Courseiva

CCNA 200-301 v2 (200-301) — Questions 301–375

1450 questions total · 20pages · All types, answers revealed

Page 4

Page 5 of 20

Page 6
301
MCQhard

A network engineer notices that users in VLAN 10 report intermittent connectivity and slow file transfers to a server on the same switch. The engineer issues the show interfaces fa0/1 command on the switch port connected to the server and observes a high number of runts, input errors, and CRC errors, while output errors are minimal. The interface configuration shows speed 100 and duplex full.

A.The server NIC is set to 10 Mbps half-duplex, causing a speed mismatch.
B.The server NIC is auto-negotiating to 100 Mbps half-duplex, resulting in a duplex mismatch.
C.The cable connecting the server to the switch is faulty, introducing excessive noise.
D.The switch port is configured with an incorrect native VLAN, causing duplex negotiation issues.
AnswerB

With the switch forced to full-duplex and the server using auto-negotiation, the server defaults to half-duplex. The duplex mismatch leads to collisions on the half-duplex side, generating runts, CRC errors, and input errors on the switch port.

Why this answer

The symptoms—high runts, input errors, and CRC errors with minimal output errors—are classic indicators of a duplex mismatch. When the switch port is hardcoded to 100 Mbps full-duplex and the server NIC auto-negotiates to 100 Mbps half-duplex (a common fallback when one side is manually set), the half-duplex side experiences collisions while the full-duplex side does not sense the collision. These collisions cause the half-duplex side to truncate frames, resulting in runts and CRC errors on the full-duplex switch port.

The speed matches (both 100 Mbps), so the issue is purely duplex-related.

Exam trap

Cisco often tests the misconception that speed and duplex mismatches always occur together; the trap here is that a duplex mismatch can exist even when speed matches, and the error pattern (high input errors, low output errors) specifically points to duplex, not cabling or VLAN issues.

Why the other options are wrong

A

Misconception that speed mismatch produces specific error counters; in reality, incompatible speeds cause link failure, not runts and CRC errors.

C

Misconception that CRC errors alone point to a bad cable; duplex mismatch is one of the most common causes of runts and CRC errors on forced-full interfaces.

D

Misconception that a VLAN mismatch can trigger interface errors; these errors are purely physical/data-link layer phenomena unrelated to VLAN settings.

302
Matchingmedium

Match each programmability term to its most accurate description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Structured representation of configuration or state

Common machine-readable data format

Specific API target or path

Credential-like access value

Why these pairings

Each term is correctly matched with its standard definition in software development and API contexts.

Exam trap

Candidates often confuse APIs with programming languages or protocols. Remember that an API is an interface, not a language or a protocol itself. It enables communication between different software systems.

When would these options actually be correct?

B

If the question asked 'Which programming language is commonly used to write automation scripts for network devices?' then Python would be a correct answer, but the term 'API' would not match that description.

C

If the question asked to match a term like 'router' or 'modem' to the description 'A hardware component that connects network devices to the internet', then this option would be correct.

D

In a question asking 'Which security protocol encrypts data transmitted over a network?', options like TLS, IPsec, or SSL would be correct. If the question were about a protocol that provides encryption, D would be correct if it named a specific encryption protocol.

Why candidates pick the wrong answer

B

Candidates may confuse APIs with scripting languages because both are used in network automation, and they often use APIs via scripts, leading to the misconception that an API is a language.

C

Candidates may confuse the term 'API' with 'access point' or assume that any technology term related to networking could be a physical device, leading them to select a hardware-related description.

D

Candidates may confuse API with security terms because APIs often use encryption (e.g., HTTPS) and are involved in secure communications, leading them to think API itself is a security protocol.

303
MCQhard

An administrator wants to permit SSH management access but block Telnet access to a device. Which statement best reflects that design goal?

A.SSH is preferred because it provides encrypted remote administration, unlike Telnet
B.Telnet is preferred because it provides stronger confidentiality than SSH
C.SSH can be used only on Layer 2 switches and not routers
D.Blocking Telnet automatically disables all AAA functions
AnswerA

SSH encrypts the entire management session, including credentials and commands, whereas Telnet transmits them in cleartext. Permitting SSH while blocking Telnet therefore meets the design goal of secure remote administration without exposing credentials to interception on the management path.

Why this answer

Permitting SSH while blocking Telnet is a hardening decision because SSH encrypts management traffic and Telnet does not. The administrator wants remote access to remain available with credentials and session data protected. Option A is correct: SSH provides encrypted remote administration.

Option B is wrong: Telnet offers no confidentiality. Option C is wrong: SSH works on routers and Layer 3 switches, not only Layer 2 switches. Option D is wrong: blocking Telnet does not disable AAA; AAA can still function over SSH or local authentication.

Exam trap

Avoid assuming that enabling both protocols or disabling both achieves security goals. Focus on encryption as the key factor.

Why the other options are wrong

B

Telnet transmits credentials and data in plaintext, so it lacks confidentiality and is less secure than SSH.

C

SSH can be configured on routers, Layer 3 switches, and any device that supports IP connectivity, not just Layer 2 switches.

D

Blocking Telnet only disables unencrypted remote access; AAA functions (e.g., authentication, authorization, accounting) remain operational via SSH or other methods.

When would these options actually be correct?

B

In a hypothetical scenario where a question asks which protocol provides stronger confidentiality in a specific legacy system that has been configured to use Telnet with additional encryption layers, option B could be considered correct. This would imply that the context allows for Telnet to be enhanced beyond its standard capabilities.

C

In a different exam scenario, if the question stated that SSH is only supported on Layer 2 switches and asked which protocol should be used for secure management of Layer 2 devices, then option C would be correct as it aligns with the constraints of that specific context.

D

If a question stated that blocking Telnet access would also disable AAA functions due to a specific device configuration or policy that ties AAA to Telnet sessions, then this option would be correct. For example, if a legacy system required Telnet for AAA operations, blocking it could impact those functionalities.

Why candidates pick the wrong answer

B

A student might confuse the terms 'confidentiality' and 'authentication' or mistakenly think that an older protocol like Telnet could be more secure due to simplicity. Some might also assume that because Telnet is widely used in legacy environments, it must have some security advantage.

C

A test-taker might confuse SSH with a Layer 2 protocol or think that because Telnet is often used for console access on switches, SSH might be restricted. The similarity in names between SSH and other Layer 2 protocols (like STP) could also cause confusion.

D

A student might think that Telnet is a required component for AAA, especially if they have seen AAA configured with Telnet in lab scenarios. The acronym AAA and its association with remote access could lead to the mistaken belief that disabling Telnet breaks AAA.

304
Drag & Drophard

Drag and drop the following steps into the correct order to describe how a router selects the best path and forwards a packet, using the routing table lookup process from destination IP to forwarding decision.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The router first identifies the destination IP, then finds the best matching route using longest prefix match, and forwards to the next hop.

Exam trap

The exam trap here is that candidates often confuse the order of steps, especially placing the longest prefix match before examining the destination IP. Remember: you must know the destination before you can look it up in the routing table.

Why candidates pick the wrong answer

B

Candidates might think the lookup process starts with the routing table because that is where the decision is made, but the destination IP must be extracted first.

C

Candidates might confuse the order because in some contexts, the next hop is known from the routing table entry, but the lookup must happen first.

D

Candidates might think the next hop is predetermined, but it depends on the destination and the routing table.

305
Multi-Selectmedium

Which TWO statements accurately describe how AI and ML concepts are applied to network operations?

Select 2 answers
A.Intent-based networking translates business intent into network policies and continuously validates that the network meets those intentions.
B.Anomaly detection uses ML models to identify deviations from normal traffic baselines, which can indicate security threats or performance issues.
C.Predictive analytics uses historical data to forecast future network conditions and automatically reconfigures network devices to prevent issues.
D.ML models in network operations are trained exclusively on labeled datasets to detect known attack signatures.
E.Rule-based systems are preferred over ML for anomaly detection because they can adapt to new, unknown patterns without manual updates.
AnswersA, B

Intent-based networking (IBN) is a policy-driven framework that captures business intent in natural language or declarative models and translates it into device-level configurations. It continuously validates the actual network state against the intended state using telemetry, model-driven assurance, and closed-loop feedback, taking corrective action when a divergence is detected. This continuous validation differentiates IBN from traditional automation, which merely pushes scripts without ongoing policy verification.

Why this answer

Intent-based networking (IBN) captures business intent in a declarative model, translates it into network policies (e.g., via Cisco DNA Center), and continuously validates that the network state matches the intended outcome using assurance and closed-loop analytics. Option B is correct because anomaly detection leverages ML models to establish a baseline of normal traffic and then flags deviations, which can indicate security threats or performance issues. Option C is incorrect because predictive analytics forecasts future network conditions but does not automatically reconfigure devices; that requires closed-loop automation.

Option D is false because ML models in network operations are not trained exclusively on labeled data; unsupervised learning can detect unknown patterns without labeled datasets. Option E is false because rule-based systems cannot adapt to new, unknown patterns without manual updates, whereas ML models are better suited for anomaly detection due to their ability to learn and generalize from data.

Exam trap

Cisco often tests the distinction between 'predictive analytics' (which forecasts but does not automatically reconfigure) and 'closed-loop automation' (which does), leading candidates to overstate the capabilities of predictive analytics in option C.

Why the other options are wrong

C

Predictive analytics forecasts future network conditions (e.g., link utilization trends) but does not automatically reconfigure devices; automation requires separate closed-loop systems like Cisco DNA Assurance with RMA (reactive, proactive, predictive) workflows. The statement incorrectly combines prediction with automatic reconfiguration.

D

ML models in network operations can be trained using both supervised learning (labeled data for known attacks) and unsupervised learning (unlabeled data to discover unknown patterns). The statement incorrectly claims exclusive use of labeled datasets, ignoring unsupervised anomaly detection which is critical for identifying novel threats.

E

Rule-based systems are static and cannot adapt to new, unknown patterns without manual rule updates. ML models, especially unsupervised learning, excel at detecting anomalies without predefined rules. The statement reverses the strengths of rule-based and ML approaches.

Why candidates pick the wrong answer

C

Students may confuse predictive analytics with closed-loop automation, assuming that forecasting inherently triggers corrective actions. In reality, prediction and automation are distinct functions that can be integrated but are not synonymous.

D

Test-takers may associate ML with supervised learning (e.g., signature-based detection) and overlook unsupervised methods. This confusion arises because traditional security tools often rely on labeled signatures, but modern AI/ML expands to unsupervised learning.

E

Students might think rule-based systems are more reliable because they are deterministic and easier to understand. However, they fail to recognize that ML's adaptability is precisely what makes it superior for detecting unknown patterns in dynamic network environments.

306
Matchingmedium

Match each HTTP method to the action it most commonly performs in a REST API.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Retrieve a resource

Create a new resource

Update or replace a resource

Remove a resource

Why these pairings

All listed mappings are correct according to RESTful API conventions. GET retrieves a resource, POST creates a new resource, PUT replaces an existing resource, and PATCH applies a partial update.

Exam trap

In this question, focus on the four methods given: GET, POST, PUT, PATCH. The most common pitfall is confusing PUT (full replacement) with PATCH (partial update). Also, remember that POST is for creating resources, not for updating or reading.

Do not apply the DELETE concept here.

307
Matchingmedium

Match each STP or switch protection feature to the problem it is mainly designed to prevent.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Reduces delay for an end-host access port to reach forwarding

Err-disables a PortFast port that unexpectedly receives a BPDU

Prevents an access or designated port from becoming a new root port because of superior BPDUs

Helps stop a non-designated port from transitioning to forwarding when BPDUs stop arriving

Why these pairings

STP protection features prevent specific problems: Root Guard protects root bridge election, BPDU Guard prevents loops on access ports, Loop Guard handles BPDU loss, UDLD detects unidirectional links, and PortFast speeds up port transition.

Exam trap

The exam trap is confusing BPDU Guard with Root Guard or Loop Guard. Remember that BPDU Guard specifically protects against rogue switches by shutting down the port if a BPDU is received on a PortFast port.

308
Multi-Selecthard

Which two statements accurately compare IPv4 private addresses and public addresses?

Select 2 answers
A.Private IPv4 addresses are not directly Internet-routable.
B.Public IPv4 addresses are intended to be globally unique and routable.
C.Private IPv4 addresses always require OSPF to function inside a LAN.
D.Public IPv4 addresses cannot exist on Internet-facing devices.
E.Private and public IPv4 addresses are both automatically translated by ARP.
AnswersA, B

Correct because RFC 1918 defines private ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) that are not globally routable; Internet routers are configured to discard packets with these source or destination addresses. This is enforced by ISPs and core routers to prevent conflicts and routing loops, since these addresses are reused by countless internal networks. To access the Internet, private addresses must be translated to a public address using NAT.

Why this answer

Private IPv4 addresses are intended for internal use and are not directly routable on the public Internet. In plain language, they are designed for use inside organizations, homes, and other local environments without consuming globally unique public space. Public addresses, by contrast, are intended to be unique and routable across the Internet. This is one of the main reasons NAT became so common in IPv4 environments.

CCNA questions often test this distinction because learners sometimes confuse “valid inside a LAN” with “routable everywhere.” Private addressing is extremely useful, but it does not eliminate the need for translation or public addressing when reaching the Internet. The two correct statements are the ones that preserve that basic separation between internal-use ranges and globally routable address space.

Exam trap

Be careful not to confuse the routability of private addresses with their validity within a LAN. Private addresses need NAT for Internet access.

Why the other options are wrong

C

Private IPv4 addresses do not require OSPF or any specific routing protocol to function inside a LAN; they can operate with static routes or any dynamic routing protocol. OSPF is just one option and is not mandatory.

D

Public IPv4 addresses are specifically used on Internet-facing devices to enable global reachability. Without public addresses, devices would not be directly accessible from the Internet.

E

ARP (Address Resolution Protocol) resolves IP addresses to MAC addresses on a local network segment and does not perform any translation between private and public addresses. NAT (Network Address Translation) handles that translation.

When would these options actually be correct?

C

If the question were to ask about the requirements for routing protocols in a specific network setup that exclusively uses OSPF for all internal communications, then this statement could be correct. For example, a scenario where a network design mandates OSPF for all routing, including private addresses, would validate this option.

D

If the exam question stated that 'Public IPv4 addresses are only used in private networks' or 'Public IPv4 addresses are never assigned to devices that connect directly to the Internet,' then option D would be correct. Such a scenario would misrepresent the nature of public IP addresses.

E

In a question that asks about the functions of ARP in a network where both private and public addressing schemes are in use, one might state that ARP is involved in the translation process, making this option correct in that context.

Why candidates pick the wrong answer

C

Students might associate private addresses with internal networks and mistakenly think OSPF is commonly used there, but OSPF is not a requirement for private address operation.

D

A student might confuse public addresses with private ones, thinking public addresses are only for internal use, but the opposite is true.

E

The acronym 'ARP' might be confused with 'NAT' or 'PAT' by students who are not clear on the functions of each protocol.

309
Multi-Selectmedium

Which TWO statements are correct regarding Protocol Data Units (PDUs) and data encapsulation in the OSI model?

Select 2 answers
A.The PDU at the Transport layer is called a frame.
B.Data is encapsulated with a TCP header at the Transport layer to form a segment.
C.The Network layer PDU is the packet, which includes the IP header.
D.The Data Link layer adds a header and trailer to create a bit.
E.Encapsulation occurs as data moves up the OSI layers from Physical to Application.
AnswersB, C

At the Transport layer, the protocol adds a TCP or UDP header to the application data, and when TCP is used, the resulting unit is called a segment. This process is part of encapsulation, where the upper-layer payload is wrapped with control information to enable reliable or best-effort delivery between ports. The segment is then handed down to the Network layer for IP encapsulation.

Why this answer

Option B is correct because at the Transport layer, application data is encapsulated with a TCP header (or UDP header) to form a segment, which is the Transport-layer PDU. Option C is correct because the Network layer PDU is the packet, formed by adding an IP header to the segment, providing logical addressing and routing information. Option A is incorrect because a frame is the Data Link layer PDU, not the Transport layer PDU.

Option D is incorrect because the Data Link layer adds a header and trailer to create a frame, not a bit; bits are the Physical layer PDU. Option E is incorrect because encapsulation occurs as data moves down the OSI layers from Application to Physical, not upward.

Exam trap

Cisco often tests the direction of encapsulation (down the stack) versus de-encapsulation (up the stack), and the specific PDU names at each layer, to catch candidates who confuse these fundamental concepts.

Why the other options are wrong

A

This statement incorrectly identifies the Transport layer PDU; it is actually a segment or datagram, while a frame is at Layer 2.

D

Bits are created at the Physical layer, not the Data Link layer; the Data Link layer creates frames.

E

This describes decapsulation, not encapsulation. Encapsulation occurs when moving down the OSI model stack.

310
Multi-Selectmedium

Which TWO statements accurately describe the responsibilities of the OSI model's Transport layer?

Select 2 answers
A.It provides logical addressing and routing to determine the best path for data.
B.It segments data from the upper layers and manages end-to-end flow control.
C.It converts data into electrical signals for transmission over the physical medium.
D.It provides reliable or unreliable delivery of data between applications on different hosts.
E.It encapsulates data into frames and adds source and destination MAC addresses.
AnswersB, D

The Transport layer is responsible for segmenting data received from upper-layer protocols into smaller, manageable units called segments. TCP, for example, implements end-to-end flow control using a sliding window, which prevents a fast sender from overwhelming a slower receiver by adjusting the amount of data transmitted before requiring an acknowledgment. This explicit segmentation and flow-control management is separate from the delivery-reliability service, though both are Transport-layer duties.

Why this answer

The Transport layer (Layer 4) segments data from upper layers and manages end-to-end flow control using mechanisms like TCP's sliding window to prevent overwhelming a slow receiver. Option D is correct because the Transport layer provides either reliable delivery (TCP) or unreliable delivery (UDP) between applications on different hosts, ensuring data reaches the appropriate application via port numbers. Option A is incorrect because logical addressing and routing are functions of the Network layer (Layer 3).

Option C is incorrect because converting data into electrical signals is the responsibility of the Physical layer (Layer 1). Option E is incorrect because encapsulating data into frames with MAC addresses is a function of the Data Link layer (Layer 2).

Exam trap

Cisco often tests the distinction between Transport layer flow control (end-to-end) and Network layer congestion control (path-based), leading candidates to confuse Layer 4 segmentation with Layer 3 routing functions.

Why the other options are wrong

A

Logical addressing and routing are Network layer (Layer 3) functions, not Transport layer responsibilities.

C

Converting data into electrical signals is the Physical layer (Layer 1) function, not Transport layer.

E

Encapsulation into frames with MAC addresses is a Data Link layer (Layer 2) function, not Transport layer.

Why candidates pick the wrong answer

A

Students often confuse the Transport layer with the Network layer because both deal with end-to-end delivery. However, the Network layer handles logical addressing and routing, while the Transport layer manages the connection between applications.

C

Students may think that all layers eventually convert data to signals, but this specific conversion is exclusive to the Physical layer. The Transport layer works with segments and does not interact directly with the physical medium.

E

Students often confuse encapsulation at different layers. The Transport layer adds a header with port numbers, but framing and MAC addressing occur at the Data Link layer. This confusion is common when learning the OSI model.

311
MCQmedium

A network engineer is troubleshooting a connectivity issue between two hosts on different subnets. The sending host has constructed a packet with a destination IP address of 192.168.2.10. As the packet travels down the OSI model layers on the sending host, which Protocol Data Unit (PDU) name is assigned to the data at the Transport layer after TCP segments are created, and at which layer does the IP address get encapsulated?

A.PDU is a frame; IP address is added at the Data Link layer.
B.PDU is a segment; IP address is added at the Network layer.
C.PDU is a packet; IP address is added at the Transport layer.
D.PDU is a datagram; IP address is added at the Transport layer.
AnswerB

At the Transport layer, TCP encapsulates the application data into a segment, adding source and destination port numbers. This segment is then passed down to the Network layer, where the IP header—containing source and destination IP addresses—is added to create a packet. This is the correct sequence of encapsulation for TCP/IP communication.

Why this answer

At the Transport layer, TCP divides data into segments, so the PDU is called a segment, making B correct. The destination IP address (192.168.2.10) is added at the Network layer, where the IP header encapsulates the segment into a packet. Option A is wrong because a frame is a Data Link layer PDU, and IP addresses are not added at that layer.

Option C is wrong because the PDU at the Transport layer is a segment, not a packet, and IP addresses are added at the Network layer, not the Transport layer. Option D is wrong because 'datagram' typically refers to UDP’s Transport layer PDU (not TCP), and IP addresses are not added at the Transport layer.

Exam trap

Cisco often tests the precise PDU naming per layer (segment for TCP at Transport, packet for IP at Network) and the layer where IP addresses are added, tricking candidates who confuse 'packet' with 'segment' or think IP addresses are added at the Transport layer.

Why the other options are wrong

A

The PDU at the Transport layer is a segment, not a frame. Frames are the PDU at the Data Link layer (Layer 2). Additionally, IP addresses are added at the Network layer (Layer 3), not the Data Link layer.

C

A packet is the PDU at the Network layer (Layer 3), not the Transport layer. The IP address is added at the Network layer, not the Transport layer. The Transport layer PDU is a segment (for TCP) or a datagram (for UDP).

D

A datagram is the PDU for UDP at the Transport layer, but the question specifies TCP segments. Even if it were UDP, the IP address is still added at the Network layer, not the Transport layer.

Why candidates pick the wrong answer

A

Students often confuse the Data Link layer with the Network layer because both involve addressing (MAC vs. IP). The term 'frame' is commonly associated with encapsulation, leading to the mistaken belief that IP addresses are added at Layer 2.

C

The term 'packet' is widely used in networking and often misapplied to any encapsulated data unit. Students may incorrectly associate the IP address with the Transport layer because both are involved in end-to-end communication.

D

Students may recall that UDP uses datagrams and think that the IP address is part of the Transport layer encapsulation. However, IP addressing is always a Network layer function, regardless of the Transport protocol.

312
PBQhard

You are connected to R1, a multilayer switch acting as the STP root bridge. Configure Root Guard on the designated port toward R2 (G0/1), Loop Guard on the uplink port G0/2, and BPDU Guard on PortFast-enabled access port G0/3. After configuration, a superior BPDU is received on G0/1, causing it to be blocked by Root Guard; later, an unauthorized BPDU on G0/3 triggers err-disable. Troubleshoot and verify the expected port states.

Hints

  • •Root Guard only blocks a port when it receives a superior BPDU; it does not affect normal operation.
  • •Loop Guard prevents alternate or root ports from becoming designated in case of BPDU loss.
  • •BPDU Guard err-disables a PortFast port immediately upon BPDU reception.
A.G0/1 is in blocking state (Root Guard), G0/2 is in forwarding state (Loop Guard), G0/3 is in err-disable state (BPDU Guard).
B.G0/1 is in forwarding state (Root Guard), G0/2 is in blocking state (Loop Guard), G0/3 is in err-disable state (BPDU Guard).
C.G0/1 is in err-disable state (Root Guard), G0/2 is in forwarding state (Loop Guard), G0/3 is in blocking state (BPDU Guard).
D.G0/1 is in blocking state (Root Guard), G0/2 is in loop-inconsistent state (Loop Guard), G0/3 is in err-disable state (BPDU Guard).
AnswerA
solution
! R1
interface GigabitEthernet0/1
no spanning-tree guard root
spanning-tree guard root
end
interface GigabitEthernet0/3
shutdown
no shutdown
end

Why this answer

The root guard on G0/1 correctly blocked the port when a superior BPDU was received, preventing an unauthorized root bridge. Loop Guard was applied specifically to the uplink port G0/2 to prevent forwarding loops in case of uni-directional link failure. BPDU Guard on G0/3 placed the port into err-disable state upon receiving an unexpected BPDU, which protects the PortFast edge port.

To restore G0/3, you must manually shut/no shut the interface after removing the offending device.

Exam trap

Do not confuse the actions of Root Guard (blocking) with BPDU Guard (err-disable). Root Guard blocks the port temporarily; BPDU Guard err-disables the port until manual intervention. Also, Loop Guard does not block immediately; it only reacts when BPDUs stop.

Why the other options are wrong

B

Root Guard blocks the port upon receiving a superior BPDU, not forwards. Loop Guard transitions to blocking only after BPDU loss, not while BPDUs are still received.

C

Root Guard results in a blocking state, not err-disable. BPDU Guard results in err-disable, not blocking.

D

Loop Guard does not immediately place the port in loop-inconsistent state; it only does so after BPDU loss. Here, BPDUs are still being received.

Why candidates pick the wrong answer

B

Candidates may confuse Root Guard with BPDU Guard, thinking it err-disables, or think Loop Guard always blocks the port.

C

Candidates may think Root Guard err-disables because it's a security feature, or confuse the actions of Root Guard and BPDU Guard.

D

Candidates may think Loop Guard always puts the port in a special state, but it only activates upon BPDU loss.

313
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure NTP with authentication on a Cisco router.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, define the NTP authentication key using the ntp authentication-key command to create the key that will be used. Second, enable NTP authentication globally with ntp authenticate so that the router requires keys for NTP associations. Third, specify which keys are trusted with ntp trusted-key so the router accepts those keys.

Fourth, associate the NTP server with the key using the ntp server command with the key option, linking the server to the trusted key. Finally, verify the authenticated association using show ntp associations to confirm the configuration is working. This order is required because the key must exist before it can be trusted, authentication must be enabled before keys are checked, and the server must be configured with the key only after it is trusted.

314
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure Root Guard on designated ports, Loop Guard on non-designated ports, and BPDU Guard on PortFast ports, and then recover a port that enters err-disabled due to BPDU Guard.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order begins with Root Guard on designated ports to prevent them from becoming root ports upon receiving superior BPDUs. Next, Loop Guard is applied to non-designated ports (alternate/backup) to protect against unidirectional link failures. Then, BPDU Guard is placed on PortFast-enabled ports to shut them down if a BPDU is received, preventing rogue switch connections.

Finally, recovery from BPDU Guard err-disable requires a manual interface reset (shutdown/no shutdown) because the errdisable cause 'bpduguard' has no automatic timeout.

Exam trap

Cisco exams often test the specific port roles for each STP protection feature. Remember: Root Guard is for designated ports, Loop Guard is for non-designated ports (alternate/backup), and BPDU Guard is for PortFast ports. Also, recovery from err-disabled due to BPDU Guard requires manual interface reset, not just waiting or removing the configuration.

Why candidates pick the wrong answer

B

Candidates might confuse the port roles for each feature or think that a switch reload is a valid recovery method for err-disabled ports.

C

Candidates might think that errdisable timeout automatically recovers the port without manual intervention, or they may confuse the port roles for each feature.

D

Candidates might think that BPDU Guard should be applied to all ports for maximum protection, or that removing the cause of err-disable is sufficient for recovery.

315
Multi-Selectmedium

Which TWO statements accurately describe cabling and SFP transceiver diagnostics?

Select 2 answers
A.Copper SFP modules require Cat6a cabling to achieve a 100-meter reach.
B.Fiber SFP modules are typically identified by the 'GLC-T' or 'SFP-GE-T' product IDs.
C.The 'show interfaces transceiver' command displays optical power levels for both Tx and Rx on fiber SFPs.
D.The 'show cable-diagnostics tdr interface' command can measure the distance to a break in a fiber optic cable.
E.A multimode fiber SFP with LC connectors is commonly used for short-reach connections up to 550 meters.
AnswersC, E

The command 'show interfaces transceiver' is valid on Cisco switches and provides detailed diagnostics for SFP modules that support Digital Optical Monitoring. It displays the transmit optical power and receive optical power in dBm, along with temperature, voltage, and bias current. For fiber SFPs, these readings are crucial for verifying that the link is within the optical budget and for detecting fiber degradation or dirty connectors before failures occur.

Why this answer

Option C is correct because the 'show interfaces transceiver' command (and its variants like 'show interfaces transceiver detail') reports diagnostic optical parameters on fiber SFPs, including transmit (Tx) and receive (Rx) optical power levels in dBm, which is exactly how you verify link budget and signal integrity. Option E is correct because multimode fiber SFPs with LC connectors (e.g., 1000BASE-SX) are designed for short-reach campus/distribution links, typically supporting up to 550 meters over OM2 multimode fiber (and 220-550 m depending on fiber grade and modal bandwidth). Option A is wrong because copper SFPs such as 1000BASE-T have a 100-meter reach over standard Cat5e or better, not requiring Cat6a.

Option B is wrong because 'GLC-T' and 'SFP-GE-T' are copper (1000BASE-T) SFP product IDs, not fiber module identifiers. Option D is wrong because 'show cable-diagnostics tdr interface' performs Time Domain Reflectometry on copper twisted-pair Ethernet cabling, not on fiber optic cables, which cannot be tested this way.

Exam trap

Cisco often tests the distinction between copper and fiber SFP product IDs (e.g., 'GLC-T' is copper, not fiber) and the correct diagnostic commands for each media type, leading candidates to confuse TDR (copper) with fiber optical power monitoring.

Why the other options are wrong

A

The statement incorrectly mandates Cat6a cabling, whereas Cat5e and Cat6 also support the full 100-meter distance for 1000BASE-T.

B

This mixes up part number naming conventions; GLC-T and SFP-GE-T always indicate copper transceivers, not fiber.

D

TDR relies on electrical signals and impedance changes; it cannot function on fiber optics.

316
PBQhard

You are connected to R1. The network administrator has partially configured IPv4 and IPv6 on the interfaces. However, PC1 (connected to R1's G0/1) cannot reach PC2 (connected to R2's G0/1). Configure R1 and R2 so that PC1 can ping PC2. Fix any addressing errors. Use IPv4 subnet 192.0.2.0/30 for the link between R1 and R2, and 198.51.100.0/24 for the PC LANs. For IPv6, use 2001:db8:1::/64 on R1's G0/1 and 2001:db8:2::/64 on R2's G0/1, with R1's G0/1 using EUI-64 and R2's G0/1 using a static address 2001:db8:2::1/64.

Hints

  • •Check the subnet mask on the link between R1 and R2.
  • •IPv6 EUI-64 requires the interface to be up and unicast-routing enabled.
  • •Ensure both routers have routes to each other's LANs.
A.On R1, change the subnet mask on G0/0 from /24 to /30. On R1 G0/1, issue 'ipv6 address 2001:db8:1::/64 eui-64' and 'no shutdown'. Enable 'ipv6 unicast-routing' globally on both routers.
B.On R1, change the subnet mask on G0/0 from /24 to /30. On R1 G0/1, issue 'ipv6 address 2001:db8:1::/64 eui-64' and 'no shutdown'. No need to enable IPv6 unicast-routing because it is on by default.
C.On R1, change the subnet mask on G0/0 from /24 to /30. On R1 G0/1, issue 'ipv6 address 2001:db8:1::/64' (without eui-64) and 'no shutdown'. Enable 'ipv6 unicast-routing' globally on both routers.
D.On R1, change the subnet mask on G0/0 from /24 to /30. On R1 G0/1, issue 'ipv6 address 2001:db8:1::/64 eui-64' and 'no shutdown'. Enable 'ipv6 unicast-routing' globally on both routers. Also, change the default gateway on PC1 to 2001:db8:1::1.
AnswerA
solution
! R1
interface GigabitEthernet0/0
ip address 192.0.2.1 255.255.255.252
exit
interface GigabitEthernet0/1
ipv6 address 2001:db8:1::/64 eui-64
no shutdown
exit
ipv6 unicast-routing

! R2

Why this answer

The issue is a subnet mask mismatch on the link between R1 and R2: R1 uses /24 (255.255.255.0) while R2 uses /30 (255.255.255.252). This prevents R1 from having a route to R2's LAN. Fix R1's G0/0 mask to /30.

Additionally, R1's G0/1 IPv6 EUI-64 command is missing the interface identifier; the correct command is 'ipv6 address 2001:db8:1::/64 eui-64' but the interface must be enabled with 'no shutdown'. Also ensure IPv6 unicast-routing is enabled. The PCs have correct gateways.

Exam trap

Watch for subnet mask mismatches on point-to-point links; they break routing. Also, remember that IPv6 unicast-routing is disabled by default and must be enabled. EUI-64 requires the 'eui-64' keyword and generates an address based on MAC, not a static ::1.

Why the other options are wrong

B

The specific factual error is that IPv6 unicast-routing is disabled by default on Cisco routers.

C

The specific factual error is that the command without 'eui-64' assigns a static address, not an EUI-64 address.

D

The specific factual error is assuming the EUI-64 address ends with ::1, which is not guaranteed.

Why candidates pick the wrong answer

B

Candidates may think IPv6 routing is enabled by default, similar to IPv4, but it is not.

C

Candidates might forget the 'eui-64' keyword or think it is optional, but the question explicitly requires EUI-64.

D

Candidates often assume the first usable address (::1) is the router's address, but EUI-64 generates a different interface ID.

317
MCQhard

Why is a northbound API valuable to orchestration systems in a controller-based architecture?

A.It provides a defined software interface through which orchestration tools can interact with the controller.
B.It allows network devices to communicate directly with each other without the controller.
C.It is a physical interface used to connect the controller to the orchestration system.
D.It is a physical cable standard for controller uplinks.
AnswerA

A northbound API exposes network services through a clearly defined, machine-readable interface, commonly REST/JSON or NETCONF, allowing orchestration tools to programmatically query state and push configuration. This abstraction layer hides the underlying device specifics so that the orchestrator can manage the controller as a single logical entity. It is precisely this software contract that makes automated, policy-driven network orchestration possible.

Why this answer

A northbound API is valuable because it provides a defined software interface for orchestration systems to interact with the controller programmatically. Option B is incorrect because northbound APIs do not enable direct device-to-device communication; that is a function of the data plane. Option C is incorrect because northbound APIs are logical software interfaces, not physical cables or ports.

Option D is also incorrect as it mischaracterizes the API as a hardware standard.

Exam trap

A common exam trap is mistaking the northbound API for a physical connection or confusing it with southbound APIs that communicate with network devices.

Why the other options are wrong

B

This describes direct device communication or southbound APIs, not the northbound API used by orchestration.

C

Northbound APIs are logical software interfaces, not physical cable standards or hardware.

When would these options actually be correct?

B

In a question asking about the benefits of a centralized control architecture that eliminates the need for individual forwarding devices, option B could be correct. For instance, if the question specified a scenario where a software-defined networking (SDN) solution abstracts forwarding functions, this option would be valid.

C

In a question that asks about the benefits of simplifying network security protocols in a specific context, such as a hypothetical scenario where a system is designed to operate in a fully trusted environment, this option could be correct if the focus is on reducing complexity in that context.

D

In a question focused on the physical infrastructure of a network controller, such as 'What is the standard for connecting controllers to forwarding devices?' option D could be correct if it referred to a specific cable standard used for such connections.

Why candidates pick the wrong answer

B

Students might think that since the controller abstracts device details, the physical forwarding devices become unnecessary. However, the controller only manages them; the devices themselves are still required for data plane operations.

C

Some might assume that because the API simplifies interaction, security controls are bypassed. However, security is a critical aspect of API design, and authentication/authorization are enforced to prevent unauthorized access.

D

The term 'northbound' might be confused with physical directions or cabling, leading students to think it refers to a specific type of cable or port. In networking, 'northbound' refers to the direction of traffic flow toward higher-level management systems.

318
PBQmedium

You are connected to R1 via the console. R1 is a router that needs to provide DHCP services for hosts on VLAN 10 (192.168.10.0/24) and VLAN 20 (192.168.20.0/24). The DHCP server is located on VLAN 10 at 192.168.10.100, but hosts on VLAN 20 cannot reach it directly. Configure R1 to forward DHCP broadcasts from VLAN 20 to the DHCP server.

Network Topology
G0/0.10192.168.10.1/24G0/0.20192.168.20.1/24DHCP ServerVLAN 10R1VLAN 20Hosts

Hints

  • •The helper address should be placed on the interface that receives the DHCP broadcast.
  • •The helper address is the server's IP address.
  • •Only one command is needed.
A.interface GigabitEthernet0/0.20 encapsulation dot1Q 20 ip helper-address 192.168.10.100
B.interface GigabitEthernet0/0.10 encapsulation dot1Q 10 ip helper-address 192.168.10.100
C.interface GigabitEthernet0/0.20 encapsulation dot1Q 20 ip dhcp relay information option
D.ip dhcp pool VLAN20 network 192.168.20.0 255.255.255.0 default-router 192.168.20.1
AnswerA
solution
! R1
interface GigabitEthernet0/0.20
ip helper-address 192.168.10.100

Why this answer

The ip helper-address command enables the router to forward UDP broadcasts (including DHCP) to a specific server. Placing it on the VLAN 20 subinterface ensures that DHCP requests from VLAN 20 are unicast to the server on VLAN 10.

Exam trap

The key trap is placing the ip helper-address on the wrong interface. Remember: the helper-address must be on the interface that receives the client's broadcast, not on the server's interface. Also, do not confuse ip helper-address with DHCP server configuration or relay option commands.

Why the other options are wrong

B

The ip helper-address must be configured on the interface that receives the client broadcasts (VLAN 20), not the server's VLAN.

C

This command enables relay agent information insertion, not the actual forwarding of DHCP packets to a server.

D

The question states the DHCP server is at 192.168.10.100, so R1 should relay, not serve.

Why candidates pick the wrong answer

B

Candidates may think the helper-address should be on the server's subnet because the server is there.

C

Candidates may confuse DHCP relay options with the basic relay function.

D

Candidates may think they need to configure DHCP pools on the router to provide IP addresses.

319
Drag & Dropmedium

Drag and drop the following steps into the correct order to isolate and resolve interface CRC errors, duplex mismatches, and flapping on a Cisco IOS-XE switch.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Start with checking statistics to identify issues, then verify duplex and cable, replace hardware if needed, and finally confirm resolution.

Exam trap

Candidates often jump to hardware replacement or configuration changes without first gathering data. Always start with 'show interface' statistics to pinpoint the issue before taking corrective action.

Why candidates pick the wrong answer

B

Candidates might think hardware is the most common cause and jump to replacement first, but best practice is to gather evidence first.

C

Candidates might think verifying configuration is the first step, but statistics provide the evidence needed to guide further actions.

D

Candidates might think monitoring is a good starting point, but it is a passive step that should follow active troubleshooting.

320
Multi-Selectmedium

Which two statements about OSPF neighbor requirements on a shared Ethernet segment are correct? (Choose two.)

Select 2 answers
A.They must be in the same OSPF area on that link.
B.They must use the same subnet on the connected interfaces.
C.They must have identical router IDs.
D.They must use the same process ID number on both routers.
AnswersA, B

OSPF hello packets carry the area ID, and a router will only accept a neighbor if the area on the shared link matches its own. If the area IDs differ, the routers will drop each other's hello packets and never reach the 2-Way or Full state, so adjacency is impossible. Thus, being in the same area on that specific link is a strict prerequisite for forming a neighbor relationship.

Why this answer

Neighbors must agree on key parameters such as area ID and subnet, and they exchange Hello packets on the segment.

Exam trap

A frequent exam trap is confusing the OSPF process ID with the area ID or router ID requirements. Candidates often think the process ID must match between neighbors, but it is locally significant and does not affect adjacency. Another common mistake is assuming router IDs must be identical; in fact, router IDs must be unique within the OSPF domain to prevent routing conflicts.

Misunderstanding these distinctions can lead to selecting incorrect answers about neighbor requirements. The key is to focus on area ID and subnet matching for adjacency on shared Ethernet segments, not process ID or identical router IDs.

Why the other options are wrong

C

Incorrect because router IDs must be unique within the OSPF domain, not identical. Identical router IDs cause routing conflicts and prevent proper operation.

D

Incorrect because the OSPF process ID is locally significant to each router and does not need to match between neighbors for adjacency formation.

When would these options actually be correct?

C

In a different question focused on OSPF configuration best practices, if the question asked about prerequisites for OSPF routing table synchronization or specific scenarios involving OSPF route selection, then having identical router IDs might be presented as a requirement to ensure consistent routing behavior.

D

In a different exam scenario where the question asks about OSPF configuration requirements for routers that need to share routing information across multiple OSPF processes, having the same process ID would be necessary for them to exchange OSPF routing information effectively.

Why candidates pick the wrong answer

C

Students might confuse router ID with other parameters that need to match, such as area ID or subnet. They may think that identical router IDs are required for consistency, but in reality, uniqueness is critical.

D

Many students mistakenly believe that the process ID must match between neighbors, similar to how EIGRP requires the same autonomous system number. This is a common point of confusion between OSPF and other routing protocols.

321
MCQhard

A router shows this output: R1#show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 10.1.1.2 1 FULL/DR 00:00:34 192.168.12.2 GigabitEthernet0/0 10.1.1.3 1 2WAY/DROTHER 00:00:39 192.168.12.3 GigabitEthernet0/0 Which statement is correct?

A.R1 has failed to form adjacency with 10.1.1.3
B.This can be normal on a broadcast segment where DROTHER routers remain in 2-Way
C.R1 has a duplicate router ID with 10.1.1.3
D.The interface is passive
AnswerB

On multiaccess broadcast networks, OSPF elects a DR and BDR. Other routers (DROTHERs) only form fully adjacent neighbors with the DR and BDR; between DROTHERs, they stop at the 2-Way state because they do not exchange LSAs directly. This reduces flooding and is expected behavior, not an error.

Why this answer

On broadcast OSPF networks, full adjacency is typically formed with the DR and BDR. DROTHER routers can remain in the 2-Way state with one another and still be operating normally.

Exam trap

Be cautious not to confuse the 2WAY state with being a BDR or DR. Understand the significance of FULL/DR and 2WAY/DROTHER states.

Why the other options are wrong

A

The 2-Way state is a normal OSPF neighbor state on broadcast multiaccess networks for non-DR/BDR routers (DROTHERs). It indicates that bidirectional communication has been established, but full adjacency is not required because they do not exchange LSAs directly. This is not a failure.

C

A duplicate router ID would cause OSPF neighbor state to oscillate or remain in EXSTART/EXCHANGE, not stabilize in 2-Way. The output shows a stable 2-Way state, which is normal for DROTHERs. Duplicate IDs would also generate error messages in the logs.

D

A passive interface in OSPF does not send Hello packets and therefore cannot form any neighbor adjacency. The output shows two neighbors in valid states (FULL and 2-Way), which proves the interface is active and sending Hellos.

When would these options actually be correct?

A

In a different scenario where the question specifies that R1 is supposed to establish a full adjacency with all neighbors on a point-to-point link, and the output shows that it has not formed an adjacency with 10.1.1.3, then option A would be correct.

C

If the question stated that R1 was unable to establish any OSPF neighbor relationships at all, or if it showed that 10.1.1.3 was not listed in the OSPF neighbor table, then stating that R1 has a duplicate router ID with 10.1.1.3 would be correct, as it would prevent adjacency formation.

D

If the question provided output indicating that the OSPF interface was configured as passive (e.g., showing no OSPF neighbors), then stating that the interface is passive would be correct. The question would need to focus on the configuration of OSPF interfaces.

Why candidates pick the wrong answer

A

Students often associate the 2-Way state with incomplete adjacency or a problem, but in OSPF, 2-Way is a valid state for DROTHERs on broadcast segments. They may confuse it with the INIT or EXSTART states, which indicate issues.

C

Test-takers might think that any unusual neighbor state (like 2-Way) indicates a duplicate ID, but 2-Way is actually a normal state for non-DR/BDR neighbors. They may confuse the 2-Way state with the DOWN or ATTEMPT states that occur with duplicate IDs.

D

Students may think that a passive interface prevents full adjacency, but it actually prevents any adjacency at all. The presence of neighbors in the output contradicts the passive interface assumption.

322
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure Rapid PVST+ on SW1, make it the root bridge, and enable PortFast with BPDU Guard on all access ports.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order begins by entering global configuration mode, then enabling Rapid PVST+ so that subsequent spanning-tree commands operate under that mode. Next, the switch is designated as the root bridge for VLAN 1 using 'spanning-tree vlan 1 root primary', which sets a superior bridge priority. After the root election is influenced, PortFast is applied to all access interfaces to transition them directly into forwarding state.

Finally, BPDU Guard is enabled globally to protect all PortFast-enabled ports; if a BPDU is received on such a port, it is immediately put into err-disabled state, preventing potential loops. Each step builds on the previous one: enabling Rapid PVST+ must precede root setup, root selection should be completed before any access-port optimization, and BPDU Guard is applied last to secure the already-accelerated ports.

323
MCQhard

A network technician is troubleshooting a link between two Cisco switches, SW1 and SW2, connected via a single-mode fiber optic cable. The interface on SW1 is up/up, but the interface on SW2 remains down/down. The technician has verified that the fiber cable is not damaged and that the SFP modules are correctly seated. Which configuration change should the technician make to resolve the issue?

A.Configure the interface on SW2 to use the same speed and duplex settings as SW1.
B.Replace the 1000BaseSX SFP on SW2 with a 1000BaseLX SFP.
C.Enable MDIX on both interfaces to allow automatic crossover detection.
D.Change the VLAN assignment on SW2's interface to match that of SW1.
AnswerB

SW1's 1000BaseLX SFP operates at 1300 nm on single-mode fiber, while SW2's 1000BaseSX SFP operates at 850 nm on multimode fiber; the wavelength difference means the electrical-to-optical conversion at the receiver cannot interpret the incoming light signal. With a down/down status, the root cause is a media-type mismatch, so replacing the SX module with an LX SFP on SW2 ensures both ends use the same 1300 nm wavelength and fiber mode. This allows the physical layer to establish a signal and bring the interface up.

Why this answer

The issue is that SW1 is up/up but SW2 is down/down, indicating a unidirectional link. Since the fiber cable and SFP seating are verified, the most likely cause is an SFP wavelength mismatch. SW1 likely has a 1000BaseLX SFP (long-wavelength, single-mode), while SW2 has a 1000BaseSX SFP (short-wavelength, multimode).

Single-mode fiber requires LX optics; SX optics are designed for multimode fiber and will not produce a signal that can be received correctly over single-mode fiber, causing the remote interface to remain down. Replacing the 1000BaseSX SFP on SW2 with a 1000BaseLX SFP resolves the wavelength incompatibility.

Exam trap

Cisco often tests the misconception that fiber link issues are always due to physical damage or seating, when in fact the most common exam trap is an SFP type mismatch (SX vs. LX) on single-mode fiber, causing a unidirectional link.

Why the other options are wrong

A

On fiber optic links, speed and duplex are typically fixed (e.g., 1000 Mbps full duplex) and do not require manual configuration; auto-negotiation is standard for Gigabit Ethernet over fiber. Since the interface on SW1 is up/up, the settings are already compatible, so this change would not resolve the down/down state on SW2.

C

MDIX (Medium Dependent Interface Crossover) is a feature for copper Ethernet cables to automatically correct for straight-through vs. crossover cable issues. Fiber optic connections do not use MDIX because they use separate transmit and receive fibers, so enabling MDIX has no effect on fiber links.

D

A VLAN mismatch would cause the interface to be up/up but not forward traffic (Layer 2 issue), not the down/down state observed. The down/down state indicates a Layer 1 problem, such as a physical or optical incompatibility.

Why candidates pick the wrong answer

A

Students often associate speed/duplex mismatches with interface issues, but this is more common on copper Ethernet links. They may overlook that fiber links have different physical layer characteristics.

C

Test-takers may confuse MDIX with general auto-negotiation or crossover correction, not realizing it applies only to copper media.

D

Students often think VLAN mismatches cause interface down states, but they actually affect traffic flow after the link is established. The symptom of down/down points to a physical layer fault.

324
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure Router R1 with OSPFv2 process 1 to form neighbor adjacencies only on GigabitEthernet0/1 while preventing OSPF hello packets on all other OSPF-enabled interfaces.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, enter OSPF router configuration mode. Then assign a Router ID (optional but good practice). Next, advertise the local subnet with a network statement to enable OSPF on interfaces.

Then apply passive-interface default to suppress hellos on all OSPF interfaces. Finally, use no passive-interface to allow adjacency on the specific interface.

325
MCQhard

A subnet must support at least 62 usable hosts. Which prefix will create the smallest subnet that meets the requirement?

A./27
B./26
C./25
D./24
AnswerB

A /26 prefix leaves 6 host bits, yielding 64 addresses and 62 usable hosts after reserving the network and broadcast addresses. This exactly satisfies the stem's minimum of 62 usable hosts while producing the smallest subnet, since /27 would provide only 30 usable hosts and fail the requirement.

Why this answer

To support at least 62 usable hosts, the subnet needs 64 total addresses, because two of those will be reserved for the network and broadcast addresses. In plain language, the target is not 62 total addresses; it is 62 usable ones after the two reserved values are taken away. A /26 provides exactly 64 total addresses and therefore 62 usable host addresses.

This is a classic minimum-prefix question because it checks whether you can convert a host requirement into the correct power-of-two subnet size without over-allocating unnecessarily. A /27 would be too small, while /25 would work but would waste more addresses than needed. The smallest valid prefix is /26.

Exam trap

Ensure you calculate usable hosts, not total addresses. Remember that network and broadcast addresses are not usable.

Why the other options are wrong

A

A /27 prefix provides only 32 total addresses (2^(32-27)=32), with 30 usable hosts after subtracting network and broadcast addresses. This is insufficient for the requirement of at least 62 usable hosts.

C

A /25 prefix provides 128 total addresses and 126 usable hosts, which is more than required. While it meets the requirement, it is not the smallest prefix, leading to wasted IP addresses in a subnet.

D

A /24 prefix provides 256 total addresses and 254 usable hosts, far exceeding the requirement of 62 usable hosts. This is not the smallest prefix and results in significant waste of IP address space.

When would these options actually be correct?

A

If the question specified a requirement for at least 30 usable hosts, then a /27 would be the correct answer, as it accommodates exactly 30 usable addresses.

C

In a scenario where the question specifies a need for at least 126 usable hosts, a /25 subnet would be the correct answer, as it meets the requirement without exceeding it unnecessarily.

D

If the question asked for a subnet that supports at least 254 usable hosts, then /24 would be the correct answer, as it provides the necessary number of usable addresses without exceeding the requirement.

Why candidates pick the wrong answer

A

Students may mistakenly think that a /27 is sufficient because they forget to subtract the network and broadcast addresses, or they confuse the number of total addresses with usable hosts.

C

Students might choose /25 because it clearly provides enough hosts, but they overlook the requirement for the smallest prefix that meets the need, which is a common exam trap.

D

Students may default to /24 as a common subnet size without calculating the exact requirement, or they may not understand the concept of choosing the smallest prefix that satisfies the host count.

326
Matchingmedium

Match each IPv6 concept to its most accurate description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

IPv6 addressing used for wider routed communication

IPv6 addressing used only on the local segment

Host self-configuration using router advertisements

OSPF version used for IPv6 routing operation

Why these pairings

These pairings accurately define key IPv6 concepts.

Exam trap

Be careful not to confuse the scope of IPv6 address types. Link-local addresses are not routable, unique local addresses are private, and anycast is one-to-nearest, not one-to-many. Remember that 'local' in link-local means the link, not the site.

327
MCQmedium

Users receive addresses from the correct subnet and can reach destinations by IP address, but they cannot browse by hostname.

A.Default-router option
B.DNS server option
C.Lease time option
D.TFTP server option
AnswerB

The DHCP DNS-server option (option 6) provides clients with the IP address of a resolver to use for hostname-to-IP translation. When users receive a valid IP/prefix but no correct DNS server, name resolution fails even though all local network settings appear normal. Without a reachable DNS server, clients cannot resolve domain names, causing web and application connectivity failures while direct IP-based access still works.

Why this answer

If clients get an IP address and default gateway but cannot resolve names, the usual problem is the DNS server information handed out by DHCP. Without that, hostname lookups fail even though IP connectivity may still exist.

Exam trap

Don't confuse general network connectivity options with DNS-specific configurations. Focus on what each DHCP option actually configures.

Why the other options are wrong

A

The default-router option (option 3) provides the gateway for off-subnet traffic. While a missing gateway would prevent access to external networks, the scenario states users receive correct subnet addresses and can likely reach local resources. The inability to browse by hostname points to a DNS issue, not a routing problem.

C

The lease time option (option 51) determines how long a client can use an assigned IP address before renewing. It does not affect DNS resolution or hostname browsing. A missing or incorrect lease time would cause IP address expiration issues, not name resolution failures.

D

The TFTP server option (option 66) is used for booting devices like IP phones or diskless workstations to download configuration files or operating systems. It is not involved in hostname resolution. A missing TFTP server would not affect DNS lookups.

When would these options actually be correct?

A

In a different scenario where users cannot access external networks or specific services, but can resolve hostnames, the Default-router option could be missing or incorrect, leading to connectivity issues outside the local subnet.

C

If the question were about a DHCP configuration issue where clients were unable to maintain their IP addresses or frequently lost connectivity, then a missing or incorrect lease time option could be the cause, making this answer correct.

D

In a different scenario where users are unable to download configuration files or firmware updates from a TFTP server, the question might ask which DHCP option is missing. In that case, if the TFTP server option is not provided, it would be the correct answer.

Why candidates pick the wrong answer

A

Test-takers often associate internet browsing with a default gateway, assuming that if hostname resolution fails, it might be due to lack of internet connectivity. However, the question specifies that users cannot browse by hostname, which is a DNS function, not a routing one.

C

Students may confuse lease time with other DHCP options that affect network functionality, or they might think that a short lease could cause intermittent connectivity that impacts DNS. However, lease time is unrelated to DNS resolution.

D

Students may confuse TFTP with DNS because both are UDP-based services, or they might think that TFTP is needed for some name resolution process. However, TFTP has no role in DNS resolution.

328
Multi-Selectmedium

Which TWO statements accurately describe the encapsulation process and PDU naming across the OSI and TCP/IP models?

Select 2 answers
A.At the Transport layer, the TCP/IP model uses segments, while the OSI model uses packets.
B.In the OSI model, the Network layer encapsulates data into packets, while in the TCP/IP model the Internet layer performs the same function.
C.The term 'frame' is used at the Data Link layer in both the OSI and TCP/IP models, and it contains the Layer 2 header and trailer.
D.Encapsulation adds headers and trailers at each layer, so the PDU size decreases as data moves down the stack.
E.The OSI model's Session layer is responsible for end-to-end flow control using TCP segments, while the TCP/IP model combines this into the Application layer.
AnswersB, C

This is correct. The OSI Network layer (Layer 3) and the TCP/IP Internet layer are conceptually equivalent; both encapsulate the Transport layer PDU (segment or datagram) into an IP packet by adding a Layer 3 header. This packet is then passed down to the Data Link layer for framing. Thus, the function is identical in both models.

Why this answer

The OSI Network layer and the TCP/IP Internet layer both encapsulate transport layer segments or datagrams into packets by adding a Layer 3 header (e.g., IP header). This is the fundamental encapsulation step where logical addressing is applied, and the resulting PDU is called a packet in both models. The function is identical despite the different layer names.

Exam trap

Cisco often tests the precise PDU naming per layer (segment, packet, frame) and the fact that encapsulation increases PDU size, not decreases it, to catch candidates who confuse the direction of encapsulation or mix up OSI and TCP/IP layer terminology.

Why the other options are wrong

A

Misattributes the 'packet' PDU to the Transport layer – packets are created at the Network layer (Layer 3).

D

Reverses encapsulation logic: each layer adds its own overhead, increasing the size.

E

Incorrectly assigns flow control to the Session layer and misrepresents its placement in the TCP/IP model.

329
PBQhard

You are connected to SW1. Configure LACP EtherChannel between SW1 and SW2 using interfaces GigabitEthernet0/1 and GigabitEthernet0/2. Ensure the channel forms and passes traffic for VLAN 10. Troubleshoot and fix any issues preventing the channel from coming up.

Network Topology
Gi0/1Gi0/1LACPSW1SW2

Hints

  • •Check the speed and duplex settings on both member interfaces.
  • •Verify that the port-channel interface and member ports are both Layer2 or both Layer3.
  • •Ensure LACP mode is active on at least one side to initiate negotiation.
A.Configure speed 1000 and duplex full on Gi0/2, change port-channel 1 to switchport mode trunk with allowed vlan 10, and set both Gi0/1 and Gi0/2 to channel-group 1 mode active.
B.Configure speed 1000 and duplex full on Gi0/2, change port-channel 1 to no switchport, and set both Gi0/1 and Gi0/2 to channel-group 1 mode passive.
C.Configure speed 100 and duplex half on Gi0/1 to match Gi0/2, change port-channel 1 to switchport mode trunk with allowed vlan 10, and set both Gi0/1 and Gi0/2 to channel-group 1 mode active.
D.Configure speed 1000 and duplex full on Gi0/2, change port-channel 1 to switchport mode access with access vlan 10, and set both Gi0/1 and Gi0/2 to channel-group 1 mode desirable.
AnswerA
solution
! SW1
interface GigabitEthernet0/2
speed 1000
duplex full
channel-group 1 mode active
exit
interface GigabitEthernet0/1
channel-group 1 mode active
exit
interface Port-channel1
switchport
switchport mode trunk
switchport trunk allowed vlan 10
no ip address
end

Why this answer

The EtherChannel is not forming because of multiple mismatches: speed (1000 vs 100), duplex (full vs half), and the port-channel interface is configured as Layer3 (no switchport) while the member ports are Layer2 (switchport mode trunk). First, correct the speed and duplex on Gi0/2 to match Gi0/1 (speed 1000, duplex full). Then change the port-channel to switchport mode trunk and set the allowed VLAN.

Finally, change the LACP mode on both interfaces to 'active' to initiate negotiation. After these changes, the channel should come up.

Exam trap

Watch for mismatches in speed, duplex, and Layer2/Layer3 configuration between member ports and the port-channel interface. Also, ensure LACP mode is active on at least one side to initiate negotiation.

Why the other options are wrong

B

The specific factual error: The port-channel interface must match the Layer2 configuration of member ports; using no switchport creates a Layer3 interface that cannot trunk VLANs. Additionally, passive mode requires an active partner to form the channel.

C

The specific factual error: Speed and duplex should be consistent across all member links, but the correct resolution is to correct the misconfigured interface (Gi0/2) to match the working one (Gi0/1), not vice versa.

D

The specific factual error: Access mode cannot carry multiple VLANs; trunk mode is required for VLAN 10. Additionally, desirable is a PAgP keyword, not LACP. LACP uses active or passive.

Why candidates pick the wrong answer

B

Candidates might think passive mode is sufficient if the other side is active, but the question implies both sides need to be configured, and passive alone may not initiate if the peer is also passive.

C

Candidates might think consistency is key and choose to change the working interface to match the other, overlooking that the working interface likely has the desired configuration.

D

Candidates might confuse PAgP and LACP modes, or think access mode can be used if only one VLAN is needed, but the question specifies 'passes traffic for VLAN 10' implying trunking.

330
MCQmedium

An engineer successfully authenticates to a controller and receives a token. What is the usual reason for including that token in later API requests?

A.To identify and authorize the client without resending full login credentials each time
B.To convert HTTP requests into SNMP traps
C.To elect the active controller in the cluster
D.To compress JSON payloads before transport
AnswerA

Token-based API authentication allows the client to authenticate once to obtain a token (often a JWT) that serves as a proof of identity for subsequent requests, so the client does not need to resend username/password or other primary credentials on every call. The controller validates the token's signature and claims, and can authorize access based on scopes or roles embedded in the token, thereby providing both identity and authorization in a stateless, efficient manner.

Why this answer

The token proves the client has already authenticated and is authorized to continue interacting with the API for the lifetime of that token or session. It is commonly sent in an HTTP header such as Authorization. It does not replace the need for IP routing or DNS resolution.

Exam trap

Remember that tokens are specific to API authentication and should not be confused with other network security or configuration mechanisms.

Why the other options are wrong

B

Tokens are used for authentication and authorization in API requests, not for converting HTTP requests into SNMP traps. SNMP traps are asynchronous notifications sent by network devices, and token-based APIs operate at a different layer and protocol.

C

Token-based authentication is unrelated to controller cluster election. Cluster election typically uses protocols like VRRP, HSRP, or proprietary mechanisms to determine an active controller, not API tokens.

D

Token inclusion in API requests serves authentication and authorization, not data compression. JSON payload compression is typically handled by content-encoding headers (e.g., gzip) and is independent of token usage.

When would these options actually be correct?

B

If the question were about a system that translates HTTP requests into SNMP traps for monitoring purposes, and it asked about the mechanisms for handling such requests, then option B could be correct.

C

In a different question setup where the focus is on cluster management protocols, a scenario could ask about the process of selecting a primary controller in a high-availability setup, where a token is used to identify the current active controller among multiple nodes.

D

In a different question setup, if the question asked about methods to optimize data transfer in a network application, and specifically mentioned the need to reduce payload size, then option D could be correct as it would relate to techniques for compressing JSON payloads.

Why candidates pick the wrong answer

B

A student might confuse the concept of 'token' with 'trap' due to similar terminology, or think that API tokens can be used to translate between different management protocols like HTTP and SNMP.

C

The word 'token' might be associated with 'token ring' or 'election token' in networking contexts, leading a student to incorrectly link it to controller election processes.

D

A student might think that tokens are used to reduce payload size or optimize transport, confusing the concept of a security token with data compression techniques.

331
Matchingmedium

Drag and drop the syslog severity levels on the left to their corresponding names and meanings on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Emergency – system is unusable

Alert – immediate action needed

Critical – critical condition

Error – error condition

Warning – warning condition

Why these pairings

All four options correctly match syslog severity levels 0-3 with their descriptions. Levels 0 (Emergency), 1 (Alert), 2 (Critical), and 3 (Error) are the highest severity levels.

Exam trap

Remember that lower severity numbers indicate higher urgency. The exam expects you to know the order and descriptions of levels 0-3 precisely.

332
Multi-Selectmedium

Which TWO statements about IPv4 and IPv6 static routing are correct?

Select 2 answers
A.A default static route is used when no dynamic routing protocols are configured.
B.A floating static route is configured with a higher administrative distance than the primary route.
C.A floating static route must have a lower administrative distance than the primary route.
D.An IPv6 default static route uses the prefix ::/0.
E.An IPv6 static route can specify an IPv4 address as the next-hop.
AnswersB, D

A floating static route is a backup route that is installed in the routing table only when the primary route (with a lower AD) is not available. By assigning a higher AD, the router prefers the primary route when it is reachable.

Why this answer

A floating static route is configured with a higher administrative distance to serve as a backup when the primary route fails. Option D is correct because an IPv6 default static route uses the prefix ::/0 to match all destinations. Option A is incorrect because a default static route can be used independently of whether dynamic routing protocols are configured; it is simply a route with destination 0.0.0.0/0.

Option C is incorrect because a floating static route must have a higher AD, not lower, than the primary route. Option E is incorrect because an IPv6 static route cannot specify an IPv4 address as the next-hop; it must use an IPv6 address or an outgoing interface.

Exam trap

Cisco often tests the misconception that a floating static route must have a lower administrative distance than the primary route, when in fact it must be higher to serve as a backup.

Why the other options are wrong

A

A default static route is used as a gateway of last resort for any destination not in the routing table, regardless of whether dynamic routing protocols are configured. It is not dependent on the absence of dynamic routing.

C

A floating static route is designed to be a backup; therefore, it must have a higher AD than the primary route so that the primary route is preferred.

E

IPv6 static routes require an IPv6 next-hop address. Using an IPv4 address would be invalid because the router would not be able to resolve it in the IPv6 routing table.

Why candidates pick the wrong answer

A

Students may think that default routes are only needed when there is no dynamic routing, but in reality, they are often used alongside dynamic routing to provide a backup path or to reach external networks.

C

Students often confuse administrative distance with metric, thinking that a lower AD means a better route, but for floating static routes, the backup must have a higher AD to be less preferred.

E

Students may think that since routers can handle both IPv4 and IPv6, they can mix address families in static routes, but the next-hop must match the address family of the route.

333
Drag & Dropmedium

Drag and drop the following steps into the correct order to plan, configure, and apply an extended ACL that blocks Telnet traffic from the 192.168.1.0/24 network to the 10.0.0.0/24 network, applied inbound on the interface facing the source.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First, global config, then create ACL with deny and permit statements (order matters: deny first), then enter the source-facing interface and apply inbound; applying before creating ACL would fail.

Exam trap

Watch out for the order of ACL statements: deny must come before permit. Also, remember that ACLs must be created before they can be applied to an interface. Do not forget the implicit deny at the end of every ACL.

Why candidates pick the wrong answer

B

Candidates might think that applying the ACL first is acceptable because they may confuse the order of operations or think that the ACL can be created after application.

C

Candidates might think that the order does not matter or that they can place the permit first to ensure other traffic is allowed, not realizing that the deny would never be reached.

D

Candidates might think that only the Telnet traffic needs to be denied and that other traffic will be allowed by default, not realizing the implicit deny.

334
MCQhard

A route to 10.10.10.0/24 is learned through two OSPF paths. Both have the same prefix length and the same administrative distance, but one path has a lower OSPF metric. Which path is preferred?

A.The path with the lower OSPF metric
B.The path with the higher OSPF metric
C.Both paths equally, because the administrative distance is the same
D.Neither path, because two OSPF routes to the same prefix are invalid
AnswerA

OSPF calculates a metric, called cost, as the sum of outgoing interface costs along a path, and the SPF algorithm identifies the lowest-cost path to a destination. When two OSPF paths exist for the same 10.10.10.0/24 prefix, the route with the lower cost is installed in the routing table because it represents the shortest or most efficient path. Since both routes come from OSPF, their administrative distance is identical, so the OSPF metric is the sole determining factor.

Why this answer

The path with the lower OSPF metric is preferred. In practical terms, when the prefix and route source are the same, the router uses the routing protocol’s internal path-selection logic. For OSPF, the lower metric is the more attractive path.

This is a clean example of metric-based selection within one routing protocol. Administrative distance is not the deciding factor here because the source protocol is the same on both paths.

Exam trap

Remember, administrative distance only matters when comparing different routing protocols, not when choosing between paths within the same protocol.

Why the other options are wrong

B

A higher OSPF metric indicates a less desirable path, as OSPF uses cost as its metric where lower cost is preferred. Selecting a higher metric path would contradict the fundamental routing principle of choosing the best path based on lowest metric.

C

Equal administrative distance does not imply equal preference when metrics differ. The router compares metrics within the same routing protocol; if metrics are different, the lower metric path is chosen, not both.

D

OSPF can learn the same prefix via multiple paths; this is normal. The router selects the best path based on metric, and the other paths are kept in the routing table as backup or for equal-cost load balancing if metrics are equal.

When would these options actually be correct?

B

In a different question, if the context specified that the routing protocol was using a different metric system where a higher metric indicated a better path (such as a custom metric configuration), then this option could be correct. For example, a question might state that a specific implementation of OSPF has been modified to prioritize higher metrics for certain traffic types.

C

In a different scenario where a routing protocol allows for equal-cost multipath routing and treats multiple paths with the same metric and administrative distance as equally valid, this option would be correct. For example, if the question specified that the routing protocol supports load balancing, then both paths could be considered equally preferred.

D

In a question where it states that OSPF does not support multiple equal-cost paths for a specific configuration or that the routing table has a restriction preventing multiple entries for the same prefix, this option could be correct.

Why candidates pick the wrong answer

B

Students might confuse metric with other attributes like administrative distance or think that a higher metric indicates a more reliable path, but in OSPF, higher cost means less preferred.

C

Test-takers may mistakenly believe that equal administrative distance automatically leads to load balancing, but load balancing requires equal metrics, not just equal AD.

D

Some students might think that duplicate routes cause errors, but OSPF handles multiple paths gracefully and selects the best one.

335
Multi-Selectmedium

Which two statements accurately describe ARP in an IPv4 Ethernet network?

Select 2 answers
A.ARP resolves a known IPv4 address to a MAC address on the local segment.
B.ARP is used to choose the best Layer 3 path across multiple routers.
C.ARP requests are typically sent as broadcasts on the local LAN.
D.ARP can normally resolve the MAC address of a host located across a routed network.
E.ARP replaces the need for a default gateway.
AnswersA, C

ARP operates at the boundary of Layer 2 and Layer 3 on a local Ethernet segment, mapping a known IPv4 address to its corresponding MAC address. This mapping is essential because Ethernet frames require a destination MAC for delivery, while upper-layer applications only provide IP addresses. The ARP cache stores these resolved mappings to avoid repeating the request for every traffic flow.

Why this answer

ARP is the mechanism used to map a known IPv4 address to a Layer 2 MAC address on the local network segment. In plain language, if a device knows the IP address it wants to reach on the same LAN, ARP helps it discover the correct Ethernet destination MAC address to use in the frame. That is why ARP is so important for local delivery in IPv4 Ethernet environments. Without it, devices would know where they want to send traffic logically, but not how to address the actual frame on the local link.

ARP does not cross routers in the usual way, and it is not a routing protocol. It does not determine best paths to remote networks. It simply helps with local resolution of IPv4-to-MAC information. This distinction matters a lot on CCNA questions because many wrong answers try to blur the line between local neighbor resolution and routing behavior.

Exam trap

Do not confuse ARP with routing protocols or assume it functions across routers. Remember, ARP is strictly for local address resolution.

Why the other options are wrong

B

ARP operates at Layer 2 and is only concerned with resolving IP addresses to MAC addresses on the local link. Path selection between routers is performed by routing protocols (e.g., OSPF, EIGRP) and the routing table, which operate at Layer 3.

D

ARP requests are broadcast only within the local subnet and are not forwarded by routers. To reach a host on a different subnet, the source host must send the packet to its default gateway, which then uses its own ARP process to resolve the next-hop MAC.

E

ARP does not replace the default gateway; it only resolves the MAC address of the gateway or other local hosts. The default gateway is still required for routing traffic to other subnets, as ARP cannot provide Layer 3 forwarding.

When would these options actually be correct?

B

If the question were to ask about protocols that facilitate routing decisions or path selection in a multi-router environment, such as OSPF or EIGRP, then option B could be correct in that context, as those protocols do indeed choose the best Layer 3 path.

D

If the exam question were to ask about a protocol that can resolve MAC addresses across routed networks, such as when discussing proxy ARP or specific configurations involving ARP in a multi-layer switch environment, then this option would be correct.

E

In a question focused on network configuration or design where the context is a flat network without any routing, one might ask if ARP can eliminate the need for a default gateway. In such a scenario, if the question specifies that all devices are on the same subnet, the answer could be considered correct.

Why candidates pick the wrong answer

B

Students may confuse ARP with routing because both involve IP addresses. However, ARP is strictly for local MAC resolution, not for determining the best path across multiple routers.

D

A student might think ARP can resolve any IP address because ARP tables can contain entries for remote hosts learned via proxy ARP, but proxy ARP is a special case and not the normal operation. Typically, ARP is limited to the local link.

E

Since ARP is used to find the MAC address of the default gateway, some might think it eliminates the need for a gateway. However, the gateway's IP address must still be configured, and ARP only provides the MAC for that IP.

336
Multi-Selectmedium

Which TWO statements correctly describe the behavior of standard ACLs and their placement on interfaces?

Select 2 answers
A.Standard ACLs filter traffic based on source IP address only.
B.Standard ACLs should be placed as close to the source as possible.
C.Standard ACLs can filter traffic based on destination IP address.
D.Standard ACLs should be placed as close to the destination as possible.
E.Standard ACLs can filter traffic based on TCP or UDP port numbers.
AnswersA, D

Standard ACLs are the simplest type of IP access list: they match a packet solely by its source IPv4 address (using an optional wildcard mask) and permit or deny it, ignoring all other header fields. The ACL does not inspect the destination address, protocol number, or TCP/UDP ports, which is why they are less flexible than extended ACLs. This behavior makes them suitable for filtering based on the origin of traffic and for basic source‑based policy, but they cannot enforce granular application‑level controls.

Why this answer

Standard ACLs filter traffic based solely on the source IP address, using numbers 1–99 or 1300–1999 in classic Cisco IOS. They do not consider destination IP, protocol, or port numbers. Because they lack granularity, placing them close to the destination (option D) prevents them from inadvertently blocking traffic that should be permitted, as they cannot distinguish between traffic destined for different services on the same destination host.

Exam trap

Cisco often tests the misconception that standard ACLs should be placed close to the source (like extended ACLs), when in fact standard ACLs lack the granularity to do so safely and must be placed near the destination.

Why the other options are wrong

B

Standard ACLs filter only on source IP, so placing them close to the source can block traffic destined to other networks that should be allowed. The correct placement is close to the destination to minimize unintended filtering.

C

Standard ACLs do not examine destination IP addresses; they only match on source IP addresses. Filtering by destination requires an extended ACL.

E

Standard ACLs operate at Layer 3 and cannot examine Layer 4 information such as TCP or UDP port numbers. Port-based filtering requires an extended ACL.

Why candidates pick the wrong answer

B

Students often confuse the placement rule for standard ACLs with that of extended ACLs. Extended ACLs should be placed close to the source, but standard ACLs have the opposite recommendation.

C

Some students may think that since ACLs filter traffic, they can use any IP field, but standard ACLs are limited to source IP only.

E

Students may assume that all ACLs can filter on ports, but only extended ACLs have that capability. Standard ACLs are simpler and less granular.

337
MCQmedium

A network administrator at a large enterprise notices that the network monitoring system frequently generates false positive alerts for unusual traffic patterns during normal business hours. The administrator wants to reduce these false positives while still detecting genuine security threats. Which AI/ML concept would best address this requirement?

A.Deploy a predictive analytics model to forecast future traffic volumes and adjust thresholds accordingly.
B.Implement an anomaly detection system that uses machine learning to establish baseline behavior and flag deviations.
C.Apply intent-based networking to automatically enforce security policies based on high-level business intent.
D.Use deep packet inspection to examine all traffic and create static rules for known threats.
AnswerB

An ML-based anomaly detection system builds a statistical baseline of normal network behavior by learning from historical telemetry—metrics such as traffic volume, packet rates, port usage, or flow duration—and then flags significant deviations from that learned profile. Unlike static thresholds, the model adapts to seasonal patterns and gradual shifts in user behavior, so routine variations are absorbed into the baseline and only genuine outliers trigger alerts. This combination of continuous learning and multi-dimensional feature analysis directly addresses the root cause of false positives, which is the inability of fixed rules to distinguish 'unusual but normal' from 'suspicious' traffic.

Why this answer

Anomaly detection using machine learning establishes a dynamic baseline of normal network behavior, allowing the system to flag only significant deviations. This reduces false positives during normal business hours while still detecting genuine threats that deviate from the learned baseline, unlike static thresholds that trigger alerts on routine traffic variations.

Exam trap

Cisco often tests the distinction between predictive analytics (forecasting volume) and anomaly detection (learning behavior), trapping candidates who confuse adjusting thresholds with establishing a behavioral baseline.

Why the other options are wrong

A

Predictive analytics forecasts future traffic volumes but does not establish a dynamic baseline for normal behavior; thus, it cannot adapt to daily variations and would not reduce false positives from current traffic patterns.

C

Intent-based networking automates policy deployment and verification based on business intent, but it does not analyze traffic patterns or adapt alert thresholds; therefore, it does not directly reduce false positive alerts from monitoring systems.

D

Deep packet inspection with static rules can detect known threats but cannot adapt to new or evolving traffic patterns; thus, it would not reduce false positives from normal traffic variations and may even increase them due to rigid rules.

Why candidates pick the wrong answer

A

Students may think that forecasting future traffic helps adjust thresholds, but this approach is reactive and does not learn normal patterns, making it ineffective for reducing false positives.

C

Students may confuse intent-based networking with adaptive security, but its primary function is policy automation, not anomaly detection or false positive reduction.

D

Students might think that deep packet inspection provides thorough analysis, but without machine learning to establish baselines, it lacks the adaptability needed to minimize false positives.

338
Multi-Selectmedium

Which THREE statements correctly describe the behavior of LACP modes in an EtherChannel configuration?

Select 3 answers
A.Active mode will not send LACP packets unless the peer is also in active mode.
B.Passive mode will only respond to LACP packets and will not initiate negotiation.
C.Passive mode cannot form an EtherChannel with another passive mode interface.
D.Active mode will initiate LACP negotiation by sending LACP packets.
E.Both active and passive modes are supported in PAgP.
AnswersB, C, D

Passive mode in LACP operates entirely reactively: it never sends LACPDUs on its own, but it listens for incoming LACPDUs and responds only after receiving a valid negotiation request. This behavior restricts passive mode to forming channels only with active peers, as no negotiation is possible until an active-side packet arrives. The interface essentially acknowledges and follows the negotiation led by the active side.

Why this answer

B is correct because passive mode interfaces only respond to LACP packets and never initiate negotiation. C is correct because two passive interfaces will both wait for the other to initiate, so no LACP packets are sent and the EtherChannel never forms. D is correct because active mode interfaces actively send LACP packets to initiate negotiation with either an active or passive peer.

A is incorrect: active mode sends LACP packets regardless of the peer’s mode; it can form a channel with passive just as well as with active. E is incorrect because PAgP supports only desirable and auto modes, not LACP’s active/passive modes; PAgP and LACP are separate protocols.

Exam trap

A common mistake is thinking active mode requires the peer to also be active, but active can form with either active or passive, while passive–passive pairs never negotiate.

Why the other options are wrong

A

Active mode sends LACP packets unconditionally; it does not require the peer to be active and will negotiate with a passive peer.

E

PAgP uses desirable and auto modes, not the LACP active/passive modes; these modes are specific to LACP.

Why candidates pick the wrong answer

A

Students may confuse LACP active mode with PAgP desirable mode, which requires the peer to be in desirable mode to form a channel. They might think active mode also requires a matching active peer.

E

Students often confuse LACP and PAgP modes because both have two modes that serve similar functions. They may mistakenly think that active/passive are also used in PAgP.

339
MCQhard

A network technician has configured static NAT with the command ip nat inside source static 192.168.1.10 203.0.113.10. The web server at 192.168.1.10 is accessible from the internet on TCP port 80 but not on TCP port 443. The ACL applied to the outside interface permits all IP traffic. What is the most appropriate next step to troubleshoot this issue?

A.Check if the web server is running HTTPS service on port 443.
B.Verify that the ACL applied to the outside interface explicitly permits TCP port 443.
C.Examine the NAT translation table for any conflicting dynamic entries.
D.Confirm the inside global IP address mapped to the server is correct.
AnswerA

Because the existing ACL permits all IP traffic and the static NAT rule already translates port 80 successfully, the network and translation layers are validated for HTTP. Since HTTPS uses a different application-layer service and TCP port 443, the most likely failure point is the web server not listening for HTTPS connections. Checking whether the server is running HTTPS on port 443 isolates the issue to the application layer, which is the correct next step.

Why this answer

The symptom (port 80 works, port 443 fails) with a static NAT that maps the entire IP address (not just specific ports) indicates the issue is likely at the server itself, not the NAT configuration. Static NAT translates all traffic for the inside local IP to the inside global IP, so if one TCP port works and another does not, the NAT is functioning correctly. The most appropriate next step is to verify that the web server is actually listening on TCP port 443 (HTTPS), as the server may not have the HTTPS service running or configured.

Exam trap

Cisco often tests the misconception that a static NAT or ACL must be explicitly configured for each port, when in fact static NAT translates all ports, and the ACL in this scenario already permits all traffic, so the issue must be at the application layer.

Why the other options are wrong

B

The already-configured ACL permits all IP traffic, so explicitly allowing port 443 would not resolve a server not listening on that port. This step wastes time on a verified configuration.

C

Static NAT does not use dynamic overload entries. There are no conflicting entries because NAT overload is not configured, making this check irrelevant.

D

The fact that port 80 works shows the inside global IP is correct. Re-verifying it would not explain the port-specific failure, as the issue is not with the translation.

340
PBQhard

You are connected to R1. The internal network 192.168.1.0/24 must be able to access the Internet via PAT (NAT overload) using the outside interface G0/1 with IP 203.0.113.1. Additionally, a web server at 192.168.1.100 must be reachable from the Internet via static NAT to the same outside interface. The current configuration has errors. Correct the NAT configuration so that inside hosts can browse the web and the server is reachable from outside.

Hints

  • •Check which interfaces are marked as inside and outside — both were inside.
  • •The dynamic NAT rule is missing a keyword to enable port address translation.
  • •Verify the ACL used in the NAT rule matches the correct inside subnet.
A.Change interface G0/1 to 'ip nat outside', add 'overload' to the dynamic NAT rule, and correct ACL 100 to permit 192.168.1.0 0.0.0.255
B.Change interface G0/1 to 'ip nat outside', add 'overload' to the dynamic NAT rule, and change ACL 100 to permit 192.168.2.0 0.0.0.255
C.Change interface G0/1 to 'ip nat outside', remove the 'overload' keyword from the dynamic NAT rule, and correct ACL 100 to permit 192.168.1.0 0.0.0.255
D.Change interface G0/1 to 'ip nat inside', add 'overload' to the dynamic NAT rule, and correct ACL 100 to permit 192.168.1.0 0.0.0.255
AnswerA
solution
! R1
interface GigabitEthernet0/1
no ip nat inside
ip nat outside
exit
ip nat inside source list 100 interface GigabitEthernet0/1 overload
no access-list 100
access-list 100 permit ip 192.168.1.0 0.0.0.255 any

Why this answer

The configuration had three issues: (1) Interface G0/1 was incorrectly configured as 'ip nat inside' instead of 'ip nat outside' — this prevents translation as both interfaces are inside. (2) The NAT overload keyword was missing on the dynamic PAT rule — without 'overload', only one-to-one translation occurs. (3) ACL 100 was matching 192.168.2.0/24 instead of the actual inside subnet 192.168.1.0/24, so traffic from the correct subnet was not translated. Correcting these allows inside hosts to PAT to the outside IP and the static NAT to function properly.

Exam trap

Watch for three common mistakes in NAT configuration: (1) misplacing the 'inside' and 'outside' interface designations, (2) forgetting the 'overload' keyword for PAT, and (3) using an incorrect ACL that does not match the actual inside network. Always verify the ACL matches the source subnet of traffic needing translation.

Why the other options are wrong

B

The ACL must match the source subnet of the inside hosts that need translation; using 192.168.2.0/24 does not match 192.168.1.0/24.

C

The 'overload' keyword is essential for PAT; omitting it means only one inside host can use the outside IP at a time.

D

NAT requires one interface to be 'inside' and the other 'outside'; having both as 'inside' prevents translation of outbound traffic.

Why candidates pick the wrong answer

B

Candidates might misread the subnet or think the ACL is correct if they confuse the two subnets.

C

Candidates might think 'overload' is optional or confuse it with static NAT, not realizing PAT requires it.

D

Candidates might think the outside interface should be 'inside' because it connects to the internal network, or they may confuse the direction of NAT.

341
MCQhard

A technician is troubleshooting a dual-stack network where an IPv6-only host cannot reach an IPv4 resource. The technician issues the show ipv6 interface brief command on the local router and notices the interface facing the host has a link-local address but no global unicast address. The technician then checks the running configuration and finds that the command ipv6 unicast-routing is missing. What is the most likely cause?

A.An IPv6 access list on the router is blocking Router Advertisement messages.
B.IPv6 unicast routing has not been enabled on the router.
C.The IPv4 resource is not configured for NAT64 translation.
D.The host has an incorrect default gateway for IPv6.
AnswerB

The ipv6 unicast-routing command is required to enable IPv6 forwarding on Cisco routers. Without it, the router does not participate in IPv6 routing, does not generate Router Advertisements, and interfaces will not obtain global unicast addresses through SLAAC or DHCPv6 relay. The show ipv6 interface output displaying only a link-local address, combined with the absence of ipv6 unicast-routing in the configuration, confirms this root cause.

Why this answer

The missing `ipv6 unicast-routing` command means the router is not acting as an IPv6 router, so it does not send Router Advertisement (RA) messages. Without RAs, the host cannot autoconfigure a global unicast address or learn a default gateway, breaking IPv6 connectivity to any IPv4 resource even if NAT64 is present.

Exam trap

Cisco often tests the misconception that configuring an IPv6 address on an interface is sufficient for IPv6 routing, when in fact the global `ipv6 unicast-routing` command is required to enable the router to forward IPv6 packets and send Router Advertisements.

Why the other options are wrong

A

This option focuses on a filtering issue, not the disabled routing engine, and would not cause the router’s own interface to lack a global unicast address.

C

NAT64 configuration would affect translation, but the root cause visible in the output is the lack of IPv6 routing capability on the router.

D

This shifts the blame to the host, but the router-side evidence (missing command and missing global unicast) clearly indicates a router configuration problem.

342
Multi-Selectmedium

Which TWO statements are true regarding the configuration and placement of standard and extended ACLs on a router?

Select 2 answers
A.Standard ACLs are typically placed closest to the source of the traffic.
B.Extended ACLs are typically placed closest to the source of the traffic.
C.A wildcard mask of 0.0.0.0 in an ACL matches all bits of the IP address.
D.A wildcard mask of 255.255.255.255 in an ACL matches all bits of the IP address.
E.Extended ACLs should be placed on the interface closest to the destination to filter traffic before it reaches the final segment.
AnswersB, C

Extended ACLs are placed closest to the source of traffic because they can filter on multiple fields such as source and destination IP, Layer 4 ports, and protocols. Filtering early at the source prevents unwanted traffic from wasting bandwidth and router CPU resources across the entire network path. This placement also ensures that the more specific extended criteria are applied as soon as traffic enters the network, making the filtering efficient and effective.

Why this answer

Extended ACLs evaluate multiple criteria (source/destination IP, port, protocol), so placing them closest to the source prevents unwanted traffic from consuming bandwidth across the network. Option C is correct because a wildcard mask of 0.0.0.0 means all 32 bits must match, matching a single host. Option A is incorrect—standard ACLs are placed closest to the destination, not the source.

Option D is incorrect—a wildcard mask of 255.255.255.255 matches any address (ignores all bits), not all bits. Option E is incorrect—extended ACLs placed near the destination would not conserve bandwidth; they should be near the source.

Exam trap

Cisco often tests the misconception that standard ACLs should be placed close to the source, when in fact extended ACLs are placed close to the source and standard ACLs close to the destination.

Why the other options are wrong

A

Standard ACLs filter only on source IP address, so placing them close to the source can block traffic that should be allowed to other destinations, causing unnecessary denial of service.

D

A wildcard mask of 255.255.255.255 means 'ignore all bits,' so it matches any IP address, equivalent to the 'any' keyword. It does not match all bits.

E

Extended ACLs are more effective when placed near the source to filter unwanted traffic early, not near the destination. Placing them near the destination allows unwanted traffic to traverse the network unnecessarily.

Why candidates pick the wrong answer

A

Students often confuse the placement rule for standard ACLs with extended ACLs, thinking that placing ACLs near the source is always beneficial, but standard ACLs lack the granularity to filter based on destination.

D

Students may mistakenly think that a mask of all 255s means checking all bits, confusing wildcard masks with subnet masks where 255 indicates network bits.

E

Some students believe that filtering near the destination is more efficient because it only affects the final segment, but this ignores the bandwidth and processing wasted on transit.

343
Multi-Selectmedium

Which TWO statements correctly describe characteristics of SNMPv2c and SNMPv3 for network monitoring?

Select 2 answers
A.SNMPv3 supports authentication and encryption for secure network monitoring.
B.SNMPv2c uses community strings sent in clear text to authenticate requests.
C.SNMPv3 provides the same security level as SNMPv2c but with additional trap support.
D.SNMPv2c supports only GET and SET operations, but not traps.
E.SNMPv3 uses community strings to authenticate agents and managers.
AnswersA, B

SNMPv3 is correct because it introduces a User-based Security Model (USM) offering three security levels: noAuthNoPriv (no authentication or encryption, but still uses usernames), authNoPriv (HMAC-MD5 or HMAC-SHA authentication, no encryption), and authPriv (authentication plus DES or AES encryption). This allows network monitoring to operate with data integrity, source authentication, and confidentiality, protecting against sniffing and unauthorized modifications. No other version provides these combined security features, making it suitable for production and large-scale networks.

Why this answer

SNMPv3 is correct because it introduces authentication (MD5/SHA) and encryption (DES/AES) for secure monitoring. SNMPv2c is correct because it uses community strings transmitted in cleartext, lacking security. Option C is wrong: SNMPv3 is more secure than v2c, not the same.

Option D is wrong: SNMPv2c supports traps in addition to GET and SET. Option E is wrong: SNMPv3 uses usernames and security models, not community strings.

Exam trap

Cisco often tests the misconception that SNMPv3 is merely an extension of SNMPv2c with added trap support, when in fact the key differentiator is the security model (authentication and encryption), and both versions support traps.

Why the other options are wrong

C

SNMPv3 provides significantly higher security than SNMPv2c by adding authentication and encryption, whereas SNMPv2c uses only community strings in clear text. Both versions support traps, so the statement incorrectly claims SNMPv3 has additional trap support, which is not a distinguishing feature.

D

SNMPv2c supports GET, SET, and trap operations, just like SNMPv1 and SNMPv3. The statement is incorrect because it claims SNMPv2c does not support traps, which is false; traps are a key feature for asynchronous notifications in network monitoring.

E

SNMPv3 uses the User-based Security Model (USM) with usernames and authentication keys, not community strings. Community strings are a feature of SNMPv1 and SNMPv2c, which are transmitted in clear text and provide weak security.

Why candidates pick the wrong answer

C

Students may confuse the enhanced security features of SNMPv3 with additional trap functionality, or they might think that SNMPv3 is just a more secure version of SNMPv2c with the same features plus traps, but traps are present in both.

D

Test-takers might confuse SNMPv2c with an earlier or limited version, or they may think that traps were only introduced in SNMPv3. However, traps have been part of SNMP since SNMPv1.

E

Students familiar with SNMPv2c may assume that community strings are used across all versions, but SNMPv3 replaced them with a more robust user-based authentication model. The term 'community' might be mistakenly associated with SNMPv3.

344
Multi-Selectmedium

Users complain that log timestamps from several routers do not line up with one another. Which two actions are most appropriate?

Select 2 answers
A.Configure NTP on the network devices
B.Verify timezone and timestamp settings
C.Increase the syslog severity threshold to debugging
D.Disable console logging
E.Clear the logging buffer on all devices
AnswersA, B

NTP synchronises each router's clock to a common time source, so log timestamps across devices align. Without a shared reference, routers drift independently, producing the mismatched timestamps users reported; configuring NTP directly resolves that clock-skew constraint.

Why this answer

Option A is correct because configuring NTP on the routers synchronizes their clocks to a common, authoritative time source, which is the fundamental fix for timestamps that do not align across devices. Option B is correct because even with NTP running, mismatched timezone or timestamp service settings (for example, 'service timestamps log datetime localtime' versus UTC, or an incorrect clock timezone offset) will make log entries appear inconsistent, so these settings must be verified. Option C is wrong because raising the syslog severity threshold to debugging only increases the volume and detail of logged messages; it does nothing to correct clock skew.

Option D is wrong because disabling console logging merely stops messages from being displayed on the console and does not affect timestamp accuracy. Option E is wrong because clearing the logging buffer only discards stored log entries and has no effect on the time synchronization or timestamp formatting of future messages.

Exam trap

Don't confuse log display settings or buffer configurations with time synchronization settings.

Why the other options are wrong

C

Increasing the syslog severity threshold to debugging generates more log messages but does not address the root cause of time discrepancies. It can overwhelm storage and analysis without fixing the time synchronization issue.

D

Disabling console logging does not address timestamp synchronization; it only stops log messages from appearing on the console, which does not align timestamps across devices.

E

Clearing the logging buffer removes existing log entries but does not prevent future timestamps from being incorrect. The time drift persists, so new logs will still have mismatched timestamps.

When would these options actually be correct?

D

When a question asks how to reduce CPU load on a router due to excessive logging, disabling console logging is appropriate because console logging is CPU-intensive and can be disabled without losing logs to other destinations.

Why candidates pick the wrong answer

C

Students might think that more detailed logs help identify the problem, but this confuses log verbosity with time accuracy. Debugging logs do not correct clock drift.

D

Candidates may think console logging causes timestamp issues or that disabling it resets timestamps, confusing logging behavior with time synchronization.

E

Students might believe that clearing logs resets the time or fixes the issue temporarily. In reality, it only deletes historical data without addressing the root cause.

345
MCQhard

Refer to the exhibit. A network administrator is troubleshooting a connectivity issue on switch SW1. Users connected to port Gi0/3 are unable to reach resources in VLAN 30. The administrator issues the show vlan brief command and receives the output shown. What is the most likely cause of the problem?

A.The Gi0/3 port is in an error-disabled state due to port security violations.
B.The VLAN 30 SVI is administratively down.
C.VLAN 30 is administratively shut down.
D.Spanning Tree Protocol has placed Gi0/3 into a blocking state for VLAN 30.
AnswerC

The Status column for VLAN 30 reads 'act/lshut', which is Cisco's shorthand for 'active but locally shut down'—meaning the VLAN has been administratively disabled via the 'shutdown' command in VLAN configuration mode. An administratively shut down VLAN will not pass traffic for any access port assigned to it, regardless of the physical or operational state of those ports. This is a VLAN database condition, distinct from an SVI being down or an interface errdisable, and it applies to the entire broadcast domain.

Why this answer

The 'show vlan brief' output shows VLAN 30 with a status of 'act/lshut' (administratively shutdown) or 'shutdown', indicating that the VLAN has been disabled via the 'shutdown' command in VLAN configuration mode. A shutdown VLAN does not forward traffic, and all access ports assigned to it become operationally inactive for that VLAN, even though the ports themselves may still be listed in the output. The SVI for VLAN 30 would also be down.

Therefore, the most likely cause is that VLAN 30 has been administratively shut down.

Exam trap

Common mistake: Candidates think that a shutdown VLAN disappears from 'show vlan brief'. In fact, it remains listed with a status such as 'act/lshut'. A VLAN that is missing entirely means it has been deleted, not merely shutdown.

Why the other options are wrong

A

Candidates often confuse port-level issues with VLAN-level states. Port security violations would result in an err-disable status, which is not reflected in the VLAN status column; the VLAN would still show 'active' if it were enabled.

B

Candidates may mistake the VLAN shutdown for an SVI shutdown because both involve the 'shutdown' keyword. However, the SVI state would appear in 'show ip interface brief' or 'show interface vlan 30', not here.

D

Candidates often attribute connectivity loss to STP blocking, which is a common cause of forwarding issues. However, this exhibit’s specific clue is the 'act/lshut' flag, directing attention to the VLAN administrative state.

346
Multi-Selectmedium

Which command or tool would a network engineer use to verify if a client has a duplicate IP address conflict on the local subnet?

Select 2 answers
A.ipconfig /all
B.arp -a
C.nslookup
D.ping
E.tracert
AnswersB, D

arp -a displays the system's ARP cache, which maps IPv4 addresses to MAC addresses for hosts reached on the local subnet. When two devices are using the same IP, the cache may show two different MAC addresses for that same IP, or the mapping may flip back and forth between the two entries as traffic is sent. Examining the ARP table for inconsistent or changing MAC-to-IP pairings is a classic method for detecting an IP address conflict.

Why this answer

The two tools to verify a duplicate IP conflict are arp -a and ping. The arp -a command displays the ARP cache; if a duplicate IP exists, the ARP table may show multiple MAC addresses for the same IP or rapid changes. Ping can be used to send traffic to the local IP address; if a reply is received from a different MAC address than expected, it indicates a conflict.

Together, these commands help network engineers confirm IP address duplication. Other commands like ipconfig /all, nslookup, and tracert do not directly reveal such conflicts.

Exam trap

A common misconception is that ipconfig /all can detect duplicate IPs, but it only displays local configuration. In reality, arp -a and ping are the key tools to identify IP conflicts at the network layer.

Why the other options are wrong

A

`ipconfig /all` shows only the local IP configuration, not whether the same IP is assigned to another host.

C

`nslookup` resolves domain names to IP addresses and is unrelated to local IP conflicts.

E

`tracert` traces the path to a remote host, irrelevant for detecting local subnet duplicate IPs.

Why candidates pick the wrong answer

A

Students may think that because ipconfig /all shows the IP address, it can also detect conflicts, especially if they recall that Windows sometimes displays a 'duplicate IP' message. However, that message comes from the operating system's detection mechanism, not from the ipconfig command itself.

C

Students might confuse nslookup with other network diagnostic tools or think that because it queries IP addresses, it could somehow reveal conflicts. However, nslookup only resolves names to IPs and does not check for duplicate IPs on the local subnet.

E

Students might think that because tracert shows IP addresses along the path, it could reveal duplicate IPs. However, tracert only shows the path to a remote destination and does not analyze local subnet addressing or ARP entries.

347
MCQeasy

Which medium is the most common choice for a 10G uplink between wiring closets on different floors of the same building?

A.Rollover cable
B.Fiber optic cable
C.Coaxial cable
D.Console cable
AnswerB

Fiber-optic cable is the standard medium for 10G uplinks because it supports both 10GBASE-SR (multimode, 850 nm VCSELs, up to 300 m on OM3/OM4) and 10GBASE-LR (single-mode, 1310 nm, up to 10 km), providing reach and bandwidth far beyond copper twisted pair. It is immune to electromagnetic interference, has extremely low signal attenuation, and offers the full-duplex symmetric bandwidth required for switch uplinks. Enterprise switches therefore ship with SFP+ slots where fiber transceivers are the default choice for interconnecting access-layer switches to distribution or core switches.

Why this answer

Fiber is commonly used for building uplinks because it supports higher bandwidth and longer distances than typical copper for this use case.

Exam trap

Don't confuse the capabilities of multimode fiber with single-mode fiber for long-distance, high-speed connections.

Why the other options are wrong

A

A rollover cable is a specialized Cisco console cable used for out-of-band management access to a device's console port, not for network data traffic. It cannot carry 10G Ethernet signals and is physically incompatible with Ethernet interfaces.

C

Coaxial cable (e.g., RG-6) is primarily used for cable TV, broadband internet (DOCSIS), or legacy Ethernet (10BASE2/10BASE5), but it does not support 10G Ethernet speeds over the distances required between floors in a modern enterprise network. Fiber or twisted-pair copper (Cat6a/Cat7) are the standard 10G media.

D

A console cable (typically a rollover or USB-to-serial cable) is used for initial device configuration and management access, not for carrying network traffic. It cannot support 10G data rates and is not designed for switch-to-switch uplinks.

When would these options actually be correct?

A

If the exam question asked about connecting a terminal to a network device for configuration purposes, a rollover cable would be the correct choice. In such a scenario, the focus would be on management access rather than high-speed data transfer.

C

If the exam question asked for the most common medium for a 10G uplink in a legacy network setup or a specific scenario where coaxial infrastructure is already in place and being upgraded, coaxial cable could be considered a viable option.

D

If the exam question asked about connecting a network device directly to a computer for configuration purposes, a console cable would be the correct answer. This scenario would focus on device management rather than data uplinking.

Why candidates pick the wrong answer

A

Students may confuse rollover cables with other copper Ethernet cables (e.g., Cat6a) because both have RJ45 connectors, but rollover cables have a unique pinout (rolled) and are only used for console connections.

C

Coaxial cable is still used in some broadband and video applications, and its thick shielding might suggest it can handle high speeds, but it is not a standard for 10G Ethernet uplinks in structured cabling.

D

The term 'console cable' might be confused with 'crossover cable' or other Ethernet cables, but console cables are specifically for management and have different connectors and pinouts.

348
MCQhard

A router learns the same destination prefix from OSPF and EIGRP. The prefix length is identical, and both routes are valid. Which route is preferred by default?

A.The EIGRP route
B.The OSPF route
C.Both routes are installed equally because the prefix length matches
D.Neither route is used because protocols cannot advertise the same prefix
AnswerA

The EIGRP route is preferred because EIGRP's default administrative distance (AD) of 90 is lower than OSPF's default AD of 110. When a router receives the same destination prefix from multiple routing protocols, it compares AD values and installs the route with the lowest AD into the routing table. Therefore, the EIGRP route wins this selection.

Why this answer

The EIGRP route is preferred by default because EIGRP has a lower default administrative distance than OSPF. In practical terms, once the prefix length is the same, the router compares source trust. Lower administrative distance wins. EIGRP’s default of 90 beats OSPF’s default of 110.

This is not a longest-prefix question. The prefix is identical, so the decision is about source preference rather than specificity.

Exam trap

A frequent exam trap is believing that when two routing protocols advertise the same prefix with identical prefix lengths, the router installs both routes equally or performs load balancing. This misconception ignores the role of administrative distance, which is the primary factor in route preference when prefix lengths match. Another trap is thinking that OSPF is always preferred because it is a widely used IGP, but Cisco routers prioritize routes based on AD values, not protocol popularity.

Misunderstanding this can lead to incorrect answers about route selection in multi-protocol environments.

Why the other options are wrong

B

This option is incorrect because OSPF’s default administrative distance (110) is higher than EIGRP’s (90), making OSPF routes less preferred when both advertise the same prefix.

C

This option is incorrect because equal prefix length does not cause routers to install both routes equally; administrative distance determines which route is preferred and installed.

D

This option is incorrect because routers can receive and compare the same prefix from multiple routing protocols; they do not reject prefixes simply because they come from different sources.

When would these options actually be correct?

B

In a different scenario where OSPF is configured with a lower administrative distance than EIGRP, or if EIGRP is configured with a higher AD, the OSPF route would be preferred. For example, a question might specify that OSPF is set to an AD of 90 and EIGRP to 170, making the OSPF route the correct choice.

C

In a different scenario where both OSPF and EIGRP are configured to use equal-cost multi-path (ECMP) routing, the question could state that both protocols are allowed to install routes with the same prefix length, making this option correct as both routes would be used equally.

D

If the exam question stated that the router was configured to only accept routes from one protocol due to specific policy or filtering rules, then the option stating that neither route is used could be correct, as only the preferred protocol would be allowed to install routes.

Why candidates pick the wrong answer

B

Students may confuse OSPF's fast convergence or link-state nature with a higher preference, or they might think OSPF is always preferred because it is an open standard protocol.

C

Students often think that matching prefix lengths means equal preference, but they overlook the role of administrative distance in multi-protocol routing.

D

A beginner might think that duplicate routes cause conflicts or loops, but routing protocols are designed to handle multiple sources and choose the best path.

349
MCQhard

A switch unexpectedly blocks a link toward the distribution layer. Gi1/0/24 shows a path cost of 4 while Gi1/0/23 shows a path cost of 19. Why did interface Gi1/0/24 become the root port instead of Gi1/0/23?

A.Gi1/0/24 has a lower port number, so STP always prefers it first.
B.STP prefers interfaces with the highest path cost to reduce loops.
C.Gi1/0/23 is blocked because alternate ports are always chosen over root ports.
D.has a lower root path cost to the root bridge
AnswerD

This is correct because STP's root port selection is primarily based on the lowest root path cost to reach the root bridge. Gi1/0/24 has a cumulative cost of 4, whereas Gi1/0/23 has a cost of 19, so Gi1/0/24 is chosen as the root port and placed in forwarding state. Consequently, Gi1/0/23 becomes the alternate port with the higher cost and is put into blocking state to prevent Layer 2 loops.

Why this answer

Spanning Tree chooses a root port by looking for the best path toward the root bridge. In this case, Gi1/0/24 shows a cost of 4, while Gi1/0/23 shows a cost of 19. Lower cost is better, so Gi1/0/24 is selected as the root port and moves into forwarding.

Gi1/0/23 becomes an alternate port and is placed into a blocking state to prevent a loop. STP compares root path cost first; only if the cost is tied does it move on to tie-breakers like sender bridge ID and port ID. The lower cost on Gi1/0/24 explains why that port won the root-port election.

Exam trap

Remember that STP prioritizes root path cost over other factors like port numbers or bridge IDs unless there's a tie.

Why the other options are wrong

A

STP does not use port number as the primary criterion; it is only a tie-breaker when path cost, bridge ID, and sender bridge ID are all equal. Here, the path costs differ, so port number is irrelevant.

B

STP is designed to select the path with the lowest total cost to the root bridge, not the highest. Choosing a higher-cost path would increase latency and waste bandwidth.

C

The root port is the forwarding port toward the root bridge, while the alternate port is a blocked backup. The alternate port is not chosen over the root port; it only becomes active if the root port fails.

When would these options actually be correct?

A

In a different question scenario where the context involves a simplified STP decision-making process, if the question stated that all ports were configured with the same path cost, then the option could be correct if it asked which port would be preferred based on the lowest numerical identifier.

B

In a different question setup, if the question stated that STP was configured to prefer paths with higher costs for specific traffic types, then this option could be correct. For example, if the exam scenario involved a network design where certain traffic flows were intentionally routed through higher-cost paths to manage bandwidth.

C

In a different scenario where the question states that Gi1/0/23 is indeed an alternate port and that the switch is configured to prefer alternate ports over root ports, this option could be correct. For example, if the question specifies that Gi1/0/23 was previously a root port but was blocked due to a topology change, making Gi1/0/24 the new root port.

Why candidates pick the wrong answer

A

Students often confuse STP's tie-breaking rules, thinking lower port number always wins, but this only applies when all higher-priority values are identical.

B

Some might mistakenly think that higher cost implies more redundancy or loop prevention, but STP's goal is to minimize cost for optimal forwarding.

C

The terms 'alternate' and 'root' can be confusing; students may think alternate ports are preferred, but they are actually backups.

350
MCQhard

A technician is troubleshooting a network-wide broadcast storm that has caused severe performance issues. The technician notices that BPDU guard is globally enabled on the access layer switch, but no ports are in an err-disabled state. All access ports have PortFast enabled. What is the most likely cause?

A.Spanning tree is disabled globally, allowing the rogue switch to create a loop.
B.BPDU guard is misconfigured on the wrong ports, so it failed to block the rogue switch.
C.Root guard is incorrectly enabled on the access ports, causing the rogue switch to become the root bridge.
D.BPDU filter is globally enabled, causing the switch to suppress BPDUs on PortFast ports and preventing BPDU guard from triggering.
AnswerD

Global BPDU filter on a switch sets PortFast on all access ports and disables BPDU transmission and reception on those ports. The rogue switch’s BPDUs are never processed, so BPDU guard—which depends on receiving a BPDU—never err-disables the port, allowing a loop and broadcast storm.

Why this answer

BPDU guard places a port in err-disabled state upon receiving a BPDU, but BPDU filter globally enabled on PortFast ports suppresses both sending and receiving BPDUs. Since BPDU filter prevents BPDUs from being received, BPDU guard never triggers, allowing a rogue switch to participate in spanning tree and potentially cause a broadcast storm.

Exam trap

Cisco often tests the interaction between BPDU guard and BPDU filter, where candidates assume BPDU guard alone protects against rogue switches, forgetting that BPDU filter globally enabled on PortFast ports silently disables BPDU guard's detection mechanism.

Why the other options are wrong

A

This answer assumes STP is off entirely, but the presence of BPDU guard configuration indicates spanning tree is operational.

B

Candidates often assume that BPDU guard simply failed, overlooking the interaction with BPDU filter, which can neutralize guard by suppressing BPDUs.

C

Root guard is a different feature and not related to the suppression of BPDUs that would allow a loop to form undetected.

351
Multi-Selectmedium

Which two statements accurately describe CAPWAP in a controller-based WLAN context?

Select 2 answers
A.It is associated with communication between lightweight APs and the wireless LAN controller.
B.It is relevant in controller-based WLAN designs.
C.It is the same thing as a client SSID.
D.It is a replacement for WPA2 and WPA3.
E.It is used only for IPv4 ACL filtering.
AnswersA, B

CAPWAP (Control And Provisioning of Wireless Access Points) is the IETF standard protocol that creates a tunnel between lightweight access points (LAPs) and the wireless LAN controller (WLC). It carries both control plane messages (configuration, authentication) and data plane traffic (client packets) over UDP ports 5246 and 5247. This makes it the key communication channel in split-MAC architecture, not just an optional feature.

Why this answer

CAPWAP (Control and Provisioning of Wireless Access Points) is the protocol used between lightweight access points (LAPs) and the wireless LAN controller (WLC) in controller-based WLAN architectures. Options C, D, and E are incorrect: CAPWAP is not an SSID; it is a control and data tunneling protocol, not a security standard like WPA2/WPA3; and it supports both IPv4 and IPv6, not just IPv4 ACL filtering.

Exam trap

Be careful not to confuse encapsulation with encryption or assume CAPWAP is limited to a specific IP version.

Why the other options are wrong

C

CAPWAP is a control protocol for AP-WLC communication, not a client SSID—an SSID is the network name that clients see and associate with.

D

CAPWAP is not a security replacement; WPA2 and WPA3 are wireless security standards, whereas CAPWAP tunnels traffic between AP and WLC.

E

CAPWAP supports both IPv4 and IPv6 transport; it is not limited to IPv4 ACL filtering.

When would these options actually be correct?

C

If the exam question asked about the various components and configurations of a wireless network, including client-side settings, then stating that CAPWAP is the same as a client SSID could be correct in a context where the question is misleadingly phrased or focuses on user-facing aspects of WLAN.

D

In a question that asks about security protocols in WLANs, specifically focusing on their roles in authentication and encryption, this option would be correct if it stated that CAPWAP is a replacement for a specific legacy protocol that manages access point communication, but not for WPA2 or WPA3.

E

If the exam question were to ask about the specific functionalities of CAPWAP in relation to network security features, and if it were framed in a context where CAPWAP was described as a protocol that includes ACL filtering capabilities, then option E could be considered correct.

Why candidates pick the wrong answer

C

Students might confuse CAPWAP with SSID because both are associated with WLANs, but they serve entirely different purposes. The acronym similarity (both start with 'C' and 'S' sounds) can lead to this misconception.

D

Since CAPWAP is used in secure WLAN deployments, some may mistakenly think it provides security functions. However, security is handled by separate protocols like WPA2/3, 802.1X, or VPNs.

E

Because CAPWAP can carry control and data traffic, and ACLs are often applied to filter traffic on WLCs, students might incorrectly associate CAPWAP with ACL filtering. However, CAPWAP is the transport mechanism, not the filtering method.

352
MCQmedium

A network administrator is configuring a new Windows workstation on a small office network that uses IPv4 addressing. The workstation must be able to communicate with devices on other subnets and resolve hostnames via a company DNS server at 10.10.10.5. The administrator has already set the IP address to 10.10.10.10 and the subnet mask to 255.255.255.0. Which additional parameter must be configured to meet both requirements?

A.Configure a default gateway of 10.10.10.1 and a DNS server of 10.10.10.5.
B.Configure only a DNS server of 10.10.10.5.
C.Change the subnet mask to 255.255.0.0 to allow communication across subnets.
D.Configure a default gateway of 10.10.20.1 and a DNS server of 10.10.10.5.
AnswerA

This is the correct configuration because both entries are necessary and valid. The default gateway 10.10.10.1 lies on the same subnet as the workstation's IP address, so the host can resolve the gateway's MAC address via ARP and forward all out-of-subnet traffic to it. The router then routes packets between the 10.10.10.0/24 and 10.10.20.0/24 networks, enabling communication with devices on the other subnet. The DNS server 10.10.10.5 is also on the local subnet, allowing name resolution to work without requiring routing. Together, they provide both name resolution and the necessary Layer 3 path.

Why this answer

To communicate with devices on other subnets, the workstation needs a default gateway (router) to forward traffic beyond its local subnet. The IP address 10.10.10.10 with subnet mask 255.255.255.0 places it in the 10.10.10.0/24 network, so a default gateway (e.g., 10.10.10.1) is required for inter-subnet routing. Additionally, to resolve hostnames, the DNS server address must be explicitly configured; the company DNS server is at 10.10.10.5.

Option A correctly provides both parameters.

Exam trap

Cisco often tests the requirement that a default gateway must be on the same subnet as the host; the trap here is that candidates may think a DNS server alone suffices for inter-subnet communication, or they may incorrectly assume changing the subnet mask can replace a router, or they may choose a gateway on a different subnet without realizing it is unreachable.

Why the other options are wrong

B

Without a default gateway, the workstation cannot send packets to destinations outside its own subnet (10.10.10.0/24). The DNS server alone only provides name resolution, not routing to other subnets.

C

Changing the subnet mask to 255.255.0.0 would expand the broadcast domain and could cause routing problems, but it does not provide a path to other subnets. The workstation still needs a default gateway to communicate with devices outside its local network.

D

The default gateway 10.10.20.1 is not on the same subnet as the workstation (10.10.10.0/24). For a host to reach its default gateway, the gateway must be directly reachable on the local subnet. Since 10.10.20.1 is on a different subnet, the workstation cannot send traffic to it.

Why candidates pick the wrong answer

B

Students may think that DNS is the only missing piece because the IP and subnet mask are already set, overlooking the need for a default gateway to reach other subnets.

C

Some students might incorrectly believe that a larger subnet mask allows communication across subnets by including them in the same network, but this is not how routing works; it would actually break connectivity.

D

Students might think any IP can serve as a default gateway, but they must ensure it is on the same subnet. The DNS server is correct, but the gateway is misconfigured.

353
Multi-Selectmedium

Which TWO statements accurately describe 802.1Q trunking and inter-VLAN routing on Cisco switches?

Select 2 answers
A.The native VLAN on a trunk port sends frames with an 802.1Q tag containing VLAN ID 1.
B.802.1Q trunking adds a 4-byte tag that includes a 12-bit VLAN ID field, increasing the maximum frame size.
C.A router-on-a-stick configuration uses subinterfaces, each mapped to a VLAN with 802.1Q encapsulation and an IP address in a unique subnet.
D.A trunk port can only forward traffic for one VLAN at a time.
E.The native VLAN on a trunk cannot be changed from VLAN 1.
AnswersB, C

802.1Q trunking inserts a 4-byte tag field between the source MAC address and the EtherType/length field. This tag comprises a 16-bit TPID (0x8100) and a 16-bit TCI, which contains a 3-bit priority, a 1-bit Drop Eligible Indicator (DEI), and a 12-bit VLAN ID supporting up to 4094 usable VLANs. Adding this 4-byte field increases the maximum Ethernet frame size from 1518 to 1522 bytes for tagged frames.

Why this answer

Option B is correct because 802.1Q inserts a 4-byte tag into the Ethernet frame, and that tag contains a 12-bit VLAN Identifier (VID) field supporting VLAN IDs 1-4094, which increases the frame size beyond the standard 1518 bytes (up to 1522 bytes). Option C is correct because router-on-a-stick uses one physical router interface divided into logical subinterfaces, and each subinterface is configured with encapsulation dot1q <vlan-id> plus an IP address in a distinct subnet to route between VLANs. Option A is incorrect because the native VLAN is the one VLAN whose frames are sent untagged on an 802.1Q trunk, not tagged with VLAN ID 1.

Option D is incorrect because a trunk port carries traffic for multiple VLANs simultaneously, tagging frames to keep them separated. Option E is incorrect because the native VLAN is configurable per trunk port with the switchport trunk native vlan command and is not locked to VLAN 1.

Exam trap

Cisco often tests the misconception that the native VLAN is always VLAN 1 and that it is tagged, when in fact the native VLAN is untagged and can be changed to any VLAN number.

Why the other options are wrong

A

By default, frames belonging to the native VLAN (VLAN 1) traverse a trunk link without an 802.1Q tag.

D

Trunk ports differentiate frames from multiple VLANs using VLAN tags, permitting concurrent forwarding for all allowed VLANs.

E

Cisco switches allow administrators to assign any active VLAN as the native VLAN for a trunk port.

354
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure gRPC streaming telemetry subscription on a Cisco IOS-XE device, from initial setup to data collection.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order starts with entering global config, then enabling telemetry, defining subscription details (encoding and filter), specifying the receiver, and finally verifying data collection.

Exam trap

The trap is that candidates may confuse the order of enabling telemetry and defining the subscription, or think that global config is not needed first. Remember that all telemetry commands are configured in global config mode, and the subscription must be defined before the receiver can be added.

Why candidates pick the wrong answer

B

Candidates might think telemetry can be enabled from any mode, but it requires global config.

C

Candidates might think subscription details can be defined first, but the order is sequential.

D

Candidates might think receiver configuration is independent, but it is part of the subscription.

355
PBQhard

You are securing the spanning-tree topology on R1, the root bridge for VLAN 10. Intended configurations: Root Guard on GigabitEthernet1/0/3, Loop Guard on gigabit interfaces 1/0/1 and 1/0/2, and BPDU Guard on all PortFast-enabled interfaces. After initial configuration, a superior BPDU on G1/0/3 blocks the port (expected), and a host on G1/0/5 triggers BPDU Guard, causing err-disable (expected). However, you realize Loop Guard was not applied to the uplinks. Troubleshoot and apply the missing configuration.

Hints

  • •Root Guard on the root bridge may cause blocking if a superior BPDU is received; this is correct behavior unless the port should be a root port.
  • •Loop Guard prevents alternate or root ports from becoming designated in case of unidirectional link failure; it is safe on trunk uplinks.
  • •BPDU Guard err-disables a PortFast port when a BPDU is received; re-enable with 'no shutdown' after fixing the cause.
A.Remove Root Guard from G1/0/3 and configure it with 'spanning-tree guard loop' to prevent the blockage.
B.Re-enable G1/0/5 with 'no shutdown' and apply 'spanning-tree bpduguard enable' on all PortFast-enabled interfaces to prevent future err-disable.
C.Configure Loop Guard on G1/0/1 and G1/0/2 with 'spanning-tree guard loop' and recover G1/0/5 from err-disable by issuing 'shutdown' followed by 'no shutdown'.
D.Remove BPDU Guard from all PortFast interfaces and configure 'spanning-tree portfast bpdufilter default' to prevent err-disable.
AnswerC
solution
! R1
interface GigabitEthernet1/0/1
spanning-tree guard loop
interface GigabitEthernet1/0/2
spanning-tree guard loop
interface GigabitEthernet1/0/5
shutdown
no shutdown

Why this answer

The candidate must first identify that Root Guard is correctly configured on G1/0/3, causing it to block (BKN*ROOT_Guard) upon receiving a superior BPDU, which is correct behavior. However, the task states to protect the root bridge role; since R1 is already root, Root Guard is appropriate. The err-disabled port G1/0/5 indicates BPDU Guard triggered; this is expected because a host connected to a PortFast port sent a BPDU.

To resolve, the candidate should re-enable the port with 'no shutdown' and ensure BPDU Guard is properly applied. Additionally, Loop Guard is missing on uplinks G1/0/1 and G1/0/2; it must be configured with 'spanning-tree guard loop' under each interface. No changes to Root Guard are needed; the blockage is intentional.

Exam trap

Do not assume that a blocked port due to Root Guard is a problem; it is intentional. Also, do not confuse BPDU Guard with BPDU Filter; BPDU Guard err-disables, while BPDU Filter suppresses BPDUs. Remember that err-disabled ports must be manually re-enabled with 'no shutdown'.

Why the other options are wrong

A

Root Guard is designed to block a port that receives superior BPDUs, which is exactly what happened. The configuration is correct and should not be removed.

B

BPDU Guard is correctly configured; the err-disable is expected behavior when a BPDU is received on a PortFast port. The solution is to re-enable the port and ensure the host is not a switch.

D

BPDU Filter is not a substitute for BPDU Guard; it prevents the port from sending or receiving BPDUs, which can cause bridging loops. The correct action is to re-enable the port, not change the protection mechanism.

Why candidates pick the wrong answer

A

Candidates may think that any blocked port is a problem and needs to be fixed by changing the guard type, not realizing that Root Guard's purpose is to block in this scenario.

B

Candidates might think that BPDU Guard should be removed or that the configuration is missing, but it is already applied and working as designed.

D

Candidates may confuse BPDU Guard with BPDU Filter, thinking that filtering BPDUs would prevent the err-disable, but this compromises network stability.

356
Multi-Selectmedium

Which THREE statements accurately describe the role of AI agents in closed-loop remediation workflows for network automation?

Select 3 answers
A.AI agents require manual approval before executing any remediation action in a closed-loop workflow.
B.AI agents can autonomously analyze network telemetry and decide on remediation actions.
C.AI agents rely solely on static baseline configurations to detect anomalies.
D.Tool-calling allows AI agents to invoke external automation tools (e.g., Ansible, Python scripts) to execute remediation steps.
E.In a closed-loop remediation workflow, the AI agent monitors the network after action to confirm the issue is resolved and adjusts if needed.
F.AI agents eliminate the need for human oversight in network operations.
AnswersB, D, E

Autonomous analysis is enabled by the AI agent's ability to consume and correlate diverse telemetry sources — interface counters, CPU/memory utilization, routing tables, and flow records — in real time. Using machine learning models or rule-based logic, the agent identifies anomalies (e.g., high error rate, BGP session flapping) and determines the appropriate remediation step, such as adjusting OSPF cost, resetting a neighbor, or applying a temporary policy. This decision-making capability runs continuously and automatically, which is central to closed-loop automation and differentiates it from simple scripted monitoring that reacts to fixed thresholds.

Why this answer

B is correct because AI agents in closed-loop remediation workflows autonomously analyze network telemetry (e.g., gRPC, NETCONF) and decide on remediation actions without manual intervention, enabling rapid response. D is correct because tool-calling allows the AI agent to invoke external automation tools like Ansible or Python scripts to execute the chosen remediation steps. E is correct because a key part of the closed-loop is that the AI agent monitors the network after action to confirm the issue is resolved and adjusts if needed, ensuring the loop is closed.

A is wrong because closed-loop automation implies autonomous execution based on predefined policies, not requiring manual approval for every action. C is wrong because AI agents use dynamic telemetry and learned patterns, not just static baseline configurations, to detect anomalies. F is wrong because AI agents augment, not eliminate, human oversight; human intervention remains for policy exceptions and oversight.

Exam trap

Cisco often tests the misconception that AI agents require manual approval for every action in closed-loop workflows, when in fact the 'closed-loop' concept implies autonomous execution based on predefined policies.

Why the other options are wrong

A

Closed-loop remediation is defined by autonomous execution without manual approval for standard actions.

C

AI agents rely on continuous telemetry and machine learning, not solely static baseline configurations, to detect anomalies.

F

AI agents reduce but do not eliminate the need for human oversight, especially for policy exceptions and strategic decisions.

Why candidates pick the wrong answer

A

Students may confuse closed-loop automation with traditional change management processes that require manual approval, or they may think that AI agents always need human validation before acting.

C

Students may think that baselines are the primary method for anomaly detection, confusing static baselines with the dynamic baselines that AI agents actually use.

F

Students may overestimate the autonomy of AI agents, thinking that closed-loop automation means fully autonomous operations without any human involvement.

357
MCQmedium

Which traffic type is typically most sensitive to delay and jitter and is commonly prioritized with QoS?

A.Voice traffic
B.Bulk backup traffic
C.Email attachments
D.Operating system updates
AnswerA

Voice (VoIP) is the archetypal real-time traffic because human conversation requires an interactive exchange where end-to-end delay above 150 ms or excessive jitter causes perceptible degradation like echo and talker overlap. Cisco recommends Express Forwarding with priority queuing for voice to keep delay and packet loss below strict thresholds, as retransmission is useless for live audio. This makes voice the most delay-sensitive traffic type among the listed options, because any queuing delay directly compromises call quality.

Why this answer

Voice traffic is highly sensitive to delay, jitter, and packet loss, so it is commonly prioritized in QoS policies.

Exam trap

A common exam trap is assuming that all traffic types require equal QoS prioritization. Candidates might incorrectly select bulk backup traffic or email attachments because they involve large data transfers, but these are not sensitive to delay or jitter. The trap lies in confusing throughput sensitivity with latency sensitivity.

Voice traffic demands low latency and minimal jitter to maintain call quality, which is why it is prioritized. Misunderstanding this distinction can lead to choosing incorrect answers that focus on volume rather than real-time sensitivity.

Why the other options are wrong

B

Bulk backup traffic is throughput-sensitive but not delay-sensitive. It can tolerate delays and jitter without impacting the backup process, so it is not typically prioritized by QoS in Cisco networks.

C

Email attachments are not time-sensitive and can tolerate delays and jitter. They do not require prioritization in QoS policies, making this option incorrect for delay-sensitive traffic.

D

Operating system updates involve large data transfers that are throughput-sensitive but not sensitive to delay or jitter. They are usually scheduled during off-peak times and are not prioritized by QoS.

When would these options actually be correct?

B

If the exam question were to ask which traffic type is least time-sensitive and can be scheduled for off-peak hours, bulk backup traffic would be the correct answer. This would highlight scenarios where data integrity and completion are prioritized over immediate delivery.

C

If the exam question asked about traffic types that require reliable delivery rather than real-time performance, such as in a scenario discussing data integrity over speed, email attachments could be prioritized. For example, a question might focus on the importance of ensuring all data is received accurately, making email attachments the correct answer.

D

If the question were to ask which traffic type is commonly managed for reliability and consistency during scheduled maintenance windows, operating system updates could be prioritized to ensure timely deployment without interruption, making this option correct.

Why candidates pick the wrong answer

B

Students might mistakenly think that any large data transfer requires prioritization, confusing the need for bandwidth with the need for low latency. However, backups are usually scheduled during off-peak hours and do not require real-time treatment.

C

A student might assume that because email is important for business communication, it should be prioritized. However, email is not interactive and does not suffer from delay or jitter, so it is typically assigned a lower QoS class.

D

Students might think that because updates are necessary for security, they should be prioritized. However, updates are not interactive and can be scheduled during maintenance windows, so they are usually given best-effort treatment.

358
PBQmedium

You are connected to SW1 via the console. SW1 is a Layer 2 switch with two links to SW2: G0/1 and G0/2. The administrator wants to combine these two links into an EtherChannel using LACP. Configure an EtherChannel on SW1 for these ports and verify.

Hints

  • •EtherChannel requires a port-channel interface and channel-group configuration on member ports.
  • •Use mode active for LACP.
A.interface range g0/1-2 channel-group 1 mode active
B.interface range g0/1-2 channel-group 1 mode desirable
C.interface g0/1 channel-group 1 mode active interface g0/2 channel-group 1 mode passive
D.interface port-channel 1 channel-group 1 mode active
AnswerA
solution
! SW1
interface port-channel 1
interface range GigabitEthernet0/1-2
channel-group 1 mode active

Why this answer

LACP (IEEE 802.3ad) uses 'active' or 'passive' modes; at least one side must be active for the bundle to form. Configuring both G0/1 and G0/2 under an interface range with 'channel-group 1 mode active' correctly places both physical interfaces into EtherChannel 1 using LACP in active negotiation mode, which is the standard Cisco-recommended configuration for LACP on both ends.

Exam trap

200-301 often tests the LACP vs PAgP mode confusion (active/passive vs desirable/auto) and the mistake of applying channel-group commands to the logical port-channel interface instead of the physical members.

Why the other options are wrong

B

The specific factual error is that 'desirable' is a PAgP mode, not LACP. LACP uses 'active' or 'passive'.

C

The specific factual error is that LACP requires both ends to be in compatible modes (active-active or active-passive), but on the same switch, both ports should use the same mode for the same channel group.

D

The specific factual error is that 'channel-group' is a physical interface command, not a port-channel interface command. The port-channel interface is used for logical configuration (e.g., trunking) after the channel is formed.

Why candidates pick the wrong answer

B

Candidates might confuse PAgP and LACP modes, especially since both have similar concepts of negotiation.

C

Candidates might think that using 'active' on one port and 'passive' on the other is acceptable because LACP allows that between switches, but they forget that both ports on the same switch must be configured identically.

D

Candidates might think that the port-channel interface needs to be created first and then the channel-group command applied to it, but the correct order is to apply channel-group on physical interfaces.

359
MCQeasy

A company wants wireless guest users to authenticate with a username and password stored on a central server, without deploying client certificates. The wireless LAN controller must forward authentication requests to the server. Which protocol should be used between the WLC and the authentication server?

A.Kerberos
B.LDAP
C.RADIUS
D.TACACS+
AnswerC

RADIUS is the standard protocol for centralized authentication of wireless users, including 802.1X/EAP exchanges. The WLC acts as a RADIUS client, forwarding credentials to the authentication server. It supports username and password methods such as PEAP-MSCHAPv2 without requiring client certificates on the supplicant.

Why this answer

Wireless LAN controllers use RADIUS to communicate with authentication servers for 802.1X and other centralized authentication methods. RADIUS supports username and password credentials through EAP methods like PEAP, so guest or employee users can authenticate without client certificates while the WLC forwards requests to the server.

Exam trap

The trap here is conflating device administration protocols like TACACS+ with wireless user authentication, which relies on RADIUS in Cisco WLAN deployments.

360
Drag & Drophard

Drag and drop the following steps into the correct order to configure AAA with a RADIUS server and 802.1X port authentication on an IOS-XE switch.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First configure the RADIUS server, then enable AAA, create an authentication list for 802.1X, and finally apply 802.1X to the port.

Exam trap

Do not confuse the order of enabling AAA and creating authentication lists. AAA must be enabled globally before you can create authentication lists. Also, remember that the RADIUS server configuration comes first, as AAA needs to know which server to use.

Why candidates pick the wrong answer

B

Candidates might think that enabling AAA first is enough and that the authentication list can be created later, but the port configuration references the list.

C

Candidates might think that the authentication list can be created independently of AAA, but it is a subcomponent of AAA.

D

Candidates might think that applying 802.1X to the port is a simple interface command that can be done at any time, but it depends on underlying AAA configuration.

361
PBQhard

You are connected to SW1. An EtherChannel between SW1 and SW2 using LACP must be established on interfaces GigabitEthernet0/1 and GigabitEthernet0/2. Currently, the channel is not forming. Inspect the provided configuration and output, then apply the necessary commands on SW1 to resolve the issue and bring up the Port-Channel interface.

Network Topology
Gi0/1Gi0/1EtherChannelSW1SW2

Hints

  • •Check the duplex and speed settings on both member interfaces on SW1.
  • •Verify that the native VLAN (or access VLAN if not trunking) is identical on all bundled ports.
  • •Ensure both sides use compatible LACP modes (active/active or active/passive).
A.Configure both interfaces with speed 1000, duplex full, and switchport access vlan 1.
B.Change the LACP mode on SW1's Gi0/2 from active to passive.
C.Configure both interfaces with speed 100, duplex half, and switchport access vlan 10.
D.Remove the switchport access vlan command from both interfaces and configure them as trunk ports with native vlan 1.
AnswerA
solution
! SW1
interface gigabitEthernet 0/2
speed 1000
duplex full
switchport access vlan 1
end

Why this answer

The EtherChannel failed because the two member interfaces on SW1 have mismatched speed (Gi0/1: 1000 Mbps, Gi0/2: 100 Mbps) and duplex (Gi0/1: full, Gi0/2: half), and their native VLANs differ (Gi0/1: VLAN 1, Gi0/2: VLAN 10). LACP requires all bundled ports to have identical speed, duplex, and VLAN configuration. To fix, on SW1 configure both interfaces with consistent settings: set speed 1000, duplex full, and switchport access vlan 1 (or a common trunk native VLAN).

Also ensure both sides use the same LACP mode (both active or active/passive); here SW2's Gi0/2 is passive, which is acceptable with SW1's active, so the primary issue is the mismatched physical and VLAN parameters. After correction, the channel will form.

Exam trap

Do not focus solely on LACP mode mismatches; always check physical parameters (speed, duplex) and VLAN consistency first. Mismatched native VLANs are a common cause of EtherChannel failures.

Why the other options are wrong

B

The specific factual error is assuming that LACP mode must match on both sides; active/passive is acceptable.

C

The specific factual error is that the solution should aim for optimal performance, not just consistency; using 100/half is technically possible but not the best practice.

D

The specific factual error is that trunking does not fix speed/duplex mismatches, and the native VLAN must be consistent.

Why candidates pick the wrong answer

B

Candidates may think both sides need the same LACP mode, but active/passive is a common valid pairing.

C

Candidates might think any consistent configuration works, but the exam expects the best practice of using the higher speed and full duplex.

D

Candidates may think trunking is required for EtherChannel or that native VLAN mismatch is the only issue, overlooking the physical layer mismatches.

362
MCQhard

An ACL is intended to block Telnet from 10.1.1.0/24 to router VTY access while still allowing SSH from the same subnet. Which statement best explains why an extended ACL is appropriate here?

A.Because the ACL must distinguish traffic by protocol or destination port, not just by source address.
B.Because standard ACLs can match destination TCP ports just as well.
C.Because extended ACLs are required for every router login policy regardless of criteria.
D.Because SSH and Telnet always use the same port number.
AnswerA

This is correct because Telnet and SSH are both TCP-based and may originate from the same source network. A standard ACL can only filter based on source IP, so it cannot differentiate between Telnet (port 23) and SSH (port 22). An extended ACL must match the TCP destination port 23 along with source and destination addresses to block Telnet from 10.1.1.0/24 without impacting other traffic. Without this granularity, the ACL would either block all IP traffic from the source or fail to block Telnet specifically.

Why this answer

An extended ACL is appropriate because the requirement is based not only on source address but also on the specific protocol and application port involved. In practical terms, the policy must distinguish Telnet from SSH even though both originate from the same source subnet. A standard ACL would be too limited because it mainly matches only on source address.

This is the kind of requirement that shows why extended ACLs exist. They allow more granular traffic control by matching protocol and destination details, not just who sent the packet.

Exam trap

Do not confuse the ability to filter by protocol and port with filtering by IP address alone; extended ACLs are required for the former.

Why the other options are wrong

B

Standard ACLs can only filter based on source IP address, not destination ports or protocols. They lack the granularity to distinguish between Telnet and SSH traffic.

C

Extended ACLs are not required for every router login policy; they are only needed when filtering must consider protocol or port information. Simple source-based filtering can use standard ACLs.

D

SSH uses TCP port 22, while Telnet uses TCP port 23. They are distinct ports, so an ACL can differentiate them based on destination port.

When would these options actually be correct?

B

In a different scenario where the question states that both Telnet and SSH traffic are being filtered based solely on source IP addresses, and there is no requirement to distinguish between protocols or ports, option B could be correct. For example, if the question asked if a standard ACL could block all traffic from a specific subnet without regard to protocol, this option would apply.

C

In a different exam scenario, if the question stated that all types of ACLs must be extended for any login policy regardless of the criteria involved, then option C would be correct. For example, if the question specified that only extended ACLs can be used for any form of access control, then this option would apply.

D

In a different scenario where the question states that both SSH and Telnet are configured to use the same port number for some reason, such as a misconfiguration or a specific lab setup, then this option could be correct. The question would need to specify that both protocols are intentionally set to operate on the same port.

Why candidates pick the wrong answer

B

Students may confuse standard ACLs with extended ACLs, thinking they can match ports, but standard ACLs are limited to source addresses only.

C

The phrase 'required for every router login policy' might mislead students into thinking extended ACLs are mandatory for VTY access, but the need depends on the specific filtering criteria.

D

Students might mistakenly think both services use the same port due to their similar function (remote login), but they are separate protocols with different port numbers.

363
MCQhard

Refer to the exhibit. A network engineer is troubleshooting a connectivity issue on SW3. A host connected to the same segment as SW3's GigabitEthernet0/0 interface cannot reach any network resources. The engineer issues the show spanning-tree vlan 10 command and receives the output shown. Based on the output, what is the most likely cause?

A.GigabitEthernet0/0 is administratively down, which prevents the host from communicating.
B.The port is in the Blocking state because the switch detected a loop and moved the port to error-disabled state.
C.The port is blocked because SW3 has a lower bridge priority than the root bridge and should be the designated port for that segment.
D.The interface GigabitEthernet0/0 is in the Blocking state because it received a superior BPDU, making it an alternate port to the root bridge.
AnswerD

The output explicitly shows role 'Altn' and state 'BLK' for Gi0/0. An alternate port is blocked because it receives better BPDUs on that interface than it can send, providing an alternate path to the root bridge. This is correct STP behavior, and the blocking state prevents the host from communicating.

Why this answer

The output shows that GigabitEthernet0/0 is in the Blocking state for VLAN 10. In Rapid PVST+ or classic STP, a port enters the Blocking state when it receives a superior BPDU (i.e., a BPDU with a lower bridge ID or lower path cost to the root), causing it to become an alternate (or backup) port rather than a designated or root port. This prevents the host from reaching network resources because the port does not forward traffic.

Exam trap

Cisco often tests the distinction between a port being blocked due to normal STP operation (receiving a superior BPDU) versus being error-disabled or administratively down, leading candidates to incorrectly assume a physical or administrative issue.

Why the other options are wrong

A

Candidates may incorrectly associate the blocked state with an administratively disabled interface.

B

Candidates often confuse error-disabled state (caused by features like BPDU guard) with the standard STP blocking state.

C

Candidates may misunderstand the root election process and assume a lower priority switch always becomes designated for all segments, ignoring the Altn role.

364
Multi-Selectmedium

Which two statements accurately describe OSPF passive interfaces?

Select 2 answers
A.It prevents OSPF from sending hello packets on that interface.
B.It can still allow the connected network to be advertised into OSPF.
C.It changes OSPF into a static route on that interface.
D.It forces the interface to become the router ID.
E.It disables OSPF on every interface in the router automatically.
AnswersA, B

The OSPF passive-interface command suppresses the transmission of hello packets out of that specific interface, preventing the router from establishing or maintaining neighbor adjacencies on that link. Because OSPF relies on hello packets over multicast 224.0.0.5 to discover neighbors, a passive interface will not send or receive those hellos, so no OSPF neighbor relationship can form there. However, the interface remains an OSPF-attached network and its prefix is still injected into the LSDB and advertised to other neighbors reachable through active interfaces.

Why this answer

An OSPF passive interface stops hello packet exchange on that interface while still allowing the connected network to be advertised into OSPF through other active adjacencies. In plain language, it tells the router not to try to form neighbors on that interface, but not to forget that the network exists. This is very useful on user-facing or stub-like interfaces where no routing neighbor should appear.

The wrong answers often treat passive as if it disables OSPF globally or removes the network completely. The two correct answers are the ones that preserve the suppression of adjacency on that interface and the continued advertisement of the connected network.

Exam trap

A common exam trap is to confuse the effect of the OSPF passive interface command with disabling OSPF entirely on that interface or converting OSPF routes into static routes. Some candidates mistakenly believe that passive interfaces stop all OSPF activity or remove the network from OSPF advertisements. In reality, passive interfaces only stop OSPF hello packets and adjacency formation but continue to advertise the connected network.

Misunderstanding this can lead to incorrect answers or network misconfigurations, especially when interpreting how OSPF maintains routing information despite passive interfaces.

Why the other options are wrong

C

This option is incorrect because passive interfaces do not convert OSPF routes into static routes; OSPF routing remains dynamic and active elsewhere.

D

This option is incorrect because the passive-interface command does not affect the router ID selection, which is determined by other OSPF rules.

E

This option is incorrect because passive-interface affects only the specified interface unless configured globally; it does not disable OSPF on all interfaces.

When would these options actually be correct?

C

In a different question asking about the effects of configuring OSPF on a specific interface, if the question stated that passive interfaces behave like static routes in terms of not participating in OSPF neighbor relationships, option C could be considered correct.

D

In a question asking about OSPF configuration where the context is about defining router roles or attributes, one might state that a specific interface is being used to define the router ID, making it the correct answer in that scenario.

E

In a different question, if it asked about a command that globally disables OSPF on all interfaces when applied, then 'disables OSPF on every interface in the router automatically' could be correct in the context of a command that applies to all interfaces, such as 'router ospf 1' with a specific configuration.

Why candidates pick the wrong answer

C

The term 'passive' might be misinterpreted as making the route static or non-dynamic. Students may think that a passive interface means the route becomes static, but in OSPF, passive only suppresses hello packets, not the dynamic advertisement of the network.

D

Students might confuse the passive-interface command with other OSPF configuration commands that affect router identity, such as router-id, or mistakenly think that making an interface passive somehow promotes it to a special role like the router ID.

E

The word 'passive' might imply a global effect, and students may assume that configuring passive-interface on one interface disables OSPF on all interfaces. However, OSPF passive interfaces are interface-specific unless the default keyword is used.

365
MCQeasy

At which OSI layer do routers make forwarding decisions based on logical addressing?

A.Layer 1
B.Layer 2
C.Layer 3
D.Layer 4
AnswerC

Routers make forwarding decisions at OSI Layer 3, the network layer, by inspecting the destination IPv4 or IPv6 address in the packet header. They consult their routing table and apply the longest-prefix-match rule to select the next hop toward the destination network. This logical addressing allows routing across different broadcast domains.

Why this answer

Routers operate at the network layer when making forwarding decisions based on logical Layer 3 addresses such as IPv4 or IPv6 destination addresses.

Exam trap

Don't confuse the roles of routers and switches. Remember that routers use logical addressing (IP addresses) at Layer 3, while switches use physical addressing (MAC addresses) at Layer 2.

Why the other options are wrong

A

Layer 1 (Physical layer) deals with the physical transmission of bits over media, such as cables or radio frequencies. Routers do not make forwarding decisions at this layer; they only handle electrical or optical signals.

B

Layer 2 (Data Link layer) uses MAC addresses for switching within the same network segment. Routers, however, forward packets based on Layer 3 logical addresses, not MAC addresses, which are only used for next-hop delivery.

D

Layer 4 (Transport layer) handles end-to-end communication, segmentation, and flow control using protocols like TCP and UDP. Routers do not use Layer 4 information for forwarding decisions; they only examine Layer 3 headers.

When would these options actually be correct?

A

If the question were to ask about the physical aspects of network communication, such as how signals are transmitted over cables or wireless media, then Layer 1 would be the correct answer.

B

If the question asked about devices that operate at Layer 2, such as switches making decisions based on MAC addresses, then option B would be correct. An example question could be: 'At which OSI layer do switches make forwarding decisions based on physical addressing?'

D

In a question that asks about the role of Layer 4 in establishing connections and managing data transfer reliability, such as 'At which OSI layer do devices manage session establishment and data integrity?', option D would be correct.

Why candidates pick the wrong answer

A

Students might confuse the physical connectivity of routers (e.g., interfaces, cables) with the layer at which routing decisions occur, but forwarding decisions are not made at Layer 1.

B

Since routers have MAC addresses and use ARP, some may mistakenly think routing occurs at Layer 2. However, routing decisions are based on logical addressing, not MAC addresses.

D

Students might associate routers with port numbers or stateful inspection (e.g., ACLs) and think Layer 4 is involved, but basic routing is purely Layer 3.

366
Drag & Dropmedium

Drag and drop the following troubleshooting steps into the correct order to isolate CRC errors, duplex mismatches, and flapping on a Cisco IOS-XE interface.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct troubleshooting order is: first, use show commands to gather interface statistics and identify CRC errors, duplex mismatches, and flapping (Step A). Next, apply configuration changes to resolve the identified issues (Step C). Then, clear interface counters to reset the statistics (Step B).

Finally, verify the fix by monitoring interface statistics after clearing counters (Step D). This order ensures that after applying changes, you clear the old error data so that verification shows only new errors, confirming the fix. Clearing counters before verification provides a clean baseline.

Exam trap

Do not skip clearing counters before verification. After applying changes, you must clear the counters to remove old error data, then verify that new errors do not appear. The correct order is gather, apply, clear, verify.

367
MCQmedium

Which command correctly configures an IPv6 default route using next-hop address 2001:db8:1::1?

A.ipv6 route ::/0 2001:db8:1::1
B.ip route :: 2001:db8:1::1
C.ipv6 default-route 2001:db8:1::1
D.ip default-gateway 2001:db8:1::1
AnswerA

The IOS global configuration command `ipv6 route` is the valid method to install a static IPv6 route, and the network prefix `::/0` is the IPv6 default route because it matches all destination addresses. Specifying `2001:db8:1::1` as the next hop tells the router to forward all unmatched IPv6 traffic to that neighbor. This is the exact syntax Cisco IOS uses for an IPv6 default route.

Why this answer

The correct IPv6 default route uses the prefix ::/0 with the command 'ipv6 route ::/0'. Option B is wrong because 'ip route' is used for IPv4 routes, not IPv6. Option C uses 'ipv6 default-route', which is not a valid Cisco IOS command.

Option D sets the management default gateway for IPv4 only and does not insert a route into the IPv6 routing table.

Exam trap

Be cautious about the syntax order and the correct representation of the IPv6 default route prefix.

Why the other options are wrong

B

Uses 'ip route', which is for IPv4; IPv6 routes require 'ipv6 route'.

C

'ipv6 default-route' is not a valid Cisco IOS command.

D

'ip default-gateway' configures the management default gateway for IPv4, not an IPv6 routing entry.

When would these options actually be correct?

B

In a question specifically asking for an IPv4 default route configuration, where the next-hop address is also in IPv4 format, option B would be correct. For example, if the question stated to configure a default route using an IPv4 address like 192.168.1.1, then 'ip route 0.0.0.0 192.168.1.1' would be the right command.

C

If the exam question specifically asked for the command to configure a default route in a different context, such as using a specific vendor's proprietary syntax that recognizes 'ipv6 default-route', then this option would be correct.

D

If the question were focused on configuring a default gateway for a Layer 2 switch in a small network environment, where no Layer 3 routing is involved, then 'ip default-gateway 2001:db8:1::1' would be the correct command to set the gateway for the switch to reach other networks.

Why candidates pick the wrong answer

B

Students may confuse the IPv4 default route command 'ip route 0.0.0.0 0.0.0.0' with IPv6, incorrectly assuming 'ip route ::' is equivalent. The similarity in syntax can lead to this mistake.

C

The phrase 'default-route' sounds intuitive and similar to 'default-gateway' or 'default route', making it tempting for those who guess the command syntax without knowing the exact IOS command.

D

Students may recall that 'ip default-gateway' sets a default route on a switch and incorrectly assume it works for IPv6 on a router. The term 'default-gateway' is commonly associated with default routes.

368
PBQhard

You are connected to SW1. Configure an LACP EtherChannel between SW1 and SW2 using interfaces GigabitEthernet0/1 and GigabitEthernet0/2. Set the channel-group mode to active on both switches. Verify that the port-channel interface is configured with VLAN 100 as an access port. Then, troubleshoot and fix the issue that prevents the EtherChannel from forming due to a mismatched speed on one of the member links. After correction, verify the EtherChannel is up with 'show etherchannel summary'.

Hints

  • •Check the speed and duplex settings on all member interfaces.
  • •LACP requires identical speed and duplex on all ports in the channel.
  • •Use the 'speed' and 'duplex' commands under the interface to match the working member.
A.Set speed 1000 and duplex full on interface GigabitEthernet0/2 of SW1, ensuring the corresponding interface on SW2 has matching settings, then verify with 'show etherchannel summary'.
B.Change the channel-group mode to desirable on both switches and verify with 'show etherchannel summary'.
C.Remove the access VLAN configuration from the port-channel interface and configure it as a trunk port instead.
D.Configure the channel-group mode to passive on SW1 and active on SW2, then verify with 'show etherchannel summary'.
AnswerA
solution
! SW1
interface GigabitEthernet0/2
speed 1000
duplex full

Why this answer

The EtherChannel fails because interface GigabitEthernet0/2 on SW1 has a mismatched speed (likely 100 Mbps) compared to the other member link (1000 Mbps). LACP requires all member ports to have identical speed and duplex. The solution is to set the speed on Gi0/2 to 1000 and duplex to full.

After correction, the port will bundle, and the port-channel will come up. Verification with 'show etherchannel summary' should show both ports as 'P' (bundled) and the port-channel as 'SU' (in use, Layer2).

Exam trap

Do not confuse LACP modes (active/passive) with PAgP modes (desirable/auto). Also, remember that physical parameters like speed and duplex must match across all member ports; logical configurations like VLAN or trunking are separate but must also be consistent. Always verify the root cause before changing unrelated settings.

Why the other options are wrong

B

The specific factual error is that 'desirable' is a PAgP mode, not LACP. LACP uses 'active' and 'passive' modes.

C

The specific factual error is that the problem is physical (speed mismatch), not logical (VLAN/trunking). Changing the port type does not address the root cause.

D

The specific factual error is that the speed mismatch is the root cause, not the LACP mode. Even with correct modes, the EtherChannel will not form if speeds differ.

Why candidates pick the wrong answer

B

Candidates may confuse PAgP and LACP modes, especially since 'desirable' is a common PAgP mode that initiates negotiation, similar to LACP 'active'.

C

Candidates might think that VLAN mismatches or trunking issues are common EtherChannel problems, but in this scenario, the speed mismatch is the explicit issue.

D

Candidates may think that LACP mode negotiation is the issue, especially if they recall that both sides need to be in active or one active and one passive. However, the speed mismatch overrides this.

369
MCQmedium

A two-switch EtherChannel bundle is configured with LACP. One side uses active mode on both member links, while the other side uses passive mode on both member links. What is the result?

A.The bundle forms successfully
B.The links remain individual because both sides must use active
C.The bundle forms only if PAgP is also enabled
D.The channel comes up but forwards only one VLAN
AnswerA

An LACP EtherChannel bundle forms successfully when at least one side is configured in active mode. In this scenario, the active-mode switch will proactively send LACP PDUs to initiate negotiation. The passive-mode switch, while not initiating, will listen for and respond to these incoming PDUs. This mutual exchange of LACP information satisfies the protocol's requirements for link aggregation, allowing the bundle to establish and operate correctly.

Why this answer

LACP forms a channel when at least one side actively sends negotiation frames. Active-to-passive works. Passive-to-passive would fail, but that is not the case here.

Exam trap

Ensure you know that LACP only needs one side in active mode to form a channel; both sides in passive mode would fail.

Why the other options are wrong

B

LACP does not require both sides to be in active mode; active/passive is a valid combination. The passive side will respond to LACP packets from the active side, forming the bundle.

C

PAgP is a Cisco proprietary protocol and is not required for LACP. LACP and PAgP are independent; enabling PAgP does not affect LACP negotiation.

D

EtherChannel, once formed, forwards all VLANs allowed on the trunk or access ports. There is no mechanism in LACP that restricts the bundle to a single VLAN.

When would these options actually be correct?

B

In a different scenario where a question specifies that both switches must be configured in active mode for LACP to function, this option would be correct. For example, if the question stated that both ends must use active mode for a successful EtherChannel formation, then this option would apply.

C

In a different scenario where the question specifies that both switches are configured with PAgP and the exam asks about compatibility with LACP, this option would be correct. If the question states that PAgP must be enabled for any channel to form, then this option would apply.

D

This option would be correct in a scenario where a switch is configured to use a static EtherChannel without LACP, and only one VLAN is allowed due to misconfiguration or limitations in the switch's capabilities, causing it to forward traffic for only that VLAN.

Why candidates pick the wrong answer

B

Students often confuse LACP modes with PAgP modes, where PAgP requires at least one side to be in desirable mode. They may incorrectly assume both sides must be active for LACP.

C

Test-takers may think that both protocols must be enabled for compatibility, but LACP and PAgP are separate and cannot be mixed on the same bundle.

D

This distractor plays on confusion with VLAN filtering or the concept of 'one VLAN' from other features like VTP pruning or port security, but it is not related to EtherChannel formation.

370
Matchingmedium

Match each security concept to its most accurate purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Verifies identity before access is granted

Determines permitted actions after identity is verified

Records activity or session information

Protects information from unauthorized disclosure

Why these pairings

These pairings correctly define core security concepts (CIA triad plus authentication and authorization).

Exam trap

Be careful not to confuse the terms within the CIA triad or between CIA and AAA. Remember: Confidentiality = privacy, Integrity = no unauthorized changes, Availability = uptime/access. AAA: Authentication = who you are, Authorization = what you can do, Accounting = what you did.

371
PBQhard

You are connected to R1. Configure PAT (NAT overload) so that hosts on the 192.168.1.0/24 LAN can access the Internet via the outside interface GigabitEthernet 0/1 with IP 203.0.113.2/29. The current configuration has an incorrect inside/outside interface assignment and a missing overload keyword. Fix all issues.

Network Topology
G0/0192.168.1.1/24G0/1203.0.113.2/29HostsLANR1ISPInternet

Hints

  • •Check which interfaces are marked 'inside' and 'outside'.
  • •The PAT command must include the 'overload' keyword.
  • •The ACL must match the correct source subnet (192.168.1.0/24).
A.Configure 'ip nat inside' on GigabitEthernet0/0, 'ip nat outside' on GigabitEthernet0/1, correct ACL 10 to permit 192.168.1.0 0.0.0.255, and add 'overload' to the PAT command.
B.Configure 'ip nat outside' on GigabitEthernet0/0, 'ip nat inside' on GigabitEthernet0/1, keep ACL 10 as is, and add 'overload' to the PAT command.
C.Configure 'ip nat inside' on GigabitEthernet0/1, 'ip nat outside' on GigabitEthernet0/0, correct ACL 10 to permit 192.168.1.0 0.0.0.255, and add 'overload' to the PAT command.
D.Configure 'ip nat inside' on GigabitEthernet0/0, 'ip nat outside' on GigabitEthernet0/1, correct ACL 10 to permit 192.168.1.0 0.0.0.255, but do not add 'overload' to the PAT command.
AnswerA
solution
! R1
interface GigabitEthernet0/0
ip nat inside
interface GigabitEthernet0/1
ip nat outside
ip nat inside source list 10 interface GigabitEthernet0/1 overload
access-list 10 permit 192.168.1.0 0.0.0.255

Why this answer

Three issues exist: (1) The inside and outside interfaces are swapped — GigabitEthernet0/0 (LAN) should be 'ip nat inside' and GigabitEthernet0/1 (WAN) should be 'ip nat outside'. (2) The PAT command lacks the 'overload' keyword. (3) ACL 10 permits 10.0.0.0/8 but the inside subnet is 192.168.1.0/24; ACL must be corrected. Fix with 'interface GigabitEthernet0/0', 'ip nat inside', 'interface GigabitEthernet0/1', 'ip nat outside', 'ip nat inside source list 10 interface GigabitEthernet0/1 overload', and 'access-list 10 permit 192.168.1.0 0.0.0.255'.

Exam trap

A common trap is confusing which interface should be inside and which should be outside. Remember: inside is the private LAN side, outside is the public WAN side. Also, do not forget the 'overload' keyword for PAT, and ensure the ACL matches the correct source subnet.

Why the other options are wrong

B

The specific factual error: The inside/outside interface assignment is reversed; ACL 10 permits 10.0.0.0/8 instead of 192.168.1.0/24.

C

The specific factual error: The inside/outside interface assignment is reversed; the WAN interface should be outside, not inside.

D

The specific factual error: The 'overload' keyword is missing, which is required for PAT to enable many-to-one translation.

Why candidates pick the wrong answer

B

Candidates pick this because they might think the outside interface is the LAN side, or they overlook the ACL issue.

C

Candidates pick this because they might confuse which interface is inside and which is outside, or they think the 'inside' keyword refers to the internal network of the router.

D

Candidates pick this because they might think that NAT overload is enabled by default or that the 'overload' keyword is optional for PAT.

372
MCQmedium

A switch receives a unicast frame for a destination MAC address that is not yet in its MAC address table. What does the switch do?

A.Drops the frame immediately
B.Floods the frame out all ports in the same VLAN except the incoming port
C.Sends the frame to the default gateway first
D.Converts the frame to a broadcast packet
AnswerB

When a switch receives a unicast frame whose destination MAC address is absent from its MAC address table (or has aged out), it treats the frame as an unknown unicast. Standard transparent bridging behavior is to flood the frame out every port that is a member of the same VLAN as the incoming port, but not the incoming port itself. This maximizes the chance that the intended recipient, which may be on any segment in that broadcast domain, receives the frame without any Layer 3 routing or address rewriting.

Why this answer

An unknown unicast frame is flooded within the VLAN because the switch does not yet know which port leads to the destination MAC. The frame is not sent back out the receiving port.

Exam trap

Do not confuse switch flooding behavior for unknown unicast frames with dropping or routing behaviors.

Why the other options are wrong

A

Switches are designed to forward unknown unicast frames by flooding, not dropping them. Dropping would occur only if the frame is malformed or security features like port security are violated.

C

A Layer 2 switch operates at the data link layer and does not involve the default gateway for forwarding decisions. The default gateway is used for routing between VLANs or subnets, not for unknown unicast flooding within a VLAN.

D

Switches flood the original unicast frame unchanged; they do not modify the frame type to broadcast. Broadcasting would change the destination MAC to FF:FF:FF:FF:FF:FF, which is not the case for unknown unicast flooding.

When would these options actually be correct?

A

In a scenario where a switch is configured to drop all unicast frames for security reasons, such as in a highly restrictive network policy exam question, this option could be correct. For example, if the question specifies that the switch is in a security mode that prohibits unknown unicast traffic, dropping the frame would be the expected behavior.

C

In a scenario where a question asks about the behavior of a Layer 3 device, such as a router, when it receives a packet destined for an unknown IP address, the correct answer could involve sending the packet to the default gateway for further processing. This would clarify the role of the default gateway in routing decisions.

D

If the question asked about a network device that explicitly converts unicast frames to broadcast for specific purposes, such as a network appliance designed to propagate certain types of traffic, then this option could be correct. For example, a device configured to broadcast certain control messages might convert unicast frames accordingly.

Why candidates pick the wrong answer

A

Students might think that if a switch doesn't know the destination, it should discard the frame to avoid unnecessary traffic, but this is incorrect because flooding ensures delivery.

C

Students may confuse the switch's behavior with that of a host or router, where unknown destinations are sent to the default gateway. However, switches flood unknown unicasts within the VLAN.

D

The term 'flood' might be misinterpreted as 'broadcast', but flooding means sending the frame out all ports except the incoming port while preserving the original unicast destination MAC.

373
MCQhard

A subnet uses the prefix /22. How many usable host addresses are available?

A.254
B.510
C.1022
D.2046
AnswerC

A /22 prefix designates 22 network bits, leaving 10 bits for the host portion of the IPv4 address. This configuration provides 2^10, or 1024, total addresses within the subnet. However, two addresses are always reserved: one for the network address and one for the broadcast address. Subtracting these two reserved addresses from the total yields 1022 usable host addresses, directly satisfying the /22 prefix constraint specified in the question stem.

Why this answer

A /22 leaves 10 host bits available. In plain language, that means each subnet contains 2^10, or 1024, total addresses. Two of those are reserved for the network and broadcast addresses in normal IPv4 subnetting, leaving 1022 usable host addresses.

This is a common subnet-capacity calculation. The safest method is to calculate the total address count from the number of host bits and then subtract the two reserved addresses. That leads directly to the correct usable-host value.

Exam trap

Remember to subtract the network and broadcast addresses from the total number of addresses to find the usable host count.

Why the other options are wrong

A

A /24 prefix provides 256 total addresses (2^(32-24)=256), with 254 usable host addresses after subtracting the network and broadcast addresses. This does not match the /22 prefix in the question.

B

A /23 prefix provides 512 total addresses (2^(32-23)=512), with 510 usable host addresses. This is half the total addresses of a /22, so it is incorrect for the given prefix.

D

A /21 prefix provides 2048 total addresses (2^(32-21)=2048), with 2046 usable host addresses. This is double the total addresses of a /22, so it is incorrect for the given prefix.

When would these options actually be correct?

A

If the question specified a /24 subnet instead of /22, the correct calculation would yield 256 total addresses, and after excluding the network and broadcast addresses, there would be 254 usable addresses. Thus, option A would be correct.

B

If the question specified a subnet mask of /23 instead of /22, then the calculation would yield 2^(32-23) = 512 total IP addresses, and after subtracting 2 for the network and broadcast addresses, the usable addresses would be 510.

D

If the question specified a /11 subnet instead of /22, the calculation would yield 2^(32-11) = 2048 total addresses, resulting in 2046 usable addresses after accounting for the network and broadcast addresses. In this case, option D would be correct.

Why candidates pick the wrong answer

A

Students often confuse /24 with /22 because /24 is a very common subnet size, and they may incorrectly apply the 254 usable host count without calculating the correct number of bits.

B

Some students might mistakenly think that a /22 has 510 usable hosts because they confuse it with a /23, or they may incorrectly calculate the number of host bits.

D

Students may mistakenly think that a /22 has 2046 usable hosts because they confuse it with a /21, or they may incorrectly add instead of subtract when calculating host bits.

374
MCQhard

A network administrator is troubleshooting slow file transfers between two servers in different access-layer switches. The administrator runs the 'show interface' command on the uplink connecting the two switches and notices a high number of CRC errors on both ends, but a high number of late collisions on only one interface; the other interface reports no late collisions.

A.Duplex mismatch: the interface with late collisions is half-duplex while the other end is full-duplex. Configure both ends to auto-negotiate speed and duplex.
B.Speed mismatch: one interface is set to 100 Mbps, the other to 1 Gbps. This causes frequent link flaps, resulting in CRC errors. Use the 'speed' command to match the rates.
C.Faulty Ethernet cable causing signal degradation, which leads to CRC errors. The late collisions are a result of the switch misdetecting collisions due to the degraded signal. Replace the cable.
D.A broadcast storm caused by a loop is flooding the uplink with frames, leading to CRC errors and late collisions as the switch discards excess traffic. Enable Spanning Tree Protocol to block the redundant path.
AnswerA

Late collisions only occur on half-duplex Ethernet when multiple stations attempt to transmit simultaneously. When one end is full-duplex, the half-duplex end perceives any overlapping transmission as a collision, producing late collisions and CRC errors. Auto-negotiation correctly sets both ends to full-duplex when supported, fixing the problem.

Why this answer

A is correct because a duplex mismatch causes one interface to operate in half-duplex (detecting late collisions due to CSMA/CD) while the other operates in full-duplex (no collisions). The half-duplex interface waits for the carrier sense before transmitting, but the full-duplex interface transmits immediately, causing the half-duplex side to detect collisions after the transmission window (late collisions). CRC errors occur on both ends because frames are corrupted when collisions happen.

Configuring both ends to auto-negotiate ensures matching duplex and speed, resolving the issue.

Exam trap

Cisco often tests the distinction between CRC errors (which can have multiple causes like cable faults or duplex mismatch) and late collisions (which are a definitive indicator of a duplex mismatch), leading candidates to incorrectly attribute CRC errors alone to a cable issue.

Why the other options are wrong

B

Confuses speed mismatch (which prevents link establishment) with duplex mismatch (which allows the link to come up but causes errors and late collisions).

C

Assumes all interface errors are cable-related and overlooks the characteristic late-collision signature of duplex mismatch.

D

Misinterprets high utilization as a source of physical-layer errors and ignores the diagnostic value of asymmetric late collisions.

375
Multi-Selectmedium

Which two statements accurately describe why least privilege and source restriction work well together for administrative access?

Select 2 answers
A.Least privilege reduces the scope of actions an authenticated user can perform.
B.Source restriction reduces the network locations from which administrative access is permitted.
C.Either one by itself removes the need for logging.
D.Both exist only for wireless guest access policies.
E.They require all administrative traffic to use PPP encapsulation.
AnswersA, B

Least privilege ensures that an authenticated administrator can only execute the specific commands and configuration changes required for their job role. By limiting authorization to a minimal set of actions, it reduces the potential impact of mistakes, compromised credentials, or insider misuse, and enforces separation of duties. This is a core principle of Role-Based Access Control (RBAC).

Why this answer

Least privilege and source restriction work well together because they reduce risk in different ways. In practical terms, least privilege limits what a user can do after access is granted, while source restriction reduces where an administrative session is even allowed to originate. Together they reduce both exposure and potential impact.

This is a layered management-security concept and a strong exam-style reasoning item.

Exam trap

A common exam trap is believing that either least privilege or source restriction alone fully secures administrative access. Candidates may incorrectly think that limiting user permissions removes the need to restrict source IPs, or vice versa. This mistake overlooks that least privilege controls what actions a user can perform after access, but does not prevent unauthorized access attempts from untrusted locations.

Similarly, source restriction limits where access can originate but does not limit what an authenticated user can do. The exam tests understanding that both controls are necessary and complementary for robust administrative security.

Why the other options are wrong

C

This option is incorrect because neither least privilege nor source restriction eliminates the need for logging; visibility and accountability remain critical for security auditing.

D

This option is incorrect because least privilege and source restriction are broad security principles applicable to all administrative access, not limited to wireless guest access policies.

E

This option is incorrect because PPP encapsulation is unrelated to administrative access controls like least privilege and source restriction; it does not affect management access security.

When would these options actually be correct?

C

In a different exam scenario focused on the benefits of implementing security measures in a low-risk environment, a question might state that certain security practices can minimize the need for logging due to reduced risk exposure. In this context, the statement could be interpreted as correct.

D

If the exam question specifically asked about access control measures that only apply to wireless guest networks, then this option could be correct. For instance, a question might focus on security policies that limit guest access to a network, making this statement relevant.

E

In a question specifically about network protocols, if it asked which encapsulation method is required for secure administrative traffic in a legacy system, PPP encapsulation could be the correct answer due to its historical use in point-to-point connections.

Why candidates pick the wrong answer

C

A test-taker might think that if access is tightly controlled, logging becomes redundant, but in reality, logging provides visibility into any actions taken, including those by authorized users.

D

Students may associate source restriction with guest networks because guest access often uses source-based ACLs, but this is a narrow view; these principles are universal.

E

Students might confuse PPP with other security mechanisms like PAP/CHAP authentication, which can be used for access control, but PPP itself does not enforce least privilege or source restriction.

Page 4

Page 5 of 20

Page 6