might think that because NTP helps with log correlation, it somehow eliminates the need for a separate Syslog server. This confusion arises from misunderstanding the distinct roles of network services.

D

Students may associate NTP with security because accurate time is important for security logs and protocols like Kerberos. However, NTP itself does not encrypt traffic; it only provides time accuracy. The temptation comes from conflating time synchronization with security functions.

685
Multi-Selectmedium

Which two actions are reasonable examples of basic device-hardening practice?

Select 2 answers
A.Disable unused services or interfaces where practical
B.Use SSH instead of Telnet for remote management
C.Allow anonymous administrative login for convenience
D.Place all traffic in VLAN 1 so it is easier to remember
E.Remove authentication from VTY lines
AnswersA, B

Unused services like the HTTP server, CDP, or unused physical interfaces remain active by default and can be exploited as attack vectors or leak sensitive network information. Disabling these services and shutting down unused ports reduces the device's attack surface and prevents unauthorized lateral movement. This is a basic hardening step that every network administrator should implement.

Why this answer

Basic hardening is about reducing unnecessary exposure and making administrative access safer. In plain language, this usually means disabling services or interfaces that are not needed and preferring secure management protocols such as SSH. These choices shrink the attack surface and improve the security of routine device administration without requiring advanced security products.

The wrong answers in hardening questions often suggest convenience at the expense of security, such as leaving insecure access methods enabled or removing authentication. CCNA-level security expects you to recognize that strong fundamentals often come from disciplined configuration choices rather than from complex tools alone.

Exam trap

Avoid choosing convenience over security; protocols like Telnet and HTTP are easy but insecure for management.

Why the other options are wrong

C

Allowing anonymous administrative login means no authentication is required, which completely bypasses access control. This violates the principle of least privilege and exposes the device to unauthorized configuration changes.

D

VLAN 1 is the default VLAN and is often targeted in VLAN hopping attacks. Using VLAN 1 for all traffic violates the security best practice of segregating traffic and using dedicated VLANs for management, user data, and voice.

E

Removing authentication from VTY lines means anyone can connect to the device via Telnet or SSH without a password. This is a critical security flaw that allows unauthorized remote access.

When would these options actually be correct?

C

In a hypothetical exam question focused on legacy systems or specific environments where security policies are relaxed for testing purposes, allowing anonymous administrative login could be deemed acceptable for quick access or troubleshooting without strict security protocols.

D

In a question focused on simplifying network management for a small, non-critical environment where security is not a primary concern, placing all traffic in VLAN 1 might be considered acceptable for ease of configuration and maintenance.

E

In a hypothetical exam scenario focused on a legacy system with strict internal access controls where the question specifies that the system is isolated from external networks, removing authentication from VTY lines might be considered acceptable for ease of access by trusted internal personnel.

Why candidates pick the wrong answer

C

Students might think convenience is a valid trade-off for security, especially in small or lab environments. However, in any production network, anonymous access is never acceptable.

D

VLAN 1 is the default and easiest to configure, so students may assume it is safe or simpler. However, security guidelines explicitly recommend not using VLAN 1 for user traffic.

E

Students might confuse 'no authentication' with 'no password required' for convenience, or they may think that physical security alone is sufficient. However, remote management must always be authenticated.

686
MCQhard

Two routers, R1 and R2, have been configured with HSRP for VLAN 10 to provide default gateway redundancy to hosts. The virtual IP address is 192.168.10.1. After configuration, end hosts report inconsistent connectivity to the gateway, and a failover test reveals that when the active router is shut down, connectivity is lost. The network administrator checks the HSRP status on both routers. R1 shows HSRP group 10 as Active with no standby router, and R2 shows HSRP group 20 as Active with no standby router. What is the most likely cause of the redundancy failure?

A.R2 has a lower HSRP priority than R1, so it cannot become standby.
B.The HSRP group number is mismatched between R1 and R2.
C.The HSRP authentication strings do not match.
D.HSRP version 1 is used on R1 while version 2 is used on R2.
AnswerB

HSRP group numbers define distinct virtual router instances; R1 is active for group 10 with virtual IP 10.1.1.10, while R2 is active for group 20 with virtual IP 10.1.1.20. Because they belong to different groups, neither router accepts or processes the other's hello packets, so they form separate HSRP domains with no shared virtual MAC address. Consequently, the standby router cannot take over if the active fails, which is exactly the redundancy failure observed.

Why this answer

HSRP requires all routers participating in the same virtual router to use the same group number. Because R1 is active for group 10 and R2 is active for group 20, neither router has a standby for its group. If the active router for a group fails, no standby router can take over, causing loss of connectivity.

Authentication mismatch or HSRP version mismatch would typically prevent routers from forming a neighbor relationship, but the provided status showing each router active in a different group points specifically to a group mismatch.

Exam trap

Cisco often tests the HSRP group number mismatch as a subtle cause of redundancy failure because candidates focus on priority or authentication and overlook the fundamental requirement that the group number must be identical on all routers in the same virtual router group.

Why the other options are wrong

A

The output shows R2 is Active in its own group (20); priority only affects role election within the same group. The real problem is separate group numbers.

C

With mismatched authentication, the state would not be Active. The exhibit clearly shows Active on both routers, so authentication is not the cause.

D

Version mismatch would not change the displayed group number; the group number discrepancy is the direct evidence shown in the exhibit.

687
MCQmedium

You are configuring a Cisco router that connects to an ISP via a serial link. The ISP has assigned the next-hop address 203.0.113.1 for all Internet-bound traffic. You need to ensure that the router forwards all traffic for unknown destinations to this next-hop, but you do not want to use a fully specified static route. Which command should you use?

A.ip route 0.0.0.0 0.0.0.0 203.0.113.1
B.ip route 0.0.0.0 0.0.0.0 Serial0/0/0
C.ip route 203.0.113.1 255.255.255.255 Serial0/0/0
D.ip default-gateway 203.0.113.1
AnswerA

This command creates a default static route that matches all packets and forwards them to the specified next-hop address. It is the standard way to configure a default route when the exit interface is not specified, which is appropriate for multi-access networks like Ethernet. It meets the requirement without using a fully specified route.

Why this answer

A default static route is configured with the destination network 0.0.0.0 and subnet mask 0.0.0.0, followed by the next-hop IP address. This matches all packets and is the correct way to direct unknown traffic to the ISP. The other options either create a host route, point to an interface without a next-hop, or use a command that does not affect the routing table on a router.

Exam trap

The trap here is confusing the ip default-gateway command with a default route; the former is for management access on non-routing devices, not for routing transit traffic.

688
MCQmedium

Which service would a client most directly rely on to convert `server.example.com` into an IP address?

A.DNS
B.ARP
C.NTP
D.CDP
AnswerA

The Domain Name System is the service that directly performs hostname-to-IP address resolution. When a client types a URL like www.cisco.com, it sends a DNS query to a resolver, which returns the corresponding IPv4 or IPv6 address. This is the fundamental name resolution service on which applications rely before establishing TCP connections. Without DNS, users would need to memorize numeric IP addresses.

Why this answer

The client relies on DNS for name resolution. In plain language, DNS is the service that lets devices and users use readable names instead of memorizing numeric IP addresses. When the client needs to reach `server.example.com`, DNS helps translate that hostname into the IP-related information needed for actual communication.

This is different from DHCP, which supplies address configuration, and from NTP, which synchronizes time. It is also different from ARP, which resolves local IPv4 addresses to MAC addresses. The correct answer is the one associated specifically with hostname resolution.

Exam trap

A frequent exam trap is mistaking ARP for DNS because both involve address resolution. However, ARP only resolves IPv4 addresses to MAC addresses within the same local network segment and does not translate hostnames to IP addresses. Candidates might also confuse NTP or CDP as name resolution services, but NTP is for time synchronization, and CDP discovers directly connected Cisco devices.

Misunderstanding these roles leads to selecting incorrect answers, especially since the question specifically asks about converting a hostname to an IP address, which only DNS performs.

Why the other options are wrong

B

ARP is incorrect because it only resolves IPv4 addresses to MAC addresses on the local network segment and does not translate hostnames to IP addresses.

C

NTP is incorrect since it is used for synchronizing time between devices and does not perform any form of hostname or IP address resolution.

D

CDP is incorrect because it is a Cisco proprietary protocol used for discovering directly connected Cisco devices, not for resolving hostnames to IP addresses.

When would these options actually be correct?

B

If the question asked about determining the MAC address of a device given its IP address within a local network, ARP would be the correct answer. For example, 'Which protocol is used to resolve an IP address to a MAC address on a local network?' would make ARP the right choice.

C

If the exam question asked which service is responsible for synchronizing the time on a networked device, then NTP would be the correct answer. For example, a question could state, 'Which protocol ensures accurate timekeeping across devices in a network?'

D

In a question asking about the identification of neighboring Cisco devices on a network, such as 'Which protocol allows a router to discover information about directly connected devices?', CDP would be the correct answer as it is specifically designed for that purpose.

Why candidates pick the wrong answer

B

Students may confuse ARP with DNS because both involve address resolution. However, ARP resolves IP to MAC, not hostname to IP, and is limited to local network communication.

C

The acronym NTP might be confused with DNS due to both being network services, but their functions are entirely different. Students with partial knowledge might think NTP involves some form of lookup or resolution.

D

CDP's ability to provide IP addresses of neighboring devices might lead students to incorrectly assume it can resolve hostnames. However, CDP is a discovery protocol, not a name resolution service like DNS.

689
MCQhard

Why is R1 not installing the floating static default route into the routing table?

A.Because the OSPF default route has a lower administrative distance than the floating static route.
B.Because static default routes can never be used when OSPF is enabled.
C.Because the static default route must use a /24 mask instead of 0.0.0.0.
D.Because the next hop of a floating route must be a loopback address.
AnswerA

The OSPF default route has an AD of 110, while a floating static route is intentionally configured with a higher AD, such as 200. Because the router prefers lower AD, OSPF's default is installed in the routing table. The floating static route remains in the configuration as a backup and only becomes active if OSPF fails or the OSPF default disappears.

Why this answer

The floating static default route is not installed because the primary default route is already present and has a lower administrative distance. In practical terms, a floating static route is meant to sit in reserve and appear only when the preferred route is unavailable. Since the OSPF default route is active and has a better administrative distance, the backup route is not used yet.

This is a classic route-preference question. The key idea is not just that a static route exists, but that a higher-distance static route is intentionally designed to lose until the primary path disappears.

Exam trap

A frequent exam trap is assuming that a static default route must always appear in the routing table regardless of other routes. Candidates often think the floating static route is missing or misconfigured when it is simply suppressed due to its higher administrative distance compared to the OSPF default route. This misunderstanding leads to incorrect troubleshooting steps or answer choices.

Remember, floating static routes are designed to be backup routes and only become active when the primary route is unavailable, so their absence in the routing table under normal conditions is expected behavior.

Why the other options are wrong

B

Incorrect. Static default routes can coexist with OSPF routes. The router uses administrative distance to determine which route to install, so static routes are not automatically ignored when OSPF is enabled.

C

Incorrect. A default route must use the destination 0.0.0.0 with a mask of 0.0.0.0. Using a /24 mask is invalid for a default route and would not solve the issue of route selection.

D

Incorrect. Floating static routes do not require the next hop to be a loopback address. The next hop can be any reachable IP address, so this is not the reason the route is not installed.

When would these options actually be correct?

B

In a different exam scenario, if the question stated that static routes are not allowed in a specific routing protocol configuration or that the router is configured to only use OSPF for routing, then this option could be correct.

C

In a different question setup where the exam asks about the configuration of static routes specifically requiring a subnet mask, this option could be correct if the question states that a static default route must use a specific subnet mask instead of the default 0.0.0.0.

D

In a different exam scenario, if the question specified that a floating static route could only be configured with a next hop that is a loopback interface, then this option would be correct. For example, if the question stated that the router's configuration only allows loopback addresses for floating routes, this would validate option D.

Why candidates pick the wrong answer

B

Students may mistakenly think that enabling a dynamic routing protocol like OSPF disables all static routes, confusing the concept of route preference with protocol exclusivity.

C

Students may confuse the mask for a default route with the mask for a network route, thinking that a default route must have a non-zero mask to be valid.

D

Some students might recall that loopback interfaces are often used for stability in routing protocols, leading them to incorrectly assume that floating static routes also require loopback next hops.

690
Drag & Drophard

Drag and drop the following steps into the correct order for the router's routing table lookup process when forwarding a packet to a destination IP address, including the best-path selection logic.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The routing table lookup first matches the destination with the longest prefix, then applies tie-breakers: lowest administrative distance, then lowest metric, to determine the best path for forwarding.

Exam trap

Do not confuse the order of tie-breakers: administrative distance is always considered before metric. Also, remember that routing table lookup uses longest prefix match, not first match like ACLs.

Why candidates pick the wrong answer

B

Candidates often confuse the order of tie-breakers, thinking metric is more important because it is a direct measure of path cost.

C

Candidates may confuse routing table lookup with ACL processing, where the first matching entry is used.

D

Candidates might think that 'higher' is better due to other contexts (e.g., higher bandwidth is better), but for AD, lower is better.

691
MCQmedium

A port connected to an end-user PC should not send or expect VLAN tags from the endpoint. Which interface type is appropriate on the switch?

A.Access port
B.Trunk port
C.Routed port
D.Port-channel interface
AnswerA

An access port is correct because it carries traffic for exactly one VLAN and forwards untagged frames, which is exactly what a PC's NIC expects. PCs do not generate 802.1Q VLAN tags, so an access port's behavior of stripping and expecting untagged data aligns with the end-device's native Ethernet operation. Furthermore, access ports do not transmit DTP (Dynamic Trunking Protocol) frames, preventing any unwanted trunk negotiation toward the PC.

Why this answer

The appropriate interface type is an access port. In plain language, a normal user PC is expected to connect to one VLAN and send ordinary untagged Ethernet frames. The switch associates that traffic with the configured access VLAN.

This is different from a trunk, which is designed to carry multiple VLANs and commonly uses tagging to preserve VLAN identity across the link. Routed ports are Layer 3 interfaces used for routing between VLANs, not for attaching a single end-user PC. Port-channel interfaces aggregate multiple physical links for redundancy and bandwidth, but they do not determine whether VLAN tagging is used; the underlying port mode (access or trunk) still applies.

Therefore, access port is the only correct choice for an untagged, single-VLAN end-device connection.

Exam trap

Don't confuse the need for VLANs with the need for VLAN tagging. Access ports handle untagged traffic for single VLANs.

Why the other options are wrong

B

A trunk port is designed to carry traffic for multiple VLANs using 802.1Q tagging, which is not expected from a standard PC. Using a trunk port for a PC would cause the switch to expect tagged frames, leading to communication failures.

C

A routed port is a Layer 3 interface used for routing between VLANs or connecting to routers, not for connecting end-user PCs. It does not operate as a Layer 2 switchport and would not handle VLAN tagging as required.

D

A port-channel interface is a logical bundling of multiple physical links for increased bandwidth and redundancy, not a single connection to an end-user PC. It is used between switches or to servers, not for typical PC access.

When would these options actually be correct?

B

If the exam question specified a scenario where multiple VLANs need to be transmitted between switches or to a router, and the focus was on inter-switch communication rather than end-user devices, then a trunk port would be the correct answer.

C

In a scenario where the question asks for the appropriate interface type for connecting two routers or Layer 3 devices that need to communicate without VLAN tagging, a routed port would be the correct answer, as it allows for direct IP communication between devices.

D

If the exam question asked about configuring a switch to connect multiple access ports for redundancy and load balancing, where VLAN tagging is not required, then a port-channel interface would be the correct answer. The question would need to focus on link aggregation rather than VLAN handling.

Why candidates pick the wrong answer

B

Students might confuse trunk ports with the ability to carry multiple VLANs, but they forget that end devices typically do not send or understand VLAN tags.

C

Some may think a routed port can be used for any connection, but it lacks the Layer 2 switching functionality needed for a PC access connection.

D

Students might associate port-channels with any type of connection, but they are not appropriate for a simple PC connection where no link aggregation is needed.

692
Multi-Selectmedium

Which two statements accurately describe OSPF route selection or behavior at the CCNA level?

Select 2 answers
A.OSPF uses cost as its metric for choosing paths within OSPF.
B.OSPF compares its metric directly against EIGRP metrics across protocols.
C.OSPF route preference versus other route sources involves administrative distance.
D.OSPF process IDs must match between all neighboring routers.
E.OSPF can never install equal-cost paths.
AnswersA, C

OSPF assigns each interface a cost derived from bandwidth, and path selection sums these interface costs to pick the lowest-cost route to a destination. This satisfies the stem's requirement for an accurate CCNA-level statement about OSPF route selection behaviour.

Why this answer

Option A is correct because OSPF's metric is cost, which is derived from interface bandwidth (cost = reference bandwidth / interface bandwidth) and accumulated along the path, so the lowest total cost path is preferred within OSPF. Option C is correct because when OSPF competes with routes from other sources (static, EIGRP, RIP, etc.), the router uses administrative distance to decide which route source is trusted first; OSPF's default AD is 110. Option B is wrong because metrics from different routing protocols are not directly comparable — administrative distance, not the metric value, determines route preference across protocols.

Option D is wrong because OSPF process IDs are locally significant and do not need to match between neighbors. Option E is wrong because OSPF supports equal-cost multipath (ECMP) and can install multiple equal-cost routes into the routing table.

Exam trap

A frequent exam trap is confusing OSPF’s cost metric with administrative distance or thinking that OSPF process IDs must match between neighbors. Many candidates incorrectly believe that OSPF compares its metric directly against EIGRP metrics or that process IDs are globally significant. This misunderstanding leads to wrong answers because OSPF cost is only used internally within OSPF to select the best path, while administrative distance is used to compare routes from different protocols.

Also, OSPF process IDs are locally significant identifiers and do not need to match for adjacency to form.

Why the other options are wrong

B

Option B is incorrect because OSPF does not compare its metric directly against EIGRP metrics. Metrics are protocol-specific and only administrative distance is used to compare routes across different protocols.

D

Option D is incorrect because OSPF process IDs are locally significant and do not need to match between neighboring routers. Adjacency forms based on matching parameters like area ID and authentication, not process ID.

E

Option E is incorrect because OSPF supports equal-cost multipath (ECMP) routing, allowing multiple routes with the same cost to be installed and used simultaneously for load balancing.

When would these options actually be correct?

B

If the exam question asked about inter-protocol route selection or the behavior of routing protocols in a mixed environment, where OSPF and EIGRP metrics were being compared for route selection, then this option could be correct.

D

In a different context, a question could ask about OSPF configuration requirements for establishing neighbor relationships. If it specified that process IDs must match for a specific feature or scenario, then this option could be correct.

E

In a question specifically asking about OSPF's limitations in a scenario where only a single path is allowed due to configuration constraints or specific network designs, this option could be correct. For example, if the question states that OSPF is configured to not allow ECMP due to a specific policy.

Why candidates pick the wrong answer

B

Students might think that since both are routing protocols, their metrics can be compared directly, but they are calculated differently and are not interchangeable.

D

Students often confuse OSPF process IDs with EIGRP autonomous system numbers, which must match between neighbors. This leads to the incorrect assumption that OSPF process IDs must also match.

E

Some students may think OSPF only uses a single best path because they are familiar with the SPF algorithm's loop-free property, but ECMP is a standard feature in OSPF.

693
PBQeasy

You are connected to SW1 via the console. SW1 is a Layer 2 switch with an access port G0/1 connected to a server. The network administrator has noticed that the server is sending BPDUs, which could cause network instability. You need to configure PortFast and BPDU Guard on port G0/1 to prevent BPDU-related issues and ensure the port transitions to forwarding state immediately.

Network Topology
G0/1ServerSW1

Hints

  • •PortFast enables immediate transition from blocking to forwarding state.
  • •BPDU Guard disables the port if a BPDU is received.
  • •These features are typically applied to access ports connected to end devices.
A.interface G0/1 spanning-tree portfast spanning-tree bpduguard enable
B.interface G0/1 spanning-tree portfast spanning-tree guard root
C.interface G0/1 spanning-tree portfast spanning-tree bpdufilter enable
D.interface G0/1 spanning-tree portfast spanning-tree bpduguard default
AnswerA
solution
! SW1
interface GigabitEthernet0/1
spanning-tree portfast
spanning-tree bpduguard enable

Why this answer

PortFast allows an access port to bypass STP listening/learning states, providing immediate connectivity. BPDU Guard protects the network by shutting down the port if a BPDU is received, preventing potential loops from unauthorized switches.

Exam trap

Cisco exams often test the exact syntax for STP features. Remember that BPDU Guard uses 'enable' at the interface level, while BPDU Filter uses 'enable' as well. Root Guard uses 'guard root'.

Do not confuse these or use global commands on interfaces.

Why the other options are wrong

B

The specific factual error is confusing Root Guard with BPDU Guard. Root Guard is used to enforce the root bridge position, not to protect against BPDUs.

C

The specific factual error is that BPDU Filter silently drops BPDUs instead of taking action, which can allow loops to form if an unauthorized switch is connected.

D

The specific factual error is using the global configuration command on an interface. The global command enables BPDU Guard on all PortFast-enabled ports, but the question asks to configure it on a specific port.

Why candidates pick the wrong answer

B

Candidates pick this because both features are STP enhancement mechanisms, and 'guard' sounds similar to 'BPDU Guard'.

C

Candidates pick this because both BPDU Guard and BPDU Filter deal with BPDUs, and 'filter' might seem like a way to prevent BPDU issues.

D

Candidates pick this because 'default' might be misinterpreted as enabling the feature, and they may not remember the exact syntax for interface-level configuration.

694
MCQhard

A controller-based WLAN uses 5 GHz in an open office. Clients keep disconnecting when users roam between APs, but signal strength remains strong. Based on the exhibit, what is the most likely problem?

A.A transmit power mismatch is creating asymmetric coverage around AP-3.
B.The SSID must use 2.4 GHz only for roaming to work.
C.WPA2 cannot support roaming between APs.
D.The WLAN needs a different DHCP scope on each AP.
AnswerA

A transmit power mismatch on AP-3 creates an oversized basic service area, making its BSSID audible at distances where neighboring AP-3 signals are faint. Clients near the edge of that cell hear AP-3 strongly but transmit at lower client power, so the AP cannot hear them reliably, causing uplink failures and delayed roaming. The asymmetry leads to sticky clients who remain associated to AP-3 even when another AP offers a stronger uplink, degrading throughput and VoIP quality.

Why this answer

The APs are transmitting at much higher power than the clients, creating a coverage imbalance. Clients may hear the AP well enough to stay associated too long, while the AP cannot reliably hear the weaker client at the same cell edge. That leads to sticky-client and roaming issues even when RSSI looks strong.

Exam trap

A common exam trap is assuming that roaming issues are caused by encryption protocols like WPA2 or by requiring 2.4 GHz operation only. Candidates may also mistakenly believe that DHCP scopes must be unique per AP to support roaming. These misconceptions distract from the real issue: transmit power mismatch causing asymmetric coverage.

The APs transmitting at much higher power than clients cause sticky client problems, where clients do not roam properly despite strong signal strength. Understanding this subtle power imbalance is critical to avoid selecting incorrect answers related to encryption or DHCP.

Why the other options are wrong

B

Incorrect because roaming works on 5 GHz and is often preferred there; restricting SSID to 2.4 GHz is unnecessary and unrelated to the problem.

C

Incorrect because WPA2 supports roaming; encryption type does not cause clients to disconnect when roaming between APs.

D

Incorrect because DHCP scopes are shared in controller-based WLANs; separate DHCP scopes per AP are not required for roaming functionality.

When would these options actually be correct?

B

In a different scenario where a question specifies that a WLAN is configured to only operate on the 2.4 GHz band and clients are experiencing roaming issues, then stating that the SSID must use 2.4 GHz only for roaming would be correct, as it would imply that the configuration limits roaming capabilities.

C

In a different question setup where the focus is on a legacy network using WEP or an outdated protocol that does not support roaming, stating that WPA2 cannot support roaming would be correct. For example, if the question specified a network using WEP and asked about roaming capabilities, this option could be valid.

D

In a different scenario where the question specifies that each AP is on a separate subnet and requires distinct DHCP scopes for clients to connect, this option would be correct. For example, if the question described a network with multiple VLANs and DHCP servers, then having different DHCP scopes would be necessary for proper client assignment.

Why candidates pick the wrong answer

B

Students might think that 2.4 GHz has better range and thus might be better for roaming, but roaming is about handoff between APs, not range. The 5 GHz band supports roaming just as effectively.

C

Some might confuse WPA2 with older security methods that had roaming limitations, or think that encryption keys need to be renegotiated causing delays, but WPA2 handles this efficiently.

D

Students might think that each AP needs its own subnet for clients to roam, but in a controller-based WLAN, clients typically stay on the same subnet across APs, and DHCP is handled centrally.

695
PBQhard

You are connected to R1. Configure inter-VLAN routing on R1 using router-on-a-stick so that hosts in VLAN 10 (192.168.10.0/24) and VLAN 20 (192.168.20.0/24) can communicate. The switch SW1 is already configured with VLANs and trunking, but R1's current configuration prevents traffic. Identify and fix the issues.

Network Topology
G0/0trunkR1SW1

Hints

  • •Check if the physical interface is administratively down.
  • •Verify that the trunk is allowing VLANs 10 and 20.
  • •Ensure 'ip routing' is enabled (it is by default).
A.Enable the physical interface with the 'no shutdown' command on R1.
B.Change the encapsulation on the subinterfaces to use dot1Q with native VLAN 10 and 20 respectively.
C.Enable IP routing globally with the 'ip routing' command on R1.
D.Remove the 'no shutdown' from the subinterfaces and apply it only to the physical interface.
AnswerA
solution
! R1
interface GigabitEthernet0/0
no shutdown
exit
show interfaces trunk

Why this answer

The issue was that the physical interface GigabitEthernet0/0 on R1 was administratively down, causing all subinterfaces for VLANs 10 and 20 to be in a down state. Enabling it with 'no shutdown' brings the trunk up, allowing inter-VLAN routing because the switch already has trunking configured. The other options are incorrect because they suggest steps that are either already in place (IP routing) or not needed (changing encapsulation or moving no shutdown to subinterfaces).

Exam trap

A common mistake is overlooking that router-on-a-stick requires the physical interface to be administratively up, as subinterfaces cannot function independently.

Why the other options are wrong

B

Changing encapsulation is unnecessary because the subinterfaces already use the correct dot1Q encapsulation for VLANs 10 and 20.

C

The 'ip routing' command is already enabled by default on routers, and global routing is not the problem here.

D

Subinterfaces do not support a 'no shutdown' command; their operational state is determined solely by the physical interface.

Why candidates pick the wrong answer

B

Candidates might think that each subinterface should match its VLAN's native status, but the native VLAN is a trunk property, not per-VLAN.

C

Candidates often assume that inter-VLAN routing requires explicitly enabling IP routing, but it is on by default.

D

Candidates might think subinterfaces can be independently enabled/disabled, but they are logical interfaces that depend on the physical interface.

696
MCQmedium

Why is BPDU Guard commonly enabled on PortFast-enabled access ports?

A.To make STP root election happen faster
B.To disable STP permanently on access ports
C.To err-disable a port if it receives unexpected BPDUs
D.To allow only one MAC address on the access port
AnswerC

BPDU Guard is a protective feature used with PortFast on access ports to prevent loops from unauthorized BPDUs. If the port receives any BPDU, which should not occur on an end-node connection, the switch immediately err-disables the interface to stop potential bridging loops. This safeguards the network from misconfigured or malicious devices.

Why this answer

PortFast ports are meant for end devices, not for switches. BPDU Guard protects the LAN by shutting down a PortFast port that unexpectedly starts receiving BPDUs, which usually means an unauthorized switch was connected.

Exam trap

Don't confuse BPDU Guard with PortFast or BPDU filtering; each has distinct roles.

Why the other options are wrong

A

BPDU Guard is a security feature that err-disables a port upon receiving BPDUs; it does not accelerate root election. Root election speed is influenced by STP timers and bridge priorities, not BPDU Guard.

B

BPDU Guard does not disable STP permanently; it only reacts to BPDU reception by err-disabling the port. STP remains active on other ports, and the port can be re-enabled after the violation is resolved.

D

Limiting MAC addresses on a port is the function of port security, not BPDU Guard. BPDU Guard specifically monitors for BPDU frames and takes action if any are received.

When would these options actually be correct?

A

In a scenario where the exam question asks about methods to optimize STP performance and mentions features that can enhance the speed of root bridge election, this option could be correct if it was framed around a hypothetical technology that accelerates STP processes.

B

In a different exam scenario, if the question asked about a feature that disables STP on access ports to prevent any STP-related traffic, this option could be correct. For example, a question could specify a configuration where STP is not needed due to a specific network design.

D

In a different exam scenario, if the question asked about the purpose of MAC address filtering on access ports, option D could be correct. For example, a question could state, 'What is the function of limiting MAC addresses on an access port?' where the correct answer would be to allow only one MAC address.

Why candidates pick the wrong answer

A

The name 'Guard' might suggest it protects or speeds up STP processes, but its purpose is purely protective, not performance-related.

B

Students may confuse BPDU Guard with disabling STP because it prevents BPDU processing on the port, but STP is still running globally and on other ports.

D

Both features are commonly applied to access ports for security, leading to confusion between BPDU Guard and port security's MAC address limiting.

697
MCQhard

A host address is 192.168.14.222/28. Which address is the broadcast address of its subnet?

A.192.168.14.207
B.192.168.14.223
C.192.168.14.208
D.192.168.14.224
AnswerB

With /28, the host portion occupies only the last 4 bits, so the usable range for the subnet containing .222 is 192.168.14.208 through 192.168.14.223. Setting all host bits to 1 yields the broadcast address 192.168.14.223, which is the directed broadcast for the /28 subnet that includes .222. This makes .223 the correct answer.

Why this answer

A /28 subnet has a block size of 16. In practical terms, the fourth-octet blocks are 0-15, 16-31, and so on. Because 222 falls within the 208-223 block, the broadcast address is the last address in that block: 192.168.14.223.

This is a subnet-boundary question that depends on identifying the correct /28 block before choosing the broadcast address.

Exam trap

Be careful not to confuse the broadcast address with the network address of the next subnet or a host address within the subnet.

Why the other options are wrong

A

192.168.14.207 is the broadcast address of the previous /28 subnet (192.168.14.192/28), not the subnet containing 192.168.14.222.

C

192.168.14.208 is the network address (subnet ID) of the /28 subnet containing .222, not the broadcast address.

D

192.168.14.224 is the network address of the next /28 subnet (192.168.14.224/28), not the broadcast of the current subnet.

When would these options actually be correct?

A

If the question asked for the broadcast address of a different subnet, such as 192.168.14.192/28, then option A (192.168.14.207) would be correct, as it would be the broadcast address for that specific subnet.

C

If the question specified a subnet mask of /29 instead of /28, and the host address was 192.168.14.208, then option C would be the correct answer as the broadcast address would be 192.168.14.215 for that subnet.

D

If the question specified a subnet mask of /27 instead of /28, the address 192.168.14.224 would be the broadcast address for the subnet 192.168.14.192/27, which encompasses the range from 192.168.14.192 to 192.168.14.224.

Why candidates pick the wrong answer

A

A student might miscalculate the subnet boundaries or confuse the broadcast address with that of an adjacent subnet.

C

Students often confuse the network address with the broadcast address, especially when they know the subnet starts at .208.

D

A student might incorrectly add the block size (16) to the host address or think the broadcast is the next network address.

698
Drag & Dropmedium

Drag and drop the following OSPFv2 neighbor state transitions into the correct order, starting from the initial Down state on a broadcast or point-to-point network (non-NBMA).

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The standard OSPF neighbor state machine on broadcast and point-to-point networks proceeds: Down, Init, 2-Way, ExStart, Exchange, Loading, Full. The Attempt state exists only on NBMA networks and is not used here. Option D correctly lists the first five states in order: Down → Init → 2-Way → ExStart → Exchange.

Other options incorrectly include the NBMA-only Attempt state or misorder the states like Loading before Exchange.

Exam trap

Do not confuse the standard OSPF neighbor states with the NBMA-specific Attempt state; unless the network type is explicitly NBMA, assume the common broadcast/point-to-point order omitting Attempt.

When would these options actually be correct?

A

This ordering is used when configuring OSPF over NBMA networks such as Frame Relay or ATM, where the Attempt state is introduced.

Why candidates pick the wrong answer

B

Candidates may confuse the order of states after ExStart, thinking Loading follows immediately, or they may forget the Attempt state on NBMA.

C

Candidates might think Init (receiving Hello) comes before Attempt (sending Hello) because they consider receiving as the first step, but the state machine defines Attempt as the state after sending Hello.

699
MCQhard

An administrator wants to block all Telnet access to a router’s VTY lines and allow only SSH. Which change most directly supports that goal?

A.Configure the VTY lines to accept SSH and not Telnet.
B.Enable PortFast on the VTY lines.
C.Use DHCP snooping to protect the VTY lines.
D.Increase the OSPF hello interval.
AnswerA

Configuring the VTY lines to accept SSH only directly satisfies the requirement by restricting the transport protocol permitted on inbound VTY connections. Cisco IOS applies the `transport input ssh` command under `line vty`, which rejects Telnet negotiation attempts while permitting SSH sessions, blocking all Telnet access without affecting management reachability.

Why this answer

The most direct change is to configure the VTY lines to accept only SSH, which removes Telnet as an accepted protocol. Option B (PortFast) is a spanning-tree feature that speeds up port transition on access ports and has nothing to do with VTY access. Option C (DHCP snooping) is a Layer 2 security feature to prevent rogue DHCP servers; it does not affect VTY line protocols.

Option D (OSPF hello interval) is an OSPF timer adjustment, unrelated to remote access security. Therefore, only option A directly achieves the goal.

Exam trap

Avoid assuming that ACLs or global commands can replace specific VTY line configurations for protocol restriction.

Why the other options are wrong

B

PortFast is a spanning-tree feature for switch ports, not related to VTY line protocols.

C

DHCP snooping is a Layer 2 security feature against rogue DHCP servers, irrelevant to Telnet/SSH access.

D

Increasing the OSPF hello interval affects OSPF neighbor discovery, not remote access to the router.

When would these options actually be correct?

B

If the question were about optimizing switch port configurations for rapid connectivity in a network where VTY lines are used for management, then enabling PortFast could be the correct answer. For example, a question might ask how to reduce the time it takes for a switch port to become active after being connected.

C

If the question were about securing a network against unauthorized DHCP servers affecting devices that connect to the router, then using DHCP snooping would be the correct answer. In that scenario, the focus would be on protecting the network's IP address assignment rather than access protocols like Telnet or SSH.

D

If the question asked about optimizing OSPF performance in a network where OSPF is being used, increasing the hello interval could be correct. For instance, a scenario might involve reducing OSPF traffic in a stable network environment.

Why candidates pick the wrong answer

B

A student might confuse PortFast with a feature that speeds up or secures connections, but it is unrelated to VTY line configuration and is only applicable to switch ports.

C

The term 'snooping' might imply monitoring or blocking, leading a student to think it could restrict Telnet, but DHCP snooping is specifically for DHCP traffic and not for management protocols.

D

A student might think that increasing the hello interval could slow down or block Telnet sessions, but OSPF timers are unrelated to VTY line configuration and do not affect management access.

700
MCQhard

A network engineer configures a primary default route via Gi0/0 (next-hop 192.168.12.2) and a floating static default route via Gi0/1 (next-hop 192.168.12.6) with AD 200. To test failover, the engineer issues the shutdown command on Gi0/0. After this, the router does not have a default route in the routing table. Which problem explains this behavior?

A.The backup interface Gi0/1 is administratively down, making the next-hop unreachable.
B.The floating static route uses an administrative distance of 200, which is too low to replace the primary route.
C.The primary default route remains in the routing table because shutting down Gi0/0 does not remove the static route.
D.The floating static route is missing a track object, so the router cannot detect the primary path failure.
AnswerA

With Gi0/1 administratively shut down, its interface state is down at both Layer 1 and Layer 2, so the router cannot use it as a valid output interface. A static route whose configured next-hop resides on a down interface is considered unreachable, and the router will not install it in the routing table. Because both Gi0/0 and Gi0/1 are unavailable, no default route is present, and the router has no path to the unknown destination.

Why this answer

A floating static route only installs in the routing table when its administrative distance is higher than the primary route's and the primary route is removed. When Gi0/0 is shut down, the primary static default route is withdrawn, but the floating static via Gi0/1 cannot be installed because Gi0/1 itself is administratively down, so its next-hop 192.168.12.6 is unreachable. A static route requires a valid, reachable outgoing interface (and for non-point-to-point, a resolvable next-hop) before it can be placed in the RIB.

Exam trap

The trap here is assuming that a floating static route will always take over when the primary fails, without checking whether the backup interface itself is operational — candidates focus on AD values and miss the physical/link-state prerequisite.

Why the other options are wrong

B

A lower AD would make it preferred, defeating the purpose of a floating route.

C

The primary route is removed from the table when the interface goes down.

D

Track objects are optional enhancements for faster failover but not mandatory for floating static operation.

701
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure and verify OSPFv3 neighbor adjacency using link-local addresses in area 0.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order enables IPv6 unicast routing globally, creates the OSPFv3 process, enters interface configuration, assigns the interface to the OSPFv3 process in area 0 (which activates OSPFv3 on the link), and finally verifies the neighbor relationship. IPv6 unicast routing must be enabled first because OSPFv3 requires IPv6 packet forwarding. The router process must exist before an interface can be associated with it.

Assigning the interface to area 0 triggers Hello packet exchange over link-local addresses. The show command confirms the adjacency formed.

702
MCQmedium

A network administrator is troubleshooting a Windows 10 workstation that cannot access the internet. The workstation receives an IPv4 address starting with 169.254.x.x. The network uses DHCP, and other workstations on the same subnet are working correctly. What is the most likely cause of this issue?

A.The workstation's DNS server settings are incorrect.
B.The workstation's network cable is unplugged or faulty, preventing DHCP communication.
C.The DHCP server has exhausted its address pool.
D.The workstation's default gateway is misconfigured.
AnswerB

A physical connectivity issue (e.g., unplugged or faulty cable) prevents the workstation from reaching the DHCP server, causing it to fall back to APIPA. This is the most common cause when only one workstation is affected.

Why this answer

The 169.254.x.x address is an Automatic Private IP Addressing (APIPA) address assigned by Windows when DHCP fails. Since other workstations on the same subnet work correctly, the DHCP server and network are functional, isolating the issue to the specific workstation. A faulty or unplugged network cable would prevent the workstation from sending DHCP Discover messages, causing it to fall back to APIPA.

Exam trap

Cisco often tests the distinction between DHCP failure symptoms (APIPA) and other connectivity issues, trapping candidates who confuse DNS or gateway misconfigurations with the inability to obtain an IP lease.

Why the other options are wrong

A

Incorrect DNS settings prevent name resolution but do not affect IP address assignment. The workstation would still receive a valid IP from DHCP, not an APIPA address.

C

If the DHCP pool were exhausted, all workstations would fail to obtain addresses and use APIPA. The scenario states other workstations are working correctly, so pool exhaustion is not the cause.

D

A misconfigured default gateway would prevent internet access but the workstation would still receive a valid IP from DHCP. APIPA addresses are only assigned when DHCP fails entirely.

Why candidates pick the wrong answer

A

Students often confuse DNS issues with DHCP issues because both can cause internet connectivity problems. However, DNS does not impact IP address acquisition.

C

Students may think DHCP pool exhaustion is a common cause of APIPA addresses, but they overlook that it would affect multiple clients, not just one.

D

Since the symptom is no internet access, students might jump to gateway misconfiguration. However, the APIPA address indicates a DHCP failure, not a routing issue.

703
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure inter-VLAN routing using a router-on-a-stick topology.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Inter-VLAN routing via router-on-a-stick requires creating VLANs on the switch, placing access ports in those VLANs, configuring a trunk to the router with the correct native VLAN to avoid mismatch, enabling the physical router interface, and then defining subinterfaces per VLAN with 802.1Q encapsulation and IP addresses. This ensures traffic from different VLANs can be routed.

704
MCQeasy

Which static route on R1 sends all unknown IPv4 destinations to next-hop address 192.0.2.1?

A.ip route 0.0.0.0 255.255.255.255 192.0.2.1
B.ip route 0.0.0.0 0.0.0.0 192.0.2.1
C.ip route 255.255.255.255 0.0.0.0 192.0.2.1
D.ip default-gateway 192.0.2.1
AnswerB

The command ip route 0.0.0.0 0.0.0.0 192.0.2.1 installs a default static route whose prefix and mask are both all zeros. Because the routing table uses longest-prefix-match, this quad-zero route matches every IPv4 destination that is not matched by a more specific route. R1 will therefore forward all unknown IPv4 traffic out the interface toward next-hop 192.0.2.1.

Why this answer

A quad-zero route is the IPv4 default route. It matches destinations that do not have a more specific entry in the routing table.

Exam trap

A frequent exam trap is selecting a static route with the destination 0.0.0.0 but an incorrect subnet mask like 255.255.255.255, which matches only the single host 0.0.0.0 rather than all unknown destinations. Another common mistake is confusing the 'ip default-gateway' command with a default route; the former is used only on devices that do not perform routing, such as Layer 2 switches, and does not influence routing decisions on routers. Candidates must recognize that the default route requires both destination and mask to be 0.0.0.0 to function correctly as a catch-all route for unknown IPv4 destinations.

Why the other options are wrong

A

The route 'ip route 0.0.0.0 255.255.255.255 192.0.2.1' incorrectly uses a subnet mask of 255.255.255.255, which matches only the single host 0.0.0.0, not all unknown destinations. Therefore, it does not serve as a default route.

C

The route 'ip route 255.255.255.255 0.0.0.0 192.0.2.1' reverses the destination and mask fields, creating an invalid route that does not function as a default route or any valid static route.

D

'ip default-gateway 192.0.2.1' sets the default gateway for devices that do not perform routing, such as Layer 2 switches. It does not create a routing entry on routers and therefore cannot be used to send unknown IPv4 destinations.

When would these options actually be correct?

A

If the exam question asked for a specific route to a single host (e.g., 'Which static route on R1 sends traffic only for the IP address 0.0.0.0 to next-hop address 192.0.2.1?'), then option A would be correct as it defines a route for that specific host.

C

This option would be correct in a scenario where the question asks for a route that matches a specific broadcast address, such as directing traffic for all broadcast packets to a next-hop address, which would be relevant in certain network configurations.

D

If the exam question asked for the command to set a default gateway for a Layer 2 device like a switch, then 'ip default-gateway 192.0.2.1' would be the correct answer, as it would direct traffic to the specified gateway for devices that do not have a specific route.

Why candidates pick the wrong answer

A

Students may confuse the all-zeros network address with a default route, but the mask is critical. Using a /32 mask is a common mistake when trying to create a default route.

C

Some test-takers might think that using all ones in the network field represents 'all networks', but this is incorrect. The default route uses all zeros for both network and mask.

D

The term 'default-gateway' sounds similar to 'default route', leading students to believe it is the correct command for routers. However, routers use the 'ip route' command for static routing.

705
Matchingmedium

Match each service to the kind of problem it most directly helps solve.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Hostname works incorrectly or cannot be resolved into IP information

Clients need automatic IP configuration

Device timestamps do not line up consistently

Administrators need centralized event and log collection

Why these pairings

DNS solves the problem of remembering IP addresses. DHCP eliminates manual IP configuration. FTP enables file transfers.

SSH provides encrypted remote access. RADIUS and TACACS+ are AAA protocols, with RADIUS commonly used for network access and TACACS+ for device administration.

Exam trap

A common trap is confusing the roles of RADIUS and TACACS+, or thinking that services like DNS or DHCP have overlapping functions. Remember that DNS resolves names, DHCP assigns IPs, FTP transfers files, SSH secures remote access, RADIUS handles network access, and TACACS+ handles device administration.

When would these options actually be correct?

B

This would be correct in a question asking to match services to problems in a deliberately scrambled, non-standard scenario where each service is misassigned to a different problem type, such as a trick question testing attention to detail rather than actual knowledge.

C

If the question asked to match services to problems they solve in a reversed or scrambled order where the pairs are intentionally misaligned but each service is paired with a problem it actually solves (e.g., DNS - name resolution, DHCP - IP assignment, etc.), then this option would be correct if the pairings were correct. However, here the pairings are incorrect.

D

This option would be correct if the question asked to match services to problems they solve in a reversed or misaligned manner, such as 'Match each service to a problem it does NOT solve' or 'Match each service to a common misconception.'

Why candidates pick the wrong answer

B

Candidates may confuse the functions of similar protocols (e.g., RADIUS vs TACACS+) or misremember which service solves which problem, especially under time pressure or when relying on superficial similarities like 'access' or 'remote'.

C

Candidates may confuse the functions of services (e.g., thinking DNS provides encryption due to DNSSEC, or mixing up DHCP and FTP roles) or misread the matching pairs, leading to a plausible but incorrect assignment.

D

Candidates may confuse the functions of similar services (e.g., RADIUS vs. TACACS+) or misremember which service handles encryption, file transfers, or IP configuration, leading to swapped mappings.

706
MCQhard

A trunk link has a native VLAN mismatch between two switches. What is the most likely result?

A.All VLANs except the native VLAN stop forwarding immediately.
B.Untagged frames can be interpreted as belonging to different VLANs on each switch.
C.The trunk automatically converts to an access port.
D.STP is disabled on the trunk until the mismatch is corrected.
AnswerB

With a native VLAN mismatch, each switch places untagged 802.1Q frames into its locally configured native VLAN. For example, if Switch A's native VLAN is 10 and Switch B's is 20, a single untagged frame will be associated with VLAN 10 on one side and VLAN 20 on the other, effectively crossing broadcast domains and potentially exposing traffic to the wrong VLAN. This misclassification can lead to security breaches, routing loops, or connectivity anomalies because VLAN membership is not preserved end-to-end.

Why this answer

Untagged traffic may be placed into different VLANs on each side of the trunk, causing traffic leakage or connectivity problems.

Exam trap

Be careful not to confuse native VLAN mismatches with issues that affect tagged traffic or automatic switch behavior.

Why the other options are wrong

A

A native VLAN mismatch does not cause all other VLANs to stop forwarding. The trunk continues to forward frames for all VLANs, but untagged frames (native VLAN) are miscommunicated.

C

A trunk port does not automatically convert to an access port due to a native VLAN mismatch. The trunk remains operational, but the native VLAN mismatch causes problems for untagged traffic.

D

STP continues to run normally on the trunk link despite a native VLAN mismatch. The mismatch does not disable STP; it only affects the handling of untagged frames.

When would these options actually be correct?

A

In a different scenario, if the question stated that a switch was configured to drop all VLAN traffic except the native VLAN due to a specific security policy, then this option could be correct. This would imply a configuration that restricts forwarding based on VLAN settings.

C

In a different scenario where the question states that a trunk port is configured incorrectly and the switch is set to automatically convert misconfigured ports, option C could be correct. For example, if the exam asks what happens when a trunk port is misconfigured and the switch has a feature enabled that forces a trunk to revert to access mode, then this option would apply.

D

In a different scenario where the question specifies that a trunk link has been configured to disable STP for performance reasons, a native VLAN mismatch could lead to STP being disabled, making this option correct. The question would need to clarify that STP behavior is altered due to specific configurations.

Why candidates pick the wrong answer

A

Students might think that a misconfiguration on the native VLAN would disrupt all VLAN traffic, but in reality, only the native VLAN traffic is affected.

C

Some might confuse a native VLAN mismatch with other trunk misconfigurations that cause the port to revert to access mode, such as a VLAN mismatch on a DTP negotiation.

D

Students may think that any misconfiguration on a trunk would cause STP to shut down the port for safety, but STP only blocks ports to prevent loops, not due to native VLAN mismatches.

707
Multi-Selectmedium

Which two statements accurately describe subnet masks in IPv4?

Select 2 answers
A.It identifies the network-versus-host split in an IPv4 address.
B.It helps a host determine whether a destination is local or remote.
C.It resolves hostnames into IP addresses.
D.It encrypts packets before they leave the host.
E.It replaces the need for a default gateway.
AnswersA, B

A subnet mask is a 32-bit value that uses contiguous 1s to mark the network portion of an IPv4 address and contiguous 0s to mark the host portion. By ANDing an IP address with its mask, you derive the network address, which reveals the exact boundary between the bits that identify the network and the bits assigned to hosts. This boundary is the mask's defining purpose, so saying it identifies the network-versus-host split is accurate.

Why this answer

A subnet mask tells the host which part of the IPv4 address refers to the network and which part refers to the host. In plain language, it helps the device determine whether a destination is local or remote. That decision is essential because it affects whether the host uses ARP directly or forwards traffic to the default gateway.

The wrong answers usually attribute unrelated behaviors to the subnet mask, such as encryption or hostname resolution. The two correct answers are the ones that preserve its role in defining local scope and address structure.

Exam trap

Avoid confusing subnet mask functions with encryption or DNS, as these are unrelated to IP address segmentation.

Why the other options are wrong

C

Subnet masks are used solely for IP addressing and routing purposes, not for name resolution. Hostname-to-IP-address resolution is performed by the Domain Name System (DNS), which is a completely different protocol and service.

D

Subnet masks do not provide any encryption or security functionality. Encryption of packets is performed by protocols such as IPsec, TLS, or other cryptographic mechanisms, which operate independently of subnet masking.

E

A default gateway is still required for any traffic destined to a different subnet. The subnet mask only defines the local network boundary; it does not provide routing to other networks. Without a default gateway, a host cannot send packets off its subnet.

When would these options actually be correct?

C

If the exam question were to ask about the functions of DNS or the process of hostname resolution, then option C would be correct. For example, a question might ask, 'What is the primary function of a DNS server in a network?'

D

If the exam question asked about the functions of network security protocols or methods for securing data transmission over IP networks, then option D could be correct. For instance, a question might ask which methods encrypt packets before transmission, where encryption is a key focus.

E

In a question that asks about network configurations in a scenario where all devices are on the same subnet and no external routing is required, one might argue that a default gateway is unnecessary, making this option seem correct.

Why candidates pick the wrong answer

C

Students often confuse the roles of different network layer functions. Since subnet masks are involved in IP addressing, they might mistakenly think they also handle name resolution, especially when studying both topics in the same context.

D

The term 'mask' might be misinterpreted as something that hides or protects data, leading some students to incorrectly associate it with encryption or security features.

E

Some students might think that if a subnet mask defines the local network, then all destinations within that mask are reachable directly, and they might overlook the need for a gateway to reach external networks.

708
Drag & Dropmedium

A network troubleshooter is using Cisco IOS-XE's embedded packet capture feature to capture traffic on an interface and then analyze it in Wireshark to isolate a Layer 2 or Layer 3 fault. Which of the following sequences represents the correct order of steps?

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct workflow is to first define the capture point (interface and any filters), then start the capture, stop it when sufficient data is collected, export the captured packets to a file, and finally open that file in Wireshark for analysis. Starting the capture before defining the point, exporting before stopping, or defining the point after stopping all result in an invalid or incomplete capture process.

Exam trap

Remember that the capture point must be defined before starting the capture, and the capture must be stopped before exporting. Do not confuse the order of these steps.

Why candidates pick the wrong answer

B

Candidates might think starting the capture first is intuitive, but the capture point must be defined beforehand.

C

Candidates might think exporting can be done at any time, but the capture must be stopped to ensure data integrity.

D

Candidates may confuse the order, thinking start/stop can be done before configuration, but the capture point must be set first.

709
Multi-Selectmedium

Which two statements accurately describe why organizations use separate employee and guest WLANs?

Select 2 answers
A.They allow different access policies and trust boundaries for different user groups.
B.They help isolate guest access from internal corporate resources.
C.They eliminate the need for wireless security.
D.They make all roaming problems disappear automatically.
E.They replace the need for VLANs or policy controls behind the scenes.
AnswersA, B

Separate WLANs map to distinct security domains, enabling administrators to enforce role-based policies such as 802.1X authentication for employees and PSK access for guests. This segmentation establishes clear trust boundaries, so that device type, user role, or location can determine which network resources are reachable. Without multiple WLANs, all clients might share the same Layer 2 domain, making it impossible to apply differentiated security controls.

Why this answer

Organizations use separate WLANs because different user groups usually require different trust levels, policies, and access rights. In practical terms, employees may need access to internal business systems, while guests usually need a more limited and isolated experience. Separate WLANs make that segmentation and policy enforcement easier.

This is a design and security decision, not just a naming preference.

Exam trap

Avoid assuming that separate WLANs are used for performance improvements or marketing purposes; focus on security and access control.

Why the other options are wrong

C

Separate WLANs do not eliminate the need for wireless security; both employee and guest WLANs require encryption (e.g., WPA2/WPA3) and authentication mechanisms to protect data in transit and prevent unauthorized access.

D

Roaming problems, such as handoff delays or authentication re-requirements, are not automatically resolved by having separate WLANs; they depend on factors like controller configuration, AP placement, and roaming protocols (e.g., 802.11r).

E

Separate WLANs do not replace the need for VLANs or policy controls; in fact, they often rely on VLANs to segregate traffic and on additional policies (e.g., ACLs, firewall rules) to enforce access restrictions between the WLANs and the network.

When would these options actually be correct?

C

In a question that asks about the benefits of a completely unmanaged wireless environment, where security measures are not a concern, this option could be correct if it implies that security is not needed due to the nature of the network.

D

In a question focused on the benefits of advanced wireless technologies, such as a new protocol that inherently resolves roaming issues, this option could be correct if the context is about a specific feature that eliminates roaming problems.

E

In a question focused on network architecture where the context is about simplifying network management by using WLANs instead of VLANs, option E could be correct. For instance, if the question states that WLANs inherently manage segmentation without additional configurations, this option would apply.

Why candidates pick the wrong answer

C

A student might think that because guests are isolated, security is less critical, but in reality, guest WLANs still need security to prevent eavesdropping and misuse.

D

Students may confuse the concept of separate SSIDs with improved roaming, but roaming issues are related to mobility and network design, not just SSID separation.

E

A test-taker might assume that separate WLANs inherently provide full segmentation, but VLANs and policies are still required for Layer 2/3 separation and granular control.

710
MCQhard

A host address is 192.168.50.158/27. Which address is the network address of its subnet?

A.192.168.50.128
B.192.168.50.159
C.192.168.50.160
D.192.168.50.96
AnswerA

With a /27 prefix, the subnet block size is 32 addresses. The host .158 falls within the range .128–.159, and the network address is always the first address of that block, so it is 192.168.50.128. This is the lowest address that identifies this subnet.

Why this answer

A /27 subnet has a block size of 32. In practical terms, the relevant ranges in the last octet are 0-31, 32-63, 64-95, 96-127, 128-159, and so on. Because 158 falls in the 128-159 block, the network address is 192.168.50.128.

This is a block-identification question. Once you identify the correct /27 block, the network address is the first address in that range.

Exam trap

Ensure you calculate the correct block range for the subnet mask given, not just any multiple of the block size.

Why the other options are wrong

B

192.168.50.159 is the broadcast address for the 192.168.50.128/27 subnet, not the network address. The broadcast address is used to send packets to all hosts in the subnet and cannot be assigned to a host.

C

192.168.50.160 is the network address of the next /27 subnet (160-191), not the subnet containing 158. The /27 mask creates subnets with a block size of 32, so the subnet boundaries are multiples of 32.

D

192.168.50.96 is the network address of the 96-127 /27 subnet, which is an earlier subnet. The address 158 falls in the 128-159 range, not the 96-127 range.

When would these options actually be correct?

B

If the question asked for the last usable host address in the subnet 192.168.50.128/27, then 192.168.50.159 would be the correct answer, as it is the highest address before the broadcast address.

C

In a different question where the subnet mask is /26 and the host address is 192.168.50.158, the network address would be 192.168.50.128, making 192.168.50.160 a valid host address within that subnet.

D

If the question asked for a network address within a different subnet using a /25 mask, such as 192.168.50.96/25, then option D would be correct as it would represent the network address for that subnet.

Why candidates pick the wrong answer

B

Students might confuse the last usable host address (158) with the broadcast address (159) or think that the network address is the highest number in the range.

C

A student might miscalculate the subnet boundaries by using a block size of 32 but starting from 0 incorrectly, or they might think 158 is closer to 160 than to 128.

D

Students might incorrectly calculate the subnet by using a block size of 32 but starting from 96 instead of 128, or they might confuse the subnet mask and think the network address is 96.

711
MCQhard

A device administrator can log in securely over SSH, but the organization still insists on restricting source IP ranges and keeping detailed logs. Which statement best explains that decision?

A.Because secure transport alone does not remove the need for source restriction and accountability controls.
B.Because SSH is less secure than Telnet and must be compensated for.
C.Because logs automatically enforce ACL policy.
D.Because source IP restriction replaces the need for authentication.
AnswerA

Secure transport such as SSH safeguards confidentiality and integrity of the management session, but it does not filter which administrative source addresses are permitted or log which user performed specific configuration changes. Without an SSH access-class or management ACL, any reachable source can attempt a login, and without audit logs or AAA accounting, there is no accountability after the fact. Defense-in-depth therefore requires source restriction and accounting in addition to encryption.

Why this answer

The decision reflects defense in depth. SSH encrypts the session and authenticates users, but it does not limit which source IPs can connect or provide audit trails. Source IP restriction reduces the attack surface by allowing only trusted hosts, and logging provides accountability and forensic evidence.

Option B is incorrect because SSH is more secure than Telnet, not less. Option C is incorrect because logs record events but do not enforce ACLs. Option D is incorrect because source IP restriction complements authentication rather than replacing it.

Exam trap

A frequent exam trap is to believe that using SSH alone fully secures remote device access, leading to the mistaken idea that source IP restrictions and logging are redundant. This overlooks that SSH only encrypts the session and authenticates users but does not limit which hosts can connect or provide audit trails. Ignoring source IP filtering increases exposure to brute-force or credential compromise attacks from unauthorized IPs.

Similarly, neglecting logging removes visibility into who accessed the device and when, hindering incident response. The trap is confusing transport security with comprehensive access control and accountability.

Why the other options are wrong

B

SSH is more secure than Telnet, so this option incorrectly suggests it is less secure and requires compensation.

C

Logs record activity but do not automatically enforce ACL policy; enforcement is a separate function.

D

Source IP restriction limits allowed hosts but does not replace the need for user authentication.

When would these options actually be correct?

B

In a different exam scenario where the question states that SSH is being used in an environment with known vulnerabilities or outdated configurations, the statement could be correct if it emphasized the need for additional security measures due to perceived weaknesses in SSH implementation.

C

If the exam question stated that logging was an active mechanism for enforcing security policies, such as in a scenario where logs trigger automated responses to unauthorized access attempts, then this option could be correct.

D

In a different scenario where the question states that a network is entirely secured through IP whitelisting, and no other authentication methods are in place, then the option could be correct. For example, if the question specifies a legacy system that only allows access based on IP addresses without user credentials, then source IP restriction could be seen as a replacement for authentication.

Why candidates pick the wrong answer

B

A student might confuse the relative security of protocols or think that because additional controls are needed, SSH must be weak. However, the need for layered security does not imply SSH is inferior to Telnet.

C

A test-taker might think that logging can automatically trigger actions (like blocking), but standard logs are passive. Some systems can correlate logs with automated responses, but that is not inherent to logging.

D

A student might think that if only certain IPs are allowed, then anyone from those IPs is trusted, ignoring the need for user-level authentication. This is a common misconception about network access control.

712
PBQmedium

You are connected to the console of R1. The network uses IPv6 with EUI-64. R1's GigabitEthernet0/0 interface has MAC address 0011.2233.4455. You must configure the interface to generate an IPv6 link-local address using the 'ipv6 enable' command, and also assign a global unicast address 2001:db8:1::/64 using EUI-64. The interface is currently administratively down.

Network Topology
G0/0linkR1SW1

Hints

  • •EUI-64 derives the interface ID from the MAC address.
  • •The 'ipv6 enable' command generates a link-local address.
  • •The interface must be administratively brought up.
A.R1(config-if)# ipv6 enable R1(config-if)# ipv6 address 2001:db8:1::/64 eui-64 R1(config-if)# no shutdown
B.R1(config-if)# ipv6 address fe80::/10 eui-64 R1(config-if)# ipv6 address 2001:db8:1::/64 eui-64 R1(config-if)# no shutdown
C.R1(config-if)# ipv6 address 2001:db8:1::/64 eui-64 R1(config-if)# no shutdown
D.R1(config-if)# ipv6 enable R1(config-if)# ipv6 address 2001:db8:1::1/64 R1(config-if)# no shutdown
AnswerA
solution
! R1
interface GigabitEthernet0/0
ipv6 enable
ipv6 address 2001:db8:1::/64 eui-64
no shutdown

Why this answer

The ipv6 enable command explicitly creates a link-local address as required by the scenario. The global unicast address with the eui-64 keyword automatically derives the interface ID from the MAC address. Option B is incorrect because it tries to manually configure a link-local address with eui-64, which is unnecessary and invalid.

Option C omits the ipv6 enable command, failing the explicit requirement. Option D assigns a static host portion instead of using eui-64.

Exam trap

When the question specifically mandates the ipv6 enable command for link-local generation, do not omit it; simply configuring a global unicast address will also create a link-local address, but it does not meet the stated objective.

Why the other options are wrong

B

Manually configuring a link-local address with the eui-64 keyword is invalid; link-local addresses are automatically generated.

C

This option does not include the required ipv6 enable command, so it does not satisfy the explicit scenario requirement.

D

Uses a static host address (::1/64) instead of the eui-64 keyword, so the interface ID will not be generated from the MAC address.

Why candidates pick the wrong answer

B

Candidates might think they need to explicitly configure the link-local address with EUI-64, similar to the global unicast address.

C

Candidates might assume that configuring a global unicast address automatically enables IPv6 and generates a link-local address, but that is not the case.

D

Candidates might think that manually specifying the interface ID is acceptable, but the question explicitly requires EUI-64.

713
Multi-Selectmedium

Which two statements accurately describe DNS and DHCP?

Select 2 answers
A.DNS resolves names to IP information, while DHCP dynamically assigns addressing information to clients.
B.DHCP is used primarily to translate private addresses into public addresses.
C.DNS can help users reach services by hostname instead of remembering numeric IP addresses.
D.DHCP replaces the need for subnet masks and default gateways.
E.DNS and DHCP are both Layer 1 technologies.
AnswersA, C

DNS is an application-layer protocol that translates human-friendly domain names into the numeric IP addresses used for routing and identifying hosts. DHCP, on the other hand, is a network management protocol that dynamically allocates IP addresses and other network parameters such as subnet mask, default gateway, and DNS server addresses to clients when they join a network. Thus, DNS resolves names to IPs, while DHCP automates the assignment of addressing information, fulfilling two distinct but complementary roles in network connectivity.

Why this answer

DNS and DHCP solve very different problems, even though both are common infrastructure services. DNS helps devices and users find systems by name. In simple terms, it means people can type a hostname rather than memorizing numeric IP addresses. DHCP automatically gives clients important IP settings such as an address, subnet mask, default gateway, and often DNS server information.

The trick in comparison questions is not to blend their roles together. DHCP does not perform NAT, and it does not eliminate the need for addressing details; it actually supplies them.

Exam trap

A frequent exam trap is confusing DHCP with NAT or assuming DHCP replaces the need for subnet masks and default gateways. Some candidates mistakenly believe DHCP translates private IP addresses to public ones, but this is the role of NAT, not DHCP. Additionally, DHCP does not remove the need for subnet masks or default gateways; instead, it provides these parameters automatically to clients.

Misunderstanding these distinctions can lead to incorrect answers, especially when questions ask about the functions of IP services. Carefully distinguishing DHCP’s role in dynamic addressing from NAT’s role in address translation is essential to avoid this trap.

Why the other options are wrong

B

DHCP does not translate private addresses to public; that is the function of NAT.

D

DHCP does not replace the need for subnet masks and default gateways; it actually provides them automatically.

E

DNS and DHCP operate at the Application Layer (Layer 7), not Layer 1.

When would these options actually be correct?

B

If the exam question asked about protocols that manage address translation in a network, specifically focusing on how private IP addresses are converted to public addresses for internet access, then this option would be correct in that context.

D

In a question that asks about technologies that eliminate the need for traditional network configuration methods, such as static IP addressing, this option could be correct if it implies that DHCP automates configuration, thus reducing manual entry of subnet masks and gateways.

E

In a question that asks which technologies operate at Layer 1, if the context is expanded to include only Layer 1 devices or protocols, one might mistakenly categorize DHCP and DNS as Layer 1 technologies due to their reliance on physical network infrastructure for communication.

Why candidates pick the wrong answer

B

Students may confuse DHCP with NAT because both involve IP address management and are often used together in networks. The term 'translate' might be loosely associated with DHCP's role in assigning addresses, leading to this misconception.

D

Because DHCP automates the assignment of these parameters, some may incorrectly think it eliminates the need for them altogether. However, the parameters are still essential for network communication; DHCP just delivers them dynamically.

E

Students might mistakenly think that because DNS and DHCP are fundamental network services, they belong to lower layers. Additionally, the term 'Layer 1' might be confused with 'Layer 2' or 'Layer 3' due to incomplete understanding of the OSI model.

714
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure and verify HSRP with priority and preemption on an interface.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
6Step 6

Why this order

First, enter interface configuration mode to start configuring the specific interface. Next, assign an IP address because HSRP requires a real IP on the interface for communication between HSRP routers. After that, define the HSRP group and virtual IP, which clients use as their default gateway.

Then set a higher priority to influence the active router election; priority must be configured before enabling preemption, as preemption relies on priority to determine when to take over. Finally, exit configuration mode and verify with show standby to confirm the HSRP state.

715
MCQhard

An administrator connects a new access-layer switch to a distribution switch. The link comes up but remains in a blocking state and does not forward frames. The administrator issues the show command shown in the exhibit. What is the most likely reason the link is blocked?

A.BPDU Guard is enabled on the port, and the new switch's BPDUs caused the port to enter err-disable state.
B.Loop Guard is enabled, and the port has stopped receiving BPDUs, leading to a loop-inconsistent state.
C.Root Guard is configured on the port, and the new access switch is sending superior BPDUs, triggering a root-inconsistent state.
D.The port is configured with PortFast, and the new switch's BPDU triggered a loop, causing the port to err-disable.
AnswerC

Root Guard is the mechanism that enforces the root bridge position by transitioning a port to the 'root-inconsistent' state when a superior BPDU (lower bridge ID) arrives, effectively blocking the port. Because the new access switch is sending superior BPDUs, the port has been placed in a blocked state to prevent it from becoming the root port and usurping the root bridge. The 'show spanning-tree inconsistentports' output confirms this condition, and the port will automatically recover once the superior BPDUs cease, which is consistent with the exhibit.

Why this answer

The link is blocked because Root Guard is configured on the distribution switch port. When the new access-layer switch sends superior BPDUs (with a lower bridge priority), Root Guard transitions the port to a root-inconsistent (blocking) state to protect the current root bridge from being usurped. This prevents the new switch from becoming the root bridge, which would disrupt the spanning-tree topology.

Exam trap

Cisco often tests the distinction between err-disable states (BPDU Guard) and blocking states (Root Guard, Loop Guard), so the trap here is assuming any BPDU-related protection causes err-disable, when Root Guard specifically causes a blocking state without err-disable.

Why the other options are wrong

A

BPDU Guard results in err-disable, which is not reflected in the show spanning-tree inconsistentports output. The exhibit clearly shows Root Inconsistent, indicating Root Guard, not BPDU Guard.

B

Loop Guard creates a loop-inconsistent listing, not root-inconsistent. The command output explicitly indicates Root Inconsistent, ruling out Loop Guard.

D

Without BPDU Guard, PortFast does not react to BPDUs with a blocking state. The exhibit's root-inconsistent inconsistency is specific to Root Guard, not PortFast or BPDU Guard.

716
MCQhard

A router has routes to 192.168.0.0/16 and 192.168.50.0/24. Which route is used for traffic to 192.168.50.99?

A.192.168.0.0/16
B.192.168.50.0/24
C.The default route
D.Both routes equally
AnswerB

Longest-prefix match governs route selection: the /24 covers 192.168.50.99 with a 24-bit mask, while the /16 covers it with only 16 bits. Cisco IOS always prefers the more specific prefix, so traffic to 192.168.50.99 is forwarded via 192.168.50.0/24 regardless of administrative distance or metric.

Why this answer

The 192.168.50.0/24 route is used because it is more specific. In practical terms, even though the /16 also matches, the router always prefers the route that describes the destination more narrowly. Since 192.168.50.99 falls inside the /24, longest-prefix match chooses that entry.

This is a basic but essential routing rule. The broader /16 still matters for other destinations in 192.168.0.0/16, but not for this one.

Exam trap

Remember that routers prefer the most specific route, not the broadest. Always look for the longest prefix match.

Why the other options are wrong

A

The route 192.168.0.0/16 is less specific (larger subnet) than the matching /24 route. In longest prefix match routing, the more specific route (192.168.50.0/24) is always preferred for the destination 192.168.50.99.

C

A default route (0.0.0.0/0) is only used when no more specific route matches the destination. Since both 192.168.0.0/16 and 192.168.50.0/24 match 192.168.50.99, the default route is not considered.

D

Routers do not load balance between routes of different prefix lengths for the same destination. The longest prefix match rule selects a single best route. Both routes are not used equally; the /24 route is chosen.

When would these options actually be correct?

A

In a different scenario where the router has only the route 192.168.0.0/16 and no more specific routes for 192.168.50.0/24, traffic to 192.168.50.99 would use the 192.168.0.0/16 route, making this option correct.

C

In a scenario where the router only has a default route configured and no specific routes for the 192.168.50.0/24 network, a question asking which route would be used for traffic to 192.168.50.99 would correctly identify the default route as the answer.

D

In a different scenario, if the question stated that both routes had equal administrative distances and were configured in a way that allowed for load balancing, then both routes could be used simultaneously for traffic to 192.168.50.99, making this option correct.

Why candidates pick the wrong answer

A

Students may think that because 192.168.50.99 falls within the 192.168.0.0/16 range, this route would be used. However, they overlook the principle of longest prefix match, which prioritizes the route with the longer subnet mask.

C

Students might think that if a default route exists, it could be used as a catch-all. However, the default route has the lowest priority and is only used when no other matching route exists.

D

Students may confuse this with equal-cost multipath (ECMP) where multiple routes with the same prefix length and metric are used. Here, the prefix lengths differ, so ECMP does not apply.

717
MCQmedium

After a switch replacement, users in VLAN 30 cannot reach devices in other VLANs. The replacement switch has a trunk link to the distribution switch that shows as up/up. What is the most likely cause?

A.The native VLAN must be changed to 30
B.VLAN 30 is not permitted on the trunk link
C.The uplink should be configured as an access port
D.STP must be disabled on VLAN 30
AnswerB

The trunk allowed list controls which VLANs traverse the link, and without an explicit 'allowed vlan add 30' statement, frames belonging to VLAN 30 are discarded at the trunk. Because the access switch and distribution switch only carry permitted VLANs, VLAN 30 has no path to the rest of the network. This exactly matches the symptom that only VLAN 30 suffers while other VLANs work normally on the same uplink.

Why this answer

The trunk is up, but VLAN 30 is not allowed on it. Traffic from that VLAN never crosses the uplink, so inter-VLAN reachability fails for users in VLAN 30 even though the local access ports may still look fine.

Exam trap

Ensure you distinguish between management settings and VLAN configuration. Focus on trunk settings when inter-VLAN issues arise.

Why the other options are wrong

A

Changing the native VLAN to 30 would not resolve the issue because the native VLAN is used for untagged traffic on a trunk, and the problem is that VLAN 30 traffic is not being allowed at all. Additionally, native VLAN mismatch can cause connectivity issues, but it does not specifically prevent only VLAN 30 from reaching other VLANs.

C

Configuring the uplink as an access port would place it in a single VLAN, preventing traffic from multiple VLANs (including VLAN 30) from traversing the link. Since the switch needs to carry traffic for multiple VLANs, the uplink must remain a trunk port.

D

Disabling STP on VLAN 30 would be dangerous as it could cause bridging loops and network instability. Moreover, STP does not control whether a VLAN is allowed on a trunk; it only prevents loops. The issue is a missing VLAN in the trunk allowed list, not a spanning-tree problem.

When would these options actually be correct?

A

In a different scenario where a network administrator is troubleshooting a switch that has been configured with a native VLAN of 30, and the requirement is to ensure that untagged traffic is handled correctly, changing the native VLAN to 30 would be appropriate if the design specifies that all untagged traffic should belong to VLAN 30.

C

In a different question context where the prompt indicates that a switch port must connect to a single VLAN and no inter-VLAN routing is required, stating that the uplink should be configured as an access port would be correct. For example, if the question specifies that all devices on the same VLAN need to communicate without routing, this option would be valid.

D

In a scenario where a question states that VLAN 30 is experiencing broadcast storms or loops, and the exam asks for a method to stabilize the network, disabling STP on VLAN 30 could be considered correct to allow for immediate traffic flow, assuming there are no other VLANs affected.

Why candidates pick the wrong answer

A

Students might confuse native VLAN with the VLAN that is allowed on the trunk, or think that setting the native VLAN to 30 would automatically permit VLAN 30 traffic.

C

Students might think that using an access port simplifies configuration, but they overlook the need to carry multiple VLANs between switches.

D

Students might associate STP with VLAN issues because STP operates per VLAN, but they incorrectly assume that disabling STP can fix connectivity problems caused by trunk misconfiguration.

718
MCQhard

Based on the exhibit, which configuration should be added to restore DHCP service for clients in VLAN 30?

A.ip helper-address 10.99.99.20 under interface Vlan30
B.switchport mode trunk under interface Vlan30
C.ip default-gateway 10.99.99.20 under interface Vlan30
D.spanning-tree portfast under interface Vlan30
AnswerA

The VLAN 30 SVI is the Layer 3 gateway for that subnet, so DHCP client broadcasts must be relayed as unicast to the server at 10.99.99.20. The ip helper-address command enables this relay function and is correctly placed on the SVI that receives the clients' requests. Without it, the broadcast would be dropped by the router.

Why this answer

The correct fix is to add an IP helper address pointing to the remote DHCP server on the Layer 3 interface for VLAN 30. In practical terms, the clients are sending DHCP discovery as a broadcast, and the server is on another subnet. The SVI for VLAN 30 is the local gateway that must relay those requests toward the server.

This is one of the most exam-realistic campus troubleshooting scenarios because it tests both subnet boundaries and the role of the local gateway interface.

Exam trap

A common exam trap is confusing the ip helper-address command with ip default-gateway or Layer 2 commands like switchport mode trunk. Candidates might incorrectly apply switchport commands to an SVI, which is a Layer 3 interface, or think setting ip default-gateway will relay DHCP requests. These mistakes cause DHCP broadcasts to fail reaching the remote server, leading to no IP address assignment for clients.

Understanding that ip helper-address is the DHCP relay mechanism on Layer 3 interfaces is critical to avoid this trap.

Why the other options are wrong

B

Incorrect. The command switchport mode trunk is a Layer 2 switchport configuration and cannot be applied to an SVI, which is a Layer 3 interface. This does not affect DHCP relay.

C

Incorrect. The ip default-gateway command sets the default gateway for management traffic on a Layer 2 device and does not relay DHCP broadcasts. It does not restore DHCP service for clients.

D

Incorrect. The spanning-tree portfast command is used on physical Layer 2 switchports to speed up port transitions and has no effect on DHCP relay or SVIs.

When would these options actually be correct?

B

In a different scenario where the question asks about configuring a switch port to allow multiple VLANs to pass through, 'switchport mode trunk' would be the correct answer. For example, if the question specified that VLAN 30 needs to communicate with other VLANs via a trunk link, this option would be appropriate.

C

In a scenario where the question asks for configuring a Layer 2 switch to communicate with a router for routing purposes, 'ip default-gateway 10.99.99.20' would be the correct answer if the switch needs to reach the DHCP server for clients on a different VLAN.

D

In a different scenario where the question asks about optimizing switch port configurations for end devices connected to VLAN 30, 'spanning-tree portfast' would be correct to reduce the time it takes for ports to transition to the forwarding state, improving connectivity for clients.

Why candidates pick the wrong answer

B

Students may confuse SVIs with physical switch ports and think that trunking is needed to carry VLAN 30 traffic, but SVIs are already associated with a VLAN and do not require trunk configuration.

C

The term 'default-gateway' might be associated with routing, and a student might think it helps forward DHCP requests, but it does not perform DHCP relay.

D

PortFast is a common feature that students learn, and they might incorrectly assume it helps with DHCP by reducing delays, but it does not address the need to forward DHCP broadcasts across subnets.

719
MCQhard

Refer to the exhibit. A network administrator is troubleshooting why not all OSPF neighbors are fully adjacent on a multi-access broadcast segment. After issuing the show ip ospf neighbor command on R1, the output is displayed. What is the most likely cause of the 2WAY/DROTHER state for neighbor 172.16.1.1?

A.The neighbor is a DROther and a full adjacency with another DROther is not required; adjacency is formed only with the DR and BDR.
B.The OSPF hello and dead timers are mismatched between R1 and neighbor 172.16.1.1.
C.The network type is configured as point-to-point on one side and broadcast on the other, causing a DR/BDR election failure.
D.The neighbor's router ID 172.16.1.1 is not reachable, preventing the completion of the adjacency process.
AnswerA

The exhibit shows neighbor 172.16.1.1 in state 2WAY/DROTHER. In a broadcast multi-access OSPF network, DROthers exchange hellos and reach 2-Way state with each other but stop at that stage, establishing full adjacency only with the DR and BDR. This is standard OSPF behavior and the most likely reason for the state.

Why this answer

In a multi-access broadcast OSPF network, only the Designated Router (DR) and Backup Designated Router (BDR) form full adjacencies with all other routers. DROthers (routers that are neither DR nor BDR) only form full adjacencies with the DR and BDR, and remain in the 2WAY state with other DROthers. The show ip ospf neighbor output on R1 shows neighbor 172.16.1.1 as 2WAY/DROTHER, which is normal behavior because both are DROthers and do not need to exchange LSAs directly.

Exam trap

Cisco often tests the misconception that any neighbor state other than FULL is a problem, but here the trap is that 2WAY/DROTHER is actually expected behavior for non-DR/BDR routers on a broadcast segment, and candidates may incorrectly assume a timer mismatch or reachability issue.

Why the other options are wrong

B

Candidates mistakenly think any non-FULL state implies a timer mismatch, overlooking that timer issues prevent even reaching 2WAY.

C

Some candidates assume any DR/BDR-related issue indicates a network type mismatch, but the exhibit clearly shows successful DR/BDR formation, ruling out this option.

D

Candidates may confuse LSA reachability with neighbor adjacency requirements. The 2WAY state proves basic connectivity is intact.

720
MCQmedium

A switch administrator enters the following commands on interface GigabitEthernet1/0/10: interface g1/0/10 switchport mode access switchport access vlan 30 spanning-tree portfast spanning-tree bpduguard enable A user connects a small managed switch to this port, and the access port immediately changes to an err-disabled state. Which feature caused the port to shut down?

A.PortFast
B.BPDU Guard
C.Access VLAN 30 assignment
D.The interface being in access mode
AnswerB

Correct. BPDU Guard is correct because it is specifically designed to shut down an edge port that should not receive BPDUs. In plain terms, the switch sees evidence that another switch was attached and decides to protect the topology by disabling the port instead of allowing a possible loop or unexpected spanning-tree participation.

Why this answer

BPDU Guard is the feature that caused the shutdown. This question is really about separating two features that are often configured together on user-facing ports: PortFast and BPDU Guard. PortFast helps an edge port come up quickly, which is useful for PCs and phones.

BPDU Guard adds protection by watching for BPDUs on that same port. If a switch is connected where only an end device should exist, the newly connected switch may send BPDUs. The local switch interprets that as a topology risk and disables the port to protect the Layer 2 network.

The clues are the err-disabled state and the fact that another switch was connected. VLAN assignment and access mode are normal here and do not explain the shutdown.

Exam trap

Remember that BPDU Guard, not PortFast, causes a port to shut down when BPDUs are received. PortFast only affects port transition speed.

Why the other options are wrong

A

PortFast is a feature that allows a port to transition immediately to the forwarding state, bypassing the usual spanning-tree listening and learning phases. It does not cause a port to shut down or enter an err-disabled state; it only speeds up convergence for end-user devices.

C

Assigning an access VLAN (VLAN 30) simply places the port into a specific broadcast domain for user traffic. It has no mechanism to detect or react to BPDUs, and it does not cause a port to enter an err-disabled state. The port would remain operational regardless of the VLAN assignment.

D

Configuring a port as an access port is a standard practice for connecting end devices. It does not inherently cause any shutdown or err-disabled condition. The port remains up and forwarding traffic unless another feature, such as BPDU Guard, triggers a protective action.

When would these options actually be correct?

A

In a different scenario, if the question asked about a port configured for PortFast that is connected to a device that sends BPDUs, the port could go into an err-disabled state due to BPDU Guard being enabled. In this case, PortFast would be the correct answer if the focus was on the immediate transition to forwarding.

C

In a different scenario, if the question asked about a switch port configured to allow only specific VLANs and a device that sends traffic on a VLAN not permitted on that port is connected, the Access VLAN assignment could lead to issues. In such a case, the port might be disabled due to VLAN mismatches or misconfigurations.

D

In a different scenario where an exam question asks about the effects of configuring a switch port in access mode with specific VLAN assignments and other settings, a candidate might be asked to identify the potential issues caused by misconfigurations that could lead to err-disabled states. In such a case, if the question specified that the access mode was incorrectly configured for a trunking scenario, this option could be correct.

Why candidates pick the wrong answer

A

Students often confuse PortFast with BPDU Guard because they are commonly configured together on edge ports. Since PortFast is involved in the scenario, it is tempting to think it is responsible for the shutdown, but the actual disabling action is performed by BPDU Guard.

C

A test-taker might think that the VLAN assignment could cause a conflict or misconfiguration leading to a shutdown, but VLAN assignment alone does not trigger any protective action. The confusion may arise from scenarios where VLAN mismatches cause issues, but those do not result in err-disabled state.

D

Some students may think that access mode is restrictive and could cause issues when connecting a switch, but access mode simply disables trunking. The actual cause of the shutdown is the reception of a BPDU, which is detected by BPDU Guard, not by the access mode configuration.

721
MCQhard

A network engineer configures a static route: ip route 192.168.10.0 255.255.255.0 10.1.1.2. The next hop 10.1.1.2 is reachable via OSPF. Later, the engineer notices that the route to 192.168.10.0/24 has disappeared from the routing table. What is the most likely cause?

A.The OSPF route to 10.1.1.0/30 has been lost, making the next-hop address 10.1.1.2 unresolvable.
B.The static route has a higher administrative distance than OSPF, so OSPF's route to 192.168.10.0/24 replaced it.
C.The static route uses a next-hop IP address that is not directly connected, which is unsupported on this platform.
D.A routing loop caused by recursive lookups has suppressed the static route to prevent loops.
AnswerA

A recursive static route requires a next-hop that is resolvable via an existing route. Without the OSPF route to the subnet containing 10.1.1.2, the router cannot reach the next hop and removes the static route from the routing table.

Why this answer

The static route to 192.168.10.0/24 uses 10.1.1.2 as the next-hop address. For a static route with a next-hop IP (rather than an exit interface) to be installed in the routing table, the next-hop must be reachable via a valid route in the routing table. If the OSPF route to the subnet containing 10.1.1.2 (e.g., 10.1.1.0/30) is lost, the next-hop becomes unreachable, and the static route is removed from the routing table.

This is the most likely cause of the route disappearing.

Exam trap

Cisco often tests the concept that a static route with a next-hop IP requires a valid route to that IP in the routing table, and candidates mistakenly think the static route will always remain or that administrative distance is the cause of its removal.

Why the other options are wrong

B

Believing that a static route is removed from the routing table when a better route exists, rather than understanding it remains but is inactive.

C

Assuming that a static route's next-hop must be directly attached, ignoring that recursive routing via another routing protocol or static route is allowed.

D

Thinking that recursive static routes are prone to loop suppression, rather than understanding that the route is simply withdrawn when the next-hop is no longer reachable.

722
Multi-Selectmedium

Which two statements accurately describe the value of named administrative accounts?

Select 2 answers
A.They improve accountability by tying actions to specific individuals.
B.They improve traceability during audits or incident reviews.
C.They replace the need for authorization controls.
D.They can be used only with Telnet and not SSH.
E.They exist only for wireless guest administration.
AnswersA, B

Named accounts (like AAA with local or RADIUS/TACACS+) bind authenticated users to a unique identity, so every command or configuration change can be logged with the responsible person's username. This is the basis for accountability: when multiple admins share a generic credential, you cannot determine who executed a specific action, but named accounts unambiguously assign responsibility. This deterrence and forensic attribution is a core driver for using AAA rather than shared passwords.

Why this answer

Named administrative accounts are valuable because they tie actions to individual identities and make access review more meaningful. In practical terms, when multiple people share one generic admin account, accountability becomes weaker. Named identities improve traceability and support auditing, investigations, and operational review.

This is a core secure-administration concept and a good reasoning item rather than just a memorization exercise.

Exam trap

Beware of confusing named accounts with other security measures like password policies or role-based access control.

Why the other options are wrong

C

Named accounts provide identification and authentication, but authorization (what actions an account can perform) is a separate control typically enforced via privilege levels, role-based access control (RBAC), or command authorization (e.g., using TACACS+). Replacing authorization with identity alone would violate the principle of least privilege.

D

Named accounts are protocol-agnostic and work with any management protocol, including SSH, HTTPS, and SNMPv3. Telnet is insecure and rarely used in modern networks; named accounts are actually more important with secure protocols to maintain accountability without compromising security.

E

Named administrative accounts are used across all network device administration, including routers, switches, firewalls, and wireless controllers. Wireless guest administration typically uses separate guest accounts or captive portal authentication, not administrative accounts.

When would these options actually be correct?

C

In a scenario where a question asks if named administrative accounts can function independently without any authorization mechanisms, option C could be correct if it specifies that named accounts can be used in a context where no other access controls are enforced, such as in a poorly configured legacy system.

D

In a question that specifically asks about the limitations of administrative account usage in legacy systems or protocols, stating that named administrative accounts are only applicable to Telnet could be correct if the context is focused on outdated practices where SSH was not implemented.

E

If the exam question specifically asked about the purpose of administrative accounts in the context of managing wireless guest access, then this option could be correct. For example, a question could state, 'What is a primary function of named administrative accounts in wireless guest networks?'

Why candidates pick the wrong answer

C

Students may confuse authentication (who you are) with authorization (what you can do), thinking that a named account inherently defines permissions. In reality, authorization must be explicitly configured, often through AAA or local privilege levels.

D

A test-taker might associate named accounts with older protocols like Telnet because both are commonly discussed in the context of legacy network management. However, named accounts are a best practice regardless of protocol, and SSH is the standard for secure remote access.

E

The phrase 'guest administration' might lead a student to think of guest wireless networks, but administrative accounts are for managing the network infrastructure itself, not for guest access. The term 'administration' here refers to device management, not user services.

723
MCQhard

Refer to the exhibit. A network engineer is troubleshooting a connectivity issue on R1. The serial link to R2 on interface Serial0/1 is using HDLC encapsulation, and the physical cable has been verified as good. The engineer has confirmed that the encapsulation type matches on both routers and that the clock rate is correctly configured on the DCE end. Based on the output, what is the most likely cause of the line protocol down state on Serial0/1?

A.The encapsulation type is mismatched between R1 and R2.
B.The clock rate has not been configured on the DCE end of the serial link.
C.The IP address configured on Serial0/1 conflicts with another interface.
D.The keepalive packets are not being received, causing the protocol to stay down.
AnswerD

In HDLC serial links, routers exchange keepalive messages every 10 seconds by default, and the line protocol is declared down when successive keepalives are not received from the far end. Even though the physical layer is up (represented by the 'up' in 'Serial0/1 is up'), the protocol remains down because the local router has lost contact with the remote router at the data link layer. With encapsulation and clocking verified as correct, the most consistent cause is that keepalive packets are not being received, preventing the line protocol from transitioning to 'up'.

Why this answer

The output shows that the line protocol is down while the physical layer (Serial0/1 is up). With HDLC encapsulation and clock rate confirmed correct, the most likely cause is that keepalive packets are not being exchanged between R1 and R2. HDLC uses keepalives to maintain the data link layer; if they are not received (e.g., due to a misconfiguration like 'no keepalive' on one side or a faulty cable), the protocol state will remain down even though the physical layer is operational.

Exam trap

Cisco often tests the distinction between physical layer (line is up) and data link layer (protocol is down), leading candidates to incorrectly blame encapsulation or clock rate when the real issue is keepalive failure.

Why the other options are wrong

A

Candidates might fixate on the up/down status and assume encapsulation mismatch without considering the explicitly stated troubleshooting steps.

B

Students often associate up/down with missing clock rate, but the question precludes this by confirming correct configuration.

C

Some learners confuse Layer 3 problems (IP issues) with the line protocol status that reflects Layer 2 health.

724
MCQmedium

A router advertises its LAN network into OSPF, but no OSPF Hellos should be sent toward end-user devices on that LAN. Which configuration approach solves this cleanly?

A.Use ip ospf cost 65535 on the LAN interface
B.Configure the LAN interface as a passive interface in OSPF
C.Disable OSPF globally and redistribute connected routes
D.Convert the LAN interface to a loopback
AnswerB

The `passive-interface` command under the OSPF process tells OSPF to stop transmitting Hello packets on that interface while still injecting the interface's subnet as an OSPF route. This preserves full route reachability into the LAN without forming neighbor adjacencies, cutting unnecessary protocol overhead. It is the standard, purpose-built mechanism for LAN-facing OSPF interfaces.

Why this answer

A passive interface advertises the connected subnet into OSPF without sending or processing Hellos on that interface. That is exactly what you want for user-facing LANs with no OSPF neighbors.

Exam trap

A frequent exam trap is selecting the option to increase the OSPF cost on the LAN interface to prevent Hello packets. While adjusting the cost changes the metric used for route selection, it does not stop the router from sending or receiving OSPF Hellos. Another common mistake is to disable OSPF globally and redistribute connected routes, which is unnecessarily complex and does not address the problem of suppressing Hellos on a specific interface.

Additionally, converting the LAN interface to a loopback is irrelevant because loopbacks are logical interfaces used for router IDs and testing, not for controlling OSPF Hello behavior on physical LAN interfaces.

Why the other options are wrong

A

Using 'ip ospf cost 65535' on the LAN interface only changes the OSPF metric for that interface. It does not prevent the router from sending or receiving OSPF Hello packets, so neighbor adjacencies can still form, which is not the desired behavior.

C

Disabling OSPF globally and redistributing connected routes is an overly complex and unnecessary approach. It does not selectively stop Hello packets on the LAN interface and can introduce routing complexity and instability.

D

Converting the LAN interface to a loopback interface changes the interface type entirely and is not a standard or practical solution for suppressing OSPF Hellos on a LAN. Loopbacks are logical interfaces used for router IDs and testing, not for controlling OSPF Hello behavior.

When would these options actually be correct?

A

In a scenario where the question asks for a method to influence OSPF path selection without needing to suppress Hello packets, setting the OSPF cost to 65535 could be correct. For example, if the question specifies that the goal is to manipulate OSPF metrics for routing decisions without affecting neighbor relationships.

C

If a question asked how to completely eliminate OSPF from a router while still allowing connected routes to be advertised through another routing protocol, then disabling OSPF globally would be the correct approach.

D

If the question asked for a method to isolate OSPF routing from a specific segment of the network while still allowing the interface to function normally for other purposes, converting the LAN interface to a loopback could be a valid solution, as loopbacks are often used for management or routing purposes without direct user connectivity.

Why candidates pick the wrong answer

A

Students might think that setting a very high cost could effectively suppress OSPF operations on the interface, but cost only affects route selection, not protocol behavior like Hello transmission.

C

A test-taker might consider this option because redistribution can advertise routes without running OSPF on the interface, but they overlook that disabling OSPF globally affects all interfaces and requires additional configuration to re-advertise routes.

D

Students might confuse the passive-interface concept with loopback interfaces, thinking that loopbacks do not send Hellos (which is true), but this approach is impractical and alters the network design unnecessarily.

725
Matchingmedium

Match each route source or route type to its most accurate description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Present because the network is directly attached

Manually configured route

Learned dynamically through the routing protocol

Backup static route with higher administrative distance

Why these pairings

Connected routes are automatically installed when an interface is configured with an IP address and is in the up/up state. Static routes are manually configured by an administrator to specify a fixed path. OSPF is a link-state routing protocol that uses cost as its metric and maintains a complete topology database.

EIGRP is a hybrid protocol that uses bandwidth and delay as metrics and supports unequal-cost load balancing.

Exam trap

The exam often tests the automatic nature of connected routes. Do not confuse them with static or dynamic routes. Remember that connected routes appear only when the interface is up/up.

726
MCQmedium

You are configuring a Cisco switch port in a lobby area where only one device should ever connect. You want the port to learn the first MAC address it sees, and if a different MAC address appears later, you want the port to drop frames from the new address while still allowing the original device to communicate. Which port-security violation mode meets this requirement?

A.protect
B.shutdown
C.restrict
D.err-disable
AnswerA

Protect mode drops frames from any MAC address that exceeds the maximum count but never generates a log or syslog message and never shuts the port down. The already-authorized MAC address continues to communicate normally, which matches the requirement of silently discarding traffic from the unexpected new device.

Why this answer

Port security protect mode silently discards frames from any MAC address beyond the configured maximum and never logs or disables the port. This preserves connectivity for the first learned, authorized device while blocking the unexpected address, which is exactly the lobby scenario where only one device should be permitted.

Exam trap

The trap here is confusing the quiet protect mode with restrict mode, which behaves identically except that it logs violations and increments counters.

727
MCQmedium

Which OSPF network type on Ethernet performs a DR and BDR election by default?

A.Point-to-point
B.Broadcast
C.Point-to-multipoint nonbroadcast
D.Loopback
AnswerB

On Ethernet segments, OSPF automatically defaults to the broadcast network type. This type relies on multicast hello packets to 224.0.0.5 and elects a Designated Router (DR) and Backup Designated Router (BDR) to minimize the number of adjacencies and reduce LSA flooding on the multi-access link. Therefore, broadcast is the correct network type where DR/BDR election occurs.

Why this answer

Broadcast multiaccess networks such as Ethernet elect a DR and BDR by default.

Exam trap

A frequent exam trap is selecting point-to-point or point-to-multipoint nonbroadcast as the network type that performs DR/BDR elections. Candidates often assume any multi-router link requires DR/BDR, but OSPF only elects DR/BDR on broadcast and NBMA networks. Point-to-point links connect exactly two routers and do not need DR/BDR, while point-to-multipoint nonbroadcast requires manual neighbor configuration and does not elect DR/BDR by default.

Misunderstanding these distinctions leads to incorrect answers. Remember, Ethernet interfaces default to broadcast network type, which triggers DR/BDR elections automatically.

Why the other options are wrong

A

Point-to-point links connect only two routers directly and do not require or perform DR/BDR elections because there is no need to reduce flooding on a single link. Selecting this option is incorrect for Ethernet interfaces that default to broadcast.

C

Point-to-multipoint nonbroadcast network type requires manual neighbor configuration and does not perform DR/BDR elections by default. This does not match the default behavior of Ethernet interfaces.

D

Loopback interfaces are virtual interfaces used for router identification and do not participate in OSPF DR/BDR elections because they are not multiaccess networks.

When would these options actually be correct?

A

If the question were to ask about OSPF network types that do not require DR and BDR elections, such as in a scenario involving a direct link between two routers, then 'Point-to-point' would be the correct answer.

C

If the exam question asked which OSPF network type supports multiple connections to a central point without requiring a broadcast medium, or if it focused on scenarios involving non-broadcast multi-access (NBMA) networks, then point-to-multipoint nonbroadcast would be the correct answer.

D

If the question were to ask about the OSPF network type that is used for router identification or for creating a stable OSPF endpoint, then Loopback would be the correct answer. For example, a question could specify the importance of using Loopback interfaces for OSPF router IDs.

Why candidates pick the wrong answer

A

Students may confuse point-to-point with Ethernet because both can be used on point-to-point Ethernet links, but the default OSPF network type on Ethernet is broadcast, which triggers DR/BDR election.

C

The term 'nonbroadcast' might confuse students into thinking it applies to Ethernet when they consider scenarios without multicast, but Ethernet inherently supports broadcast, making this type incorrect.

D

Students might think loopback interfaces participate in OSPF elections because they can be advertised in OSPF, but they are not multi-access and thus do not require DR/BDR.

728
Multi-Selectmedium

Which two statements accurately describe why NetFlow is useful for operations teams?

Select 2 answers
A.It helps identify which conversations or applications contribute to link utilization.
B.It can provide more detail than simple interface counters alone.
C.It replaces the need for all routing protocols.
D.It is the main wireless encryption protocol for guest access.
E.It eliminates the usefulness of Syslog.
AnswersA, B

NetFlow samples or captures packet metadata into flow records that identify source/destination IP, ports, and protocol, allowing engineers to rank traffic by conversation or application. This visibility pinpoints which specific flows (e.g., a video-streaming host or an application server) are responsible for congestion, transforming raw link utilization into actionable per-flow intelligence.

Why this answer

NetFlow is useful because it helps teams move beyond simple interface utilization and see which traffic conversations are responsible for usage. In practical terms, it can reveal which hosts, protocols, or applications are contributing to the traffic profile, making it valuable for troubleshooting, capacity planning, and security investigations. Option E is incorrect because NetFlow does not eliminate the usefulness of Syslog; Syslog provides device event logging while NetFlow provides traffic flow data, and both tools complement each other in network operations.

Exam trap

A frequent exam trap is mistaking NetFlow for a routing protocol, a security mechanism, or a replacement for Syslog.

Why the other options are wrong

C

Option C is incorrect because NetFlow does not replace routing protocols; it is a monitoring technology that provides visibility into traffic flows but does not perform routing functions or influence path selection.

D

Option D is incorrect as NetFlow is unrelated to wireless encryption protocols. Wireless encryption standards like WPA2 or WPA3 handle security, whereas NetFlow focuses on traffic flow monitoring.

E

Option E is incorrect because NetFlow does not eliminate the usefulness of Syslog. Syslog provides event logging and system messages, which complement NetFlow’s traffic flow data for comprehensive network monitoring.

When would these options actually be correct?

C

In a question asking about the benefits of using a comprehensive network monitoring solution that integrates multiple functionalities, including traffic analysis and routing management, this option could be correct if it states that a specific tool replaces the need for traditional routing protocols in a simplified network environment.

D

If the exam question asked about the primary functions of wireless security protocols or the best practices for securing guest access in a wireless network, then this option could be correct. In that context, identifying the main wireless encryption protocol would be relevant.

E

In a question asking about the advantages of using NetFlow over traditional logging methods, one might state that NetFlow eliminates the need for Syslog in certain scenarios, such as when only traffic flow data is required and no event logging is necessary.

Why candidates pick the wrong answer

C

Students might confuse NetFlow with routing protocols because both involve network traffic, but NetFlow is about monitoring existing traffic, not making forwarding decisions. The word 'flow' might be mistakenly associated with routing.

D

The term 'flow' might be confused with 'Wi-Fi' or 'wireless' in some contexts, and students may think NetFlow is related to wireless security because both are network-related. However, NetFlow has no role in encryption.

E

Students might think that since NetFlow provides detailed traffic information, it could replace Syslog for monitoring. However, Syslog captures different data (e.g., interface status changes, authentication failures) that NetFlow cannot provide.

729
MCQhard

An administrator sees high interface utilization through SNMP graphs but wants to identify which conversations are responsible. Which addition best closes that visibility gap?

A.NetFlow
B.Another DHCP scope
C.A new STP priority
D.A larger OSPF metric
AnswerA

NetFlow (and similar flow export technologies) captures metadata for each IP conversation traversing the interface, including source/destination addresses, L4 ports, and byte counts. This allows the administrator to aggregate by host, application, or TCP/UDP port and immediately identify the top talkers driving the interface to high utilization. Unlike SNMP counters that show only aggregate usage, NetFlow correlates the utilization to specific flows.

Why this answer

NetFlow provides conversation-level visibility into which hosts and applications are consuming bandwidth, closing the gap left by SNMP's interface totals. A new DHCP scope assigns IP addresses but offers no traffic insight. An STP priority manages loop-free topology and does not affect monitoring.

A larger OSPF metric influences routing path selection, not traffic analysis.

Exam trap

Avoid assuming all network monitoring tools provide the same level of detail. Understand the specific capabilities of each tool.

Why the other options are wrong

B

A DHCP scope handles address assignment and has no role in traffic conversation visibility.

C

An STP priority manages spanning-tree topology and does not provide bandwidth usage details.

D

A larger OSPF metric affects routing path selection but does not reveal which conversations are using bandwidth.

When would these options actually be correct?

B

In a scenario where the question asks about expanding IP address availability in a network with multiple subnets experiencing address exhaustion, adding another DHCP scope could be the correct answer to ensure devices can obtain IP addresses.

C

In a scenario where the question asks about optimizing network performance by adjusting STP settings to prevent loops or improve redundancy, selecting a new STP priority could be correct. For example, if the question focuses on reducing broadcast storms in a VLAN environment, adjusting STP priority could be the right answer.

D

In a scenario where the question asks about optimizing OSPF routing performance or managing traffic flow in a congested network, increasing the OSPF metric for certain routes could be the correct answer. This would prioritize other routes and potentially alleviate congestion.

Why candidates pick the wrong answer

B

Students might confuse DHCP with network monitoring tools because DHCP is involved in network configuration, but it has no capability to report on traffic conversations.

C

Students might think that STP priority affects traffic paths and thus could help identify conversations, but STP only controls the logical topology for loop prevention, not traffic monitoring.

D

Students might associate OSPF metrics with traffic engineering and assume they can help identify bandwidth hogs, but metrics only influence routing decisions, not monitoring.

730
Multi-Selectmedium

Which TWO statements correctly describe the configuration and verification of EtherChannel with LACP?

Select 2 answers
A.LACP uses the 'active' and 'passive' modes to negotiate an EtherChannel.
B.The 'show etherchannel summary' command displays the channel group number, port-channel interface, member ports, and their status.
C.LACP uses the 'auto' and 'desirable' modes to negotiate an EtherChannel.
D.The 'show etherchannel summary' command shows the LACP system priority for each channel.
E.An EtherChannel can be formed only if all member ports use the same LACP mode.
AnswersA, B

This statement is correct. LACP negotiation relies on two modes: 'active' and 'passive'. An interface in 'active' mode actively sends LACP packets to initiate the link aggregation, while one in 'passive' mode waits for a response and only sends packets after receiving them. For an EtherChannel to form, at least one side must be 'active'; if both sides are 'passive', the channel will not come up because no negotiation is initiated.

Why this answer

LACP (IEEE 802.3ad) uses 'active' and 'passive' modes to negotiate an EtherChannel. Option B is correct because the 'show etherchannel summary' command displays the channel group number, port-channel interface, member ports, and their status flags (e.g., P for in port-channel, S for suspended). Option C is incorrect because 'auto' and 'desirable' are PAgP modes, not LACP modes.

Option D is incorrect because 'show etherchannel summary' does not show LACP system priority; that is displayed with 'show lacp sys-id' or 'show etherchannel detail'. Option E is incorrect because an EtherChannel can be formed with mismatched LACP modes as long as at least one side is 'active'; for example, 'active' + 'passive' works.

Exam trap

Cisco often tests the distinction between LACP modes ('active'/'passive') and PAgP modes ('auto'/'desirable'), and candidates frequently confuse which protocol uses which set of modes.

Why the other options are wrong

C

LACP does not use 'auto' and 'desirable' modes; those are PAgP modes.

D

The 'show etherchannel summary' command does not display LACP system priority; that is shown via 'show lacp sys-id' or 'show etherchannel detail'.

E

An EtherChannel can be formed even if member ports use different LACP modes (e.g., active and passive), as long as at least one side is active.

Why candidates pick the wrong answer

C

Students often confuse LACP and PAgP modes because both protocols are used for link aggregation. Since 'auto' and 'desirable' are well-known PAgP modes, test-takers with partial knowledge may mistakenly associate them with LACP.

D

Test-takers might think that because 'show etherchannel summary' provides a high-level view of EtherChannel, it would include LACP system priority. However, that information is considered detailed and is only available in more specific commands.

E

Students might assume that all ports must use the same mode for consistency, similar to other configuration parameters like speed and duplex. However, LACP is designed to allow mixed modes as long as negotiation is possible.

731
MCQmedium

Why is a default route useful on a small branch router connected to a single upstream provider?

A.It provides a simple next hop for unknown destinations toward the upstream connection.
B.It makes every route more specific.
C.It replaces the need for any interface addressing.
D.It forces all users into one VLAN.
AnswerA

The default route is a catch-all route, typically 0.0.0.0/0 for IPv4, that matches any destination not found in the routing table. On a small branch router, it points to the upstream ISP or WAN gateway, allowing all unknown traffic to be forwarded toward the provider with a single simple next hop. This eliminates the need to manually configure many remote network routes.

Why this answer

A default route is useful because it gives the branch a simple fallback next hop for destinations the router does not know specifically. In practical terms, the branch router does not need a full table of every external destination if all unknown traffic should go upstream. That keeps the design simple and efficient.

This is one of the most practical default-route use cases in small or edge networks.

Exam trap

A frequent exam trap is assuming that a default route makes every route more specific or that it replaces the need for interface addressing. Some candidates mistakenly believe the default route refines routing granularity, but it actually represents the least specific route, catching all unknown destinations. Others incorrectly think default routes eliminate the need for IP addresses on interfaces, which is false because interfaces must always have valid IP configurations for routing to function.

Misunderstanding these points can lead to incorrect answers about routing behavior and network design.

Why the other options are wrong

B

Incorrect because a default route is the least specific route and does not make routes more specific; it serves as a catch-all for unknown destinations.

C

Incorrect because interface addressing is mandatory for routing to function properly; a default route does not replace the need for IP addresses on interfaces.

D

Incorrect because default routes influence packet forwarding decisions and have no impact on VLAN assignments, which are Layer 2 configurations.

When would these options actually be correct?

B

In a scenario where a question asks about route summarization or optimization techniques in a complex network with multiple subnets, stating that a default route can make routes more specific could be correct if discussing how it simplifies routing decisions by summarizing multiple routes into one.

C

In a question about a router configuration where a network is entirely using a point-to-point link with no local subnets, and the question asks if a default route can eliminate the need for interface addressing, this option could be considered correct as the context implies a simplified setup.

D

In a different scenario, a question might ask about network segmentation strategies in a multi-VLAN environment where a network administrator needs to ensure all traffic from users is confined to a specific VLAN for security or management purposes. In that case, the option could be correct if the context involves forcing users into a designated VLAN.

Why candidates pick the wrong answer

B

Students might confuse the default route with route summarization or aggregation, which can make routes more specific by combining them. However, the default route is the opposite—it is the most general route.

C

Some learners might think that a default route can serve as a substitute for proper addressing because it directs all traffic to a single next hop, but addressing is still required for the router to function at Layer 3.

D

Test-takers might associate 'default' with a default VLAN (VLAN 1) or think that a default route somehow forces traffic into a single VLAN, but these are unrelated concepts.

732
MCQhard

A network technician is troubleshooting connectivity between two directly connected Cisco switches. Hosts on VLAN 10 connected to SwitchA cannot ping the default gateway on SwitchB. The interface on SwitchB shows up/up, but the interface on SwitchA shows up/down. The technician examines the interface configuration and status on SwitchA. What is the most likely cause of this issue?

A.Replace the Ethernet cable because it is faulty.
B.Configure both interfaces with the same duplex and speed settings, either both auto or both manually set to full-duplex and 1000 Mbps.
C.Issue the 'shutdown' and 'no shutdown' commands on the interface to recover from err-disabled state.
D.Check the VLAN configuration on SwitchA because the interface is administratively down.
AnswerB

The line protocol being down with up/up on the remote suggests a duplex mismatch, which can occur when one side is manually set and the other is auto-negotiating. Setting both sides consistently resolves the issue.

Why this answer

The interface on SwitchA shows up/down, meaning Layer 1 is active but the line protocol is down. This is commonly caused by a speed mismatch between the two ends. A duplex mismatch, in contrast, typically results in both interfaces showing up/up with CRC errors.

Therefore, the most likely cause is that the speed settings differ—for example, one interface is set to auto-negotiate while the other is hard-coded to a specific speed. Configuring both interfaces with identical speed and duplex settings, either both auto or both manually configured, resolves the issue.

Exam trap

The trap is that up/down is often misinterpreted as a faulty cable or an err-disabled state, but it actually points to a speed mismatch or auto-negotiation failure, not a duplex mismatch.

Why the other options are wrong

A

The interface status shows 'up, line protocol is down', which indicates a Layer 2 issue, not a physical cable fault. Additionally, no CRC, runts, giants, or collisions are reported, so the cable is likely not faulty.

C

The interface status is 'up, line protocol is down', not 'err-disabled'. The err-disabled state would show 'err-disabled' in the interface status, and a shutdown/no shutdown would be appropriate only for err-disabled recovery.

D

The interface status is 'up', not 'administratively down'. An administratively down interface would show 'administratively down, line protocol is down'. VLAN configuration issues typically cause the interface to be up/up but unable to forward traffic, not up/down.

Why candidates pick the wrong answer

A

Students often assume that any connectivity problem is due to a bad cable, especially when the interface is up/down. However, the absence of physical layer errors suggests the cable is fine.

C

Students may confuse the 'up/down' state with an err-disabled state, as both can cause connectivity loss. However, err-disabled is a specific condition triggered by port security or other violations.

D

Students might think VLAN misconfiguration can cause the interface to go down, but VLAN issues usually affect Layer 3 connectivity, not the line protocol state of a trunk or access port.

733
MCQhard

A host is configured as 192.168.50.130/25. Which address is the broadcast address for its subnet?

A.192.168.50.127
B.192.168.50.128
C.192.168.50.255
D.192.168.50.254
AnswerC

With a /25 prefix, the subnet mask is 255.255.255.128, which splits the 192.168.50.0/24 network into two 128-address blocks. The address 192.168.50.130 falls into the upper block, 192.168.50.128/25, which spans .128 through .255. The broadcast address is the last address in that block, .255, where all seven host bits are set to 1.

Why this answer

A /25 divides the /24 into two blocks: 0–127 and 128–255. In plain language, because the host ends in 130, it belongs to the upper half, which starts at 128 and ends at 255. The last address in that block is the broadcast address, so the broadcast is 192.168.50.255.

This is a classic subnetting pattern because it tests whether you can identify not just the subnet, but also the reserved last address in that subnet.

Exam trap

A frequent exam trap is mistaking the network address or a high usable host address for the broadcast address. Candidates often select 192.168.50.128, confusing it as the broadcast because it is the start of the upper subnet, or 192.168.50.254, assuming it is the broadcast since it is near the subnet's end. The trap lies in not recognizing that the broadcast address is always the highest address in the subnet, which in this case is 192.168.50.255.

Misidentifying these addresses leads to incorrect subnet calculations and can cause network communication failures in real scenarios.

Why the other options are wrong

A

192.168.50.127 is the broadcast address for the lower /25 subnet (192.168.50.0/25), not the subnet containing 192.168.50.130. Since the host IP is in the upper subnet, this option is incorrect.

B

192.168.50.128 is the network address of the upper /25 subnet (192.168.50.128/25), not the broadcast address. Network addresses cannot be assigned to hosts or used as broadcast addresses, so this option is incorrect.

D

192.168.50.254 is a valid usable host address within the upper /25 subnet. It is not the broadcast address, so this option is incorrect.

When would these options actually be correct?

A

In a different scenario where the subnet mask is /25 and the network address is 192.168.50.0, the broadcast address for the subnet would be 192.168.50.127. A question could ask for the broadcast address of the subnet 192.168.50.0/25, making this option correct.

B

If the question specified a subnet mask of /25 for the address 192.168.50.128, then option B would be correct as the broadcast address for that subnet would be 192.168.50.255, and the first usable address would be 192.168.50.129.

D

If the question specified a subnet mask of /24 instead of /25, then 192.168.50.254 would be the broadcast address for the subnet 192.168.50.0/24, as it would cover the range from 192.168.50.0 to 192.168.50.255.

Why candidates pick the wrong answer

A

Students often confuse the broadcast address of the lower subnet with that of the upper subnet, especially when the host IP is close to the subnet boundary.

B

Some might think that the first address after the subnet boundary is the broadcast, but it is actually the network address. The broadcast is the last address in the range.

D

Students might assume that the last usable host address (.254) is the broadcast, but the broadcast is actually the very last address (.255) in the subnet.

734
MCQmedium

A network engineer queries a REST API and receives data in JSON format. Which statement about JSON is correct?

A.JSON is a transport protocol that replaces HTTPS
B.JSON stores data as key-value pairs and arrays
C.JSON can be used only with Cisco DNA Center
D.JSON requires XML tags around each object
AnswerB

JSON's syntax is built around two core structures: objects, which are unordered collections of key-value pairs enclosed in curly braces, and arrays, which are ordered lists of values enclosed in square brackets. Each value within an object or array can itself be a string, number, boolean, null, or another nested object or array. This self-describing, hierarchical format is language-independent, making it both human-readable and easily parsed by machines.

Why this answer

JSON is a lightweight data-interchange format that represents data as key-value pairs and arrays. Option A is incorrect because JSON is not a transport protocol; it is a data format exchanged over HTTPS. Option C is incorrect because JSON is platform-agnostic and used by many APIs, not limited to Cisco DNA Center.

Option D is incorrect because JSON uses a flexible syntax with colons and brackets, not XML tags.

Exam trap

Avoid confusing JSON with binary formats or assuming it requires a schema like XML.

Why the other options are wrong

A

JSON is a lightweight data-interchange format, not a transport protocol. HTTPS is a secure version of HTTP used for communication, and JSON does not replace it; instead, JSON data is often transmitted over HTTPS.

C

JSON is a platform-independent data format used by many APIs and services, not just Cisco DNA Center. It is supported by virtually all programming languages and is a standard for web APIs across different vendors.

D

JSON does not use XML tags; it uses a syntax of curly braces, colons, and commas to define objects and arrays. XML uses angle brackets for tags, which is a different markup language.

When would these options actually be correct?

A

If the exam question stated that JSON is a protocol designed to facilitate data transfer over the internet, and it was framed in a context where JSON was being compared to other transport protocols, then option A could be considered correct.

C

If the question were framed to ask about a proprietary API that only supports JSON for data interchange within Cisco DNA Center, then this option could be considered correct in that specific context.

D

If the question were to ask about a data format that requires XML tags for structuring data, such as in a comparison between XML and JSON, then this option would be correct. For example, a question could ask, 'Which format requires tags to define objects?'

Why candidates pick the wrong answer

A

Students might confuse JSON with a protocol because it is commonly used in API communications, leading them to think it is a transport protocol rather than a data format.

C

A student might associate JSON with Cisco DNA Center because it is commonly used in Cisco's REST APIs, but this does not mean it is exclusive to that platform.

D

Students might confuse JSON with XML because both are used for data interchange, but they have distinct syntaxes. The mention of 'tags' is a clear indicator of XML, not JSON.

735
Matchingmedium

Match each REST-style method to the most common intent.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Retrieve information

Create or submit data

Update or replace a resource

Remove a resource

Why these pairings

RESTful methods map to CRUD operations: GET retrieves, POST creates, PUT replaces, PATCH partially updates, DELETE removes, and OPTIONS returns allowed methods.

Exam trap

The exam tests your understanding of the specific intent of each HTTP method. Common traps include confusing GET with POST for creation, or PUT with PATCH for updates. Remember: GET is read-only, POST creates, PUT replaces, PATCH modifies partially.

When would these options actually be correct?

B

If the question asked 'Which HTTP method is used to retrieve a resource?' then 'GET - Retrieve a resource' would be correct. Alternatively, if the question was about a non-standard API that uses GET for creation (which violates REST principles), but this is not typical for the exam.

C

If the question asked 'Which method is used to submit data to create a new resource?', then POST would be correct.

D

In a question asking 'Which HTTP method is used to replace an entire resource?' or 'Which method is idempotent and updates a resource by sending a complete representation?', PUT would be correct.

Why candidates pick the wrong answer

B

Candidates may confuse GET with POST because they know both can send data, or they might think 'GET' can create resources if the server processes query parameters to create something, which is a common misconception.

C

Candidates may confuse POST with GET because both can send data, but they forget that POST is for creation/submission, not retrieval.

D

Candidates may confuse PUT with PATCH, or think 'update' broadly applies to PUT, overlooking the 'partial' distinction.

736
Multi-Selectmedium

Which two statements accurately describe WPA2 and WPA3 in wireless security?

Select 2 answers
A.Both are wireless security standards used to help protect WLAN access and traffic.
B.WPA3 is the newer standard relative to WPA2.
C.Both are names for specific 802.11 radio frequencies.
D.WPA2 and WPA3 are types of trunk ports.
E.WPA3 eliminates the need for SSIDs.
AnswersA, B

WPA2 and WPA3 are security protocols that provide authentication and encryption for wireless LANs. WPA2 relies on AES-CCMP for data confidentiality, while WPA3 uses AES-GCMP (with 128-bit keys) and mandates Protected Management Frames to strengthen integrity. They both secure the communications between a wireless client and an access point, thereby protecting WLAN access and traffic from eavesdropping, tampering, and unauthorized use.

Why this answer

WPA2 and WPA3 are wireless security standards used to protect WLAN access and traffic. In practical terms, both are associated with securing wireless communication, but WPA3 is generally positioned as the newer standard with security improvements over WPA2. The key idea at CCNA level is recognizing them as WLAN security standards rather than confusing them with SSIDs, controllers, or radio bands.

You do not need deep protocol internals here. You need the role and relative positioning right.

Exam trap

Avoid assuming WPA3 is limited to specific frequency bands or that WPA2 offers superior security features.

Why the other options are wrong

C

WPA2 and WPA3 are security protocols, not radio frequencies. 802.11 radio frequencies refer to bands like 2.4 GHz and 5 GHz, which are unrelated to security standards.

D

Trunk ports are a concept in switched networks for carrying multiple VLANs, typically using 802.1Q tagging. WPA2 and WPA3 have nothing to do with switch port configuration.

E

WPA3 does not eliminate the need for SSIDs; SSIDs are still required to identify and differentiate wireless networks. WPA3 focuses on authentication and encryption, not network identification.

When would these options actually be correct?

C

If the exam question asked about the naming conventions of wireless standards and their association with specific frequency bands, then this option could be correct if it referred to a hypothetical scenario where WPA2 and WPA3 were misinterpreted as frequency designations.

D

If the exam question specifically asked about types of network configurations or VLAN implementations, a statement about WPA2 and WPA3 being types of trunk ports could be correct in a hypothetical context where the question mistakenly conflates wireless security with network topology.

E

If the exam question were to ask about a hypothetical future wireless security standard that integrates SSID-less connections, then this option could be correct. For example, a question might state, 'What advancements in wireless security protocols eliminate the need for SSIDs?'

Why candidates pick the wrong answer

C

Students might confuse the '802.11' in Wi-Fi standards with security protocols, or mistakenly think that WPA versions correspond to different frequency bands.

D

The term 'trunk' might be confused with 'wireless' due to similar-sounding terminology, or a student might incorrectly associate security with port types.

E

A student might think that newer security standards remove older concepts like SSIDs, or confuse SSID with security features like pre-shared keys.

737
PBQhard

You are connected to R1. The network uses a router-on-a-stick design with a single switch (SW1) and two VLANs (10 and 20). Currently, hosts in VLAN 10 cannot ping hosts in VLAN 20, and the trunk between R1 and SW1 shows a native VLAN mismatch. Examine the provided configuration and output, then apply the necessary corrections to R1 so that inter-VLAN routing works correctly.

Hints

  • •Check the native VLAN on the trunk — it might not match the switch.
  • •Examine each subinterface's encapsulation — one may have the wrong VLAN ID.
  • •Is IP routing enabled? The router needs to forward between VLANs.
A.Change the native VLAN on R1's trunk interface to 99, correct the encapsulation on G0/0.20 to dot1Q 20, and enable IP routing globally.
B.Change the native VLAN on R1's trunk interface to 99, correct the encapsulation on G0/0.20 to dot1Q 20, but do not enable IP routing because it is enabled by default.
C.Change the native VLAN on R1's trunk interface to 1, correct the encapsulation on G0/0.20 to dot1Q 20, and enable IP routing globally.
D.Change the native VLAN on R1's trunk interface to 99, correct the encapsulation on G0/0.10 to dot1Q 10, and enable IP routing globally.
AnswerA
solution
! R1
interface GigabitEthernet0/0
switchport trunk native vlan 99
exit
interface GigabitEthernet0/0.20
encapsulation dot1Q 20
exit
ip routing

Why this answer

The configuration has three issues: 1) The native VLAN on the trunk is VLAN 1, but the switch expects VLAN 99 (common mismatch scenario). 2) Subinterface G0/0.20 uses encapsulation dot1Q 10 instead of 20, causing VLAN 20 traffic to be mis-tagged. 3) The 'ip routing' command is missing globally, so R1 cannot route between subinterfaces. To fix, configure the main interface G0/0 with 'encapsulation dot1Q 99 native' to set the native VLAN to 99, correct the encapsulation on G0/0.20 to 'dot1Q 20', and enable IP routing with 'ip routing'.

Exam trap

Candidates often forget to enable 'ip routing' globally, assuming it is on by default. They may also overlook the native VLAN mismatch or incorrectly use a Layer 2 switchport command instead of 'encapsulation dot1Q 99 native' on the router interface.

Why the other options are wrong

B

The specific factual error is that IP routing is not enabled by default; it requires the 'ip routing' global command.

C

The specific factual error is that the native VLAN must match on both sides; changing R1's native VLAN to 1 does not match the switch's native VLAN 99.

D

The specific factual error is that the subinterface G0/0.20 is associated with VLAN 20, so its encapsulation must be dot1Q 20, not 10.

Why candidates pick the wrong answer

B

Candidates may assume that a router automatically routes between interfaces, but in Cisco IOS, routing must be enabled globally.

C

Candidates might think that native VLAN 1 is the default and acceptable, but the switch has been configured with native VLAN 99, so R1 must match that.

D

Candidates might confuse the VLAN IDs or think that correcting the native VLAN is sufficient, but the subinterface encapsulation must match the VLAN it serves.

738
PBQhard

You are connected to R1. Configure NTP client so that R1 synchronizes with the NTP server at 198.51.100.10, using its Loopback0 (10.0.0.1/32) as the source interface. Also configure syslog to send messages of severity 5 (notifications) and above to 192.0.2.20. The current configuration shows a misconfigured NTP server address and an incorrect logging trap level. Verify with 'show ntp status' (stratum should not be 16) and 'show logging'.

Hints

  • •Check the NTP server address in running-config — it might point to a wrong IP.
  • •Verify that the source interface for NTP is configured; otherwise R1 may use an unreachable interface.
  • •The logging trap level is set too high (debugging) — change it to notifications (level 5) to filter out lower severity messages.
A.ntp server 198.51.100.10 source Loopback0 logging trap notifications
B.ntp server 198.51.100.10 source Loopback0 logging trap 4
C.ntp server 198.51.100.10 logging trap notifications
D.ntp server 203.0.113.5 source Loopback0 logging trap 7
AnswerA
solution
! R1
configure terminal
no ntp server 203.0.113.5
ntp server 198.51.100.10
ntp source Loopback0
no logging trap debugging
logging trap notifications
end
write memory

Why this answer

The misconfigured NTP server address (203.0.113.5) and the debug-level logging trap (7) must be corrected to meet requirements. The correct commands are 'ntp server 198.51.100.10 source Loopback0' to use the specified server and Loopback0 as source, and 'logging trap notifications' (severity 5) to send only notifications and more severe messages. Option B is wrong because 'logging trap 4' sets the trap level to warning, which would not forward notifications.

Option C misses the source interface, and Option D uses the wrong NTP server and an overly verbose trap level.

Exam trap

Candidates often confuse the numeric severity levels with the keyword equivalents for logging trap. Also, they may forget to specify the source interface for NTP, assuming the router will use the loopback automatically. Always verify that the NTP source interface is explicitly configured when required.

Why the other options are wrong

B

logging trap 4 sets the severity to warning (4), so it does not include notifications (5).

C

The missing source interface causes NTP to use an incorrect source address, likely resulting in unsynchronized status.

D

The NTP server address is incorrect and 'logging trap 7' sends all debug messages instead of limiting to notifications and above.

Why candidates pick the wrong answer

B

Candidates might think that using the numeric value is acceptable, but the question explicitly mentions the keyword, so the answer using the keyword is more precise.

C

Candidates may forget to specify the source interface, especially if they assume the router will automatically use the loopback interface.

D

This option reflects the misconfigured state mentioned in the question, so candidates might think it is the correct fix, but it actually perpetuates the errors.

739
MCQhard

A router has an OSPF-learned route to a destination prefix and also a directly connected route to a broader supernet that includes that destination. The OSPF route is more specific. Which route is used for the destination?

A.The more specific OSPF route
B.The directly connected broader route
C.Both routes equally
D.Neither route can be used because the sources differ
AnswerA

Cisco IOS route selection compares prefix length before administrative distance, so the longest-match rule wins. The OSPF route's /30 or similar mask is longer than the connected supernet's mask, so it is installed in the routing table for that destination despite OSPF's higher administrative distance.

Why this answer

The more specific OSPF route is used. In practical terms, route specificity is checked before broader route-source considerations when the prefixes are different. Even though the connected route is a directly attached source and often strongly trusted, it still loses if it is less specific than another matching route.

This is a subtle route-selection question because it combines source type and specificity. The key is that longest-prefix match comes first.

Exam trap

A common exam trap is assuming that directly connected routes always take precedence over OSPF routes because they have a lower administrative distance. Candidates may incorrectly select the broader directly connected route, forgetting that routers first apply longest prefix match before considering administrative distance. This leads to the mistaken belief that a less specific connected route overrides a more specific OSPF route.

The trap is confusing route source preference with prefix specificity, which can cause incorrect answers on routing questions involving multiple route sources.

Why the other options are wrong

B

This option is incorrect because a directly connected route, even though it has a lower administrative distance, does not override a more specific OSPF route due to prefix length precedence.

C

This option is incorrect because routers do not use multiple routes equally when one route is a more specific match; only the best matching route is used for forwarding.

D

This option is incorrect because routers can compare and select routes from different sources; differing sources do not prevent route usage if one route is the best match.

When would these options actually be correct?

B

In a scenario where the OSPF route is down or not available, and the question asks which route would be used for the destination, the directly connected broader route would then be the correct answer as it would be the only available route.

C

In a different question where both routes are equally preferred due to equal administrative distances or when using a routing policy that allows for load balancing, the exam could state that both routes are valid and can be used simultaneously for the destination prefix.

D

In a different scenario, if the question stated that both routes were from different routing protocols and the router was configured to not use OSPF routes due to administrative distance settings, then this option could be correct, indicating that neither route would be used.

Why candidates pick the wrong answer

B

Students might think that directly connected routes have a lower administrative distance (0) than OSPF (110), so they would be preferred. However, prefix length takes precedence over administrative distance in the route selection process.

C

Students may confuse this scenario with ECMP, where multiple routes to the same destination are used for load balancing. However, ECMP requires identical prefix lengths and metrics, not different prefix lengths.

D

Students might think that routes from different sources are incomparable or that administrative distance alone determines the winner. However, prefix length is the primary factor, and different sources are compared normally.

740
Multi-Selectmedium

Which two tasks are strong candidates for network automation? (Choose two.)

Select 2 answers
A.Polling many devices for interface status on a schedule
B.Replacing a failed power supply in a branch switch
C.Pushing a standard NTP configuration to many routers
D.Tracing one cable through a crowded rack by hand
E.Listening for fan noise in a wiring closet
AnswersA, C

Automation excels at scheduled, repetitive data collection. Polling interface status from hundreds of devices via SNMP, NETCONF, or streaming telemetry is a deterministic, read-only operation that can be automated to run at consistent intervals, capturing operational state without human intervention. This enables proactive monitoring, historical trend analysis, and quick fault detection, while reducing the burden on network engineers who would otherwise manually connect to each device. The scale and regularity of the task make it a textbook candidate for automation.

Why this answer

Automation works best for repetitive, rule-based tasks such as gathering state information or pushing standard configuration changes across many devices.

Exam trap

Avoid assuming that all network tasks can be automated. Focus on repetitive and rule-based tasks.

Why the other options are wrong

B

Replacing a failed power supply is a physical hardware task that requires hands-on intervention, not a software-based or configuration task that network automation tools can perform.

D

Tracing a cable by hand is a physical, manual task that cannot be automated with network automation tools, which focus on software-based configuration and monitoring.

E

Listening for fan noise is a physical inspection task that relies on human senses and cannot be performed by network automation software, which deals with digital data and configurations.

When would these options actually be correct?

B

In a question asking about tasks that involve hardware maintenance or physical repairs in a network environment, such as 'Which tasks can be performed by on-site technicians?', option B would be correct as it directly relates to hardware replacement.

D

If the exam question asked for tasks that require physical interaction or manual troubleshooting in a network environment, then tracing a cable would be appropriate. For example, a question might ask for tasks that involve identifying physical connectivity issues in a data center.

E

If the exam question asked for tasks related to environmental monitoring or physical maintenance of network equipment, then listening for fan noise could be considered a valid task. For example, a question might ask which tasks can help ensure optimal hardware performance in a data center.

Why candidates pick the wrong answer

B

Students might think that any repetitive task in network operations is automatable, but automation primarily targets software-configurable tasks, not physical hardware replacements.

D

Students might confuse cable tracing with tasks like network discovery or topology mapping, which can be automated, but physical tracing remains a manual process.

E

Students might think that environmental monitoring (e.g., via sensors) is automatable, but the specific act of listening by ear is not a digital workflow.

741
MCQeasy

Users can reach a server by IP address but not by hostname. Which service should be checked first?

A.NTP
B.DNS
C.QoS
D.HSRP
AnswerB

Users can reach a server by IP address but not by hostname. This is the classic symptom of a DNS resolution failure: the client cannot translate the fully qualified domain name (FQDN) into an IP address, so the connection attempt fails at the name lookup stage. The fact that the IP path itself works proves Layer 3 routing and the server's services are reachable, isolating the problem to name resolution.

Why this answer

If the server is reachable by IP but not by name, the likely issue is name resolution, which points to DNS.

Exam trap

A common exam trap is selecting NTP, QoS, or HSRP as the cause when users cannot reach a server by hostname. NTP synchronizes time and does not affect name resolution. QoS prioritizes traffic but does not translate hostnames to IP addresses.

HSRP provides gateway redundancy and does not influence DNS functionality. Choosing any of these distractors wastes time and leads to incorrect troubleshooting. The key is to recognize that hostname resolution depends solely on DNS, so DNS must be the first service checked when IP connectivity exists but hostname access fails.

Why the other options are wrong

A

NTP (Network Time Protocol) is responsible for synchronizing clocks across devices but does not handle hostname resolution or IP address translation, so it cannot cause hostname access failures.

C

QoS (Quality of Service) manages traffic prioritization and bandwidth allocation but does not perform any function related to hostname resolution or IP address translation.

D

HSRP (Hot Standby Router Protocol) provides gateway redundancy and failover but does not influence DNS or the ability to resolve hostnames to IP addresses.

When would these options actually be correct?

A

If the exam question asked about issues related to time synchronization affecting application performance that relies on timestamps, NTP could be the correct answer. For example, if users are experiencing problems with logging or data integrity due to time discrepancies, NTP would be the service to check.

C

In a scenario where a question asks about troubleshooting network performance issues related to bandwidth allocation or latency, QoS would be the correct service to check first. For instance, if users report slow access to a server by both IP and hostname, indicating potential traffic shaping issues.

D

In a scenario where the question asks about ensuring high availability and failover for multiple routers in a network, HSRP would be the correct answer. For example, if users are unable to reach a server due to a router failure, checking HSRP configurations would be appropriate.

Why candidates pick the wrong answer

A

Students might confuse NTP with DNS because both are network services, or they might think time synchronization is needed for hostname resolution, but that is incorrect.

C

Students might think QoS could block or delay DNS traffic, but the symptom is specific to hostname resolution, not performance. QoS issues would typically cause poor performance, not complete failure to resolve.

D

Students might confuse HSRP with DNS because both involve redundancy or failover, but HSRP is unrelated to name resolution. The symptom of being able to reach by IP but not hostname points to DNS, not gateway redundancy.

742
MCQmedium

Why is a default route often described as a route of last resort?

A.Because it is used only when no more specific route matches.
B.Because it always has the lowest bandwidth.
C.Because it is more specific than any other route.
D.Because it can be learned only through OSPF.
AnswerA

The default route, 0.0.0.0/0, matches every IP destination, but routers use longest-prefix-match forwarding. A packet is sent via the default route only when no other route in the routing table has a longer prefix length that matches the destination. Thus it acts as the final fallback, or route of last resort.

Why this answer

It is described that way because it is used only when no more specific route matches the destination. In practical terms, the router checks for connected, static, or dynamic routes that describe the destination more precisely. If it finds none, the default route becomes the fallback path.

This phrase captures the default route’s purpose exactly. It is not the fastest route or the most specific route. It is simply the catch-all route for otherwise unknown destinations.

Exam trap

A frequent exam trap is assuming the default route is the most specific or fastest route, or that it is exclusively learned through OSPF. Candidates may confuse the default route with routes learned dynamically or with specific metrics. The default route is actually the least specific route, matching all destinations not covered by other entries.

Misunderstanding this can lead to incorrect answers about routing behavior and protocol dependencies, especially since default routes can be configured statically or learned via multiple protocols, not just OSPF.

Why the other options are wrong

B

This option is incorrect because bandwidth does not determine whether a route is a default route. Default routes are about specificity and fallback behavior, not link speed or bandwidth.

C

This option is incorrect because the default route is the least specific route, not more specific than others. It matches all destinations not covered by other routes, so it cannot be more specific.

D

This option is incorrect because default routes can be learned through various routing protocols such as OSPF, EIGRP, or configured statically. It is not exclusive to OSPF.

When would these options actually be correct?

B

In a question asking about the characteristics of routing protocols and their performance metrics, if it specified that the default route is always chosen when bandwidth is the primary consideration, this option could be correct. For example, if the question stated that the default route is selected based on bandwidth constraints in a specific network configuration.

C

In a different scenario, if the question asked about a routing protocol that uses a default route as a more specific option for certain traffic, such as a specialized routing setup in a lab environment, this option could be correct. For example, if a question stated that a specific routing protocol treats a default route as a specific route for certain traffic classes, option C could be valid.

D

If the question asked specifically about OSPF and its ability to learn routes, a scenario could involve discussing OSPF's limitations in certain configurations where a default route is only propagated through OSPF, making this option correct in that context.

Why candidates pick the wrong answer

B

Students may confuse the concept of 'last resort' with a route that has poor performance characteristics, such as low bandwidth, or they might mistakenly associate default routes with backup links that have lower bandwidth.

C

The phrase 'route of last resort' might be misinterpreted as 'most specific' because it is the final option, but in routing terminology, specificity refers to prefix length, not priority.

D

Students may recall that OSPF can generate a default route using the 'default-information originate' command, leading them to incorrectly assume that OSPF is the only way to learn a default route.

743
MCQhard

A network engineer notices that a newly connected switch-to-switch link is up, but traffic from multiple VLANs is not passing. When issuing the show interfaces trunk command, no trunk ports are listed. Both switch ports are configured with switchport mode dynamic auto. What is the most likely cause?

A.There is a native VLAN mismatch between the two switches.
B.The connecting cable is a straight-through Ethernet cable rather than a crossover cable.
C.One switch lacks a VLAN that exists on the other switch.
D.Both ports are set to dynamic auto, so neither switch initiates DTP negotiation.
AnswerD

In dynamic auto mode, a switch port passively waits for DTP negotiation requests. When both ends are dynamic auto, no side initiates the negotiation, so the ports default to access mode. This perfectly matches the symptom: the link is up, but no trunk appears under show interfaces trunk, and multi-VLAN traffic is not passing.

Why this answer

When both switch ports are configured with switchport mode dynamic auto, neither actively initiates Dynamic Trunking Protocol (DTP) negotiation. DTP dynamic auto ports wait for the other side to send DTP frames to form a trunk; since both sides are passive, the link remains in access mode and does not become a trunk, preventing traffic from multiple VLANs from passing.

Exam trap

Cisco often tests the subtle difference between dynamic auto (passive) and dynamic desirable (active) DTP modes, leading candidates to incorrectly assume that two dynamic auto ports will automatically form a trunk.

Why the other options are wrong

A

Confusing DTP trunk negotiation with the operational consequences of a native VLAN mismatch.

B

Assuming that a crossover cable is mandatory for switch-to-switch connections, ignoring auto-MDIX.

C

Mistaking the ability to forward traffic for a specific VLAN with the ability to negotiate a trunk.

744
MCQhard

Two switches, SW1 and SW2, are connected via a trunk link. Hosts in VLAN 50 on SW1 cannot communicate with hosts in VLAN 50 on SW2, while hosts in other VLANs communicate normally. What is the most likely cause?

A.VLAN 50 is not allowed on the trunk from SW1.
B.The native VLAN must be changed to 50 on both switches.
C.The trunk must be changed to an access port.
D.The switches must run PPP on the uplink.
AnswerA

The trunk between SW1 and SW2 has a configured allowed VLAN list that excludes VLAN 50; any frames tagged for that VLAN are dropped at the trunk interface. Because 802.1Q trunks only forward VLANs explicitly permitted in the `switchport trunk allowed vlan` list, the missing entry prevents VLAN 50 traffic from reaching SW2. This would cause clients in VLAN 50 to lose connectivity across the link.

Why this answer

The strongest explanation is that VLAN 50 is missing from the allowed VLAN list on one side of the trunk. In practical terms, the trunk is up and carrying other VLANs, so the problem is selective rather than total. When one VLAN is omitted from the allowed list, only that VLAN fails while others continue to work normally.

This is a high-value switching troubleshooting pattern because it rewards careful reading of operational output rather than generic trunk theory.

Exam trap

Be careful to distinguish between total trunk failures and selective VLAN issues. Check the allowed VLAN list on trunk links when only one VLAN is affected.

Why the other options are wrong

B

The native VLAN is used for untagged traffic on a trunk and does not affect the forwarding of tagged frames for other VLANs. Changing the native VLAN to 50 would not resolve the issue because VLAN 50 frames are still tagged and require inclusion in the allowed VLAN list.

C

An access port can only carry a single VLAN, so changing the trunk to an access port would prevent the link from carrying multiple VLANs, including VLAN 50. The link is intended to carry multiple VLANs, so a trunk is required.

D

PPP (Point-to-Point Protocol) is a WAN protocol used on serial links, not on Ethernet trunks. Ethernet trunks use 802.1Q or ISL encapsulation, and PPP has no relevance to VLAN trunking issues.

When would these options actually be correct?

B

In a different scenario where the question specifies that both switches are configured with VLAN 50 as the native VLAN and that there is a requirement for untagged traffic to be sent on VLAN 50, this option would be correct. The question could ask about the implications of having mismatched native VLANs causing connectivity issues.

C

In a different scenario where the question specifies that a switch is incorrectly configured to use an access port for a connection that should carry multiple VLANs, changing the trunk to an access port could be the correct answer if the goal is to isolate traffic to a single VLAN.

D

In a different scenario where the question specifies that the switches are connected via a serial link requiring PPP for communication, and the configuration is incorrectly set to Ethernet, this option would be correct. The question might ask about the necessary protocol for inter-switch communication in a non-Ethernet environment.

Why candidates pick the wrong answer

B

Students often confuse the native VLAN with the concept of a 'management VLAN' or think that setting the native VLAN to the desired VLAN will automatically allow that VLAN across the trunk, but the native VLAN only affects untagged frames.

C

Some test-takers might think that if a specific VLAN is not working, converting the link to an access port and assigning it to VLAN 50 could solve the problem, but this would break connectivity for other VLANs and is not a proper solution for inter-switch VLAN communication.

D

Students might recall that PPP can be used for authentication or encapsulation on point-to-point links and mistakenly think it could be applied to Ethernet trunks, but PPP is not used in Ethernet switching environments.

745
PBQhard

You have console access to both R1 and R2. Configure OSPFv2 on both routers to establish a single-area adjacency in area 0. The link between R1 and R2 uses 10.0.0.0/30. Currently, OSPF is not configured on either router. After configuration, verify the adjacency forms and routes are exchanged.

Network Topology
G0/010.0.0.1/30G0/010.0.0.2/3010.0.0.0/30R1R2

Hints

  • •Use 'router ospf <process-id>' to enter OSPF configuration mode.
  • •The network statement uses a wildcard mask, not a subnet mask. For a /30, use 0.0.0.3.
  • •Remember to set a router-id; it can be any IP address, but must be unique per router.
A.Configure 'router ospf 1' on R1 and R2, set router-id, and use 'network 10.0.0.0 0.0.0.3 area 0' on both routers.
B.Configure 'router ospf 1' on R1 only, and use 'network 10.0.0.0 0.0.0.3 area 0' on R1; R2 does not need OSPF configuration because it will learn routes via the directly connected interface.
C.Configure 'router ospf 1' on both routers, set router-id, and use 'network 10.0.0.0 255.255.255.252 area 0' on both routers.
D.Configure 'router ospf 1' on both routers, set router-id, and use 'network 10.0.0.0 0.0.0.0 area 0' on both routers.
AnswerA
solution
! R1
configure terminal
router ospf 1
router-id 1.1.1.1
network 10.0.0.0 0.0.0.3 area 0
network 192.168.1.0 0.0.0.255 area 0
network 10.1.1.1 0.0.0.0 area 0
passive-interface GigabitEthernet0/1
passive-interface Loopback0
end

Why this answer

The essential requirement is enabling OSPFv2 on both routers with matching area 0 on the 10.0.0.0/30 link. On R1 and R2, enter 'router ospf 1', set a unique router-id, and use 'network 10.0.0.0 0.0.0.3 area 0' to advertise the link. The solution commands include optional networks (192.168.1.0/24 and Loopback0) that are not required for the adjacency and are shown only as examples; candidates should focus on the link network.

After configuration, 'show ip ospf neighbor' should show a FULL state. Common mistakes include using a subnet mask instead of a wildcard mask (option C) or a /32 wildcard (option D), and not configuring OSPF on R2 (option B).

Exam trap

Remember that OSPF network statements use wildcard masks, not subnet masks. Also, both routers must be configured; OSPF does not automatically enable on all interfaces. Use 'show ip ospf neighbor' to verify adjacency formation.

Why the other options are wrong

B

The specific factual error is that OSPF is a dynamic routing protocol that must be enabled on both ends of a link for adjacency to form; one-sided configuration does not work.

C

The specific factual error is confusing subnet masks with wildcard masks; OSPF uses inverse masks in network statements.

D

The specific factual error is using a host wildcard mask that does not cover the actual interface IPs; the correct wildcard mask must include the range of IPs on the link.

Why candidates pick the wrong answer

B

Candidates might think that because the link is directly connected, OSPF will automatically discover neighbors without explicit configuration on both sides.

C

Candidates often mistakenly use subnet masks instead of wildcard masks because they are more familiar with subnet masks from IP addressing.

D

Candidates might think that using a host mask (0.0.0.0) is sufficient because the network statement is for the network address, but OSPF matches the interface IP, not the network address.

746
Multi-Selectmedium

Which two statements accurately describe APIs in controller-based networking?

Select 2 answers
A.They provide a defined interface through which software can communicate with the controller.
B.They can be used by automation tools to retrieve data or request changes.
C.They replace all need for forwarding devices.
D.They remove the need for authentication and authorization.
E.They are Ethernet cabling standards.
AnswersA, B

APIs provide a formal, documented contract that shields external clients from the controller's internal mechanics. For example, a northbound REST API defines specific URIs, methods, and schemas for exchanging operational state or configuration data. This allows software to communicate precisely and predictably without needing to understand the underlying controller implementation.

Why this answer

APIs are important in controller-based networking because they give external software a defined way to request data or trigger changes on the controller. In plain language, they make the controller accessible to automation tools, dashboards, orchestration systems, and custom scripts. This helps integrate the controller into broader workflows. APIs do not eliminate the need for security controls, but they do make software-driven operations possible.

The wrong answers usually confuse APIs with physical interfaces or claim that they remove the need for authentication. The two correct answers are the ones focused on programmatic access and software integration.

Exam trap

Avoid confusing APIs with physical interfaces or assuming they bypass security protocols.

Why the other options are wrong

C

APIs are software interfaces that enable communication with the controller, but they do not replace forwarding devices like switches and routers. These devices still handle packet forwarding based on policies set via the controller; the controller does not eliminate the need for physical or virtual forwarding hardware.

D

APIs do not remove the need for authentication and authorization. In fact, secure API access typically requires credentials, tokens, or certificates to ensure only authorized users or systems can interact with the controller. Removing these controls would create severe security vulnerabilities.

E

APIs are software interfaces, not physical cabling standards. Ethernet cabling standards like Cat5e, Cat6, or fiber optics define physical layer specifications for wired network connections. Confusing APIs with cabling is a fundamental category error.

When would these options actually be correct?

C

In a question focused on the theoretical aspects of network architecture, where the context is about a fully virtualized environment that abstracts traditional hardware, this option could be correct if it states that APIs can eliminate the need for physical forwarding devices in such a scenario.

D

If the exam question were to focus on a hypothetical scenario where an API is designed for a fully trusted internal network with no security concerns, it could state that authentication and authorization are not necessary, making this option correct.

E

If the exam question asked about networking standards or protocols related to Ethernet technology, such as 'Which of the following are standards for Ethernet cabling?' then option E would be the correct answer, as it would accurately describe a category of networking specifications.

Why candidates pick the wrong answer

C

A student might think that because the controller centralizes control and uses APIs for automation, the forwarding devices become unnecessary. However, the controller only manages the control plane; the data plane still requires forwarding devices to actually move traffic.

D

Some might assume that because APIs are automated, security checks are bypassed. However, automation does not imply lack of security; APIs enforce authentication and authorization to protect network resources.

E

The term 'interface' in networking can refer to both physical ports and software APIs. A student with limited exposure might mistakenly associate 'interface' with physical cabling, especially if they have not yet learned about software-defined networking concepts.

747
MCQhard

R1 and R2 are directly connected and both configured for OSPF area 0. The IP addresses are correct, but the routers do not become neighbors. What is the most likely cause?

A.The OSPF network types on the interfaces do not match.
B.The routers need matching hostnames to exchange LSAs.
C.The /30 subnet is too small for OSPF to operate.
D.The interfaces must be converted into switch trunks.
AnswerA

This is correct because OSPF network type controls fundamental adjacency behaviors such as Hello/Dead timer intervals and DR/BDR election. A point-to-point interface expects to form an adjacency without a DR, while a broadcast interface will wait for a DR/BDR process, and their timer values typically differ. Even if both routers have matching subnet masks and are directly connected, a mismatch in network type causes the routers to discard each other's Hello packets or fail to reach Full state, preventing any LSA exchange.

Why this answer

The most likely cause is an OSPF network type mismatch. In practical terms, both routers are on the same IP segment and both are trying to use OSPF in the same area, but they do not agree on the type of OSPF network the interface represents. That matters because OSPF behavior changes depending on the network type, including how neighbors are discovered and how adjacencies are formed.

This is a classic exam-style troubleshooting case because the obvious items look correct: IP addressing works and the area matches. But a mismatch between point-to-point and broadcast expectations can still stop the relationship from forming cleanly. That makes network type mismatch the strongest answer here.

Exam trap

A frequent exam trap is to overlook the importance of matching OSPF network types on connected interfaces. Candidates might assume that correct IP addressing and area numbers are sufficient for adjacency. However, if one router uses a broadcast network type and the other uses point-to-point, they will not become neighbors despite appearing correctly configured.

This subtle mismatch is often missed because it does not generate explicit errors, leading to confusion and incorrect troubleshooting steps.

Why the other options are wrong

B

This option is incorrect because OSPF neighbor relationships do not depend on matching hostnames. Hostnames are administrative identifiers and do not affect OSPF protocol operations or LSA exchanges.

C

This option is incorrect because a /30 subnet is a standard subnet size for point-to-point links and does not prevent OSPF from operating or forming adjacencies. OSPF works normally over /30 subnets.

D

This option is incorrect because OSPF runs over routed interfaces and does not require interfaces to be configured as switch trunks. Trunking is related to VLAN tagging and switching, not OSPF adjacency.

When would these options actually be correct?

B

In a different scenario, if the question specified that the routers were configured to use OSPF with a custom authentication method that required matching hostnames for verification, then this option could be correct. For example, if the routers were part of a security policy that mandates hostname verification for OSPF neighbor relationships.

C

In a different scenario, if the question stated that OSPF requires a minimum of a /29 subnet for its operation due to specific network design constraints or if it involved a multi-access network setup, then this option could be correct.

D

In a different scenario where the question involves OSPF running on a switch with multiple VLANs, and the interfaces are configured as access ports instead of trunk ports, this option could be correct. If the routers were connected through a switch that required trunking for OSPF to function, then this would be a valid cause for neighbor issues.

Why candidates pick the wrong answer

B

Students may confuse the requirement for matching hostnames in other protocols (like EIGRP) or think that OSPF uses hostnames for neighbor authentication, but OSPF does not require hostname matching.

C

Some might think that OSPF requires a larger subnet (like /24) because they associate OSPF with broadcast networks, but OSPF works fine with /30 on point-to-point links.

D

Students may confuse OSPF with VLAN routing or think that trunking is needed for OSPF to carry multiple VLANs, but OSPF operates at Layer 3 and does not require trunk ports.

748
MCQhard

Why are data models such as YANG important in network automation?

A.They define a structured way to represent configuration and state data
B.They replace IPv4 and IPv6 addressing
C.They remove the need for routing protocols
D.They are used only for naming wireless SSIDs
AnswerA

YANG defines a hierarchical, schema-based data model (RFC 6020/7950) that standardizes how configuration and operational state are represented, enabling programmatic access via NETCONF/RESTCONF. This structured representation allows automation tools to reliably validate, read, and modify device settings across vendors without ad-hoc CLI parsing.

Why this answer

Data models such as YANG standardize how configuration and operational data are described, which improves consistency for automation systems and APIs.

Exam trap

A common exam trap is to mistakenly believe that YANG data models replace fundamental network functions such as IPv4/IPv6 addressing or routing protocols. Some candidates incorrectly assume that because YANG structures configuration data, it eliminates the need for routing protocols like OSPF or EIGRP, or that it changes how IP addresses function. However, YANG is strictly a modeling language that describes how configuration and state data are represented for automation purposes.

It does not alter core networking protocols or addressing schemes. Confusing these roles can lead to selecting incorrect answers that misattribute YANG’s purpose.

Why the other options are wrong

B

Option B is incorrect because YANG does not replace IPv4 or IPv6 addressing schemes. IP addressing remains a core network function independent of data modeling languages.

C

Option C is wrong since YANG does not remove the need for routing protocols. Routing protocols like OSPF and EIGRP continue to operate and are configured using data models but are not replaced by them.

D

Option D is false because YANG’s scope is much broader than naming wireless SSIDs. It models a wide range of network configurations and operational data beyond wireless settings.

When would these options actually be correct?

B

If the exam question asked about the evolution of network protocols and their roles in addressing schemes, or if it specifically inquired about the future of IP addressing, then option B could be correct in a context discussing the transition from IPv4 to IPv6.

C

In a question asking about the impact of automation on network architecture, if it stated that automation frameworks can streamline or simplify routing processes, this option could be considered correct in the context of discussing how certain automation tools might reduce the complexity of routing protocol management.

D

If the exam question asked specifically about the use of YANG in a context limited to wireless networking, such as configuring wireless access points or SSIDs, then option D could be correct. For example, a question might ask, 'What is a specific application of YANG in managing wireless network configurations?'

Why candidates pick the wrong answer

B

A student might confuse YANG with a protocol that modifies network layer addressing, or think that automation models can eliminate the need for traditional addressing, but YANG only structures how addressing is represented.

C

A test-taker might assume that automation and data models can replace dynamic routing by hardcoding routes, but YANG is about representation, not replacing functionality.

D

A student with limited exposure to YANG might only have seen it used in wireless contexts, such as modeling SSID parameters, and incorrectly assume that is its sole purpose.

749
MCQhard

Users report that their PCs take over 30 seconds to obtain IP addresses and reach the network after being powered on. A network technician checks a switch port connected to a PC and observes that the port transitions through blocking, listening, learning, and then forwarding states, taking about 30 seconds to complete. The switch is running standard 802.1D STP. The technician confirms the port is an access port and only connects to a PC. What should the technician do next?

A.Reduce the STP forward delay timer globally on the switch.
B.Enable PortFast on the access port.
C.Disable STP on the access VLAN assigned to the port.
D.Enable Rapid PVST+ on the switch.
AnswerB

PortFast is designed for ports that connect to end hosts. It forces the port to transition directly to the forwarding state, skipping the normal STP listening and learning phases, which is exactly what is needed to eliminate the 30-second boot-time delay.

Why this answer

The 30-second delay is caused by the standard 802.1D STP port states (blocking → listening → learning → forwarding). Since the port is an access port connecting only to a PC (an end host), there is no risk of a bridging loop. Enabling PortFast immediately transitions the port to the forwarding state, bypassing the listening and learning states and eliminating the delay.

Exam trap

Cisco often tests the misconception that disabling STP or changing global timers is acceptable for a single access port, when the correct solution is to use PortFast to bypass the STP states safely only on end-host ports.

Why the other options are wrong

A

This action is too drastic and impacts all ports, whereas the issue is specific to access ports connected to end devices. PortFast is the standard, safe method for eliminating delay on edge ports.

C

Candidates might think that turning off STP on a single VLAN is a quick fix, but it removes the safety net against loops and is not a recommended network practice. PortFast provides the immediate-forwarding benefit while preserving STP loop protection.

D

Candidates often assume that Rapid PVST+ immediately forwards on all access ports, but the edge port behavior must be configured. The scenario explicitly mentions the port is an access port connected only to a PC; the immediate fix is to enable PortFast, not change the entire STP mode.

750
PBQmedium

You are connected to the console of R1. The output of 'show interfaces serial0/0/0' displays that the interface is administratively down (status: administratively down, line protocol is down). The network administrator reports that the serial link between R1 and R2 was recently configured but is not working. You need to troubleshoot and restore connectivity. The serial interface on R1 is Serial0/0/0, and the link is a point-to-point HDLC connection.

Network Topology
S0/0/0S0/0/0serial cableR1R2

Hints

  • •Check the interface status with show interfaces.
  • •Look for 'administratively down' in the output.
  • •Use the no shutdown command to enable the interface.
A.Enter interface configuration mode for Serial0/0/0 and issue the 'no shutdown' command.
B.Enter global configuration mode and issue the 'clock rate 64000' command.
C.Enter interface configuration mode for Serial0/0/0 and issue the 'encapsulation ppp' command.
D.Enter privileged EXEC mode and issue the 'clear interface serial0/0/0' command.
AnswerA
solution
! R1
interface Serial0/0/0
no shutdown

Why this answer

The status 'administratively down' on a Cisco interface means the interface has been manually disabled with the shutdown command. The fix is to enter interface configuration mode for Serial0/0/0 and issue no shutdown, which brings the interface up and allows the line protocol to initialize. This is the direct cause of the reported link failure.

Exam trap

200-301 often tests whether candidates can distinguish 'administratively down' (shutdown command) from other down states, and whether they incorrectly apply clock rate or encapsulation changes before simply enabling the interface.

Why the other options are wrong

B

The specific factual error: The 'clock rate' command configures the clocking rate on a DCE serial interface, not the administrative state.

C

The specific factual error: The encapsulation command changes the Layer 2 protocol but does not affect the administrative state of the interface.

D

The specific factual error: The 'clear interface' command does not enable an administratively down interface; it only resets statistics.

Why candidates pick the wrong answer

B

Candidates pick this because they may confuse a clocking issue with an administrative shutdown, or think that setting a clock rate is necessary for HDLC links.

C

Candidates pick this because they might think the link is down due to encapsulation mismatch, but the question states it is an HDLC connection and the issue is administrative.

D

Candidates pick this because they may think 'clear' will reset the interface to an operational state, similar to a reload, but it does not override the shutdown command.

Page 9

Page 10 of 20

Page 11