Courseiva

CCNA 200-301 v2 (200-301) — Questions 826–900

1450 questions total · 20pages · All types, answers revealed

Page 11

Page 12 of 20

Page 13
826
MCQmedium

A network technician is troubleshooting a connectivity issue where a host cannot communicate with a remote server. The technician notices that frames are being dropped at an intermediate switch. At which OSI model layer does the switch primarily operate, and what is the Protocol Data Unit (PDU) used at that layer?

A.Layer 1; bits
B.Layer 2; frames
C.Layer 3; packets
D.Layer 4; segments
AnswerB

Switches are Layer 2 devices that forward frames. When a frame arrives, the switch parses its Data Link header, reads the destination MAC address, and looks up that address in its MAC address table to determine the egress port. It then forwards the entire frame out the appropriate interface (or floods it if the address is unknown), making 'Layer 2; frames' the correct answer.

Why this answer

Switches primarily operate at Layer 2 (Data Link layer) of the OSI model, where they make forwarding decisions based on MAC addresses. The Protocol Data Unit (PDU) at this layer is the frame, which includes the MAC header, payload, and trailer. When frames are dropped at an intermediate switch, it indicates a Layer 2 issue such as a MAC address table problem, VLAN mismatch, or duplex mismatch.

Exam trap

Cisco often tests the distinction that a standard switch operates at Layer 2, but candidates may incorrectly choose Layer 3 because they associate switches with VLANs or IP routing, forgetting that basic switching is a Layer 2 function.

Why the other options are wrong

A

Switches do not operate at Layer 1; hubs and repeaters do.

C

While some multilayer switches can route, the basic switch in this scenario operates at Layer 2.

D

Segments are used by transport layer protocols, not by switches.

827
Multi-Selectmedium

Which TWO statements about IPv4 and IPv6 static routes, including floating static routes, are correct?

Select 2 answers
A.A floating static route uses a higher administrative distance than the primary route to provide backup connectivity.
B.An IPv6 static route using a link-local next-hop address must include both the next-hop address and the outgoing interface.
C.In IPv6, the default route prefix is 0.0.0.0/0.
D.For a floating static route to be installed in the routing table, it must have an administrative distance lower than that of the primary route.
E.An IPv4 static route will only be inserted into the routing table if its next-hop IP address belongs to a directly connected subnet.
AnswersA, B

A floating static route acts as a backup by intentionally using an administrative distance (AD) that is higher than that of the primary route. Since routing protocols and static routes are selected by lowest AD, the floating route remains out of the routing table while the primary route is active. Only when the primary route is removed due to failure does the router install the floating route, providing connectivity.

Why this answer

A floating static route is configured with a higher administrative distance (AD) than the primary route. This ensures the floating route is only used when the primary route fails, as the router prefers routes with lower AD values. For example, if the primary route has an AD of 1 (static route default), the floating static route might be set to AD 200, making it a backup.

Exam trap

Cisco often tests the distinction between IPv4 and IPv6 default route prefixes (0.0.0.0/0 vs ::/0) and the requirement for specifying the outgoing interface with IPv6 link-local next-hop addresses, which candidates frequently confuse.

Why the other options are wrong

C

0.0.0.0/0 is the IPv4 default route; the correct IPv6 default prefix is ::/0.

D

A floating static route must have a higher AD, not lower, so that it is less preferred and only installed when the primary (lower AD) route is lost.

E

Cisco IOS requires the next-hop to be reachable, but it does not have to be directly connected. As long as a route exists to reach that next-hop (even recursively), the static route can be installed.

828
MCQhard

A switch receives superior BPDUs on a port where the design requires that no downstream device ever become the root path for that segment. Which feature is the best fit for that requirement?

A.Root guard
B.BPDU Guard
C.Port security
D.DHCP Snooping
AnswerA

Root guard is the correct STP protection mechanism for this scenario. When a port configured with root guard receives a superior BPDU (one advertising a better bridge ID or lower root path cost), it transitions the port to a root-inconsistent state, effectively blocking it. This prevents the port from becoming a root port and stops an unauthorized switch from hijacking the root bridge role, thereby preserving the intended spanning-tree topology.

Why this answer

Root guard is the best fit because it is designed to prevent a port from becoming the path toward a new root bridge when superior BPDUs are received. In practical terms, it protects the intended STP topology by keeping that port from taking on a root-related forwarding role when the design says it should not.

This is different from BPDU Guard, which is more commonly used on edge ports to disable them entirely if BPDUs appear. Root guard is about protecting topology roles, not just edge-port assumptions.

Exam trap

A common exam trap is selecting BPDU guard instead of root guard because both involve BPDU handling. BPDU guard disables a port immediately upon receiving any BPDU, which is suitable for edge ports but not for ports where topology control is required. Root guard, on the other hand, only blocks ports that receive superior BPDUs, allowing normal BPDUs from the current root bridge.

Confusing these features can lead to incorrect answers, as BPDU guard does not protect the root path role but rather protects against unauthorized devices on edge ports.

Why the other options are wrong

B

BPDU guard is incorrect because it disables a port upon receiving any BPDU, which is suitable for edge ports but does not control root path roles or topology changes.

C

Port security is unrelated to STP root path control; it manages MAC address access on a port and does not affect BPDU processing or root bridge election.

D

DHCP snooping protects against rogue DHCP servers by filtering DHCP messages and does not interact with STP or root bridge election mechanisms.

When would these options actually be correct?

B

In a scenario where the question asks about protecting edge ports from receiving BPDUs while allowing them to remain operational, BPDU Guard would be the correct answer. For example, if the question specified that the goal was to prevent accidental topology changes on access ports, BPDU Guard would fit.

C

In a scenario where the question asks about securing a switch port against unauthorized devices connecting, while ensuring that only specific MAC addresses are allowed, port security would be the correct answer. This could involve a network segment where only known devices should be permitted to communicate.

D

In a scenario where a question asks about securing a network against rogue DHCP servers and ensuring that only trusted DHCP servers can assign IP addresses, DHCP Snooping would be the correct answer. This would involve configuring the switch to allow DHCP responses only from specific trusted ports.

Why candidates pick the wrong answer

B

Candidates may confuse BPDU Guard with Root Guard due to their similar functions in protecting the network topology, leading them to mistakenly believe that BPDU Guard can also prevent a downstream device from becoming the root bridge.

C

Candidates may confuse port security with STP features, thinking that limiting MAC addresses could also prevent topology changes. This misunderstanding can lead them to select port security when they are actually looking for a solution related to STP behavior.

D

Candidates might confuse DHCP Snooping with general network security features, thinking it could relate to controlling device roles in STP due to its focus on preventing unauthorized access, leading them to mistakenly select it.

829
MCQhard

A network administrator wants to receive an immediate notification from a device when a significant event occurs, rather than polling the device repeatedly. Which SNMP feature is most associated with that requirement?

A.SNMP traps
B.Syslog severity 7
C.DHCP relay
D.NetFlow exporters
AnswerA

An SNMP trap is an unsolicited, event-driven message that a managed device sends directly to a network management station (NMS) to alert it of a fault, status change, or security incident. Unlike SNMP polling, which requires the NMS to request information, traps are pushed immediately when the triggering event occurs, enabling real-time notification without waiting for a poll cycle. This is exactly the behavior described by the requirement to receive an immediate notification from a device.

Why this answer

SNMP traps are the correct answer because they are an SNMP feature that sends unsolicited, event-driven notifications from the device to the management system when a significant event occurs, eliminating the need for polling. Option B (syslog severity 7) is incorrect because syslog is a separate protocol for logging; while syslog messages are also sent unsolicited, the question specifically asks for an SNMP feature. Options C (DHCP relay) and D (NetFlow exporters) are unrelated to immediate event notifications: DHCP relay forwards broadcast requests, and NetFlow exports traffic flow data for analysis.

Exam trap

A frequent exam trap is mistaking syslog messages or NetFlow exporters as the mechanism for immediate event notifications in SNMP. Syslog severity levels, such as severity 7, relate to logging detail but do not trigger unsolicited alerts to management stations. Similarly, NetFlow exporters focus on traffic flow analysis rather than event-driven notifications.

Candidates may also confuse DHCP relay, which is unrelated to SNMP, with notification features. The key is to remember that only SNMP traps send unsolicited, immediate notifications, distinguishing them from polling or other monitoring tools.

Why the other options are wrong

B

Syslog severity 7 refers to debug-level logging detail but does not trigger unsolicited alerts; syslog messages require polling or log monitoring and are not part of SNMP's event-driven notification.

C

DHCP relay is a mechanism to forward DHCP requests across networks and has no role in SNMP or event-driven notifications, making it irrelevant to the question.

D

NetFlow exporters provide detailed traffic flow information for analysis but do not send immediate event notifications; they are unrelated to SNMP traps or polling mechanisms.

When would these options actually be correct?

B

If the exam question asked about logging mechanisms for troubleshooting and monitoring network devices, specifically focusing on the level of detail in logs, then Syslog severity 7 would be the correct answer as it indicates the most granular logging level.

C

If the question were about configuring a network to ensure that DHCP requests are properly forwarded to a remote server, then DHCP relay would be the correct answer. This would involve scenarios where devices are on different subnets and need to communicate with a centralized DHCP server.

D

If the exam question asked about monitoring network traffic and the need to analyze flow data for performance or security purposes, then NetFlow exporters would be the correct answer, as they facilitate the export of flow information to a collector for analysis.

Why candidates pick the wrong answer

B

Candidates may confuse the need for immediate notifications with the detailed logging provided by syslog, thinking that severity levels can also trigger alerts, leading them to choose this option.

C

Candidates may confuse DHCP relay with network monitoring concepts, thinking that it plays a role in event notifications due to its involvement in network communication. This confusion can lead them to select it mistakenly.

D

Candidates might choose this option because they associate network monitoring with flow data collection, thinking that NetFlow exporters could somehow relate to event notifications, despite the lack of real-time alerting capabilities.

830
MCQhard

Refer to the exhibit. A network engineer notices packet loss and sluggish application performance on a branch-office uplink. While troubleshooting, the engineer executes the show interfaces GigabitEthernet0/1 command on the router. Based on the output, what is the most likely cause of the performance issue?

A.The interface is experiencing excessive collisions due to a duplex mismatch.
B.An upstream device is sending traffic at a rate higher than this interface can transmit, causing the output queue to overflow.
C.The interface is receiving corrupted frames, indicated by the zero input errors on the interface.
D.The output queue is full because its size is too small, and increasing the queue depth will resolve the packet loss.
AnswerB

The output queue is maxed (40/40) and output drops are very high (12450). The 5-minute output rate of 10 Mbps is far below the interface bandwidth of 100 Mbps, yet the queue is overflowing, which indicates microbursts from a faster upstream link overwhelming the slower interface. This is the classic signature of a speed mismatch.

Why this answer

The interface shows a high number of output drops, indicating that the output queue is experiencing congestion and packets are being dropped because the router cannot transmit traffic as fast as it is being received from the upstream device. This causes packet loss and sluggish performance.

Exam trap

Cisco often tests the distinction between output drops (congestion) and input errors (physical layer issues), and the trap here is that candidates may misinterpret 'output drops' as a sign of duplex mismatch or assume that increasing queue depth is a fix, when the real issue is a speed mismatch between incoming and outgoing traffic.

Why the other options are wrong

A

Candidates sometimes associate packet loss with duplex mismatches, but a duplex mismatch would also show collisions and typically input errors, both of which are zero here.

C

Zero input errors means no physical-layer receiving problems; the candidate may misinterpret the absence of errors as a sign of some other problem, which is logically incorrect.

D

Increasing the queue size is a common workaround that masks the real problem, but the underlying mismatch in forwarding rates remains. CCNA candidates may incorrectly focus on the queue size rather than the relationship between the 100 Mb/s interface speed and a faster upstream sender.

831
PBQmedium

You are connected to SW1, a Cisco switch that is experiencing intermittent connectivity issues. The network administrator suspects a duplex mismatch between SW1 and the connected router R1. Use CDP to verify the status and check interface statistics.

Network Topology
G0/0G0/1linkR1SW1

Hints

  • •CDP shows the remote device's capabilities and interface details.
  • •Look at the duplex settings on both sides; a mismatch often causes CRC errors.
  • •The interface counters show late collisions if duplex mismatch exists.
A.The switch port is set to half duplex, and the router is set to full duplex, causing CRC errors and late collisions.
B.The switch port is set to full duplex, and the router is set to half duplex, causing runts and FCS errors.
C.The switch port and router are both set to half duplex, but the cable is faulty, causing CRC errors.
D.The switch port is set to auto-negotiation, and the router is set to half duplex, causing late collisions.
AnswerA
solution
! SW1
show cdp neighbors GigabitEthernet0/1 detail
show interfaces GigabitEthernet0/1
show interfaces GigabitEthernet0/1 counters errors

Why this answer

The switch port is manually set to half duplex while the router likely negotiates to full duplex, causing a mismatch. CDP output from the switch will show the router's duplex as full. Interface statistics will show increasing CRC errors and late collisions.

The solution is to set the switch port to auto-negotiation or match the duplex setting with the router.

Exam trap

The exam trap is that candidates may confuse the symptoms of duplex mismatch (CRC errors and late collisions) with other issues like cable faults or speed mismatches. Also, they might forget that CDP can be used to verify the duplex setting of a neighbor. Always check CDP output and interface error counters when troubleshooting connectivity issues.

Why the other options are wrong

B

The specific factual error is that the switch port is manually set to half duplex, not full duplex. Also, runts and FCS errors are not the primary indicators of a duplex mismatch.

C

The specific factual error is that a duplex mismatch requires different duplex settings; both half duplex would not cause a mismatch. Faulty cables are a different issue.

D

The specific factual error is that auto-negotiation would likely result in half duplex on both sides, avoiding a mismatch. The scenario states the switch port is manually set to half duplex, not auto.

Why candidates pick the wrong answer

B

Candidates might pick this because they know duplex mismatches cause errors, but they confuse the direction of the mismatch or the specific error types.

C

Candidates might pick this because CRC errors are common in both duplex mismatches and cable faults, and they may overlook the CDP verification step.

D

Candidates might pick this because they know auto-negotiation can cause issues if one side is manually configured, but they forget that auto-negotiation will match the manually set speed/duplex if possible.

832
MCQhard

R1 cannot reach host 10.3.3.1 on R3. The technician checks routing: R1 has a route to 10.3.3.0/24 via next-hop 10.1.1.2 (R2). R2 has a route to 10.3.3.0/24 via next-hop 10.2.2.2 (R3). A ping from R1 to 10.3.3.1 times out. A ping from R2 to 10.3.3.1 succeeds. What should the technician do next?

A.Verify that R3 has a route back to R1’s subnet.
B.Check whether an inbound ACL on R3 is blocking packets with R1’s source IP address.
C.Verify the OSPF neighbor adjacency between R2 and R3.
D.Test for an MTU mismatch along the path from R1 to R3.
AnswerA

If R3 were missing a route to R1’s subnet, it would not be able to send reply packets to R1. However, R2 and R1 typically reside in the same stub network (e.g., 10.1.1.0/24). The fact that R2 can ping R3 successfully proves that R3 already has a working return path to that network via R2. Checking the routing table at this stage duplicates a condition that is already indirectly verified.

Why this answer

Since R2 can ping 10.3.3.1 successfully, R2 has connectivity to R3, and R3 can send replies to R2's subnet. The failure from R1 indicates that while the forward path from R1 to R3 works, the return path from R3 to R1 is broken. The most likely cause is that R3 does not have a route back to R1's subnet (10.1.1.0/24).

Therefore, the technician should verify R3's routing table for a return route to R1's subnet. An inbound ACL on R3 would affect the forward path (the echo request), not the return path, and would be a secondary check after confirming routing.

Exam trap

A successful ping from an intermediate router does not prove end-to-end connectivity. You must always consider the return path from the destination to the original source. A missing route on the destination router back to the source subnet is a common cause of asymmetric reachability.

Why the other options are wrong

C

This option investigates a Layer 3 adjacency that the successful R2-to-R3 ping has already validated. Candidates often default to checking neighbor state without considering the evidence that rules it out.

D

Candidates may recall MTU as a cause of intermittent connectivity issues, but here the symptom is a total failure from one source, making MTU a low-probability next step.

When would these options actually be correct?

B

R2 can reach R3, confirming that general routing, OSPF, and the return path to R2 are all operational; the failure is specific to R1’s source IP, making ACL inspection the most logical next action.

833
MCQmedium

A switchport should automatically disable itself if too many MAC addresses are learned beyond the configured secure limit. Which port-security violation mode causes that behavior?

A.shutdown
B.protect
C.restrict
D.dynamic
AnswerA

In port-security violation mode 'shutdown', the switchport is immediately placed into the error-disabled state upon a MAC address violation. This is the default and most restrictive violation mode, effectively disabling the port until an administrator manually issues the 'shutdown' and 'no shutdown' commands or the port is configured for auto-recovery via errdisable recovery. It fully blocks all traffic and generates a syslog/SNMP message.

Why this answer

Shutdown is the violation mode that error-disables the port. In plain language, when the switch sees a port-security violation under shutdown mode, it reacts by taking the interface out of service rather than simply dropping frames quietly. That behavior is useful when the administrator wants a clear and strong response to unauthorized devices.

This matters because port security has several violation modes and they do not behave the same way. Restrict and protect can keep the interface up, while shutdown is the mode associated with the most visible response.

Exam trap

Be aware that not all port-security violation modes disable the port. Only Shutdown mode does this.

Why the other options are wrong

B

The 'protect' mode does not disable the port when the secure MAC address limit is exceeded; instead, it drops packets from unknown MAC addresses without generating a notification. This behavior does not match the requirement of the question.

C

The 'restrict' mode allows traffic to pass but drops packets from unknown MAC addresses, without disabling the port. This does not meet the requirement of automatically disabling the port when the MAC address limit is exceeded.

D

The 'dynamic' option is incorrect because it does not refer to a specific port-security violation mode that disables the port when the MAC address limit is exceeded. Instead, it implies the dynamic learning of MAC addresses without enforcing a security limit.

When would these options actually be correct?

B

In a different scenario, if the question asked which port-security mode allows traffic from known MAC addresses while silently dropping traffic from unknown MAC addresses without shutting down the port, 'protect' would be the correct answer.

C

In a scenario where the question asks which port-security violation mode allows traffic to continue while limiting the number of MAC addresses, 'restrict' would be the correct answer. For example, if the question specifies that the goal is to maintain network connectivity while preventing excessive MAC address learning, 'restrict' fits that requirement.

D

In a different question asking about the behavior of a switchport that learns MAC addresses dynamically and can adjust its settings based on traffic patterns, 'dynamic' could be the correct answer. For example, if the question focused on how a port can adapt to changing network conditions without manual configuration, 'dynamic' would apply.

Why candidates pick the wrong answer

B

Candidates may choose 'protect' because they understand it limits traffic based on MAC addresses, leading them to mistakenly associate it with security measures that involve disabling the port.

C

Candidates may choose 'restrict' because it sounds like a security measure that limits access, leading them to believe it could also involve disabling the port, creating confusion with the intended functionality.

D

Candidates may choose 'dynamic' because it sounds like a proactive approach to managing MAC addresses, leading them to mistakenly associate it with automatic security measures rather than the specific disabling behavior required by the question.

834
MCQhard

A user can connect to the employee SSID and receive the correct employee IP subnet, but access to one internal application fails only for that WLAN while wired users succeed. Which troubleshooting area is the strongest first focus?

A.A WLAN-specific policy or filtering rule affecting access to that application
B.The SSID broadcast setting
C.Whether the access point has a valid hostname
D.Whether the client is using PPP instead of Ethernet
AnswerA

The user successfully associates with the employee SSID and obtains an IP address, proving that physical connectivity, authentication, and DHCP are functioning. A failure isolated to one application on that specific WLAN points to a WLAN-level ACL, application filter, or policy applied on the wireless LAN controller that is dropping or denying that app's traffic. This is consistent with a selective deny rather than an infrastructure fault.

Why this answer

The strongest first focus is the policy or filtering path specific to that WLAN or traffic class. In practical terms, the user has already shown that the correct WLAN join, authentication, and subnet assignment are working. Because wired users succeed and only one application fails from that WLAN, the most likely issue is a WLAN-specific policy, ACL, firewall rule, or path treatment affecting that application.

This is a realistic selective-access troubleshooting scenario and tests whether the candidate narrows the fault domain correctly.

Exam trap

Avoid assuming the problem is with the user's device or general network settings when the issue is isolated to a specific WLAN.

Why the other options are wrong

B

The SSID broadcast setting does not directly impact the ability of users to connect to an internal application once they are authenticated and assigned an IP address. Since wired users can access the application, the issue is likely related to WLAN-specific configurations rather than SSID visibility.

C

The access point's hostname does not directly impact application access; it primarily affects network identification and management. Since the issue is specific to WLAN access and not present for wired users, the hostname is unlikely to be the cause.

D

This option is wrong because the issue pertains to application access over a specific WLAN, not the type of connection (PPP vs. Ethernet). The problem likely lies in WLAN configuration rather than the protocol used by the client device.

When would these options actually be correct?

B

In a different scenario where the question specifies that users cannot see the SSID at all, leading to connection issues, the SSID broadcast setting could be the correct focus. For example, if users are unable to connect to the WLAN due to it being hidden, this option would be relevant.

C

In a scenario where a question asks about connectivity issues related to DNS resolution for a specific application, and the problem is identified as being due to the access point not having a valid hostname registered in the DNS, this option would be correct.

D

In a scenario where a question asks about a client device that is unable to connect to a network due to using PPP instead of Ethernet, and the focus is on connectivity issues related to protocol compatibility, this option would be correct.

Why candidates pick the wrong answer

B

Candidates might choose this option because they associate SSID visibility with connectivity issues, leading them to believe it could affect application access, even when the user is already connected.

C

Candidates may confuse hostname validity with connectivity issues, thinking that if the hostname is incorrect, it could lead to application access failures, especially if they lack understanding of how WLAN and wired connections differ in this context.

D

Candidates may choose this option due to a misunderstanding of how different connection types can affect network access, leading them to believe that the protocol used could be the root cause of application access issues.

835
MCQhard

A subnet must support 30 usable IPv4 host addresses. Which prefix is the smallest that meets the requirement?

A./28
B./27
C./26
D./25
AnswerB

A /27 prefix has a subnet mask of 255.255.255.224, which creates 32 total addresses. After reserving the network address and broadcast address, exactly 30 usable host addresses remain, making it the smallest prefix that satisfies the requirement of 30 usable IPv4 hosts. Thus, /27 is the correct choice because it provides the precise number of needed addresses without wasting space.

Why this answer

A /27 is the smallest valid prefix. In plain language, a /27 provides 32 total addresses, and after subtracting the network and broadcast addresses, 30 usable host addresses remain. A /28 would be too small because it provides only 14 usable hosts.

This is a classic minimum-prefix question because it checks whether you can work backward from a host requirement and choose the smallest subnet that fits without over-allocating more space than necessary.

Exam trap

A frequent exam trap is choosing a /28 prefix because it appears to be the closest to supporting 30 hosts. However, a /28 subnet only provides 16 total addresses, of which 14 are usable for hosts after excluding the network and broadcast addresses. This mistake arises from confusing total addresses with usable hosts or failing to subtract the reserved addresses.

Selecting a /28 leads to insufficient host capacity, causing network issues or exam failure. Always remember that usable hosts equal total addresses minus two, which is critical when calculating subnet sizes for CCNA questions.

Why the other options are wrong

A

Option A (/28) is incorrect because a /28 subnet provides only 16 total addresses, which results in 14 usable host addresses after subtracting the network and broadcast addresses. This is insufficient to support 30 hosts.

C

Option C (/26) is incorrect because although it supports 62 usable hosts, it is larger than necessary for 30 hosts, leading to inefficient IP address allocation.

D

Option D (/25) is incorrect because it provides 126 usable host addresses, which is far more than required, resulting in significant address space waste.

When would these options actually be correct?

A

If the question specified a requirement for 14 usable IPv4 host addresses instead of 30, then a /28 subnet would be the correct answer, as it meets that specific need.

C

If the exam question required a subnet that supports at least 62 usable addresses, then /26 would be the correct answer, as it provides the necessary capacity while still being a valid subnet size.

D

If the exam question specified a requirement for a subnet that supports up to 126 usable addresses, then /25 would be the correct choice, as it would provide sufficient capacity for that scenario.

Why candidates pick the wrong answer

A

Candidates may choose /28 due to a misunderstanding of subnetting calculations, mistakenly believing that a smaller subnet can still accommodate more hosts than it actually can.

C

Candidates may choose /26 due to a misunderstanding of subnetting, mistakenly believing that a larger subnet is always acceptable without considering the requirement for the smallest prefix.

D

Candidates may choose /25 due to a misunderstanding of subnetting, thinking that a larger subnet is always acceptable, or they might miscalculate the number of usable addresses needed for the given requirement.

836
Matchingmedium

Drag and drop the syslog and NTP items on the left to the correct descriptions on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Alert: immediate action needed

Notification: normal but significant condition

Reference clock (e.g., atomic clock or GPS)

NTP client synchronized to a stratum 1 server

Configures the device as an NTP client

Displays syslog messages in the buffer

Why these pairings

Each item is correctly paired with its description: A identifies the syslog facility (the source of the log), B indicates syslog severity (urgency level), C correctly describes an NTP server (time source), and D correctly describes an NTP client (time requester). These are foundational definitions for syslog and NTP operations.

Exam trap

Watch out for confusing syslog severity levels with facility types. Also, ensure you correctly match the NTP client and server roles in the context of time synchronization.

837
MCQhard

Exhibit: A standard ACL meant to block host 10.10.10.50 from reaching any remote network was applied inbound on the branch router's LAN interface, but users report that all local traffic from that host is now blocked. What is the better placement?

A.Leave it inbound on the LAN because standard ACLs belong near the source
B.Move it outbound on the WAN-facing interface closer to the destination
C.Convert it to a VTY access-class
D.Apply it inbound on all switch access ports
AnswerB

A standard ACL filters only on source IP address, so it should be applied outbound on the WAN-facing interface, as far from the source as the destination path allows. This placement blocks host 10.10.10.50 from reaching the WAN/remote side with a single rule, avoiding unnecessary processing on internal LAN interfaces. It is the recommended best practice for standard ACLs.

Why this answer

A standard ACL matches only the source address. If it is placed near the source, it can block that host from reaching destinations you did not intend to affect. Standard ACLs are best placed close to the destination.

Exam trap

A frequent exam trap is believing that standard ACLs should always be applied inbound near the source to block unwanted traffic early. Since standard ACLs filter only by source IP, placing them inbound on a LAN interface can block all traffic from that host, including local communications within the LAN. This leads to unintended network outages and user complaints.

The trap is confusing the ACL placement rule for extended ACLs, which are placed near the source, with the rule for standard ACLs, which should be placed near the destination to avoid over-blocking.

Why the other options are wrong

A

Leaving the standard ACL inbound on the LAN interface is incorrect because standard ACLs filter only by source IP, which causes all traffic from that host, including local LAN traffic, to be blocked. This disrupts local communications and is not best practice.

C

Converting the ACL to a VTY access-class is irrelevant to the question because VTY access-classes control remote management access to the router, not general traffic filtering from a host to remote networks.

D

Applying the ACL inbound on all switch access ports is impractical and inefficient. It would block traffic at multiple points unnecessarily and does not address the specific need to filter traffic from the host to remote networks.

When would these options actually be correct?

A

In a different scenario where the question asks about the best practice for applying standard ACLs to control traffic from multiple hosts on a LAN, stating that standard ACLs belong near the source could be correct if the goal is to restrict access to a specific resource without affecting local traffic flow.

C

In a scenario where the question asks how to restrict remote access to a router's management interface (VTY) from a specific IP address, converting an ACL to a VTY access-class would be the correct approach. This would effectively block that host from accessing the router's management functions while allowing other traffic.

D

In a scenario where the question specifies that all devices connected to the switch ports should be restricted from accessing a specific remote network, applying the ACL inbound on all switch access ports would be the correct approach to enforce that restriction.

Why candidates pick the wrong answer

A

Candidates may find this option appealing because it aligns with the general principle that ACLs should be placed close to the source of traffic to minimize unnecessary processing, leading to a misconception about their placement in this specific context.

C

Candidates may find this option tempting because they might confuse the purpose of VTY access-classes with the need to control access to network resources, leading them to think it could solve the problem of blocking a specific host.

D

Candidates may choose this option because they might confuse the need for access control on switch ports with the requirement to block a specific host's access, leading them to think that applying the ACL broadly would achieve the desired outcome.

838
MCQmedium

R1 has the following static route configured: ip route 0.0.0.0 0.0.0.0 203.0.113.1 What does this route accomplish?

A.It blocks unknown destinations from leaving the router.
B.It creates a host route to 203.0.113.1 only.
C.It advertises all connected routes into OSPF.
D.It creates a default route used when no more specific route exists.
AnswerD

This static route has a destination of 0.0.0.0 and a mask of 0.0.0.0, which is the IPv4 default route. It matches any IP packet whose destination does not have a more specific (longer-prefix) match in the routing table, so it acts as the gateway of last resort. Next hop 203.0.113.1 is where all unmatched traffic is forwarded.

Why this answer

This command creates a default static route. In everyday terms, it tells the router, “If you do not know a more specific way to reach a destination, send the traffic to 203.0.113.1.” That next-hop address usually points toward an upstream router or ISP edge. The command does not describe one specific remote network; it represents every destination not otherwise matched by a more specific entry.

At the routing-table level, `0.0.0.0 0.0.0.0` is the broadest possible IPv4 prefix. Because it matches everything, it is used only when nothing more specific exists.

Exam trap

Do not confuse default routes with specific network routes or access control lists; focus on the 0.0.0.0/0 prefix.

Why the other options are wrong

A

This option is incorrect because static routes do not inherently block traffic; they simply define paths for routing packets. A static route allows traffic to specific destinations, rather than blocking unknown ones.

B

This option is wrong because the static route configured does not limit routing to a single host; instead, it typically defines a broader range or a default route for multiple destinations.

C

This option is wrong because static routes do not inherently advertise routes into OSPF; they simply define a path to a specific destination. The question specifically asks about the function of a static route, which does not involve OSPF route advertisement.

When would these options actually be correct?

A

In a different question context, if the question asked about a router's access control list (ACL) or firewall rules that specifically deny traffic to unknown destinations, then this option would be correct, as those configurations can block such traffic.

B

If the exam question specified that the static route was configured with a subnet mask of 255.255.255.255 for the IP address 203.0.113.1, then it would create a host route to that specific IP address, making this option correct.

C

If the question were about a router configuration that includes both static routes and OSPF, and it asked how static routes can be redistributed into OSPF, then this option could be correct. In that context, a static route could be configured to be advertised into OSPF through redistribution commands.

Why candidates pick the wrong answer

A

Candidates might choose this option due to a misunderstanding of static routes and their role in routing; they may confuse routing with access control mechanisms that manage traffic flow based on destination addresses.

B

Candidates may be tempted by this option because they might confuse the concept of a static route with host routes, leading them to believe that a specific IP address configuration implies a host route.

C

Candidates may find this option tempting because they might confuse static routes with dynamic routing protocols like OSPF, leading them to mistakenly believe that static routes can automatically participate in OSPF route advertisements.

839
MCQhard

Why is the combination of strong authentication and centralized logging better than either control by itself?

A.Authentication improves prevention, while centralized logging improves visibility and investigation.
B.They are redundant because both perform exactly the same task.
C.Centralized logging makes authentication unnecessary.
D.Strong authentication removes the need for any event records.
AnswerA

Strong authentication (e.g., MFA, certificates) enforces identity verification before access is granted, thereby reducing the likelihood of unauthorized entry—this is a preventive control. Centralized logging, by contrast, aggregates security events from diverse systems into a single repository, enabling real-time monitoring, forensic analysis, and post-incident investigation. Together they form a defense-in-depth strategy: one blocks initial compromise, while the other provides the visibility needed to detect, respond to, and learn from attempted or successful attacks.

Why this answer

The combination is better because strong authentication helps prevent unauthorized access, while centralized logging helps detect, review, and investigate what happened across the environment. In practical terms, one control is stronger on prevention, and the other is stronger on visibility and accountability. Together they provide broader protection than either one alone.

This reflects a real security principle: mature security depends on layers of control, not one mechanism trying to do every job.

Exam trap

A common exam trap is believing that strong authentication alone is enough to secure a network, leading to the misconception that event logging is unnecessary. Candidates may also incorrectly assume that centralized logging can replace authentication by simply recording events without preventing unauthorized access. This misunderstanding overlooks the complementary roles these controls play: authentication stops unauthorized users upfront, while logging provides the visibility needed to detect and investigate incidents.

Ignoring either control weakens overall security and can cause candidates to select incorrect answers that underestimate the importance of layered defenses.

Why the other options are wrong

B

This option is incorrect because authentication and logging serve different purposes; authentication controls access, while logging records events. They are not redundant but complementary.

C

This option is wrong because centralized logging only records events and does not prevent unauthorized access, so it cannot replace strong authentication.

D

This option is incorrect because even with strong authentication, event records remain essential for auditing, troubleshooting, and investigating security incidents.

When would these options actually be correct?

B

In a question that asks about the efficiency of security measures in a highly controlled environment, where both strong authentication and logging are implemented to achieve the same goal of access control, option B could be correct if the context implies that they are used interchangeably without recognizing their distinct roles.

C

If the exam question were to ask about a scenario where centralized logging is implemented in a highly secure environment that relies solely on logging for access control, then this option could be considered correct. For example, a question might describe a system where access is granted based on log entries rather than traditional authentication methods.

D

In a scenario where the exam question specifically states that strong authentication methods are infallible and cannot be bypassed, one might argue that event records are redundant. This would imply that if authentication is always successful, there is no need to log events.

Why candidates pick the wrong answer

B

Candidates may choose this option due to a misunderstanding of security concepts, believing that if both controls aim to enhance security, they must be performing the same function, leading to confusion about their specific roles.

C

Candidates might choose this option due to a misunderstanding of the roles of authentication and logging, believing that logging alone can suffice for security, especially if they have encountered scenarios where logging is emphasized without adequate authentication.

D

Candidates may find this option tempting because they might believe that robust authentication alone could sufficiently secure a system, leading them to overlook the importance of logging for monitoring and incident response.

840
MCQmedium

A phone and a PC are attached to the same switchport. The intended data VLAN is VLAN 10, and the phone uses voice VLAN 20. The switchport currently has `switchport voice vlan 20` configured. The phone works, but the PC cannot reach the data network. Which command is most likely missing?

A.switchport mode dynamic auto
B.switchport voice vlan 20
C.switchport access vlan 10
D.spanning-tree guard root
AnswerC

The PC fails to reach the network because it is untagged on the access port while the switchport is likely in its default VLAN 1 or a mismatched VLAN. Issuing 'switchport access vlan 10' explicitly assigns the data VLAN to the port, ensuring the PC's traffic is placed in the correct Layer 2 domain. The phone can still tag its voice traffic with VLAN 20 via the voice VLAN feature, but the access VLAN governs the untagged PC traffic.

Why this answer

When a Cisco IP phone and a PC share one port, the switchport often needs both a data VLAN and a voice VLAN. If the voice VLAN exists but the data access VLAN is wrong or missing, the phone can work while the PC fails.

Exam trap

Ensure both data and voice VLANs are configured when devices share a port. Don't confuse duplex or trunk settings with VLAN issues.

Why the other options are wrong

A

The phone works but the PC cannot reach the data network, indicating the PC is not in the correct VLAN. 'switchport mode dynamic auto' sets the port to negotiate trunking via DTP, which does not assign a data VLAN to the PC.

B

The PC cannot reach the data network because the switchport is likely configured as a voice VLAN only, but the data VLAN (access VLAN) is missing. Option B configures the voice VLAN, which is correct for the phone, but does not set the access VLAN for the PC.

D

The issue is that the PC cannot reach the data network, which is typically configured via the access VLAN. Spanning-tree guard root is unrelated to VLAN assignment; it prevents a switch from becoming the root bridge, not connectivity issues on a specific VLAN.

When would these options actually be correct?

A

This command would be correct when the question asks for a switchport configuration that allows dynamic trunk negotiation with a neighboring switch, such as in a scenario where you want the port to become a trunk if the neighbor is set to 'dynamic desirable' or 'trunk'.

B

In a scenario where a phone and PC are connected to the same switchport, and the phone works but the PC cannot reach the data network, the missing setting is the access VLAN for the PC. Option C (switchport access vlan 10) would be correct if VLAN 10 is the data VLAN.

D

A question where a switchport is connected to a switch that should not become the root bridge, and the network experiences instability due to rogue root bridge elections. The correct answer would be to enable root guard on that port.

Why candidates pick the wrong answer

A

Candidates may confuse dynamic trunking protocols with VLAN assignment, thinking that 'dynamic auto' will automatically assign the PC to the correct VLAN, but it only affects trunking mode, not access VLAN.

B

Candidates may think that since the phone works, the voice VLAN is correctly configured, and they might overlook that the PC needs a separate data VLAN. They might assume the voice VLAN setting is the missing piece, but it is already present.

D

Candidates may confuse root guard with other security features or think that spanning-tree issues could cause connectivity loss for the PC, but the symptom here is VLAN-specific, not spanning-tree related.

841
Multi-Selectmedium

Which two statements accurately describe basic WLAN security at the CCNA level?

Select 2 answers
A.WPA2 is generally considered stronger than WEP for wireless security.
B.Open wireless access provides meaningful default encryption.
C.Open wireless access does not provide the same protection as a secured WLAN.
D.A longer SSID makes WEP cryptographically strong.
E.WPA2 relies on TKIP encryption
AnswersA, C

WPA2 uses AES-CCMP with strong key management, whereas WEP's RC4 with static, easily cracked keys offers negligible protection. This satisfies the stem's requirement for an accurate CCNA-level security statement by naming the actual encryption and keying difference between the two standards.

Why this answer

Option A is correct because WPA2 uses AES-CCMP encryption, which is cryptographically far stronger than WEP's flawed RC4-based implementation with its weak IVs and easily cracked keys. Option C is correct because an open WLAN transmits frames without any encryption or authentication, so any nearby client can capture and read the traffic, unlike a WLAN protected by WPA2/WPA3. Option B is wrong because open wireless access provides no encryption at all, only association without credentials.

Option D is wrong because SSID length is just a network name and has no cryptographic role; WEP's weakness lies in its RC4/IV design, not the SSID. Option E is wrong because WPA2 mandates AES-CCMP, while TKIP is associated with the older WPA (and WPA2's optional TKIP compatibility mode), not WPA2's standard encryption.

Exam trap

Avoid confusing open networks with secured ones and remember that WEP is outdated and insecure.

Why the other options are wrong

B

Open wireless access does not provide any default encryption, so it is not secure.

D

A longer SSID does not strengthen WEP; WEP's vulnerability is due to its use of static keys and weak RC4 algorithm, not SSID length.

E

WPA2 is a wireless security standard (Wi-Fi Protected Access 2), unrelated to Ethernet duplex modes.

When would these options actually be correct?

B

If the question were to ask about the benefits of open wireless access in a controlled environment, such as a guest network with additional security measures in place, one might argue that it provides a form of encryption through other means, like VPNs used by clients.

D

If the exam question were to ask about factors that influence the strength of encryption methods, a longer SSID could be considered in a hypothetical context where it is mistakenly believed to add complexity to the encryption process, thus making it seem stronger.

E

If the exam question asked about the characteristics of network protocols in a mixed environment, including both wired and wireless technologies, and specifically inquired about the relationship between WPA2 and Ethernet protocols, this option could be correct in a context that mistakenly conflates the two.

Why candidates pick the wrong answer

B

Candidates may confuse the term 'open' with the idea that some level of security or encryption is automatically applied, especially if they have encountered scenarios where open networks are secured through additional protocols.

D

Candidates may be tempted by this option due to a misunderstanding of how SSIDs and encryption work, mistakenly believing that increasing the length of the SSID could somehow enhance security measures.

E

Candidates may confuse WPA2 with other networking terms due to a lack of clarity on the differences between wireless security protocols and wired network configurations, leading to the selection of this option.

842
Multi-Selecthard

Users can browse websites by IP address but not by hostname. The default gateway is reachable and general internet connectivity works. Which two causes are the most likely?

Select 2 answers
A.The clients are missing a valid DNS server setting
B.DNS queries may be blocked somewhere along the path
C.The routers are missing NTP configuration
D.The switch access ports should be changed to dynamic desirable
AnswersA, B

Without a valid DNS server setting, the client's resolver has no IP address to send hostname queries to, so name resolution returns a 'server not found' or timeout error. Browsing by IP address works because HTTP requests target the IP directly and never invoke the DNS lookup process. This is a classic missing-DNS configuration issue at the client or DHCP scope.

Why this answer

If IP connectivity works but hostnames fail, the problem is usually DNS configuration or DNS reachability, not general routing.

Exam trap

A frequent exam trap is to assume that if users cannot browse websites by hostname, the problem must be with routing or the default gateway. However, the question states the default gateway is reachable and general internet connectivity works, which rules out routing issues. Another trap is to confuse unrelated configurations like NTP or switch port settings as causes for DNS failures.

The key is to focus on DNS-specific causes: missing DNS server settings on clients or DNS traffic being blocked. Misinterpreting these symptoms leads to incorrect answers that do not address the root cause of hostname resolution failure.

Why the other options are wrong

C

Incorrect. NTP configuration affects time synchronization but does not impact DNS resolution or hostname-based browsing, so it is unrelated to this issue.

D

Incorrect. Changing switch access ports to dynamic desirable affects VLAN trunk negotiation (DTP) but does not influence DNS resolution or hostname connectivity.

When would these options actually be correct?

C

In a question where devices fail to authenticate or certificates are rejected, and the symptom is time-related errors (e.g., 'certificate expired' or 'authentication fails'), missing NTP configuration would be a likely cause.

D

This option would be correct in a question about a switch not forming a trunk with another switch, where the access port mode prevents trunk negotiation. For example: 'Two switches fail to establish a trunk link; which configuration change could resolve the issue?'

Why candidates pick the wrong answer

C

Candidates may confuse NTP with DNS because both involve network services, or they might think time sync is required for all network operations, overlooking that DNS is the specific service needed for hostname resolution.

D

Candidates may confuse 'dynamic desirable' with a general 'dynamic' setting that seems like it could fix connectivity, or they might think changing port modes can resolve any network issue without understanding DTP's specific role.

843
Multi-Selectmedium

Which two statements accurately describe why DNS issues can look like general connectivity problems to users?

Select 2 answers
A.Users often access services by name, so failed name resolution can feel like total connectivity loss.
B.Testing by IP address versus hostname can help distinguish DNS issues from raw path issues.
C.DNS failure automatically means the default gateway is missing.
D.If DNS fails, DHCP and NTP must also fail immediately.
E.DNS replaces the need for routing between subnets.
AnswersA, B

DNS translates human-friendly domain names into IP addresses, so when name resolution fails, client applications cannot even initiate a session to a server. Because users rarely type raw IP addresses, every attempted connection appears to fail, making a single DNS outage feel identical to a complete network outage. The data path may be fully operational, but the user perceives total connectivity loss.

Why this answer

DNS issues can look like general connectivity problems because many users think in terms of names, not IP addresses. In practical terms, they may report that 'the network is down' when the actual routed path works but hostname resolution does not. That is why testing by IP versus name is such a useful troubleshooting step.

The distinction between transport reachability and naming is critical in user-facing support.

Exam trap

A common exam trap is assuming that DNS failure means the default gateway or other network infrastructure is missing or malfunctioning. Candidates might incorrectly link DNS issues to routing failures or DHCP and NTP outages, which are separate services. This misunderstanding leads to wasted troubleshooting effort on routing tables or gateway configurations when the real problem lies in DNS server availability or client resolver settings.

The exam tests your ability to isolate DNS as an application-layer service distinct from network-layer connectivity.

Why the other options are wrong

C

Incorrect because DNS failure does not imply the default gateway is missing. Routing and DNS are separate functions, and gateway issues are unrelated to DNS resolution.

D

Incorrect because DHCP and NTP are independent IP services. DNS failure does not cause these services to fail immediately or automatically.

E

Incorrect because DNS does not replace routing. DNS resolves names to IP addresses, while routing protocols determine packet forwarding between subnets.

When would these options actually be correct?

C

In a question that specifically asks about scenarios where DNS failures directly impact the default gateway's functionality, such as in a misconfigured network where DNS settings are tied to gateway operations, this option could be correct. For instance, if a network's routing relies on DNS resolution for gateway identification, a DNS failure could indeed lead to a perceived loss of the default gateway.

D

If the exam question asked about the dependencies between network services and specified a scenario where DNS, DHCP, and NTP were configured on the same server, and that server experienced a complete failure, then this option could be correct. In that case, the failure of DNS could imply a broader service outage affecting DHCP and NTP.

E

In a question focused on the role of DNS in network architecture, if it asked whether DNS can eliminate the need for routing protocols in specific scenarios, option E could be correct if discussing a hypothetical network design that relies solely on DNS for service discovery within a single subnet.

Why candidates pick the wrong answer

C

Candidates may choose this option due to a misunderstanding of how network layers interact, leading them to believe that DNS issues must affect all aspects of connectivity, including the default gateway.

D

Candidates might choose this option due to a misunderstanding of how network services interact, mistakenly believing that all services dependent on DNS must fail together, reflecting a common misconception about service dependencies.

E

Candidates might choose this option due to a misunderstanding of DNS's role in network communication, mistakenly believing that DNS can handle routing tasks, leading to confusion about the functions of different network components.

844
Multi-Selectmedium

Which three features are used to mitigate Layer 2 security threats on a Cisco switch? (Choose three.)

Select 3 answers
.PortFast on all access ports to prevent STP convergence delays.
.Dynamic ARP Inspection (DAI) to prevent ARP spoofing.
.DHCP snooping to build a trusted binding database.
.BPDU guard to shut down ports receiving BPDUs on access ports.
.EtherChannel load balancing to increase bandwidth.
.VLAN 1 as the native VLAN on trunk ports for management.

Why this answer

Dynamic ARP Inspection (DAI) is correct because it validates ARP packets against the DHCP snooping binding table, dropping ARP spoofing/poisoning attempts that enable man-in-the-middle attacks at Layer 2. DHCP snooping is correct because it builds and maintains the trusted binding database of IP-to-MAC-to-port-to-VLAN mappings that DAI relies on, and it also rate-limits and filters rogue DHCP server messages. BPDU guard is correct because it err-disables access ports that receive BPDUs, preventing an attacker from injecting a rogue switch or manipulating STP topology.

PortFast is not a mitigation feature — it only speeds up STP convergence on edge ports and actually increases risk unless paired with BPDU guard. EtherChannel load balancing is a bandwidth/availability feature, not a Layer 2 threat mitigation. Using VLAN 1 as the native VLAN on trunks is a poor practice that can enable VLAN hopping, so it does not mitigate threats.

Exam trap

Cisco often tests the distinction between features that improve STP convergence (like PortFast) and features that provide security (like BPDU guard), causing candidates to mistakenly select PortFast as a security feature.

845
MCQmedium

Two switches are connected with EtherChannel using LACP. One side is configured with mode active and the other side with mode passive. What happens?

A.The channel forms successfully
B.The channel stays down because both sides must be active
C.The channel forms only if PAgP is also enabled
D.The channel becomes a static Port-Channel
AnswerA

LACP's active/passive mode is a standard, valid combination. The active switch actively sends LACP PDUs (protocol data units) to negotiate the link, while the passive switch listens and responds, allowing the port-channel to form. Since one side is active, the negotiation completes and the EtherChannel becomes operational as a dynamic LACP bundle.

Why this answer

LACP forms an EtherChannel when at least one side actively negotiates. Active plus passive is a valid combination, so the bundle comes up if the physical settings match.

Exam trap

A frequent exam trap is believing that both sides of an LACP EtherChannel must be configured in active mode for the channel to form. This misconception leads to the incorrect assumption that active-passive combinations will fail. In reality, LACP requires only one side to be active to initiate negotiation, while the other side can be passive and respond.

Another trap is confusing LACP with PAgP, expecting that enabling PAgP alongside LACP will help form the channel, which is false because these protocols are incompatible. Understanding these nuances prevents misinterpretation of EtherChannel negotiation behavior on the exam.

Why the other options are wrong

B

This option is incorrect because both sides do not need to be active. One side active and the other passive is sufficient for LACP negotiation and channel formation.

C

This option is incorrect because PAgP is a different, Cisco proprietary protocol and does not work alongside LACP. Enabling PAgP does not affect LACP negotiation.

D

This option is incorrect because configuring one side as active and the other as passive uses LACP negotiation, not a static Port-Channel. Static Port-Channels require manual configuration on both ends without negotiation.

When would these options actually be correct?

B

If the question specified that both switches were configured with LACP but required both to be in active mode for the channel to form, then this option would be correct. For example, a question could state that both switches must be in active mode for LACP to function properly.

C

In a different scenario where the question specifies that both switches are configured for PAgP and that LACP is not supported or enabled, the answer could be correct if the exam asks about the necessity of PAgP for channel formation.

D

This option would be correct in a scenario where both switches are configured to use static EtherChannel without LACP or PAgP. In that case, if one side is set to dynamic negotiation, it would not form a channel, and the static configuration would prevail.

Why candidates pick the wrong answer

B

Candidates may choose this option due to a misunderstanding of LACP's operational modes, mistakenly believing that both sides must actively negotiate for the channel to form, leading to confusion about the requirements for successful EtherChannel setup.

C

Candidates may choose this option due to confusion between LACP and PAgP, mistakenly believing that both protocols must be enabled simultaneously for EtherChannel to function properly.

D

Candidates may find this option tempting because they might confuse the negotiation modes of LACP with static configurations, leading them to believe that a mismatch in modes would default to a static setup.

846
MCQhard

R1 and R2 are connected via Ethernet and are configured with OSPF, but they fail to form an adjacency. Upon checking the interface configurations, you see that R1’s interface is in OSPF area 0 while R2’s interface is in area 1, and both interfaces use default timers and are in the same subnet. What is the most likely reason?

A.The OSPF areas do not match on the shared segment.
B.The routers must use the same process ID.
C.The interfaces are in different IPv4 subnets.
D.OSPF cannot run on Ethernet interfaces.
AnswerA

OSPF requires both neighbors to agree on the area ID for a given link; a mismatch prevents the formation of adjacency because the Hello packets carry the area ID and a mismatch causes the receiving router to drop them. Even if subnets and timers match, an area mismatch leaves the neighbor state stuck in Down or Attempt.

Why this answer

The most likely cause is an OSPF area mismatch on the shared segment. R1 and R2 are in the same IP subnet and use default hello/dead timers, so neither subnet mismatch nor timer mismatch is the problem. OSPF can run on Ethernet interfaces.

However, OSPF requires neighbors on the same link to agree on the area ID; here they differ, preventing adjacency. Option B is incorrect because OSPF process IDs are locally significant and do not need to match.

Exam trap

A common mistake is believing that OSPF process IDs must match between routers to form an adjacency; process IDs are locally significant and do not need to match.

Why the other options are wrong

B

This option is incorrect because OSPF process IDs are locally significant and do not need to match between routers. Different process IDs do not prevent adjacency formation.

C

This option is incorrect because the interfaces are in the same IPv4 subnet (10.1.50.0/24), which is a prerequisite for OSPF adjacency on broadcast networks.

D

This option is incorrect because OSPF commonly runs on Ethernet interfaces. Ethernet is a supported media type for OSPF neighbor discovery and adjacency formation.

When would these options actually be correct?

B

In a different scenario where the question specifies that the routers are configured with multiple OSPF processes and the exam asks about the necessity of matching process IDs for adjacency, this option would be correct. For example, if the question involved multiple OSPF instances on the same router, it would be relevant.

C

In a different question setup, if the exam asked about OSPF adjacency issues where the interfaces of R1 and R2 are indeed in different IPv4 subnets, this option would be correct. For example, if the question specified that R1's interface is in 192.168.1.0/24 and R2's interface is in 192.168.2.0/24, then this option would apply.

D

In a different exam scenario, if the question stated that R1 and R2 were configured on a non-Ethernet interface type, such as a serial link, and asked about OSPF compatibility, then this option could be correct if the context implied that OSPF was not supported on that specific interface type.

Why candidates pick the wrong answer

B

Candidates may find this option tempting because they might confuse OSPF process IDs with the requirement for matching OSPF configurations, leading them to believe that process IDs play a critical role in forming adjacencies.

C

Candidates may choose this option due to a misunderstanding of OSPF requirements, believing that adjacency cannot be formed if routers are on different subnets, which is a common misconception.

D

Candidates may find this option tempting because they might recall that certain routing protocols have limitations on specific interface types, leading to confusion about OSPF's compatibility with Ethernet.

847
MCQmedium

A network administrator is configuring a Cisco IOS switch port that connects to an IP phone and a PC daisy-chained behind the phone. The administrator wants the PC's data traffic to be untagged on VLAN 20, and the phone's voice traffic to be tagged with VLAN 30. The phone is already configured to use VLAN 30 for voice. Which configuration on the switch port will accomplish this?

A.switchport mode trunk switchport trunk native vlan 20 switchport trunk allowed vlan 30
B.switchport mode trunk switchport trunk native vlan 30 switchport trunk allowed vlan 20
C.switchport mode access switchport access vlan 30 switchport voice vlan 20
D.switchport mode access switchport access vlan 20 switchport voice vlan 30
AnswerD

This configuration sets the port as an access port for data VLAN 20 and uses the voice VLAN 30 for tagged voice traffic. The phone will receive untagged data frames on VLAN 20 and will tag its voice frames with VLAN 30. This is the standard Cisco configuration for a port connecting to an IP phone with a PC behind it.

Why this answer

The correct configuration uses an access port for data VLAN 20 and a voice VLAN 30. This allows the PC to send untagged data frames that are assigned to VLAN 20, while the IP phone tags its voice frames with VLAN 30. This is the standard and recommended approach for connecting an IP phone and PC to a single switch port.

Exam trap

The trap here is confusing the voice VLAN and data VLAN assignments, or incorrectly using a trunk port when an access port with voice VLAN is sufficient.

848
PBQhard

You are connected to R1, a multilayer switch acting as a DNS forwarder for two VLANs. Users on VLAN 10 report that they cannot resolve 'files.example.com' while VLAN 20 works fine. The DNS server 198.51.100.53 is reachable but returns SERVFAIL for queries from subnet 192.168.10.0/24, while server 203.0.113.53 responds correctly for both VLANs. Diagnose and fix the DNS resolution issue using nslookup and dig, then adjust the IOS-XE configuration to ensure proper name resolution. Choose the best fix that permanently resolves the problem.

Network Topology
G0/0/010.0.0.1/30198.51.100.53linkG0/0/1.10192.168.10.1/24G0/0/1.20192.168.20.1/24R1DNS ServersVLAN 10VLAN 20

Hints

  • •The first DNS server returns SERVFAIL for the A record query.
  • •The second DNS server resolves the name correctly.
  • •Use 'no ip name-server <ip>' to remove a faulty server.
A.Remove the faulty primary DNS server using 'no ip name-server 198.51.100.53' and keep the working secondary server 203.0.113.53.
B.Add a static DNS entry for 'files.example.com' using 'ip host files.example.com 10.0.0.1' on R1.
C.Change the DNS server order so that the working server is primary using 'ip name-server 203.0.113.53 198.51.100.53'.
D.Configure the router to use only the faulty server by removing the working server with 'no ip name-server 203.0.113.53'.
AnswerA
solution
! R1
configure terminal
no ip name-server 198.51.100.53
end

Why this answer

The faulty DNS server 198.51.100.53 returns SERVFAIL for the A record query, indicating a misconfiguration or missing record on that server. Although reordering (Option C) would allow resolution to work by querying the functional server first, it is not the optimal fix because the broken server remains in the list and could still be used if the primary times out or for future queries. The best practice is to completely remove the faulty server using 'no ip name-server 198.51.100.53'.

Option B adds a static entry that only helps one domain and does not address the root cause. Option D would make the router use only the broken server, worsening the problem.

Exam trap

Do not confuse a reachable DNS server with a functional one. SERVFAIL means the server is responding but cannot resolve the query. The solution is to remove the faulty server, not reorder or add static entries.

Why the other options are wrong

C

Reordering the name servers works around the issue temporarily but leaves the faulty server in the configuration, which is not a permanent solution and violates best practice of removing misconfigured DNS servers.

Why candidates pick the wrong answer

B

Candidates might think that adding a static entry is a quick fix for resolution failures, but this does not address the root cause and would not help with other domain queries.

C

Candidates may think that making the working server primary will solve the issue, but they overlook that the router still tries the faulty server first and may not fall back if the response is an error.

D

Candidates might misinterpret the diagnostic output and think the faulty server is the correct one to keep, but this would cause complete resolution failure.

849
MCQeasy

A small office wants branch routers to automatically hand out IP addresses, default gateway values, and DNS servers to clients. Which service should be configured?

A.DNS
B.DHCP
C.NTP
D.TACACS+
AnswerB

DHCP automatically assigns IP addresses, subnet masks, default gateways, DNS servers, and other network parameters from a defined scope. This eliminates the need for manual static configuration, ensuring that each client receives valid, non-conflicting addressing. In a small office, the branch router can act as a DHCP server or BOOTP relay agent to dynamically hand out IPs to hosts.

Why this answer

DHCP is built for this exact job. It centrally provides addressing details so endpoints do not need to be configured by hand.

Exam trap

A common exam trap is confusing DHCP with other network services like DNS, NTP, or TACACS+. DNS only resolves domain names to IP addresses and does not assign IP addresses or default gateways. NTP synchronizes time across devices but does not handle IP addressing.

TACACS+ is an AAA protocol used for authentication and authorization, not for assigning IP addresses or network parameters. Selecting any of these instead of DHCP leads to incorrect answers because they do not fulfill the requirement of automatically handing out IP addresses and related network configuration to clients.

Why the other options are wrong

A

DNS resolves domain names to IP addresses but does not assign IP addresses, default gateways, or DNS server settings to clients. It is not responsible for automatic IP configuration, so it is incorrect for this question.

C

NTP synchronizes time across network devices and does not provide IP addressing or network configuration parameters to clients, making it irrelevant for this question.

D

TACACS+ is an AAA protocol used for authentication, authorization, and accounting. It does not handle IP address assignment or network parameter distribution, so it is not the correct service here.

When would these options actually be correct?

A

If the question asked about a service that resolves domain names for clients in a network, such as 'Which service translates domain names into IP addresses for client devices?', then DNS would be the correct answer.

C

In a scenario where the question asks about synchronizing time across devices in a network, such as ensuring that all routers and servers have the same time for logging and security purposes, NTP would be the correct answer.

D

If the question asked about securing access to network devices and managing user permissions, then TACACS+ would be the correct answer. For example, a scenario might involve configuring user access controls for routers and switches in a corporate environment.

Why candidates pick the wrong answer

A

Candidates may confuse DNS with DHCP due to their roles in network configuration, thinking that both are involved in providing necessary information to clients, leading them to mistakenly select DNS.

C

Candidates may confuse NTP with DHCP due to both being essential network services, leading them to mistakenly believe that NTP could also handle IP address assignment tasks.

D

Candidates might confuse TACACS+ with DHCP due to both being related to network management, leading them to mistakenly believe that TACACS+ could also handle IP address assignment tasks.

850
Multi-Selecthard

A switch port is configured with DHCP snooping trust on the uplink toward the legitimate DHCP server, and DHCP snooping is enabled on the user VLAN. A user connects a rogue DHCP server to an untrusted access port. Which two statements describe what DHCP snooping does in this situation? (Choose two.)

Select 2 answers
A.DHCP server messages received on the untrusted access port are dropped.
B.The access port is automatically converted to a trusted port after the first DHCP packet is seen.
C.The switch disables the entire VLAN and places it in err-disabled state.
D.The rogue server's MAC address is added to the snooping binding table as a trusted entry.
E.Client DHCP messages received on the untrusted access port are still forwarded toward the trusted uplink.
AnswersA, E

DHCP snooping classifies ports as trusted or untrusted. Server-originated messages such as OFFER and ACK arriving on an untrusted port are discarded, which prevents a rogue server on an access port from handing out addresses. This is the core protection the feature provides in this scenario.

Why this answer

DHCP snooping builds a binding table from legitimate client transactions and blocks server messages on untrusted ports. Client messages on untrusted access ports are permitted and forwarded uplink, while rogue server offers on those same ports are discarded. This combination stops the rogue server without disrupting normal client DHCP behavior.

Exam trap

The trap here is assuming DHCP snooping blocks all DHCP traffic on untrusted ports, when it actually blocks only server-originated messages and still permits client requests.

851
MCQhard

Two switches are connected using four Gigabit Ethernet interfaces configured as an EtherChannel with LACP. The network administrator notices that only two of the four interfaces are active in the port-channel, and the other two are in a suspended state. Upon further investigation, the administrator finds that the two inactive interfaces correspond to remote interfaces that are configured with the 'on' mode, while the active ones correspond to remote interfaces configured with LACP active/passive. The administrator also verifies that all local interfaces have the same speed, duplex, and VLAN. What is the most likely cause of the suspended interfaces?

A.The interfaces are in err-disabled state due to a spanning-tree loop.
B.The remote switch interfaces corresponding to the suspended local interfaces are configured with the 'on' mode instead of 'active' or 'passive' for LACP.
C.The port-channel interface is shutdown.
D.There is a mismatch in the allowed VLANs on the member interfaces.
AnswerB

When one switch has LACP active/passive and the other has 'on' (static), LACP negotiation fails, and the ports become suspended. Changing the remote switch to 'active' or 'passive' allows LACP to negotiate and bundle the ports.

Why this answer

LACP requires both ends of a link to be configured in either 'active' or 'passive' mode to negotiate an EtherChannel. If some remote interfaces are set to 'on' mode (static EtherChannel), LACP negotiation fails on those links, causing the corresponding local LACP-enabled interfaces to remain in a suspended state. The local switch detects that LACP PDUs are not received on those interfaces and suspends them to prevent misconfiguration.

The other two interfaces with correctly configured remote peers form the EtherChannel successfully.

Exam trap

Cisco often tests the misconception that all interfaces must match in speed, duplex, and VLAN to form an EtherChannel, but the trap here is that the LACP mode mismatch (active/passive vs. on) is the specific cause of suspended interfaces even when other parameters are consistent.

Why the other options are wrong

A

The exhibit shows the ports as suspended, not err-disabled. Spanning-tree loops typically cause err-disable, not suspension.

C

The port-channel is up (U), so it is not shutdown.

D

The scenario explicitly states that all interfaces are configured with the same VLAN, so this is not the cause.

852
Drag & Dropmedium

Drag and drop the following steps into the correct order to describe the router's routing table lookup process for a destination IP address, including the best-path selection logic (longest prefix match, then administrative distance, then metric) and the final forwarding decision.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The router applies longest prefix match first, then administrative distance, then metric, in that order, to select the best path and forward the packet.

Exam trap

Do not confuse the order of tiebreakers: longest prefix match always comes first, then administrative distance, then metric. Many candidates mistakenly swap AD and metric or think metric is compared first.

Why candidates pick the wrong answer

B

Candidates may think AD is more important than prefix length because it determines route preference between different routing protocols.

C

Candidates may confuse the order of tiebreakers, thinking metric is compared first because it is often used within a routing protocol.

D

Candidates may think metric is more granular and thus compared first, but AD is the higher-level tiebreaker.

853
PBQhard

You are connected to R1. The inside network 192.168.1.0/24 must be able to reach the internet via PAT (overload) using the public IP 203.0.113.1 on interface GigabitEthernet0/1. Additionally, a web server at 192.168.1.10 must be reachable from the internet via static NAT to 203.0.113.10. The current configuration is not working. Identify and fix all issues.

Hints

  • •Check the ACL for the correct inside network.
  • •The PAT command is missing a keyword to enable port address translation.
  • •Ensure the 'overload' keyword is present in the ip nat inside source list command.
A.Change ACL 100 to permit 192.168.1.0 0.0.0.255, add 'overload' to the ip nat inside source list command, and verify with 'show ip nat translations'.
B.Change ACL 100 to permit 192.168.1.0 0.0.0.255 and add the 'overload' keyword to the ip nat inside source list command.
C.Add the 'overload' keyword to the ip nat inside source list command and verify with 'show ip nat translations'.
D.Change ACL 100 to permit 192.168.1.0 0.0.0.255 and verify with 'show ip nat translations'.
AnswerA
solution
! R1
conf t
no access-list 100
access-list 100 permit 192.168.1.0 0.0.0.255
ip nat inside source list 100 interface GigabitEthernet0/1 overload
end

Why this answer

The configuration has two issues: (1) ACL 100 permits 192.168.2.0/24 instead of 192.168.1.0/24, so the inside traffic is not matched for PAT. (2) The 'ip nat inside source list' command lacks the 'overload' keyword, preventing port address translation. The static NAT entry for the web server is correctly configured and does not depend on the ACL; it will work once the ACL is fixed. To resolve: change ACL 100 to permit 192.168.1.0 0.0.0.255, add 'overload' to the ip nat inside source list command, and verify with 'show ip nat translations'.

Exam trap

Candidates often overlook that the ACL must match the inside network exactly, and that 'overload' is required for PAT. Additionally, they may forget to verify with 'show ip nat translations' to confirm the configuration is working.

Why the other options are wrong

B

The answer fails to include the verification step, which is a critical part of troubleshooting and ensuring the configuration is applied correctly.

C

The ACL must match the correct inside network; without fixing it, PAT will not apply to the intended traffic.

D

The 'overload' keyword is essential for PAT; omitting it means the router will perform dynamic NAT without port translation, which is insufficient for multiple hosts.

Why candidates pick the wrong answer

B

Candidates might think only the configuration changes are needed, overlooking the importance of verifying with 'show ip nat translations'.

C

Candidates might focus only on the missing 'overload' keyword and forget that the ACL is also misconfigured.

D

Candidates might think fixing the ACL is enough, not realizing that PAT requires the 'overload' keyword.

854
PBQmedium

You are connected to SW1 via console. SW1 is a Layer 2 switch connected to two other switches (SW2 and SW3) via trunk links. The network administrator wants to ensure that SW1 becomes the root bridge for VLAN 10 and VLAN 20. Currently, SW2 is the root for both VLANs. Configure SW1 to become the root bridge for these VLANs using the Cisco-recommended macro STP commands.

Network Topology
trunktrunkSW2SW1SW3

Hints

  • •Use the 'root primary' macro to set the bridge priority to 24576.
  • •Ensure VLANs 10 and 20 exist on SW1.
A.spanning-tree vlan 10 root primary; spanning-tree vlan 20 root primary
B.spanning-tree vlan 10 root secondary; spanning-tree vlan 20 root secondary
C.spanning-tree vlan 10 priority 4096; spanning-tree vlan 20 priority 4096
D.spanning-tree vlan 10 root; spanning-tree vlan 20 root
AnswerA
solution
! SW1
spanning-tree vlan 10 root primary
spanning-tree vlan 20 root primary

Why this answer

The 'spanning-tree vlan <vlan> root primary' command is the Cisco-recommended macro that sets the bridge priority to 24576, which is lower than the default 32768, making SW1 the root bridge for those VLANs. Option A correctly uses this macro. Option C, while it could achieve the same goal by setting priority to 4096, is not the macro command and would be considered a static configuration; the question specifically asks for the appropriate macro commands.

Option B sets priority to 28672 as a secondary root, and Option D is invalid syntax.

Exam trap

Do not confuse 'root primary' with 'root secondary'. 'root primary' sets priority to 24576 to become root; 'root secondary' sets priority to 28672 to act as backup. Also, remember that the 'root' keyword must be followed by 'primary' or 'secondary'.

Why the other options are wrong

B

Option B uses 'root secondary', which sets the priority to 28672, making SW1 a backup root, not the primary root bridge.

C

Option C uses a static priority assignment of 4096, which would also make SW1 root, but the question expects the Cisco-recommended macro command 'root primary'.

D

Option D uses incomplete syntax 'spanning-tree vlan 10 root' without 'primary' or 'secondary', which is invalid.

Why candidates pick the wrong answer

B

Candidates may confuse 'root primary' and 'root secondary', thinking 'secondary' is needed to become the root, or they may misremember the command syntax.

C

Candidates might think manually setting a very low priority is the best way, but the 'root primary' command is the recommended and simpler approach.

D

Candidates may abbreviate or forget the full syntax, assuming 'root' alone is sufficient to make the switch root.

855
MCQhard

A router has a connected route to 192.168.1.0/24 and also has a default route. Which route is used for traffic to 192.168.1.55?

A.The connected route to 192.168.1.0/24
B.The default route
C.Both routes equally
D.Neither route
AnswerA

Longest-prefix match governs route selection: the /24 connected route is more specific than the default route's /0, so it wins. Traffic to 192.168.1.55 falls inside 192.168.1.0/24 and is forwarded out that connected interface rather than following the default route.

Why this answer

The connected route is used because it is both directly attached and more specific than the default route. In plain language, the router already knows that the destination belongs to one of its local interface networks, so it has no reason to send that traffic to a fallback route.

This is one of the most basic route-selection behaviors. Default routes matter only when no better match exists. Here, a directly connected, exact matching network is already present.

Exam trap

A common exam trap is assuming that the default route will be used for all traffic not explicitly configured, including traffic destined for directly connected subnets. Candidates may mistakenly select the default route because it appears as a fallback path, ignoring that connected routes always take precedence due to their specificity and administrative distance. Another trap is thinking that both routes could be used simultaneously or load-balanced, which is incorrect because the router selects only the best matching route based on prefix length and administrative distance.

Why the other options are wrong

B

Incorrect. The default route is less specific and only used when no matching connected or static route exists. Since a connected route matches, the default route is ignored.

C

Incorrect. The router does not load-balance equally between a connected route and a default route. It selects the single best route based on prefix length and administrative distance.

D

Incorrect. The router clearly has a matching connected route for the destination subnet, so it will use that route rather than discarding the traffic.

When would these options actually be correct?

B

If the question stated that the router had no connected routes and only a default route configured, then the default route would be used for any traffic, including to 192.168.1.55. This would make option B the correct answer.

C

In a different scenario where a router has two equal-length routes to the same destination, such as two connected routes to 192.168.1.0/24 and 192.168.1.0/24 with different interfaces, the router might use both routes equally for load balancing, making this option correct.

D

This option would be correct in a scenario where the router has no valid routes for the destination IP address, such as when the connected route is down or misconfigured, and the default route is not set up to handle that specific traffic.

Why candidates pick the wrong answer

B

Candidates may choose this option if they misunderstand the concept of routing priorities, thinking that the default route is always used for all traffic unless specified otherwise, leading them to overlook the specificity of connected routes.

C

Candidates may choose this option due to a misunderstanding of routing priorities, believing that multiple routes can be used simultaneously without considering the specificity of the routes.

D

Candidates may choose this option due to a misunderstanding of routing priorities, mistakenly believing that a default route would be used even when a more specific connected route exists.

856
PBQhard

You are connected to a multilayer switch MLS1. Configure Root Guard on switchport GigabitEthernet 0/1 (connected to an unauthorized switch) so that if a superior BPDU is received, the port is blocked instead of causing a topology change. Also enable Loop Guard on uplink GigabitEthernet 0/2 (connected to the root bridge) to prevent unidirectional link issues. Finally, enable BPDU Guard on PortFast-enabled access port GigabitEthernet 0/3 (connected to a host) so that if a BPDU is received, the port goes err-disabled. After configuration, a superior BPDU is received on G0/1 and the port is blocked; a BPDU is received on G0/3 and the port goes err-disabled. Verify these protections are active.

Hints

  • •Root Guard is configured per interface under interface configuration mode using 'spanning-tree guard root'.
  • •Loop Guard is configured per interface using 'spanning-tree guard loop'.
  • •BPDU Guard is enabled on PortFast ports with 'spanning-tree bpduguard enable'.
A.Root Guard on G0/1, Loop Guard on G0/2, BPDU Guard on G0/3
B.Root Guard on G0/1, UplinkFast on G0/2, BPDU Guard on G0/3
C.BPDU Guard on G0/1, Loop Guard on G0/2, Root Guard on G0/3
D.Root Guard on G0/1, Loop Guard on G0/2, PortFast on G0/3
AnswerA
solution
! MLS1
interface GigabitEthernet0/1
spanning-tree guard root
interface GigabitEthernet0/2
spanning-tree guard loop
interface GigabitEthernet0/3
spanning-tree portfast
spanning-tree bpduguard enable

Why this answer

Root Guard was correctly configured on G0/1, so when a superior BPDU arrived, the port entered root-inconsistent state instead of becoming root port. Loop Guard on G0/2 prevents alternate port from becoming root if BPDUs stop. BPDU Guard on G0/3 correctly triggered err-disable upon receiving a BPDU on a PortFast port.

To restore G0/3, use 'shutdown' then 'no shutdown' after removing the BPDU source. Verification commands confirm the protections are working.

Exam trap

Trap: Mixing up which protection goes where. Root Guard is for ports that should never become root (e.g., facing unauthorized switches). Loop Guard is for ports that are alternate or root ports (uplinks).

BPDU Guard is for PortFast-enabled access ports. Also, remember that BPDU Guard triggers err-disable, while Root Guard triggers root-inconsistent (blocking) state.

Why the other options are wrong

B

UplinkFast is not designed to detect or prevent unidirectional links; it only accelerates failover.

C

The protections are applied to the wrong ports: BPDU Guard should be on access ports, Root Guard on ports facing potential rogue switches, and Loop Guard on uplinks.

D

PortFast does not prevent BPDU reception; it only skips the listening and learning states. Without BPDU Guard, the port would still process BPDUs and could become a root port.

Why candidates pick the wrong answer

B

Candidates may confuse UplinkFast with Loop Guard because both are STP enhancement features, but they serve different purposes.

C

Candidates may know the features but misapply them to the wrong interfaces due to confusion about where each protection is appropriate.

D

Candidates may think PortFast is sufficient for access ports, but it must be paired with BPDU Guard to provide security against rogue switches.

857
Drag & Dropmedium

Drag and drop the following steps into the correct order to troubleshoot and resolve excessive interface errors caused by a duplex mismatch on a Cisco switch interface.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order starts with identifying symptoms using show interfaces to see error counters like CRC and late collisions. Next, check the local interface speed and duplex with show interfaces status. Then discover the neighbor's speed and duplex, for instance via show cdp neighbors detail, to confirm a mismatch.

After identifying the mismatch, configure the interface with the correct settings (e.g., speed and duplex commands). Finally, verify the resolution by running show interfaces again to ensure errors are no longer incrementing.

858
PBQeasy

You are connected to SW1 via the console. SW1 is a Layer 2 switch connected to multiple PCs. The network administrator wants to implement port security on port G0/1 to allow only one MAC address and to shut down the port if a violation occurs. Additionally, the administrator wants the MAC address to be learned dynamically and added to the running configuration as sticky. Configure port security on G0/1 accordingly.

Network Topology
G0/1PC1SW1

Hints

  • •Port security must be enabled on the interface first.
  • •Sticky MAC automatically adds learned MAC addresses to the running config.
  • •The violation mode 'shutdown' places the port in err-disabled state.
A.SW1(config)# interface G0/1 SW1(config-if)# switchport port-security SW1(config-if)# switchport port-security maximum 1 SW1(config-if)# switchport port-security mac-address sticky SW1(config-if)# switchport port-security violation shutdown
B.SW1(config)# interface G0/1 SW1(config-if)# switchport port-security SW1(config-if)# switchport port-security maximum 1 SW1(config-if)# switchport port-security mac-address sticky SW1(config-if)# switchport port-security violation protect
C.SW1(config)# interface G0/1 SW1(config-if)# switchport port-security SW1(config-if)# switchport port-security maximum 1 SW1(config-if)# switchport port-security mac-address 0000.1111.2222 SW1(config-if)# switchport port-security violation shutdown
D.SW1(config)# interface G0/1 SW1(config-if)# switchport port-security SW1(config-if)# switchport port-security maximum 1 SW1(config-if)# switchport port-security mac-address sticky SW1(config-if)# switchport port-security violation restrict
AnswerA
solution
! SW1
interface GigabitEthernet0/1
switchport port-security
switchport port-security maximum 1
switchport port-security violation shutdown
switchport port-security mac-address sticky

Why this answer

The requirement is one MAC, sticky learning, and shutdown on violation. The correct sequence enables port security, sets maximum 1, enables sticky MAC learning, and sets violation mode to shutdown. Sticky learning dynamically learns the MAC and writes it into the running configuration as a sticky secure MAC address.

Exam trap

200-301 often tests the difference between violation modes — candidates pick restrict or protect thinking they 'block' traffic, but only shutdown err-disables the port as the question requires.

Why the other options are wrong

B

The violation mode 'protect' silently drops frames from unknown MACs without disabling the port, which contradicts the requirement to shut down the port.

C

The 'mac-address' command with a specific address statically assigns that MAC, which is not dynamic. Sticky learning uses the 'mac-address sticky' command to dynamically learn and save the first MAC.

D

The 'restrict' mode does not disable the port; it only drops offending frames and logs the violation. The requirement explicitly states to shut down the port, which requires the 'shutdown' violation mode.

Why candidates pick the wrong answer

B

Candidates may confuse the violation modes or think 'protect' is sufficient because it blocks unauthorized traffic, but they overlook the specific requirement to shut down the port.

C

Candidates might think that manually entering a MAC address is acceptable, but the requirement explicitly asks for dynamic learning with sticky. Also, they may not know the difference between static and sticky MAC addresses.

D

Candidates may think 'restrict' is more secure than 'protect' because it logs violations, but they miss the specific requirement to shut down the port. Also, 'restrict' is a common violation mode that can be confused with 'shutdown'.

859
PBQhard

You are connected to Switch1. Configure an LACP EtherChannel between Switch1 and Switch2 using interfaces GigabitEthernet0/1 and GigabitEthernet0/2. The channel must be in active mode on both sides, and the port-channel interface must have VLAN 10 as the access VLAN. The current configuration has a speed/duplex mismatch and inconsistent VLAN assignments preventing the channel from forming. Verify the channel is up using 'show etherchannel summary'.

Network Topology
Gi0/1Gi0/1EtherChannelSwitch1Switch2

Hints

  • •Check that all member interfaces have the same speed and duplex settings.
  • •Ensure all interfaces (including the port-channel) are in the same VLAN.
  • •Both sides must use LACP active mode for the channel to form.
A.Set speed auto on Gi0/1 and Gi0/2, set duplex auto on both, change access VLAN on Gi0/2 to 10, change access VLAN on Port-channel1 to 10, and set channel-group mode active on both interfaces.
B.Set speed 1000 on Gi0/1, set duplex full on Gi0/1, change access VLAN on Gi0/1 to 20, change access VLAN on Port-channel1 to 20, and set channel-group mode passive on both interfaces.
C.Set speed 100 on Gi0/2, set duplex half on Gi0/2, change access VLAN on Gi0/1 to 20, change access VLAN on Port-channel1 to 20, and set channel-group mode desirable on both interfaces.
D.Set speed auto on Gi0/1 and Gi0/2, set duplex auto on both, change access VLAN on Gi0/1 to 10, change access VLAN on Port-channel1 to 10, and set channel-group mode active on Gi0/1 and passive on Gi0/2.
AnswerA
solution
! Switch1
interface gigabitethernet0/1
speed auto
duplex auto
channel-group 1 mode active
exit
interface gigabitethernet0/2
speed auto
duplex auto
switchport access vlan 10
channel-group 1 mode active
exit
interface port-channel 1
switchport access vlan 10
end

Why this answer

The EtherChannel is not forming due to three issues: (1) Speed mismatch: Gi0/1 is set to 100 Mbps while Gi0/2 is 1000 Mbps; both must match (e.g., auto). (2) Duplex mismatch: Gi0/1 is half-duplex, Gi0/2 is full-duplex; both must be the same (e.g., full). (3) VLAN mismatch: Gi0/1 is in VLAN 10, Gi0/2 in VLAN 20, and Port-channel1 is in VLAN 1; all access VLANs must be consistent (set to VLAN 10). Additionally, the channel-group mode should be 'active' on both interfaces for LACP. The solution involves setting speed and duplex to auto, changing the access VLAN on Gi0/2 and the port-channel to VLAN 10, and setting channel-group mode to active.

Exam trap

The exam trap here is that candidates may focus only on resolving the speed/duplex and VLAN mismatches but forget to check the LACP mode requirement. Also, they might confuse LACP modes (active/passive) with PAgP modes (desirable/auto). Always verify that the mode matches the protocol and the requirement.

Why the other options are wrong

B

The specific factual error: passive mode on both sides will not form an LACP EtherChannel because neither side initiates negotiation; at least one side must be active.

C

The specific factual error: 'desirable' is a PAgP mode; LACP uses 'active' or 'passive'. Using 'desirable' would not form an LACP EtherChannel.

D

The specific factual error: the requirement explicitly states 'active mode on both sides', so setting one side to passive violates the requirement, even though the channel might still form.

Why candidates pick the wrong answer

B

Candidates pick this because they know speed/duplex must match but may incorrectly assume forcing a specific speed is acceptable, and they may confuse passive with active mode.

C

Candidates pick this because they may confuse PAgP and LACP modes, or think 'desirable' is a valid LACP mode. Also, they might think matching to the slower speed is acceptable.

D

Candidates pick this because they know that an active/passive combination works for LACP, but they overlook the explicit requirement for both sides to be active.

860
MCQhard

Refer to the exhibit. A network administrator is troubleshooting an NTP synchronization issue on R1. The router is configured with the command ntp server 10.1.1.100, but the clock remains unsynchronized. The administrator issues the show ntp status command. What is the most likely cause of the problem?

A.The NTP authentication key configured on R1 does not match the one on the server.
B.The system time on R1 is set to an epoch that is too far from the server's time, causing NTP to refuse to synchronize.
C.The NTP service is not enabled on R1; the 'ntp server' command only defines a server but does not start the NTP process.
D.The router cannot reach the NTP server 10.1.1.100 at UDP port 123 due to a routing issue or an access list.
AnswerD

The exhibit clearly shows 'no reference clock' and stratum 16, which indicates that R1 has not received any NTP packets from the configured server. This is a classic symptom of network unreachability—the router’s NTP requests are not making it to the server or responses are not coming back, often caused by a missing route or an ACL filtering UDP 123.

Why this answer

The `show ntp status` output would show the clock as unsynchronized if R1 cannot communicate with the NTP server at 10.1.1.100. NTP uses UDP port 123, and a routing issue or an access list blocking this port would prevent the exchange of NTP packets, leaving the clock unsynchronized. The `ntp server` command configures R1 as a client to request synchronization, but it does not guarantee reachability.

Exam trap

Cisco often tests the misconception that the `ntp server` command alone is insufficient and that an additional 'ntp enable' command is needed, but in reality, the client process is automatically started by the `ntp server` command.

Why the other options are wrong

A

Candidates often confuse unsynchronized status with authentication issues, but authentication failures do not prevent reception of packets; they just discard them after arrival.

B

A common myth is that NTP cannot sync if the clocks are too far apart. While extreme offsets may delay sync, they do not prevent the router from hearing the server, so the reference clock field would still show the server’s IP or clock ID.

C

Some candidates mistakenly believe that a separate 'ntp enable' command is required. In IOS, configuring an ntp server automatically enables NTP, so the service is active.

861
PBQhard

You are connected to R1 via console. R1 is directly connected to R2 over a 1000BASE-T link that is failing to come up. Configure interface GigabitEthernet0/0 on R1 with the correct speed and duplex settings to match R2's configuration, and then verify the link is operational. Additionally, determine the appropriate SFP type for a new 40 km fiber link between R1 and R2.

Network Topology
G0/010.0.0.1/30G0/010.0.0.2/30linkR1R2

Hints

  • •Check R2's running config to see if speed and duplex are manually set.
  • •Auto-negotiation failure can occur when one side is set to auto and the other to fixed settings.
  • •For distances over 10 km on fiber, you typically need a 1000BASE-ZX SFP.
A.Configure interface GigabitEthernet0/0 with 'speed 1000' and 'duplex full'. For the new fiber link, use a 1000BASE-ZX SFP.
B.Configure interface GigabitEthernet0/0 with 'speed auto' and 'duplex auto'. For the new fiber link, use a 1000BASE-SX SFP.
C.Configure interface GigabitEthernet0/0 with 'speed 1000' and 'duplex half'. For the new fiber link, use a 1000BASE-LX SFP.
D.Configure interface GigabitEthernet0/0 with 'speed 100' and 'duplex full'. For the new fiber link, use a 1000BASE-EX SFP.
AnswerA
solution
! R1
interface GigabitEthernet0/0
speed 1000
duplex full

Why this answer

The link is down because R1 is set to auto-negotiate speed and duplex while R2 is hardcoded to 1000 Mbps full duplex. This mismatch causes the link to fail. To fix, configure R1's GigabitEthernet0/0 with 'speed 1000' and 'duplex full'.

For the new 40 km fiber link, a 1000BASE-ZX SFP is required as it supports distances up to 70 km. (1000BASE-LX supports only up to 10 km and is insufficient for 40 km.) Verify with 'show interfaces GigabitEthernet0/0' to see the link state change to up/up.

Exam trap

Do not assume auto-negotiation always works; when one side is hardcoded, the other must match. Also, know the distance limitations of SFP types: SX (short), LX (long, 10 km), ZX (extended, 70 km).

Why the other options are wrong

B

Auto-negotiation cannot match a hardcoded speed/duplex; 1000BASE-SX is for short distances (up to 550 m).

C

Gigabit Ethernet does not support half duplex; 1000BASE-LX maximum distance is 10 km.

D

Speed mismatch (100 vs 1000) will cause link failure; 1000BASE-EX is not an IEEE standard (ZX is used for extended reach).

Why candidates pick the wrong answer

B

Candidates may think auto-negotiation is always best and confuse SX (short) with long-range SFPs.

C

Candidates may think half duplex is acceptable or that LX can be extended beyond its standard range.

D

Candidates may confuse EX with extended reach or think a lower speed might work.

862
MCQmedium

Which security concept gives a user only the permissions required to perform assigned tasks and nothing more?

A.Defense in depth
B.Least privilege
C.Segmentation
D.Availability
AnswerB

Least privilege grants users only the permissions needed for their assigned tasks, nothing extra. This limits the blast radius of compromised accounts or insider misuse by removing unnecessary access rights, directly matching the stem's requirement of minimal, task-specific permissions.

Why this answer

Least privilege is the security principle that grants users only the specific permissions necessary to perform their job functions, minimizing potential damage from errors or malicious actions. Defense in depth is a layered security strategy using multiple controls, not a principle of limiting permissions. Segmentation divides a network into isolated segments to contain threats, but does not directly govern individual user permissions.

Availability ensures systems and data are accessible when needed, which is unrelated to restricting access rights.

Exam trap

Don't confuse access control methods like RBAC, DAC, or MAC with the principle of least privilege, which specifically minimizes permissions.

Why the other options are wrong

A

Defense in depth refers to a layered security approach that employs multiple security measures to protect information. It does not specifically address the principle of granting users only the necessary permissions for their tasks.

C

Segmentation refers to dividing a network into segments to enhance security and manageability, rather than limiting user permissions. It does not directly address the concept of granting only necessary permissions to users.

D

Availability refers to ensuring that systems and data are accessible when needed, which does not relate to limiting user permissions for task completion. This option does not address the principle of restricting access based on necessity.

When would these options actually be correct?

A

If the exam question asked about a comprehensive security strategy that includes various protective measures, such as firewalls, intrusion detection systems, and access controls, then 'Defense in depth' would be the correct answer, as it emphasizes multiple layers of security.

C

If the question asked about a security strategy that involves isolating different parts of a network to limit access and reduce risk, then segmentation would be the correct answer. For instance, a question might focus on methods to prevent lateral movement in a network breach.

D

If the question were to ask about the primary goal of a security framework designed to ensure that systems remain operational and accessible to authorized users, 'Availability' would be the correct answer. For example, a question might ask about the key objectives of the CIA triad, where availability is one of the core principles.

Why candidates pick the wrong answer

A

Candidates may choose this option because they recognize that a robust security posture involves multiple strategies, leading them to mistakenly associate defense in depth with the principle of least privilege.

C

Candidates may confuse segmentation with the principle of least privilege, as both aim to enhance security; however, segmentation focuses on network structure rather than user permissions, leading to misconceptions.

D

Candidates may confuse availability with access control concepts due to their overlapping roles in security. The term 'availability' might seem relevant when considering user permissions, leading to an incorrect assumption that it relates to limiting access.

863
PBQhard

You are managing a Cisco WLC (192.168.1.10) via its web UI. The wireless network 'CorpSecure' has been configured but clients cannot associate. Some report 'wrong password' errors; others see the SSID but fail to connect. Additionally, management access to the WLC web UI is intermittent. Identify and resolve the issues so that wireless clients can successfully associate with 'CorpSecure' using WPA3-Personal and the WLC web UI is reliably accessible from the management VLAN (VLAN 10).

Hints

  • •Check the security settings on the WLAN; clients expecting WPA3 will fail with WPA2 configured.
  • •An SSID that is hidden (Broadcast disabled) may not appear in client scans unless manually entered.
  • •Management access issues might be unrelated to the WLAN config; verify the management interface IP and default gateway are correct.
A.Configure the SSID with WPA3-Personal; verify management interface is on VLAN 10 with correct gateway.
B.Change the SSID security to WPA2-PSK and disable SSID broadcast; reset the WLC to factory defaults.
C.Update the WLC firmware to the latest version and change the management VLAN to VLAN 1.
D.Reconfigure the SSID with WPA3-Enterprise and enable SSID broadcast; set the management interface to use DHCP.
AnswerA
solution
! WLC
Navigate to WLANs > Edit CorpSecure > Security > Layer 2 > Select WPA3-Personal (AES) > Apply
Navigate to WLANs > Edit CorpSecure > SSID > Enable Broadcast SSID > Apply

Why this answer

The primary issue is a security mismatch: the SSID is set to WPA2-PSK while clients expect WPA3, causing 'wrong password' errors. Since clients can see the SSID, broadcast is already enabled; the secondary connection failures may be due to incompatible devices, but the correct fix is to change the security to WPA3-Personal (AES). Additionally, verify that the management interface is on VLAN 10 with the correct gateway to ensure reliable WLC web UI access.

Exam trap

Candidates might mistakenly conclude the SSID broadcast is disabled and enable it unnecessarily, overlooking that the visible SSID indicates broadcast is already on, or they might ignore the management VLAN configuration.

Why the other options are wrong

B

The specific factual error: WPA2-PSK is not compatible with clients expecting WPA3-Personal, and hiding the SSID prevents clients from seeing it.

C

The specific factual error: VLAN 1 is the default and often discouraged for management; the issue is not firmware-related but configuration-based.

D

The specific factual error: WPA3-Enterprise is not appropriate without a RADIUS server, and DHCP for management can lead to unreliable access.

Why candidates pick the wrong answer

B

Candidates might think resetting the WLC is a quick fix, or they may confuse WPA2 and WPA3 requirements.

C

Candidates may assume a firmware bug causes intermittent access, or they may think VLAN 1 is always correct for management.

D

Candidates might confuse WPA3-Personal with WPA3-Enterprise, or think DHCP is more reliable than static IP for management.

864
MCQhard

An EtherChannel between two switches is configured for LACP. One switch shows the member interfaces as bundled, while the other shows them as individual interfaces. Which explanation is most likely if both sides are using LACP?

A.The member interface settings do not match closely enough for bundling, even though both sides use LACP.
B.LACP always requires one side to use PAgP as a backup.
C.EtherChannel cannot operate on switch trunks.
D.One switch must disable STP before EtherChannel can form.
AnswerA

LACP negotiation alone does not guarantee bundling; the member interfaces must also share identical physical and logical parameters such as speed, duplex, VLAN membership, native VLAN, and trunk mode. If any of these settings differ, the LACP control plane will detect the mismatch and keep the ports in a standalone state. Thus, even with LACP active on both ends, inconsistent interface configurations prevent the EtherChannel from forming.

Why this answer

The most likely explanation is that some other interface settings do not match, even though both sides are using the same EtherChannel protocol. In practical terms, LACP alone is not enough. The candidate member interfaces also need to agree on characteristics such as speed, duplex, switchport mode, allowed VLANs where relevant, and other channel-related settings. If they do not, one side may treat the links as separate instead of bundling them.

This is a common troubleshooting pattern because it tests whether you know that EtherChannel success depends on more than just the negotiation protocol name.

Exam trap

Don't assume LACP alone ensures bundling; check all interface settings for consistency.

Why the other options are wrong

B

This option is incorrect because LACP (Link Aggregation Control Protocol) does not require PAgP (Port Aggregation Protocol) as a backup; they are separate protocols. LACP can operate independently without needing PAgP on either side of the EtherChannel.

C

This option is incorrect because EtherChannel can indeed operate on switch trunks, allowing multiple VLANs to be carried over a single logical link. The issue in the question pertains to LACP configuration mismatches, not trunking capabilities.

D

This option is incorrect because Spanning Tree Protocol (STP) does not need to be disabled for EtherChannel to form; EtherChannel can operate alongside STP. Disabling STP can lead to network loops and is not a requirement for EtherChannel functionality.

When would these options actually be correct?

B

In a different scenario, a question might state that a switch is configured to use LACP but has a fallback mechanism that defaults to PAgP if LACP fails. In this case, the option would be correct as it describes a situation where LACP requires PAgP as a backup protocol.

C

If a question asked about the limitations of EtherChannel configurations specifically in relation to VLANs and trunking, stating that EtherChannel cannot operate on switch trunks would be correct. For example, if the question specified that both switches were configured as access ports only, this option could be valid.

D

In a different scenario where the question specifies that a network design mandates disabling STP to prevent loops in a specific topology, and the exam asks about prerequisites for EtherChannel formation under those conditions, this option could be correct.

Why candidates pick the wrong answer

B

Candidates may find this option tempting because they might confuse LACP with PAgP, thinking that both protocols can work together or that one is required as a fallback for the other, leading to misconceptions about their operational requirements.

C

Candidates may choose this option due to a common misconception that EtherChannel configurations are incompatible with trunking, leading to confusion about the requirements for successful EtherChannel setups.

D

Candidates might choose this option due to a common misconception that STP must be disabled to allow for EtherChannel, especially if they have encountered configurations where STP issues caused problems in bundled interfaces.

865
Multi-Selectmedium

Which three of the following statements about the routing table lookup process on a Cisco router are true? (Choose three.)

Select 3 answers
A.The router performs a longest prefix match to select the most specific route for a destination IP.
B.If an exact match is found for the destination network, the router will forward the packet regardless of any more specific routes.
C.A default route (0.0.0.0/0) is used only when no other route matches the destination IP.
D.The router does not perform recursive resolution when the next-hop IP address is not directly connected.
E.The router always prefers routes with a higher administrative distance over those with a lower administrative distance.
F.A directly connected route is automatically installed in the routing table when an interface is configured with an IP address and is up/up.
AnswersA, C, F

When a router receives a packet, it examines the destination IP address and searches its routing table for the route with the longest prefix length, meaning the highest number of matching bits in the network portion. This ensures that the most specific route, such as a /24, is chosen over a less specific one, like a /16, even if both entries could theoretically match. The longest prefix match algorithm is fundamental to IP routing because it enables precise path selection in networks with overlapping routes.

Why this answer

The routing table uses longest prefix match (A) to find the most specific route. The default route (C) is used only when no other route matches. Directly connected routes (F) are automatically installed when the interface is up/up.

Option D is incorrect because the router does recursively resolve the next‑hop IP when it is not directly connected.

Exam trap

Cisco often tests the misconception that an exact match overrides a more specific route, but the longest prefix match rule always selects the route with the longest subnet mask, regardless of administrative distance or metric.

Why the other options are wrong

D

When the next-hop IP is not directly connected, the router does recursively resolve the address to determine the outgoing interface.

866
MCQhard

Exhibit: SW2 receives superior BPDUs on both uplinks. One uplink becomes the root port and the other becomes alternate. Which factor is considered first when SW2 chooses the root port?

A.Lowest local interface MAC address
B.Lowest root path cost
C.Highest duplex setting
D.Lowest configured VLAN number
AnswerB

The spanning-tree root port election first compares the cumulative root path cost advertised in each received BPDU. The port with the lowest root path cost to the root bridge is selected as the root port, because it offers the most efficient shortest path toward the root. Only when costs are equal does STP proceed to other tie-breakers such as the sender bridge ID and sender port ID.

Why this answer

STP chooses the best path to the root bridge based first on the lowest root path cost. If the cost ties, it then checks the sender bridge ID and sender port ID as tie-breakers.

Exam trap

Remember that STP prioritizes root path cost first, not bridge or port IDs. Misunderstanding the order of evaluation can lead to incorrect answers.

Why the other options are wrong

A

This option is wrong because the selection of the root port is based on the lowest root path cost, not the local interface MAC address. The MAC address is not a factor in determining the root port in the Spanning Tree Protocol (STP) process.

C

This option is wrong because the selection of the root port in Spanning Tree Protocol (STP) is based on the lowest root path cost, not the duplex settings of the interfaces. Duplex settings do not influence the port selection process in STP.

D

The lowest configured VLAN number is not a factor in determining the root port in Spanning Tree Protocol (STP). The selection process prioritizes path cost, not VLAN configuration.

When would these options actually be correct?

A

In a different question setup where the focus is on determining the primary interface for a device based on MAC addresses (e.g., a scenario involving MAC address-based load balancing), the lowest local interface MAC address could be the correct criterion for selection.

C

In a different question context where the focus is on interface capabilities, such as determining which port to use for data transmission based on performance metrics, the highest duplex setting could be considered. For example, a question might ask which port should be prioritized for traffic if all other factors are equal.

D

In a different scenario where the question asks about VLAN prioritization in a multi-VLAN environment, the lowest configured VLAN number could be relevant. For example, if the question focuses on how VLAN IDs impact traffic flow or STP behavior in a specific VLAN context, this option could be correct.

Why candidates pick the wrong answer

A

Candidates may find this option tempting because they might confuse the MAC address with the criteria used in other networking protocols, leading them to believe it plays a role in STP root port selection.

C

Candidates may find this option tempting because they might confuse physical layer characteristics, such as duplex settings, with logical layer decisions in network protocols, leading to an assumption that performance metrics influence port selection.

D

Candidates may confuse VLAN configuration with STP operations, mistakenly believing that VLAN IDs influence port selection. This confusion can lead them to select this option, thinking it relates to network topology management.

867
MCQhard

Exhibit: R1 has the static route 'ip route 0.0.0.0 0.0.0.0 192.0.2.2 200' and also learns a default route from OSPF. Which default route will be installed while the OSPF route is present?

A.The static default route
B.The OSPF default route
C.Both default routes with per-packet load balancing
D.Neither route because floating statics suppress dynamic defaults
AnswerB

The OSPF default route is the preferred route because it has a lower administrative distance (110) than the floating static default route, which is configured with a higher AD (e.g., 200) to serve as a backup. OSPF injects the default via 'default-information originate', and the routing table installs only the OSPF route for 0.0.0.0/0. The static route remains in the configuration but is not used until the OSPF route disappears.

Why this answer

The OSPF external default route wins because its administrative distance is 110, which is lower than the floating static route's distance of 200. The static route is intentionally given a higher AD so it is used only as a backup.

Exam trap

A common exam trap is assuming that static routes always override dynamic routes because static routes have a default administrative distance of 1. However, in this question, the static route is configured with an administrative distance of 200, making it less preferred than the OSPF route with an AD of 110. This floating static route is intended as a backup and will not be installed while the OSPF route is present.

Misreading the static route’s AD or ignoring it leads to the incorrect conclusion that the static route will be used, which is a frequent mistake in CCNA routing questions.

Why the other options are wrong

A

The static default route has an administrative distance of 200, which is higher than OSPF’s 110. Therefore, it is less preferred and will not be installed while the OSPF route is present, making this option incorrect.

C

Cisco routers do not perform per-packet load balancing between routes with different administrative distances. The route with the lowest AD is installed exclusively, so this option is incorrect.

D

Floating static routes do not suppress dynamic routes; instead, they serve as backups when dynamic routes are unavailable. Therefore, neither route is not installed is incorrect because the OSPF route will be installed.

When would these options actually be correct?

A

In a different scenario where the OSPF route is not present or is down, the static default route would be the only available route to the default gateway, making it the correct answer for a question asking which default route would be installed.

C

In a different scenario where both routes have the same administrative distance, such as if the static route's distance is changed to match that of OSPF, the router could perform per-packet load balancing between the two default routes.

D

In a different scenario where the static route has an administrative distance lower than the OSPF route (e.g., 110), the static route would take precedence. The question could specify that the static route is configured with a lower administrative distance than the OSPF route, making this option correct.

Why candidates pick the wrong answer

A

Candidates may choose this option because they might overlook the administrative distance concept, mistakenly believing that static routes always take precedence over dynamic routes regardless of the routing protocol's state.

C

Candidates may choose this option due to a misunderstanding of how routing protocols interact, leading them to believe that multiple default routes can be utilized simultaneously for load balancing.

D

Candidates may find this option tempting because they might confuse the concept of administrative distances and assume that static routes always take precedence over dynamic routes without considering their specific values.

868
Matchingmedium

Match each automation transport or interaction term to its most accurate description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Encrypted transport commonly used for API communication

Architectural style often using HTTP methods

Structured data format commonly used in API payloads

Credential-like value often used to control API access

Why these pairings

Options A and B are correct. RESTCONF is a stateless, HTTP-based protocol that supports both XML and JSON encoding. NETCONF is a stateful, RPC-based protocol that uses XML encoding and operates over SSH or TLS.

Option C is incorrect because gRPC is an RPC framework that can support both stateless and stateful interactions, but it is not stateless; it uses HTTP/2 and Protocol Buffers. Option D is incorrect because SSH is a stateful protocol that establishes an encrypted session for secure remote access and file transfers.

Exam trap

Be careful not to confuse RESTCONF (stateless) with NETCONF (stateful). Also, remember that gRPC and SSH are stateful protocols.

When would these options actually be correct?

C

A question asking: 'Which protocol uses HTTP/2 and Protocol Buffers for efficient, high-performance remote procedure calls?' would make gRPC the correct answer.

D

In a question asking 'Which protocol provides encrypted remote CLI access to network devices and supports secure file transfer using SCP or SFTP?', SSH would be the correct answer.

Why candidates pick the wrong answer

C

Candidates may confuse gRPC's use of HTTP/2 with HTTP-based REST protocols, or mistakenly think gRPC is stateless due to its high-performance design, overlooking its support for stateful streams.

D

Candidates may confuse SSH's secure shell capabilities with automation transports, or mistakenly think SSH is stateless because it can be used for quick commands, overlooking its session-based stateful nature.

869
MCQhard

R1 and R2 should form an OSPF adjacency on their shared GigabitEthernet link, but they remain stuck in EXSTART. What is the most likely cause?

A.The routers are using different OSPF areas.
B.The interface MTU values do not match.
C.One side is configured as passive-interface.
D.The subnet mask on the link is incorrect.
AnswerB

A mismatch in interface MTU is the classic cause of OSPF neighbors becoming stuck in EXSTART or EXCHANGE. During the Database Description (DBD) packet exchange, each router includes its MTU in the DBD header; if the receiving router sees a larger MTU than its own, it drops the packet, so the neighbor state never progresses past EXSTART. This correctly explains why the adjacency fails to reach FULL.

Why this answer

The MTU values do not match. OSPF neighbors can discover each other and even move through earlier states, but an MTU mismatch commonly leaves them stuck in EXSTART or EXCHANGE because the routers do not agree on database description packet sizing. Area mismatch, network mismatch, and passive-interface issues usually prevent a much earlier stage of adjacency formation.

Exam trap

A common exam trap is selecting area mismatch or passive-interface as the cause of OSPF adjacency stuck in ExStart. While area mismatch prevents neighbor formation entirely, and passive-interface stops hello packets, these issues cause earlier failures, not ExStart stalls. The ExStart state specifically involves negotiating database description packets, which requires matching MTU values.

Candidates often overlook MTU mismatches because neighbors appear in the topology, misleading them to suspect other configuration errors. Understanding that MTU mismatch allows neighbor discovery but blocks database synchronization is key to avoiding this trap.

Why the other options are wrong

A

Both routers are configured in area 0, so area mismatch is not the cause. Area mismatches prevent neighbor discovery, which would stop adjacency formation before ExStart.

C

If one interface is passive, OSPF hello packets are not sent, preventing neighbor formation altogether. This would stop adjacency formation earlier than ExStart.

D

The subnet mask is consistent on both sides, allowing neighbor discovery. Incorrect subnet masks would prevent neighbors from recognizing each other, blocking adjacency before ExStart.

When would these options actually be correct?

A

In a different scenario where the question specifies that both routers are in the same OSPF area but are unable to establish adjacency, this option would be correct if the routers were configured to use different OSPF area IDs, preventing adjacency formation.

C

In a different scenario, if the question stated that OSPF adjacency was not forming at all and one router was configured with a passive-interface command on the shared link, then this option would be correct as it would directly prevent OSPF from establishing a neighbor relationship.

D

In a different scenario, if the question were about OSPF failing to establish an adjacency due to incorrect IP addressing, including a mismatched subnet mask, this option would be correct. For example, if R1 and R2 were on different subnets, OSPF would not form an adjacency.

Why candidates pick the wrong answer

A

Candidates may choose this option due to a common misconception that OSPF requires routers to be in the same area for adjacency, leading them to overlook other factors like MTU mismatches that can cause EXSTART issues.

C

Candidates might choose this option because they recall that passive-interface settings can disrupt OSPF adjacencies, leading them to mistakenly assume it applies in this situation without considering the specific EXSTART state.

D

Candidates may choose this option because they associate subnet mask issues with general connectivity problems, leading them to believe it could affect OSPF adjacency formation.

870
PBQhard

You are connected to WLC-1 via SSH. A new SSID 'CorpSecure' must be configured for 5 GHz clients using WPA3-Personal. However, after creation, clients can see the SSID but fail to associate. Review the WLC configuration and fix the issue so that clients can successfully associate and obtain an IP address from VLAN 100 (subnet 10.0.100.0/24).

Network Topology
G0/0192.168.1.10/24G0/110.0.0.1/30G0/210.0.100.1/24SwitchManagementWLC-1Upstream RouterClient VLAN 100

Hints

  • •Check the current security settings on the WLAN; they are using WPA2, not WPA3.
  • •The radio policy is not set — clients may try to connect on 2.4 GHz, but the SSID should be 5 GHz only.
  • •Ensure the WLAN is enabled after changes.
A.Change the WLAN security to WPA3-Personal, enable AES-CCMP for WPA3, set the radio policy to 5 GHz, and ensure the WLAN is mapped to the dynamic interface for VLAN 100.
B.Change the WLAN security to WPA2-Personal, enable TKIP encryption, and set the radio policy to 5 GHz.
C.Change the WLAN security to WPA3-Personal, enable AES-CCMP, but leave the radio policy as 'All' (both 2.4 GHz and 5 GHz).
D.Change the WLAN security to WPA3-Personal, enable AES-CCMP, set the radio policy to 5 GHz, but do not enable the WLAN after changes.
AnswerA
solution
! WLC-1
config wlan security wpa3 1 enable
config wlan security wpa3 psk 1 set ascii CorpSecurePass123
config wlan radio-policy 1 5ghz
config wlan enable 1
config wlan security wpa3 ciphers 1 aes-ccmp

Why this answer

The SSID was configured with WPA2 instead of WPA3. The WLC also had no radio policy set for 5 GHz only. To fix, change the WLAN security to WPA3-Personal, enable AES-CCMP for WPA3, and set the radio policy to 5 GHz.

Additionally, ensure the WLAN is mapped to the appropriate dynamic interface for VLAN 100, not the management interface, and that client VLAN 100 is reachable. The commands to modify the WLAN are: config wlan security wpa3 1 enable, config wlan security wpa3 psk ascii CorpSecurePass123 1, config wlan radio policy 802.11a-only 1, and config wlan enable 1.

Exam trap

Students often forget to change the radio policy from 'All' to a specific band, or they confuse WPA2 with WPA3. Also, they may overlook enabling the WLAN after configuration. Ensure you understand the specific requirements for WPA3 and the need to match the radio policy to the client band.

Why the other options are wrong

B

The specific factual error is that WPA2-Personal with TKIP does not meet the WPA3-Personal requirement; WPA3 mandates AES-CCMP.

C

The specific factual error is that the radio policy must be set to 5 GHz only, not 'All', to restrict access to 5 GHz clients.

D

The specific factual error is that the WLAN remains disabled, so clients cannot associate even if other settings are correct.

Why candidates pick the wrong answer

B

Candidates might pick this because they are more familiar with WPA2 and may not realize that WPA3 is required, or they confuse TKIP with AES.

C

Candidates might pick this because they think 'All' is acceptable or they forget to change the radio policy, assuming it defaults correctly.

D

Candidates might pick this because they focus only on security and radio settings, forgetting the final step of enabling the WLAN, which is a common oversight.

871
MCQhard

A network engineer is configuring a new switch port for a VoIP phone that will have a PC daisy-chained behind it. The engineer wants to ensure that voice traffic is tagged with VLAN 100 and data traffic is untagged in VLAN 200. Which configuration should be applied to the switch port?

A.Configure the port as an access port in VLAN 200 and enable voice VLAN 100 with the switchport voice vlan 100 command.
B.Configure the port as a trunk port with native VLAN 200 and allowed VLAN 100.
C.Configure the port as an access port in VLAN 100 and enable voice VLAN 200 with the switchport voice vlan 200 command.
D.Configure the port as a trunk port with native VLAN 100 and allowed VLAN 200.
AnswerA

This configuration sets the port as an access port for data traffic in VLAN 200, while enabling voice VLAN 100 for VoIP traffic. The phone will tag voice traffic with VLAN 100, and the PC's data traffic will be untagged and assigned to VLAN 200. This meets the requirement of tagged voice and untagged data on the same port.

Why this answer

The correct configuration uses the voice VLAN feature on an access port. The port is set to access VLAN 200 for data traffic, and the voice VLAN 100 is enabled. The VoIP phone will tag voice frames with VLAN 100, while the PC's data frames remain untagged and are placed in VLAN 200.

This is the standard Cisco approach for connecting a phone and PC on a single switch port.

Exam trap

The trap here is assuming that a trunk port is required for voice and data separation, when the voice VLAN feature on an access port achieves the same result with simpler configuration.

872
MCQhard

A router shows the following route: O 10.10.40.0/24 [110/20] via 192.0.2.2, 00:00:12, GigabitEthernet0/0 What does the value 110 represent?

A.The OSPF cost to the destination
B.The administrative distance of OSPF
C.The number of hops to the destination
D.The route age in seconds
AnswerB

In OSPF, the first number within the brackets of an IP routing table entry is the administrative distance (AD). For OSPF, this is a fixed default of 110, which represents the protocol's trustworthiness compared to other routing sources. The router uses this value to select the best route when multiple protocols offer paths to the same destination, with lower AD being preferred. Here, the '110' matches OSPF's standard AD, confirming this is the correct interpretation.

Why this answer

In Cisco route output, the value in brackets is [administrative distance/metric].

Exam trap

A frequent exam trap is mistaking the administrative distance value for the OSPF cost or metric. The number 110 in the route output is the administrative distance, not the cost to reach the destination. The OSPF cost is the second number inside the brackets, which in this example is 20.

Confusing these values can lead to incorrect assumptions about route preference and path selection. Remember, administrative distance compares trustworthiness between routing protocols, while the metric determines the best path within a single protocol.

Why the other options are wrong

A

The OSPF cost to the destination is not represented by the first number in brackets; it is the second number. Therefore, 110 cannot be the OSPF cost.

C

The number of hops is not indicated by the value 110. OSPF does not use hop count as its metric, so this option is incorrect.

D

The route age is shown separately after the next-hop IP address and interface, not inside the brackets. Thus, 110 does not represent route age.

When would these options actually be correct?

A

In a question asking about the OSPF cost to a specific destination, where the context is focused on OSPF metrics and path selection, this option could be correct. For example, if the question provided a route with an OSPF cost value instead of an administrative distance, then option A would be valid.

C

In a different question, if it asked for the number of hops in a routing protocol that uses hop count as its metric, such as RIP, and provided a route with a hop count value, then this option would be correct.

D

In a different question, if it asked for the age of a route in a routing table output that specifically included a field for route age, such as 'Route age: 00:00:12,' then the option could be correct if it explicitly stated that the age was represented in seconds.

Why candidates pick the wrong answer

A

Candidates might confuse the administrative distance with OSPF cost due to their close association in routing protocols, leading them to mistakenly select this option when they recall that OSPF uses costs for path metrics.

C

Candidates may confuse the concept of administrative distance with hop count, especially if they have encountered routing protocols that use hops as a metric, leading them to mistakenly select this option.

D

Candidates may find this option tempting because they might confuse route age with the time since the route was last updated, leading them to mistakenly associate the time format with the value 110.

873
Multi-Selectmedium

Which two statements about NTP are correct? (Choose two.)

Select 2 answers
A.Accurate time helps correlate log messages across multiple devices.
B.NTP replaces the need for DNS in enterprise networks.
C.NTP synchronizes clocks between network devices and time sources.
D.NTP is used to negotiate EtherChannel parameters.
AnswersA, C

When network devices have synchronized time, their logs can be aligned to a common timeline, allowing an administrator to trace a single event across multiple routers, switches, and firewalls. Without synchronized time, an attacker or a fault can be obscured by skewed timestamps. This correlation is fundamental to efficient incident response and root-cause analysis.

Why this answer

NTP synchronizes time across devices, which is important for logging, certificates, and event correlation.

Exam trap

A common exam trap is mistaking NTP for a service that replaces DNS or manages link aggregation like EtherChannel. Some candidates incorrectly believe NTP handles domain name resolution or negotiates EtherChannel parameters because these are also fundamental network services. However, NTP’s sole purpose is to synchronize time across devices.

Selecting options that confuse NTP with DNS or EtherChannel leads to incorrect answers. Understanding that NTP only manages time synchronization helps avoid this trap and ensures accurate selection of correct options related to time correlation and clock synchronization.

Why the other options are wrong

B

This option is incorrect because NTP does not replace DNS. DNS resolves domain names to IP addresses, while NTP only synchronizes time across devices.

D

This option is incorrect because NTP does not negotiate EtherChannel parameters. EtherChannel negotiation is handled by protocols like PAgP or LACP, unrelated to time synchronization.

When would these options actually be correct?

B

In a different question asking about protocols that can replace or serve as alternatives to DNS in certain scenarios, such as in a specialized network environment where time-based domain resolution is implemented, option B could be correct.

D

If the exam question were to ask about protocols used for negotiating link aggregation parameters in a network, then option D could be correct in the context of discussing protocols like LACP or PAgP, which do manage EtherChannel configurations.

Why candidates pick the wrong answer

B

Candidates may confuse the roles of NTP and DNS, thinking that accurate time synchronization could somehow eliminate the need for DNS in managing network resources, leading them to select this option mistakenly.

D

Candidates may confuse NTP with other network protocols and assume that it could play a role in device configuration processes, leading them to mistakenly select this option without fully understanding the specific functions of NTP.

874
MCQhard

A network engineer notices that R1 is using the static route to 192.168.10.0/24 via next-hop 10.1.1.2 instead of the OSPF route via 10.2.2.2, even though the OSPF path has lower latency. What is the most likely cause?

A.The static route has a lower administrative distance than the OSPF route.
B.The OSPF route has a higher metric than the static route.
C.Equal-cost multi-path (ECMP) is disabled for OSPF.
D.The static route is configured with a higher next-hop IP address, so it is preferred.
AnswerA

Administrative distance is the first criterion used to select routes from different routing protocols. A static route has an AD of 1, while OSPF has an AD of 110. The lower AD wins, so the static route is installed in the routing table and used for forwarding, regardless of the OSPF path's better performance.

Why this answer

R1 prefers the static route over the OSPF route because static routes have a default administrative distance (AD) of 1, whereas OSPF has a default AD of 110. Since a lower AD indicates a more trustworthy route, the static route is installed in the routing table regardless of metric or latency. The OSPF route, despite having lower latency, is not used because AD is evaluated before metric.

Exam trap

Cisco often tests the distinction between administrative distance and metric, trapping candidates who assume lower latency or lower metric always determines the best path, when in fact AD is evaluated first for routes from different sources.

Why the other options are wrong

B

Common misconception that metrics are compared across different routing protocols. In reality, AD is evaluated first, and only routes from the same protocol with equal AD are compared by metric.

C

Mistaking ECMP as the mechanism for selecting between two routes from different sources; in this scenario, the static route's AD disqualifies the OSPF route entirely.

D

Misunderstanding that IP addresses, not administrative distance or metrics, influence path selection.

875
MCQmedium

Given the JSON snippet below, what is the value of hostname? { "device": { "hostname": "R1", "mgmt_ip": "192.0.2.10" } }

A.device
B.hostname
C.R1
D.192.0.2.10
AnswerC

In JSON, the hostname key maps to the string value "R1", so when the snippet is parsed, the expression device.hostname returns R1. This is the actual configured hostname of the network device, as opposed to the key name or other attributes.

Why this answer

The key hostname inside the device object has the value R1.

Exam trap

Be careful not to confuse keys with their values in JSON objects. Ensure you are extracting the correct value by identifying the correct key.

Why the other options are wrong

A

The option 'device' is incorrect because it refers to the key in the JSON structure, not the value associated with the 'hostname' key. The question specifically asks for the value of 'hostname'.

B

Option B is incorrect because it simply repeats the key 'hostname' from the JSON structure without providing the actual value associated with it, which is what the question asks for.

D

This option is wrong because the question specifically asks for the value of 'hostname', which is defined as 'R1' in the JSON snippet. '192.0.2.10' is the value of 'mgmt_ip', not 'hostname'.

When would these options actually be correct?

A

If the question asked for the top-level key in the JSON snippet, such as 'What is the main object in the JSON structure?', then 'device' would be the correct answer as it represents the primary object containing the hostname.

B

In a different question that asks for the name of the key in the JSON structure rather than its value, 'hostname' would be the correct answer. For example, if the question were to identify the key associated with the value 'R1', then option B would be appropriate.

D

If the question were to ask for the value of 'mgmt_ip' instead of 'hostname', then '192.0.2.10' would be the correct answer. In that case, the focus would shift to the management IP address of the device.

Why candidates pick the wrong answer

A

Candidates may be tempted to choose 'device' because it is a prominent part of the JSON structure and could be misinterpreted as the answer when focusing on the overall organization of the data.

B

Candidates might choose this option because they misinterpret the question as asking for the name of the field rather than the value it holds, leading to confusion between keys and values in JSON.

D

Candidates may be tempted to choose this option because they might confuse the structure of the JSON and mistakenly associate 'mgmt_ip' with 'hostname', thinking both are equally relevant.

876
MCQhard

A network administrator is troubleshooting connectivity issues between two switches. Hosts connected to Switch A cannot ping hosts on Switch B. The link between the switches shows as up/up on both ends, but interface error counters (CRC, runts) are increasing rapidly. What should the administrator do to resolve the issue?

A.Replace the faulty cable between the two switches.
B.Change the duplex setting on SwitchA's interface to auto-negotiation.
C.Replace the SFP module on SwitchA's GigabitEthernet0/1 port.
D.Enable the interface with 'no shutdown' command.
AnswerB

The correct fix is to change the duplex setting on SwitchA's interface to auto-negotiation. The interface is manually hard-coded to full-duplex, while the remote switch is likely auto-negotiating and has fallen back to half-duplex due to the negotiation failure. This duplex mismatch causes late collisions and poor performance. On 1000BASE-T, auto-negotiation is mandatory, so both ends must either auto-negotiate or be manually set to identical duplex and speed settings; changing SwitchA to auto allows both sides to agree on full-duplex.

Why this answer

The increasing CRC and runts errors on an up/up link indicate a duplex mismatch, where one side is using full duplex and the other half duplex. Assuming SwitchB is using auto-negotiation (the default on Cisco switches), changing SwitchA's interface to auto-negotiation will allow both ends to negotiate the correct duplex setting, resolving the mismatch and stopping the errors.

Exam trap

Cisco often tests the misconception that a link showing 'up/up' means the physical layer is perfect, when in reality duplex mismatch causes high error rates while keeping the interface up, leading candidates to incorrectly suspect cable or hardware faults.

Why the other options are wrong

A

Cable issues would manifest as input errors or interface flapping, but the counters show zero errors.

C

No errors are reported, so the SFP is functioning correctly.

D

The 'show interface' output clearly shows the interface is up, so no shutdown is not needed.

877
Multi-Selectmedium

Which two statements about standard and extended IPv4 ACLs are correct?

Select 2 answers
A.A standard ACL matches only the source IPv4 address.
B.An extended ACL can match protocol information and Layer 4 ports.
C.A standard ACL is normally placed as close to the source as possible.
D.An extended ACL cannot filter ICMP traffic.
E.Both ACL types require named ACL syntax to match traffic.
AnswersA, B

A standard ACL evaluates packets using only the source IPv4 address in the IP header, ignoring destination, protocol, and port information. This coarse filtering means it cannot differentiate between services like HTTP and SSH on the same destination host. As a result, standard ACLs are typically placed near the destination to avoid inadvertently blocking traffic to other networks.

Why this answer

Standard ACLs match only the source IPv4 address, while extended ACLs can match protocol and source and destination details including ports. Because standard ACLs are less granular, they are usually placed closer to the destination. Extended ACLs are usually placed closer to the source.

Exam trap

A frequent exam trap is assuming that standard ACLs can filter traffic based on protocol types or Layer 4 ports, which they cannot. This misconception leads to incorrect placement decisions, such as placing standard ACLs near the source, which risks blocking legitimate traffic from other sources. Another trap is believing extended ACLs cannot filter ICMP traffic, but extended ACLs do support ICMP filtering.

Misunderstanding these facts can cause confusion in both exam scenarios and real-world network design, resulting in incorrect ACL configurations and ineffective traffic control.

Why the other options are wrong

C

This option is incorrect because standard ACLs are usually placed closer to the destination, not the source, to avoid blocking legitimate traffic from other sources.

D

This option is incorrect since extended ACLs can filter ICMP traffic by specifying the ICMP protocol in the ACL configuration.

E

This option is incorrect because both numbered and named ACLs are valid for standard and extended ACLs; named ACL syntax is not required.

When would these options actually be correct?

C

In a question that asks about the placement of ACLs specifically for optimizing bandwidth usage or reducing load on upstream devices, option C could be correct if it stated that a standard ACL is placed close to the source to filter traffic before it enters the network.

D

In a different exam question asking specifically about the capabilities of standard ACLs versus extended ACLs in filtering traffic types, if the question stated that extended ACLs cannot filter ICMP, then option D would be correct, as it would align with the constraints of that specific scenario.

E

In a scenario where the exam question specifies that only named ACLs are allowed for configuration, and asks which types of ACLs can be used, option E would be correct if both standard and extended ACLs were defined to require named syntax exclusively.

Why candidates pick the wrong answer

C

Candidates may choose this option due to a misunderstanding of ACL placement strategies, confusing the general practice of placing access lists with the specific type of ACL being discussed.

D

Candidates may choose this option due to a misunderstanding of the capabilities of extended ACLs, often confusing them with standard ACLs, which only filter based on source IP addresses and do not consider protocol types.

E

Candidates may find this option tempting because they might confuse the use of named ACLs with the general configuration of ACLs, leading them to believe that named syntax is a necessity for both types.

878
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure and recover from a BPDU guard violation on a PortFast-enabled access port.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order is: first configure PortFast and BPDU guard on the interface (A). Then connect a switch to trigger a BPDU guard violation (B). Next, perform a shutdown followed by no shutdown to recover from the errdisable state (C).

Finally, verify that the port is forwarding traffic (D). This sequence ensures the violation occurs before recovery, which is the realistic scenario.

Exam trap

The trap is to think recovery must happen first, but the violation must occur to put the port into errdisable before recovery. The correct order is configure, trigger violation, recover, verify.

879
Multi-Selectmedium

Which two statements accurately describe why source restriction and logging are often used together for administrative access?

Select 2 answers
A.Source restriction narrows the allowed origin space for administrative sessions.
B.Logging improves visibility and accountability for what happened during administrative access.
C.Logging removes the need for authentication.
D.Source restriction works only when Syslog is disabled.
E.Both controls exist only for guest wireless networks.
AnswersA, B

Source restriction applies network-layer filtering, such as ACLs or management access lists, to administrative protocols (SSH, HTTPS, SNMP) so only traffic from explicitly permitted source IP addresses or subnets reaches the device's management plane. This shrinks the attack surface by blocking unauthorized origins before they can attempt authentication or exploit a service.

Why this answer

Source restriction and logging are often used together because they help answer two different security questions. In practical terms, source restriction limits where administrative sessions may originate, while logging helps show what happened once access was attempted or granted. This combination improves both exposure reduction and post-event visibility.

This is a strong layered-security reasoning item because it focuses on complementary controls rather than one-control thinking.

Exam trap

A frequent exam trap is to believe that logging can replace source restriction or that source restriction only works if logging is disabled. Candidates may incorrectly think that visibility through logs is enough to secure administrative access, ignoring the importance of limiting where management sessions can originate. Another mistake is to assume these controls are only relevant for guest wireless networks, which is false because they apply broadly to all management-plane security.

Understanding that source restriction and logging serve distinct but complementary roles is critical to avoid this trap.

Why the other options are wrong

C

Logging provides visibility but does not replace authentication; authentication is still required for access.

D

Source restriction operates independently of Syslog; it does not require Syslog to be disabled or enabled.

E

Source restriction and logging apply to all administrative access, not just guest wireless networks, which is too narrow of a context.

When would these options actually be correct?

C

In a scenario where the question asks about the role of logging in a system that uses a single sign-on (SSO) mechanism, one might argue that logging can reduce the need for repeated authentication prompts, thereby streamlining user access while still maintaining a record of actions.

D

In a different question context focused on Syslog configurations, if the question asked about the limitations of source restriction in environments where Syslog is disabled, option D could be correct, indicating that source restriction would not function properly without logging enabled.

E

In a different exam scenario focusing on security measures specifically for guest wireless networks, a question might ask about controls that are particularly relevant to that context. If the question specified that logging and source restriction are primarily implemented for guest networks, then option E could be correct.

Why candidates pick the wrong answer

C

Candidates may choose this option due to a misunderstanding of how logging and authentication interact, mistakenly believing that robust logging can substitute for the need to authenticate users before granting access.

D

Candidates may find this option tempting due to a misunderstanding of how logging and source restriction interact, leading them to believe that logging is a prerequisite for source restriction to function effectively.

E

Candidates may choose this option due to a misunderstanding that associates logging and source restriction primarily with guest networks, possibly because they recall seeing these controls implemented in such environments during practical experiences or training.

880
Drag & Drophard

Drag and drop the following steps into the correct order to configure a Cisco IOS-XE router as a DHCP relay agent and verify the DHCP DORA process for a client on a remote subnet. OPTIONS: A: Configure the ip helper-address command on the interface facing the client, then verify connectivity to the DHCP server, and finally capture the DORA process using debug ip dhcp relay. [CORRECT] B: Configure the ip helper-address command on the interface facing the DHCP server, then verify connectivity to the client, and finally capture the DORA process using debug ip dhcp server packet. C: Configure the ip dhcp relay information option command on the interface facing the client, then verify connectivity to the DHCP server, and finally capture the DORA process using debug ip dhcp server packet. D: Configure the ip helper-address command on the interface facing the client, then capture the DORA process using debug ip dhcp server packet, and finally verify connectivity to the DHCP server.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The relay agent must be configured first by setting the ip helper-address on the client-facing interface, then verifying connectivity to the DHCP server. The DORA process should be observed using a relay-specific debug command such as debug ip dhcp relay; the originally listed debug ip dhcp server packet would show no output on a pure relay agent, making it incorrect for verification. Therefore, only option A is correct.

Exam trap

A common trap is placing the ip helper-address on the wrong interface or using the wrong debug command. Always place the helper address on the client-facing interface, and verify relay operation with debug ip dhcp relay, not debug ip dhcp server packet.

Why candidates pick the wrong answer

B

Candidates might think the helper address should point toward the server, so they configure it on the server-facing interface.

C

Candidates may confuse DHCP relay commands with DHCP snooping or option 82 commands.

D

Candidates might think debugging can be done at any time, but proper troubleshooting order is to verify first.

881
MCQmedium

Which field is modified by each router hop in an IPv4 packet to prevent endless forwarding loops?

A.Source port
B.TTL
C.Sequence number
D.CRC in the Ethernet trailer
AnswerB

In IPv4, the Time-to-Live (TTL) field is set by the source and decremented by exactly one by every router that forwards the packet; when the counter reaches zero, the router drops the packet and sends an ICMP Time Exceeded message to the sender. This decrementing process is the standard hop-limit mechanism that prevents packets from circulating endlessly, and it is the only field in the IP header that each router modifies purely to manage network loop prevention.

Why this answer

The Time to Live field is decremented at each hop.

Exam trap

A frequent exam trap is selecting transport-layer fields like source port or sequence number as the field modified by each router hop. These fields are part of TCP or UDP headers and remain unchanged by routers during forwarding. Another common mistake is confusing the Ethernet frame CRC with the TTL; while the CRC is recalculated on each link to verify frame integrity, it does not control packet lifetime or prevent routing loops.

Misunderstanding these distinctions can lead to incorrect answers about how routers manage packet forwarding and loop prevention.

Why the other options are wrong

A

Source port is a transport-layer field used by TCP/UDP to identify application endpoints and is not modified by routers during forwarding, so it cannot prevent forwarding loops.

C

Sequence number is part of the transport layer used for ordering segments in TCP and is not altered by routers, so it does not affect packet forwarding or loop prevention.

D

CRC in the Ethernet trailer is recalculated on each link to verify frame integrity but does not influence IP packet forwarding decisions or prevent routing loops.

When would these options actually be correct?

A

In a question asking about the transport layer's role in establishing connections, such as 'Which field is used to identify a specific application on a host in a TCP segment?', the source port would be the correct answer.

C

If the question were about TCP packets specifically, asking which field is modified to ensure data is received in the correct order, then the sequence number would be the correct answer, as it is crucial for maintaining the integrity of the data stream.

D

If the exam question asked about fields modified in the data link layer or specifically about Ethernet frame structures, then 'CRC in the Ethernet trailer' could be correct as it would pertain to error detection in frames at that layer.

Why candidates pick the wrong answer

A

Candidates may confuse the source port with other fields that manage packet flow, mistakenly believing it plays a role in routing behavior, especially if they are thinking about connection-oriented protocols.

C

Candidates may confuse the sequence number with other fields that are modified during packet transmission, leading them to mistakenly believe it plays a role in routing decisions, especially if they have a basic understanding of TCP/IP protocols.

D

Candidates may confuse the role of CRC in ensuring data integrity with the need to manage packet forwarding, leading them to mistakenly think it relates to loop prevention.

882
MCQmedium

Which spanning-tree port role receives the best BPDU toward the root bridge on a nonroot switch?

A.Designated port
B.Alternate port
C.Root port
D.Disabled port
AnswerC

The root port is the switch port with the lowest path cost to the root bridge, making it the interface that receives the best BPDU (lowest root ID, lowest cost, etc.) on a non-root switch. It is the only port role that actively forwards traffic toward the root bridge, and its selection is based on superior spanning tree information. This port is the single forwarding path to the root, which directly matches the question's requirement of receiving the best BPDU toward the root.

Why this answer

The root port is the port on a nonroot switch with the lowest path cost to the root bridge.

Exam trap

Be careful not to confuse port roles. Remember, the root port is specifically for receiving the best BPDU toward the root bridge, not for forwarding or redundancy.

Why the other options are wrong

A

The designated port is responsible for forwarding traffic to and from a network segment and does not receive the best BPDU toward the root bridge; instead, it sends BPDUs to other ports. Therefore, it cannot be the correct answer for identifying the port role that receives the best BPDU on a nonroot switch.

B

The alternate port does not receive the best BPDU toward the root bridge; instead, it serves as a backup path to the root bridge when the primary path fails. It is in a blocking state and does not forward traffic.

D

A Disabled port does not participate in the Spanning Tree Protocol (STP) and does not receive any BPDUs, making it incapable of receiving the best BPDU toward the root bridge.

When would these options actually be correct?

A

In a different question asking which port role on a switch forwards traffic to the root bridge while also being the only port on a segment, the designated port would be the correct answer. This scenario would highlight its role in managing traffic flow toward the root bridge.

B

In a question asking which port role can transition to forwarding state if the primary root port fails, the alternate port would be the correct answer. This scenario would focus on redundancy and failover mechanisms in spanning tree protocols.

D

In a different question asking about the state of a port that is intentionally configured to not forward traffic and is administratively shut down, a Disabled port could be the correct answer, as it would be the only port state mentioned that does not participate in STP.

Why candidates pick the wrong answer

A

Candidates may confuse the roles of designated and root ports, as both are involved in the spanning tree process, leading them to mistakenly select the designated port due to its active role in forwarding traffic.

B

Candidates may confuse the alternate port's role in providing redundancy with its ability to receive BPDUs, leading them to mistakenly believe it is involved in the best path selection toward the root bridge.

D

Candidates may confuse Disabled ports with other port roles, thinking that any port state could potentially receive BPDUs, especially if they overlook the specific requirement of receiving the best BPDU.

883
Multi-Selectmedium

A network administrator is configuring a Cisco router to act as a DHCP server for a new VLAN. The router must provide IP addresses, default gateway, and DNS server information to clients. Which two commands are required in the DHCP pool configuration to provide the default gateway and DNS server to clients? (Choose two.)

Select 2 answers
A.network 10.1.1.0 255.255.255.0
B.default-router 10.1.1.1
C.dns-server 8.8.8.8
D.lease 0 8
E.ip helper-address 10.1.1.1
AnswersB, C

The default-router command in DHCP pool configuration specifies the default gateway address that will be provided to DHCP clients. In this scenario, it sets the gateway to 10.1.1.1, which is essential for clients to reach other networks. Without this command, clients would not receive a default gateway and could only communicate on the local subnet.

Why this answer

To provide default gateway and DNS server information to DHCP clients, the DHCP pool must include the default-router and dns-server commands. The default-router command supplies the gateway address, and the dns-server command supplies the DNS server address. The network command defines the pool subnet, the lease command sets lease time, and ip helper-address is used for DHCP relay, not for these parameters.

Exam trap

The trap here is mixing up the network command, which defines the pool, with the default-router and dns-server commands, which actually provide the gateway and DNS information.

884
PBQmedium

You are connected to SW1 via the console. SW1 is a Layer 2 switch connected to router R1 via trunk link G0/1. R1 performs inter-VLAN routing using subinterfaces. VLANs 10, 20, and 30 exist on SW1. Hosts in VLAN 10 (192.168.10.0/24) can ping R1's subinterface, but cannot communicate with hosts in VLAN 20. You suspect the trunk is not allowing VLAN 20 traffic.

Network Topology
G0/0.10192.168.10.1G0/1trunkR1SW1

Hints

  • •Check which VLANs are allowed on the trunk.
  • •The 'allowed vlan' command can be used to add or remove VLANs.
  • •Verify that VLAN 20 exists on the switch.
A.Configure 'switchport trunk allowed vlan add 20' on SW1's G0/1 interface.
B.Configure 'switchport mode access' on SW1's G0/1 interface.
C.Configure 'switchport trunk native vlan 20' on SW1's G0/1 interface.
D.Configure 'switchport trunk allowed vlan except 20' on SW1's G0/1 interface.
AnswerA
solution
! SW1
interface GigabitEthernet0/1
switchport trunk allowed vlan add 20

Why this answer

The symptom — VLAN 10 hosts can reach R1's subinterface but VLAN 20 hosts cannot communicate — points to VLAN 20 being pruned from the trunk. The correct fix is to add VLAN 20 to the trunk's allowed VLAN list on SW1's G0/1 interface using 'switchport trunk allowed vlan add 20', which preserves existing allowed VLANs while permitting VLAN 20. This restores 802.1Q tagging for VLAN 20 traffic across the trunk to R1.

Exam trap

200-301 often tests the misconception that configuring a native VLAN or changing port mode will fix VLAN reachability — candidates overlook that the allowed VLAN list on a trunk is exclusive once explicitly set and must be amended with the 'add' keyword.

Why the other options are wrong

B

Access mode carries only a single VLAN, so it would stop inter-VLAN routing entirely.

C

The native VLAN is for untagged frames; changing it does not add VLAN 20 to the allowed list.

D

The 'except' keyword excludes the specified VLAN, so it would prevent VLAN 20 from being carried.

Why candidates pick the wrong answer

B

Candidates might think changing the port mode will fix VLAN-specific issues, but it actually disables trunking.

C

Candidates confuse native VLAN configuration with allowed VLAN configuration, thinking it permits VLAN traffic.

D

Candidates might misread 'except' as 'include' or think it adds the VLAN, but it actually removes it.

885
PBQmedium

You are connected to SW1 via the console. SW1 is a Layer 2 switch with two VLANs: VLAN 10 (Sales) and VLAN 20 (Engineering). A router R1 is connected to port G0/1 on SW1 for inter-VLAN routing. Currently, the router is not routing between VLANs because the trunk is not configured correctly. Configure the switch port as a trunk and ensure the router can route between VLANs using subinterfaces (Router-on-a-Stick).

Network Topology
G0/0R1SW1 G0/1

Hints

  • •The router expects a trunk link to carry multiple VLANs.
  • •Allowed VLAN list must include only the VLANs that need routing.
  • •The switch port must be in trunk mode, not access.
A.Configure the switch port as a trunk with 802.1Q encapsulation and allow VLANs 10 and 20.
B.Configure the switch port as an access port in VLAN 10 and add VLAN 20 as a secondary VLAN.
C.Configure the switch port as a trunk with ISL encapsulation and allow all VLANs.
D.Configure the switch port as a trunk with 802.1Q encapsulation and allow VLANs 1, 10, and 20.
AnswerA
solution
! SW1
interface GigabitEthernet0/1
switchport trunk encapsulation dot1q
switchport mode trunk
switchport trunk allowed vlan 10,20

Why this answer

The switch port was in access mode, which only carries one VLAN. Changing it to trunk with 802.1Q encapsulation allows multiple VLANs to traverse to the router. The allowed VLAN list restricts to VLANs 10 and 20 for security.

Exam trap

The trap is that candidates may confuse trunking with access ports, use outdated encapsulation (ISL), or include unnecessary VLANs like VLAN 1. Always remember that for Router-on-a-Stick, the switch port must be a trunk with 802.1Q and only allow the required VLANs.

Why the other options are wrong

B

Access ports cannot carry multiple VLANs; they are assigned to a single VLAN. The concept of secondary VLAN does not exist for access ports.

C

ISL encapsulation is deprecated in favor of 802.1Q, which is the industry standard. Allowing all VLANs violates the principle of least privilege.

D

Including VLAN 1 is unnecessary and can be a security concern. The allowed VLAN list should be restricted to only the VLANs that need to be routed.

Why candidates pick the wrong answer

B

Candidates might think that an access port can be configured with multiple VLANs by using the 'switchport access vlan' command multiple times or by adding a secondary VLAN, which is a common misconception.

C

Candidates familiar with older Cisco equipment might recall ISL as a valid trunking method. Also, allowing all VLANs might seem simpler, but it is not best practice.

D

Candidates might think that VLAN 1 must always be allowed because it is the default VLAN, or they might include it out of habit without considering security implications.

886
Multi-Selectmedium

A network administrator is configuring a new switch and needs to set up VLANs. The administrator wants to ensure that VLAN 10 is used for voice traffic and VLAN 20 for data traffic on a port connected to an IP phone and a PC. Which two commands are required on the interface to achieve this configuration? (Choose two.)

Select 2 answers
A.switchport mode access
B.switchport voice vlan 10
C.switchport mode trunk
D.switchport trunk encapsulation dot1q
E.switchport access vlan 20
AnswersB, E

This command configures VLAN 10 as the voice VLAN. The IP phone will tag its voice traffic with VLAN 10, while data traffic from the PC remains untagged and is assigned to the access VLAN. This enables proper QoS and segmentation for voice.

Why this answer

To support both voice and data on a single port, the interface must be in access mode with a voice VLAN. The 'switchport access vlan 20' command assigns the data VLAN, and 'switchport voice vlan 10' assigns the voice VLAN. The phone tags voice traffic, while data traffic remains untagged.

Exam trap

The trap here is assuming that a trunk is needed for voice and data; however, Cisco's voice VLAN feature allows an access port to carry both by tagging voice traffic.

887
MCQhard

The SVI for VLAN 20 has `ip nat outside` and the WAN interface has `ip nat inside`. Hosts in VLAN 20 must reach the internet through PAT, but users report no external connectivity. Which configuration issue best explains the problem?

A.The ACL should deny 192.168.20.0/24 instead of permit it
B.The interfaces are marked with inside and outside in the wrong places
C.PAT cannot be used with a /30 WAN link
D.NAT overload requires a route-map instead of an ACL
AnswerB

When PAT is configured, Cisco IOS identifies traffic to translate based on the inside and outside interface roles. If those labels are swapped, traffic arriving from the campus LAN appears on the 'outside' interface, so it is not considered an 'inside local' source and the translation rule does not trigger. As a result, packets are forwarded without translation and hosts on VLAN 20 cannot reach the internet through PAT. The fix is to mark the LAN-facing interface as 'inside' and the WAN-facing interface as 'outside' so the NAT process operates in the correct direction.

Why this answer

NAT overload works only when the inside and outside interfaces are identified correctly. Here the roles are reversed, so translations are not built in the right direction.

Exam trap

A frequent exam trap is assuming that the ACL or the subnet mask is the cause of NAT failure when the real issue is reversed inside and outside interface roles. Candidates often overlook the importance of interface designation commands (ip nat inside and ip nat outside), which are crucial for NAT operation. Without correct interface roles, the router cannot translate addresses properly, causing hosts to lose external connectivity even if ACLs and routing are correct.

This trap is tempting because ACLs and subnetting are more familiar concepts, but interface roles are equally critical for NAT to function.

Why the other options are wrong

A

Option A is incorrect because the ACL used for NAT must permit the inside local subnet (192.168.20.0/24) to allow translation. Denying this subnet would block NAT translation, but the question states the ACL permits it, so this is not the cause.

C

Option C is incorrect because a /30 WAN link is commonly used in point-to-point connections and does not prevent PAT from functioning. PAT works independently of the WAN subnet size.

D

Option D is incorrect because NAT overload can be configured using a standard ACL; a route-map is optional and not required. The absence of a route-map does not cause the connectivity issue described.

When would these options actually be correct?

A

In a different scenario where the question specifies that traffic from the 192.168.20.0/24 subnet should be blocked for security reasons, and the goal is to restrict access to certain external resources, then denying this subnet would be the correct answer.

C

In a different scenario, if a question states that a network is configured with a /30 WAN link and asks whether PAT can be implemented, the correct answer would be that PAT cannot be used due to the lack of available IP addresses for translation, making this option valid.

D

In a different scenario where the question specifies that advanced traffic management is needed for NAT overload, and the use of a route-map is explicitly required to match specific traffic types or conditions, this option would be correct. For example, if the question involved complex routing policies that necessitate route-maps for NAT configurations.

Why candidates pick the wrong answer

A

Candidates may choose this option due to a misunderstanding of ACL functionality, thinking that denying the VLAN subnet could be a straightforward solution to connectivity issues without fully analyzing the NAT configuration.

C

Candidates may be tempted by this option due to a misunderstanding of NAT and PAT limitations, particularly in relation to subnet sizes and their implications for address translation, leading them to incorrectly assume a /30 subnet is incompatible with PAT.

D

Candidates may be tempted by this option due to confusion between basic NAT configurations and more advanced routing techniques, leading them to believe that a route-map is necessary for all forms of NAT, including PAT.

888
PBQmedium

You are connected to R1 via console. R1 connects three subnets: 10.0.1.0/24 (area 0), 10.0.2.0/24 (area 0), and 10.0.3.0/24 (area 0). The serial link to R2 uses IP subnet 10.0.0.0/30 and is in OSPF area 1. The network administrator wants to advertise a single summary route for these three subnets to R2, reducing the OSPF link-state database size in area 1. R1 is already running OSPF with network statements for its connected subnets in their respective areas. You need to configure route summarization on R1 so that only the summary route is advertised to R2 via the serial link.

Hints

  • •Summarization in OSPF is configured under the router ospf process using the area range command.
  • •The summary route must cover all subnets with a single prefix.
  • •Verify that the summary route appears in the OSPF database as a type 3 summary LSA.
A.router ospf 1 area 0 range 10.0.0.0 255.255.252.0
B.router ospf 1 summary-address 10.0.0.0 255.255.252.0
C.interface serial 0/0/0 ip summary-address ospf 1 10.0.0.0 255.255.252.0
D.router ospf 1 area 0 range 10.0.0.0 255.255.255.0
AnswerA
solution
! R1
router ospf 1
area 0 range 10.0.0.0 255.255.252.0

Why this answer

The 'area 0 range' command creates a summary route for the specified range, which is then advertised as a type 3 summary LSA to other areas. This reduces routing table size and prevents flapping.

Exam trap

Be careful not to confuse OSPF summarization commands with those of other routing protocols. OSPF uses 'area range' for internal summarization and 'summary-address' for external routes, while EIGRP uses 'summary-address' on interfaces. Also, ensure you calculate the correct summary mask that covers all subnets without being too broad or too specific.

Why the other options are wrong

B

The 'summary-address' command is not valid for OSPF; it is used in EIGRP and BGP.

C

The 'ip summary-address ospf' command is used for external route summarization, not for summarizing internal OSPF routes within an area.

D

The mask 255.255.255.0 is too specific and only covers a single /24 network, not the required range.

Why candidates pick the wrong answer

B

Candidates may confuse OSPF summarization with EIGRP summarization, as both protocols use similar concepts but different commands.

C

Candidates might think that summarization is configured on the interface facing the upstream router, but OSPF internal summarization is done at the area level, not per interface.

D

Candidates may mistakenly use a /24 mask thinking it summarizes the subnets, but they need to calculate the correct prefix length that covers all subnets.

889
MCQmedium

A network administrator is configuring a switch port that connects to a Cisco IP phone, which in turn has a desktop PC attached to its PC port. The administrator wants the phone to be placed in VLAN 100 and the PC in VLAN 200 on the same physical switch port. Which configuration should be applied to the switch port?

A.Configure the port as a trunk port and allow VLAN 100 and VLAN 200 on the trunk.
B.Configure the port as an access port in VLAN 100 and enable the voice VLAN 100 on the port.
C.Configure the port as a dynamic auto port and enable VLAN 100 and VLAN 200 with the switchport trunk allowed vlan command.
D.Configure the port as an access port in VLAN 200 and configure the voice VLAN as 100 using the switchport voice vlan 100 command.
AnswerD

This is the correct configuration for a Cisco IP phone with a PC attached. The access VLAN (200) carries untagged data traffic from the PC, while the voice VLAN (100) carries tagged voice traffic from the phone. The switchport voice vlan command enables the phone to receive its VLAN information via CDP or LLDP-MED and tag voice frames appropriately.

Why this answer

The correct approach uses an access port for the PC data VLAN and the switchport voice vlan command for the phone voice VLAN. This allows the phone to tag voice traffic with VLAN 100 while the PC sends untagged traffic in VLAN 200. The phone learns the voice VLAN through CDP or LLDP-MED and can also pass through the PC data.

Exam trap

The trap here is assuming that a trunk port is required to support both a voice and data VLAN on a single switch port.

890
Drag & Dropmedium

Drag and drop the following steps into the correct order to sequence the DNS resolution process from a client query to receiving an A-record response, followed by the nslookup and dig diagnostic workflow for troubleshooting missing or wrong DNS records.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The DNS resolution process starts with the client query, server response, and client use. Troubleshooting follows with nslookup for basic queries and dig for detailed diagnostics.

Exam trap

Do not confuse the order of DNS resolution with the troubleshooting workflow. The client uses the IP address immediately after receiving the response; troubleshooting tools are used only when there is a problem.

Why candidates pick the wrong answer

B

Candidates might think dig is more powerful and should be used first, but the standard workflow is to start with simpler tools.

C

Candidates might confuse the order of events, thinking the client uses the IP address immediately after sending the query.

D

Candidates might think troubleshooting is part of the normal resolution process, but it is only done when there is an issue.

891
Multi-Selectmedium

Which TWO of the following statements accurately describe the configuration and behavior of Root Guard, Loop Guard, and BPDU Guard in Rapid PVST+ environments?

Select 2 answers
A.Root Guard, when enabled on a port, prevents that port from becoming the root port by placing it in a root-inconsistent state if a superior BPDU is received.
B.Root Guard automatically shuts down the port when a superior BPDU is received, similar to BPDU Guard.
C.Loop Guard, when enabled, disables a port if BPDUs are no longer received on it, preventing a unidirectional link failure.
D.BPDU Guard, when enabled, puts the port in an errdisable state if a BPDU is received, which is typically used on access ports to prevent unauthorized switches from connecting.
E.BPDU Guard places the port in a blocking state (loop-inconsistent) when a BPDU is received, similar to Loop Guard.
AnswersA, D

Root Guard, enabled on a designated port, does not prevent the switch from receiving a superior BPDU; instead, it reacts by moving the port into a root-inconsistent state, which blocks all traffic on that port while the superior BPDU continues to arrive. Once the superior BPDUs stop, the port automatically returns to its normal designated role. This behavior keeps an unauthorized switch from becoming the root bridge, but it does not disable the port or require manual intervention.

Why this answer

Root Guard prevents a port from becoming a root port by placing it in a root-inconsistent (blocking) state upon receiving a superior BPDU, protecting the root bridge placement. Option D is correct because BPDU Guard errdisables a port upon receiving a BPDU, a feature typically applied to access ports to block unauthorized switches. Option B is wrong: Root Guard does not shut down the port; it places it in a blocked state, unlike BPDU Guard's errdisable action.

Option C is wrong: Loop Guard does not disable a port when BPDUs stop being received; instead, it moves the port to a loop-inconsistent (blocking) state to guard against unidirectional link failures. Option E is wrong: BPDU Guard errdisables ports, whereas the loop-inconsistent blocking state is used by Loop Guard or Root Guard, not BPDU Guard.

Exam trap

Cisco often tests the distinction between 'shutdown' (errdisable) and 'blocking' (inconsistent state) — candidates confuse BPDU Guard's errdisable behavior with Root Guard's or Loop Guard's blocking behavior, leading them to incorrectly select Option B.

Why the other options are wrong

B

Root Guard does not shut down the port; it places the port in a root-inconsistent state, which effectively blocks traffic but does not disable the port. BPDU Guard, on the other hand, errdisables the port.

C

Loop Guard does not disable the port; it places the port into a loop-inconsistent state, blocking traffic on that port until BPDUs are received again. The port remains administratively up.

E

BPDU Guard errdisables the port, not just blocks it. Loop Guard uses a loop-inconsistent state, which is different from errdisable. BPDU Guard is a more severe reaction.

892
MCQhard

After hardening SSH by disabling password authentication and restricting access to an ACL permitting only the management subnet 10.1.10.0/24, configuring RADIUS AAA authentication, enabling port security with a maximum of two MAC addresses on all access ports, and implementing DHCP snooping and DAI on VLAN 10, the administrator finds that users in VLAN 10 obtain DHCP addresses and access the network normally, but SSH from the management workstation (10.1.10.20) to the switch fails with timeouts.

A.The SSH ACL is misconfigured and denies port 22 from the management subnet.
B.The management workstation’s IP-to-MAC binding is missing from the DHCP snooping binding table, causing DAI to drop its ARP traffic.
C.Port security on the switch interface connected to the management workstation has learned two MAC addresses and shut down the port.
D.RADIUS AAA authentication is missing the shared secret on the switch, causing SSH login timeouts.
AnswerB

Dynamic ARP Inspection (DAI) validates ARP packets against the DHCP snooping binding table, which contains IP-to-MAC mappings learned from DHCP. Because the management workstation uses a static IP address, no DHCP binding is ever recorded, so the switch has no entry for that IP. As a result, DAI classifies the workstation's ARP replies as invalid and drops them, preventing L2 reachability. This matches the symptom precisely: only the statically configured host fails, while DHCP-assigned management hosts continue to work normally.

Why this answer

The management workstation (10.1.10.20) is on the same VLAN 10 where DHCP snooping and DAI are enabled. DAI validates ARP packets against the DHCP snooping binding table. Since the workstation uses a static IP address, its IP-to-MAC binding is not automatically added to the DHCP snooping database.

DAI will drop the workstation's ARP replies, preventing the switch from learning its MAC address and causing SSH timeouts.

Exam trap

Cisco often tests the interaction between security features like DAI and static IP hosts, where candidates overlook that DAI requires explicit static bindings for non-DHCP clients, leading to connectivity failures that appear as timeouts rather than explicit denials.

Why the other options are wrong

A

Misunderstanding ACL processing—assumes a simple subnet permit ACL would block port 22 by default, but the ACL entry permits all traffic from the subnet, not just specific ports.

C

Assumes port security is the first cause of connectivity failure when MAC limits are configured, but the symptom does not indicate a port security violation; the port would need to go into err-disabled, which is not mentioned.

D

AAA failures manifest as authentication errors or prompts that time out after attempting RADIUS, but they typically affect all attempts, not a single source, unless combined with ACLs that permit other hosts but block this one.

893
PBQhard

You are connected to R1 (192.0.2.1/24, management IP). The network team needs to automate interface configuration using RESTCONF. Construct a valid RESTCONF GET request to retrieve the operational status of GigabitEthernet0/1 using the ietf-interfaces YANG module, and a PATCH request to set the description of that interface to 'Link to R2' using the Cisco-IOS-XE-native YANG module. Identify the error that occurs if the Accept header is set to application/json instead of application/yang-data+json.

Network Topology
G0/0192.0.2.1/24G0/010.0.0.2/30G0/1 (10.0.0.1/30)R1R2

Hints

  • •RESTCONF uses a specific media type for YANG data; check the Accept header.
  • •The YANG module paths differ between ietf-interfaces and Cisco-IOS-XE-native.
  • •The interface name must be URL-encoded if it contains special characters; GigabitEthernet0/1 is safe.
A.The server returns a 406 Not Acceptable error because RESTCONF requires the Accept header to be 'application/yang-data+json'.
B.The server returns a 400 Bad Request error because the Accept header must be 'application/json' for RESTCONF.
C.The server returns a 415 Unsupported Media Type error because the Accept header is set incorrectly.
D.The server returns a 200 OK response but ignores the Accept header and returns data in XML format.
AnswerA
solution
! R1
GET request: GET https://192.0.2.1/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet0/1 HTTP/1.1
Headers: Host: 192.0.2.1, Accept: application/yang-data+json
PATCH request: PATCH https://192.0.2.1/restconf/data/Cisco-IOS-XE-native:native/interface/GigabitEthernet=0/1/description HTTP/1.1
Headers: Host: 192.0.2.1, Content-Type: application/yang-data+json, Accept: application/yang-data+json
Body: {"description": "Link to R2"}

Why this answer

The correct base URI for RESTCONF on Cisco IOS-XE is https://<device-ip>/restconf/data. For the ietf-interfaces module, the YANG path is /ietf-interfaces:interfaces/interface=GigabitEthernet0%2F1 (note the percent-encoded slash in the key). For the Cisco-IOS-XE-native module, the path is /Cisco-IOS-XE-native:native/interface/GigabitEthernet=0%2F1/description.

The Accept header must be 'application/yang-data+json'; using 'application/json' returns a 406 Not Acceptable error. The PATCH request body must contain the new description in JSON format. Failing to percent-encode the interface name will result in an invalid URI.

Exam trap

The exam tests your knowledge of RESTCONF media types and URL encoding: remember to percent-encode the slash in interface names (e.g., GigabitEthernet0%2F1) and distinguish between 406 (Accept error) and 415 (Content-Type error).

Why the other options are wrong

B

The specific factual error: RESTCONF requires 'application/yang-data+json', not 'application/json'.

C

The specific factual error: 415 relates to Content-Type, not Accept. Accept errors yield 406.

D

The specific factual error: RESTCONF does not silently fall back; it returns a 406 error.

Why candidates pick the wrong answer

B

Candidates might think 'application/json' is acceptable because JSON is commonly used, but RESTCONF mandates a specific media type.

C

Candidates may confuse Accept and Content-Type headers, thinking both cause 415 errors.

D

Candidates might assume the server is lenient and will respond with a default format, but RESTCONF is strict about media types.

894
MCQhard

Exhibit: SW1 is configured for EtherChannel with LACP, but the bundle does not form. What is the most likely cause?

A.The interfaces should use PAgP instead of LACP on both ends
B.One side is using LACP and the other side is using a static EtherChannel mode
C.The links must be routed ports before EtherChannel can form
D.EtherChannel requires three or more member links
AnswerB

The correct explanation is that EtherChannel will not form because the interface configurations are incompatible: one side is running LACP in active mode, which sends LACP PDUs to negotiate a channel, while the other side is configured with a static mode (mode on), which does not send or process LACP PDUs. Without LACP negotiation from both peers, the switch sees no valid LACP partner and refuses to bundle the links. To fix this, both ends must use LACP (active/passive) or both must use static mode.

Why this answer

For an LACP EtherChannel to form, both sides must negotiate with LACP using active or passive mode. One side here is set to channel-group mode on, which creates a static channel and does not speak LACP. That mismatch prevents the bundle from forming.

Exam trap

Ensure both sides of the EtherChannel are set to negotiate with LACP; avoid static channel settings.

Why the other options are wrong

A

This option is incorrect because the question specifies that LACP is being used, which is incompatible with PAgP. EtherChannel can operate with either LACP or PAgP, but not both simultaneously.

C

This option is wrong because EtherChannel can form with access ports or trunk ports, and there is no requirement for the interfaces to be routed ports for EtherChannel to function.

D

EtherChannel can function with as few as two member links; therefore, requiring three or more member links is not a valid reason for the bundle not forming in this scenario.

When would these options actually be correct?

A

In a different scenario where a question asks about a misconfiguration in an EtherChannel setup using PAgP, if both ends of the connection were configured for PAgP instead of LACP, then this option would be correct. For example, if a question stated that both ends were set to PAgP and the bundle failed to form, this would be a valid reason.

C

If the question specified that the interfaces were configured as routed ports and required to form an EtherChannel, then this option would be correct. In that scenario, the exam would be testing knowledge on the prerequisites for EtherChannel formation specifically related to port types.

D

In a different question context where the exam specifies that an EtherChannel configuration must include at least three links for proper operation, option D would be correct. For example, a question could state that a network engineer is attempting to configure an EtherChannel with only two links and is encountering issues.

Why candidates pick the wrong answer

A

Candidates may be tempted by this option because they might confuse EtherChannel protocols and assume that if one protocol fails, another must be the solution, leading them to overlook the specific protocol in use.

C

Candidates may choose this option due to a common misconception that EtherChannel only works with Layer 2 interfaces, leading them to incorrectly believe that routed ports are incompatible with EtherChannel configurations.

D

Candidates may be misled by the common belief that more links enhance redundancy and performance, leading them to think that a minimum number of links is required for EtherChannel to work.

895
PBQhard

You are connected to R1 via the console. The network currently uses EIGRP as its IGP, but you recently configured a static default route toward R2 (next-hop 203.0.113.2) to reach the Internet. However, traffic from R1 to the Internet is not taking the expected path. Examine the provided routing table and partial configuration, then fix the issue so that the static default route is used only when the EIGRP-learned default route is unavailable.

Network Topology
G0/010.0.0.1/30G0/010.0.0.2/30G0/1203.0.113.1/30203.0.113.2/30R1R2ISP

Hints

  • •Compare the administrative distances of the two default routes in the routing table.
  • •The static route currently has a lower AD (1) than EIGRP (90), so it is not acting as a backup.
  • •To make a static route a floating static, you need to configure an AD higher than the dynamic protocol's AD.
A.Configure the static route with an administrative distance of 100 using 'ip route 0.0.0.0 0.0.0.0 203.0.113.2 100'.
B.Remove the EIGRP default route by configuring 'no network 0.0.0.0' under the EIGRP process.
C.Increase the metric of the EIGRP default route to make it less preferred than the static route.
D.Configure the static route with a next-hop of 203.0.113.2 and a metric of 100.
AnswerA
solution
! R1
configure terminal
no ip route 0.0.0.0 0.0.0.0 203.0.113.2 10
ip route 0.0.0.0 0.0.0.0 203.0.113.2 100
end
write memory

Why this answer

The static default route was configured with an administrative distance (AD) of 10, which is lower than the EIGRP‑learned default route's AD of 90. This made the static route the preferred path, overriding the intended primary EIGRP route. To create a floating static route that only activates when the EIGRP route disappears, the static AD must be raised above 90—using 'ip route 0.0.0.0 0.0.0.0 203.0.113.2 100' ensures the EIGRP route is primary.

Option B is wrong because removing the EIGRP route eliminates the preferred path entirely, defeating the backup purpose. Option C fails because EIGRP metrics are irrelevant against a lower‑AD static route; AD dictates route source preference. Option D is incorrect because static routes do not accept a metric parameter—the trailing number sets the AD, not a metric.

Exam trap

Don't confuse administrative distance with metric. When comparing routes from different sources (static vs. EIGRP), AD is the deciding factor.

Also, remember that static routes use AD, not metric, to influence preference. The 'ip route' command syntax does not include a metric parameter.

Why the other options are wrong

B

The specific factual error: EIGRP does not use 'network 0.0.0.0' to advertise a default route; default routes are typically redistributed or generated via 'ip default-network' or redistribution. Removing the EIGRP default route would break the intended primary path.

C

The specific factual error: Administrative distance is the primary factor for route selection between different routing protocols or sources. Changing the EIGRP metric does not affect the comparison with a static route.

D

The specific factual error: The 'ip route' command syntax is 'ip route prefix mask {next-hop | interface} [distance] [name] [permanent] [tag tag]'. There is no metric parameter. The correct way to make a static route less preferred is to set a higher administrative distance.

Why candidates pick the wrong answer

B

Candidates might think removing the EIGRP route would force the static route to be used, but this does not achieve the desired redundancy and violates the requirement to keep the EIGRP route as primary.

C

Candidates often confuse metric with administrative distance, thinking that a higher metric makes a route less preferred. However, metric only applies within the same routing protocol.

D

Candidates may think that since EIGRP uses metric, they can set a metric on the static route to make it less preferred, but this is not supported. They might also confuse metric with administrative distance.

896
Multi-Selectmedium

Which TWO statements correctly describe the encapsulation process at the OSI model Transport layer?

Select 2 answers
A.It adds source and destination IP addresses to the data.
B.It breaks data into smaller units called segments (for TCP) or datagrams (for UDP).
C.It adds a header that includes source and destination MAC addresses.
D.It adds a header that includes source and destination port numbers.
E.It converts data into bits for transmission over the physical medium.
AnswersB, D

The Transport layer accepts data from upper layers and divides it into appropriately sized units for transmission. For TCP, these units are called segments, and for UDP, they are datagrams. This segmentation enables efficient network usage, and TCP further assigns sequence numbers to these units so the receiving host can reorder them correctly and request retransmission of missing data. This is a fundamental Transport layer role, ensuring that upper-layer data is properly prepared for network delivery.

Why this answer

At the Transport layer (Layer 4), TCP segments data into segments and UDP segments data into datagrams. This segmentation allows efficient transmission and reassembly at the destination. The Transport layer header includes source and destination port numbers to identify the communicating applications, not IP or MAC addresses.

Exam trap

Cisco often tests the distinction between OSI model layers, and the trap here is confusing the Transport layer's port numbers and segmentation with the Network layer's IP addressing or the Data Link layer's MAC addressing.

Why the other options are wrong

A

The Transport layer uses port numbers, not IP addresses. IP addresses are added during Network layer encapsulation.

C

MAC addresses are used for local delivery on a network segment and are part of Layer 2 encapsulation.

E

The Physical layer handles the actual transmission of raw bits over the network medium.

897
MCQmedium

Which IPv6 protocol function replaces ARP?

A.DHCPv6
B.Neighbor Discovery
C.EUI-64
D.SLAAC
AnswerB

Neighbor Discovery (ND) replaces ARP by using ICMPv6 Neighbor Solicitation and Neighbor Advertisement messages to dynamically resolve IPv6 addresses to link-layer MAC addresses. It also handles router discovery, prefix discovery, and duplicate address detection, making it the core protocol for link-local interactions in IPv6. ND tracks neighbor reachability state in the neighbor cache, just as ARP did in IPv4.

Why this answer

IPv6 uses Neighbor Discovery Protocol to resolve Layer 3-to-Layer 2 information and perform related local-link functions such as router discovery and address resolution.

Exam trap

Be careful not to confuse protocols that manage IP addresses or routing with those that resolve addresses.

Why the other options are wrong

A

DHCPv6 is not a protocol that replaces ARP; instead, it is used for assigning IP addresses and configuration information to IPv6 devices. ARP is replaced by the Neighbor Discovery Protocol in IPv6, which performs similar functions for address resolution.

C

EUI-64 is not a protocol but a method for generating IPv6 interface identifiers. It does not perform the function of resolving link-layer addresses like ARP does in IPv4.

D

SLAAC (Stateless Address Autoconfiguration) is a method for automatically configuring IPv6 addresses but does not perform the function of resolving link-layer addresses like ARP does in IPv4. Therefore, it cannot replace ARP in IPv6.

When would these options actually be correct?

A

If the exam question asked about protocols involved in IPv6 address assignment or configuration, such as 'Which protocol is responsible for dynamically assigning IPv6 addresses to devices?', then DHCPv6 would be the correct answer.

C

If the exam question asked about methods for generating IPv6 addresses or identifiers, specifically in the context of creating unique addresses from MAC addresses, then EUI-64 would be the correct answer.

D

If the exam question asked which protocol is responsible for automatically configuring IPv6 addresses without requiring a DHCP server, then SLAAC would be the correct answer. This would focus on address assignment rather than address resolution.

Why candidates pick the wrong answer

A

Candidates may find DHCPv6 tempting because it is a well-known protocol associated with IP address management, leading them to mistakenly associate it with the address resolution functions that ARP performed in IPv4.

C

Candidates may confuse EUI-64 with address resolution functions due to its association with IPv6 addressing, leading them to mistakenly believe it plays a role similar to ARP.

D

Candidates might choose SLAAC because it is associated with IPv6 address configuration, leading to confusion between address assignment and address resolution functions, making it seem relevant to the question.

898
PBQhard

You are connected to a multilayer switch MLS1. The network has two other switches: SW2 and SW3. The interface GigabitEthernet0/1 already has PortFast and BPDU Guard enabled. Configure MLS1 as the root bridge for VLAN 10 and VLAN 20 using the root primary command. After configuration, verify that the interface is not in err-disabled state and that the root bridge role is correctly assigned.

Network Topology
Gi0/1Gi0/2Gi0/3SiMLS1PCSW2SW3

Hints

  • •Use spanning-tree vlan root primary to set the switch as root for specified VLANs.
  • •Verify with show spanning-tree vlan <vlan> to confirm root bridge priority is 24576.
  • •Check interface status with show interfaces gigabitethernet 0/1 status to ensure it is not err-disabled.
A.Configure 'spanning-tree vlan 10 root primary' and 'spanning-tree vlan 20 root primary' on MLS1. Verify with 'show spanning-tree vlan 10' and 'show interfaces gigabitEthernet0/1 status'.
B.Configure 'spanning-tree vlan 10 root primary' and 'spanning-tree vlan 20 root secondary' on MLS1. Verify with 'show spanning-tree vlan 10' and 'show interfaces gigabitEthernet0/1 status'.
C.Configure 'spanning-tree vlan 10 priority 4096' and 'spanning-tree vlan 20 priority 4096' on MLS1. Verify with 'show spanning-tree vlan 10' and 'show interfaces gigabitEthernet0/1 status'.
D.Configure 'spanning-tree vlan 10 root primary' and 'spanning-tree vlan 20 root primary' on MLS1. Then configure 'spanning-tree portfast default' and 'spanning-tree bpduguard default' globally. Verify with 'show spanning-tree vlan 10' and 'show interfaces gigabitEthernet0/1 status'.
AnswerA
solution
! MLS1
spanning-tree vlan 10 root primary
spanning-tree vlan 20 root primary

Why this answer

The interface Gi0/1 already has PortFast and BPDU Guard configured, so no additional configuration is needed for that step. Using 'spanning-tree vlan 10 root primary' and 'spanning-tree vlan 20 root primary' sets the priority to 24576, ensuring MLS1 becomes root for both VLANs. Verify with 'show spanning-tree vlan 10' to see the priority changed and 'show interfaces gigabitEthernet0/1 status' to confirm the port is not err-disabled.

Exam trap

Do not confuse 'root primary' with 'root secondary' or manual priority settings. The 'root primary' command automatically sets the priority to 24576, which is the recommended value. Also, avoid adding unnecessary global commands when the interface already has the required features configured.

Why the other options are wrong

B

Using 'root secondary' for VLAN 20 sets priority to 28672, leaving MLS1 as backup root, not the primary root.

C

Manually setting priority to 4096 is valid but not the recommended method; 'root primary' is simpler and ensures proper value.

D

Global portfast and bpduguard are not required because the interface is already configured with those features; this adds unnecessary commands.

Why candidates pick the wrong answer

B

Candidates may confuse 'root primary' and 'root secondary', thinking both are needed for redundancy, but the requirement is for MLS1 to be the root, not a backup.

C

Candidates might think manually setting a low priority is equivalent to 'root primary', but the command is a best practice and ensures proper operation with other switches.

D

Candidates might think global configuration is a best practice, but the question specifies the interface already has these features enabled, so additional configuration is unnecessary and could be counterproductive.

899
Multi-Selectmedium

Which two statements accurately describe APIs in network automation?

Select 2 answers
A.APIs provide a defined way for software systems to interact.
B.APIs can be used by automation tools to retrieve data or request changes.
C.APIs eliminate all need for authentication.
D.APIs are a form of Ethernet duplex setting.
E.APIs are only valid on devices running Telnet.
AnswersA, B

An API (Application Programming Interface) defines a contract of protocols, request/response formats, and rules that allows software components to communicate and exchange data. In networking, this abstraction lets a client application interact with a network device or controller without needing to know the device's internal command syntax or OS details. For example, a REST API uses HTTP methods like GET and POST to retrieve or alter network state, making the interaction standardized and machine-readable.

Why this answer

APIs (Application Programming Interfaces) define a standardized, structured method for software systems to communicate, enabling network automation tools to programmatically retrieve operational data or push configuration changes. This eliminates the need for manual CLI or SNMP interactions, allowing scalable and repeatable automation workflows. Options A and B correctly describe this.

Option C is false because APIs require authentication; they do not bypass security. Option D is false because APIs are software interfaces, not Ethernet duplex settings. Option E is false because APIs work over various protocols (e.g., HTTP/HTTPS), not just Telnet.

Exam trap

Cisco often tests the misconception that APIs bypass security, but in reality, APIs enforce authentication and authorization just as strictly as CLI or SNMP.

Why the other options are wrong

C

This option is incorrect because APIs typically require authentication to ensure secure access and prevent unauthorized use, which is a fundamental aspect of API design.

D

APIs are not related to Ethernet duplex settings; they are software interfaces that enable communication between different applications or systems. This option misrepresents the fundamental purpose of APIs in network automation.

E

APIs are not limited to devices running Telnet; they can be implemented on various platforms and protocols, including HTTP and REST, which are widely used in modern network automation.

When would these options actually be correct?

C

If the exam question stated that it was referring to a hypothetical API in a controlled environment where all users are trusted and no sensitive data is handled, then the statement could be considered correct as authentication might be deemed unnecessary.

D

If the exam question asked about network protocols or physical layer characteristics, such as 'What are the different types of Ethernet configurations?' then stating that APIs are a form of Ethernet duplex setting could be correct in a context where the question is misleadingly framed to confuse API functionality with network hardware settings.

E

If the exam question specified that it was discussing legacy network devices or specific protocols that only support Telnet, then stating that APIs are valid only on devices running Telnet could be correct in that narrow context.

Why candidates pick the wrong answer

C

Candidates may choose this option due to a misunderstanding of API functionality, mistakenly believing that APIs simplify interactions to the point of eliminating security measures like authentication.

D

Candidates may confuse the term 'API' with networking concepts they are familiar with, leading them to mistakenly associate it with Ethernet settings, especially if they have limited experience with APIs in network automation.

E

Candidates may choose this option due to a misunderstanding of legacy network protocols, mistakenly believing that APIs are exclusively tied to Telnet, which is a common protocol for remote device management.

900
PBQhard

You are connected to R1. Configure OSPFv2 on R1 and R2 so that they form a full adjacency and can exchange routes. The current configuration has mismatched hello/dead timers blocking the adjacency. Adjust only the necessary settings on R1 to match R2's OSPF timers.

Network Topology
G0/0192.0.2.1/30G0/0192.0.2.2/30linkR1R2

Hints

  • •Check the OSPF interface timers on both routers using 'show ip ospf interface'.
  • •The dead interval must be exactly four times the hello interval unless manually set.
  • •Use the 'ip ospf hello-interval' and 'ip ospf dead-interval' commands under the interface configuration.
A.Configure 'ip ospf hello-interval 5' and 'ip ospf dead-interval 20' on R1's GigabitEthernet0/0 interface.
B.Configure 'ip ospf hello-interval 10' and 'ip ospf dead-interval 40' on R2's interface to match R1's default timers.
C.Configure 'ip ospf hello-interval 5' on R1's GigabitEthernet0/0 interface only; the dead interval will adjust automatically.
D.Configure 'ip ospf dead-interval 20' on R1's GigabitEthernet0/0 interface only; the hello interval will adjust automatically.
AnswerA
solution
! R1
interface gigabitethernet0/0
ip ospf hello-interval 5
ip ospf dead-interval 20

Why this answer

The adjacency between R1 and R2 is not forming because the OSPF hello and dead timers are mismatched. R1 has default timers (Hello 10, Dead 40) while R2 has custom timers (Hello 5, Dead 20). To form an adjacency, OSPF timers must match on both ends.

On R1, you need to configure the OSPF interface timers to match R2 by issuing 'ip ospf hello-interval 5' and 'ip ospf dead-interval 20' on interface GigabitEthernet0/0. After applying these commands, the adjacency should come up.

Exam trap

A common trap is assuming that changing only the hello interval will automatically adjust the dead interval, or vice versa. In Cisco IOS, these timers are independent and must be set explicitly. Also, note that the dead interval must be at least four times the hello interval, but that relationship is not enforced automatically.

Why the other options are wrong

B

The specific factual error is that the instruction limits changes to R1 only; modifying R2 is not allowed.

C

The specific factual error is that the dead interval is not automatically derived from the hello interval; it must be set separately.

D

The specific factual error is that the hello interval is not automatically derived from the dead interval; both must be set explicitly.

Why candidates pick the wrong answer

B

Candidates might think it's acceptable to change either router, but the question restricts adjustments to R1.

C

Candidates may recall that the dead interval is typically four times the hello interval and assume it adjusts automatically, but Cisco IOS requires explicit configuration.

D

Candidates may assume that setting the dead interval alone will cause the hello interval to adjust proportionally, but this is not the case in Cisco IOS.

Page 11

Page 12 of 20

Page 13