Courseiva

CCNA 200-301 v2 (200-301) — Questions 1051–1125

1450 questions total · 20pages · All types, answers revealed

Page 14

Page 15 of 20

Page 16
1051
MCQhard

Exhibit: R1 has a default route pointing to 10.1.1.2. Users lose internet access when that next hop fails, even though a floating static backup exists. Why is the backup not installed?

A.The backup route has a higher administrative distance and therefore is never considered
B.The primary static route remains installed because there is no tracking to remove it
C.Floating statics work only with dynamic routing protocols
D.The backup route must use the same next hop as the primary route
AnswerB

In the absence of IP SLA tracking or a similar object-tracking mechanism, the router continues to install the primary static route even after its next hop becomes unreachable. Static routes do not have built-in liveness detection, so the route remains in the routing table and traffic is sent toward the dead 10.1.1.2 next hop. The floating backup route, having a higher administrative distance, is never selected because the lower-AD primary is still present.

Why this answer

A floating static route is used only when the primary route disappears from the routing table. If the primary interface stays up and the next hop becomes unreachable beyond that segment, the route can remain installed unless tracking or another detection mechanism removes it.

Exam trap

A frequent exam trap is believing that a floating static route activates automatically when the primary next hop fails. Many candidates overlook that the router only removes the primary static route if it detects the route is invalid or unreachable. Without IP SLA or object tracking, the router sees the primary route as valid because the interface remains up, so it never installs the backup route.

This misunderstanding causes confusion about why users lose internet access despite a floating static backup being configured. The exam tests your knowledge of how Cisco routers handle administrative distance and route tracking, not just static route configuration.

Why the other options are wrong

A

Option A incorrectly states that the backup route is never considered because of its higher administrative distance. In reality, the higher AD is intentional to make it a floating static route that only activates when the primary route is removed.

C

Option C is incorrect because floating static routes do not require dynamic routing protocols to work. They are static routes with adjusted administrative distance and can function independently.

D

Option D is wrong because backup routes typically use a different next hop to provide true redundancy. Using the same next hop would not protect against next-hop failure.

When would these options actually be correct?

A

In a different scenario, if the question stated that the backup route had an administrative distance of 20 while the primary route had an administrative distance of 10, then option A would be correct, as the backup would never be considered due to the higher administrative distance.

C

In a question where the configuration of a router includes both static and dynamic routing protocols, and the scenario specifies that floating static routes are not being utilized due to the presence of a dynamic routing protocol, this option would be correct. For example, if the question stated that a floating static route was not being considered because a dynamic protocol was overriding it, then this option would apply.

D

In a scenario where a question specifies that both the primary and backup static routes must have the same next hop for redundancy to be valid, this option would be correct. For example, if the exam states that both routes are required to point to the same next hop for the floating static to take effect.

Why candidates pick the wrong answer

A

Candidates may choose this option because they understand that administrative distance affects route selection, leading them to mistakenly believe that a higher distance always prevents a route from being used, without considering the specific context of the question.

C

Candidates may choose this option due to a misunderstanding of how floating static routes interact with dynamic routing protocols, leading them to believe that such routes are incompatible with dynamic routing configurations.

D

Candidates may choose this option due to a misunderstanding of how floating static routes function, mistakenly believing that they require identical next hops to be valid. This misconception can stem from confusion with dynamic routing protocols that often have stricter requirements.

1052
MCQmedium

A host with IP address 172.16.50.130 and mask 255.255.255.192 needs to reach 172.16.50.190. Which statement is correct?

A.The destination is on a remote subnet, so the host must send to the default gateway.
B.The destination is local, so the host ARPs for 172.16.50.190 directly.
C.The destination is a directed broadcast for the local subnet.
D.The source host is using the network address of the subnet.
AnswerB

With a /26 mask, 172.16.50.130 and 172.16.50.190 both reside in the 172.16.50.128/26 subnet, whose broadcast address is .191. Because the destination is on the same data-link segment, the host does not involve the default gateway; instead, it sends an ARP request for .190 and forwards the frame directly to that resolved MAC address.

Why this answer

Both 172.16.50.130 and 172.16.50.190 fall within the 172.16.50.128/26 subnet (range .128 to .191). Therefore, the destination is local, and the host will use ARP to resolve the destination IP directly. Option A is incorrect because the destination is not remote.

Option C is incorrect because the directed broadcast address for this subnet is 172.16.50.191, not .190. Option D is incorrect because 172.16.50.130 is a valid host address, not the network address (.128).

Exam trap

Be cautious of subnet mask calculations and ensure you understand the IP range it defines.

Why the other options are wrong

A

The destination is local to the same /26 subnet, so it does not need to go through the default gateway.

C

The subnet directed broadcast is 172.16.50.191 (the last address in the .128/26 range), not .190.

D

The source address 172.16.50.130 is a usable host address, not the network address of the subnet.

When would these options actually be correct?

A

In a different scenario where the host's IP address is 172.16.50.130 with a subnet mask of 255.255.255.128, and the destination IP is 172.16.51.190, the destination would be on a different subnet, requiring the host to send packets to the default gateway.

C

If the question stated that the host's subnet mask was 255.255.255.128, making the subnet range 172.16.50.128 to 172.16.50.255, then 172.16.50.190 would be a directed broadcast address for the subnet 172.16.50.128/25, making this option correct.

D

In a different scenario where the question specifies that the host's IP address is 172.16.50.128 with the same subnet mask, option D would be correct, as 172.16.50.128 is indeed the network address of the subnet 172.16.50.128/26.

Why candidates pick the wrong answer

A

Candidates may choose this option due to a misunderstanding of subnetting, leading them to incorrectly assume that any IP outside the first three octets must be on a different subnet.

C

Candidates may choose this option due to confusion about subnetting and broadcast addresses, leading them to incorrectly assume that any address outside the host's IP is a broadcast address.

D

Candidates may be tempted by this option due to a misunderstanding of subnetting concepts, leading them to incorrectly identify valid host addresses as network addresses.

1053
Multi-Selectmedium

Which TWO statements about fiber optic cables and SFP/SFP+ transceivers are correct?

Select 2 answers
A.Single-mode fiber (SMF) uses a smaller core diameter than multimode fiber (MMF).
B.Multimode fiber supports longer distances than single-mode fiber.
C.SFP+ transceivers are commonly used for 10 Gigabit Ethernet connections.
D.SFP modules support data rates up to 10 Gbps.
E.Multimode fiber typically has a core diameter of 9 microns.
AnswersA, C

Single-mode fiber is engineered with a much smaller core—typically 9 microns—compared to multimode fiber's 50- or 62.5-micron core. This narrow core forces light to travel in a single straight path, virtually eliminating modal dispersion. As a result, SMF supports longer transmission distances and higher bandwidth than MMF, which is why it is used for long-haul and carrier-grade links.

Why this answer

Single-mode fiber (SMF) has a core diameter of about 9 microns, which is smaller than multimode fiber (MMF) cores of 50 or 62.5 microns. Option C is correct because SFP+ transceivers are indeed designed for 10 Gigabit Ethernet, supporting data rates up to 10 Gbps. Option B is wrong because multimode fiber is used for shorter distances (up to a few hundred meters) due to higher modal dispersion, while single-mode fiber supports longer distances (tens of kilometers).

Option D is wrong because standard SFP modules support up to 1 Gbps, not 10 Gbps; SFP+ modules handle 10 Gbps. Option E is wrong because a 9-micron core is characteristic of single-mode fiber, not multimode fiber.

Exam trap

Cisco often tests the misconception that 'multimode' implies longer reach due to its name, but the opposite is true because of modal dispersion limits.

Why the other options are wrong

B

Single-mode fiber supports much longer distances (up to 10 km or more) than multimode fiber (typically up to 550 m for 10 Gbps).

D

SFP is limited to 1 Gbps; for 10 Gbps, SFP+ is required.

E

This describes single-mode fiber, not multimode.

1054
MCQhard

A subnet must support at least 62 usable IPv4 host addresses. Which prefix is the most restrictive that meets the requirement?

A./27
B./26
C./25
D./24
AnswerB

A /26 leaves 6 host bits, giving 64 addresses minus network and broadcast, so exactly 62 usable hosts. A /27 yields only 30, insufficient; /26 is the most restrictive prefix satisfying the 62-host minimum without wasting address space.

Why this answer

A /26 is the smallest valid answer. In practical terms, a /26 provides 64 total addresses and 62 usable host addresses after subtracting the network and broadcast addresses. A /27 would be too small because it provides only 30 usable hosts.

This is a standard minimum-prefix question because it checks whether you can work backward from the host requirement and choose the smallest subnet that fits.

Exam trap

Avoid confusing total addresses with usable ones; remember to subtract network and broadcast addresses.

Why the other options are wrong

A

A /27 subnet provides only 30 usable host addresses (32 total minus 2 for network and broadcast), which does not meet the requirement of at least 62 usable addresses.

C

Option C: /25 provides 126 usable host addresses, which exceeds the requirement of at least 62 usable addresses. However, it is not the smallest prefix that meets the requirement, as /26 suffices with 62 usable addresses.

D

Option D: /24 provides 256 total addresses, with 254 usable, which exceeds the requirement of at least 62 usable addresses. However, it is not the smallest prefix that meets the requirement.

When would these options actually be correct?

A

If the question asked for the smallest subnet that supports at least 30 usable addresses, then /27 would be the correct answer, as it provides exactly 30 usable addresses.

C

In a scenario where a question specifies the need for a subnet that can accommodate at least 126 usable addresses, option C: /25 would be the correct choice, as it meets the requirement without exceeding it unnecessarily.

D

In a different scenario where the question asks for a subnet that can support a larger number of hosts, such as at least 200 usable addresses, /24 would be the correct answer as it provides 254 usable addresses.

Why candidates pick the wrong answer

A

Candidates may confuse the number of usable addresses with the total number of addresses in the subnet, leading them to mistakenly believe that /27 could meet a lower requirement than specified.

C

Candidates may choose option C because they recognize that /25 offers a substantial number of addresses, leading them to mistakenly believe it is the smallest prefix that meets the requirement without considering the specific need for minimality.

D

Candidates may choose /24 because it is a common subnet size that many are familiar with, leading them to assume it is a safe choice for any requirement without calculating the specific needs.

1055
MCQmedium

A network administrator is configuring a new Windows 10 workstation on a network that uses DHCP. The workstation receives an IPv4 address of 169.254.10.20 with a subnet mask of 255.255.0.0 and no default gateway. The user cannot access the internet or other subnets. What is the most likely cause of this issue?

A.The workstation has a duplicate IP address conflict.
B.The workstation's DNS server configuration is incorrect.
C.The workstation's subnet mask is misconfigured.
D.The DHCP server is unreachable or not responding.
AnswerD

When a DHCP client fails to receive an IP address from a DHCP server, it self-assigns an APIPA address from the 169.254.0.0/16 range. This explains the observed address and the absence of a default gateway.

Why this answer

The IP address 169.254.10.20 with a /16 subnet mask is an Automatic Private IP Addressing (APIPA) address, which Windows assigns when a DHCP discovery broadcast (DHCPDISCOVER) fails to receive a response from a DHCP server. Without a valid DHCP lease, the workstation has no default gateway, so it cannot communicate outside its local subnet, explaining the lack of internet or inter-subnet access. The most likely cause is that the DHCP server is unreachable or not responding, forcing the client to self-assign an APIPA address.

Exam trap

Cisco often tests the misconception that a 169.254.x.x address indicates a duplicate IP or a subnet mask issue, but the real trap is that APIPA is a direct symptom of DHCP server unavailability, not a configuration error on the client.

Why the other options are wrong

A

Duplicate IP conflicts typically result in a warning but do not cause the system to assign a 169.254.x.x address.

B

DNS issues do not affect IP address assignment via DHCP.

C

The subnet mask is correct for the APIPA range; the problem is the lack of a DHCP server response.

1056
PBQhard

You are connected to SW1. Configure an LACP EtherChannel between SW1 and SW2 using ports GigabitEthernet0/1 and GigabitEthernet0/2. Set the channel-group mode to active on both sides. The port-channel interface should be configured as a trunk allowing VLANs 10, 20, and 30. Initially, the EtherChannel fails to form due to mismatched speed/duplex on one link. Identify and correct the issue, then verify the channel is up and operational.

Network Topology
Gi0/1-Gi0/2Gi0/1-Gi0/2EtherChannelSW1SW2

Hints

  • •Check the speed and duplex settings on each member interface.
  • •LACP requires all ports in the channel to have identical speed and duplex.
  • •Use 'show interfaces status' to quickly see speed/duplex mismatches.
A.Change speed and duplex on Gi0/2 to 1000 and full, then verify with 'show etherchannel summary'.
B.Change the channel-group mode on Gi0/2 to passive, then verify with 'show etherchannel summary'.
C.Change the allowed VLANs on the port-channel to include only VLAN 1, then verify with 'show etherchannel summary'.
D.Change the port-channel interface to access mode, then verify with 'show etherchannel summary'.
AnswerA
solution
! SW1
interface GigabitEthernet0/2
speed 1000
duplex full

Why this answer

The EtherChannel fails because GigabitEthernet0/2 has speed 100 and duplex half, while GigabitEthernet0/1 has speed 1000 and duplex full. LACP requires all member ports to have identical speed and duplex settings. To resolve, change the speed and duplex on Gi0/2 to match Gi0/1: 'speed 1000' and 'duplex full'.

After correction, the channel will bundle. Verify with 'show etherchannel summary' to see both ports in the 'P' (bundled) state.

Exam trap

Do not confuse Layer 1 issues (speed/duplex) with Layer 2 configuration (VLANs, trunking) or LACP mode settings. Always check physical parameters first when an EtherChannel fails to form.

Why the other options are wrong

B

The specific factual error is that LACP modes must be compatible (active-active or active-passive), but the question states both sides are active, so mode is not the issue.

C

The specific factual error is that VLAN settings are irrelevant to the physical bundling of ports in an EtherChannel.

D

The specific factual error is that interface mode is a Layer 2 property unrelated to the physical bundling process.

Why candidates pick the wrong answer

B

Candidates might think that LACP mode mismatch is the cause, especially if they recall that one side must be active and the other passive in some configurations.

C

Candidates might confuse trunk configuration requirements with EtherChannel prerequisites, thinking that VLAN mismatches can prevent channel formation.

D

Candidates might think that trunk mode requires additional configuration that could cause issues, or they might confuse the port-channel interface configuration with the physical port settings.

1057
MCQhard

R1 loses its route to 192.168.20.0/24 whenever R2's GigabitEthernet0/0 interface flaps. The network engineer has configured a floating static route with an administrative distance of 200. The OSPF route has an AD of 110. After R2's G0/0 interface recovers, the floating static route appears in the routing table instead of the OSPF route. What should the technician do next?

A.Adjust the administrative distance of the floating static route to 201.
B.Check the carrier delay timers on R2's GigabitEthernet0/0 interface.
C.Clear the IP routing table and reset the OSPF process on R1.
D.Verify that the MTU on R1 and R2's GigabitEthernet0/0 interfaces match.
AnswerB

A high carrier-delay (interface debounce) timer can keep the link down for too long after a flap, delaying OSPF neighbor formation. While the interface remains down, the floating static route stays in the table. Checking this timer is a logical, non‑destructive next step.

Why this answer

When R2's GigabitEthernet0/0 interface flaps, the OSPF neighbor relationship goes down, causing R1 to lose the OSPF route. The floating static route (AD 200) then takes over. After the interface recovers, OSPF should re-establish and install its route (AD 110) over the static route.

However, if the carrier delay timer on R2's interface is set too high, the interface may not come up quickly enough for OSPF to re-converge before the floating static route is already installed and preferred. Checking and adjusting the carrier delay timer ensures that the interface state change is propagated promptly, allowing OSPF to re-establish and replace the static route.

Exam trap

Cisco often tests the concept that a floating static route can persist after a link recovers due to interface timers (carrier delay) delaying OSPF convergence, leading candidates to mistakenly focus on administrative distance adjustments or clearing the routing table.

Why the other options are wrong

A

Misunderstanding of route preference: a higher AD value does not keep a floating static installed when a better OSPF route becomes available.

C

Troubleshooting should follow the OSI model bottom‑up; immediately resetting processes skips basic interface‑level verification.

D

It targets a different root cause (OSPF adjacency failure due to MTU) that would manifest constantly, not only after interface recovery.

1058
MCQhard

A network requires at least 500 usable host addresses in one IPv4 subnet. Which prefix is the smallest that meets the requirement?

A./24
B./23
C./22
D./25
AnswerB

A /23 mask provides 2^(32-23) = 512 addresses, yielding 510 usable hosts after reserving network and broadcast, which exceeds the 500 required. A /24 gives only 254 usable hosts, so /23 is the smallest prefix meeting the constraint.

Why this answer

To support at least 500 usable hosts, the subnet must provide at least 502 total addresses when the network and broadcast addresses are included. In plain language, that means 256 total addresses in a /24 are not enough, so the next larger power-of-two block is required. A /23 provides 512 total addresses and 510 usable host addresses, which satisfies the requirement while remaining the smallest valid option.

This is a classic host-capacity question because it checks whether you can work backward from a required usable host count and choose the smallest prefix that works without wasting more space than necessary.

Exam trap

Be careful not to confuse the total number of addresses with the number of usable host addresses. Remember to account for network and broadcast addresses.

Why the other options are wrong

A

A /24 subnet provides only 256 usable host addresses, which is insufficient for the requirement of at least 500 usable addresses. Therefore, it cannot be the correct answer.

C

Option C (/22) provides 1022 usable addresses, which exceeds the requirement of 500 usable addresses, but it is not the smallest prefix that meets the requirement. The correct answer is /23, which provides exactly 510 usable addresses.

D

Option D: /25 provides only 126 usable host addresses, which is insufficient for a requirement of at least 500 usable addresses in a single subnet.

When would these options actually be correct?

A

If the question specified a requirement for a network with fewer than 256 usable host addresses, such as needing a subnet for a small office or a specific application, then a /24 would be the correct choice.

C

In a scenario where the question asks for a subnet that can accommodate at least 1000 usable addresses, option C (/22) would be correct, as it provides 1022 usable addresses, satisfying the requirement.

D

In a scenario where a question asks for the smallest subnet that can accommodate 126 usable hosts, option D: /25 would be the correct answer, as it meets the requirement exactly.

Why candidates pick the wrong answer

A

Candidates may mistakenly believe that a /24 subnet is sufficient due to familiarity with common subnet sizes, leading them to overlook the specific requirement for at least 500 usable addresses.

C

Candidates may choose option C because they recognize that it meets the minimum address requirement, but they overlook the need for the smallest prefix, leading to confusion between sufficient and optimal solutions.

D

Candidates may choose /25 due to a misunderstanding of subnetting, thinking that smaller prefixes can still accommodate more hosts than they actually can, or they may confuse the number of hosts with the prefix length.

1059
MCQhard

A network administrator is deploying a new branch office that will have 500 devices in a single VLAN. The administrator wants to minimize broadcast traffic and improve performance by segmenting the network into smaller broadcast domains while keeping the design simple. Which action best accomplishes this?

A.Increase the MTU on all switch ports to reduce broadcast overhead.
B.Configure private VLANs to isolate all devices from each other.
C.Create multiple VLANs and assign devices to them based on function, then route between the VLANs.
D.Enable storm control on the switch ports to limit broadcast traffic.
AnswerC

Creating multiple VLANs splits the single large broadcast domain into several smaller ones, reducing broadcast traffic and improving performance. Routing between the VLANs allows devices in different VLANs to communicate when needed. This approach is simple, scalable, and directly addresses the goal of minimizing broadcast traffic in a 500-device network.

Why this answer

Segmenting a large flat network into multiple VLANs creates smaller broadcast domains, which directly reduces broadcast traffic and improves performance. Storm control only limits rates without segmenting, MTU changes are irrelevant to broadcast domains, and private VLANs add complexity and restrict communication. Routing between VLANs preserves necessary connectivity, making the VLAN approach the simplest effective solution for the 500-device branch.

Exam trap

The trap here is confusing traffic-rate limiting tools like storm control with actual broadcast domain segmentation.

1060
Multi-Selecteasy

An engineer is reviewing transport protocols for a new application. Which two characteristics are associated with TCP rather than UDP?

Select 2 answers
A.Connection establishment before data transfer
B.Best-effort delivery with no acknowledgments
C.Sequencing and retransmission support
D.Lower overhead because no session state is tracked
AnswersA, C

TCP performs a three-way handshake (SYN, SYN-ACK, ACK) to establish a connection before any application data is transmitted, ensuring both hosts are synchronized and ready. This connection-oriented process negotiates initial sequence numbers and window sizes, providing a reliable session foundation. UDP, in contrast, sends datagrams immediately without any setup, so this behavior is uniquely characteristic of TCP and therefore correct.

Why this answer

TCP is connection-oriented and provides reliability with sequence numbers, acknowledgments, and retransmissions. UDP is lighter but does not guarantee delivery.

Exam trap

Don't confuse reliability with speed; TCP's reliability features add overhead, making it slower than UDP.

Why the other options are wrong

B

Best-effort delivery with no acknowledgments is a characteristic of UDP, not TCP. TCP provides reliable delivery with acknowledgments and retransmission.

D

TCP has higher overhead because it maintains session state (sequence numbers, acknowledgments, etc.), while UDP is stateless and has lower overhead. The question asks for characteristics of TCP, not UDP.

When would these options actually be correct?

B

This option would be correct in a question asking for characteristics of UDP, such as 'Which two characteristics are associated with UDP rather than TCP?'

D

This option would be correct if the question were 'Which two characteristics are associated with UDP rather than TCP?' or 'Which characteristic describes UDP compared to TCP?'

Why candidates pick the wrong answer

B

Candidates may confuse the terms 'best-effort' with TCP's reliable delivery, or they might think TCP also uses best-effort at the network layer, ignoring transport layer reliability.

D

Candidates may confuse the characteristics of TCP and UDP, or they might think 'lower overhead' is a general advantage that could apply to TCP in some contexts, but TCP's overhead is inherently higher due to its reliability features.

1061
MCQhard

A packet is larger than the outgoing interface MTU and the DF bit is set in the IPv4 header. What should the router do?

A.Fragment the packet anyway and forward all fragments.
B.Drop the packet and send an ICMP message indicating fragmentation was needed.
C.Clear the DF bit and then fragment the packet.
D.Encapsulate the packet in GRE automatically.
AnswerB

When the DF bit is set and the packet exceeds the outgoing interface MTU, the router cannot fragment it without violating the IPv4 specification. The only compliant action is to discard the packet and return an ICMP Type 3, Code 4 message carrying the MTU of the next-hop link. This error informs the source so it can reduce its segment size, which is the basis of Path MTU Discovery.

Why this answer

If fragmentation is required but DF is set, the router drops the packet and returns an ICMP unreachable message indicating fragmentation was needed.

Exam trap

A common exam trap is selecting option A, assuming the router will fragment the packet despite the DF bit. Remember, the DF (Don't Fragment) bit explicitly prevents fragmentation. Another trap is option C, thinking the router can clear the DF bit and fragment, which routers do not do.

Option D is unrelated to MTU handling and can mislead if you confuse GRE tunneling with fragmentation behavior.

Why the other options are wrong

A

Incorrect because the DF bit explicitly forbids fragmentation; the router cannot fragment the packet if DF is set.

C

Incorrect because routers do not clear the DF bit to fragment packets; they respect the DF bit as set by the source.

D

Incorrect because GRE encapsulation is unrelated to MTU handling and fragmentation behavior.

When would these options actually be correct?

A

In a different scenario where the DF bit is not set, a question might ask what a router should do when a packet exceeds the MTU. In that case, the router could fragment the packet and forward all fragments without violating protocol rules.

C

In a different scenario where the question specifies that the DF bit is not set, a router could clear the DF bit and fragment the packet to fit the MTU of the outgoing interface. This would be a valid action when fragmentation is permissible.

D

In a different scenario where the question asks about handling packets that need to be tunneled for secure transmission, and the GRE protocol is explicitly mentioned, the correct answer could involve encapsulating packets in GRE regardless of MTU issues, assuming the context allows for such a solution.

Why candidates pick the wrong answer

A

Candidates may choose this option due to a misunderstanding of how fragmentation works in relation to the DF bit, leading them to incorrectly assume that routers can override the DF setting.

C

Candidates may choose this option because they recall that fragmentation is a common network operation and mistakenly believe that routers can modify packet headers to facilitate forwarding, especially under pressure during an exam.

D

Candidates may find this option tempting because GRE is often associated with tunneling and can handle larger packets, leading to confusion about its role in fragmentation scenarios.

1062
PBQhard

You are connected to R1. Configure DHCP server on R1 to assign addresses from 192.168.50.0/24 to hosts on VLAN 50, excluding 192.168.50.1-192.168.50.20, with default-router 192.168.50.1 and DNS server 8.8.8.8. On switch SW1, configure DHCP snooping globally and on VLAN 50, and enable trusted ports on the uplink to R1. Then, a host on VLAN 50 reports it received an incorrect IP address; troubleshoot and fix the issue: the wrong helper-address is configured on SW1, the excluded range is too large, and a rogue DHCP server is present on port Fa0/5.

Hints

  • •Check the DHCP snooping configuration first — is it enabled and on the correct VLAN?
  • •Look at the helper-address: the DHCP server is on the SVI, not on the point-to-point link.
  • •The excluded range on R1 is too large; it should only exclude the first 20 addresses.
A.Enable DHCP snooping globally and on VLAN 50, trust the uplink port to R1, correct the excluded range on R1 to 192.168.50.1-192.168.50.20, and change the helper-address on SW1's G0/1 to 192.168.50.1.
B.Enable DHCP snooping globally and on VLAN 50, trust the uplink port to R1, and change the helper-address on SW1's G0/1 to 10.0.0.1.
C.Enable DHCP snooping globally and on VLAN 50, trust the uplink port to R1, and correct the excluded range on R1 to 192.168.50.1-192.168.50.20.
D.Enable DHCP snooping globally and on VLAN 50, trust the uplink port to R1, and change the helper-address on SW1's G0/1 to 192.168.50.1.
AnswerA
solution
! R1
configure terminal
no ip dhcp excluded-address 192.168.50.1 192.168.50.100
ip dhcp excluded-address 192.168.50.1 192.168.50.20
end
write memory

! SW1
configure terminal
ip dhcp snooping
ip dhcp snooping vlan 50
interface GigabitEthernet0/1
ip dhcp snooping trust
no ip helper-address 10.0.0.1
ip helper-address 192.168.50.1
interface FastEthernet0/5
shutdown
end
write memory

Why this answer

The host received a wrong IP because a rogue DHCP server on Fa0/5 was responding. First, enable DHCP snooping globally with 'ip dhcp snooping' and on VLAN 50 with 'ip dhcp snooping vlan 50'. Then, trust the uplink port to R1 (G0/1) with 'ip dhcp snooping trust'.

Next, fix the excluded range on R1: change it to exclude only the first 20 addresses (192.168.50.1-192.168.50.20) so that hosts can obtain other addresses. Finally, correct the helper-address on SW1's G0/1: change 'ip helper-address 10.0.0.1' to 'ip helper-address 192.168.50.1' because the DHCP server is on the VLAN 50 SVI, not on the point-to-point link.

Exam trap

This question tests your ability to troubleshoot a multi-faceted DHCP issue. Common traps include: (1) forgetting that DHCP snooping must be enabled both globally and per VLAN, (2) assuming the helper-address should be the router's link IP instead of the server's SVI IP, (3) overlooking the excluded range configuration, and (4) thinking that only one of the issues needs to be fixed. Always verify all components: snooping, trust, helper-address, and pool configuration.

Why the other options are wrong

B

The helper-address must be the IP of the DHCP server, which is the SVI address 192.168.50.1, not the link address 10.0.0.1.

C

The helper-address misconfiguration prevents DHCP requests from being forwarded to the correct server, so fixing only the excluded range is insufficient.

D

The excluded range must be corrected to allow hosts to receive addresses from the pool; otherwise, the DHCP server will not assign addresses.

Why candidates pick the wrong answer

B

Candidates might think the helper-address should be the next-hop IP or the IP of the router interface facing the switch.

C

Candidates might focus only on the excluded range issue and overlook the helper-address, especially if they assume the helper-address is correct.

D

Candidates might think that DHCP snooping alone will solve the issue, or they may forget to adjust the excluded range after troubleshooting.

1063
MCQhard

If a host has a valid IP address and subnet mask but no default gateway, what is the most likely result?

A.The host can usually reach only local-subnet destinations and not remote networks.
B.The host cannot use ARP at all.
C.The host automatically joins every subnet in the LAN.
D.The host becomes the default gateway for other devices.
AnswerA

Without a default route, the host's IP stack has no next-hop entry for packets whose destination IPv4 address is outside the host's directly connected subnet. The host will attempt to deliver such packets to the local network only if a matching route exists, but since the destination is off-subnet, no ARP resolution is possible and the packets are discarded. Conversely, destination addresses within the host's configured subnet are considered on-link, so the host uses ARP to resolve their MAC addresses and can communicate with them directly.

Why this answer

The host will normally reach local destinations but fail to reach remote networks. In practical terms, the subnet mask still lets the host identify what is local, but without a default gateway it has no next hop for off-subnet traffic. That means local ARP-based communication can still work, while remote communication usually fails.

This is a core host-configuration concept and a very common certification question. The missing gateway does not break all communication — it breaks off-subnet communication.

Exam trap

A common exam trap is assuming that a host without a default gateway cannot use ARP or communicate at all. This is incorrect because ARP is used for local Layer 2 address resolution and remains functional. Another trap is believing the host automatically joins other subnets or becomes a gateway for others, which does not happen.

The key mistake is confusing local subnet communication with remote network access. The default gateway only affects off-subnet traffic, so the host can still communicate locally but fails to reach remote destinations.

Why the other options are wrong

B

This option is incorrect because ARP is used for local Layer 2 address resolution and remains functional even if the default gateway is missing; the host can still resolve MAC addresses on the local subnet.

C

This option is incorrect because the host’s subnet membership is determined by its IP address and subnet mask, not by the presence or absence of a default gateway; it does not join other subnets automatically.

D

This option is incorrect because a host does not become a default gateway for other devices simply by lacking a configured gateway; routing and gateway roles require explicit configuration on routers.

When would these options actually be correct?

B

In a different question, if it stated that a host was configured with a static IP address but was isolated from the local network (e.g., due to a misconfiguration), then it might be plausible to say that the host cannot use ARP at all because it cannot communicate with any devices to resolve addresses.

C

In a different scenario where the question states that the host is configured with a special network protocol that allows it to bridge multiple subnets without a default gateway, option C could be correct. For example, if the host is part of a virtualized environment that uses overlay networking, it may interact with multiple subnets seamlessly.

D

In a scenario where the question states that a host has been configured with routing capabilities and is set to act as a gateway for other devices, this option would be correct. For example, if the question specifies a router-like setup where a host is assigned a role to route traffic, then it could act as a default gateway.

Why candidates pick the wrong answer

B

Candidates might choose this option due to a misunderstanding of ARP's function, mistakenly believing that a lack of a default gateway entirely disables ARP capabilities, rather than recognizing its local subnet functionality.

C

Candidates may find this option tempting due to a misunderstanding of how network protocols can allow devices to communicate across subnets, leading them to incorrectly assume that a lack of a default gateway means automatic access to all subnets.

D

Candidates may find this option tempting because they might confuse the concept of a host's role in a network with that of a router, leading them to incorrectly assume that any host can serve as a gateway.

1064
MCQeasy

An AP broadcasts the correct SSID, but many clients on one floor experience poor performance while the same SSID works well on another floor. Which category of issue is most strongly suggested first?

A.A radio-frequency or local wireless environment issue on that floor
B.The SSID name must be misspelled only on that floor
C.BGP autonomous system mismatch
D.IPv6 loopback addressing on the clients
AnswerA

The problem is strictly local to that floor while the AP continues to broadcast the correct SSID, which isolates the fault to Layer 1 RF conditions rather than the WLAN configuration. Interference from co-channel neighboring APs, physical obstructions, or RF absorption by building materials can degrade signal-to-noise ratio enough to cause client disconnects or poor throughput even though the beacon remains visible. This matches the symptom of a location-specific environmental issue.

Why this answer

The issue is location-specific, with performance problems only on one floor. This strongly suggests a local radio frequency (RF) or wireless environment issue such as interference, signal attenuation, or channel congestion on that floor. The SSID is correctly broadcast because clients on other floors connect successfully, so option B (misspelling) is not plausible.

Options C and D are unrelated to wireless performance: BGP is a routing protocol not used in basic WLAN deployments, and IPv6 loopback addressing does not affect client connectivity or throughput. Therefore, the most direct and likely first suspect is an RF or environmental issue on that specific floor.

Exam trap

Avoid assuming that SSID issues are always configuration-related; consider environmental factors when performance issues are location-specific.

Why the other options are wrong

B

An SSID misspelling would prevent all clients from seeing the SSID, but since clients on other floors connect successfully, this cannot be the issue.

C

BGP autonomous system mismatch is a routing protocol concept unrelated to wireless LAN performance issues and would not cause performance problems on a single floor.

D

IPv6 loopback addressing is a configuration detail that does not impact wireless client performance or connectivity in a local-area network context.

When would these options actually be correct?

B

In a scenario where a question specifies that clients are unable to connect to the SSID at all on one floor while it works perfectly on another, and the problem is attributed to a typo in the SSID configuration on that specific floor, then this option would be correct.

C

If the exam question described a scenario where multiple networks are interconnected and clients on one floor are unable to reach external resources due to routing issues, a BGP autonomous system mismatch could be the correct answer, indicating a problem with inter-network routing.

D

In a different question scenario where clients are unable to connect to the network at all, and the question specifies that the issue is related to IPv6 configurations, a focus on loopback addressing could be correct if the loopback address is incorrectly configured, preventing proper communication over the network.

Why candidates pick the wrong answer

B

Candidates may choose this option due to a common misconception that connectivity issues often stem from simple configuration errors, such as misspellings, rather than more complex environmental factors.

C

Candidates may confuse the symptoms of poor performance with broader network issues, leading them to incorrectly associate routing protocols like BGP with local connectivity problems, especially if they lack familiarity with wireless troubleshooting.

D

Candidates may choose this option due to a misunderstanding of how IPv6 addressing works, mistakenly believing that loopback addressing could impact client connectivity in a wireless environment, especially if they are familiar with IPv4 addressing concepts.

1065
MCQhard

Why might a controller return interface information as a JSON array instead of a single JSON object?

A.Because an array is the appropriate structure for an ordered list of multiple interface entries.
B.Because a JSON object cannot contain fields.
C.Because arrays are used only for IPv6 interfaces.
D.Because arrays eliminate the need for API authentication.
AnswerA

In JSON, an array is an ordered collection of values, making it the correct structure to represent multiple interface entries where each entry follows a sequential order and may repeat. A controller returning interface information as an array allows consumers to iterate over the list predictably, with each element being a distinct interface object. This mirrors the data model for a list of interfaces rather than a single scalar value.

Why this answer

A controller might return interface information as a JSON array because there are multiple interface records to present as a list. In practical terms, an array is the correct structure when the response includes several similar items, such as multiple interfaces, routes, or VLANs. Each element in the array can then be its own object with fields like name, status, or IP address.

This is a data-structure recognition question. It is not about networking behavior directly, but about understanding how automation systems represent repeated information.

Exam trap

A frequent exam trap is believing that JSON objects cannot contain multiple fields or that arrays are only used for specific interface types like IPv6. This misunderstanding leads to incorrect assumptions about data representation in network automation. Candidates might also confuse data structure choices with unrelated concepts like API authentication, mistakenly thinking arrays affect security.

The trap lies in conflating the purpose of JSON arrays as a data structure for multiple similar items with other unrelated networking or security concepts. Understanding that arrays simply represent ordered lists of items, such as multiple interfaces, is crucial to avoid this confusion.

Why the other options are wrong

B

This option is incorrect because JSON objects do contain fields; they are collections of key-value pairs representing attributes of a single entity, so the claim that objects cannot contain fields is false.

C

This option is wrong because JSON arrays are a general data structure used for any list of items, not exclusively for IPv6 interfaces; interface type does not dictate JSON structure.

D

This option is incorrect because the choice of JSON data structure (array vs. object) does not affect API authentication or security; these are separate concerns unrelated to data formatting.

When would these options actually be correct?

B

If the exam question asked about the limitations of JSON objects in a specific context, such as a scenario where a JSON object was improperly formatted or lacked fields due to a programming error, this option could be correct.

C

In a different question asking why arrays are specifically used for representing IPv6 interfaces in a networking API, this option could be correct if the context is limited to a system that only supports IPv6 and requires array structures for its interface data.

D

In a different question context that asks about the benefits of using arrays in API responses, one might argue that using arrays can simplify data handling, which could be misinterpreted as reducing the need for authentication due to perceived simplicity in data management.

Why candidates pick the wrong answer

B

Candidates might choose this option due to a misunderstanding of JSON structures, confusing the capabilities of objects and arrays. The phrasing may lead them to believe that objects are somehow less capable than arrays in terms of containing data.

C

Candidates may choose this option due to a misunderstanding of JSON structures and a common association of arrays with lists of items, leading them to incorrectly link arrays exclusively with IPv6 interfaces.

D

Candidates might choose this option due to a misunderstanding of how data structures relate to security practices, leading them to incorrectly associate the use of arrays with reduced complexity in API design.

1066
MCQhard

A host uses address 192.168.5.126/25. Which address is the broadcast address for its subnet?

A.192.168.5.63
B.192.168.5.127
C.192.168.5.128
D.192.168.5.255
AnswerB

The /25 CIDR notation specifies a subnet mask of 255.255.255.128, meaning the first 25 bits define the network portion. For the host 192.168.5.126, the network address is 192.168.5.0, as the 25th bit is 0. This subnet, 192.168.5.0/25, encompasses IP addresses from 192.168.5.0 to 192.168.5.127. The broadcast address is always the last address in the subnet range, where all host bits are set to one, which in this scenario is 192.168.5.127.

Why this answer

A /25 divides the /24 into two halves: 0–127 and 128–255. In plain language, the host address 192.168.5.126 is in the lower half, which runs from .0 through .127. The last address in that block is the broadcast address, so the broadcast is 192.168.5.127.

This is a classic subnetting question because it checks whether you can identify the correct block and then select the last address in that block as the broadcast address.

Exam trap

Remember that the broadcast address is the last address in the subnet, not the first address of the next subnet or the broadcast for the entire /24.

Why the other options are wrong

A

Option A (192.168.5.63) is incorrect because it does not fall within the subnet defined by the address 192.168.5.126/25, which has a valid range of 192.168.5.128 to 192.168.5.255 for host addresses.

C

The address 192.168.5.128 is incorrect because it falls outside the subnet defined by 192.168.5.126/25, which includes addresses from 192.168.5.0 to 192.168.5.127. The broadcast address for this subnet is 192.168.5.127.

D

Option D, 192.168.5.255, is incorrect because it is the broadcast address for the entire 192.168.5.0/24 subnet, not the /25 subnet specified in the question.

When would these options actually be correct?

A

If the question were to ask for the broadcast address of a subnet defined by 192.168.5.0/26, then option A (192.168.5.63) would be correct, as it would represent the broadcast address for that specific subnet range.

C

If the question specified a subnet mask of /24 instead of /25, then 192.168.5.128 would be the correct broadcast address for the subnet 192.168.5.0/24, which ranges from 192.168.5.0 to 192.168.5.255.

D

If the question asked for the broadcast address of the 192.168.5.0/24 subnet instead of the /25 subnet, then option D would be correct, as it represents the highest address in that larger subnet.

Why candidates pick the wrong answer

A

Candidates may be tempted by this option because they might confuse the subnet mask and miscalculate the broadcast address, mistakenly believing that the lower range of addresses is valid for the given subnet.

C

Candidates might choose this option due to a misunderstanding of subnetting, mistakenly associating the higher address in the range with the broadcast address without calculating the correct subnet mask.

D

Candidates might choose option D due to a misunderstanding of subnetting, confusing the broader /24 range with the specific /25 range, leading them to think of the highest address in the entire subnet.

1067
MCQhard

A trunk is up between two switches, but traffic for VLAN 40 fails while other VLANs work. Which output item should be checked first?

A.Whether VLAN 40 is included in the allowed VLAN list on the trunk
B.Whether the router ID matches on both switches
C.Whether NetFlow is enabled on the VLAN
D.Whether NTP is synchronized on the switches
AnswerA

A trunk being administratively up indicates the physical and data-link layers are functioning, but Layer 2 connectivity for a particular VLAN depends on the VLAN being present in the trunk's allowed list (via switchport trunk allowed vlan). If VLAN 40 is not included on one or both sides, its frames are silently discarded or not placed on the trunk, even though other VLANs pass normally. This configuration discrepancy is the classic cause of a single-VLAN outage on an otherwise healthy trunk.

Why this answer

The first thing to check is whether VLAN 40 appears in the trunk’s allowed VLAN list. In practical terms, this is a selective failure, not a total trunk failure. Since other VLANs are crossing successfully, the link is operational. That strongly suggests one VLAN is being excluded rather than the trunk being generally broken.

This is one of the most common VLAN troubleshooting patterns in switching.

Exam trap

Avoid assuming a total trunk failure when only one VLAN is affected. Focus on VLAN-specific configurations.

Why the other options are wrong

B

This option is wrong because the router ID is relevant for routing protocols, not for VLAN traffic issues on a trunk link. The problem specifically pertains to VLAN 40 traffic, which is not influenced by router IDs.

C

NetFlow is a network protocol used for collecting IP traffic information, but it does not directly affect VLAN traffic flow on a trunk link. Therefore, checking if NetFlow is enabled does not address the issue of VLAN 40 traffic failure.

D

NTP synchronization is not directly related to VLAN traffic issues on a trunk link; it primarily affects time-sensitive protocols. Therefore, checking NTP synchronization would not help diagnose why VLAN 40 traffic is failing.

When would these options actually be correct?

B

In a question about OSPF or EIGRP configuration, where the focus is on ensuring proper routing between switches, checking the router ID would be crucial to confirm that both switches are configured to recognize each other in the routing domain.

C

In a question where the focus is on monitoring and analyzing traffic flows within a network, a scenario might ask about verifying configurations related to traffic analysis. If the question involved ensuring that traffic data is being collected for VLAN 40, then checking if NetFlow is enabled would be relevant.

D

In a different scenario where the question asks about the overall stability and performance of network services that rely on accurate timekeeping, such as logging or security protocols, verifying NTP synchronization could be crucial. For instance, if the question involved troubleshooting time-sensitive applications, this option could be relevant.

Why candidates pick the wrong answer

B

Candidates may choose this option due to a misunderstanding of the relationship between VLANs and routing protocols, mistakenly believing that routing configuration issues could affect VLAN traffic.

C

Candidates may confuse traffic analysis tools like NetFlow with VLAN configurations, thinking that monitoring settings could impact VLAN traffic, leading them to incorrectly select this option.

D

Candidates might choose this option due to a general understanding that synchronization issues can lead to various network problems, leading them to mistakenly believe it could impact VLAN traffic.

1068
MCQhard

An engineer wants a static route to be used only if the OSPF route to the same network disappears. What should be configured?

A.A static route with lower administrative distance than OSPF
B.A static route with higher administrative distance than OSPF
C.A second OSPF route with a lower metric
D.A default route with no next hop
AnswerB

Configuring a static route with an administrative distance (AD) higher than OSPF's default AD (110) ensures it is less preferred by the router. Routers always prioritise routes with lower ADs when multiple paths to the same destination exist. This setup precisely satisfies the requirement for the static route to be used *only if* the OSPF route, which normally has a lower AD and is thus preferred, becomes unavailable in the routing table.

Why this answer

A floating static route is given a higher administrative distance than the preferred dynamic route so it stays out of the routing table unless the dynamic route is lost.

Exam trap

Remember, administrative distance determines route preference across different protocols, not metrics.

Why the other options are wrong

A

This option is wrong because a static route with a lower administrative distance than OSPF would take precedence over OSPF routes, making it active even when OSPF is available, contrary to the requirement of using the static route only when the OSPF route is unavailable.

C

This option is wrong because a second OSPF route with a lower metric would not serve as a backup to the existing OSPF route; instead, it would be preferred over the static route, which contradicts the requirement for the static route to be used only if the OSPF route disappears.

D

A default route with no next hop would not serve as a backup for an OSPF route because it lacks specificity and cannot direct traffic to a specific network. It would be ineffective in scenarios where a specific static route is needed when OSPF fails.

When would these options actually be correct?

A

In a different scenario where the question asks for a static route that should always be preferred over OSPF routes for a specific network, configuring a static route with a lower administrative distance would be correct to ensure it is used preferentially.

C

In a scenario where the question asks for a method to ensure that a specific OSPF route is preferred for traffic, while a static route should only be used if the OSPF route fails, this option would be correct if the static route had a lower metric than the existing OSPF route.

D

If a question asked for a route that should be used for all traffic when no specific routes exist, a default route with no next hop could be correct. For example, in a scenario where a network is designed to send all unmatched traffic to a single exit point without needing to specify a next hop.

Why candidates pick the wrong answer

A

Candidates might choose this option because they understand that lower administrative distances indicate higher preference, leading them to mistakenly believe that this would ensure the static route is used when OSPF is down.

C

Candidates may choose this option because they may misinterpret the question as seeking a way to enhance routing redundancy, thinking that adding another OSPF route would provide a backup solution.

D

Candidates may find this option tempting because it seems like a catch-all solution for routing, especially if they misunderstand the need for specificity in routing tables and the role of default routes.

1069
MCQhard

Users in a branch office can reach internal networks but cannot browse the Internet. The router has a correct default route and PAT is configured. Which missing item is the most likely cause if inside hosts are still using private source addresses on the WAN?

A.A correct ACL or source match identifying inside local addresses for NAT
B.An STP root bridge election on the WAN side
C.A voice VLAN on the branch access switches
D.A loopback interface with a higher IP address
AnswerA

PAT (NAT overload) relies on an access list or route map to identify which inside local source addresses are eligible for translation. If that match is missing or incorrect, the router has a route for the internal networks and will forward the packets, but it never rewrites the source to the public address. As a result, private addresses are sent out the WAN unmodified, and return traffic cannot be routed back, which exactly matches the reported symptom.

Why this answer

If inside hosts are still appearing with private source addresses on the WAN side, the most likely missing element is a correct NAT inside source match for the internal subnet. In plain language, the router knows where Internet traffic should go because the default route exists, but it is not actually translating the private addresses before sending the traffic out. That means upstream devices see RFC 1918 private addresses that are not valid on the public Internet and return traffic fails.

This is a common CCNA troubleshooting pattern: routing and NAT are separate functions. A valid default route only tells the router where to send packets. It does not automatically translate them. PAT also depends on a correct ACL or source match identifying which inside addresses should be translated. If that match is missing or wrong, the router forwards the traffic but without performing the necessary translation. That is why the missing or incorrect NAT match is the most likely root cause.

Exam trap

A common exam trap is assuming that configuring a default route and enabling PAT alone guarantees Internet access for inside hosts. Candidates often overlook the necessity of a correct NAT ACL or source match that explicitly identifies which inside local addresses should be translated. Without this ACL, the router forwards packets with private IP addresses unchanged, causing return traffic to fail because upstream devices reject packets with non-routable source addresses.

This mistake leads to the false conclusion that routing or PAT is misconfigured, when the real issue is the missing or incorrect NAT match.

Why the other options are wrong

B

Incorrect because Spanning Tree Protocol (STP) root bridge election affects Layer 2 switching topology, not Layer 3 NAT translation or routing on the WAN interface.

C

Incorrect because voice VLAN configuration on branch access switches does not influence NAT translation or whether private IP addresses are translated on the WAN interface.

D

Incorrect because a loopback interface IP address does not affect PAT translation of inside user traffic; PAT depends on NAT ACLs and routing, not loopback IP addresses.

When would these options actually be correct?

B

In a different scenario, if the question involved issues with VLANs and STP configurations affecting traffic flow between multiple switches, a candidate might need to identify the root bridge to ensure proper traffic forwarding, making this option relevant.

C

In a different scenario where the question specifies that voice traffic is prioritized over data traffic and there are issues with voice traffic not reaching the WAN, a voice VLAN could be the correct answer if the configuration of the VLAN is misconfigured, preventing proper communication.

D

In a scenario where the question asks about routing issues or path selection in a network where multiple loopback interfaces exist, a loopback interface with a higher IP address could be the correct answer if it is being used as a next-hop address for routing decisions, affecting connectivity.

Why candidates pick the wrong answer

B

Candidates may mistakenly associate STP with connectivity issues, believing that problems in Layer 2 could impact Layer 3 operations like NAT, leading them to select this option despite its irrelevance to the question.

C

Candidates may confuse VLAN configurations with routing issues, thinking that any misconfiguration related to VLANs could affect overall network connectivity, leading them to mistakenly select this option.

D

Candidates may be tempted by this option due to a misunderstanding of how routing and NAT interact, thinking that the loopback interface's configuration might influence the NAT process or connectivity to external networks.

1070
MCQmedium

A client receives an IP address but cannot reach remote networks. Which DHCP option is most likely missing or incorrect?

A.DNS server option
B.Lease time option
C.Default gateway option
D.TFTP server option
AnswerC

The DHCP 'Default Gateway' option (router option) supplies the client with the IP address of the local router that provides exit from the subnet. Without a correct gateway address, the client does not know where to forward packets destined for non-local networks, so it attempts to ARP for the destination address directly and ultimately drops the traffic. This is why an incorrect or missing gateway prevents all off-subnet communication.

Why this answer

The client can obtain an IP address but cannot reach remote networks, which indicates that the DHCP server is not providing the default gateway (option 3). Without a default gateway, the client has no route to destinations outside its local subnet, so traffic to remote networks is dropped. The DHCP server must be configured to supply the router's IP address as the default gateway for clients to forward inter-network traffic.

Exam trap

Cisco often tests the distinction between DHCP options by presenting a symptom like 'can't reach the internet' and expecting candidates to recognize that the default gateway (option 3) is the critical missing piece, not DNS or lease time.

Why the other options are wrong

A

The DNS server option is not critical for basic connectivity to remote networks; it primarily affects name resolution. If a client can obtain an IP address but cannot reach remote networks, the issue is more likely related to the default gateway configuration.

B

The lease time option specifies how long a DHCP lease is valid, but it does not affect the ability to reach remote networks. Therefore, a missing or incorrect lease time would not directly cause connectivity issues.

D

The TFTP server option is not necessary for a client to reach remote networks, as it primarily facilitates file transfers and does not impact routing or network accessibility. Therefore, its absence would not directly cause connectivity issues to remote networks.

When would these options actually be correct?

A

In a different scenario where the question specifies that clients can access local resources but fail to resolve domain names, the DNS server option would be the correct answer. For example, if the client can ping local IPs but not external domains, the DNS configuration would be the likely issue.

B

In a different scenario, if a question asks about DHCP configurations affecting client connectivity specifically related to lease durations, a missing lease time option could lead to clients not being able to renew their IP addresses, thus causing connectivity issues.

D

In a scenario where a question asks about a client that can reach local resources but cannot download files from a remote server, the TFTP server option could be missing or incorrectly configured. This would directly affect the client's ability to access TFTP services, making this option correct in that context.

Why candidates pick the wrong answer

A

Candidates may choose this option because they associate DNS with network connectivity issues, especially if they have encountered problems where name resolution failures caused access issues. This can lead to confusion about the role of DNS in overall network functionality.

B

Candidates may confuse the lease time option with overall network connectivity, thinking that if a client cannot reach remote networks, it could be due to lease issues rather than routing configurations.

D

Candidates may be tempted by this option because TFTP is often associated with network services and can seem relevant when discussing connectivity issues, leading them to mistakenly believe it could impact overall network access.

1071
MCQeasy

A network engineer is configuring a Cisco router that must forward all traffic destined to unknown networks to the next-hop 192.0.2.1. The engineer enters the command ip route 0.0.0.0 0.0.0.0 192.0.2.1. After this configuration, which routing table entry will be created?

A.A static route for 0.0.0.0/32 via 192.0.2.1
B.A dynamic route learned via a routing protocol
C.A directly connected route for 192.0.2.0/24
D.A static route for 0.0.0.0/0 via 192.0.2.1
AnswerD

This command creates an IPv4 default static route. The destination 0.0.0.0 with mask 0.0.0.0 matches all packets that do not have a more specific route, and the next-hop is the specified IP address. It appears in the routing table as a candidate default route, often shown as S* 0.0.0.0/0.

Why this answer

The command ip route 0.0.0.0 0.0.0.0 192.0.2.1 defines a default static route. The destination prefix 0.0.0.0/0 matches any IPv4 address, making it the least specific route. If no other route matches a packet's destination, this default route is used.

It is a static route and appears in the routing table with a source code of S and a candidate default marker.

Exam trap

The trap here is confusing the mask 0.0.0.0 with a host route (/32) instead of recognizing it as the default route prefix /0.

1072
MCQmedium

A network automation script sends this HTTP request to a controller API: POST /api/v1/devices What does the POST method typically indicate in a RESTful API?

A.It retrieves an existing resource without changing it
B.It creates a new resource or submits data to be processed
C.It deletes the targeted resource permanently
D.It replaces the entire existing resource in an idempotent way
AnswerB

Correct. This is correct. POST commonly creates a new resource or submits data to the API for processing. In automation questions, that usually means the script is asking the controller to add something or perform an action using the payload it sends.

Why this answer

POST usually means the client is submitting information to create a new resource or asking the server to process the provided payload. In a controller-based networking context, that often means onboarding a device, creating an object, or starting a workflow. This question is testing method recognition rather than deep programming skill.

GET is commonly used for retrieval, DELETE for removal, and PUT for full replacement or update behavior that is typically idempotent. POST is different because repeating the same POST can create multiple objects or trigger repeated actions, depending on the API design. For CCNA purposes, the plain-English takeaway is simple: POST is generally associated with create-or-submit behavior, not read-only retrieval.

Exam trap

Remember that POST is for creating resources, not retrieving, deleting, or updating them.

Why the other options are wrong

A

Option A is incorrect because the POST method is not used for retrieving resources; instead, it is intended for creating new resources or submitting data for processing in a RESTful API context.

C

The POST method is used to create or submit data, not to delete resources. Option C incorrectly describes the function of the DELETE method in RESTful APIs, which is responsible for removing resources.

D

Option D is incorrect because the POST method is not idempotent and does not replace an existing resource; it is primarily used to create new resources or submit data.

When would these options actually be correct?

A

If the question were to ask about the HTTP GET method instead of POST, option A would be correct, as GET is specifically designed to retrieve existing resources without making any changes to them.

C

If the question were to ask about the DELETE method in a RESTful API context, stating that it permanently deletes a targeted resource would be correct. For example, a question could ask, 'What does the DELETE method typically indicate in a RESTful API?'

D

If the question were to ask about the PUT method instead of POST, and the context specified that the operation was intended to update an existing resource, then option D would be correct as PUT is idempotent and replaces the entire resource.

Why candidates pick the wrong answer

A

Candidates may choose this option due to a misunderstanding of HTTP methods, confusing POST with GET, or recalling that some methods can retrieve data without modification, leading to an incorrect association.

C

Candidates may confuse the POST method with other HTTP methods due to overlapping functionalities in API design, leading them to mistakenly associate POST with deletion instead of creation.

D

Candidates may confuse the POST method with the PUT method, as both are used to modify resources, leading them to mistakenly believe that POST can also replace existing resources.

1073
MCQhard

A company wants unauthorized devices plugged into unused wall ports to have as little chance of gaining access as possible. Which action most directly supports that goal?

A.Administratively disable unused switch ports.
B.Convert every unused port into a trunk.
C.Enable Telnet on unused ports for monitoring.
D.Remove all VLAN assignments from active user ports.
AnswerA

Administratively disabling unused switch ports, typically with the shutdown command in interface configuration mode, places the port in an administratively down state so no device can establish link connectivity or pass traffic. This directly eliminates the exposure of unneeded wall jacks because even if a rogue device is physically plugged in, the switch will not forward frames or negotiate an active Layer 1 link. Unlike VLAN or trunk adjustments, this hardening step does not alter the operation of active user ports and is the industry-standard first-line defense against unauthorized access to unused infrastructure.

Why this answer

Administratively shutting down unused switch ports most directly supports the goal because it eliminates the access point entirely. Option B, converting unused ports into trunks, would actually increase risk by potentially allowing VLAN hopping and unauthorized traffic. Option D, removing VLAN assignments from active user ports, does not address unused ports and could disrupt legitimate users by forcing them into the default VLAN.

Disabling unused ports is a simple and effective hardening measure that reduces attack surface.

Exam trap

Don't confuse methods that limit or monitor access with those that completely prevent it. Focus on actions that eliminate the risk entirely.

Why the other options are wrong

B

Converting unused ports into a trunk does not prevent unauthorized access; it actually allows multiple VLANs to be carried over a single link, potentially exposing sensitive data. This action could inadvertently grant access to unauthorized devices if they connect to these trunked ports.

C

Enabling Telnet on unused ports does not prevent unauthorized access; instead, it creates a potential security vulnerability by allowing remote access to those ports. This action could expose the network to unauthorized monitoring or control.

D

Removing VLAN assignments from active user ports does not prevent unauthorized devices from accessing the network; it could disrupt legitimate user access instead. The goal is to secure unused ports, not impact active ones.

When would these options actually be correct?

B

If the question asked about optimizing network performance or allowing multiple VLANs for a specific purpose, converting unused ports into a trunk could be the correct answer. For instance, if a network administrator needs to consolidate VLAN traffic for efficiency, this option would be appropriate.

C

If the question asked about monitoring and managing network traffic on all ports, including unused ones, enabling Telnet could be seen as a way to track unauthorized access attempts. In such a scenario, the focus would be on visibility rather than prevention.

D

In a scenario where the question asks how to enhance security by isolating user devices from unauthorized access, and specifically mentions VLAN management, removing VLAN assignments from active ports could be correct if it prevents unauthorized access by segmenting the network effectively.

Why candidates pick the wrong answer

B

Candidates may choose this option because they associate trunk ports with increased network capacity and flexibility, mistakenly believing that it enhances security by managing VLANs effectively, rather than recognizing the security implications of unauthorized access.

C

Candidates may choose this option because they associate Telnet with network management and monitoring, mistakenly believing that enabling it on unused ports would provide oversight and security against unauthorized access.

D

Candidates may choose this option thinking that removing VLAN assignments would enhance security by limiting access points, not realizing that it could inadvertently disrupt legitimate user connectivity.

1074
MCQhard

A switchport connected to another switch is configured with `switchport mode dynamic auto` on both ends. What is the most likely outcome if neither side actively negotiates trunking?

A.The link is likely to remain non-trunking because both sides are waiting passively.
B.The link always becomes a trunk immediately.
C.The link becomes a routed Layer 3 link.
D.All VLANs are deleted from both switches.
AnswerA

On a switchport configured with dynamic auto, the interface passively listens for DTP frames but does not actively send them. Since the neighboring switch is also in dynamic auto, neither side initiates a trunk negotiation, so DTP never completes and the link remains in its default access mode, functioning as a normal nontrunking port.

Why this answer

If both ends are set to dynamic auto, the most likely outcome is that the link does not become a trunk automatically. In plain language, both interfaces are waiting passively for the other side to initiate the negotiation. Since neither side is actively trying to form the trunk, the link typically remains non-trunking unless one side is changed to a more active mode or trunk is configured directly.

This is a classic DTP behavior question because it tests whether you understand the difference between active and passive negotiation roles. The correct answer is the one that reflects the passive nature of dynamic auto on both sides.

Exam trap

Be careful not to confuse dynamic auto with dynamic desirable. Only dynamic desirable actively negotiates trunking.

Why the other options are wrong

B

This option is wrong because `switchport mode dynamic auto` does not force immediate trunking; it relies on negotiation, and if neither side actively negotiates, the link remains non-trunking.

C

This option is wrong because a switchport configured with `switchport mode dynamic auto` does not automatically convert to a routed Layer 3 link unless explicitly configured to do so. The default behavior is to remain in access mode unless trunking is negotiated.

D

Option D is incorrect because configuring `switchport mode dynamic auto` does not delete VLANs; it merely affects trunk negotiation. VLANs remain configured on the switches regardless of trunking status.

When would these options actually be correct?

B

In a different scenario where both switches are configured with `switchport mode trunk`, the link would always become a trunk immediately upon connection, regardless of negotiation. A question could specify that both ends are set to trunk mode, leading to this outcome.

C

In a different scenario, if the question specified that both switches were configured with `switchport mode access` and there was no trunk negotiation, then the link would indeed operate as a routed Layer 3 link if the switches were configured to route traffic.

D

In a different scenario where a question states that a switchport is configured to delete VLAN information upon a specific command or configuration change, option D could be correct. For example, if the question involved a command that explicitly removes VLAN configurations, then this option would apply.

Why candidates pick the wrong answer

B

Candidates may choose this option due to a misunderstanding of dynamic trunking protocols, mistakenly believing that any configuration involving 'dynamic' would automatically result in trunking without considering the negotiation process.

C

Candidates may choose this option due to a misunderstanding of switchport modes and the assumption that dynamic configurations imply automatic Layer 3 functionality, leading to confusion between access and trunking modes.

D

Candidates may find this option tempting due to a misunderstanding of how switchport configurations impact VLANs, leading them to incorrectly associate trunking negotiation failures with VLAN deletion.

1075
MCQhard

Refer to the exhibit. A network engineer is troubleshooting an ACL that is not filtering traffic as expected. The engineer runs the show access-lists 110 command and notices that all access control entries (ACEs) show zero matches, even though traffic that should match the permit or deny statements is traversing the network. The engineer then checks the interface configuration. What is the most likely cause?

A.The ACL is applied to the interface in the wrong direction (inbound instead of outbound).
B.The access-list 110 syntax has incorrect subnet masks causing no matches.
C.The ACL 110 is not applied to any interface.
D.The interface GigabitEthernet0/0 is administratively down, preventing ACL processing.
AnswerC

The 'Inbound access list is not set' and 'Outgoing access list is not set' lines in the exhibit directly prove that no ACL has been applied to GigabitEthernet0/0. Since ACL 110 exists but isn't attached to any interface, it never processes traffic and shows zero hit counts.

Why this answer

If an ACL is not applied to any interface, it will never process traffic, and the 'show access-lists' command will show zero matches for all ACEs. The engineer confirmed that traffic matching the ACL entries is traversing the network, but the ACL counters remain at zero, which directly indicates that the ACL is not being invoked by any interface configuration. Applying an ACL to an interface with the 'ip access-group' command is required for it to filter traffic.

Exam trap

Cisco often tests the distinction between creating an ACL and applying it to an interface, trapping candidates who assume that simply defining an ACL with 'access-list' commands is enough to filter traffic, when in fact the 'ip access-group' command under the interface is mandatory for the ACL to take effect.

Why the other options are wrong

A

A common mistake is to try to explain zero matches by directional misapplication without first checking whether an ACL is actually present. The exhibit explicitly shows no ACL is bound.

B

Some candidates fixate on ACL configuration details instead of verifying interface assignment. The output confirms the interface has no ACL, not that an ACL is configured incorrectly.

D

Candidates sometimes misread interface status. This output clearly shows the interface is enabled and up, so a down state is not the issue.

1076
MCQhard

Why is administratively shutting down unused switch ports considered a useful hardening measure?

A.It reduces the attack surface by removing unnecessary network entry points.
B.It increases available bandwidth on the switch backplane.
C.It enables 802.1Q trunking on all remaining ports.
D.It forces port security to activate automatically.
AnswerA

An unused enabled switchport is a potential access point for unauthorized devices, allowing threats such as ARP spoofing, DHCP starvation, or rogue access points. Administratively shutting it down disables the physical layer, preventing any frames from entering or leaving that interface and eliminating this entry vector. This is a fundamental network-hardening practice that reduces the attack surface without affecting other ports.

Why this answer

Unused active ports create unnecessary opportunity for unauthorized connection. Disabling them reduces the attack surface and makes opportunistic access much harder. Option B is incorrect because administratively shutting down a port does not increase backplane bandwidth; bandwidth is a fixed hardware characteristic.

Option C is incorrect because shutting down ports does not enable 802.1Q trunking; trunking is configured separately. Option D is incorrect because port security must be explicitly enabled; it is not activated automatically by shutting down ports.

Exam trap

Do not confuse port shutdown with network performance improvements or IP address management. Focus on security implications.

Why the other options are wrong

B

This option is incorrect because shutting down unused switch ports does not directly increase available bandwidth; rather, it is a security measure to minimize potential vulnerabilities. Bandwidth on the switch backplane is determined by the overall switch architecture and the active ports' configurations, not by disabling unused ports.

C

This option is wrong because administratively shutting down unused switch ports does not enable 802.1Q trunking; trunking is a configuration that allows multiple VLANs to traverse a single physical link, which is unrelated to the status of unused ports.

D

This option is wrong because administratively shutting down unused switch ports does not automatically activate port security; it is a separate configuration that must be enabled explicitly on the switch.

When would these options actually be correct?

B

In a question focused on optimizing network performance, such as 'What actions can improve the overall bandwidth efficiency of a switch?', this option could be correct if it specifies that shutting down unused ports can help allocate resources more effectively by reducing unnecessary traffic on the switch.

C

In a question focused on VLAN configuration, where the context is about optimizing trunking capabilities across a switch, stating that enabling 802.1Q trunking on all remaining ports is correct could be valid. For example, if the question asks how to ensure that all active ports can handle multiple VLANs efficiently, this option could be correct.

D

In a question asking about the benefits of enabling port security on a switch, one might state that shutting down unused ports can help ensure that port security is enforced on active ports, as it reduces the risk of unauthorized access through unused ports.

Why candidates pick the wrong answer

B

Candidates may be tempted by this option because they associate port management with performance improvements, leading them to believe that disabling ports could somehow enhance bandwidth availability.

C

Candidates may choose this option due to a misunderstanding of the relationship between port status and VLAN configurations, mistakenly believing that shutting down ports directly facilitates trunking capabilities.

D

Candidates may choose this option because they associate port security with overall network security and might mistakenly believe that shutting down ports triggers security features automatically, reflecting a misunderstanding of how these configurations interact.

1077
MCQhard

A non-root switch has two uplinks toward the root bridge. One path has a lower total STP cost than the other. What role will the lower-cost uplink have?

A.Alternate port
B.Root port
C.Designated port
D.Disabled port
AnswerB

The root port is selected on each non-root bridge by comparing received BPDUs; the port with the lowest cumulative root path cost (with tie-breaking rules) becomes the root port, placing it in the forwarding state. This is the port that provides the single best path toward the root bridge, carrying all upstream traffic. Since the non-root switch has two uplinks, the one with the lower cost to the root is the root port.

Why this answer

On a non-root switch, the port with the lowest path cost toward the root bridge becomes the root port. The higher-cost uplink would become an alternate (blocked) port. A designated port is found on the upstream switch toward this switch, not on the non-root switch itself.

A disabled port is administratively shut down, which does not apply here.

Exam trap

Remember, the root port is determined by the lowest path cost to the root bridge, not by any other criteria.

Why the other options are wrong

A

The higher-cost uplink becomes an alternate (blocked) port, not the lower-cost one.

C

A designated port exists on the upstream switch toward this switch, not on the non-root switch.

D

A disabled port is administratively shut down, not a port with a lower STP cost.

When would these options actually be correct?

A

In a different scenario where a switch has multiple uplinks and one link fails, the remaining uplink with a higher cost could be designated as an alternate port, providing a backup path to the root bridge while the primary path is down.

C

In a different scenario, if the question stated that a switch has multiple segments and one of the uplinks is the only connection to a segment with multiple switches, then that uplink could be designated if it has the lowest cost to the root bridge for that segment.

D

In a different scenario, if a switch is configured with a specific port that has been administratively shut down or if the STP has determined that the port should not be used due to a loop or misconfiguration, the question might ask about the status of that port, making 'disabled port' the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse the roles of ports in STP, especially if they focus on the presence of multiple uplinks and mistakenly associate lower-cost paths with alternate roles instead of recognizing the active forwarding role of the root port.

C

Candidates might confuse the roles of ports in STP, thinking that any port involved in forwarding traffic could be designated, especially if they overlook the specific context of uplinks and cost comparisons.

D

Candidates may confuse the concept of port states in STP and mistakenly think that a lower-cost path could be disabled due to misconfigurations or administrative actions, leading them to choose this option.

1078
PBQhard

You are connected to R1 (192.0.2.1/24). Use RESTCONF to query the operational state of GigabitEthernet0/0 using the ietf-interfaces YANG module. Then, send a PATCH request to disable the interface (set 'enabled' to false) using the Cisco-IOS-XE-native YANG module. Identify the error when a PATCH request is sent with the wrong Content-Type header (application/json instead of application/yang-data+json) and when the PATCH URI uses an incorrect YANG path (ietf-interfaces instead of Cisco-IOS-XE-native).

Hints

  • •RESTCONF requires Content-Type: application/yang-data+json for write operations.
  • •The ietf-interfaces module is read-only for operational state; use Cisco-IOS-XE-native for configuration changes.
  • •Check the URI path: /restconf/data/ followed by the YANG module and container/leaf.
A.The PATCH request fails with a 415 Unsupported Media Type error because the Content-Type header must be application/yang-data+json, not application/json.
B.The PATCH request fails with a 404 Not Found error because the URI uses ietf-interfaces, which is a read-only module for operational state; the server cannot write to it.
C.The PATCH request succeeds but the interface is not disabled because the body must use 'shutdown' instead of 'enabled'.
D.The PATCH request fails with a 400 Bad Request error because the body must be XML, not JSON.
AnswerA
solution
! R1
GET /restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet0/0 --header 'Accept: application/yang-data+json'
PATCH /restconf/data/Cisco-IOS-XE-native:native/interface/GigabitEthernet=0/0 --header 'Content-Type: application/yang-data+json' -d '{"Cisco-IOS-XE-native:interface":{"GigabitEthernet":[{"name":"0/0","shutdown":true}]}}'

Why this answer

The correct GET request uses the ietf-interfaces YANG module path to retrieve interface state. For the PATCH, the Cisco-IOS-XE-native module is used because it supports writing native configuration (including shutdown). Sending PATCH with Content-Type: application/json is rejected because RESTCONF requires application/yang-data+json.

Using ietf-interfaces in the PATCH URI fails because that module is read-only for operational state; the server returns 404 or 405. The correct PATCH body sets 'shutdown' to true within the native interface container.

Exam trap

The trap is that candidates may focus on the YANG module path error (ietf-interfaces vs Cisco-IOS-XE-native) and miss that the question explicitly asks about the error when the Content-Type header is wrong. Always read the question carefully to identify the specific condition being tested.

Why the other options are wrong

B

The specific factual error is that the question asks about the error when the Content-Type header is wrong, not the URI path. The URI path error is a separate issue.

C

The specific factual error is that a wrong Content-Type header causes a rejection before any body parsing, so the request does not succeed.

D

The specific factual error is that RESTCONF does accept JSON; the issue is the exact media type string, not the format.

Why candidates pick the wrong answer

B

Candidates might pick this because they know that ietf-interfaces is read-only and that using it in a PATCH would fail, but they overlook that the question is specifically about the Content-Type header error.

C

Candidates might think that the server might accept the request but ignore the 'enabled' field, not realizing that the Content-Type error prevents processing.

D

Candidates might confuse RESTCONF with NETCONF, which uses XML, or think that JSON is not supported, but RESTCONF supports both.

1079
MCQhard

Clients in VLAN 30 are not receiving addresses from the DHCP server located in VLAN 99. Which configuration change should be made on the Layer 3 interface for VLAN 30?

A.Add ip dhcp snooping trust under interface Vlan30.
B.Add switchport mode trunk under interface Vlan30.
C.Add ip default-gateway 10.99.99.20 under interface Vlan30.
D.Add ip helper-address 10.99.99.20 under interface Vlan30.
AnswerD

This is correct because the SVI for VLAN 30 is the interface that receives the client DHCP broadcasts. By adding `ip helper-address 10.99.99.20`, the Layer 3 device forwards the request as a unicast packet to the DHCP server in VLAN 99.

Why this answer

The DHCP server is on a different subnet, so the client broadcast messages from VLAN 30 will not naturally cross the Layer 3 boundary. In simple terms, the clients are asking for an address by shouting on their own floor of the building, but the server lives on another floor and cannot hear that broadcast directly. The router or Layer 3 switch must relay the request for them. On Cisco devices, that relay function is usually configured with `ip helper-address` on the interface that receives the client broadcasts.

Here, that receiving interface is Vlan30, because that is the default gateway for the clients in VLAN 30. Pointing `ip helper-address` to 10.99.99.20 tells the Layer 3 device to forward DHCP requests to the remote server. DHCP snooping trust is a separate security feature, trunk mode is unrelated to an SVI, and `ip default-gateway` is not the correct solution for relaying DHCP across subnets.

Exam trap

Remember that DHCP snooping and trunk mode do not facilitate DHCP relay. Focus on the purpose of `ip helper-address` for relaying requests across VLANs.

Why the other options are wrong

A

This option is wrong because enabling DHCP snooping trust on VLAN 30 does not facilitate communication with the DHCP server in VLAN 99; it only protects against rogue DHCP servers.

B

Adding 'switchport mode trunk' under interface Vlan30 is incorrect because VLAN 30 is already configured as a Layer 3 interface, and trunking is not applicable to Layer 3 interfaces. This command is used for Layer 2 interfaces to allow multiple VLANs over a single link.

C

This option is wrong because the command 'ip default-gateway' is used to set a default gateway for a Layer 2 device, not for enabling DHCP relay on a Layer 3 interface. Clients in VLAN 30 need a helper address to reach the DHCP server in VLAN 99.

When would these options actually be correct?

A

In a different scenario where the question asks about securing a network with multiple VLANs and preventing unauthorized DHCP servers, adding 'ip dhcp snooping trust' under interface Vlan30 would be correct to allow trusted DHCP responses from a legitimate server.

B

In a different scenario where the question asks about configuring a Layer 2 switch port that connects to another switch, and the requirement is to allow multiple VLANs to traverse that link, 'switchport mode trunk' would be the correct configuration to enable trunking on that interface.

C

In a scenario where the question asks about configuring a Layer 2 switch that needs to communicate with a router for routing purposes, using 'ip default-gateway 10.99.99.20' would be correct to ensure the switch can reach the router for management traffic.

Why candidates pick the wrong answer

A

Candidates may choose this option due to a misunderstanding of DHCP snooping, believing that it directly relates to the DHCP process rather than its role in securing the network against rogue servers.

B

Candidates may choose this option because they might confuse Layer 3 interfaces with Layer 2 configurations, thinking that trunking is necessary for VLAN communication, especially if they are familiar with VLAN setups in general.

C

Candidates may choose this option because they recognize the need for a default gateway for devices in a VLAN, mistakenly believing it applies to enabling DHCP services instead of understanding the specific role of DHCP relay.

1080
Matchingmedium

Drag and drop the route types on the left to the correct administrative distance and use case descriptions on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

AD 1; manually configured path

AD 5; backup route when primary fails

AD 1; catch-all for unknown destinations

AD 110; used for internal routing within an AS

AD 0; network directly attached to router interface

Why these pairings

All the given pairings are correct. Connected routes use AD 0 because they are directly connected. Static routes use AD 1 as they are manually configured.

EIGRP internal routes have AD 90, and OSPF routes have AD 110; both are IGPs used for routing within the same autonomous system.

Exam trap

A common mistake is confusing the AD values of connected (0) and static (1). Also, note that EIGRP internal (90) and OSPF (110) are both IGPs but with different ADs; some might incorrectly assign OSPF an AD of 90.

1081
MCQhard

A network administrator is configuring a Cisco router with two interfaces: GigabitEthernet0/0 and GigabitEthernet0/1. The administrator wants to configure a static route to the 10.1.1.0/24 network via the next-hop IP address 192.168.1.2. Which command correctly accomplishes this?

A.ip route 10.1.1.0 255.255.255.0 GigabitEthernet0/0
B.ip route 10.1.1.0 255.255.255.0 192.168.1.2 name BACKUP
C.ip route 10.1.1.0 255.255.255.0 192.168.1.2 10
D.ip route 10.1.1.0 255.255.255.0 192.168.1.2
AnswerD

This command creates a static route for the 10.1.1.0/24 network with the next-hop address 192.168.1.2. The syntax ip route destination_network subnet_mask next_hop is correct for Cisco IOS. It tells the router to forward packets destined for 10.1.1.0/24 to the next-hop router at 192.168.1.2. This is the standard way to configure a static route.

Why this answer

The correct command to configure a static route with a next-hop IP address is ip route destination_network subnet_mask next_hop. In this case, ip route 10.1.1.0 255.255.255.0 192.168.1.2 is correct. It installs a route to 10.1.1.0/24 via 192.168.1.2.

Other options either use an exit interface instead of the next-hop, add an unnecessary administrative distance, or incorrectly include a name parameter.

Exam trap

The trap here is misremembering the static route syntax, such as placing the administrative distance before the next-hop or confusing the order of parameters.

1082
MCQhard

A subnet has the network address 192.168.20.128/26. What is the broadcast address?

A.192.168.20.159
B.192.168.20.191
C.192.168.20.192
D.192.168.20.255
AnswerB

192.168.20.191 is the broadcast address for the 192.168.20.128/26 subnet. A /26 prefix leaves 6 host bits (32-26=6), yielding 2^6=64 addresses per subnet. Starting at network address .128, the valid addresses run from .129 through .190, and .191 is the final address (broadcast) before the next subnet begins at .192.

Why this answer

A /26 subnet uses blocks of 64 addresses. In plain language, the block that starts at 192.168.20.128 runs through 192.168.20.191. The first address in that block is the network address, and the last address is the broadcast address. That means the broadcast address is 192.168.20.191.

This is a standard subnetting calculation. Once the block size is identified, the broadcast address is simply the last address in the block.

Exam trap

Be careful not to confuse the broadcast address with the first address of the next subnet or with the broadcast address of a different subnet mask.

Why the other options are wrong

A

Option A (192.168.20.159) is incorrect because the broadcast address for the subnet 192.168.20.128/26 is 192.168.20.191, calculated as the highest address in the subnet range from 192.168.20.128 to 192.168.20.191.

C

The option C, 192.168.20.192, is incorrect because it falls outside the range of the subnet defined by 192.168.20.128/26, which has a valid broadcast address of 192.168.20.191.

D

The broadcast address for the subnet 192.168.20.128/26 is 192.168.20.191, not 192.168.20.255. The address 192.168.20.255 is the broadcast address for the entire 192.168.20.0/24 network, which is not relevant to the specified subnet.

When would these options actually be correct?

A

If the question specified a subnet mask of /25 instead of /26, the network address would be 192.168.20.128 and the broadcast address would then be 192.168.20.159, making this option correct.

C

If the question specified a different subnet, such as 192.168.20.192/26, then option C would be the correct broadcast address for that subnet, as it would encompass the range from 192.168.20.192 to 192.168.20.255.

D

If the question asked for the broadcast address of the entire 192.168.20.0/24 network instead of the specific /26 subnet, then 192.168.20.255 would be the correct answer, as it serves as the broadcast address for that larger subnet.

Why candidates pick the wrong answer

A

Candidates may choose this option due to confusion between subnet ranges, mistakenly calculating the broadcast address by incorrectly interpreting the subnet mask or misaligning the address range.

C

Candidates might choose this option due to confusion between the subnet address and the broadcast address, especially if they miscalculate the range or overlook the CIDR notation.

D

Candidates may choose this option due to familiarity with the concept of broadcast addresses, often associating the highest address in a subnet with the broadcast address without considering the specific subnet mask provided.

1083
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure BPDU Guard, Loop Guard, and Root Guard on a Cisco switch.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
6Step 6
7Step 7

Why this order

The correct order starts by entering global configuration mode, then globally enabling PortFast on all access ports to allow immediate transition to forwarding state. BPDU Guard is then enabled globally on all PortFast-enabled ports to protect against unauthorized switches. Next, Loop Guard is enabled globally to prevent loops from unidirectional links.

Afterwards, the specific uplink interface is selected and Root Guard is applied to prevent a rogue switch from becoming the root bridge. This sequence follows Cisco best practices: apply fast convergence first, then protect the edge with BPDU Guard, apply loop prevention globally, and finally secure core links with Root Guard.

1084
MCQmedium

A host at 192.168.50.10/24 needs to send traffic to 192.168.60.20. Which MAC address will it normally place in the Ethernet destination field for the first frame?

A.The MAC address of the remote host at 192.168.60.20
B.The broadcast MAC address only
C.The MAC address of its configured default gateway
D.Its own source MAC address
AnswerC

When a host must send traffic to an IP address outside its local subnet (like 192.168.60.x from 192.168.50.0/24), it cannot resolve that remote IP to a MAC address via ARP, since ARP is confined to the local broadcast domain. Instead, the host looks up its routing table, identifies the configured default gateway as the next hop, and ARPs for that gateway's IP address to obtain its MAC. The resulting Ethernet frame then uses the gateway's MAC as the destination L2 address, while the destination IP remains the remote host's address, relying on the router to perform Layer 3 forwarding.

Why this answer

When a host wants to send traffic to a different IP subnet, it does not send the frame directly to the remote device’s MAC address. In plain language, the host knows the destination IP is off its local network, so it hands the traffic to the local router. That means the Ethernet frame is addressed to the default gateway’s MAC address, while the IP packet inside still carries the final remote IP destination.

A host uses ARP to learn MAC addresses on its own LAN. Since the remote host is not local, the sender does not ARP for the remote host’s MAC. Instead, it ARPs for the gateway interface on the same subnet.

Exam trap

A frequent exam trap is selecting the remote host’s MAC address as the Ethernet destination for off-subnet traffic. This is incorrect because ARP requests cannot resolve MAC addresses beyond the local subnet. Candidates may confuse IP routing with MAC addressing and assume direct frame delivery to the remote device.

The trap lies in overlooking the default gateway’s role as the local next-hop device that receives frames destined for remote IPs. Remember, the host always sends the frame to the gateway’s MAC, not the remote host’s MAC, when the destination is outside the local subnet.

Why the other options are wrong

A

Incorrect because the remote host’s MAC address is not known to the sender and cannot be resolved via ARP across subnets. The host must send to the gateway’s MAC instead.

B

Incorrect because broadcast MAC addresses are used only for ARP requests or broadcast traffic, not for normal unicast data frames to a specific remote IP.

D

Incorrect because a device’s own MAC address is used as the source MAC in frames it sends, never as the destination MAC.

When would these options actually be correct?

A

In a scenario where both hosts are on the same subnet (e.g., 192.168.50.0/24), a question might ask what MAC address a host would use to communicate directly with another host on the same network. In that case, the MAC address of the remote host at 192.168.60.20 would be correct.

B

In a scenario where a host is broadcasting a message to all devices on the local network segment, such as an ARP request to discover the MAC address of 192.168.60.20, the broadcast MAC address (FF:FF:FF:FF:FF:FF) would be the correct choice.

D

In a different question where a host needs to send traffic to a device on the same local network, and the question specifies that the destination is reachable directly, the host would place its own MAC address in the source field while the destination MAC would be that of the intended recipient.

Why candidates pick the wrong answer

A

Candidates may choose this option due to a misunderstanding of MAC address resolution, thinking that the destination MAC address is always needed for any communication, regardless of subnetting.

B

Candidates might choose this option because they recall that broadcast messages are used for network discovery and may confuse it with the need to reach a host outside the local subnet.

D

Candidates may choose this option because they might confuse the source MAC address with the destination MAC address, thinking that the host would use its own address in the Ethernet frame for communication.

1085
MCQhard

Refer to the exhibit. A network engineer is troubleshooting a missing route on R1. The router R3 is configured to advertise network 192.168.30.0/24 via OSPF, but the route is not present in the OSPF routing table of R1 when issuing the show ip route ospf command. What is the most likely cause?

A.R3 has not enabled OSPF on the network 192.168.30.0/24 using the network command.
B.R3 has passive-interface default configured and has not issued the no passive-interface command on the interface facing the OSPF neighbor.
C.R1 has an inbound ACL applied to GigabitEthernet0/1 that blocks OSPF multicast traffic to 224.0.0.5 and 224.0.0.6.
D.R3's OSPF router ID is duplicated with another OSPF router, causing the SPF algorithm to drop routes.
AnswerB

Passive-interface default suppresses OSPF hello packets on all interfaces unless explicitly enabled. Without hellos, an adjacency cannot form, so R1 never learns the 192.168.30.0/24 route. The exhibit shows OSPF working with another neighbor, confirming the problem is isolated to R3’s interface configuration.

Why this answer

R3 has passive-interface default configured, which makes all interfaces passive by default, preventing OSPF hello packets from being sent. Without the no passive-interface command on the interface facing R1, R3 cannot form an OSPF adjacency, so R1 never learns the 192.168.30.0/24 route. This is a common misconfiguration when using passive-interface default to suppress OSPF on non-neighbor interfaces.

Exam trap

Cisco often tests the passive-interface default behavior where candidates assume that configuring OSPF with a network statement is sufficient to form adjacencies, overlooking that passive-interface default silently blocks hello packets on all interfaces unless explicitly overridden.

Why the other options are wrong

A

The question says R3 advertises the network via OSPF; a missing network command would contradict that, so the failure must be in adjacency formation.

C

The presence of other OSPF routes on the same interface disproves a blanket multicast ACL; the issue is specific to R3’s adjacency.

D

A duplicate router ID could prevent adjacency, but the scenario’s focus on passive-interface default provides a more common and direct cause for a total lack of adjacency when OSPF is correctly configured on the network.

1086
MCQhard

Refer to the exhibit. A network administrator is troubleshooting connectivity issues for hosts on VLAN 50 on SW1. The hosts on VLAN 50 cannot reach any devices outside SW1, even though the trunk link between SW1 and SW2 is up. The administrator issues the 'show interfaces GigabitEthernet0/1 trunk' command on SW1. Based on the output, what is the most likely cause of the issue?

A.The native VLAN on the trunk is misconfigured, causing VLAN 50 traffic to be dropped.
B.The trunk is operating in access mode instead of trunk mode, preventing VLAN 50 traffic.
C.VLAN 50 is not in the allowed VLAN list on the trunk.
D.Spanning tree protocol has blocked the trunk port for VLAN 50, isolating the hosts.
AnswerC

The exhibit's 'Vlans allowed on trunk' line explicitly lists '1-49,60-4094', which omits VLAN 50. This configured allowed list filters which VLANs can traverse the trunk; any VLAN not listed is blocked, even if it is defined on the switch. The absence of VLAN 50 from the allowed list means its frames are dropped at the trunk interface, isolating hosts in VLAN 50 from other switches. This is the exact administrative misconfiguration causing the problem.

Why this answer

The 'show interfaces GigabitEthernet0/1 trunk' output would list the allowed VLANs on the trunk. If VLAN 50 is not included in the allowed VLAN list, traffic from VLAN 50 will be dropped at the trunk, preventing hosts on SW1 from reaching devices outside SW1. This is the most likely cause because the trunk is up but VLAN 50 traffic is not forwarded.

Exam trap

Cisco often tests the distinction between native VLAN misconfiguration and allowed VLAN list misconfiguration, where candidates mistakenly attribute all trunk issues to native VLAN mismatches rather than checking the allowed VLAN list.

Why the other options are wrong

A

The assumption that a native VLAN mismatch can drop tagged VLAN traffic is a common misunderstanding.

B

Misreading the output may lead to believing the trunk is not in trunking mode.

D

Confusing spanning tree blocking with allowed VLAN filtering; the output shows no block state, only absence of the VLAN.

1087
PBQmedium

You are connected to the console of SW1. The network administrator reports that a workstation connected to interface FastEthernet0/1 cannot communicate with the rest of the network. The workstation is configured for VLAN 10, but the interface is in VLAN 1.

Hints

  • •Use 'show vlan brief' to see VLAN assignments.
  • •The interface is currently in VLAN 1.
  • •Change the access VLAN to 10.
A.Configure the interface as a trunk port.
B.Configure the interface as an access port and assign it to VLAN 10.
C.Configure the interface as a trunk port and allow VLAN 10.
D.Configure the interface as a dynamic desirable port.
AnswerB
solution
! SW1
interface FastEthernet0/1
switchport access vlan 10

Why this answer

The workstation is configured for VLAN 10, but the switch interface is in VLAN 1. To restore connectivity, the interface must be configured as an access port and assigned to VLAN 10, matching the workstation's VLAN. This places the port in the correct broadcast domain so the workstation can communicate with other VLAN 10 devices and its gateway.

Exam trap

200-301 often tests the difference between access and trunk port configuration — candidates pick trunk because they think VLAN 10 must be 'allowed', but an end-device port should be an access port in VLAN 10.

Why the other options are wrong

A

Trunk ports are used to carry multiple VLANs between switches, not to assign a single workstation to a specific VLAN.

C

Trunk ports are designed to carry multiple VLANs and are typically used between switches, not for end-user devices.

D

DTP modes control whether a port becomes a trunk or remains an access port; they do not change the access VLAN.

Why candidates pick the wrong answer

A

Candidates might think that because the workstation is in VLAN 10, the port needs to be a trunk to carry that VLAN, but access ports are used for end devices.

C

Candidates might think that allowing VLAN 10 on a trunk would let the workstation communicate, but the workstation is an end device that expects an access port.

D

Candidates might confuse DTP modes with VLAN assignment, thinking that 'dynamic desirable' will automatically put the port in the correct VLAN.

1088
MCQhard

Refer to the exhibit. An administrator is troubleshooting connectivity from a branch router R1 to the internet. A ping to 8.8.8.8 from R1 fails. The output of the show ip route command is shown. What is the most likely cause?

A.The default route is missing from the routing table.
B.The next-hop IP address for the default route is not reachable.
C.The static route has an incorrect administrative distance.
D.The ip routing process has not been enabled.
AnswerB

The default route via 203.0.113.1 is present, but the routing table contains no connected or static route to reach 203.0.113.1. Without a route to the next-hop, the default route cannot be used, causing the ping failure.

Why this answer

The ping to 8.8.8.8 fails because the default route (0.0.0.0/0) points to a next-hop IP address that is not reachable. The routing table shows the default route is present, but if the next-hop address is not in the routing table via a connected or static route, the router cannot resolve the Layer 2 adjacency and will not forward packets. This is confirmed by the fact that the default route exists but the ping fails, indicating a reachability issue with the next hop.

Exam trap

Cisco often tests the misconception that a missing default route is the only reason for internet connectivity failure, but the trap here is that the default route is present yet the next-hop is unreachable, which candidates overlook because they focus solely on the existence of the route rather than its reachability.

Why the other options are wrong

A

Candidates may misinterpret a failed ping as indicating no default route exists, overlooking that the route is present but unusable.

C

Candidates may think a higher AD is blocking the route, but the AD is standard and not the issue.

D

A common troubleshooting step is to verify ip routing, but the exhibit clearly shows an active routing table.

1089
MCQmedium

Why is SSH preferred over Telnet for remote device administration?

A.SSH uses less bandwidth because it removes the TCP header
B.SSH encrypts management traffic, while Telnet sends data in clear text
C.SSH works only on console ports, which are more secure
D.SSH does not require user authentication
AnswerB

SSH encrypts the entire management session using protocols like AES, ensuring that usernames, passwords, and configuration commands are transmitted in ciphertext. Telnet, by contrast, sends all data in plaintext over TCP port 23, so anyone with a packet sniffer can read sensitive credentials and device output. This confidentiality makes SSH the standard for secure remote administration.

Why this answer

SSH protects credentials and management traffic by encrypting the session. Telnet does not provide encryption, so usernames, passwords, and commands can be exposed in transit.

Exam trap

Don't confuse ease of configuration or bandwidth usage with security features. Focus on the encryption aspect of SSH.

Why the other options are wrong

A

This option is incorrect because SSH does not inherently use less bandwidth than Telnet; both protocols utilize TCP, and SSH's encryption actually adds overhead, potentially increasing bandwidth usage.

C

This option is incorrect because SSH can operate over various types of connections, including console ports, but it is not limited to them. Telnet can also be used over console ports, making this statement misleading.

D

This option is incorrect because SSH does require user authentication, typically through passwords or public key authentication, which is essential for secure access. In contrast, Telnet does not enforce strong authentication mechanisms.

When would these options actually be correct?

A

In a different context, a question might ask which protocol is more efficient for low-bandwidth environments without considering security. If the question specifically states that SSH's bandwidth efficiency is being compared in a scenario where TCP header removal is a factor, then this option could be correct.

C

In a question that specifically asks about the security of console port access methods, stating that SSH works only on console ports could be correct if the context implies that SSH is the preferred method for console access due to its encryption capabilities, while Telnet is not secure.

D

In a different exam scenario, if the question asked about protocols that do not require user authentication for remote access, then this option could be correct. For example, a question about unsecured protocols might highlight that Telnet allows access without authentication, making it a valid point in that context.

Why candidates pick the wrong answer

A

Candidates may find this option appealing due to a misunderstanding of how SSH operates, mistakenly believing that its design inherently optimizes bandwidth usage compared to Telnet, especially if they focus on performance over security.

C

Candidates may be drawn to this option because they associate SSH with enhanced security and may mistakenly believe that its use is restricted to more secure environments like console ports, leading to confusion about its actual operational scope.

D

Candidates may find this option tempting due to a misunderstanding of SSH's authentication mechanisms, confusing it with other protocols that might not require authentication, leading to the assumption that SSH operates similarly.

1090
MCQmedium

A branch LAN requires 50 usable IPv4 host addresses. What is the most efficient subnet mask that provides at least 50 usable hosts?

A./27
B./26
C./25
D./24
AnswerB

A /26 prefix has 6 host bits, so 2^6 = 64 total addresses, minus 2 for network and broadcast gives 62 usable hosts. This exactly satisfies the requirement of 50 usable addresses with headroom for future growth, and is the smallest prefix that meets the need, avoiding unnecessary address waste.

Why this answer

A /26 provides 64 total addresses and 62 usable host addresses, which is the smallest subnet mask (largest prefix length) that fits 50 hosts, making it the most efficient choice.

Exam trap

Read the requirement carefully. Cisco often uses subtle wording like 'most efficient' or 'industry standard' to eliminate technically correct but non-optimal answers.

Why the other options are wrong

A

A /27 subnet provides only 30 usable host addresses, which is insufficient for the requirement of 50 usable addresses. Therefore, it does not meet the needs of the branch LAN.

C

Option C: /25 provides 126 usable addresses, which exceeds the requirement of 50 usable addresses. However, it is not the smallest prefix that meets the requirement.

D

Option D, /24, provides 256 total addresses, which exceeds the requirement of 50 usable addresses. However, it is not the smallest prefix that meets the requirement, as /26 provides 64 addresses, which is sufficient and more efficient.

When would these options actually be correct?

A

In a different scenario where a branch LAN only requires up to 30 usable IPv4 host addresses, a question could ask for the smallest prefix that meets this requirement. In that case, /27 would be the correct answer.

C

If the exam question specified a need for at least 50 usable addresses but allowed for additional addresses for future growth, then /25 would be the correct choice, as it provides ample room for expansion while still meeting the minimum requirement.

D

In a scenario where a question specifies a need for a larger subnet to accommodate future growth or additional devices, such as requiring 200 usable addresses, option D (/24) would be the correct choice. This would be appropriate if the network is expected to expand significantly.

Why candidates pick the wrong answer

A

Candidates may choose /27 due to a misunderstanding of subnetting calculations, mistakenly believing that it provides enough addresses or confusing it with a similar option that does meet the requirement.

C

Candidates may choose /25 because they misinterpret the requirement as needing a larger subnet for potential future devices, mistakenly believing that a larger prefix is always better for accommodating growth.

D

Candidates may choose option D because they recognize that /24 offers a large number of addresses and may mistakenly believe that more addresses are always better, overlooking the need for efficiency in subnetting.

1091
MCQhard

Two directly connected routers running OSPFv3 do not form an adjacency. Both interfaces have valid IPv6 addresses and can ping each other using link-local addresses. What is the most likely cause?

A.The interfaces are assigned to different OSPFv3 areas.
B.The routers need global unicast addresses before OSPFv3 can run.
C.The router IDs must be identical before adjacency can form.
D.The link-local addresses must be learned from DHCPv6.
AnswerA

In OSPFv3 (and OSPFv2), each interface belongs to exactly one area. Two routers directly connected on the same link must have that link in the same area to become neighbors; if they differ, the Hello packets are rejected because the Area ID is carried in the OSPF header, and the neighbor relationship stays down.

Why this answer

The most likely cause is an OSPFv3 area mismatch on the interface. In practical terms, OSPFv3 still requires neighbors on the same link to agree on the area assignment, just as OSPF for IPv4 does. Link-local reachability alone is not enough to form an adjacency. The protocol parameters still have to match.

This is an important IPv6 routing point because people sometimes assume that successful IPv6 ping means the routing protocol should automatically work. It does not. Adjacency depends on protocol alignment, not just basic connectivity.

Exam trap

A frequent exam trap is to assume that because two routers can ping each other using IPv6 link-local addresses, their OSPFv3 adjacency should automatically form. This mistake overlooks the critical requirement that both routers must be configured in the same OSPFv3 area. Candidates might also incorrectly believe that global unicast addresses are necessary for OSPFv3 adjacency or that router IDs must be identical.

These misconceptions lead to selecting incorrect answers, as adjacency depends on matching area IDs and unique router IDs, not on global addressing or identical IDs.

Why the other options are wrong

B

Incorrect. OSPFv3 forms adjacencies using IPv6 link-local addresses, so global unicast addresses are not mandatory for adjacency formation or neighbor discovery.

C

Incorrect. Router IDs must be unique identifiers for OSPF routers. Identical router IDs cause adjacency failure, but they do not need to be identical to form adjacency.

D

Incorrect. IPv6 link-local addresses are automatically configured on interfaces and do not require DHCPv6. OSPFv3 uses these link-local addresses for neighbor communication.

When would these options actually be correct?

B

In a different scenario where the question specifies that OSPFv3 is configured to require global unicast addresses for its operation, and the routers are only configured with link-local addresses, this option would be correct as it would prevent adjacency formation.

C

In a different scenario, if the question specified that both routers were configured with the same router ID, and that was a requirement for forming an adjacency, then this option would be correct. For example, if the question stated that the routers were misconfigured to have the same router ID, it would prevent adjacency.

D

In a different scenario where the question specifies that OSPFv3 is configured on routers that only have link-local addresses and no global unicast addresses are assigned, this option would be correct. The question could state that the routers are unable to form an OSPFv3 adjacency due to the absence of global unicast addresses, which are necessary for routing beyond the local link.

Why candidates pick the wrong answer

B

Candidates may choose this option due to a common misconception that OSPF requires global unicast addresses, leading them to overlook the capabilities of OSPFv3 with link-local addresses.

C

Candidates might choose this option due to a misunderstanding of OSPFv3 requirements, conflating the need for unique router IDs with adjacency formation, as they may have encountered similar concepts in other routing protocols.

D

Candidates may choose this option due to a misunderstanding of OSPFv3 requirements, mistakenly believing that global unicast addresses are mandatory for any OSPFv3 operation, leading to confusion about the protocol's capabilities.

1092
PBQhard

You are connected to R1. The link between R1 and R2 is down. The output of 'show interfaces gigabitEthernet0/0' on R1 shows: 'GigabitEthernet0/0 is administratively down, line protocol is down (disabled)', with IP address 203.0.113.1/30, MTU 1500, and no input/output errors. Determine the root cause and configure the necessary fix to bring the interface up and restore connectivity.

Network Topology
G0/0203.0.113.1/30G0/0203.0.113.2/30linkR1R2

Hints

  • •Check the interface status: 'show interfaces' reveals administratively down.
  • •The 'shutdown' command disables the interface; use 'no shutdown' to enable it.
  • •After enabling, verify with 'show ip interface brief'.
A.Enter interface configuration mode for GigabitEthernet0/0 and issue the 'no shutdown' command.
B.Enter interface configuration mode and issue the 'speed 100' command to match the remote interface speed.
C.Enter interface configuration mode and issue the 'duplex full' command to force full-duplex operation.
D.Enter interface configuration mode and issue the 'no keepalive' command to disable keepalives.
AnswerA
solution
! R1
configure terminal
interface gigabitethernet0/0
no shutdown

Why this answer

The interface status 'administratively down' means the interface was manually shut down using the 'shutdown' command. To bring it up, you must enter interface configuration mode and issue 'no shutdown', which administratively enables the interface. The other options are incorrect: setting speed to 100 Mbps or forcing full-duplex will not fix an administratively down state, and disabling keepalives is unrelated to the interface being disabled.

Exam trap

Candidates often miss the 'administratively down' keyword in show interfaces output and instead look for speed/duplex mismatches; always read the interface status first.

Why the other options are wrong

B

A speed mismatch would show 'up, line protocol down' and possibly increased input errors, but the interface here is 'administratively down'—manually disabled.

C

A duplex mismatch would cause late collisions or CRC errors, not an 'administratively down' status, which indicates a shutdown state.

D

Disabling keepalives has no effect on 'administratively down' because the interface is disabled at the administrative level, not because of a keepalive failure.

Why candidates pick the wrong answer

B

Candidates might think a speed mismatch is the cause because it is a common layer 1 issue, but the output clearly shows 'administratively down', which is a layer 2 administrative state.

C

Candidates may confuse 'line protocol is down' with a duplex mismatch, but the 'administratively down' keyword clearly indicates the interface was manually disabled.

D

Candidates might think keepalive mismatch is the problem because it is a common cause of line protocol down, but the 'administratively down' state is distinct and indicates a shutdown command.

1093
PBQhard

You are connected to R1 via console. Configure OSPFv3 for IPv6 on R1 and R2 so that IPv6 loopback interfaces on both routers can communicate. R1's GigabitEthernet0/0 and R2's GigabitEthernet0/1 are directly connected. Ensure OSPFv3 is enabled on the correct interfaces and verify neighbors and routes.

Network Topology
G0/02001:db8:12::1/64G0/12001:db8:12::2/64linkR1R2

Hints

  • •OSPFv3 must be enabled per-interface, not globally.
  • •Use the same OSPFv3 process ID and area on both routers.
  • •Check which interfaces are physically connected between the routers.
A.Enable OSPFv3 on R1's GigabitEthernet0/0 and Loopback0, and on R2's GigabitEthernet0/1 and Loopback0.
B.Enable OSPFv3 only on the loopback interfaces of both routers.
C.Enable OSPFv3 on R1's GigabitEthernet0/0 and R2's GigabitEthernet0/1 only, without loopbacks.
D.Enable OSPFv3 on R1's Loopback0 and R2's GigabitEthernet0/1 only.
AnswerA
solution
! R1
interface GigabitEthernet0/0
ipv6 ospf 1 area 0
interface Loopback0
ipv6 ospf 1 area 0

! R2
interface GigabitEthernet0/1
ipv6 ospf 1 area 0
interface Loopback0
ipv6 ospf 1 area 0

Why this answer

The issue is that OSPFv3 is not enabled on the interfaces. On R1, OSPFv3 must be enabled on GigabitEthernet0/0 (the link to R2) and Loopback0 (to advertise the loopback). On R2, OSPFv3 must be enabled on GigabitEthernet0/1 (the link to R1) and Loopback0.

After enabling OSPFv3 on the correct interfaces, the neighbor adjacency forms and routes are exchanged.

Exam trap

A common trap is to enable OSPFv3 only on the link interfaces or only on the loopbacks. Remember that OSPFv3 must be enabled on every interface that needs to be advertised or that participates in neighbor discovery. Also, note that OSPFv3 uses 'ipv6 ospf <process-id> area <area-id>' under the interface, not the network statement used in OSPFv2.

Why the other options are wrong

B

OSPFv3 requires the link interface to be enabled to form neighbors; loopback-only configuration results in no neighbor relationship.

C

OSPFv3 must be enabled on the loopback interfaces to advertise their prefixes; otherwise, they remain unknown to the neighbor.

D

Both routers must have OSPFv3 enabled on the link interface to form an adjacency, and both loopbacks must be enabled to advertise their prefixes.

Why candidates pick the wrong answer

B

Candidates may think that since loopbacks are the endpoints, enabling OSPFv3 only on them is sufficient, ignoring the need for adjacency on the transit link.

C

Candidates might focus only on forming the neighbor adjacency and forget that the loopback prefixes need to be explicitly advertised.

D

Candidates may incorrectly think that enabling OSPFv3 on one side of the link is enough, or they may mix up which interfaces need configuration.

1094
MCQhard

A switch port connected to an end host is configured with both PortFast and BPDU Guard. What is the most likely outcome if a small switch is connected there and starts sending BPDUs?

A.The port is error-disabled by BPDU Guard.
B.The port automatically becomes the root port.
C.The port converts into a trunk for the attached switch.
D.The port ignores the BPDU because PortFast disables STP entirely.
AnswerA

BPDU Guard places a PortFast-enabled port into err-disabled state the moment it receives a BPDU, since PortFast ports should only face end hosts. Connecting a switch generates BPDUs, triggering immediate shutdown, satisfying the stem's requirement to prevent loops and rogue switch attachment.

Why this answer

BPDU Guard places the port into an error-disabled state upon receiving a BPDU, because PortFast defines the port as an edge port that should never receive BPDUs. Option B is incorrect because receiving a BPDU does not automatically make a port a root port; root port selection depends on bridge ID and path cost, and BPDU Guard prevents further STP processing by disabling the port. Option C is incorrect because a port cannot convert to a trunk solely by receiving a BPDU; trunking requires manual configuration or Dynamic Trunking Protocol (DTP).

Option D is incorrect because PortFast does not disable STP entirely; it only speeds up initial convergence, and BPDU Guard actively responds to BPDUs by error-disabling the port.

Exam trap

Remember, BPDU Guard is about protection, not ignoring or processing BPDUs. It disables the port to prevent loops.

Why the other options are wrong

B

This option is wrong because a port configured with PortFast and BPDU Guard will not automatically become the root port when it receives BPDUs; instead, it will be error-disabled due to BPDU Guard's protective mechanism.

C

This option is incorrect because a port configured with PortFast and BPDU Guard does not convert to a trunk when receiving BPDUs; instead, BPDU Guard will disable the port to prevent potential loops.

D

This option is incorrect because PortFast does not disable Spanning Tree Protocol (STP) entirely; it only allows the port to transition to the forwarding state immediately without waiting for STP convergence. BPDU Guard will still take effect if BPDUs are received on a PortFast-enabled port.

When would these options actually be correct?

B

In a different scenario where a switch is configured without BPDU Guard and a port is set to participate in STP, if it receives BPDUs from a connected switch, it could potentially become the root port if it has the lowest bridge ID and path cost.

C

In a different scenario where a switch port is configured to allow trunking and is connected to another switch that is sending BPDUs, the port could be set to automatically negotiate trunking, making it a trunk port. The question would need to specify that trunking is enabled and that BPDUs are expected as part of the configuration.

D

In a different scenario where a switch is configured to disable STP entirely on a specific port, a question might ask what happens when a BPDU is received on that port. In that case, the correct answer could be that the port ignores the BPDU since STP is completely disabled.

Why candidates pick the wrong answer

B

Candidates may find this option tempting because they might confuse the behavior of STP with PortFast configurations, thinking that any BPDU received would lead to a re-evaluation of the port's role in the STP topology.

C

Candidates might be tempted by this option due to a misunderstanding of how switch port configurations work, particularly the interaction between PortFast and trunking, leading them to incorrectly assume that receiving BPDUs would trigger trunking.

D

Candidates may find this option tempting because they might confuse PortFast's functionality with STP being entirely disabled, leading them to believe that no BPDUs would be processed at all.

1095
MCQhard

A host is configured with 10.1.1.34/30. Which address is the broadcast address for its subnet?

A.10.1.1.31
B.10.1.1.35
C.10.1.1.32
D.10.1.1.36
AnswerB

The /30 subnet mask specified for the host 10.1.1.34 allocates two bits for host addresses. This creates a subnet containing four addresses in total. The network address for 10.1.1.34/30 is 10.1.1.32, where all host bits are zero. Consequently, the broadcast address is the last address in this subnet, where all host bits are set to one, which calculates to 10.1.1.35.

Why this answer

A /30 subnet has a block size of 4. In practical terms, the last-octet blocks are 0–3, 4–7, 8–11, and so on. Because 34 falls within the 32–35 block, the broadcast address is the last address in that block: 10.1.1.35.

This question tests whether you can identify the correct subnet block before choosing the broadcast address.

Exam trap

Ensure you correctly identify the subnet range and understand the roles of network, host, and broadcast addresses.

Why the other options are wrong

A

The address 10.1.1.31 is incorrect as a broadcast address for the subnet 10.1.1.34/30; the correct broadcast address is 10.1.1.35, derived from the subnet mask which allows for only 4 IP addresses (10.1.1.34 to 10.1.1.37).

C

The address 10.1.1.32 is not the broadcast address for the subnet 10.1.1.34/30; instead, it is the network address for the subnet, which is 10.1.1.32 to 10.1.1.35.

D

The address 10.1.1.36 is incorrect because it exceeds the valid range for a /30 subnet, which only allows for four IP addresses (two usable hosts, one network, and one broadcast). The broadcast address for the subnet 10.1.1.34/30 is 10.1.1.35.

When would these options actually be correct?

A

In a different context, if the subnet mask were /29 instead of /30, the broadcast address for the subnet 10.1.1.24/29 would be 10.1.1.31, making this option correct for that specific question.

C

If the question specified a subnet mask of /29 instead of /30, then 10.1.1.32 would be the broadcast address for the subnet 10.1.1.32/29, which ranges from 10.1.1.32 to 10.1.1.39.

D

In a different question where the subnet mask is /29 and the network address is 10.1.1.32, the broadcast address would be 10.1.1.39. In this scenario, option D (10.1.1.36) could be presented as a potential answer for a question regarding valid addresses within that subnet.

Why candidates pick the wrong answer

A

Candidates may be tempted by this option because it follows the pattern of common subnetting calculations, where the last address in a range is often mistakenly assumed to be the broadcast address without careful consideration of the subnet mask.

C

Candidates may confuse the calculation of broadcast addresses and mistakenly identify the next address after the network address as the broadcast address, especially when dealing with small subnets.

D

Candidates may choose option D due to a misunderstanding of subnetting boundaries, mistakenly believing that addresses immediately following the last usable IP might be valid broadcast addresses in different subnet configurations.

1096
MCQhard

A network technician connects a new Cisco switch to an existing access switch using a Category 5e copper patch cable. The link fails to come up, and the interface status shows 'err-disabled'. The technician checks the interface diagnostics and the running configuration. What action should the technician take to resolve the problem?

A.Replace the Category 5e cable with a Category 6 cable to support Gigabit Ethernet.
B.Configure the interface as a trunk port and disable spanning-tree BPDU guard.
C.Replace the copper SFP with a fiber SFP to increase the distance.
D.Manually set the speed and duplex to 1000 Mbps and full duplex on both switches.
AnswerB

The port is in err-disabled because bpduguard is enabled. Since this is a connection between two switches, the port should be configured as a trunk (or at least not as an access port with portfast) and bpduguard should be disabled to prevent the errdisable state.

Why this answer

The most likely reason for the err-disabled state is a spanning-tree BPDU guard violation on the access switch's port configured with PortFast. When another switch is connected, it sends BPDUs, triggering BPDU guard to error-disable the port. Configuring the interface as a trunk port and disabling BPDU guard (option B) resolves the issue by allowing BPDUs without triggering the protection.

Option A is unnecessary because Category 5e supports Gigabit Ethernet. Option C is irrelevant since the problem is not distance-related. Option D is risky because auto-negotiation is preferred and manual settings can cause mismatches.

Exam trap

Cisco often tests the misconception that err-disabled is always caused by speed/duplex mismatches or cable issues, but the trap here is that BPDU guard on a PortFast access port is a frequent and specific cause when connecting another switch.

Why the other options are wrong

A

The symptom is err-disabled, not a speed or duplex mismatch; cable type is not the issue.

C

The port is a built-in copper port, not an SFP-based interface; distance is not the issue.

D

The err-disabled state is due to BPDU guard, not speed/duplex mismatch; manual settings would not fix the root cause.

1097
Matchingeasy

Which term refers to a lightweight data-interchange format that is easy for humans to read and write, and easy for machines to parse and generate?

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Lightweight structured data format often used in API responses

Data modeling language for network configuration and state

Architecture style that commonly uses HTTP methods such as GET and POST

Credential or value used to authorize API requests

Why these pairings

JSON (JavaScript Object Notation) is a lightweight data-interchange format that is easy for humans to read and write, and easy for machines to parse and generate. It is commonly used in REST APIs. XML (eXtensible Markup Language) is also a data format but it is more verbose and uses tags; it is typically associated with SOAP rather than being the best match for the description given.

REST (Representational State Transfer) is an architectural style, not a data format, and SOAP (Simple Object Access Protocol) is a protocol, not a data format. Therefore, only JSON correctly matches the description of a lightweight data format.

Exam trap

The trap is confusing data formats with API protocols. Many candidates mistakenly think XML or JSON are protocols because they are used with REST/SOAP, but they are formats. Remember: formats describe data structure; protocols define communication rules.

When would these options actually be correct?

B

If the question asked 'Which data format uses tags like <name>value</name>?' or 'Which format is commonly used in SOAP web services?', then XML would be correct.

C

REST would be correct in a question asking to match API architectural styles to their characteristics, such as 'Which API style uses standard HTTP methods and is stateless?'

D

In a question asking to match API protocols to their characteristics, SOAP would be correct for 'uses XML-based messaging' or 'supports WS-Security'. For example, 'Match each API protocol to its primary messaging format: SOAP → XML'.

Why candidates pick the wrong answer

B

Candidates may confuse XML with JSON as both are data interchange formats, or they might think XML is more 'standard' and thus the correct answer.

C

Candidates often confuse REST with a data format because it is commonly used with JSON in web APIs, leading them to think it is a data format itself.

D

Candidates may confuse SOAP with a data format because it uses XML, or they might think 'API term' includes SOAP as a valid option, overlooking that JSON is the only data format listed.

1098
MCQhard

A network engineer is troubleshooting a link between two Cisco Catalyst 9300 switches that are connected via a single-mode fiber optic cable. The link is up, but the interface counters show a high number of CRC errors and frame check sequence (FCS) errors. The interface is configured for 1000 Mbps and full duplex on both ends. What is the most likely cause of these errors?

A.A speed or duplex mismatch between the two switches
B.Faulty or dirty fiber optic cable or connectors
C.Incorrect SFP+ module type inserted in the switch
D.Excessive cable length beyond the distance limit
AnswerB

The diagnostic optical monitoring (DOM) reports a receive power of -20 dBm on SwitchA, which falls well below the typical receive sensitivity range for 10GBASE-LR modules (often around -14.4 dBm for 10 Gbps, though less sensitive for 1 Gbps). Such excessive optical loss is usually caused by contamination on the fiber end faces, damaged fiber, or poor splices/connectors. Since the transmit power on the remote side may be within normal range, the large difference points to a physical-layer attenuation rather than a module failure.

Why this answer

CRC and FCS errors indicate corruption at the data-link layer, typically caused by physical-layer issues such as signal degradation. Since the link is up and both ends are configured for 1000 Mbps full duplex, a speed/duplex mismatch is ruled out. Dirty or faulty single-mode fiber connectors or the cable itself can introduce optical signal loss or reflections, leading to bit errors that manifest as CRC/FCS errors.

Exam trap

Cisco often tests the distinction between CRC errors (physical-layer signal integrity) and duplex mismatch symptoms (late collisions, runts), leading candidates to incorrectly choose a speed/duplex mismatch when the interface counters show CRC errors.

Why the other options are wrong

A

The exhibit confirms consistent speed and duplex settings.

C

The modules are correctly identified and match the fiber type.

D

There is no evidence of the cable length in the exhibit, and the low power is more indicative of a physical fault rather than simply exceeding distance limits.

1099
Multi-Selectmedium

Which TWO statements accurately describe the use of ipconfig, ping, and tracert when troubleshooting a client that cannot reach a remote server?

Select 2 answers
A.A successful ping to 127.0.0.1 confirms that the TCP/IP stack on the local host is functional.
B.If ping to the default gateway fails, the issue is certainly caused by a faulty Ethernet cable.
C.An ipconfig output showing an IPv4 address of 169.254.x.x indicates the DHCP client could not obtain an IP address and self-assigned an APIPA address.
D.A tracert that shows 'Request timed out' for the very first hop proves the local default gateway router is down or unreachable.
E.Running ipconfig /release followed by ipconfig /renew will always restore connectivity if the Ethernet cable is unplugged and re-plugged.
AnswersA, C

A successful ping to 127.0.0.1 validates the operation of the TCP/IP protocol stack on the local machine, because the loopback address routes packets directly back to the same host without leaving the computer. This test exercises the IP layer, ICMP, and the loopback interface, but it cannot confirm that the network adapter, cable, or any external path is working. The loopback ping is the most basic layer-3 test and must succeed before any network connectivity can be expected.

Why this answer

Option A is correct because pinging the loopback address 127.0.0.1 sends the ICMP Echo Request through the local host's own TCP/IP stack without touching any network hardware, so a successful reply verifies that the stack is installed and functioning. Option C is correct because the 169.254.0.0/16 range is the APIPA (Automatic Private IP Addressing) block that Windows assigns when a DHCP client cannot reach a DHCP server, so an ipconfig address in 169.254.x.x directly indicates DHCP failure. Option B is wrong because a failed ping to the default gateway could stem from many causes beyond a bad cable, such as a disabled NIC, wrong IP/subnet configuration, VLAN mismatch, or a down gateway interface.

Option D is wrong because 'Request timed out' on the first hop can also result from ICMP being blocked or rate-limited by the gateway, not only from the router being down. Option E is wrong because ipconfig /release and /renew only re-acquire a DHCP lease and cannot restore connectivity when the physical link is unplugged, since no DHCP traffic can traverse a disconnected cable.

Exam trap

Cisco often tests the misconception that a failed ping to the default gateway always points to a physical layer issue, when in fact it could be due to logical misconfigurations, firewall rules, or the gateway itself being operational but not responding to ICMP.

Why the other options are wrong

B

A single cable fault is only one of many possibilities; more testing is needed before concluding physical layer failure.

D

Timed-out hops in tracert do not directly prove the router is down; it may simply not be generating ICMP Time Exceeded messages.

E

These commands do not guarantee a lease; the DHCP server must be operational and reachable.

1100
Multi-Selectmedium

Which two statements accurately describe common uses of NTP in network operations?

Select 2 answers
A.It helps align device clocks across the network.
B.It improves the reliability of event timelines and log correlation.
C.It replaces the need for Syslog.
D.It assigns IP addresses to hosts.
E.It provides WLAN encryption.
AnswersA, B

NTP synchronises device clocks to a common reference time source, satisfying the requirement to align clocks across the network. Accurate, consistent timestamps are essential for correlating syslog and SNMP events, validating certificate lifetimes, and interpreting time-based ACLs, so this statement accurately describes a core operational use.

Why this answer

Option A is correct because NTP (Network Time Protocol) synchronizes the clocks of network devices to a common time reference, typically a stratum-0/1 source, keeping routers, switches, and servers aligned within milliseconds. Option B is correct because accurate, consistent timestamps from NTP make event timelines reliable and enable log correlation across multiple devices, which is essential for troubleshooting, SIEM analysis, and forensic investigations. The unmarked options do not belong: NTP does not replace Syslog (C), which is a separate logging/transport mechanism; it does not assign IP addresses (D), which is the role of DHCP; and it does not provide WLAN encryption (E), which is handled by protocols such as WPA2/WPA3.

Exam trap

A frequent exam trap is assuming that NTP performs functions beyond time synchronization, such as replacing Syslog or assigning IP addresses. Candidates might incorrectly select options suggesting NTP handles logging or DHCP tasks because these services are all related to network management. However, NTP’s sole purpose is to synchronize device clocks.

Confusing NTP with DHCP or Syslog overlooks their distinct roles and can lead to selecting incorrect answers. Understanding that NTP supports but does not replace logging or address assignment is crucial to avoid this trap.

Why the other options are wrong

C

This option is incorrect because NTP does not replace Syslog; Syslog is responsible for logging events, while NTP only synchronizes time.

D

This option is incorrect because IP address assignment is handled by DHCP, not NTP, which only manages time synchronization.

E

This option is incorrect because NTP has no role in providing WLAN encryption; encryption is managed by wireless security protocols like WPA2 or WPA3.

When would these options actually be correct?

C

If the exam question asked about protocols that can replace or enhance logging mechanisms in a network, and if it included a context where time synchronization impacts log accuracy, then a statement about NTP replacing Syslog could be considered correct.

D

If the exam question asked about protocols used for network configuration and management, including IP address assignment, then option D could be correct in a context discussing DHCP or similar protocols that manage IP addressing.

E

If the exam question asked about protocols that provide security features for wireless networks, then option E could be correct. For example, a question might ask which protocols are used to secure WLAN communications, where encryption methods would be relevant.

Why candidates pick the wrong answer

C

Candidates might confuse the roles of NTP and Syslog due to their interrelated functions in network operations, leading them to believe that time synchronization could eliminate the need for logging protocols.

D

Candidates may confuse NTP with other network services that manage device configurations, leading them to mistakenly believe that NTP could also handle IP address assignments, especially if they are not fully aware of the distinct roles of different network protocols.

E

Candidates may confuse NTP's role in network operations with security features, leading them to mistakenly associate it with WLAN encryption due to the importance of timing in secure communications.

1101
Multi-Selectmedium

Which TWO statements about SFP transceivers and fiber optic cabling are correct?

Select 2 answers
A.SFP transceivers are permanently installed on the switch motherboard and cannot be replaced.
B.1000BASE-SX SFP transceivers are designed for multimode fiber and typically support distances up to 550 meters.
C.Multimode fiber typically uses laser-based transmitters for long-distance transmission.
D.Single-mode fiber (SMF) with 1000BASE-LX SFP transceivers can support distances up to 5 km.
E.Single-mode fiber has a larger core diameter than multimode fiber, allowing longer distances.
AnswersB, D

1000BASE-SX operates at 850 nm over multimode fibre, supporting up to 550 m on 50-micron OM2 cabling. This satisfies the stem's requirement for a correct statement pairing the SX transceiver with multimode media and its typical distance limit.

Why this answer

Option B is correct because 1000BASE-SX is the IEEE 802.3z standard for Gigabit Ethernet over multimode fiber (MMF), using short-wavelength 850 nm VCSEL/laser transmitters and supporting distances up to 550 m with 50-micron MMF (and 220–275 m with 62.5-micron MMF). Option D is correct because 1000BASE-LX uses long-wavelength 1310 nm optics and, when paired with single-mode fiber (SMF), can reach approximately 5 km (and up to 10 km in some implementations), making it suitable for campus backbone runs. Option A is wrong because SFP (Small Form-factor Pluggable) transceivers are hot-swappable modular devices that plug into SFP slots or cages, not permanently soldered to the motherboard.

Option C is wrong because multimode fiber is typically used with LED or VCSEL sources for shorter distances; long-distance transmission is the domain of single-mode fiber with laser transmitters. Option E is wrong because single-mode fiber has a much smaller core diameter (about 9 microns) than multimode fiber (50 or 62.5 microns), which is precisely what enables single-mode's lower modal dispersion and longer reach.

Exam trap

Cisco often tests the misconception that multimode fiber always uses lasers for long distances, when in fact multimode fiber is optimized for shorter runs with LED or VCSEL sources, while single-mode fiber uses lasers for extended reach.

Why the other options are wrong

A

This statement is false because SFP slots are designed for modular, replaceable transceivers.

C

Laser transmitters are used in single-mode fiber for longer distances; multimode uses LED/VCSEL.

E

Single-mode fiber has a smaller core, not larger. The smaller core reduces dispersion and allows longer reach.

1102
PBQhard

You are connected to R1 via the console. R1 has two directly connected interfaces: G0/0 to R2 (IPv4 only) and G0/1 to a LAN switch (dual stack). Your task: configure IPv4 and IPv6 default routes on R1 pointing to R2 (next-hop 10.0.0.2 and 2001:db8:1::2). Also configure a floating static route to 192.0.2.0/24 via R2 with an administrative distance of 10 (so it is used only if the directly connected route fails). The current running-config shows an incorrect static route that causes recursive routing failure. Identify and fix the issue.

Network Topology
G0/010.0.0.1/30G0/010.0.0.2/30linkG0/1192.168.1.1/24R2R1switchLAN

Hints

  • •Check the next-hop IP in the static route to 192.0.2.0/24 — is it a directly connected neighbor?
  • •For a floating static route, the administrative distance must be higher than the primary route's AD.
  • •Use 'show ip route 192.0.2.0' to see if the route is flagged as 'recursive failure'.
A.Remove the incorrect static route 192.0.2.0 255.255.255.0 10.0.0.1 and add ip route 192.0.2.0 255.255.255.0 10.0.0.2 10
B.Remove the incorrect static route 192.0.2.0 255.255.255.0 10.0.0.1 and add ip route 192.0.2.0 255.255.255.0 10.0.0.2 1
C.Keep the existing static route and add ip route 192.0.2.0 255.255.255.0 10.0.0.2 10
D.Remove the incorrect static route 192.0.2.0 255.255.255.0 10.0.0.1 and add ip route 192.0.2.0 255.255.255.0 g0/0
AnswerA
solution
! R1
no ip route 192.0.2.0 255.255.255.0 10.0.0.1
ip route 192.0.2.0 255.255.255.0 10.0.0.2 10

Why this answer

The static route to 192.0.2.0/24 uses next-hop 10.0.0.1, which is R1's own interface IP, not R2's. This causes recursive routing failure because the router tries to reach itself. The correct next-hop should be 10.0.0.2 (R2's G0/0 IP).

Additionally, the floating static route must have a higher AD (10) so it is less preferred than the directly connected route (AD 0). Remove the incorrect route and add the correct floating static route with AD 10.

Exam trap

Watch out for recursive routing failures caused by using the router's own interface IP as the next-hop. Also, remember that floating static routes require a higher administrative distance than the primary route to act as a backup.

Why the other options are wrong

B

The specific factual error: The AD of a floating static route must be higher than the primary route's AD to serve as a backup. Here AD 1 is lower than 0? Actually directly connected routes have AD 0, so AD 1 is higher than 0, but the question states the floating static route should be used only if the directly connected route fails, so AD must be higher than 0. AD 1 is higher than 0, so it would still be a backup? Wait, the primary route is directly connected (AD 0).

A floating static route with AD 1 would be less preferred than AD 0, so it would only be used if the directly connected route fails. That is correct behavior. However, the question says 'with an administrative distance of 10' so AD 1 is not 10.

The error is that the AD is not 10 as specified. Also, the explanation in the stem says 'the floating static route must have a higher AD (10) so it is less preferred than the directly connected route (AD 0).' Actually AD 1 is also higher than 0, so it would also be less preferred. But the question explicitly asks for AD 10.

So the answer is wrong because it uses AD 1 instead of 10.

C

The specific factual error: The incorrect static route remains in the routing table, causing recursive routing failure. The router will still try to resolve the next-hop 10.0.0.1, which is its own interface, leading to a loop.

D

The specific factual error: The route does not have an administrative distance of 10, and using an exit interface instead of a next-hop IP is not the intended configuration. Also, the route would be installed with default AD 1, not 10.

Why candidates pick the wrong answer

B

Candidates might think any AD higher than 0 works, but the question specifies AD 10, so using AD 1 is not compliant with the requirement.

C

Candidates might think that adding a more specific route (with AD 10) will override the existing route, but since both routes have the same prefix and mask, the one with lower AD is preferred. The existing route has AD 1 (default) and the new route has AD 10, so the existing route remains active and causes failure.

D

Candidates might think that using an exit interface avoids recursive lookup, but the question explicitly requires a floating static route with AD 10, and the next-hop IP is specified as 10.0.0.2.

1103
MCQhard

Refer to the exhibit. A network administrator connects an IP phone to interface GigabitEthernet1/0/1 on a Cisco Catalyst switch. The PC connected through the phone works normally on the data VLAN, but the phone cannot obtain an IP address and fails to register with the call server. Which action will resolve the problem?

A.Configure 'switchport trunk allowed vlan 10,20' on interface Gi1/0/1 and change the switchport mode to trunk.
B.Add 'switchport voice vlan 20' on interface GigabitEthernet1/0/1.
C.Issue 'switchport access vlan 20' and 'switchport voice vlan 10' on interface Gi1/0/1.
D.Enable 'switchport port-security mac-address sticky' on the interface and manually add the phone’s MAC address to the access VLAN.
AnswerB

The 'switchport voice vlan 20' command is the correct Cisco IOS configuration for a voice-enabled access port. It leaves VLAN 10 as the default access VLAN for PC data (untagged) while defining VLAN 20 as the voice VLAN for the IP phone. The phone discovers VLAN 20 via CDP or LLDP and tags its voice frames with 802.1Q, keeping voice and data in separate Layer 2 domains and subnets.

Why this answer

The PC works on the data VLAN, but the phone cannot obtain an IP address, indicating the phone is not receiving the correct VLAN assignment. The phone should be placed in the voice VLAN (VLAN 20) using the 'switchport voice vlan 20' command, which allows the switch to tag the phone's traffic with VLAN 20 via CDP/LLDP, enabling it to get an IP from the voice VLAN DHCP server.

Exam trap

Cisco often tests the distinction between 'switchport access vlan' (for data) and 'switchport voice vlan' (for voice), and the trap here is that candidates may confuse which VLAN is assigned to which device, or incorrectly think trunking is required for a phone connection.

Why the other options are wrong

A

A trunk port does not provide the voice VLAN advertisement mechanism to the phone; the PC would need to send tagged frames, which typical endpoint NICs do not do.

C

The phone requires access to VLAN 20 for voice services, and the PC must remain in VLAN 10 for data; this configuration does the opposite, failing to meet the requirement.

D

The phone still cannot learn the voice VLAN; port security does not provide a DHCP address or make the switch advertise VLAN 20 to the phone.

1104
MCQhard

A user reports that they cannot access the company's internal web server at 'intranet.company.local' from their workstation. The workstation can ping the web server's IP address 192.168.10.50 successfully, and other internal services like email (mail.company.local) are reachable. Which DNS record issue is most likely causing this problem?

A.Add a CNAME record that aliases 'intranet.company.local' to 'webserver.company.local'
B.Add an A record mapping 'intranet.company.local' to IP address 192.168.10.50
C.Verify the PTR record for 192.168.10.50 points to 'intranet.company.local'
D.Check the NS records for the 'company.local' zone to ensure proper delegation
AnswerB

The nslookup output confirms that a forward lookup for 'intranet.company.local' returns no A record, even though the target IP 192.168.10.50 is reachable on the network. Creating an A record in the company.local DNS zone maps the hostname to that IP address, allowing clients to resolve the name to the correct destination. Because the IP is already valid and no CNAME or other record exists, a direct A record is the minimal, correct fix.

Why this answer

The workstation can ping the web server's IP address (192.168.10.50), confirming network connectivity and that the server is online. However, the user cannot access the server by its hostname 'intranet.company.local', which indicates a DNS resolution failure. Since other internal services like email are reachable, the DNS zone is functioning, but there is no A record that maps the hostname 'intranet' to its IP address.

Adding an A record for 'intranet.company.local' pointing to 192.168.10.50 will resolve the issue.

Exam trap

Cisco often tests the distinction between forward DNS records (A/AAAA) and reverse DNS records (PTR), and candidates mistakenly choose PTR when the symptom is a forward resolution failure, confusing the direction of the lookup.

Why the other options are wrong

A

The root cause is a missing A record; a CNAME record would not resolve without an A record for the target.

C

PTR records are not used for forward name resolution; the issue is with the forward lookup zone.

D

The zone delegation is working (other records resolve), so NS records are not the cause.

1105
MCQhard

A network engineer notices that an uplink port on a distribution switch has moved to a root-inconsistent state and is blocking traffic. The port is configured with Root Guard and is connected to a new access switch. The new access switch has a lower bridge priority than the current root bridge. What is the most likely cause?

A.BPDU Guard has errdisabled the port because a BPDU was received on an access port.
B.BPDU Filter is blocking inbound BPDUs, causing the switch to fail to detect the topology change and isolate the port.
C.Root Guard has placed the port into root-inconsistent state because the new switch advertised a superior BPDU.
D.Loop Guard has detected a unidirectional link and placed the port in a blocking state to prevent a loop.
AnswerC

Root Guard is designed to prevent the port from becoming a root port. Upon receiving a superior BPDU (lower bridge ID), it places the port in root-inconsistent state, effectively blocking traffic. This directly matches the symptom described.

Why this answer

Root Guard is configured on the uplink port of the distribution switch. When the new access switch advertises a superior BPDU (lower bridge priority than the current root bridge), Root Guard places the port into a root-inconsistent state to prevent the distribution switch from accepting the new switch as the root bridge. This blocks traffic on that port to protect the spanning-tree topology.

Exam trap

Cisco often tests the distinction between Root Guard and BPDU Guard, where candidates confuse the root-inconsistent state with an errdisable state or assume any BPDU-related protection will errdisable the port.

Why the other options are wrong

A

Candidates mistakenly equate BPDU Guard with any BPDU-induced blocking, but the state 'root-inconsistent' is specific to Root Guard.

B

Candidates may think that filtering BPDUs leads to port isolation, but BPDU Filter would not trigger a protective state like root-inconsistent.

D

Candidates often confuse Loop Guard and Root Guard because both can cause inconsistent states, but Loop Guard triggers loop-inconsistent, not root-inconsistent, and is triggered by BPDU loss, not receipt of superior BPDUs.

1106
MCQmedium

A PC connected to switch port Gi0/10 should be in VLAN 20 but receives broadcasts only from VLAN 1. Which switchport setting is most likely wrong?

A.switchport mode trunk
B.switchport access vlan 20 missing or incorrect
C.speed 1000
D.duplex full
AnswerB

The access VLAN assignment on a switchport determines which untagged (native) VLAN the port belongs to. If a PC on interface Gi0/10 should be in VLAN 20 but is not, the most direct cause is that the port is either left in the default VLAN (often VLAN 1) or configured with a different access VLAN via the 'switchport access vlan' command. Without this correct mapping, the PC's frames are forwarded in the wrong broadcast domain and cannot reach VLAN 20 resources. This is the primary configuration that controls the behavior described.

Why this answer

The PC is receiving broadcasts only from VLAN 1, which indicates the switchport is not correctly assigned to VLAN 20. The most likely cause is that the 'switchport access vlan 20' command is missing or incorrect, leaving the port in its default VLAN (VLAN 1). This prevents the PC from participating in VLAN 20 and receiving its broadcasts.

Exam trap

Cisco often tests the misconception that a trunk port is needed for VLAN membership, but for a single end device, an access port with the correct VLAN assignment is required.

Why the other options are wrong

A

The switchport mode trunk setting is incorrect because a trunk port allows multiple VLANs to pass, while the question indicates that the PC should only receive broadcasts from VLAN 20. Therefore, the issue lies with the access VLAN configuration.

C

The speed setting of 1000 Mbps (1 Gbps) does not influence VLAN membership or broadcast traffic; it only affects the data transfer rate. Therefore, this option does not address the issue of the PC receiving broadcasts only from VLAN 1.

D

The duplex setting of the switch port does not influence VLAN membership or broadcast traffic. Therefore, a duplex configuration of 'full' does not affect the ability of a PC to receive broadcasts from VLAN 20.

When would these options actually be correct?

A

In a scenario where the question specifies that a switch port should be configured to allow multiple VLANs for a server that needs to communicate across VLANs, the correct answer would be that the switchport mode trunk is incorrectly set to access mode. This would lead to the server not receiving broadcasts from the required VLANs.

C

In a different scenario, if a question asked about a switch port configuration issue causing a device to experience connectivity problems due to mismatched speeds between the switch and the connected device, then 'speed 1000' could be the correct answer if the device only supports lower speeds, leading to a failure in communication.

D

In a different scenario where the question asks about the performance of a network connection, a candidate might be asked what could cause a device to experience packet loss or communication issues. If the question specifies that the switch port is set to 'half duplex', then 'duplex full' would be the correct answer as it would resolve the communication issue.

Why candidates pick the wrong answer

A

Candidates may choose this option because they associate trunking with VLAN communication and might overlook the specific requirement for the PC to be in a single VLAN, leading to confusion about the port's intended configuration.

C

Candidates might choose this option because they associate speed settings with connectivity issues, mistakenly believing that incorrect speed configurations could impact VLAN membership or broadcast traffic.

D

Candidates may mistakenly believe that duplex settings impact VLAN functionality, leading them to choose this option when they see issues with broadcast traffic, despite it being unrelated.

1107
MCQhard

After connecting a new switch to interface GigabitEthernet1/0/1 on a distribution switch, a network engineer notices that the interface is in err-disable state. The engineer checks the configuration and finds that spanning-tree portfast and spanning-tree bpduguard enable are applied to the interface. What is the most likely cause of the err-disable state?

A.BPDU Guard was incorrectly enabled on a port that should be a trunk link.
B.The connected switch is sending BPDUs with a lower bridge priority.
C.Spanning-tree PortFast is enabled on a port that connects to another switch.
D.The port is configured as an access port, but should be a trunk.
AnswerC

PortFast skips the listening and learning STP states and is designed for end hosts. When combined with BPDU Guard, the switch was instructed to disable the port upon receiving any BPDU. The downstream switch naturally sends BPDUs, causing BPDU Guard to react and place the port in err-disable. Removing PortFast (and leaving BPDU Guard alone, or disabling BPDU Guard on that link) would resolve the issue.

Why this answer

PortFast is designed for end-host ports that should not receive BPDUs. When PortFast is enabled on a port connecting to another switch, the switch will immediately transition the port to forwarding state, but if it then receives a BPDU from the connected switch, BPDU Guard will error-disable the port. This is the most common cause of err-disable state when both PortFast and BPDU Guard are configured on an inter-switch link.

Exam trap

Cisco often tests the misconception that BPDU Guard alone causes err-disable, but the trap here is that PortFast must be enabled for BPDU Guard to trigger err-disable on a port receiving BPDUs from another switch.

Why the other options are wrong

A

Candidates often associate BPDU Guard exclusively with access ports and assume configuring it on a trunk is itself a misconfiguration, overlooking that PortFast is the real culprit.

B

Students may confuse root bridge placement with BPDU Guard operation, thinking that a BPDU from a superior switch might cause a port to be disabled, when in fact BPDU Guard is content-agnostic.

D

Candidates may think that because a link between switches should be a trunk, the access mode misconfiguration is the root cause. However, they miss the fact that BPDU Guard acts on the BPDU regardless of the port mode, and the real misconfiguration is PortFast.

1108
MCQmedium

A switch displays this output: Port Name Status Vlan Fa0/1 connected 10 Fa0/2 connected 10 Fa0/24 connected trunk Which port should be checked first if a user in VLAN 20 cannot reach the distribution switch over the uplink?

A.Fa0/1
B.Fa0/2
C.Fa0/24
D.Any access port in VLAN 1
AnswerC

Fa0/24 is the only port configured as a trunk, which is necessary for carrying traffic from multiple VLANs, including VLAN 20, to the distribution switch over the uplink. When a user in VLAN 20 cannot reach the distribution switch, this trunk port represents the primary path for inter-VLAN communication upstream. Investigating its configuration for allowed VLANs or potential physical layer issues is the logical first step to diagnose the connectivity problem for VLAN 20.

Why this answer

If users in VLAN 20 must cross the uplink, the trunk port is the first place to verify allowed VLANs and tagging.

Exam trap

Don't confuse access ports with trunk ports; only trunk ports can carry multiple VLANs.

Why the other options are wrong

A

Fa0/1 is connected to VLAN 10, and since the user in VLAN 20 cannot reach the distribution switch, checking this port would not address the issue, as it is not part of the user's VLAN.

B

Fa0/2 is connected to VLAN 10, which means it cannot facilitate communication for a user in VLAN 20. The issue lies with the trunk port, which is responsible for carrying multiple VLANs, including VLAN 20.

D

Option D is incorrect because it suggests checking any access port in VLAN 1, which is not relevant to the user's issue in VLAN 20. The problem lies with the trunk port not allowing VLAN 20 traffic, not with access ports in VLAN 1.

When would these options actually be correct?

A

In a different scenario where the question specifies that VLAN 10 is experiencing connectivity issues or misconfigurations affecting users on that VLAN, checking Fa0/1 would be appropriate to troubleshoot the problem.

B

In a scenario where the question specifies that VLAN 20 is configured on Fa0/2 and the user is attempting to reach a device on VLAN 20, checking Fa0/2 would be the correct action to troubleshoot connectivity issues related to that specific VLAN.

D

In a scenario where the question asks which access port in VLAN 1 should be checked for connectivity issues affecting users in VLAN 1, option D would be correct. This could involve a misconfiguration or a device connected to an access port in VLAN 1 that is not functioning properly.

Why candidates pick the wrong answer

A

Candidates may choose Fa0/1 due to its status as a connected port, mistakenly believing that any active port could be relevant to the user's connectivity issue without considering VLAN assignments.

B

Candidates may choose Fa0/2 because it is an active port and they might assume that any connected port could potentially be involved in the issue, especially if they misunderstand VLAN configurations.

D

Candidates may choose this option due to a misunderstanding of VLANs, thinking that any access port might be relevant for troubleshooting connectivity issues, regardless of the specific VLAN in question.

1109
MCQeasy

A branch router should automatically learn the IP address of a time source so logs from all devices show matching timestamps. Which service provides that function?

A.DNS
B.NTP
C.TFTP
D.NetFlow
AnswerB

Network Time Protocol (NTP) provides automatic time synchronization by allowing a router to discover NTP servers via broadcast, multicast, or DHCP option 42. A branch router can thus learn the IP address of an authoritative time source without manual per-device configuration, ensuring consistent timestamps for logs and authentication. This is the correct service for the requirement.

Why this answer

NTP synchronizes clocks across network devices. When timestamps line up, syslog messages and troubleshooting output become much more useful.

Exam trap

A common exam trap is selecting DNS as the answer because it involves IP addresses and network services, tempting candidates to confuse name resolution with time synchronization. Another trap is choosing TFTP, since it is a network protocol often associated with configuration and file transfers, misleading candidates to think it manages device settings including time. NetFlow might also confuse candidates because it deals with network traffic data, but it does not affect device clocks.

The key is to recognize that only NTP is designed specifically to synchronize time across devices, which is critical for matching timestamps in logs.

Why the other options are wrong

A

DNS resolves hostnames to IP addresses, enabling devices to locate servers and services by name. However, DNS does not synchronize device clocks or manage time, so it cannot ensure matching timestamps in logs.

C

TFTP is a simple protocol used for transferring files such as configurations and IOS images. It does not provide any time synchronization capabilities and cannot ensure matching timestamps in device logs.

D

NetFlow is a network protocol that collects and exports IP traffic flow information for analysis. It does not affect device clocks or time synchronization and thus cannot provide matching timestamps.

When would these options actually be correct?

A

In a scenario where the question asks about a service that resolves hostnames to IP addresses for network devices, DNS would be the correct answer. For example, if the question focused on how devices can locate and communicate with each other using domain names, DNS would be the appropriate choice.

C

If the question were about a scenario where a router needs to download configuration files or firmware updates from a server, TFTP would be the correct answer, as it is specifically designed for simple file transfers in a network.

D

If the exam question asked about a service that analyzes and reports on network traffic patterns, or if it inquired about tools for monitoring network performance, then NetFlow would be the correct answer as it provides detailed traffic analysis.

Why candidates pick the wrong answer

A

Candidates may confuse DNS with time synchronization services due to their roles in network functionality, leading them to mistakenly believe that DNS can also handle time-related tasks.

C

Candidates may confuse TFTP with other network services and mistakenly associate it with device management tasks, leading them to believe it could also handle time synchronization, despite its actual purpose.

D

Candidates may confuse NetFlow with time synchronization services due to its role in network management, leading them to incorrectly associate it with log timestamping functionalities.

1110
MCQhard

A switch should automatically disable any access port that receives a BPDU from an attached device. Which feature directly provides that behavior?

A.Root Guard
B.Loop Guard
C.BPDU Guard
D.PortFast
AnswerC

BPDU Guard is the correct answer because it is specifically designed to protect access ports, which should operate as edge ports in a spanning-tree domain. When an access port with BPDU Guard enabled receives any BPDU, the switch immediately places the port into the err-disabled state, effectively shutting it down to prevent a potential switching loop or unauthorized switch connection. This behavior directly matches the requirement of automatically disabling an access port that receives BPDUs.

Why this answer

BPDU Guard is designed for edge ports that should never see BPDUs. If a BPDU arrives, the port is placed into an err-disabled state to protect the topology. Root Guard and Loop Guard solve different STP problems.

Exam trap

A common exam trap is confusing BPDU Guard with Root Guard or Loop Guard. Candidates may incorrectly select Root Guard because it involves BPDUs and port blocking, but Root Guard only prevents a port from becoming a root port and does not err-disable the port. Loop Guard is often mistaken as it protects against unidirectional link failures but does not disable ports on BPDU receipt.

The key distinction is that BPDU Guard immediately disables the port upon receiving any BPDU, which is the behavior the question describes. Misunderstanding these differences can lead to incorrect answers.

Why the other options are wrong

A

Root Guard prevents a port from becoming a root port if superior BPDUs are received, maintaining the root bridge position, but it does not err-disable the port upon BPDU receipt. Therefore, it does not fulfill the requirement to disable access ports that receive BPDUs.

B

Loop Guard protects against unidirectional link failures by preventing a port from transitioning to forwarding state if BPDUs stop arriving on non-designated ports. It does not disable ports upon receiving BPDUs, so it does not meet the behavior described in the question.

D

PortFast is a feature that allows ports to transition quickly to forwarding state, bypassing the usual STP listening and learning states. It does not disable ports upon receiving BPDUs and therefore does not provide the behavior described.

When would these options actually be correct?

A

If the exam question asked about a feature that prevents a switch port from becoming a root port and maintains the integrity of the spanning tree by blocking ports that receive BPDUs from non-root bridges, then Root Guard would be the correct answer.

B

If the exam question asked about a feature that prevents loops by blocking ports that receive unexpected BPDUs, Loop Guard would be the correct answer. For example, a question could specify a scenario where a switch needs to maintain a loop-free topology in a redundant network setup.

D

If the question asked about a feature that enhances the speed of port activation without considering BPDU reception, such as 'Which feature allows a switch port to immediately enter the forwarding state?' then PortFast would be the correct answer.

Why candidates pick the wrong answer

A

Candidates may confuse Root Guard with BPDU Guard due to their similar names and both being related to spanning tree protocol protection mechanisms, leading them to incorrectly assume Root Guard provides the desired behavior.

B

Candidates may confuse Loop Guard with BPDU Guard due to their similar names and functions related to BPDUs, leading them to incorrectly associate Loop Guard with the behavior of disabling ports upon receiving BPDUs.

D

Candidates may confuse PortFast with BPDU Guard due to their association with port states and rapid convergence, leading them to mistakenly believe that PortFast also handles BPDU reception.

1111
Matchingeasy

Match each basic automation term to its most accurate meaning.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Software interface used for communication

Structured data format

Secure transport for the communication

Credential-like value used to help control access

Why these pairings

Automation refers to the use of technology to perform tasks with minimal human intervention, reducing manual effort and errors. Orchestration is the coordination of multiple automated tasks into a seamless workflow, ensuring proper sequencing and dependencies. A script is a set of instructions written in a scripting language that is executed by an interpreter, often used to automate repetitive tasks.

A workflow is a defined sequence of steps that accomplishes a specific business process, which can be automated to streamline operations.

Exam trap

Be careful not to confuse automation with orchestration: automation is about individual task execution, while orchestration coordinates multiple automated tasks. Similarly, a script is a specific set of instructions, whereas a workflow is a higher-level sequence that may involve multiple scripts or automation tools.

1112
Multi-Selectmedium

Which TWO statements correctly describe the OSI model layers and their corresponding PDU names during encapsulation?

Select 2 answers
A.The Transport layer encapsulates data into segments.
B.The Network layer encapsulates segments into packets.
C.The Data Link layer encapsulates packets into bits.
D.The Session layer encapsulates segments into sessions.
E.The Physical layer encapsulates frames into bits.
AnswersA, B

The Transport layer encapsulates upper-layer data (from the Session layer or Application layer) by adding a TCP or UDP header to create a segment. This header includes source and destination port numbers, and for TCP also sequence numbers, acknowledgment numbers, and window size, enabling reliable end-to-end delivery. This process of dividing data and prepending transport control information is exactly what produces the segment PDU, making this statement correct.

Why this answer

Both A and B are correct. During encapsulation, the Transport layer (Layer 4) adds a header to upper-layer data to form segments, and the Network layer (Layer 3) encapsulates those segments into packets by adding a network-layer header (e.g., IP). Option C is incorrect because the Data Link layer encapsulates packets into frames, not bits; bits are the raw transmission unit at the Physical layer.

Option D is incorrect because the Session layer manages sessions but does not produce a PDU called 'sessions'; encapsulation of segments only occurs at Layers 4 and below. Option E is incorrect because the Physical layer transmits frames as bits but does not perform encapsulation; encapsulation ends at the Data Link layer.

Exam trap

Cisco often tests the specific PDU names at each layer (e.g., segment vs. packet vs. frame vs. bit) and the order of encapsulation, so the trap here is confusing the Data Link layer PDU (frame) with bits or mixing up the Session layer's role with encapsulation.

Why the other options are wrong

C

The Data Link layer encapsulates packets into frames, not bits; bits are the PDU of the Physical layer.

D

The Session layer handles session management and does not perform encapsulation into 'sessions'; encapsulation at this layer is not defined.

E

The Physical layer transmits frames as bits but does not encapsulate frames into bits; encapsulation ends at Layer 2.

1113
PBQhard

You are connected to R1. The inside network 192.168.1.0/24 must be able to access the internet using PAT (NAT overload) with the outside interface G0/1 IP 203.0.113.1. Additionally, the internal server at 192.168.1.10 must be reachable from the internet via static NAT to 203.0.113.10. The current configuration is incomplete and contains errors. Identify and fix all issues so that both PAT and static NAT work correctly.

Network Topology
G0/0192.168.1.1/24G0/1203.0.113.1/24LANinsideR1outsideInternet

Hints

  • •Check which interfaces are marked as inside/outside — they may be reversed.
  • •Look at the ACL used for dynamic NAT — does it match the correct inside subnet?
  • •Is the 'overload' keyword present on the ip nat inside source command?
A.Swap ip nat inside/outside on interfaces, add 'overload' to the dynamic NAT rule, and correct ACL 1 to permit 192.168.1.0/24.
B.Change the static NAT inside address to 192.168.1.1 and add 'overload' to the dynamic NAT rule.
C.Remove the static NAT configuration and rely solely on PAT for the server.
D.Add the 'overload' keyword to the dynamic NAT rule and correct ACL 1 to permit 192.168.1.0/24.
AnswerA
solution
! R1
interface GigabitEthernet0/0
ip nat inside
exit
interface GigabitEthernet0/1
ip nat outside
exit
no ip nat inside source list 1 pool GLOBAL
ip nat inside source list 1 pool GLOBAL overload
no access-list 1
access-list 1 permit 192.168.1.0 0.0.0.255

Why this answer

The configuration had multiple faults: 1) Inside/outside interfaces were swapped – G0/0 (LAN) should be inside, G0/1 (WAN) should be outside. 2) The PAT command was missing the 'overload' keyword. 3) ACL 1 permitted the wrong subnet (192.168.2.0/24 instead of 192.168.1.0/24). 4) The static NAT configuration was correct, but the interface misconfiguration prevented it from working. Fixes: swap ip nat inside/outside on the interfaces, add 'overload' to the dynamic NAT rule, and correct ACL 1 to permit 192.168.1.0/24.

Exam trap

This question tests your ability to identify multiple simultaneous NAT configuration errors. Common traps include forgetting the 'overload' keyword, misconfiguring ACLs, and swapping inside/outside interfaces. Always verify interface NAT directions first, as they are foundational.

Why the other options are wrong

B

The specific factual error is that the static NAT inside address is already correct; altering it is unnecessary and incorrect.

C

The specific factual error is that static NAT is required for inbound access; PAT alone cannot provide a fixed public-to-private mapping.

D

The specific factual error is that interface NAT direction is fundamental; if inside/outside are reversed, NAT translations will not be applied correctly.

Why candidates pick the wrong answer

B

Candidates might think the server's inside address should be the default gateway (192.168.1.1) or confuse it with the inside global address.

C

Candidates might think PAT can handle all traffic, but PAT only translates multiple private addresses to a single public address and does not allow unsolicited inbound connections without additional configuration.

D

Candidates might focus on the ACL and PAT keyword but overlook the interface configuration, which is a common misconfiguration in NAT setups.

1114
MCQhard

A switch trunk is carrying several VLANs, but VLAN 99 traffic is failing. The trunk allowed list includes VLAN 99 on both sides. Which statement best explains why a VLAN can still fail even when it is allowed?

A.Because the VLAN may still be absent, inactive, or otherwise not operational locally even if it is allowed on the trunk
B.Because allowing a VLAN on a trunk automatically disables it
C.Because VLANs can cross trunks only when PAT is enabled
D.Because VLAN 99 must always be the native VLAN
AnswerA

An entry in the trunk's allowed VLAN list only authorizes 802.1Q frames for that VLAN to pass; it does not create or activate the VLAN. If VLAN 99 is absent from the local VLAN database, is administratively shutdown with the 'shutdown vlan' command, or has no active member ports or up SVI, it is not operational locally. Therefore, even though the trunk configuration permits VLAN 99, end-to-end connectivity will fail because the VLAN is not functioning on the switch itself.

Why this answer

A VLAN can still fail across a trunk even when it is allowed because the allowed list is only one part of the overall design. In plain language, a switch may permit the VLAN on the link, but if the VLAN does not actually exist locally, is not active, or if some other trunk characteristic is inconsistent, traffic can still fail. This is an important CCNA troubleshooting principle: one correct line of configuration does not guarantee the full end-to-end condition is correct.

Candidates often stop at the allowed VLAN list because it is visible in common show commands. However, VLAN presence, local status, and other trunk parameters still matter. The best answer is the one recognizing that permission on the trunk does not automatically prove the entire VLAN path is healthy.

Exam trap

A common exam trap is assuming that simply including VLAN 99 in the trunk allowed list guarantees that VLAN 99 traffic will pass. Many candidates stop troubleshooting once they see the VLAN is allowed on the trunk, neglecting to verify if VLAN 99 is actually created and active on each switch. This mistake leads to incorrect conclusions, as the allowed list only controls trunk forwarding permissions, not VLAN existence or operational status.

The exam tests your understanding that VLAN configuration and status are equally critical for successful VLAN traffic flow.

Why the other options are wrong

B

Incorrect. Allowing a VLAN on a trunk does not disable it; this option contradicts how VLANs and trunks operate in Cisco switches.

C

Incorrect. Port Address Translation (PAT) is unrelated to VLAN trunking. VLANs do not require PAT to cross trunks.

D

Incorrect. VLAN 99 does not have to be the native VLAN to function on a trunk. The native VLAN is independent of VLAN allowance and operation.

When would these options actually be correct?

B

In a different scenario, if a question stated that enabling a VLAN on a trunk link would automatically disable it due to a misconfiguration or a specific switch model behavior, then this option could be correct. For example, a question could involve a legacy switch that has a unique feature where enabling VLANs on a trunk link disables them until explicitly activated.

C

In a scenario where the question asks about the conditions under which VLANs can only communicate across trunks if Port Address Translation (PAT) is enabled, this option would be correct. For example, if the exam focused on specific configurations that require PAT for inter-VLAN routing, then this statement would apply.

D

In a different question, if it were stated that VLAN 99 must be the native VLAN for traffic to be allowed on the trunk, then this option would be correct. For example, if the question specified that any VLAN must be configured as the native VLAN to pass traffic, then this statement would apply.

Why candidates pick the wrong answer

B

Candidates may find this option tempting because it suggests a direct relationship between VLAN configuration and operational status, which aligns with common misconceptions about VLAN management and trunking behavior.

C

Candidates may choose this option due to a misunderstanding of VLAN configurations and trunking principles, mistakenly believing that enabling a VLAN on a trunk link could somehow interfere with its functionality.

D

Candidates may choose this option due to a misunderstanding of native VLANs and trunk configurations, believing that a VLAN must be the native VLAN to function properly on a trunk link.

1115
PBQhard

You are connected to a multilayer switch MLS1. Configure a static default route for IPv4 that points to next-hop 192.0.2.2, but also configure a floating static default route with an administrative distance of 10 that uses next-hop 198.51.100.2. Additionally, configure a static host route for IPv6 host 2001:db8:1::10/128 via next-hop 2001:db8:1::1. The current configuration has a recursive routing failure for the IPv4 default route because the next-hop 192.0.2.2 is not reachable; you must first fix that by adding a directly connected static route. Ensure the floating route becomes active only when the primary route fails.

Network Topology
192.0.2.2/30G0/0SiMLS1R2

Hints

  • •The default route fails because the next-hop is not directly connected and there is no route to reach it.
  • •You need a static route to the network containing 192.0.2.2, specifying the outgoing interface.
  • •Use the command 'ip route 192.0.2.0 255.255.255.252 GigabitEthernet0/0 192.0.2.2' to fix recursive routing.
A.ip route 0.0.0.0 0.0.0.0 192.0.2.2 ip route 0.0.0.0 0.0.0.0 198.51.100.2 10 ip route 192.0.2.0 255.255.255.252 GigabitEthernet0/0 192.0.2.2 ipv6 route 2001:db8:1::10/128 2001:db8:1::1
B.ip route 0.0.0.0 0.0.0.0 192.0.2.2 ip route 0.0.0.0 0.0.0.0 198.51.100.2 10 ip route 192.0.2.0 255.255.255.0 GigabitEthernet0/0 ipv6 route 2001:db8:1::10/128 2001:db8:1::1
C.ip route 0.0.0.0 0.0.0.0 192.0.2.2 ip route 0.0.0.0 0.0.0.0 198.51.100.2 10 ip route 192.0.2.2 255.255.255.255 GigabitEthernet0/0 ipv6 route 2001:db8:1::10/128 2001:db8:1::1
D.ip route 0.0.0.0 0.0.0.0 192.0.2.2 ip route 0.0.0.0 0.0.0.0 198.51.100.2 10 ip route 192.0.2.0 255.255.255.252 198.51.100.2 ipv6 route 2001:db8:1::10/128 2001:db8:1::1
AnswerA
solution
! MLS1
configure terminal
ip route 192.0.2.0 255.255.255.252 GigabitEthernet0/0 192.0.2.2

Why this answer

The IPv4 primary default route fails because next-hop 192.0.2.2 is not directly connected and no recursive route exists to it. The floating static route with next-hop 198.51.100.2 is in the directly connected Vlan20 subnet (198.51.100.1/30), so it installs without issue. To fix the primary default route, add a directly connected static route for the network containing 192.0.2.2, e.g., ip route 192.0.2.0 255.255.255.252 GigabitEthernet0/0 192.0.2.2.

The IPv6 host route is correct if next-hop 2001:db8:1::1 is reachable.

Exam trap

Be careful with recursive routing failures: a static route with a next-hop that is not directly connected requires a route to that next-hop in the routing table. Always ensure the next-hop is reachable, either by a directly connected route or another static/dynamic route. Also, remember that a floating static route uses a higher administrative distance than the primary route, so it only becomes active when the primary route is removed.

Why the other options are wrong

B

The specific factual error is using an incorrect subnet mask and omitting the next-hop IP in the directly connected static route. The mask should match the point-to-point link (typically /30 or /31), and the next-hop must be specified to ensure the route is directly connected.

C

The specific factual error is using a /32 mask instead of the subnet mask of the link. A /32 route to the next-hop IP is a valid workaround but is not the standard practice; the question expects a directly connected route to the network containing the next-hop, not a host route.

D

The specific factual error is using the floating route's next-hop as the next-hop for the directly connected route. The directly connected route must be to the network containing 192.0.2.2, not to the backup next-hop.

Why candidates pick the wrong answer

B

Candidates might think a /24 mask is acceptable because it includes the next-hop IP, but they forget that a static route to a directly connected network should use the exact prefix length of the interface subnet.

C

Candidates might think a host route to the next-hop is sufficient to resolve the recursive routing failure, and it does work, but it is not the intended solution. The question asks for a 'directly connected static route' to the network, implying a subnet route.

D

Candidates might confuse the two next-hops and think that pointing the directly connected route to the backup next-hop will somehow make the primary route work, but it does not resolve the recursive routing failure for 192.0.2.2.

1116
MCQhard

An administrator wants to permit HTTP and HTTPS from 10.1.10.0/24 to a web server at 198.51.100.20 and deny everything else from that subnet. Which ACL type is required?

A.Named standard ACL
B.Extended ACL
C.Prefix list
D.MAC access-list
AnswerB

An extended ACL is required because the administrator needs to match both HTTP (TCP/80) and HTTPS (TCP/443) from a specific source address. Extended ACLs evaluate source and destination IP, protocol (TCP), and destination port numbers, enabling precise filtering of application-layer traffic. The syntax, such as permit tcp host 10.0.0.1 any eq 80 and eq 443, supports matching these services. This granularity is exactly what the scenario demands, making it the correct choice.

Why this answer

A standard ACL can match only the source address. To permit specific protocols and ports such as TCP 80 and 443 to a specific destination, the administrator must use an extended ACL.

Exam trap

A frequent exam trap is selecting a standard ACL when the question requires filtering by both source and destination IP addresses plus specific protocols or ports. Standard ACLs only filter by source IP, so they cannot distinguish HTTP or HTTPS traffic to a particular destination. Another trap is confusing prefix lists or MAC access-lists as suitable options; prefix lists filter routes, not traffic by port, and MAC access-lists filter Layer 2 addresses, not Layer 3 or 4 information.

Misunderstanding these differences leads to incorrect ACL type selection and exam failure.

Why the other options are wrong

A

Named standard ACLs filter traffic only by source IP address and cannot filter by destination IP or specific TCP ports like 80 or 443, making them unsuitable for permitting HTTP and HTTPS to a specific server.

C

Prefix lists are used to filter routes based on IP prefixes in routing protocols and cannot filter traffic by protocol or port, so they cannot meet the requirement to permit HTTP and HTTPS traffic specifically.

D

MAC access-lists filter traffic based on Layer 2 MAC addresses and cannot filter by Layer 3 IP addresses or Layer 4 ports, so they cannot selectively permit HTTP and HTTPS traffic to a specific IP address.

When would these options actually be correct?

A

In a different scenario where the requirement is to permit all traffic from a specific source IP address to any destination without specifying protocols or ports, a named standard ACL would be appropriate. For example, if the question asked to allow all traffic from 10.1.10.0/24 to any destination, a named standard ACL would suffice.

C

If the exam question asked about filtering routes for a specific subnet to control which networks can be advertised or learned, a prefix list would be the correct answer. For example, a question might ask how to allow only certain subnets to be advertised to a routing protocol.

D

If the question were to ask about filtering traffic based on MAC addresses within a local network segment, such as allowing specific devices to communicate while blocking others, then a MAC access-list would be the correct choice.

Why candidates pick the wrong answer

A

Candidates may choose this option due to familiarity with standard ACLs and their use in controlling traffic based on source IP addresses, leading them to overlook the need for protocol and port specificity in this case.

C

Candidates may confuse prefix lists with access control lists due to their similar purpose in network management, leading them to mistakenly believe that prefix lists can also handle traffic filtering based on protocols and ports.

D

Candidates may confuse MAC access-lists with other types of access control lists due to their general understanding of network security, leading them to incorrectly assume that MAC filtering could apply to IP-based protocols like HTTP and HTTPS.

1117
PBQhard

You are connected to R1. Configure R1 as a DHCP server for VLAN 20 clients (192.168.20.0/24) with DNS server 203.0.113.10 and default gateway 192.168.20.1. On switch SW1, enable DHCP snooping globally and on VLAN 20, configure the uplink to R1 as trusted, and ensure that the DHCP server is reachable via ip helper-address on the VLAN 20 SVI. Currently, clients are not receiving IP addresses because of misconfigurations: the excluded-address range on R1 is too large (excluding the entire subnet), the helper-address on SW1 points to a wrong IP (192.0.2.99), and a rogue DHCP server is connected to port Fa0/3 on SW1. Fix all issues so that clients can get addresses securely.

Hints

  • •The excluded-address range is too broad; narrow it to only the gateway and a small reserved range.
  • •The helper-address must point to the DHCP server's IP, which is on a different subnet.
  • •DHCP snooping must be enabled globally and per VLAN, and the port connecting to the legitimate DHCP server must be trusted.
A.On R1, change the excluded-address range to 192.168.20.1 192.168.20.1; on SW1, configure ip helper-address 10.0.0.1 under interface Vlan20; enable DHCP snooping globally and on VLAN 20, and configure the uplink to R1 as trusted.
B.On R1, remove the excluded-address range entirely; on SW1, configure ip helper-address 192.168.20.1 under interface Vlan20; enable DHCP snooping globally and on VLAN 20, and configure the uplink to R1 as trusted.
C.On R1, change the excluded-address range to 192.168.20.1 192.168.20.254; on SW1, configure ip helper-address 192.0.2.99 under interface Vlan20; enable DHCP snooping globally and on VLAN 20, and configure the uplink to R1 as trusted.
D.On R1, change the excluded-address range to 192.168.20.1 192.168.20.1; on SW1, configure ip helper-address 10.0.0.1 under interface Vlan20; enable DHCP snooping globally and on VLAN 20, but do not configure any trusted ports.
AnswerA
solution
! R1
no ip dhcp excluded-address 192.168.20.0 192.168.20.255
ip dhcp excluded-address 192.168.20.1
ip dhcp excluded-address 192.168.20.2 192.168.20.10

! SW1
ip dhcp snooping
ip dhcp snooping vlan 20
interface FastEthernet0/1
ip dhcp snooping trust
exit
interface Vlan20
no ip helper-address 192.0.2.99
ip helper-address 10.0.0.1

Why this answer

The DHCP server had an excluded-address range covering the entire subnet (192.168.20.0–255), which prevented any IP from being assigned. Fix: change the excluded range to only include the gateway (192.168.20.1) and optionally other reserved addresses. The helper-address on SW1 pointed to 192.0.2.99 (nonexistent) instead of the DHCP server at 10.0.0.1; correct it.

DHCP snooping was disabled; enable it globally and on VLAN 20, then configure the uplink to R1 (port connecting to R1) as trusted and the port connecting the rogue server (Fa0/3) as untrusted (or simply leave it untrusted by default, but the rogue server will be blocked).

Exam trap

A common trap is forgetting that the excluded-address range should only reserve specific addresses, not the whole subnet. Another trap is confusing the helper-address with the default gateway or leaving the incorrect IP. Also, many candidates enable DHCP snooping but forget to configure the trusted port, which breaks legitimate DHCP traffic.

Why the other options are wrong

B

The helper-address must point to the DHCP server, not the default gateway. The excluded-address range should include the gateway to prevent conflicts.

C

The excluded-address range must be limited to reserved addresses only, not the entire usable range. The helper-address must be corrected to 10.0.0.1.

D

DHCP snooping requires the port connected to the legitimate DHCP server to be explicitly trusted; otherwise, all DHCP server messages are discarded.

Why candidates pick the wrong answer

B

Candidates may think that the gateway IP can be assigned to clients and that the helper-address should be the gateway, confusing the roles of DHCP and routing.

C

Candidates might think that excluding a large range is safe or that the helper-address is correct as given, not realizing the IP is incorrect.

D

Candidates may assume that enabling DHCP snooping globally and per VLAN is sufficient, forgetting to designate trusted ports, or they may think the uplink is automatically trusted.

1118
MCQhard

A host is configured as 172.16.20.190/26. Which range contains the usable host addresses for that subnet?

A.172.16.20.129 to 172.16.20.190
B.172.16.20.128 to 172.16.20.191
C.172.16.20.130 to 172.16.20.191
D.172.16.20.193 to 172.16.20.254
AnswerA

A /26 mask yields 64 addresses, so the subnet increments by 64 in the fourth octet: 172.16.20.128 to 172.16.20.191. Excluding the network (.128) and broadcast (.191) addresses leaves usable hosts 172.16.20.129 through 172.16.20.190, which matches the host's own subnet exactly.

Why this answer

A /26 uses blocks of 64 addresses. In practical terms, the fourth-octet ranges are 0–63, 64–127, 128–191, and 192–255. Since 190 falls inside the 128–191 block, the network address is .128 and the broadcast address is .191. That leaves .129 through .190 as the usable range.

This is a strong test of whether you can identify the correct block and then exclude the reserved boundary addresses correctly.

Exam trap

A frequent exam trap is selecting an answer range that includes the network or broadcast address as usable hosts. For example, option B lists 172.16.20.128 to 172.16.20.191, which incorrectly includes the network (.128) and broadcast (.191) addresses. These addresses are reserved and cannot be assigned to hosts.

Another trap is excluding valid host addresses or including addresses from adjacent subnets, as seen in options C and D. Misidentifying subnet boundaries or forgetting to exclude reserved addresses causes these errors, leading to incorrect subnetting answers.

Why the other options are wrong

B

Option B incorrectly includes the network address (172.16.20.128) and broadcast address (172.16.20.191) as usable hosts, which are reserved and cannot be assigned to devices, making this option invalid.

C

Option C excludes the first usable host address (172.16.20.129) and incorrectly includes the broadcast address (172.16.20.191), which is not assignable to hosts, thus making it an incorrect range.

D

Option D lists a range starting at 172.16.20.193, which belongs to the next subnet block (192–255) and does not include the IP 172.16.20.190, so it is unrelated and incorrect for this question.

When would these options actually be correct?

B

If the question asked for the range of all IP addresses within the subnet, including the network and broadcast addresses, then option B would be correct, as it would encompass the entire range from 172.16.20.128 to 172.16.20.191.

C

If the question specified a subnet mask of /25 instead of /26, the usable host range would be 172.16.20.129 to 172.16.20.254, making option C correct as it would then include valid host addresses within that range.

D

If the question specified a different subnet, such as 172.16.20.192/26, then option D would be correct, as it would represent the usable host addresses within that subnet range.

Why candidates pick the wrong answer

B

Candidates may choose this option because it closely resembles the correct range and includes the last usable address, leading to confusion between usable and total address ranges in subnetting.

C

Candidates may choose option C due to confusion about subnet boundaries, mistakenly thinking that the broadcast address can be included in the usable range, especially if they miscalculate the subnet mask.

D

Candidates might choose this option due to a misunderstanding of subnetting boundaries, mistakenly believing that addresses beyond the subnet's defined range could still be valid host addresses.

1119
PBQhard

You are connected to SW1. The network has three switches (SW1, SW2, SW3) running Rapid-PVST+. SW1 should be the root bridge for VLAN 10. PortFast and BPDU Guard must be enabled on all edge ports connected to end hosts. An err-disabled port (G0/1) has occurred due to a BPDU violation on an edge port. Recover the port and ensure it is configured correctly to prevent recurrence.

Network Topology
Gi0/0Gi0/0Gi0/2Gi0/0Gi0/1SW1SW2SW3Host

Hints

  • •The port is in err-disabled state. You need to manually recover it by cycling the interface.
  • •After recovery, verify the port is forwarding and still has PortFast and BPDU Guard enabled.
  • •If the err-disabled condition recurs, the connected device may be sending BPDUs; consider removing BPDU Guard from that port if it is not truly an edge port.
A.Enter interface configuration mode for Gi0/1, issue 'shutdown' followed by 'no shutdown', then configure 'spanning-tree bpduguard disable' on the interface.
B.Enter interface configuration mode for Gi0/1, issue 'shutdown' followed by 'no shutdown', then configure 'spanning-tree portfast' and 'spanning-tree bpduguard enable' on the interface.
C.Enter interface configuration mode for Gi0/1, issue 'shutdown' followed by 'no shutdown', then configure 'spanning-tree guard root' on the interface.
D.Enter interface configuration mode for Gi0/1, issue 'shutdown' followed by 'no shutdown', then verify that the connected device is not a switch or remove it from the network.
AnswerD
solution
! SW1
configure terminal
interface gigabitEthernet 0/1
shutdown
no shutdown
end

Why this answer

The port Gi0/1 is in err-disabled state because BPDU Guard disabled it after receiving a BPDU on a PortFast edge port. First, shut down the interface and then re-enable it with 'no shutdown' to recover from err-disabled. However, to prevent recurrence, the root cause must be addressed: the connected device (likely another switch) should not be sending BPDUs on an edge port.

Optionally, you can disable BPDU Guard on that specific port if it is not truly an edge port, but the task requires PortFast and BPDU Guard on edge ports. The correct fix is to ensure no BPDUs are sent from the downstream device or use 'spanning-tree bpduguard disable' on that port if it is not an edge port (but the task mandates BPDU Guard). Since the scenario requires BPDU Guard, the candidate should recover the port and then verify that the connected device is not a switch (or remove it from the topology).

Exam trap

The exam trap is that candidates may focus on recovering the port (shutdown/no shutdown) but forget to address why the BPDU was received. Simply re-enabling BPDU Guard or reapplying PortFast will not prevent recurrence. The key is to ensure the connected device is not sending BPDUs, either by removing it or reclassifying the port.

Why the other options are wrong

A

The specific factual error is that BPDU Guard should not be disabled on a port that is supposed to be an edge port with BPDU Guard enabled.

B

The specific factual error is that simply re-enabling the same features does not prevent recurrence; the source of BPDUs must be removed or the port must be reconfigured as a non-edge port.

C

The specific factual error is that Root Guard and BPDU Guard serve different purposes; Root Guard does not stop BPDU Guard from disabling the port.

Why candidates pick the wrong answer

A

Candidates may think that disabling BPDU Guard prevents the port from going err-disabled again, but this contradicts the requirement to keep BPDU Guard enabled.

B

Candidates may think that re-applying the configuration ensures the port is correctly configured, but they overlook that the BPDU source is still present.

C

Candidates may confuse Root Guard with BPDU Guard or think that any spanning-tree guard feature can solve the issue.

1120
Drag & Dropmedium

Drag and drop the following steps into the correct order to interpret packet capture output for L2/L3 troubleshooting.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
6Step 6

Why this order

The logical troubleshooting sequence for packet capture analysis starts at Layer 2 to verify the data link layer. First, examine the source and destination MAC addresses in the Ethernet header to confirm correct frame delivery. Next, check for ARP requests and responses to ensure proper IP-to-MAC resolution.

Then, analyze the source and destination IP addresses to verify Layer 3 addressing and routing. After that, look for ICMP Destination Unreachable or Time Exceeded messages to identify network path issues. Proceed to inspect transport layer port numbers (TCP/UDP) to identify the service and possible blocking.

Finally, review TCP flags (e.g., SYN, RST, FIN) to understand session state and detect retransmissions or connection issues.

1121
Multi-Selectmedium

Which three statements accurately describe the role of Cisco's AI-powered security features (such as Cisco AI Network Analytics, Stealthwatch, or DNA Center's AI-Enhanced Analytics) in network security operations? (Choose three.)

Select 3 answers
.AI models can detect zero-day exploits by analyzing behavioral anomalies
.AI-powered systems can correlate logs from multiple sources to identify complex attack chains
.AI can automate the response to certain security incidents, such as blocking malicious IPs
.AI is only effective against known, signature-based threats
.AI eliminates the need for firewall rules and access control lists
.AI security models require no human oversight once deployed

Why this answer

Cisco's AI-powered security features detect zero-day exploits by analyzing behavioral anomalies and deviations from learned baselines, without relying on signatures. These systems correlate logs from multiple Cisco products (e.g., firewalls, endpoints, cloud) to uncover multi-step attack chains. AI can also automate responses such as blocking malicious IPs via Cisco security controls, reducing mean time to respond (MTTR).

However, AI complements but does not replace traditional security tools like firewall rules or ACLs, and it requires ongoing human oversight for validation and tuning.

Exam trap

Cisco often tests the misconception that AI is only for signature-based detection or that it fully replaces traditional security controls, when in reality AI complements existing tools and still requires human oversight.

1122
MCQhard

A router has the following routes in its routing table: a static route to 10.60.4.16/28, an OSPF route to 10.60.4.0/24, and an EIGRP route to 10.60.0.0/16. Which route will be used for a packet destined to 10.60.4.17?

A.The static route to 10.60.4.16/28
B.The OSPF route to 10.60.4.0/24
C.The EIGRP route to 10.60.0.0/16
D.No route at all
AnswerA

The destination address 10.60.4.17 falls within all three advertised prefixes, but the router selects the route with the longest prefix match. The static route to 10.60.4.16/28 uses a 28-bit subnet mask, which is longer than the 24-bit OSPF route and the 16-bit EIGRP route. Because this /28 prefix provides the most specific match for the destination, it overrides the other less-specific entries in the routing table.

Why this answer

The route used will be the route with the longest matching prefix. In practical terms, 10.60.4.17 falls inside the /28 route shown, and that is more specific than the broader /24 and /16 alternatives. Because specificity comes first, the /28 route wins.

This is a clean route-table interpretation problem that mirrors actual exam-style thinking very closely.

Exam trap

Remember, the longest prefix match rule is crucial; don't assume broader prefixes are better.

Why the other options are wrong

B

This option is wrong because the OSPF route to 10.60.4.0/24 does not directly match the destination 10.60.4.17, which falls under the static route to 10.60.4.16/28. OSPF would not be preferred if a more specific static route exists.

C

The EIGRP route to 10.60.0.0/16 is not used for the destination 10.60.4.17 because it does not match the more specific subnet of 10.60.4.16/28, which is preferred in routing decisions.

D

This option is wrong because there is a valid static route to the destination 10.60.4.17 via the static route to 10.60.4.16/28, making it reachable. Therefore, stating 'no route at all' is incorrect in this context.

When would these options actually be correct?

B

If the question asked which route would be used for a destination within the 10.60.4.0/24 subnet without a more specific static route, then the OSPF route to 10.60.4.0/24 would be the correct answer, as it would be the best match for any address in that range.

C

If the question asked which route would be used if the static route to 10.60.4.16/28 were removed, then the EIGRP route to 10.60.0.0/16 would be the correct answer, as it would be the next best match for the destination.

D

In a scenario where the routing table has been cleared or all routes have been removed, a question could ask if there are any routes available for destination 10.60.4.17. In this case, the correct answer would be 'No route at all' as there would be no valid paths to the destination.

Why candidates pick the wrong answer

B

Candidates might choose this option due to a misunderstanding of OSPF's role in routing, believing that OSPF routes are always preferred over static routes, especially when they see a broader subnet that includes the destination.

C

Candidates may choose this option due to familiarity with EIGRP and its broader subnet coverage, mistakenly believing it would be preferred over a more specific static route.

D

Candidates may choose this option due to a misunderstanding of the routing table's contents or a lack of familiarity with static versus dynamic routes, leading them to believe that if a specific route isn't mentioned, none exist.

1123
MCQmedium

A network operations team is implementing an automated system to detect and remediate interface flapping on core switches. The system must be able to query the network device for interface status and execute commands to disable or reconfigure the interface if a pattern of flapping is detected. Which protocol or technology enables the system to programmatically interact with the network device for both monitoring and configuration changes?

A.SNMP
B.NETCONF
C.CLI scripting
D.Syslog
AnswerB

NETCONF is the correct protocol because it defines IETF-standard XML-based RPCs executed over SSH, allowing an automation agent to retrieve, install, manipulate, and delete device configuration. It operates on multiple datastores (candidate, running, startup) with support for validation, commit, and rollback, and is coupled with YANG models to provide structured, vendor-neutral data. This transactional model-driven design makes NETCONF ideal for closed-loop remediation where an autonomous agent must reliably implement config changes and undo them on failure.

Why this answer

NETCONF is the correct choice because it is a standardized network configuration protocol that allows automated systems to retrieve operational data and push configuration changes securely. In this scenario, the system would use NETCONF to query interface status and then apply remediation configurations. SNMP can monitor but has limited configuration capabilities, CLI scripting is non-programmatic and error-prone, and Syslog is only for logging.

Exam trap

Many candidates confuse SNMP with configuration protocols, but SNMP is not designed for robust configuration management; NETCONF and RESTCONF are the modern programmatic interfaces emphasized in CCNA automation topics.

Why the other options are wrong

A

SNMP is limited to monitoring and basic sets, not suited for complex remediation workflows.

C

CLI scripting lacks structured programmability and is error-prone for automation.

D

Syslog is a logging protocol and cannot be used to push configuration changes.

1124
MCQhard

A switch port connected to a user PC is configured as a trunk. The PC cannot communicate normally. What is the best explanation?

A.The port role is wrong because a normal PC-facing switchport should usually be an access port, not a trunk
B.A user PC requires EtherChannel to function
C.Trunk mode disables MAC address learning automatically
D.Trunk mode forces the switch to stop using IP addressing
AnswerA

A normal PC expects to receive and send untagged Ethernet frames in a single VLAN, so the switchport facing it should be an access port assigned to one access VLAN. Configuring it as a trunk makes the switch tag frames with 802.1Q headers, which the PC's NIC typically cannot process, breaking connectivity. Thus the port role is the primary misconfiguration.

Why this answer

The best explanation is that the port role is wrong: a PC-facing port should be an access port, not a trunk, because PCs normally send untagged frames and cannot process VLAN tags. Option B is incorrect because EtherChannel is used for link aggregation, not required for a single PC. Option C is wrong because trunk mode does not disable MAC address learning.

Option D is irrelevant, as switches do not stop using IP addressing in trunk mode.

Exam trap

Be careful not to confuse physical link issues with logical configuration mismatches. A trunk port on a user PC is a logical mismatch, not a hardware failure.

Why the other options are wrong

B

A user PC does not require EtherChannel to function; EtherChannel is a method for bundling multiple physical links into a single logical link, which is not necessary for standard PC connectivity.

C

Trunk mode does not disable MAC address learning; it actually allows the switch to learn MAC addresses from multiple VLANs. Therefore, a switch port configured as a trunk can still learn MAC addresses normally.

D

Trunk mode does not disable IP addressing; it allows multiple VLANs to be carried over a single link, and IP addressing is still applicable to the switch interfaces. Therefore, the user PC's inability to communicate is not due to trunk mode disabling IP addressing.

When would these options actually be correct?

B

In a different question scenario where a network engineer is troubleshooting a link aggregation setup, a user PC connected to a switch port configured for EtherChannel might fail to communicate if EtherChannel is misconfigured or not properly negotiated, making this option correct.

C

In a scenario where a question states that a switch is configured to prevent MAC address learning for security reasons, and a user PC is connected to a trunk port, this option would be correct. The question would need to specify that MAC address learning is intentionally disabled on trunk ports.

D

In a scenario where a question states that a switch is configured to only allow access ports and is explicitly designed to prevent any IP addressing on trunk ports, option D could be correct. For example, if the question specifies that the switch's configuration is intended to isolate VLANs without IP communication, then trunk mode would indeed stop IP addressing.

Why candidates pick the wrong answer

B

Candidates may choose this option due to a misunderstanding of network configurations, believing that advanced features like EtherChannel are necessary for all devices, especially in complex environments.

C

Candidates may confuse trunk mode with other configurations that limit MAC address learning, leading them to believe that trunking could inherently disable this feature. This misconception can arise from a lack of understanding of how VLANs and trunking work.

D

Candidates may confuse trunk mode with access mode capabilities and mistakenly believe that trunking limits IP addressing, especially if they have encountered scenarios where VLAN configurations affect communication. This misunderstanding can lead them to choose this option when they see 'trunk mode' mentioned.

1125
MCQhard

A host is assigned 192.168.10.33/28. Which subnet contains that host?

A.192.168.10.16/28
B.192.168.10.32/28
C.192.168.10.48/28
D.192.168.10.0/28
AnswerB

A /28 prefix length yields a block size of 16 addresses, so subnets are aligned on multiples of 16: 0, 16, 32, 48, and so on. The host address 192.168.10.33 falls in the range 32–47, making 192.168.10.32/28 the correct subnet. Within that block, .33 is a usable address, as the network and broadcast addresses are .32 and .47 respectively.

Why this answer

A /28 subnet uses blocks of 16 addresses. In plain language, the last octet ranges move in increments of 16: 0–15, 16–31, 32–47, 48–63, and so on. Since the host address ends in 33, it belongs to the 32–47 block. That means the containing subnet is 192.168.10.32/28.

This style of subnetting question is common because it tests whether you can identify the correct network boundary quickly. The key is to recognize the block size from the prefix and then place the address inside the correct interval without confusing the host with the network address.

Exam trap

Be careful not to confuse the host address with the network address or miscalculate the subnet boundaries.

Why the other options are wrong

A

Option A (192.168.10.16/28) is incorrect because it represents a different subnet, specifically the range 192.168.10.16 to 192.168.10.31, which does not include the host 192.168.10.33.

C

Option C is wrong because the host IP 192.168.10.33/28 falls within the subnet range of 192.168.10.32 to 192.168.10.47, making 192.168.10.48/28 an entirely different subnet that does not include the host.

D

Option D (192.168.10.0/28) is incorrect because it represents a different subnet than the one containing the host 192.168.10.33. The subnet for 192.168.10.33/28 is 192.168.10.32/28, which includes IPs from 192.168.10.32 to 192.168.10.47.

When would these options actually be correct?

A

If the question asked for the subnet that includes the IP address 192.168.10.33 with a subnet mask of /27 instead of /28, option A would be correct, as 192.168.10.16/27 encompasses the range from 192.168.10.16 to 192.168.10.47.

C

If the question asked for the next subnet after 192.168.10.32/28, then 192.168.10.48/28 would be the correct answer, as it represents the subsequent subnet in the sequence.

D

If the question asked for the subnet that includes the first usable IP address in the 192.168.10.0/28 range, then option D would be correct, as 192.168.10.0 is the network address for that subnet.

Why candidates pick the wrong answer

A

Candidates may choose this option due to a misunderstanding of subnetting, mistakenly believing that the first subnet in the range is always the correct answer without calculating the specific subnet for the given IP address.

C

Candidates might choose this option due to a misunderstanding of subnetting boundaries, mistakenly believing that 192.168.10.48 is close enough to the given host IP to be relevant.

D

Candidates may mistakenly choose option D because they recognize 192.168.10.0 as a common network address and may not fully understand the implications of subnetting and the specific range of usable IPs.

Page 14

Page 15 of 20

Page 16