Courseiva

CCNA 200-301 v2 (200-301) — Questions 901–975

1450 questions total · 20pages · All types, answers revealed

Page 12

Page 13 of 20

Page 14
901
MCQeasy

An engineer receives API output that starts with curly braces and contains name-value pairs. Which data format is being used?

A.YANG
B.JSON
C.Syslog
D.SMTP
AnswerB

A payload that begins with a curly brace is the signature of a JSON object. JSON (JavaScript Object Notation) is a lightweight, language-independent data-interchange format in which data is organized as key-value pairs within braces. REST APIs commonly return JSON, and the very first character being '{' confirms the representation is a JSON document rather than a flat text or structured binary format.

Why this answer

JSON represents data as objects and arrays using braces, brackets, and name-value pairs. It is the most common format you will see in modern network APIs.

Exam trap

A frequent exam trap is mistaking YANG for the data format when seeing curly braces and name-value pairs. YANG is a modeling language that defines the structure and constraints of network data but does not represent the actual data payload. Candidates might also confuse Syslog or SMTP with JSON due to their familiarity with network protocols, but these protocols do not use JSON’s syntax.

This confusion leads to selecting incorrect answers, especially under time pressure. Recognizing that JSON is the payload format commonly used in Cisco APIs helps avoid this mistake and correctly interpret automation output.

Why the other options are wrong

A

YANG is a modeling language used to define the structure and constraints of network data but does not represent the actual data payload format. The question describes data output starting with curly braces and name-value pairs, which is a data format, not a model, so YANG is incorrect.

C

Syslog is a protocol used for sending event messages and logs from network devices. Its message format does not use curly braces or name-value pairs as JSON does, so it does not match the described API output format.

D

SMTP is a protocol for sending email messages and does not relate to network device data formats or API outputs. It does not use curly braces or name-value pairs in its message structure, making it irrelevant to the question.

When would these options actually be correct?

A

When asked which data modeling language is used to define the structure of NETCONF or RESTCONF configuration data, YANG would be the correct answer.

C

A question asking which protocol is used for centralized logging of network device events, where the answer options include Syslog, SNMP, and NetFlow.

D

A question asks which protocol is used to send email messages between mail servers. In that context, SMTP would be the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse YANG with JSON because YANG models can be serialized in JSON format, leading them to think YANG itself is a data format.

C

Candidates may confuse Syslog with JSON because both can be used in API contexts (e.g., sending logs as JSON), but Syslog itself is not a data format.

D

Candidates may confuse data formats with protocols, or they might think SMTP can carry structured data like JSON, but the question specifically asks about the data format itself.

902
Multi-Selectmedium

Which TWO statements about floating static routes and default routes are correct?

Select 2 answers
A.A floating static route uses an administrative distance higher than that of the primary route to act as a backup.
B.A floating static route must have a lower administrative distance than the primary route to ensure faster convergence.
C.A default route can be configured as a static route with destination 0.0.0.0/0 for IPv4 and ::/0 for IPv6.
D.Floating static routes are supported only for IPv6, not for IPv4.
E.A default static route cannot be configured as a floating static route.
AnswersA, C

A floating static route is configured with an administrative distance (AD) higher than that of the primary route, such as AD 200 instead of the default AD 1 for a directly connected static route. This higher AD makes the route less preferred, so the router uses the primary route as long as it exists in the routing table; if the primary route disappears, the floating static route is installed as a backup and traffic is sent via its next hop.

Why this answer

A floating static route is configured with a higher administrative distance (AD) than the primary route. This ensures the floating route remains inactive in the routing table unless the primary route fails, at which point the router installs the floating static route as a backup. The higher AD makes it less preferred than the primary dynamic or static route.

Exam trap

Cisco often tests the misconception that a floating static route must have a lower AD to be 'faster,' when in fact it requires a higher AD to serve as a backup; candidates also mistakenly think default routes cannot be made floating or that floating routes are IPv6-only.

Why the other options are wrong

B

Floating static routes require a higher AD, not lower, to be less preferred than the primary route.

D

Both IPv4 and IPv6 static routes can be configured as floating routes by setting a higher AD.

E

You can have multiple default static routes with different ADs, making the higher AD one a floating backup.

903
MCQhard

A switchport on one side of a link is configured as a trunk, but the peer side is configured as an access port. What is the most likely result?

A.The link roles are mismatched, so VLAN traffic will not be handled as intended.
B.The access side automatically becomes a routed port.
C.Both switches automatically synchronize their switchport settings.
D.The mismatch forces OSPF to change router IDs.
AnswerA

This is correct because a switchport configured as trunk on one side and access on the other creates a Layer 2 mismatch: the trunk side expects IEEE 802.1Q-tagged frames for multiple VLANs, while the access side expects untagged frames on a single VLAN. As a result, VLAN traffic is not forwarded consistently—frames tagged by the trunk are often dropped by the access port, and untagged frames from the access side may be mishandled. The link may still go up (depending on DTP settings), but the intended VLAN segmentation and inter-switch trunking behavior are broken.

Why this answer

The most likely result is a logical mismatch that prevents VLAN traffic from crossing the link as intended. In practical terms, one side is trying to carry multiple VLANs with tagging behavior, while the other side is treating the connection as a normal one-VLAN endpoint port. That disagreement usually leads to unexpected or failed traffic behavior.

This is a classic switching mismatch scenario. The link may still be physically up, but the two sides do not agree on how the traffic should be handled.

Exam trap

Don't assume mismatches always result in physical link failure; focus on logical traffic handling issues.

Why the other options are wrong

B

This option is incorrect because an access port does not automatically convert to a routed port when connected to a trunk port; it remains an access port and will not participate in Layer 3 routing.

C

This option is wrong because switchport settings do not automatically synchronize between devices; each port retains its configuration independently, leading to a mismatch in link roles.

D

This option is incorrect because the configuration mismatch between a trunk and an access port does not directly affect OSPF router IDs, which are determined by the OSPF process itself and not by switchport configurations.

When would these options actually be correct?

B

In a different question scenario where a switchport is explicitly configured to operate as a routed port and is connected to another switchport configured as an access port, the access port could be described as behaving like a routed port due to its Layer 3 capabilities being utilized.

C

In a different question scenario where both switches are designed to support automatic configuration protocols like Cisco's Dynamic Trunking Protocol (DTP), a question could ask what happens when one switch is set to negotiate trunking while the other is set to access mode. In this case, synchronization could occur if both sides were configured to use DTP.

D

If the question were about OSPF behavior in a scenario where a router's interfaces are misconfigured, such as having a mismatched network type or area configuration, then a change in router IDs could occur due to OSPF recalculating its topology. In that case, the option would be correct.

Why candidates pick the wrong answer

B

Candidates may find this option tempting because they might confuse the concepts of access ports and routed ports, leading them to believe that any misconfiguration would trigger an automatic change in port type.

C

Candidates may find this option tempting because they might recall concepts related to automatic negotiation protocols, leading them to assume that switch configurations can synchronize without manual intervention.

D

Candidates may choose this option due to a misunderstanding of how OSPF operates and the assumption that any configuration mismatch would lead to OSPF changes, reflecting a common misconception about routing protocols and their dependencies on interface settings.

904
PBQhard

You are connected to R1. The network uses DNS to resolve hostnames for remote device management. Currently, R1 cannot resolve the hostname 'ServerA' via DNS. Using the nslookup and dig commands, you have gathered the following outputs: nslookup ServerA Server: 203.0.113.1 Address: 203.0.113.1#53 Name: ServerA.example.com Address: 203.0.113.10 dig ServerA ... ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: ... ... The show running-config command shows that 'ip domain-lookup' is enabled, the name-server is 203.0.113.1, and no static host entries are configured. Diagnose and fix the DNS resolution failure. Ensure that R1 can successfully resolve 'ServerA' to its intended IP address 198.51.100.10.

Hints

  • •Check the output of 'nslookup' and 'dig' carefully; nslookup may show a different IP than expected.
  • •The DNS server returns a response but with an incorrect record — consider using a static host entry or a different DNS server.
  • •Verify that the DNS server's A record for ServerA actually points to 198.51.100.10, not 203.0.113.10.
A.Add a static host entry: 'ip host ServerA 198.51.100.10'
B.Change the DNS server to 8.8.8.8 using 'ip name-server 8.8.8.8'
C.Enable 'ip domain lookup' with 'ip domain-lookup' command
D.Configure the correct domain name using 'ip domain-name example.com'
AnswerA
solution
! R1
! Remove the incorrect static host entry if present (optional, but to force DNS resolution)
no ip host ServerA
! Alternatively, correct the DNS server or add a correct static entry:
ip host ServerA 198.51.100.10
! Or configure a different DNS server that has the correct A record:
ip name-server 198.51.100.1

Why this answer

The nslookup output misleadingly shows a response with IP 203.0.113.10, but the dig output reveals NXDOMAIN, indicating the DNS server has no valid A record for ServerA. The returned address is a default domain record that does not point to the correct device. Since the external DNS server cannot be modified, the quickest and valid fix is to add a static host entry on R1 using 'ip host ServerA 198.51.100.10', which overrides DNS and ensures correct resolution.

Option B is incorrect because changing to 8.8.8.8 would still depend on a remote server having the correct record, which is not guaranteed. Option C is wrong because 'ip domain-lookup' is already enabled, so disabling/enabling it has no effect. Option D is wrong because modifying the domain name only affects how FQDN is built but does not fix the missing A record or wrong IP issue.

Exam trap

Do not assume that a DNS server that responds is correctly configured. Always verify the actual record returned. The nslookup output may show a response, but the IP could be wrong.

Use 'dig' to see the exact answer section. Also, remember that static host entries override DNS and are useful for troubleshooting.

Why the other options are wrong

B

The DNS server is reachable and responds, but with incorrect data. Simply changing the server may not fix the issue if the new server also lacks the correct record.

C

The command 'ip domain-lookup' enables DNS resolution, but it is enabled by default. The problem is the incorrect DNS record, not the feature being disabled.

D

The domain name is already being used in the query (ServerA.example.com). Configuring a different domain name would change the query but not fix the incorrect record for ServerA.

Why candidates pick the wrong answer

B

Candidates often assume DNS issues are due to unreachability and try to change the server to a public one like 8.8.8.8, overlooking that the current server is responding but with wrong data.

C

Candidates might think DNS resolution is not working because the feature is disabled, especially if they forget that it is enabled by default. However, the nslookup output confirms DNS is active.

D

Candidates may think that the hostname is not being fully qualified, but the output shows the domain is appended. They might also confuse this with the need to set a domain name for other features like SSH.

905
MCQhard

Clients on a network can browse the internet by IP address but fail when using hostnames. What is the most likely problem?

A.The default gateway on the PC is incorrect.
B.The client is using the wrong DNS server address.
C.NAT overload is failing on the edge router.
D.The switchport must be converted to a routed port.
AnswerB

A misconfigured DNS server address causes the client to send name resolution queries to an endpoint that either cannot answer authoritatively or is completely unreachable. Since the client can already reach 8.8.8.8 by IP, the issue is specifically that the DNS resolver is not returning the A/AAAA record needed to translate the hostname. Verify the configured DNS server with ipconfig /all or nslookup, and correct it to a valid internal or public resolver such as 8.8.8.8.

Why this answer

The client can browse by IP address but not by hostname, which indicates that IP connectivity and routing are functional, but name resolution is failing. Since DNS translates hostnames to IP addresses, the most likely fault is that the client is configured with an incorrect DNS server address, preventing it from resolving domain names.

Exam trap

Cisco often tests the distinction between IP connectivity issues and name resolution issues, and the trap here is that candidates may incorrectly blame the default gateway or NAT when the symptom clearly isolates the problem to DNS.

Why the other options are wrong

A

This option is wrong because if the default gateway on the PC were incorrect, the client would not be able to reach any external IP addresses, not just hostnames. The issue specifically pertains to DNS resolution, not routing.

C

NAT overload failing on the edge router would typically affect the ability to connect to the internet entirely, not just when using hostnames. Since clients can browse by IP, this indicates NAT is functioning correctly.

D

This option is wrong because the issue described pertains to DNS resolution, not layer 2 switching or routing. The problem is related to hostname resolution failures, which are not affected by the switchport type.

When would these options actually be correct?

A

In a different scenario where a question states that clients cannot access any external resources, including IP addresses, and the default gateway is incorrectly configured, this option would be correct. For example, if the question specifies that the clients are unable to communicate outside their local subnet, then an incorrect default gateway would be the cause.

C

In a scenario where clients cannot access any external resources, including both IP addresses and hostnames, and the question specifies issues with NAT configurations, this option could be correct if the NAT overload configuration is misconfigured or overloaded.

D

In a different scenario, if the question stated that clients are unable to communicate with devices on different subnets and the switchport configuration was incorrectly set to access mode instead of routed mode, this option would be correct. It would indicate that the switchport needs to be configured to allow routing between VLANs.

Why candidates pick the wrong answer

A

Candidates might choose this option because they associate connectivity issues with routing problems, and the default gateway is a common troubleshooting point for network access issues, leading to confusion about the specific nature of the problem.

C

Candidates might be drawn to this option due to a misunderstanding of NAT functionality, assuming that any internet connectivity issue must relate to NAT configurations, especially if they have seen similar questions in practice exams.

D

Candidates may choose this option due to a misunderstanding of the network layers, thinking that routing issues at the switchport level could impact hostname resolution, especially if they are familiar with switch configurations.

906
MCQmedium

On a router performing NAT, where should ip nat inside be applied?

A.On the interface facing the internal private network
B.On the interface facing the ISP only
C.On every routed interface on the router
D.Only on loopback interfaces
AnswerA

The interface facing the internal private network is the inside side of the NAT boundary. By issuing the `ip nat inside` command on it, the router identifies the interface through which privately addressed hosts originate traffic. This designation enables the NAT process to translate source addresses as packets exit and to reverse translations when returning traffic arrives. Without this marking, the router cannot determine which interface is internal, so translation for internal-originated flows fails.

Why this answer

The inside designation belongs on the interface facing the private internal network. The outside designation belongs on the interface facing the public or external network.

Exam trap

A frequent exam trap is misapplying the ip nat inside command to the interface facing the ISP or external network. This mistake reverses the NAT boundary, causing translation to fail because the router expects private addresses on the inside interface only. Another trap is assuming all interfaces require NAT configuration, leading to unnecessary or incorrect commands on unrelated interfaces.

Additionally, some candidates incorrectly think loopback interfaces should be marked inside or outside, but NAT operates on interfaces connected to actual networks. Recognizing that ip nat inside must be on the internal private network interface prevents these common errors.

Why the other options are wrong

B

Incorrect. The interface facing the ISP is typically marked with ip nat outside, not ip nat inside, because it represents the public or external side of the NAT boundary.

C

Incorrect. Not every routed interface requires NAT configuration. Only interfaces that participate in NAT translation should be marked as inside or outside to define the translation boundaries.

D

Incorrect. NAT is not limited to loopback interfaces, and loopbacks are generally not used for NAT inside or outside designation since NAT operates on interfaces connected to real networks.

When would these options actually be correct?

B

If the question were to ask where to apply 'ip nat outside', which designates the interface connected to the ISP, then option B would be correct. This would involve a scenario focused on configuring NAT for outbound traffic from a private network to the internet.

C

If the question were to ask about a scenario where NAT needs to be applied to all interfaces for a specific routing protocol or multi-homed setup, then applying 'ip nat inside' on every routed interface could be correct to ensure proper address translation across all routes.

D

In a scenario where the question specifies that NAT is to be configured for a router that only routes traffic through loopback interfaces for testing or simulation purposes, applying 'ip nat inside' on loopback interfaces would be appropriate to manage NAT for traffic originating from those interfaces.

Why candidates pick the wrong answer

B

Candidates might choose this option due to confusion between the roles of inside and outside interfaces in NAT configurations, mistakenly thinking that the ISP-facing interface should also have NAT settings applied.

C

Candidates may choose this option due to a misunderstanding of NAT configuration, thinking that all interfaces need NAT applied to ensure connectivity, rather than recognizing the specific roles of inside and outside interfaces.

D

Candidates may be tempted by this option if they associate loopback interfaces with internal routing and mistakenly believe that NAT can be applied there for internal traffic management.

907
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure and verify HSRP active/standby election, including priority, preempt, virtual IP, and failover verification.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The order ensures the interface is ready, then priority and preempt are set to influence the election, followed by the virtual IP and verification of failover behavior.

Exam trap

Do not configure the virtual IP before setting priority and preempt, as the router may become active with default priority and then preempt later, causing unnecessary flapping. Always configure the interface first, then priority/preempt, then virtual IP.

Why candidates pick the wrong answer

B

Candidates might think the virtual IP is the most important and should be configured first, but the interface must be ready first.

C

Candidates might think priority and preempt are the first steps because they influence the election, but the interface must be ready first.

D

Candidates might think the virtual IP is the core of HSRP and should come right after the interface, but priority/preempt should come before to avoid a brief election with default values.

908
MCQhard

A host uses the subnet mask 255.255.254.0. Which prefix length does this represent?

A./22
B./23
C./24
D./25
AnswerB

A prefix length of /23 means 23 bits are set to 1 in the subnet mask, which in binary is 11111111.11111111.11111110.00000000. This converts directly to decimal 255.255.254.0, where the third octet has seven network bits and one host bit. Since the fourth octet contributes eight more host bits, the total host address space is 2^9 = 512 addresses, verifying that /23 is the correct representation.

Why this answer

The mask 255.255.254.0 represents /23. In plain language, the first two octets are fully network bits, the third octet contributes 7 more network bits because 254 in binary is 11111110, and the last octet contributes none. That totals 23 network bits.

This is a common prefix-conversion question because candidates often memorize the usual masks but hesitate when a non-/24 boundary appears. Recognizing that 255.255.254.0 equals /23 is important for subnetting and local-scope calculations.

Exam trap

Be cautious of common subnet masks like /24 and ensure you count the bits correctly, especially in non-standard masks.

Why the other options are wrong

A

Option A is incorrect because the subnet mask 255.255.254.0 corresponds to a prefix length of /23, not /22. A /22 prefix would indicate a subnet mask of 255.255.252.0.

C

The subnet mask 255.255.254.0 corresponds to a prefix length of /23, not /24. A /24 prefix length would indicate a subnet mask of 255.255.255.0, which allows for fewer hosts per subnet.

D

Option D is incorrect because a subnet mask of 255.255.254.0 corresponds to a prefix length of /23, not /25. A /25 subnet mask would allow for only 128 IP addresses, which is not applicable here.

When would these options actually be correct?

A

In a different question asking for the prefix length of a subnet mask of 255.255.252.0, option A would be correct, as that mask represents a /22 prefix length.

C

If the question asked for the prefix length of a subnet mask of 255.255.255.0, then option C (/24) would be correct, as this mask allows for 256 IP addresses in a single subnet, suitable for smaller networks.

D

If the question asked for the prefix length of a subnet mask of 255.255.255.128, then option D would be correct, as that subnet mask corresponds to a /25 prefix length, allowing for 128 IP addresses.

Why candidates pick the wrong answer

A

Candidates may choose this option due to confusion between the number of bits used for the subnet mask and the resulting prefix length, leading them to miscalculate the correct prefix.

C

Candidates may choose /24 because it is a common subnet mask for smaller networks, leading to confusion when interpreting subnet masks and their corresponding prefix lengths.

D

Candidates might choose option D due to confusion between the number of available hosts and the prefix length, as they may associate smaller subnet sizes with higher prefix lengths without fully understanding the relationship between subnet masks and their corresponding prefix lengths.

909
Multi-Selectmedium

A network technician is configuring a new Cisco switch and needs to secure unused switch ports to prevent unauthorized access. The technician decides to disable the ports and place them in an unused VLAN. Which two commands are required to accomplish this on each unused interface? (Choose two.)

Select 2 answers
A.shutdown
B.switchport mode access
C.switchport access vlan 999
D.switchport trunk allowed vlan none
E.no switchport
AnswersA, C

The 'shutdown' command administratively disables the interface, preventing any traffic from being sent or received. This is a critical step to secure unused ports. When a port is shut down, it cannot be used for unauthorized access. This command is entered in interface configuration mode. It is one of the two required commands to disable the ports as specified in the scenario.

Why this answer

To secure unused ports, you should administratively disable them with the 'shutdown' command and assign them to an unused VLAN using 'switchport access vlan 999'. This prevents unauthorized devices from connecting and isolates any potential traffic. Setting the port to access mode is also good practice but not one of the two required commands in this scenario.

Exam trap

The trap here is thinking that setting the port to access mode or using trunk commands is sufficient to secure unused ports, when the key actions are disabling the port and placing it in an unused VLAN.

910
MCQhard

A switchport is configured as a trunk on one side and access on the other side of the same physical link. What is the most likely result?

A.The link roles are mismatched, so VLAN traffic will not be handled as intended across the link.
B.The access side automatically becomes a routed port.
C.The switches automatically synchronize their configurations.
D.The mismatch forces OSPF to choose a new router ID.
AnswerA

When one side is a trunk and the peer is an access port, the link's encapsulation expectations conflict: the trunk port transmits 802.1Q-tagged frames while the access port accepts only untagged frames, so the access port typically drops or misplaces that traffic into its native VLAN. This logical mismatch means the VLAN traffic cannot traverse the link correctly, even though the physical link stays up.

Why this answer

A trunk/access mismatch prevents the link from carrying VLAN traffic as intended. Option A correctly identifies this mismatch. Option B is wrong because access ports remain Layer 2 switchports; there is no automatic conversion to a routed port.

Option C fails because switch configurations are never auto-synchronized due to a port role mismatch. Option D is incorrect: OSPF router ID is chosen based on loopback or highest IP address and is unaffected by a Layer 2 port mismatch.

Exam trap

Beware of assuming automatic negotiation fixes all mismatches; DTP cannot resolve a trunk/access mismatch.

Why the other options are wrong

B

Access ports do not automatically become routed ports; they remain Layer 2 switchports unless explicitly configured with 'no switchport'.

C

Switches do not automatically synchronize configurations; this is not a feature supported on Cisco switches to resolve mismatches.

D

OSPF router ID is determined by the highest loopback or IP address, not by Layer 2 port configuration mismatches.

When would these options actually be correct?

B

In a different scenario where the question specifies that a switchport is configured as an access port and is connected to a Layer 3 switch that is set to route traffic, the access port could be considered a routed port if the switch is configured to route traffic from that port.

C

In a different scenario where two switches are connected and both are set to automatically synchronize their configurations, a question might ask about the behavior of switches when connected with mismatched port types. In that case, if both switches support a configuration synchronization feature, the option could be correct.

D

In a different scenario where the question specifies that OSPF is configured on both switches and that the port configurations impact OSPF adjacency, a mismatch could lead to OSPF recalculating the router ID due to changes in the network topology.

Why candidates pick the wrong answer

B

Candidates may find this option tempting because they might confuse the concepts of access ports and routed ports, believing that a configuration change would automatically elevate the port's functionality without realizing that explicit configuration is required.

C

Candidates may choose this option because they might confuse the concept of configuration synchronization in networking with the behavior of mismatched port types, leading to an assumption that switches would automatically adjust their settings.

D

Candidates may choose this option because they associate network configuration mismatches with OSPF behavior, mistakenly believing that any configuration issue would trigger a change in OSPF parameters like the router ID.

911
MCQmedium

Users in 10.10.10.0/24 must be prevented from reaching the web server at 172.16.1.10 over HTTP, but all other traffic should be allowed. Which ACL entry should appear first in the ACL?

A.permit tcp 10.10.10.0 0.0.0.255 host 172.16.1.10 eq 80
B.deny ip 10.10.10.0 0.0.0.255 host 172.16.1.10
C.deny tcp 10.10.10.0 0.0.0.255 host 172.16.1.10 eq 80
D.deny udp 10.10.10.0 0.0.0.255 host 172.16.1.10 eq 80
AnswerC

This extended ACL entry correctly uses the deny keyword with protocol tcp, source 10.10.10.0 0.0.0.255, destination host 172.16.1.10, and destination port eq 80 to match HTTP traffic. Because web browsing uses TCP port 80, this statement blocks exactly the HTTP requests from the 10.10.10.0/24 users to that specific web server while leaving all other protocols and ports unaffected. The wildcard mask 0.0.0.255 limits the match to the 10.10.10.0/24 subnet, and the explicit host keyword ties the rule to one destination, satisfying the narrow security requirement.

Why this answer

The requirement is specific: block HTTP traffic from one source subnet to one server, but allow everything else. In plain terms, you do not want to shut off all communication to the server or all communication from the users. You only want to stop normal web traffic that uses TCP port 80. That means the ACL should start with a deny statement that matches TCP from 10.10.10.0/24 to host 172.16.1.10 on destination port 80.

Using `deny ip` would block every IP-based protocol to that host, which is broader than the requirement. Using UDP port 80 does not match normal HTTP. And a permit statement would do the opposite of what is needed.

Exam trap

A frequent exam trap is selecting a deny ip statement to block HTTP traffic, which seems simpler but actually blocks all IP traffic from the source subnet to the destination host. This overbroad denial disrupts legitimate communications such as DNS, SSH, or other TCP/UDP services, violating the requirement to allow all other traffic. Another trap is denying UDP port 80, which is incorrect because HTTP uses TCP, not UDP.

Candidates may also mistakenly place a permit statement first, which would allow the HTTP traffic instead of blocking it. Recognizing the correct protocol and port and placing the deny statement first is critical to avoid these pitfalls.

Why the other options are wrong

A

This option permits TCP traffic from 10.10.10.0/24 to the web server on port 80, which is the exact traffic that must be blocked. Therefore, it contradicts the requirement and is incorrect.

B

This option denies all IP traffic from the source subnet to the destination host, which is too broad. It blocks all protocols and ports, not just HTTP, violating the requirement to allow other traffic.

D

This option denies UDP traffic on port 80, but HTTP uses TCP port 80. Denying UDP port 80 does not block HTTP traffic and therefore does not meet the requirement.

When would these options actually be correct?

A

In a different scenario where the requirement is to allow HTTP traffic from 10.10.10.0/24 to 172.16.1.10 while denying all other traffic, option A would be correct. For example, if the question stated that users should be allowed to access the web server but not other services, this entry would fit.

B

In a scenario where the objective is to block all traffic from the 10.10.10.0/24 subnet to the web server at 172.16.1.10, regardless of the protocol, this option would be correct. For example, if the question asked to prevent any communication to the server, not just HTTP, this would be the right choice.

D

In a scenario where the question specifies that users should be prevented from accessing a service that uses UDP on port 80 (hypothetically, if a web service were using UDP), then option D would be the correct answer. For example, if the question stated that UDP traffic from 10.10.10.0/24 to 172.16.1.10 on port 80 should be denied, this option would apply.

Why candidates pick the wrong answer

A

Candidates may find option A tempting because it directly addresses the HTTP traffic on port 80, which is a common requirement in access control lists, leading to confusion about the context of the question.

B

Candidates may choose this option because it seems to address the requirement of blocking traffic, and they might misinterpret the question as needing to block all access to the server rather than just HTTP.

D

Candidates may choose this option due to a misunderstanding of the protocols involved, mistakenly believing that blocking UDP traffic could also impact HTTP traffic, or because they see 'deny' and assume it aligns with the goal of restricting access.

912
Multi-Selecthard

A controller exposes a YANG-modeled interface configuration through an API. Which two statements correctly describe the purpose of YANG in that workflow?

Select 2 answers
A.It provides a structured data model for configuration and operational data
B.It helps standardize how network elements represent managed data
C.It replaces IP addressing on routed interfaces
D.It is a spanning-tree optimization mechanism
AnswersA, B

YANG defines a hierarchical, tree-like schema that organizes both configuration data (intended state) and operational state data (actual state) for network devices. This structured model enables programmatic access and automation, as APIs like NETCONF/RESTCONF use YANG to validate and manipulate the data. It provides a clear, machine-readable representation of what a device can do and how its configuration is structured.

Why this answer

YANG is a modeling language. It defines the structure of network data so controllers and devices can exchange information consistently through APIs such as RESTCONF or NETCONF.

Exam trap

A frequent exam trap is mistaking YANG for a network protocol or function rather than a data modeling language. For example, options suggesting YANG replaces IP addressing or optimizes spanning-tree protocols are incorrect because YANG does not perform routing or Layer 2 operations. Candidates might confuse YANG’s role with actual network services instead of recognizing it as a schema that defines how configuration and state data are structured and exchanged.

This misunderstanding can lead to selecting incorrect answers that describe network functions rather than data modeling purposes.

Why the other options are wrong

C

Option C is incorrect because YANG does not replace IP addressing on routed interfaces. IP addressing is a network-layer function, while YANG models the data representing such configurations but does not perform addressing itself.

D

Option D is wrong as YANG has no role in spanning-tree optimization or Layer 2 loop prevention. YANG is a data modeling language and does not influence protocol operations like STP.

When would these options actually be correct?

C

In a question about network automation tools that directly configure IP addresses on interfaces, an option stating 'It replaces IP addressing on routed interfaces' could be correct if the tool (e.g., a controller using YANG) abstracts away manual IP configuration, but YANG alone does not replace IP addressing.

D

In a question about spanning-tree enhancements, an option describing a mechanism that optimizes spanning-tree convergence (e.g., 'It is a spanning-tree optimization mechanism') could be correct if referring to a feature like PortFast, UplinkFast, or BackboneFast.

Why candidates pick the wrong answer

C

Candidates may confuse YANG with a configuration protocol that directly sets IP addresses, or think that because YANG models interface configuration, it somehow replaces the need for IP addressing itself.

D

Candidates may confuse YANG with other network technologies or assume any 'optimization' term relates to YANG, especially if they have limited understanding of YANG's role in model-driven programmability.

913
MCQhard

A network engineer is troubleshooting connectivity issues for hosts in VLAN 10. Hosts in VLAN 10 are unable to ping the default gateway at 192.168.10.1. The engineer checks the switch configuration and notices that the SVI for VLAN 10 is configured with an IP address, but the interface is in a down/down state. What is the most likely cause of this issue?

A.The interface is administratively shut down.
B.VLAN 10 does not exist in the VLAN database.
C.The IP address is not in the correct subnet for VLAN 10.
D.The switch does not have a default gateway configured.
AnswerB

The SVI for VLAN 10 is down/down because the VLAN is not created. Once VLAN 10 is created with the 'vlan 10' command in global configuration mode, the SVI will come up if there is at least one active port in that VLAN.

Why this answer

An SVI (Switch Virtual Interface) will remain in a down/down state if the corresponding VLAN does not exist in the switch's VLAN database. Even if the SVI is configured with an IP address, the interface cannot come up because there is no Layer 2 VLAN to associate with it. This is a common cause of SVI down/down issues when the VLAN has not been created or has been deleted.

Exam trap

Cisco often tests the distinction between an SVI being down due to a missing VLAN versus an administratively shutdown interface, leading candidates to mistakenly choose the administrative shutdown option when the interface status shows 'down/down' instead of 'administratively down'.

Why the other options are wrong

A

The running-config shows 'no shutdown', so this is not the cause.

C

The IP address and subnet mask are correctly configured for the VLAN.

D

The SVI status is not affected by the presence or absence of a default gateway.

914
Multi-Selectmedium

Which TWO statements are true regarding VLAN configuration, 802.1Q trunking, and the native VLAN?

Select 2 answers
A.On an 802.1Q trunk, frames in the native VLAN are always tagged with a VLAN ID.
B.The native VLAN should be changed from the default VLAN 1 to an unused VLAN for security reasons.
C.802.1Q is a Cisco proprietary trunking protocol.
D.802.1Q supports up to 4094 VLANs (VLAN IDs 1–4094).
E.The native VLAN must be the same on both ends of an 802.1Q trunk for the trunk to operate.
AnswersB, D

Changing the native VLAN from the default VLAN 1 to an unused VLAN is a Cisco-recommended hardening step because VLAN 1 is well-documented and often carries control-plane traffic such as CDP, VTP, and PAgP. Attackers can exploit the default native VLAN to launch double-tagging (VLAN hopping) attacks, so moving native VLAN to a dedicated unused VLAN reduces the risk of layer 2 traffic being intercepted or misforwarded. Additionally, using an unused VLAN ensures that no legitimate user traffic is accidentally sent untagged on the trunk, which prevents VLAN misclassification.

Why this answer

Changing the native VLAN from the default VLAN 1 to an unused VLAN is a recommended security best practice to prevent VLAN hopping attacks. Option D is correct because 802.1Q uses a 12-bit VLAN ID field, allowing VLAN IDs from 1 to 4094 (0 and 4095 are reserved). Option A is false: on an 802.1Q trunk, frames in the native VLAN are typically sent untagged.

Option C is false: 802.1Q is an IEEE standard, not Cisco proprietary (ISL is Cisco proprietary). Option E is false: the native VLAN does not have to match on both ends; mismatched native VLANs can cause traffic to be misclassified but the trunk will still operate.

Exam trap

Cisco often tests the misconception that 802.1Q is proprietary (it is not) and that native VLAN frames are always tagged (they are untagged by default), leading candidates to incorrectly select options A or C.

Why the other options are wrong

A

The native VLAN is specifically the VLAN that does not get a tag; all other VLANs are tagged.

C

802.1Q is an open standard, whereas ISL was Cisco proprietary.

E

Mismatched native VLANs can lead to security vulnerabilities and misrouting, but the trunk itself may still come up.

915
PBQhard

You are connected to R1. Configure AAA with a RADIUS server at 10.0.0.2 using key 'cisco123' for authentication. Then troubleshoot why 802.1X on interface GigabitEthernet0/1 remains in unauthorized state. Ensure that the default login authentication uses RADIUS first, then local fallback, and fix any configuration issues that prevent 802.1X from working.

Network Topology
G0/010.0.0.1/3010.0.0.2/30linkG0/1linkR1RADIUS ServerClient PC

Hints

  • •Check the AAA authentication method for dot1x — it currently uses 'local' but no local users exist.
  • •The default login authentication also uses 'local' — you need to add RADIUS as primary method.
  • •Ensure the RADIUS server's IP and key are correct — but the issue is the authentication method list, not connectivity.
A.Configure 'aaa authentication dot1x default group radius' and 'aaa authentication login default group radius local' and ensure the RADIUS server is reachable with the correct key.
B.Configure 'aaa authentication dot1x default local' and 'aaa authentication login default local' and create a local user with the same credentials as the RADIUS server.
C.Configure 'aaa authentication dot1x default group radius' and 'aaa authentication login default local' and ensure the RADIUS server key is 'cisco123'.
D.Configure 'aaa authentication dot1x default group radius' and 'aaa authentication login default group radius local' and change the RADIUS server key to 'cisco'.
AnswerA
solution
! R1
configure terminal
aaa authentication login default group radius local
aaa authentication dot1x default group radius
end
write memory

Why this answer

The 802.1X port is stuck in UNAUTHORIZED because AAA authentication for dot1x is set to 'local' but there is no local user database configured. Additionally, the RADIUS server is configured but not used for dot1x or login. The fix is to change 'aaa authentication dot1x default' to use group radius, and 'aaa authentication login default' to group radius local for fallback.

Also ensure the RADIUS server is reachable and the key matches the server.

Exam trap

Candidates often forget that 802.1X requires a RADIUS server for authentication, not local, and that the login authentication method list must also be configured correctly. They may also overlook the need for the RADIUS key to match exactly.

Why the other options are wrong

B

The specific factual error is that 802.1X should use RADIUS for authentication, not local, and the login default should have RADIUS as the primary method.

C

The specific factual error is that the login default should be 'group radius local' to meet the requirement of RADIUS first then local fallback.

D

The specific factual error is that the key must match exactly; changing it to 'cisco' would break communication with the RADIUS server.

Why candidates pick the wrong answer

B

Candidates might think that since RADIUS is configured, using 'local' would fall back to RADIUS, but 'local' means local user database only, not RADIUS.

C

Candidates might focus only on 802.1X and overlook the login authentication requirement, thinking local is sufficient for login.

D

Candidates might think the key can be any value as long as it's consistent, but the question specifies the key is 'cisco123', so it must be used as given.

916
PBQhard

You are connected to a multilayer switch MLS1. Configure Root Guard on the designated port facing another switch SW2 to prevent it from becoming root, configure Loop Guard on the uplink port to the core, and configure BPDU Guard on a PortFast-enabled access port. After configuration, a superior BPDU arrives on the designated port—confirm it is blocked by Root Guard. Then, simulate a BPDU on the access port to verify it goes err-disabled due to BPDU Guard.

Hints

  • •Root Guard is configured per interface under the interface configuration mode.
  • •Loop Guard uses the same command but with 'loop' keyword.
  • •BPDU Guard on PortFast ports can be enabled globally or per interface; use per-interface for this task.
A.Root Guard on Gi0/2, Loop Guard on Gi0/1, BPDU Guard on Gi0/0
B.Root Guard on Gi0/1, Loop Guard on Gi0/2, BPDU Guard on Gi0/0
C.Root Guard on Gi0/0, Loop Guard on Gi0/1, BPDU Guard on Gi0/2
D.Root Guard on Gi0/2, Loop Guard on Gi0/0, BPDU Guard on Gi0/1
AnswerA
solution
! MLS1
interface GigabitEthernet0/2
spanning-tree guard root
exit
interface GigabitEthernet0/1
spanning-tree guard loop
exit
interface GigabitEthernet0/0
spanning-tree bpduguard enable
exit

Why this answer

First, Root Guard was applied on Gi0/2 (the designated port) with 'spanning-tree guard root' to prevent SW2 from becoming root. Second, Loop Guard was applied on the uplink Gi0/1 with 'spanning-tree guard loop' to protect against unidirectional links. Third, BPDU Guard was applied on the PortFast-enabled access port Gi0/0 with 'spanning-tree bpduguard enable'.

When a superior BPDU arrives on Gi0/2, Root Guard transitions it to a root-inconsistent (blocked) state. If a BPDU is received on Gi0/0, BPDU Guard err-disables the port. Verification shows the blocked state on Gi0/2 and err-disabled on Gi0/0.

Exam trap

Do not confuse the purposes of Root Guard, Loop Guard, and BPDU Guard. Root Guard blocks superior BPDUs on designated ports; Loop Guard prevents loops on root/alternate ports; BPDU Guard err-disables PortFast ports upon BPDU reception. Pay attention to port roles: designated, root, and access.

Why the other options are wrong

B

Root Guard is intended for ports that should not become root; applying it on the uplink would block legitimate superior BPDUs from the core. Loop Guard on the designated port would not protect against unidirectional links on the uplink.

C

Root Guard on an access port is unnecessary and would not prevent the switch from becoming root via other ports. BPDU Guard on the designated port would disable it instead of blocking the BPDU.

D

Loop Guard on an access port does not protect against unidirectional links on the uplink. BPDU Guard on the uplink would err-disable the core connection if a BPDU is received, which is undesirable.

Why candidates pick the wrong answer

B

Candidates may confuse which port is designated versus uplink, or think Root Guard should be on all ports.

C

Candidates might think Root Guard is a general protection and apply it to all ports, or confuse the functions of Root Guard and BPDU Guard.

D

Candidates may misplace Loop Guard and BPDU Guard due to misunderstanding of where unidirectional links or BPDU threats occur.

917
MCQmedium

A host can reach other devices on its local subnet, but it cannot reach remote networks. The host has a valid IP address and subnet mask. Which missing item is the strongest suspect?

A.Default gateway information
B.STP priority information
C.A voice VLAN setting
D.An OSPF process ID
AnswerA

A host reaches its local subnet because it can ARP for those destinations, but for any address outside that subnet, it must forward the packet to a router. Without a default gateway, the host has no next-hop IP address, so it drops or returns an error for all off-subnet traffic. The default gateway is the router interface on the host's subnet, and missing it precisely matches the symptom of local reachability but remote unreachability.

Why this answer

The strongest suspect is a missing default gateway. In practical terms, the host can still identify and reach local addresses because it has its own IP and subnet mask. But without a default gateway, it has no next hop for destinations outside the local subnet. That is why local communication works while remote communication fails.

This is one of the most common host-configuration troubleshooting patterns on the exam and in real networks.

Exam trap

A common exam trap is selecting options related to routing protocols like OSPF or Layer 2 technologies such as STP or VLANs when the issue is actually a missing default gateway. Candidates might incorrectly assume that the host needs an OSPF process ID or STP priority to reach remote networks. However, hosts do not run routing protocols and do not participate in STP decisions.

The real problem is the absence of default gateway information, which prevents the host from forwarding packets beyond its local subnet. Misunderstanding this leads to incorrect answers that focus on advanced protocols rather than basic IP configuration.

Why the other options are wrong

B

Incorrect because STP priority is a Layer 2 switch parameter that does not affect host IP routing or the ability to reach remote networks. Hosts do not participate in STP decisions.

C

Incorrect because voice VLAN settings relate to Layer 2 segmentation for voice traffic and do not impact the host’s IP routing or default gateway configuration needed for remote communication.

D

Incorrect because hosts do not run routing protocols like OSPF and do not require an OSPF process ID. Routing protocols are configured on routers, not end hosts.

When would these options actually be correct?

B

In a scenario where the question asks about issues related to Layer 2 network topology and redundancy, a question could state that a network is experiencing broadcast storms or connectivity issues due to improper STP configuration. In that case, the STP priority information would be the correct focus for troubleshooting.

C

In a question asking about issues with voice traffic on a network, where a host can communicate locally but experiences problems with voice quality or connectivity, a missing voice VLAN setting could be the correct answer if the question specifies that voice traffic is not being prioritized or routed correctly.

D

In a question where a network administrator is troubleshooting routing issues on a router and needs to ensure that OSPF is correctly configured, a missing or incorrect OSPF process ID could prevent the router from participating in OSPF routing, leading to connectivity issues with remote networks.

Why candidates pick the wrong answer

B

Candidates may be tempted by this option because they recognize STP as a critical component of network design and may mistakenly associate it with connectivity issues, thinking that any Layer 2 setting could impact Layer 3 communication.

C

Candidates may confuse VLAN settings with routing issues, thinking that if local communication is fine, VLAN configurations could still impact overall network performance, especially in environments where voice traffic is critical.

D

Candidates may be tempted by this option because OSPF is a well-known routing protocol, and they might mistakenly associate it with connectivity issues, thinking that any routing-related configuration could be relevant to the problem presented.

918
MCQhard

A network engineer is configuring a switch port for a new wireless access point that will support multiple SSIDs mapped to different VLANs. The AP will be powered by PoE and will tag traffic for each SSID. Which configuration on the switch port is most appropriate?

A.Configure the port as a trunk port and set the native VLAN to VLAN 1, allowing all VLANs.
B.Configure the port as a trunk port, set the native VLAN to the AP management VLAN, and allow the SSID VLANs on the trunk.
C.Configure the port as an access port in the management VLAN and use 802.1X authentication for the SSIDs.
D.Configure the port as an access port in the management VLAN and enable voice VLAN for the SSIDs.
AnswerB

This is the correct configuration for an AP supporting multiple SSIDs. The AP management traffic is typically untagged and placed in the native VLAN, while each SSID's traffic is tagged with its respective VLAN. The trunk allows multiple VLANs to traverse the link. This setup enables the AP to map each SSID to a different VLAN and tag frames accordingly.

Why this answer

For an access point supporting multiple SSIDs, the switch port should be configured as a trunk. The native VLAN is used for untagged management traffic from the AP, while each SSID's traffic is tagged with its corresponding VLAN. Allowing only the necessary VLANs on the trunk is a best practice.

This configuration ensures proper segmentation and security.

Exam trap

The trap here is assuming an access port with voice VLAN can handle multiple SSIDs, or that allowing all VLANs is acceptable.

919
Drag & Dropmedium

Drag and drop the following steps into the correct order to troubleshoot a suspected duplex mismatch and CRC errors on a Cisco switch interface using CLI commands.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Start by examining current interface stats, then fix the mismatch, and finally clear and recheck counters.

Exam trap

The trap is that candidates often clear counters before fixing the issue, thinking they need a clean baseline. However, you must first see the errors to confirm the problem. Also, some may try to fix before inspecting, which is not systematic troubleshooting.

Why candidates pick the wrong answer

B

Candidates might think clearing counters is a necessary first step to get a clean baseline, but you need to see the current errors first.

C

Candidates may think clearing counters after inspection but before the fix is acceptable, but the correct sequence is to fix first, then clear, then verify.

D

Candidates might think that since duplex mismatch is suspected, they can go straight to fixing it, but proper troubleshooting requires verification first.

920
MCQhard

After enabling Dynamic ARP Inspection on VLAN 20, a network engineer notices that some hosts lose connectivity. The affected hosts have correct IP addresses and MAC addresses, but they cannot ping the default gateway. All other hosts on the same VLAN work fine. Further investigation reveals that the non-functioning hosts are using static IP configurations, while the working hosts are DHCP clients. What is the most likely cause?

A.The DHCP snooping binding table is exhausted and cannot accept new bindings for the static hosts.
B.IP Source Guard is also enabled on VLAN 20 and is blocking traffic from hosts that have no DHCP snooping binding.
C.DAI is dropping ARP packets from the static hosts because they do not have a corresponding entry in the DHCP snooping binding table.
D.The switch is detecting ARP spoofing from the static hosts and has shut down their switchport interfaces for security.
AnswerC

When DAI is enabled, it checks every ARP packet on untrusted ports against the DHCP snooping binding table. Since the static hosts have no DHCP lease, no binding exists, and DAI drops their ARP packets, preventing them from learning the gateway MAC address and causing loss of connectivity.

Why this answer

Dynamic ARP Inspection (DAI) relies on the DHCP snooping binding table to validate ARP packets. When a host uses a static IP address, it does not have an entry in that table, so DAI treats its ARP packets as invalid and drops them. This prevents the static host from resolving the default gateway's MAC address, breaking connectivity even though the IP and MAC are correct.

Exam trap

Cisco often tests the dependency of DAI on DHCP snooping, and the trap here is that candidates assume DAI validates based on the actual IP/MAC correctness rather than requiring a binding table entry.

Why the other options are wrong

A

Candidates may think that a large number of untrusted hosts could overwhelm the binding table, but static hosts do not interact with DHCP and would not fill the table or be rejected.

B

Candidates often confuse DAI and IP Source Guard since both use DHCP snooping; however, DAI specifically validates ARP packets, which matches the symptom of connectivity loss due to ARP resolution failure.

D

Some candidates might associate ARP security features with port shutdown, but standard DAI operation does not disable ports, and the symptom does not indicate interface down events.

921
Multi-Selectmedium

Which three of the following are benefits of integrating AI into network operations? (Choose three.)

Select 3 answers
.Reduced mean time to repair (MTTR) through faster incident diagnosis
.Improved accuracy in capacity planning by predicting traffic trends
.Automated enforcement of security policies based on real-time risk analysis
.Complete elimination of network downtime
.Zero configuration required for new network devices
.Total removal of human network engineers from operations

Why this answer

AI reduces mean time to repair (MTTR) by rapidly diagnosing incidents through automated correlation of telemetry and logs. It improves capacity planning by analyzing traffic patterns and predicting future demands, enabling proactive scaling. Automated security policy enforcement uses real-time risk analysis to adjust rules dynamically.

The three distractors are wrong because AI cannot guarantee complete elimination of network downtime (unexpected hardware failures still occur), zero configuration for new devices (initial setup and integration still require human input), or total removal of human engineers (AI augments but does not replace strategic oversight and complex problem-solving).

Exam trap

Candidates often mistake AI's ability to automate specific tasks for a complete replacement of human roles or an unrealistic promise of absolute network reliability—AI enhances operations, it does not make them foolproof.

Why the other options are wrong

D

AI-driven operations can minimize downtime but cannot eliminate it entirely due to unpredictable hardware failures and external factors.

E

New network devices still require initial configuration and policy assignment; AI may assist but cannot achieve zero configuration.

F

Human engineers remain essential for strategic planning, complex troubleshooting, and overseeing AI-driven processes.

922
MCQhard

Why is a northbound API especially useful in a controller-based network architecture?

A.It allows external software to interact programmatically with the controller.
B.It is the cable standard used to connect access points.
C.It replaces all need for authentication and authorization.
D.It makes VLAN tagging unnecessary.
AnswerA

Northbound APIs expose controller functions through REST or similar interfaces, letting orchestration tools, scripts and applications query topology, push configuration and automate provisioning. This programmability is the defining benefit of controller-based architectures, separating external software interaction from southbound device protocols.

Why this answer

A northbound API is especially useful because it gives external applications and automation tools a defined way to communicate with the controller. In plain language, it allows software above the controller to request information, apply policies, or trigger changes without manual per-device interaction. That is one of the main reasons controller-based networking fits well with orchestration and automation.

Option C is incorrect because a northbound API does not replace authentication and authorization; it is an interface that uses existing security mechanisms. Option D is incorrect because VLAN tagging is a data‑plane function unaffected by the northbound API; the API does not eliminate the need for VLANs. The controller is the centralized system, and the northbound API is the software-facing interface that exposes it.

The correct answer is the one centered on application integration rather than on physical connectivity or device forwarding.

Exam trap

Avoid confusing northbound APIs with hardware configuration or physical connectivity functions.

Why the other options are wrong

C

A northbound API does not replace authentication or authorization; it relies on those mechanisms to secure API access.

D

VLAN tagging is a data‑plane feature independent of the northbound API; the API does not make VLAN tagging unnecessary.

When would these options actually be correct?

B

If the question were about the physical infrastructure of a network and asked about the standards for connecting devices like access points, then option B could be correct in identifying a specific cable standard, such as Ethernet or Cat5.

C

In a different context, a question might ask about the benefits of a hypothetical API that operates without any security measures, focusing on ease of integration. In that case, the answer could be that it replaces the need for authentication and authorization, making it suitable for rapid prototyping or internal tools.

D

If the exam question were to ask about a network architecture that uses a single flat network without segmentation requirements, such as a small home network or a very basic setup, then this option could be considered correct as VLAN tagging might not be necessary.

Why candidates pick the wrong answer

B

Candidates might choose this option due to a misunderstanding of network architecture concepts, conflating the role of APIs with physical connectivity standards, which can lead to confusion about their respective functions.

C

Candidates may be drawn to this option due to a misunderstanding of API functions, conflating ease of use with security, leading them to believe that a simplified API would inherently bypass security requirements.

D

Candidates may find this option tempting because they might confuse the simplification of network management in a controller-based architecture with the elimination of fundamental networking concepts like VLAN tagging.

923
PBQhard

You are connected to R1 via console. R1 and R2 are directly connected via GigabitEthernet0/0. Configure OSPF process 1 on both routers so that they form a full adjacency. R1's router-id must be 1.1.1.1, and R2's router-id must be 2.2.2.2. Use network statements to advertise the direct link. Ensure that R1 does not send OSPF hellos out of its GigabitEthernet0/1 interface. The current configuration on R1 has mismatched hello and dead timers, and an incorrect network type, preventing adjacency. Fix all issues.

Network Topology
G0/0192.0.2.1/30G0/0192.0.2.2/30linkR1R2

Hints

  • •Check the hello and dead timer values on R1 vs R2 using show ip ospf interface.
  • •The default hello timer for broadcast networks is 10 seconds, dead timer 40 seconds.
  • •Use interface configuration mode to change OSPF timers.
A.On R1, configure 'ip ospf hello-interval 10' and 'ip ospf dead-interval 40' under interface GigabitEthernet0/0, and ensure network type is broadcast. On R2, configure 'router-id 2.2.2.2' under router ospf 1. Also, on R1, add 'passive-interface GigabitEthernet0/1' under router ospf 1.
B.On R1, configure 'ip ospf hello-interval 30' and 'ip ospf dead-interval 120' under interface GigabitEthernet0/0, and set network type to point-to-point. On R2, configure 'router-id 2.2.2.2' under router ospf 1. Also, on R1, add 'passive-interface default' under router ospf 1.
C.On R1, configure 'ip ospf hello-interval 10' and 'ip ospf dead-interval 40' under interface GigabitEthernet0/0, and set network type to point-to-point. On R2, configure 'router-id 2.2.2.2' under router ospf 1. Also, on R1, add 'passive-interface GigabitEthernet0/1' under router ospf 1.
D.On R1, configure 'ip ospf hello-interval 10' and 'ip ospf dead-interval 40' under interface GigabitEthernet0/0, and ensure network type is broadcast. On R2, configure 'router-id 2.2.2.2' under router ospf 1. Also, on R1, add 'network 10.0.0.0 0.255.255.255 area 0' under router ospf 1.
AnswerA
solution
! R1
interface GigabitEthernet0/0
ip ospf hello-interval 10
ip ospf dead-interval 40

Why this answer

The adjacency was failing because R1 had incorrect hello (30) and dead (120) timers, while R2 used defaults (10/40). Additionally, R1’s network type was set to a non-broadcast type, causing a mismatch. To fix, on R1’s GigabitEthernet0/0, set hello-interval 10, dead-interval 40, and network type broadcast.

In OSPF process 1 on R1, configure passive-interface GigabitEthernet0/1 to suppress hellos on that interface. On R2, under router ospf 1, set router-id 2.2.2.2. Option A addresses all requirements.

Option B uses wrong timers and passive-interface default, which blocks hellos on all interfaces, breaking adjacency. Option C sets network type point-to-point, creating a type mismatch with R2’s broadcast, preventing adjacency. Option D omits the passive-interface command, failing to suppress hellos on GigabitEthernet0/1 as required.

Exam trap

The exam trap is that candidates may focus on the network type or extra network statements, but the primary issue is the timer mismatch. OSPF requires hello and dead timers to match for adjacency. Also, remember that 'passive-interface default' suppresses hellos on all interfaces, which would break the adjacency; use specific passive-interface commands.

Why the other options are wrong

B

Incorrect timers (30/120) break adjacency, and 'passive-interface default' suppresses hellos on all interfaces, including the transit link.

C

Network type point-to-point on R1 does not match R2's default broadcast, causing a type mismatch that prevents OSPF adjacency.

D

Omits the required 'passive-interface GigabitEthernet0/1' command, leaving hellos sending on that interface.

Why candidates pick the wrong answer

B

Candidates might think that since R1 had mismatched timers, they should keep those values and adjust R2 instead, or they might confuse the default timers with the existing mismatched ones.

C

Candidates might think that point-to-point is more efficient or that it avoids DR/BDR elections, but for a simple direct link, broadcast works fine and is the default. They may also confuse the requirement to fix the network type with the timer issue.

D

Candidates might think that adding a network statement is necessary to advertise the link, but the question states to use network statements to advertise the direct link, implying a specific statement is already in place or should be configured. They may also confuse the requirement with the need to include all interfaces.

924
Drag & Dropmedium

Which of the following correctly describes the sequence of the TCP three-way handshake between a client and a server?

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The TCP three-way handshake establishes a reliable connection in three steps: the client sends a SYN, the server replies with SYN-ACK, and the client acknowledges with an ACK. Option A correctly depicts this. Option B omits the server's SYN, leaving synchronization incomplete.

Option C reverses the roles by having the server initiate, which never occurs in a standard handshake. Option D begins with a SYN-ACK, which is not a valid initial packet; the handshake must start with a SYN.

Exam trap

Do not confuse the roles: the client always initiates with a SYN, the server responds with SYN-ACK, and the client finishes with an ACK. Watch out for options that reverse the order or swap the flags.

Why candidates pick the wrong answer

B

Candidates might confuse the roles, thinking the server only acknowledges the client's SYN and then the client sends a combined SYN-ACK.

C

Candidates may think the handshake is symmetric or confuse it with other protocols where the server initiates.

D

Candidates might misremember the order or think the client sends a SYN-ACK to propose parameters.

925
MCQhard

A host is configured as 10.20.30.95/27. Which address is the network address of its subnet?

A.10.20.30.32
B.10.20.30.64
C.10.20.30.95
D.10.20.30.96
AnswerB

The /27 prefix length means the subnet mask is 255.255.255.224, giving a block size of 32 addresses. The host address 10.20.30.95 falls within the range 10.20.30.64 through 10.20.30.95, making .64 the first address of that subnet. Since the network address is always the first address in the block, 10.20.30.64 is indeed the network for this host.

Why this answer

A /27 uses blocks of 32 addresses. In plain language, the ranges in the last octet are 0–31, 32–63, 64–95, 96–127, and so on. Since the host address ends in 95, it belongs to the 64–95 block. The first address in that block is the network address, which is 10.20.30.64.

This is a classic subnet-boundary question because it tests whether you can identify the containing block and then choose the first address in that block as the network address.

Exam trap

A frequent exam trap is mistaking the host IP address for the network address or incorrectly identifying the subnet block boundaries. Candidates often select the host IP itself or the next block's starting address as the network address. For example, choosing 10.20.30.95 or 10.20.30.96 instead of 10.20.30.64.

This happens because the subnet mask’s block size (32 addresses for /27) is overlooked, leading to confusion about which block the host belongs to. Misunderstanding this can cause incorrect subnetting and routing errors in real networks.

Why the other options are wrong

A

10.20.30.32 is incorrect because the host IP 10.20.30.95 does not fall within the 32–63 subnet block. This address belongs to a different subnet block and cannot be the network address for the given host.

C

10.20.30.95 is incorrect because it is the host IP address itself, not the network address. The network address must be the first address in the subnet block, not a host address.

D

10.20.30.96 is incorrect because it is the first address of the next subnet block (96–127). The host IP 10.20.30.95 belongs to the previous block, so 10.20.30.96 cannot be its network address.

When would these options actually be correct?

A

In a different question setup where the subnet mask is /26 instead of /27, the address 10.20.30.32 could be the correct network address for the subnet containing 10.20.30.95.

C

In a different question, if it asked for the specific address assigned to the host within its subnet, then 10.20.30.95 would be the correct answer. For example, 'What is the IP address assigned to the host in the subnet 10.20.30.64/27?' would make this option correct.

D

In a different question setup where the subnet mask is changed to /26, the network address would be 10.20.30.64, and the first usable host address would then be 10.20.30.65, making 10.20.30.96 a valid host address in that context.

Why candidates pick the wrong answer

A

Candidates may be tempted by option A because it is a lower address within the range and might mistakenly associate it with a common subnet calculation, especially if they misinterpret the subnet mask.

C

Candidates may choose this option because it is the address provided in the question, leading to confusion between the host address and the network address.

D

Candidates may choose this option because they misinterpret the subnetting rules and mistakenly believe that any address immediately following the network address can be considered a network address.

926
PBQmedium

You are connected to R1 via the console. R1 is a router that connects to the internet via GigabitEthernet0/0 (198.51.100.1/30) and to the internal network via GigabitEthernet0/1 (10.1.1.1/24). You need to implement a security policy that permits HTTP traffic (port 80) from the internal network to a web server at 10.1.1.100, and denies all other traffic from internal hosts to the internet. The ACL should be named 'INTERNET-FILTER' and applied inbound on GigabitEthernet0/1.

Network Topology
G0/110.1.1.1/24G0/0198.51.100.1/30Web ServerInternalR1ISPInternet

Hints

  • •The ACL should be applied to the interface facing the internal network.
  • •The permit statement must be before the deny statement.
  • •Use the 'eq' keyword to specify port 80.
A.ip access-list extended INTERNET-FILTER permit tcp 10.1.1.0 0.0.0.255 host 10.1.1.100 eq 80 deny ip 10.1.1.0 0.0.0.255 any ! interface GigabitEthernet0/1 ip access-group INTERNET-FILTER in
B.ip access-list standard INTERNET-FILTER permit 10.1.1.0 0.0.0.255 ! interface GigabitEthernet0/1 ip access-group INTERNET-FILTER in
C.ip access-list extended INTERNET-FILTER permit tcp host 10.1.1.100 10.1.1.0 0.0.0.255 eq 80 deny ip any any ! interface GigabitEthernet0/1 ip access-group INTERNET-FILTER in
D.ip access-list extended INTERNET-FILTER permit tcp 10.1.1.0 0.0.0.255 host 10.1.1.100 eq 80 deny ip any any ! interface GigabitEthernet0/0 ip access-group INTERNET-FILTER in
AnswerA
solution
! R1
ip access-list extended INTERNET-FILTER
permit tcp 10.1.1.0 0.0.0.255 host 10.1.1.100 eq 80
deny ip 10.1.1.0 0.0.0.255 any
interface GigabitEthernet0/1
ip access-group INTERNET-FILTER in

Why this answer

The named extended ACL filters traffic based on source, destination, and protocol. The permit allows HTTP from internal to the web server. The deny blocks all other internal-to-internet traffic.

Applying it inbound on the internal interface filters traffic as it enters the router.

Exam trap

Watch out for the direction of the ACL application: inbound on the internal interface filters traffic entering the router from the internal network. Also, remember that extended ACLs are needed when filtering by destination or port.

Why the other options are wrong

B

Standard ACLs cannot match destination IP addresses or port numbers; they only match source IP addresses.

C

The ACL entry incorrectly specifies the web server as the source and the internal network as the destination, which is the opposite of the required direction.

D

Applying the ACL inbound on the external interface filters traffic entering from the internet, not traffic from the internal network. The correct placement is inbound on the internal interface.

Why candidates pick the wrong answer

B

Candidates might think a standard ACL is sufficient because they only need to permit the internal network, but they overlook the need to restrict to a specific destination and port.

C

Candidates may confuse source and destination when writing ACL entries, especially when focusing on the web server as the target of the policy.

D

Candidates might think that applying the ACL on the external interface is more secure, but they forget that the direction of traffic must match the policy intent.

927
Drag & Dropmedium

Drag and drop the following steps into the correct order to plan, configure, and apply an extended ACL that permits web traffic from the 10.1.1.0/24 network to the server 192.168.2.10 while blocking all other traffic inbound on GigabitEthernet0/1.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

ACL configuration requires defining permit/deny statements first, then applying to the interface inbound, and finally verification.

Exam trap

A common trap is to think that you can apply an ACL to an interface before defining it, or that verification should be done before application. Always remember: define, apply, then verify.

Why candidates pick the wrong answer

B

Candidates might think that applying the ACL first and then defining it is acceptable because they confuse the order of operations with other configuration steps where the interface is selected first.

C

Candidates might think verification should be done before applying to catch errors early, but in practice, verification of ACLs involves checking the applied configuration and testing traffic flow.

D

Candidates might be confused by the sequence and think that applying and verifying first is a way to test the interface, but they overlook the necessity of having the ACL defined first.

928
Multi-Selectmedium

Which TWO DHCP snooping trust states are valid on a Cisco switch? (Choose two.)

Select 2 answers
A.Trusted
B.Untrusted
C.Secure
D.Authorized
E.Relay
AnswersA, B

A trusted port is configured using 'ip dhcp snooping trust' and is allowed to forward all DHCP messages, including server responses. This is typically applied to ports connecting to DHCP servers or upstream relay agents.

Why this answer

DHCP snooping is a security feature that filters untrusted DHCP messages on a switch. The only two valid trust states are 'trusted' and 'untrusted'. A trusted port is typically an uplink to a legitimate DHCP server, while an untrusted port is a downstream port where DHCP client messages are expected and server-originated messages are blocked.

Exam trap

Cisco often tests the exact terminology of DHCP snooping trust states, and the trap here is that candidates confuse 'trusted' and 'untrusted' with other security terms like 'secure' or 'authorized' from different features (e.g., port security or 802.1X).

Why the other options are wrong

C

This is a distractor term that does not exist in the DHCP snooping configuration. The correct states are trusted and untrusted.

D

This term is borrowed from other security contexts and is not applicable to DHCP snooping trust states.

E

This confuses the DHCP relay agent feature with DHCP snooping trust states. They are different mechanisms.

929
MCQhard

Based on the exhibit, why is traffic to 192.168.40.200 using the default route instead of the intended static route?

A.The static route next hop is unreachable or invalid for forwarding.
B.Default routes always override static routes.
C.The destination must be configured as a /16, not a /24.
D.Static routes can be used only if OSPF is disabled.
AnswerA

The IPv4 routing table installs a static route only when the next-hop address is reachable via a valid connected or static interface route. If the next hop is unreachable—for example, no directly connected network matches it or the recursive lookup fails—the route is not inserted into the RIB, and traffic to 192.168.40.200 falls back to the default route. Therefore, the static route next hop being unreachable or invalid correctly explains why the destination is not using the static path.

Why this answer

The intended static route is not being used because the next hop for that static route is not reachable from the current routing table. In practical terms, a route can be configured, but the router still needs a way to resolve and forward to the next-hop address. If that next hop is unreachable, the route may not be installed or usable, so traffic falls back to the default route instead.

This is a realistic troubleshooting pattern because the configuration line alone can look correct until you compare it with actual reachability.

Exam trap

Be cautious of confusing administrative distance with reachability issues. Always verify the next hop's reachability.

Why the other options are wrong

B

This option is incorrect because static routes do not inherently get overridden by default routes; rather, the routing table prioritizes routes based on their specificity and administrative distance.

C

This option is incorrect because the subnet mask of the destination IP does not affect the functionality of static routes in this context; static routes can operate with various subnet masks without being limited to /16 or /24.

D

This option is incorrect because static routes can coexist with dynamic routing protocols like OSPF; they do not require OSPF to be disabled to function properly.

When would these options actually be correct?

B

In a different scenario where the question states that the routing protocol is configured to prioritize default routes over static routes due to specific administrative distance settings, option B could be correct. For example, if a network is designed to always prefer default routes for certain traffic types, this option would apply.

C

In a different scenario where a question specifies that a static route must match the subnet mask of the destination network exactly, and the configured static route is /24 while the destination is /16, this option would be correct as it would indicate a misconfiguration preventing traffic from routing properly.

D

In a different scenario, if a question specifies that a network is configured to use OSPF exclusively and that static routes are not permitted due to policy or design constraints, then this option would be correct.

Why candidates pick the wrong answer

B

Candidates might choose this option due to a common misconception that default routes always take precedence over static routes, leading to confusion about route prioritization in routing protocols.

C

Candidates may find this option appealing due to a common misconception that subnet mask mismatches directly impact routing decisions, leading them to believe that the specific mask is critical to route functionality.

D

Candidates may choose this option due to a misunderstanding of routing protocols, believing that static routes are incompatible with dynamic protocols like OSPF, leading to confusion about their operational relationship.

930
MCQhard

An administrator notices that hosts in VLAN 30 on SW1 cannot communicate with hosts in VLAN 30 on SW2, even though both switches are connected via an 802.1Q trunk. Traffic for VLANs 10 and 20 passes without issues across the same trunk. The trunk is configured to allow all VLANs, and the allowed VLAN list explicitly includes VLAN 30. What is the most likely cause of the problem?

A.The native VLAN is mismatched between SW1 and SW2, and VLAN 30 is the native VLAN on one side.
B.The trunk encapsulation is set to ISL on one switch and 802.1Q on the other.
C.Spanning Tree Protocol has placed VLAN 30 in a blocking state on the trunk link.
D.The switched virtual interface (SVI) for VLAN 30 on SW1 is administratively down.
AnswerA

A native VLAN mismatch causes one switch to send untagged frames for VLAN 30 while the other expects tagged frames, so the receiving switch cannot associate the untagged traffic with VLAN 30, leading to a communication failure only for that VLAN.

Why this answer

The most likely cause is a native VLAN mismatch. When the native VLAN is mismatched on an 802.1Q trunk, traffic for the native VLAN is not tagged, so frames from VLAN 30 on one switch are received as untagged frames on the other switch and placed into the switch's configured native VLAN. If the native VLAN on one side is VLAN 30 and on the other side is a different VLAN (e.g., VLAN 1), the hosts in VLAN 30 cannot communicate because the frames are interpreted as belonging to different VLANs.

Traffic for VLANs 10 and 20 passes because they are not the native VLAN and are properly tagged.

Exam trap

Cisco often tests the native VLAN mismatch scenario by describing a trunk that works for most VLANs but fails for one specific VLAN, leading candidates to incorrectly suspect STP blocking or SVI issues instead of recognizing the native VLAN mismatch.

Why the other options are wrong

B

This would cause a complete trunk failure, not a failure limited to a single VLAN.

C

STP would not randomly block one VLAN on a point-to-point trunk while the rest are forwarding; this is not a typical behavior.

D

Layer 2 switching within the same VLAN does not require an SVI; an SVI is only needed for routing between VLANs or management.

931
MCQhard

Exhibit: A switch interface connected to an IP phone and PC is configured as an access port in VLAN 10. The PC works, but the phone does not register. What additional configuration is most likely needed?

A.switchport trunk encapsulation dot1q
B.switchport voice vlan <voice-vlan-id>
C.channel-group 1 mode active
D.ip helper-address on the switchport
AnswerB

This command configures a dedicated voice VLAN on an access port connected to an IP phone. It allows the phone to tag voice traffic with the specified VLAN ID while the attached PC remains untagged in the access VLAN, enabling separate QoS policies and subnets for voice and data. This is the standard Cisco configuration for a single switchport carrying both phone and PC traffic.

Why this answer

An IP phone commonly requires a voice VLAN so tagged voice traffic is separated from the data VLAN used by the attached PC. Without a voice VLAN, the PC can still work on the access VLAN while the phone fails to register properly.

Exam trap

Don't confuse portfast or trunk mode with the need for a voice VLAN. Focus on the specific requirements of IP phones.

Why the other options are wrong

A

This option is incorrect because the question specifies an access port configuration, which does not require trunk encapsulation. Access ports do not use trunking protocols like dot1q, as they are meant for single VLAN traffic only.

C

This option is wrong because the channel-group command is used for configuring EtherChannel, which is not relevant to the issue of the IP phone not registering on an access port. The problem lies in the VLAN configuration for voice traffic, not in link aggregation.

D

The 'ip helper-address' command is used to forward DHCP requests from clients to a DHCP server, but it does not address the registration issue of the IP phone in this scenario, which is related to VLAN configuration.

When would these options actually be correct?

A

In a scenario where the question involves a switch port configured as a trunk, and the requirement is to ensure proper encapsulation for multiple VLANs, this option would be correct. For example, if the question asked about a trunk port connecting to a router or another switch, specifying trunk encapsulation would be necessary.

C

In a different scenario where the question involves configuring multiple switches for load balancing and redundancy, the option 'channel-group 1 mode active' would be correct if the exam asked about setting up an EtherChannel between two switches to aggregate bandwidth and ensure high availability.

D

In a question where a network administrator is troubleshooting DHCP issues for multiple devices on a subnet, and the devices are unable to obtain IP addresses, the correct answer would involve configuring 'ip helper-address' on the switchport to direct DHCP requests to the appropriate server.

Why candidates pick the wrong answer

A

Candidates may find this option tempting because they might associate VLAN configurations with trunking, especially if they have experience with mixed VLAN environments where trunking is common.

C

Candidates may find this option tempting because they might confuse the need for proper link configuration with the requirement for voice VLANs, thinking that channel aggregation could somehow resolve connectivity issues for devices on the same port.

D

Candidates might choose this option because they associate 'ip helper-address' with network connectivity issues, mistakenly thinking it could resolve any problem related to device registration or connectivity.

932
MCQhard

Two directly connected routers, R1 and R2, are configured with single-area OSPF in Area 0. The administrator notices that they are not forming a full OSPF neighbor adjacency. The exhibit displays relevant portions of the running configurations. What is the most likely cause of the problem?

A.The network command on R1 does not include the correct subnet mask.
B.R1's passive-interface default prevents OSPF hello packets from being sent on GigabitEthernet0/0.
C.The GigabitEthernet0/0 interface on R2 is administratively down.
D.The routers are configured with different OSPF area IDs.
AnswerB

R1's configuration includes `passive-interface default`, which makes all OSPF-enabled interfaces passive by default. A passive interface does not send or process OSPF hello packets, so R1 never establishes a neighbor relationship on GigabitEthernet0/0. Unless a `no passive-interface GigabitEthernet0/0` statement is present, hellos are suppressed even though the interface is up and the network statement matches.

Why this answer

The passive-interface default command on R1 sets all interfaces to passive by default, which prevents OSPF hello packets from being sent out GigabitEthernet0/0. Without hello packets, R1 cannot discover R2 or form a neighbor adjacency, even though the network command is correctly configured. This is the most likely cause because the exhibit shows R1's configuration includes passive-interface default without a corresponding no passive-interface GigabitEthernet0/0 statement.

Exam trap

Cisco often tests the passive-interface default command as a trap, because candidates may overlook that it applies to all interfaces unless explicitly overridden, leading them to incorrectly focus on network command mismatches or area ID issues.

Why the other options are wrong

A

The network statement is syntactically correct and covers the interface IP address, so it does enable OSPF process on that interface (subject to the passive-interface setting).

C

The configuration shows 'no shutdown', indicating the interface is enabled. Administrative down would require the 'shutdown' command or lack of 'no shutdown'.

D

The output clearly shows 'area 0' in both routers' OSPF configurations, so area mismatch is not the cause.

933
MCQhard

A network engineer is troubleshooting intermittent connectivity on an access switch port connected to a server. The output of 'show interfaces gigabitEthernet 1/0/24' shows an increasing number of runts and giants, but no CRC errors. The 'show interfaces status' command indicates the port is in 'err-disabled' state every few hours and must be manually re-enabled. What is the most likely cause of this issue?

A.Duplex mismatch between the switch port and the server NIC
B.Faulty cable or connector causing physical layer errors
C.Incorrect VLAN configuration on the switch port
D.Speed mismatch between the switch port and the server NIC
AnswerB

Runts and giants without CRC errors often indicate physical layer issues like a bad cable, connector, or excessive noise. The cable length at maximum (100 meters) and MDIX off suggest potential signal degradation, leading to intermittent flapping and err-disabled state.

Why this answer

Runts and giants without CRC errors indicate a physical-layer issue that corrupts the frame preamble or interframe gap but not the actual data payload. A faulty cable or connector can cause signal degradation leading to these framing errors. The intermittent err-disabled state is typically triggered by link-flap (repeated link up/down events) caused by the unstable physical connection, not directly by alignment or frame-check error counters.

Exam trap

Cisco often tests the distinction between CRC errors (data corruption) and runts/giants (framing errors) to mislead candidates into thinking duplex mismatch is the cause, but duplex mismatch produces CRC errors and collisions, not runts/giants without CRC errors.

Why the other options are wrong

A

Duplex mismatch would cause CRC errors and late collisions, which are not present in the exhibit.

C

VLAN mismatch does not cause runts or giants; it causes Layer 2 issues like no connectivity.

D

Speed mismatch would prevent the link from coming up or cause CRC errors, but the link is up at 1000 Mb/s.

934
MCQhard

Exhibit: A client can ping 8.8.8.8 but cannot browse to www.example.com. Which service is most likely failing?

A.NTP
B.DNS
C.DHCP snooping
D.HSRP
AnswerB

The client can ping 8.8.8.8, proving IP connectivity and routing are operational, but it cannot browse to www.example.com. Browsing requires resolving the hostname to an IP address via DNS. Since the ping to a public IP succeeds, the failure is isolated to name resolution, meaning the DNS query is failing, the DNS server is unreachable, or the client's DNS settings are incorrect.

Why this answer

The client has IP connectivity because it can reach 8.8.8.8 directly. The problem appears only when using a hostname, which points to a DNS resolution issue rather than a routing issue.

Exam trap

A frequent exam trap is assuming that successful ping to an IP address means all network services are functioning correctly. Candidates often overlook that ping uses numeric IP addresses and does not test DNS resolution. This leads to the incorrect conclusion that the network is fully operational, causing them to eliminate DNS as a problem.

The trap is reinforced by the presence of other options like DHCP snooping or HSRP, which are unrelated to hostname resolution but may seem plausible. Recognizing that DNS specifically enables hostname-to-IP translation is essential to avoid this mistake.

Why the other options are wrong

A

NTP (Network Time Protocol) synchronizes clocks across devices but does not affect the ability to resolve domain names or browse websites. Since the client can ping an IP address, time synchronization issues are unlikely to cause the browsing failure.

C

DHCP snooping is a security feature that prevents rogue DHCP servers but does not directly impact DNS resolution or hostname-based browsing. The client already has IP connectivity, so DHCP snooping is not the issue.

D

HSRP provides gateway redundancy and failover but does not influence DNS or hostname resolution. Since the client can reach an external IP, the default gateway is functioning, so HSRP failure is unlikely.

When would these options actually be correct?

A

If the question were about a scenario where a device is unable to synchronize its time with an NTP server, and this time discrepancy causes issues with time-sensitive applications or protocols, then NTP would be the correct answer. For example, if a client can access IP addresses but fails to authenticate to a time-sensitive service due to incorrect timestamps, NTP would be the failing service.

C

If the question were framed to ask about a network where clients are unable to obtain IP addresses due to DHCP snooping being misconfigured, leading to connectivity issues, then selecting DHCP snooping would be correct. For example, if clients could ping known IPs but not access any domain names due to IP assignment issues, it would fit.

D

If the question were framed around a scenario where a client is unable to reach a default gateway due to a failure in HSRP, such as when two routers are configured for HSRP and one fails, causing loss of redundancy, then HSRP would be the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse the importance of synchronized time in network operations with general connectivity issues, leading them to incorrectly associate NTP with browsing problems when they see a network-related question.

C

Candidates might confuse DHCP snooping with general connectivity issues, thinking that any network-related problem could be attributed to DHCP configurations, especially if they have limited experience with DNS and its role in name resolution.

D

Candidates may confuse HSRP with general network connectivity issues, thinking that if redundancy fails, it could impact the ability to access web resources, leading them to select this option.

935
MCQhard

Based on the exhibit, what is the strongest explanation for why clients can browse by IP address but not by hostname?

A.Name resolution is failing even though IP connectivity works.
B.The client has the wrong default gateway.
C.The switch trunk native VLAN is wrong.
D.The server must run PPP before hostnames can work.
AnswerA

IP connectivity is proven because browsing by IP address succeeds, so the fault lies above Layer 3. Hostname browsing depends on DNS, therefore a failure in name resolution — not routing or interface state — is the strongest explanation for the symptom described.

Why this answer

The strongest explanation is a DNS failure or DNS configuration problem. In practical terms, successful browsing by IP address shows that the client can already reach the destination over the network path. When the same service fails only by hostname, the issue is much more likely in name resolution than in routing, switching, or raw connectivity.

This is one of the most useful support patterns because it quickly separates path problems from naming problems.

Exam trap

A frequent exam trap is assuming that if hostname resolution fails, the problem must be with routing or VLAN configurations such as the default gateway or switch trunk native VLAN. However, since clients can browse by IP address, these path elements are functioning correctly. Misattributing the failure to routing or VLAN issues wastes time and leads to incorrect answers.

The key mistake is not recognizing that DNS operates at a higher layer and that name resolution failures are distinct from IP connectivity problems.

Why the other options are wrong

B

Option B is incorrect because the client can already reach the server by IP address, proving the default gateway is functioning properly and not the cause of hostname resolution failure.

C

Option C is wrong since a switch trunk native VLAN mismatch would cause broader connectivity issues, not just hostname resolution failures. The symptom is specific to name-based access, not total path failure.

D

Option D is incorrect because PPP is unrelated to DNS or hostname resolution in this context. PPP is a WAN protocol and does not affect LAN-based DNS name resolution.

When would these options actually be correct?

B

In a different scenario where a client is unable to connect to any external resources, including both IP and hostname, the question might ask why the client cannot access the internet. In that case, if the default gateway is misconfigured, it would be the correct answer as it would block all traffic.

C

In a different scenario, if the question involved a network where clients are unable to communicate across VLANs due to misconfigured trunk settings, and the context indicated that hostname resolution relies on inter-VLAN routing, then this option could be correct.

D

In a scenario where the question asks about the necessity of specific protocols for establishing network connections, such as a question about how to configure a network for dial-up connections, this option could be correct if it stated that PPP is required for establishing a connection before DNS queries can be made.

Why candidates pick the wrong answer

B

Candidates may choose this option because they associate default gateway issues with connectivity problems, leading them to mistakenly believe it could affect hostname resolution despite existing IP connectivity.

C

Candidates might choose this option due to a misunderstanding of how VLANs and trunking affect network communication, mistakenly believing that improper VLAN configurations could impact hostname resolution.

D

Candidates might find this option tempting due to a misunderstanding of the relationship between network protocols and name resolution, leading them to incorrectly associate PPP with hostname functionality.

936
MCQmedium

A small office network uses a single public IP address on its router's WAN interface. The network administrator needs to allow all internal hosts to access the internet, but must also ensure that an internal web server with a private IP address is reachable from the internet. Which NAT configuration should the administrator implement to meet both requirements?

A.Configure dynamic NAT with a pool of public IPs and static NAT for the web server.
B.Configure PAT (overload) for internal hosts and static NAT for the web server.
C.Configure only PAT (overload) for all internal hosts including the web server.
D.Configure static NAT for the web server and use only the public IP for internal hosts.
AnswerB

This is correct because PAT (overload) allows all internal hosts to share the single public IP for outbound traffic by multiplexing sessions through unique source ports. Simultaneously, a static NAT entry maps the web server's private address to the same public IP (or a dedicated global address) to create a permanent one-to-one relationship. That permanent mapping lets Internet clients initiate inbound connections to the web server, while PAT handles all other internal hosts' outbound requests. Together, they maximize the use of the limited public address space while providing both outbound and inbound connectivity.

Why this answer

PAT (Port Address Translation), also known as NAT overload, allows multiple internal hosts to share a single public IP address by mapping each session to a unique port number, satisfying the requirement for internet access. Static NAT is then used to create a one-to-one mapping from the public IP (on a specific port) to the private IP of the internal web server, making it reachable from the internet. This combination meets both outbound connectivity for all hosts and inbound access to the web server without needing additional public IPs.

Exam trap

Cisco often tests the misconception that PAT alone can handle inbound traffic, but the trap here is that PAT only translates outbound sessions unless a static entry is explicitly configured for the server, leading candidates to incorrectly select option C.

Why the other options are wrong

A

Only one public IP is available, so a pool cannot be created.

C

Inbound access to the web server would not be possible without a static mapping.

D

Internal hosts would not be able to access the internet because they lack public IP assignments.

937
MCQhard

A host is physically connected to switch port Gi0/3. The technician runs 'show mac address-table' but does not find the host's MAC address for Gi0/3. The port status shows 'up/up', and the host was connected only a few minutes ago. What should the technician do next?

A.Clear the MAC address table with 'clear mac address-table dynamic' to force immediate relearning.
B.Verify the VLAN assignment on Gi0/3 using 'show vlan brief' or 'show interfaces Gi0/3 switchport'.
C.Check the STP state of Gi0/3 with 'show spanning-tree interface Gi0/3' to ensure it is not blocking.
D.Inspect the ARP cache with 'show ip arp' to check for duplicate IP addresses.
AnswerB

The switch learns MAC addresses per VLAN. If Gi0/3 is in an unexpected VLAN, the MAC address will be learned in that VLAN's table and not visible in the default or expected VLAN view. Checking the VLAN membership directly confirms whether the host is in the correct Layer 2 broadcast domain.

Why this answer

The most likely reason a newly connected host's MAC address does not appear in the MAC address table is that the switch port is in the wrong VLAN or is administratively configured as an access port in a VLAN that does not match the host's expected VLAN. The 'show vlan brief' command verifies VLAN existence and port membership, while 'show interfaces Gi0/3 switchport' confirms the operational VLAN assignment. Since the port is up/up and the host was connected only minutes ago, the switch should have learned the MAC address via normal flooding; its absence points to a VLAN mismatch or port configuration issue, not a stale table or STP blocking.

Exam trap

Cisco often tests the misconception that a missing MAC address is due to STP blocking or a stale table, when in fact the port being 'up/up' and recently connected makes VLAN misconfiguration the most logical first step to troubleshoot.

Why the other options are wrong

A

This is a drastic action that does not address a VLAN mismatch; the same symptom would recur.

C

Jumping to STP before confirming basic Layer 2 VLAN membership is not the most efficient next step.

D

This option confuses Layer 2 MAC learning with Layer 3 ARP resolution, and does not help locate the MAC entry in the address table.

938
MCQhard

Refer to the exhibit. A network engineer is troubleshooting an OSPF adjacency issue between R1 and R2. The output of the show ip ospf neighbor command on R1 shows the neighbor relationship with R2 stuck in the EXSTART/DROTHER state. What is the most likely cause?

A.OSPF network type mismatch between R1 and R2, preventing full adjacency.
B.Duplicate OSPF Router IDs on R1 and R2, causing DBD packet rejection.
C.OSPF authentication mismatch on the link, causing DBD packets to be rejected.
D.MTU mismatch on the link between R1 and R2, causing DBD packets to be dropped.
AnswerD

The EXSTART/DROTHER state in the exhibit indicates that OSPF is stuck in the DBD exchange phase. This is a classic symptom of an MTU mismatch, where one side creates DBD packets larger than the other's MTU, leading to silent drops. The output directly confirms the neighbor is in EXSTART, not EXCHANGE or FULL.

Why this answer

The EXSTART/DROTHER state indicates that the routers have progressed beyond the 2-WAY state but are stuck during the Database Description (DBD) packet exchange phase. An MTU mismatch between R1 and R2 causes DBD packets to be dropped because the receiving router will reject packets larger than its configured interface MTU, preventing the routers from completing the master/slave election and database synchronization.

Exam trap

The trap here is that candidates often confuse the EXSTART/DROTHER state with authentication or network type mismatches, but Cisco specifically tests that MTU mismatches cause DBD packet drops during the database exchange phase, not earlier adjacency stages.

Why the other options are wrong

A

Candidates may confuse adjacency failures with DBD exchange problems, but network type mismatch leads to a different state (2-WAY).

B

Candidates think duplicate Router IDs might cause DBD exchange failure, but duplicate IDs prevent neighbor discovery entirely.

C

Many associate EXSTART with any adjacency issue, but authentication errors prevent the neighbor from being listed at all.

939
MCQhard

Exhibit: A script sends an API request and receives HTTP status code 401. What does that code indicate?

A.The requested resource was not found
B.The client is not authenticated successfully
C.The server completed the request successfully
D.The server rejected the request because the JSON body was too large
AnswerB

A 401 Unauthorized status code explicitly indicates that the HTTP request was received but the server could not authenticate the client's identity. This means the script failed to provide valid credentials, such as a missing API key, expired token, or malformed Authorization header. The server must verify who the client is before processing the request, and without valid authentication it responds with 401 rather than fulfilling the API call. Therefore, the client is not authenticated successfully.

Why this answer

HTTP 401 means the request was not accepted because authentication is required or the provided credentials or token were invalid. In practice, the first thing to check is the token, username, password, or auth header format.

Exam trap

Don't confuse authentication errors with server errors or resource availability issues. Focus on the specific meaning of each HTTP status code.

Why the other options are wrong

A

HTTP status code 401 specifically indicates unauthorized access due to missing or invalid authentication. A 'resource not found' is indicated by 404, not 401.

C

HTTP 401 indicates authentication failure, not successful completion. A 200-level code would indicate success.

D

HTTP 401 indicates authentication failure, not a request entity too large. The '413 Payload Too Large' status code is used when the request body exceeds the server's limit.

When would these options actually be correct?

A

If the question were 'What does HTTP status code 404 indicate?', then option A would be correct, as 404 means the requested resource was not found.

C

If the question asked 'What does HTTP status code 200 indicate?' or 'Which status code means the request succeeded?', then 'The server completed the request successfully' would be correct.

D

A question asks: 'A client sends a POST request with a JSON payload exceeding the server's maximum allowed size. Which HTTP status code would the server return?' In that scenario, D (413) would be correct.

Why candidates pick the wrong answer

A

Candidates may confuse 401 with 404 because both are client error codes, and they might think 'not found' is a generic error for any failed request.

C

Candidates may confuse 401 with a successful response because they think 'unauthorized' means the request was processed but denied, or they misremember status code ranges.

D

Candidates may confuse 401 with 413 because both involve client errors, or they might think a large JSON body causes an authentication-like rejection due to server security policies.

940
PBQmedium

You are connected to R1 via console. R1 has three directly connected subnets: 192.168.1.0/24 (G0/0), 192.168.2.0/24 (G0/1), and 192.168.3.0/24 (G0/2). You need to configure a summary route to be advertised to a neighbor via a static route pointing to Null0 to prevent routing loops. The summary should cover all three subnets.

Hints

  • •Determine the smallest subnet mask that can summarize the three /24 networks.
  • •The summary route should be a single prefix that covers all three subnets.
  • •Use Null0 as the next-hop to drop traffic that does not match a more specific route.
A.ip route 192.168.0.0 255.255.252.0 Null0
B.ip route 192.168.1.0 255.255.252.0 Null0
C.ip route 192.168.0.0 255.255.255.0 Null0
D.ip route 192.168.0.0 255.255.254.0 Null0
AnswerA
solution
! R1
ip route 192.168.0.0 255.255.252.0 Null0

Why this answer

The three subnets 192.168.1.0/24, 192.168.2.0/24, and 192.168.3.0/24 can be summarized as 192.168.0.0/22, which covers 192.168.0.0 to 192.168.3.255. A static route to Null0 ensures that traffic matching the summary but not a more specific route is dropped, preventing routing loops.

Exam trap

When summarizing, ensure the summary network address is the first address in the block (aligned to the subnet boundary) and the mask is calculated correctly. A common mistake is to start the summary at the first subnet address (192.168.1.0) instead of the network address (192.168.0.0). Also, verify the mask covers all subnets without including extra networks.

Why the other options are wrong

B

The network address is wrong; the summary must start at 192.168.0.0, not 192.168.1.0.

C

The subnet mask /24 is too small; it does not summarize the three subnets.

D

The subnet mask /23 is too specific; it only covers two of the three subnets.

Why candidates pick the wrong answer

B

Candidates might think the summary should start at the first subnet (192.168.1.0) but forget that the summary network address must be aligned to the subnet boundary.

C

Candidates might confuse the summary route with a static route to a specific subnet, or think that using the first subnet's mask is sufficient.

D

Candidates might miscalculate the summary mask, thinking that /23 covers 192.168.0.0 to 192.168.3.255, but it actually only covers up to 192.168.1.255.

941
MCQmedium

A branch router learns a route to 10.20.30.0/24 from OSPF with metric 30 and also has a static route to the same prefix with an administrative distance of 5. Which route will appear in the routing table?

A.The OSPF route because metric 30 is lower than the static route metric
B.The static route because its administrative distance is lower
C.Both routes with equal preference because they point to the same prefix
D.Neither route until the router performs a full SPF recalculation
AnswerB

A static route is assigned an administrative distance of 1 by default in Cisco IOS, whereas an OSPF internal route has an AD of 110. Because the router always prefers the route with the lowest AD, it installs the static route in the routing table and uses it to forward traffic to 10.20.30.0/24. The OSPF route is retained in the OSPF database but not placed in the RIB.

Why this answer

The router installs the static route because administrative distance is compared before metric when two different routing sources advertise the same prefix. OSPF metric matters only against other OSPF choices, not against a lower-AD static route.

Exam trap

A common exam trap is to confuse the OSPF metric with administrative distance and assume the route with the lower metric is preferred. Since OSPF’s metric is 30 and the static route’s metric is not applicable or higher, candidates may incorrectly select the OSPF route. However, Cisco routers first compare administrative distance, which is a measure of route trustworthiness across different routing sources.

Because the static route has a lower administrative distance (5) than OSPF (110), the static route is preferred and installed in the routing table. Misunderstanding this leads to incorrect route selection and exam errors.

Why the other options are wrong

A

This option is incorrect because metric values are only compared among routes learned from the same routing protocol. The OSPF metric of 30 is irrelevant when compared to a static route, which is a different routing source with a lower administrative distance.

C

This option is incorrect because routers do not install multiple routes to the same prefix from different routing protocols unless they have equal administrative distance and are configured for load balancing. Here, the static route’s lower AD prevents the OSPF route from being installed.

D

This option is incorrect because the router does not delay route installation until a full SPF recalculation. Route selection is immediate based on administrative distance and metric rules. SPF recalculation only affects OSPF route selection, not cross-protocol comparisons.

When would these options actually be correct?

A

In a different scenario, if the question stated that the static route had an administrative distance of 200, the OSPF route would be selected due to its lower administrative distance, making option A correct. This would change the preference dynamics between the routes.

C

In a different question where both OSPF and static routes are configured for ECMP and have the same administrative distance, the routing table could show both routes as valid options for load balancing traffic to the same prefix.

D

In a scenario where a router is configured to only install routes after a full SPF recalculation is completed, such as during a network convergence event, this option could be correct. For example, if the router has just rebooted and is waiting for OSPF to converge, it might not install any routes until the SPF process is complete.

Why candidates pick the wrong answer

A

Candidates may be misled by the metric comparison, mistakenly believing that a lower OSPF metric automatically makes it the preferred route, without considering the critical role of administrative distance in route selection.

C

Candidates may choose this option due to a misunderstanding of how routing protocols interact, assuming that multiple valid routes can coexist without considering administrative distance and routing table rules.

D

Candidates may choose this option due to a misunderstanding of how routing protocols interact with static routes, believing that OSPF must always recalculate before any routes are used, which is not the case with static routes.

942
MCQmedium

Hosts in VLAN 10 need to communicate with hosts in VLAN 20. What is required for that communication to work?

A.A DHCP server
B.A DNS server
C.A Layer 3 routing function
D.A second access switch
AnswerC

Layer 3 routing is the required mechanism because VLANs represent separate broadcast domains and distinct IP subnets. A router or multilayer switch must inspect the destination IP address, perform a route lookup, and rewrite the frame's MAC addresses before forwarding the packet to the destination VLAN. Without this IP-level forwarding decision, frames remain confined to their originating Layer 2 domain, so no traffic can cross the VLAN boundary.

Why this answer

Traffic between VLANs must be routed. A router or multilayer switch provides the Layer 3 function needed for inter-VLAN communication.

Exam trap

Do not confuse trunk links or access ports with routing functions; they serve different purposes in VLAN configurations.

Why the other options are wrong

A

A DHCP server is not required for communication between VLANs; it only assigns IP addresses to devices within a network. VLAN communication requires routing, which a DHCP server does not provide.

B

A DNS server is not required for VLAN communication, as DNS resolves domain names to IP addresses, which does not facilitate inter-VLAN routing. Communication between VLANs requires Layer 3 routing, not name resolution.

D

A second access switch is not required for VLAN communication; VLANs can communicate through a Layer 3 device such as a router or a Layer 3 switch. The existing switch infrastructure can handle VLANs without needing additional switches.

When would these options actually be correct?

A

If the question asked about enabling IP address assignment for hosts in VLAN 10 and VLAN 20, where both VLANs are on the same network segment, then a DHCP server would be necessary to ensure that devices in both VLANs receive valid IP addresses.

B

In a question asking about network services needed for host name resolution in a multi-VLAN environment, where hosts in different VLANs need to resolve each other's domain names, a DNS server would be essential for that purpose.

D

If the exam question specified that the network was experiencing performance issues due to too many VLANs being managed by a single switch, and suggested that adding a second access switch could help distribute the load and improve communication efficiency, then this option would be correct.

Why candidates pick the wrong answer

A

Candidates may confuse the need for IP address assignment with the requirement for inter-VLAN communication, leading them to believe that a DHCP server is essential for connectivity between VLANs.

B

Candidates may confuse the need for network services in a multi-VLAN setup, mistakenly believing that DNS is necessary for communication, as it is often associated with network functionality and connectivity.

D

Candidates might choose this option because they associate VLANs with physical switch configurations and believe that additional hardware is necessary for inter-VLAN communication, overlooking the role of Layer 3 routing.

943
MCQhard

A multilayer switch must route traffic between VLAN 10 and VLAN 20. Which condition is required for that to happen?

A.SVIs for the VLANs plus Layer 3 routing enabled on the switch
B.All ports in both VLANs configured as trunks
C.A separate OSPF process on every access port
D.Port security disabled on every edge port
AnswerA

On a multilayer switch, inter-VLAN routing is accomplished by creating a Switch Virtual Interface (SVI) for each VLAN and assigning each SVI an IP address in its respective subnet. These SVIs act as the default gateway for hosts in their VLAN, and the switch must have IP routing globally enabled with 'ip routing' so it can forward packets between the SVIs at Layer 3. This is the standard method for inter-VLAN routing on a multilayer switch, as opposed to using an external router or router-on-a-stick.

Why this answer

Inter-VLAN routing on a multilayer switch depends on having functional Layer 3 gateway interfaces for the VLANs and routing enabled on the switch. In plain language, the switch needs a routed brain for each VLAN, usually in the form of SVIs, and it must actually be operating as a Layer 3 device rather than only as a pure Layer 2 switch. Without those conditions, traffic may switch inside a VLAN but cannot be routed between different VLANs.

This is a core CCNA design idea because people often assume creating VLANs alone automatically gives them inter-VLAN communication. In reality, VLANs create separation, and routing is what reconnects them under controlled conditions. A trunk between switches can carry VLAN traffic, but it does not itself perform Layer 3 routing between the VLANs. The correct answer is the requirement that makes the switch act as the gateway between VLANs.

Exam trap

Don't confuse trunking with routing; trunk ports carry VLAN traffic but don't route it.

Why the other options are wrong

B

This option is wrong because configuring all ports as trunks does not facilitate inter-VLAN routing; SVIs and Layer 3 routing are necessary for that functionality.

C

This option is wrong because OSPF is a routing protocol used for dynamic routing, and access ports do not participate in routing processes. Routing between VLANs requires SVIs and Layer 3 capabilities, not OSPF on access ports.

D

Port security being disabled on every edge port is not a requirement for routing traffic between VLANs; it pertains to security configurations rather than routing functionality. VLAN routing can occur regardless of port security settings.

When would these options actually be correct?

B

If the question asked about ensuring VLAN traffic can traverse between switches without specifying routing, and focused on the physical connection setup, then having all ports configured as trunks would be correct to allow VLAN tagging and traffic flow.

C

If the question asked about configuring a Layer 3 switch to support dynamic routing protocols for VLANs, and it specified that OSPF should be used for inter-VLAN routing, then having a separate OSPF process on every access port would be relevant to the configuration.

D

In a scenario where the question asks about ensuring that a switch can handle traffic without any security restrictions, such as in a lab environment where security is not a concern, the requirement to disable port security on edge ports would be correct.

Why candidates pick the wrong answer

B

Candidates may choose this option because they associate trunking with VLAN communication and may overlook the requirement for Layer 3 routing to enable inter-VLAN traffic.

C

Candidates may find this option tempting because they associate OSPF with routing and may incorrectly believe that it is necessary for VLANs to communicate, overlooking the need for SVIs and Layer 3 routing instead.

D

Candidates may confuse the need for proper VLAN configurations with security settings, mistakenly believing that disabling port security is essential for routing capabilities, especially if they associate VLANs with access control measures.

944
MCQhard

A network engineer is troubleshooting a link between two Cisco Catalyst 9300 switches that are connected via a 10GBASE-SR SFP+ module on each end over OM3 multimode fiber. The link is up, but the interface counters show a high number of CRC errors and runts. The engineer runs 'show interfaces Gi1/0/1' and 'show interfaces Gi1/0/1 transceiver details'. What is the most likely cause of the errors?

A.The SFP+ module is faulty and needs replacement.
B.The fiber patch cables are too long, exceeding the 300-meter distance limit for 10GBASE-SR over OM3 fiber.
C.The interface speed is mismatched; the switch interface shows 1000Mb/s but the SFP+ is 10GBASE-SR.
D.The receive optical power is too low, indicating a fiber or connector issue.
AnswerD

The receive power of -15.1 dBm is below the typical receive sensitivity for 10GBASE-SR (about -12.6 dBm). This causes bit errors that appear as CRC errors and runts. The transmit power is normal, so the issue is on the receive side, likely dirty connectors or a damaged fiber.

Why this answer

The high CRC errors and runts on a 10GBASE-SR link over OM3 fiber, combined with the 'show interfaces transceiver details' command, point to a physical-layer issue. Low receive optical power (below the receiver sensitivity threshold) causes bit errors that manifest as CRC errors and runts, even though the link is up. This is the most common cause when the fiber and transceivers are otherwise compatible.

Exam trap

Cisco often tests the misconception that CRC errors always indicate a faulty transceiver or cable length issue, when in reality low optical power from dirty or damaged connectors is a more common and subtle cause on fiber links.

Why the other options are wrong

A

The transceiver diagnostics show no fault flags, and the module is reporting nominal bit rate and other values within range.

B

The distance itself is within spec; the issue is the receive power being too low, not the distance exceeding the limit.

C

This is a configuration mismatch, but it does not directly cause CRC errors. The CRC errors are due to low receive power.

945
PBQhard

You are connected to R1 via console. The network consists of R1, R2, and a multilayer switch MLS1. R1's GigabitEthernet0/0 connects to MLS1's GigabitEthernet1/0/1 (VLAN 10), and MLS1's GigabitEthernet1/0/2 connects to R2's GigabitEthernet0/0. The goal is to enable IPv6 communication between R1 and R2 across the layer-3 switch. Currently, R1 and R2 cannot ping each other's IPv6 addresses. Configure R1's G0/0 with the IPv6 prefix 2001:db8:1:10::/64 using EUI-64, and R2's G0/0 with static IPv6 address 2001:db8:1:10::2/64. Also ensure MLS1 has IPv6 routing enabled and an IPv6 address on VLAN 10 (2001:db8:1:10::3/64). Troubleshoot and fix any layer-2 or layer-3 issues preventing connectivity.

Network Topology
G0/0G1/0/1G1/0/1G0/0SiMLS1R1R2

Hints

  • •R1's G0/0 has no IPv6 address configured.
  • •The correct command uses the 'eui-64' keyword to generate the interface ID from the MAC.
  • •After configuration, R1 should be able to ping the other IPv6 addresses.
A.Configure 'ipv6 address 2001:db8:1:10::/64 eui-64' on R1's G0/0 interface.
B.Enable IPv6 routing on R1 with 'ipv6 unicast-routing'.
C.Configure 'ipv6 address 2001:db8:1:10::1/64' on R1's G0/0 interface (without EUI-64).
D.Change the VLAN on MLS1's G1/0/1 to match R1's VLAN.
AnswerA
solution
! R1
interface GigabitEthernet0/0
ipv6 address 2001:db8:1:10::1/64 eui-64
end

Why this answer

R1 has no IPv6 address configured on G0/0. The required prefix is 2001:db8:1:10::/64 using EUI-64, which generates the interface ID from the MAC address. The command 'ipv6 address 2001:db8:1:10::/64 eui-64' must be entered in interface configuration mode.

Additionally, MLS1 has IPv6 routing enabled (as seen by the connected route), but R1's interface is missing the IPv6 address. After configuration, R1 will be able to ping R2 and MLS1. No other changes are needed because R2 and MLS1 are correctly configured.

Exam trap

Do not confuse global IPv6 routing enablement with interface address configuration. The presence of a connected route indicates routing is enabled; the missing piece is the interface address. Also, pay attention to specific requirements like EUI-64.

Why the other options are wrong

B

IPv6 unicast-routing is already enabled; the problem is at the interface level.

C

The requirement specifies EUI-64; omitting it results in a static address that does not match the intended configuration.

D

The VLAN configuration is correct; no change is needed.

Why candidates pick the wrong answer

B

Candidates often assume that IPv6 routing must be enabled globally, but in this scenario it is already configured.

C

Candidates might think a static address is sufficient, but the question mandates EUI-64.

D

Candidates might suspect a layer-2 issue, but the problem is at layer 3 on R1.

946
PBQhard

You are connected to switch SW1. The network uses Rapid-PVST+ and SW1 has been accidentally configured with a low spanning-tree priority, causing it to become the root bridge for VLAN 10 even though it should not be. Additionally, an edge port connected to a server is repeatedly receiving BPDUs, causing it to go into err-disabled state. Configure SW1 so that it is never the root bridge for VLAN 10, and configure the edge port so that it automatically recovers from err-disabled state after 300 seconds. Finally, verify that SW1 is not the root bridge for VLAN 10.

Network Topology
Gi0/0Gi0/0Gi0/1SW1SW2Server

Hints

  • •To prevent a switch from becoming root, set its priority to a value higher than the current root's priority (e.g., 32768).
  • •The errdisable recovery cause command enables automatic recovery; the interval command sets the timeout.
  • •After configuration, verify with 'show spanning-tree vlan 10' that the bridge ID priority is not the lowest.
A.spanning-tree vlan 10 priority 36864; errdisable recovery cause bpduguard; errdisable recovery interval 300; show spanning-tree vlan 10
B.spanning-tree vlan 10 priority 4096; errdisable recovery cause bpduguard; errdisable recovery interval 300; show spanning-tree vlan 10
C.spanning-tree vlan 10 root secondary; errdisable recovery cause bpduguard; errdisable recovery interval 300; show spanning-tree vlan 10
D.spanning-tree vlan 10 priority 32768; errdisable recovery cause all; errdisable recovery interval 300; show spanning-tree vlan 10
AnswerA
solution
! SW1
no spanning-tree vlan 10 priority 4096
spanning-tree vlan 10 priority 32768
errdisable recovery cause bpduguard
errdisable recovery interval 300

Why this answer

The issue is that SW1 has the spanning-tree priority for VLAN 10 set to 4096, which makes it the root bridge. To prevent this, you must set the priority higher than the current root bridge's priority (e.g., 32768 or higher). Additionally, the edge port (G0/1) is in err-disabled state because it received a BPDU while PortFast was enabled (BPDU Guard triggered).

To automatically recover from err-disabled, you need to configure errdisable recovery cause bpduguard and set the interval to 300 seconds. After configuration, verify with 'show spanning-tree vlan 10' that SW1 is no longer the root and 'show errdisable recovery' to confirm the recovery settings.

Exam trap

Students often confuse the priority values: lower priority is better to become root. To prevent a switch from becoming root, set its priority higher than the current root's. Also, remember that 'root secondary' sets a low priority (28672) and does not prevent root election.

For errdisable recovery, use the specific cause (bpduguard) rather than 'all'.

Why the other options are wrong

B

The priority 4096 is too low and would still result in SW1 being the root bridge.

C

The 'root secondary' command does not prevent the switch from becoming root; it only makes it the backup root.

D

Using 'cause all' is not the best practice; the requirement is to recover from bpduguard specifically.

Why candidates pick the wrong answer

B

Candidates might think that since 4096 is the default for some switches, it is acceptable, but the goal is to prevent SW1 from becoming root, so a higher priority is needed.

C

Candidates may confuse 'root secondary' with a command that prevents root selection, but it actually sets a low priority for failover.

D

Candidates might think 'cause all' is acceptable because it includes bpduguard, but it is not the precise configuration asked for.

947
MCQhard

Refer to the exhibit. A network administrator runs the show vlan brief command on SW2. Interface GigabitEthernet0/2 is intended to be an access port in VLAN 10, but it does not appear in the output. What is the most likely cause?

A.The interface is configured with switchport mode dynamic auto and no trunk has been negotiated, causing it to be hidden.
B.The interface is administratively shut down, and down ports are excluded from the show vlan brief output.
C.The interface is configured as a trunk port and therefore does not appear under any VLAN in show vlan brief.
D.VLAN 10 is not active, so the port assigned to it is not displayed in the listing.
AnswerC

show vlan brief only displays ports that are in access mode. Trunk ports are not included because they belong to all VLANs allowed on the trunk. The output shows VLAN 10 with members Gi0/9–Gi0/11 but not Gi0/2, confirming it is not an access port.

Why this answer

The `show vlan brief` command displays only access ports and their assigned VLANs. Trunk ports, which carry multiple VLANs, are not listed in this output. If GigabitEthernet0/2 is configured as a trunk port (e.g., with `switchport mode trunk` or dynamically via DTP), it will not appear under any VLAN in the `show vlan brief` output, even if it is intended to be an access port in VLAN 10.

Exam trap

Cisco often tests the distinction between access and trunk port behavior in `show vlan brief` output, trapping candidates who assume all switchports appear in the VLAN listing regardless of mode.

Why the other options are wrong

A

Confusion about how dynamic trunking protocol (DTP) modes interact with VLAN membership display.

B

Misconception that only operational interfaces are shown in VLAN membership tables.

D

Overlooking the explicit 'active' status and port list for VLAN 10 in the output.

948
PBQmedium

You are connected to R1 via the console. R1 is a new router that connects to three subnets: 192.168.1.0/24 (connected to GigabitEthernet0/0), 192.168.2.0/24 (connected to GigabitEthernet0/1), and 192.168.3.0/24 (connected to GigabitEthernet0/2). R1 must be able to ping the loopback0 interface of R2 (192.168.100.1/32) which is reachable via R2's Serial0/0/0 interface (10.0.0.2/30). The link between R1 and R2 is 10.0.0.0/30, with R1's interface being 10.0.0.1/30. No dynamic routing protocols are configured. Configure R1 to reach the loopback address of R2 using a host-specific static route (not a default route).

Network Topology
G0/0192.168.1.1/24S0/0/010.0.0.2/30R1R2

Hints

  • •The destination is a single host address.
  • •Use the next-hop IP address of R2's serial interface.
  • •The command starts with 'ip route'.
A.ip route 192.168.100.1 255.255.255.255 10.0.0.2
B.ip route 192.168.100.0 255.255.255.0 10.0.0.2
C.ip route 192.168.100.1 255.255.255.255 192.168.1.1
D.ip route 0.0.0.0 0.0.0.0 10.0.0.2
AnswerA
solution
! R1
ip route 192.168.100.1 255.255.255.255 10.0.0.2

Why this answer

A host-specific static route to 192.168.100.1/32 via next-hop 10.0.0.2 is correct because the destination is a single host (loopback0 of R2) and the next-hop is R2's Serial0/0/0 interface IP on the 10.0.0.0/30 link. The command 'ip route 192.168.100.1 255.255.255.255 10.0.0.2' exactly matches this requirement. It uses a /32 mask to specify only that host, and the correct next-hop address.

Exam trap

The trap here is confusing a host route (/32) with a subnet route (/24) or using an incorrect next-hop address that is not on the directly connected link, which would cause the route to be invalid.

Why the other options are wrong

B

The mask must match the destination exactly; a /24 mask is too broad for a /32 host route.

C

The next-hop address must be directly connected; 192.168.1.1 is not a valid next hop from R1.

D

A default route is too broad; the requirement is for a specific route to the loopback address.

Why candidates pick the wrong answer

B

Candidates often default to a classful or common subnet mask without considering the exact prefix length of the destination.

C

Candidates might confuse the next-hop with an IP address from one of R1's own subnets, but it must be the neighbor's IP on a shared link.

D

Candidates might think a default route is simpler and still works, but the question expects a precise static route to the destination.

949
MCQeasy

Which protocol is used to resolve a hostname such as www.example.com into an IP address?

A.DNS
B.DHCP
C.NTP
D.SNMP
AnswerA

DNS (Domain Name System) is the hierarchical distributed database that resolves human-readable hostnames like www.example.com to numerical IP addresses. It uses recursive and iterative queries across root, TLD, and authoritative name servers to return the correct address. DNS is the standard protocol specifically designed for hostname-to-IP resolution.

Why this answer

DNS resolves names to addresses. DHCP hands out addressing parameters, NTP synchronizes time, and SNMP is used for management and monitoring.

Exam trap

A frequent exam trap is mistaking DHCP for DNS because both protocols are essential IP services and often appear together in network configurations. Candidates may incorrectly select DHCP, thinking it resolves hostnames, but DHCP only assigns IP addresses and network parameters, not name resolution. Another trap is confusing NTP or SNMP with DNS due to their roles in network operations; however, NTP synchronizes time and SNMP manages devices, neither resolving hostnames.

Understanding that DNS specifically maps domain names to IP addresses prevents this common mistake.

Why the other options are wrong

B

DHCP is incorrect because it only leases IP addressing information and other network parameters to clients; it does not translate hostnames to IP addresses, which is the core function of DNS.

C

NTP is incorrect as it is used solely for synchronizing clocks across network devices and does not handle any form of hostname or IP address resolution.

D

SNMP is incorrect because it is a protocol for monitoring and managing network devices, not for resolving hostnames or IP addresses.

When would these options actually be correct?

B

A question asking which protocol automatically assigns IP addresses to hosts on a network, such as 'Which protocol is used to dynamically assign an IP address to a client?' would have DHCP as the correct answer.

C

In a question asking which protocol synchronizes time across network devices, NTP would be the correct answer. For example: 'Which protocol ensures consistent timestamps on logs from routers and switches?'

D

SNMP would be correct in a question like: 'Which protocol is used to monitor and manage network devices, such as routers and switches, by collecting and organizing information about their performance?'

Why candidates pick the wrong answer

B

Candidates may confuse DHCP with DNS because both involve IP addresses; DHCP assigns them, while DNS resolves names to them.

C

Candidates may confuse NTP with DNS because both involve network services and the acronyms are similar, or they might think time synchronization is needed for name resolution.

D

Candidates may confuse SNMP with DNS because both are network protocols, or they might think SNMP can resolve names due to its role in network management systems that often include name resolution features.

950
Multi-Selectmedium

Which two statements accurately describe DNS in normal network operation?

Select 2 answers
A.DNS helps resolve hostnames into IP-related information.
B.DNS makes networks easier for humans to use by allowing names instead of raw IP addresses.
C.DNS dynamically assigns host IP addresses like DHCP.
D.DNS replaces the need for default gateways.
E.DNS is the spanning-tree protocol used on VLAN trunks.
AnswersA, B

DNS operates as a distributed hierarchical database that maps human-readable hostnames to IP addresses via A and AAAA records, plus reverse lookups. This name-to-address resolution is the core function enabling clients to reach hosts without knowing their numeric addresses.

Why this answer

Option A is correct because DNS (Domain Name System) performs name resolution, translating human-readable hostnames such as www.example.com into IP-related information like A records (IPv4 addresses) and AAAA records (IPv6 addresses). Option B is correct because this name-to-address mapping lets users reference hosts by meaningful names instead of memorizing raw IP addresses, which is the core usability benefit of DNS in normal network operation. Option C is incorrect because dynamic IP address assignment is the function of DHCP (Dynamic Host Configuration Protocol), not DNS, which resolves names rather than leasing addresses.

Option D is incorrect because default gateways are configured on hosts to route traffic off the local subnet, and DNS does not replace that routing function. Option E is incorrect because the Spanning Tree Protocol (STP, IEEE 802.1D) prevents Layer 2 loops on switches and VLAN trunks, and has nothing to do with DNS.

Exam trap

A frequent exam trap is mistaking DNS for DHCP or routing protocols. Some candidates incorrectly believe DNS dynamically assigns IP addresses like DHCP or that it replaces the need for default gateways. This confusion arises because both DNS and DHCP are IP services but serve fundamentally different roles.

DNS strictly resolves hostnames to IP addresses and does not handle IP address allocation or routing decisions. Misinterpreting DNS’s function can lead to selecting incorrect answers that describe DHCP’s role or routing concepts, which do not apply to DNS.

Why the other options are wrong

C

Option C is incorrect because DNS does not assign IP addresses; this is the role of DHCP. Confusing these two services is a common error, but they serve distinct purposes in IP networking.

D

Option D is wrong because DNS does not replace default gateways. Default gateways are necessary for routing traffic between different networks, a function unrelated to DNS name resolution.

E

Option E is incorrect as DNS is unrelated to the Spanning Tree Protocol (STP), which manages Layer 2 loop prevention on VLAN trunks. DNS operates at higher layers for name resolution.

When would these options actually be correct?

C

If the exam question were to ask about network services that provide IP address assignments to devices on a network, then this option would be correct. For example, a question could state, 'Which protocol is responsible for dynamically assigning IP addresses to clients in a network?'

D

If the exam question were to ask about the roles of various network protocols in a routing context, a statement might be framed to imply that DNS can serve as a default gateway in a specific network architecture, perhaps in a hypothetical scenario where DNS is integrated with routing functionalities.

E

If the exam question asked about network protocols and their functions in managing VLANs, specifically in the context of preventing broadcast storms or ensuring loop-free topologies, then option E could be correct. For example, a question could ask which protocol is responsible for maintaining a loop-free network in a VLAN environment.

Why candidates pick the wrong answer

C

Candidates may confuse DNS with DHCP due to their complementary roles in network management, leading them to mistakenly believe that DNS also handles IP address assignments.

D

Candidates may confuse DNS with other network services that manage traffic flow, leading them to mistakenly believe that DNS could serve as a default gateway due to its role in facilitating network communication.

E

Candidates may find option E tempting because it includes technical terminology related to networking, and they might confuse the roles of different protocols, mistakenly associating DNS with VLAN management due to their familiarity with both concepts.

951
MCQmedium

What problem does DHCP snooping help prevent?

A.Unauthorized DHCP server responses from user-facing ports
B.Layer 3 route loops
C.Trunk encapsulation mismatch
D.Weak SSH ciphers
AnswerA

DHCP snooping is a security feature on switches that filters DHCP messages. It builds a binding table of trusted DHCP server ports and untrusted user-facing ports. It drops DHCP server responses (DHCPOFFER, DHCPACK, DHCPNAK) received on untrusted ports, preventing a rogue DHCP server from assigning malicious IP configurations. This mitigates man-in-the-middle and denial-of-service attacks.

Why this answer

DHCP snooping marks interfaces as trusted or untrusted and blocks rogue DHCP server messages arriving on untrusted ports.

Exam trap

A frequent exam trap is selecting options related to Layer 3 routing issues or encryption weaknesses, such as route loops or weak SSH ciphers, when asked about DHCP snooping. Candidates may mistakenly think DHCP snooping prevents routing problems or secures SSH sessions. However, DHCP snooping specifically targets unauthorized DHCP server messages at Layer 2 and does not affect routing protocols or encryption.

Misunderstanding this scope leads to incorrect answers. Remember, DHCP snooping’s primary function is to block rogue DHCP servers on untrusted ports, not to solve routing or encryption problems.

Why the other options are wrong

B

Incorrect. Layer 3 route loops are routing protocol issues and are not addressed by DHCP snooping, which operates at Layer 2 for DHCP message validation.

C

Incorrect. Trunk encapsulation mismatches relate to VLAN tagging and trunk negotiation, which DHCP snooping does not influence or prevent.

D

Incorrect. Weak SSH ciphers pertain to encryption security and have no connection to DHCP snooping, which focuses solely on DHCP message filtering.

When would these options actually be correct?

B

In a question focused on Layer 3 network stability, such as 'What mechanisms can prevent routing loops in a Layer 3 network?' option B would be correct, as it directly addresses the issue of routing loops that can occur in IP networks.

C

In a question asking about issues related to VLAN trunking and encapsulation, such as 'What can cause VLAN traffic to be improperly forwarded between switches?', option C would be correct as it directly addresses the problem of mismatched trunk encapsulation.

D

If the question were about securing SSH connections, specifically asking what measures can be taken to prevent weak encryption algorithms from being used, then 'Weak SSH ciphers' could be a correct answer. This would involve scenarios discussing SSH configuration and security best practices.

Why candidates pick the wrong answer

B

Candidates may confuse DHCP snooping with broader network stability concepts, leading them to mistakenly associate it with preventing routing issues, especially if they have encountered similar terms in their studies.

C

Candidates may confuse DHCP snooping with general network security measures and assume it could also prevent other types of network misconfigurations, such as trunk mismatches, due to a lack of understanding of specific DHCP functions.

D

Candidates may choose this option due to a general understanding of network security and the importance of strong encryption, leading them to mistakenly associate it with DHCP security measures.

952
MCQhard

Users on the inside network can browse the web, but the company now needs an internal web server at 192.168.10.50 to be reachable consistently from outside using one public IP address. Which design is most appropriate?

A.Use static NAT for the server and continue using PAT for user outbound access.
B.Use PAT only for everything, including the published server.
C.Disable NAT because private IPv4 addresses are Internet-routable.
D.Use DHCP relay for the server to make it reachable from outside.
AnswerA

Static NAT maps the one public IP permanently to 192.168.10.50, giving inbound sessions a stable translation, while PAT continues multiplexing outbound user traffic over the same address. This satisfies both the consistent external reachability and existing browsing requirements.

Why this answer

The best design is static NAT for the server while continuing to use PAT for general user outbound traffic. In plain language, user browsing and server publishing are two different requirements. PAT is great for letting many inside users share one public address for outbound access. But a server that outside clients must find reliably needs a fixed one-to-one public identity. That is exactly what static NAT provides.

This is an important design distinction. PAT solves address conservation for many clients. Static NAT solves predictability for inbound access to a specific internal system. The strongest answer is the one that uses each NAT method for the job it fits best.

Exam trap

A common exam trap is selecting PAT for both outbound and inbound traffic, mistakenly believing PAT can provide a stable public IP for a server. PAT dynamically assigns ports for outbound sessions but does not guarantee a fixed public IP and port combination for inbound connections. This leads to unpredictable external access to the internal server, which fails the requirement for consistent reachability.

Another trap is disabling NAT entirely, which ignores that private IPv4 addresses are not routable on the public Internet, making the server unreachable externally. Misunderstanding DHCP relay as a solution for public reachability is also a frequent error, as DHCP relay only forwards DHCP requests and does not affect NAT or routing.

Why the other options are wrong

B

Option B is incorrect because using PAT alone cannot guarantee a fixed public IP and port for the internal server. PAT dynamically assigns ports for outbound sessions, which prevents predictable inbound access to the server from outside.

C

Option C is incorrect because private IPv4 addresses are not routable on the public Internet. Disabling NAT would make the internal server unreachable externally, violating the requirement for consistent outside access.

D

Option D is incorrect because DHCP relay only forwards DHCP requests between clients and servers and does not affect NAT or the server's public reachability. It does not solve the problem of making the internal web server accessible from outside.

When would these options actually be correct?

B

In a scenario where all internal services, including web servers, are designed to be accessed externally without needing a consistent IP address for each service, and the organization is comfortable with dynamic port assignments, using PAT for everything could be appropriate.

C

In a scenario where a company is transitioning to IPv6 and has fully migrated its internal network to use public IPv6 addresses, disabling NAT could be correct. The question would specify that the internal web server uses a public IPv6 address, making it routable on the Internet without NAT.

D

If the question were about configuring a network where internal clients need to obtain IP addresses dynamically from a DHCP server located on a different subnet, and the focus was solely on ensuring internal clients can reach the DHCP server, then using DHCP relay would be appropriate.

Why candidates pick the wrong answer

B

Candidates may choose this option because they understand that PAT is commonly used for outbound connections and might mistakenly believe it can also handle inbound requests effectively without recognizing the limitations for server accessibility.

C

Candidates may choose this option due to a misunderstanding of NAT's role in network design, believing that eliminating NAT would simplify access to internal resources without recognizing the implications for private address routing.

D

Candidates might choose this option due to a misunderstanding of DHCP relay's function, confusing it with NAT solutions that manage external access, leading them to think it could help with server reachability.

953
MCQmedium

A show ip nat translations command displays this entry: Inside global 203.0.113.10:30001 Inside local 192.168.10.25:51514 Outside local 198.51.100.20:443 Outside global 198.51.100.20:443 Which statement is correct?

A.192.168.10.25 is the inside local address of the host
B.203.0.113.10 is the inside local address of the host
C.198.51.100.20 is the translated private address of the internal client
D.The entry proves static NAT is being used without port translation
AnswerA

The inside local address is the original private IP address of the host as it appears in the internal network before NAT is applied. In the translation entry, 192.168.10.25 is shown as the source address that the router will translate, identifying the actual internal host. Because it is a private address in the RFC 1918 range, it correctly matches the definition of an inside local address.

Why this answer

Inside local is the actual address assigned to the inside host before translation. The inside global address is the public representation used after NAT, and the port values show PAT is in use.

Exam trap

Be careful not to confuse inside local with inside global addresses, and understand the difference between local and global in NAT terminology.

Why the other options are wrong

B

This option is wrong because 203.0.113.10 is the inside global address, not the inside local address. The inside local address is 192.168.10.25, which is correctly identified in option A.

C

This option is incorrect because 198.51.100.20 is the outside local address, not a translated private address. The inside local address is specifically 192.168.10.25, as indicated in the NAT translation entry.

D

This option is incorrect because the entry shows that 203.0.113.10 is the inside global address, not the inside local address. The inside local address is 192.168.10.25, which is correctly identified in option A.

When would these options actually be correct?

B

In a different question where the context specifies that the NAT configuration is being examined for a device that has been misconfigured, leading to confusion between inside local and inside global addresses, option B could be correct if it explicitly states that 203.0.113.10 is being referred to as the inside local address due to a specific scenario or misinterpretation.

C

In a different question setup where the NAT configuration is explicitly described as using static NAT with a mapping that translates a private address to a public address, and the question asks for the translated address of an internal client, then 198.51.100.20 could be correctly identified as the translated private address.

D

In a different question, if the NAT configuration specifically stated that 203.0.113.10 was assigned as the inside local address due to a misconfiguration or a specific static NAT mapping, then option D would be correct. For example, a question might present a scenario where a static NAT mapping is explicitly defined to use the same address for both inside local and global.

Why candidates pick the wrong answer

B

Candidates may choose this option due to a misunderstanding of NAT terminology, confusing inside local and inside global addresses, especially if they have encountered similar address formats in different contexts.

C

Candidates may confuse the terms 'translated private address' and 'outside local address,' leading them to mistakenly identify 198.51.100.20 as a private address due to its common usage in NAT scenarios.

D

Candidates may be tempted by this option because they might confuse static NAT with dynamic NAT, leading them to incorrectly assume that the presence of an outside global address means static NAT is in use, especially if they overlook the port translation aspect.

954
MCQhard

A network engineer is troubleshooting connectivity between two hosts in different VLANs on the same switch. Host A in VLAN 10 (10.10.10.5/24) cannot ping Host B in VLAN 20 (10.10.20.5/24). The switch is configured as a router-on-a-stick with a trunk port to an external router. The trunk port is up/up, but inter-VLAN routing fails. What is the most likely cause?

A.The trunk port is not in trunking mode; it is in dynamic desirable mode.
B.The native VLAN on the switch trunk is VLAN 1, but the router subinterface for VLAN 1 is not configured with the 'native' keyword or is missing.
C.The VLANs are not allowed on the trunk; the allowed VLAN list is missing VLAN 10 and 20.
D.The switch ports Gi0/4 and Gi0/5 are in access mode but not assigned to the correct VLANs.
AnswerC

When an allowed VLAN list on a trunk is configured and does not include VLAN 10 and VLAN 20, all tagged frames from those VLANs are dropped, causing inter-VLAN routing failure even though the trunk is up/up.

Why this answer

The most likely cause is that the allowed VLAN list on the trunk is missing VLAN 10 and 20. Even though the trunk port is up/up, if the switch's allowed VLAN list has been restricted (for example, using the switchport trunk allowed vlan command) and does not include those VLANs, all frames tagged with VLAN 10 or 20 will be discarded at the trunk. This directly prevents inter-VLAN routing despite the trunk being operational, whereas a native VLAN mismatch only affects untagged traffic and would not impact the tagged frames between the two hosts.

Exam trap

A common trap is assuming an up/up trunk automatically passes traffic for all VLANs, overlooking that the allowed VLAN list can be manually pruned and must include every VLAN that needs to traverse the trunk.

Why the other options are wrong

A

Dynamic desirable mode can still form a trunk if the other side is willing; the trunk is already up/up, so the port mode is not the issue.

B

A native VLAN mismatch or missing native subinterface only affects untagged frames; the hosts in VLAN 10 and VLAN 20 send tagged traffic, so this would not break their routing.

D

The hosts' access port configurations would prevent intra-VLAN communication if misassigned, but the question describes an inter-VLAN routing failure through the trunk, not a problem with the access ports themselves.

When would these options actually be correct?

B

This is the root cause because the native VLAN mismatch disrupts the control plane or routing traffic.

955
MCQhard

Which summary route best represents these four networks? 10.20.0.0/24 10.20.1.0/24 10.20.2.0/24 10.20.3.0/24

A.10.20.0.0/22
B.10.20.0.0/23
C.10.20.0.0/24
D.10.20.0.0/21
AnswerA

10.20.0.0/22 is the correct summary because it aggregates exactly the four /24 networks 10.20.0.0, 10.20.1.0, 10.20.2.0, and 10.20.3.0 into a single contiguous block. The /22 prefix length means the first 22 bits are fixed, covering address space from 10.20.0.0 to 10.20.3.255, which is a power-of-two boundary and the smallest supernet that contains all four without any wasted addresses.

Why this answer

Four contiguous /24 networks starting at 10.20.0.0 summarize cleanly into 10.20.0.0/22. That block covers 10.20.0.0 through 10.20.3.255.

Exam trap

Be careful to calculate the correct subnet mask that covers all given networks without including unnecessary additional ranges.

Why the other options are wrong

B

Option B, 10.20.0.0/23, is incorrect because it only encompasses two of the four specified networks (10.20.0.0/24 and 10.20.1.0/24), failing to include the other two networks (10.20.2.0/24 and 10.20.3.0/24).

C

Option C is incorrect because it only summarizes a single network (10.20.0.0/24) and does not encompass the other three networks (10.20.1.0/24, 10.20.2.0/24, 10.20.3.0/24) that need to be included in the summary route.

D

Option D (10.20.0.0/21) is incorrect because it encompasses a larger range of addresses than required, including networks that are not part of the specified four networks, which are only within the /24 range of 10.20.0.0 to 10.20.3.0.

When would these options actually be correct?

B

If the question asked for a summary route that only included the first two networks (10.20.0.0/24 and 10.20.1.0/24), then 10.20.0.0/23 would be the correct answer, as it would effectively summarize those two networks.

C

In a different question where only the network 10.20.0.0/24 is being considered for summarization, such as when asked to identify the route for a single subnet, option C would be the correct answer.

D

In a different scenario where the question asks for a summary route that includes not only the four specified networks but also additional networks such as 10.20.4.0/24 and 10.20.5.0/24, then 10.20.0.0/21 would be the correct answer as it would cover all those networks.

Why candidates pick the wrong answer

B

Candidates might choose this option because they recognize that 10.20.0.0/23 covers multiple subnets, leading them to mistakenly believe it could summarize a larger range than it actually does.

C

Candidates may choose this option because it represents a valid subnet and they might misinterpret the question as asking for the most specific route rather than a summary of multiple networks.

D

Candidates may find this option tempting because it appears to provide a broader summary, which can seem advantageous in scenarios where summarization is desired, leading to a misunderstanding of the specific address range required.

956
MCQhard

A user on a wireless guest network can associate successfully, obtains an IP address, but cannot reach the Internet. Which troubleshooting area should be examined first if the WLAN itself is working?

A.The post-association forwarding or policy path, such as guest routing or Internet access policy
B.The SSID broadcast name, because it must be wrong
C.The AP radio antenna type only
D.OSPFv3 area configuration on the laptop
AnswerA

Since the client has already associated and obtained an IP address (implied by 'can associate successfully'), the failure point must be downstream of L2 association. The post-association path encompasses the WLAN-to-VLAN mapping, firewall rules, NAT, ACLs, or default gateway routing that determines guest Internet access. If any of these policy constructs is misconfigured or missing, the client will sit with a valid IP but no usable connectivity.

Why this answer

If association and addressing are already successful, the first area to examine is the forwarding or policy path beyond simple WLAN join behavior. In practical terms, the client has passed the discovery, authentication, and addressing stages. The problem is now more likely to involve routing, gateway reachability, NAT, firewall policy, or guest-access restrictions rather than the SSID itself.

This question is about understanding which stage of the workflow has already succeeded.

Exam trap

Avoid assuming issues with association or IP assignment when these steps have already succeeded.

Why the other options are wrong

B

The SSID broadcast name is not relevant in this scenario because the user has already associated successfully and obtained an IP address, indicating that the SSID is correct and functioning.

C

The AP radio antenna type does not directly impact a user's ability to obtain an IP address or reach the Internet after successful association. This option is irrelevant since the user is already connected to the network.

D

OSPFv3 area configuration is related to routing protocols and is not directly relevant to a user's inability to access the Internet on a guest network after successfully associating. The issue is likely related to network policies or forwarding paths rather than routing configurations on the user's device.

When would these options actually be correct?

B

In a different scenario where a user cannot connect to the network at all, a question might ask about issues with SSID broadcasting. If the SSID is hidden or incorrectly configured, it would prevent users from associating, making this option correct.

C

In a scenario where a user is unable to associate with the wireless network at all, a question could ask about troubleshooting connectivity issues related to the AP's antenna type, such as determining if the antenna is malfunctioning or improperly configured, affecting the signal strength.

D

If the exam question involved a scenario where a user was unable to communicate with other devices on the same subnet due to OSPFv3 misconfigurations affecting routing tables, then examining OSPFv3 area configuration would be appropriate. This would imply a more complex network setup where routing protocols directly impact connectivity.

Why candidates pick the wrong answer

B

Candidates may mistakenly believe that if a user cannot access the Internet, the problem must be related to the network name, especially if they lack understanding of the association process and IP address assignment.

C

Candidates may choose this option due to a misunderstanding of the role of antenna types in wireless connectivity, mistakenly believing that antenna configuration could affect Internet access rather than just association.

D

Candidates may choose this option due to a misunderstanding of the relationship between routing protocols and connectivity issues, especially if they have encountered OSPF-related questions in other contexts and mistakenly apply that knowledge here.

957
MCQhard

A DHCP client on VLAN 30 is not receiving an IP address from a DHCP server (10.99.99.20) on another subnet. The SVI for VLAN 30 is configured with an IP address and is up, but the DHCP relay command is missing. Which command should be added to the SVI configuration?

A.ip directed-broadcast
B.ip helper-address 10.99.99.20
C.service dhcp-server 10.99.99.20
D.default-router 10.99.99.20
AnswerB

On the VLAN 30 SVI, the DHCP client's broadcast is not forwarded by default because routers do not forward link-local broadcasts. The command `ip helper-address 10.99.99.20` instructs the router to convert that DHCPDISCOVER broadcast into a unicast packet and send it to the DHCP server at 10.99.99.20, while also inserting the SVI's IP address as the giaddr field. This allows the server to know which subnet the client is on and assign an address from the correct pool. Without this command, the client's broadcast remains confined to VLAN 30 and the server never receives the request.

Why this answer

DHCP Discover messages are broadcasts and do not cross routers by default. On an SVI or routed interface facing the clients, an ip helper-address relays those broadcasts to the DHCP server on another subnet.

Exam trap

A frequent exam trap is selecting ip directed-broadcast or default-router as the solution for DHCP relay issues. ip directed-broadcast only enables forwarding of directed broadcasts but does not relay DHCP requests to servers on other subnets. default-router is a DHCP pool parameter that assigns a gateway to clients but does not affect how DHCP broadcasts are forwarded. Another trap is assuming service dhcp-server is an interface command for relay, which it is not. These distractors test your understanding of DHCP relay mechanisms and Cisco IOS command usage.

Why the other options are wrong

A

The ip directed-broadcast command enables forwarding of directed broadcasts but does not relay DHCP requests. It is unrelated to DHCP relay and will not solve the problem of clients not receiving addresses from a remote DHCP server.

C

service dhcp-server is not a valid Cisco IOS interface command for DHCP relay. It does not configure the router to forward DHCP broadcasts and thus will not resolve the issue.

D

default-router is a DHCP pool parameter used to assign the default gateway IP address to clients. It does not configure the interface to relay DHCP broadcasts and is not relevant to the relay configuration.

When would these options actually be correct?

A

In a different scenario where a network administrator needs to allow directed broadcasts for a specific application that requires it, such as a legacy system that relies on broadcast messages, this option would be appropriate.

C

In a different scenario where the question asks about configuring a DHCP server directly on a router, 'service dhcp-server 10.99.99.20' could be correct if the router is intended to provide DHCP services to clients on the same subnet.

D

In a different scenario where the question asks for the configuration of a VLAN interface to provide a default gateway for devices within that VLAN, specifying 'default-router 10.99.99.20' would be correct if 10.99.99.20 is indeed the gateway for that VLAN.

Why candidates pick the wrong answer

A

Candidates may choose this option due to a misunderstanding of how DHCP operates across subnets, mistakenly believing that enabling directed broadcasts would solve the issue of clients not receiving IP addresses.

C

Candidates might choose this option because it contains 'dhcp-server', which could mislead them into thinking it relates to DHCP functionality, especially if they are familiar with DHCP server configurations.

D

Candidates may be tempted by this option because they might confuse the need for a default gateway with the requirement for DHCP address assignment, leading them to think that specifying a default router could help with DHCP issues.

958
Multi-Selectmedium

Which TWO of the following statements correctly describe REST API operations?

Select 2 answers
A.The HTTP PUT method is used to retrieve a resource representation.
B.JSON is the only data format supported by REST APIs.
C.API keys and OAuth tokens are common methods for authenticating REST API requests.
D.The HTTP DELETE method corresponds to the Update operation in CRUD.
E.REST APIs commonly use HTTP status codes to indicate the result of a request.
AnswersC, E

Authentication in REST APIs commonly uses API keys or OAuth tokens to verify the identity of the client making the request. An API key is a long-lived identifier often placed in a custom header or query parameter, while OAuth2 tokens, typically Bearer tokens inserted in the Authorization header, provide scoped, short-lived access on behalf of a user or service. Both mechanisms allow the server to recognize and authorize requests consistently across a stateless API, a key requirement of REST. Using these methods distinguishes authentication from authorization and prevents anonymous access.

Why this answer

Option C is correct because REST APIs typically authenticate requests using credentials such as API keys (often sent in an Authorization or custom header) or OAuth 2.0 bearer tokens, which are standard mechanisms for identifying and authorizing clients. Option E is correct because REST relies on HTTP semantics, and servers return status codes like 200 OK, 201 Created, 400 Bad Request, 401 Unauthorized, 404 Not Found, and 500 Internal Server Error to indicate the outcome of an operation. Option A is wrong because PUT is used to create or replace a resource, whereas retrieval is performed with GET.

Option B is wrong because REST APIs can exchange data in multiple formats, including JSON, XML, YAML, and plain text, depending on content negotiation. Option D is wrong because DELETE maps to the Delete operation in CRUD, while Update corresponds to PUT or PATCH.

Exam trap

Cisco often tests the mapping of HTTP methods to CRUD operations, where candidates confuse PUT (Update) with GET (Read) or DELETE (Delete) with Update, and assume JSON exclusivity despite REST's format-agnostic design.

Why the other options are wrong

A

Retrieval is performed by the GET method, not PUT.

B

JSON is popular but not exclusive; XML is widely used, and many REST implementations support both.

D

DELETE is used to remove a resource, which maps to the Delete operation, not Update.

959
MCQmedium

A network engineer must summarize the following routes before advertising them upstream: 172.16.32.0/24 172.16.33.0/24 172.16.34.0/24 172.16.35.0/24 Which summary route should be used?

A.172.16.32.0/22
B.172.16.32.0/23
C.172.16.32.0/21
D.172.16.34.0/22
AnswerA

A /22 prefix has a block size of 4 in the third octet, so 172.16.32.0/22 spans 172.16.32.0 through 172.16.35.255, exactly covering the four /24 routes 172.16.32.0/24, 172.16.33.0/24, 172.16.34.0/24, and 172.16.35.0/24. The network address 172.16.32.0 is aligned to a multiple-of-four boundary (32 % 4 = 0), making it a valid summary. It is the smallest CIDR block that cleanly encapsulates all four contiguous subnets with no additional address space.

Why this answer

The correct summary is 172.16.32.0/22 because a /22 covers exactly four consecutive /24 networks when the starting boundary is aligned correctly. This is the part many people miss: summarization is not only about how many networks fit into a block, but also where that block starts. Here the four /24 networks begin neatly at 172.16.32.0 and continue through 172.16.35.255, which is the exact range a /22 covers.

A /23 would be too small, while a /21 would be unnecessarily broad and could advertise addresses you do not intend to include. The /22 beginning at 172.16.34.0 is not on a valid /22 boundary, so that option is misaligned.

Exam trap

Ensure the summary route starts on the correct boundary and covers exactly the intended range without including extra networks.

Why the other options are wrong

B

Option B, 172.16.32.0/23, is incorrect because it only summarizes two of the four provided routes (172.16.32.0/24 and 172.16.33.0/24), failing to include the other two routes (172.16.34.0/24 and 172.16.35.0/24).

C

Option C (172.16.32.0/21) includes a broader range of addresses than necessary, covering 172.16.32.0 to 172.16.39.255, which exceeds the specified routes and could lead to incorrect routing information being advertised.

D

Option D is incorrect because the summary route 172.16.34.0/22 would only cover the addresses from 172.16.34.0 to 172.16.35.255, missing the routes 172.16.32.0/24 and 172.16.33.0/24.

When would these options actually be correct?

B

In a different scenario where only the first two routes (172.16.32.0/24 and 172.16.33.0/24) need to be summarized for a specific upstream connection, option B would be the correct answer as it accurately summarizes those two networks.

C

In a scenario where a network engineer needs to summarize routes that include 172.16.32.0/24, 172.16.33.0/24, 172.16.34.0/24, 172.16.35.0/24, and additional routes such as 172.16.36.0/24 to 172.16.39.0/24, then 172.16.32.0/21 would be the correct summary route to encompass all those networks.

D

In a different scenario, if the question specified that only the routes 172.16.34.0/24 and 172.16.35.0/24 needed to be summarized, then 172.16.34.0/22 would be the correct answer as it would encompass both of those subnets.

Why candidates pick the wrong answer

B

Candidates may be tempted by option B because it appears to summarize a contiguous block of addresses, leading them to mistakenly believe it covers all required routes.

C

Candidates may choose this option due to a misunderstanding of subnetting, believing that a larger subnet mask would always be more efficient without considering the specific address ranges that need to be summarized.

D

Candidates may find option D tempting because it appears to summarize a contiguous block of addresses, leading them to believe it could be a valid summarization without considering all specified routes.

960
MCQhard

Users on the inside network can browse the Internet through PAT, but an internal web server must now be reachable from outside on a predictable public IP. Which change best fits the requirement?

A.Add static NAT for the server and continue using PAT for user browsing.
B.Replace PAT entirely with DHCP relay.
C.Disable NAT because the server already has a private address.
D.Move the server into the native VLAN.
AnswerA

Static NAT is required to give the internal server a one-to-one mapping to a public IPv4 address, making it reachable from the Internet while preserving its private address. PAT (overload) should remain enabled to translate many internal user sessions to the same public IP for outbound browsing. These two translation mechanisms can coexist in a single NAT configuration, with the router selecting static NAT for the server's destination and PAT for user traffic.

Why this answer

The best change is to add a static NAT mapping for the internal web server while keeping PAT in place for ordinary users. In practical terms, PAT is excellent for many internal clients sharing one public address for outbound traffic, but it does not give an internal server the stable one-to-one public identity that outside clients expect for predictable inbound access.

This is a standard NAT design distinction. User browsing and published server access are different requirements, and the best design often uses PAT for one and static NAT for the other.

Exam trap

A frequent exam trap is selecting DHCP relay or VLAN changes as solutions for making an internal server reachable from outside. DHCP relay only forwards DHCP requests across subnets and does not provide any public IP mapping or NAT functionality. Similarly, moving a server into the native VLAN does not affect its public IP address or NAT translation.

Another common mistake is disabling NAT entirely, which breaks Internet connectivity because private IP addresses cannot be routed on the public Internet. Understanding that static NAT is required for predictable inbound access while PAT supports outbound user browsing is critical to avoid these traps.

Why the other options are wrong

B

Incorrect because DHCP relay only forwards DHCP requests and does not provide any mechanism for publishing an internal server to the Internet or managing NAT translations.

C

Incorrect because disabling NAT leaves the internal server with a private IP address that is not routable on the Internet, making it unreachable from outside networks.

D

Incorrect because moving the server into the native VLAN affects only Layer 2 segmentation and does not provide a public IP address or NAT translation necessary for Internet access.

When would these options actually be correct?

B

In a scenario where a network is configured to use DHCP for assigning IP addresses to devices, and there is a need to allow external clients to access a specific server without using NAT, a question might ask how to configure the network to allow external access while maintaining DHCP functionality. In that case, replacing PAT with DHCP relay could be the correct answer.

C

In a scenario where a question asks about a network configuration where all internal devices need to communicate directly with each other without any address translation, disabling NAT could be the correct answer to simplify the network and avoid unnecessary complexity.

D

In a scenario where the question specifies that the server needs to be accessible by internal users only and that VLAN configurations are being reviewed for internal traffic optimization, moving the server into the native VLAN could enhance internal communication without requiring NAT.

Why candidates pick the wrong answer

B

Candidates may confuse the need for external access with the need for IP address management, leading them to believe that DHCP relay could somehow facilitate external connectivity, despite it being unrelated to NAT functions.

C

Candidates may be tempted by this option because they might believe that since the server has a private address, it can be accessed directly without NAT, overlooking the requirement for external accessibility.

D

Candidates may choose this option due to a misunderstanding of VLANs and their role in network segmentation, believing that simply changing VLANs can resolve accessibility issues without considering NAT requirements.

961
MCQeasy

Which term describes a string or credential passed to an API to prove the client is allowed to access a resource?

A.Metric
B.Token
C.Lease
D.Tuple
AnswerB

A token is a compact credential string, such as an OAuth 2.0 bearer token or a JWT, that the client presents to an API, typically in the Authorization header. It grants authenticated access and may carry scopes or expiry, making it the correct term for a credential passed to an API.

Why this answer

A token is commonly used for API authorization. It is often included in an HTTP header and lets the server verify the caller has permission.

Exam trap

A common exam trap is mistaking the term 'token' for other networking terms such as 'metric,' 'lease,' or 'tuple.' Candidates might confuse 'metric' as a general value related to network performance or 'lease' as a temporary credential, but these terms do not relate to API authorization. Another trap is assuming that any credential passed to an API is called a 'lease' or 'tuple,' which are unrelated concepts. Recognizing that a token specifically serves as an authorization credential passed to prove client access rights is critical to avoid this confusion.

Why the other options are wrong

A

Metric is a routing concept representing route cost and does not relate to API access or authorization credentials, so it is incorrect.

C

Lease refers to DHCP IP address assignment duration and is unrelated to API credentials or authorization, making it incorrect.

D

Tuple is a data structure term and does not describe any form of authorization credential for API access, so it is incorrect.

When would these options actually be correct?

A

In a question about monitoring or performance, such as 'Which term describes a value used to measure the performance of an API endpoint?', metric would be the correct answer.

C

In a question about DHCP operation, 'lease' would be correct when asking: 'What term describes the temporary assignment of an IP address to a client by a DHCP server?'

D

In a question about data structures or database queries, such as 'Which term describes an ordered list of elements in Python or a row in a relational database?', tuple would be the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse 'metric' with 'token' because both are strings used in API contexts, but metrics are for measurement, not authentication.

C

Candidates may confuse 'lease' with 'token' because both involve temporary access, but a lease is about resource allocation duration, not API authentication credentials.

D

Candidates may confuse 'tuple' with 'token' due to similar spelling or think it refers to a security credential like a 'token' in some contexts.

962
MCQmedium

On an 802.1Q trunk, which VLAN is sent untagged by default on many Cisco switches unless changed?

A.VLAN 10
B.VLAN 20
C.VLAN 1
D.The highest configured VLAN
AnswerC

By default, Cisco switches configure VLAN 1 as the native VLAN on an 802.1Q trunk. Frames in the native VLAN are transmitted without a VLAN tag, while all other VLANs carry a 802.1Q tag. This default behavior ensures that control-plane traffic like CDP, VTP, and DTP, which typically run on VLAN 1, can traverse the trunk without tagging.

Why this answer

On many Cisco platforms, VLAN 1 is the default native VLAN. Native VLAN traffic is sent untagged unless the native VLAN is changed.

Exam trap

Be cautious not to confuse commonly used VLANs in practice with the default native VLAN set by Cisco.

Why the other options are wrong

A

VLAN 10 is not the default untagged VLAN on Cisco switches; instead, VLAN 1 is typically used for this purpose unless configured otherwise. Therefore, selecting VLAN 10 would be incorrect in the context of the question.

B

VLAN 20 is not the default untagged VLAN on Cisco switches; instead, VLAN 1 is typically sent untagged on 802.1Q trunks unless configured otherwise. Therefore, selecting VLAN 20 does not align with the standard behavior of Cisco switch configurations.

D

This option is incorrect because the default untagged VLAN on many Cisco switches is VLAN 1, not the highest configured VLAN. The highest configured VLAN can vary based on the network setup and does not have a default status in this context.

When would these options actually be correct?

A

If the exam question specified a scenario where VLAN 10 was explicitly configured as the native VLAN on a specific switch or in a particular network design, then it would be the correct answer. For example, a question could state that a network administrator has changed the default native VLAN to VLAN 10.

B

If the exam question specified a scenario where VLAN 20 was explicitly configured as the native VLAN on a particular Cisco switch, then VLAN 20 would be the correct answer. For example, a question could ask which VLAN is untagged on a switch where the administrator has changed the default native VLAN to 20.

D

In a different question asking which VLAN is used as the native VLAN when a switch is configured to use the highest VLAN number as the native VLAN, option D would be correct. For instance, if a switch has VLANs 1 through 50 configured and the question specifies that the highest VLAN is set as the native VLAN, then VLAN 50 would be the answer.

Why candidates pick the wrong answer

A

Candidates might choose VLAN 10 due to familiarity with common VLAN configurations or because they recall that VLAN 10 is often used in various network setups, leading to confusion about default settings.

B

Candidates may choose VLAN 20 due to familiarity with VLAN configurations and assumptions that it could be a common choice for native VLANs, especially if they have encountered scenarios where VLAN 20 is used in practice.

D

Candidates might choose this option due to a misunderstanding of VLAN configurations, thinking that the highest VLAN is always the default untagged VLAN, especially if they have encountered scenarios where custom configurations are used.

963
Multi-Selectmedium

Which TWO statements correctly describe IPv4 and IPv6 host configuration?

Select 2 answers
A.APIPA assigns an IPv4 address in the 169.254.0.0/16 range when a DHCP server is unavailable.
B.IPv6 link-local addresses are always assigned using EUI-64 and start with FE80::/10.
C.EUI-64 is used to generate the network prefix of an IPv6 address from the interface's MAC address.
D.A host can have only one default gateway configured at a time for both IPv4 and IPv6.
E.The ipconfig command on Windows can display both IPv4 and IPv6 addresses, subnet masks, default gateways, and DNS servers.
AnswersA, E

APIPA is a fallback mechanism in IPv4 used by Windows hosts when a DHCP server cannot be reached after a timeout. It automatically configures an interface address from the 169.254.0.0/16 range with a /16 subnet mask, enabling local communication on that subnet only. Because APIPA addresses are not routable, no default gateway is assigned, so internet access is unavailable until DHCP succeeds.

Why this answer

APIPA (Automatic Private IP Addressing) automatically assigns an IPv4 address from the 169.254.0.0/16 range when a DHCP server is unavailable, enabling local subnet communication without manual configuration. Option E is correct because the ipconfig command on Windows displays both IPv4 and IPv6 addresses, subnet masks, default gateways, and DNS servers. Option B is incorrect because while IPv6 link-local addresses start with FE80::/10, they are not always assigned using EUI-64; they can also be randomly generated (privacy extensions) or manually configured.

Option C is incorrect because EUI-64 generates the interface identifier (host portion) of an IPv6 address from the MAC address, not the network prefix — the prefix is provided via SLAAC, DHCPv6, or manual configuration. Option D is incorrect because a host can have multiple default gateways configured for redundancy, though only one is active at a time per routing table; additionally, IPv4 and IPv6 default gateways are independent and can coexist.

Exam trap

Cisco often tests the misconception that EUI-64 generates the network prefix of an IPv6 address, when in fact it generates only the interface identifier (host portion), while the network prefix is assigned via SLAAC, DHCPv6, or manual configuration.

Why the other options are wrong

B

The statement incorrectly claims that link-local addresses are always assigned using EUI-64.

C

The statement confuses the role of EUI-64; it creates the interface ID, not the network prefix.

D

The statement is too restrictive; multiple default gateways can be configured, especially in multi-homed hosts.

964
Multi-Selectmedium

Which TWO statements about IPv4 and IPv6 ACLs are true?

Select 2 answers
A.Standard IPv4 ACLs use numbers in the range 100-199.
B.Extended IPv4 ACLs should be placed as close to the source as possible to minimize unnecessary traffic on the network.
C.IPv6 ACLs are always named and can filter traffic based on source and destination IPv6 addresses, as well as protocol types.
D.Standard IPv4 ACLs filter only the source IP address and are best placed close to the source to be most effective.
E.Numbered ACLs allow individual access control entries (ACEs) to be deleted without removing the entire ACL.
AnswersB, C

Extended IPv4 ACLs can match on source and destination addresses, protocol, and TCP/UDP ports, so they can selectively deny specific traffic flows while permitting unrelated traffic. Placing such an ACL closest to the source of that traffic stops unwanted packets immediately at the ingress edge, preventing them from consuming bandwidth and router processing power on every intermediate link toward the destination. This granularity makes source-side placement safe and efficient, unlike standard ACLs.

Why this answer

Extended IPv4 ACLs filter on source and destination IP addresses, ports, and protocols, so placing them as close to the source as possible prevents unwanted traffic from traversing the network, reducing bandwidth waste and security risks. This is a best practice for extended ACLs, unlike standard ACLs which should be placed close to the destination.

Exam trap

Cisco often tests the placement rule reversal—candidates confuse standard ACL placement (close to destination) with extended ACL placement (close to source), or mix up the number ranges for standard vs. extended ACLs.

Why the other options are wrong

A

The number range 100–199 is used for extended ACLs, not standard ones.

D

The placement advice is reversed: standard ACLs belong near the destination, not the source.

E

This is a common misconception; the ability to delete individual ACEs is a feature of named ACLs, not numbered.

965
MCQhard

A company wants a server on the inside network to be reachable consistently from outside using one known public IP address. Which NAT approach best fits that goal?

A.Static NAT
B.PAT overload only
C.No NAT at all, because private IPv4 addresses are Internet-routable
D.DHCP relay
AnswerA

Static NAT establishes a permanent one-to-one mapping between an inside private IPv4 address and an inside global public IPv4 address. Because the binding is fixed, inbound packets arriving at the public address are always translated to the same internal host, making the server reliably reachable from the Internet. This determinism is exactly why a company would choose static NAT for a server that must be accessible without session-specific state.

Why this answer

Static NAT best fits that goal because it creates a fixed, predictable one-to-one mapping between the internal server and a public address. In plain language, outside systems always know which public IP represents that server. This predictability is exactly what is needed when a service must be reachable consistently from the outside.

PAT is better suited for many outbound clients sharing one address, not for presenting one inside server with a permanent public identity. Dynamic NAT from a pool can also vary depending on design. The correct answer is the one that provides the most stable and direct one-to-one mapping.

Exam trap

A frequent exam trap is selecting PAT overload as the solution for making an internal server reachable from outside. PAT is designed for multiple internal clients to share a single public IP for outbound connections, not for providing a fixed public IP to a server. Another common mistake is thinking private IP addresses can be accessed directly from the Internet without NAT, which is incorrect because private IPs are non-routable externally.

Misunderstanding DHCP relay as related to NAT or public reachability is also a trap; DHCP relay only forwards DHCP requests and does not affect NAT mappings or external accessibility.

Why the other options are wrong

B

PAT overload is incorrect because it is designed for many internal clients sharing a single public IP for outbound traffic, not for providing a fixed public IP to a server.

C

No NAT is incorrect since private IPv4 addresses are not routable on the Internet and require NAT to be accessible externally.

D

DHCP relay is unrelated to NAT or public reachability; it only forwards DHCP requests and does not affect how internal servers are accessed from outside.

When would these options actually be correct?

B

In a question where the requirement is to allow multiple internal servers to access the Internet using a single public IP address without needing consistent external access to any specific server, PAT overload would be the correct choice.

C

In a scenario where a question asks about a network setup that uses only public IP addresses throughout, and the focus is on internal routing without the need for NAT, then this option could be correct. For example, a question might specify a fully public IPv6 network where NAT is unnecessary.

D

If the question asked about enabling DHCP functionality for devices on a network that require IP address assignment from a remote DHCP server, then DHCP relay would be the correct answer, as it facilitates the communication necessary for DHCP in such scenarios.

Why candidates pick the wrong answer

B

Candidates may confuse PAT overload with static NAT, thinking that since it allows multiple connections, it could also provide consistent external access, leading them to select this option incorrectly.

C

Candidates may be tempted by this option due to a misunderstanding of private versus public IP address functionality, leading them to incorrectly assume that private addresses can be used directly for external access.

D

Candidates may confuse DHCP relay with NAT concepts, thinking that it could somehow assist in making internal servers accessible externally, due to a lack of clarity on the distinct roles of NAT and DHCP in network configurations.

966
MCQhard

R1 learns three OSPF routes to different destinations: O 10.10.10.0/24 O IA 10.20.20.0/24 O E2 10.30.30.0/24 Which statement is correct about these route types?

A.O IA is an external route redistributed from another routing protocol.
B.O E2 is an OSPF external type 2 route.
C.O means the route was learned through EIGRP.
D.All three routes were learned from the same OSPF area type.
AnswerB

In OSPF, the route code 'O' indicates a route learned via the OSPF protocol, and 'E2' specifically denotes an external type 2 route. This type is redistributed from another routing protocol into OSPF, and its metric is the external cost only, without adding the internal cost to the ASBR. The 'O E2' code is exactly the standard representation for such externally redistributed type 2 routes.

Why this answer

An O route is intra-area, O IA is interarea, and O E2 is an external type 2 route redistributed into OSPF. The codes describe route origin, not just preference. CCNA expects you to identify them quickly when reading the routing table.

Exam trap

A frequent exam trap is confusing the OSPF route codes, especially mistaking 'O IA' (inter-area) for an external route redistributed from another protocol. Candidates often incorrectly assume that 'O IA' means external, but it actually represents routes learned from a different OSPF area within the same autonomous system. Another common mistake is thinking the 'O' code indicates EIGRP routes, which it does not; EIGRP uses different codes such as 'D'.

This confusion can cause candidates to select incorrect answers about route origins or types. Carefully distinguishing between intra-area, inter-area, and external routes based on OSPF codes is essential to avoid this pitfall.

Why the other options are wrong

A

Option A incorrectly states that 'O IA' is an external route redistributed from another routing protocol. In reality, 'O IA' stands for inter-area routes within OSPF, not external routes. External routes use 'O E1' or 'O E2' codes.

C

Option C incorrectly claims that 'O' means the route was learned through EIGRP. The 'O' code is exclusive to OSPF intra-area routes. EIGRP routes use the code 'D' in Cisco routing tables.

D

Option D is incorrect because the three routes represent different OSPF route types: intra-area (O), inter-area (O IA), and external (O E2). They do not all come from the same OSPF area type.

When would these options actually be correct?

A

In a different scenario where the question specifies routes learned from a redistribution of another routing protocol into OSPF, such as EIGRP or BGP, option A would be correct if it referred to an external route. For example, 'Which OSPF route type indicates an external route redistributed from another protocol?'

C

In a different question, if the context specifies that the routing table is being analyzed for EIGRP routes, and the notation 'D' is used for EIGRP, then an option stating 'O' indicates EIGRP could be correct if misinterpreted. For example, if the question mistakenly labeled EIGRP routes with 'O', it could lead to this being the right answer.

D

In a different question setup where all routes were explicitly stated to be learned from the same OSPF area, such as 'All routes are from OSPF area 0,' this option would be correct as it would confirm that they share the same area type.

Why candidates pick the wrong answer

A

Candidates may confuse OSPF route types due to similarities in terminology, leading them to mistakenly associate 'IA' with external routes, especially if they have experience with multiple routing protocols.

C

Candidates may confuse the routing protocol identifiers due to similar acronyms and may mistakenly believe that 'O' could represent EIGRP in a context where multiple protocols are discussed, leading to misinterpretation.

D

Candidates might choose this option due to a misunderstanding of OSPF route types, mistakenly believing that all OSPF routes must originate from the same area, leading them to overlook the specific types presented.

967
MCQhard

A switch should disable an edge port immediately if a BPDU is received on it. Which feature is intended for that specific behavior?

A.BPDU Guard
B.Loop Guard
C.Root Guard
D.UDLD
AnswerA

BPDU Guard is correct because it is specifically designed to protect edge ports configured with PortFast. When a BPDU is received on such a port, BPDU Guard immediately places the port into the error-disabled state, preventing an unexpected switch from creating a Layer 2 loop. This action is immediate and automatic, requiring manual re-enabling or errdisable auto-recovery, which matches the behavior described in the question.

Why this answer

The feature is BPDU Guard. In plain language, the administrator is treating the port as an end-device-only edge interface and wants the switch to react aggressively if it ever sees spanning-tree control traffic there. BPDU Guard does exactly that: if a BPDU appears on a protected edge port, the switch places the interface into an err-disabled state to help prevent accidental loops or rogue switch connections.

This is different from root guard and loop guard, which solve other spanning-tree control problems. BPDU Guard is the specific answer when the requirement is “if you ever hear a BPDU here, shut the port down quickly.”

Exam trap

A common exam trap is confusing BPDU Guard with Root Guard or Loop Guard. Candidates may incorrectly select Root Guard because it also deals with BPDUs, but Root Guard only blocks ports from becoming root ports and does not disable the port immediately. Loop Guard protects against unidirectional link failures and does not shut down ports upon BPDU receipt.

Another mistake is thinking UDLD handles BPDU protection; however, UDLD only detects unidirectional physical link failures and is unrelated to STP BPDU processing. Understanding that BPDU Guard uniquely disables edge ports upon BPDU detection is critical to avoid this trap.

Why the other options are wrong

B

Loop Guard is incorrect because it protects against unidirectional link failures by preventing a port from transitioning to forwarding when BPDUs stop, but it does not disable a port upon BPDU receipt.

C

Root Guard is incorrect because it prevents a port from becoming a root port by blocking superior BPDUs but does not disable the port immediately when a BPDU is received on an edge port.

D

UDLD is incorrect because it detects unidirectional physical link failures and does not interact with BPDU processing or disable ports based on BPDU reception.

When would these options actually be correct?

B

If the question asked about a feature that prevents loops by blocking ports that receive unexpected BPDUs, then Loop Guard would be the correct answer. For example, a question could specify a scenario where a switch is configured to maintain a loop-free topology.

C

In a scenario where the question asks about preventing a port from becoming a root port in a network with multiple switches, and emphasizes maintaining the intended root bridge, Root Guard would be the correct answer. For example, a question might state that a network administrator wants to ensure that only designated switches can become the root bridge.

D

If the question asked about a feature that detects unidirectional links and prevents loops in a network, then UDLD would be the correct answer. For example, a scenario could involve a network design question where ensuring bidirectional communication is critical.

Why candidates pick the wrong answer

B

Candidates may choose Loop Guard because they understand it relates to BPDU handling and network stability, leading to confusion with the specific requirement of disabling an edge port immediately.

C

Candidates may confuse Root Guard with BPDU Guard due to both features dealing with BPDUs and spanning tree protocols, leading them to incorrectly associate Root Guard with immediate port disabling.

D

Candidates may confuse UDLD with features related to loop prevention and port protection, leading them to mistakenly believe it addresses BPDU reception issues.

968
MCQmedium

A network administrator is troubleshooting a connectivity issue between two hosts on different subnets. The administrator captures packets on the source host and notices that the frames contain the correct source and destination MAC addresses but the encapsulated packets have incorrect source and destination IP addresses. According to the OSI model, which layer is most likely responsible for this issue?

A.Physical Layer (Layer 1)
B.Data Link Layer (Layer 2)
C.Network Layer (Layer 3)
D.Transport Layer (Layer 4)
AnswerC

The Network Layer is responsible for logical addressing, routing, and forwarding packets based on IP addresses. When an IP address is incorrect, the host cannot participate in proper network communication, and routers cannot make accurate forwarding decisions. Because the problem directly involves IP addresses, the Network Layer is the most likely layer where the fault exists.

Why this answer

The Network Layer (Layer 3) is responsible for logical addressing (IP addresses) and routing packets between different subnets. Since the captured frames have correct MAC addresses (Layer 2) but incorrect source and destination IP addresses, the issue lies in how the IP headers are being constructed or assigned, which is a Layer 3 function. This could be caused by misconfigured IP addresses, subnet masks, or default gateways on the source host.

Exam trap

Cisco often tests the distinction between MAC addresses (Layer 2) and IP addresses (Layer 3) in troubleshooting scenarios, and the trap here is that candidates might incorrectly blame the Data Link Layer because they see 'frames' and 'MAC addresses' in the question, without recognizing that the IP address error points to the Network Layer.

Why the other options are wrong

A

The issue is with the IP addresses, which are not handled at Layer 1.

B

The MAC addresses are correct, so the Data Link Layer is functioning properly.

D

IP addresses are not part of the Transport Layer header; they belong to the Network Layer.

969
MCQhard

A multilayer switch has working SVIs for VLAN 10 and VLAN 20, but traffic between the VLANs fails. Hosts can ping their own gateway interfaces. Which misconfiguration is most strongly suggested if the SVIs themselves are correct?

A.IP routing is not enabled on the multilayer switch.
B.Both VLANs need to use the same IP subnet.
C.All access ports must be converted into trunks.
D.The wireless controller must provide the default gateway.
AnswerA

The correct answer is that IP routing is not enabled globally on the multilayer switch. Even with SVIs for VLAN 10 and 20 created and hosts able to ping their respective gateways, the switch will not forward packets between VLANs unless the `ip routing` global configuration command has been issued. Without this command, the switch functions as a Layer 2 device; it has SVI interfaces but no Layer 3 forwarding table to route traffic from one subnet to another. To fix this, you must enable IP routing and, if needed, configure static routes or a dynamic routing protocol.

Why this answer

IP routing is not enabled. The switch can ping SVIs locally because they are directly connected, but without `ip routing`, it cannot forward packets between VLANs. Option B is wrong because different VLANs require different subnets for routing.

Option C is wrong because access ports do not need to be trunks; SVIs handle routing at Layer 3. Option D is wrong because the wireless controller does not provide the default gateway for wired VLAN routing; the SVI does.

Exam trap

Remember that SVIs alone do not enable inter-VLAN routing; IP routing must be explicitly enabled on the switch.

Why the other options are wrong

B

Different VLANs must use different IP subnets for routing; using the same subnet would break Layer 3 separation.

C

Access ports remain as access ports; inter-VLAN routing requires SVIs with routing enabled, not trunk conversion of access ports.

D

The default gateway for each VLAN is the SVI IP address; a wireless controller is irrelevant to Layer 3 forwarding between wired VLANs.

When would these options actually be correct?

B

In a different scenario where the question states that both VLAN 10 and VLAN 20 are configured with the same IP subnet, such as 192.168.1.0/24, this option would be correct. This would lead to IP address conflicts and prevent inter-VLAN communication.

C

In a different scenario, if the question stated that VLANs 10 and 20 were configured on a switch with all ports set as access ports and required trunking to allow inter-VLAN traffic, then this option would be correct.

D

In a different scenario where the question states that hosts in VLAN 10 and VLAN 20 are connected to a wireless network and the wireless controller is responsible for routing traffic between VLANs, then this option would be correct. For example, if the question specifies that the wireless controller is the primary device managing VLAN traffic, then it would need to provide the default gateway.

Why candidates pick the wrong answer

B

Candidates may choose this option due to a misunderstanding of VLAN configurations, thinking that VLANs must share the same subnet for communication, which is a common misconception in networking.

C

Candidates may choose this option because they might confuse the need for trunking in scenarios involving multiple VLANs on a single physical link, leading them to mistakenly believe that all access ports must be trunks for routing to occur.

D

Candidates might choose this option due to a common misconception that wireless networks always require a controller for routing, leading them to overlook the multilayer switch's role in inter-VLAN communication.

970
MCQhard

A wireless site reports that users can connect to the SSID, but performance drops sharply around the conference area whenever the room fills up. Based on the exhibit, what is the most likely cause?

A.Adjacent-channel interference caused by overlapping 2.4 GHz channels
B.A DHCP exhaustion problem on the WLAN
C.An authentication mismatch between the APs and clients
D.A missing default route on the wireless controller
AnswerA

Adjacent-channel interference is the likely culprit because the 2.4 GHz band provides only three non-overlapping channels (1, 6, and 11); if an AP is configured on channel 3, it overlaps both channels 1 and 6, forcing clients to contend with simultaneous signals. This causes excessive frame collisions and retransmissions, which severely degrade throughput and latency even though clients maintain their association to the SSID. The mismatch between successful association and poor performance points directly to a Layer 1 RF problem rather than a higher-layer failure.

Why this answer

The 2.4 GHz radios are using overlapping channels. In 2.4 GHz, the standard non-overlapping channels are 1, 6, and 11 in many regulatory domains. Using channels 1, 3, and 6 creates adjacent-channel interference, which hurts throughput especially in dense client areas.

Exam trap

A common exam trap is to confuse wireless connectivity issues caused by RF interference with DHCP or authentication problems. Because users can connect to the SSID, candidates might incorrectly suspect DHCP exhaustion or authentication mismatches. However, DHCP exhaustion prevents clients from obtaining IP addresses, not causing throughput drops.

Similarly, authentication mismatches prevent connection entirely. Another trap is to blame routing issues like a missing default route on the wireless controller, which affects network reachability but not local wireless signal quality. The key is to recognize that overlapping 2.4 GHz channels cause adjacent-channel interference, which degrades performance even when clients connect successfully.

Why the other options are wrong

B

Incorrect. DHCP exhaustion would prevent some clients from obtaining IP addresses, but it does not cause RF interference or a sharp drop in wireless throughput. Since users can connect, DHCP exhaustion is unlikely.

C

Incorrect. An authentication mismatch would prevent clients from connecting to the SSID. Since users can connect, authentication is working properly and is not the cause of performance degradation.

D

Incorrect. A missing default route on the wireless controller affects upstream network connectivity but does not cause local RF interference or throughput drops in the wireless environment.

When would these options actually be correct?

B

In a different question setup where users report being unable to connect to the SSID or frequently losing connection, and the network has a limited number of IP addresses available, a DHCP exhaustion problem would be the correct answer. This scenario would focus on IP address allocation rather than performance degradation.

C

In a different scenario where users report being unable to connect to the SSID or are frequently disconnected when moving between access points, an authentication mismatch could be the correct answer. This would involve a question focusing on connectivity issues rather than performance degradation.

D

In a scenario where a question describes a wireless network that is unable to route traffic properly, leading to connectivity issues for clients, a missing default route on the wireless controller would be the correct answer. This could occur in a setup where clients are unable to access external resources due to misconfigured routing.

Why candidates pick the wrong answer

B

Candidates may confuse performance issues with connectivity problems, leading them to consider DHCP exhaustion as a potential cause. The idea that a crowded environment could overwhelm available IP addresses might make this option seem plausible.

C

Candidates may choose this option because they associate performance issues with authentication problems, especially if they have encountered similar scenarios in their studies or practical experience, leading to a misinterpretation of the symptoms described.

D

Candidates might choose this option due to a misunderstanding of network routing concepts, thinking that routing issues could impact performance, especially in a busy area, rather than recognizing that performance is more likely affected by interference or bandwidth limitations.

971
Drag & Dropmedium

Drag and drop the following steps into the correct order to describe the router's routing table lookup process for a destination IP address, including best-path selection using longest prefix match, administrative distance, and metric.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The order follows the router's decision process: longest prefix match first, then administrative distance, then metric, leading to the forwarding decision.

Exam trap

Students often confuse the order of AD and metric, thinking metric is compared before AD. Remember: AD is a tiebreaker between different routing protocols (e.g., OSPF vs. EIGRP), while metric is a tiebreaker within the same protocol.

Also, longest prefix match always comes first—never skip it.

Why candidates pick the wrong answer

B

Candidates might think AD is more important because it determines trustworthiness, but they forget that the most specific route is always preferred regardless of AD.

C

Candidates might confuse the order of AD and metric, thinking metric is more granular and thus compared first, but AD is the higher-level tiebreaker.

D

Candidates might think metric is the most important because it directly indicates path cost, but they overlook that prefix length and AD are higher-priority criteria.

972
Multi-Selectmedium

A network administrator is implementing 802.1X port-based authentication on a Cisco switch. The switch will act as the authenticator, and a RADIUS server will provide authentication services. Which two statements are true regarding this deployment? (Choose two.)

Select 2 answers
A.The supplicant must be configured with the RADIUS server's IP address.
B.The authentication server can be a Cisco ISE appliance or any RADIUS-compliant server.
C.The switch forwards EAPoL frames between the supplicant and the authentication server.
D.The switch authenticates the supplicant using its MAC address by default.
E.The switch uses RADIUS to communicate with the authentication server.
AnswersB, E

The authentication server in 802.1X can be any RADIUS-compliant server, such as Cisco Identity Services Engine (ISE), Microsoft Network Policy Server (NPS), or FreeRADIUS. The switch acts as a RADIUS client. The server validates the supplicant's credentials and returns an accept or reject decision. Cisco ISE is a common choice in Cisco environments, but it is not the only option.

Why this answer

In 802.1X, the switch is the authenticator and communicates with the RADIUS server using RADIUS protocol. The supplicant communicates with the switch using EAPoL. The authentication server can be any RADIUS-compliant server, such as Cisco ISE.

The switch does not forward EAPoL frames to the server; it translates them into RADIUS. The supplicant does not need the RADIUS server IP, and MAC address authentication is not the default method.

Exam trap

The trap here is thinking the switch forwards EAPoL frames directly to the RADIUS server, when it actually encapsulates them into RADIUS packets.

973
MCQmedium

Exhibit: Users report that they can see the corporate SSID but fail authentication immediately after entering credentials. Guest wireless works on the same access point. Which issue is most likely?

A.The AP is using the wrong channel width
B.The RADIUS or AAA server is unreachable for the enterprise WLAN
C.The corporate SSID has a mismatched RADIUS shared secret
D.The SSID must be configured as hidden
AnswerB

WPA2-Enterprise requires the AP to forward EAP frames from the client to a RADIUS/AAA server for authentication. If that server is unreachable, clients can still discover the SSID and associate at Layer 2, but the 802.1X exchange times out because no Access-Request ever receives a response. The guest WLAN is unaffected because it does not depend on AAA, isolating the fault to the enterprise WLAN's backend.

Why this answer

When clients can see the SSID and associate at Layer 2 but fail right after entering credentials, a broken 802.1X or RADIUS path is a common cause. RF coverage is clearly not the main problem because the SSID is visible and guest service works.

Exam trap

Be careful not to confuse visibility and connectivity issues with authentication problems. The SSID is visible, so focus on authentication-related configurations.

Why the other options are wrong

A

The AP using the wrong channel width would not cause immediate authentication failures; it typically affects connectivity or performance rather than authentication processes. Since the guest wireless works, the channel width is likely not the issue.

C

A mismatched RADIUS shared secret would cause authentication failures, but guest wireless works on the same access point, indicating the AP itself is functional; the more likely cause is that the RADIUS server is completely unreachable, not just a shared secret mismatch.

D

Configuring the SSID as hidden would not cause immediate authentication failures; users would simply not see the SSID unless they manually entered it. The issue described involves users seeing the SSID but failing authentication, indicating a problem beyond SSID visibility.

When would these options actually be correct?

A

In a scenario where users are experiencing poor performance or intermittent connectivity issues on a specific SSID, a question might ask about the impact of channel width on wireless communication. If the question specifies that users can connect but experience slow speeds, then this option could be correct.

C

If the question were about a scenario where users are trying to connect to a guest network that requires a PSK, and they report that they can connect but are unable to authenticate, then the expiration of the guest PSK would be the correct answer.

D

In a different scenario where users are unable to see the corporate SSID at all, a question might ask about visibility issues related to SSID configuration. If the question specified that users could not connect because the SSID was hidden, then this option would be correct.

Why candidates pick the wrong answer

A

Candidates may confuse channel width with overall wireless performance issues, leading them to believe that it could impact authentication. This misunderstanding can make the option seem plausible, especially if they are not fully aware of how authentication processes work.

C

Candidates may choose this option because they recognize that authentication issues can arise from credential problems, and they might mistakenly associate the inability to authenticate with an expired PSK, especially if they have experience with guest networks.

D

Candidates might choose this option due to a misunderstanding of SSID visibility and authentication processes, thinking that if users can see the SSID, it must be configured correctly, and thus they might overlook other potential issues like authentication mechanisms.

974
MCQhard

Two switches are connected by a trunk. VLAN 50 exists on both switches, but traffic still fails across the link. The allowed VLAN list is correct. Which additional item should be checked next?

A.Check for a trunk mismatch such as native VLAN inconsistency or other trunk-parameter problems.
B.Reset OSPF process IDs on both switches.
C.Add ip helper-address under every access interface.
D.Disable the MAC address table.
AnswerA

A trunk with VLAN 50 allowed on both ends is only a prerequisite for Layer 2 connectivity; native VLAN mismatch or an inconsistent allowed VLAN list can still cause VLAN 50 frames to be tagged with the wrong VLAN ID or dropped entirely. Verifying trunk encapsulation (802.1Q), trunk mode (desirable/trunk), and especially native VLAN consistency is the correct next step because these parameters govern whether frames in VLAN 50 are correctly forwarded across the link.

Why this answer

After confirming that the VLAN exists on both switches and is allowed on the trunk, another important item to verify is whether the trunk itself is actually operational with the expected encapsulation and whether there is a native VLAN or other trunk inconsistency. In plain language, just because the VLAN is listed does not guarantee the trunk is healthy in every relevant way. Trunking problems can still occur because of broader configuration mismatches.

This question is about disciplined troubleshooting. Once the obvious allowed-list issue is ruled out, the next step is to keep checking other trunk-related characteristics rather than jumping immediately to unrelated routing or service features. The correct answer is the one that stays grounded in trunk-specific verification.

Exam trap

Don't jump to unrelated issues like spanning tree or IP configuration when the problem is clearly trunk-related.

Why the other options are wrong

B

Resetting OSPF process IDs does not address VLAN traffic issues over a trunk link, as OSPF is a routing protocol and unrelated to Layer 2 VLAN configurations.

C

Adding an ip helper-address is irrelevant to VLAN traffic issues across a trunk link, as this command is used for forwarding DHCP requests, not for resolving VLAN connectivity problems.

D

Disabling the MAC address table would not resolve VLAN traffic issues across a trunk link, as it pertains to Layer 2 forwarding and would disrupt normal switch operations, leading to further connectivity problems.

When would these options actually be correct?

B

In a question where OSPF routing issues are explicitly mentioned, such as 'OSPF routes are not being advertised between two switches,' resetting OSPF process IDs could be a valid troubleshooting step to refresh the routing tables and re-establish adjacency.

C

In a question about configuring a router to support DHCP relay for multiple VLANs, where the scenario specifies that clients in different VLANs are unable to receive IP addresses, the option to add ip helper-address would be correct.

D

In a question where the focus is on troubleshooting Layer 2 issues related to excessive MAC address table entries causing performance degradation, disabling the MAC address table temporarily could be a valid step to reset the switch's learning process and alleviate the issue.

Why candidates pick the wrong answer

B

Candidates may confuse Layer 2 VLAN issues with Layer 3 routing problems, leading them to believe that OSPF configuration could impact VLAN traffic, especially if they have encountered similar scenarios in their studies.

C

Candidates may choose this option due to a misunderstanding of how VLANs and DHCP interact, thinking that helper addresses could somehow assist with VLAN traffic issues.

D

Candidates may choose this option due to a misunderstanding of how MAC address tables function, thinking that clearing the table might resolve connectivity issues without considering the specific VLAN configuration and trunking parameters.

975
MCQhard

A network administrator is troubleshooting an issue where hosts on VLAN 10 cannot ping the default gateway at 192.168.10.1. The router (R1) has an SVI for VLAN 10 with IP 192.168.10.1/24. The administrator captures traffic on the router's G0/0/0 interface (trunk to the switch) and reviews the embedded packet capture output. What is the root cause of the problem?

A.The router's SVI for VLAN 10 is administratively down.
B.The switch port connecting the host is configured in the wrong VLAN (e.g., VLAN 20 instead of VLAN 10).
C.An inbound ACL on the router's SVI is blocking ICMP echo requests from the host.
D.The router has ICMP redirects enabled, causing it to ignore the pings.
AnswerB

The router is sending ARP requests, but the host never receives them because the switch port is in a different VLAN. This prevents the router from learning the host's MAC address, causing the ping to fail.

Why this answer

The captured traffic on the trunk shows that the router is not receiving any frames tagged with VLAN 10 from the host. If the switch port connecting the host is configured in VLAN 20 instead of VLAN 10, the host's frames will be tagged with VLAN 20 (or remain untagged in the access VLAN 20) and will not reach the router's SVI for VLAN 10, causing the ping to fail. This is the most direct cause given the symptom that the host cannot ping the default gateway.

Exam trap

Cisco often tests the distinction between Layer 2 and Layer 3 issues, and the trap here is that candidates assume the problem is on the router (e.g., ACL or interface state) when the packet capture reveals that the traffic never reaches the router's SVI due to a VLAN mismatch on the switch access port.

Why the other options are wrong

A

The SVI is operational, so this cannot be the root cause.

C

The router receives the ICMP requests, so an inbound ACL would have dropped them before they reached the capture buffer.

D

ICMP redirects do not prevent the router from responding to pings; they only send redirect messages when appropriate.

Page 12

Page 13 of 20

Page 14