Courseiva

CCNA 200-301 v2 (200-301) — Questions 976–1050

1450 questions total · 20pages · All types, answers revealed

Page 13

Page 14 of 20

Page 15
976
PBQhard

You are connected to Multilayer Switch SW1. Configure LACP EtherChannel between SW1 and SW2 using ports GigabitEthernet0/1 and GigabitEthernet0/2. Ensure the channel is formed and active. The current configuration has mismatched VLAN assignments and speed/duplex settings preventing the channel from coming up. Verify the channel state using 'show etherchannel summary'.

Network Topology
Gi0/1Gi0/1LACP EtherChannelSW1SW2

Hints

  • •Check that both physical ports have identical speed and duplex settings.
  • •Ensure the allowed VLAN list on each member port matches the Port-channel interface.
  • •Use 'show etherchannel summary' to see if ports are in a suspended (D) or bundled (P) state.
A.Configure both Gi0/1 and Gi0/2 with speed 1000, duplex full, and switchport trunk allowed vlan 10,20,30.
B.Configure both Gi0/1 and Gi0/2 with speed 100, duplex half, and switchport trunk allowed vlan 30.
C.Configure both Gi0/1 and Gi0/2 with speed 1000, duplex full, and switchport trunk allowed vlan 10,20.
D.Configure both Gi0/1 and Gi0/2 with speed 1000, duplex full, and switchport mode access.
AnswerA
solution
! SW1
interface GigabitEthernet0/1
switchport trunk allowed vlan 10,20,30
exit
interface GigabitEthernet0/2
speed 1000
duplex full
switchport trunk allowed vlan 10,20,30
exit

Why this answer

The EtherChannel is down because the two member ports on SW1 have inconsistent configurations. GigabitEthernet0/1 is set to speed 1000 and duplex full with allowed VLANs 10,20, while GigabitEthernet0/2 is set to speed 100 and duplex half with allowed VLAN 30. LACP requires all member ports to have identical speed, duplex, and VLAN allowed lists.

To fix, on SW1 configure both Gi0/1 and Gi0/2 with the same speed (1000), duplex (full), and trunk allowed VLANs (10,20,30). The Port-channel interface already has the correct allowed VLANs. After correction, 'show etherchannel summary' should show both ports as bundled (P).

Exam trap

The exam trap is that candidates often focus only on speed/duplex mismatches and forget that VLAN allowed lists must also match. Additionally, they may assume that the Port-channel interface inherits settings from member ports, but in fact, the member ports must match the Port-channel configuration.

Why the other options are wrong

B

The specific factual error is that LACP requires all member ports to have identical configurations, and this option does not align with the existing Port-channel configuration.

C

The specific factual error is that the VLAN allowed list must match across all member ports and the Port-channel interface; omitting VLAN 30 will cause inconsistency.

D

The specific factual error is that LACP requires consistent switchport mode (access or trunk) across all member ports and the Port-channel interface.

Why candidates pick the wrong answer

B

Candidates might pick this if they think matching the slower port's settings is acceptable, but LACP requires all ports to be identical and consistent with the Port-channel interface.

C

Candidates might pick this if they think only the common VLANs are needed, but LACP requires exact match of allowed VLANs.

D

Candidates might pick this if they confuse access mode with trunk mode or think that speed/duplex are the only requirements, ignoring the VLAN mode.

977
MCQmedium

A network administrator is evaluating a controller-based assurance platform that uses machine learning to baseline normal traffic patterns. The platform alerts on deviations that may indicate a security incident. Which characteristic best describes how this AI-driven approach improves network operations compared to traditional threshold-based monitoring?

A.It replaces the need for SNMP polling and syslog collection.
B.It eliminates the need for any human review of alerts.
C.It dynamically learns normal behavior and can detect subtle anomalies that static thresholds miss.
D.It guarantees zero false positives by using deterministic rules.
AnswerC

Machine learning models establish a baseline of normal traffic and performance, then flag deviations. This allows detection of subtle, previously unseen anomalies—such as a slow data exfiltration or new application pattern—that fixed thresholds would not catch. It improves mean time to detect and reduces alert fatigue by focusing on meaningful changes rather than static limits.

Why this answer

Machine learning in network operations builds a behavioral baseline and detects deviations, enabling identification of subtle or novel anomalies that static thresholds cannot. This reduces false alarms from fixed limits and helps surface security or performance issues earlier. It does not remove the need for human oversight, guarantee zero false positives, or replace underlying telemetry protocols.

Exam trap

The trap here is assuming AI eliminates human involvement or all false positives; it augments monitoring by learning baselines, not by providing deterministic perfection.

978
MCQmedium

A network engineer is configuring a new Cisco Catalyst 9300 switch. The switch currently has all interfaces in VLAN 1, and the engineer needs to segment traffic for the Finance department. The engineer creates VLAN 20 and assigns it the name 'Finance'. Which command sequence is required to place access ports FastEthernet 1/0/1 through 1/0/10 into VLAN 20?

A.Switch(config)# interface range FastEthernet 1/0/1 - 10 Switch(config-if-range)# switchport mode access Switch(config-if-range)# switchport access vlan 20
B.Switch(config)# vlan 20 Switch(config-vlan)# name Finance Switch(config-vlan)# exit Switch(config)# interface range FastEthernet 1/0/1 - 10 Switch(config-if-range)# switchport trunk allowed vlan 20
C.Switch(config)# interface range FastEthernet 1/0/1 - 10 Switch(config-if-range)# switchport mode trunk Switch(config-if-range)# switchport trunk native vlan 20
D.Switch(config)# vlan 20 Switch(config-vlan)# name Finance Switch(config-vlan)# interface FastEthernet 1/0/1 - 10 Switch(config-if-range)# switchport access vlan 20
AnswerA

This sequence correctly enters interface range configuration mode, sets the ports to access mode, and assigns VLAN 20 as the access VLAN. On Cisco switches, access ports must be explicitly set to access mode if they are not already, and the switchport access vlan command assigns the VLAN. Without setting the mode, the ports might remain in dynamic mode, causing issues. This is the standard method to assign multiple ports to a VLAN efficiently.

Why this answer

To assign multiple access ports to a VLAN, you must enter interface range configuration, set the ports to access mode, and then assign the VLAN. The switchport mode access command ensures the ports operate as access ports, and switchport access vlan 20 assigns the VLAN. This is the standard and efficient way to configure multiple ports simultaneously on Cisco switches.

Exam trap

The trap here is confusing trunk commands like 'switchport trunk allowed vlan' with access VLAN assignment, or forgetting to set the port mode to access, leading to dynamic mode behavior.

979
MCQhard

A router interface is configured with 192.0.2.97/28. What is the network address of the subnet?

A.192.0.2.80
B.192.0.2.96
C.192.0.2.111
D.192.0.2.112
AnswerB

A /28 mask leaves four host bits, giving sixteen addresses per subnet in blocks of 16. The address 192.0.2.97 falls within the block spanning 192.0.2.96 to 192.0.2.111, so 192.0.2.96 is the network address, satisfying the subnet boundary constraint.

Why this answer

A /28 uses blocks of 16 addresses. The block containing .97 runs from .96 through .111, so .96 is the network address.

Exam trap

Be careful not to confuse the given IP address or the broadcast address with the network address.

Why the other options are wrong

A

Option A (192.0.2.80) is incorrect because the subnet mask /28 indicates a block size of 16, making the valid network addresses range from 192.0.2.96 to 192.0.2.111. The network address for this subnet is 192.0.2.96.

C

The address 192.0.2.111 is not a valid network address for the subnet defined by 192.0.2.97/28, as it falls outside the range of usable addresses for that subnet, which spans from 192.0.2.96 to 192.0.2.111.

D

Option D, 192.0.2.112, is wrong because it does not represent the network address for the subnet defined by the IP address 192.0.2.97/28. The correct network address is 192.0.2.96, which is the first address in the subnet range.

When would these options actually be correct?

A

If the question were to ask for the network address of a subnet with a different subnet mask, such as /26, which has a block size of 64, then 192.0.2.80 could be the correct answer as it would represent the network address for the range 192.0.2.64 to 192.0.2.127.

C

If the question were to ask for the broadcast address of the subnet 192.0.2.96/28, then 192.0.2.111 would be the correct answer, as it is the last address in that subnet range.

D

If the question asked for the broadcast address of the subnet instead of the network address, then 192.0.2.112 would be correct, as it is the last address in the subnet range for 192.0.2.96/28.

Why candidates pick the wrong answer

A

Candidates might choose this option due to a misunderstanding of subnetting, mistakenly calculating the network address based on an incorrect block size or misinterpreting the range of addresses within the subnet.

C

Candidates may confuse the network address with the last usable address in the subnet, leading them to mistakenly select 192.0.2.111, which is the highest usable IP address in that range.

D

Candidates may choose this option due to confusion between network and broadcast addresses, as they might remember that the last address in a subnet is often significant and mistakenly associate it with the question.

980
MCQhard

A router has a static route to 10.20.20.0/24 and also has a default route. Which route is used for traffic to 10.20.20.8?

A.The static route to 10.20.20.0/24
B.The default route
C.Both routes are used equally
D.Neither route is valid
AnswerA

The static route to 10.20.20.0/24 is used because routers employ longest prefix match (LPM) to select the most specific route in the routing table. With a destination of 10.20.20.0/24, the /24 prefix has 24 matching bits, whereas the default route has only 0 matching bits. Therefore, the /24 route is preferred and installed as the best route.

Why this answer

The static route to 10.20.20.0/24 is used because it is more specific than the default route. In practical terms, the router always chooses the route that most precisely matches the destination before falling back to the default route.

This question reinforces the idea that the default route is a route of last resort, not a preferred choice when a better match already exists.

Exam trap

A frequent exam trap is assuming the default route is used whenever it exists, ignoring the presence of more specific static routes. This misunderstanding leads to incorrect answers because routers always prefer the route with the longest matching prefix, not the default route unless no other matches exist.

Why the other options are wrong

B

This option is incorrect because the default route is less specific and only used when no other matching routes exist. Here, a more specific static route is present.

C

This option is incorrect because routers do not load balance equally between a specific static route and a default route; they prefer the most specific route.

D

This option is incorrect because the static route to 10.20.20.0/24 clearly matches the destination, making it a valid route for forwarding traffic.

When would these options actually be correct?

B

In a different scenario where the router has no specific route to the 10.20.20.0/24 network and only has a default route configured, then traffic to 10.20.20.8 would be directed through the default route, making option B the correct answer.

C

In a different scenario where the router has equal-cost multipath (ECMP) routing enabled and both the static route and default route are configured with the same administrative distance, a question could ask which route would be used for load balancing, making this option correct.

D

This option would be correct in a scenario where the router has no valid routes configured at all, meaning neither the static route nor the default route is operational due to misconfiguration or failure, leading to an inability to route any traffic.

Why candidates pick the wrong answer

B

Candidates might choose this option if they misunderstand the concept of route specificity, believing that the default route is always used for any unmatched traffic, rather than recognizing the priority of static routes.

C

Candidates might choose this option due to a misunderstanding of routing priorities, thinking that multiple routes can be used simultaneously without recognizing that static routes take precedence over default routes.

D

Candidates may choose this option due to a misunderstanding of routing priorities, thinking that if a specific route is not functioning, then no routes can be valid, leading to confusion about the operational status of routes.

981
PBQhard

You are connected to R1 via the console. Configure single-area OSPFv2 on R1 and R2 so that they form a full adjacency. The link between R1 and R2 uses 203.0.113.0/30. R1 has G0/0 203.0.113.1/30 and R2 has G0/0 203.0.113.2/30. R1's router-id must be 1.1.1.1, and R2's router-id must be 2.2.2.2. R1's GigabitEthernet0/0 interface is configured as a passive interface under OSPF, preventing OSPF hello messages from being sent out of that interface. Ensure that R1 does not send OSPF hellos out of its loopback0 interface (203.0.113.129/32). After configuration, verify the adjacency is established and OSPF routes are exchanged.

Hints

  • •Check if G0/0 is passive on R1 using 'show ip ospf interface'
  • •The passive-interface default command makes all interfaces passive unless explicitly excluded
  • •Use 'no passive-interface <interface>' under router ospf to allow hellos on the link
A.The adjacency fails because R1's GigabitEthernet0/0 interface is configured as passive-interface. Remove the passive-interface command for G0/0.
B.The adjacency fails because the router-id 1.1.1.1 is not reachable from R2. Configure a static route for 1.1.1.1/32 on R2.
C.The adjacency fails because the subnet mask on the link is /30 but OSPF expects a /24. Change the mask to /24 on both interfaces.
D.The adjacency fails because OSPF is not enabled on R2's GigabitEthernet0/0 interface. Configure 'ip ospf 1 area 0' on R2's G0/0.
AnswerA
solution
! R1
router ospf 1
no passive-interface GigabitEthernet0/0

Why this answer

The adjacency fails because R1's GigabitEthernet0/0 interface is configured as passive-interface (the 'No Hellos' line in show ip ospf interface). This prevents R1 from sending OSPF hellos to R2. To fix, remove the passive-interface command for G0/0.

The loopback0 interface should remain passive. After removal, verify with 'show ip ospf neighbor' to see the neighbor state change to FULL and 'show ip route ospf' to see routes.

Exam trap

The trap is that candidates may overlook the 'passive-interface' command's effect on hello suppression. They might focus on router-id or subnet issues instead. Always check 'show ip ospf interface' for passive status when adjacency fails.

Why the other options are wrong

B

The router-id is used only for OSPF router identification and does not need to be reachable; adjacency uses interface IP addresses.

C

OSPF does not require a specific subnet mask; it uses the configured mask on the interface as the network type.

D

OSPF is enabled on R2's G0/0; the issue is on R1's side where the passive-interface prevents hellos.

Why candidates pick the wrong answer

B

Candidates might think that since router-id is an IP address, it must be reachable for OSPF to work, confusing it with a loopback interface used for BGP or other protocols.

C

Candidates might recall that some routing protocols (like RIPv2) have issues with certain masks, or confuse OSPF network types (point-to-point vs broadcast) with mask requirements.

D

Candidates often check both sides for OSPF enablement and might assume R2 is misconfigured, especially if they see 'show ip ospf neighbor' showing nothing.

982
MCQhard

A branch router has two equal-cost static routes to the same destination network. Both routes are displayed in the output of the show ip route command, and pings from the router to both next-hop IP addresses succeed. Despite this, all traffic heading toward that destination is egressing only a single interface. The technician suspects Cisco Express Forwarding (CEF) is not performing load balancing as expected. What should the technician do next?

A.Issue the show ip cef <destination> detail command to inspect the CEF FIB entry and verify both adjacencies are present.
B.Check the interface output rates with show interface to see if both interfaces are transmitting traffic.
C.Display the routing table again with show ip route to ensure both static routes are still installed.
D.Verify the bandwidth configured on the outgoing interfaces using show interfaces or show running-config.
AnswerA

show ip cef will display the FIB entry, which already includes both equal‑cost paths because they are in the routing table. It will confirm that CEF has installed both paths but will not reveal why traffic uses only one of them. This step restates what the routing table has already shown, skipping a deeper data‑plane check.

Why this answer

CEF performs load balancing over equal-cost paths using a hash of the packet's destination (or source/destination) address to select a path. The interface bandwidth is not a factor for equal-cost load balancing; it is used for metric calculation in routing protocols, not for CEF path selection. When traffic uses only one interface despite two equal-cost routes in the routing table, you should verify that CEF has installed both paths in its FIB and resolved both next-hop addresses to adjacencies.

The command 'show ip cef <destination> detail' displays the FIB entry and associated adjacencies, confirming both paths are available for load balancing.

Exam trap

Candidates may incorrectly assume that interface bandwidth controls CEF load sharing. In reality, CEF equal-cost load balancing is based on a hash algorithm, not bandwidth. The correct verification is checking the CEF FIB entry and its adjacencies.

Why the other options are wrong

B

Exam‑takers may confuse verifying the symptom with identifying the root cause. Seeing only one interface transmitting confirms the problem but offers no corrective insight.

C

A common reflex is to re‑verify the obvious; however, the question states the routes are present and next‑hops are reachable, so revisiting the RIB is redundant.

When would these options actually be correct?

D

The technician needs to check a data‑plane parameter that could silently skew CEF load‑balancing when two equal‑cost static routes are present but traffic stays on one path.

983
Multi-Selectmedium

Which two statements accurately describe route summarization?

Select 2 answers
A.It can reduce the number of individual routes that must be advertised.
B.It can help improve routing scalability by simplifying route information.
C.It forces every router to use only a default route.
D.It is the same thing as PAT overload.
E.It automatically encrypts routing updates.
AnswersA, B

Summarization combines multiple contiguous subnet prefixes into a single aggregate route, so a router advertises one summary instead of many specific entries. For example, 10.1.1.0/24 through 10.1.4.0/24 can be advertised as 10.1.0.0/22, shrinking the routing table and update size. This reduces bandwidth and processing required for routing protocol updates.

Why this answer

Route summarization combines multiple specific routes into a smaller number of broader advertisements. In plain language, it lets a router describe a group of networks with one shorter, more general route instead of announcing each one individually. This can reduce routing-table size and improve scalability. It can also reduce the amount of routing information that must be exchanged across certain boundaries.

The wrong answers often confuse summarization with default routing or encryption. The two correct statements are the ones that preserve its aggregation and scaling purpose.

Exam trap

A frequent exam trap is mistaking route summarization for default routing or NAT-related functions. Some candidates incorrectly believe summarization forces routers to use only a default route, which is false because summarization still advertises specific aggregated routes, not just a default. Others confuse summarization with PAT overload, a NAT feature unrelated to routing.

Additionally, some think summarization automatically encrypts routing updates, which it does not. These misconceptions can lead to incorrect answers and misunderstandings about routing behavior in Cisco networks.

Why the other options are wrong

C

Option C is incorrect because summarization does not force routers to use only a default route; it aggregates routes but still allows routers to use more specific routes within the summary when available.

D

Option D is incorrect since route summarization is a routing optimization technique and is unrelated to PAT overload, which is a NAT function that translates multiple private IP addresses to a single public IP address with port differentiation.

E

Option E is incorrect because route summarization does not involve encryption of routing updates; encryption is a separate security feature not related to summarization.

When would these options actually be correct?

C

In a question focused on routing protocols that require a default route for all traffic, such as in a stub network scenario, this option could be correct if the question specifies that summarization leads to a configuration where only a default route is used for all traffic.

D

In a different context, if the question asked about methods of optimizing network address translation or asked for techniques related to IP address management, then option D could be correct if discussing how PAT overload can reduce the complexity of managing multiple IP addresses in a network.

E

In a question specifically about routing protocols that include security features, such as OSPF with authentication, an option stating that routing updates are encrypted could be correct if the context involves secure routing protocols that utilize encryption methods.

Why candidates pick the wrong answer

C

Candidates may find this option tempting due to a misunderstanding of how summarization simplifies routing tables, leading them to incorrectly associate it with the use of default routes in network configurations.

D

Candidates may choose this option due to confusion between routing concepts and network address translation techniques, leading them to associate summarization with address management strategies like PAT.

E

Candidates may be tempted by this option due to a misunderstanding of routing protocols and security, conflating the concepts of route summarization with the need for secure communication in network routing.

984
MCQhard

Refer to the exhibit. A network engineer notices that traffic from R1 to the 10.1.0.0/16 network is taking a longer path than expected despite OSPF being the only routing protocol. The engineer examines the OSPF LSDB on R1 to investigate. Based on the output, what is the most likely cause of the suboptimal routing?

A.The reference bandwidth has been misconfigured on R1, causing the OSPF cost calculation to be inflated for some links.
B.The ABR is filtering the 10.1.0.0/16 route from Area 1 into Area 0, causing the router to recalculate the metric higher.
C.The ABR is configured with the 'area 1 range 10.1.0.0 255.255.0.0 cost 1000' command.
D.The metric-type for OSPF external routes has been set to type 2, causing the metric to be inflated to 1000 for the 10.1.0.0/16 prefix.
AnswerC

The ABR (10.1.1.1) is advertising a Type 3 summary LSA for 10.1.0.0/16 with a metric of 1000. This matches the behavior of the 'area range' command with the 'cost' keyword, which overrides the default metric calculation for inter-area summaries and injects the specified cost. The other LSAs from the same ABR use normal metrics, confirming the summary-specific configuration.

Why this answer

The OSPF LSDB output shows that the route to 10.1.0.0/16 has a metric of 1000, which is unusually high for an intra-area or inter-area route. The 'area 1 range 10.1.0.0 255.255.0.0 cost 1000' command on the ABR sets a fixed cost for the summarized route, overriding the default OSPF cost calculation. This causes R1 to see a higher metric for the summarized route, leading to suboptimal routing if a lower-cost path exists via another area or router.

Exam trap

Cisco often tests the distinction between route summarization with a fixed cost versus default OSPF cost calculation, and the trap here is that candidates may confuse the 'area range cost' command with external route metric manipulation or filtering, rather than recognizing it as a summary route cost override.

Why the other options are wrong

A

Candidates may attribute arbitrary high metrics to a bandwidth calculation error, without noticing that only one LSA is affected.

B

A misunderstanding that filtering can somehow alter the metric rather than block the advertisement completely.

D

Confusion between external and inter-area route types leads candidates to think that metric-type manipulation could affect an internal summary LSA.

985
MCQmedium

A network engineer is automating the configuration of a new branch office router. The engineer needs a protocol that uses a YANG data model, supports both configuration and operational state retrieval, and operates over SSH for secure transport. Which protocol should the engineer use?

A.SNMP
B.NETCONF
C.RESTCONF
D.CLI scripting
AnswerB

NETCONF is an IETF-standard protocol that uses YANG data models to define configuration and operational state data, encoding operations like get, edit-config, and commit in XML over a secure SSH transport. It explicitly separates the running configuration from operational state, supports transactional commit/rollback and candidate datastores, and provides a session-oriented, RPC-based mechanism ideal for automating network device configuration securely. These capabilities make NETCONF the correct choice for the scenario.

Why this answer

NETCONF (Network Configuration Protocol) is the correct choice because it uses YANG data models for configuration and operational state retrieval, and it operates over SSH (RFC 6242) for secure transport. Unlike SNMP, NETCONF provides transactional configuration changes and separates configuration from operational state data, making it ideal for automated router configuration.

Exam trap

Cisco often tests the distinction between NETCONF and RESTCONF, where the trap is that both use YANG, but candidates forget that NETCONF specifically requires SSH transport, while RESTCONF uses HTTP/HTTPS, making NETCONF the only correct answer when the question specifies 'operates over SSH'.

Why the other options are wrong

A

SNMP does not use YANG data models and typically operates over UDP, not SSH.

C

RESTCONF uses HTTP/HTTPS for transport, not SSH, so it does not meet the requirement of operating over SSH.

D

CLI scripting lacks a standardized data model like YANG and is not a protocol that operates over SSH in the same structured manner as NETCONF.

986
MCQeasy

A junior administrator at a branch office connects a new Cisco IP phone to switch port FastEthernet0/12. The phone must receive power from the switch, and a PC will later be daisy-chained to the phone's PC port. The switch must also ensure the voice traffic is carried in VLAN 50 while data traffic stays in VLAN 10. Which configuration on the interface accomplishes these requirements?

A.switchport mode access, switchport access vlan 50, switchport voice vlan 10, and power inline auto
B.switchport mode access, switchport access vlan 10, switchport voice vlan 50, and power inline auto
C.switchport mode trunk, switchport trunk native vlan 10, switchport trunk allowed vlan 50, and power inline never
D.switchport mode dynamic auto, switchport access vlan 10, switchport voice vlan 50, and power inline auto
AnswerB

This configuration places the port in access mode for data in VLAN 10, tags voice frames with VLAN 50 using the voice VLAN command, and enables PoE delivery to the phone with power inline auto. The phone receives power and both voice and data traffic are properly segmented, which is the standard Cisco IP telephony deployment on a switch access port.

Why this answer

An access port with a data VLAN and a separate voice VLAN is the standard way to connect a Cisco IP phone that also provides a PC port. Enabling power inline auto supplies PoE so the phone powers up, and the voice VLAN command causes the phone to tag its voice frames into VLAN 50 while the attached PC remains in VLAN 10.

Exam trap

The trap here is assuming a trunk is required to carry both voice and data, when a single access port with the voice vlan command already separates the two traffic types.

987
MCQhard

A user reports that the corporate SSID is visible and accepts the correct password, but the client always lands in a quarantined remediation network. Which troubleshooting area is strongest?

A.Post-authentication policy, role, or VLAN assignment logic
B.Whether the SSID is hidden instead of broadcast
C.Whether the AP uplink uses PPP encapsulation
D.Whether OSPF designated routers are elected correctly
AnswerA

This symptom occurs after the client has successfully authenticated, meaning the fault lies in how the AP or controller authorizes the session. Post-authentication policies, role assignments, or VLAN selection determine which network segment and access level the client receives. If that logic misapplies, the client can have valid credentials yet be placed in the wrong VLAN or denied services, exactly matching the described behavior.

Why this answer

The strongest troubleshooting area is post-authentication policy or role assignment. The client already sees the SSID and successfully authenticates, so the problem is not RF visibility or password failure. Landing in a remediation network indicates a policy decision after authentication, such as a mismatched VLAN assignment or client role.

Option B (hidden SSID) is irrelevant because the SSID is visible. Option C (PPP encapsulation) does not affect post-authentication network placement. Option D (OSPF DR election) is unrelated to client VLAN assignment.

Exam trap

Don't confuse initial connectivity problems with post-authentication issues. Focus on what happens after the connection is established.

Why the other options are wrong

B

A hidden SSID would prevent the SSID from appearing, but the user reports the SSID is visible, so this does not match the symptom.

C

PPP encapsulation on an AP uplink concerns Layer 2 framing, not the post-authentication VLAN or policy assignment that causes quarantine.

D

OSPF designated router election occurs at Layer 3 within routing, while the issue is about client VLAN placement after authentication, which is a Layer 2 access-control function.

When would these options actually be correct?

B

In a different scenario where a user reports being unable to connect to a corporate SSID, and the troubleshooting focuses on whether the SSID is hidden or not, the question could ask about the impact of hidden SSIDs on client connectivity, making this option correct.

C

In a different scenario where the question focuses on the configuration of access points and their uplink connections, a question might ask about the impact of using PPP encapsulation on client connectivity and network access. In that case, if a client is unable to connect due to improper uplink configuration, this option would be correct.

D

In a question focused on routing protocols and network topology, where the scenario involves troubleshooting OSPF issues, such as incorrect router elections leading to suboptimal routing paths, this option would be correct. For example, if a user cannot access certain network resources due to routing misconfigurations, this would be the right choice.

Why candidates pick the wrong answer

B

Candidates may choose this option due to a common misconception that hidden SSIDs enhance security, leading them to believe that visibility is directly related to authentication issues.

C

Candidates may be tempted by this option due to a misunderstanding of network protocols, thinking that the encapsulation method could affect client connectivity, especially if they have encountered PPP issues in other contexts.

D

Candidates might choose this option due to a misunderstanding of network troubleshooting, mistakenly believing that routing issues could affect client access to the network, especially if they are familiar with OSPF and its role in network performance.

988
MCQhard

Why is administratively shutting down unused switch ports considered a useful hardening practice?

A.Because it reduces attack surface by removing unused active connection points.
B.Because it forces all users to manage devices with SSH.
C.Because it converts remaining ports into trunks.
D.Because it replaces VLAN segmentation.
AnswerA

When a port is left enabled but unused, it remains an active connection point that an attacker could plug into, potentially gaining unauthorized network access. Administratively shutting it down places the interface in an administratively down state, which disables the link at Layer 1/2 and effectively removes that exposure. This reduces the attack surface by eliminating avoidable entry points into the network.

Why this answer

Unused active ports create unnecessary exposure. In practical terms, if a port is not needed, leaving it active gives someone an opportunity to connect a device where no legitimate business need exists. Shutting the port down removes that access point and reduces attack surface.

This is a simple but effective hardening measure. It does not replace other controls, but it removes a risk that does not need to exist in the first place.

Exam trap

Do not confuse port shutdown with performance improvements or VLAN configuration changes; focus on security implications.

Why the other options are wrong

B

This option is incorrect because administratively shutting down unused switch ports does not enforce SSH for device management; it simply disables unused ports to enhance security.

C

This option is wrong because administratively shutting down unused switch ports does not convert remaining ports into trunk ports; it simply disables access ports to enhance security.

D

This option is wrong because administratively shutting down unused switch ports does not directly replace VLAN segmentation; rather, it focuses on reducing the number of active ports to mitigate security risks.

When would these options actually be correct?

B

In a question asking about best practices for managing network devices, specifically focusing on access control and secure management protocols, this option could be correct if it stated that forcing users to manage devices with SSH enhances security by ensuring encrypted communication.

C

This option would be correct in a question that asks about configuring switch ports for specific VLANs where trunking is necessary, such as when discussing how to enable trunking on a switch after disabling unused ports to ensure only necessary connections are active.

D

In a question asking about the benefits of VLAN segmentation in a network design context, option D could be correct if it states that replacing VLAN segmentation with another method is beneficial for simplifying network management or enhancing security in a specific scenario.

Why candidates pick the wrong answer

B

Candidates may choose this option due to a misunderstanding of network security practices, believing that shutting down ports directly relates to enforcing secure management protocols like SSH.

C

Candidates may choose this option due to a misunderstanding of port configurations, thinking that disabling ports automatically leads to trunking on remaining ports, reflecting a gap in knowledge about switch port functionality.

D

Candidates may find this option tempting because they might associate the concept of shutting down ports with improving network segmentation, leading to confusion about the relationship between port management and VLANs.

989
MCQmedium

A user reports that websites can be opened by IP address but not by hostname. Which service is the strongest suspect?

A.DNS
B.STP
C.PAT
D.Port security
AnswerA

DNS (Domain Name System) is the service responsible for translating human-friendly hostnames into IP addresses. When a website opens by IP but not by hostname, it indicates the client cannot resolve the name to an IP, so DNS resolution is failing. This can be due to a misconfigured DNS server, incorrect resolver settings on the host, or a missing DNS record for the site. Since direct IP access bypasses DNS, the rest of Layer 3 connectivity is intact.

Why this answer

DNS is the strongest suspect because the network path clearly works at the IP layer. In practical terms, if the user can reach the site by numeric address, then routing and basic connectivity are functioning. The missing piece is name resolution, and that is exactly what DNS provides.

This is one of the clearest troubleshooting patterns in networking. If names fail but IP works, start with DNS.

Exam trap

A common exam trap is selecting PAT or port security as the cause of hostname resolution failure. PAT manages IP address translation for outbound connections but does not resolve hostnames, so it cannot cause DNS failures. Similarly, port security restricts switch port access based on MAC addresses and does not affect DNS or name resolution.

Another tempting but incorrect choice is STP, which operates at Layer 2 to prevent loops and has no role in IP name resolution. Candidates must avoid confusing these distinct network services and focus on DNS when hostname resolution fails but IP connectivity works.

Why the other options are wrong

B

STP (Spanning Tree Protocol) is incorrect because it operates at Layer 2 to prevent network loops and does not handle hostname resolution or IP services.

C

PAT (Port Address Translation) is incorrect because it translates private IP addresses to public IPs for outbound traffic but does not affect DNS or hostname resolution.

D

Port security is incorrect because it controls access to switch ports based on MAC addresses and does not provide or affect hostname resolution services.

When would these options actually be correct?

B

If the question were about a network topology where a loop is causing broadcast storms and preventing devices from communicating properly, a question could ask which protocol is responsible for maintaining a loop-free environment. In that case, STP would be the correct answer.

C

If the question were to ask about a scenario where users can access services using IP addresses but not through specific port numbers due to address translation issues, PAT would be the correct answer. For example, if a user can connect to a web server using its IP but cannot access it via a specific service port due to misconfigured PAT rules.

D

If the question were about a network where users were unable to connect to devices on the network due to unauthorized MAC addresses being blocked by port security, then port security would be the correct answer. In this scenario, the inability to access devices would be due to port security settings.

Why candidates pick the wrong answer

B

Candidates may confuse STP with other network services and protocols, leading them to mistakenly believe it could be related to hostname resolution issues due to its role in network stability.

C

Candidates may confuse PAT with DNS issues, thinking that if IP addresses work, there might be a translation issue affecting port access, leading them to choose this option mistakenly.

D

Candidates may choose this option if they associate network access issues with security measures, mistakenly believing that port security could impact hostname resolution due to its role in controlling device access on the network.

990
MCQhard

Hosts on the inside network can reach the internet, but return traffic is failing after a new router was installed. The router's configuration shows that the LAN-facing interface has been configured with 'ip nat outside' and the WAN-facing interface with 'ip nat inside'. What configuration mistake is the most likely cause?

A.The NAT inside and outside interface roles are reversed.
B.The ACL must deny RFC1918 traffic before NAT can work.
C.PAT cannot use an interface address for overload.
D.The inside subnet must be configured as /24 on both interfaces.
AnswerA

Cisco NAT requires the interface connected to the internal network (where private IP addresses reside) to be configured with 'ip nat inside', and the interface connected to the public network (the internet) with 'ip nat outside'. The scenario describes the LAN-facing interface as 'ip nat outside' and the WAN-facing interface as 'ip nat inside'. This reversal prevents the router from correctly translating the source private IP addresses of outbound traffic into a public IP. Consequently, return traffic from the internet, destined for the public IP, cannot be reverse-translated and routed back to the internal hosts, satisfying the constraint that return traffic is failing.

Why this answer

NAT overload requires the LAN-facing interface to be marked as ip nat inside and the WAN-facing interface as ip nat outside. The exhibit shows those roles reversed, so translations will not occur correctly. The ACL itself is fine for matching the inside subnet.

Exam trap

A frequent exam trap is reversing the NAT inside and outside interface roles. Candidates may see that hosts can initiate traffic to the internet and mistakenly assume NAT is correctly configured. However, if the router’s interfaces are misassigned, return traffic from the internet will not be translated back to the inside hosts, causing connectivity failures.

This trap exploits the partial functionality of NAT where outbound packets appear to succeed but inbound packets fail, leading to confusion during troubleshooting and exam scenarios.

Why the other options are wrong

B

Incorrect. The ACL in NAT configurations is used to identify which inside addresses to translate, not to filter or deny traffic. Denying RFC1918 traffic in the ACL is unnecessary and unrelated to the NAT failure described.

C

Incorrect. Using the outside interface IP address for PAT overload is a standard and supported practice in Cisco NAT configurations. This option does not explain the return traffic failure.

D

Incorrect. The inside subnet should only be configured on the LAN interface. The WAN interface typically uses a different subnet and should not share the inside subnet.

This misconfiguration would cause routing issues but is not the primary cause of NAT return traffic failure here.

When would these options actually be correct?

B

In a different scenario where a question states that NAT is configured but only private IP addresses are being routed to the internet, and the ACL is explicitly set to deny RFC1918 addresses, this option would be correct. It would imply that the ACL is blocking necessary traffic for NAT to operate.

C

In a scenario where a question specifies that PAT is configured incorrectly and explicitly states that it cannot use an interface address for overload, this option would be correct. For example, if the question describes a setup where multiple internal hosts are trying to access the internet but are configured to use the router's interface address directly without proper overload settings.

D

In a different scenario where a question specifies that both the inside and outside interfaces must have the same subnet mask for proper routing and NAT to function, option D would be correct. For example, if the question states that mismatched subnet masks are causing routing issues, then this option would be valid.

Why candidates pick the wrong answer

B

Candidates may find this option tempting because they might recall that ACLs can impact NAT operations, leading them to mistakenly believe that denying private addresses is a necessary step for NAT to function properly.

C

Candidates may choose this option due to a misunderstanding of PAT functionality, thinking that it cannot use the interface address, especially if they confuse it with static NAT configurations that require specific mappings.

D

Candidates may choose this option because they associate NAT functionality with subnet configurations, believing that consistent subnet masks are essential for NAT operations, leading to confusion about the specific requirements for NAT to function correctly.

991
MCQhard

A host uses the subnet mask 255.255.255.240. How many usable host addresses exist in each subnet?

A.12
B.14
C.16
D.30
AnswerB

A subnet mask of 255.255.255.240 is a /28 prefix, meaning 4 bits are available for host addresses. This yields 2^4 = 16 total IP addresses within the subnet. To determine usable host addresses, subtract the network address and the broadcast address, leaving 16 - 2 = 14 assignable addresses. So 14 is the correct number of usable hosts for a /28 network.

Why this answer

The mask 255.255.255.240 corresponds to /28. In practical terms, that leaves 4 host bits, which gives 16 total addresses in each subnet. After subtracting the network and broadcast addresses, 14 usable hosts remain.

This is a classic host-capacity calculation and a very common subnetting pattern on the exam.

Exam trap

A frequent exam trap is selecting the total number of addresses in the subnet (16) instead of the usable host addresses (14). Candidates often forget to subtract the network and broadcast addresses, which are reserved and cannot be assigned to hosts. Another common mistake is confusing the /28 subnet mask with /27, which offers 30 usable hosts, leading to incorrect answers like 30.

This confusion arises because both subnet masks are close in size but differ significantly in host capacity. Always remember that usable hosts equal total addresses minus two reserved addresses.

Why the other options are wrong

A

Option A states 12 usable hosts, which is incorrect because a /28 subnet provides 16 total addresses. Subtracting the network and broadcast addresses leaves 14 usable hosts, not 12. This option underestimates the host capacity.

C

Option C claims 16 usable hosts, which is incorrect because 16 represents the total number of addresses in the subnet, including network and broadcast addresses. Usable hosts must exclude these two reserved addresses.

D

Option D suggests 30 usable hosts, which corresponds to a /27 subnet mask (255.255.255.224), not /28. This overestimates the host count for the given subnet mask and is therefore incorrect.

When would these options actually be correct?

A

This option would be correct in a scenario where the question mistakenly asks for the total number of addresses in the subnet instead of usable addresses. For example, if the question stated, 'How many total addresses exist in a subnet with a mask of 255.255.255.240?' then 16 would be the correct answer.

C

If the question asked about the total number of addresses in a subnet with a mask of 255.255.255.240, then the correct answer would be 16, as it counts all addresses including the network and broadcast addresses.

D

If the question specified a subnet mask of 255.255.255.252, which allows for 4 total addresses, then option D would be correct, as there would be 2 usable host addresses in that subnet.

Why candidates pick the wrong answer

A

Candidates may choose this option due to confusion between total addresses and usable addresses, leading them to incorrectly calculate the usable host count without considering the network and broadcast addresses.

C

Candidates may choose this option due to a misunderstanding of how to calculate usable addresses versus total addresses, leading them to mistakenly count all addresses in the subnet.

D

Candidates might choose option D because they miscalculate the total number of addresses without considering the reserved network and broadcast addresses, leading them to believe that all addresses are usable.

992
MCQhard

An enterprise network uses an IPv6 dual-stack design. Router R1 has a primary default route ::/0 via 2001:db8:1::1 with AD 1 and a floating default route with AD 10 via link-local address fe80::2. After the primary link fails, the floating route fails to install, and R1 loses all external connectivity. The administrator confirms the backup interface is up/up.

A.The administrative distance of the backup route is 10, so it is not installed while the primary route still exists.
B.The floating static route uses a link-local next-hop but does not specify an exit interface, making the route incomplete.
C.The floating static route will be installed only if the primary link is administratively shut down, not after a physical failure.
D.The next-hop fe80::2 is unreachable because IPv6 neighbor discovery is disabled on the backup interface.
AnswerB

An IPv6 static route that uses a link-local next-hop such as fe80::2 must also specify the exit interface because link-local addresses are only meaningful on a specific link. Without that interface keyword, the router cannot determine which interface to use to reach the next hop, so the route is considered incomplete and is not installed in the routing table. This remains true even if the next-hop address is otherwise reachable, and it is exactly why the backup route fails to appear when the primary route is removed. The correct configuration would include the outgoing interface, for example 'ipv6 route 2001:db8::/32 GigabitEthernet0/1 fe80::2'.

Why this answer

A floating static route using a link-local next-hop (fe80::2) must also specify an exit interface (e.g., GigabitEthernet0/1) to be considered complete. Without the exit interface, the router cannot determine which interface to use for neighbor discovery, leaving the route incomplete and unable to be installed into the routing table. This is a common requirement for IPv6 static routes with link-local addresses, as the next-hop is not globally unique.

Exam trap

Cisco often tests the requirement that IPv6 static routes with link-local next-hops must include an exit interface, tricking candidates into thinking the route is valid without it or misattributing the failure to administrative distance or interface status.

Why the other options are wrong

A

A floating static route with a higher AD is installed when the lower AD route is removed because of interface failure.

C

Floating static routes do not distinguish between physical and administrative interface down events; the primary route is removed in both cases.

D

The immediate cause is the missing exit interface; neighbor discovery configuration does not make an incomplete static route valid.

993
MCQmedium

A network administrator needs to configure VLANs and access ports on 200 managed switches across multiple locations. The administrator requires a solution that uses a push‑based deployment model, does not require any agent software to be installed on the switches, and can be executed from a central control node. Which automation tool is most suitable for this task?

A.Puppet
B.Chef
C.Ansible
D.Python scripts
AnswerC

Ansible is the correct answer because it employs a push-based, agentless model over SSH (or WinRM). The control node connects directly to managed hosts, executes modules written in Python, and applies YAML playbooks in real time, with no persistent agent installed on targets. This makes Ansible ideal for immediate orchestration and configuration tasks, especially in dynamic environments where maintaining agents on every node is impractical.

Why this answer

Ansible is the most suitable tool because it uses a push-based model (SSH) to apply configurations directly to network devices without requiring any agent software. It operates from a central control node, making it ideal for managing 200 switches across multiple locations with a single playbook execution.

Exam trap

Cisco often tests the distinction between push-based (Ansible) and pull-based (Puppet, Chef) models, and the trap here is assuming that any scripting language like Python is a complete automation tool rather than a component that requires additional orchestration.

Why the other options are wrong

A

Requires agents and is pull‑based, failing both the agentless and push requirements.

B

Agents are mandatory, and the pull mechanism contradicts the push requirement.

D

Lacks built‑in push‑based orchestration, idempotency, and agentless design without significant custom development, making it less suitable than a purpose‑built tool.

994
MCQhard

Refer to the exhibit. A network technician is troubleshooting router R1, which cannot reach hosts on the internet. R1 is connected to an ISP router at 203.0.113.1. The exhibit shows the output of the show ip route command. What is the most likely cause of the issue?

A.A static default route is not configured on R1, and OSPF is not advertising a default route.
B.The OSPF neighbor relationship with the ISP router is down.
C.The interface connecting to the ISP router is in a shutdown state.
D.An incorrect next-hop address was specified in the static default route, making the route invalid.
AnswerA

The output explicitly shows 'Gateway of last resort is not set' and no 0.0.0.0/0 route. A default route is required to reach external networks like the internet. The OSPF-learned route proves OSPF adjacency, but the absence of O*E2 or similar default route indicates default-information originate is not configured.

Why this answer

The exhibit shows that R1 has no default route (0.0.0.0/0) in its routing table, and the only routes present are OSPF-learned internal routes. Since R1 cannot reach the internet, the most likely cause is that no static default route is configured pointing to the ISP router (203.0.113.1) and OSPF is not injecting a default route into R1. Without a default route, R1 has no path for traffic destined outside its OSPF domain.

Exam trap

Cisco often tests the misconception that OSPF automatically shares a default route to all neighbors, when in fact it requires explicit configuration via the 'default-information originate' command.

Why the other options are wrong

B

Candidates often assume OSPF is not working at all when a default route is missing, ignoring other OSPF routes in the table.

C

Candidates may assume any connectivity failure means an interface is disabled, but the routing table would show no connected network if the interface were shut down.

D

Candidates might think a misconfigured static route would cause the problem, but they overlook that the route would still appear in the table, just with a different next-hop.

995
MCQhard

Dynamic ARP Inspection is most effective at preventing which attack?

A.SYN flood
B.ARP spoofing
C.Route summarization error
D.Rogue DHCP relay
AnswerB

Dynamic ARP Inspection (DAI) is an L2 security feature that intercepts ARP packets on untrusted switch ports and verifies that the sender MAC and IP addresses match the DHCP snooping binding table. Any ARP response announcing a conflict or forged MAC-IP pairing—the defining characteristic of ARP spoofing—is dropped. By blocking these poisoned frames, DAI prevents an attacker from redirecting traffic to a rogue host for on-path interception or man-in-the-middle attacks.

Why this answer

Dynamic ARP Inspection (DAI) validates ARP packets on a per-interface basis, dropping invalid ARP replies and thus preventing ARP spoofing and poisoning attacks. Option A (SYN flood) is a Layer 4 TCP attack mitigated by TCP flood protection or SYN cookies, not DAI. Option C (route summarization error) is a routing misconfiguration unrelated to ARP security.

Option D (rogue DHCP relay) is prevented by DHCP snooping, which works alongside DAI but DAI itself does not block rogue DHCP relays.

Exam trap

Be careful not to confuse ARP spoofing with other types of spoofing attacks like IP or DNS spoofing.

Why the other options are wrong

A

SYN flood is a Layer 4 TCP attack that is blocked by flood guards, not by DAI.

C

Route summarization error is a routing protocol misconfiguration and is unrelated to ARP packet validation.

D

Rogue DHCP relay is mitigated by DHCP snooping, not by Dynamic ARP Inspection.

When would these options actually be correct?

A

If the question were to ask about a security mechanism that protects against various types of DoS attacks, including SYN floods, then this option could be correct. For example, a question might focus on overall network security measures that mitigate multiple attack vectors, including SYN floods.

C

If the exam question asked about the effectiveness of security measures in preventing routing protocol misconfigurations or errors, then a focus on route summarization could be relevant. For example, a question could ask which method helps prevent routing loops caused by incorrect summarization.

D

If the exam question asked about security measures to prevent unauthorized DHCP servers from distributing IP addresses in a network, then 'Rogue DHCP relay' would be the correct answer. This would focus on DHCP snooping or similar technologies rather than ARP-related protections.

Why candidates pick the wrong answer

A

Candidates may confuse ARP-related security measures with general network security concepts, leading them to mistakenly associate SYN floods with ARP Inspection due to a lack of clarity on the specific functions of each security mechanism.

C

Candidates may confuse ARP-related security with routing issues due to overlapping knowledge areas in networking, leading them to mistakenly associate route summarization with ARP protection.

D

Candidates may confuse DHCP-related attacks with ARP-related protections due to their overlapping roles in network security, leading them to mistakenly believe that Dynamic ARP Inspection could mitigate DHCP issues.

996
MCQeasy

A network administrator is using a Python script to retrieve interface statistics from a Cisco IOS XE device via RESTCONF. The script sends an HTTP GET request to the RESTCONF endpoint. Which HTTP status code indicates that the request was successful and the response body contains the requested data?

A.200 OK
B.304 Not Modified
C.201 Created
D.204 No Content
AnswerA

HTTP 200 OK indicates that the request succeeded and the response body contains the requested resource representation. In RESTCONF, a successful GET returns 200 with the data in JSON or XML format. This is the standard success code for retrieving information.

Why this answer

In RESTCONF, a successful GET request that returns data uses the HTTP 200 OK status code. This indicates that the server has processed the request and the response body contains the requested representation, such as interface statistics in JSON or XML. Other 2xx codes like 201 or 204 have different meanings related to resource creation or empty responses.

Exam trap

The trap here is assuming any 2xx status code means success with data, but 204 specifically means no content is returned.

997
MCQmedium

An automation script must retrieve the current configuration state of a device from a REST API without modifying anything. Which HTTP method should it use?

A.DELETE
B.GET
C.PUT
D.POST
AnswerB

GET is the correct choice because it is a safe, idempotent HTTP method defined by RFC 7231 specifically for retrieving the current representation of a resource. It performs no state change on the server, so the script can fetch the running configuration without risking any modification. The response body carries the requested configuration data, making GET the semantically exact operation for a read-only retrieval.

Why this answer

When a script only needs to read information, the normal REST choice is GET. In plain terms, GET asks the server, “Show me the current data,” without telling it to create, replace, or delete anything. That is why GET is the standard method for retrieving device state, configuration details, statistics, or inventory information from an API endpoint.

The other methods imply change. POST commonly creates or submits data. PUT commonly updates an existing resource. DELETE removes something. For a read-only query, GET is the clean and expected method.

Exam trap

Avoid confusing HTTP methods that modify data (POST, PUT, DELETE) with GET, which is read-only.

Why the other options are wrong

A

The DELETE method is used to remove a resource from the server, which directly modifies the state of the device's configuration. Since the question specifies that the script must retrieve the configuration without making any modifications, DELETE is not appropriate.

C

The PUT method is used to update or replace a resource on a server, which contradicts the requirement of retrieving the current configuration state without making any modifications.

D

The POST method is used to send data to a server to create or update a resource, which contradicts the requirement of retrieving the current configuration state without modifying anything.

When would these options actually be correct?

A

In a different scenario where the question asks for the method to remove a specific configuration setting from a device's REST API, the DELETE method would be correct. For example, if the question stated, 'An automation script must remove a specific configuration from a device using a REST API,' then DELETE would be the appropriate choice.

C

In a different scenario where the question asks for the method to update the configuration state of a device using a REST API, the PUT method would be correct, as it is specifically designed for resource updates.

D

If the exam question asked which HTTP method should be used to send data to a server to create a new resource based on the current configuration state, then POST would be the correct answer.

Why candidates pick the wrong answer

A

Candidates may choose DELETE due to a misunderstanding of HTTP methods, confusing the action of retrieving information with the action of removing it, especially if they are not fully aware of the implications of each method.

C

Candidates may confuse PUT with GET due to their similar roles in RESTful APIs, leading them to mistakenly believe that PUT can also be used for retrieving data, especially if they are less familiar with the specific functions of each HTTP method.

D

Candidates may confuse POST with data retrieval due to its common use in web applications, where forms often use POST to submit data, leading to the mistaken belief that it could also be used for fetching information.

998
MCQhard

A network administrator notices that file transfers to a server are extremely slow, and on the switch interface connecting to the server, the output of 'show interfaces' indicates a high number of runts and CRC errors, but no collisions. Which of the following is the most likely cause?

A.The cable connecting the server to the switch is faulty.
B.The switch port is configured for full-duplex, but the server's NIC is set to half-duplex.
C.The switch port speed is set to 100 Mbps, but the server NIC is set to 10 Mbps.
D.The server's NIC driver is outdated, causing packet loss.
AnswerB

A duplex mismatch where the switch uses full-duplex and the server uses half-duplex results in the full-duplex side (switch) showing runts and CRC errors without collisions, while the half-duplex side sees collisions. This matches the 'show interfaces' output and explains the slow transfers due to excessive retransmissions.

Why this answer

The combination of runts (frames smaller than 64 bytes) and CRC errors with zero collisions is a classic symptom of a duplex mismatch. When one side operates at full-duplex and the other at half-duplex, the half-duplex side will detect collisions and invoke its backoff algorithm, causing the full-duplex side to receive truncated frames (runts) and frames with invalid FCS (CRC errors). The switch interface statistics show no collisions because the switch port is full-duplex and does not detect collisions, while the server's half-duplex NIC is causing the corruption.

Exam trap

Cisco often tests the distinction between symptoms of duplex mismatch versus cable faults, where candidates mistakenly attribute runts and CRC errors to a bad cable, ignoring the critical clue of zero collisions that points to a mismatch.

Why the other options are wrong

A

While a faulty cable could cause CRC errors, it would likely produce other error types and might not exhibit the specific pattern of only runts and CRC errors with no collisions. This pattern strongly points to a duplex mismatch.

C

A speed mismatch would generally cause the link to fail entirely; you wouldn't see interface errors because there would be no connectivity. The scenario describes connectivity with errors, so this is unlikely.

D

Outdated drivers may cause performance problems, but they do not produce the specific interface error counters on the switch. The recorded runts and CRC errors point to a physical or data-link layer issue, not a driver problem.

999
MCQhard

A router has this command configured: `ip nat inside source static 192.168.1.50 203.0.113.50`. What is the main effect of this configuration?

A.It creates a permanent one-to-one translation between the inside host and a public address
B.It enables PAT overload for all internal users
C.It blocks inbound access to the inside host permanently
D.It changes the host subnet mask to a public prefix
AnswerA

This command creates a permanent one-to-one mapping between a single inside local IP address (192.168.1.50) and a fixed inside global public IP address. The translation is inserted statically and remains in the NAT table until manually deleted, allowing bidirectional traffic initiation. This distinguishes it from dynamic NAT, which uses a pool and times out.

Why this answer

This command creates a static NAT mapping between one inside local address and one inside global address. In plain language, the internal device at 192.168.1.50 will always appear as 203.0.113.50 to the outside world. That fixed relationship is useful when a particular internal host or service must be reachable consistently from outside networks.

This is different from PAT, which shares one public address across many sessions using ports. Static NAT is one-to-one and predictable. It does not dynamically pull from a pool in this syntax. The key idea is permanence: the same inside device is always mapped to the same outside address.

Exam trap

A common exam trap is mistaking static NAT for PAT or dynamic NAT. Candidates may incorrectly assume that the command enables PAT overload, allowing many internal users to share one public IP, but static NAT provides a fixed one-to-one mapping without port translation. Another trap is thinking static NAT blocks inbound traffic; in reality, it enables inbound access to the mapped inside host.

Misunderstanding these differences can lead to selecting incorrect answers about NAT behavior and configuration.

Why the other options are wrong

B

This option is incorrect because PAT overload uses a different command syntax involving 'overload' and allows many internal hosts to share one public IP, which is not the case here.

C

This option is wrong since static NAT does not inherently block inbound access; instead, it enables external hosts to reach the inside host via the mapped public IP.

D

This option is incorrect because NAT translation does not modify the subnet mask of the inside host; it only changes the IP address seen externally.

When would these options actually be correct?

B

In a different question, if the command were `ip nat inside source list 1 interface Serial0 overload`, it would enable PAT for all internal users, allowing multiple devices to share a single public IP address through port numbers.

C

If the question were about a firewall configuration that explicitly denies all inbound traffic to a specific host, then stating that it blocks inbound access would be correct. For example, a question could ask about a firewall rule that drops all packets destined for a specific internal IP.

D

If the question were about a command that explicitly modifies the IP address configuration of a device, such as `ip address 203.0.113.50 255.255.255.0`, then this option would be correct, as it would indicate that the host's subnet mask is being changed to a public prefix.

Why candidates pick the wrong answer

B

Candidates may confuse static NAT with PAT due to their similar purposes in network address translation, leading them to incorrectly assume that the command enables overload for multiple users.

C

Candidates might choose this option due to a misunderstanding of NAT concepts, confusing the static mapping with security features that restrict access to internal hosts.

D

Candidates might choose this option due to a misunderstanding of NAT concepts, conflating NAT operations with IP address configuration changes, leading them to believe that NAT inherently modifies subnet masks.

1000
MCQmedium

Which port-security violation mode drops frames from unauthorized MAC addresses but keeps the interface up and does not send an SNMP trap or syslog message?

A.protect
B.restrict
C.shutdown
D.shutdown vlan
AnswerA

Protect is the quietest switchport port-security violation mode: when the port's MAC address table is full, it silently drops frames from new, unknown MAC addresses while continuing to forward traffic for already-learned addresses. No SNMP trap or syslog message is generated, and the port remains up and operational, making the violation virtually invisible to network monitoring. This is the correct answer because the question asks which mode drops frames without any further action or notification.

Why this answer

Protect silently drops frames from unauthorized sources while leaving the interface up. Restrict also drops frames but increments the violation counter and can generate notifications.

Exam trap

Be careful not to confuse Protect with Restrict, as both drop frames but only Restrict sends notifications.

Why the other options are wrong

B

The 'restrict' mode allows frames from unauthorized MAC addresses to be dropped while sending SNMP traps and syslog messages, which contradicts the requirement of keeping the interface up without notifications.

C

The 'shutdown' mode disables the interface when a violation occurs, which is contrary to the requirement of keeping the interface up. It also does not align with the need to drop frames without sending SNMP traps or syslog messages.

D

The 'shutdown vlan' mode disables the entire VLAN when a violation occurs, which is not aligned with the requirement to keep the interface up. This option also typically sends SNMP traps or syslog messages, which contradicts the question's criteria.

When would these options actually be correct?

B

In a different question, if asked about a port-security mode that drops unauthorized MAC frames but also sends alerts to network management systems, 'restrict' would be the correct answer, as it fits the criteria of notifying administrators while maintaining interface functionality.

C

In a question asking for a port-security violation mode that completely disables the interface upon detecting unauthorized MAC addresses, 'shutdown' would be the correct answer. This scenario would focus on a strict security posture where any unauthorized access leads to immediate interface shutdown.

D

In a scenario where the question asks which port-security violation mode disables a specific VLAN but still allows other VLANs to function normally, 'shutdown vlan' would be the correct answer. This could involve a focus on VLAN-specific security measures rather than interface status.

Why candidates pick the wrong answer

B

Candidates may choose 'restrict' because it sounds similar to 'protect' and implies a proactive approach to security, leading them to mistakenly associate it with a mode that drops unauthorized traffic without shutting down the interface.

C

Candidates may choose 'shutdown' because it is a well-known port-security mode that directly addresses unauthorized access, leading to confusion with the requirement to drop frames while keeping the interface operational.

D

Candidates may find 'shutdown vlan' tempting because it suggests a strong security posture by disabling a VLAN, which might seem like a logical choice when considering unauthorized access prevention.

1001
MCQhard

R1 has routes to 172.16.10.0/24 from multiple sources. Which route will be installed?

A.The OSPF route with metric 20
B.The EIGRP internal route
C.The RIP route because hop count is lowest
D.The static route with administrative distance 95
AnswerB

EIGRP internal routes carry a default administrative distance of 90, lower than OSPF (110), RIP (120) and external EIGRP (170), so the router installs this route into the routing table when multiple sources advertise the same 172.16.10.0/24 prefix.

Why this answer

Routers compare route source trust first using administrative distance. EIGRP internal routes have an AD of 90, which is lower than OSPF (110), RIP (120), and a static route with AD 95. Therefore, the EIGRP internal route is installed, regardless of metrics.

Exam trap

A common trap is confusing administrative distance with routing metric, causing candidates to choose OSPF due to its lower metric or the static route with AD 95 over the correct EIGRP route.

Why the other options are wrong

A

The OSPF route (AD 110) has a lower metric but a higher administrative distance than EIGRP, so it loses.

C

The RIP route (AD 120) has the highest administrative distance and loses regardless of its hop count metric.

D

The static route with AD 95 loses to the EIGRP internal route (AD 90) because a lower AD is preferred.

When would these options actually be correct?

A

If the question stated that OSPF and EIGRP have the same administrative distance (e.g., both set to 120) and OSPF's metric (20) is better than EIGRP's metric, then the OSPF route would be installed based on lowest metric.

C

In a scenario where all routes are from RIP (e.g., multiple RIP paths to the same network), the route with the lowest hop count would be installed. For example, if the question asked 'Which RIP route will be installed?' and two RIP routes with different hop counts exist, the one with the lowest hop count is correct.

D

If the question stated that the static route had an administrative distance of 85 (lower than all dynamic protocols), or if the dynamic routes were all from protocols with higher ADs (e.g., RIP at 120, OSPF at 110), then the static route with AD 95 would be installed.

Why candidates pick the wrong answer

A

Candidates may focus on the metric value (20) being low and assume that OSPF will win, forgetting that administrative distance is evaluated first before metric comparison.

C

Candidates may mistakenly believe that the metric (hop count) is the deciding factor across different routing protocols, ignoring the higher priority of administrative distance.

D

Candidates may think that a static route with a low AD (95) is always preferred over dynamic routes, but they forget that EIGRP internal routes have an even lower AD (90).

1002
Drag & Drophard

Drag and drop the following steps into the correct order to configure a new WLAN on a Cisco WLC using IOS-XE CLI, including WPA3-Personal security, and to complete a wireless client association with DHCP.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The configuration order follows the Cisco IOS-XE WLC CLI: first enter global config, create the WLAN profile, set security (WPA3-Personal/SAE), enable the WLAN, then the client associates and gets an IP via DHCP.

Exam trap

Be careful with the order of operations: you must create the WLAN profile first, then configure security, then enable the WLAN. Also, remember that DHCP IP assignment occurs after the client associates, not before.

Why candidates pick the wrong answer

B

Candidates might think enabling the WLAN early is fine because they plan to configure security later, but the CLI requires security configuration before enabling.

C

Candidates might think security can be configured globally or before creating the WLAN, but it is profile-specific.

D

Candidates might think DHCP is a prerequisite for association, but association must complete first for the client to communicate with the DHCP server.

1003
Multi-Selecthard

Which two conditions must match on two switch ports before they can successfully form a Layer 2 EtherChannel? (Choose two.)

Select 2 answers
A.The switchport mode and VLAN settings
B.The STP root bridge ID on both switches
C.The speed and duplex settings
D.The interface description
E.The ARP timeout value
AnswersA, C

For an EtherChannel to operate correctly, each member port on both switches must be assigned the same switchport mode (access or trunk) and, if trunking, the identical set of allowed VLANs. When mode or VLAN permissions differ across links, frames may be dropped or forwarded inconsistently because the channel treats all member ports as a single logical link, and STP or negotiation protocols will reject the bundle if these attributes disagree.

Why this answer

Layer 2 EtherChannel members must have compatible Layer 2 configuration. Port mode, VLAN-related settings, speed, and duplex all need to align for the bundle to form correctly.

Exam trap

Remember that EtherChannel requires consistent speed and duplex settings, and also consistent switchport mode (access or trunk) and allowed VLANs.

Why the other options are wrong

B

This option is wrong because the STP root bridge ID does not directly affect the formation of an EtherChannel; EtherChannel requires matching port configurations, not spanning tree parameters.

D

The interface description does not affect the formation of an EtherChannel, as it is merely a label for identification purposes and does not influence Layer 2 connectivity or protocol negotiation.

E

The ARP timeout value does not affect the formation of a Layer 2 EtherChannel, as EtherChannel operates at Layer 2 and is concerned with port configurations, not Layer 3 settings like ARP.

When would these options actually be correct?

B

In a different question asking about the prerequisites for a stable spanning tree topology, the STP root bridge ID would be relevant. For example, if the question focused on ensuring consistent spanning tree behavior across multiple switches, matching root bridge IDs would be necessary.

D

In a question focused on network documentation or management best practices, where candidates are asked to identify the importance of consistent interface descriptions across switch ports for ease of troubleshooting and management, this option would be correct.

E

In a question focused on Layer 3 configurations or network performance optimization, a scenario might ask about factors that influence ARP behavior, where candidates must identify the correct ARP timeout settings for different network segments.

Why candidates pick the wrong answer

B

Candidates may find this option tempting because they understand that STP is crucial for Layer 2 networks and might mistakenly believe that its parameters are relevant to EtherChannel formation.

D

Candidates may mistakenly believe that interface descriptions play a role in EtherChannel formation due to their importance in network documentation and clarity, leading to confusion about their technical relevance in this specific context.

E

Candidates may confuse Layer 2 EtherChannel requirements with Layer 3 functionalities, mistakenly thinking that ARP settings could impact the link aggregation process.

1004
MCQmedium

A network technician is troubleshooting a connectivity issue between two hosts. Host A sends a web request to Host B. The technician captures packets on the link between the two hosts and sees the data as '01010101...'. At which layer of the OSI model is this data being transmitted, and what is the correct PDU name for this layer?

A.Data Link layer; frames
B.Physical layer; bits
C.Network layer; packets
D.Transport layer; segments
AnswerB

The Physical layer (Layer 1) is responsible for the transmission and reception of unstructured raw bit streams over a physical medium, such as copper wire, fiber, or radio waves. At this layer, the PDU is simply the bit, and there is no recognition of packets, frames, or segments—only signaling states that represent 0s and 1s. The captured data '01010101...' exactly matches this definition, making 'Physical layer; bits' the correct answer.

Why this answer

The data shown as '01010101...' represents raw binary bits being transmitted over the physical medium. At the Physical layer (Layer 1), data is encoded as electrical signals, light pulses, or radio waves, and the PDU is called bits. This matches the description of the captured data.

Exam trap

Cisco often tests the distinction between the Physical layer's raw bits and the Data Link layer's frames, expecting candidates to recognize that binary sequences without structure belong to Layer 1, not Layer 2.

Why the other options are wrong

A

The technician sees raw bits before framing, so this is not the Data Link layer.

C

The Network layer deals with logical addressing and routing, not the physical transmission of bits.

D

The Transport layer is above the Physical layer and does not deal with bit-level transmission.

1005
Multi-Selectmedium

Which three options are true regarding the operation of Dynamic ARP Inspection (DAI) on a Cisco switch? (Choose three.)

Select 3 answers
.DAI validates ARP packets based on the DHCP snooping binding database.
.DAI can be configured to drop ARP packets with invalid MAC-to-IP address bindings.
.DAI is typically enabled on untrusted ports that face end hosts.
.DAI encrypts ARP replies to prevent eavesdropping.
.DAI relies on the MAC address table to validate ARP requests.
.DAI prevents rogue DHCP server attacks by inspecting DHCP offers.

Why this answer

Dynamic ARP Inspection (DAI) validates ARP packets by intercepting them on untrusted ports and checking the MAC-to-IP address binding against the DHCP snooping binding database. If the binding is invalid or missing, DAI drops the packet, preventing ARP spoofing attacks. This is why all three statements are correct: DAI relies on the DHCP snooping database, drops invalid bindings, and is enabled on untrusted ports facing end hosts.

Exam trap

Cisco often tests the misconception that DAI validates ARP packets using the MAC address table or ARP cache, when in fact it strictly relies on the DHCP snooping binding database.

1006
Multi-Selectmedium

Which two statements accurately describe controller-based networking at the CCNA level?

Select 2 answers
A.A controller can centralize management and policy logic.
B.Northbound APIs can allow external applications to communicate with the controller.
C.Controllers eliminate all need for switches and routers.
D.Controllers are unrelated to automation.
E.Controllers require Telnet for all communication.
AnswersA, B

A controller centralizes management and policy logic, providing a single point from which administrators define and enforce network-wide configurations, security policies, and quality-of-service rules. This abstraction simplifies operations compared with per-device CLI management, allowing consistent policy application across many switches and routers without replacing the forwarding infrastructure itself.

Why this answer

A software-defined networking (SDN) controller centralizes management, policy logic, and network intelligence, reducing manual per-device configuration. Option B is correct because northbound APIs (e.g., REST APIs) allow external applications, orchestration tools, and automation scripts to interact with the controller for dynamic network control. Option C is wrong because controllers do not eliminate switches and routers; these devices still forward packets based on instructions from the controller.

Option D is wrong because controllers are fundamental to network automation—they provide programmable interfaces and centralized logic that enable automated provisioning and policy enforcement. Option E is wrong because modern controllers use secure communication channels such as HTTPS, SSH, or TLS, not Telnet (which is insecure and rarely used in controller architectures).

Exam trap

A frequent exam trap is selecting answers that imply controllers replace all network devices or that they are unrelated to automation. Some candidates mistakenly believe that controller-based networking removes the need for switches and routers, which is incorrect because these devices still perform actual packet forwarding. Others overlook the role of controllers in automation, ignoring that controllers expose northbound APIs specifically to enable external applications and automation tools to interact with the network.

Misunderstanding these points can lead to choosing incorrect options that overstate or understate the controller’s role.

Why the other options are wrong

C

This option is incorrect because controllers do not eliminate the need for switches and routers; these devices still perform the actual packet forwarding in the network.

D

This option is incorrect since controllers are highly relevant to automation, providing APIs and centralized control that enable automated network management workflows.

E

This option is incorrect because controller communication is not universally based on Telnet; modern controllers use secure protocols and APIs rather than relying solely on Telnet.

When would these options actually be correct?

C

In a question focused on theoretical networking concepts where the context implies a fully virtualized network environment, one might argue that in such a scenario, traditional switches and routers could be deemed unnecessary. This could be framed in a way that emphasizes a completely software-defined approach.

D

In a question specifically focused on traditional networking concepts, where the role of automation is not mentioned, this option could be correct if it asked about the functions of legacy networking devices that do not utilize controller-based architectures.

E

In a different exam scenario focused on legacy systems or specific configurations, a question might state that a particular controller only supports Telnet for communication due to compatibility with older network devices. In that case, option E would be correct.

Why candidates pick the wrong answer

C

Candidates may find this option tempting due to a misunderstanding of the role of controllers, mistakenly believing that advanced networking technologies can fully replace traditional hardware, especially in discussions about software-defined networking.

D

Candidates may choose this option due to a misunderstanding of the role of controllers in modern networking, confusing them with traditional networking practices where automation was less prevalent, leading to the assumption that controllers are not related to automation.

E

Candidates may choose this option due to a misunderstanding of traditional network management practices, where Telnet was commonly used, leading them to incorrectly associate it with all types of network controllers.

1007
PBQhard

Which option performs the RESTCONF operations correctly?

Network Topology
G0/0192.168.1.1/30G0/0192.168.1.2/30linkR1R2

Hints

  • •Check the YANG module path: ietf-interfaces vs Cisco-IOS-XE-native
  • •Ensure the Accept header matches the data format (yang-data+json)
  • •For PATCH, the Content-Type must be application/yang-data+json, not application/json
A.GET /restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet0/0 with Accept: application/yang-data+json; then PATCH same URI with Content-Type: application/yang-data+json and body {"ietf-interfaces:interface":{"duplex":"full"}}; expect 204 No Content.
B.GET /restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet0/0 with Accept: application/json; then PATCH same URI with Content-Type: application/json and body {"duplex":"full"}; expect 204 No Content.
C.GET /restconf/data/Cisco-IOS-XE-native:interface/GigabitEthernet0/0 with Accept: application/yang-data+json; then PATCH same URI with Content-Type: application/yang-data+json and body {"Cisco-IOS-XE-native:interface":{"duplex":"full"}}; expect 204 No Content.
D.GET /restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet0/0 with Accept: application/yang-data+json; then PATCH same URI with Content-Type: application/yang-data+json and body {"duplex":"full"}; expect 200 OK.
AnswerA
solution
! R1
GET request URI: /restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet0/0
GET headers: Accept: application/yang-data+json
PATCH request URI: /restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet0/0
PATCH headers: Content-Type: application/yang-data+json
PATCH body: {"ietf-interfaces:interface": {"duplex": "full"}}

Why this answer

The correct base URI for RESTCONF is /restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet0/0. The Accept header must be application/yang-data+json. If the Content-Type header is incorrect (e.g., application/json), the router will return a 415 Unsupported Media Type error.

Using the wrong YANG module path, such as Cisco-IOS-XE-native:interface/GigabitEthernet0/0, will result in a 404 Not Found because the data model does not match. After a successful GET, the PATCH request must include the same URI with Content-Type: application/yang-data+json and a JSON body specifying "duplex": "full". The response should be a 204 No Content if successful.

Exam trap

Watch out for the required media type: RESTCONF uses application/yang-data+json, not generic application/json. Also, the YANG path must match the data model; for standard interface settings, use ietf-interfaces, not Cisco-IOS-XE-native. Finally, remember that a successful PATCH returns 204 No Content, not 200 OK.

Why the other options are wrong

B

The specific factual error is that RESTCONF requires the media type application/yang-data+json for YANG data, not generic application/json.

C

The specific factual error is that the duplex setting is defined in the ietf-interfaces YANG model, not in Cisco-IOS-XE-native. The URI path must match the data model.

D

The specific factual errors are: (1) The PATCH body must be structured as {"ietf-interfaces:interface":{"duplex":"full"}} to match the YANG data tree; (2) The success response for PATCH is 204 No Content, not 200 OK.

Why candidates pick the wrong answer

B

Candidates might think that application/json is acceptable because it is a common JSON media type, but RESTCONF mandates the specific yang-data+json subtype.

C

Candidates might assume that Cisco-specific modules are required for device configuration, but for standard interface settings like duplex, the IETF model is used.

D

Candidates might think that sending only the leaf is sufficient and that 200 OK is the standard success response, but RESTCONF uses 204 for successful PATCH and requires the full data path.

1008
MCQmedium

A user says the phone connected to a switch port works, but the attached PC does not get network access. What is the most likely switch-side issue?

A.The access VLAN for the PC is misconfigured
B.The voice VLAN should always match the access VLAN
C.PortFast blocks the PC from sending traffic
D.The phone requires the switch to be in trunk mode
AnswerA

In a typical IP phone topology, the phone passes PC traffic toward the switch as untagged frames, relying on the port's access VLAN assignment. If the PC's access VLAN is incorrect or doesn't match the intended data subnet, the PC receives no valid IP connectivity even though the phone registers. The voice VLAN only affects the phone's tagged voice traffic; it does not fix PC data VLAN misconfiguration.

Why this answer

An IP phone can use a voice VLAN while the attached PC uses the access VLAN. If the access VLAN is missing or wrong, the phone may still work while the PC fails.

Exam trap

Ensure you understand the difference between voice and access VLANs and how they affect different devices on the same port.

Why the other options are wrong

B

The voice VLAN and access VLAN are typically different; matching them would defeat the purpose of separating voice and data traffic, and it would not cause the PC to lose network access.

D

In the described scenario, the phone works but the PC does not, indicating a VLAN mismatch for the PC's access VLAN, not a trunk mode issue. Trunk mode is not required for a phone; instead, the switch port typically uses a voice VLAN and an access VLAN, with the phone tagging voice traffic and passing PC traffic untagged.

When would these options actually be correct?

B

In a scenario where a switch port is configured with a single VLAN for both voice and data (e.g., a small office without separate voice VLAN), the voice VLAN should match the access VLAN to ensure the phone and PC can communicate on the same network.

D

If the question stated that the phone is not working at all and the switch port is connected to an IP phone that requires multiple VLANs (e.g., voice and data), then the switch port might need to be in trunk mode to carry both tagged and untagged traffic. For example, a scenario where the phone fails to get an IP address and the PC also has no connectivity could indicate a trunk misconfiguration.

Why candidates pick the wrong answer

B

Candidates may confuse the concept of VLAN matching with simplicity, thinking that using the same VLAN for voice and data avoids misconfiguration issues.

D

Candidates may confuse the need for trunking between switches with the requirement for a switch-to-phone connection, not realizing that most IP phones use a special voice VLAN configuration (access port with voice VLAN) rather than a full trunk.

1009
MCQhard

A host uses subnet mask 255.255.255.224. How many total addresses exist in each subnet block?

A.16
B.32
C.30
D.64
AnswerB

The subnet mask 255.255.255.224 has 27 network bits, denoted as /27. The total number of addresses in a subnet is calculated as 2^(32-27) = 2^5 = 32. This total includes both the network address and the broadcast address, so the full address block size is 32 addresses.

Why this answer

The subnet mask 255.255.255.224 (/27) has 5 host bits, so each subnet has 2^5 = 32 total addresses. Option A (16) results from confusing /27 with /28 (4 host bits = 16). Option D (64) results from confusing /27 with /26 (6 host bits = 64).

Option C (30) is the number of usable host addresses (32 - 2 = 30), not the total addresses asked for in the question.

Exam trap

Be careful to distinguish between total addresses and usable addresses. Many candidates automatically think of usable addresses when subnetting.

Why the other options are wrong

A

16 would be the total addresses for a /28 mask (4 host bits), not the /27 mask specified.

C

30 is the number of usable host addresses (total addresses minus network and broadcast), not the total addresses.

D

64 would be the total addresses for a /26 mask (6 host bits), not the /27 mask specified.

When would these options actually be correct?

A

If the question specified a subnet mask of 255.255.255.240 instead, which corresponds to 28 subnet bits, then the total number of addresses would be 16. This would make option A the correct answer in that context.

C

If the question asked for the number of usable addresses in a subnet with a mask of 255.255.255.224, option C would be correct, as there are 30 usable addresses after accounting for the network and broadcast addresses.

D

In a different question, if the subnet mask were 255.255.255.192, which allows for 64 addresses per subnet, option D would be correct. The question would need to specify that subnet mask to align with this answer.

Why candidates pick the wrong answer

A

Candidates may choose this option due to confusion between the number of usable addresses and total addresses, mistakenly recalling that 16 is a common subnet size for smaller networks.

C

Candidates may choose this option due to confusion between total addresses and usable addresses, leading them to mistakenly calculate the usable addresses instead of the total available in the subnet.

D

Candidates may choose this option due to confusion between the number of usable addresses and total addresses, or they might mistakenly associate larger subnet masks with larger address counts without proper calculation.

1010
Drag & Dropmedium

Drag and drop the following steps into the correct order to describe the router's routing table lookup process from receiving a packet with a destination IP address to making the forwarding decision, including best-path selection criteria.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The process starts with packet arrival, then longest prefix match, followed by tie-breaking using administrative distance and metric, culminating in forwarding.

Exam trap

Do not confuse the order of longest prefix match and administrative distance. Longest prefix match is always performed first; administrative distance and metric are tie-breakers applied only when multiple routes match the same prefix length.

Why candidates pick the wrong answer

B

Candidates might think that administrative distance is considered first because it is a primary selection criterion, but the longest prefix match is always evaluated first.

C

Candidates might think that once a longest prefix match is found, the router immediately forwards, forgetting that multiple routes may exist requiring tie-breaking.

D

Candidates might confuse the order of operations, thinking that tie-breaking happens first because it is a key concept, but the routing table lookup always starts with longest prefix match.

1011
Multi-Selectmedium

Which TWO statements correctly describe differences between 802.11ac (Wi-Fi 5) and 802.11ax (Wi-Fi 6)?

Select 2 answers
A.802.11ac uses OFDMA, while 802.11ax uses only OFDM.
B.802.11ax supports 1024-QAM modulation, whereas 802.11ac supports up to 256-QAM.
C.Both 802.11ac and 802.11ax operate exclusively in the 5 GHz band.
D.802.11ax operates in both the 2.4 GHz and 5 GHz bands, while 802.11ac operates only in the 5 GHz band.
E.802.11ac introduces target wake time (TWT) for improved power saving, but 802.11ax does not support it.
AnswersB, D

802.11ax increases the maximum modulation order to 1024-QAM, encoding 10 bits per subcarrier symbol, whereas 802.11ac caps at 256-QAM, encoding 8 bits per symbol. This yields a raw data rate increase of roughly 25% at equivalent channel width and coding rate, but only when signal-to-noise ratio is sufficient to support the denser constellation without excessive bit errors.

Why this answer

Options B and D are correct. 802.11ax (Wi-Fi 6) introduces 1024-QAM for higher data rates (B), while 802.11ac maxes at 256-QAM. Additionally, 802.11ax supports both 2.4 GHz and 5 GHz bands, whereas 802.11ac is limited to 5 GHz only (D). Option A is incorrect because it reverses the roles: 802.11ac uses OFDM, and 802.11ax uses OFDMA.

Option C is incorrect because 802.11ax also operates in 2.4 GHz. Option E is incorrect because Target Wake Time (TWT) is introduced in 802.11ax, not 802.11ac.

Exam trap

Cisco often tests the misconception that 802.11ac also uses OFDMA or that both standards operate in the same frequency bands, so candidates must remember that OFDMA is exclusive to 802.11ax and that 802.11ac is 5 GHz only.

Why the other options are wrong

A

This statement reverses the technologies: 802.11ac uses OFDM, and 802.11ax uses OFDMA.

C

802.11ax adds 2.4 GHz support for backward compatibility and better range.

E

TWT is a feature of 802.11ax, not 802.11ac.

1012
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure a WPA3 SSID on a Cisco WLC and complete a wireless client association.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The steps follow the standard WLC configuration sequence: create the WLAN, set WPA3-Personal security, enable it, then the client associates and gets an IP.

Exam trap

The trap is that candidates may think security can be configured after enabling the WLAN, or that client IP assignment occurs before association. Remember: always configure all settings before enabling the WLAN, and client DHCP occurs after association.

Why candidates pick the wrong answer

B

Candidates might think enabling is a separate step that can be done at any time, but the WLAN must be created first.

C

Candidates might think security can be changed after enabling, but best practice is to configure all settings before enabling.

D

Candidates might confuse the order of client operations, thinking DHCP happens before association, but association is required first.

1013
Multi-Selectmedium

Which TWO statements correctly describe the behavior of standard ACLs when applied to an interface?

Select 2 answers
A.Standard ACLs filter traffic based on source and destination IP addresses.
B.Standard ACLs should be placed as close to the destination as possible.
C.Standard ACLs can filter traffic based on protocol type (TCP, UDP, ICMP).
D.Standard ACLs use an implicit deny any statement at the end.
E.Standard ACLs are applied to interfaces in the inbound direction only.
AnswersB, D

Because standard ACLs only match the source IP address, applying them near the source can inadvertently drop traffic intended for other destinations. To minimize this risk, standard ACLs should be placed as close to the destination as possible, where the source address's reach is limited and the filter's impact is scoped. This placement reduces collateral damage to legitimate traffic that should only be filtered near the target network.

Why this answer

Standard ACLs filter traffic based solely on the source IP address, not the destination. Because they do not consider destination addresses, placing them as close to the destination as possible prevents them from inadvertently blocking traffic that should reach other parts of the network. This placement ensures that only the intended traffic is filtered at the final hop before the destination.

Exam trap

Cisco often tests the misconception that standard ACLs can filter on destination addresses or protocols, leading candidates to choose option A or C, when in fact standard ACLs only match source IP addresses and always end with an implicit deny any.

Why the other options are wrong

A

This describes the capability of extended ACLs, not standard ACLs.

C

Protocol filtering is a feature of extended ACLs, not standard ACLs.

E

Both inbound and outbound application are possible, though placement depends on the filtering strategy.

1014
MCQeasy

Which data format is commonly used with REST APIs to represent objects, arrays, and key-value pairs?

A.JSON
B.STP
C.EIGRP
D.802.1Q
AnswerA

JSON (JavaScript Object Notation) is a lightweight, text-based data-interchange format that organizes data into key-value pairs and arrays. It is language-agnostic, human-readable, and natively parseable by virtually every programming language, making it the de facto standard for representing resources in REST API request and response bodies, typically transmitted over HTTP with the Content-Type: application/json header.

Why this answer

JSON is a common data-interchange format used in APIs and automation systems.

Exam trap

Avoid assuming older technologies like XML are still the most common choice for modern REST APIs.

Why the other options are wrong

B

STP (Spanning Tree Protocol) is a network protocol used for preventing loops in Ethernet networks, and it is not a data format used with REST APIs. Therefore, it does not represent objects, arrays, or key-value pairs.

C

EIGRP (Enhanced Interior Gateway Routing Protocol) is a routing protocol used for exchanging routing information within an autonomous system, not a data format for representing objects or key-value pairs in APIs.

D

802.1Q is a networking standard used for VLAN tagging in Ethernet frames, not a data format for representing objects or key-value pairs in APIs. It does not relate to REST API data representation.

When would these options actually be correct?

B

If the exam question asked about protocols used for data transmission in network environments, particularly in relation to Ethernet networks, STP could be the correct answer. For example, a question could ask about protocols that manage network topology to prevent loops.

C

If the question were about identifying protocols used in network communication, particularly those that manage routing information, EIGRP would be the correct answer when asking about dynamic routing protocols in a network setup.

D

If the question asked about network protocols or standards related to VLANs and their role in data transmission, then 802.1Q would be the correct answer as it defines how to tag Ethernet frames for VLAN identification.

Why candidates pick the wrong answer

B

Candidates may confuse STP with data formats due to its acronym and association with network technologies, leading them to mistakenly think it relates to data representation in APIs.

C

Candidates may confuse EIGRP with data handling concepts due to its technical nature and familiarity in networking, leading them to mistakenly associate it with data formats used in API communication.

D

Candidates may confuse 802.1Q with data transmission concepts in networking, leading them to mistakenly associate it with data formats used in APIs, due to its relevance in network communication.

1015
MCQmedium

A network operations team wants to use a controller's API to automatically back up device configurations daily. The API provides a GET endpoint that returns the running configuration as JSON. Which consideration is most important when designing the automation to ensure reliable backups?

A.The script should disable SSL verification to speed up the backup process.
B.The script must store the API token in the URL to simplify authentication.
C.The script should use the POST method to retrieve the configuration for better performance.
D.The script must handle pagination and rate limiting to avoid incomplete or failed requests.
AnswerD

APIs often enforce pagination and rate limits. If the script ignores these, it may receive only a partial configuration or be throttled, leading to failed or incomplete backups. Implementing pagination handling and respecting rate limits ensures the full configuration is retrieved reliably. This is a critical design consideration for production automation.

Why this answer

Reliable API-driven backups require handling pagination and rate limiting, because APIs may return partial data or throttle excessive requests. Using GET is correct for retrieval, while POST is not. Storing tokens in URLs and disabling SSL verification are insecure practices that do not improve reliability.

The key is to design for complete, uninterrupted data retrieval.

Exam trap

The trap here is focusing on authentication or transport security while overlooking that APIs often paginate and rate-limit responses, which directly affects backup completeness.

1016
MCQhard

A technician is troubleshooting an issue where internal hosts can successfully ping internet addresses but cannot establish HTTP sessions. The router is configured with PAT (overload) and uses an access list to define the inside local addresses. Recently, the internal network was renumbered from 192.168.0.0/24 to 10.0.0.0/24. What is the most likely cause?

A.The router's HTTP inspection rule is blocking outbound TCP port 80.
B.The NAT access list still permits 192.168.0.0/24 and does not match the new 10.0.0.0/24 addresses.
C.The outside interface access list is blocking TCP packets from the new 10.0.0.0/24 subnet.
D.The default route has been changed to point to the wrong next-hop address, causing only HTTP packets to be dropped.
AnswerB

Because the ACL that defines inside local addresses for PAT was never updated after renumbering, no dynamic translations are created for HTTP sourced from 10.0.0.0/24.

Why this answer

The NAT access list (used with 'ip nat inside source list') still references the old 192.168.0.0/24 subnet. After renumbering to 10.0.0.0/24, the access list does not match the new inside local addresses, so PAT (overload) translation is not performed for those hosts. ICMP (ping) can still succeed if the router has a route to the internet and the packets are not translated, but HTTP sessions fail because the return traffic cannot be mapped back to the internal hosts without a NAT translation entry.

Exam trap

Cisco often tests the misconception that ping success implies full connectivity; the trap here is that ICMP can work without NAT translation if the router has a route, but TCP sessions require proper NAT entries for return traffic.

Why the other options are wrong

A

Candidates may confuse security inspection with NAT translation, assuming that a protocol‑specific inspection is needed for HTTP.

C

Tempting because an ACL could selectively block TCP; however, the question provides context about the renumbering, which directly points to the NAT configuration.

D

Candidates may assume that different protocols might take different paths, but a single default route applies uniformly to all IP traffic.

1017
MCQhard

A switch has a root port and an alternate port for the same VLAN. Which statement best explains the operational role of the alternate port?

A.It is a backup path toward the root bridge and normally does not forward while the active root path is healthy.
B.It always forwards traffic at the same time as the root port for load balancing.
C.It is the port that elects the root bridge for the VLAN.
D.It is a special routed port used for inter-VLAN communication.
AnswerA

In Rapid PVST+ or classic STP, an alternate port receives a superior BPDU from another switch on the same segment, providing a redundant path to the root. It remains in discarding/blocking state while the root port is healthy, and only transitions to forwarding if the root port fails, ensuring a loop-free topology while preserving redundancy.

Why this answer

The alternate port acts as a backup path toward the root bridge and stays in a non-forwarding state under normal conditions. In practical terms, STP keeps it ready in case the active path fails, but it does not allow it to forward frames while the primary root path is healthy. That is how STP preserves redundancy without creating loops.

This question is useful because many learners understand root ports and designated ports but do not clearly understand what the alternate role represents.

Exam trap

Don't confuse STP's redundancy roles with load balancing or congestion management. Remember, alternate ports are for backup, not active traffic routing.

Why the other options are wrong

B

Option B is incorrect because an alternate port does not forward traffic while the root port is active; it serves as a backup path and only becomes active if the root port fails.

C

This option is wrong because the alternate port does not participate in the election process for the root bridge; it only serves as a backup path to the root bridge once it is established.

D

Option D is incorrect because an alternate port is not a routed port; it operates at Layer 2 and is part of the Spanning Tree Protocol, which does not involve routing functionalities for inter-VLAN communication.

When would these options actually be correct?

B

If the question were to ask about a network configuration that uses multiple paths for load balancing and specifies that both the root port and alternate port can forward traffic simultaneously, then option B would be correct.

C

If the question asked about the role of a port in the Spanning Tree Protocol (STP) during the election process, specifically focusing on how ports contribute to determining the root bridge, then this option would be correct.

D

If the question were to ask about the function of a routed port in a Layer 3 switch that facilitates inter-VLAN communication, then option D would be correct. In that scenario, the routed port would be responsible for forwarding traffic between different VLANs.

Why candidates pick the wrong answer

B

Candidates might choose this option due to a misunderstanding of spanning tree protocols, confusing the roles of root and alternate ports with load balancing concepts commonly used in other networking scenarios.

C

Candidates may choose this option due to a misunderstanding of STP roles, confusing the functions of port types and the process of root bridge election, leading them to think that alternate ports have a role in that election.

D

Candidates may find this option tempting due to a misunderstanding of port types in VLAN configurations, conflating Layer 2 switching concepts with Layer 3 routing functionalities, leading to confusion about their roles.

1018
MCQmedium

A network engineer is configuring a new Cisco switch that will carry traffic for multiple VLANs between two buildings. The link between the two switches must transport frames for VLAN 10, 20, and 30, and both switches must be able to identify which VLAN each frame belongs to. Which configuration should be applied to the inter-switch link on both switches?

A.Configure the ports as trunk ports using 802.1Q encapsulation.
B.Configure the ports as trunk ports using ISL encapsulation.
C.Configure the ports as routed ports with IP addresses in each VLAN subnet.
D.Configure the ports as access ports and assign them to VLAN 10.
AnswerA

A trunk port using 802.1Q encapsulation inserts a VLAN tag into each frame so the receiving switch can identify which VLAN the frame belongs to. This allows a single physical link to carry traffic for VLAN 10, 20, and 30 simultaneously. 802.1Q is the standard trunking encapsulation on Cisco switches and is required for multi-VLAN links between switches.

Why this answer

The inter-switch link must carry frames for multiple VLANs while preserving VLAN identity, which is exactly what an 802.1Q trunk does. Access ports serve only one VLAN, ISL is a legacy nonstandard encapsulation, and routed ports operate at Layer 3 and cannot transport VLAN-tagged frames. Configuring 802.1Q trunking on both ends ensures frames for VLAN 10, 20, and 30 are tagged and correctly identified by the receiving switch.

Exam trap

The trap here is assuming that any trunk encapsulation works, when only the standards-based 802.1Q option is appropriate on modern Cisco switches.

1019
MCQhard

An IPv6 host has a global unicast address and a correct default route learned from a router advertisement, but the next-hop entry shown on the host uses a link-local address rather than a global unicast address. What is the best explanation?

A.IPv6 hosts commonly use the router’s link-local address as the next hop on the local segment.
B.The host has learned the wrong default route because IPv6 gateways must always be global unicast.
C.The host can reach only local destinations when the next hop is link-local.
D.The router advertisement has failed because it did not provide a MAC address.
AnswerA

In IPv6, routers send Router Advertisements (RAs) on the local link with their link-local address as the source and as the advertised next-hop address. Hosts install a default route (::/0) pointing to that link-local address, which is reachable on the same link. This is standard operation; global unicast addresses are not required—or even preferred—for next-hop determination.

Why this answer

That behavior is normal in IPv6. In practical terms, the host only needs to reach the router on the local segment, so it uses the router’s link-local address as the next-hop target. The packet still leaves the local link toward remote destinations, but the immediate neighbor on that link is identified by link-local addressing.

This is an important IPv6 concept because many people assume the default gateway must be a globally routable address. It does not. On the local link, the host is really forwarding to its directly attached router interface, and the router’s link-local address is enough for that local handoff.

Exam trap

Don't assume that a default gateway must be a global unicast address in IPv6; link-local addresses are used for local communication.

Why the other options are wrong

B

This option is incorrect because IPv6 gateways do not have to be global unicast; link-local addresses are valid for routing within the local network segment. The host can use the link-local address of the router as the next hop for packets destined to other networks.

C

This option is incorrect because a host with a link-local next hop can still reach global unicast addresses, as link-local addresses are used only for communication within the same local network segment.

D

This option is wrong because a router advertisement does not need to provide a MAC address for the next-hop link-local address to be valid; link-local addresses are inherently usable for local communication without MAC address specification.

When would these options actually be correct?

B

In a scenario where a question states that an IPv6 host is configured to only communicate with other devices on the same local link and does not require global connectivity, the statement that 'IPv6 gateways must always be global unicast' could be correct. This would imply a misunderstanding of link-local addressing in a strictly local context.

C

In a scenario where a question specifies that the host is configured to communicate only within a local network and does not have a global unicast address, stating that a link-local next hop limits communication to local destinations would be accurate.

D

In a question where the context specifies that router advertisements are expected to include MAC addresses for proper routing functionality, option D could be correct if the absence of a MAC address leads to a failure in establishing a valid next-hop address.

Why candidates pick the wrong answer

B

Candidates may find this option tempting due to a common misconception that global unicast addresses are necessary for all routing scenarios, leading them to overlook the valid use of link-local addresses in local network communications.

C

Candidates may choose this option due to a misunderstanding of link-local addresses, believing they inherently restrict communication to local destinations without considering the broader context of IPv6 routing capabilities.

D

Candidates might choose this option due to a misunderstanding of the role of MAC addresses in IPv6 routing, mistakenly believing that a lack of MAC address information invalidates link-local addresses in router advertisements.

1020
MCQhard

Based on the exhibit, why is the ACL not meeting the requirement to block only HTTPS traffic to the server?

A.Because the ACL entry is too broad and blocks all IP traffic to the host.
B.Because HTTPS uses UDP, not TCP.
C.Because standard ACLs are required for HTTPS filtering.
D.Because the destination must always be a wildcarded subnet, not a host.
AnswerA

The ACL entry uses the keyword 'ip', which matches every IP protocol including TCP, UDP, ICMP, and GRE. To block only HTTPS, the administrator must specify 'tcp' and match destination port 443, as in 'deny tcp any host 192.0.2.10 eq 443'. Because 'deny ip' is all-encompassing, it prevents all traffic to the host, not just HTTPS, which is why the ACL fails the requirement.

Why this answer

The ACL fails because it uses 'deny ip' which blocks all IP traffic to the server, not just HTTPS. To block only HTTPS, the ACL should match TCP port 443 with 'deny tcp eq 443'. Option B is wrong because HTTPS uses TCP, not UDP.

Option C is wrong because extended ACLs (not standard) are required to filter by port. Option D is wrong because a host destination is perfectly valid in extended ACLs; a wildcard subnet is not required.

Exam trap

Ensure you understand the difference between blocking specific ports and blocking all traffic. Misconfiguring an ACL by using 'deny ip' instead of 'deny tcp eq 443' is a common mistake.

Why the other options are wrong

B

HTTPS uses TCP, not UDP.

C

Standard ACLs cannot filter by port; extended ACLs are required.

D

Extended ACLs support host destinations; a wildcard subnet is not required for a specific host.

When would these options actually be correct?

B

In a different question scenario where the focus is on protocols and their transport layers, if the question asked about blocking traffic for a protocol that indeed uses UDP, such as QUIC (which is used for HTTP/3), then this option could be correct.

C

In a different exam scenario where the question states that only standard ACLs can be used for filtering traffic types, and the focus is on the limitations of standard ACLs in filtering specific protocols, this option could be correct. For example, if the question specified that only standard ACLs are allowed for traffic filtering, it would imply that advanced filtering for HTTPS is not possible.

D

In a different exam scenario where the question specifically states that only wildcarded subnets can be used for ACL entries, option D would be correct. For instance, if the question asked about a requirement to block traffic to a range of IP addresses rather than a single host, this option would apply.

Why candidates pick the wrong answer

B

Candidates may be misled by the association of HTTPS with secure communication and mistakenly recall that it could use UDP, leading them to select this option without fully understanding the transport layer details.

C

Candidates might choose this option due to a misunderstanding of the transport layer protocols, confusing HTTPS with other protocols that do use UDP, such as DNS or certain streaming services.

D

Candidates might choose this option due to a misunderstanding of ACL configurations, believing that specific destination types (wildcarded subnets) are universally required for all types of traffic filtering, including HTTPS.

1021
Multi-Selectmedium

Which statement correctly describes a feature of WPA3 security in wireless LANs?

Select 1 answer
A.WPA3 uses TKIP encryption for backward compatibility with legacy devices.
B.WPA3 introduces Simultaneous Authentication of Equals (SAE) to resist offline dictionary attacks.
C.WPA3 relies solely on 802.1X/EAP authentication for both personal and enterprise modes.
D.WPA3 mandates the use of GCMP-256 encryption for enhanced security.
E.WPA3 makes Protected Management Frames (PMF) optional to support older clients.
AnswersB

WPA3 replaces the pre-shared key (PSK) four-way handshake with the Simultaneous Authentication of Equals (SAE) protocol, also known as Dragonfly. SAE uses a secure password-authenticated key exchange that provides forward secrecy and prevents an attacker from capturing the handshake and performing offline dictionary or brute-force attacks. Even if the password is weak, each guess requires interaction with the network, greatly increasing the difficulty of compromise.

Why this answer

WPA3 introduces Simultaneous Authentication of Equals (SAE), which uses a Dragonfly key exchange to resist offline dictionary attacks and provide forward secrecy. Option A is wrong because WPA3 does not use or support TKIP encryption; it mandates AES. Option C is wrong because WPA3-Personal uses SAE, not 802.1X/EAP.

Option D is wrong because GCMP-256 is only mandatory in the optional WPA3-Enterprise 192-bit security mode, not across all WPA3 deployments; standard WPA3-Personal uses AES-GCMP with 128-bit keys. Option E is wrong because WPA3 requires Protected Management Frames (PMF) by default, unlike WPA2.

Exam trap

Many candidates incorrectly assume WPA3 universally uses GCMP-256 encryption, confusing the optional enterprise mode with the baseline WPA3-Personal requirement.

Why the other options are wrong

A

WPA3 mandates AES encryption and does not include TKIP for any compatibility; TKIP was deprecated in WPA2.

C

WPA3-Personal uses SAE, not 802.1X/EAP; only WPA3-Enterprise relies on 802.1X.

D

GCMP-256 is only mandated in the optional WPA3-Enterprise 192-bit mode; standard WPA3 uses GCMP with 128-bit keys.

E

Protected Management Frames (PMF) are required, not optional, in WPA3 to mitigate management frame attacks.

When would these options actually be correct?

D

When configuring WPA3 on APs and clients, GCMP-256 is required for full compliance.

1022
MCQhard

A router shows the following routing table entries for the same destination: O 10.10.50.0/24 [110/20] via 192.168.12.2, GigabitEthernet0/0 D 10.10.50.0/24 [90/30720] via 192.168.13.2, GigabitEthernet0/1 Which route will become the active route in the routing table?

A.The OSPF route, because its metric is lower
B.The EIGRP route, because its administrative distance is lower
C.Both routes, because the prefixes are identical
D.Neither route, because the metrics use different scales
AnswerB

EIGRP is selected because Cisco routers use administrative distance (AD) as the primary trust metric when multiple routing protocols propose the same prefix. The default AD for EIGRP internal routes is 90, while OSPF's default AD is 110; the lower AD wins, so the EIGRP route is installed in the routing table. The metric values from different protocols are never compared against each other—the router first chooses the protocol with the best AD, and only then uses that protocol's metric for path selection. Therefore, even though OSPF may report a numerically smaller cost, EIGRP's lower AD takes precedence.

Why this answer

The EIGRP route becomes active because the router compares administrative distance first when the same destination is learned from different routing protocols. This is one of the most common Cisco exam traps: candidates compare the OSPF metric value of 20 to the EIGRP metric value and assume the smaller number must win. That is not how route selection works across different protocols.

OSPF metrics and EIGRP metrics are calculated differently, so the router does not compare them directly. Instead it checks administrative distance. EIGRP internal routes default to 90, while OSPF routes default to 110.

Since 90 is lower than 110, the EIGRP route is trusted more and is installed as the active path.

Exam trap

Avoid comparing metric values directly between different protocols; focus on administrative distance first.

Why the other options are wrong

A

This option is incorrect because the active route is determined by the administrative distance, not the metric. In this case, the EIGRP route has a lower administrative distance than the OSPF route, making it the active route.

C

This option is incorrect because only one route can be active for a given destination in a routing table, and having identical prefixes does not mean both routes can be active simultaneously. The router will select the route with the lower administrative distance, which is not addressed here.

D

This option is wrong because both routes are valid, and the router will select the route with the lower administrative distance, not the metric. The administrative distance of the EIGRP route is lower than that of the OSPF route, making it the active route.

When would these options actually be correct?

A

In a different scenario where both routes have the same administrative distance, but the OSPF route has a lower metric than the EIGRP route, the question could ask which route would be preferred based on metric alone. In that case, the OSPF route would indeed be the correct answer.

C

In a different question where the routing table entries for the same destination were configured to allow for equal-cost multi-path (ECMP) routing, both routes could be active. For example, if the question specified that the routing protocol supports ECMP, then this option would be correct.

D

This option would be correct in a scenario where the question specifies that the metrics of the routing protocols are not comparable, such as when using different protocols that do not interact or when metrics are based on different criteria. For example, if the question stated that both routes were from different routing protocols with incompatible metrics, then neither would be selected.

Why candidates pick the wrong answer

A

Candidates may be tempted by this option due to a common misconception that lower metrics always take precedence, leading them to overlook the importance of administrative distance in route selection.

C

Candidates may find this option tempting because they might recall that multiple routes can exist for the same destination, leading to confusion about the conditions under which they can be simultaneously active.

D

Candidates may find this option tempting because they might confuse the concept of metrics with administrative distance, thinking that different metrics automatically disqualify routes from being active.

1023
MCQhard

A trunk between two switches is up, but users in VLAN 40 cannot communicate across it. The output shows both sides allow VLAN 40. What is another likely trunk-related cause to check next?

A.Native VLAN mismatch between the two trunk ends
B.Missing router ID in OSPF
C.Incorrect NTP source interface
D.Lack of PAT overload on the WAN router
AnswerA

A native VLAN mismatch on an 802.1Q trunk means each switch expects a different VLAN ID for untagged frames. If VLAN 40 is the native VLAN on one side but not the other, frames sent untagged from one switch are received and categorized into the wrong VLAN or dropped, breaking connectivity for that VLAN. This is a classic trunk misconfiguration to verify after confirming the allowed VLAN list includes VLAN 40 on both ends. Cisco best practice is to set the native VLAN to an unused VLAN or ensure it matches exactly on both trunk peers.

Why this answer

If VLAN 40 is allowed on both ends and the trunk is up, a native VLAN mismatch is still worth checking because trunk problems are not limited to the allowed VLAN list. In plain language, the link may be carrying traffic, but if the two switches disagree on how untagged traffic should be treated, behavior can still become unpredictable. Native VLAN mismatches are a well-known source of warnings and unexpected traffic handling on 802.1Q trunks.

That does not mean every VLAN problem is caused by the native VLAN, but once the obvious allowed-list issue has been ruled out, it becomes a logical next trunk-specific item to verify.

Exam trap

Don't assume that allowed VLANs are the only trunk-related issue; native VLAN mismatches can also disrupt communication.

Why the other options are wrong

B

This option is wrong because the question specifically addresses VLAN communication issues over a trunk link, which are unrelated to OSPF router ID configuration. OSPF router ID affects routing protocols, not VLAN traffic directly.

C

NTP source interface is unrelated to VLAN communication issues over a trunk link; it primarily affects time synchronization across devices. Since the question focuses on VLAN connectivity, this option does not address the core problem.

D

Lack of PAT overload on the WAN router is unrelated to VLAN communication issues between switches. This option pertains to address translation for outbound traffic, not VLAN trunking problems.

When would these options actually be correct?

B

In a different scenario, if the question were about OSPF routing issues where the router ID is not set, candidates might be asked to troubleshoot OSPF adjacency problems. In that case, a missing router ID would prevent OSPF neighbors from forming, making this option correct.

C

In a scenario where the question involves troubleshooting time-sensitive applications that rely on accurate timestamps for logging or coordination, a missing or incorrectly configured NTP source interface could lead to discrepancies in time, causing issues in those applications.

D

In a question focused on NAT configurations, if the scenario involves multiple internal networks needing to share a single public IP address, the lack of PAT overload on the WAN router would be a valid concern affecting outbound connectivity.

Why candidates pick the wrong answer

B

Candidates might choose this option due to a misunderstanding of how routing protocols interact with VLANs, mistakenly believing that OSPF configuration could impact VLAN communication across a trunk link.

C

Candidates might confuse the importance of time synchronization in network operations with VLAN functionality, leading them to mistakenly believe that NTP configuration could impact VLAN communication.

D

Candidates may confuse general connectivity issues with NAT configurations, thinking that any routing or address translation problem could impact VLAN communication, leading them to select this option.

1024
PBQhard

You are connected to a multilayer switch MLS1. The network has two other switches SW1 and SW2 forming a triangle topology. Currently, SW1 is the root bridge but it should be SW2. Additionally, configure PortFast and BPDU Guard on interface GigabitEthernet0/2 of MLS1, which connects to a host. Simulate a BPDU violation on that port and then recover the port from err-disabled state.

Network Topology
Gi0/0Gi0/0Gi0/1Gi0/1Gi0/2Gi0/2Gi0/2SiMLS1SW1SW2Host

Hints

  • •Check which switch is currently root and change the priority on MLS1 to allow SW2 to become root.
  • •The err-disabled port needs to be re-enabled with 'no shutdown' after the cause is removed.
  • •Ensure PortFast and BPDU Guard are configured on the edge port.
A.On MLS1, remove 'spanning-tree vlan 1 root primary' and set priority to 4096; on SW2, set priority to 0. On MLS1 Gi0/2, configure 'spanning-tree portfast' and 'spanning-tree bpduguard enable'. After BPDU violation, recover with 'shutdown' then 'no shutdown'.
B.On MLS1, set priority to 0 to make it root; on SW2, set priority to 4096. On MLS1 Gi0/2, configure 'spanning-tree portfast' and 'spanning-tree bpduguard enable'. After BPDU violation, recover by removing BPDU Guard.
C.On MLS1, remove 'spanning-tree vlan 1 root primary' and set priority to 4096; on SW2, set priority to 0. On MLS1 Gi0/2, configure 'spanning-tree portfast' and 'spanning-tree bpduguard enable'. After BPDU violation, recover by reloading MLS1.
D.On MLS1, set priority to 0; on SW2, set priority to 4096. On MLS1 Gi0/2, configure 'spanning-tree portfast' and 'spanning-tree bpduguard enable'. After BPDU violation, recover with 'no shutdown'.
AnswerA
solution
! MLS1
configure terminal
no spanning-tree vlan 1 root primary
spanning-tree vlan 1 priority 4096
interface gigabitEthernet 0/2
no shutdown

Why this answer

Currently, SW1 is the root bridge per the topology, but the goal is to make SW2 the root. On MLS1, removing the 'spanning-tree vlan 1 root primary' command and setting a higher priority (4096) ensures it does not interfere. On SW2, set priority to 0 to make it root.

On MLS1 Gi0/2, configure PortFast and BPDU Guard. If a BPDU is received, the port goes err-disabled; to recover, issue 'shutdown' then 'no shutdown' after resolving the BPDU source.

Exam trap

Trap: Candidates may forget that the root bridge is determined by lowest priority. They might set the wrong switch to lower priority or use incorrect recovery methods like reloading or removing BPDU Guard.

Why the other options are wrong

B

The specific factual error: Setting MLS1 priority to 0 makes it root, opposite of the requirement. Removing BPDU Guard does not recover the port; 'no shutdown' is needed.

C

The specific factual error: Reloading the switch is not the standard recovery for an err-disabled port; 'no shutdown' is the proper command.

D

The specific factual error: MLS1 should have a higher priority (e.g., 4096) and SW2 a lower priority (e.g., 0) to make SW2 root. The option does the opposite.

Why candidates pick the wrong answer

B

Candidates might think setting a lower priority always makes a switch root, but they overlook the requirement that SW2 should be root. They may also confuse recovery methods.

C

Candidates might think that a reload clears all errors, but it is overkill and not the recommended practice. They may not know the 'no shutdown' recovery.

D

Candidates may confuse which switch should have the lower priority. They might think the current root should keep a low priority, but the requirement is to change the root to SW2.

1025
PBQhard

You are connected to R1. The link between R1 and R2 is experiencing packet loss and slow performance. Examine the following partial show interface output: R1# show interfaces gigabitEthernet 0/0 GigabitEthernet0/0 is up, line protocol is up Duplex: Full, Speed: Auto, 100Mb/s Input errors: 12345, CRC: 5000, frame: 0, overrun: 0, ignored: 0 R2# show interfaces gigabitEthernet 0/0 GigabitEthernet0/0 is up, line protocol is up Duplex: Half, Speed: Auto, 100Mb/s Input errors: 0, CRC: 0, collisions: 5000, late collisions: 0 Identify the root cause of the issue, and apply the necessary fix on R1 to resolve the problem.

Network Topology
G0/010.0.0.1/30G0/010.0.0.2/30linkR1R2

Hints

  • •Look at the number of input errors versus CRC errors.
  • •Check the duplex setting on both interfaces.
  • •A high number of input errors without CRC often indicates a duplex mismatch.
A.Configure the interface with 'duplex half' to match the half-duplex setting on R2.
B.Configure the interface with 'speed 100' to force the link speed to 100 Mbps.
C.Replace the Ethernet cable with a new one to fix the physical layer issue.
D.Configure the interface with 'no shutdown' to bring the interface up.
AnswerA
solution
! R1
interface gigabitethernet0/0
duplex half

Why this answer

The output reveals a duplex mismatch. R1 is operating in full‑duplex mode, while R2 is in half‑duplex mode. On the full‑duplex side (R1), simultaneous transmissions from both ends result in corrupted frames, visible as a high count of CRC errors.

On the half‑duplex side (R2), ordinary collisions occur because R2 uses CSMA/CD, but no CRC errors are seen because it detects collisions and retransmits. The only immediate fix from R1—since R2 is fixed at half‑duplex—is to change R1's interface to half‑duplex using the command 'duplex half', which matches the settings and stops the corrupted frames. (Long‑term, both sides should ideally be set to full‑duplex, but that requires access to R2.)

Exam trap

A common mistake is to misinterpret the presence of CRC errors on R1 as indicating a cable fault. In a duplex mismatch, the full-duplex side (R1) experiences collisions that manifest as CRC errors (since it does not use CSMA/CD), while the half-duplex side (R2) shows collisions but no CRC errors. Therefore, high CRC errors on one side with no CRC errors but many collisions on the other side is a classic sign of a duplex mismatch, not a physical layer issue.

Why the other options are wrong

B

The specific factual error is that speed mismatch does not cause the high input error count without CRC errors; duplex mismatch does.

C

The specific factual error is that cable issues produce CRC errors, not just input errors; the absence of CRC errors rules out cable problems.

D

The specific factual error is that 'no shutdown' is used to enable an interface that is administratively down; here the interface is up and passing traffic.

Why candidates pick the wrong answer

B

Candidates might think that packet loss is due to speed mismatch, especially if they see 'speed' in the output, but the error pattern points to duplex.

C

Candidates often jump to cable replacement when they see errors, but the specific error type (input errors without CRC) points to duplex mismatch.

D

Candidates might think the interface is down due to errors, but the output shows it is up; they may confuse error counters with interface state.

1026
PBQhard

You are connected to R1. Configure IPv4 and IPv6 addressing on R1's interfaces so that R1 can reach R2's loopback0 (192.0.2.1/32) and R2's IPv6 loopback0 (2001:db8:1::1/64). R1 has a misconfigured subnet mask on G0/0 and is missing its default gateway. Additionally, R1 has a duplicate IPv4 address on G0/1 that must be corrected. Use EUI-64 for R1's IPv6 link-local address on G0/0 and static IPv6 for the global unicast address on G0/1.

Network Topology
G0/010.0.0.1/30G0/010.0.0.2/30linkR1R2

Hints

  • •Check the subnet mask on G0/0 — it should match the link between R1 and R2.
  • •R1 needs a default route to reach networks beyond R2.
  • •G0/1's IP address conflicts with R2's G0/1 — use a different subnet.
A.Change G0/0 mask to /30, add default route via 10.0.0.2, change G0/1 IP to 192.0.2.2/30, enable IPv6 on G0/0 with EUI-64 link-local, assign 2001:db8:2::1/64 to G0/1
B.Change G0/0 mask to /24, add default route via 10.0.0.1, change G0/1 IP to 10.0.0.6/30, enable IPv6 on G0/0 with EUI-64 link-local, assign 2001:db8:1::1/64 to G0/1
C.Change G0/0 mask to /30, add default route via 10.0.0.1, change G0/1 IP to 192.0.2.2/30, enable IPv6 on G0/0 with EUI-64 link-local, assign 2001:db8:2::1/64 to G0/1
D.Change G0/0 mask to /30, add default route via 10.0.0.2, change G0/1 IP to 10.0.0.6/30, enable IPv6 on G0/0 with EUI-64 link-local, assign 2001:db8:2::1/64 to G0/1
AnswerA
solution
! R1
interface gigabitethernet0/0
ip address 10.0.0.1 255.255.255.252
ipv6 enable
ipv6 address fe80::/64 eui-64
exit
interface gigabitethernet0/1
ip address 192.0.2.2 255.255.255.252
ipv6 address 2001:db8:2::1/64
exit
ip route 0.0.0.0 0.0.0.0 10.0.0.2

Why this answer

Ly fixes the subnet mask on G0/0 to /30, adds the default gateway via 10.0.0.2, resolves the duplicate IP on G0/1 by assigning 192.0.2.2/30, and sets up IPv6 addressing as required (EUI-64 on G0/0 and static 2001:db8:2::1/64 on G0/1). However, for full IPv6 reachability to R2's loopback0 (2001:db8:1::1/64), R1 also needs an IPv6 route (e.g., a static route to 2001:db8:1::/64 via R2's link-local or global address on G0/1). Without this, Option A only ensures IPv4 connectivity but not IPv6.

Among the given options, A is the best because it addresses all IPv4 issues and the IPv6 addressing requirements, though it is incomplete for IPv6 routing.

Exam trap

Watch out for common mistakes: using the wrong subnet mask (e.g., /24 instead of /30), pointing the default gateway to the wrong next-hop (e.g., 10.0.0.1 instead of 10.0.0.2), and failing to resolve duplicate IPs by moving to a different subnet. Also, ensure IPv6 addresses are unique and not conflicting with other devices.

Why the other options are wrong

B

The subnet mask on G0/0 must match the connected network (/30), not /24. The default gateway should point to the neighbor's IP (10.0.0.2). The new G0/1 IP must be in a different subnet to avoid duplication.

The IPv6 global unicast address on G0/1 must be unique and not conflict with R2's loopback.

C

The default gateway must be the IP address of the directly connected neighbor (R2's G0/0), which is 10.0.0.2, not 10.0.0.1.

D

The IP address 10.0.0.6/30 is in the same subnet as R2's G0/1 (10.0.0.5/30), so it does not resolve the duplicate address conflict. A different subnet must be used.

Why candidates pick the wrong answer

B

Candidates might think /24 is a common mask and that 10.0.0.1 is a typical gateway. They may also mistakenly believe that 10.0.0.6/30 is different from 10.0.0.5/30, not realizing they are in the same subnet. Using 2001:db8:1::1/64 might seem like a valid global unicast address but it duplicates R2's loopback.

C

Candidates often assume the default gateway is the first usable IP in the subnet (10.0.0.1) without verifying the actual neighbor's IP. They may also confuse the router's own IP with the gateway.

D

Candidates might think that 10.0.0.6 is different from 10.0.0.5 and therefore not a duplicate, but they overlook that both are in the same /30 subnet. They may also assume that using a different host ID within the same subnet is sufficient.

1027
Multi-Selecthard

A static default route is configured on R1 toward ISP-A, and a second default route toward ISP-B is configured with a higher administrative distance. Which two statements are correct during normal operation and after ISP-A failure?

Select 2 answers
A.The route through ISP-A is preferred during normal operation
B.The route through ISP-B acts as a floating backup
C.Both defaults are always installed and used equally
D.The backup route is ignored permanently because only one default route can exist
AnswersA, B

During normal operation, the static default route toward ISP-A is installed in the routing table because it has the default administrative distance of 1 for a static route. Cisco routers select the route with the lowest AD for a given prefix, so the ISP-A default outranks the ISP-B route, which is configured with a higher AD (typically 200). Consequently, all unmatched traffic is forwarded via ISP-A under steady-state conditions.

Why this answer

This is a classic floating static design. The lower-AD default route is primary, and the higher-AD default waits in reserve.

Exam trap

A frequent exam trap is assuming that both default routes are simultaneously active and load-balanced, or that the backup route is permanently ignored because only one default route can exist. The trap lies in misunderstanding administrative distance behavior: the higher AD route is not used until the primary route fails. Misreading this can lead to incorrect answers claiming equal usage or permanent backup route exclusion.

Remember, Cisco routers always prefer the route with the lowest administrative distance and only switch to the floating static route when the primary path is lost.

Why the other options are wrong

C

This option is incorrect because Cisco routers do not install multiple default routes with different administrative distances simultaneously; only the route with the lowest AD is installed and used.

D

This option is incorrect because the backup route is not ignored permanently; it becomes active when the primary default route toward ISP-A fails, ensuring continuous connectivity.

When would these options actually be correct?

C

If both default routes had the same administrative distance and ECMP (equal-cost multipath) was enabled, both would be installed and traffic load-balanced equally.

D

If the question stated that both default routes have the same administrative distance and metric, and the router uses only one default route (e.g., due to hardware limitations or a specific IOS version), then only one would be installed and used.

Why candidates pick the wrong answer

C

Candidates may think that multiple default routes can coexist and be used simultaneously without considering administrative distance or routing table behavior.

D

Candidates may mistakenly believe that only one default route can exist in the routing table, confusing the concept of a single default gateway in a host with multiple default routes in a router.

1028
Drag & Dropmedium

Drag and drop the following steps into the correct order to plan, configure, and apply an extended ACL that permits only HTTP traffic from the 192.168.1.0/24 network to the server at 10.0.0.100, and then verify the configuration.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First, enter config mode. Then create the ACL allowing HTTP from the source network to the destination host. Apply it inbound on the appropriate interface.

Save and verify the configuration.

Exam trap

Remember that ACLs are created in global configuration mode, not interface mode. Also, apply ACLs inbound on the interface closest to the source for efficiency. Pay attention to whether the requirement is to permit or deny traffic.

Why candidates pick the wrong answer

B

Candidates may think outbound application is equivalent, but it wastes router resources by processing unwanted traffic through the router.

C

Candidates might confuse the creation step with the application step, thinking both happen in interface mode.

D

Candidates may misread the requirement or think deny is needed to block other traffic, but the ACL must explicitly permit the desired traffic.

1029
MCQmedium

Why is DHCP often preferred over manual addressing on larger user networks?

A.It automates host IP configuration and reduces manual effort and mistakes.
B.It replaces DNS completely.
C.It removes the need for default gateways.
D.It is required by all routing protocols.
AnswerA

DHCP automates host IP configuration by centrally assigning addresses, subnet masks, default gateways, and DNS information, which eliminates tedious manual entry on each device. On larger networks, this reduces administrative overhead and the risk of human error, such as typos or duplicate addressing, while also making IP address management more consistent and easier to track.

Why this answer

DHCP is often preferred because it automates host configuration and reduces both manual work and configuration mistakes. In practical terms, it is far easier to let endpoints receive addresses, masks, gateways, and DNS settings automatically than to configure each device by hand.

This improves scale, consistency, and operational efficiency. That is why DHCP is such a common service in enterprise access networks.

Exam trap

A common exam trap is selecting options that confuse DHCP with DNS or routing protocols. Some candidates mistakenly believe DHCP replaces DNS or removes the need for default gateways. However, DHCP only automates IP configuration; it does not perform name resolution like DNS, nor does it eliminate the requirement for a default gateway.

Another trap is assuming routing protocols depend on DHCP, which is incorrect because routing protocols operate independently of IP address assignment methods. Understanding these distinctions is essential to avoid incorrect answers related to IP services in the CCNA exam.

Why the other options are wrong

B

This option is incorrect because DHCP does not replace DNS. DNS is a separate service responsible for name resolution, while DHCP only provides IP configuration parameters including DNS server addresses.

C

This option is wrong because DHCP does not remove the need for default gateways. Hosts still require gateway information to communicate outside their subnet, and DHCP typically provides this information during configuration.

D

This option is incorrect because routing protocols do not depend on DHCP. Routing protocols function independently of IP address assignment methods and do not require DHCP to operate on user networks.

When would these options actually be correct?

B

In a question that asks about the relationship between DHCP and DNS, where it specifically states that DHCP can provide DNS server information to clients, option B could be correct if it implies that DHCP can fulfill some DNS-related functions in certain contexts.

C

In a question focused on network configurations where the context is a specific type of network that does not require inter-network communication, such as a closed-loop system, this option could be correct if it states that devices within that system do not need a default gateway.

D

In a question asking which services are mandatory for specific routing protocols to operate effectively, if the question specified that DHCP is necessary for dynamic IP address assignment in a particular routing protocol scenario, then this option could be correct.

Why candidates pick the wrong answer

B

Candidates may choose this option due to a misunderstanding of how DHCP and DNS interact, mistakenly believing that DHCP's role in IP configuration implies it can also handle name resolution tasks, leading to confusion about their distinct functions.

C

Candidates may choose this option due to a misunderstanding of DHCP's role in network configuration, mistakenly believing that DHCP's automation extends to eliminating the need for default gateways entirely.

D

Candidates may choose this option due to a misunderstanding of network services, conflating the roles of DHCP and routing protocols, leading them to believe that DHCP is essential for routing functionality.

1030
MCQhard

Exhibit: Users on SW2 in VLAN 30 can reach local devices but not hosts in VLAN 30 on SW1. What is the most likely reason?

A.The trunk native VLAN is 1 on both sides
B.VLAN 30 is not allowed on the trunk
C.SW2 must run VTP server mode
D.Spanning tree blocks all user VLANs by default
AnswerB

Inter-switch traffic for a VLAN requires that VLAN to be present in the trunk's allowed list on both ends. When VLAN 30 is omitted or 'pruned' from that list, frames are discarded at the trunk port, so SW2's local clients can communicate within their broadcast domain but cannot reach devices beyond the switch. The command 'show interfaces trunk' would reveal that VLAN 30 is not in the allowed VLAN list, confirming the filter is the cause.

Why this answer

The trunk is allowing only VLANs 10 and 20. Even though both switches have VLAN 30 defined locally, VLAN 30 traffic cannot cross the trunk unless that VLAN is allowed on the link. Option A is incorrect because the native VLAN (default 1) does not affect tagged VLAN 30 traffic, and native VLAN mismatch causes different issues.

Option C is incorrect because VTP is used for VLAN database synchronization, not for forwarding traffic over a trunk; switches do not need to be VTP servers to pass VLAN traffic. Option D is incorrect because spanning tree only blocks redundant paths to prevent loops, not all user VLANs by default.

Exam trap

Ensure you verify trunk configurations when VLAN traffic is not passing between switches, even if VLANs are correctly configured locally.

Why the other options are wrong

A

This option is incorrect because the native VLAN being set to 1 does not prevent VLAN 30 traffic from being transmitted across the trunk link. The issue lies in VLAN 30 not being allowed on the trunk, which is not addressed by the native VLAN setting.

C

This option is incorrect because VTP server mode is not required for VLANs to communicate across switches; VLAN configuration can be done independently on each switch. The issue in the question is related to trunking and VLAN allowance, not VTP mode.

D

Spanning Tree Protocol (STP) does not block all user VLANs by default; it only blocks specific ports to prevent loops. In this case, the issue is related to VLAN 30 not being allowed on the trunk, not STP blocking the VLAN.

When would these options actually be correct?

A

In a scenario where the question specifies that a trunk link is misconfigured with a native VLAN that is not set to match on both ends, leading to VLAN traffic being dropped, this option could be correct. For example, if the question states that VLAN 30 is configured but traffic is not passing due to mismatched native VLAN settings, this would be the right answer.

C

In a scenario where a question asks about the necessity of VTP server mode for VLAN propagation across multiple switches, and it specifies that VLANs must be synchronized across the network, this option would be correct. For example, if the question states that SW1 and SW2 are part of a larger VTP domain and VLAN configurations must be consistent across all switches.

D

In a different scenario where a question states that all VLANs are configured correctly but a specific VLAN is being blocked due to STP configuration issues, option D would be correct. For example, if a question describes a network with multiple VLANs and asks why users cannot communicate due to STP settings, option D would apply.

Why candidates pick the wrong answer

A

Candidates may choose this option due to a common misconception that native VLAN configurations directly affect all VLAN traffic, leading them to overlook the specific trunk configuration details that are crucial in this scenario.

C

Candidates may choose this option due to a misunderstanding of VTP's role in VLAN management and a belief that VTP server mode is essential for VLAN communication, leading them to overlook the actual trunking issue presented in the question.

D

Candidates may choose this option due to a general understanding of STP and its role in preventing loops, mistakenly believing that it applies to all VLANs without considering the specific context of VLAN configuration and trunk settings.

1031
MCQhard

A network administrator has several access points. All APs except one have successfully joined the wireless controller. The administrator verifies the failing AP’s IP address, subnet mask, and controller IP address are correctly configured. What is the most likely reason the AP cannot join the controller?

A.The AP has an incorrect default gateway for its subnet.
B.CAPWAP can be used only if the AP has no IP address.
C.The AP must use PPP instead of Ethernet to reach the controller.
D.The controller can support only 14 APs maximum.
AnswerA

If the AP's default gateway is incorrect, the access point cannot route CAPWAP packets off its local subnet to reach a controller on a different IP subnet. CAPWAP discovery and join responses from the controller would never arrive, even though the AP's own IP address and controller discovery mechanism (such as DNS or broadcast) are correctly set. The result is the AP stuck in an unjoined/disabled state, exactly as shown.

Why this answer

The most likely cause is that the AP has an incorrect default gateway. For the AP to reach the controller (which may be on a different subnet), it needs a correct default gateway to route traffic. The other APs joined successfully, eliminating a controller-wide issue.

Option B is incorrect because CAPWAP requires an IP address; it does not work without one. Option C is incorrect because CAPWAP uses IP/UDP, not PPP. Option D is unlikely because there is no indication that the controller is at its AP limit; the problem affects only one AP, suggesting an individual misconfiguration.

Exam trap

Avoid assuming global issues when only one AP is affected; focus on individual AP configuration and connectivity.

Why the other options are wrong

B

CAPWAP tunnels require the AP to have an IP address; the statement is false.

C

CAPWAP operates over IP using UDP ports, not PPP.

D

The controller may have an AP capacity limit, but with only one AP failing and no evidence that the limit is 14, this is not the strongest explanation.

When would these options actually be correct?

B

In a different scenario where the question states that an AP is configured without an IP address and is attempting to connect to a controller, this option would be correct. The question could specify that the AP is in a factory default state with no IP configuration.

C

In a different exam scenario where the question specifies that the AP is configured to use PPP (Point-to-Point Protocol) for its connection, and the controller only supports Ethernet connections, this option would be correct as it would explain the failure to join the controller.

D

In a different scenario, if a question stated that a wireless controller can only support a maximum of 14 APs and asked why an additional AP could not join, then this option would be correct as it directly addresses the limitation of the controller's capacity.

Why candidates pick the wrong answer

B

Candidates may find this option tempting because they might confuse the requirements for CAPWAP with other protocols that can operate without an IP address, leading to a misunderstanding of the AP's connectivity requirements.

C

Candidates may find this option tempting due to a misunderstanding of CAPWAP protocols and their requirements, leading them to incorrectly associate IP address assignment with connectivity issues.

D

Candidates may find this option tempting because they might recall limitations on device connections in networking, leading them to assume that capacity issues could affect AP connectivity without considering other factors.

1032
Multi-Selectmedium

Which TWO statements correctly describe the configuration and verification of AAA with RADIUS/TACACS+ and 802.1X port-based authentication on IOS-XE?

Select 2 answers
A.The switch port must be configured as an access port and the command 'authentication port-control auto' must be applied.
B.AAA authentication for 802.1X must be configured using TACACS+ as the protocol of choice.
C.The global command 'aaa new-model' is sufficient to enable 802.1X on all interfaces.
D.RADIUS is the recommended protocol for 802.1X authentication because it supports EAP and is widely used in network access control.
E.802.1X can be configured on a trunk port to authenticate multiple VLANs simultaneously.
AnswersA, D

802.1X operates only on Layer 2 access ports because it authenticates a single connected host before any traffic is forwarded. The interface must be an access port, and 'authentication port-control auto' is required so the port begins in the unauthorized state, forcing the supplicant to complete EAP/RADIUS authentication before the port becomes authorized. Without 'auto', the port would default to the authorized state and bypass authentication.

Why this answer

802.1X requires the switch port to be an access port (not trunk or dynamic) and the 'authentication port-control auto' command enables EAPoL-based authentication. Option D is correct because RADIUS is the recommended protocol for 802.1X; it natively supports EAP extensions and is widely used for network access control, whereas TACACS+ does not support EAP and is more suited for device administration. Option B is false because AAA authentication for 802.1X should use RADIUS, not TACACS+.

Option C is false because 'aaa new-model' only activates the AAA framework; 802.1X requires additional global commands like 'dot1x system-auth-control' and per-interface configuration. Option E is false because 802.1X is typically configured on access ports and cannot be used on trunk ports to authenticate multiple VLANs; the port must be in access mode.

Exam trap

Cisco often tests the misconception that 'aaa new-model' alone enables all AAA features, including 802.1X, when in fact it only activates the AAA framework and separate interface-level commands are required.

Why the other options are wrong

B

TACACS+ encrypts only the password and is designed for device administration, not for 802.1X authentication which requires EAP support—RADIUS is the correct choice.

C

The global command 'aaa new-model' enables the AAA architecture but does not automatically enable 802.1X on interfaces; additional commands like 'dot1x system-auth-control' and per-interface 'authentication port-control auto' are needed.

E

802.1X requires the switch port to be in access mode, not trunk mode; trunk ports do not support 802.1X because multiple VLANs would conflict with the authentication process.

1033
MCQhard

A network engineer is troubleshooting a Cisco IOS router that should forward DHCP requests from a LAN segment to a centralized DHCP server at 10.1.1.10. The router's LAN interface is GigabitEthernet0/1 with IP address 192.168.20.1/24. The engineer enters the command ip helper-address 10.1.1.10 on interface GigabitEthernet0/1. However, clients on the LAN are not receiving IP addresses. Which condition would cause the DHCP relay to fail?

A.The DHCP server is on a different subnet than the LAN interface, so relay is not possible.
B.The router's LAN interface is configured with the ip helper-address command but the global configuration is missing the service dhcp command.
C.An access list applied to the LAN interface is blocking inbound UDP port 67 traffic from the DHCP clients.
D.The router does not have a route to reach the DHCP server at 10.1.1.10, so it cannot forward the relayed packets.
AnswerD

For the router to relay DHCP requests, it must have a route to the DHCP server's IP address. If no route exists, the router cannot forward the unicast packets, and clients will not receive leases. This is a common and definitive cause of relay failure. The scenario implies connectivity may be missing, and this condition directly prevents the relay from working.

Why this answer

DHCP relay requires the router to have a route to the DHCP server so it can unicast the client's request. Without a route, the relayed packets are dropped, and clients receive no address. While other conditions like ACLs or disabled service dhcp could interfere, the absence of a route is a fundamental and sufficient cause for relay failure in this scenario.

Exam trap

The trap here is assuming that because the DHCP server is on a different subnet, relay cannot work, when in fact relay is designed for that exact situation and the real issue is often routing.

1034
Multi-Selectmedium

Which three of the following are valid features of Enhanced Interior Gateway Routing Protocol (EIGRP)? (Choose three.)

Select 3 answers
.EIGRP maintains a topology table containing all routes learned from neighbors.
.EIGRP uses the Diffusing Update Algorithm (DUAL) to ensure loop-free paths.
.EIGRP supports unequal-cost load balancing using the 'variance' command.
.EIGRP is a link-state routing protocol similar to OSPF.
.EIGRP uses multicast address 224.0.0.5 for all neighbor communications.
.EIGRP automatically summarizes routes at classful boundaries by default on all interfaces.

Why this answer

All three statements are correct features of EIGRP. EIGRP maintains a topology table that stores all routes learned from directly connected neighbors, including feasible successors. It uses the Diffusing Update Algorithm (DUAL) to guarantee loop-free paths by performing a diffusing computation when a route is lost.

Additionally, EIGRP supports unequal-cost load balancing by using the 'variance' command, which allows traffic to be distributed across multiple paths with different metrics, as long as the metric of the alternate path is within the variance multiplier times the best metric.

Exam trap

Cisco often tests the distinction between EIGRP's topology table (which stores all learned routes) and its routing table (which stores only the best routes), and candidates may confuse the 'variance' command with equal-cost load balancing only, forgetting that it enables unequal-cost load balancing.

1035
MCQhard

Refer to the exhibit. A network engineer notices that a user connected to GigabitEthernet0/5 cannot access the network. The engineer issues the show port-security interface GigabitEthernet0/5 command. Based on the output, what is the most likely cause of the issue?

A.The interface is administratively shut down.
B.An unauthorized device with a different MAC address was connected, triggering a port-security violation and placing the port in an error-disabled state.
C.The sticky MAC address feature is disabled, allowing any MAC address to cause a violation.
D.The maximum number of secure MAC addresses has been exceeded, causing the port to err-disable.
AnswerB

The output shows 'Port Status: Secure-shutdown' after a violation, a violation count of 3, and the 'Last Source Address' (aaaa.bbbb.cccc) differing from the sticky MAC. This confirms an unauthorized MAC triggered the violation and shut down the port.

Why this answer

The output of 'show port-security interface GigabitEthernet0/5' would show a port status of 'err-disabled' and a security violation count greater than zero. This occurs because an unauthorized device with a different MAC address connected to the port, triggering a port-security violation (typically a security violation action of 'shutdown'), which places the interface in an error-disabled state. This matches the scenario where the user cannot access the network.

Exam trap

Cisco often tests the distinction between the violation action 'shutdown' (which err-disables the port) and 'restrict' or 'protect' (which do not err-disable), and candidates may confuse exceeding the maximum MAC addresses with the specific trigger of a different MAC address being seen after the maximum is already learned.

Why the other options are wrong

A

A common misconception is that any down state is an admin shutdown, but Cisco IOS distinguishes 'Secure-shutdown' for port-security errdisable from 'administratively down'.

C

Some candidates misread the output and assume sticky is off, but the presence of a sticky MAC count proves it is active.

D

It is tempting to assume any violation with maximum 1 is due to exceeding the limit, but in this case the secure MAC is the original sticky address, and the violation is from a different unauthorized MAC, which still respects the limit count but fails the authorization check.

1036
Multi-Selectmedium

An engineer is comparing data serialization formats used by controllers and automation tools. Which two statements correctly describe JSON?

Select 2 answers
A.It represents data as key-value pairs and arrays
B.It is commonly used in REST API payloads
C.It requires closing tags like XML
D.It can only represent numeric values
AnswersA, B

JSON represents structured data as an unordered collection of key-value pairs inside an object, where keys are double-quoted strings and values can be any valid JSON type. It also supports arrays as ordered lists of values, which map directly to lists in programming languages. This means JSON can describe both records and collections of records, making it a foundational format for data interchange.

Why this answer

JSON structures data using key-value pairs (objects) and ordered lists (arrays), which are fundamental to its syntax. Option B is correct as JSON is the standard payload format for REST API requests and responses due to its lightweight nature and ease of parsing. Option C is incorrect because JSON does not use closing tags; instead, it relies on curly braces {} for objects and square brackets [] for arrays.

Option D is incorrect because JSON supports multiple data types beyond numeric values, including strings, booleans, null, arrays, and nested objects.

Exam trap

A frequent exam trap is assuming JSON requires closing tags similar to XML, which is incorrect. JSON uses braces and brackets to define objects and arrays without paired tags, so confusing these formats can lead to wrong answers. Another common mistake is believing JSON only supports numeric values, ignoring that it also supports strings, booleans, null, arrays, and nested objects.

Misunderstanding these details can cause candidates to incorrectly reject JSON as a serialization format in automation scenarios, especially when comparing it to XML or other data formats.

Why the other options are wrong

C

Option C is incorrect because JSON does not require closing tags like XML; it uses braces and brackets to delimit data structures, making this statement false.

D

Option D is incorrect as JSON supports a variety of data types beyond numeric values, including strings, booleans, arrays, objects, and null, so it is not limited to numbers.

When would these options actually be correct?

C

If the question asked 'Which statement correctly describes XML?', then 'It requires closing tags like XML' would be correct, as XML elements must have both opening and closing tags.

D

In a question about a data serialization format that only supports numeric values (e.g., a custom binary format or a specific use case like Protocol Buffers with only numeric fields), this option would be correct.

Why candidates pick the wrong answer

C

Candidates familiar with XML may incorrectly assume JSON also uses closing tags because both are data serialization formats, leading to confusion between their syntax rules.

D

Candidates may confuse JSON with simpler formats or mistakenly think JSON is limited to numbers due to its use in numeric-heavy contexts like configuration files.

1037
PBQhard

You are connected to R1, a router that must establish OSPFv3 adjacency with R2 over the directly connected link G0/0. The current configuration is incomplete: OSPFv3 process is configured but not enabled on the interface, and global IPv6 unicast routing is missing. Configure R1 so that it becomes an OSPFv3 neighbor with R2 and learns the loopback route 2001:db8:1:2::/64 via OSPFv3. Then verify neighbor state and routing table.

Network Topology
G0/02001:db8:0:1::1/64G0/02001:db8:0:1::2/64linkR1R2

Hints

  • •OSPFv3 requires IPv6 unicast routing to be enabled globally before it can operate.
  • •OSPFv3 is enabled on an interface using the 'ipv6 ospf <process-id> area <area-id>' command.
  • •Without the interface-level command, the router will not send hellos and will not form an adjacency.
A.Enable IPv6 unicast routing globally and activate OSPFv3 on GigabitEthernet0/0 with the command 'ipv6 ospf 1 area 0'.
B.Enable IPv6 unicast routing globally and configure OSPFv3 process 1 with the 'network' command under the OSPFv3 router configuration mode.
C.Enable IPv6 unicast routing globally and configure OSPFv3 process 1 with the 'router-id' command to ensure adjacency.
D.Enable IPv6 unicast routing globally and configure OSPFv3 process 1 with the 'passive-interface default' command to allow adjacency.
AnswerA
solution
! R1
ipv6 unicast-routing
interface GigabitEthernet0/0
ipv6 ospf 1 area 0

Why this answer

R1 is missing two critical configurations: global IPv6 unicast routing must be enabled with 'ipv6 unicast-routing', and OSPFv3 must be activated on GigabitEthernet0/0 using 'ipv6 ospf 1 area 0' under the interface. Without these, R1 cannot send or receive OSPFv3 hellos, so no adjacency forms and routes are not exchanged. After applying both commands, the neighbor state becomes FULL and the remote loopback appears in the IPv6 routing table.

Exam trap

The exam trap is that OSPFv3 configuration differs from OSPFv2: OSPFv3 does not use network statements under the router process; instead, it is enabled directly on the interface. Additionally, IPv6 unicast routing must be globally enabled before OSPFv3 can function. Candidates often forget one of these two steps.

Why the other options are wrong

B

The specific factual error is that OSPFv3 uses interface-level configuration, not network statements under the OSPF process.

C

The specific factual error is that setting a router ID alone does not activate OSPFv3 on an interface; OSPFv3 must be explicitly enabled on the interface.

D

The specific factual error is that 'passive-interface default' would actually prevent adjacency, not help form it.

Why candidates pick the wrong answer

B

Candidates familiar with OSPFv2 might mistakenly apply the same 'network' command logic to OSPFv3, not realizing the difference in configuration method.

C

Candidates may think that configuring a router ID is the key missing step, especially if they see OSPFv3 process running but no neighbor forming, but they overlook the interface activation.

D

Candidates might confuse 'passive-interface' with enabling OSPF on an interface, or think that making an interface passive is necessary for OSPF to work, but the opposite is true for adjacency formation.

1038
Multi-Selecthard

Exhibit: An OSPFv2 adjacency between two routers on Ethernet is not forming. Which two mismatches would directly prevent the routers from becoming neighbors?

Select 2 answers
A.Different OSPF area assignments on the interfaces
B.Authentication mismatch between the interfaces
C.Different hostnames on the routers
D.Different loopback addresses used for management
E.One router using SSH version 2
AnswersA, B

When two routers on the same Ethernet segment have different OSPF area assignments, the area ID embedded in each Hello packet differs. A router receiving a Hello with a mismatched area ID discards the packet, preventing the neighbor relationship from even reaching the 2-Way state. Thus, area numbers must match exactly on the shared link for OSPFv2 adjacency to form.

Why this answer

On an OSPFv2 network, area mismatch and authentication mismatch both directly prevent adjacency formation. Mismatched timers (such as hello or dead intervals) also block adjacency on all network types, including Ethernet. In this scenario, the correct choices are area mismatch (A) and authentication mismatch (B).

Exam trap

A common exam trap is selecting options like different hostnames or loopback addresses as causes for OSPF adjacency failure. Candidates may mistakenly believe that router identification parameters affect neighbor formation. However, OSPF adjacency strictly depends on protocol parameters such as area ID and authentication.

Hostnames and loopback interfaces are used for management or router ID purposes but do not block adjacency. Misunderstanding this can lead to incorrect troubleshooting steps or exam answers, wasting valuable time and causing confusion.

Why the other options are wrong

C

Different hostnames do not affect OSPF adjacency since hostnames are used only for identification and management, not neighbor formation.

D

Different loopback addresses used for management do not influence OSPF adjacency on Ethernet interfaces, so they do not block neighbor relationships.

E

One router using SSH version 2 is unrelated to OSPF adjacency because SSH is a management protocol and does not impact routing protocol neighbor formation.

When would these options actually be correct?

C

In a question about EIGRP neighbor formation over Frame Relay, mismatched hostnames could prevent adjacency if the hostname is used in the EIGRP authentication process (e.g., MD5 authentication with key-chain).

D

In a question about OSPF router ID selection, if two routers have the same router ID (e.g., due to identical loopback addresses), they would not form an adjacency. The correct answer would be that identical router IDs prevent neighbor formation.

E

In a question about why SSH access to a router fails between two devices, mismatched SSH versions (e.g., one using SSHv1 and the other SSHv2) would prevent secure connection.

Why candidates pick the wrong answer

C

Candidates may confuse hostname with router ID or think that OSPF uses hostnames for neighbor verification, leading them to incorrectly select this option.

D

Candidates may confuse loopback addresses with OSPF router IDs, thinking mismatched loopbacks cause issues, or they may overgeneralize that any IP mismatch prevents OSPF adjacency.

E

Candidates may confuse security protocols used for device management with routing protocol authentication, thinking any mismatch in security settings blocks OSPF adjacency.

1039
MCQhard

Refer to the exhibit. A network administrator is troubleshooting an OSPF adjacency on R1's GigabitEthernet0/0 interface connected directly to R2. R2 is powered on and shows correct OSPF configuration, but the adjacency is stuck in the INIT or DOWN state. Based on the output, what is the most likely cause of the failure?

A.The OSPF network type on R1's GigabitEthernet0/0 does not match the network type on R2.
B.The OSPF hello and dead timers on R1 do not match those configured on R2.
C.The GigabitEthernet0/0 interface on R1 has been assigned to a different OSPF area than R2's connected interface.
D.The OSPF passive-interface command has been applied to GigabitEthernet0/0, preventing hello packets from being sent.
AnswerD

The line 'No Hellos (Passive interface)' in the output is the direct and definitive indication that the GigabitEthernet0/0 interface has been configured with the OSPF passive-interface command. This command prevents OSPF from sending Hello packets out of this interface, and without Hellos, R1 cannot discover R2 or form an adjacency with it. Passive-interface is a common administrative choice to stop OSPF on a LAN segment while still advertising the connected subnet, but it breaks neighbor formation entirely, which is exactly the problem described in the scenario.

Why this answer

The adjacency is stuck in INIT or DOWN state, which indicates that R1 is not receiving OSPF Hello packets from R2. The passive-interface command on GigabitEthernet0/0 prevents R1 from sending Hellos, so R2 never sees R1, and R1 may see R2's Hellos (stuck in INIT) or not (stuck in DOWN). This matches the symptom exactly, as passive-interface suppresses outgoing Hellos while still allowing the interface to be advertised.

Exam trap

Cisco often tests the passive-interface command as a subtle cause of OSPF adjacency failure, where candidates mistakenly think it only affects routing updates (like in EIGRP) rather than Hello suppression in OSPF.

Why the other options are wrong

A

Candidates may think network type mismatch when they see no adjacency, but the exhibit does not indicate a mismatch and explicitly shows the passive state.

B

Timer mismatch is a classic troubleshooting trap, but the 'No Hellos (Passive interface)' message overrides any timer considerations.

C

Candidates may guess area mismatch as a cause, but the exhibit provides no evidence of it, while the passive-interface message is a direct cause.

1040
MCQeasy

A network technician is configuring a new Cisco switch. The technician wants to connect a server that requires 802.1Q trunking to carry multiple VLANs. The server's network interface card supports VLAN tagging and is configured to use VLAN 10, 20, and 30. Which switch port mode should be configured on the switch port connected to the server?

A.Access mode
B.Dynamic auto mode
C.Dynamic desirable mode
D.Trunk mode
AnswerD

Trunk mode allows multiple VLANs to traverse the link by tagging frames with VLAN IDs. The server's NIC supports 802.1Q tagging and needs to communicate on VLANs 10, 20, and 30. Configuring the switch port as a trunk will enable this functionality.

Why this answer

Trunk mode is required to carry multiple VLANs over a single link. The server supports 802.1Q tagging, so configuring the switch port as a trunk allows VLAN 10, 20, and 30 traffic to pass. Access mode is for single VLAN, and dynamic modes rely on DTP, which the server does not support.

Exam trap

The trap here is assuming that dynamic auto or desirable modes will work with a server, but they require DTP, which servers typically do not support.

1041
Drag & Dropmedium

Drag and drop the following steps into the correct order to implement a basic network monitoring workflow using telemetry and streaming analytics on Cisco IOS-XE.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The workflow begins by collecting data via telemetry from network devices (A), then streaming that data to an analytics platform (B). After streaming, the data is monitored using dashboards (C), and finally alerts are generated for threshold violations (D).

Exam trap

Students often reverse the order of streaming and monitoring; data must be streamed before it can be visualized.

1042
MCQhard

A host has a valid IP address and subnet mask from DHCP but cannot reach remote networks because no gateway was provided. What is the best explanation?

A.The host has no next-hop gateway for traffic destined outside its local subnet.
B.The host cannot use ARP on the local network anymore.
C.The host automatically becomes part of every remote subnet.
D.The host must convert its access port into a trunk.
AnswerA

A DHCP lease supplies the host's IP address, subnet mask, and often a default gateway, but without that gateway entry the host's routing table contains no route for off-subnet destinations. When a packet's destination IP is outside the host's local subnet, the host must send it to a next-hop router; in its absence, the packet is dropped or never transmitted. The host can still communicate with neighbors on the same subnet, but it is effectively isolated from all other networks.

Why this answer

The best explanation is that the host has no next-hop path for off-subnet traffic. In plain language, the device knows what its own local network looks like, but it does not know where to send packets when the destination is outside that local range. Without a default gateway, remote communication usually fails even though local communication can still work.

This is a core host-configuration concept. The correct answer is the one focused on the absence of a next hop for remote destinations.

Exam trap

A common exam trap is assuming that a host without a default gateway cannot communicate at all. Many candidates mistakenly believe that missing a gateway disables all network communication, but in reality, the host can still communicate with devices on its local subnet using ARP. The trap lies in confusing local subnet communication with remote network access.

The question specifically tests understanding that the lack of a gateway prevents forwarding to remote networks, not local connectivity. Misreading this can lead to selecting incorrect options that focus on ARP or subnet expansion rather than the gateway role.

Why the other options are wrong

B

This option is incorrect because ARP is used for local subnet communication and does not depend on the presence of a default gateway. The host can still use ARP to communicate locally.

C

This option is wrong because a host does not automatically become part of every remote subnet without a gateway. The subnet mask defines the local subnet boundaries, and gateway absence does not change this.

D

This option is unrelated to the problem. Converting an access port to a trunk port affects VLAN tagging on switches but does not impact a host’s ability to have or use a default gateway.

When would these options actually be correct?

B

In a different scenario where a question states that a host is unable to communicate with any devices on the local network and has been misconfigured with an incorrect subnet mask, option B could be correct, as ARP requests would fail due to the host being unable to identify devices in the same subnet.

C

In a question where a host is configured with multiple subnets and routing protocols are enabled, stating that it automatically becomes part of every remote subnet could be correct if discussing a scenario involving dynamic routing or a specific network design that allows for such behavior.

D

In a scenario where a question asks about VLAN configurations and the need for a switch port to carry multiple VLANs for inter-VLAN routing, converting an access port to a trunk would be the correct answer. This would apply if the question specified that the host needs to communicate across different VLANs.

Why candidates pick the wrong answer

B

Candidates may choose this option due to a misunderstanding of ARP functionality, thinking that a lack of a gateway affects local network communication, leading to confusion about the role of ARP in local subnet communication.

C

Candidates may find this option tempting due to a misunderstanding of how subnets and routing work, mistakenly believing that a device can communicate across all networks without proper routing configurations.

D

Candidates might choose this option due to confusion between layer 2 switching and layer 3 routing concepts, mistakenly believing that port configuration changes can resolve routing issues.

1043
PBQmedium

You are connected to R1 via console. R1 is connected to three routers (R2, R3, R4) over Ethernet links, all in OSPF area 0. Due to network topology, R1 should not become the Designated Router (DR) or Backup Designated Router (BDR) on any of its interfaces. You need to configure R1's OSPF priority appropriately to ensure it never participates in DR/BDR elections.

Network Topology
G0/010.0.0.1/24G0/110.0.1.1/24G0/210.0.2.1/24R1R2R3R4

Hints

  • •The DR/BDR election is based on the highest OSPF priority, with a tiebreaker on router ID.
  • •Setting the priority to 0 on an interface means the router cannot become DR or BDR.
  • •The command is configured under the interface.
A.Set the OSPF priority to 0 on all interfaces of R1.
B.Set the OSPF priority to 255 on all interfaces of R1.
C.Set the OSPF priority to 1 on all interfaces of R1.
D.Set the OSPF priority to 0 on the loopback interface of R1.
AnswerA
solution
! R1
interface GigabitEthernet0/0
ip ospf priority 0
interface GigabitEthernet0/1
ip ospf priority 0
interface GigabitEthernet0/2
ip ospf priority 0

Why this answer

In OSPF, the router with the highest priority becomes the Designated Router (DR), and the second highest becomes the Backup Designated Router (BDR). A priority of 0 makes a router ineligible to participate in DR/BDR elections on that interface. Setting priority to 0 on all interfaces of R1 ensures it will never become DR or BDR on any segment.

Exam trap

200-301 often tests the misconception that priority 255 prevents DR election, when in fact 0 is the correct value to make a router ineligible, and that priority must be set on all relevant interfaces, not just loopback.

Why the other options are wrong

B

A priority of 255 is the highest possible value, ensuring the router becomes the DR or BDR, not excluding it.

C

Priority 1 is the default and allows the router to be elected if it has the highest priority or Router ID.

D

Loopback interfaces are not used for DR/BDR elections; they are logical interfaces. The priority must be set on the physical interfaces connecting to other routers.

Why candidates pick the wrong answer

B

Candidates may mistakenly think that a high priority prevents election, or they confuse priority with the concept of 'preference'.

C

Candidates might think that a low priority (like 1) excludes the router, but only 0 does that.

D

Candidates may think that OSPF priority is a global setting or that loopback interfaces influence elections, but they don't.

1044
MCQeasy

An ACL on R1 contains only these entries: access-list 101 permit tcp 10.10.10.0 0.0.0.255 any eq 443 access-list 101 permit icmp any any What happens to an HTTP packet sourced from 10.10.10.25 and destined for 198.51.100.10 if ACL 101 is applied in the traffic path?

A.It is permitted because the source subnet is allowed.
B.It is denied by the implicit deny.
C.It is translated by NAT before the ACL is checked.
D.It is converted to HTTPS automatically.
AnswerB

The HTTP packet, utilising TCP port 80, does not match the first ACL entry, which specifically permits TCP traffic only for destination port 443. It also fails to match the second entry, which permits ICMP traffic. As the packet does not match any explicit `permit` statement within ACL 101, it is processed by the implicit `deny ip any any` that exists at the end of every Cisco access control list. This mechanism ensures the HTTP packet is denied.

Why this answer

HTTP uses TCP port 80, not 443. Because the ACL does not include a permit for that traffic, it is dropped by the implicit deny at the end of the ACL. The ICMP entry is irrelevant because the packet is TCP.

Exam trap

Be careful not to confuse TCP with ICMP or overlook the specific port numbers in ACL entries.

Why the other options are wrong

A

This option is wrong because the ACL only permits TCP traffic on port 443 and ICMP traffic, so an HTTP packet (port 80) from the specified source would be denied by the implicit deny rule at the end of the ACL.

C

This option is wrong because NAT does not occur before ACL evaluation; the ACL is applied directly to the packet as it arrives at the interface. Therefore, the HTTP packet is evaluated against the ACL without any translation taking place.

D

This option is wrong because the ACL does not automatically convert HTTP traffic to HTTPS; it only permits or denies traffic based on the defined rules. The packet from 10.10.10.25 is not permitted by the ACL since it is not targeting port 443.

When would these options actually be correct?

A

In a different scenario where the ACL allowed all traffic from the source subnet (e.g., 'access-list 101 permit ip 10.10.10.0 0.0.0.255 any'), then an HTTP packet from 10.10.10.25 would be permitted, making this option correct.

C

In a different scenario where the question specifies that NAT is configured on the router and the ACL is applied after NAT processing, an HTTP packet could be translated to a different address before being evaluated by the ACL. In this case, the packet might be permitted or denied based on the translated address.

D

In a different scenario, if the question stated that the network device has a feature that automatically upgrades HTTP traffic to HTTPS based on specific configurations, then this option could be correct. For example, if the device was configured to enforce secure connections for all HTTP traffic, the packet could be converted to HTTPS before being processed.

Why candidates pick the wrong answer

A

Candidates may choose this option because they might misinterpret the ACL's source address as sufficient for permitting all types of traffic, overlooking the specific port restrictions.

C

Candidates may find this option tempting because they might confuse the order of operations in packet processing, thinking that NAT would modify the packet before ACL evaluation, which is a common misconception in networking.

D

Candidates may choose this option due to a common understanding that many modern networks implement security features that automatically upgrade HTTP to HTTPS, leading to confusion about the capabilities of ACLs in this context.

1045
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure a Cisco switch as a DHCP relay agent with DHCP snooping, where the DHCP server is located on a remote router.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, the DHCP server must be properly configured on the router. Next, DHCP snooping is enabled globally on the switch to protect against rogue servers. Then, the specific client VLANs must be added to the snooping database.

After that, the uplink interface to the DHCP server must be trusted to allow legitimate server responses. Finally, the ip helper-address command is placed on the client's SVI to forward DHCP broadcasts to the remote server.

1046
MCQhard

A network engineer notices that traffic from the router to server 192.168.10.5 is being sent over a slow backup link, even though the primary high-speed link is up. The routing table has an OSPF route for 192.168.10.0/24 via the primary link and a static host route to 192.168.10.5/32 via the backup link. Why is the backup link used for traffic to the server?

A.The static route has an administrative distance of 1, which is lower than OSPF's 110, so it is always preferred.
B.The router is load-balancing between the two routes, and traffic is being hashed to the backup link for this particular flow.
C.The OSPF route is not installed in the routing table because the static route has a better AD.
D.The static /32 route is a more specific match than the OSPF /24 route, so it is selected regardless of administrative distance.
AnswerD

The router selects the static /32 route because it offers the longest prefix match for destination 192.168.10.5. Even though OSPF has a higher administrative distance, prefix length is evaluated first in the forwarding decision. The /32 route exactly matches the destination, whereas the /24 route only matches the general subnet, so the more specific route is always chosen.

Why this answer

The router uses the most specific matching route in the routing table to forward traffic. The static host route to 192.168.10.5/32 has a longer prefix length (32 bits) than the OSPF route for 192.168.10.0/24 (24 bits), making it a more specific match. Even though OSPF has a higher administrative distance, the longest prefix match rule takes precedence over administrative distance when both routes are present in the routing table.

Exam trap

Cisco often tests the misconception that administrative distance is the sole factor in route selection, when in fact the longest prefix match rule is evaluated first and takes priority over AD for any routes that are already in the routing table.

Why the other options are wrong

A

Administrative distance is only compared when two routes have the same prefix length. Here, the /32 route has a longer prefix, so it is chosen first.

B

Load balancing requires routes with identical prefix lengths and metrics. The /32 and /24 routes are treated as different destinations.

C

AD is only compared when routes have the exact same prefix length. The routing table can hold multiple overlapping routes as long as they differ in prefix length.

1047
MCQhard

An OSPF-enabled router has two paths to the same destination network, and both paths have the same OSPF cost. What is the most likely default behavior?

A.Install both routes and use equal-cost multipath forwarding
B.Discard both routes because OSPF cannot handle duplicates
C.Always keep only the route learned first
D.Replace both routes with a default route
AnswerA

OSPF is a link-state protocol that computes the shortest path tree using Dijkstra's algorithm, and when two or more paths to a destination have identical metrics, it intentionally installs them all as equal-cost multipath routes. These parallel next hops are placed in the routing table, and Cisco IOS uses CEF to load-balance traffic across them, maximizing bandwidth utilization and providing fast failover if one link goes down.

Why this answer

When OSPF learns two equally good paths to the same destination, the router can install both and perform equal-cost multipath forwarding. In plain language, the router does not have to throw one away simply because there are two valid answers. If the routes are truly equal from OSPF’s perspective, it can use both paths to improve resilience and share traffic.

This is a classic routing behavior question because many candidates assume the router must always choose only one best path. In reality, equal-cost multipath is a normal feature in many routing environments. The key is that the paths must be equally good according to the protocol’s metric logic.

Exam trap

A frequent exam trap is believing that OSPF must select only one best route when multiple paths have the same cost. Many candidates mistakenly think OSPF discards duplicates or keeps only the first learned route. This misunderstanding leads to incorrect answers suggesting route discarding or default route replacement.

The trap arises because some routing protocols or older implementations do not support equal-cost multipath. However, OSPF explicitly supports installing multiple equal-cost routes to improve load balancing and fault tolerance, so assuming otherwise causes errors in exam scenarios.

Why the other options are wrong

B

Incorrect because OSPF can handle multiple equal-cost routes and does not discard them; it uses all equal-cost paths to improve traffic distribution.

C

Incorrect since OSPF does not keep only the first learned route when multiple equal-cost paths exist; it installs all such routes for load balancing.

D

Incorrect because OSPF does not replace multiple valid equal-cost routes with a default route; default routes are used only when no specific routes exist.

When would these options actually be correct?

B

In a hypothetical exam scenario where the question specifies that OSPF is configured to only allow unique routes and duplicates are filtered out, option B would be correct. For example, if the question states that 'OSPF is configured with a unique route filter,' then discarding duplicates would be the expected behavior.

C

In a different scenario where a routing protocol only allows a single route to a destination, such as a legacy protocol that does not support multipath routing, the question might ask what happens when two routes are learned, leading to the correct answer being to keep only the first learned route.

D

In a different scenario, if the question specified that OSPF was configured to use a default route for all traffic due to specific routing policies or if the network was designed to only allow a default route for redundancy, then this option could be correct.

Why candidates pick the wrong answer

B

Candidates might choose this option due to a misunderstanding of OSPF's capabilities, thinking that it cannot manage multiple paths to the same destination, leading to the assumption that duplicates must be discarded.

C

Candidates may find this option tempting due to a misunderstanding of OSPF's capabilities, mistakenly believing that it cannot handle multiple routes to the same destination, leading them to choose the option that suggests discarding duplicates.

D

Candidates might choose this option due to a misunderstanding of OSPF's behavior with multiple routes, confusing it with other routing protocols that may discard routes in favor of a default route under certain conditions.

1048
MCQhard

Refer to the exhibit. An administrator has configured PAT for internal hosts to access the internet, but users report that they cannot reach external websites. The administrator suspects a NAT issue and runs the show ip nat statistics command. What is the most likely cause of the problem?

A.The NAT overload pool is incorrectly configured with the inside interface Gi0/1 instead of the outside interface Gi0/0.
B.The access-list 1 used in the NAT statement is not matching any traffic.
C.CEF switching is disabled, causing all packets to be punted to the process level and NAT to fail.
D.The maximum number of NAT translations has been reached, causing new translations to be denied.
AnswerA

The ip nat inside source list 1 interface GigabitEthernet0/1 overload statement binds the overload pool to Gi0/1, which is an inside interface per the interface commands. Since NAT overload must use the outside interface's address as the public source address, this misconfiguration prevents any valid translation from being built. The dynamic mapping line clearly shows the wrong interface, making this the definitive root cause of the misses.

Why this answer

The show ip nat statistics output likely shows that the NAT overload pool is referencing the inside interface (Gi0/1) instead of the outside interface (Gi0/0). For PAT (overload) to work, the router must translate the source IP of internal traffic to the IP address of the outside interface (Gi0/0) that connects to the internet. If the pool incorrectly uses the inside interface IP, the translated packets will have a source address that is not routable on the external network, causing connectivity failure.

Exam trap

Cisco often tests the distinction between inside and outside interface configuration in NAT, where candidates may overlook that the overload pool must reference the outside interface (Gi0/0) rather than the inside interface (Gi0/1) for internet-bound traffic.

Why the other options are wrong

B

Candidates may focus on Hits: 0 and Misses: 15042 as typical of an ACL issue, but the explicit interface binding in the dynamic mapping is the direct evidence of misconfiguration.

C

The high CEF Punted count mirrors the misses, leading some to believe CEF is the problem, but the exhibit does not indicate CEF is disabled.

D

Candidates might assume that a high miss count reflects a full translation table, but the total active translations show 0.

1049
MCQhard

Which command output would be the best next step to verify whether the port-channel is operational after configuration changes?

A.show etherchannel summary
B.show ip ospf neighbor
C.show ip route
D.show access-lists
AnswerA

This command displays the EtherChannel bundle status, including the port-channel interface, member ports, and their state (e.g., LACP, PAgP, or static). It directly shows whether the port channel is up and which physical interfaces are bundled, making it the best next step to confirm EtherChannel operation.

Why this answer

The best next step is to check EtherChannel status directly. In practical terms, after fixing the member-link configuration, the quickest verification is to inspect the summary output that shows whether the bundle exists and whether the member ports are actively participating. That is more direct than checking unrelated switching or routing tables.

This is a simulation-style 'what do you verify next' question, which is important for realistic CCNA prep.

Exam trap

Avoid confusing general interface or trunk status with specific EtherChannel status. Always use the command that directly addresses the feature in question.

Why the other options are wrong

B

The command 'show ip ospf neighbor' is used to display OSPF neighbor relationships, which is not directly related to verifying the operational status of a port-channel. This command would not provide information about the port-channel configuration or status.

C

The command 'show ip route' is used to display the routing table of a device, which does not provide information about the operational status of a port-channel after configuration changes.

D

The command 'show access-lists' is not relevant for verifying the operational status of a port-channel; it focuses on access control lists rather than link aggregation status.

When would these options actually be correct?

B

In a different scenario where the question asks about verifying OSPF neighbor relationships after configuring OSPF on a router, 'show ip ospf neighbor' would be the correct command to check if OSPF is functioning properly and neighbors are established.

C

In a scenario where the question asks for verification of routing paths and connectivity issues, 'show ip route' would be the correct command to determine if routes are correctly established and if traffic can be forwarded through the configured interfaces.

D

In a different exam scenario where the question asks about troubleshooting traffic filtering or security policies, 'show access-lists' would be the correct command to verify which traffic is permitted or denied based on configured access lists.

Why candidates pick the wrong answer

B

Candidates may choose this option because they associate OSPF with network connectivity and assume that verifying OSPF neighbors could indirectly indicate the status of the port-channel, especially if they are not fully aware of the specific commands for EtherChannel verification.

C

Candidates might choose this option because they associate port-channel functionality with routing, thinking that verifying the routing table could indirectly confirm connectivity through the port-channel.

D

Candidates may choose this option because they associate access lists with traffic management and might mistakenly believe that verifying access lists is part of checking overall link functionality.

1050
MCQmedium

An API call returns HTTP status code 401. What does that usually mean?

A.The resource was moved permanently
B.The request was successful but no content was returned
C.Authentication is required or the credentials are invalid
D.The server cannot parse JSON
AnswerC

HTTP 401 Unauthorized is specifically the status code that signals a failure to authenticate: either no credentials were supplied in the request, or the provided credentials (e.g., API key, token, username/password) were invalid or expired. The server sends a 401 to force the client to re-authenticate with valid credentials before the requested API resource can be accessed. It is not a permission-denied error like 403, but strictly an authentication error.

Why this answer

A 401 response means the request lacks valid authentication credentials. The token may be missing, expired, or invalid.

Exam trap

A frequent exam trap is confusing the 401 Unauthorized status code with other HTTP errors such as 403 Forbidden or 400 Bad Request. Candidates might incorrectly assume a 401 means the server cannot parse the request or that the resource was moved, which are actually indicated by 400 and 301 status codes respectively. This misunderstanding leads to incorrect troubleshooting steps in automation scenarios.

Remember, 401 always points to missing or invalid authentication credentials, not to resource relocation or malformed requests.

Why the other options are wrong

A

Option A is incorrect because a 301 status code indicates that the requested resource has been moved permanently to a new URL, not an authentication issue. Confusing 301 with 401 can lead to misdiagnosing API errors.

B

Option B is incorrect since a 204 status code means the request was successful but no content was returned. It does not indicate any authentication problem, unlike 401 which specifically relates to authorization failures.

D

Option D is incorrect because a server's inability to parse JSON usually results in a 400 Bad Request error, not a 401 Unauthorized. The 401 code is strictly about authentication, not parsing or syntax errors.

When would these options actually be correct?

A

In a question asking about the meaning of HTTP status code 301, such as 'What does HTTP status code 301 indicate when returned by a server?', option A would be correct as it accurately describes the permanent redirection of a resource.

B

If the question asked about an HTTP status code that indicates a successful request with no content returned, such as 204 No Content, then option B would be correct. This would involve a scenario where the API successfully processes a request but has no data to return.

D

If the question were about a scenario where a server received a request with malformed JSON data in the body and could not process it, then a status code indicating a parsing error, such as 400 Bad Request, would be appropriate. In that context, option D could be correct.

Why candidates pick the wrong answer

A

Candidates may confuse HTTP status codes and their meanings, leading them to mistakenly associate 401 with resource movement due to a lack of familiarity with the specific codes and their definitions.

B

Candidates may confuse the 401 status code with other success-related codes, leading them to mistakenly believe that a successful request could yield no content, especially if they are not fully familiar with the nuances of HTTP status codes.

D

Candidates might confuse the implications of different HTTP status codes and associate 401 with general request failures, leading them to mistakenly select an option related to parsing errors.

Page 13

Page 14 of 20

Page 15