Courseiva

CCNA 200-301 v2 (200-301) — Questions 451–525

1450 questions total · 20pages · All types, answers revealed

Page 6

Page 7 of 20

Page 8
451
Multi-Selectmedium

Which TWO of the following are valid interpretations of errors seen in the output of the 'show interface' command?

Select 2 answers
A.CRC errors indicate that frames were received with an invalid checksum, often due to cabling issues.
B.Runts are frames that are larger than the maximum allowed size.
C.Giants are frames that are smaller than 64 bytes.
D.Input errors include runts, giants, CRC errors, and frame errors.
E.Flaps indicate that the interface is physically disconnected.
AnswersA, D

A CRC error means the Ethernet frame's frame check sequence (FCS) computed at the receiver does not match the value transmitted, indicating corruption during transit. This is commonly caused by faulty cabling, bad connectors, electromagnetic interference, or a marginal transceiver, rather than by a software issue. CRC errors may also be accompanied by alignment errors if the corruption shifts bit boundaries, pointing further to a physical-layer problem.

Why this answer

CRC errors (option A) indicate frames with an invalid checksum, often due to cabling issues, which is correct. Option D is also correct: 'Input errors' is a cumulative counter that includes runts, giants, CRC errors, and frame errors. Option B is wrong because runts are frames smaller than 64 bytes, not larger.

Option C is wrong because giants are frames larger than the maximum allowed size (typically 1518 bytes), not smaller than 64 bytes. Option E is wrong because 'flaps' refer to an interface going up and down repeatedly, not necessarily physically disconnected; it could be due to duplex mismatch or other reasons.

Exam trap

Cisco often tests the exact byte thresholds for runts (less than 64 bytes) and giants (greater than 1518 bytes), and candidates frequently reverse these values or confuse them with other error types.

Why the other options are wrong

B

Runts are frames smaller than 64 bytes, not larger than the maximum size.

C

Giants are frames larger than the maximum allowed size (typically 1518 bytes), not smaller than 64 bytes.

E

Flaps indicate an interface repeatedly transitioning between up and down states, not necessarily a physical disconnection.

Why candidates pick the wrong answer

B

Students may confuse 'runts' with 'giants' due to the opposite-sounding names, or assume 'runts' refers to something undersized but incorrectly think it means oversized.

C

The terms 'runts' and 'giants' are easily confused because they are opposites; a student might mistakenly swap their definitions.

E

The term 'flap' might be interpreted as a single change in state (like a flap of a wing), but in networking it specifically implies repeated transitions.

452
PBQhard

You are connected to R1. The network administrator wants to permit only HTTPS traffic (TCP port 443) from the 192.0.2.0/24 network to the 203.0.113.0/24 network, while denying all other IP traffic. Currently, an ACL applied inbound on G0/1 is blocking all traffic, including HTTPS. Identify the issue and correct the ACL configuration so that only HTTPS traffic is permitted.

Network Topology
G0/1192.0.2.1/24linkG0/1203.0.113.1/24InternetR1R2

Hints

  • •The ACL is currently blocking all traffic because of the deny any any entry.
  • •You need to remove the existing ACL and recreate it with a permit statement for HTTPS.
  • •Remember the implicit deny at the end of every ACL; you don't need an explicit deny statement.
A.Remove the existing ACL, then create an extended ACL with a permit statement for tcp 192.0.2.0 0.0.0.255 203.0.113.0 0.0.0.255 eq 443, and apply it inbound on G0/1.
B.Add a permit statement for tcp 192.0.2.0 0.0.0.255 203.0.113.0 0.0.0.255 eq 443 before the existing deny ip any any entry in the ACL.
C.Remove the existing ACL and create a standard ACL with permit 192.0.2.0 0.0.0.255, then apply it inbound on G0/1.
D.Remove the existing ACL and create an extended ACL with a permit statement for tcp any any eq 443, then apply it inbound on G0/1.
AnswerA
solution
! R1
configure terminal
no ip access-list extended BLOCK_IN
ip access-list extended BLOCK_IN
permit tcp 192.0.2.0 0.0.0.255 203.0.113.0 0.0.0.255 eq 443
end
write memory

Why this answer

The ACL BLOCK_IN currently has a single deny ip any any entry, which blocks all traffic inbound on G0/1. The correct solution is to first remove the existing ACL, then create a new extended ACL that permits TCP 443 from source network 192.0.2.0/24 to destination network 203.0.113.0/24, and apply it inbound on G0/1. The implicit deny at the end of the ACL will then block all other traffic, achieving the desired policy.

Exam trap

The exam trap is that candidates may think adding a permit statement before the deny will work, but if they add a new entry without specifying a sequence number, it is inserted after the existing deny ip any any, so the deny remains first and blocks all traffic.

Why the other options are wrong

B

The specific factual error is that the order of entries matters; a deny any any at the end would block all traffic, but here it is placed before the permit, so the deny is evaluated first.

C

The specific factual error is that standard ACLs lack the capability to filter by protocol or port; extended ACLs are required for such granularity.

D

The specific factual error is that the permit statement uses 'any' for source and destination, making it too permissive and not matching the specified networks.

Why candidates pick the wrong answer

B

Candidates might think that adding a permit statement before the deny will override it, but they overlook that the deny ip any any matches all traffic and will be hit first if placed before the permit.

C

Candidates might confuse standard and extended ACL capabilities, thinking a standard ACL can filter by port if applied correctly.

D

Candidates might focus only on the port number and forget to specify the source and destination networks, leading to an overly broad permit.

453
MCQhard

A router receives two routes to 10.50.0.0/16: one from OSPF and one static route with an administrative distance of 90. Which route is installed by default?

A.The static route, because its administrative distance is lower than OSPF's
B.The OSPF route, because dynamic routes always override static routes
C.Both routes, because equal destination networks always load-balance
D.Neither route, because the destinations overlap
AnswerA

The static route is correct because its administrative distance is 90, which is lower than OSPF's default of 110. The router compares administrative distance values when multiple routing sources advertise the same prefix, and it installs the route with the lowest AD in the routing table. Since 90 is less than 110, the static route is preferred over the OSPF route.

Why this answer

By default, the static route with administrative distance 90 is installed because it is preferred over the OSPF route with default administrative distance 110. In plain language, the router is being told that the manually configured route is more trustworthy than the OSPF-learned one, so it chooses the static path first. The protocol type alone does not decide the outcome. Administrative distance is the key comparison when two different route sources offer the same destination prefix length.

This is a classic routing-selection question because many learners incorrectly assume OSPF always wins over static routes unless the static route uses the default administrative distance. Once the static route is given a value lower than OSPF’s 110, it becomes the preferred path unless a more specific route exists elsewhere.

Exam trap

A frequent exam trap is assuming that dynamic routing protocols like OSPF always override static routes regardless of administrative distance. Many candidates mistakenly believe that static routes only win if they use the default AD of 1. However, if a static route is manually assigned an AD lower than OSPF's default 110, it becomes the preferred route.

This misunderstanding leads to incorrect answers because the exam tests knowledge of how administrative distance influences route selection, not just the routing protocol type. Remember, the router always chooses the route with the lowest administrative distance, even if it is a static route with a custom AD.

Why the other options are wrong

B

Incorrect. Dynamic routes do not always override static routes; route preference depends on administrative distance, not just whether a route is dynamic or static.

C

Incorrect. Equal destination networks do not automatically cause load balancing if the routes have different administrative distances; only routes with equal AD and metrics are load-balanced.

D

Incorrect. Overlapping destinations from different sources are common and do not prevent route installation; the router uses administrative distance to choose the preferred route.

When would these options actually be correct?

B

If the question stated that the OSPF route had a lower administrative distance than the static route, or if it specified that the static route was not installed due to a configuration issue, then this option would be correct.

C

In a different scenario where both the OSPF route and static route have the same administrative distance, a question could ask which routes would be installed if load balancing is enabled. In that case, both routes could be installed for the same destination network.

D

If the question stated that both routes had the same administrative distance and were configured to not allow overlapping routes, then this option would be correct. For example, if the router was configured to only accept one route for a specific destination and the routes were set to be mutually exclusive.

Why candidates pick the wrong answer

B

Students may mistakenly believe that dynamic routing protocols always override static routes due to their adaptive nature, but in Cisco IOS, static routes have a lower default AD (1) unless manually changed, and here the static route's AD is explicitly set to 90, which is still lower than OSPF's 110.

C

Students might think that any two routes to the same network will be load-balanced, but Cisco routers require equal AD and metric for load balancing across equal-cost paths. Different routing sources typically have different ADs, preventing load balancing.

D

A student might confuse overlapping routes with conflicting routes that cause routing loops or ambiguity, but in this case, the routes are identical in prefix length, so the router simply picks the best one based on AD.

454
Multi-Selectmedium

Which TWO statements about network automation tools are true?

Select 2 answers
A.Ansible uses an agentless architecture and communicates with network devices over SSH by default.
B.Python is a general-purpose programming language often used with libraries like Netmiko and NAPALM to automate network tasks.
C.Puppet and Chef both use a push-based model where the master server initiates configuration changes on managed nodes.
D.Chef playbooks are written in YAML, while Ansible uses a Ruby-based DSL for defining desired state.
E.Ansible requires an agent to be installed on managed network devices, while Puppet does not.
AnswersA, B

Ansible operates without any persistent agent installed on the target device. Instead, the Ansible controller connects over SSH (or other supported connection methods like NETCONF for network devices) and executes a transient module that performs the required task, then cleans up after itself. This agentless design simplifies initial setup and avoids compatibility issues with device firmware.

Why this answer

Ansible is agentless, meaning it does not require any software installed on managed network devices. It connects to devices over SSH by default (or API for some platforms) and pushes configuration modules directly, making it lightweight and easy to deploy in network environments.

Exam trap

Cisco often tests the confusion between push-based and pull-based models, as well as which tools use agents versus agentless architectures, to catch candidates who memorize buzzwords without understanding the underlying communication patterns.

Why the other options are wrong

C

Ansible is the tool known for push-based orchestration; Puppet and Chef rely on agent-initiated pull cycles.

D

Mixing up the DSL/language associations: Ansible = YAML, Chef = Ruby, Puppet = Puppet DSL (declarative).

E

This error stems from confusing the agentless nature of Ansible with the agent-based architecture of Puppet/Chef.

455
MCQhard

A router has routes to 192.168.0.0/16 and 192.168.100.0/24. Which route is used for traffic to 192.168.100.77?

A.192.168.0.0/16
B.192.168.100.0/24
C.Both routes are discarded because they overlap.
D.The default route is preferred if present.
AnswerB

The route 192.168.100.0/24 is selected because it has a longer prefix length (24 bits) than 192.168.0.0/16, and routers use the most specific matching prefix (longest prefix match) to forward traffic. For destination 192.168.100.77, the /24 route provides a more precise match, satisfying the constraint of optimal path selection based on subnet mask length.

Why this answer

The route to 192.168.100.0/24 is used because it is more specific. In plain language, even though the /16 route covers a large address range that includes the destination, the /24 route describes the destination network more precisely. Longest-prefix match therefore prefers the /24.

This is a basic but critical routing-table concept. The router does not choose the broader route when a narrower one matches the same destination.

Exam trap

A frequent exam trap is to select the broader route 192.168.0.0/16 because it seems to cover more addresses, including the destination. Candidates may mistakenly think that a larger subnet mask means a better route or that overlapping routes cause the router to discard both. However, Cisco routers always prefer the most specific route based on the longest-prefix match rule.

Overlapping routes are normal and do not cause discarding; instead, the router uses the route with the longest subnet mask. Misunderstanding this can lead to incorrect answers and confusion about routing behavior.

Why the other options are wrong

A

192.168.0.0/16 is a less specific route covering a larger address range. Although it includes 192.168.100.77, it is not chosen because a more specific route exists. Selecting this ignores the longest-prefix match rule.

C

Both routes are not discarded because overlapping routes are common in routing tables. The router uses the longest-prefix match to select the best route, so discarding overlapping routes is incorrect.

D

The default route is only preferred if no specific matching route exists. Since both 192.168.0.0/16 and 192.168.100.0/24 match the destination, the router chooses the more specific /24 route, not the default.

When would these options actually be correct?

A

In a scenario where the question specifies that the router is configured to prefer the less specific route for some reason, such as a policy-based routing configuration that prioritizes broader networks, then 192.168.0.0/16 could be the correct answer.

C

In a scenario where a router has conflicting routes to the same destination but with different subnet masks, and the router is configured to discard overlapping routes due to administrative policies, this option would be correct. For example, if a question stated that both routes were configured with the same administrative distance and the router was set to ignore overlapping routes, then this answer would apply.

D

In a different scenario where the router has no specific routes for the destination IP and only a default route is configured, the default route would be used for traffic to 192.168.100.77, making this option correct.

Why candidates pick the wrong answer

A

Students might think that because 192.168.100.77 falls within the 192.168.0.0/16 range, this route would be used. However, they overlook the principle of longest prefix match, which gives priority to the more specific /24 route.

C

Some students may incorrectly believe that overlapping prefixes cause conflicts or errors, leading to route discarding. In reality, routers handle overlapping routes gracefully by preferring the most specific one.

D

Students might think that the default route is always preferred or that it overrides specific routes. In fact, the default route has the lowest priority and is only a last resort.

456
Matchingmedium

Match each basic IPv4 concept to its most accurate role.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Defines network versus host portions of the address

Next hop used for off-subnet traffic

Address used to reach all hosts in the local broadcast domain

Address identifying an individual device in the subnet

Why these pairings

An IP address uniquely identifies a device on an IP network. A subnet mask separates the network and host portions of an IP address, enabling devices to determine if a destination is local or remote. A default gateway is the router IP that forwards traffic to other networks when the destination is not on the local subnet.

A DNS server translates domain names into IP addresses, allowing devices to reach websites by name.

Exam trap

Do not confuse the subnet mask's role with that of the default gateway. The subnet mask helps identify the network, while the default gateway enables communication outside the local subnet.

457
Matchingmedium

Match each IPv6 address type or concept to its most accurate description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

IPv6 address type used for wider routed communication

IPv6 address type used only on the local segment

Address used by a device to refer to itself

Method for deriving an interface identifier from a MAC address

Why these pairings

Each IPv6 address type has a distinct purpose: Global Unicast for public routing, Link-Local for local segment, Unique Local for private site, Multicast for group communication, Anycast for nearest device, and SLAAC for stateless address assignment.

Exam trap

The most common trap is confusing the scope of Link-Local and Unique Local addresses. Remember: Link-Local is only for the local link, while Unique Local is for private site-wide use but not internet-routable. Also, don't confuse multicast with unicast.

When would these options actually be correct?

B

This option would be correct if the question asked: 'Which IPv6 address type is automatically assigned on each interface, used for neighbor discovery, and is not routable beyond the local link?'

C

In a question asking for an IPv6 address type that is globally unique but not intended for public routing, such as 'Which IPv6 address type is globally unique but limited to private networks?' Unique Local would be correct.

D

A question asking: 'Which IPv6 address type is used for one-to-many communication, where a single packet is sent to multiple destinations?' would make Multicast the correct answer.

Why candidates pick the wrong answer

B

Candidates may confuse 'link-local' with 'local' and assume it can be used within the entire enterprise, similar to how IPv4 private addresses work, not realizing link-local is strictly single-link.

C

Candidates may confuse 'unique' with 'globally unique and routable,' incorrectly assuming Unique Local addresses function like Global Unicast addresses.

D

Candidates may confuse multicast with unicast, or think 'multi' implies multiple hosts in a one-to-one context, misunderstanding the one-to-many nature of multicast.

458
MCQmedium

Why is NTP especially valuable when a network uses centralized Syslog servers?

A.Because synchronized clocks make log timestamps easier to correlate across devices
B.Because NTP converts Syslog into a routing protocol
C.Because NTP automatically creates DHCP pools
D.Because NTP eliminates the need for a Syslog server
AnswerA

When all network devices reference the same authoritative NTP source, their log timestamps are expressed in the same time scale, so an administrator can accurately sequence events across routers, switches, and firewalls during troubleshooting. Centralized log correlation depends on consistent timestamps; without NTP, even devices with identical configurations can drift, making a single incident appear to happen at different times or in the wrong order. NTP therefore makes centralized logging meaningful by providing a common temporal reference.

Why this answer

NTP is especially valuable because centralized logs are much easier to interpret when device clocks are synchronized. In plain language, if multiple routers and switches send messages to one logging server but each device believes a different time, the event sequence becomes confusing. NTP helps align those clocks so the timestamps in the logs are consistent and the team can reconstruct incidents more accurately.

This is a practical operations concept rather than a syntax question. Syslog solves the collection problem, and NTP solves the time-correlation problem. Together they make logs more useful than either one alone. That is why the best answer focuses on timestamp consistency rather than on routing, VLAN, or NAT behavior.

Exam trap

A common exam trap is selecting an answer that incorrectly attributes routing or DHCP functions to NTP, such as thinking NTP converts Syslog into a routing protocol or automatically creates DHCP pools. These options confuse NTP’s fundamental role in time synchronization with unrelated network services. Another trap is assuming NTP eliminates the need for a Syslog server, which is false because NTP only provides accurate timestamps; it does not collect or store logs.

Understanding that NTP’s value lies in timestamp consistency, not in changing or replacing other protocols, is critical to avoid these mistakes.

Why the other options are wrong

B

Incorrect because NTP does not convert Syslog into a routing protocol; NTP’s function is strictly time synchronization, unrelated to routing protocols.

C

Incorrect because NTP does not create DHCP pools; DHCP pool creation is unrelated to time synchronization and is managed by DHCP services.

D

Incorrect because NTP does not eliminate the need for a Syslog server; it complements Syslog by providing accurate timestamps but does not replace log collection.

When would these options actually be correct?

B

In a hypothetical exam question asking about the integration of Syslog with routing protocols, if it stated that NTP enhances the functionality of Syslog by enabling time-stamped logging for routing updates, then option B could be correct in that context.

C

If the exam question asked about a protocol that manages IP address allocation and network configuration, such as DHCP, then this option could be correct in that context. For instance, a question could ask which protocol is responsible for dynamically assigning IP addresses to devices on a network.

D

In a question that asks about the benefits of NTP in a network where logging is not required or where all devices operate independently without centralized logging, stating that NTP eliminates the need for a Syslog server could be correct.

Why candidates pick the wrong answer

B

Students might confuse the term 'protocol' and think NTP can convert one protocol into another, or they may mistakenly believe that NTP integrates with Syslog to change its format.

C

A student might associate NTP with automatic configuration or think that time synchronization is needed for DHCP lease times, but NTP does not create DHCP pools.

D

A test-taker might think that because NTP improves log accuracy, it somehow makes the Syslog server unnecessary, confusing correlation with elimination.

459
MCQmedium

A network administrator is configuring DHCP snooping on a Cisco Catalyst switch. The switch has a trunk port Gi1/0/24 connecting to another switch, and several access ports connecting to end-user PCs. The administrator issues the commands 'ip dhcp snooping', 'ip dhcp snooping vlan 10', and then configures interface Gi1/0/24 with 'ip dhcp snooping trust'. A PC connected to Gi1/0/5 (an untrusted port) sends a DHCPDISCOVER. What will the switch do with this DHCPDISCOVER message?

A.Drop the DHCPDISCOVER because only trusted ports can send DHCP messages.
B.Forward the DHCPDISCOVER to trusted ports only, and drop any DHCPOFFER received on untrusted ports.
C.Forward the DHCPDISCOVER to all ports in VLAN 10, including untrusted access ports.
D.Convert the untrusted port to a trusted port automatically after receiving the first DHCPDISCOVER.
AnswerB

With DHCP snooping enabled on VLAN 10, the switch treats Gi1/0/5 as untrusted by default. It allows client-originated DHCPDISCOVER messages to be forwarded toward trusted ports (such as the uplink to the DHCP server) but blocks DHCP server replies like DHCPOFFER on untrusted ports. This prevents rogue DHCP servers on access ports while permitting legitimate client requests.

Why this answer

When DHCP snooping is enabled on a VLAN, switch ports are untrusted by default. Client DHCP messages such as DHCPDISCOVER are allowed from untrusted ports and forwarded toward trusted ports. Server messages such as DHCPOFFER, DHCPACK, and DHCPNAK are dropped if received on untrusted ports.

Trusting the uplink port allows legitimate server replies to enter the switch while blocking rogue DHCP servers on access ports.

Exam trap

The trap here is assuming that untrusted ports cannot send any DHCP messages, when in fact they can send client-originated requests but cannot receive server replies.

460
MCQhard

A wireless client joins the correct SSID and gets an address in the correct employee subnet, but cannot reach only one internal application while everything else works. Which troubleshooting area is the strongest first target?

A.The path or policy specific to that application, since general employee connectivity already works.
B.The SSID broadcast setting, because the client must not be joined correctly.
C.The voice VLAN on the wired access port connected to the AP uplink.
D.The OSPF router ID on the client device.
AnswerA

The client has already associated to the correct SSID, authenticated, and received a valid IP address from the expected subnet, proving that the WLAN and general network path are functional. Since other employees can connect and general connectivity works, the failure is isolated to application-specific transport, such as traffic filtering rules, access control lists, firewall policies, or per-application VPN/proxy configurations. Therefore, troubleshooting should focus on the path and policies that govern that particular application.

Why this answer

The strongest first target is the application path or policy specific to that application because the client already has general connectivity: it joined the correct SSID, authenticated, and obtained an IP address in the employee subnet. A failure limited to one internal application indicates that basic WLAN join, DHCP, and overall routing are working; therefore, ACLs, firewall rules, DNS resolution for that service, or application-specific policies are the likely cause. Option B (SSID broadcast setting) is irrelevant because the client successfully joined the SSID and has connectivity.

Option C (voice VLAN on the wired access port) is not a first target because the symptom involves a single data application, not voice, and the client is on the employee subnet, not a voice VLAN. Option D (OSPF router ID on the client) is invalid because client devices do not typically run OSPF; OSPF runs on routers, not wireless clients.

Exam trap

Avoid restarting troubleshooting from basic connectivity steps when the problem is isolated to a specific application.

Why the other options are wrong

B

The client has already joined the correct SSID, authenticated, and received an IP address in the correct subnet, so the SSID broadcast setting is not the issue. The problem is specific to one application, not general connectivity.

C

The voice VLAN on the AP uplink is used for VoIP traffic, not for general data applications. Since the client can access other internal resources, the issue is not related to the AP uplink configuration.

D

OSPF router IDs are used by routers in OSPF routing, not by end-client devices. Clients do not run OSPF, so this is irrelevant to the problem.

When would these options actually be correct?

B

In a different scenario where a client cannot connect to any SSID and fails to obtain an IP address, a question might ask about connectivity issues. In that case, troubleshooting the SSID broadcast setting would be appropriate to ensure the client can see and join the network.

C

If the question stated that multiple applications were inaccessible or that the client was experiencing issues with general network connectivity, then investigating the voice VLAN on the wired access port could be relevant. This would indicate a broader network issue affecting multiple services.

D

In a different question, if a client device is unable to communicate with any network resources and the issue is suspected to be related to routing, asking about the OSPF router ID could be relevant. For instance, if the question states that the client is on a subnet that should be reachable but isn't, then the OSPF configuration could be the focus.

Why candidates pick the wrong answer

B

Students might think that SSID broadcast issues could cause partial connectivity, but the client's successful association and IP address assignment rule out this possibility.

C

A test-taker might confuse the voice VLAN with general data VLANs or think that AP uplink issues could affect specific applications, but the symptom of single-application failure points elsewhere.

D

Students might mistakenly think that OSPF is involved in internal application connectivity, but OSPF is a routing protocol for routers, not for client devices.

461
PBQmedium

You are connected to SW1 via console. SW1 is a Layer 2 switch with two ports (G0/1 and G0/2) connected to a host. The host should be able to send and receive traffic on VLAN 10 and VLAN 20. Configure the two ports as a trunk link to the host, but ensure that the trunk only carries VLANs 10 and 20, and set the native VLAN to VLAN 99.

Network Topology
G0/1, G0/2HostSW1

Hints

  • •Use the 'switchport trunk allowed vlan' command to restrict which VLANs are carried.
  • •The native VLAN must match on both ends of the trunk.
A.interface range gigabitethernet0/1-2 switchport mode trunk switchport trunk allowed vlan 10,20 switchport trunk native vlan 99
B.interface range gigabitethernet0/1-2 switchport mode trunk switchport trunk allowed vlan 10-20 switchport trunk native vlan 99
C.interface range gigabitethernet0/1-2 switchport mode trunk switchport trunk allowed vlan 10,20 switchport native vlan 99
D.interface range gigabitethernet0/1-2 switchport mode trunk switchport trunk allowed vlan 10,20 switchport trunk native vlan 1
AnswerA
solution
! SW1
interface gigabitethernet0/1
switchport mode trunk
switchport trunk allowed vlan 10,20
switchport trunk native vlan 99
interface gigabitethernet0/2
switchport mode trunk
switchport trunk allowed vlan 10,20
switchport trunk native vlan 99

Why this answer

The correct configuration sets the ports as trunk, restricts allowed VLANs to exactly 10 and 20 with 'switchport trunk allowed vlan 10,20', and sets the native VLAN to 99 with 'switchport trunk native vlan 99'. This matches every requirement in the question: trunk mode, only VLANs 10 and 20 carried, native VLAN 99.

Exam trap

The trap here is confusing the allowed VLAN list syntax — candidates often pick '10-20' thinking it means '10 and 20', when it actually permits every VLAN in that range.

Why the other options are wrong

B

The specific factual error is using a range (10-20) instead of a list (10,20), which includes unintended VLANs.

C

The specific factual error is omitting the 'trunk' keyword in the native VLAN command, which is required for trunk ports.

D

The specific factual error is setting the native VLAN to 1 instead of 99, which does not meet the requirement.

Why candidates pick the wrong answer

B

Candidates might think the hyphen means 'and' and includes only the specified VLANs, but in Cisco IOS, a hyphen indicates a range.

C

Candidates may think 'switchport native vlan' is sufficient, but on a trunk port, the full command is 'switchport trunk native vlan'.

D

Candidates might forget to change the native VLAN from the default (VLAN 1) or assume it doesn't matter, but the question explicitly requires VLAN 99.

462
PBQhard

You are troubleshooting a PC connected to switch SW1. The PC cannot access the internet. SW1 is connected to router R1 via port G0/1. R1 provides default gateway and DHCP services. Analyze the provided show output and fix the connectivity issue so that the PC can ping 8.8.8.8. === Show output from R1 === <pre> R1# show ip interface brief Interface IP-Address OK? Method Status Protocol GigabitEthernet0/0 unassigned YES manual administratively down down GigabitEthernet0/1 10.0.0.1 YES NVRAM up up </pre> === Show output from PC === <pre> C:\> ipconfig Ethernet adapter Ethernet0: Connection-specific DNS Suffix . : IPv4 Address. . . . . . . . . . : 169.254.123.45 Subnet Mask . . . . . . . . . . : 255.255.0.0 Default Gateway . . . . . . . . : </pre> === Show output from SW1 === <pre> SW1# show vlan brief VLAN Name Status Ports ---- -------------------------------- --------- ------------------------------- 1 default active Gi0/1, Gi0/2, Gi0/3 </pre>

Network Topology
G0/1G0/2G0/1G0/0SW1PC1R1

Hints

  • •Check if R1's interface connected to SW1 has an IP address.
  • •The DHCP pool expects the default gateway to be on the same subnet as the clients.
  • •APIPA address means the PC did not receive a DHCP offer.
A.Configure R1's interface G0/0 with IP address 192.168.1.1/24 and ensure the interface is not administratively down.
B.Change the VLAN on SW1's port G0/2 to VLAN 10 and configure R1's subinterface G0/0.10 with IP 192.168.1.1/24.
C.Enable DHCP snooping on SW1 and configure the port G0/2 as a trusted port.
D.Configure a static IP address of 192.168.1.10/24 on the PC with default gateway 192.168.1.1.
AnswerA
solution
! R1
interface gigabitethernet0/0
ip address 192.168.1.1 255.255.255.0
no shutdown

Why this answer

The PC's APIPA address (169.254.x.x) indicates DHCP failure. The router's DHCP pool is correctly configured and has a lease, but the show output reveals that R1's interface G0/0 is administratively down and has no IP address. Without a working IP on G0/0, the router cannot serve DHCP or route traffic for VLAN 1, even though both the PC and the router are in the same VLAN.

Option A fixes the root cause by assigning the correct subnet IP and bringing the interface up. Option B is incorrect because moving the PC to a different VLAN or creating subinterfaces does nothing to enable the router's physical interface where DHCP and routing must run. Option C is wrong because DHCP snooping or trust configurations are irrelevant when the router's own interface is down/unaddressed.

Option D is a workaround that only masks the problem; the scenario requires a working DHCP service, and a static IP would not restore the intended design.

Exam trap

This question tests your ability to identify that a router interface must have an IP address in the client subnet for DHCP to work, even if the DHCP pool is correctly configured. Many candidates focus on VLANs or DHCP server settings but overlook the basic requirement of an IP address on the router interface.

Why the other options are wrong

B

Changing VLANs or using subinterfaces does not solve the problem because the router's physical interface must be up and have an IP address to serve the VLAN.

C

Enabling DHCP snooping or trust settings on the switch cannot fix a router interface that is administratively down and unassigned.

D

Assigning a static IP to the PC circumvents but does not resolve the root issue of the router's interface being down, and the scenario requires DHCP.

Why candidates pick the wrong answer

B

Candidates might think that DHCP requires a different subnet or VLAN, or they may confuse this scenario with router-on-a-stick configurations where subinterfaces are used for inter-VLAN routing.

C

Candidates may think that DHCP snooping is required to allow DHCP traffic across switches, or they may confuse this with scenarios where DHCP is failing due to rogue servers or untrusted ports.

D

Candidates might think that since DHCP failed, a static IP is a quick fix. However, they overlook that the router interface is not configured, so the default gateway would be unreachable.

463
MCQhard

A routing table contains these entries for the same destination space: 10.1.0.0/16, 10.1.10.0/24, and 0.0.0.0/0. Which route is used for traffic to 10.1.10.44?

A.10.1.0.0/16
B.10.1.10.0/24
C.0.0.0.0/0
D.No route, because the entries overlap
AnswerB

Longest prefix match governs route selection: the /24 mask is more specific than the /16 and the default route, so 10.1.10.0/24 wins. Traffic to 10.1.10.44 falls inside that subnet, making it the chosen next hop regardless of the other entries.

Why this answer

The 10.1.10.0/24 route is used because it is the most specific matching prefix. In plain language, even though the /16 route and the default route could also match, the /24 route describes the destination range more precisely. Longest-prefix match therefore selects the /24 entry.

This is a foundational route-selection rule. The default route remains important as a fallback, but it is not used when more specific routes exist. Likewise, the /16 route is less specific than the /24, so it loses for this destination.

Exam trap

A frequent exam trap is selecting the less specific route (10.1.0.0/16) or the default route (0.0.0.0/0) for the destination 10.1.10.44. Candidates might mistakenly believe that overlapping routes cause conflicts or that the default route overrides specific routes. However, Cisco routers always apply the longest-prefix match rule, choosing the most specific subnet mask that fits the destination IP.

Overlapping routes do not cause routing failures; instead, they provide multiple options where the router picks the best match. Misunderstanding this can lead to incorrect answers and confusion about routing behavior.

Why the other options are wrong

A

The 10.1.0.0/16 route is less specific than the 10.1.10.0/24 route. Although it matches the destination IP, the router prefers the more specific /24 prefix, so this option is incorrect.

C

The 0.0.0.0/0 default route is only used when no other specific route matches the destination. Since both /16 and /24 routes match, the default route is not chosen here, so this option is incorrect.

D

Overlapping routes like 10.1.0.0/16 and 10.1.10.0/24 are common and do not prevent routing. The router resolves overlaps by selecting the longest prefix, so this option is incorrect.

When would these options actually be correct?

A

In a different scenario where the routing table only includes the entry 10.1.0.0/16 and no more specific routes for 10.1.10.0/24, the 10.1.0.0/16 route would be the correct answer for traffic to 10.1.10.44, as it would be the only available route.

C

In a different scenario where the routing table only contains the default route 0.0.0.0/0 and no other specific routes, any traffic, including to 10.1.10.44, would be directed through this default route. A question could specify that no other routes exist.

D

In a different scenario where the routing table entries are configured incorrectly or the router is set to reject overlapping routes, a question could ask what happens when two routes overlap, leading to confusion about which route is used. In such a case, if the question specified that overlapping routes are not allowed, this option could be correct.

Why candidates pick the wrong answer

A

Students might think that since 10.1.10.44 falls within the 10.1.0.0/16 range, the /16 route would be used, but they overlook the more specific /24 route.

C

Students may confuse the default route as a catch-all that overrides other routes, but it is actually the least preferred route and only used as a last resort.

D

Students might think that overlapping routes create ambiguity or errors, but routers are designed to handle overlapping prefixes using the longest prefix match algorithm.

464
Multi-Selectmedium

Which three options correctly describe how a router processes a packet destined for a remote network? (Choose three.)

Select 3 answers
.It decrements the Time-to-Live (TTL) field in the IP header.
.It performs a lookup in the routing table for the destination IP address.
.It rewrites the source and destination MAC addresses for the next hop.
.It replaces the source IP address with its own outgoing interface IP.
.It sends an ARP request for every destination IP address in the packet.
.It encapsulates the entire packet in a new Layer 2 frame with the original MAC addresses.

Why this answer

When a router forwards a packet to a remote network, it first decrements the Time-to-Live (TTL) field in the IP header to prevent infinite loops. It then performs a routing table lookup for the destination IP address to determine the next-hop interface and IP. Finally, it rewrites the source and destination MAC addresses for the next hop, because MAC addresses are only relevant on the local link and must be updated at each Layer 3 hop.

Exam trap

Cisco often tests the distinction between Layer 2 (MAC) and Layer 3 (IP) header changes, so the trap here is that candidates mistakenly think the source IP address is rewritten at each hop, confusing routing with NAT or PAT.

465
Matchingeasy

Match each common network device or concept to its primary role.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Forwards traffic between networks

Forwards local traffic inside a LAN

Applies permit/deny policy to traffic

Provides wireless connectivity

Why these pairings

Router routes between networks; switch forwards within LAN; hub repeats signals; firewall filters traffic; AP provides Wi-Fi; modem converts digital to analog for WAN.

Exam trap

Be careful not to confuse the functions of routers and switches, as both forward traffic but at different layers. Also, remember that a home 'router' often includes a switch, AP, and modem, but the primary role of a router is routing between networks.

When would these options actually be correct?

B

This option would be correct if the question asked to match devices to roles in a reversed or intentionally mislabeled scenario, such as 'Match each device to its secondary or less common function' or in a trick question where the roles are deliberately swapped to test knowledge of incorrect pairings.

C

In a question asking to match devices to secondary or less common functions, such as 'Match each device to a possible secondary role in a network,' where options are intentionally mismatched to test deeper knowledge. For example, a router can filter traffic via ACLs, a switch can repeat signals in a broadcast domain, a hub can route in a very basic sense if it's a layer 3 hub, a firewall can forward within a LAN if configured as a transparent firewall, an AP can convert digital to analog in the RF domain, and a modem can provide Wi-Fi if it's a gateway.

D

In a question asking to match devices to their secondary or less common functions, such as 'Match each device to a possible secondary role,' where Router could provide Wi-Fi in a home router, Switch could convert digital to analog if it includes a modem, Hub could route in a very basic sense, Firewall could forward within LAN if acting as a router, AP could filter traffic if it has firewall features, and Modem could repeat signals if it includes a repeater function.

Why candidates pick the wrong answer

B

Candidates may confuse the roles of routers and switches (both forward data) or hubs and firewalls (both deal with traffic), or they may misremember the functions of modems and APs due to overlapping wireless and WAN concepts.

C

Candidates may confuse the functions due to overlapping features in modern devices (e.g., routers with firewall capabilities, switches with routing) or misremember basic definitions under exam pressure.

D

Candidates may confuse the roles due to overlapping functions in integrated devices (e.g., home routers combine router, switch, AP, and modem) or misremember basic networking definitions.

466
PBQhard

You are connected to R1 via the console. R1 is a Cisco ISR 4321 router running IOS-XE. The network team has recently changed the routing protocol from EIGRP to OSPF, but some routes are missing from the routing table. You need to analyze the OSPF neighbor states and LSDB to identify the issue.

Network Topology
G0/010.0.1.1/30G0/010.0.1.2/30linkG0/1192.168.1.1/24linkR1R2SW1

Hints

  • •Check if OSPF neighbors are in FULL state.
  • •Look for mismatched OSPF network types or hello intervals.
  • •Verify that both routers are in area 0.
A.Use 'show ip ospf neighbor' to check neighbor state; if not FULL, examine 'show ip ospf interface' for mismatched hello/dead intervals or network type.
B.Use 'show ip route ospf' to verify OSPF routes; if missing, re-enter the OSPF process and redistribute connected routes.
C.Use 'debug ip ospf events' to monitor OSPF packets; if no packets are seen, reconfigure OSPF router ID and clear the OSPF process.
D.Use 'show ip protocols' to verify OSPF process configuration; if incorrect, delete and recreate the OSPF process with the correct network statements.
AnswerA
solution
! R1
show ip ospf neighbor
show ip ospf interface gigabitethernet0/0
show ip route ospf

! R2
show ip ospf neighbor
show ip ospf interface

Why this answer

When OSPF routes are missing, the first diagnostic step is to verify adjacency formation with 'show ip ospf neighbor'; a state other than FULL (e.g., EXSTART, EXCHANGE, or 2-WAY) points to a Layer 2/3 or parameter mismatch. The most common culprits are mismatched hello/dead intervals, area IDs, authentication, MTU, or network type, which are all visible via 'show ip ospf interface'. This methodical approach isolates whether the problem is adjacency or LSDB/route calculation.

Exam trap

200-301 often tests whether candidates jump to configuration changes (redistribution, router ID, process recreation) instead of first verifying OSPF neighbor state and interface parameters, which is the correct diagnostic sequence.

Why the other options are wrong

B

The specific factual error is that 'show ip route ospf' shows only existing OSPF routes, not neighbor states. Redistribution is not needed for directly connected interfaces in the same OSPF area.

C

The specific factual error is that debugging is not the initial diagnostic step; it should be used after verifying neighbor states and interface parameters. Changing the router ID is unnecessary unless there is a duplicate router ID issue.

D

The specific factual error is that 'show ip protocols' does not display per-interface OSPF parameters. The problem is likely at the interface level, not the process level.

Why candidates pick the wrong answer

B

Candidates pick this because they think missing routes are due to redistribution issues, but the problem is likely at the adjacency level.

C

Candidates pick this because debugging seems like a direct way to see OSPF activity, but it is resource-intensive and often not needed for basic parameter mismatches.

D

Candidates pick this because they assume the OSPF process configuration is incorrect, but the issue is more likely mismatched interface parameters between neighbors.

467
PBQhard

You are connected to R1 via console. The network has a primary link to the ISP via R2 and a backup link via R3. Configure IPv4 and IPv6 floating static default routes on R1 so that the primary path goes through R2 (AD 1) and the backup through R3 (AD 10). Additionally, configure a static route on R1 for the internal LAN 192.168.10.0/24 via R2 (AD 1). The current configuration includes a static default route ip route 0.0.0.0 0.0.0.0 10.0.0.3, which causes a recursive routing failure because 10.0.0.3 is not a valid next-hop address. Identify and fix the issue, then apply the floating static routes.

Network Topology
G0/010.0.0.1/30G0/010.0.0.2/30link1G0/1G0/010.0.0.6/30link2R1R2R3

Hints

  • •The IPv4 default route to 10.0.0.2 is missing from the routing table. Check if the next-hop is reachable via a directly connected interface.
  • •Remove the existing problematic static default route and reconfigure it with an explicit administrative distance of 1.
  • •For IPv6, use the ipv6 route command with the prefix ::/0 and specify the next-hop and administrative distance.
A.Remove the existing incorrect IPv4 static default route and reconfigure the primary IPv4 default route with the correct next-hop address (10.0.0.2) and AD 1. Add the backup IPv4 default route via 10.0.0.6 with AD 10. Then add IPv6 static default routes: ipv6 route ::/0 2001:DB8:1:1::2 1 and ipv6 route ::/0 2001:DB8:2:1::2 10. Also add the static route for 192.168.10.0/24 via 10.0.0.2 with AD 1.
B.Add a static route to 10.0.0.0/30 via the backup link to R3, then the default route to 10.0.0.2 will work. Then configure IPv6 default routes with AD 1 and 10 as described.
C.Change the administrative distance of the IPv4 default route to 10 and the backup to 1, so the backup becomes primary. Then configure IPv6 default routes with AD 10 and 1 respectively.
D.Remove the existing IPv4 static default route and configure it with the next-hop as the exit interface (e.g., GigabitEthernet0/0) instead of the IP address. Then add IPv6 default routes using the exit interface as well.
AnswerA
solution
! R1
no ip route 0.0.0.0 0.0.0.0 10.0.0.2
ip route 0.0.0.0 0.0.0.0 10.0.0.2 1
ipv6 route ::/0 2001:DB8:1:1::2 1
ipv6 route ::/0 2001:DB8:2:1::2 10

Why this answer

The IPv4 default route currently uses next-hop 10.0.0.3, which is not a valid address on any directly connected interface, causing a recursive lookup failure. Option A fixes this by removing the incorrect route and correctly adding the primary (10.0.0.2 with AD 1) and backup (10.0.0.6 with AD 10) default routes, fulfilling the floating static requirement. It also adds both IPv6 floating default routes and the LAN static route.

Option B is wrong because adding a route to 10.0.0.0/30 via R3 does not fix the next-hop 10.0.0.3 failure for the default route. Option C incorrectly reverses the administrative distances, making the backup path the primary. Option D erroneously uses an exit interface instead of the correct next-hop IP, which is not suitable for multi-access or point-to-point networks without additional configuration and does not resolve the original misconfigured next-hop.

Exam trap

Be careful: Recursive routing failure means the next-hop is not reachable. Check if the next-hop is directly connected and the interface is up. Do not confuse administrative distance with metric; lower AD is preferred.

Also, ensure IPv6 routes use the correct next-hop addresses and AD values.

Why the other options are wrong

B

Adding a static route to the backup link does not correct the invalid next-hop 10.0.0.3 used in the default route and fails to address the root cause of the recursive lookup failure.

C

Swapping the administrative distances makes the backup path preferred instead of the primary, violating the requirement that R2 be the primary with AD 1.

D

Configuring the default route with an exit interface rather than a next-hop IP can cause ARP resolution issues in broadcast networks and does not replace the incorrect next-hop 10.0.0.3.

Why candidates pick the wrong answer

B

Candidates might think that the recursive routing failure is due to the next-hop not being in the routing table, so they try to add a route to it. However, the next-hop should be directly connected; if it's not, the interface may be down or misconfigured.

C

Candidates might confuse the concept of floating static routes and think that a higher AD is preferred, or they might incorrectly assume that the backup should have a lower AD to be used when the primary fails.

D

Candidates might think that using an exit interface avoids recursive lookups and is simpler, but it is not appropriate for multi-access networks and does not fix the underlying connectivity issue.

468
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure a router-on-a-stick topology for inter-VLAN routing between VLANs 10 and 20, using 802.1Q trunking with native VLAN 99 for management traffic.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
6Step 6

Why this order

The sequence follows Cisco's best practices: VLANs are created first, then access ports are assigned to them. The switch trunk is configured with 802.1Q encapsulation and the native VLAN set to 99 before the router end. On the router, the physical interface must be enabled before subinterfaces can operate.

The native VLAN subinterface is created first to handle untagged frames, then the data VLAN subinterfaces are configured. This order avoids errors such as missing VLANs, incorrect encapsulation, and physical link down state.

469
MCQhard

A switch is configured with DHCP snooping and Dynamic ARP Inspection. Hosts suddenly lose connectivity after changing IP settings manually. Which explanation is strongest?

A.DAI is rejecting ARP traffic because the manual IP change does not match trusted snooping bindings.
B.STP is blocking the host because its MAC address changed.
C.OSPF authentication failed on the access port.
D.The switch requires PPP authentication before allowing ARP traffic.
AnswerA

Dynamic ARP Inspection (DAI) intercepts ARP packets arriving on untrusted switch ports and validates them against the DHCP snooping binding table. When the administrator manually changed the IP address on the host, that new address is absent from the binding table, so DAI considers the ARP packet invalid and drops it. The switch also verifies that the sender MAC matches the bound MAC, further reinforcing the rejection.

Why this answer

DAI uses DHCP snooping binding to validate ARP messages; a manual IP change creates a mismatch, causing DAI to block ARP. Option B is incorrect because STP prevents loops and does not block based on MAC address changes. Option C is incorrect because OSPF authentication is a routing protocol feature irrelevant on an access port.

Option D is incorrect because PPP authentication applies to serial links, not Ethernet ARP.

Exam trap

Be cautious not to confuse DHCP snooping's role with DHCP server functionality or ARP cache operations.

Why the other options are wrong

B

STP (Spanning Tree Protocol) prevents loops in redundant topologies and does not block hosts based on IP or MAC address changes. It operates at Layer 2 and is unrelated to IP address configuration.

C

OSPF is a Layer 3 routing protocol used between routers, not on access ports connecting hosts. OSPF authentication is configured on router interfaces and does not apply to host ARP traffic on a switch.

D

PPP (Point-to-Point Protocol) authentication is used on serial links or PPPoE connections, not on Ethernet switch ports. It is unrelated to ARP inspection or DHCP snooping in a switched network.

When would these options actually be correct?

B

In a different scenario where a switch is configured with STP and a host changes its MAC address due to a hardware failure or network interface card (NIC) replacement, the question could state that STP is blocking the port due to a violation of MAC address consistency. This would make option B the correct answer.

C

If the question were about a scenario where OSPF is configured on the switch and the access port requires OSPF authentication, a failure in the authentication process could prevent OSPF routes from being exchanged, leading to connectivity issues. In this case, the question would need to focus on OSPF settings and their impact on host connectivity.

D

In a different scenario where a switch is configured to require PPP authentication for all traffic on access ports, a question might ask why ARP packets are being blocked. In that case, if a host attempts to send ARP traffic without completing PPP authentication, this option would be correct.

Why candidates pick the wrong answer

B

Students may confuse STP's MAC address learning with IP address changes, thinking that a new IP triggers a topology change or port blocking, but STP only reacts to topology changes, not host IP modifications.

C

Test-takers might associate authentication with security features and incorrectly assume OSPF authentication could be involved, but OSPF is not used for host connectivity validation.

D

The term 'authentication' may lead students to think of any security mechanism, but PPP authentication is specific to WAN links and not applicable to LAN switching security features.

470
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure PAT (overload) on a Cisco router using a single public IP address on the outside interface.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order is A, B, C, D, E. First, enter global configuration mode. Second, create an access list to match the traffic to be translated.

Third, configure the inside interface with 'ip nat inside'. Fourth, configure the outside interface with 'ip nat outside'. Fifth, apply PAT with 'ip nat inside source list <ACL> interface <outside-if> overload'.

This final command enables PAT using the outside interface's public IP.

Exam trap

Learners often forget to assign the 'ip nat inside' and 'ip nat outside' interface commands, or they configure them in the wrong order relative to the source NAT statement.

471
MCQhard

Two switches should form an EtherChannel using LACP. One side is configured active and the other passive. If the port settings otherwise match, what is the expected result?

A.The EtherChannel should form if the other interface settings are compatible.
B.The EtherChannel fails because both sides must be active.
C.the bundle forms but only in PAgP mode
D.only the active side attempts to bundle
AnswerA

LACP requires at least one side in active mode to initiate negotiation; passive waits for the peer. Active on one switch and passive on the other therefore forms the bundle, provided speed, duplex, VLAN and trunk settings match on both members.

Why this answer

The EtherChannel should form successfully. In plain language, active mode initiates LACP negotiation and passive mode listens and responds. Because one side is active, the negotiation can begin and the bundle can come up as long as the underlying interface settings are compatible.

This is a standard LACP pairing. The important lesson is that active/passive works, while passive/passive usually does not. The correct answer is the one that recognizes active/passive as a valid combination.

Exam trap

Remember that active/passive works for LACP, but passive/passive does not initiate negotiation.

Why the other options are wrong

C

LACP and PAgP are incompatible, so the bundle cannot form in PAgP mode when one side uses LACP.

D

The passive side will respond to LACP negotiations, so both sides participate and the bundle forms.

When would these options actually be correct?

B

In a different scenario where the question specifies that both switches must be configured in active mode for an EtherChannel to form, this option would be correct. For example, if the question stated that both switches were required to be in active mode for LACP to function, then this option would accurately reflect that requirement.

C

In a different question setup, if the scenario involved a configuration where the switches were set to operate in a Layer 3 mode and the interfaces were configured to act as routed ports, then the statement about ports becoming routed interfaces could be correct.

D

In a different scenario where the question specifies that the interfaces are configured to operate in a mode that requires VLANs to be explicitly removed before forming an EtherChannel, this option could be correct. For example, if the question states that the interfaces must be in a specific mode that does not support VLAN tagging, then this option would apply.

Why candidates pick the wrong answer

B

Students often think that both sides must be in the same mode (active/active or passive/passive) for negotiation to work, but active/passive is a standard and functional combination.

C

Some might confuse LACP with routing protocols or think that bundling ports automatically changes their interface type, but EtherChannel is independent of Layer 3 configuration.

D

Test-takers might think that LACP clears VLANs to ensure compatibility, but in reality, VLAN mismatch is a common cause of EtherChannel failure, not something LACP resolves automatically.

472
PBQmedium

You are connected to SW1 via the console. SW1 is a Layer 2 switch with two VLANs: VLAN 10 (Sales) and VLAN 20 (Engineering). Port G0/1 is connected to a sales PC, and port G0/2 is connected to an engineering PC. You need to ensure that each PC is in the correct VLAN. However, the sales PC is currently unable to ping the engineering PC because they are in different VLANs. You have a router R1 connected to SW1 via port G0/3. Configure inter-VLAN routing using Router-on-a-Stick on R1, and ensure SW1's port G0/3 is properly configured as a trunk.

Network Topology
G0/1G0/1G0/3G0/3G0/0G0/2SW1PC1VLAN 10R1PC2VLAN 20

Hints

  • •Router-on-a-Stick uses subinterfaces on the router with 802.1Q encapsulation.
  • •The switch port connected to the router must be configured as a trunk to carry multiple VLANs.
  • •Each subinterface must have an IP address in the respective VLAN's subnet.
A.Configure subinterfaces on R1 with encapsulation dot1Q and assign IP addresses in VLAN 10 and VLAN 20. Configure SW1 interface G0/3 as a trunk port.
B.Configure a routed port on SW1 G0/3 and assign an IP address. Then configure static routes on R1 to reach each VLAN.
C.Configure SW1 interface G0/3 as an access port in VLAN 10. Then configure R1 with a single IP address in VLAN 10 and enable proxy ARP.
D.Configure SW1 interface G0/3 as a trunk port. Then configure R1 with a single IP address on the physical interface and enable VLAN routing using the 'vlan' command.
AnswerA
solution
! R1
interface GigabitEthernet0/0.10
encapsulation dot1Q 10
ip address 192.168.10.1 255.255.255.0
interface GigabitEthernet0/0.20
encapsulation dot1Q 20
ip address 192.168.20.1 255.255.255.0
interface GigabitEthernet0/0
no shutdown

! SW1
interface GigabitEthernet0/3
switchport mode trunk

Why this answer

Router-on-a-Stick requires the router's physical interface to be divided into subinterfaces, each tagged with 802.1Q encapsulation for a specific VLAN and assigned an IP address that serves as that VLAN's default gateway. The switch port facing the router must be configured as a trunk so it can carry tagged frames for both VLAN 10 and VLAN 20. This combination lets R1 route between the two VLANs while SW1 remains a Layer 2 device.

Exam trap

The trap here is confusing a routed port (Layer 3 switch port) with a trunk port; candidates who pick the routed-port option forget that inter-VLAN routing via a router requires 802.1Q subinterfaces on a trunk, not a single Layer 3 link.

Why the other options are wrong

B

Layer 2 switches do not support routed ports; they only support switchport mode access or trunk.

C

An access port cannot carry multiple VLANs; a trunk is required for Router-on-a-Stick.

D

Router-on-a-Stick requires subinterfaces; a single IP address on the physical interface only handles one VLAN. The 'vlan' command is not used on routers for inter-VLAN routing.

Why candidates pick the wrong answer

B

Candidates may confuse Layer 2 and Layer 3 switch capabilities or think that a routed port can be used on any switch.

C

Candidates might think that placing the router in one VLAN and using proxy ARP can bridge VLANs, but proxy ARP only helps with same-subnet communication.

D

Candidates may think that a trunk port on the switch automatically allows the router to route between VLANs without subinterfaces, or they confuse switch VLAN configuration with router subinterfaces.

473
MCQhard

An engineer is troubleshooting an OSPF adjacency between two directly connected routers, R1 and R2. R1 is configured with a passive-interface default under the OSPF process, and the interface connecting to R2 is not explicitly set to no passive-interface. The engineer runs a show ip ospf neighbor command on R1 and sees no neighbors. What is the most likely reason for the missing adjacency?

A.The network statement does not match the interface IP address.
B.The passive-interface default command is preventing OSPF hellos on the interface.
C.The router-id is not configured, so OSPF cannot form an adjacency.
D.There is an OSPF authentication mismatch between R1 and R2.
AnswerB

The passive-interface default command configures OSPF so that every interface is passive unless explicitly overridden with 'no passive-interface'. A passive interface does not send OSPF hello packets, but the connected subnet is still advertised into the OSPF database. Without a 'no passive-interface' statement applied to the link between R1 and R2, neither router will send hellos, and an adjacency can never form—exactly matching the symptom of no neighbors.

Why this answer

The `passive-interface default` command under the OSPF process makes all interfaces passive by default, meaning OSPF Hellos are not sent unless explicitly overridden with `no passive-interface`. Since the interface to R2 was not configured with `no passive-interface`, R1 does not send Hellos, preventing adjacency. Option A is less likely because even if the network statement is correct, a passive interface still blocks Hellos.

Option C is incorrect because OSPF automatically selects a router-id if not configured (highest loopback or interface IP), and a missing router-id does not prevent Hellos. Option D is unsupported by the scenario; no authentication mismatch is indicated.

Exam trap

Cisco often tests the nuance that `passive-interface default` suppresses Hellos on all interfaces unless overridden, leading candidates to overlook the fact that even directly connected routers cannot form an adjacency without Hellos being sent.

Why the other options are wrong

A

The network statement 10.0.0.0 0.255.255.255 area 0 matches any IP in the 10.0.0.0/8 range, which likely includes the interface IP. Therefore, the network statement is not the issue.

C

A router-id is automatically selected from the highest loopback or physical interface IP if not manually configured. Lack of manual configuration does not prevent adjacency formation; OSPF will still function.

D

The running-config does not show any authentication configuration, and the symptom (no neighbors) is consistent with passive interfaces, not authentication mismatches. An authentication mismatch would typically show neighbors in EXSTART/EXCHANGE state, not missing entirely.

Why candidates pick the wrong answer

A

Students often think that a missing or incorrect network statement is the primary cause of OSPF adjacency failures, but in this scenario the network statement is correctly configured.

C

Many students believe that a router-id must be explicitly configured for OSPF to work, but OSPF can dynamically select a router-id from available IP addresses.

D

Authentication mismatches are a common cause of OSPF adjacency issues, so students may jump to that conclusion without checking for passive interface configuration.

474
MCQhard

A branch router uses PAT for Internet access. Users can browse out, but the administrator wants a specific internal web server to be reachable from outside on a consistent public address. Which design fits that requirement best?

A.Use static NAT for the server and PAT for general user outbound traffic.
B.Use only PAT for everything, including predictable outside server reachability.
C.Disable NAT entirely because private IPv4 addresses are Internet-routable.
D.Use DHCP relay to publish the server externally.
AnswerA

Static NAT maps the server's private address to a fixed public address, giving inbound reachability on a consistent address, while PAT overloads the router's public address for outbound user sessions. This satisfies the stem's requirement for both consistent inbound access and general Internet browsing.

Why this answer

The best design is to use static NAT for the internal web server while continuing to use PAT for general user outbound access. In plain language, PAT is ideal for many inside users sharing one public address for ordinary outbound traffic, but a server that must be reachable predictably from the outside needs a fixed public identity. Static NAT provides that one-to-one mapping.

This is a practical mixed-design scenario. The network can use PAT for user convenience and address conservation while still reserving a stable translation for a server that external clients need to find reliably. The correct answer recognizes that different NAT methods can serve different purposes in the same environment.

Exam trap

A common exam trap is selecting PAT alone to provide external access to an internal server. While PAT efficiently supports many users sharing one public IP for outbound traffic, it does not assign a fixed public IP to any internal host. This means the server’s public identity changes dynamically, preventing reliable inbound connections.

Candidates often confuse PAT’s port translation with static IP mapping, overlooking that servers need static NAT for consistent external reachability. Misunderstanding this distinction leads to incorrect answers and design flaws in real networks.

Why the other options are wrong

B

Incorrect because PAT alone cannot provide a stable public IP for inbound connections to a server, making it unsuitable for predictable external access to internal services.

C

Incorrect because private IPv4 addresses are not routable on the Internet, so disabling NAT would prevent internal hosts from accessing external networks and external clients from reaching internal servers.

D

Incorrect because DHCP relay is used to forward DHCP requests across networks and does not influence NAT or the public accessibility of internal servers.

When would these options actually be correct?

B

In a scenario where all devices, including servers, are intended to share a single public IP address for outbound traffic without the need for external access to specific internal servers, using only PAT would be appropriate. For example, a question might ask for a configuration where all internal devices need to access the internet but do not require any inbound connections.

C

In a scenario where a question states that a network is using IPv6, which allows for global addressing without NAT, disabling NAT would be correct to allow direct access to internal servers from the Internet.

D

If the exam question asked about a scenario where a server needs to receive IP address assignments dynamically from an external DHCP server, and the focus was on ensuring that the server can communicate with clients outside its local network, then using DHCP relay would be correct.

Why candidates pick the wrong answer

B

Students might think PAT can handle all traffic types, including inbound server access, because PAT is commonly used for outbound traffic. They may overlook that PAT does not create a stable public identity for inbound connections without additional configuration like port forwarding.

C

Some students may confuse private addresses with public addresses or think that all IPv4 addresses are globally routable. They might also misunderstand the purpose of NAT as optional rather than necessary for private-to-public communication.

D

Students might associate 'relay' with forwarding traffic or think DHCP relay can somehow expose internal servers externally. The term 'relay' can be misleading, causing confusion with port forwarding or NAT.

475
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure HSRP version 2 on an interface and ensure the router becomes the active router, then verify the HSRP state.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order for configuring HSRP version 2 to ensure the router becomes the active router is: first configure HSRP version 2 on the interface, then configure the HSRP group and virtual IP address, then set the HSRP priority to a higher value, then enable HSRP preempt, and finally verify using 'show standby'. Only option A follows this sequence. Options B, C, and D are incorrect because they place version after group, priority before version, or preempt before priority.

Exam trap

Candidates often place version configuration after group creation or set preempt before priority. Remember: version must be set before the group is created, priority before preempt.

Why candidates pick the wrong answer

B

Candidates pick this because they think version can be changed at any time without affecting the group, or they focus on priority/preempt first.

C

Candidates pick this because they think version must come first, then priority/preempt, but they forget that the group must exist first.

D

Candidates pick this because they think preempt is independent of priority order, or they confuse the order with other protocols like VRRP.

476
MCQhard

A host sends an IPv4 packet larger than the outgoing interface MTU, and the DF bit is not set. What will a router normally do?

A.Drop the packet without notification
B.Fragment the packet before forwarding
C.Convert the packet into UDP
D.Forward it unchanged and let the switch fragment it
AnswerB

When the outgoing interface has a smaller MTU than the incoming packet and the IP header's Do Not Fragment (DF) bit is 0, the router correctly fragments the packet into smaller Layer 3 pieces that each fit the outgoing MTU. Each fragment gets its own IP header with the same identification field, a fragment offset, and the More Fragments flag set as needed, allowing the destination host to reassemble the original packet. This is the standard expected IPv4 behavior for an intermediate router.

Why this answer

If fragmentation is allowed, an IPv4 router can fragment a packet to fit the outgoing interface MTU. If DF were set, the router would instead drop the packet and typically send an ICMP message back to the source.

Exam trap

Be careful not to confuse the behavior when the DF bit is set with when it is not set. Remember, fragmentation is allowed when DF is not set.

Why the other options are wrong

A

A router does not drop the packet without notification when the DF bit is not set; instead, it fragments the packet. Dropping without notification only occurs when the DF bit is set and the packet exceeds the MTU, in which case the router sends an ICMP Fragmentation Needed message.

C

Routers operate at Layer 3 (IP) and do not modify the transport layer protocol (e.g., UDP or TCP) to handle MTU issues. Converting a packet to UDP would change the protocol and is not a function of IP fragmentation or any standard routing behavior.

D

Switches operate at Layer 2 and do not perform IP fragmentation. Fragmentation is a Layer 3 function handled by routers or the source host. The router must fragment the packet before forwarding it to the switch.

When would these options actually be correct?

A

In a different scenario where the question specifies that the DF bit is set, and the packet exceeds the MTU, the router would drop the packet without notification, making this option correct.

C

In a different question, if the scenario involved a network device that specifically translates protocols for application-layer communication, such as a gateway or proxy server, the option could be correct. For example, a question might ask what happens when an application requires UDP but receives TCP packets.

D

In a different scenario where the question specifies that the packet is being processed by a Layer 2 switch that does not perform IP fragmentation, the option could be correct if the switch is configured to handle larger frames and simply forwards the packet without fragmentation.

Why candidates pick the wrong answer

A

Students may confuse this scenario with the case where the DF bit is set, leading to packet drop. They might also think that routers always drop oversized packets, but fragmentation is the default behavior when DF is not set.

C

A student might think that changing the protocol could reduce packet size or that UDP is used for fragmentation, but this is incorrect. The confusion may arise from the fact that UDP has a smaller header than TCP, but routers do not perform such conversions.

D

Students might think that switches can handle fragmentation because they forward packets, but switches only forward frames based on MAC addresses and do not process IP headers for fragmentation. The term 'switch' is often misassociated with routing functions.

477
Multi-Selecthard

Exhibit: A company wants to export traffic statistics from routers to a collector for visibility into top talkers and application usage. Which two statements are accurate?

Select 2 answers
A.NetFlow can export flow data to a collector
B.NetFlow helps identify traffic patterns and top talkers
C.Syslog and NetFlow are the same feature with different names
D.NetFlow replaces routing protocols for path selection
E.NetFlow only works on Layer 2 switches and never on routers
AnswersA, B

NetFlow operates on the device by maintaining an in-memory cache of active flows; when a flow expires or the cache fills, the exporter packages the records into UDP datagrams, usually on port 2055 or 9996, and sends them to an external collector. The collector (e.g., SolarWinds, PRTG, Elastic) stores and correlates these records for historical reporting, capacity planning, and traffic accounting. Thus export is the essential delivery mechanism that makes the captured flow metadata usable for centralized analysis.

Why this answer

NetFlow exports flow records to a collector and is useful for traffic analysis and accounting visibility, enabling identification of top talkers and application usage (options A and B are correct). Syslog reports events and messages, but does not replace flow records for conversation-level traffic statistics, so option C is incorrect. NetFlow does not replace routing protocols for path selection; it is a traffic monitoring tool, not a routing mechanism, so option D is incorrect.

NetFlow works on routers and Layer 3 switches, not only Layer 2 switches, so option E is incorrect.

Exam trap

Be cautious not to confuse general network monitoring tools like Syslog and SNMP with specialized traffic analysis tools like NetFlow.

Why the other options are wrong

D

NetFlow does not replace routing protocols; it is a monitoring tool that provides traffic statistics, not a path-selection mechanism.

E

NetFlow operates on routers and Layer 3 switches, not just Layer 2 switches, and is commonly used on routers for traffic analysis.

When would these options actually be correct?

C

If the question asked 'Which two statements are true about Syslog and NetFlow?' and included an option stating 'Both Syslog and NetFlow can be used for network monitoring and troubleshooting,' that would be correct because both provide visibility into network events, albeit different types of data.

D

In a question asking which technology can be used to influence routing decisions based on traffic flows, such as in traffic engineering with MPLS-TE or policy-based routing, NetFlow itself is not used, but if the question were about a protocol that replaces routing protocols for path selection, the answer would be something like MPLS-TE or segment routing, not NetFlow.

E

In a question that asks 'Which device type is limited to Layer 2 switching and cannot run NetFlow?', the correct answer would be a pure Layer 2 switch that does not support NetFlow, but modern switches often do.

Why candidates pick the wrong answer

C

Candidates may confuse Syslog and NetFlow because both are used for network monitoring and generate logs or records, leading to the mistaken belief they are interchangeable or the same feature.

D

Candidates may confuse NetFlow's ability to analyze traffic flows with the idea that it can control or replace routing decisions, especially if they think 'flow' implies path selection.

E

Candidates may confuse NetFlow with features like port mirroring that are more common on switches, or mistakenly think NetFlow is only for Layer 2 due to its flow-based nature.

478
Matchingmedium

Drag and drop the port configuration commands/technologies on the left to their corresponding descriptions on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Configures the port as a non-trunking access port

Limits the number of MAC addresses on a desktop access port

Separates VoIP traffic into a dedicated VLAN

Assigns the data VLAN for desktop or AP devices

Immediately transitions an end-device port to forwarding state

Macro that sets portfast, mode access, and port-security for IoT/virtual hosts

Why these pairings

These are common Cisco IOS commands used for port configuration, each with a specific function.

Exam trap

Candidates often confuse commands that set port mode (access/trunk) with commands that assign VLANs or set encapsulation. Remember that 'switchport mode access' is the specific command to make a port an access port; other commands like 'switchport access vlan' or 'switchport trunk encapsulation' serve different purposes and do not change the port mode.

479
PBQmedium

You are connected to SW1 via the console. SW1 is a multilayer switch with SVIs for VLANs 10 (192.168.10.1/24) and 20 (192.168.20.1/24). Hosts in VLAN 10 can ping their default gateway (192.168.10.1), but cannot ping hosts in VLAN 20. You suspect IP routing is not enabled or the SVIs are not up.

Hints

  • •Check if IP routing is enabled globally.
  • •Verify that the SVIs are up/up.
  • •Use ping with source to test connectivity between VLANs.
A.Enable IP routing on SW1 with the 'ip routing' global configuration command.
B.Configure a trunk port between SW1 and an external router, then enable routing on the router.
C.Ensure the SVIs are not shut down and have the 'no shutdown' command applied.
D.Add a static route on SW1 pointing to the VLAN 20 subnet via the VLAN 10 SVI.
AnswerA
solution
! SW1
ip routing

Why this answer

A multilayer switch requires 'ip routing' to forward packets between VLANs. Without it, the switch acts as a Layer 2 device. Enabling IP routing allows the SVIs to route traffic between VLANs.

The verification commands confirm routing is active and SVIs are operational.

Exam trap

The trap is that candidates may focus on interface status or static routes, overlooking the fundamental requirement of 'ip routing' on a multilayer switch. Remember that SVIs can be up and pingable, but without IP routing enabled, the switch cannot forward packets between VLANs.

Why the other options are wrong

B

The specific factual error is that the question states SW1 is a multilayer switch with SVIs, so it can route internally without an external router. The issue is that IP routing is not enabled on the switch itself.

C

The specific factual error is that the SVIs are already up (hosts can ping the gateway), so 'no shutdown' is not the missing step. The problem is at Layer 3 routing, not Layer 2/3 interface status.

D

The specific factual error is that directly connected networks do not require static routes; the switch automatically installs them when the SVI is up. The problem is that 'ip routing' is not enabled, so the switch does not use these routes for forwarding.

Why candidates pick the wrong answer

B

Candidates might confuse the need for inter-VLAN routing with the router-on-a-stick method, especially if they are more familiar with Layer 2 switches.

C

Candidates often check interface status first when troubleshooting connectivity, so they might assume the SVIs are down even though the hosts can reach the gateway.

D

Candidates might think that inter-VLAN routing requires explicit static routes, not realizing that a multilayer switch with SVIs automatically has connected routes and only needs 'ip routing' enabled.

480
MCQhard

A host is configured with IP address 192.168.70.18/30. Which addresses belong to the same subnet block?

A.192.168.70.16 through 192.168.70.19
B.192.168.70.18 through 192.168.70.21
C.192.168.70.12 through 192.168.70.15
D.192.168.70.20 through 192.168.70.23
AnswerA

A /30 prefix (255.255.255.252) defines a block of exactly 4 addresses aligned to multiples of 4. The IP 192.168.70.18 falls within the block 192.168.70.16/30, where .16 is the network address, .17 and .18 are usable host addresses, and .19 is the broadcast address. Therefore the entire subnet range is 192.168.70.16 through 192.168.70.19.

Why this answer

A /30 subnet has a block size of 4. In practical terms, the relevant blocks in the last octet are 0–3, 4–7, 8–11, 12–15, 16–19, and so on. Because 18 falls inside the 16–19 block, the subnet includes network address .16, usable hosts .17 and .18, and broadcast .19.

This question checks whether you can identify the correct /30 block and understand all addresses that fall inside it.

Exam trap

Be careful not to confuse adjacent subnet blocks or miscalculate the block size of a /30 subnet.

Why the other options are wrong

B

A /30 subnet always has a block size of 4 addresses, starting at multiples of 4. The block starting at .18 would be 192.168.70.16–.19, not .18–.21. The range .18–.21 crosses a subnet boundary and includes addresses from two different subnets.

C

The block 192.168.70.12–.15 is a different /30 subnet (network .12, broadcast .15). The host .18 belongs to the subnet .16–.19, not .12–.15.

D

The block 192.168.70.20–.23 is the next /30 subnet (network .20, broadcast .23). The host .18 is not in this range; it is in the .16–.19 subnet.

When would these options actually be correct?

B

If the question asked for the range of addresses in a /29 subnet instead of /30, then option B would be correct, as a /29 subnet allows for IP addresses from 192.168.70.16 to 192.168.70.23.

C

If the question were to ask for the range of addresses in the subnet defined by a different CIDR notation, such as 192.168.70.12/30, then the range 192.168.70.12 through 192.168.70.15 would be correct, as it would represent the valid addresses in that subnet.

D

If the question asked for the addresses in the subnet of 192.168.70.20/30, then option D would be correct, as it would include the range from 192.168.70.20 to 192.168.70.23, which belongs to that subnet.

Why candidates pick the wrong answer

B

Students might think that since .18 is the host address, the subnet includes .18 and the next three addresses, not realizing that subnet boundaries are fixed at multiples of the block size.

C

A student might miscalculate the block size or confuse the subnet boundaries, thinking that .18 falls into the previous block because of incorrect arithmetic.

D

Students might incorrectly add the block size to the host address (18+4=22) and assume the subnet starts at .20, forgetting that subnet boundaries are based on the network address, not the host address.

481
PBQmedium

You are connected to R1 via the console. R1 is an NTP client that should synchronize its clock with NTP server 192.168.1.100. The timezone is UTC-5 (Eastern Standard Time). Configure NTP on R1 so that it becomes an NTP client. Additionally, configure the router to log NTP synchronization status messages to the console and buffer logging using the numeric severity level 6 (informational).

Network Topology
G0/0192.168.1.1/24LANR1NTP server

Hints

  • •Use ntp server command to point to the NTP server.
  • •Logging level 6 corresponds to informational.
  • •Buffered and console logging commands are separate.
A.ntp server 192.168.1.100 logging console informational logging buffered informational
B.ntp peer 192.168.1.100 logging console 6 logging buffered 6
C.ntp server 192.168.1.100 logging console 6 logging buffered 6
D.ntp server 192.168.1.100 logging console informational logging buffered 6
AnswerC
solution
! R1
ntp server 192.168.1.100
logging buffered 6
logging console 6

Why this answer

The correct configuration uses 'ntp server 192.168.1.100' to set the NTP server, and 'logging console 6' and 'logging buffered 6' to set both console and buffer logging to severity level 6 (informational). The numeric level 6 is equivalent to 'informational', but the question specifies using the numeric severity level 6.

Exam trap

200-301 often tests the difference between numeric and keyword logging levels; candidates may assume they are interchangeable, but the question may require a specific format.

Why the other options are wrong

A

Uses the keyword 'informational' instead of the required numeric severity level 6.

B

The ntp peer command establishes a peer relationship, not a client-server relationship. The logging syntax is also incorrect.

D

Mixes numeric and keyword severity levels; both must be numeric 6 to meet the requirement.

When would these options actually be correct?

A

This configuration is used when a router needs to synchronize its clock with an NTP server and log NTP events for monitoring and troubleshooting.

Why candidates pick the wrong answer

B

Candidates may confuse ntp peer with ntp server, thinking both can be used for client synchronization. They might also think that using the numeric level 6 is acceptable without the keyword.

D

Candidates might think that mixing keyword and numeric is acceptable, or they may forget to use the keyword for buffered logging.

482
Matchingmedium

Match each HTTP method to the most common API action.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Retrieve information

Create a new resource

Replace or update a resource representation

Remove a resource

Why these pairings

The correct answer is the ordered matching D, C, A, B: DELETE pairs with Remove, PUT pairs with Update, GET pairs with Retrieve, and POST pairs with Create. Treat the options as one matching sequence, not as four independently correct statements.

Exam trap

Do not treat each HTTP method-action pair as independently correct. For this matching item, select the sequence D → C → A → B (DELETE → Remove, PUT → Update, GET → Retrieve, POST → Create).

483
MCQmedium

An automation script needs to send a bearer token when calling a controller REST API over HTTPS. Where is that token most commonly included?

A.In the HTTP Authorization header
B.In the Ethernet trailer
C.In the DNS response section
D.In the TCP checksum field
AnswerA

RFC 6750 specifies that a bearer token is transmitted in the HTTP Authorization request header using the Bearer authentication scheme (e.g., `Authorization: Bearer <token>`). This header is parsed by the resource server to validate the client's identity and permissions before processing the request. Because HTTP is the application-layer protocol used for REST APIs, this is the only correct placement for the token among the options listed.

Why this answer

Bearer tokens are typically sent in the HTTP Authorization header. Query parameters or request bodies may carry credentials in some custom APIs, but the normal REST pattern is an Authorization header such as 'Authorization: Bearer <token>'.

Exam trap

Remember that bearer tokens are part of the request, not the response, and should be in the Authorization header, not in query parameters or the request body.

Why the other options are wrong

B

The Ethernet trailer contains a Frame Check Sequence (FCS) for error detection at Layer 2, not application-layer data like bearer tokens. Tokens are part of the HTTP application layer and are never placed in the Ethernet trailer.

C

DNS responses contain resource records like A, AAAA, or CNAME, which map domain names to IP addresses. They have no role in carrying authentication tokens for REST API calls, as DNS is a separate protocol for name resolution.

D

The TCP checksum field is used for error detection of the TCP segment header and payload at the transport layer. It is computed by the sender and verified by the receiver; it does not carry any application data such as bearer tokens.

When would these options actually be correct?

B

If the question asked where to include metadata for Ethernet frames in a network communication scenario, the Ethernet trailer could be referenced as it contains necessary information for data transmission, making it relevant in that specific context.

C

If the exam question were focused on a scenario where DNS was being used to authenticate a client to a server, and the question specified that the bearer token was being transmitted as part of a custom DNS protocol extension, then this option could be correct.

D

In a hypothetical question where the focus is on TCP packet structure and error-checking mechanisms, a candidate might be asked about the purpose of the TCP checksum field. In that context, a correct answer could involve discussing how it ensures data integrity, potentially leading to confusion about where application data is placed.

Why candidates pick the wrong answer

B

Students might confuse the term 'trailer' with 'header' or think that security tokens could be embedded in lower-layer fields for encryption, but Ethernet trailers are purely for error checking and not for carrying application data.

C

A student might think that since DNS is used to resolve the controller's hostname, the token could be included in the DNS response. However, DNS is not involved in application-layer authentication and does not carry bearer tokens.

D

Students might confuse the checksum field with a field that could carry security information, or think that tokens could be embedded in transport-layer headers for encryption. However, TCP checksums are purely for integrity and not for authentication tokens.

484
PBQhard

You are connected to R1, a Cisco IOS-XE router that serves as the DNS resolver for the local network. The router can reach the DNS server at 198.51.100.53, but internal hosts cannot resolve the hostname 'fileserver.courseiva.com' (expected IP 203.0.113.10). Which configuration will resolve the issue?

Network Topology
G0/0192.168.1.1/24R1switch

Hints

  • •The DNS server returns NXDOMAIN, meaning it has no record for that hostname or IP.
  • •Use the 'ip host' command to create a static DNS entry on the router.
  • •For reverse lookup, the PTR record must be configured; a single 'ip host' with the IP first automatically creates a PTR entry.
A.Add a static host entry: ip host fileserver.courseiva.com 203.0.113.10
B.Change the DNS server to 203.0.113.53 using the command 'ip name-server 203.0.113.53'
C.Add a static route to 198.51.100.53 via the next-hop interface
D.Configure the router to use the DNS server at 8.8.8.8 using 'ip name-server 8.8.8.8'
AnswerA
solution
! R1
ip host fileserver.courseiva.com 203.0.113.10
ip host 203.0.113.10 fileserver.courseiva.com

Why this answer

The DNS server is reachable but does not have an A record for fileserver.courseiva.com, so NXDOMAIN is returned. The router can resolve the name locally by adding a static host entry with `ip host`. This bypasses the external DNS and directly maps the hostname to the correct IP.

Changing the DNS server to another unknown IP does not guarantee resolution, and static routes or external public DNS are irrelevant for this internal name.

Exam trap

Candidates often attempt to change the DNS server IP or troubleshoot routing, but the core issue is the absence of a DNS record. The `ip host` command provides a simple, static solution without altering external DNS infrastructure.

Why the other options are wrong

B

The current DNS server is reachable but lacks the record; simply changing the DNS server to an arbitrary IP would not guarantee resolution unless that server is known to hold the correct record, and there is no indication that 203.0.113.53 is a valid DNS server.

C

DNS resolution failure is not due to routing: the router can already reach the DNS server. Adding a static route will not fix missing DNS records.

D

The Google public DNS server likely does not have an entry for the internal hostname fileserver.courseiva.com, so this will not enable resolution.

Why candidates pick the wrong answer

B

Candidates pick this because they think the issue is with the DNS server IP, and they assume 203.0.113.53 might be a working DNS server, confusing the host IP with a DNS server address.

C

Candidates pick this because they think the router cannot reach the DNS server, even though the question states it can. They may confuse DNS resolution issues with routing problems.

D

Candidates pick this because 8.8.8.8 is a well-known DNS server, and they assume it will resolve any hostname. They overlook that the hostname is internal and not registered in public DNS.

485
MCQhard

An OSPF router learns a route with metric 20 and another OSPF route to the same destination with metric 30. The prefix length is the same. Which path is preferred?

A.The route with metric 20
B.The route with metric 30
C.Both routes are rejected because the metrics differ
D.The default route is preferred
AnswerA

OSPF uses a cost metric based on interface bandwidth, and lower cost indicates a more efficient path. When a router receives multiple OSPF routes to the same destination, it installs the route with the lowest metric into its routing table. Thus, the route with metric 20 is preferred because it offers a shorter or faster path than metric 30. This is standard OSPF path selection behavior, so the correct choice is the 20-metric route.

Why this answer

The OSPF path with metric 20 is preferred because, within the same routing protocol and for the same prefix length, the metric is used to compare candidate paths. In practical terms, the router is not comparing source trust here because both routes come from OSPF. It is comparing OSPF’s own internal path-cost values, and the lower metric wins.

This question is about separating administrative distance from metric. Since both routes come from the same protocol, metric is the deciding factor.

Exam trap

A common exam trap is confusing administrative distance with metric when comparing routes from the same protocol. Candidates might incorrectly think that a higher metric route is rejected or that administrative distance plays a role in choosing between two OSPF routes. In reality, OSPF always prefers the route with the lowest metric, and both routes remain valid candidates.

Misunderstanding this can lead to incorrect answers about route selection or route rejection, especially when multiple OSPF routes to the same prefix exist with different metrics.

Why the other options are wrong

B

This option is incorrect because a higher metric indicates a less preferred path in OSPF. The route with metric 30 is less optimal than the one with metric 20 and therefore not preferred.

C

This option is incorrect because OSPF does not reject routes simply because their metrics differ. Differing metrics are normal and help the router choose the best path rather than causing route rejection.

D

This option is incorrect because the router already has specific OSPF routes to the destination. A default route is not preferred when a more specific route with a valid metric exists.

When would these options actually be correct?

B

In a different scenario where OSPF is configured to prefer higher metrics due to specific policy routing or administrative decisions, a question might ask which route is preferred when the metrics are intentionally inverted, making 30 the preferred choice.

C

In a scenario where a question specifies that OSPF routes are only accepted if they have the same metric, and both routes have different metrics, it could state that the router rejects all routes that do not meet this criterion, making this option correct.

D

In a different scenario where the question specifies that the OSPF router has no other routes to the destination and the default route is configured, the default route would be preferred over any other routes, including those with higher metrics.

Why candidates pick the wrong answer

B

Students may mistakenly think that a higher metric indicates a more reliable or recently learned route, but OSPF uses lower metric as the primary tie-breaker for equal prefix lengths.

C

Some might confuse OSPF with protocols that require equal metrics for load balancing, but OSPF only load-balances when metrics are equal; differing metrics simply result in a single best path.

D

Students may think that a default route is always preferred as a catch-all, but specific routes always take precedence over default routes in the routing table.

486
MCQhard

A host address is 10.55.8.117/29. Which address is the network address of the subnet?

A.10.55.8.112
B.10.55.8.119
C.10.55.8.120
D.10.55.8.116
AnswerA

10.55.8.112 is the network address because the /29 prefix length equates to a 255.255.248 subnet mask, creating subnets with 8 addresses each. The host address 10.55.8.117 falls within the range 112 through 119, so the network address is the first address in that block, 10.55.8.112, with 10.55.8.119 as the broadcast address.

Why this answer

A /29 subnet has a block size of 8. In practical terms, the relevant last-octet blocks are 112-119 for this host. That means the network address is 10.55.8.112. Once you identify the correct block, the first address in the block is the network address.

This is a useful addressing-boundary question because it checks careful block calculation, not memorized guesses.

Exam trap

Be careful not to confuse the network address with the first usable host or the broadcast address.

Why the other options are wrong

B

10.55.8.119 is the broadcast address for the subnet 10.55.8.112/29, not the network address. The broadcast address is the last address in the block (112+8-1=119) and is used to send traffic to all hosts in the subnet.

C

10.55.8.120 is the network address of the next /29 subnet (120-127), not the current one. The current subnet ends at 119, so 120 belongs to a different subnet.

D

10.55.8.116 is a valid host address within the subnet 10.55.8.112/29 (usable range: 113-118). It is not the network address, which must be the first address (112).

When would these options actually be correct?

B

In a different question where the subnet mask is /29 and the host address is 10.55.8.119, asking for the broadcast address of the subnet, option B would be correct as it represents the last usable address before the broadcast address of 10.55.8.127.

C

If the question were to ask for the broadcast address of the subnet instead of the network address, 10.55.8.120 could be correct, as it is the last address in the subnet range for 10.55.8.112/29.

D

In a different question setup where the subnet mask is /28 and the host address is 10.55.8.116, option D would be the correct answer as it would then represent the network address for that subnet, which includes addresses from 10.55.8.112 to 10.55.8.127.

Why candidates pick the wrong answer

B

Students often confuse the broadcast address with the network address because both are special addresses within the subnet. The broadcast address is the highest address, while the network address is the lowest.

C

A common mistake is to assume the network address is the next multiple of 8 after the host address, but the correct network address is the multiple of 8 that is less than or equal to the host address.

D

Students may think the network address is close to the host address, such as rounding down to the nearest even number, but the correct method is to find the block boundary using the subnet mask.

487
MCQmedium

A REST API query returns this JSON snippet: { "interface": { "name": "GigabitEthernet1", "admin-status": "up", "oper-status": "down" } } What does this indicate?

A.The interface is shut down by configuration.
B.The interface is enabled but the link is not operational.
C.The interface is operating normally.
D.The interface is a loopback.
AnswerB

With the JSON output showing an administrative status of 'up' and an operational status of 'down', the interface is administratively enabled (not manually disabled) but has no working link. This typically means there is no cable connected, the remote peer is down, or the physical/media layer is faulty, so the link cannot carry traffic.

Why this answer

The interface is administratively enabled, but it is not operationally passing traffic or achieving link.

Exam trap

Be careful not to confuse 'admin-status' with 'oper-status'. They represent different states of the interface.

Why the other options are wrong

A

The admin-status is 'up', which means the interface is not administratively shut down. A shut down interface would show admin-status as 'down'.

C

An interface operating normally would have oper-status 'up'. The oper-status 'down' indicates the interface is not passing traffic, so it is not functioning normally.

D

A loopback interface is a virtual interface that is always up/up (admin up, oper up) unless administratively shut down. The JSON shows oper-status 'down', which is not typical for a loopback.

When would these options actually be correct?

A

In a different scenario where the JSON snippet indicated 'admin-status': 'down', a question could ask what the configuration state of the interface is. In that case, option A would be correct, as it would indicate the interface is administratively shut down.

C

In a different question setup where the operational status of the interface is explicitly stated as 'up', a candidate might choose this option to indicate that the interface is functioning correctly and passing traffic as expected.

D

In a different question context where the JSON snippet indicates an interface with an operational status of 'up' and is explicitly identified as a loopback interface, this option would be correct. For example, if the question asked about the characteristics of loopback interfaces, this option would apply.

Why candidates pick the wrong answer

A

Students may confuse 'oper-status: down' with an administrative shutdown, but the admin-status field clearly indicates the interface is enabled.

C

Students might see admin-status 'up' and assume the interface is working, but they must check oper-status to confirm actual operation.

D

Students may think any interface with 'up' admin-status is a loopback, but loopback interfaces are virtual and have different characteristics.

488
Multi-Selectmedium

Which THREE statements accurately describe the characteristics of NETCONF and RESTCONF for programmatic network configuration?

Select 3 answers
A.NETCONF uses HTTP methods such as GET, POST, PUT, and DELETE to manipulate configuration data.
B.NETCONF uses XML-encoded RPCs over a secure transport such as SSH or TLS.
C.RESTCONF supports both XML and JSON encoding and uses HTTP methods.
D.Both NETCONF and RESTCONF rely on YANG data models to define the structure of configuration and operational data.
E.NETCONF uses a separate commit operation to apply changes, while RESTCONF uses a similar commit mechanism.
AnswersB, C, D

NETCONF is a network management protocol that encodes all operations, such as <get>, <get-config>, and <edit-config>, as XML Remote Procedure Calls (RPCs). These RPCs are transmitted over a secure, connection-oriented transport: SSH is mandatory for NETCONF (RFC 6242), and TLS is supported as an alternative transport. This XML/RPC architecture differs fundamentally from RESTCONF's HTTP-based REST semantics.

Why this answer

NETCONF uses XML-encoded Remote Procedure Calls (RPCs) over a secure transport such as SSH or TLS, making option B correct. RESTCONF supports both XML and JSON encoding and uses standard HTTP methods (GET, POST, PUT, PATCH, DELETE), so option C is correct. Both NETCONF and RESTCONF rely on YANG data models to define the structure of configuration and operational data, confirming option D.

Option A is incorrect because NETCONF does not use HTTP methods; that is a characteristic of RESTCONF. Option E is wrong because RESTCONF does not use a separate commit operation; changes are applied immediately with each HTTP request, unlike NETCONF's candidate config and commit model.

Exam trap

Cisco often tests the misconception that NETCONF uses HTTP methods like RESTCONF, leading candidates to incorrectly select option A as a correct statement about NETCONF.

Why the other options are wrong

A

NETCONF uses XML‑encoded RPCs over SSH or TLS, not HTTP methods; HTTP methods are used by RESTCONF.

E

RESTCONF does not have a separate commit operation; changes are applied immediately with each HTTP request, unlike NETCONF's explicit commit step.

Why candidates pick the wrong answer

A

Students may confuse NETCONF with RESTCONF, assuming both use HTTP methods since both are used for network configuration. The similar-sounding names and overlapping functionality can lead to this misconception.

E

Students might assume that because both protocols use YANG models and serve similar purposes, they would share a commit mechanism. However, RESTCONF follows RESTful principles where each request is atomic and immediately applied.

489
MCQeasy

What data format is commonly used in REST API responses because it is lightweight and easy for applications to parse?

A.BGP
B.JSON
C.STP
D.ARP
AnswerB

JSON (JavaScript Object Notation) is the standard data format for REST API responses because it is lightweight, human-readable, and language-independent. Its key-value structure maps directly to objects in most programming languages, making it trivial to parse and generate. Unlike XML, JSON has a compact syntax with minimal overhead, which reduces bandwidth and latency in HTTP transactions. This practical interoperability is why RESTful APIs overwhelmingly default to JSON for serializing payloads.

Why this answer

JSON is widely used in REST APIs for structured data exchange.

Exam trap

Avoid assuming older or more traditional formats like XML or CSV are used in modern REST APIs; JSON is the standard.

Why the other options are wrong

A

BGP (Border Gateway Protocol) is a path-vector routing protocol used to exchange routing information between autonomous systems, not a data serialization format. It is unrelated to REST API data formatting.

C

STP (Spanning Tree Protocol) is a Layer 2 protocol that prevents loops in Ethernet networks, not a data format for APIs. It operates at the data link layer and has no role in REST API responses.

D

ARP (Address Resolution Protocol) is used to map IP addresses to MAC addresses in local networks, not a data serialization format. It is a network layer protocol, not an API data format.

When would these options actually be correct?

A

If the question were to ask about networking protocols used for routing data between networks, BGP would be the correct answer. For example, a question might state, 'Which protocol is essential for inter-domain routing on the internet?'

C

If the exam question asked about protocols used in network communications that ensure loop-free topologies in switched networks, then STP would be the correct answer. For example, a question might ask which protocol is crucial for maintaining network stability in a Layer 2 Ethernet environment.

D

If the exam question asked about protocols used for network communication and their roles in data transmission, ARP could be the correct answer when discussing how devices resolve IP addresses to MAC addresses on a local network.

Why candidates pick the wrong answer

A

Students might confuse the acronym BGP with JSON due to both being associated with networking, but BGP is a protocol, not a data format.

C

The acronym STP might be mistaken for a data format because it is a common networking term, but it is unrelated to API data representation.

D

ARP is a well-known networking protocol, and students might incorrectly think it could be used for data exchange in APIs due to its role in network communication.

490
MCQhard

A network administrator has configured 802.1X port-based authentication on a Cisco IOS-XE switch for a new access port connected to a user workstation. The workstation is failing to gain network access. The switch port is in the 'authorized' state, but the workstation cannot ping the default gateway. The administrator checks the running configuration and the authentication session details. What is the most likely cause of the issue?

A.The RADIUS server has not been configured with the correct shared secret, causing authentication to fail silently.
B.The RADIUS server returned a VLAN ID that placed the port in a VLAN lacking connectivity to the default gateway, such as a VLAN without an SVI or incorrect subnet assignment.
C.The switch port is in 'err-disabled' state due to a port-security violation, preventing any traffic.
D.The workstation's supplicant is not configured with the correct EAP method, causing the authentication to use the guest VLAN instead.
AnswerB

After successful 802.1X authentication, the switch can dynamically assign the port to a VLAN specified in the RADIUS Access-Accept message. If that VLAN exists but is not the correct user VLAN—for example, a dead-end VLAN or a VLAN where the default gateway IP is not configured or reachable—the device will appear authorized but will be unable to reach the gateway, exactly matching the symptoms.

Why this answer

The switch port is in the 'authorized' state, indicating that 802.1X authentication succeeded and the RADIUS server sent an Access-Accept. However, the workstation cannot ping the default gateway, pointing to a connectivity issue after authentication. The most likely cause is that the RADIUS server returned a VLAN assignment (via the Tunnel-Private-Group-ID attribute) that placed the port in a VLAN that is not the intended one, such as a management VLAN without a gateway, or a VLAN missing a routed SVI, leaving the workstation isolated despite successful authentication.

Exam trap

Cisco often tests the distinction between authentication success (port state 'authorized') and network connectivity success (correct VLAN assignment), tricking candidates into focusing on authentication failures when the real issue is a post-authentication VLAN misconfiguration.

Why the other options are wrong

A

The show authentication sessions output indicates 'Authz Success', meaning authentication and authorization succeeded. A shared secret mismatch would cause authentication failure, not a successful authorization.

C

The show command output clearly shows the port status as 'AUTHORIZED' and 'Authz Success'. There is no indication of err-disable. Port-security violations would show a different status, such as 'err-disabled' or 'security-violation'.

D

The output shows 'authVlan = 100' and the session is authorized with 'method = dot1x' and 'status = AUTHORIZED'. This indicates the supplicant successfully authenticated and was placed in the auth VLAN, not the guest VLAN. If the supplicant had failed, the port would be in the guest VLAN.

Why candidates pick the wrong answer

A

Students often confuse shared secret issues with other RADIUS configuration problems, but the authentication success message rules this out.

C

Port security violations are a common cause of connectivity issues, and students may assume any access problem is due to err-disable without checking the port status.

D

Students may think that EAP method mismatch leads to guest VLAN usage, but the authorization success shows the supplicant authenticated correctly.

491
MCQhard

An engineer is allowed to log in to a router but cannot enter configuration mode. Which AAA function most directly explains that outcome?

A.Authorization
B.Authentication
C.Accounting
D.DNS
AnswerA

Authorization is the AAA component that determines what an authenticated user is permitted to do, including which commands they may execute and whether they can enter privileged EXEC or global configuration modes. In this scenario, authentication already succeeded because the user logged in, but the router's authorization policy restricts this user to lower privilege levels, preventing configuration access. Thus, the correct answer is authorization.

Why this answer

Authorization most directly explains the outcome. In practical terms, the user has already passed authentication because login succeeded, but the permissions assigned to that identity do not allow configuration-level actions. This is exactly the sort of role separation authorization is meant to enforce.

This is a good example of why authentication and authorization are not the same thing.

Exam trap

A common exam trap is assuming that authentication alone controls all user permissions after login. Candidates often confuse authentication with authorization, thinking that successful login means full access. However, authentication only verifies identity, while authorization determines what commands or modes the user can access.

This confusion leads to incorrect answers, especially when a user can log in but cannot enter configuration mode. Remember, authorization is the AAA function that restricts user capabilities after authentication succeeds.

Why the other options are wrong

B

Authentication is incorrect because it only verifies the user's identity to allow login; it does not control what commands or modes the user can access after login.

C

Accounting is incorrect because it only records user activity and command usage for auditing purposes and does not influence login permissions or command access.

D

DNS is incorrect because it is related to name resolution and does not control user authentication, authorization, or command permissions on network devices.

When would these options actually be correct?

B

If the question asked about a scenario where an engineer is unable to log in at all due to incorrect credentials or failed identity verification, then authentication would be the correct answer, as it directly pertains to the login process.

C

If the question asked about monitoring user actions and logging their activities on the router, then accounting would be the correct answer. For example, a question might state that a user can log in and perform actions, but their activities are being recorded for auditing purposes.

D

If the question were about a scenario where a router's DNS settings were misconfigured, leading to failures in resolving hostnames, the correct answer could be DNS. For example, if the question asked why a router cannot reach external servers due to DNS issues, option D would be appropriate.

Why candidates pick the wrong answer

B

Students often confuse authentication and authorization because both are part of AAA and involve user access. They may think that if a user cannot perform certain actions, it must be an authentication failure, but authentication only checks identity, not permissions.

C

Accounting is the least understood AAA component. A test-taker might think that if an action is not allowed, it might be because it is not being accounted for, but accounting has no role in access control.

D

DNS is a common networking term, and a student with limited AAA knowledge might guess it as a distractor, especially if they recall that DNS is used for network services. However, it is completely irrelevant to AAA functions.

492
Multi-Selectmedium

Which TWO statements correctly describe the configuration and verification of OSPFv3 for IPv6?

Select 2 answers
A.OSPFv3 uses link-local IPv6 addresses to form neighbor adjacencies.
B.OSPFv3 uses global unicast IPv6 addresses to form neighbor adjacencies.
C.OSPFv3 is automatically enabled on all IPv6-enabled interfaces when the routing process is configured.
D.The 'show ospfv3 neighbor' command displays neighbor state, neighbor ID, and interface information.
E.The 'show ospfv3 neighbor' command displays the IPv6 address of the neighbor's interface as the neighbor ID.
AnswersA, D

When an OSPFv3 router sends Hello packets, it uses the IPv6 link-local address assigned to the outgoing interface as the source, and similarly for Database Description and other OSPFv3 packets. Because link-local addresses (FE80::/10) are valid only on the local segment and cannot be routed, they guarantee that OSPFv3 control traffic stays on that link. This design allows an adjacency to form even if the interface has no global IPv6 address configured.

Why this answer

OSPFv3 for IPv6 uses link-local IPv6 addresses (FE80::/10) to form neighbor adjacencies, not global unicast addresses (so B is incorrect). OSPFv3 does not automatically enable on all IPv6 interfaces; each interface must be explicitly configured under the OSPFv3 process using the 'ipv6 ospf' command (so C is incorrect). The 'show ospfv3 neighbor' command displays the neighbor's Router ID (a 32-bit value), not the IPv6 address of the neighbor's interface (so E is incorrect).

Correct options A and D accurately describe OSPFv3 neighbor formation using link-local addresses and the information shown by the 'show ospfv3 neighbor' command, which includes neighbor state, neighbor ID, and interface.

Exam trap

Cisco often tests the misconception that OSPFv3 behaves like OSPFv2 by using global unicast addresses for neighbor formation, or that enabling the OSPFv3 process automatically activates it on all interfaces, when in fact each interface must be explicitly enabled under the OSPFv3 process.

Why the other options are wrong

B

OSPFv3 uses link-local addresses, not global unicast addresses, for neighbor formation.

C

OSPFv3 requires explicit interface configuration under the routing process; it is not automatically enabled.

E

The neighbor ID shown is the Router ID, not the IPv6 address of the neighbor's interface.

Why candidates pick the wrong answer

B

Students may confuse OSPFv3 with OSPFv2, which uses IPv4 addresses for neighbor formation, or mistakenly think that global addresses are required for routing protocol communication.

C

Some routing protocols like RIPng are automatically enabled on all interfaces, leading students to incorrectly assume OSPFv3 behaves similarly.

E

Students may assume that because OSPFv3 is for IPv6, the neighbor ID would be an IPv6 address, but OSPFv3 retains the concept of a 32-bit router ID for identification.

493
MCQhard

In a network running STP, SW2 became the root bridge for VLAN 10. Both SW1 and SW2 have the same bridge priority. Why did SW2 become the root?

A.Because SW2 has the lower bridge ID due to the lower MAC address.
B.Because SW2 has the higher VLAN number configured.
C.Because SW2 has more trunk ports than SW1.
D.Because SW2 has the highest bridge priority.
AnswerA

In STP, each switch's bridge ID is composed of a configurable priority (default 32768) and its MAC address, concatenated to form a unique identifier. When SW1 and SW2 have equal bridge priority, the election breaks the tie by comparing the MAC portion, and the numerically lower MAC address wins. Since SW2's MAC is lower, its bridge ID is lower, making it the root bridge for the VLAN.

Why this answer

SW2 became the root bridge because its bridge ID is lower. In practical terms, spanning tree elects the root bridge by comparing bridge IDs, which are based on priority plus MAC address. The device with the lowest bridge ID wins. In the exhibit, both switches use the same priority, so the tie is broken by the lower MAC address.

This is a classic STP interpretation question. Many learners focus only on priority, but if priorities match, the MAC address becomes decisive.

Exam trap

Remember, in STP, lower values are preferred. If priorities match, the MAC address decides the root bridge.

Why the other options are wrong

B

The VLAN number is not a factor in the STP root bridge election. The election is based solely on bridge ID, which consists of bridge priority and MAC address.

C

The number of trunk ports does not affect the root bridge election. STP uses bridge ID (priority and MAC address) to determine the root bridge, not port count or type.

D

The root bridge is elected based on the lowest bridge ID, not the highest. A higher bridge priority (numerically larger) makes a switch less likely to become root.

When would these options actually be correct?

B

In a different question setup where the context involves selecting a root bridge based solely on VLAN configuration, such as asking which switch would be preferred if all other factors were equal and only VLAN numbers were considered, this option could be correct.

C

In a different question setup, if the question asked why a switch with the most trunk ports would be preferred for forwarding traffic in a network, then this option could be correct. For example, if the question focused on optimizing traffic flow and redundancy in a network design scenario, the switch with more trunk ports might be favored.

D

In a different question context where the bridge priority is the only factor being considered, and SW2's bridge priority is indeed higher than that of other switches, this option would be correct. For example, if the question asked which switch would become the root bridge if all other factors were equal but bridge priority was higher for SW2.

Why candidates pick the wrong answer

B

Students might confuse VLAN numbering with bridge priority or think that higher VLAN numbers have some influence, but STP operates per VLAN with independent elections.

C

Some might think that more trunk ports indicate a more central switch, but STP does not consider port count in the election process.

D

Students may mistakenly think 'highest' means best, but in STP, lower values are preferred for both priority and MAC address.

494
MCQhard

A router pair is directly connected, but they do not become OSPF neighbors. IP addressing and area assignment are correct. What is the most likely cause?

A.OSPF network type mismatch on the connected interfaces
B.Duplicate default routes on both routers
C.Missing VLAN trunking on the link
D.The OSPF process IDs are required to match
AnswerA

One side configured as point-to-point expects no DR/BDR election and often uses a different hello/dead interval, while the other side as broadcast conducts DR/BDR elections and relies on matching timers. This mismatch prevents the routers from reaching the two-way state, so they never form a stable adjacency even though the link is physically up.

Why this answer

OSPF network type mismatch is a frequent reason for adjacency failure when basic IP and area settings are correct. If one side is configured as broadcast and the other as point-to-point, the hello timers, neighbor discovery behavior, and designated router election rules diverge, preventing neighbor formation. Unlike process IDs (which are locally significant), a mismatch in network type directly affects how OSPF hellos are processed.

This is a well-known L2/L3 misconfiguration that must be checked alongside router‑ID and authentication parameters.

Exam trap

A common exam trap is assuming that OSPF process IDs must match on both routers to form neighbors. Many candidates mistakenly believe process IDs are globally significant, but they are only locally important identifiers. Another tempting mistake is blaming IP addressing or area mismatches without checking the OSPF network type.

Since network type controls how OSPF hellos are sent and received, a mismatch between broadcast and point-to-point types can silently block adjacency formation even when IP and area configurations appear correct. This subtlety often leads to confusion during troubleshooting and exam scenarios.

Why the other options are wrong

B

Incorrect because duplicate default routes affect routing decisions but do not impact the OSPF neighbor formation process, which depends on hello packets and network type compatibility.

C

Incorrect since VLAN trunking applies to Layer 2 switch ports, not routed interfaces running OSPF. The problem described involves OSPF adjacency, not VLAN or trunk configuration.

D

Incorrect because OSPF process IDs are locally significant identifiers and do not need to match between routers for neighbor relationships to form. This does not cause adjacency failure.

When would these options actually be correct?

B

In a different scenario where the question involves troubleshooting routing issues in a network with multiple routing protocols, and the presence of duplicate default routes is explicitly stated as causing routing conflicts, this option would be correct.

C

In a scenario where the question specifies that OSPF is being used over a trunk link between two switches, and the interfaces are configured as access ports instead of trunk ports, this option would be correct. The lack of trunking would prevent OSPF from seeing the necessary subnets to form neighbors.

D

In a different scenario where the question specifies that two routers are configured with different OSPF process IDs and are unable to establish adjacency, this option would be correct. For example, if the question indicates that both routers are configured with different OSPF process IDs but are intended to be in the same OSPF area, then this would be the cause of the issue.

Why candidates pick the wrong answer

B

Students might confuse routing issues with neighbor formation, thinking that duplicate routes could cause instability that prevents adjacency. However, OSPF neighbor formation is independent of the routes being advertised.

C

Test-takers might assume that any link between routers needs trunking if they are familiar with switch configurations, but OSPF neighbor formation over routed interfaces does not involve VLANs.

D

Many students mistakenly believe that OSPF process IDs must match because they are used to configure OSPF, but they are only used to identify the OSPF process on the local router.

495
MCQeasy

Which HTTP method is commonly used to retrieve information from a REST API without modifying the resource?

A.POST
B.GET
C.PUT
D.DELETE
AnswerB

The GET method is designed to retrieve a representation of a specified resource — it is safe, meaning it never changes server state, and idempotent, so multiple identical requests produce the same result. In RESTful APIs, GET is the standard operation for querying or fetching information, and it typically carries no request body, with all parameters in the URL query string.

Why this answer

GET is the standard HTTP method for retrieving a resource representation without changing the resource.

Exam trap

Do not confuse retrieval with modification. GET retrieves data without altering the resource, unlike POST, PUT, or DELETE.

Why the other options are wrong

A

POST is used to create a new resource or submit data to be processed, which often results in a change in server state. It is not idempotent and is not designed for retrieval without modification.

C

PUT is used to update or replace an existing resource, which modifies the resource. It is not a safe or idempotent method for retrieval without side effects.

D

DELETE is used to remove a resource, not retrieve it. Using DELETE would modify the resource by deleting it, which contradicts the requirement of not modifying the resource.

When would these options actually be correct?

A

If the question were to ask which HTTP method is commonly used to send data to a REST API for creating a new resource, then POST would be the correct answer. This would align with the intended use of the method.

C

In a scenario where the question asks which HTTP method is used to update a resource on a REST API, the correct answer would be PUT. For example, 'Which HTTP method would you use to update the details of a user profile in a REST API?' would make PUT the right choice.

D

In a different exam scenario, a question might ask which HTTP method is used to remove a resource from a REST API, with options including POST, GET, PUT, and DELETE. In this case, DELETE would be the correct answer.

Why candidates pick the wrong answer

A

POST is a common HTTP method, and students might think it can be used to retrieve data because it can send data to the server, but the primary purpose is creation or submission, not safe retrieval.

C

PUT is often associated with updating resources, and students might mistakenly believe it can retrieve data because it targets a specific resource URI, but its operation is modification, not retrieval.

D

Students might confuse DELETE with a method that retrieves information because both involve accessing a resource, but DELETE's purpose is removal, not retrieval.

496
Drag & Dropmedium

Drag and drop the following IOS-XE CLI commands into the correct order to configure AAA with a RADIUS server and then enable 802.1X port authentication on an interface.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

AAA configuration must precede 802.1X. The correct order is: first enable AAA globally with 'aaa new-model', then define the RADIUS server with 'radius server RADIUS-SERVER', then globally enable 802.1X with 'dot1x system-auth-control', and finally on the interface set authentication port-control with 'authentication port-control auto'.

Exam trap

Do not confuse the order of global AAA enablement and RADIUS server definition. AAA must be enabled first. Also, remember that global 802.1X enablement comes before interface-specific commands.

497
PBQhard

You are connected to SW1 via the console. SW1 is a Layer 2 switch connected to a PC on port G0/1. The network administrator wants to secure the port by allowing only two MAC addresses and enabling sticky MAC learning. Additionally, if a violation occurs, the port should be put into error-disabled state. Configure port security on G0/1 with maximum MAC addresses of 2, sticky learning, and shutdown violation mode.

Network Topology
G0/1SW1PC

Hints

  • •Port security must first be enabled with switchport port-security.
  • •Sticky MAC dynamically learns and saves MAC addresses to running-config.
A.SW1(config-if)# switchport port-security SW1(config-if)# switchport port-security maximum 2 SW1(config-if)# switchport port-security mac-address sticky SW1(config-if)# switchport port-security violation shutdown
B.SW1(config-if)# switchport port-security SW1(config-if)# switchport port-security maximum 2 SW1(config-if)# switchport port-security mac-address sticky SW1(config-if)# switchport port-security violation restrict
C.SW1(config-if)# switchport port-security SW1(config-if)# switchport port-security maximum 2 SW1(config-if)# switchport port-security mac-address sticky SW1(config-if)# switchport port-security violation protect
D.SW1(config-if)# switchport port-security SW1(config-if)# switchport port-security maximum 2 SW1(config-if)# switchport port-security mac-address 0000.1111.2222 SW1(config-if)# switchport port-security violation shutdown
AnswerA
solution
! SW1
interface GigabitEthernet0/1
switchport port-security
switchport port-security maximum 2
switchport port-security mac-address sticky
switchport port-security violation shutdown

Why this answer

The correct configuration enables port security, sets the maximum MAC addresses to 2, enables sticky learning, and sets the violation mode to shutdown. This meets all requirements: limiting MAC addresses, sticky learning, and error-disabling the port on violation.

Exam trap

200-301 often tests the difference between violation modes, particularly that 'restrict' and 'protect' do not error-disable the port, which is a common misconception.

Why the other options are wrong

B

The violation mode 'restrict' does not place the port in error-disabled state; it only drops traffic from unauthorized MACs and increments a counter.

C

The 'protect' mode drops violating frames but does not disable the port or generate syslog messages; it is the least restrictive violation mode.

D

The command 'switchport port-security mac-address' manually assigns a MAC address, whereas 'switchport port-security mac-address sticky' enables dynamic learning and storage of MAC addresses.

Why candidates pick the wrong answer

B

Candidates may confuse 'restrict' with 'shutdown' because both are violation actions, but only 'shutdown' disables the port.

C

Candidates might think 'protect' is a safe option because it prevents unauthorized access, but it does not meet the requirement of error-disabling the port.

D

Candidates may think that manually configuring a MAC address is equivalent to sticky learning, but sticky learning is a dynamic process that automatically adds MACs as they are seen.

498
PBQhard

You are connected to R1 via console. R1 must reach the remote loopback 2001:db8:1::1/128 on R3 via R2 (2001:db8:0:2::2/64). Currently, IPv6 ping fails. Additionally, configure a floating static default route via R2 (198.51.100.2/30) with an appropriate AD so that it only becomes active if a dynamic default route (with default AD 1) is absent. Identify and fix the recursive routing failure, correct the next-hop, set the correct AD, and ensure the default route is present.

Network Topology
G0/12001:db8:0:2::1/64G0/12001:db8:0:2::2/64G0/12001:db8:0:2::2/64R2R1R3

Hints

  • •Check if the next-hop address is directly connected; use show ipv6 route to see if a recursive route exists.
  • •The default AD for a static route is 1; for a floating static route to back up a dynamic protocol, use a higher AD (e.g., 254).
  • •Use the exit interface in the static route to avoid recursive lookup failure.
A.Change the IPv6 static route to '2001:db8:1::1/128 GigabitEthernet0/1 2001:db8:0:2::2' and set the floating default route's AD to 254.
B.Change the IPv6 static route to '2001:db8:1::1/128 2001:db8:0:2::1' and set the floating default route's AD to 1.
C.Change the IPv6 static route to '2001:db8:1::1/128 GigabitEthernet0/1 2001:db8:0:2::2' and set the floating default route's AD to 1.
D.Change the IPv6 static route to '2001:db8:1::1/128 2001:db8:0:2::2' and set the floating default route's AD to 254.
AnswerA, D
solution
! R1
no ipv6 route 2001:db8:1::1/128 2001:db8:0:2::1
ipv6 route 2001:db8:1::1/128 GigabitEthernet0/1 2001:db8:0:2::2
no ip route 0.0.0.0 0.0.0.0 198.51.100.2 1
ip route 0.0.0.0 0.0.0.0 198.51.100.2 254

Why this answer

The original IPv6 static route uses the next-hop 2001:db8:0:2::1, which is R1's own G0/1 address, causing a routing loop. Correct the route by specifying a directly connected remote next-hop (2001:db8:0:2::2) either with or without the exit interface. Set the floating static default route with an AD higher than the dynamic route's default AD (e.g., 254) so it becomes a backup.

Option A (exit interface + next-hop) and Option D (next-hop only) both achieve this; Options B and C fail due to wrong next-hop or AD.

Exam trap

Be careful: using the router's own IP as a next-hop creates a forwarding loop, not a reachability failure. For a floating static route, the AD must be higher than the active route's AD to act as a backup.

Why the other options are wrong

B

The next-hop is R1's own address (loop) and AD 1 makes the route equally preferred to dynamic routes, defeating the floating purpose.

C

AD 1 makes the route equally preferred, not a floating backup.

Why candidates pick the wrong answer

B

Candidates may think that any IPv6 address can be used as a next-hop without considering direct connectivity, and they may mistakenly believe that AD 1 is appropriate for a floating route because it is the default for static routes.

C

Candidates may think that AD 1 is the default for static routes and assume it is correct for a floating route, not realizing that a floating route must have a higher AD to serve as a backup.

499
Multi-Selecteasy

A support engineer is explaining why a host uses ARP before sending a frame on an Ethernet LAN. Which two statements are correct?

Select 2 answers
A.ARP resolves an IPv4 address to a MAC address
B.A host may ARP for its default gateway when sending to a remote network
C.ARP is used to discover the remote router's OSPF router ID
D.ARP replaces DNS for hostname resolution
AnswersA, B

ARP's core function is to dynamically discover the hardware (MAC) address associated with a given IPv4 address when a host must deliver a frame on the same Layer 2 segment. The host broadcasts an ARP request containing the target IPv4 address; the node that owns that address replies with its MAC address, which is then stored in the ARP cache. Without this mapping, the host cannot construct the Ethernet frame header with the correct destination MAC, making ARP a prerequisite for IPv4 communication over most LAN technologies.

Why this answer

On Ethernet, the sender needs a destination MAC address. For remote destinations, that usually means ARPing for the default gateway's MAC.

Exam trap

A frequent exam trap is selecting options that confuse ARP with DNS or routing protocol functions. For example, some may incorrectly believe ARP resolves hostnames like DNS or discovers OSPF router IDs. These misunderstandings arise because ARP and DNS both involve address resolution, but ARP only maps IPv4 addresses to MAC addresses on the local LAN, while DNS maps hostnames to IP addresses.

Similarly, ARP does not interact with routing protocols like OSPF. Misinterpreting ARP’s role leads to incorrect answers and can cost points on the CCNA exam.

Why the other options are wrong

C

Incorrect because ARP does not discover routing protocol identifiers like OSPF router IDs; these are unrelated to Layer 2 address resolution.

D

Incorrect because ARP does not replace DNS; DNS resolves hostnames to IP addresses, whereas ARP resolves IP addresses to MAC addresses.

When would these options actually be correct?

C

In a question about OSPF neighbor discovery on a point-to-point link, an option stating 'OSPF uses hello packets to discover neighbor router IDs' would be correct. Alternatively, if the question asked about discovering a router's OSPF router ID, the correct answer would involve show commands or OSPF processes, not ARP.

D

In a question about protocols that map hostnames to IP addresses, an option stating 'DNS replaces the need for hosts file entries' would be correct, but ARP is not involved in hostname resolution.

Why candidates pick the wrong answer

C

Candidates may confuse ARP's role in discovering MAC addresses with other discovery protocols, or mistakenly think ARP is involved in OSPF operations because both operate at Layer 2/3 boundaries.

D

Candidates may confuse ARP with DNS because both involve address resolution (IP to MAC vs. hostname to IP), leading to the mistaken belief that ARP can substitute for DNS.

500
Multi-Selectmedium

Which three of the following are characteristics of Layer 2 Ethernet switches that improve network performance? (Choose three.)

Select 3 answers
.They create separate collision domains per port.
.They forward frames based on the destination MAC address.
.They reduce the number of broadcast domains.
.They can perform cut-through switching to reduce latency.
.They use IP addresses to make forwarding decisions.
.They automatically block all unknown unicast frames.

Why this answer

Layer 2 Ethernet switches improve network performance by creating separate collision domains per port, eliminating collisions between devices on different ports. They forward frames based on the destination MAC address, enabling efficient hardware-based switching. Cut-through switching reduces latency by starting to forward as soon as the destination MAC address is read.

The other options are incorrect: switches do not reduce broadcast domains (broadcasts are forwarded to all ports in the same VLAN unless a router or VLAN segmentation is used); switches operate at Layer 2 using MAC addresses, not IP addresses; and unknown unicast frames are flooded out all ports except the incoming port, not automatically blocked, to ensure connectivity if the destination is unknown.

Exam trap

Cisco often tests the distinction between collision domains and broadcast domains, where candidates mistakenly think switches reduce broadcast domains, but switches only segment collision domains while broadcast domains are controlled by VLANs or routers.

501
MCQmedium

A campus switch has VLANs 10, 20, and 30 configured. Port GigabitEthernet0/5 connects to a server that must send and receive traffic for all three VLANs, and the server's NIC supports 802.1Q tagging. The administrator wants the server to handle VLAN tagging itself. Which configuration on GigabitEthernet0/5 is appropriate?

A.switchport mode access and switchport access vlan 10
B.switchport mode trunk, switchport trunk native vlan 10, and switchport access vlan 20
C.switchport mode trunk and switchport trunk allowed vlan 10,20,30
D.switchport mode dynamic desirable and switchport trunk allowed vlan 10,20,30
AnswerC

A trunk port with the allowed VLAN list permits the server to send and receive tagged frames for VLANs 10, 20, and 30. Because the server NIC supports 802.1Q, it can create and interpret the tags itself, so the switch does not need to assign an access VLAN. This matches the requirement for a single interface carrying multiple VLANs.

Why this answer

When a server NIC performs 802.1Q tagging itself, the switch port must be a trunk so tagged frames for multiple VLANs can pass. Restricting the allowed VLAN list to 10, 20, and 30 limits unnecessary traffic and matches the requirement. A static trunk avoids DTP negotiation issues with a server that does not run DTP.

Exam trap

The trap here is assuming an access port can carry multiple VLANs if the NIC tags frames, but access ports do not forward tagged traffic for other VLANs.

502
MCQhard

A network engineer has enabled DHCP snooping on a Catalyst switch to prevent rogue DHCP servers. All access ports in VLAN 10 are untrusted. A router attached to a trunk port on the switch acts as the default gateway for VLAN 10 and is configured with the ip helper-address 10.1.2.5, which points to a remote DHCP server. After enabling DHCP snooping, hosts in VLAN 10 cannot obtain IP addresses; packet captures show DHCPDISCOVER messages are sent, but no DHCPOFFER is received. What is the most likely cause?

A.The router's ip helper-address command is pointing to an incorrect DHCP server IP address.
B.The switch port connecting to the router is not configured as a trusted port for DHCP snooping.
C.The DHCP server is on a different subnet, so the switch needs a switched virtual interface (SVI) in VLAN 10 with an IP address for Layer 3 connectivity.
D.DHCP snooping is dropping DHCPDISCOVER messages because the client access ports are untrusted.
AnswerB

DHCP snooping trusts only designated ports to forward DHCP server messages. Since the router relays the DHCPOFFER onto the trunk port, an untrusted port will cause the switch to discard the offer, resulting in DHCP failure.

Why this answer

DHCP snooping treats all ports as untrusted by default. When a router acting as a DHCP relay is connected to an untrusted trunk port, the switch drops DHCPOFFER messages received from the router because they originate from an untrusted interface. Configuring the trunk port as trusted allows DHCP server responses (OFFER, ACK) to pass through to clients.

Exam trap

Cisco often tests the distinction that DHCP snooping blocks DHCP server messages (OFFER/ACK/NAK) on untrusted ports, not client messages (DISCOVER/REQUEST), leading candidates to incorrectly assume client messages are dropped.

Why the other options are wrong

A

This distractor exploits the common tendency to blame the helper address configuration first, overlooking the security feature that silently drops the returning DHCPOFFER.

C

This plays on the misconception that a switch requires an IP address on the client VLAN to facilitate DHCP, when in fact the router acting as the relay agent provides Layer 3 connectivity.

D

This misinterprets DHCP snooping behavior: it assumes all DHCP traffic is filtered on untrusted ports, overlooking the critical distinction that only server-side messages are blocked, not client requests.

503
MCQmedium

A user reports that their desk port stopped working immediately after they connected a small switch. The interface shows err-disabled, and the log mentions BPDU Guard. What most likely happened?

A.The port received a BPDU and BPDU Guard shut it down.
B.DHCP snooping blocked the user's ARP requests.
C.Port security moved the port to protect mode.
D.The trunk native VLAN matched incorrectly.
AnswerA

BPDU Guard on a PortFast-enabled edge port immediately err-disables the interface upon receiving any BPDU, typically from an unauthorized switch. This matches the symptom of a desk port stopping right after connection, and the log would explicitly show 'bpduguard error detected' putting the port in err-disable state.

Why this answer

BPDU Guard is commonly enabled on PortFast access ports to protect the topology. If the port receives a BPDU, the switch assumes another switch may have been connected and places the port into err-disabled state. That is exactly the protective behavior you want at the edge.

Exam trap

A frequent exam trap is mistaking BPDU Guard triggers for issues caused by DHCP snooping or port security. Candidates may incorrectly assume that DHCP snooping blocking ARP or port security violations cause the err-disabled state when the log explicitly mentions BPDU Guard. Another pitfall is confusing native VLAN mismatches on trunks as the cause, but these do not generate BPDU Guard errors.

The key is to recognize that BPDU Guard specifically responds to receiving BPDUs on PortFast-enabled ports, which signals an unexpected switch connection and leads to err-disable. Misreading the log or symptoms can lead to selecting incorrect answers that do not align with BPDU Guard’s function.

Why the other options are wrong

B

Incorrect. DHCP snooping blocks unauthorized DHCP messages but does not cause BPDU Guard to err-disable a port. The log specifically mentions BPDU Guard, so DHCP snooping is unrelated here.

C

Incorrect. Port security violations cause err-disable states but are triggered by MAC address violations, not by receiving BPDUs. The log message points to BPDU Guard, not port security.

D

Incorrect. A trunk native VLAN mismatch causes VLAN tagging issues but does not trigger BPDU Guard or err-disable a port due to BPDU reception. This option does not explain the BPDU Guard log message.

When would these options actually be correct?

B

In a scenario where a user connects a device that sends DHCP requests and the switch is configured with DHCP snooping, a question could ask about the impact of DHCP snooping on ARP requests. If the switch detects invalid ARP requests from a rogue device, it could block those requests, making this option correct.

C

If the question described a scenario where a switch port was configured with port security and a device connected had a MAC address not previously seen, resulting in a violation, then port security could indeed place the port in protect mode. This would be a valid context for option C to be correct.

D

In a different question setup, if a user reports that a trunk port is not passing traffic and the logs indicate a native VLAN mismatch, then this option would be correct. The question would need to focus on trunk configurations and VLAN settings to validate this scenario.

Why candidates pick the wrong answer

B

Students might confuse DHCP snooping with BPDU Guard because both are security features that can block traffic. However, DHCP snooping operates at Layer 2/3 for DHCP messages, while BPDU Guard specifically handles BPDUs and err-disables the port.

C

Port security and BPDU Guard are both common access port security features. A student might think that connecting a switch triggers port security due to multiple MAC addresses, but the log explicitly points to BPDU Guard, making this incorrect.

D

Students might associate VLAN mismatches with spanning-tree issues, but BPDU Guard is a separate mechanism. The scenario describes a desk port (access port) and a small switch, which is more likely to trigger BPDU Guard than a native VLAN mismatch.

504
Multi-Selectmedium

Which three options best describe how machine learning models are trained for network anomaly detection? (Choose three.)

Select 3 answers
.Using historical baseline traffic data to learn normal behavior patterns
.Labeling datasets with known attack signatures for supervised learning
.Applying unsupervised clustering to identify deviations without predefined labels
.Requiring manual threshold configuration for every monitored metric
.Training exclusively on synthetic data generated by simulation tools
.Relying solely on SNMP polling intervals to detect anomalies

Why this answer

Machine learning models for network anomaly detection are effectively trained using historical baseline traffic data to learn normal behavior patterns, which allows the model to identify deviations that may indicate anomalies. Labeled datasets with known attack signatures enable supervised learning, where the model learns to classify traffic as normal or malicious based on examples. Unsupervised clustering techniques, such as k-means or DBSCAN, can identify deviations without predefined labels by grouping similar data points and flagging outliers as potential anomalies.

The three incorrect options—manual threshold configuration, training exclusively on synthetic data, and reliance on SNMP polling—are not characteristic of ML training methods. Manual threshold configuration is a rule‑based approach that does not involve learning from data. Training exclusively on synthetic data is not representative of real‑world traffic patterns and would not generalize well.

Relying solely on SNMP polling intervals is a traditional monitoring method, not a machine learning technique.

Exam trap

Cisco often tests the distinction between traditional rule-based monitoring (e.g., SNMP thresholds) and machine learning approaches, expecting candidates to recognize that ML models learn patterns automatically rather than relying on static thresholds or synthetic-only data.

505
MCQmedium

Which protocol is most directly responsible for keeping device clocks synchronized across a network?

A.NTP
B.TFTP
C.DHCP
D.CDP
AnswerA

NTP (Network Time Protocol) is the correct answer because it is the industry-standard protocol designed specifically to synchronize device clocks across a network. It uses a hierarchical stratum system to distribute accurate time from authoritative time sources, typically over UDP port 123, ensuring consistent timestamps for syslogs, authentication, and network troubleshooting. Without NTP, event logs and monitoring data from different devices cannot be reliably correlated.

Why this answer

The correct protocol is NTP. In plain language, NTP helps devices agree on the current time so that logs, authentication events, monitoring data, and troubleshooting records line up accurately. Without consistent time, a network team may see events from multiple devices but be unable to reconstruct the actual sequence correctly.

This matters more than many people realize because accurate time underpins many operational workflows. Syslog messages, security events, and monitoring alerts become much easier to trust when devices are synchronized. DHCP, TFTP, and CDP are useful for other purposes, but they do not exist to align device clocks. NTP is the protocol specifically associated with time synchronization.

Exam trap

A frequent exam trap is selecting DHCP, TFTP, or CDP as the protocol responsible for clock synchronization. DHCP is often confused because it deals with network configuration, but it does not synchronize time. TFTP might seem relevant due to its role in transferring files like configurations, but it has no time-related function.

CDP is a Cisco proprietary protocol for device discovery and neighbor information exchange, not for time services. Candidates must recognize that only NTP is designed specifically to keep device clocks synchronized across a network, which is critical for accurate logging and event correlation.

Why the other options are wrong

B

TFTP is incorrect because it is a simple file transfer protocol used for tasks like configuration file transfers, not for synchronizing device clocks.

C

DHCP is incorrect because it provides IP addressing and network configuration to clients but does not handle time synchronization between devices.

D

CDP is incorrect because it is a Cisco proprietary protocol for device discovery and neighbor information exchange, not for clock synchronization.

When would these options actually be correct?

B

If the question were to ask which protocol is used for transferring files in a network environment, especially in scenarios where minimal overhead is desired, TFTP would be the correct answer. This could involve a question about lightweight file transfer methods in embedded systems.

C

In a question asking which protocol is responsible for providing network configuration settings, including IP addresses, subnet masks, and default gateways, DHCP would be the correct answer. For example, a question could ask about the protocol that dynamically assigns IP addresses to devices in a local area network.

D

If the exam question asked which protocol is used for discovering and sharing information about network devices, particularly in a Cisco environment, then CDP would be the correct answer, as it facilitates device identification and topology mapping.

Why candidates pick the wrong answer

B

Students may confuse TFTP with NTP due to the similar acronyms (both end in 'TP') and the fact that both are UDP-based protocols. However, their purposes are entirely different.

C

Because DHCP can offer an NTP server address, some students might think DHCP directly synchronizes clocks. However, the actual synchronization is performed by NTP, not DHCP.

D

Students might confuse CDP with NTP because both are commonly used in Cisco networks and both involve device communication. However, CDP is for neighbor discovery, not time sync.

506
Drag & Dropmedium

Drag and drop the following phases into the correct order to configure gRPC streaming telemetry subscription setup and then the NetFlow data path sequence.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First configure telemetry, then set up NetFlow export, define the flow monitor, and finally apply it to an interface.

Exam trap

Be careful not to apply a flow monitor to an interface before it is defined, and remember that telemetry configuration must precede NetFlow export setup.

Why candidates pick the wrong answer

B

Candidates might think that defining and applying the flow monitor first is logical, but they overlook that telemetry setup is a prerequisite for NetFlow export.

C

Candidates may assume NetFlow export is independent of telemetry and can be configured first, but telemetry is a prerequisite for the data path.

D

Candidates might think applying the flow monitor to the interface is the first step, but they forget that the flow monitor must exist first.

507
PBQhard

You are connected to R1 via console. PC1 is connected to R1's GigabitEthernet0/1 interface and is configured with a static IP address. PC1 cannot reach the internet (203.0.113.1). Identify and resolve the connectivity issue. Configure R1 to restore full connectivity for PC1.

Network Topology
203.0.113.1/30PC1Internet

Hints

  • •The problem is not with IP addressing or routing; R1 can reach the internet.
  • •PC1 uses a private IP address (RFC 1918), which must be translated before leaving R1.
  • •Check if NAT is configured on R1.
A.Configure NAT overload on R1: define ACL 1 to permit 192.168.1.0 0.0.0.255, set GigabitEthernet0/0 as outside and GigabitEthernet0/1 as inside, and apply ip nat inside source list 1 interface GigabitEthernet0/0 overload.
B.Configure a static route on R1: ip route 0.0.0.0 0.0.0.0 GigabitEthernet0/0 203.0.113.1.
C.Change PC1's default gateway to 203.0.113.1.
D.Enable IP routing on R1 and configure OSPF.
AnswerA
solution
! R1
access-list 1 permit 192.168.1.0 0.0.0.255
ip nat inside source list 1 interface GigabitEthernet0/0 overload
interface GigabitEthernet0/1
ip nat inside
interface GigabitEthernet0/0
ip nat outside

Why this answer

PC1 has a default gateway of 192.168.1.1, which is correct, but R1 is not performing NAT. R1 can reach the internet (203.0.113.1) but PC1 cannot because R1 drops packets from PC1 destined to the internet without source NAT. The fix is to configure NAT overload (PAT) on R1: define an ACL to match PC1's subnet, configure the inside and outside interfaces, and enable NAT on the outside interface.

This will translate PC1's private IP to R1's public IP.

Exam trap

The trap is that candidates may focus on routing (default route, routing protocols) or IP addressing (default gateway) when the real issue is NAT. Always verify if private IPs are being translated when hosts cannot reach the internet, even if the router itself has connectivity.

Why the other options are wrong

B

The specific factual error is that a default route is already in place and working; adding another does not solve the NAT problem.

C

The specific factual error is that a host's default gateway must be on the same subnet; 203.0.113.1 is not reachable directly from PC1.

D

The specific factual error is that OSPF does not solve the private-to-public address translation problem; it only exchanges routes between routers.

Why candidates pick the wrong answer

B

Candidates might think the issue is a missing default route, especially if they overlook that R1 can already ping the internet.

C

Candidates might mistakenly think the default gateway should be the internet router's IP, not understanding that the gateway must be local.

D

Candidates might think that a routing protocol is needed to reach the internet, but in this scenario a static default route already exists.

508
MCQhard

An EtherChannel uses LACP. One side is configured correctly, but the peer side has a different switchport mode on one of the member links. What is the most likely result?

A.The bundle may fail to form correctly because the member-link settings are inconsistent.
B.The switch automatically rewrites the peer configuration to match.
C.LACP converts the mismatched link into a routed interface automatically.
D.The mismatched link is placed in a spanning-tree blocking state.
AnswerA

When LACP is enabled on the local switch but the member links are not configured with identical parameters—such as speed, duplex, VLAN allowed lists, or trunk mode—the negotiation will fail or result in a suspended port-channel. LACP requires the same physical and administrative settings on every member link; otherwise, the misconfigured links will not join the channel group, and the bundle will either stay down or operate intermittently. The result is not a partial bundle but a failure to form the full port-channel as intended.

Why this answer

The most likely result is that the bundle will not form cleanly because EtherChannel requires member links to agree on important operational settings. In practical terms, LACP negotiation alone is not enough. The links also need compatible characteristics such as switchport mode, VLAN handling, speed, and duplex where relevant.

This is a common troubleshooting pattern. It tests whether you know that bundle membership depends on configuration consistency, not just on enabling LACP.

Exam trap

Do not assume LACP can resolve all configuration mismatches. Ensure all settings are consistent across member links.

Why the other options are wrong

B

Switches do not automatically rewrite peer configurations; configuration changes must be made manually or via network automation tools. LACP only negotiates parameters like speed and duplex, not switchport mode or VLAN settings.

C

LACP operates at Layer 2 and does not change the interface type; a mismatched link remains a Layer 2 interface. Converting to a routed interface requires manual configuration with 'no switchport' command.

D

This is incorrect because a switchport mode mismatch in an EtherChannel typically causes the link to be suspended or placed into an errdisable state, not into a spanning-tree blocking state. Spanning tree deals with loops, not port-channel parameter mismatches.

When would these options actually be correct?

B

In a different scenario where a question asks about a switch with a feature that automatically synchronizes configurations between peers, option B could be correct. For instance, if the question described a proprietary protocol that allows automatic configuration adjustments, then this option would apply.

C

In a different scenario where a question states that a switch is configured to automatically convert interfaces based on specific conditions, such as mismatched configurations, then this option could be correct. For instance, if the question involves a switch model that supports automatic interface type adjustments under certain circumstances.

D

In a different scenario where the question asks about the impact of VLAN configurations on spanning tree protocol (STP) operations, this option could be correct if it stated that a VLAN mismatch could affect the root bridge election process. For example, if the question involved VLAN configurations and STP, option D could be valid.

Why candidates pick the wrong answer

B

Students might think that LACP's negotiation capabilities extend to automatically correcting misconfigurations, but LACP only ensures consistent operational parameters on both ends, not switchport mode or VLAN membership.

C

The term 'LACP' might be confused with 'routed port' or 'Layer 3' functionality, but LACP is purely for link aggregation and does not alter the interface's Layer 2 or Layer 3 status.

D

Students may associate VLANs and STP with EtherChannel because both involve multiple links, but the root bridge election is unrelated to EtherChannel member link consistency.

509
PBQhard

You are troubleshooting a PC (PC-A) connected to switch SW1, which is connected to router R1. PC-A has an APIPA address (169.254.23.45) and cannot reach the internet (203.0.113.1). You confirm that R1 has a correctly configured DHCP pool for the 192.168.10.0/24 subnet, but the DHCP service is not enabled. The network uses VLAN 10 with subnet 192.168.10.0/24. Verify and correct the configuration on PC-A, SW1, and R1 to restore full connectivity.

Network Topology
G0/0/0192.168.10.1/24G0/0/0192.168.10.1/24203.0.113.1PC-ASW1R1Internet

Hints

  • •Check if the DHCP server process is running on R1.
  • •APIPA addresses (169.254.x.x) indicate DHCP failure.
  • •The DHCP pool is configured but not yet active.
A.Enable the DHCP service on R1 with the 'service dhcp' command.
B.Configure a default gateway on PC-A with the IP address 192.168.10.1.
C.Change the VLAN on SW1's interface connected to PC-A from VLAN 10 to VLAN 1.
D.Add the 'ip helper-address' command on R1's interface connected to SW1.
AnswerA
solution
! R1
service dhcp

! SW1


! PC-A

Why this answer

The APIPA address (169.254.x.x) indicates that PC-A failed to obtain a DHCP lease. The correct solution is to enable the DHCP service on R1 with 'service dhcp', which is not running despite the configured pool. Option B is incorrect because setting a default gateway on PC-A with a static IP would still require a valid address in the subnet; the APIPA address cannot communicate with 192.168.10.1.

Option C is wrong because the PC-A interface on SW1 is correctly assigned to VLAN 10. Option D is unnecessary since R1 is directly connected to the same subnet, so 'ip helper-address' is only used to forward DHCP broadcasts across router boundaries.

Exam trap

Do not assume that configuring a DHCP pool is sufficient; the DHCP service must be explicitly enabled with 'service dhcp'. Also, remember that APIPA addresses indicate DHCP failure, not just a missing gateway.

Why the other options are wrong

B

The PC's APIPA address cannot reach the 192.168.10.1 gateway because it is not in the same subnet, so configuring a default gateway alone does not restore connectivity.

C

Changing the VLAN to VLAN 1 would isolate PC-A from the correct subnet (VLAN 10), breaking connectivity instead of fixing it.

D

The 'ip helper-address' command is used on interfaces that need to forward DHCP broadcasts to a remote DHCP server; here R1 itself is the DHCP server and is directly attached, so the command is not needed.

Why candidates pick the wrong answer

B

Candidates might think that a missing default gateway is the primary issue, especially if they see that the PC has an IP address (even an APIPA) and assume the gateway is the only missing piece.

C

Candidates might think that using the default VLAN (VLAN 1) is always correct, or they might confuse VLAN assignment with IP subnetting.

D

Candidates often associate DHCP troubleshooting with the 'ip helper-address' command and may apply it unnecessarily when the DHCP server is local.

510
PBQhard

You are connected to R1. Configure OSPFv3 for IPv6 so that R1 and R2 can exchange IPv6 routes over their directly connected link. Enable IPv6 routing, assign OSPFv3 process and area on the interface, and verify that the neighbor adjacency forms and routes appear in the IPv6 routing table.

Network Topology
G0/02001:DB8:1::1/64G0/0 2001:DB8:1::2/64R1R2

Hints

  • •OSPFv3 requires IPv6 unicast routing to be enabled globally.
  • •OSPFv3 is enabled on the interface, not under a router ospf process like OSPFv2.
  • •Use 'ipv6 ospf <process-id> area <area-id>' on the interface.
A.Enable IPv6 routing with 'ipv6 unicast-routing', configure OSPFv3 on the interface with 'ipv6 ospf 1 area 0', and verify with 'show ospfv3 neighbor' and 'show ipv6 route ospf'.
B.Enable IPv6 routing with 'ipv6 unicast-routing', configure OSPFv3 globally with 'router ospfv3 1' and 'router-id 1.1.1.1', then assign the interface to area 0 with 'ipv6 ospf 1 area 0'.
C.Enable IPv6 routing with 'ipv6 unicast-routing', configure OSPFv3 on the interface with 'ipv6 ospf 1 area 0', and verify with 'show ip ospf neighbor' and 'show ip route ospf'.
D.Enable IPv6 routing with 'ipv6 unicast-routing', configure OSPFv3 on the interface with 'ipv6 ospf 1 area 0', and verify with 'show ospfv3 neighbor' and 'show ipv6 route'.
AnswerA
solution
! R1
configure terminal
ipv6 unicast-routing
interface GigabitEthernet0/0
ipv6 ospf 1 area 0
end

Why this answer

It includes enabling IPv6 routing with 'ipv6 unicast-routing', applying OSPFv3 to the interface using 'ipv6 ospf 1 area 0', and verifying with the correct OSPFv3-specific commands 'show ospfv3 neighbor' and 'show ipv6 route ospf'. Option B is incorrect because it adds a global 'router ospfv3 1' command, which is unnecessary; OSPFv3 can be configured directly on the interface without a global process. Option C is incorrect because it uses IPv4 OSPF verification commands 'show ip ospf neighbor' and 'show ip route ospf', which are not valid for OSPFv3.

Option D is incorrect because although it uses the correct 'show ospfv3 neighbor', the 'show ipv6 route' command does not filter to OSPF-learned routes, so it displays all IPv6 routes rather than just OSPF routes.

Exam trap

Do not confuse OSPFv3 with OSPFv2. OSPFv3 uses 'ipv6 ospf' on the interface and 'show ospfv3 neighbor' for verification. Also, remember to enable IPv6 routing with 'ipv6 unicast-routing'.

Why the other options are wrong

B

Adding a global 'router ospfv3 1' command is unnecessary; OSPFv3 can be enabled directly on the interface without a separate global configuration.

C

Using 'show ip ospf neighbor' and 'show ip route ospf' are IPv4 OSPFv2 commands, not valid for OSPFv3 which requires 'show ospfv3 neighbor' and 'show ipv6 route ospf'.

D

The 'show ipv6 route' command displays all IPv6 routes, not just OSPF-learned ones; the filter 'ospf' is required to see OSPF routes specifically.

Why candidates pick the wrong answer

B

Candidates may confuse OSPFv3 with OSPFv2, which requires a router process and router-id.

C

Candidates may mistakenly use IPv4 OSPF commands out of habit, not realizing OSPFv3 has its own set of show commands.

D

Candidates may think 'show ipv6 route' is sufficient, but it does not filter for OSPF routes, which is important for verification.

511
MCQhard

A client connects to an employee WLAN using 802.1X authentication. The authentication process completes successfully, but the client fails to obtain an IP address via DHCP. What is the most likely cause?

A.The client is being placed into the wrong policy or VLAN after successful authentication.
B.The WLAN is configured with the wrong SSID, which prevents DHCP packets from being forwarded.
C.The client has a static IP address manually configured, causing a DHCP conflict.
D.The access point is configured with an incorrect default gateway, preventing DHCP relay.
AnswerA

After successful 802.1X/RADIUS authentication, the controller or switch can assign a VLAN through attributes such as Tunnel-Private-Group-ID. If that assigned VLAN lacks a DHCP server or is not properly configured on the trunk, the client ends up in the wrong subnet with no usable IP. This is the strongest explanation because it directly maps the symptom to the post-authentication policy, rather than a client-side or AP-management issue.

Why this answer

Even after successful 802.1X authentication, the client may be assigned to the wrong VLAN or policy through RADIUS attributes (such as Tunnel-Type or Cisco AV-pair). If that VLAN lacks a DHCP server or correct subnet, the client will not receive an IP address. The other options describe issues that either prevent association entirely (wrong SSID) or are not typical causes in controller-based WLANs (static IP, AP gateway misconfiguration).

Exam trap

Cisco often tests the distinction between authentication success and post-authentication network access, leading candidates to focus on pre-authentication issues (like wrong PSK or RADIUS timeout) when the real problem is VLAN assignment or DHCP relay misconfiguration.

Why the other options are wrong

B

An incorrect SSID would prevent the client from associating to the WLAN at all, not allow authentication followed by DHCP failure.

C

A statically configured IP is less likely the strongest cause because the client would either not use DHCP or would obtain an APIPA address, and the issue is specifically about failing to obtain a correct address via DHCP.

D

The access point’s default gateway does not impact DHCP forwarding for client traffic; in controller-based deployments, DHCP packets are handled by the controller or bridged directly to the wired network.

When would these options actually be correct?

B

In a different question scenario, if the context involved a client device that was configured with a static IP address and subnet mask that did not match the network's DHCP settings, this option could be correct, as it would explain why the device cannot communicate properly on the network.

C

In a different question setup where the focus is on network topology and loop prevention, a scenario could involve a network experiencing broadcast storms due to STP misconfigurations, leading to clients being unable to communicate effectively, thus making this option correct.

D

In a different scenario where the question specifies that the client is part of a multi-site network with complex routing requirements, and the WLAN's operation is dependent on BGP for route advertisement, this option would be correct if the client fails to connect due to BGP misconfiguration.

Why candidates pick the wrong answer

B

Students may think that a wrong subnet mask could cause connectivity issues, but here the client gets an address from a different subnet entirely, which is not caused by a mask typo. The mask typo would not change the subnet assigned by DHCP.

C

Students might confuse STP root guard with other security features or think that STP issues could affect VLAN assignment. However, STP root guard does not influence DHCP or VLAN assignment for wireless clients.

D

Students might think that BGP is needed for routing or that it is a common protocol in networking, but it is not used on client devices. The question is about basic WLAN connectivity, not inter-domain routing.

512
PBQhard

You are connected to R1 via the console. R1 and R2 are connected via a fiber link using SFPs. The link is not coming up. Configure the correct SFP type on R1's interface GigabitEthernet0/0 to support the required 2 km distance, and fix any auto-negotiation or speed/duplex misconfiguration so that the link becomes operational.

Network Topology
G0/010.0.0.1/30G0/010.0.0.2/302 km fiberR1R2

Hints

  • •Check the transceiver details to see the current SFP's distance capability.
  • •The link requires 2 km; the current SFP only supports 550 m.
  • •Auto-negotiation is not used on fiber links; disable it with 'no negotiation auto'.
A.Replace SFP with 1000BASE-LX, configure 'no negotiation auto' on GigabitEthernet0/0, and remove 'speed 1000' and 'duplex full'.
B.Replace SFP with 1000BASE-SX, configure 'negotiation auto' on GigabitEthernet0/0, and keep 'speed 1000' and 'duplex full'.
C.Replace SFP with 1000BASE-LX, configure 'negotiation auto' on GigabitEthernet0/0, and keep 'speed 1000' and 'duplex full'.
D.Replace SFP with 1000BASE-LX, configure 'no negotiation auto' on GigabitEthernet0/0, and configure 'speed 100' and 'duplex full'.
AnswerA
solution
! R1
interface gigabitEthernet 0/0
no speed 1000
no duplex full
no negotiation auto
end

Why this answer

For a 2 km fiber link, a 1000BASE-LX SFP is required (supports up to 10 km). Fiber SFPs like 1000BASE-LX typically do not support auto-negotiation; speed and duplex are fixed. Therefore, the interface should have 'no negotiation auto' configured and no explicit speed/duplex commands.

Option A implements these changes. Option B uses 1000BASE-SX, which is suitable only for up to 550 m. Option C leaves auto-negotiation enabled, which is unsupported.

Option D sets speed to 100, which is incompatible with a GigabitEthernet interface.

Exam trap

Do not assume auto-negotiation is always required; fiber SFPs use fixed parameters. Also, remember that 1000BASE-SX is for short distances (up to 550 m), while 1000BASE-LX supports longer distances (up to 10 km).

Why the other options are wrong

B

Uses 1000BASE-SX, which cannot support the required 2 km distance.

C

Retains 'negotiation auto', which is not supported on fiber SFPs and prevents the link from establishing.

D

Configures 'speed 100', a value incompatible with a 1000BASE-LX SFP, causing a link failure.

Why candidates pick the wrong answer

B

Candidates may think SX is standard for short distances and assume auto-negotiation is always required.

C

Candidates may believe auto-negotiation is needed for all Ethernet links, not realizing fiber SFPs have fixed parameters.

D

Candidates may think keeping speed/duplex is harmless, but the question expects a clean configuration that removes misconfigurations.

513
MCQhard

A company wants to connect two sites across an IP network by creating a logical tunnel between the edge routers. Which technology is most directly associated with that requirement?

A.GRE
B.PortFast
C.DHCP relay
D.Root guard
AnswerA

Generic Routing Encapsulation (GRE) is a tunneling protocol that takes an entire packet and encapsulates it inside another IP packet, effectively creating a logical point-to-point link between two routers across an IP network. By configuring a GRE tunnel on each site's edge router, the two sites can exchange private addresses and routing information as if they were directly connected on the same link. This makes GRE a standard solution for site-to-site connectivity over IP networks, because it provides a simple, logical path for arbitrary payload traffic.

Why this answer

GRE is the most directly associated technology because it creates a logical tunnel between routers across an existing IP network. In practical terms, it allows the routers to treat the path as a virtual point-to-point connection for encapsulated traffic.

The question is specifically about tunneling between sites, not about plain routing, management, or switching behavior.

Exam trap

A common exam trap is mistaking GRE for unrelated Cisco features like PortFast or DHCP relay. PortFast is a Spanning Tree Protocol optimization for edge ports and does not create tunnels. DHCP relay forwards DHCP requests and is unrelated to site-to-site connectivity.

Another trap is confusing GRE with security features like IPsec; GRE itself does not encrypt traffic but only encapsulates it. Candidates might also overlook that GRE tunnels require proper MTU handling to avoid fragmentation issues, which can cause connectivity problems if ignored.

Why the other options are wrong

B

PortFast is incorrect because it is an STP feature that immediately transitions a switch port to forwarding state and does not provide any tunneling or routing capabilities.

C

DHCP relay is incorrect because it only forwards DHCP broadcast requests between clients and servers and does not create tunnels or connect sites logically over an IP network.

D

Root guard is incorrect because it is an STP topology protection feature that prevents a port from becoming a root port, and it does not create tunnels or affect routing.

When would these options actually be correct?

B

If the question asked about optimizing switch port behavior in a network where rapid connectivity is needed for end devices, PortFast would be the correct answer. For example, a scenario involving a network with multiple switches where minimizing downtime during network topology changes is critical would validate its use.

C

If the question asked about connecting clients to a DHCP server located on a different subnet, where the relay agent is required to forward DHCP messages, then DHCP relay would be the correct answer. This scenario focuses on DHCP functionality rather than tunneling.

D

If the exam question asked about securing the spanning tree topology in a network with multiple switches, where preventing rogue switches from becoming the root bridge is critical, then root guard would be the correct answer. This scenario would focus on maintaining network stability rather than tunneling.

Why candidates pick the wrong answer

B

Students might confuse PortFast with a feature that speeds up network connectivity, but it is unrelated to tunneling or site-to-site connections.

C

The term 'relay' might suggest forwarding traffic between networks, leading students to think it could be used for site-to-site connectivity, but it is not a tunneling technology.

D

The word 'guard' might imply a security or connectivity feature, but root guard is specifically for STP and has no role in tunneling.

514
PBQhard

You are connected to R1, a multilayer switch acting as the STP root for VLAN 10. Configure Root Guard on the designated port facing a downstream switch to prevent a rogue switch from becoming root. Also, enable Loop Guard on the uplink port to prevent STP loops, and configure BPDU Guard on a PortFast-enabled access port. Ensure that if a superior BPDU is received on the Root Guard port, it is blocked, and if a BPDU is received on the BPDU Guard port, it goes err-disabled.

Network Topology
G0/010.0.0.1/30G0/010.0.0.2/30trunkG0/1192.168.10.1/24R2R1access vlan 10SW2PC

Hints

  • •Root Guard is applied on designated ports to block superior BPDUs.
  • •Loop Guard is applied on root or alternate ports to prevent loops if BPDUs stop.
  • •BPDU Guard with PortFast err-disables the port upon receiving any BPDU.
A.The configuration is correct; no changes are needed.
B.Root Guard should be applied on G0/0 instead of G0/1, and Loop Guard on G0/1 instead of G0/0.
C.BPDU Guard should be configured on G0/1 instead of G0/2, and Loop Guard should be removed from G0/0.
D.Root Guard should be applied on G0/2 instead of G0/1, and BPDU Guard should be removed from G0/2.
AnswerA
solution
! R1

Why this answer

R1 is the STP root for VLAN 10. The downstream port (G0/1) is a designated port, so Root Guard is correctly applied to prevent a superior BPDU from being accepted. The uplink port (G0/0) is a root port, so Loop Guard should be applied there to prevent an STP loop if BPDUs stop arriving.

The access port (G0/2) has PortFast and BPDU Guard enabled, which will err-disable the port if a BPDU is received. The current configuration is correct; no changes are needed. If a superior BPDU arrives on G0/1, Root Guard will block the port.

If a BPDU arrives on G0/2, BPDU Guard will err-disable it.

Exam trap

The trap is that candidates may think changes are needed because they misapply STP protections to the wrong port types. Remember: Root Guard on designated ports, Loop Guard on root/alternate ports, BPDU Guard on PortFast access ports.

Why the other options are wrong

B

Root Guard is only effective on designated ports; applying it to a root port would not prevent a rogue switch from becoming root. Loop Guard on a designated port is unnecessary and could cause false positives.

C

BPDU Guard on a trunk port would err-disable it upon receiving a BPDU, which is normal for trunk ports. Loop Guard on the root port is essential for loop prevention; removing it would leave the network vulnerable.

D

Root Guard on an access port would block the port if a superior BPDU is received, but access ports should not receive BPDUs if PortFast is enabled. BPDU Guard already handles that by err-disabling the port.

Why candidates pick the wrong answer

B

Candidates often confuse which STP protection goes on which port type, thinking Root Guard should be on the root port to protect it, but it actually protects downstream designated ports.

C

Candidates might think BPDU Guard should be on all ports to prevent BPDU attacks, but it is specifically for PortFast-enabled access ports. They may also underestimate the importance of Loop Guard on root ports.

D

Candidates might think Root Guard provides additional protection on access ports, but it is redundant and misapplied. They may also confuse the purpose of Root Guard and BPDU Guard.

515
PBQhard

You are connected to a multilayer switch MLS1 via the console. Configure MLS1 so that IP phones connected to interface GigabitEthernet0/1 receive power via PoE, use VLAN 10 for data traffic, and use VLAN 20 for voice traffic, while the access port for an AP on GigabitEthernet0/2 should be placed in VLAN 30 and have PoE disabled. Verify your configuration using appropriate show commands.

Hints

  • •Voice VLAN is configured with a separate command from the access VLAN.
  • •PoE can be disabled per interface using 'power inline never'.
  • •Use 'show interfaces switchport' to see both voice and access VLAN assignments.
A.interface GigabitEthernet0/1 switchport mode access switchport access vlan 10 switchport voice vlan 20 power inline auto ! interface GigabitEthernet0/2 switchport mode access switchport access vlan 30 power inline never
B.interface GigabitEthernet0/1 switchport mode trunk switchport trunk allowed vlan 10,20 power inline auto ! interface GigabitEthernet0/2 switchport mode access switchport access vlan 30 power inline never
C.interface GigabitEthernet0/1 switchport mode access switchport access vlan 20 switchport voice vlan 10 power inline auto ! interface GigabitEthernet0/2 switchport mode access switchport access vlan 30 power inline never
D.interface GigabitEthernet0/1 switchport mode access switchport access vlan 10 switchport voice vlan 20 power inline never ! interface GigabitEthernet0/2 switchport mode access switchport access vlan 30 power inline auto
AnswerA
solution
! MLS1
interface GigabitEthernet0/1
switchport voice vlan 20
power inline auto
interface GigabitEthernet0/2
switchport access vlan 30
power inline never

Why this answer

For the IP phone port (G0/1), you need to enable PoE (power inline auto) and configure the voice VLAN (switchport voice vlan 20) so that the phone uses VLAN 20 for voice and the access VLAN 10 for data. For the AP port (G0/2), you must change the access VLAN to 30 and disable PoE (power inline never) to prevent powering the AP through the switch. Verify with 'show interfaces switchport' to confirm voice VLAN and access VLAN settings, and 'show power inline' to check PoE status.

Exam trap

A common trap is confusing the voice VLAN command with trunking or swapping the access and voice VLANs. Also, remember that IP phones require PoE, while the AP in this scenario does not. Always verify with show commands.

Why the other options are wrong

B

The specific factual error is that IP phones typically use an access port with a voice VLAN, not a trunk port. Trunking is unnecessary and can cause compatibility issues.

C

The specific factual error is confusing the access VLAN and voice VLAN assignments. The voice VLAN is configured with 'switchport voice vlan', and the access VLAN with 'switchport access vlan'.

D

The specific factual error is reversing the PoE settings: 'power inline never' on the phone port and 'power inline auto' on the AP port.

Why candidates pick the wrong answer

B

Candidates might think that because the phone uses two VLANs (data and voice), a trunk is needed to carry both, but Cisco's voice VLAN feature handles this without trunking.

C

Candidates may misread the requirement or think the voice VLAN is the same as the access VLAN, leading to the swap.

D

Candidates might confuse which device needs PoE or mistakenly think the AP requires PoE, but the question explicitly states the AP should have PoE disabled.

516
Multi-Selectmedium

Which TWO statements correctly describe the behavior of PAT (Port Address Translation) as configured on a Cisco router?

Select 2 answers
A.PAT translates multiple internal addresses to a single public IP address by using unique source port numbers.
B.PAT requires a 1:1 mapping of internal to external IP addresses.
C.PAT can only be configured with a pool of public IP addresses.
D.PAT uses both IP addresses and port numbers to track translations.
E.PAT translations are always static and never time out.
AnswersA, D

PAT distinguishes between multiple internal hosts sharing the same public IP by assigning a different source port for each session. The router maintains a translation table that tracks the original internal IP and port along with the assigned public IP and port.

Why this answer

PAT (Port Address Translation) translates multiple internal private IP addresses to a single public IP address by assigning unique source port numbers to each session, allowing many internal hosts to share one public IP. This is correctly described in option A. Option D is also correct because PAT uniquely identifies each translation by both the IP address and the port number, enabling the router to demultiplex return traffic.

Option B is wrong because PAT uses many-to-one mapping, not 1:1; a 1:1 mapping is characteristic of static NAT. Option C is incorrect because PAT can operate with a single public IP address (often the outside interface address) rather than requiring a pool. Option E is false because PAT translations are dynamically created and time out after a period of inactivity; they are not static.

Exam trap

Cisco often tests the misconception that PAT requires a pool of public IPs or a 1:1 mapping, when in fact PAT is designed for many-to-one translation using port numbers, and can operate with a single public IP address.

Why the other options are wrong

B

PAT does not require a 1:1 mapping; it allows many internal addresses to share a single public IP. A 1:1 mapping is characteristic of static NAT, not PAT.

C

PAT can be configured with either a single public IP address (using the interface address) or a pool of public IP addresses. It does not require a pool; a single address is sufficient for PAT overload.

E

PAT translations are dynamic and have a timeout (default 86400 seconds for general translations, but shorter for TCP/UDP). They are removed after the session ends or the timeout expires.

Why candidates pick the wrong answer

B

Students often confuse PAT with static NAT, thinking that each internal host needs its own public IP. They may also misinterpret 'translation' as requiring a one-to-one correspondence.

C

Some students believe that PAT, like dynamic NAT, requires a pool of addresses. They may not realize that PAT can overload a single address by using port numbers.

E

Students may think that all NAT translations are static because they hear about 'static NAT' or confuse PAT with static entries. They might also assume that translations persist indefinitely.

517
PBQhard

You are connected to R1, a branch router. Configure an extended ACL named BRANCH_IN that permits only HTTP (TCP port 80) traffic from the internal network 192.168.1.0/24 to the web server at 203.0.113.10, and permits ICMP echo-reply from any source to any destination. Apply the ACL inbound on the interface facing the internal network. Then verify that only the specified traffic is allowed.

Network Topology
G0/0192.168.1.1/24G0/1203.0.113.2/30HostsInternal LANR1ISPWeb Server

Hints

  • •The ACL is defined but not yet applied to an interface.
  • •Consider which direction traffic from the internal network flows relative to the interface.
  • •Use 'ip access-group' under the correct interface configuration mode.
A.ip access-list extended BRANCH_IN permit tcp 192.168.1.0 0.0.0.255 host 203.0.113.10 eq 80 permit icmp any any echo-reply ! interface GigabitEthernet0/0 ip access-group BRANCH_IN in
B.ip access-list extended BRANCH_IN permit tcp 192.168.1.0 0.0.0.255 host 203.0.113.10 eq 80 permit icmp any any echo-reply ! interface GigabitEthernet0/0 ip access-group BRANCH_IN out
C.ip access-list extended BRANCH_IN permit tcp 192.168.1.0 0.0.0.255 host 203.0.113.10 eq 80 permit icmp any any ! interface GigabitEthernet0/0 ip access-group BRANCH_IN in
D.ip access-list extended BRANCH_IN permit tcp 192.168.1.0 0.0.0.255 host 203.0.113.10 eq 80 permit icmp any any echo-reply ! interface GigabitEthernet0/0 ip access-group BRANCH_IN in ! interface GigabitEthernet0/1 ip access-group BRANCH_IN in
AnswerA
solution
! R1
interface GigabitEthernet0/0
ip access-group BRANCH_IN in

Why this answer

It creates an extended ACL that permits TCP port 80 from the internal 192.168.1.0/24 to the web server 203.0.113.10 and permits only ICMP echo-reply, then applies it inbound on the internal interface G0/0, matching the requirement. Option B is wrong because the ACL is applied outbound on G0/0, but traffic from internal hosts to the web server exits via the WAN interface (G0/1), not G0/0. Option C is wrong because it permits all ICMP (any any) instead of only echo-reply, allowing unnecessary ICMP traffic.

Option D is wrong because it applies the ACL inbound on both G0/0 and G0/1; applying it on G0/1 would incorrectly filter inbound traffic from the ISP, potentially blocking the web server's responses.

Exam trap

Pay close attention to the direction of traffic flow. The ACL must be applied inbound on the interface that receives traffic from the internal network. Also, be precise with ICMP types: 'echo-reply' is the response to a ping, not the initial echo request.

Why the other options are wrong

B

The ACL is applied in the wrong direction. Applying it outbound would filter traffic leaving the interface, not entering it.

C

The ACL permits all ICMP traffic instead of only echo-reply. This violates the requirement to permit only ICMP echo-reply.

D

Applying the ACL to an additional interface (G0/1) is unnecessary and may cause unintended filtering. The requirement specifies only one interface.

Why candidates pick the wrong answer

B

Candidates might confuse the direction of traffic flow and think that outbound on the internal interface is correct because traffic from internal users goes out.

C

Candidates may think that permitting all ICMP is acceptable or may forget to specify the echo-reply type, especially if they are used to allowing ping in both directions.

D

Candidates might think that applying the ACL to both interfaces provides better security, or they may misidentify which interface is internal.

518
Multi-Selectmedium

Which two statements about YANG are correct?

Select 2 answers
A.It defines structured models for configuration and state data
B.It is commonly associated with NETCONF and RESTCONF
C.It is a replacement for OSPF adjacency formation
D.It is the same thing as JSON syntax
E.It automatically discovers neighbors on a LAN
AnswersA, B

YANG is a data modeling language used to define the hierarchical structure of configuration and operational state data on network devices. It specifies which data is available, its constraints, and how it is organized, independent of any particular protocol. The models written in YANG serve as the authoritative schema for management systems and devices.

Why this answer

YANG is a data modeling language used to describe configuration and operational state. It is commonly used with NETCONF and RESTCONF, but it is not itself the transport protocol.

Exam trap

A common exam trap is mistaking YANG for a routing protocol or a data format. Some candidates incorrectly believe YANG replaces protocols like OSPF for adjacency formation or that it is the same as JSON syntax. This confusion arises because YANG models can be encoded in JSON or XML, but YANG itself is a modeling language, not a transport or routing protocol.

Misunderstanding this can lead to selecting incorrect answers that describe YANG as performing routing or neighbor discovery functions, which it does not. Recognizing YANG’s role as a data modeling language avoids this pitfall.

Why the other options are wrong

C

Option C is incorrect because YANG is not a routing protocol and does not handle OSPF adjacency formation or any routing functions.

D

Option D is incorrect as YANG is a modeling language, not a data format like JSON. Although YANG models can be encoded in JSON, they are not the same thing.

E

Option E is incorrect because YANG does not perform network discovery functions such as automatically discovering neighbors on a LAN; that is outside its scope.

When would these options actually be correct?

C

In a question asking which protocol or mechanism is used to form OSPF adjacencies, 'OSPF adjacency formation' would be correct, but YANG is unrelated.

D

If the question were 'Which data serialization format is commonly used with YANG?' then 'JSON' would be a correct answer, as YANG models can be encoded in JSON.

E

In a question about protocols that automatically discover neighbors on a LAN, options like LLDP (IEEE 802.1AB) or CDP (Cisco Discovery Protocol) would be correct. For example: 'Which protocol automatically discovers neighboring devices on a LAN?'

Why candidates pick the wrong answer

C

Candidates may confuse YANG with protocols that manage network configurations or operations, mistakenly thinking it replaces routing protocols like OSPF.

D

Candidates may confuse YANG's use of JSON for encoding data with YANG being equivalent to JSON, especially when they see YANG examples represented in JSON syntax.

E

Candidates may confuse YANG with protocols that perform discovery because YANG is often used in network automation contexts where devices are discovered, but YANG itself does not perform discovery.

519
MCQhard

A host address is 192.168.90.33/28. Which address is the last usable host in the subnet?

A.192.168.90.46
B.192.168.90.47
C.192.168.90.33
D.192.168.90.48
AnswerA

192.168.90.46 is the last usable host address in the /28 subnet that contains .33. A /28 prefix has a block size of 16, so the subnet boundaries are 192.168.90.32 and 192.168.90.47. The address .46 has all host bits set to 1 except the last one, making it the highest address that can be assigned to a device. The next address, .47, is the directed broadcast for this subnet.

Why this answer

The /28 subnet mask (255.255.255.240) gives a block size of 16 addresses. The network address for 192.168.90.33 is 192.168.90.32, so the broadcast address is 192.168.90.47. The last usable host is the broadcast address minus one, which is 192.168.90.46.

Exam trap

Cisco often tests the distinction between the broadcast address and the last usable host, tricking candidates who forget to subtract one from the broadcast address.

Why the other options are wrong

B

192.168.90.47 is the broadcast address for the subnet 192.168.90.32/28. Broadcast addresses cannot be assigned to hosts; they are used to send traffic to all hosts in the subnet.

C

192.168.90.33 is the first usable host in the subnet (network address .32 + 1). The question asks for the last usable host, not the first.

D

192.168.90.48 is the network address of the next subnet (192.168.90.48/28). It is not part of the current subnet and cannot be used as a host address in the subnet containing .33.

When would these options actually be correct?

B

If the question asked for the last address in the subnet instead of the last usable host, option B would be correct, as the broadcast address for the subnet 192.168.90.32/28 is indeed 192.168.90.47.

C

If the question asked for the first usable host address in the subnet 192.168.90.32/28, then option C would be correct, as it represents the first address available for assignment to a host.

D

If the question asked for the first address in the next subnet after 192.168.90.32/28, then 192.168.90.48 would be the correct answer, as it represents the start of the subnet 192.168.90.48/28.

Why candidates pick the wrong answer

B

Students often confuse the last usable host with the broadcast address, especially when the subnet boundary is not obvious. The broadcast is one less than the next subnet's network address, and it's easy to mistakenly think it's usable.

C

A test-taker might see that .33 is a valid host and assume it is the last because it is close to the given address, without calculating the subnet range correctly.

D

Students may think that .48 is the last usable because it is numerically higher than .46, not realizing that subnet boundaries restrict the range. They might also confuse it with the broadcast address of the previous subnet.

520
MCQhard

A network engineer adds a loopback interface Lo0 with IP address 172.16.0.1/32 to router R1. After restarting the OSPF process, the OSPF router-ID changes from 10.1.1.1 to 172.16.0.1, and the neighbor relationship with R2 resets. What should the technician do next to prevent this disruption the next time a loopback is added?

A.Configure passive-interface Lo0 under the OSPF process
B.Configure a static router-id using the router-id command under the OSPF process
C.Set a higher OSPF priority on the router’s interfaces
D.Configure the OSPF area as a stub area
AnswerB

The OSPF router-ID is dynamically derived from the highest loopback or active interface IP unless overridden. Creating another loopback with a numerically higher address would cause OSPF to adopt it as the new router-ID at the next process restart, tearing down every existing neighbor relationship. The `router-id` command forces the router to retain that fixed value indefinitely, because manually configured router-IDs take precedence over all IPv4/IPv6 interface addresses, making the network stable regardless of later loopback additions.

Why this answer

The OSPF router-ID is dynamically selected based on the highest IP address of any loopback interface, or if none exist, the highest IP of any physical interface. Adding a new loopback with a higher IP than the current router-ID causes OSPF to reselect a new router-ID upon process restart, which resets all neighbor adjacencies. Configuring a static router-ID with the 'router-id' command under the OSPF process prevents this disruption by fixing the router-ID regardless of interface IP changes.

Exam trap

Cisco often tests the misconception that adding a loopback interface automatically changes the OSPF router-ID immediately, but the trap here is that the router-ID only changes after an OSPF process restart or router reload, and candidates may incorrectly think passive-interface or priority settings can prevent the disruption.

Why the other options are wrong

A

Passive-interface does not influence router-ID selection, which is based solely on highest active loopback IP address at process initialization.

C

Confusing DR election parameters with router-ID election leads candidates to a parameter that is irrelevant to router-ID stability.

D

Changing area type does not address router-ID fluctuation; it targets LSDB optimization, which is unrelated to the dynamic router-ID re-election after loopback addition.

521
MCQhard

An OSPF-enabled router R1 fails to advertise the 192.168.50.0/24 network to neighbor R2, even though the neighbor relationship is up. Which misconfiguration on R1 would cause this?

A.The OSPF process must be process ID 50 to advertise 192.168.50.0/24
B.The wildcard network statement does not match 192.168.50.0/24
C.OSPF cannot advertise a directly connected LAN
D.R2 needs a default route before learning intra-area routes
AnswerB

The OSPF network statement uses a wildcard mask that is the inverse of the interface's subnet mask. To advertise 192.168.50.0/24, the network statement must match that exact prefix, typically by using 192.168.50.0 0.0.0.255. If the wildcard mask is misconfigured—for example, 0.0.0.127 or 0.0.0.15—the interface will be excluded from the OSPF process, so R1 will not originate the route and R2 cannot learn it.

Why this answer

If the network statement on R1 does not match the interface connected to 192.168.50.0/24, OSPF will not enable on that interface and the subnet will not be advertised. The route stays absent from neighbors despite OSPF running elsewhere.

Exam trap

A frequent exam trap is believing that the OSPF process ID must match across routers to advertise specific networks or that OSPF cannot advertise directly connected LANs. Candidates may also incorrectly assume that a default route is required on a router before it can learn intra-area routes. These misconceptions lead to overlooking the actual cause: a mismatched wildcard mask in the network statement that prevents OSPF from activating on the interface.

This trap causes candidates to focus on irrelevant configuration elements instead of verifying the network statement accuracy.

Why the other options are wrong

A

The OSPF process ID is locally significant and does not affect which networks are advertised. Changing the process ID to 50 is unnecessary and does not solve the problem of missing routes.

C

OSPF can advertise directly connected LANs if their interfaces are included in the OSPF network statements. This option is incorrect because directly connected LANs are advertised when properly configured.

D

A default route is not required for a router to learn intra-area OSPF routes. OSPF routers exchange routing information through link-state advertisements without needing a default route first.

When would these options actually be correct?

A

In a different scenario where a question states that R1 is configured to use a specific OSPF process ID (e.g., 50) and asks if R2 can receive advertisements from R1, this option would be correct if R2's configuration also required matching that process ID to receive updates.

C

In a different scenario where the question states that R1 is configured to only advertise certain subnets and the specific subnet in question is not directly connected, then this option could be correct. For example, if the question specifies that R1 is configured to only advertise subnets that are not directly connected to its interfaces.

D

In a different scenario where the question states that R2 is configured to only accept routes if a default route is present, this option would be correct. For example, if R2's routing policy required a default route to be configured before accepting any OSPF routes, then this statement would apply.

Why candidates pick the wrong answer

A

Students often mistakenly think that the OSPF process ID must match the network number or area ID, confusing it with other protocols like EIGRP where the autonomous system number must match between routers.

C

Some students confuse OSPF with BGP, which by default does not advertise directly connected networks unless explicitly configured with the network command. Additionally, the concept of 'passive interface' might lead to confusion, but OSPF can still advertise the subnet even if the interface is passive.

D

Students may confuse OSPF with stub areas or default routing concepts. In some OSPF area types (like stub areas), a default route is injected, but for standard intra-area routes, no default is required.

522
MCQhard

A network administrator is troubleshooting a connectivity issue between two routers, R1 and R2, connected via a serial link. R1 is configured with PPP encapsulation and CHAP authentication. R2 is configured with PPP encapsulation but no authentication. The link is down. Which statement explains the most likely cause?

A.The link is down because PPP encapsulation is not compatible with serial interfaces.
B.CHAP authentication failed because R2 did not send a challenge.
C.The link is down because CHAP requires the same hostname on both routers.
D.The link is down because R1 requires authentication but R2 is not configured to authenticate.
AnswerD

When one side of a PPP link is configured with authentication (CHAP) and the other side is not, the authentication will fail. R1 will send a CHAP challenge to R2, but R2 will not have the necessary credentials or configuration to respond. As a result, the link will not come up. This is the most likely cause of the connectivity issue. Both ends must agree on authentication parameters for the link to establish.

Why this answer

In PPP, if one side is configured with authentication (CHAP) and the other side is not, the authentication process will fail, and the link will not come up. R1 will send a challenge, but R2 cannot respond appropriately. Both ends must have compatible authentication configurations.

The most likely cause is the mismatch in authentication settings.

Exam trap

The trap here is assuming that CHAP requires identical hostnames or that PPP is incompatible with serial interfaces, rather than recognizing the authentication mismatch as the cause.

523
MCQhard

A user reports they cannot access any network resources. A network administrator runs ipconfig on the user's Windows PC and sees an IPv4 address of 169.254.45.3/16. The administrator then pings the default gateway 10.0.0.1, which fails, and uses traceroute to 10.0.0.1, which shows only '1 * * * Request timed out.' What is the most likely cause of the problem?

A.The PC's DNS server address is incorrect.
B.The switch port is in an administratively down state.
C.The Ethernet cable is unplugged from the PC.
D.The DHCP server is unreachable.
AnswerD

The 169.254.x.x APIPA address indicates that the PC is configured for DHCP but did not receive a DHCP offer. Because the address is not in the same subnet as the default gateway, all connectivity beyond the local link fails.

Why this answer

The 169.254.45.3/16 address is an Automatic Private IP Addressing (APIPA) address, assigned by Windows when a DHCP discovery fails. The failed ping and traceroute to the default gateway confirm that the PC has no IP connectivity to the network. Since the PC has an APIPA address, it was unable to reach a DHCP server to obtain a valid IPv4 address; the most likely cause is that the DHCP server is unreachable.

The presence of an APIPA address also indicates the PC's NIC has a working physical and data-link connection, ruling out a disconnected cable or disabled switch port.

Exam trap

Cisco often tests the distinction between a link-local APIPA address and a 'Media disconnected' state; the trap here is that candidates may assume a physical issue (unplugged cable or disabled port) when the presence of an APIPA address actually proves the physical and data link layers are operational.

Why the other options are wrong

A

DNS misconfiguration would not prevent direct IP connectivity to the gateway.

B

With the port down, the PC would not assign any IP address; APIPA assignment requires an active link.

C

Physical disconnection prevents link establishment, so no IP address is assigned.

524
MCQhard

A host with address 10.0.0.130/25 needs to identify its subnet. Which subnet is correct?

A.10.0.0.0/25
B.10.0.0.64/25
C.10.0.0.128/25
D.10.0.0.192/25
AnswerC

The /25 prefix length creates subnets with a block size of 128 addresses. The host address 10.0.0.130 has a last octet binary of 10000010, which lies within the 128-255 range, so it belongs to the subnet that starts at 10.0.0.128. The network address is therefore 10.0.0.128, with usable host addresses 10.0.0.129 through 10.0.0.254 and a broadcast address of 10.0.0.255.

Why this answer

A /25 uses blocks of 128 addresses. In plain language, that means the fourth-octet ranges are 0–127 and 128–255. Since the host address ends in 130, it belongs to the upper block, which means the subnet is 10.0.0.128/25.

This kind of question is a staple of subnetting because it tests whether you can identify the correct subnet boundary from the prefix and host address. Once you recognize the /25 split, the answer becomes straightforward.

Exam trap

Be careful not to confuse the subnet mask with the number of addresses it covers. Always calculate the address range based on the subnet mask.

Why the other options are wrong

A

The subnet 10.0.0.0/25 covers addresses 10.0.0.0 through 10.0.0.127. Since 10.0.0.130 is outside this range, it cannot belong to this subnet. The host's address must be within the subnet's range.

B

The /25 prefix length has a subnet size of 128, so valid network addresses are multiples of 128 (0, 128, 256, etc.). 10.0.0.64 is not a multiple of 128, so it is not a valid /25 network address.

D

The /25 prefix length creates subnets with a block size of 128, starting at 0, 128, 256, etc. 10.0.0.192/25 would be a valid subnet if the network started at 192, but 192 is not a valid /25 boundary because 192 is not a multiple of 128.

When would these options actually be correct?

A

If the question asked for the base address of the subnet that includes all addresses from 10.0.0.0 to 10.0.0.127, then option A would be correct as it represents the starting address of that subnet.

B

In a question where the subnet mask is changed to /26 and the host address is specified as 10.0.0.130, option B (10.0.0.64/25) could be correct if the question asks for the subnet that includes addresses from 10.0.0.64 to 10.0.0.127. This would make it a valid subnet for a different host range.

D

This option would be correct if the question asked for the subnet of a host with an address in the range of 10.0.0.192 to 10.0.0.255, such as 10.0.0.200/25. In that case, 10.0.0.192/25 would accurately represent the subnet for that host.

Why candidates pick the wrong answer

A

A student might assume that any address starting with 10.0.0.x belongs to the 10.0.0.0/24 network and forget that the /25 mask splits the /24 into two subnets. They may incorrectly think 10.0.0.0/25 includes all addresses from 0 to 255.

B

Students often confuse /25 with /26 (which has a 64-address block size) or /27 (32-address block). The number 64 is a common boundary for /26 subnets, leading to the mistaken belief that 10.0.0.64/25 is valid.

D

Students often confuse /25 boundaries with /26 boundaries (which increment by 64) or mistakenly think that any address ending in .192 could be a subnet start. The number 192 is a common subnet boundary for /26 or /27, leading to this error.

525
PBQmedium

You are connected to the console of R1. The network administrator reports that R1 cannot discover neighboring devices via CDP. R1 is connected to SW1 via GigabitEthernet0/0. You suspect CDP is disabled globally or on the interface. Your task is to enable CDP and verify neighbor discovery.

Network Topology
G0/0G0/1R1SW1

Hints

  • •CDP can be disabled globally or per interface.
  • •Use the 'show cdp' command to check global status.
  • •After enabling, wait a few seconds for neighbor discovery.
A.Enter global configuration mode, issue 'cdp run', then enter interface configuration mode for GigabitEthernet0/0 and issue 'cdp enable'.
B.Enter global configuration mode, issue 'cdp enable', then enter interface configuration mode for GigabitEthernet0/0 and issue 'cdp run'.
C.Enter global configuration mode, issue 'cdp run', then enter interface configuration mode for GigabitEthernet0/0 and issue 'no cdp disable'.
D.Enter global configuration mode, issue 'cdp enable', then enter interface configuration mode for GigabitEthernet0/0 and issue 'no cdp disable'.
AnswerA
solution
! R1
cdp run
interface GigabitEthernet0/0
cdp enable

Why this answer

CDP was disabled globally and on the interface. Enabling CDP globally and then on the interface allows R1 to discover directly connected Cisco devices.

Exam trap

Remember that CDP requires two separate commands: 'cdp run' globally and 'cdp enable' on each interface. Do not confuse the global and interface commands, and do not invent commands like 'no cdp disable'.

Why the other options are wrong

B

The specific factual error is that 'cdp enable' is used on interfaces, not globally. The global command to enable CDP is 'cdp run'.

C

The specific factual error is that 'no cdp disable' is not a valid Cisco IOS command. The proper command is 'cdp enable'.

D

The specific factual errors are: the global command should be 'cdp run', and the interface command should be 'cdp enable'.

Why candidates pick the wrong answer

B

Candidates might confuse the global and interface commands, thinking 'cdp enable' works globally because it sounds like it enables CDP.

C

Candidates might think that since CDP can be disabled per interface with 'cdp disable', using 'no cdp disable' would re-enable it, but that command does not exist.

D

Candidates might combine two common misconceptions: confusing global and interface commands, and thinking 'no cdp disable' is valid.

Page 6

Page 7 of 20

Page 8