Courseiva

CCNA 200-301 v2 (200-301) — Questions 376–450

1450 questions total · 20pages · All types, answers revealed

Page 5

Page 6 of 20

Page 7
376
Drag & Dropmedium

Drag and drop the following steps into the correct order to describe the data encapsulation process as it flows down the OSI model from the source host.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Encapsulation proceeds from the top OSI layers to the bottom. First, the application generates data (Step 1). The Transport layer then adds a header (TCP or UDP) to create a segment (Step 2) because this is the first step in preparing data for reliable delivery.

The Network layer adds an IP header to form a packet (Step 3), which provides logical addressing and routing information. The Data Link layer adds a frame header and trailer to create a frame (Step 4), enabling physical addressing (MAC) and error detection. Finally, the Physical layer converts the frame to bits for transmission (Step 5), as it is the layer that ultimately puts signals on the wire.

377
Multi-Selectmedium

Which three of the following are correct statements about VLAN configuration and verification on a Cisco switch? (Choose three.)

Select 3 answers
.The 'switchport mode access' command places the interface into a non-trunking mode.
.By default, all ports on a Cisco switch are in VLAN 1.
.The 'show vlan brief' command displays VLANs that are active on the switch.
.VLANs 1002–1005 are reserved for user-created VLANs.
.A VLAN must be manually created before its name can be assigned.
.The 'switchport trunk native vlan' command restricts the native VLAN to only tagged frames.

Why this answer

The correct statements are: (1) The 'switchport mode access' command places the interface into a non-trunking mode; (2) By default, all ports on a Cisco switch are in VLAN 1; (3) The 'show vlan brief' command displays VLANs that are active on the switch. The remaining statements are false because: VLANs 1002–1005 are reserved for legacy FDDI/Token Ring VLANs, not for user-created VLANs; a VLAN does not need to be manually created before its name can be assigned (assigning a port to a new VLAN can automatically create it, after which you can set its name); and the 'switchport trunk native vlan' command does not restrict the native VLAN to only tagged frames—native VLAN traffic is sent untagged.

Exam trap

Candidates often confuse the native VLAN as carrying tagged frames, and mistakenly believe VLANs 1002–1005 are user-configurable, when in fact they are reserved for legacy technologies.

Why the other options are wrong

D

VLANs 1002–1005 are reserved for legacy FDDI and Token Ring, not user-created VLANs.

F

The native VLAN on a trunk sends frames untagged; this command sets the native VLAN, not a tagging restriction.

378
Multi-Selectmedium

Which two statements accurately describe IPv6 link-local addresses?

Select 2 answers
A.They are used for communication on the local segment only.
B.They are globally routable across the Internet.
C.They are commonly involved in local IPv6 neighbor interactions.
D.They exist only when DHCPv6 fails.
E.They replace the need for any default gateway logic.
AnswersA, C

Link-local addresses, identified by the FE80::/10 prefix, are automatically configured on every IPv6 interface and are valid only within the local network segment. A router will never forward a packet with a link-local source or destination address, so traffic using these addresses stays entirely on the local link, making this statement accurate for local-only communication.

Why this answer

IPv6 link-local addresses are designed for communication on the local segment only. In plain language, they allow devices to talk to nearby neighbors without needing globally routable addresses. They play an important role in IPv6 functions such as Neighbor Discovery and are commonly used when hosts communicate with the default gateway on the same link. These addresses are normal and expected in IPv6 environments.

They are not globally Internet-routable, and they are not just emergency fallbacks for DHCPv6 failure. The two correct answers are the ones that preserve their local-link purpose and their importance in standard IPv6 behavior rather than treating them as optional or globally reachable.

Exam trap

Remember that link-local addresses are not routable and are not a fallback for DHCPv6. They are essential for local communications.

Why the other options are wrong

B

Link-local addresses have a scope of link-local (fe80::/10) and are not forwarded by routers, making them non-routable across the Internet. They are intended only for communication on a single network segment.

D

Link-local addresses are automatically generated on all IPv6 interfaces regardless of DHCPv6. They are a mandatory part of IPv6 operation, not a fallback mechanism.

E

For off-link communication, IPv6 hosts still require a default gateway (usually a router's link-local address) to forward packets beyond the local segment. Link-local addresses do not eliminate the need for routing logic.

When would these options actually be correct?

B

If the exam question asked about the characteristics of global unicast addresses or the general routing capabilities of IPv6 addresses, then option B would be correct, as global unicast addresses are indeed routable across the Internet.

D

In a question that asks about the conditions under which IPv6 link-local addresses are assigned, if it specifies that they are only assigned when DHCPv6 is not available, then option D would be correct. For example, 'What happens to IPv6 link-local address assignment when DHCPv6 is not configured?'

E

If the exam question asked about the role of link-local addresses in a network where no routers exist and all devices communicate directly without a gateway, this option could be correct, as link-local addresses would be sufficient for local communication.

Why candidates pick the wrong answer

B

Students may confuse link-local addresses with global unicast addresses, which are globally routable. The term 'address' might imply routability, but the 'link-local' scope explicitly restricts it.

D

Students might think link-local addresses are similar to Automatic Private IP Addressing (APIPA) in IPv4, which is used when DHCP fails. However, IPv6 link-local addresses are always present and not dependent on DHCP.

E

Since link-local addresses are used for neighbor discovery and local communication, some might incorrectly assume they handle all routing needs. However, routing to other networks still requires a gateway.

379
MCQmedium

Why might voice traffic be placed in a priority queue on a WAN link?

A.To increase the TTL value of voice packets
B.To reduce delay and jitter for time-sensitive traffic
C.To change RTP into TCP for reliability
D.To avoid assigning IP addresses to phones
AnswerB

Voice traffic consists of real-time RTP/UDP packets that are extremely sensitive to network latency and jitter. A priority queue on a WAN ensures that these voice packets are forwarded before packets in lower-priority queues, minimizing queuing delay and smoothing inter-packet timing. This is essential because excessive delay makes conversations unintelligible, and jitter causes choppy audio that the playout buffer cannot fully compensate for.

Why this answer

Voice traffic is delay-sensitive. Prioritization helps reduce queuing delay and jitter so real-time audio remains intelligible.

Exam trap

A common exam trap is selecting answers that confuse QoS prioritization with unrelated network functions such as increasing the TTL value of voice packets or converting RTP traffic into TCP. These options are incorrect because QoS focuses on managing packet scheduling and queuing rather than altering packet headers or transport protocols. Another trap is thinking that IP address assignment relates to QoS, which it does not.

Recognizing that priority queuing specifically targets delay-sensitive traffic like voice helps avoid these misleading options.

Why the other options are wrong

A

Increasing the TTL value of voice packets is unrelated to QoS or priority queuing. TTL controls packet lifetime and does not affect delay or jitter, so this option is incorrect.

C

QoS does not convert RTP (used for voice) into TCP. RTP is typically carried over UDP for real-time performance, so this option is incorrect.

D

Assigning IP addresses to phones is handled by DHCP or static configuration, not by QoS or priority queuing. This option is unrelated to voice traffic prioritization.

When would these options actually be correct?

A

In a different question asking about methods to manage packet lifetimes in a network, increasing the TTL value could be correct if the context involves ensuring packets can traverse more hops without being dropped, especially in a large network with many routers.

C

If the exam question asked about a scenario where voice traffic needs to be transmitted reliably over a network that only supports TCP, then the option could be correct. For example, a question could state that a specific application requires voice data to be sent over TCP due to network constraints, making this conversion necessary.

D

In a question asking about network management strategies for VoIP systems, where the focus is on minimizing administrative overhead, this option could be correct if it discusses the avoidance of DHCP for IP address assignment to simplify network configuration.

Why candidates pick the wrong answer

A

Students might confuse TTL with QoS mechanisms because both involve packet handling, but TTL is a layer 3 hop-count mechanism, not a queuing or priority tool.

C

Test-takers may think that reliability (TCP) is always better, but for real-time voice, UDP's lower overhead is preferred, and QoS prioritization is used instead of protocol conversion.

D

Students might associate voice traffic with IP phones and mistakenly think queuing is related to IP address management, but these are separate network functions.

380
MCQhard

A network engineer is configuring a floating static route on a Cisco router to provide backup connectivity to a remote network 172.16.0.0/16. The primary route is learned via OSPF. The engineer wants the static route to be used only if the OSPF route is lost. Which command should be used?

A.ip route 172.16.0.0 255.255.0.0 192.168.1.2 200
B.ip route 172.16.0.0 255.255.0.0 192.168.1.2 110
C.ip route 172.16.0.0 255.255.0.0 192.168.1.2 255
D.ip route 172.16.0.0 255.255.0.0 192.168.1.2 90
AnswerA

A distance of 200 is higher than OSPF's 110, so the static route will not be installed in the routing table as long as the OSPF route exists. If the OSPF route is lost, the static route becomes the best available and is installed. This is the definition of a floating static route, providing backup connectivity.

Why this answer

A floating static route is a static route with a higher administrative distance than the primary route, so it remains inactive until the primary route is lost. For OSPF with a default distance of 110, the static route must have a distance greater than 110, such as 200. When the OSPF route disappears, the static route is installed and used.

Exam trap

The trap here is setting the administrative distance equal to or lower than the primary route, which would either cause load balancing or make the static route primary, defeating its purpose as a backup.

381
MCQmedium

Why does a passive interface in OSPF still matter even though it does not send hello packets?

A.The connected network can still be advertised into OSPF through other active adjacencies
B.The passive interface automatically becomes the OSPF router ID
C.The passive interface disables all OSPF operation on the router
D.The passive interface converts OSPF into EIGRP on that link
AnswerA

Even when an interface is configured as passive for OSPF, the router still includes that interface's connected subnet in OSPF advertisements, provided the interface is covered by a network statement or under the OSPF process. Passive-interface only disables hello transmission and neighbor discovery on that link, so the prefix is still injected into the LSDB and propagated via active adjacencies on other interfaces.

Why this answer

A passive interface still matters because the connected network can still be advertised into OSPF even though the interface itself does not form neighbor relationships. In plain language, the router is saying, “This network is mine, and I want others to know about it, but I do not want to speak OSPF directly on this interface.” That is useful on user-facing or stub-like interfaces where no OSPF neighbor should exist.

This distinction is important because some engineers assume passive means “ignored entirely.” It does not. The connected network can still appear in routing updates sent through real neighbors on other interfaces. What changes is neighbor formation on the passive interface itself.

Exam trap

Don't assume 'passive' means the interface is ignored; it still advertises its network.

Why the other options are wrong

B

The OSPF router ID is determined by the highest IP address on a loopback interface or the highest active physical interface IP at the time of OSPF process startup, not by passive-interface configuration. A passive interface does not influence router ID selection.

C

The passive-interface command only suppresses OSPF hello packets on that specific interface; OSPF continues to operate normally on other interfaces, forming adjacencies and exchanging routing information. It does not disable OSPF globally.

D

The passive-interface command is specific to OSPF and does not change the routing protocol. OSPF remains OSPF; it simply stops sending hellos on that interface. EIGRP has its own passive-interface command with similar behavior but does not convert protocols.

When would these options actually be correct?

B

In a different context, if a question asked about how OSPF selects a router ID and included a scenario where a passive interface was the only interface on the router, then this option could be correct as it would imply that the passive interface is the only available IP address for the router ID.

C

In a different exam question asking about the effects of configuring an interface as passive in OSPF, if the question stated that the passive interface would stop all OSPF processes on the router, then this option could be correct if the context was about a misconfigured router where all interfaces were set to passive.

D

In a different question, if it asked about a scenario where a routing protocol can be changed or configured to operate differently on a specific interface, one might mistakenly think that a command could convert OSPF to EIGRP, leading to this option being perceived as correct.

Why candidates pick the wrong answer

B

Students might confuse the passive behavior (no hello packets) with the router ID election process, thinking that a passive interface, being 'inactive' in terms of hello exchange, could be used as a stable identifier. However, router ID is independent of hello suppression.

C

The term 'passive' might imply that the interface is completely inactive in OSPF, leading students to think OSPF is disabled on the entire router. In reality, only hello exchange is stopped on that interface.

D

Students might think that because the interface stops sending OSPF hellos, it might switch to another protocol like EIGRP. However, passive-interface only affects hello behavior and does not alter the routing protocol itself.

382
Multi-Selectmedium

Which TWO actions does DHCP snooping perform by default on a Cisco switch?

Select 2 answers
A.It blocks DHCP server messages received on untrusted ports.
B.It generates a Cisco Discovery Protocol packet for each DHCP request.
C.It builds a DHCP binding table.
D.It relays DHCP requests across VLANs.
E.It converts DHCP broadcasts into unicasts.
AnswersA, C

DHCP snooping marks each switch port as either trusted or untrusted. Ports connected to legitimate DHCP servers are configured as trusted, while all other ports are untrusted. When a DHCP server message such as DHCPOFFER, DHCPACK, or DHCPNAK arrives on an untrusted port, the switch drops it, preventing a rogue device from issuing fraudulent IP configuration to clients. This enforcement is the core security function of DHCP snooping.

Why this answer

DHCP snooping is a security feature that, by default, filters DHCP server messages (such as DHCPOFFER, DHCPACK, and DHCPNAK) received on untrusted ports. This prevents rogue DHCP servers from offering malicious IP configurations to clients. The switch also automatically builds and maintains a DHCP snooping binding table, which maps client MAC addresses to leased IP addresses, VLANs, and port information, to validate DHCP traffic.

Exam trap

Cisco often tests the distinction between DHCP snooping's default actions (filtering on untrusted ports and building the binding table) and optional features like DHCP relay or broadcast-to-unicast conversion, which are not part of DHCP snooping itself.

Why the other options are wrong

B

This statement incorrectly associates two separate features; DHCP snooping operates at Layer 2 for DHCP security, not for CDP.

D

This function belongs to the relay agent, not to DHCP snooping, which operates within a single VLAN to enforce security policies.

E

This is a relay agent feature; DHCP snooping does not alter the broadcast nature of DHCP packets, it only filters them.

383
MCQmedium

When spanning tree elects a root bridge, which value is considered first?

A.Lowest MAC address only
B.Lowest bridge priority only
C.Lowest bridge ID, which begins with priority
D.Highest interface bandwidth
AnswerC

In STP, the root bridge is elected by comparing the 8-byte bridge ID (BID), which is formed by a 2-byte priority value followed by the 6-byte MAC address. The lowest BID wins, and because priority occupies the most significant bytes, a switch with a lower priority always beats a switch with a higher priority. Only when priorities are identical does the MAC address become the tiebreaker within the same BID comparison. Thus the actual election value is the full bridge ID, beginning with priority.

Why this answer

The root bridge is the switch with the lowest bridge ID. The bridge ID is made up of priority and MAC address, so priority is considered first, then MAC address if priorities tie.

Exam trap

Remember that the bridge priority is evaluated before the MAC address in the root bridge election process.

Why the other options are wrong

A

The MAC address is only used as a tiebreaker when bridge priorities are equal. It is not the first value considered in root bridge election.

B

The bridge priority is only the first part of the bridge ID; the full bridge ID (priority + MAC address) is compared. If priorities are equal, the MAC address is used as a tiebreaker.

D

Interface bandwidth is used to calculate path cost, which influences port roles (root port, designated port) but does not affect root bridge election. Root bridge election is based solely on bridge ID.

When would these options actually be correct?

A

In a different question that asks specifically about the criteria for selecting a root bridge when multiple bridges have the same priority, the lowest MAC address would be the deciding factor. For example, if the question specifies that all bridges have the same priority, then the lowest MAC address would be the correct answer.

B

In a different question that asks specifically for the criteria used to determine the root bridge when only considering priority values, option B could be correct if the question states that all bridges have the same MAC address, thus making the lowest bridge priority the deciding factor.

D

In a different question that asks about factors influencing network performance or path selection in a Layer 2 network, the highest interface bandwidth could be relevant. For example, a question might ask which attribute affects the best path selection for data traffic in a network topology.

Why candidates pick the wrong answer

A

Students may confuse the role of MAC address in bridge ID with it being the primary criterion, especially since MAC addresses are unique and often used in other networking decisions.

B

It is tempting because priority is the most significant field in the bridge ID, leading some to think it alone determines the root bridge, but the MAC address is also part of the comparison.

D

Students may think higher bandwidth is better and assume it influences root bridge selection, confusing path cost metrics with the bridge ID comparison.

384
PBQmedium

You are connected to SW1 via the console. SW1 is a Layer 2 switch. Ports G0/1 and G0/2 are connected to two PCs that should be in VLAN 10 (Sales). Port G0/3 is a trunk link to another switch. The PCs are currently unable to communicate because the ports are in VLAN 1. Configure the switch to place the ports in the correct VLAN and ensure the trunk is properly configured with 802.1Q encapsulation and native VLAN 99.

Network Topology
trunkPC1SW1 G0/1SW1 G0/2OtherSwitch

Hints

  • •Check the current VLAN assignment on access ports.
  • •The trunk encapsulation must be set to dot1q for 802.1Q support.
  • •Native VLAN should match on both ends of the trunk.
A.Create VLAN 10, assign G0/1 and G0/2 as access ports in VLAN 10, configure G0/3 as trunk with encapsulation dot1q and native VLAN 99.
B.Create VLAN 10, assign G0/1 and G0/2 as access ports in VLAN 10, configure G0/3 as trunk with encapsulation isl and native VLAN 99.
C.Create VLAN 10, assign G0/1 and G0/2 as trunk ports in VLAN 10, configure G0/3 as trunk with encapsulation dot1q and native VLAN 99.
D.Create VLAN 10, assign G0/1 and G0/2 as access ports in VLAN 10, configure G0/3 as trunk with encapsulation dot1q and native VLAN 1.
AnswerA
solution
! SW1
interface GigabitEthernet0/1
switchport access vlan 10
interface GigabitEthernet0/2
switchport access vlan 10
interface GigabitEthernet0/3
switchport trunk encapsulation dot1q
switchport trunk native vlan 99

Why this answer

Option A is correct because it creates VLAN 10, assigns the access ports G0/1 and G0/2 to VLAN 10, and configures G0/3 as a trunk with 802.1Q encapsulation and native VLAN 99. This matches the requirements: PCs in VLAN 10, trunk using dot1q (the standard for Cisco switches), and native VLAN 99. The commands would be: vlan 10, interface range g0/1-2, switchport mode access, switchport access vlan 10; interface g0/3, switchport trunk encapsulation dot1q, switchport mode trunk, switchport trunk native vlan 99.

Exam trap

The trap is selecting ISL encapsulation (deprecated) or forgetting to set the native VLAN correctly. Candidates may also confuse access and trunk port configurations, especially when the question asks for both.

Why the other options are wrong

B

The specific factual error is that ISL is a legacy Cisco proprietary trunking protocol, and modern switches default to 802.1Q. The question specifies 802.1Q encapsulation.

C

The specific factual error is that ports connected to end devices (PCs) should be access ports, not trunk ports. Trunk ports are used for inter-switch links.

D

The specific factual error is that the native VLAN must be explicitly set to 99. Native VLAN 1 is the default and is often targeted in VLAN hopping attacks.

Why candidates pick the wrong answer

B

Candidates might pick this because they remember ISL as a trunking protocol and think it is still widely used, or they confuse it with 802.1Q.

C

Candidates might pick this because they think trunk ports can be used for any connection, or they confuse the concept of trunking with VLAN assignment.

D

Candidates might pick this because they know native VLAN 1 is the default and think it is acceptable, or they forget to change it as per the requirement.

385
PBQhard

You are troubleshooting PAT and static NAT on R1. The inside network 192.168.10.0/24 must be translated to the public IP 203.0.113.1 (interface G0/1) using port address translation. Additionally, the server at 192.168.10.100 must be reachable from the outside via static NAT to 203.0.113.5. The current configuration is not working. Identify and correct the errors in the running config on R1.

Hints

  • •Check which subnet the ACL is matching — it might not be your inside network.
  • •Look at the PAT command: is there an 'overload' keyword? Without it, only one translation is allowed.
  • •Verify the static NAT mapping: the inside server IP should match the actual server.
A.The ACL in the NAT configuration incorrectly permits network 192.168.20.0/24 instead of 192.168.10.0/24, and the PAT command is missing the 'overload' keyword.
B.The static NAT entry uses the wrong inside address; it should be 192.168.10.100 but is configured with 192.168.10.1.
C.The PAT command is missing the 'overload' keyword, and the static NAT entry maps to the wrong public IP; it should use 203.0.113.1 instead of 203.0.113.5.
D.The static NAT entry maps the server to the wrong public IP, 203.0.113.1 instead of 203.0.113.5, and the ACL incorrectly permits network 192.168.20.0/24.
AnswerA
solution
! R1
configure terminal
no access-list 100
access-list 100 permit ip 192.168.10.0 0.0.0.255 any
ip nat inside source list 100 interface GigabitEthernet0/1 overload
end
write memory

Why this answer

The running configuration has two errors. First, access-list 100 incorrectly permits the 192.168.20.0/24 network instead of the inside network 192.168.10.0/24, so PAT will not translate any internal hosts. Second, the PAT command is missing the 'overload' keyword, which means only a single translation is possible, breaking connectivity for multiple devices.

The static NAT entry for the server is correctly mapping 192.168.10.100 to 203.0.113.5 and does not need correction.

Exam trap

Watch out for ACLs that match the wrong subnet in NAT configurations. Also, remember that PAT requires the 'overload' keyword; without it, only one translation is allowed. Static NAT often uses a different public IP than the PAT pool to avoid conflicts.

Why the other options are wrong

B

The static NAT entry is correct; the inside address 192.168.10.100 is properly mapped to 203.0.113.5.

C

Static NAT requires a separate public IP to avoid overlapping with PAT translations. The public IP 203.0.113.5 is appropriate.

D

The static NAT entry is correctly configured with 192.168.10.100 and 203.0.113.5; the error is solely in the ACL and missing overload keyword.

Why candidates pick the wrong answer

B

Candidates might assume a typo in the static NAT because they focus on the server's IP, but the configuration is actually correct.

C

Candidates may think all translations must use the same public IP, but static NAT often uses a dedicated IP for inbound access.

D

Candidates might think all translations should share the same public IP for simplicity, but that would break inbound access to the server.

386
Multi-Selectmedium

Which two statements accurately describe DNS in everyday network use?

Select 2 answers
A.DNS helps resolve hostnames into IP-related information.
B.DNS makes services easier to use by allowing names instead of raw IP addresses.
C.DNS automatically assigns IP addresses to hosts.
D.DNS replaces the need for subnet masks.
E.DNS elects the STP root bridge.
AnswersA, B

DNS translates human-readable hostnames into IP-related records, including A, AAAA and CNAME entries, so clients can locate services without memorising addresses. This satisfies the stem's requirement that the statement reflect everyday resolution behaviour, where forward lookups from name to address underpin nearly all routine network communication.

Why this answer

Option A is correct because DNS is fundamentally a name-resolution service: a resolver queries name servers for records such as A (IPv4 address), AAAA (IPv6 address), CNAME (alias), and PTR (reverse lookup), returning IP-related information for a hostname. Option B is correct because this resolution lets users and applications reference friendly names like www.example.com instead of remembering raw IP addresses, which is the core usability benefit of DNS in everyday networking. The remaining options do not belong: IP address assignment is handled by DHCP (or static configuration), not DNS; subnet masks are part of IP addressing and routing and are unaffected by DNS; and STP root bridge election is a Layer 2 switching function determined by bridge ID (priority plus MAC address), entirely unrelated to DNS.

Exam trap

A frequent exam trap is mistaking DNS for DHCP or other network functions. Some candidates incorrectly believe DNS assigns IP addresses to hosts, but that role belongs to DHCP. Others confuse DNS with protocols like STP, which manages network topology but is unrelated to name resolution.

This confusion arises because both DNS and DHCP are IP services, but they serve distinct purposes. Misunderstanding these roles can lead to incorrect answers and misconfiguration in real networks. Remember, DNS only resolves hostnames into IP-related information and does not handle IP address assignment or network path selection.

Why the other options are wrong

C

Option C is incorrect because DNS does not assign IP addresses; that task belongs to DHCP, which dynamically provides IP configuration to hosts on a network.

D

Option D is incorrect because DNS does not replace subnet masks; subnet masks are used to define network and host portions of an IP address and control routing and addressing scope.

E

Option E is incorrect because DNS has no role in Spanning Tree Protocol (STP) operations, such as electing the root bridge; these functions are unrelated to DNS.

When would these options actually be correct?

C

In a question focused on the functionalities of a network protocol that combines DNS and DHCP, such as a scenario where a system automatically assigns IP addresses and resolves hostnames, this option could be correct. For example, a question might ask about a system that integrates both DNS and DHCP functionalities.

D

In a question asking about the roles of different networking protocols, if it specifically inquires about protocols that manage IP address assignments, then a statement about DNS replacing subnet masks could be correct if it were framed in a context where DNS is integrated with DHCP for dynamic address assignment.

E

In a question specifically focused on network protocols and their roles in managing network topology, a statement about DNS electing the STP root bridge could be correct if the question incorrectly conflates DNS functionality with network management tasks typically handled by STP.

Why candidates pick the wrong answer

C

Students often confuse DNS with DHCP because both are essential network services that involve IP addresses. The similarity in acronyms and their frequent co-occurrence in network setups can lead to the mistaken belief that DNS handles address assignment.

D

A test-taker might think that since DNS can return IP addresses, it could also return subnet masks, especially if they are aware of DNS records like SRV or TXT that can carry arbitrary data. However, standard DNS resolution does not include subnet mask information.

E

The acronyms DNS and STP might be confused by someone who is not fully familiar with networking protocols. Additionally, both protocols are fundamental to network operations, but their roles are distinct, and a student might incorrectly associate them due to their importance.

387
PBQhard

You are troubleshooting connectivity from R1 to the 172.16.20.0/24 network. The network engineer configured a floating static route on R1 as a backup for the OSPF-learned route, but after the primary OSPF route fails, the backup does not take over. Examine the current routing table and partial configuration on R1, then fix the issue so that when the OSPF neighbor goes down, R1 can still reach 172.16.20.0/24 via R3.

Network Topology
G0/010.0.0.1/30G0/010.0.0.2/30G0/1203.0.113.1/30G0/0203.0.113.2/30R2OSPFR1static backupR3

Hints

  • •Check if the next-hop address is reachable via a directly connected interface.
  • •A static route with a next-hop that is not directly connected requires a valid route to that next-hop.
  • •Configure the static route with an exit interface to make it directly connected.
A.Change the static route to use an exit interface: ip route 172.16.20.0 255.255.255.0 GigabitEthernet0/1 203.0.113.2
B.Change the administrative distance of the static route to 110
C.Remove the OSPF process from R1
D.Add a static route to 203.0.113.0/24 via R1's directly connected interface
AnswerA
solution
! R1
no ip route 172.16.20.0 255.255.255.0 203.0.113.2 130
ip route 172.16.20.0 255.255.255.0 GigabitEthernet0/1 203.0.113.2 130

Why this answer

The floating static route was configured with an administrative distance of 130, intended to be higher than OSPF's default AD of 110 so it would only be used as a backup. However, the static route's AD is set as 130 (the command uses the distance option), which is correct. The problem is that OSPF's AD is 110, which is lower, so the static route is not installed while OSPF is up.

But when OSPF fails, the static route should appear. The issue is that the static route is pointing to a next-hop (203.0.113.2) that is not directly connected; R1 has no route to 203.0.113.2, causing the static route to be inactive. To fix, you must either change the next-hop to a directly connected interface (e.g., GigabitEthernet0/1) or add a route to reach 203.0.113.2.

The simplest solution is to configure the static route with an exit interface: 'ip route 172.16.20.0 255.255.255.0 GigabitEthernet0/1 203.0.113.2'. This ensures the route is valid when the OSPF route disappears.

Exam trap

Trap: Candidates often focus on administrative distance values but forget that a static route must have a valid next-hop to be installed. Always verify that the next-hop is reachable (directly connected) or specify an exit interface for floating static routes.

Why the other options are wrong

B

The specific factual error is that a floating static route must have a higher AD than the dynamic protocol to act as a backup; setting it equal or lower would disrupt the primary route.

C

The specific factual error is that removing OSPF is an extreme measure that breaks connectivity, whereas a floating static route is meant to be a seamless backup.

D

The specific factual error is that adding an extra static route is not the standard solution; Cisco recommends using the exit interface for directly connected next-hops to ensure route validity.

Why candidates pick the wrong answer

B

Candidates might think that matching the AD would allow the static route to take over, but they overlook that the static route would then be preferred over OSPF, not just a backup.

C

Candidates might think that if OSPF is removed, the static route will be used, but this does not solve the underlying issue of the static route being inactive due to an unreachable next-hop.

D

Candidates might think that making the next-hop reachable via another static route will solve the problem, but they overlook that the floating static route would then depend on another static route, which may not be desirable.

388
MCQhard

A technician is troubleshooting a network issue where hosts in VLAN 20 on SW1 cannot communicate with hosts in VLAN 20 on SW2. Both switches are connected by an Ethernet trunk link that is up/up and configured as a trunk. The VLAN databases on both switches include VLAN 20, and the spanning tree for VLAN 20 is in a forwarding state on all ports. Hosts within VLAN 20 on each switch can communicate with each other locally. What is the most likely cause?

A.The native VLAN is mismatched on the two ends of the trunk.
B.VLAN 20 has not been created in the VLAN database on SW2.
C.The trunk encapsulation is mismatched between SW1 and SW2.
D.VLAN 20 is not in the switchport trunk allowed VLAN list on the trunk port between SW1 and SW2.
AnswerD

When a trunk port’s allowed VLAN list explicitly excludes a VLAN, the switch drops all frames tagged for that VLAN, even though the VLAN exists locally and the trunk is active. This results in the described symptom of local intra-VLAN communication working but no cross-switch communication for VLAN 20.

Why this answer

The most likely cause is that VLAN 20 is not included in the allowed VLAN list on the trunk port between SW1 and SW2. Even though the trunk is up/up and VLAN 20 exists in the VLAN database, the switchport trunk allowed vlan command restricts which VLANs can traverse the trunk. If VLAN 20 is omitted from this list, frames from VLAN 20 will be dropped at the trunk, preventing inter-switch communication for that VLAN.

Exam trap

Cisco often tests the distinction between VLAN existence in the database and VLAN permission on a trunk; candidates mistakenly think that if a VLAN is created and spanning tree is forwarding, it must work, but the trunk allowed list is an independent filter that can block traffic.

Why the other options are wrong

A

Candidates may think that a native VLAN mismatch breaks all trunk functions.

B

Candidates may assume that a missing VLAN on one switch explains inter-switch failures, ignoring that local communication would also fail.

C

Candidates might overlook that the trunk link is operational, which implies matching encapsulation.

389
MCQeasy

Which field in an IPv4 packet is primarily used to prevent packets from looping forever in the network?

A.Version
B.Header checksum
C.Time to Live
D.Protocol
AnswerC

Time to Live (TTL) is the loop-prevention field in an IPv4 header. Each router decrements TTL by at least 1, and when it reaches 0, the router discards the packet and typically sends an ICMP Time Exceeded message back to the source. This guarantees that no packet can traverse a routing loop forever, bounding the network diameter.

Why this answer

Each router decrements the TTL field by one. When TTL reaches zero, the packet is discarded. That mechanism prevents indefinite looping.

Exam trap

Remember that TTL is about lifespan and loop prevention, not error checking or addressing.

Why the other options are wrong

A

The Version field (4 bits) indicates the IP version (e.g., IPv4 or IPv6) and has no role in loop prevention. It is used by routers to interpret the packet header correctly.

B

The Header Checksum field detects errors in the IPv4 header only; it does not limit packet forwarding or prevent loops. If corrupted, the packet is discarded, but this does not stop looping.

D

The Protocol field identifies the next-level protocol (e.g., TCP, UDP, ICMP) carried in the payload. It has no impact on packet forwarding or loop prevention.

When would these options actually be correct?

A

If the question were to ask about identifying the field that specifies the IP protocol version or the format of the packet, then the Version field would be the correct answer. For example, a question could state, 'Which field indicates the version of the Internet Protocol being used in an IPv4 packet?'

B

If the exam question asked about a field that ensures data integrity and error checking in an IPv4 packet, then the Header checksum would be the correct answer. For example, a question could specify the function of fields that maintain data accuracy during transmission.

D

If the question asked about identifying the field that specifies the transport layer protocol used in the packet, then 'Protocol' would be the correct answer, as it directly indicates which protocol should handle the packet at the destination.

Why candidates pick the wrong answer

A

Students might think 'version' controls packet lifetime or hop count, confusing it with TTL due to both being header fields.

B

Because checksums ensure data integrity, some may incorrectly assume they also prevent infinite loops by discarding corrupted packets that could loop.

D

Some might confuse 'protocol' with routing protocols that manage paths, but the Protocol field in the IP header is unrelated to loop prevention.

390
PBQhard

You are connected to R1 via console. R1 and R2 are connected via a serial link. OSPFv2 has been configured, but the adjacency is stuck in EXSTART state. You suspect a mismatched MTU. On R1, the interface MTU is currently set to 1400, while R2 uses the default MTU of 1500. You need to verify and fix the issue.

Network Topology
S0/0/010.0.0.1/30S0/0/010.0.0.2/30serial linkR1R2

Hints

  • •The issue is with MTU mismatch.
  • •Check the MTU on R1's serial interface.
  • •After fixing, reset the OSPF process to force adjacency.
A.On R1, configure the interface MTU to 1500 and then clear the OSPF process using 'clear ip ospf process'.
B.On R1, configure the interface MTU to 1500 and then reload the router to apply the change.
C.On R1, configure the interface MTU to 1500 and then change the OSPF network type to point-to-point.
D.On R1, configure the interface MTU to 1500 and then adjust the OSPF hello and dead timers to match R2.
AnswerA
solution
! R1
interface Serial0/0/0
ip mtu 1500
clear ip ospf process
end

Why this answer

OSPF requires matching MTU values on a link. The incorrect MTU on R1 (1400) caused the adjacency to stall in EXSTART. Setting MTU to 1500 and clearing the OSPF process allows proper adjacency formation.

Exam trap

Do not confuse the states of OSPF adjacency. EXSTART state is specifically related to DBD exchange and MTU mismatch, while INIT or 2-WAY states are more common with hello/dead timer mismatches. Always verify MTU when adjacency is stuck in EXSTART.

Why the other options are wrong

B

The specific factual error is that a reload is not required to apply MTU changes; the interface MTU is applied immediately, and the OSPF process can be cleared to re-establish adjacencies.

C

The specific factual error is that OSPF network type does not affect MTU requirements; MTU must match regardless of network type.

D

The specific factual error is that timer mismatches affect the INIT and 2-WAY states, while EXSTART is associated with MTU or database descriptor (DBD) packet issues.

Why candidates pick the wrong answer

B

Candidates might think that a reload is needed to apply configuration changes, but in Cisco IOS, many interface parameters take effect immediately without reload.

C

Candidates may confuse MTU issues with network type issues, as both can cause OSPF adjacency problems. However, EXSTART state specifically points to MTU mismatch.

D

Candidates often confuse the symptoms of timer mismatches with MTU mismatches. Both can prevent full adjacency, but the stuck state differs.

391
Multi-Selectmedium

Which two statements accurately describe the relationship between a network address and a broadcast address in IPv4 subnetting?

Select 2 answers
A.The network address is the first address in the subnet block.
B.The broadcast address is the last address in the subnet block.
C.Both addresses are normal host addresses that can be assigned to users.
D.The broadcast address always becomes the default gateway.
E.These concepts exist only in IPv6 and not IPv4.
AnswersA, B

In IPv4, the network address is the first (lowest) address within a subnet block, obtained by setting all host bits to 0. This address uniquely identifies the subnet and is used by routers in their routing tables; it cannot be assigned to any host interface. It is the starting boundary from which the usable host range begins.

Why this answer

The network address identifies the beginning of the subnet block, and the broadcast address identifies the final address in that block. In practical terms, both are reserved and are not assigned to ordinary hosts. The usable host range falls between them.

This is a very basic subnetting truth, but it is foundational for every other addressing calculation.

Exam trap

Be cautious not to confuse the roles of network and broadcast addresses with usable host addresses.

Why the other options are wrong

C

Both the network address and broadcast address are reserved addresses within a subnet and cannot be assigned to hosts. The network address identifies the subnet itself, and the broadcast address is used for one-to-all communication. Assigning them to hosts would cause conflicts.

D

The default gateway is typically the IP address of a router interface on the subnet, which is a normal host address within the usable range. The broadcast address is the last address in the subnet and is reserved for broadcasting; it cannot be used as a gateway.

E

Network and broadcast addresses are fundamental to IPv4 subnetting and are defined in IPv4 standards. IPv6 does not use broadcast addresses; instead, it uses multicast and anycast. Therefore, stating these concepts exist only in IPv6 is factually incorrect.

When would these options actually be correct?

C

In a hypothetical question asking which addresses can be assigned to hosts in a specific subnet configuration, if the context allowed for a broader interpretation of 'addresses' without specifying roles, this option could be correct if it included non-reserved addresses.

D

In a different question asking about the configuration of a specific network device where the broadcast address is mistakenly configured as the default gateway, this option could be correct. For example, if a question states that a network device is set up incorrectly and asks for the misconfigured address type, option D could be the right answer.

E

If the question were rephrased to ask about the differences between IPv4 and IPv6 addressing schemes, stating that network and broadcast addresses are concepts that exist only in IPv4 would be correct. For example, a question could ask which addressing scheme utilizes broadcast addresses, making option E accurate.

Why candidates pick the wrong answer

C

A student might think that since these are valid IP addresses within the subnet range, they could be used like any other host address, not realizing they are reserved by protocol standards.

D

Some might mistakenly believe that the broadcast address serves as a gateway because it is a well-known address, but in practice, the gateway is a specific router interface, not the broadcast address.

E

Students may confuse IPv6's lack of broadcast with the idea that network and broadcast addresses are IPv6 concepts, especially since IPv6 uses different addressing mechanisms. However, the question explicitly refers to IPv4.

392
MCQhard

Refer to the exhibit. A network engineer is troubleshooting a DHCP issue where DHCP clients on the LAN subnet are sending DHCPDISCOVER messages but the DHCP server does not receive them. The output of the show ip dhcp binding command on R1 is shown. What is the most likely cause of the problem?

A.DHCP service is disabled on R1.
B.The ip helper-address command is configured on the WAN interface instead of the LAN interface facing the DHCP clients.
C.The DHCP pool is configured with a network address that does not match the client subnet.
D.The default-router option is missing from the DHCP pool configuration.
AnswerB

The show ip dhcp binding output shows zero bindings because the router is not relaying DHCP broadcasts. For a DHCP relay agent to work, the ip helper-address must be placed on the interface that receives client broadcasts (the LAN interface). Configuring it on the WAN interface sends relay messages toward the server in the wrong direction, so client DISCOVERs never reach the DHCP server.

Why this answer

The DHCP clients on the LAN subnet are sending DHCPDISCOVER messages, but the DHCP server does not receive them because the ip helper-address command is misconfigured on the WAN interface instead of the LAN interface facing the clients. The ip helper-address command must be applied on the ingress interface (the LAN interface) that receives the broadcast DHCPDISCOVER messages, so that the router can convert the broadcast into a unicast directed to the DHCP server. When placed on the WAN interface, it does not intercept the broadcasts from the LAN clients, and the DHCP server never receives the relayed request.

Exam trap

Cisco often tests the concept that the ip helper-address command must be configured on the interface that receives the DHCP client broadcasts (the LAN interface), not on the interface facing the DHCP server, leading candidates to overlook the direction of traffic flow.

Why the other options are wrong

A

Candidates may think that an empty binding table means the service is off, but the command itself would fail or show a service status if DHCP were truly disabled.

C

Candidates often associate 'no addresses assigned' with a pool misconfiguration, but a pool mismatch would not prevent the server from seeing DISCOVER messages and possibly creating failed or erroneous bindings.

D

Candidates may confuse a missing option with a complete failure of DHCP operation, but IP address leasing is independent of options like default-router.

393
Multi-Selectmedium

Which two statements about RESTful APIs are correct? (Choose two.)

Select 2 answers
A.They commonly use HTTP methods such as GET and POST.
B.They require Layer 2 adjacency between client and server.
C.They often exchange structured data such as JSON.
D.They replace the need for routing protocols on the network.
AnswersA, C

RESTful APIs are built around standard HTTP verbs, with GET and POST being the most fundamental. GET performs safe, idempotent resource retrieval, while POST submits data to create or process a resource, aligning with the request/response model of the web. These methods provide a uniform interface for clients to interact with server resources, independent of the underlying implementation. This design is why such APIs are called representational state transfer (REST).

Why this answer

REST commonly uses HTTP verbs and typically exchanges structured data such as JSON.

Exam trap

A frequent exam trap is the misconception that RESTful APIs require Layer 2 adjacency between client and server devices. Some candidates mistakenly believe that because RESTful APIs use HTTP, they must operate only within the same broadcast domain or VLAN. However, RESTful APIs function over routed IP networks just like any other web traffic, so Layer 2 adjacency is not necessary.

Another trap is thinking that RESTful APIs replace routing protocols, which is incorrect since APIs only provide programmable access to device functions and do not handle routing or forwarding.

Why the other options are wrong

B

Option B is incorrect because RESTful APIs do not require Layer 2 adjacency; they operate over routed IP networks, allowing clients and servers to communicate across different subnets.

D

Option D is incorrect because RESTful APIs do not replace routing protocols; they provide programmable access to device functions but do not handle routing or forwarding decisions.

When would these options actually be correct?

B

If the question were about a specific protocol that operates at Layer 2, such as Ethernet, and asked about the requirements for communication between devices on the same local network, then this option could be correct.

D

In a question that asks about network architecture where RESTful APIs are integrated into a system that uses a flat network design, one might argue that they reduce the complexity of routing by allowing direct communication between services, thus making routing protocols less relevant in that specific context.

Why candidates pick the wrong answer

B

Students might confuse the client-server model with direct physical connections, or think that APIs require a direct link like some legacy protocols. However, REST is designed to work over routed networks.

D

Some may think that because APIs enable communication between applications, they eliminate the need for underlying network protocols. However, APIs rely on the network stack and do not replace routing.

394
MCQmedium

A network administrator is troubleshooting a switch that is receiving DHCPDISCOVER messages from a client on VLAN 20, but the DHCP server on a different subnet never sees those requests. The interface VLAN 20 has the address 10.20.0.1/24, and the DHCP server address is 10.99.0.10. Which command should be applied to enable the switch to forward these requests to the server?

A.ip dhcp pool VLAN20
B.ip forward-protocol udp 67
C.ip dhcp relay information option
D.ip helper-address 10.99.0.10
AnswerD

The ip helper-address command on the client VLAN's SVI converts broadcast DHCPDISCOVER messages into unicast packets destined for the specified server address. It also fills in the gateway address field so the server can select the correct scope for the 10.20.0.0/24 subnet, allowing the reply to be routed back to the client.

Why this answer

DHCP relay is configured with the ip helper-address command on the interface facing the clients, which unicasts their DHCP broadcasts to the specified server and sets the gateway address so the server can match the correct scope. Without it, the broadcast stays on the local subnet and the remote server never receives the request.

Exam trap

The trap here is assuming that enabling option 82 or listing UDP port 67 is enough, when only the ip helper-address statement actually forwards the client request to the server.

395
Matchingmedium

Drag and drop the switch port configuration commands on the left to the correct descriptions on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Statically configures the port as an access port

Sets the data VLAN for an access port

Assigns the VLAN for IP phone voice traffic

Permanently sets the interface as a trunk port

Restricts which VLANs traverse the trunk

Why these pairings

The command 'switchport mode access' statically sets the port as an access port. 'switchport access vlan 10' assigns VLAN 10 as the data VLAN for connected devices. 'switchport voice vlan 20' defines the VLAN used by a Cisco IP phone for voice traffic. 'switchport mode trunk' forces the port into permanent trunking mode. 'switchport trunk allowed vlan 100,200' restricts the trunk to carry only VLANs 100 and 200.

396
Multi-Selectmedium

Which TWO commands can a network technician use on a modern Linux host to verify the IP address configuration and test reachability to a remote server?

Select 2 answers
A.ip addr
B.ifconfig
C.tracert
D.ping
E.nslookup
AnswersA, D

ip addr, part of the iproute2 suite, is the modern replacement for ifconfig, displaying all interfaces, their IPv4/IPv6 addresses, MAC addresses, and administrative state. It only inspects local interface configuration; it does not generate any network traffic toward a remote host, so it cannot verify end-to-end reachability.

Why this answer

The `ip addr` command (option A) is the modern Linux utility for displaying IP address configuration, replacing the deprecated `ifconfig`. The `ping` command (option D) uses ICMP Echo Request/Reply messages to test Layer 3 reachability to a remote server. `ifconfig` (option B) is deprecated and not expected for current certification exams; `tracert` (option C) is a Windows command; `nslookup` (option E) performs DNS lookups but does not verify IP configuration or connectivity.

Exam trap

Cisco often tests the distinction between Windows and Linux commands, so the trap here is that candidates may mistakenly select `tracert` (a Windows command) instead of recognizing that the Linux equivalent is `traceroute`, or they may choose `ifconfig` without knowing it is deprecated in favor of `ip addr`.

Why the other options are wrong

B

Although `ifconfig` can still display IP settings, it is a deprecated legacy command and the question expects the modern `ip addr` from the iproute2 suite.

C

`tracert` is the Windows traceroute utility; the Linux command is `traceroute`.

E

`nslookup` is a DNS troubleshooting tool and cannot verify interface IP configuration or test basic reachability like `ping`.

Why candidates pick the wrong answer

B

Students often remember `ifconfig` from older Linux courses or Windows (where it is `ipconfig`). The similar name and historical use make it a common distractor, even though it is no longer the recommended tool.

C

The similarity between `tracert` and `traceroute` leads students to believe they are interchangeable. Without knowing the OS-specific naming, a test-taker might incorrectly select this option.

E

Students may confuse name resolution with connectivity testing, thinking that if a name resolves, the host is reachable. However, DNS resolution can succeed even if the host is down or unreachable.

397
Multi-Selectmedium

A network administrator is configuring OSPFv2 on a Cisco router. The router is connected to two different areas: Area 0 and Area 1. The administrator wants to summarize the routes from Area 1 into Area 0. Which two statements are true about OSPF inter-area route summarization? (Choose two.)

Select 2 answers
A.Summarization is configured on the ABR using the area range command.
B.The summary route is advertised as a Type 3 LSA.
C.Summarization is configured using the summary-address command on the ABR.
D.Summarization requires the area to be a stub area.
E.Summarization can only be configured on an ASBR.
AnswersA, B

The area range command is used on an Area Border Router (ABR) to summarize routes from a specific area into other areas. It takes the area ID and the summary prefix as parameters. This command helps reduce the size of the routing table in other areas by advertising a single summary route instead of multiple more specific routes.

Why this answer

Inter-area route summarization in OSPF is performed on an Area Border Router (ABR) using the area range command. The ABR advertises a single Type 3 summary LSA for the summarized prefix into other areas, reducing the number of LSAs and routing table entries. It does not require a stub area, and the summary-address command is for external summarization on an ASBR.

Exam trap

The trap here is confusing the roles of ABR and ASBR and mixing up the area range and summary-address commands, which are used for different types of summarization.

398
PBQmedium

You are connected to R1 via the console. R1 and R2 are running OSPFv2 in area 0. R1's router ID is 1.1.1.1, and R2's router ID is 2.2.2.2. Both routers are connected via GigabitEthernet0/0 on the 192.168.12.0/30 subnet. You need to ensure that R1 does not send OSPF hello messages out of its Loopback0 interface, while still advertising the loopback network into OSPF.

Network Topology
Lo010.0.0.1/32G0/0192.168.12.2/30R1R2

Hints

  • •The command is configured under the OSPF process.
  • •Use the keyword 'passive-interface' followed by the interface name.
  • •This prevents OSPF from sending hello messages on that interface.
A.Configure the passive-interface Loopback0 command under the OSPF process.
B.Remove the network 192.168.12.0 0.0.0.3 area 0 command from the OSPF configuration.
C.Configure the ip ospf passive-interface command on GigabitEthernet0/0.
D.Configure the network 192.168.12.0 0.0.0.3 area 0 command under the OSPF process.
AnswerA
solution
! R1
router ospf 1
passive-interface Loopback0

Why this answer

Configuring the Loopback0 interface as passive under the OSPF process suppresses the sending of hello messages on that interface, preventing unnecessary adjacencies. The network is still advertised because OSPF includes the subnet in its LSAs.

Exam trap

Trap: Candidates may confuse passive-interface with removing network statements or applying it to the wrong interface. Remember that passive-interface suppresses hellos but still advertises the network, and it should be applied to the interface that should not form adjacencies, not the transit link.

Why the other options are wrong

B

The specific factual error is that the network statement for the transit link is necessary for OSPF adjacency; removing it would break the OSPF neighbor relationship.

C

The specific factual error is that applying passive-interface to the transit link would prevent the OSPF neighbor relationship from forming, which is not the goal.

D

The specific factual error is that adding a network statement does not suppress hello messages; it only includes the interface in the OSPF process.

Why candidates pick the wrong answer

B

Candidates might think that removing the network statement from the transit link would stop hello messages on that interface, but it would actually prevent the adjacency entirely.

C

Candidates might confuse the interface to be made passive, thinking that making the transit link passive would solve the problem, but it would break the adjacency.

D

Candidates might think that adding a network statement for the transit link would somehow affect hello suppression on Loopback0, but it is unrelated.

399
MCQmedium

A junior administrator is configuring a Cisco router that must forward DHCP requests from the 10.20.30.0/24 LAN to a DHCP server at 192.168.100.50. The LAN interface is Gi0/0 with IP 10.20.30.1. Which single command is required on Gi0/0 so the router relays these broadcasts?

A.ip forward-protocol udp 192.168.100.50
B.ip dhcp relay 192.168.100.50
C.ip dhcp pool LAN
D.ip helper-address 192.168.100.50
AnswerD

The ip helper-address command on the LAN interface tells the router to receive UDP broadcasts on that interface and forward them as unicasts to the specified server address. For DHCP, UDP port 67 broadcasts are forwarded automatically, allowing the router to act as a relay agent for clients on 10.20.30.0/24.

Why this answer

The router must act as a DHCP relay agent because clients broadcast on the local segment while the server sits on a different subnet. Configuring the LAN interface with ip helper-address pointing to the server converts those broadcasts into unicasts toward 192.168.100.50, enabling address assignment without placing a DHCP server on every LAN.

Exam trap

The trap here is confusing DHCP relay with DHCP server configuration, since both use DHCP-related keywords but only the helper-address command relays requests to an external server.

400
MCQmedium

Which command enables IPv6 routing on a Cisco router?

A.ipv6 unicast-routing
B.ipv6 enable
C.ip routing ipv6
D.ipv6 route enable
AnswerA

The global configuration command 'ipv6 unicast-routing' is the correct and required command to enable IPv6 routing on a Cisco router. It enables IPv6 packet forwarding on all interfaces and allows the router to route IPv6 traffic between networks. Without this command, the router will not forward IPv6 packets but will still process traffic explicitly addressed to itself.

Why this answer

The global configuration command 'ipv6 unicast-routing' enables IPv6 forwarding on a Cisco router. 'ipv6 enable' is an interface-level command used to enable IPv6 on a specific interface, not globally. 'ip routing ipv6' and 'ipv6 route enable' are syntactically invalid commands that do not exist in Cisco IOS.

Exam trap

Be careful not to confuse interface-specific commands with global routing commands. Remember that enabling IPv6 globally requires a specific command.

Why the other options are wrong

B

'ipv6 enable' is an interface command, not a global command to enable IPv6 routing.

C

'ip routing ipv6' is not a valid Cisco IOS command.

D

'ipv6 route enable' is not a valid Cisco IOS command.

When would these options actually be correct?

B

In a scenario where the question asks for a command to enable IPv6 on an interface, such as 'Which command would you use to enable IPv6 on a specific interface?', 'ipv6 enable' would be the correct answer.

C

If the exam question asked for a command related to configuring IPv6 routing protocols or managing IPv6 routes, 'ip routing ipv6' could be interpreted as a command for enabling IPv6 routing in that context, especially if it was framed around routing protocol configurations.

D

In a different scenario, if the question were about enabling a specific IPv6 routing protocol or feature that uses a command similar to 'ipv6 route enable', this option could be correct. For example, if the question asked about enabling a specific routing protocol that requires a similar command structure, it could be valid.

Why candidates pick the wrong answer

B

Students often confuse 'ipv6 enable' with enabling IPv6 routing because the command name suggests enabling IPv6. However, it only configures IPv6 on an interface, not the routing process.

C

Test-takers might guess this command because it resembles 'ip routing' for IPv4, assuming a similar pattern for IPv6. However, Cisco uses a different keyword structure for IPv6.

D

The phrase 'route enable' sounds like it would enable routing, and 'ipv6 route' is a valid command for static routes, so students might incorrectly assume this command enables the routing process.

401
MCQmedium

A network engineer is tasked with monitoring a large enterprise network that requires high-frequency, real-time data collection from thousands of routers and switches. The engineer needs a solution that minimizes CPU overhead on the network devices and supports push-based data delivery. Which technology should the engineer choose for this requirement?

A.SNMPv2c with frequent polling intervals
B.Streaming telemetry
C.NetFlow
D.IPFIX
AnswerB

Streaming telemetry uses a push-based model in which devices continuously stream operational data (e.g., CPU, memory, interface counters) to collectors via protocols like gRPC with GPB or JSON encoded data over a long-lived session. This dramatically reduces overhead on the device because the collector subscribes to specific data paths and the device sends updates at configured cadence or on event-driven triggers, eliminating the need for repeated request-response polling. This approach scales to thousands of devices and provides near-real-time visibility, making it the optimal choice for large-scale network monitoring.

Why this answer

Streaming telemetry uses a push model (e.g., gRPC or UDP-based dial-out) to continuously send structured data (YANG-modeled, often encoded in GPB or JSON) from network devices to a collector, which eliminates the need for periodic polling. This minimizes CPU overhead because the device only encodes and transmits data when a subscription triggers an update, rather than processing repeated SNMP GET requests. It is designed for high-frequency, real-time data collection at scale, making it ideal for monitoring thousands of routers and switches with minimal performance impact.

Exam trap

Cisco often tests the distinction between pull-based (SNMP) and push-based (telemetry) models, and the trap here is that candidates may confuse NetFlow or IPFIX as 'push-based' monitoring tools for device health metrics, when they are actually designed for traffic flow analysis and lack the structured, high-frequency, model-driven data collection that streaming telemetry provides.

Why the other options are wrong

A

SNMPv2c uses a pull model where the manager polls devices for data. Frequent polling intervals increase CPU usage on network devices and can cause scalability issues with thousands of devices, making it unsuitable for high-frequency, real-time data collection with minimal overhead.

C

NetFlow is designed for traffic flow analysis, capturing details like source/destination IPs and ports, not for collecting device health metrics such as CPU or memory. Its export mechanism can be CPU-intensive and does not provide the push-based efficiency needed for real-time monitoring of device status.

D

IPFIX is an extension of NetFlow for flexible flow export and shares the same focus on traffic flows, not device health metrics. Like NetFlow, it does not offer the push-based, low-overhead data delivery required for real-time monitoring of thousands of devices.

Why candidates pick the wrong answer

A

Students may think SNMP is the standard for network monitoring and that increasing polling frequency can achieve real-time data, but they overlook the CPU overhead and scalability limitations of the pull model.

C

Students may confuse NetFlow with a general monitoring tool because it exports data, but they fail to recognize its specific focus on traffic flows rather than device metrics.

D

Students might think IPFIX is more advanced and could be used for device monitoring, but it is still flow-based and not designed for telemetry data collection.

402
MCQeasy

A host sends traffic to a web server on another subnet. Which address is used as the destination MAC address in the first Ethernet frame sent by the host?

A.The MAC address of the remote web server
B.The MAC address of the local default gateway
C.The MAC address of the DNS server
D.The broadcast MAC address
AnswerB

The host's routing table indicates that the destination IP is not on the local subnet, so the packet must be sent to the default gateway. The destination MAC in the Ethernet frame is therefore the gateway's interface MAC, resolved via ARP, while the destination IP address remains that of the web server. The gateway then strips the frame and forwards the packet toward the remote subnet, changing the frame headers at each hop while preserving the IP addresses.

Why this answer

When a host wants to communicate with a device on a different subnet, it cannot reach that device directly. The host must send the frame to its default gateway, which is the router that connects to other subnets. Therefore, the destination MAC address in the first Ethernet frame is the MAC address of the local default gateway, not the remote web server (A).

The DNS server (C) is used for name resolution, not for forwarding traffic. The broadcast MAC address (D) would send the frame to all devices on the local subnet, which is not appropriate for unicast communication to a remote destination.

Exam trap

Remember that the destination MAC address for remote communication is the default gateway's, not the remote host's.

Why the other options are wrong

A

The MAC address of the remote web server is not used because the remote host is on a different subnet and cannot be reached directly at Layer 2.

C

The DNS server is used for domain name resolution, not for forwarding data frames to remote subnets.

D

The broadcast MAC address would send the frame to all devices on the local subnet, which is incorrect for unicast traffic to a remote destination.

When would these options actually be correct?

A

In a different scenario where a question asks about the MAC address used in a direct communication between two devices on the same local network, the MAC address of the remote web server would be the correct answer if both devices are on the same subnet and can communicate directly.

C

In a different exam scenario, if the question asked about the MAC address used when a host is sending a DNS query to a DNS server within the same local subnet, then the correct answer would be the MAC address of the DNS server, as the host would communicate directly with it without needing to go through a gateway.

D

If the question were to ask about the initial frame sent by a host to discover all devices on the local network, such as during an ARP request for an IP address, the destination MAC address would be the broadcast MAC address (FF:FF:FF:FF:FF:FF).

Why candidates pick the wrong answer

A

Students may think that the destination MAC address should always be the final destination's MAC, but this is only true for devices on the same subnet. For off-subnet traffic, the MAC address of the default gateway is used.

C

Students might confuse the role of DNS in name resolution with the process of determining the next-hop MAC address. They may think that the DNS server provides the MAC address or is involved in the forwarding decision.

D

Students may recall that ARP uses broadcast to find the MAC address of the default gateway, but the actual data frame uses the learned unicast MAC address, not a broadcast. They might mistakenly think the data frame itself is broadcast.

403
Multi-Selectmedium

Which two statements accurately describe why logs and accounting records both matter in secure operations?

Select 2 answers
A.They improve visibility into events and activity after access occurs.
B.They help with accountability and incident review.
C.They replace the need for authentication entirely.
D.They are useful only on wireless guest networks.
E.They automatically create access policies for administrators.
AnswersA, B

Logs and accounting records capture who accessed what, when, and from where, giving post-event visibility that real-time controls alone cannot provide. This satisfies the scenario's focus on activity after access occurs, enabling detection of misuse and forensic reconstruction.

Why this answer

Option A is correct because logs and accounting records capture events and activity after access has occurred, giving security teams the visibility needed to detect anomalies, trace what happened, and reconstruct timelines during investigations. Option B is correct because these records establish accountability by tying actions to identities and support incident review, allowing responders to determine who did what, when, and how during a security event. Options C, D, and E are incorrect: logging and accounting do not replace authentication (they depend on it to attribute activity to a user or process), they are valuable across all systems and networks rather than only wireless guest networks, and they do not automatically generate access policies for administrators—policy creation remains a separate administrative function.

Exam trap

Don't confuse logs and accounting records with access control measures; they are about visibility and traceability, not prevention.

Why the other options are wrong

C

Logs and accounting records do not replace authentication; they complement it by recording who accessed what and when. Authentication is still required to verify identity before access is granted, and logs only capture activity after authentication occurs.

D

Logging and accounting are essential across all network segments, including wired, wireless, VPN, and data center environments. Limiting them to wireless guest networks would leave other critical areas unmonitored, creating security gaps.

E

Logs and accounting records are passive records of events; they do not automatically create or modify access policies. Policy creation requires administrative action based on analysis of logs, not the logs themselves.

When would these options actually be correct?

C

In a question focused on theoretical frameworks for security models, such as 'What are the implications of eliminating authentication in a secure system?', option C could be correct if discussing a hypothetical scenario where logs are used as the sole method of access control, which is not practical but could be a point of discussion.

D

In a question focused specifically on the security measures applicable to wireless guest networks, where the context emphasizes the unique challenges and requirements of managing guest access, this option could be correct if it stated that logs are particularly useful in that scenario.

E

If the exam question were to ask about automated systems that utilize logs to dynamically adjust access controls based on user behavior, then this option could be correct. For example, a question about a security system that analyzes logs to enforce real-time access policies would validate this statement.

Why candidates pick the wrong answer

C

Students might think that because logs provide visibility into user actions, they could substitute for authentication. However, authentication is a prerequisite for logging meaningful data, and without it, logs cannot identify who performed an action.

D

A student might associate accounting with guest network portals that require login, but accounting is a broader concept used in AAA (Authentication, Authorization, and Accounting) for all network access, not just guest networks.

E

Some might confuse accounting with authorization, thinking that because accounting tracks usage, it can automatically adjust policies. However, accounting is about recording, not enforcing or defining access rules.

404
MCQhard

A user connects a small unmanaged switch to an access port, and the port immediately transitions to err-disabled. Which feature most likely caused this behavior?

A.UDLD aggressive
B.BPDU Guard
C.Root guard
D.Loop guard
AnswerB

BPDU Guard is a spanning-tree protection feature applied to PortFast-enabled edge ports. When any BPDU is received on such a port, the switch immediately shuts the interface down and places it in an err-disabled state, because a legitimate access port should never receive BPDUs. This prevents an unauthorized user switch from participating in spanning tree and creating a Layer 2 loop.

Why this answer

BPDU Guard is the correct answer because it is specifically designed to protect access ports configured with PortFast. When an unauthorized switch is connected to such a port, BPDU Guard detects the incoming BPDU and immediately places the port into err-disabled state, preventing potential loops or topology changes. UDLD aggressive detects unidirectional links but does not cause err-disabled due to BPDU reception.

Root guard blocks ports that attempt to become the root bridge by placing them in root-inconsistent state (not err-disabled). Loop guard prevents alternate/root ports from becoming designated in the absence of BPDUs, putting the port into loop-inconsistent state, again not err-disabled.

Exam trap

Remember that BPDU Guard specifically targets BPDUs on PortFast ports, not general security or loop prevention.

Why the other options are wrong

A

UDLD aggressive detects unidirectional links but does not cause err-disabled on receiving BPDUs; it operates at Layer 1/2 for fiber links.

C

Root guard prevents a port from becoming the root bridge by moving it to root-inconsistent state, not err-disabled.

D

Loop guard prevents alternate/root ports from becoming designated when BPDUs stop, putting the port in loop-inconsistent state, not err-disabled.

When would these options actually be correct?

A

If the question were about a scenario where a unidirectional link was created due to a faulty cable or misconfiguration, and the port transitioned to err-disabled due to UDLD aggressive detecting this condition, then option A would be the correct answer.

C

In a scenario where a switch is configured to prevent a specific port from becoming the root port due to a topology change, a question might ask about the impact of connecting a device that sends BPDUs. In this case, root guard would be the correct answer if the port was configured to block root port transitions.

D

If the question were about a scenario where a switch port is experiencing a loop due to misconfigured trunking or multiple connections creating a loop, then loop guard would be the correct answer. In that case, the question would focus on preventing loops rather than the behavior of access ports.

Why candidates pick the wrong answer

A

Students may confuse UDLD with BPDU Guard because both are spanning-tree protection features that can place a port in err-disable state, but they operate on different triggers.

C

Root guard and BPDU Guard both involve BPDU processing and can cause port state changes, leading students to mistakenly think root guard would also err-disable the port.

D

The name 'loop guard' suggests it prevents loops, and students might assume it would react to an unauthorized switch by disabling the port, but its actual mechanism is different.

405
Multi-Selectmedium

A network administrator is configuring a new switch port for a server that will host multiple VLANs. The server's NIC supports 802.1Q tagging. The administrator wants to ensure that only VLANs 10, 20, and 30 can traverse the link. Which two commands must be configured on the switch port to achieve this? (Choose two.)

Select 2 answers
A.switchport mode trunk
B.switchport access vlan 10
C.switchport voice vlan 20
D.switchport trunk allowed vlan 10,20,30
E.switchport nonegotiate
AnswersA, D

This command sets the port to trunk mode, which is required for carrying multiple VLANs with 802.1Q tagging. A trunk port allows traffic from multiple VLANs to pass through a single physical link. Without trunk mode, the port would only support a single VLAN, and the server would not be able to communicate on multiple VLANs.

Why this answer

To configure a trunk port that carries only VLANs 10, 20, and 30, you must set the port to trunk mode and then specify the allowed VLANs. The switchport mode trunk command enables trunking, and the switchport trunk allowed vlan 10,20,30 command restricts the trunk to those VLANs. This ensures the server can communicate on the required VLANs while blocking others.

Exam trap

The trap here is thinking that setting an access VLAN or voice VLAN is sufficient for a trunk port, or that disabling DTP negotiation restricts VLANs.

406
Multi-Selectmedium

Which TWO statements are true regarding switch port configuration for access, voice, and trunk ports?

Select 2 answers
A.A switch port configured as a trunk port can simultaneously carry untagged traffic for the native VLAN and tagged traffic for multiple other VLANs.
B.When a port is configured with both an access VLAN and a voice VLAN, the switchport must be set to trunk mode.
C.The switchport mode dynamic auto command sets the port to actively attempt to form a trunk if the neighbor initiates negotiation.
D.An access port with a voice VLAN configured sends CDP or LLDP information to the IP phone to identify the voice VLAN.
E.Issuing the switchport trunk allowed vlan command automatically includes the native VLAN in the allowed list, so it never needs to be explicitly added.
AnswersA, D

A trunk port uses IEEE 802.1Q tagging to carry frames from multiple VLANs simultaneously, but it handles the native VLAN uniquely by leaving those frames untagged as they traverse the trunk. All other VLANs in the allowed list are transmitted with 802.1Q tags, allowing a single physical link to carry many logical networks. The native VLAN is designated with 'switchport trunk native vlan' and is subject to the allowed VLAN list, so if that list is pruned, the native VLAN may also be excluded unless explicitly left in.

Why this answer

Option A is correct because an 802.1Q trunk port transmits frames for the native VLAN untagged while tagging frames for all other allowed VLANs, allowing one link to carry both native and multiple tagged VLANs simultaneously. Option D is correct because when a voice VLAN is configured on an access port, the switch uses CDP (or LLDP-MED) to advertise the voice VLAN ID to the attached IP phone, which then tags its voice traffic with that VLAN. Option B is wrong because a port with both an access VLAN and a voice VLAN is configured as an access port with the 'switchport voice vlan' command, not as a trunk.

Option C is wrong because 'switchport mode dynamic auto' only passively waits for the neighbor to initiate trunking; it is 'dynamic desirable' that actively attempts to form a trunk. Option E is wrong because the native VLAN is not automatically added to the allowed VLAN list by 'switchport trunk allowed vlan'; it must be explicitly included if it is to be permitted on the trunk.

Exam trap

Cisco often tests the distinction between 'dynamic auto' and 'dynamic desirable' DTP modes, where candidates mistakenly think 'auto' actively initiates trunk negotiation, when in fact it only responds to incoming DTP messages.

Why the other options are wrong

B

Multi-VLAN access ports (access + voice) stay in access mode; trunk mode is not required and would incorrectly pass all VLANs.

C

Dynamic desirable actively initiates, but dynamic auto is passive.

E

When you prune the allowed VLANs, any omitted VLANs (including the native VLAN) are blocked unless added back.

407
Multi-Selectmedium

Which TWO interface issues can be identified by analyzing the output of the 'show interfaces' command?

Select 2 answers
A.Duplex mismatch
B.Routing protocol misconfiguration
C.Speed mismatch
D.VLAN mismatch
E.STP topology change
AnswersA, C

A duplex mismatch occurs when one device is manually set to full duplex and the other is auto-negotiating or set to half duplex, often on a point-to-point link. The full-duplex side does not defer and sends anytime, while the half-duplex side only transmits when it senses the wire free, leading to collisions and late collisions on the half-duplex side; 'show interfaces' will display late collisions, runts, CRC errors, or excessive input errors on one or both sides. This is a classic Layer 1/physical problem that shows up clearly in interface counters.

Why this answer

The 'show interfaces' command displays interface statistics and operational status, including duplex and speed settings. A duplex mismatch occurs when one end of a link is set to full-duplex and the other to half-duplex, leading to collisions and CRC errors visible in the output. Speed mismatch is also detectable because the interface will show the negotiated speed or errors like 'input errors' if the speeds do not match.

Exam trap

Cisco often tests that 'show interfaces' reveals physical-layer issues like duplex and speed mismatches, but candidates mistakenly think it also shows Layer 2 or Layer 3 problems such as VLAN or routing misconfigurations.

Why the other options are wrong

B

Routing protocol misconfiguration is a Layer 3 issue that does not manifest in the 'show interfaces' output, which focuses on Layer 1 and Layer 2 interface statistics. To diagnose routing issues, you would use commands like 'show ip route' or 'show ip protocols'.

D

A VLAN mismatch is a Layer 2 issue that does not appear in the 'show interfaces' output; it is diagnosed using 'show vlan' or 'show interfaces trunk'. The 'show interfaces' command shows physical and data link layer statistics, not VLAN membership.

E

STP topology changes are not directly visible in 'show interfaces'; they are monitored using 'show spanning-tree' or 'debug spanning-tree events'. The 'show interfaces' command does not provide information about spanning-tree state changes.

Why candidates pick the wrong answer

B

Students might think that interface errors could be caused by routing problems, but routing protocols operate above the interface level and do not affect interface counters directly.

D

Students may confuse interface errors with VLAN mismatches because both involve Layer 2, but VLAN mismatches are not reflected in interface counters like CRC errors or collisions.

E

Students might think that interface counters could indicate STP issues, but STP topology changes are control plane events that do not affect interface statistics like input errors or collisions.

408
MCQhard

A network technician is troubleshooting an inter-VLAN routing issue on a multilayer switch. Hosts on VLAN 10 can reach the SVI for VLAN 10 (10.0.10.1) but cannot reach hosts on VLAN 20. The technician has verified that 'ip routing' is enabled and that the 'show ip route' command displays directly connected routes for both VLANs. No static routes are configured. What should the technician do next?

A.Check the ARP table for entries on VLAN 20.
B.Issue the 'show ip routing' command again to confirm routing is enabled.
C.Configure a default route pointing to the next-hop gateway.
D.Verify the VLAN membership of the destination host on VLAN 20.
AnswerA

The Layer 3 routing table is correct; the problem is likely that the switch lacks a Layer 2 MAC address for the destination host on VLAN 20. Examining the ARP cache will confirm whether the switch can map the destination IP to a MAC address, and if not, will show that ARP resolution is failing, which explains the connectivity break.

Why this answer

The hosts on VLAN 10 can reach the SVI (10.0.10.1) but not hosts on VLAN 20, which indicates that Layer 3 routing is working (ip routing enabled, directly connected routes present). The issue is likely that the switch does not have the MAC address of the destination host in VLAN 20 in its ARP table, so it cannot forward frames to that host. Checking the ARP table for VLAN 20 entries will reveal whether the switch has resolved the Layer 3-to-Layer 2 address mapping for the destination.

Exam trap

Cisco often tests the misconception that if 'ip routing' is enabled and routes are present, inter-VLAN routing should work, but they trap candidates by omitting the critical step of ARP resolution, which is required to deliver frames to the destination host's MAC address.

Why the other options are wrong

B

This option revisits a step already completed and verified, making it redundant. Candidates might think double-checking routing is safe, but the scenario explicitly states routing is working as expected.

C

Some candidates might believe inter-VLAN communication requires a default route, but directly connected routes already provide full reachability without static routing. This action is overly drastic and misdirected.

D

Candidates often jump to VLAN misconfigurations when inter-VLAN communication fails, even when routing is confirmed. The scenario already establishes the VLAN 20 host's location; the next logical layer to inspect is ARP resolution.

409
MCQhard

Refer to the exhibit. A network administrator is troubleshooting connectivity to devices in VLAN 10 on a Layer 3 switch. The administrator issues the show ip interface brief command on SW1 and sees the output displayed. What is the most likely reason that the VLAN 10 SVI is not functioning?

A.No active ports are assigned to VLAN 10.
B.The VLAN 10 SVI has been administratively shut down.
C.The IP address configured on the VLAN 10 SVI is incorrect for the subnet.
D.The switch ports assigned to VLAN 10 are all configured as trunk ports.
AnswerA

The SVI for VLAN 10 will not transition to up/up until at least one switch port is in the up/up state and actively assigned to VLAN 10 (either as an access port in that VLAN or as a trunk port that has VLAN 10 allowed and active). With no active member ports, the switch considers the VLAN to have no operational Layer 2 presence, so the SVI's line protocol remains down even though the VLAN exists and is configured with an IP address. This is a standard Cisco IOS behavior: the SVI's status mirrors the presence of an active port in the associated VLAN, not merely the VLAN's existence.

Why this answer

The VLAN 10 SVI will remain in a down/down state if there are no active ports assigned to VLAN 10, because a Layer 3 switch requires at least one active Layer 2 interface in the VLAN to bring the SVI up. This is a fundamental behavior of Cisco switches: the SVI is operationally down until the VLAN has at least one active port in a non-blocking state. The show ip interface brief output would show the VLAN10 interface as 'down/down' rather than 'administratively down' or 'up/up'.

Exam trap

Cisco often tests the subtle distinction between an SVI being 'down/down' due to no active ports in the VLAN versus 'administratively down' due to a shutdown command, and candidates may incorrectly assume a misconfigured IP address or trunk port issue is the cause.

Why the other options are wrong

B

Candidates often confuse 'down' with 'administratively down', assuming any disabled interface will show 'down'. They need to distinguish the two statuses.

C

Some candidates think a misconfigured IP address can cause an interface to be down, but status does not reflect IP configuration.

D

A common misunderstanding is that trunk ports do not make a VLAN active; in reality, a trunk carrying VLAN 10 can activate the SVI as long as the trunk is up/up and the VLAN is not pruned.

410
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure an IOS-XE device as an NTP client and set up syslog reporting of NTP events to a remote log server.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order is to first enter global configuration mode, then configure the NTP server to define the time source, then configure the logging host to specify the remote syslog server, then enable logging of NTP events so that NTP-related syslog messages are generated and sent to the configured host, and finally verify the configuration. This corresponds to option A. Option B is incorrect because configuring the logging host before the NTP server would attempt to send logs before time synchronization is set up.

Option C is incorrect because enabling NTP event logging before configuring both the NTP server and the logging host means there is no NTP server to generate events and no logging destination to send them to. Option D is incorrect because enabling logging of NTP events before configuring the logging host would cause generated messages to be dropped if the logging host is not yet set; the logging host must be configured before enabling NTP event logging. Therefore, only option A is correct.

Exam trap

The trap is that candidates may think any order of these configuration commands is acceptable, but the required order is to configure the NTP server first, then the logging host, then enable NTP event logging, and finally verify.

Why candidates pick the wrong answer

B

Candidates might think logging configuration is independent of NTP and can be done first, but best practice is to set NTP first.

C

Candidates might assume logging can be enabled at any time, but it requires NTP to be configured first to generate meaningful events.

D

Candidates might think enabling logging first is fine, but the logging host must be defined to actually send logs.

411
MCQmedium

A wireless client can see two SSIDs from the same company: Corp and Guest. Which statement best explains what an SSID represents in this situation?

A.It is the wireless network name presented to clients for a specific WLAN.
B.It is the encryption algorithm securing the WLAN.
C.It is the radio antenna inside the AP.
D.It is the management IP address of the controller.
AnswerA

An SSID (Service Set Identifier) is the human-readable network name that an access point broadcasts in beacon and probe response frames so clients can identify and select a specific WLAN. It distinguishes multiple wireless networks on the same radio by presenting a unique name, up to 32 bytes, while the BSSID differentiates APs within the same SSID. This is why a wireless client sees the SSID as the network name before associating, making it the correct definition.

Why this answer

An SSID is the name that identifies a specific wireless LAN to clients. In practical terms, Corp and Guest are two different WLAN identifiers presented to users, even if they are broadcast by the same physical access point infrastructure. The SSID tells the client which wireless network it is trying to join.

This matters because people often confuse SSIDs with the access point itself or with the security protocol. The SSID is the network identifier, not the hardware or the encryption standard.

Exam trap

Do not confuse SSIDs with physical devices or security protocols; they are identifiers for networks.

Why the other options are wrong

B

The SSID is simply the network name broadcast by the access point; encryption algorithms like WPA2 or WPA3 are configured separately on the WLAN and are not part of the SSID itself.

C

An SSID is a logical identifier, not a physical component. The radio antenna is hardware that transmits and receives wireless signals, but it does not define the network name.

D

The management IP address of a wireless controller is used for administrative access to the controller, not for client connectivity. Clients use the SSID to identify and connect to a WLAN, not the controller's IP.

When would these options actually be correct?

B

In a different question, if asked about the components of WLAN security, such as 'What is the role of encryption in a WLAN?', option B could be correct if it specifically referred to the encryption algorithm securing the WLAN, such as WPA2 or AES.

C

In a different question, if asked about the components of a wireless access point and their functions, stating that the radio antenna is a critical part of the AP could be correct. For example, a question could ask, 'What component of an AP is responsible for signal transmission and reception?'

D

In a different question, if it asked for the role of the management IP address in a wireless network setup, stating that it is the management IP address of the controller would be correct, as it directly relates to how the controller is accessed and managed.

Why candidates pick the wrong answer

B

Students often confuse the SSID with security settings because both are configured when setting up a wireless network, and the SSID is commonly associated with the security type in client connection dialogs.

C

Since the SSID is broadcast over the air via the antenna, some learners mistakenly think the SSID is a property of the antenna itself, rather than a configurable parameter on the access point.

D

In centralized WLAN architectures, the controller manages multiple APs and their SSIDs, so a student might incorrectly associate the controller's IP with the SSID, especially when configuring the controller via its management interface.

412
MCQmedium

A routing table entry begins with the code C. What does that code indicate?

A.A route learned through EIGRP
B.A connected network
C.A candidate default route
D.A static route to a classful network
AnswerB

The code 'C' in a Cisco IOS routing table represents a connected (directly attached) network. This entry is automatically generated when an interface has a valid IP address configured and is in the up/up state, and it carries an administrative distance of 0, meaning it is the most trustworthy source of routing information.

Why this answer

In Cisco routing table output, C indicates a directly connected network. These routes are installed when an interface is up and has an address in that subnet.

Exam trap

A frequent exam trap is mistaking the 'C' code for a static route or a route learned via a routing protocol like EIGRP. Some candidates incorrectly assume 'C' means candidate default or static, but Cisco IOS uses 'S' for static routes and 'D' for EIGRP-learned routes. Misreading these codes can lead to incorrect conclusions about how a route was learned or its trustworthiness.

Remember, 'C' always means the route is directly connected to the router, which is fundamental for understanding routing behavior and troubleshooting.

Why the other options are wrong

A

Option A is incorrect because EIGRP-learned routes are marked with 'D' in Cisco IOS routing tables, not 'C'. The letter 'D' stands for 'Dynamically learned' via EIGRP, so 'C' cannot represent EIGRP routes.

C

Option C is incorrect because candidate default routes are not indicated by 'C'. Cisco uses 'S*' or other notations for candidate default routes, so 'C' does not represent default routes.

D

Option D is incorrect because static routes use the code 'S' in Cisco routing tables. The code 'C' never represents static routes, so this option is invalid.

When would these options actually be correct?

A

If the question asked what code represents a route learned through EIGRP, then option A would be correct. For example, a question could state, 'What code indicates a route learned via EIGRP in a routing table?'

C

In a different question, if asked what code represents a route that is a candidate for becoming the default route, option C would be correct. This would require a context where the question specifies default routes and their candidates.

D

If the question were to ask about a routing table entry that begins with the code S, then option D would be correct, as it would indicate a static route to a classful network. This would clarify the context of static routes in relation to classful addressing.

Why candidates pick the wrong answer

A

Some students may associate 'C' with 'Cisco' or think it stands for 'Cisco protocol', but EIGRP is a Cisco proprietary protocol. However, the routing table codes are standardized: 'C' for connected, 'D' for EIGRP, 'O' for OSPF, etc.

C

The word 'candidate' starts with 'C', so students might mistakenly think 'C' stands for 'candidate'. However, in Cisco IOS, 'C' is exclusively for connected networks, and default routes are shown with a '*' or as a static route with 'S*'.

D

Students might confuse 'C' with 'classful' or think that static routes are also 'connected' in a sense, but the routing table codes are distinct. The 'C' code is only for networks directly attached to the router's interfaces.

413
PBQhard

You are connected via the console to R1, a new Cisco ISR 4321 router. The network team requires that all routers be reachable via SSH for management. R1's management interface is GigabitEthernet0/0 with IP 192.168.1.1/24. You need to configure SSH on R1, including a hostname, domain name, RSA key pair of 1024 bits, local user 'admin' with secret 'cisco123', and enable SSH version 2. Additionally, configure the vty lines to accept only SSH connections and use local authentication.

Network Topology
G0/0192.168.1.1/24linkR1Management Network

Hints

  • •You need to set hostname and domain name before generating RSA keys.
  • •Use 'crypto key generate rsa modulus 1024' to create the key pair.
  • •Configure vty lines to only allow SSH and use local authentication.
A.R1(config)# hostname R1 R1(config)# ip domain-name example.com R1(config)# crypto key generate rsa modulus 1024 R1(config)# username admin secret cisco123 R1(config)# ip ssh version 2 R1(config)# line vty 0 4 R1(config-line)# transport input ssh R1(config-line)# login local
B.R1(config)# hostname R1 R1(config)# ip domain-name example.com R1(config)# crypto key generate rsa general-keys modulus 1024 R1(config)# username admin password cisco123 R1(config)# ip ssh version 2 R1(config)# line vty 0 4 R1(config-line)# transport input ssh telnet R1(config-line)# login local
C.R1(config)# hostname R1 R1(config)# ip domain-name example.com R1(config)# crypto key generate rsa modulus 1024 R1(config)# username admin secret cisco123 R1(config)# ip ssh version 2 R1(config)# line vty 0 4 R1(config-line)# transport input all R1(config-line)# login local
D.R1(config)# hostname R1 R1(config)# ip domain-name example.com R1(config)# crypto key generate rsa modulus 1024 R1(config)# username admin secret cisco123 R1(config)# ip ssh version 2 R1(config)# line vty 0 4 R1(config-line)# transport input ssh R1(config-line)# password cisco123 R1(config-line)# login
AnswerA
solution
! R1
hostname R1
ip domain-name example.com
crypto key generate rsa modulus 1024
username admin secret cisco123
line vty 0 4
transport input ssh
login local

Why this answer

SSH configuration requires a hostname, domain name, RSA key pair, local username, and vty line settings. The command sequence ensures SSH version 2 is used and only SSH connections are accepted on the vty lines.

Exam trap

Watch for subtle differences: 'username secret' vs 'username password', 'transport input ssh' vs 'transport input all' or 'transport input ssh telnet', and 'login local' vs 'login'. Also ensure the hostname and domain name are set before generating RSA keys.

Why the other options are wrong

B

Using 'password' instead of 'secret' stores the password in plaintext; allowing Telnet alongside SSH does not restrict to SSH only.

C

'transport input all' permits Telnet and other protocols, which is not restrictive enough.

D

Using 'password' and 'login' on vty lines enables password-only authentication, not local user authentication.

Why candidates pick the wrong answer

B

Candidates may think 'password' is acceptable or forget that 'transport input ssh' alone is needed to restrict to SSH.

C

Candidates might think 'all' is safe or forget that the default allows Telnet; they may not realize 'all' includes insecure protocols.

D

Candidates may confuse line password authentication with local authentication, or think 'login' is sufficient without specifying 'local'.

414
MCQmedium

Which feature helps prevent a rogue DHCP server from handing out addresses on a campus switch network?

A.PortFast
B.DHCP snooping
C.HSRP
D.LLDP
AnswerB

DHCP snooping is a Layer 2 security feature on switches that filters DHCP traffic by designating trusted ports (typically uplinks to known DHCP servers) and untrusted ports (end-user access ports). It builds a DHCP snooping binding table of legitimate leases and drops DHCPOFFER or DHCPACK messages arriving on untrusted ports, which directly blocks a rogue DHCP server from successfully handing out IP addresses. This is the standard mitigation for rogue DHCP server attacks.

Why this answer

DHCP snooping classifies interfaces as trusted or untrusted and can block unauthorized DHCP server replies arriving on untrusted ports.

Exam trap

Avoid confusing PortFast (which skips STP convergence) with DHCP-specific features like DHCP Snooping.

Why the other options are wrong

A

PortFast is a Spanning Tree Protocol feature that immediately transitions an access port to the forwarding state, bypassing the listening and learning states. It does not inspect or validate DHCP messages, so it cannot prevent a rogue DHCP server from handing out addresses.

C

HSRP (Hot Standby Router Protocol) provides first-hop redundancy by allowing multiple routers to share a virtual IP address, ensuring gateway availability. It does not inspect DHCP traffic or provide any mechanism to block unauthorized DHCP servers.

D

LLDP (Link Layer Discovery Protocol) is a vendor-neutral protocol used for discovering neighboring devices and their capabilities by exchanging information such as device type, management addresses, and VLAN IDs. It has no role in DHCP security or filtering DHCP messages.

When would these options actually be correct?

A

In a different exam scenario, a question might ask about features that optimize switch port behavior for end devices in a network where rapid connectivity is crucial. In that case, a question could ask about improving the speed of port activation for devices like VoIP phones, making PortFast the correct answer.

C

If the exam question asked about ensuring high availability and redundancy for gateway devices in a network, HSRP would be the correct answer, as it allows multiple routers to work together to present a single virtual IP address to clients.

D

If the exam question asked about protocols that enhance network management and device discovery, LLDP would be the correct answer. For example, a question could focus on how to identify and manage devices on a switch network, where LLDP plays a crucial role.

Why candidates pick the wrong answer

A

Students might think PortFast provides security because it is often used on edge ports where end devices connect, and they may confuse its rapid transition with a security feature that blocks unauthorized servers.

C

Because HSRP involves IP address management and redundancy, some students might mistakenly believe it can also manage or secure DHCP address assignment, especially since both operate at Layer 3.

D

LLDP is a Layer 2 protocol that operates on switches, and students might confuse it with DHCP snooping because both are associated with network discovery and management, but they serve entirely different purposes.

415
MCQhard

Refer to the exhibit. A network administrator is troubleshooting connectivity issues. Hosts on the 192.168.10.0/24 network cannot reach servers on the 192.168.20.0/24 network, but they can successfully reach other networks, including the Internet. The administrator runs the show ip access-lists command on the router (output shown). What is the most likely cause?

A.The ACL is applied in the wrong direction on the interface.
B.The ACL is missing a permit statement for the 192.168.20.0/24 destination.
C.The order of the ACL entries causes the deny statement to match first.
D.The implicit deny at the end is blocking the traffic to 192.168.20.0/24.
AnswerC

Extended IP access list 110 processes entries sequentially. Entry 10 denies traffic from 192.168.10.0/24 to 192.168.20.0/24, and entry 20 permits the same source to any destination. Because the deny is listed first, it is matched before the permit, causing the traffic to be dropped.

Why this answer

The ACL is processed top-down, and the first matching entry determines the action. In this scenario, the deny statement for 192.168.10.0/24 to 192.168.20.0/24 appears before any permit statement for that traffic, so packets from the 192.168.10.0/24 network to the 192.168.20.0/24 network are denied immediately, even if a later permit statement would have allowed them. This explains why hosts can reach other networks (including the Internet) but not the 192.168.20.0/24 servers.

Exam trap

Cisco often tests the concept of ACL order of operations, where candidates mistakenly think that a later permit statement will override an earlier deny, or that the implicit deny is the culprit when an explicit deny is actually matching first.

Why the other options are wrong

A

Candidates may assume any ACL misbehavior is due to wrong interface direction, ignoring that the specific symptom (only 192.168.20.0 is unreachable) points to the deny rule itself.

B

Candidates often focus on what an ACL ‘lacks’ rather than the sequence, missing that the existing permit any covers the destination but is shadowed by the earlier deny.

D

Candidates might recall that all ACLs have an implicit deny, but they fail to realize that a packet matching an earlier deny is already discarded, and the implicit deny only applies to unmatched traffic.

416
MCQhard

A network administrator implements a set of spanning-tree enhancements to secure the switching infrastructure. Later, a help desk ticket reports that a user in a remote office cannot connect to any network resources. While investigating, the administrator notices that the switch port connecting the remote office switch to the distribution switch is in a 'root-inconsistent' state and is blocking traffic. Which protection feature, if misapplied, most likely caused this issue?

A.Loop Guard
B.Root Guard
C.BPDU Guard
D.BPDU Filter
AnswerB

Root Guard ensures that a port cannot become a root port. When a superior BPDU is received on a Root Guard-enabled port, the port transitions to a root-inconsistent state and blocks traffic, exactly as described in the scenario.

Why this answer

Root Guard is the correct answer because it forces an interface to be a designated port. If a switch receives a superior BPDU (indicating a root bridge with a lower bridge ID) on a Root Guard-enabled port, the port is placed into a 'root-inconsistent' state and blocks traffic to prevent the attached switch from becoming the root bridge. This matches the symptom described: a port in 'root-inconsistent' state blocking traffic after spanning-tree enhancements were applied.

Exam trap

Cisco often tests the distinction between 'root-inconsistent' (Root Guard) and 'loop-inconsistent' (Loop Guard) states, and the trap here is that candidates confuse the two or assume BPDU Guard is responsible for any BPDU-related blocking.

Why the other options are wrong

A

A loop-inconsistent state is different from the root-inconsistent state observed. Loop Guard acts when BPDUs stop arriving, not when they appear with a superior root claim.

C

While BPDU Guard also reacts to incoming BPDUs, it puts the port in err-disabled (shutdown) state, not a blocking state named 'root-inconsistent'. The symptom described is not error-disabled.

D

BPDU Filter would not cause the port to show a root-inconsistent state. The symptom is a protective blocking state, which BPDU Filter does not provide.

417
MCQhard

Two routers are directly connected over IPv6 and should form an OSPFv3 adjacency, but they do not. Link-local addressing is present on both interfaces. Which issue is most likely to prevent the adjacency?

A.The interfaces are assigned to different OSPFv3 areas.
B.The routers need matching hostnames before OSPFv3 can start.
C.IPv6 requires a /64 only for routing protocols to function.
D.OSPFv3 cannot run on directly connected interfaces.
AnswerA

OSPFv3 requires that all routers on the same link share the same area ID; if one interface belongs to area 0 and the other to area 1, the Area ID field in the Hello packet doesn't match, and the packet is silently dropped. The neighbor state stays in DOWN because OSPFv3 cannot form an adjacency when the area numbers are different. This is a core OSPF principle: neighbors must be configured with the same area on the connecting link.

Why this answer

An area mismatch is a strong and direct explanation. In plain language, even though the routers can have valid IPv6 addressing and proper link-local communication on the interface, OSPFv3 still requires the two ends of the shared segment to agree on the area context for the adjacency. If one side places the interface in one area and the other side places it in another, the routers will not treat each other as valid neighbors.

This is very similar in principle to OSPF for IPv4. Link-local addressing matters in OSPFv3, but the protocol still enforces key neighbor-formation checks. The correct answer is the one that focuses on a required protocol match rather than on a vague issue like hostname or cable color.

Exam trap

Focus on OSPFv3 configuration requirements like area matching, not on distractors such as hostnames or prefix length.

Why the other options are wrong

B

OSPFv3 adjacency formation does not depend on hostnames; hostnames are only used for identification in show commands and have no impact on routing protocol operation.

C

OSPFv3 can use any valid IPv6 prefix length, including /64, /126, or /127, for the link between routers. The /64 requirement is for SLAAC, not for routing protocols.

D

OSPFv3 is specifically designed to run on directly connected interfaces, just like OSPFv2. It forms adjacencies over directly connected links to exchange routing information.

When would these options actually be correct?

B

In a different scenario, if the question specified that OSPFv3 requires routers to have matching hostnames for a specific proprietary implementation or feature, then this option could be correct. For example, if the exam asked about a vendor-specific OSPFv3 implementation that enforces hostname matching for security reasons.

C

In a different exam scenario, if the question stated that OSPFv3 was configured on a link with a prefix length other than /64 and asked whether this would affect OSPFv3 operation, then this option could be correct, as it would imply a misunderstanding of the requirements for OSPFv3.

D

In a different scenario where the question states that OSPFv3 is being configured on a non-directly connected interface, such as a point-to-point link that requires additional encapsulation, this option could be correct if the exam asks about the limitations of OSPFv3 in that context.

Why candidates pick the wrong answer

B

Students might confuse hostname requirements with other protocols like EIGRP that use router IDs, or mistakenly think that matching hostnames are needed for neighbor relationships.

C

The /64 prefix is commonly associated with IPv6 and often required for features like SLAAC, leading students to incorrectly assume it is mandatory for all IPv6 operations, including routing.

D

Students might confuse OSPFv3 with other protocols that require intermediate devices, or think that IPv6 routing protocols have different adjacency requirements.

418
MCQhard

Two switches are configured for LACP EtherChannel. One side is set to passive and the other side is also set to passive. What is the most likely outcome?

A.The EtherChannel will not form because neither side initiates LACP negotiation.
B.The EtherChannel always forms because passive mode is preferred.
C.The links automatically become a routed interface.
D.The switches delete the bundle configuration automatically.
AnswerA

In LACP, passive mode places the port in a listening state and does not transmit negotiation packets; it only responds to incoming LACP PDUs. Since both switches are configured passive, neither sends an LACP PDU, so the negotiation never begins. Consequently, the EtherChannel remains down and the individual ports stay in their normal operational state as separate access/trunk links.

Why this answer

The EtherChannel will not form because LACP passive mode only listens for negotiation; it does not initiate it. When both sides are set to passive, neither side sends LACP packets, so the bundle cannot be established. This is a deterministic outcome, not merely unlikely.

Exam trap

Ensure at least one side is set to active in LACP configurations to avoid non-formation of the channel.

Why the other options are wrong

B

Passive mode does not initiate LACP negotiation; it only responds to incoming LACPDUs. Therefore, with both sides passive, no LACPDUs are exchanged, and the EtherChannel will not form. The statement that passive mode is preferred is incorrect; active mode is typically used on at least one side to initiate the channel.

C

LACP operates at Layer 2 and does not change the interface type. The ports remain switchports (Layer 2) unless explicitly configured with 'no switchport'. LACP mode has no effect on Layer 3 routing functionality.

D

LACP configuration is not automatically deleted when negotiation fails. The configuration remains in the running-config, and the ports will simply not form an EtherChannel. The administrator must manually remove the configuration if desired.

When would these options actually be correct?

B

In a different scenario where both switches are configured to use LACP but one switch is set to active mode while the other is set to passive, this option could be correct. In such a case, the active switch would initiate the negotiation, allowing the EtherChannel to form successfully.

C

If the question were to state that both switches are configured for LACP but with one switch set to active mode and the other to passive, the links could potentially become routed interfaces if the configuration allows for it. This scenario would require specific routing configurations to be in place.

D

In a different scenario where a switch is configured to automatically remove any EtherChannel configurations if no negotiation occurs within a certain timeout period, this option could be correct. For instance, a question could specify that the switches have a timeout setting that triggers deletion of the bundle if no active negotiation is detected.

Why candidates pick the wrong answer

B

Students may confuse passive mode with desirable mode in PAgP, where desirable-desirable forms a channel. Since LACP passive is similar to PAgP auto, they might incorrectly assume that passive-passive works, but LACP requires at least one active side.

C

Some students might think that because LACP is a protocol that runs between switches, it could automatically enable routing, but that is not the case. The confusion may arise from the fact that some EtherChannel configurations can be used for routed interfaces, but the LACP mode itself does not cause that.

D

Students might think that if the EtherChannel does not form, the switch would automatically clean up the configuration to avoid errors, but Cisco switches do not automatically remove configured port-channel interfaces or channel-group assignments.

419
MCQhard

Why is a northbound API generally more useful to orchestration software than a human-readable CLI screen?

A.Because the API provides a structured interface intended for software interaction.
B.Because CLI output cannot be read by humans.
C.Because APIs remove the need for authentication.
D.Because orchestration software cannot use HTTPS.
AnswerA

This is correct because a northbound API exposes network functions through a structured, software-friendly interface, typically using JSON or XML models. This enables orchestration tools to programmatically query state, push configuration changes, and validate results in a predictable, machine-readable format. Such structured interaction is far more efficient and reliable for automation than screen-scraping or manual commands.

Why this answer

A northbound API is more useful because it is designed for structured software interaction. In practical terms, orchestration systems need predictable data and predictable request methods. Human-readable CLI output is optimized for people, not for stable machine parsing. APIs provide the cleaner contract between the controller and the automation platform.

This is a core programmability idea. Human-readable output is useful for operators, but structured APIs are better for software systems.

Exam trap

A common exam trap is to confuse the usability of CLI output with its suitability for automation. While CLI screens are indeed human-readable and essential for manual network management, they are not designed for software consumption due to inconsistent formatting and lack of structured data. Another trap is to mistakenly believe that APIs remove security requirements like authentication; in fact, APIs enforce strict authentication and authorization to protect network resources.

Misunderstanding these points can lead to incorrect answers that underestimate the importance of structured, secure interfaces in network automation.

Why the other options are wrong

B

This option is incorrect because CLI output is specifically designed to be human-readable; the problem is not readability but the lack of structured data suitable for software parsing.

C

This option is incorrect because APIs still require authentication and authorization to secure network access; they do not remove the need for security controls.

D

This option is incorrect because orchestration software commonly uses HTTPS-based APIs for secure communication; the inability to use HTTPS is not a valid reason for preferring APIs over CLI.

When would these options actually be correct?

B

In a different question asking about the limitations of CLI tools in terms of accessibility for visually impaired users, this option could be correct. If the question focused on the challenges of interpreting CLI output for non-technical users, it could also apply.

C

In a different context, a question might ask about a hypothetical API designed for internal use within a secure network where authentication is not needed due to trusted access. In that scenario, the statement could be considered correct.

D

In a different question that asks about the limitations of orchestration software in environments where only non-secure HTTP is available, option D could be correct. For example, if the question specifies that the orchestration software is designed to operate in a legacy system without HTTPS support, then this option would be valid.

Why candidates pick the wrong answer

B

Students might confuse the verbosity or complexity of CLI output with being unreadable, especially when dealing with large amounts of data. However, the key point is that CLI is human-readable, whereas APIs are machine-readable.

C

Some students might think that because APIs are automated, they bypass security checks. However, automation does not eliminate security; APIs enforce authentication and authorization just like any other interface.

D

Students might confuse northbound APIs with other protocols that do not use HTTPS, or they might think that orchestration software uses only proprietary protocols. However, modern orchestration tools widely adopt HTTPS for its security and ubiquity.

420
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure Root Guard on designated ports, Loop Guard on non-designated ports, and BPDU Guard on PortFast ports, and then recover a port that enters err-disabled state.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Only option A correctly follows the sequence of configuring Root Guard on designated ports, Loop Guard on non-designated ports, BPDU Guard on PortFast ports, then enabling errdisable recovery globally, and finally manually re-enabling the port. Option B assigns Loop Guard to designated ports and Root Guard to non-designated ports, which is incorrect. Option C correctly assigns protections but starts with BPDU Guard, deviating from the specified order.

Option D assigns Root Guard to non-designated ports and Loop Guard to designated ports, which is incorrect.

Exam trap

The exam trap is confusing which protection goes on which port role. Remember: Root Guard protects designated ports from becoming root; Loop Guard protects non-designated ports from becoming forwarding; BPDU Guard protects PortFast ports. Also, recovery order: global first, then interface re-enable.

Why candidates pick the wrong answer

B

Candidates may confuse the port roles for Root Guard and Loop Guard, or think that manual re-enablement should precede global recovery configuration.

C

Candidates might think BPDU Guard should be configured first because it's commonly used, or they may not realize the correct recovery sequence.

D

Candidates often confuse the port roles for Root Guard and Loop Guard, thinking Root Guard protects against loops (which is Loop Guard's function).

421
Matchingeasy

Match the data format to its most accurate characteristic.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Lightweight format commonly used by REST APIs

Markup-style format that uses opening and closing tags

Human-friendly format that relies heavily on indentation

Simple tabular format with comma-separated values

Why these pairings

JSON is lightweight and key-value based, XML uses tags and attributes, YAML relies on indentation, CSV is for tabular data, Protobuf is a binary schema-driven format, and HTML is for web page structure.

Exam trap

Avoid confusing the characteristics of different data formats. Remember that JSON uses key-value pairs, XML uses tags, YAML uses indentation, CSV is tabular, Protobuf is binary, and HTML is for web structure.

When would these options actually be correct?

B

If the question asked 'Which data format is schema-driven and uses tags and attributes?' then XML would be the correct answer.

C

If the question asked 'Which data format uses indentation for structure and is often used for configuration files?', then YAML would be the correct answer.

D

In a question asking 'Which data format is commonly used for exporting spreadsheet data and is characterized by comma-separated values?', CSV would be the correct answer.

Why candidates pick the wrong answer

B

Candidates may confuse XML's schema support (XSD) with binary encoding, or associate 'schema-driven' with structured formats like XML without realizing it's text-based.

C

Candidates may confuse YAML with XML because both are used for data serialization, and they might incorrectly associate tags/attributes with YAML due to lack of familiarity with YAML's syntax.

D

Candidates may confuse CSV with HTML due to both being used in web contexts, or mistakenly think CSV can define page structure because it can be embedded in web pages.

422
Matchingmedium

Match each wireless term to its most accurate meaning.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Centralized platform used to manage access points

Name that identifies the wireless network to clients

Wireless security standard

Protocol associated with AP-to-controller communication

Why these pairings

SSID is the human-readable network name. BSSID is the unique MAC address of an AP radio. ESSID is the same SSID used across multiple APs in an extended network.

Beacons are management frames that advertise the network. Probe requests are sent by clients to find APs. Association is the process of connecting a client to an AP.

Exam trap

Do not confuse SSID with BSSID, Beacon frames, or Association. SSID is simply the network name; the other terms refer to different concepts.

When would these options actually be correct?

B

If the question asked 'What is the BSSID?' or 'Which term refers to the MAC address of an access point's radio?', then this option would be correct.

C

If the question asked 'Which term describes a management frame sent by access points to advertise the network?' then 'Beacon frame' would be correct, but 'SSID' is not a frame.

D

If the question asked 'Match each wireless term to its most accurate meaning' and the term was 'Association' or 'Authentication', then option D's description would be correct for that term.

Why candidates pick the wrong answer

B

Candidates may confuse SSID with BSSID because both are associated with wireless networks and the terms sound similar, leading to a mix-up of their definitions.

C

Candidates confuse the SSID (the name) with the beacon frame that carries it, because the SSID is commonly seen in beacon transmissions.

D

Candidates may confuse the SSID broadcast (which is part of the connection process) with the entire connection process itself, or they may think SSID refers to the act of identifying the network during connection.

423
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure AAA with a RADIUS server and 802.1X port authentication on a Cisco IOS-XE switch.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Start by entering global configuration mode and enabling AAA with 'aaa new-model'. Next, create an authentication method list using 'aaa authentication dot1x default group radius' to define the method for 802.1X. Then, configure the RADIUS server parameters using 'radius-server host' and 'radius-server key' so the switch knows where to send authentication requests; note that the method list can reference the 'radius' group even before the server is specified.

Finally, enable 802.1X system-wide with the global command 'dot1x system-auth-control' to activate 802.1X globally. This order ensures each prerequisite is met before the next step.

Exam trap

A common mistake is omitting the global 'dot1x system-auth-control' command, which is required to enable 802.1X system-wide before configuring interface-level authentication.

424
MCQmedium

A switch interface connected to another switch must carry VLANs 10, 20, and 30 only. Which command best enforces that requirement on the trunk?

A.switchport trunk allowed vlan 10,20,30
B.switchport access vlan 10,20,30
C.switchport mode dynamic auto
D.switchport trunk native vlan 10,20,30
AnswerA

The correct command for a trunk interface is `switchport trunk allowed vlan 10,20,30`; it explicitly defines the allowed VLAN list for IEEE 802.1Q tagging. By specifying only VLANs 10, 20, and 30, the administrator ensures that frames from other VLANs are not forwarded across this trunk, providing precise traffic segmentation between the two switches.

Why this answer

The correct command is the one that explicitly sets the allowed VLAN list on the trunk. In plain language, the administrator wants the inter-switch link to carry only the named VLANs instead of every VLAN by default. Cisco trunks can transport multiple VLANs, but that does not mean every VLAN should always be permitted. Restricting the allowed list supports cleaner design and helps reduce unnecessary VLAN transport.

This is a common CCNA switching task because it distinguishes between creating a trunk and controlling what the trunk actually carries. Simply enabling trunking is not enough when the requirement names exact VLANs. The answer must directly restrict the allowed list rather than change the native VLAN or apply an unrelated access-port command.

Exam trap

A common exam trap is selecting commands that do not correctly restrict VLANs on a trunk. For example, using 'switchport access vlan 10,20,30' is invalid because access ports support only one VLAN. Another trap is confusing the native VLAN setting with allowed VLANs; 'switchport trunk native vlan' only defines the untagged VLAN and does not filter VLANs.

Also, relying on dynamic trunk negotiation commands like 'switchport mode dynamic auto' does not restrict VLANs and can lead to trunks carrying all VLANs by default. These mistakes cause VLAN traffic to flow where it shouldn’t, violating design requirements.

Why the other options are wrong

B

Incorrect because 'switchport access vlan' applies only to access ports and cannot specify multiple VLANs; it does not configure trunk VLANs.

C

Incorrect because 'switchport mode dynamic auto' controls trunk negotiation but does not limit which VLANs are allowed on the trunk.

D

Incorrect because 'switchport trunk native vlan' sets only one native VLAN for untagged traffic and does not restrict the allowed VLAN list.

When would these options actually be correct?

B

In a different scenario where the question asks for the configuration of a switch port that should only allow traffic from a single VLAN, such as 'Which command sets the access VLAN for a port to VLAN 10?' this option would be correct, as it would specify the single VLAN for that access port.

C

In a scenario where the question asks for configuring a switch port to automatically negotiate trunking without specifying VLAN restrictions, 'switchport mode dynamic auto' would be the correct answer. For example, if the question required enabling trunking without VLAN filtering, this command would be appropriate.

D

In a different scenario where the question asks for configuring the native VLAN for untagged traffic on a trunk link, and it specifies that VLAN 10 should be the native VLAN while VLANs 20 and 30 are allowed, then 'switchport trunk native vlan 10' would be the correct command.

Why candidates pick the wrong answer

B

Students might confuse 'access vlan' with 'trunk allowed vlan' because both involve VLAN configuration. The word 'access' might be misinterpreted as allowing access to multiple VLANs, but it is strictly for a single VLAN on an access port.

C

Students may think 'dynamic auto' automatically handles VLANs or that it implies trunking with specific VLANs. However, it only controls trunk negotiation, not the allowed VLAN list.

D

Students might confuse 'native vlan' with 'allowed vlan' because both are trunk-related commands. The word 'native' might be misread as 'allowed', leading to the incorrect assumption that it can specify multiple VLANs.

425
Multi-Selectmedium

Which TWO statements accurately describe Network Address Translation (NAT) types?

Select 2 answers
A.Static NAT creates a fixed one-to-one mapping between a local and global address and is typically used to allow external connectivity to internal servers.
B.Dynamic NAT assigns a public IP from a pool for the duration of a translation, but it does not modify Layer 4 port numbers.
C.PAT only translates TCP packets because it uses port numbers, leaving UDP translation unsupported.
D.Static NAT entries are automatically removed after periods of inactivity to free up public addresses.
E.With PAT, if the public IP address pool is exhausted, new translations fail because PAT requires unique public IPs for each private host.
AnswersA, B

Static NAT builds a permanent one-to-one binding between an inside local address and an inside global address, with no port translation. Because the mapping is fixed and predictable, external hosts can reliably initiate connections to internal servers, which is why it suits inbound service publishing.

Why this answer

Option A is correct because static NAT (also called one-to-one NAT) permanently maps a single private (local) address to a single public (global) address, which is exactly the configuration used to publish internal servers such as web or mail hosts to the Internet. Option B is correct because dynamic NAT draws a public address from a configured pool and creates a temporary one-to-one binding for the duration of the session, and since it operates strictly at Layer 3 it does not rewrite TCP/UDP port numbers (that is the job of PAT/overloading). Option C is wrong because PAT translates both TCP and UDP (and ICMP query IDs), since it multiplexes on any Layer 4 identifier, not TCP alone.

Option D is wrong because static NAT mappings are manually configured and persist until an administrator removes them; they are not aged out by inactivity timers. Option E is wrong because PAT specifically allows many private hosts to share a single public IP by translating source ports, so exhaustion of a public pool is not the failure mode described.

Exam trap

Cisco often tests the misconception that PAT only works with TCP, but in reality PAT supports both TCP and UDP, and the trap here is that candidates confuse PAT's use of port numbers with a protocol limitation.

Why the other options are wrong

C

PAT works with any transport protocol that has port fields—TCP, UDP, and even ICMP through the identifier field.

D

Only dynamic translations (from dynamic NAT or PAT) have idle timeouts; static mappings are permanent.

E

This statement describes dynamic NAT pool exhaustion, not PAT, which uses port multiplexing.

426
MCQmedium

What problem is HSRP designed to solve?

A.Layer 2 switching loops
B.Loss of the default gateway if one router fails
C.Duplicate MAC addresses on trunks
D.Wireless interference
AnswerB

HSRP (Hot Standby Router Protocol) is a Cisco-proprietary First Hop Redundancy Protocol designed to eliminate the single point of failure that a default gateway represents. It allows two or more routers to share a virtual IP address and virtual MAC address, so hosts send traffic to the virtual gateway regardless of which physical router is active. If the active router fails or its upstream link goes down, the standby router assumes the virtual IP/MAC in seconds, preserving seamless connectivity to external networks.

Why this answer

HSRP provides a virtual default gateway so hosts continue forwarding traffic even if one physical gateway router fails.

Exam trap

Avoid confusing HSRP with load balancing or security protocols. Remember, HSRP is about redundancy, not traffic distribution or encryption.

Why the other options are wrong

A

Layer 2 switching loops are prevented by Spanning Tree Protocol (STP), not by HSRP. HSRP operates at Layer 3 to provide default gateway redundancy, not loop prevention.

C

Duplicate MAC addresses on trunks are typically caused by misconfigurations or bridging loops, not by HSRP. HSRP uses a virtual MAC address that is unique and does not cause duplication issues.

D

Wireless interference is a physical layer issue related to radio frequency signals, not something HSRP addresses. HSRP is a Layer 3 redundancy protocol for routers.

When would these options actually be correct?

A

If the exam question asked about protocols designed to prevent Layer 2 issues or improve redundancy at Layer 2, such as STP or Rapid STP, then this option could be correct. For example, a question might ask, 'What protocol is used to prevent Layer 2 switching loops in a network?'

C

In a question asking about protocols or solutions specifically designed to manage or mitigate issues with MAC address conflicts in a switched environment, such as 'What protocol can help resolve duplicate MAC address issues on a trunk link?', option C would be the correct answer.

D

If the exam question asked about protocols or solutions that mitigate wireless network issues, such as interference from other devices or overlapping channels, then this option could be correct in that context.

Why candidates pick the wrong answer

A

Students may confuse HSRP with protocols that handle redundancy at Layer 2, such as STP, because both involve failover scenarios. The term 'redundancy' can be misleading.

C

Because HSRP involves virtual MAC addresses, students might think it could lead to duplicate MACs, but HSRP is designed to avoid this by using a standardized virtual MAC format.

D

Students might associate 'redundancy' with wireless failover, but HSRP is specifically for wired router redundancy, not wireless connectivity issues.

427
Matchingmedium

Match each HTTP method to the most accurate action it commonly represents in REST-style APIs.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Retrieve existing information

Submit or create data

Update or replace an existing resource

Remove a resource

Why these pairings

HTTP methods correspond to CRUD operations in REST: GET for read, POST for create, PUT for full update, PATCH for partial update, DELETE for delete, and HEAD for headers only.

Exam trap

The trap is assuming GET can perform any operation beyond retrieval. Remember that GET must be safe and idempotent; it should never modify or delete resources. Always associate GET with read-only operations.

When would these options actually be correct?

B

If the question asked 'Which HTTP method is used to retrieve a representation of a resource?' then GET would be correct, but the action 'Create a new resource' is incorrect for GET.

C

In a question asking about HTTP methods for a non-RESTful API or a poorly designed system, or if the question specifically asks for the method used to send update data via query parameters (though this is not standard REST).

D

If the question asked about a non-standard or legacy API where a GET request with a specific query parameter (e.g., ?action=delete) triggers deletion, or in a poorly designed API that misuses HTTP methods, then GET could be associated with deletion.

Why candidates pick the wrong answer

B

Candidates may confuse GET with POST due to common misuse in web forms where GET is sometimes used to submit data, or they may not clearly distinguish between HTTP method semantics.

C

Candidates may confuse GET with POST or PUT, or think that sending data in the URL (e.g., /resource?update=value) constitutes an update, overlooking the semantic meaning of HTTP methods.

D

Candidates may confuse the action with the method if they have seen APIs that use GET for deletion via query parameters, or they may not fully understand the standard HTTP method semantics and think any action can be performed with any method.

428
MCQmedium

Why is disabling unused services on network devices considered a sound security practice?

A.Because it reduces unnecessary attack surface and exposure on the device.
B.Because it automatically improves routing convergence.
C.Because it guarantees the device cannot be misconfigured.
D.Because it converts the device into a controller.
AnswerA

Every enabled network service (e.g., HTTP server, SNMP, Telnet, CDP) creates listening ports and daemons that can be probed or exploited. Disabling unused services eliminates those potential entry points, shrinking the attack surface and reducing the device's exposure to malicious traffic or reconnaissance. This aligns with the security principle of least privilege, where only essential functions remain active.

Why this answer

It is considered sound because every enabled service is a potential attack surface or management exposure point. In practical terms, if a service is not needed, leaving it enabled creates unnecessary risk without business value. Reducing what is listening or available on a device helps limit opportunities for misuse or exploitation.

Option B is incorrect because disabling unused services does not affect routing protocol convergence; that is a routing protocol function. Option C is wrong because no single security practice can guarantee the device cannot be misconfigured; misconfiguration remains possible through other means. Option D is nonsensical because disabling services does not turn the device into a controller.

Exam trap

Don't confuse the primary goal of security practices with secondary benefits like performance or compliance.

Why the other options are wrong

B

Disabling unused services does not affect routing convergence, which depends on routing protocols and network topology. Service hardening and routing optimization are separate concerns.

C

Disabling services reduces risk but does not guarantee prevention of misconfiguration; human error can still occur in other settings. Security hardening is a layered approach, not a silver bullet.

D

Disabling services does not change a device's role; a router remains a router, and a switch remains a switch. Converting a device to a controller requires specific software and configuration changes.

When would these options actually be correct?

B

In a question focused on optimizing network performance or improving routing protocols, an option stating that disabling unused services improves routing convergence could be correct if it implies that reducing unnecessary processes allows for faster protocol updates. For example, if the question asked how to enhance routing efficiency by minimizing resource usage, this option could apply.

C

In a question focused on best practices for device configuration management, where the emphasis is on ensuring devices are locked down to prevent any configuration errors, this option could be correct if it stated that disabling services helps prevent misconfigurations by limiting available options.

D

In a question asking about the benefits of enabling specific services on a network device to enhance its role as a controller, option D could be correct. For instance, if the question specifies that enabling certain services is necessary for the device to function as a controller in a network management scenario, then this option would apply.

Why candidates pick the wrong answer

B

Students might think that reducing services frees up CPU or memory, potentially improving routing performance, but convergence is not directly impacted by disabling unused services.

C

The word 'guarantees' might mislead students into thinking that disabling services eliminates all configuration errors, but it only reduces the attack surface.

D

Students might confuse 'disabling services' with 'enabling controller functions' in SDN environments, but these are distinct actions.

429
PBQhard

You are connected to the console of R1, a Cisco router that is part of a larger network. The network operations team uses Ansible to manage configurations. You need to write an Ansible playbook that configures an interface description on R1. The playbook should use the ios_config module.

Hints

  • •The ios_config module uses 'parents' to specify the configuration context.
  • •The playbook should target the correct host group.
  • •Remember to include the YAML front matter.
A.--- - name: Configure interface description hosts: R1 gather_facts: no tasks: - name: Add description to Gi0/0 ios_config: lines: - description Link to Core parents: interface GigabitEthernet0/0
B.--- - name: Configure interface description hosts: R1 gather_facts: no tasks: - name: Add description to Gi0/0 ios_config: lines: - interface GigabitEthernet0/0 - description Link to Core
C.--- - name: Configure interface description hosts: R1 gather_facts: no tasks: - name: Add description to Gi0/0 ios_command: commands: - configure terminal - interface GigabitEthernet0/0 - description Link to Core
D.--- - name: Configure interface description hosts: R1 gather_facts: no tasks: - name: Add description to Gi0/0 ios_config: lines: - description Link to Core parents: GigabitEthernet0/0
AnswerA
solution
! R1
---
- hosts: routers
  gather_facts: no
  tasks:
    - name: Configure interface description
      ios_config:
        lines:
          - description WAN Link
        parents: interface GigabitEthernet0/0

Why this answer

The playbook uses the ios_config module to add the description line under the interface configuration. The 'parents' parameter sets the context to 'interface GigabitEthernet0/0'. The playbook must be saved as a .yml file and run with ansible-playbook.

Exam trap

A common trap is confusing ios_config with ios_command, or incorrectly formatting the 'parents' parameter. Remember that ios_config is for configuration changes and requires the 'parents' parameter to specify the exact command that enters the configuration context, such as 'interface GigabitEthernet0/0'.

Why the other options are wrong

B

The specific factual error: The 'lines' parameter should only contain the configuration commands to be applied under the parent context, not the parent command itself.

C

The specific factual error: The ios_command module does not handle configuration mode properly and is not intended for configuration tasks; it sends commands and returns output without state management.

D

The specific factual error: The 'parents' parameter expects the exact command that enters the configuration context, such as 'interface GigabitEthernet0/0', not just the interface name.

Why candidates pick the wrong answer

B

Candidates might think that including the 'interface' command in the lines list would work, similar to how one would type commands in the CLI sequentially.

C

Candidates might confuse ios_command with ios_config, thinking that any command can be sent via ios_command, including configuration commands.

D

Candidates might assume that the 'parents' parameter only needs the interface name, similar to how some other automation tools might accept abbreviated context identifiers.

430
Multi-Selectmedium

Which two statements accurately describe why SSH is preferred over Telnet for device administration?

Select 2 answers
A.SSH is generally considered the more secure choice for remote CLI administration.
B.Telnet is generally considered less secure for remote device administration.
C.SSH eliminates the need for authentication and authorization policy.
D.Telnet is required before SSH can operate.
E.SSH is used only on wireless controllers and nowhere else.
AnswersA, B

SSH is generally considered the more secure choice for remote CLI administration because it encrypts all traffic, providing data confidentiality and integrity. It also uses cryptographic host keys to authenticate the server, and supports secure password and public-key authentication for the user. These protections make SSH the preferred protocol for managing network devices remotely over untrusted networks.

Why this answer

SSH is preferred because it encrypts all traffic, including authentication credentials, making it secure for remote CLI administration, whereas Telnet transmits data in plaintext and is considered less secure. Option C is incorrect because SSH does not eliminate authentication; it requires authentication and often enforces stronger policies. Option D is false because SSH and Telnet are independent protocols; Telnet is not required for SSH to operate.

Option E is wrong because SSH is used on routers, switches, firewalls, and many other devices, not only wireless controllers.

Exam trap

Don't confuse protocol security features with ease of configuration or performance. Focus on security benefits.

Why the other options are wrong

C

SSH does not eliminate the need for authentication and authorization policies; it only provides a secure transport layer. Network devices still require AAA (Authentication, Authorization, and Accounting) or local username/password configurations to control access.

D

Telnet is not a prerequisite for SSH; they are independent protocols. SSH can be configured and used on a device without Telnet ever being enabled. In fact, many devices have SSH enabled by default while Telnet is disabled for security reasons.

E

SSH is not limited to wireless controllers; it is widely used on routers, switches, firewalls, servers, and many other network devices. It is a universal protocol for secure remote administration across all types of infrastructure.

When would these options actually be correct?

C

If the question were to ask about a hypothetical protocol that provides access without any authentication or authorization requirements, then this option could be correct. For example, a question about a fictional remote access method that operates without security measures would validate this statement.

D

In a different context, a question might ask about the relationship between protocols in a specific network setup where Telnet is used to establish a baseline for understanding SSH's enhancements. In that case, it could be framed that Telnet must be configured first before transitioning to SSH for secure communications.

E

In a question specifically asking about the use of SSH in a wireless networking context, where the focus is solely on wireless controllers, stating that SSH is used only on those devices could be correct if the question explicitly limits the scope to that environment.

Why candidates pick the wrong answer

C

Students might think that encryption alone handles security entirely, overlooking that access control policies are separate from the encryption protocol. The term 'secure' in SSH can be misinterpreted as covering all security aspects.

D

Some might think SSH is an extension or upgrade of Telnet, similar to how HTTPS is related to HTTP. However, SSH is a completely different protocol with its own handshake and encryption mechanisms.

E

A student might have only seen SSH used on wireless controllers in a lab or specific scenario, leading to the incorrect assumption that it is exclusive to those devices. The broad applicability of SSH is often underestimated.

431
Matchingmedium

Drag each automation or API concept from the left to its corresponding description on the right. Not all descriptions are used. Concepts: - Northbound API - Southbound API - JSON - HTTPS

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Application-facing interface to the controller

Controller-facing interface toward managed infrastructure

Structured data format

Secure transport for API communication

Why these pairings

Northbound API: the application-facing interface of an SDN controller, allowing apps to request services. Southbound API: the interface that enables the controller to configure managed devices, such as OpenFlow. JSON: a structured data format using key/value pairs and arrays, lightweight and machine‑friendly.

HTTPS: secure, encrypted transport for API communications, protecting data in transit. Distractors: 'Human-readable serialization format' describes YAML, not JSON or APIs. 'Protocol for network device configuration' might refer to NETCONF or CLI, not HTTPS or the APIs listed.

Exam trap

Be careful not to confuse JSON and YAML: JSON uses brackets and is machine-friendly, while YAML uses indentation and is human-friendly. Also, remember that Ansible uses YAML, not XML.

432
MCQhard

Two OSPF routers connected on an Ethernet link remain in the INIT state. Which issue is the most likely cause?

A.The routers have identical router IDs
B.The routers cannot exchange Hellos bidirectionally on the segment
C.The routers have already reached FULL and are waiting to install routes
D.The routers are using the same OSPF process ID
AnswerB

In OSPF, the INIT state means that a router has received a Hello packet from a neighbor but did not find its own Router ID listed in that Hello, so bidirectional communication is not yet confirmed. This situation often arises from mismatched OSPF network types, incorrect subnet masks, or outbound/inbound Hello filtering on the Ethernet segment. Until both routers see each other's Router IDs in their respective Hello packets, they cannot proceed to 2-WAY and beyond, leaving the adjacency perpetually stuck in INIT.

Why this answer

INIT means a router is seeing Hellos from its neighbor but does not see its own router ID in the neighbor field of received Hellos. A common cause is one-way communication or a mismatched multicast/adjacency problem, often at Layer 2.

Exam trap

A common exam trap is to assume that duplicate router IDs cause routers to remain stuck in the INIT state. While duplicate router IDs do cause adjacency issues, they typically result in different neighbor states or error messages, not the INIT state specifically. Another trap is to think that using the same OSPF process ID on both routers causes adjacency failure; however, the process ID is locally significant and does not affect neighbor formation.

Misinterpreting the INIT state as a sign of routers already being fully adjacent or waiting to install routes is also incorrect, as FULL is a later state. The key is to recognize that INIT indicates one-way Hello communication, often due to Layer 2 or multicast issues.

Why the other options are wrong

A

Duplicate router IDs cause adjacency problems but usually result in neighbor states other than INIT or generate specific error messages. INIT state more commonly indicates one-way Hello communication rather than duplicate router ID issues.

C

Incorrect. FULL is the final OSPF neighbor state indicating full adjacency and route exchange completion. INIT is an early state and does not mean routers are waiting to install routes.

D

Incorrect. The OSPF process ID is locally significant and does not affect neighbor adjacency formation. Using the same or different process IDs on routers does not cause them to remain stuck in the INIT state.

When would these options actually be correct?

A

In a different scenario, if the question asked about OSPF routers failing to establish adjacency due to configuration errors, such as a misconfigured network segment where router IDs are incorrectly set to the same value, this option could be correct. For example, if the routers were on a point-to-point link and the question specified that they could not form a neighbor relationship due to identical router IDs, then this would be valid.

C

In a different scenario where the question states that two OSPF routers are already in the FULL state and are experiencing issues with route installation, this option would be correct, indicating that they are waiting for route updates or processing.

D

In a scenario where the question specifies that two OSPF routers are on different networks but have been configured with the same OSPF process ID, the option would be correct if the question asks about potential issues in establishing OSPF adjacency. In this case, the process ID conflict would prevent proper neighbor formation.

Why candidates pick the wrong answer

A

Students may confuse the symptoms of duplicate router IDs with one-way communication, as both can prevent full adjacency. However, duplicate IDs are detected during the exchange of Database Description packets, not during the Hello phase.

C

Students might think that after reaching FULL, routers wait for a timer to install routes, confusing OSPF with other protocols like EIGRP. However, OSPF installs routes immediately upon reaching FULL.

D

Students often confuse the OSPF process ID with the area ID or autonomous system number, thinking they must match for adjacency. However, only area ID, subnet mask, Hello/dead intervals, and authentication must match.

433
PBQhard

You are connected to R1, a Cisco ISR 4331 router running IOS-XE. Your task is to enable SNMP v2c with community string 'public' (read-only) and 'private' (read-write), and configure SNMP v3 with a user 'admin' using SHA authentication (password 'Cisco123') and AES 128 encryption (password 'Cisco456'). Additionally, configure SNMP traps to be sent to a management server at 203.0.113.10 for both v2c and v3. Finally, enable NetFlow export to a collector at 203.0.113.20, using version 9. Verify your configuration using 'show snmp' and 'show ip cache flow'.

Hints

  • •Remember to apply NetFlow on an interface for traffic capture.
  • •SNMPv3 user requires both auth and priv passwords.
  • •Use 'snmp-server enable traps' before configuring trap hosts.
A.snmp-server community public RO snmp-server community private RW snmp-server user admin v3group v3 auth sha Cisco123 priv aes 128 Cisco456 snmp-server enable traps snmp-server host 203.0.113.10 version 2c public snmp-server host 203.0.113.10 version 3 auth admin ip flow-export destination 203.0.113.20 2055 ip flow-export version 9
B.snmp-server community public snmp-server community private snmp-server user admin v3 auth md5 Cisco123 priv des56 Cisco456 snmp-server enable traps snmp-server host 203.0.113.10 version 2c public snmp-server host 203.0.113.10 version 3 auth admin ip flow-export destination 203.0.113.20 2055 ip flow-export version 9
C.snmp-server community public RO snmp-server community private RW snmp-server user admin v3 auth sha Cisco123 priv aes 128 Cisco456 snmp-server enable traps snmp-server host 203.0.113.10 version 2c private snmp-server host 203.0.113.10 version 3 auth admin ip flow-export destination 203.0.113.20 2055 ip flow-export version 9
D.snmp-server community public RO snmp-server community private RW snmp-server user admin v3 auth sha Cisco123 priv aes 128 Cisco456 snmp-server enable traps snmp-server host 203.0.113.10 version 2c public snmp-server host 203.0.113.10 version 3 auth admin ip flow-export destination 203.0.113.20 2055 ip flow-export version 5
AnswerA
solution
! R1
snmp-server community public RO
snmp-server community private RW
snmp-server user admin v3 auth sha Cisco123 priv aes 128 Cisco456
snmp-server enable traps
snmp-server host 203.0.113.10 version 2c public
snmp-server host 203.0.113.10 version 3 auth admin
ip flow-export destination 203.0.113.20 2055
ip flow-export version 9
interface GigabitEthernet0/1
ip flow ingress
exit

Why this answer

The router lacks SNMP and NetFlow configuration. For SNMP v2c, you must define community strings with 'snmp-server community public RO' and 'snmp-server community private RW'. For SNMP v3, you create a user within a group; the command requires a group name, e.g., 'snmp-server user admin v3group v3 auth sha Cisco123 priv aes 128 Cisco456'.

Traps are enabled and sent to 203.0.113.10 via v2c with the public community and v3 with the admin user. NetFlow export uses version 9 to collector 203.0.113.20. Verification commands show SNMP details and flow cache export settings.

Exam trap

Watch out for common mistakes: using MD5/DES instead of SHA/AES for SNMPv3, forgetting RO/RW keywords on community strings, using the wrong community string for traps, and selecting the wrong NetFlow version. Always verify the exact requirements in the question.

Why the other options are wrong

B

The specific factual error: SNMPv3 user is configured with MD5 and DES instead of SHA and AES 128; community strings are missing RO/RW keywords.

C

The specific factual error: The v2c trap host uses 'private' instead of 'public' community string.

D

The specific factual error: NetFlow export version is set to 5 instead of 9.

Why candidates pick the wrong answer

B

Candidates might pick this because MD5 and DES are older but still commonly seen in legacy configurations, and they may forget to specify RO/RW for community strings.

C

Candidates might pick this because they confuse which community string is used for traps; they may think the read-write community is needed for sending traps.

D

Candidates might pick this because version 5 is still widely used and they may not remember that version 9 is required for template-based export.

434
MCQhard

An EtherChannel should form using LACP between two switches. One side is configured for LACP active, and the other side is configured for LACP active. What is the expected result if the other link settings also match?

A.The EtherChannel should form if the other interface settings are compatible.
B.The channel fails because both sides must be passive.
C.The channel becomes a routed interface automatically.
D.All VLAN tags are removed from the bundle by default.
AnswerA

A valid LACP EtherChannel can form with both switches in active mode because active interfaces actively transmit LACP protocol data units (PDUs) and negotiate the bundle. As long as the physical interface settings (speed, duplex, allowed VLANs, trunk encapsulation, and switchport mode) are consistent on both sides, the channel will come up. The active/active pairing is a standard and robust configuration for dynamic link aggregation.

Why this answer

The EtherChannel should form successfully if the underlying link settings are compatible. LACP active/active is a valid combination, as both switches actively negotiate the bundle. However, the channel does not automatically become a routed interface (option C is incorrect because EtherChannel can operate as Layer 2 or Layer 3 depending on configuration, not automatically due to LACP mode).

Additionally, VLAN tags are not removed by default from the bundle (option D is incorrect; VLAN tagging is preserved based on the switchport mode and allowed VLAN settings). The key troubleshooting point is to ensure that other interface parameters such as speed, duplex, and VLAN settings match across the member ports.

Exam trap

Don't confuse LACP active/active with incompatible settings; they are designed to negotiate successfully.

Why the other options are wrong

B

LACP passive/passive is the pairing that fails to form an EtherChannel because both sides wait for the other to initiate negotiation, resulting in no LACP PDUs being sent. Active/active is a valid and functional combination.

C

LACP operates at Layer 2 and does not change the interface type; the EtherChannel remains a Layer 2 port-channel unless explicitly configured with 'no switchport' or an IP address. The question does not mention any Layer 3 configuration.

D

EtherChannel formation does not alter VLAN tagging; if the interfaces are trunk ports, VLAN tags remain intact. The bundle simply aggregates bandwidth while preserving existing VLAN configurations.

When would these options actually be correct?

B

In a different scenario, if the question stated that both sides were configured for LACP passive, then this option would be correct. The question would need to specify that both switches cannot negotiate the EtherChannel actively, thus requiring one side to be passive for the channel to form.

C

In a different scenario where the question states that the EtherChannel is configured with 'no switchport' command on both ends, indicating that the interfaces are intended to be routed, this option would be correct as the interfaces would indeed become routed interfaces.

D

In a different question, if it asked about a specific configuration where the EtherChannel is set up to operate in a mode that strips VLAN tags, such as when using a specific type of trunking protocol that does not support VLANs, this option would be correct.

Why candidates pick the wrong answer

B

Students may confuse LACP modes with PAgP, where desirable/desirable is needed, or mistakenly think that both sides must be passive for compatibility.

C

Some might think that bundling links automatically creates a routed interface, confusing EtherChannel with features like routed ports or SVI.

D

Test-takers might incorrectly assume that bundling strips VLAN information, perhaps confusing EtherChannel with features like VLAN pruning or access port behavior.

435
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure and recover from a BPDU Guard violation on a PortFast-enabled access port using Cisco IOS-XE CLI commands.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Only Option A correctly lists the steps to configure and manually recover from a BPDU Guard violation on a PortFast-enabled port. Option B is invalid because the command 'clear spanning-tree bpduguard' does not exist; the proper recovery is shutdown/no shutdown. Option C incorrectly applies the global command 'spanning-tree portfast bpduguard default' in interface mode; it should be used in global configuration mode.

Option D includes an unnecessary 'Enter interface configuration mode' step after the global recovery command and does not reflect the correct sequence for automatic recovery.

Exam trap

Confusing the global default command 'spanning-tree portfast bpduguard default' with the interface command 'spanning-tree bpduguard enable'. Also, remember that the 'errdisable recovery cause bpduguard' command is a global configuration command, not a privileged EXEC command.

Why candidates pick the wrong answer

B

Candidates might think that clearing the BPDU guard error is sufficient to recover the port, similar to clearing other error conditions.

C

Candidates may confuse global and interface configuration modes for BPDU Guard, thinking 'default' can be used per interface.

D

Candidates may know about errdisable recovery and think it is the correct manual recovery method, but it is automatic and not part of the manual CLI steps.

436
PBQhard

You are connected to R1. Configure static NAT for a public web server (198.51.100.10 to 192.168.1.10) and PAT for the 192.168.1.0/24 LAN to use interface GigabitEthernet0/1 with overload. The current configuration has misconfigured NAT that prevents both types from working. Identify and fix the issues so that internal hosts can access the internet and external hosts can reach the internal web server.

Network Topology
G0/0192.168.1.1/24G0/1203.0.113.1/30Internal hostsLANR1InternetISP

Hints

  • •Check the NAT direction on each interface: which one faces the internal LAN and which faces the internet?
  • •Look at the ACL in the PAT command — does it match the correct subnet?
  • •The PAT command is missing a keyword that enables port multiplexing.
A.Change interface GigabitEthernet0/1 to 'ip nat outside', add 'overload' to the PAT command, and correct ACL 1 to permit 192.168.1.0 0.0.0.255.
B.Change interface GigabitEthernet0/1 to 'ip nat outside', add 'overload' to the PAT command, and change ACL 1 to permit 192.168.2.0 0.0.0.255.
C.Change interface GigabitEthernet0/1 to 'ip nat inside', add 'overload' to the PAT command, and correct ACL 1 to permit 192.168.1.0 0.0.0.255.
D.Change interface GigabitEthernet0/1 to 'ip nat outside', remove the 'overload' keyword from the PAT command, and correct ACL 1 to permit 192.168.1.0 0.0.0.255.
AnswerA
solution
! R1
configure terminal
interface GigabitEthernet0/1
no ip nat inside
ip nat outside
exit
no ip nat inside source list 1 interface GigabitEthernet0/1
ip nat inside source list 1 interface GigabitEthernet0/1 overload
no access-list 1
access-list 1 permit 192.168.1.0 0.0.0.255
end

Why this answer

Three issues exist: (1) GigabitEthernet0/1 is the outside interface but is configured as 'ip nat inside' — it should be 'ip nat outside'. (2) The PAT command lacks the 'overload' keyword, so it does one-to-one translation instead of port address translation. (3) ACL 1 permits 192.168.2.0/24, but the inside LAN is 192.168.1.0/24 — the ACL must match the correct subnet. Correcting these allows PAT for the LAN and static NAT for the web server.

Exam trap

Watch out for three common traps: (1) Misidentifying inside vs. outside interfaces—the interface facing the public network is always outside. (2) Forgetting the 'overload' keyword for PAT—without it, you get dynamic NAT, not PAT. (3) Using the wrong ACL—the ACL must match the inside network exactly.

Why the other options are wrong

B

The ACL must match the inside network; permitting a different subnet will not translate traffic from the correct LAN.

C

The NAT inside/outside designation is based on the direction of traffic; the interface facing the public network must be outside.

D

Without 'overload', the router will not use port numbers to multiplex multiple inside hosts to a single public IP.

Why candidates pick the wrong answer

B

Candidates may misread the LAN subnet or think the ACL is correct as given.

C

Candidates often confuse inside and outside interfaces, especially when both static NAT and PAT are used.

D

Candidates may think 'overload' is optional or misunderstand its purpose in conserving IP addresses.

437
MCQmedium

Exhibit: A user can ping 8.8.8.8 successfully but cannot browse to www.example.com by name. Which service is the most likely failing component?

A.NTP
B.DNS
C.Syslog
D.CDP
AnswerB

Ping to 8.8.8.8 succeeds because it uses an IP address directly, bypassing any name resolution. Browsing a website normally requires translating a domain name (like www.example.com) into an IP address via DNS queries sent to a configured resolver, typically over UDP/53. If DNS is misconfigured, unreachable, or the resolver is down, the browser cannot resolve the hostname and will report a name resolution failure or server not found, while ICMP ping to a known IP remains unaffected.

Why this answer

If connectivity to an IP address works but name-based access fails, the path is up and the problem is usually name resolution. DNS is the service that translates hostnames into IP addresses.

Exam trap

A common exam trap is assuming that because a user can ping an IP address like 8.8.8.8, all network services are functioning correctly. This leads to mistakenly blaming routing or connectivity issues rather than DNS. Candidates may also confuse NTP or Syslog as affecting web access, but these services do not resolve domain names.

Misunderstanding the role of CDP as a discovery protocol rather than a name resolution service can also cause confusion. The key trap is not recognizing that ping tests IP connectivity but DNS is required for translating domain names to IP addresses.

Why the other options are wrong

A

NTP (Network Time Protocol) synchronizes clocks across network devices but does not impact the ability to resolve domain names or browse websites. Time synchronization issues rarely cause name resolution failures, so NTP is not the failing component here.

C

Syslog collects and stores system logs for monitoring and troubleshooting but does not affect DNS resolution or web browsing. A syslog failure would not prevent browsing by hostname, so it is not the cause.

D

CDP (Cisco Discovery Protocol) is used for discovering directly connected Cisco devices and does not play any role in DNS or web name resolution. CDP failure would not cause inability to browse websites by name.

When would these options actually be correct?

A

In a question where the focus is on time synchronization issues, such as a scenario where a user is unable to authenticate to a time-sensitive application due to incorrect timestamps, NTP would be the correct answer. For example, if a user cannot log into a secure service because their device's clock is out of sync, NTP would be the failing component.

C

If the question were to ask about issues related to logging or monitoring network events, such as 'What service is failing if logs are not being recorded from network devices?', then Syslog would be the correct answer as it directly relates to log management.

D

In a question asking about network topology issues where devices are not discovering each other or communicating effectively due to misconfigured CDP settings, CDP would be the correct answer. For example, if the question stated that devices are unable to identify each other on the same VLAN, CDP would be relevant.

Why candidates pick the wrong answer

A

Students might think that time synchronization is required for secure web browsing (HTTPS) or DNS security extensions, but basic name resolution does not depend on accurate time.

C

Students may confuse syslog with DNS because both are application-layer protocols, but syslog is unrelated to name resolution.

D

Students might think CDP is related to network discovery and could affect connectivity, but it does not impact name resolution.

438
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure a single-area OSPFv2 network on two Cisco routers (R1 and R2) and observe the neighbor state transitions from Down to Full.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First configure OSPF process and router-id on R1, then add the network; repeat on R2; ensure interfaces are up; finally verify neighbor states to see the full transition sequence.

Exam trap

The trap is that candidates might think interfaces must be up before OSPF configuration, or that verification can be done after configuring only one router. The correct sequence ensures both routers are configured before checking neighbor states.

Why candidates pick the wrong answer

B

Candidates might think interfaces must be up before any OSPF configuration, but OSPF can be configured first; the key is that the network command must be present for OSPF to form adjacencies.

C

Candidates might think that interfaces must be up before any OSPF configuration to avoid errors, but OSPF can be configured on down interfaces; the neighbor state will not progress until interfaces are up.

D

Candidates might think that interfaces must be up on R1 before moving to R2, but OSPF configuration on R2 does not depend on R1's interface state; the neighbor state will not form until both sides are configured.

439
Drag & Dropmedium

Drag and drop the following commands into the correct order to configure OSPFv3 for IPv6 on a Cisco router.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Commands must be executed in order: global config, IPv6 routing, interface config, OSPFv3 on interface, then verification.

Exam trap

The most common trap is starting with the OSPFv3 router configuration command without first enabling IPv6 routing globally. Also, candidates may try to apply the interface-level OSPFv3 command before entering interface configuration mode.

440
PBQmedium

You are connected to R1 via console. R1's GigabitEthernet0/0 (10.0.0.1/30) connects to an ISP, and GigabitEthernet0/1 (192.168.1.1/24) connects to the internal LAN. The network administrator needs to monitor R1's system messages. Configure R1 to send syslog messages with severity level 5 (notifications) and above to the syslog server at 10.0.0.2. Also, ensure that logging is enabled and that messages include the timestamp and source interface.

Hints

  • •Use 'logging host' to specify the syslog server.
  • •Set the severity with 'logging trap' using the severity name or number.
  • •Configure the source interface with 'logging source-interface'.
A.logging on logging trap notifications logging source-interface GigabitEthernet0/0 logging host 10.0.0.2 service timestamps log datetime
B.logging on logging trap informational logging source-interface GigabitEthernet0/1 logging host 10.0.0.2 service timestamps log datetime
C.logging on logging trap 5 logging source-interface GigabitEthernet0/0 logging 10.0.0.2 service timestamps
D.logging on logging trap notifications logging source-interface GigabitEthernet0/1 logging host 10.0.0.2 service timestamps debug datetime
AnswerA
solution
! R1
logging host 10.0.0.2
logging trap notifications
logging source-interface GigabitEthernet0/0
logging on
service timestamps log datetime msec

Why this answer

The logging commands enable syslog output. 'logging trap notifications' sets severity to 5 (notifications). 'logging source-interface' ensures syslog messages originate from a consistent IP. 'service timestamps' adds time information to log entries for easier troubleshooting.

Exam trap

Pay close attention to the exact syntax of commands: 'logging host' vs 'logging', 'service timestamps log' vs 'service timestamps debug'. Also, remember that the source interface should be the one closest to the syslog server, not necessarily the LAN interface. Severity levels: emergencies (0) to debugging (7); notifications is level 5.

Why the other options are wrong

B

The specific factual error: The trap level is set too low (informational instead of notifications), and the source interface is incorrect.

C

The specific factual error: The logging host command is missing the 'host' keyword, and the timestamps command is incomplete.

D

The specific factual error: The timestamps command applies to debug messages instead of log messages, and the source interface is wrong.

Why candidates pick the wrong answer

B

Candidates might pick this because they confuse severity levels or think the source interface should be the LAN interface for internal logging.

C

Candidates might pick this because they know numeric severity levels are valid but forget the exact syntax for the logging host command.

D

Candidates might pick this because they confuse 'log' and 'debug' timestamps, or think the source interface should be the LAN interface.

441
MCQhard

A wireless client can associate to the correct corporate SSID and authenticate successfully, but receives an address from the guest network instead of the employee network. Which troubleshooting area is strongest?

A.Incorrect WLAN-to-role or VLAN mapping after successful authentication.
B.The client must be using the wrong subnet mask manually.
C.The AP must be missing PPP encapsulation.
D.The issue is that STP root election failed.
AnswerA

After a wireless client successfully authenticates via methods such as 802.1X, the WLAN controller or lightweight AP maps the client to a VLAN based on the SSID's WLAN profile or RADIUS attributes like Tunnel-Private-Group-ID. If the WLAN is incorrectly bound to a guest VLAN, or the RADIUS server returns a mismatched VLAN ID, the client associates cleanly but receives an IP from the wrong subnet. This exact description matches an incorrect WLAN-to-role or VLAN mapping, which is a common configuration error in enterprise Wi-Fi.

Why this answer

The client successfully authenticates to the corporate SSID but receives an IP address from the guest network, indicating that the authentication phase is working correctly. The issue lies in the post-authentication mapping: the WLAN is likely mapped to the wrong VLAN or role (e.g., a RADIUS server attribute or local VLAN assignment is misconfigured), causing the client to be placed in the guest VLAN instead of the employee VLAN. This is a common misconfiguration in WLAN-to-VLAN or WLAN-to-role mapping after successful 802.1X authentication.

Exam trap

Cisco often tests the distinction between authentication success and post-authentication authorization (VLAN/role mapping), tricking candidates into focusing on DHCP or IP configuration issues when the real problem is the VLAN assignment after authentication.

Why the other options are wrong

B

The client receives an address from the guest network, indicating that the DHCP server or VLAN assignment is incorrect. A manually configured wrong subnet mask would not cause the client to obtain an IP from a different network; it would simply prevent proper communication within the assigned subnet. The issue is at the network assignment level, not a host configuration error.

C

PPP encapsulation is used on serial WAN links, not in wireless LAN environments. Wireless clients connect via 802.11, and APs use Ethernet or CAPWAP to connect to the network. PPP has no role in VLAN assignment or DHCP for wireless clients.

D

STP root election determines the root bridge in a switched network to prevent loops, but it does not affect VLAN assignment for wireless clients. Even if STP root election failed, it would not cause a client to receive an IP from the wrong network; it would more likely cause network instability or loops.

When would these options actually be correct?

B

In a different scenario, if a question specified that a client is unable to connect to any network and is manually configured with an incorrect subnet mask, this option could be correct. For example, if a client is set to a subnet mask that does not match the network's addressing scheme, it would fail to communicate with the intended network.

C

In a different scenario where the question involves a wireless client that cannot connect to the network at all, and the troubleshooting focuses on link-layer protocols, a question could ask about issues related to PPP encapsulation. If a client is unable to establish a connection due to misconfigured PPP settings, this option would be correct.

D

In a different scenario, if the question involved a network where multiple VLANs are interconnected and STP is misconfigured, leading to network loops or blocked ports, then a failure in STP root election could cause devices to lose connectivity or receive incorrect IP addresses from unintended VLANs.

Why candidates pick the wrong answer

B

Students often think of IP configuration issues when a client gets an unexpected address, but the scenario describes successful association and authentication, pointing to a network-side mapping problem rather than a client-side manual setting.

C

PPP is a common topic in CCNA, and students might confuse it with other encapsulation protocols or think it applies to wireless connections. However, it is irrelevant to WLAN client-to-VLAN mapping.

D

STP is a fundamental switching concept, and students might incorrectly associate any network issue with STP. However, the symptom of wrong IP subnet assignment is clearly a VLAN mapping problem, not a spanning-tree issue.

442
Multi-Selecthard

A switch interface connected to a Cisco IP phone with a PC behind it must carry voice and data correctly. Which two switchport commands are appropriate on that access port?

Select 2 answers
A.switchport mode trunk
B.switchport access vlan 10
C.switchport voice vlan 20
D.channel-group 1 mode active
E.spanning-tree cost 1
AnswersB, C

The 'switchport access vlan 10' command sets the port's untagged VLAN for data frames, which is exactly how the connected PC should be carried. In the standard Cisco IP phone topology, the phone passes PC traffic through untagged while tagging its own voice frames on a separate VLAN. Assigning access VLAN 10 ensures the PC's traffic is placed in the correct data VLAN.

Why this answer

The access VLAN carries the workstation data traffic, and the voice VLAN carries tagged voice traffic for the IP phone. That is the standard campus switchport design for a phone with a PC behind it. The port itself remains an access port, but the two most directly relevant commands here are the access VLAN and voice VLAN assignments.

Exam trap

Don't confuse trunk mode with the need for VLAN tagging; access ports can handle both data and voice VLANs without being trunks.

Why the other options are wrong

A

Configuring an access port as a trunk would cause the switch to expect 802.1Q tagging on all frames, but the PC behind the phone typically sends untagged frames. This would break connectivity for the PC unless the phone is configured to tag PC traffic, which is not standard.

D

The channel-group command is used to create an EtherChannel, which bundles multiple physical links into a single logical link. This is not relevant for a single access port connecting to an IP phone and PC, as there is only one physical link.

E

The spanning-tree cost command manually sets the STP path cost for a port, which is used for loop prevention. It does not affect VLAN assignment or voice/data separation, so it does not address the requirement of carrying voice and data correctly.

When would these options actually be correct?

A

In a scenario where the question specifies a need for a switch port to connect multiple VLANs for devices such as multiple IP phones or a mix of voice and data traffic across different VLANs, 'switchport mode trunk' would be the correct command to enable trunking.

D

In a different scenario where the question asks about configuring a switch port for an EtherChannel setup that aggregates multiple links for redundancy and increased bandwidth, 'channel-group 1 mode active' would be appropriate to enable LACP (Link Aggregation Control Protocol) for the EtherChannel.

E

In a scenario where the exam question asks about optimizing Spanning Tree Protocol settings for a specific port, and the focus is on adjusting port costs to influence path selection in a redundant network topology, this command could be correct.

Why candidates pick the wrong answer

A

Students might think that because the IP phone uses a tagged VLAN, the port must be a trunk. However, Cisco IP phones use a special voice VLAN feature on access ports, not a full trunk.

D

Students might confuse the need for additional bandwidth or redundancy on a user port, but EtherChannel is typically used on uplinks or server connections, not on edge ports.

E

Students might think that adjusting STP cost is necessary for voice traffic to ensure fast convergence, but this is not a standard configuration for IP phone ports. Voice VLAN and QoS are the primary concerns.

443
PBQhard

You are connected to R1. Configure SNMPv3 with authentication (SHA) and encryption (AES-128) for user 'monitor' in group 'AdminGroup', and also configure SNMPv2c read-only community string 'cisco123' to send traps to the management server at 192.0.2.100. Additionally, configure NetFlow on interface GigabitEthernet0/0 to export flow data to 198.51.100.50 using version 9. Verify your configuration using the appropriate show commands.

Network Topology
G0/010.0.0.1/30G0/010.0.0.2/30linkG0/1203.0.113.1/30G0/1203.0.113.2/30linkR1R2R3

Hints

  • •SNMPv3 requires a view before creating the group.
  • •Remember to enable NetFlow on the interface in both ingress and egress directions.
  • •The SNMPv2c community string must be configured before the trap host can reference it.
A.snmp-server group AdminGroup v3 priv read AdminView; snmp-server user monitor AdminGroup v3 auth sha cisco123 priv aes 128 cisco123; snmp-server community cisco123 ro; snmp-server host 192.0.2.100 traps version 2c cisco123; interface GigabitEthernet0/0; ip flow-export destination 198.51.100.50 9996; ip flow-export version 9; ip flow ingress
B.snmp-server group AdminGroup v3 auth read AdminView; snmp-server user monitor AdminGroup v3 auth sha cisco123 priv aes 128 cisco123; snmp-server community cisco123 ro; snmp-server host 192.0.2.100 traps version 2c cisco123; interface GigabitEthernet0/0; ip flow-export destination 198.51.100.50 9996; ip flow-export version 9; ip flow ingress
C.snmp-server group AdminGroup v3 priv read AdminView; snmp-server user monitor AdminGroup v3 auth sha cisco123 priv des 56 cisco123; snmp-server community cisco123 ro; snmp-server host 192.0.2.100 traps version 2c cisco123; interface GigabitEthernet0/0; ip flow-export destination 198.51.100.50 9996; ip flow-export version 9; ip flow ingress
D.snmp-server group AdminGroup v3 priv read AdminView; snmp-server user monitor AdminGroup v3 auth sha cisco123 priv aes 128 cisco123; snmp-server community cisco123 ro; snmp-server host 192.0.2.100 traps version 2c cisco123; interface GigabitEthernet0/0; ip flow-export destination 198.51.100.50 9996; ip flow-export version 5; ip flow ingress
AnswerA
solution
! R1
snmp-server group AdminGroup v3 priv read AdminView
snmp-server view AdminView iso included
snmp-server user monitor AdminGroup v3 auth sha cisco123 priv aes 128 cisco123
snmp-server community cisco123 RO
snmp-server host 192.0.2.100 version 2c cisco123
snmp-server enable traps
interface GigabitEthernet0/0
ip flow ingress
ip flow egress
exit
ip flow-export destination 198.51.100.50 2055
ip flow-export version 9

Why this answer

The configuration was missing SNMPv3 user, group, and trap settings. We added the SNMPv3 user 'monitor' with SHA authentication and AES-128 encryption, created a view and group 'AdminGroup' with read access, and configured the SNMPv2c community string 'cisco123' for read-only access. We also enabled SNMP traps to the manager at 192.0.2.100 and configured NetFlow on GigabitEthernet0/0 to export to 198.51.100.50 using version 9.

Verification commands show the SNMP configuration and NetFlow flow cache.

Exam trap

Pay close attention to the exact security requirements: 'priv' for encryption, AES-128 specifically, and NetFlow version 9. The exam often tests subtle differences between 'auth' and 'priv' levels, encryption algorithms, and NetFlow versions.

Why the other options are wrong

B

The group level 'auth' does not permit encryption; 'priv' is required for AES-128 encryption.

C

The encryption algorithm specified is DES (56-bit) instead of AES-128.

D

NetFlow export version is 5, not 9 as required.

Why candidates pick the wrong answer

B

Candidates may confuse 'auth' and 'priv' levels, thinking 'auth' includes encryption, but 'auth' only requires authentication, while 'priv' requires both authentication and encryption.

C

Candidates might default to DES because it is an older standard or confuse the encryption types. However, AES-128 is the specified requirement.

D

Candidates may be more familiar with NetFlow version 5 or forget to specify version 9. Version 5 is still commonly used but does not meet the requirement.

444
MCQhard

R1 and R2 are directly connected and running OSPF. The IP addressing is correct and both routers are in area 0, but they do not form an adjacency. What is the most likely cause?

A.The OSPF MTU values do not match on the connected interfaces.
B.The routers must use identical hostnames before OSPF can form neighbors.
C.The routers must use VLAN 1 for OSPF to operate.
D.The interfaces need to be configured as trunks instead of routed ports.
AnswerA

When OSPF neighbors exchange Database Description (DD) packets, each packet includes an interface MTU field. If the MTU values differ, the receiving router detects a mismatch and drops the DD packet, leaving the adjacency stuck in the ExStart or Exchange state. This prevents the routers from completing the database synchronization process, so the OSPF neighbor relationship cannot come up.

Why this answer

The most likely cause is an MTU mismatch between the two interfaces. During the OSPF database exchange process, neighbors must agree on the MTU value to successfully exchange DBD packets; a mismatch typically causes the adjacency to become stuck in the ExStart or Exchange state. Basic connectivity (e.g., ping) often still works because ICMP packets are small, but the OSPF adjacency fails due to the MTU discrepancy.

Exam trap

Don't overlook MTU settings when OSPF adjacency issues arise, especially when basic connectivity is confirmed.

Why the other options are wrong

B

OSPF neighbor formation does not depend on hostnames; it relies on matching parameters such as area ID, authentication, hello/dead intervals, and network type. Hostnames are only used for local identification and do not affect OSPF adjacency.

C

OSPF can operate over any VLAN or routed interface; there is no requirement to use VLAN 1. The adjacency issue is unrelated to VLAN numbering, and OSPF works independently of VLAN assignments on routed ports.

D

OSPF is designed to run on routed interfaces (Layer 3 interfaces) and does not require trunking. Trunk ports are used for carrying multiple VLANs between switches, not for OSPF adjacency between routers.

When would these options actually be correct?

B

In a different scenario where the question specifies that OSPF adjacency formation is contingent upon matching router configurations, including hostnames for identification purposes in a lab setup, this option could be correct.

C

In a different scenario where the question specifies that OSPF is only configured to operate on VLAN 1, and both routers are incorrectly configured on different VLANs, this option would be correct. The question would need to emphasize that OSPF requires VLAN 1 for adjacency.

D

In a different scenario where the question specifies that OSPF is being used in a network with VLANs and requires trunking for inter-VLAN routing, this option could be correct. For example, if the question states that OSPF must be configured on trunk interfaces to communicate between different VLANs, then this option would apply.

Why candidates pick the wrong answer

B

Students might confuse the requirement for matching OSPF router IDs (which are typically IP addresses) with hostnames, or they may think that consistent naming is necessary for network protocols to communicate.

C

Some might think that VLAN 1 is the default VLAN and therefore necessary for routing protocols, but this is incorrect because OSPF runs at Layer 3 and does not depend on specific VLANs.

D

Test-takers may confuse the need for trunking in switch-to-switch connections with router-to-router connections, or they may think that OSPF requires a specific encapsulation like dot1q, which is not true for point-to-point links.

445
MCQhard

A wireless client associates to an AP and successfully authenticates to the correct SSID, but it does not obtain an IP address. The WLC is running in local mode. What should the technician do next?

A.Check the DHCP server to ensure it has available leases.
B.Verify the AP’s operating channel for interference.
C.Verify the VLAN mapping on the WLC for the client’s WLAN.
D.Verify the WPA3 PSK on the client.
AnswerC

In local mode, the WLC bridges client traffic to a specified VLAN. An incorrect or missing VLAN ID prevents the DHCP discovery from reaching the DHCP server. This step directly confirms whether the client’s traffic is placed on the correct subnet.

Why this answer

When a wireless client authenticates to the SSID but fails to obtain an IP address, the most likely cause is a VLAN mapping mismatch on the WLC. In local mode, the WLC maps the WLAN to a specific VLAN (via the interface or VLAN tag), and if that VLAN does not have a DHCP relay or is not trunked to the correct switch, the client's DHCP requests will never reach the DHCP server. This is a common Layer 2 connectivity issue that prevents IP address assignment even though authentication succeeds.

Exam trap

Cisco often tests the misconception that DHCP issues are always server-side (Option A), when in reality the WLC's VLAN-to-interface mapping is a critical Layer 2 configuration that must be verified first in a wireless context.

Why the other options are wrong

A

Troubleshooting at Layer 3 (IP) before verifying Layer 2 (VLAN) connectivity skips a fundamental step in the OSI model.

B

Confuses a Layer 1 problem with a Layer 2/3 problem. The client’s association proves the RF link is functional.

D

This investigates a condition that has already been ruled out (authentication succeeded) and does not address the IP assignment failure.

446
Multi-Selectmedium

Which two statements accurately describe why APIs and human-oriented CLIs are both still useful in network operations?

Select 2 answers
A.APIs are useful for structured, repeatable software-driven interaction.
B.CLIs are still useful for direct human troubleshooting and inspection.
C.APIs make all CLIs obsolete in every situation.
D.CLIs are only useful for configuring initial device settings and cannot be used for monitoring.
E.Neither interface should ever return structured data.
AnswersA, B

APIs (e.g., RESTCONF, NETCONF, or vendor REST APIs) provide machine-readable structured data (JSON/XML) and standardized operations that enable deterministic, repeatable automation. Unlike human-typed CLI commands, API calls can be idempotent, scripted, and integrated with CI/CD pipelines, making them ideal for configuration management, telemetry collection, and orchestration at scale. This is why they are foundational to software-defined networking and DevOps practices.

Why this answer

APIs and CLIs are both useful because they serve different operational strengths. In practical terms, APIs are better for repeatable software interaction and structured automation, while CLIs remain valuable for direct human troubleshooting and ad hoc inspection. Mature environments often use both depending on the task.

This is not an either-or question. It is about fit for purpose.

Exam trap

Don't assume one technology is replacing the other; understand their complementary roles.

Why the other options are wrong

C

This statement is incorrect because CLIs remain essential for tasks that require human judgment, such as debugging complex issues, interactive configuration, and learning device behavior. APIs complement but do not replace CLIs, as many operational scenarios benefit from direct human interaction.

D

This is incorrect because CLIs are widely used for monitoring, troubleshooting, and ad-hoc inspection beyond initial configuration.

E

This statement is incorrect because structured data (e.g., JSON, XML) is commonly returned by both APIs and modern CLIs (e.g., via 'show' commands with formatting options) to facilitate machine parsing and automation. Returning structured data is a best practice for integrating network devices with management systems.

When would these options actually be correct?

C

If the exam question asked about the evolution of network interfaces and their relevance in modern environments, stating that APIs have rendered CLIs obsolete could be correct if framed in a context where automation is prioritized over manual troubleshooting.

D

In a question specifically asking about the use of CLIs in wireless networking environments, where the context is limited to wireless devices, this statement could be correct if it highlights that CLIs are primarily utilized in that specific scenario.

E

In a different question context that asks whether APIs and CLIs should never return structured data, this option could be correct if the question is framed around a specific scenario where unstructured data is the only valid output format, such as legacy systems that do not support structured responses.

Why candidates pick the wrong answer

C

Students might think that because APIs enable automation, they can fully replace manual CLI usage, overlooking the need for human intuition and flexibility in troubleshooting and ad-hoc operations.

D

A test-taker might confuse the limited CLI on wireless clients with the broader use of CLIs in network operations, or mistakenly think that wireless devices are the primary CLI users due to their prevalence in small networks.

E

Students might believe that CLIs should only return human-readable text and that structured data is exclusive to APIs, not realizing that many CLIs now support structured output to bridge the gap between human and machine interaction.

447
MCQmedium

Why is route summarization often useful at distribution or area boundaries in larger networks?

A.It reduces the number of route advertisements by combining multiple specific prefixes
B.It forces all users into the same VLAN
C.It automatically encrypts routing protocols
D.It removes the need for IP addressing
AnswerA

At distribution or area boundaries, route summarisation aggregates multiple specific prefixes into a single, less specific advertisement, directly reducing the number of entries in the routing table and the volume of link-state or distance-vector updates. This satisfies the constraint of limiting control-plane overhead across the boundary, as fewer advertisements mean less processing and bandwidth consumption on routers at the summarisation point.

Why this answer

Route summarization is useful there because it reduces the number of specific prefixes that must be advertised upstream or across boundaries. In plain language, instead of sending many small route entries, the network can often advertise one broader summary that represents them collectively. This helps control routing-table growth and can make the design more scalable and easier to manage.

Summarization does not eliminate the need for routing detail inside the local area, but it can simplify what needs to be shared outward. That is why it is especially valuable at aggregation points such as distribution layers or area boundaries.

Exam trap

A common exam trap is selecting options that confuse route summarization with unrelated networking concepts such as VLAN design or encryption. For example, option B incorrectly states that summarization forces all users into the same VLAN, which is false because VLANs are Layer 2 constructs unrelated to routing summarization. Option C mistakenly associates summarization with automatic encryption of routing protocols, which is incorrect since encryption is a separate security feature.

Option D wrongly claims summarization removes the need for IP addressing, which is impossible because routing depends on IP addresses. Understanding that summarization only aggregates routing prefixes without altering VLANs, encryption, or IP addressing is essential to avoid these traps.

Why the other options are wrong

B

Incorrect because route summarization is a routing concept and does not influence VLAN membership or force users into the same VLAN, which is a Layer 2 function.

C

Incorrect because route summarization does not provide encryption; encryption of routing protocols is a separate security feature unrelated to summarization.

D

Incorrect because summarization does not remove the need for IP addressing; routing depends on IP addresses to forward packets correctly.

When would these options actually be correct?

B

In a different question asking about VLAN configurations, if the question were to focus on how to manage broadcast domains effectively in a large network, option B could be correct. For example, if the question stated, 'What method can be used to ensure all devices in a large organization are in the same broadcast domain?' then forcing users into the same VLAN would be the right answer.

C

In a question asking about the security features of routing protocols, such as 'Which of the following enhances the security of routing information?' option C could be correct if it referred to a protocol that includes built-in encryption mechanisms, like OSPF with IPsec.

D

In a question asking about the benefits of a network design that eliminates the need for IP addressing entirely, such as in a theoretical or highly abstract scenario involving a completely different routing paradigm, option D could be considered correct.

Why candidates pick the wrong answer

B

Students might confuse summarization with network segmentation or grouping, mistakenly thinking it consolidates users into a single broadcast domain, similar to how VLANs group users.

C

The term 'summarization' might be misassociated with security features, or students may think that reducing routing updates inherently secures them, but encryption is a distinct function.

D

Students might think that because summarization reduces the number of routes, it also reduces the need for IP addresses, but IP addresses are still required for each host and interface.

448
MCQhard

A router learns 192.168.30.0/24 from OSPF and also has a static route to 192.168.30.0/24 with administrative distance 200. Which route is installed in the routing table while both are available?

A.The OSPF route
B.The static route
C.Both routes equally for load balancing
D.Neither route, because they conflict
AnswerA

OSPF has a default administrative distance of 110, while the static route was configured with an administrative distance of 200. Cisco routers always prefer the route with the lowest AD, so the OSPF route is installed in the routing table as the best path to 192.168.30.0/24. This is why the OSPF route is selected over the static route.

Why this answer

The OSPF route is installed because its default administrative distance of 110 is lower than the static route’s configured administrative distance of 200. In practical terms, the static route has been intentionally made a backup. It is present in the configuration, but it does not become active while the lower-distance OSPF route is healthy.

This is a classic floating-static design question. The important point is that route-source preference depends on administrative distance when the prefix length is the same.

Exam trap

A common exam trap is assuming that static routes always take precedence over dynamic routes because their default administrative distance is 1. In this question, the static route’s administrative distance is manually set to 200, which is higher than OSPF’s default 110. Many candidates mistakenly select the static route, overlooking that a higher administrative distance means lower preference.

This trap tests your understanding that administrative distance values can be adjusted to create floating static routes that serve as backups rather than primary routes.

Why the other options are wrong

B

Incorrect because the static route has a higher administrative distance (200) than OSPF (110), making it less preferred and preventing it from being installed while the OSPF route is available.

C

Incorrect because routers do not install multiple routes with different administrative distances to the same prefix simultaneously; only the route with the lowest administrative distance is installed.

D

Incorrect because routers can and do choose one preferred route when multiple routes to the same prefix exist; conflicting routes do not cause both to be rejected.

When would these options actually be correct?

B

In a different scenario where the static route to 192.168.30.0/24 has an administrative distance lower than OSPF (e.g., 90), the static route would be installed in the routing table instead of the OSPF route.

C

In a different scenario where both routes have the same administrative distance and the router is configured to allow equal-cost multi-path (ECMP) routing, both routes could be installed for load balancing. For example, if both routes had an administrative distance of 110, the router would use both for traffic distribution.

D

In a different scenario where both routes have the same administrative distance, and the router cannot determine a preferred route due to a configuration error or miscommunication, the question could state that neither route is installed due to a conflict in routing protocols.

Why candidates pick the wrong answer

B

Students may think that static routes always take precedence over dynamic routes, but that is only true when the static route uses the default AD of 1. Here, the static route's AD is explicitly set to 200, making it less preferred.

C

Students might confuse this with equal-cost multipath (ECMP) where multiple routes with the same AD and metric are used for load balancing. However, here the AD values differ, so ECMP does not apply.

D

Students may think that having two routes to the same network causes a conflict or error, but routing protocols handle this by preferring the route with the lower AD. The router does not reject both routes.

449
MCQhard

A network administrator recently configured BPDU Guard on all access ports of a switch to protect against rogue switches. After the change, users in VLAN 10 report intermittent connectivity issues and frequent link flaps. The administrator checks the switch and notices that several ports are in an err-disabled state. What is the most likely cause of the problem?

A.Root Guard is preventing the port from becoming a root port.
B.BPDU Guard is enabled on access ports that are receiving BPDUs, causing the ports to go into err-disabled state.
C.Loop Guard has detected a unidirectional link and placed the port into err-disabled state.
D.BPDU Guard is globally enabled but not configured on the interface, so the port is err-disabled due to a BPDU received.
AnswerB

BPDU Guard is a security feature that intentionally places a PortFast-enabled access port into err-disabled when any BPDU is received, protecting against rogue switches attempting to participate in spanning tree. When an unauthorized device sends BPDUs, the switch immediately disables the port and logs an error, requiring an administrator to manually re-enable it or rely on errdisable recovery. This matches the scenario where access ports receiving BPDUs are error-disabled.

Why this answer

BPDU Guard is configured to protect against rogue switches by placing a port into an err-disabled state upon receiving a BPDU. In this scenario, BPDU Guard is enabled on access ports that are receiving BPDUs (possibly from a rogue switch or misconfiguration), causing the ports to err-disable and flap. PortFast is not required for BPDU Guard to function; the issue is that BPDUs are being received on ports that are not expected to receive them.

The intermittent connectivity occurs as ports cycle into err-disabled and are re-enabled.

Exam trap

A common mistake is believing BPDU Guard requires PortFast to function; in reality, BPDU Guard can be enabled per-interface without PortFast and will err-disable the port when a BPDU is received.

Why the other options are wrong

A

Root Guard prevents a port from becoming a root port by placing it in a root-inconsistent state, not err-disabled. It does not cause link flaps or err-disable ports.

C

Loop Guard prevents alternate or root ports from becoming designated in the absence of BPDUs, but it does not err-disable ports. It places ports in a loop-inconsistent state, which is not err-disabled.

D

The global 'spanning-tree portfast bpduguard default' command only applies BPDU Guard to PortFast-enabled ports. If a port receives a BPDU and is not PortFast, it will not be err-disabled by this global command. The scenario states BPDU Guard was configured on all access ports, implying interface-level configuration.

Why candidates pick the wrong answer

A

Students may confuse Root Guard with BPDU Guard because both are STP security features, and the term 'guard' suggests protection, leading to the assumption that it could cause err-disable.

C

Loop Guard also deals with BPDU issues and can cause port blocking, so students might mistakenly think it causes err-disable, especially since both features are related to STP protection.

D

Students may not fully understand the difference between global and interface BPDU Guard configuration, and might think global application alone can cause err-disable on any port receiving a BPDU.

450
MCQhard

A branch office needs four subnets from the 192.168.50.0/24 network, with each subnet supporting up to 50 hosts. Which prefix length should be used for each subnet?

A./25
B./26
C./27
D./28
AnswerB

A /26 prefix borrows 2 host bits from the /24, yielding 4 equal-sized subnets (2^2 = 4), each with 62 usable addresses (2^6 - 2 = 62). This exactly meets the branch office requirement for four subnets while providing sufficient host capacity for typical devices. The subnet mask 255.255.255.192 is the correct choice.

Why this answer

Each subnet must support at least 50 hosts, so /26 is the smallest suitable prefix because it provides 62 usable addresses. A /24 can be split into exactly four /26 subnets.

Exam trap

A frequent exam trap is selecting a subnet mask that provides enough hosts but not enough subnets, or vice versa. For instance, choosing /25 seems tempting because it supports 126 hosts, which exceeds the 50-host requirement. However, /25 only creates two subnets from a /24, which fails the requirement for four subnets.

Another trap is picking /27, which creates enough subnets but only supports 30 hosts, insufficient for 50 hosts per subnet. Candidates must carefully balance subnet count and host capacity to avoid these pitfalls.

Why the other options are wrong

A

/25 provides 126 usable hosts per subnet, which is more than enough for 50 hosts, but it only creates two subnets from a /24 network. Since four subnets are required, /25 is insufficient for subnet count.

C

/27 creates eight subnets from a /24, which is enough subnets, but each subnet only supports 30 usable hosts. This is less than the required 50 hosts, so /27 is not suitable.

D

/28 creates sixteen subnets but only supports 14 usable hosts per subnet, which is far below the 50-host requirement. Therefore, /28 is not a valid option.

When would these options actually be correct?

A

In a scenario where a network engineer needs to create two subnets from a /24 network, each supporting up to 126 hosts, option A (/25) would be correct. This would allow for two subnets, each with sufficient capacity for a larger number of hosts than required.

C

In a scenario where the requirement is to create subnets for a network that only needs to support up to 30 hosts each, such as a small office with limited devices, /27 would be the correct choice as it allows for 30 usable addresses per subnet.

D

In a different scenario where a network administrator needs to create multiple subnets for a small office with a maximum of 14 hosts each, using the 192.168.50.0/24 network, a /28 subnet would be appropriate as it allows for 16 IP addresses, accommodating the host requirement.

Why candidates pick the wrong answer

A

Students might choose /25 because it provides more than enough hosts per subnet (126 usable addresses) and they may overlook the requirement for exactly four subnets, focusing only on the host count.

C

Students might choose /27 because it can create more than four subnets, and they may incorrectly assume that more subnets are better or forget to verify the host capacity per subnet.

D

Students might choose /28 if they focus solely on the number of subnets (16 subnets easily exceeds the requirement of four) without considering the host capacity per subnet, or they may confuse the host calculation with a different prefix length.

Page 5

Page 6 of 20

Page 7