Courseiva

CCNA 200-301 v2 (200-301) — Questions 526–600

1450 questions total · 20pages · All types, answers revealed

Page 7

Page 8 of 20

Page 9
526
MCQhard

A network technician is troubleshooting a DHCP relay issue. The router at the branch office is supposed to forward DHCP requests from local clients to a central DHCP server. Clients connected to Gi0/1 are not receiving IP addresses. The technician verifies that the DHCP server is reachable from the router, that no ACLs are blocking DHCP traffic, and that the DHCP scope on the server has available leases. Upon checking the running configuration, the technician notices that the ip helper-address command is applied to interface Gi0/0 (the WAN link toward the server) instead of Gi0/1. What should the technician do next?

A.Check the DHCP server logs for any error or warning messages related to the clients' requests.
B.Move the ip helper-address command from interface Gi0/0 to interface Gi0/1.
C.Issue the show ip interface brief command to ensure that interface Gi0/1 is in an up/up state.
D.Remove the ip helper-address from Gi0/0 and then reapply it to the same interface to ensure the command is active.
AnswerB

DHCP relay requires the helper address to be configured on the interface that faces the DHCP clients (the broadcast domain where clients send their DHCPDISCOVER messages). By moving the command to Gi0/1, the router will correctly intercept and forward client requests to the DHCP server.

Why this answer

The ip helper-address command must be applied to the interface that receives the DHCP broadcast from clients, which is Gi0/1 in this scenario. It converts the broadcast into a unicast directed to the DHCP server. Applying it to Gi0/0 (the WAN interface) is ineffective because broadcasts are not forwarded across routers by default, and the helper address must be on the ingress interface of the client subnet.

Exam trap

Cisco often tests the misconception that the ip helper-address should be placed on the interface closest to the server (outbound), when in fact it must be on the interface that receives the client broadcast (inbound).

Why the other options are wrong

A

This skips the obvious configuration mismatch and targets the wrong component. It assumes the issue is on the server side rather than the router's DHCP relay placement.

C

This action investigates Layer 1/2 status when the problem is already identified as a Layer 3 (DHCP relay) configuration error. It skips applying the fix and delays resolution.

D

Candidates might think the command simply didn't take effect and that reapplying it solves the problem, misunderstanding the directional requirement of DHCP relay placement.

527
MCQhard

A network engineer has implemented DHCP snooping on a Cisco switch to prevent unauthorized DHCP servers. The switch's VLAN 100 SVI is configured with ip helper-address to relay DHCP requests to a legitimate server in VLAN 200. Clients in VLAN 100 cannot obtain IP leases, even though the DHCP server is reachable from the switch and has available addresses.

A.The ip helper-address command has been incorrectly applied to VLAN 100 instead of VLAN 200.
B.The switch port that connects to the DHCP server's VLAN is not configured as a trusted DHCP snooping port.
C.DHCP snooping must be disabled globally because it conflicts with the configured DHCP relay agent.
D.The DHCP server lacks a valid default gateway, preventing replies from reaching the relay agent's SVI subnet.
AnswerB

DHCP snooping drops DHCPOFFER and DHCPACK messages received on untrusted ports, since only trusted ports are allowed to accept server-originated replies. The switch port connected to the legitimate DHCP server in VLAN 200 must be explicitly configured as trusted with 'ip dhcp snooping trust'. Without that, the relay agent forwards the client's DISCOVER, but the server's OFFER/ACK are silently discarded, leaving clients without a lease despite the relay configuration.

Why this answer

DHCP snooping treats all switch ports as untrusted by default, which blocks DHCP server messages (OFFER, ACK) from entering the switch. Even though the switch itself can reach the DHCP server, the relayed reply from the server arrives on a port that is not trusted, so DHCP snooping drops the packet before it can be forwarded to the client. Configuring the port connecting to the DHCP server as a trusted port allows the server's responses to pass through the switch, resolving the issue.

Exam trap

Cisco often tests the interaction between DHCP snooping and DHCP relay, where candidates mistakenly think the relay bypasses snooping or that the issue is with the helper-address configuration, rather than the untrusted port blocking the server's unicast reply.

Why the other options are wrong

A

Many engineers mistakenly think the helper should reside on the server VLAN; however, it must reside on the client-facing L3 interface.

C

A common misconception is that DHCP relay bypasses snooping, but snooping still inspects the server's unicast response and drops it unless the ingress port is trusted.

D

Candidates often suspect routing issues, but verified reachability eliminates this. The problem lies in the snooping policy, not IP connectivity.

528
Multi-Selectmedium

Which two statements about ARP on an IPv4 Ethernet network are correct? (Choose two.)

Select 2 answers
A.An ARP request is sent as a Layer 2 broadcast.
B.An ARP reply is normally sent as a unicast frame.
C.ARP is used to map IPv6 addresses to MAC addresses.
D.ARP is forwarded by routers across subnets by default.
AnswersA, B

An ARP request is a broadcast at Layer 2 because the sender knows the target IPv4 address but not the target MAC address. To reach all devices on the local Ethernet segment, the frame's destination MAC is set to FF:FF:FF:FF:FF:FF, causing switches to flood it out all ports and every host in the VLAN to process it. Only the device configured with the target IPv4 address responds.

Why this answer

ARP resolves an IPv4 address to a MAC address on the local segment. ARP requests are broadcast; ARP replies are typically unicast.

Exam trap

Be careful not to confuse ARP requests with replies, and remember that ARP operates only within a local segment.

Why the other options are wrong

C

ARP is specifically designed for IPv4 networks to map IPv4 addresses to MAC addresses. IPv6 uses Neighbor Discovery Protocol (NDP) with ICMPv6 messages to perform address resolution, not ARP.

D

ARP operates only within a single broadcast domain (subnet) and is not forwarded by routers. Routers separate broadcast domains and do not forward ARP requests or replies across subnets by default.

When would these options actually be correct?

C

In a question focused on IPv6 networking, where the task is to identify protocols that map addresses, an option stating that ARP maps IPv6 addresses to MAC addresses could be correct if it was framed in the context of discussing legacy support or compatibility considerations in mixed environments.

D

If the question were to ask about protocols that can be forwarded by routers, such as ICMP or routing protocols, then this option could be correct in the context of discussing how certain network protocols behave across subnets.

Why candidates pick the wrong answer

C

Students may confuse ARP with a general address resolution protocol and assume it works for both IPv4 and IPv6, especially since both involve mapping network-layer addresses to data-link layer addresses.

D

Test-takers might think that because routers forward IP packets, they would also forward ARP messages, not realizing that ARP is a Layer 2 protocol confined to the local network segment.

529
PBQhard

You are connected to R1, a Cisco router running IOS-XE. Configure SNMP v2c with a read-only community string 'publicRW' (note: the string is intentionally misnamed for the task), and SNMP v3 with user 'admin' using MD5 authentication (password 'cisco123') and DES encryption (password 'cisco456'). Ensure SNMP traps for linkUp/linkDown are sent to the management server at 192.0.2.100. Additionally, configure NetFlow export to send version 9 flow records to 192.0.2.200 on UDP port 2055, and ensure that only inbound traffic on GigabitEthernet0/0 is monitored. Finally, verify your configuration using 'show snmp' and 'show ip cache flow'.

Network Topology
G0/010.0.0.1/30G0/010.0.0.2/30linkR1R2

Hints

  • •Remember to create the SNMP v3 user with both auth and priv parameters.
  • •NetFlow requires both a destination and version; also apply flow monitoring on an interface.
  • •Use 'snmp-server enable traps' to activate trap generation before specifying the host.
A.snmp-server community publicRW ro snmp-server user admin admin v3 auth md5 cisco123 priv des cisco456 snmp-server enable traps snmp linkdown linkup snmp-server host 192.0.2.100 traps version 2c publicRW ip flow-export destination 192.0.2.200 2055 ip flow-export version 9 interface GigabitEthernet0/0 ip flow ingress
B.snmp-server community publicRW ro snmp-server user admin admin v3 auth md5 cisco123 priv des cisco456 snmp-server enable traps snmp linkdown linkup snmp-server host 192.0.2.100 traps version 2c publicRW ip flow-export destination 192.0.2.200 2055 ip flow-export version 9
C.snmp-server community publicRW ro snmp-server user admin admin v3 auth md5 cisco123 priv des cisco456 snmp-server enable traps snmp linkdown linkup snmp-server host 192.0.2.100 traps version 2c publicRW ip flow-export destination 192.0.2.200 2055 ip flow-export version 9 interface GigabitEthernet0/0 ip flow egress
D.snmp-server community publicRW ro snmp-server user admin admin v3 auth md5 cisco123 priv des cisco456 snmp-server enable traps snmp linkdown linkup snmp-server host 192.0.2.100 traps version 2c publicRW ip flow-export destination 192.0.2.200 2055 ip flow-export version 9 interface GigabitEthernet0/0 ip flow monitor FLOW-MONITOR input
AnswerA
solution
! R1
snmp-server user admin admin v3 auth md5 cisco123 priv des cisco456
snmp-server enable traps snmp linkdown linkup
snmp-server host 192.0.2.100 traps version 2c publicRW
ip flow-export destination 192.0.2.200 2055
ip flow-export version 9
interface GigabitEthernet0/0
ip flow ingress
end

Why this answer

The initial configuration has an SNMP v2c community string 'publicRW' set as RO, but the task requires it to be the read-only string. The SNMP v3 user 'admin' with MD5/DES is missing entirely, as are trap destinations and NetFlow export. To fix, first add the SNMP v3 user with 'snmp-server user admin admin v3 auth md5 cisco123 priv des cisco456', then enable traps with 'snmp-server enable traps snmp linkdown linkup' and 'snmp-server host 192.0.2.100 traps version 2c publicRW'.

For NetFlow, configure 'ip flow-export destination 192.0.2.200 2055', 'ip flow-export version 9', and apply flow monitoring on an interface (e.g., 'interface GigabitEthernet0/0' with 'ip flow ingress'). The 'show snmp' command will display the community strings and trap receivers, while 'show ip cache flow' will show flow records.

Exam trap

Students often forget to apply NetFlow on an interface with 'ip flow ingress' or confuse it with Flexible NetFlow commands. Also, they may omit the trap enable command or use the wrong SNMP version for trap delivery. Always ensure that NetFlow collection is enabled on an interface and that SNMP traps are both enabled globally and sent to the correct host.

Why the other options are wrong

B

The configuration omits the 'ip flow ingress' (or any) interface command, so NetFlow will not collect any traffic.

C

The 'ip flow egress' command monitors outbound traffic, not the specified inbound traffic on GigabitEthernet0/0.

D

The 'ip flow monitor FLOW-MONITOR input' command references a flexible NetFlow monitor that does not exist; traditional 'ip flow ingress' is required.

Why candidates pick the wrong answer

B

Candidates may think that configuring the export destination and version is sufficient for NetFlow to work, forgetting that flow collection must be enabled on an interface.

C

Candidates might confuse ingress and egress directions, or think that egress is also acceptable without considering the context of the verification command.

D

Candidates familiar with newer IOS-XE versions might use Flexible NetFlow commands, but the task explicitly asks for version 9, which is traditional NetFlow. The 'ip flow monitor' command is a common trap for those who confuse the two.

530
MCQmedium

Which command places a switch interface into trunking mode directly instead of relying on negotiation?

A.switchport mode trunk
B.switchport access vlan 10
C.switchport mode dynamic auto
D.spanning-tree portfast
AnswerA

The switchport mode trunk command explicitly configures the interface as an 802.1Q trunk, forcing it to carry traffic for multiple VLANs over the link. This direct configuration overrides any dynamic trunking protocol (DTP) negotiation, ensuring the port advertises itself as a trunk regardless of the neighbor's default state. It is the only command among these that definitively places the interface into trunking mode without relying on remote device behavior.

Why this answer

The direct command is `switchport mode trunk`. In plain language, this tells the switch to behave as a trunk port rather than waiting to negotiate that role through DTP. That makes the administrative intent clear and avoids ambiguity. In many production environments, explicit configuration is preferred because it is easier to understand and troubleshoot than relying on negotiation behavior.

This is a core CCNA switching idea because trunks and access ports serve very different purposes. The wrong answers either describe negotiation states or commands that relate to other aspects of VLAN behavior. The best answer is the one that directly forces the interface into trunk mode instead of merely suggesting or passively waiting for trunking.

Exam trap

Be careful not to confuse commands that involve negotiation or specify encapsulation with those that directly set the mode.

Why the other options are wrong

B

The command 'switchport access vlan 10' assigns the interface to a specific access VLAN, placing it in access mode, not trunk mode. Trunk mode is required to carry multiple VLANs, and this command does not enable trunking.

C

The command 'switchport mode dynamic auto' places the interface in a mode that waits for the neighboring switch to initiate trunking via DTP. It does not directly force trunking; the interface will only become a trunk if the neighbor is set to 'dynamic desirable' or 'trunk'.

D

The command 'spanning-tree portfast' is used to speed up the transition of an access port to the forwarding state, bypassing the listening and learning phases. It has no effect on trunking mode and is unrelated to VLAN trunk configuration.

When would these options actually be correct?

B

In a different question, if asked about configuring an access port for a specific VLAN, 'switchport access vlan 10' would be the correct answer. For example, a question might ask how to set an interface to carry traffic for VLAN 10 only.

C

In a scenario where the question asks for a command that enables dynamic trunking negotiation, 'switchport mode dynamic auto' would be correct. For example, if the question specified the need for a switch to automatically negotiate trunking with a connected switch, this command would be appropriate.

D

If the exam question asked about configuring an interface to quickly transition to forwarding state for end devices, 'spanning-tree portfast' would be the correct answer. This scenario would focus on optimizing STP for access ports rather than trunking.

Why candidates pick the wrong answer

B

Students might confuse VLAN assignment with trunking, thinking that specifying a VLAN somehow enables trunking. However, trunking is about tagging frames from multiple VLANs, not just assigning a single VLAN.

C

Test-takers may think 'dynamic auto' automatically creates a trunk, but it actually relies on negotiation and does not guarantee trunking. It is often confused with 'dynamic desirable', which actively attempts to form a trunk.

D

Students might associate 'portfast' with fast convergence or think it enables some form of trunking, but it is purely an STP optimization for edge ports and does not affect trunk mode.

531
MCQeasy

A junior administrator is asked to configure a Cisco router interface with the IPv4 address 10.1.1.1 and a subnet mask of 255.255.255.0 so it can route traffic for the 10.1.1.0/24 network. Which command correctly assigns this address to the interface?

A.ipv4 address 10.1.1.1 255.255.255.0
B.ip address 10.1.1.1 mask 255.255.255.0
C.ip address 10.1.1.1 255.255.255.0
D.ip address 10.1.1.1/24
AnswerC

The ip address command on a Cisco router interface accepts the address followed by a dotted-decimal subnet mask, so ip address 10.1.1.1 255.255.255.0 correctly assigns the address and mask. This is the standard syntax used in interface configuration mode and produces the intended 10.1.1.0/24 network on that interface.

Why this answer

Cisco IOS interface configuration uses the ip address command with the address and a dotted-decimal subnet mask, so ip address 10.1.1.1 255.255.255.0 is correct. Slash notation, the ipv4 keyword, and an extra mask keyword are all invalid in this context. Getting the exact syntax right is essential because a rejected command leaves the interface unaddressed and unable to route for the 10.1.1.0/24 network.

Exam trap

The trap here is mixing CIDR slash notation or non-IOS keywords into a command that requires a dotted-decimal mask.

532
Drag & Dropmedium

Drag and drop the following steps into the correct order to retrieve the operational status of interface GigabitEthernet0/0 using NETCONF and the ietf-interfaces YANG model.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
6Step 6

Why this order

First, establish an SSH connection to the device's NETCONF subsystem (TCP port 830). The NETCONF protocol then performs a capability exchange via <hello> messages to ensure both sides support the required YANG models. Next, a <get> RPC with an XPath filter is sent to request the specific interface status.

The server replies with <rpc-reply> containing the XML data. The client parses the XML to extract the desired value. Finally, the NETCONF session is closed by a <close-session> RPC, and the SSH connection is terminated.

This order ensures a proper NETCONF transaction lifecycle.

533
MCQhard

A host cannot communicate with its default gateway. The technician uses the show arp command on the host and sees that the ARP entry for the gateway IP is incomplete. The technician has already verified that the Ethernet cable is securely connected and the switch port is active. What should the technician do next?

A.Check the switch port’s VLAN configuration and ensure the host and router interface are in the same VLAN.
B.Replace the Ethernet cable between the host and the switch.
C.Clear the ARP cache on the host and attempt to ping the gateway again.
D.Check the router’s routing table for a route to the host’s subnet.
AnswerA

If the host and gateway are in different VLANs, the ARP request broadcast never reaches the gateway, so the entry stays incomplete. This step directly addresses the most probable Layer 2 fault after excluding physical issues.

Why this answer

An incomplete ARP entry for the default gateway indicates that the host sent an ARP request but never received a reply. Since the physical layer (cable and switch port) is verified as operational, the most likely cause is a Layer 2 mismatch: the host and the router interface are in different VLANs, preventing the ARP reply from reaching the host. Checking the switch port's VLAN configuration ensures both devices are in the same broadcast domain, which is required for ARP to function.

Exam trap

Cisco often tests the distinction between Layer 2 connectivity (ARP, VLANs) and Layer 3 connectivity (routing), leading candidates to incorrectly focus on routing tables or ARP cache clearing when the real issue is a VLAN mismatch.

Why the other options are wrong

B

Candidates may equate a physical link symptom with a faulty cable, but the port’s active status indicates a good L1 connection. This action skips necessary logical checks.

C

This is a common ‘quick fix’ mindset, but in a structured troubleshooting process, clearing the cache hides information without solving the root cause.

D

Candidates might confuse local ARP failure with reachability issues to a remote subnet, but the gateway is the router itself. Routing is irrelevant until the destination is off-segment.

534
MCQeasy

Which HTTP method is normally used by a REST API client to retrieve data from a resource without changing it?

A.POST
B.PUT
C.GET
D.DELETE
AnswerC

The GET method is the correct choice because it is specifically defined for retrieving the current representation of a resource identified by a URI. It is a safe and idempotent method, meaning it causes no side effects on the server and multiple identical requests return the same result. A RESTful API client uses GET to read resource state, such as fetching a JSON document.

Why this answer

GET requests read a resource. They are used to retrieve state or information without modifying the target object.

Exam trap

Confusing HTTP methods can lead to selecting POST or PUT when the question specifically asks for retrieving data without modification. POST is often associated with creating resources, and PUT with updating them. Selecting DELETE is clearly incorrect as it removes resources.

The trap is to overlook that GET is the only method designed to safely retrieve data without side effects, which is critical in REST API operations relevant to network programmability.

Why the other options are wrong

A

POST is incorrect because it is used to create or submit data, not to retrieve data without changes.

B

PUT is incorrect as it replaces or updates a resource, which modifies the data rather than just retrieving it.

D

DELETE is incorrect since it removes a resource, not retrieves data.

When would these options actually be correct?

A

In a question asking which HTTP method is used to submit data to a server for processing, such as creating a new user account or submitting a form, POST would be the correct answer.

B

In a different question asking which HTTP method is used to update an existing resource on a server, the correct answer would be PUT. For example, a question could state, 'Which HTTP method is used to send data to a server to update an existing resource?'

D

If the question were to ask which HTTP method is used to remove a resource from a REST API, then DELETE would be the correct answer. For example, a question might state, 'Which HTTP method is used to delete a specific resource identified by a URI?'

Why candidates pick the wrong answer

A

Students may confuse POST with GET because both can send data to the server, but POST is intended for state-changing operations, not retrieval.

B

Students might think PUT can retrieve data because it is often used in CRUD operations alongside GET, but its purpose is to update, not retrieve.

D

Students might mistakenly associate DELETE with retrieval due to its role in CRUD, but it is exclusively for deletion.

535
MCQhard

Exhibit: A router has the following routes in its routing table: - OSPF: 10.1.1.0/24 - Static: 10.1.1.128/25 - Default: 0.0.0.0/0 A packet is destined for 10.1.1.130. Which route does the router use?

A.The OSPF 10.1.1.0/24 route
B.The static 10.1.1.128/25 route
C.The default route
D.The router load-balances across all three
AnswerB

Although the OSPF route has a lower administrative distance, the destination 10.1.1.130 falls inside the 10.1.1.128/25 range, and the forwarding decision uses longest-prefix-match: the /25 mask represents 128 addresses, while the /24 represents 256, making the /25 the most specific, or longest, prefix that contains the destination. Therefore, the router forwards this packet via the static route, not by any other attribute.

Why this answer

Routers use longest-prefix match before they think about metrics. The /25 route for 10.1.1.128/25 is more specific than the /24 or the default route, so traffic for 10.1.1.130 follows that path.

Exam trap

A common exam trap is to select a route based solely on routing protocol preference or administrative distance without considering prefix length. Many candidates incorrectly choose the OSPF 10.1.1.0/24 route because OSPF is a dynamic protocol and might assume it is preferred over a static route. However, Cisco routers always apply longest-prefix match first, so the static 10.1.1.128/25 route is chosen because it is more specific.

Another trap is to think the router load-balances across all routes, but load balancing only occurs among routes with equal prefix length and metric, not across different subnet sizes.

Why the other options are wrong

A

The OSPF 10.1.1.0/24 route matches the destination IP but has a shorter prefix length than the static /25 route. Since longest-prefix match takes priority, this route is not used.

C

The default route is a last-resort route used only when no other specific routes match the destination IP. Since more specific routes exist, it is not selected here.

D

The router does not load-balance across routes with different prefix lengths because longest-prefix match selects a single best route, so this option is incorrect.

When would these options actually be correct?

A

In a scenario where the question asks which route would be used if the destination IP were 10.1.1.0, the OSPF 10.1.1.0/24 route would be the correct answer, as it matches the entire subnet and is the best match for that specific address.

C

In a scenario where the router has no specific routes for the destination address and only a default route configured (e.g., 0.0.0.0/0), a packet destined for an unknown address would use the default route. An exam question could specify that no other routes are available for the destination.

D

In a different scenario where multiple equal-cost routes exist for the same destination, and the router is configured to load-balance, this option would be correct. For example, if there were multiple static routes to 10.1.1.130 with the same metric, the router would indeed load-balance traffic across them.

Why candidates pick the wrong answer

A

Students may think that because the /24 route is learned via OSPF (a dynamic routing protocol) and has a lower administrative distance than a static route, it would be preferred. However, prefix length takes precedence over administrative distance in the forwarding decision.

C

Students might think that if a default route exists, it will be used as a catch-all. However, the router always checks for more specific matches first; the default route is the last resort.

D

Students may confuse equal-cost multipath (ECMP) load balancing with the general concept of having multiple routes. They might think that because multiple routes exist, the router will distribute traffic among them, but that only happens when routes are equally specific.

536
MCQmedium

A switch stack is running PVST+. Users on VLAN 40 lose connectivity for roughly 30 seconds every time the uplink on SW2 flaps. Based on the exhibit, which change would most directly improve convergence for this VLAN?

A.Configure spanning-tree mode rapid-pvst.
B.Increase the bridge priority on SW2 for VLAN 40.
C.Disable PortFast on all access ports.
D.Convert the uplink to a routed port.
AnswerA

Configuring `spanning-tree mode rapid-pvst` directly addresses the 30-second connectivity loss by enabling Rapid PVST+ (R-PVST+). PVST+ utilises fixed listening and learning states, contributing to the observed delay during topology changes. R-PVST+ employs a rapid convergence mechanism, such as the Proposal/Agreement (P/A) process, allowing designated and root ports to transition to forwarding much faster, often within sub-seconds. This significantly reduces the reconvergence time for VLAN 40 when SW2's uplink flaps, directly improving user connectivity.

Why this answer

The output shows VLAN 40 is still using the legacy IEEE STP process, which converges much more slowly than Rapid PVST+. Moving the switch to rapid-pvst mode gives VLAN 40 the faster proposal/agreement behavior that typically cuts convergence time from tens of seconds to a few seconds.

Exam trap

A frequent exam trap is selecting options that change the root bridge election or port roles, such as increasing bridge priority, assuming this will speed up convergence. While root bridge placement affects path selection, it does not reduce the inherent delay caused by legacy STP timers. Another trap is disabling PortFast on access ports, which only affects edge port transitions and does not influence uplink link flap recovery times.

Additionally, converting uplinks to routed ports changes the network design and removes STP from those ports, which is not the intended solution for VLAN-specific STP convergence delays. The key mistake is confusing topology optimization with protocol speed improvements.

Why the other options are wrong

B

Increasing bridge priority changes root bridge election but does not speed up the STP convergence process, so it does not resolve the 30-second connectivity loss.

C

Disabling PortFast affects only edge ports and does not influence the convergence time of uplink ports or VLANs experiencing link flaps.

D

Converting the uplink to a routed port removes it from STP but alters network design and does not specifically improve VLAN 40’s STP convergence speed.

When would these options actually be correct?

B

In a different scenario where the question asks about optimizing the spanning tree topology for a network with multiple VLANs and where SW2 is not the root bridge, increasing the bridge priority could help in making SW2 the root bridge, potentially improving overall network performance.

C

In a scenario where a question asks about improving convergence time on access ports that are incorrectly configured with PortFast enabled, disabling PortFast could be the correct answer. This would apply if the exam context indicated that the access ports were causing issues due to improper handling of STP states.

D

In a scenario where the question asks how to optimize routing performance for inter-VLAN traffic and reduce latency, converting the uplink to a routed port could be the correct answer. This would be appropriate if the focus was on routing efficiency rather than spanning tree convergence.

Why candidates pick the wrong answer

B

Students may think that making SW2 the root bridge would speed up convergence because the root bridge is central to STP operations. However, root bridge election does not affect the convergence time of individual link flaps; the STP mode is the key factor.

C

Some might confuse PortFast with features that affect uplink convergence, or think that disabling unnecessary features could improve stability. However, PortFast is designed for access ports and does not impact uplink STP convergence.

D

Routed ports do not participate in STP, so a student might think that eliminating STP on the uplink would avoid convergence delays. However, this ignores the need for loop prevention in a switched network and the fact that the uplink is a trunk carrying multiple VLANs.

537
MCQeasy

Which Cisco IOS command configures a default static route pointing to next hop 203.0.113.1?

A.ip route 0.0.0.0 0.0.0.0 203.0.113.1
B.ip default-gateway 203.0.113.1
C.default-information originate 203.0.113.1
D.route add 0.0.0.0 203.0.113.1
AnswerA

The correct Cisco IOS command for a default static route is "ip route 0.0.0.0 0.0.0.0 203.0.113.1". The all-zero prefix and all-zero mask act as a wildcard, matching every destination IP address. Traffic with no more specific route matching in the routing table is forwarded to the next hop 203.0.113.1, establishing a default gateway for the router.

Why this answer

A default static route uses the all-zero network and mask, followed by the next-hop IP address or exit interface.

Exam trap

Remember that a default static route uses the all-zero network and mask, not a /32 mask or an exit interface unless specified.

Why the other options are wrong

B

The ip default-gateway command is used on Cisco switches in Layer 2 mode or on routers when IP routing is disabled. On a router with IP routing enabled, this command does not create a static route; it only sets the default gateway for the management interface, not for forwarding traffic.

C

The default-information originate command is used in routing protocols like OSPF or EIGRP to inject a default route into the routing domain. It does not create a static route itself; it only advertises an existing default route (which must already be present in the routing table) to other routers.

D

The route add command is used in Windows or Linux operating systems, not in Cisco IOS. Cisco IOS uses the ip route command to configure static routes. Using route add on a Cisco router would result in an unrecognized command error.

When would these options actually be correct?

B

If the exam question asked for the command to configure a default gateway on a Layer 2 switch or a router in a non-routing mode, then 'ip default-gateway 203.0.113.1' would be the correct answer, as it specifies the next hop for traffic leaving the device.

C

If the exam question asked for a command to advertise a default route to other routers in a routing protocol like OSPF or EIGRP, then 'default-information originate' would be the correct answer, indicating that the router should inform others about the default route.

D

If the question were about configuring static routes on a Linux-based router or system, 'route add 0.0.0.0 203.0.113.1' would be the correct command to set a default route to the next hop 203.0.113.1.

Why candidates pick the wrong answer

B

Students often confuse ip default-gateway with a default static route because both involve a default path. However, ip default-gateway is only effective when routing is disabled, whereas a default static route is used when routing is enabled.

C

The phrase 'default' in the command name leads students to think it creates a default route. However, it is a routing protocol command, not a static route configuration command.

D

Students familiar with other operating systems may mistakenly apply the same syntax to Cisco IOS. The similarity in purpose (adding a route) makes it tempting, but the command syntax is platform-specific.

538
MCQhard

A network engineer receives a call that users in VLAN 10 on Switch B cannot ping the default gateway, which is a router on a stick connected to Switch A. The engineer checks the Spanning Tree Protocol state on the interface connecting Switch A to Switch B (GigabitEthernet0/1) and finds it is in a root-inconsistent state. Which command output best explains the cause of the issue?

A.The interface is in err-disable state due to BPDU guard.
B.Root guard is enabled and the port received a superior BPDU, causing it to become root-inconsistent.
C.Loop guard is enabled and the port is in a blocking state due to missing BPDUs.
D.The port is in a forwarding state but the VLAN is misconfigured.
AnswerB

Root guard is correctly the cause: when a port configured with root guard receives a superior BPDU (i.e., a BPDU that would make the local switch root or change the root bridge), the port is moved to a root-inconsistent state. This blocks all traffic on the port to protect the existing root bridge and prevent a rogue switch from hijacking the spanning tree. The symptom matches exactly—the port is administratively placed in this state, not in err-disable or loop-inconsistent.

Why this answer

Root guard, when enabled on a port, places that port into a root-inconsistent blocking state if it receives a superior BPDU, preventing the switch from becoming the root bridge. This root-inconsistent state stops forwarding traffic, which explains why users in VLAN 10 cannot reach the default gateway. The port remains physically up but is blocked by spanning tree, so normal interface status would not show a down state, making the root-inconsistent state the key indicator.

Exam trap

Candidates often confuse root guard with BPDU guard: BPDU guard err-disables a port upon receiving any BPDU on a PortFast port, while root guard responds to superior BPDUs by placing the port in root-inconsistent state, not err-disable.

Why the other options are wrong

A

BPDU guard causes an err-disable state, which would show the interface as down or err-disabled, not as root-inconsistent.

C

Loop guard places a port into loop-inconsistent blocking state when BPDUs stop being received, not when a superior BPDU is received.

D

A forwarding state would allow traffic; the problem here is that the port is in a blocked state due to root guard, not a misconfigured VLAN.

Why candidates pick the wrong answer

A

Students may confuse BPDU guard with root guard because both involve BPDU protection and can cause ports to block. The term 'err-disable' is commonly associated with BPDU guard, making it a plausible distractor.

C

Both root guard and loop guard are STP enhancement features that can cause ports to block. Students may confuse the conditions: root guard reacts to superior BPDUs, while loop guard reacts to missing BPDUs.

D

Students might think that VLAN misconfiguration could cause connectivity issues, and if they overlook the interface status, they might choose this option. However, the interface being down points to a Layer 1 or STP issue, not a VLAN mismatch.

539
PBQmedium

You are connected to SW1 via console. SW1 is a Layer 2 switch. Port G0/1 connects to a PC that should be allowed only one MAC address. Currently, the port is configured with default settings. You need to enable port security on G0/1, set the maximum MAC addresses to 1, configure the port to shut down if a violation occurs, and ensure that the first learned MAC address is sticky (i.e., saved to the running config).

Network Topology
G0/1PCSW1

Hints

  • •Port security must be enabled on an access port or trunk port.
  • •The 'sticky' keyword makes the MAC address sticky and adds it to the running config.
A.interface G0/1 switchport port-security switchport port-security maximum 1 switchport port-security violation shutdown switchport port-security mac-address sticky
B.interface G0/1 switchport port-security switchport port-security maximum 1 switchport port-security violation protect switchport port-security mac-address sticky
C.interface G0/1 switchport port-security switchport port-security maximum 2 switchport port-security violation shutdown switchport port-security mac-address sticky
D.interface G0/1 switchport port-security switchport port-security maximum 1 switchport port-security violation shutdown switchport port-security mac-address 0000.1111.2222
AnswerA
solution
! SW1
interface gigabitethernet0/1
switchport port-security
switchport port-security maximum 1
switchport port-security violation shutdown
switchport port-security mac-address sticky

Why this answer

Enabling port security and setting maximum MAC addresses to 1 limits the port to one device. The violation shutdown mode disables the port if another MAC attempts to use it. Sticky MAC learning dynamically learns the first MAC and saves it to the running configuration.

Exam trap

Be careful to distinguish between the different violation modes: shutdown (disables port), protect (drops packets without notification), and restrict (drops packets and sends SNMP trap). Also, note that sticky MAC learning is different from statically configuring a MAC address; sticky learning automatically saves the learned MAC to the running config.

Why the other options are wrong

B

The violation mode 'protect' does not shut down the port; it only drops offending traffic. The question explicitly requires the port to shut down.

C

The maximum MAC addresses must be set to 1 to restrict the port to a single device. Setting it to 2 allows an additional device.

D

The command 'switchport port-security mac-address 0000.1111.2222' statically assigns a MAC address, which does not allow dynamic learning. Sticky learning is enabled with the 'sticky' keyword.

Why candidates pick the wrong answer

B

Candidates may confuse the different violation modes (protect, restrict, shutdown) and might think 'protect' is sufficient because it prevents unauthorized traffic, but it does not disable the port.

C

Candidates might mistakenly think that the default maximum is 1 or that setting it to 2 is acceptable, but the question explicitly requires a maximum of 1.

D

Candidates may think that manually configuring a MAC address is equivalent to sticky learning, but sticky learning dynamically learns and saves the first MAC, whereas static configuration requires manual entry and does not adapt.

540
MCQmedium

Which IPv6 address type is automatically created on an interface and used for communication on the local link only?

A.Global unicast
B.Link-local
C.Unique local
D.Multicast
AnswerB

Link-local addresses (fe80::/10) are automatically generated on all IPv6-enabled interfaces and remain confined to a single link; they are not routed by routers. This automatic creation happens immediately when IPv6 is enabled on the interface, and the address is typically derived from the interface's MAC address using EUI-64 or generated randomly with privacy extensions. This is the address type the question refers to.

Why this answer

Every IPv6-enabled interface generates a link-local address, typically in the FE80::/10 range. It is used for neighbor discovery, local communication, and next-hop resolution on the same link.

Exam trap

A common exam trap is confusing link-local addresses with unique local or global unicast addresses. Link-local addresses are automatically generated and only valid on the local link, whereas unique local addresses resemble private IPv4 addresses but are routable within an organization. Multicast addresses are not assigned to interfaces for unicast communication, so selecting multicast is incorrect.

Understanding the scope and automatic generation of link-local addresses is critical.

Why the other options are wrong

A

Global unicast addresses are routable beyond the local link and are not automatically created for local link communication only.

C

Unique local addresses are similar to private IPv4 addresses and are routable within an organization, not limited to the local link.

D

Multicast addresses are used for group communication and are not assigned as interface addresses for unicast communication.

When would these options actually be correct?

A

If the question asked for an IPv6 address type that is routable on the internet and can be used for global communication, then Global unicast would be the correct answer, as it is designed for that purpose.

C

If the question were to ask which IPv6 address type is used for communication within a private network and is not routable on the global internet, then Unique Local would be the correct answer, as it fits the criteria for private addressing.

D

If the question asked for the type of IPv6 address used for sending packets to multiple devices on a local network segment, then 'multicast' would be the correct answer. For example, a question could specify the address type used for group communication within a local subnet.

Why candidates pick the wrong answer

A

Students might think global unicast is automatically created because of SLAAC (Stateless Address Autoconfiguration), but SLAAC generates addresses based on a prefix advertised by a router, not automatically without a router. Additionally, global unicast is not limited to the local link.

C

Students may confuse unique local with link-local because both are not globally routable. However, unique local addresses are site-local (routable within an organization) and not automatically generated for local-link-only communication.

D

Students may confuse multicast with link-local because both are confined to the local link in some contexts (e.g., multicast groups like FF02::1). However, multicast is not a unicast address type assigned to an interface; it is a destination address for group communication.

541
MCQhard

A network administrator is troubleshooting an IPv6 connectivity issue on a newly deployed router. The router's G0/0/0 interface is configured with an IPv6 address using EUI-64, but hosts on that subnet cannot reach the router's link-local address. The administrator runs 'show ipv6 interface g0/0/0' and sees that the interface is up/up but the IPv6 address is not in the expected format. What is the most likely cause of the problem?

A.The interface is administratively down.
B.The IPv6 address was not configured correctly; the 'ipv6 address' command was likely omitted or misconfigured.
C.The MAC address of the interface is invalid, preventing EUI-64 from generating a proper address.
D.The router is not sending Router Advertisements, so hosts cannot autoconfigure.
AnswerB

If the 'ipv6 address' command was omitted, IPv6 is not enabled, and no link-local address exists. If it was misconfigured (e.g., missing the `eui-64` keyword), the router would still have a link-local address, so the symptom of hosts unable to reach the link-local address would not occur. Therefore, omission is the most likely cause given the symptom.

Why this answer

The router's G0/0/0 interface is up/up, but the IPv6 address is not in the expected EUI-64 format. This indicates that the 'ipv6 address' command was likely omitted entirely, because if it were simply misconfigured (e.g., without the `eui-64` keyword), the router would still automatically generate a link-local address, and hosts would be able to reach it. Since hosts cannot reach the link-local address, IPv6 is not enabled on the interface at all.

The correct configuration requires the `ipv6 address` command with the appropriate prefix and the `eui-64` keyword.

Exam trap

Cisco often tests the distinction between interface status (up/up) and configuration correctness, leading candidates to assume that a working interface means the IPv6 address is properly configured, when in fact the address may be missing or misconfigured.

Why the other options are wrong

A

The 'show ipv6 interface' output shows 'up, line protocol is up', indicating the interface is not administratively down. An administratively down interface would show 'administratively down' in the output.

C

The link-local address (FE80::21A:2BFF:FE3C:4D5E) is correctly formed using EUI-64, which requires a valid MAC address. The presence of 'FF:FE' in the middle indicates EUI-64 is functioning properly, so the MAC address is valid.

D

The output shows 'ND router advertisements are sent every 200 seconds', confirming that Router Advertisements are enabled. The problem is about the router's own IPv6 address, not host autoconfiguration.

Why candidates pick the wrong answer

A

Students often confuse 'up/up' with 'administratively down' when troubleshooting connectivity issues, but the output clearly indicates the interface is operational.

C

Students may think that an invalid MAC address could cause EUI-64 to fail, but the output shows a properly formed link-local address, ruling out this issue.

D

Router Advertisements are critical for SLAAC, and students might assume that missing RAs cause connectivity issues. However, the question focuses on the router's address, not host configuration.

542
MCQhard

A route to 10.10.20.0/24 disappears when an OSPF adjacency fails. Which design would most directly provide an automatic backup without changing the primary OSPF path during normal operation?

A.A floating static route with a higher administrative distance than OSPF
B.A standard static route with the default administrative distance of 1
C.Removing OSPF entirely and using only a default route
D.Disabling the routing table on the router until failure occurs
AnswerA

A floating static route is configured with an administrative distance greater than OSPF's default of 110 (commonly 120 or 150). Because the router prefers the lowest AD, this route stays out of the routing table while OSPF is healthy, but it is immediately installed when OSPF loses the route. This gives you a backup path without ever overriding OSPF's normal forwarding decision, which is exactly what a floating route is designed to do.

Why this answer

The most direct design is a floating static route with a higher administrative distance than OSPF. In plain language, that means the router keeps a manually configured backup route in reserve but does not use it while the OSPF route remains healthy. If the OSPF path disappears, the backup static route becomes active automatically. This is a very common and practical way to add simple failover.

The key requirement in the question is that the primary OSPF path should remain unchanged under normal conditions. A normal static route with default distance would override OSPF and break that goal. A floating static route avoids that by staying less preferred until a failure occurs. That is why it is the correct design choice here.

Exam trap

Avoid assuming that static routes are always less preferred than dynamic routes without considering administrative distance.

Why the other options are wrong

B

A standard static route with the default administrative distance of 1 would override the OSPF route (AD 110) because a lower AD is preferred. This would replace the primary OSPF path with the static route, not provide a backup that only activates upon failure.

C

Removing OSPF entirely eliminates the primary dynamic routing protocol, which is not a backup solution. The question requires preserving OSPF as the normal path and only providing an automatic backup when OSPF fails.

D

Disabling the routing table is not a valid operational practice; routers require the routing table to forward packets. This option does not provide any automatic backup mechanism and would break connectivity entirely.

When would these options actually be correct?

B

In a different scenario where the question asks for a static route to be preferred under all circumstances, a standard static route with an administrative distance of 1 would be correct. For example, if the question specifies that OSPF is not required and a static route should always be used for traffic to a specific destination.

C

In a scenario where a network is designed to only use a default route for all outbound traffic, and OSPF is deemed unnecessary due to a simple topology, the question might ask for the most efficient routing method. In that case, using a default route would be the correct answer.

D

In a scenario where a question asks for a method to temporarily suspend routing while performing maintenance or troubleshooting without affecting the overall network performance, disabling the routing table could be deemed appropriate to ensure no traffic is routed incorrectly during that time.

Why candidates pick the wrong answer

B

Students may think that any static route can serve as a backup, but they overlook that the default AD of 1 makes it preferred over OSPF, thus changing the primary path rather than floating behind it.

C

Some might think that using only a default route simplifies the design, but this does not maintain OSPF as the primary path and does not provide a backup for the specific /24 route.

D

The idea of 'disabling until failure' might sound like a failover concept, but it is not how routing works. Students may confuse this with route filtering or policy-based routing, but it is not a standard feature.

543
Matchingmedium

Match each API workflow concept to the description that best fits it.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Target resource path

Requested action such as retrieve or delete

Access-related value carried by the client

Structured payload format

Why these pairings

Ly defines REST as a stateless architectural style using standard HTTP methods (GET, POST, PUT, DELETE) and typically exchanging data in JSON or XML. Option B is incorrect because SOAP uses XML, not JSON, and is not lightweight; it is a protocol with strict standards. Option C is incorrect because GraphQL is a query language, not a protocol requiring XML schemas; it allows clients to request specific data, often using JSON.

Option D is incorrect because webhooks are callback-based push notifications triggered by events, not periodic polling.

Exam trap

Candidates often confuse the characteristics of REST and SOAP, mistakenly thinking SOAP is lightweight or uses JSON, or that GraphQL requires XML schemas. Webhooks are frequently misinterpreted as polling mechanisms instead of event-driven callbacks.

When would these options actually be correct?

B

If the question asked: 'Which protocol uses XML-based messaging, supports ACID transactions, and is often used in enterprise environments?' then SOAP would be correct.

C

If the question asked: 'Which API technology uses a type system to define queries and mutations, allowing clients to request exactly the data they need?' then GraphQL would be the correct answer.

D

In a question asking to match 'a method for polling servers at regular intervals to check for updates' to the correct concept, the answer would be 'polling' or 'long polling', not webhooks.

Why candidates pick the wrong answer

B

Candidates may confuse SOAP with REST due to both being web service protocols, or mistakenly think JSON is used in SOAP because JSON is common in modern APIs.

C

Candidates may confuse GraphQL's subscription feature for real-time notifications and mistakenly think it requires XML schemas due to familiarity with SOAP's strict XML requirements.

D

Candidates may confuse webhooks with polling because both are used to get updates, but they forget that webhooks are event-driven push notifications, not scheduled pull requests.

544
PBQhard

You are connected to R1. The inside network 192.168.1.0/24 must be translated to the outside interface IP (198.51.100.1) using PAT (NAT overload). Additionally, a static NAT entry must map host 192.168.1.10 to 203.0.113.10. The current configuration is incomplete and contains errors. Correct the configuration so that both translations work properly.

Network Topology
G0/0 inside192.168.1.1/24G0/1 outside198.51.100.1/24R1

Hints

  • •Check the direction of NAT on each interface (inside vs outside).
  • •The PAT command requires the keyword 'overload' to enable port address translation.
  • •The access list must match the inside local network, not a different subnet.
A.interface GigabitEthernet0/1 ip nat outside ! access-list 1 permit 192.168.1.0 0.0.0.255 ! ip nat inside source list 1 interface GigabitEthernet0/1 overload ip nat inside source static 192.168.1.10 203.0.113.10
B.interface GigabitEthernet0/1 ip nat inside ! access-list 1 permit 192.168.1.0 0.0.0.255 ! ip nat inside source list 1 interface GigabitEthernet0/1 overload ip nat inside source static 192.168.1.10 203.0.113.10
C.interface GigabitEthernet0/1 ip nat outside ! access-list 1 permit 10.0.0.0 0.255.255.255 ! ip nat inside source list 1 interface GigabitEthernet0/1 ip nat inside source static 192.168.1.10 203.0.113.10
D.interface GigabitEthernet0/1 ip nat outside ! access-list 1 permit 192.168.1.0 0.0.0.255 ! ip nat inside source list 1 interface GigabitEthernet0/1 overload ip nat inside source static tcp 192.168.1.10 80 203.0.113.10 80
AnswerA
solution
! R1
interface GigabitEthernet0/1
ip nat outside
exit
ip nat inside source list 1 interface GigabitEthernet0/1 overload
access-list 1 permit 192.168.1.0 0.0.0.255

Why this answer

The configuration has three issues: 1) GigabitEthernet0/1 is incorrectly set as 'ip nat inside' instead of 'ip nat outside'. 2) The PAT command is missing the 'overload' keyword. 3) Access-list 1 permits 10.0.0.0/8, not the inside subnet 192.168.1.0/24. The commands fix these: change the interface to 'ip nat outside', add 'overload' to the PAT command, and update the ACL to permit the correct inside network.

Exam trap

Watch out for three common mistakes: 1) Forgetting to set the outside interface as 'ip nat outside'. 2) Using an ACL that does not match the inside network. 3) Omitting the 'overload' keyword for PAT. Also, do not add protocol/port to static NAT unless specifically required.

Why the other options are wrong

B

The specific factual error is that the interface facing the outside (public) network is incorrectly configured as 'ip nat inside'.

C

The specific factual errors are: 1) The ACL does not match the correct inside network. 2) The 'overload' keyword is omitted, preventing PAT from working.

D

The specific factual error is that the static NAT command includes protocol and port, limiting the translation to TCP port 80 only.

Why candidates pick the wrong answer

B

Candidates might think that both inside and outside interfaces can be marked as 'inside' if they are internal, but the outside interface must be explicitly marked as 'outside'.

C

Candidates might mistakenly use a standard ACL that permits a different private range (10.0.0.0/8) and forget the 'overload' keyword, thinking it is optional.

D

Candidates might think that static NAT requires specifying a port for the translation, but a simple 'ip nat inside source static' without port creates a one-to-one mapping for all traffic.

545
MCQmedium

Why is NTP especially valuable when a company uses a centralized Syslog server?

A.It synchronizes device clocks so centralized log timestamps can be correlated accurately.
B.It assigns the Syslog server its IP address.
C.It replaces the need for Syslog entirely.
D.It encrypts all Syslog messages automatically.
AnswerA

Syslog entries carry only local device clocks, so unsynchronised clocks make correlating events across devices impossible. NTP aligns all devices to a common time source, giving the centralised Syslog server consistent timestamps for accurate forensic and troubleshooting timelines.

Why this answer

NTP is especially valuable because it aligns device clocks, which makes centralized log timestamps much easier to interpret. In practical terms, if devices disagree on time, the combined log stream becomes harder to trust and correlate. NTP improves the timeline accuracy of operational and security analysis.

This is why NTP and Syslog are often discussed together. One centralizes events, and the other makes those events easier to line up correctly.

Exam trap

A common exam trap is to confuse NTP’s role with other network functions such as IP addressing or encryption. Some candidates incorrectly think NTP assigns IP addresses to devices or encrypts Syslog messages. This misunderstanding leads to selecting options that describe unrelated functions.

NTP’s sole purpose is to synchronize clocks across devices, enabling accurate timestamping of logs. Misinterpreting this can cause candidates to overlook the critical importance of time alignment in centralized logging environments, which is the core reason NTP is valuable when using a centralized Syslog server.

Why the other options are wrong

B

Incorrect because NTP does not assign IP addresses; IP addressing is handled by DHCP or manual configuration, not time synchronization protocols.

C

Incorrect because NTP does not replace Syslog; NTP provides time synchronization, while Syslog collects and centralizes log messages from devices.

D

Incorrect because NTP does not encrypt Syslog messages; encryption requires separate protocols such as TLS or IPsec, not time synchronization services.

When would these options actually be correct?

B

In a question focused on network configuration protocols, such as one asking about how devices obtain their network settings, option B could be correct if it stated that a protocol assigns IP addresses. For example, a question could ask which protocol is responsible for assigning IP addresses to devices in a network.

C

If the exam question asked about technologies that can replace traditional logging methods or systems, then this option could be correct. For example, a question could ask about a hypothetical scenario where a new logging protocol entirely supersedes Syslog, making NTP irrelevant.

D

If the exam question asked about a protocol that provides both time synchronization and encryption for log messages, such as a secure logging protocol that includes NTP-like features, then this option would be correct. For example, a question could specify a scenario where encrypted logging is required alongside time synchronization.

Why candidates pick the wrong answer

B

Students might confuse NTP with DHCP or other protocols that provide network configuration, or they might think that NTP is involved in network discovery. However, NTP's sole purpose is time synchronization.

C

A student might think that since NTP provides timestamps, it could replace the need for a separate logging system. However, Syslog is needed for the actual log content and transport.

D

Students might assume that because NTP is a network protocol, it could also handle security. However, NTP has no encryption capabilities; it is purely for time synchronization.

546
PBQhard

You are connected to R1 via console. R1 is a router that connects two internal subnets (192.168.1.0/24 and 192.168.2.0/24) to the internet via a serial link to ISP. Currently, no ACL is applied. Your task is to configure an extended named ACL on R1 that permits only HTTP (TCP/80) and HTTPS (TCP/443) traffic from the 192.168.1.0/24 subnet to the internet, and denies all other traffic from that subnet. Traffic from 192.168.2.0/24 must be permitted without restriction. Apply the ACL inbound on the interface facing the internal subnets. Additionally, verify that the implicit deny is not blocking necessary traffic by ensuring that the ACL correctly handles the traffic.

Network Topology
G0/0192.168.1.1/24serialR1ISP

Hints

  • •Traffic from 192.168.1.0/24 enters R1 through G0/0, so apply the ACL inbound on G0/0.
  • •The ACL must include a permit statement for 192.168.2.0/24 to avoid being blocked by implicit deny.
  • •Use the 'eq' keyword to match specific port numbers for HTTP (80) and HTTPS (443).
A.ip access-list extended FILTER permit tcp 192.168.1.0 0.0.0.255 any eq 80 permit tcp 192.168.1.0 0.0.0.255 any eq 443 permit ip 192.168.2.0 0.0.0.255 any interface g0/0 ip access-group FILTER in
B.ip access-list extended FILTER permit tcp 192.168.1.0 0.0.0.255 any eq 80 permit tcp 192.168.1.0 0.0.0.255 any eq 443 permit ip 192.168.2.0 0.0.0.255 any interface g0/0 ip access-group FILTER out
C.ip access-list extended FILTER permit tcp 192.168.1.0 0.0.0.255 any eq 80 permit tcp 192.168.1.0 0.0.0.255 any eq 443 permit ip 192.168.2.0 0.0.0.255 any interface g0/1 ip access-group FILTER in
D.ip access-list extended FILTER permit tcp 192.168.1.0 0.0.0.255 any eq 80 permit tcp 192.168.1.0 0.0.0.255 any eq 443 permit ip 192.168.2.0 0.0.0.255 any interface g0/0 ip access-group FILTER in interface g0/1 ip access-group FILTER in
AnswerA
solution
! R1
ip access-list extended FILTER
permit tcp 192.168.1.0 0.0.0.255 any eq 80
permit tcp 192.168.1.0 0.0.0.255 any eq 443
permit ip 192.168.2.0 0.0.0.255 any
interface gigabitEthernet0/0
ip access-group FILTER in

Why this answer

The task required an extended ACL to permit HTTP/HTTPS from 192.168.1.0/24 and all traffic from 192.168.2.0/24. The candidate must create a named ACL (e.g., FILTER), add two permit statements for TCP/80 and TCP/443 from 192.168.1.0 0.0.0.255 to any, then a permit ip from 192.168.2.0 0.0.0.255 to any. The ACL is applied inbound on G0/0 (the interface facing 192.168.1.0/24) because traffic from that subnet enters R1 through G0/0.

Applying it outbound on G0/0 would be incorrect, as it would only filter traffic leaving that subnet, not entering. Also, the ACL must be applied on the correct interface to avoid blocking traffic from 192.168.2.0/24, which enters via G0/1.

Exam trap

The most common trap is confusing inbound vs outbound ACL application. Remember: inbound ACL filters traffic entering the interface; outbound ACL filters traffic leaving the interface. For traffic originating from a subnet, apply the ACL inbound on the interface connected to that subnet.

Why the other options are wrong

B

The ACL is applied in the wrong direction. For traffic originating from 192.168.1.0/24, the ACL must be applied inbound on the interface where that traffic enters the router (G0/0).

C

The ACL is applied on the wrong interface. The interface facing the restricted subnet (192.168.1.0/24) is G0/0, not G0/1.

D

The ACL should only be applied on the interface where the restricted subnet traffic enters (G0/0). Applying it on G0/1 is redundant and could inadvertently filter traffic from 192.168.2.0/24 if the ACL is modified later.

Why candidates pick the wrong answer

B

Candidates often confuse inbound vs outbound ACL application. They might think 'outbound' filters traffic going out to the internet, but the direction is relative to the interface, not the destination.

C

Candidates might mistakenly think that because the ACL permits all traffic from 192.168.2.0/24, it should be applied on that interface. However, the ACL must be applied on the interface where the traffic to be filtered enters.

D

Candidates might think that since the ACL permits traffic from both subnets, it should be applied on both interfaces to be thorough. However, the ACL is designed to restrict traffic from 192.168.1.0/24, so it only needs to be applied where that traffic enters.

547
MCQhard

A network administrator is troubleshooting connectivity loss in a switched network. All switches run Rapid PVST+. A host connected to an access port on SwitchC can no longer reach the default gateway. The access port is configured with PortFast and BPDU Guard. The administrator checks the interface status and finds it in an err-disabled state. What is the most likely cause of this issue?

A.The root bridge election failed, causing a loop.
B.BPDU Guard detected a BPDU on a PortFast-enabled port and disabled it.
C.Rapid PVST+ is not compatible with PortFast.
D.The port is configured as a trunk but should be an access port.
AnswerB

BPDU Guard is a security feature that monitors PortFast-enabled ports for incoming BPDUs. When a BPDU is received, it immediately transitions the port to err-disabled state to prevent a potential switching loop, as a valid access port should never receive BPDUs. This exactly matches the symptom: Gi0/1 is down/err-disabled after BPDU Guard was enabled. The port will remain disabled until manually re-enabled or errdisable recovery is configured.

Why this answer

B is correct because BPDU Guard is designed to protect the spanning-tree topology by disabling a PortFast-enabled port if it receives a BPDU, placing the port in err-disabled state. Option A is incorrect: a root bridge election failure would not cause a port to err-disable; loops do not directly trigger this state without BPDU Guard. Option C is incorrect because PortFast and BPDU Guard work with all spanning-tree variants including Rapid PVST+.

Option D is incorrect: a trunk misconfiguration alone would not cause err-disable unless BPDU Guard detects a BPDU on a PortFast port.

Exam trap

Cisco often tests the misconception that PortFast and BPDU Guard are incompatible with Rapid PVST+, but in reality, PortFast is a port-level feature that works identically across all spanning-tree variants, and BPDU Guard is the mechanism that causes the err-disabled state when a BPDU is received.

Why the other options are wrong

A

A root bridge election failure would not place the port in err-disabled state; it would cause loops but not trigger BPDU Guard directly.

C

PortFast and BPDU Guard are fully compatible with Rapid PVST+; this option implies incompatibility, which is incorrect.

D

A trunk misconfiguration alone would not cause the port to go err-disable unless a BPDU is received on a PortFast-enabled port, and BPDU Guard is the specific mechanism for that.

Why candidates pick the wrong answer

A

Students may associate connectivity loss with root bridge issues or loops, but the err-disabled state specifically points to a port security feature like BPDU Guard.

C

Some might think that Rapid PVST+ requires BPDUs on all ports, but PortFast is a standard feature that bypasses the listening/learning states and works with any spanning-tree mode.

D

Students might confuse access port configuration with trunk issues, especially if they think the default gateway is on a different VLAN. However, the err-disabled state is directly caused by BPDU Guard.

548
MCQmedium

Exhibit: R1 has a static default route to 192.0.2.2 and also learns a default route from OSPF. Which default route is installed in the routing table?

A.The OSPF default route because dynamic routes are preferred
B.The static default route because its administrative distance is lower
C.Both default routes because they have the same prefix length
D.Neither route until a floating static route is configured
AnswerB

Although both routes share the same /0 prefix, the static default route is installed because its administrative distance of 1 is far lower than OSPF's 110. The Cisco routing table uses AD to break ties between routes to the same destination learned from different protocols, and the lower the AD, the more trustworthy the source. Therefore, the static default route is selected and placed in the routing table, while the OSPF default route is not installed unless the static route fails.

Why this answer

When two routes to the same prefix are learned from different sources, the router compares administrative distance first. A static route has AD 1 by default, while OSPF has AD 110, so the static default route wins unless its AD was changed manually.

Exam trap

A common exam trap is believing that OSPF default routes always override static default routes because dynamic routing protocols are 'more intelligent' or 'preferred.' This misconception leads to selecting the OSPF route as installed, ignoring the fundamental Cisco routing rule that administrative distance determines route preference. Since static routes have a default AD of 1 and OSPF routes have an AD of 110, the static route is preferred unless its AD is manually changed. Misunderstanding this can cause incorrect answers and confusion about route installation behavior.

Why the other options are wrong

A

This option is incorrect because dynamic routes like OSPF are not automatically preferred over static routes. Administrative distance determines preference, and static routes have a lower AD than OSPF by default.

C

This option is incorrect because having the same prefix length does not mean both routes are installed. The router uses administrative distance to choose a single best route.

D

This option is incorrect because a normal static default route is valid and installed immediately. A floating static route is only needed if you want a backup route with a higher AD.

When would these options actually be correct?

A

In a different scenario where the static route has a higher administrative distance than the OSPF default route, such as if the static route was configured with an AD of 200, then the OSPF default route would be installed in the routing table instead of the static one.

C

In a different scenario where the question states that both routes are being used for load balancing and the router is configured to support multiple equal-cost routes, this option could be correct, allowing both default routes to be installed in the routing table.

D

In a different scenario where the static route has a higher administrative distance than the OSPF route, and there is a configuration that prevents the static route from being installed until a floating static route is defined, this option would be correct. For example, if the static route's administrative distance was set to a higher value than OSPF's.

Why candidates pick the wrong answer

A

Students may think that dynamically learned routes are more trustworthy because they reflect current network topology, but static routes have a lower AD by design.

C

Students often confuse the rule that equal prefix length allows load balancing with the rule that AD is the primary tiebreaker; they may think equal prefix length means both routes are installed.

D

The term 'floating static route' is often misunderstood; students may think that all static routes require special configuration to be installed, but only those with higher AD than the dynamic route are considered floating.

549
MCQmedium

You are configuring a Cisco router that connects to an ISP through two different providers. The primary path is learned dynamically through OSPF, and the backup path is a static route pointing to a next-hop of 203.0.113.1. You need the static route to remain in the routing table only when the OSPF-learned default route is unavailable. Which configuration should you apply?

A.ip route 0.0.0.0 0.0.0.0 203.0.113.1 110
B.ip route 0.0.0.0 0.0.0.0 203.0.113.1 90
C.ip route 0.0.0.0 0.0.0.0 203.0.113.1 permanent
D.ip route 0.0.0.0 0.0.0.0 203.0.113.1 250
AnswerD

Assigning an administrative distance of 250 to the static default route makes it less preferred than the OSPF-learned default route, which has a default administrative distance of 110. The static route is installed in the routing table only when the OSPF route is removed, providing the required floating backup behavior.

Why this answer

A floating static route is created by configuring a static route with an administrative distance higher than that of the dynamic routing protocol providing the primary route. OSPF's default administrative distance is 110, so a static route with a distance of 250 will not be installed while the OSPF route exists. When OSPF loses the route, the static route becomes active and provides backup connectivity.

Exam trap

The trap here is assuming that any static route automatically acts as a backup without adjusting its administrative distance above the dynamic protocol's distance.

550
MCQhard

A router has the following routes in its routing table: a static route to 10.1.1.0/24 with administrative distance 1, an OSPF route to 10.1.1.0/24 with administrative distance 110, and an EIGRP route to 10.1.1.0/24 with administrative distance 90. A packet arrives destined for 10.1.1.50. Which route will the router use to forward the packet?

A.The static route
B.The EIGRP route
C.The OSPF route
D.The router will load-balance between all three routes
AnswerA

The static route has an administrative distance of 1, which is lower than both OSPF (110) and EIGRP (90). When multiple routes to the same destination exist from different sources, the router prefers the route with the lowest administrative distance. Therefore, the static route is installed in the routing table and used to forward the packet.

Why this answer

Administrative distance is used to select the best route when multiple routing sources provide a route to the same destination. The static route has the lowest administrative distance (1), so it is preferred over EIGRP (90) and OSPF (110). The packet will be forwarded using the static route.

Exam trap

The trap here is assuming that the dynamic routing protocol with the lowest administrative distance among dynamic protocols is chosen, forgetting that a static route has an even lower distance.

551
PBQhard

You are connected to R1. Configure HSRP so that R1 becomes the active router for VLAN 10, with a virtual IP of 192.168.10.1. Ensure that R1 preempts if it comes back online after a failure. Also, configure R1 to decrement its HSRP priority by 20 if its GigabitEthernet0/1 interface goes down. The current configuration shows both routers as active — identify and fix the issues.

Network Topology
Gi0/0.10192.168.10.3/24Gi0/0.10192.168.10.2/24switchR1R2

Hints

  • •Both routers show Active because they have equal priority and no preempt.
  • •The virtual IP configured is 192.168.10.254 but the task requires 192.168.10.1.
  • •To ensure R1 is active, set its priority higher than R2's default (100) and enable preempt.
A.Change the virtual IP to 192.168.10.1, set priority to 110, enable preempt, and track interface GigabitEthernet0/1 with decrement 20.
B.Change the virtual IP to 192.168.10.1, set priority to 100, enable preempt, and track interface GigabitEthernet0/1 with decrement 20.
C.Change the virtual IP to 192.168.10.254, set priority to 110, enable preempt, and track interface GigabitEthernet0/1 with decrement 20.
D.Change the virtual IP to 192.168.10.1, set priority to 110, enable preempt, but do not track any interface.
AnswerA
solution
! R1
interface GigabitEthernet0/0.10
standby 10 ip 192.168.10.1
standby 10 priority 110
standby 10 preempt
standby 10 track GigabitEthernet0/1 20

Why this answer

The scenario indicates both routers appear as Active, which is abnormal. This could result from a misconfigured virtual IP or group number mismatch. The required fix is to set the virtual IP to 192.168.10.1, assign R1 a higher priority (110 vs R2's default 100), enable preempt so R1 reclaims active role after failure, and track GigabitEthernet0/1 with a decrement of 20 to lower priority if that interface goes down.

Exam trap

Watch for three common mistakes: (1) forgetting to set a higher priority to win the election, (2) using the wrong virtual IP address, and (3) omitting the track command when required. Also note that preempt alone does not guarantee active status if priorities are equal.

Why the other options are wrong

B

HSRP election uses priority as the primary tie-breaker; equal priority leads to comparison of primary IP addresses, which may not favor R1.

C

The virtual IP address must be consistent across all HSRP routers and match the configured gateway; a mismatch prevents proper operation.

D

Without tracking, R1's priority remains unchanged even if the uplink fails, so R1 would remain active despite losing connectivity, causing traffic black-holing.

Why candidates pick the wrong answer

B

Candidates may think preempt alone is sufficient to make R1 active, but preempt only triggers re-election after a failure; it does not guarantee R1 wins if priorities are equal.

C

Candidates might confuse the virtual IP with the standby IP or assume any unused IP in the subnet works, but the question explicitly requires 192.168.10.1.

D

Candidates may overlook the tracking requirement or think preempt alone handles failover, but tracking is needed to lower priority and trigger a switchover when the tracked interface goes down.

552
Drag & Dropmedium

Drag and drop the following steps into the correct order to create VLANs, assign access ports, configure 802.1Q trunks, set the native VLAN, and verify with 'show vlan brief' and 'show interfaces trunk'.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

VLANs must be created before assigning ports; trunking is configured after access ports; verification is the final step.

Exam trap

Do not confuse the order of VLAN creation and port assignment. VLANs must be created before ports can be assigned to them. Also, native VLAN configuration is part of trunk configuration and should be done after trunk mode is set.

Why candidates pick the wrong answer

B

Candidates may think port assignment can be done first because they configure interfaces before VLANs in some scenarios, but VLAN creation is a prerequisite.

C

Candidates might think native VLAN is set independently of trunking, but it only applies to trunk ports.

D

Candidates may confuse the order of VLAN creation and trunk configuration, thinking trunks can be set up before VLANs exist.

553
MCQmedium

A switch displays the following output: Interface Status VLAN Gi1/0/5 connected 20 Gi1/0/6 notconnect 1 Gi1/0/24 trunk trunk Which interface is operating as an access port in VLAN 20?

A.Gi1/0/5
B.Gi1/0/6
C.Gi1/0/24
D.None of the interfaces
AnswerA

The output for Gi1/0/5 shows an interface that is up/connected and explicitly assigned to VLAN 20 as an access port, which exactly matches the requirement stated in the question. The status column indicates the link is active, and the VLAN column confirms membership in VLAN 20, leaving no doubt that this is the correct interface.

Why this answer

The output explicitly shows Gi1/0/5 in VLAN 20 and not operating as a trunk.

Exam trap

Be careful not to confuse trunk ports with access ports or assume interfaces not shown in the output are relevant.

Why the other options are wrong

B

Gi1/0/6 is an access port in VLAN 1 (the default VLAN), not VLAN 20. The question specifically asks for an interface operating as an access port in VLAN 20, so this option is incorrect.

C

Gi1/0/24 is configured as a trunk port, which carries traffic for multiple VLANs and is not an access port. Access ports belong to a single VLAN, so this option is incorrect.

D

Gi1/0/5 is clearly an access port in VLAN 20, so there is an interface that matches the description. Therefore, 'None of the interfaces' is incorrect.

When would these options actually be correct?

B

If the question asked for an interface that is not currently operational but was previously configured as an access port in VLAN 20, Gi1/0/6 could be the correct answer. This could occur in a scenario where the interface has been administratively shut down but retains its VLAN assignment.

C

If the question asked which interface is configured to allow traffic for multiple VLANs, or if it specified that Gi1/0/24 was set to access mode for VLAN 20, then this option would be correct.

D

In a different scenario where the question states that all interfaces are configured as trunk ports or are not assigned to any VLAN, then 'None of the interfaces' would be correct if no access port exists for VLAN 20.

Why candidates pick the wrong answer

B

A student might see that Gi1/0/6 is an access port (since it shows a VLAN number and not 'trunk') and assume it could be in VLAN 20, but the output clearly shows it is in VLAN 1.

C

A student might confuse the word 'trunk' in the VLAN column with being a trunk port, but the question asks for an access port, and trunk ports are not access ports.

D

A student might overlook Gi1/0/5 if they misinterpret the output or think that 'connected' status does not imply access port, but the VLAN assignment confirms it.

554
MCQmedium

A network engineer successfully logs in to a router, but cannot enter configuration mode because the command is rejected by policy. Which AAA function is controlling this behavior?

A.Authentication
B.Authorization
C.Accounting
D.Encryption
AnswerB

Authorization is the AAA component that determines which commands a successfully authenticated user is permitted to execute. Even after a valid login, the router consults authorization rules, such as privilege levels or per-command permissions from a TACACS+ or RADIUS server, to decide whether to allow a specific command. If the user lacks the required privilege or is not explicitly authorized, the command is rejected. Thus, the engineer's inability to run the command is directly due to authorization failing.

Why this answer

Authentication confirms identity. Authorization determines which commands, privilege levels, or resources that authenticated user is permitted to access.

Exam trap

A common exam trap is confusing authentication with authorization. Candidates often think that if a user cannot enter configuration mode, it means the login failed, which is incorrect. Authentication only confirms the user's identity during login.

Once authenticated, authorization controls what commands or modes the user can access. Misunderstanding this distinction leads to incorrect answers. The question states the user successfully logged in, so the failure to enter configuration mode is due to authorization restrictions, not authentication failure.

Why the other options are wrong

A

Authentication is the process of verifying a user's identity during login. Since the engineer successfully logged in, authentication has already succeeded and is not preventing command execution.

C

Accounting records user activities and commands for auditing purposes but does not grant or deny access to commands or configuration modes, so it cannot be the cause of the command rejection.

D

Encryption protects data confidentiality during transmission but does not control user access or command permissions, so it is unrelated to the inability to enter configuration mode.

When would these options actually be correct?

A

In a different question, if it asked about the process that prevents a user from logging in altogether due to incorrect credentials, then authentication would be the correct answer. For example, if a user attempts to log in with a wrong username or password, authentication would fail.

C

If the question were about monitoring user activities and resource usage on the router, such as tracking which commands were executed by users, then accounting would be the correct answer. For example, a question could ask about the function that logs user actions after they have been authenticated and authorized.

D

If the question were about securing the communication between the router and a management station, asking which AAA function ensures that the data is encrypted during transmission, then encryption would be the correct answer.

Why candidates pick the wrong answer

A

Students often confuse authentication with authorization because both are AAA components and the terms sound similar. They may think that if a command is rejected, it must be an authentication issue.

C

Test-takers might think accounting includes monitoring and controlling access because it logs events, but its function is purely record-keeping, not enforcement.

D

Encryption is often associated with secure access (e.g., SSH for login), so a student might incorrectly assume it also controls command permissions.

555
MCQhard

A network engineer notices that users on VLAN 100 are experiencing intermittent connectivity to the server farm. The switch connecting these users shows no errors on the uplink interface, but the server farm switch reports a high number of input errors on its connected interface. The engineer runs 'show controllers' on the server farm switch. What is the most likely cause of the issue?

A.The interface is configured with the wrong duplex setting.
B.The SFP module is faulty or incompatible with the cable type.
C.The cable is too long, causing attenuation.
D.Auto-negotiation is disabled, causing a speed mismatch.
AnswerB

The 'show controllers' output shows the media type as 1000BaseSX SFP with auto-negotiation off, but the interface is reporting no errors. However, the other switch sees input errors. This points to a hardware issue with the SFP, such as a faulty module or a mismatch between the SFP and the fiber cable (e.g., using a single-mode SFP with multi-mode fiber).

Why this answer

The 'show controllers' command on the server farm switch reveals physical-layer issues such as framing errors, CRC errors, or alignment errors, which are often caused by faulty or incompatible SFP modules. Since the uplink interface on the user switch shows no errors, the problem is isolated to the server farm switch's interface, and a faulty SFP can introduce signal degradation or electrical issues without necessarily causing complete link failure. Option B is correct because SFP incompatibility or defects commonly produce input errors at the physical layer, even when the link appears up.

Exam trap

Cisco often tests the distinction between 'show interfaces' (which shows input errors but not the specific physical-layer cause) and 'show controllers' (which reveals the exact physical-layer errors), leading candidates to mistakenly choose duplex mismatch or cable length issues without recognizing that the command output points to SFP or transceiver problems.

Why the other options are wrong

A

The 'show controllers' output confirms Full-duplex on both ends, so a duplex mismatch is not the cause. Duplex mismatch would typically cause collisions or CRC errors, which are not indicated here.

C

While excessive cable length can cause attenuation and errors, the 'show controllers' output does not show specific error counters like symbol errors or FCS errors that would indicate attenuation. The link is up and no errors are reported on this switch, making cable length an unlikely cause.

D

Speed is set to 1000 Mbps on both ends, and auto-negotiation is off, which is normal for fiber connections. A speed mismatch would prevent the link from coming up or cause constant errors, but the link is up and no errors are reported on this switch.

Why candidates pick the wrong answer

A

Students often associate input errors with duplex mismatch, as it is a common cause of errors on Ethernet links. However, the output clearly shows both ends are set to Full-duplex, ruling this out.

C

Cable length is a known cause of signal degradation and errors, so students might jump to this conclusion. However, the absence of related error counters and the fact that errors are only seen on one side suggest a hardware issue rather than a cable length problem.

D

Auto-negotiation is often misunderstood; students may think disabling it always causes issues. However, for fiber Gigabit Ethernet, auto-negotiation is optional and speed is typically fixed. The absence of errors on this switch indicates speed mismatch is not the problem.

556
MCQeasy

Which OSPF component is used to identify routers uniquely inside an OSPF domain?

A.Area ID
B.Router ID
C.Hello timer
D.Wildcard mask
AnswerB

The Router ID is a 32-bit value, typically derived from the highest loopback address or manually configured, that uniquely identifies an OSPF speaker within the autonomous system. It is carried in all OSPF packets and used as the originating router ID in LSAs, ensuring that each router is recognized as a distinct entity. Without a unique Router ID, OSPF neighbors could not reliably build a link-state database or exchange routing information.

Why this answer

The router ID is the unique identifier OSPF uses for each router. It is not the same thing as the process ID, which is locally significant only.

Exam trap

A frequent exam trap is mistaking the OSPF area ID for the router ID. While area IDs define logical groupings of routers within an OSPF domain, they do not uniquely identify individual routers. Another pitfall is confusing the router ID with the OSPF process ID, which is locally significant and does not uniquely identify routers.

Additionally, some candidates incorrectly select hello timers or wildcard masks, which serve different purposes such as neighbor keepalive intervals and network statement definitions, respectively. Understanding these distinctions is critical to avoid selecting incorrect options that sound related but serve different functions.

Why the other options are wrong

A

Area ID identifies OSPF areas, which are logical subdivisions within the OSPF domain, but it does not uniquely identify individual routers. Selecting area ID confuses the concept of router identification with area grouping.

C

Hello timer controls how often OSPF routers send hello packets to maintain neighbor adjacency. It does not serve as a unique identifier for routers.

D

Wildcard mask is used in OSPF network statements to specify which IP addresses belong to an OSPF area. It does not identify routers uniquely.

When would these options actually be correct?

A

If the question asked which component is used to define the structure of OSPF routing domains or how OSPF routers are organized into areas, then Area ID would be the correct answer, as it specifies the area to which routers belong.

C

In a question asking about OSPF configuration parameters, such as 'What is the default interval for sending OSPF hello packets?', the correct answer would be the Hello timer, as it directly pertains to the timing of OSPF neighbor discovery.

D

In a question asking about OSPF configuration and routing policies, such as 'What is the purpose of a wildcard mask in OSPF?' the option would be correct as it relates to defining networks and interfaces for OSPF routing.

Why candidates pick the wrong answer

A

Students may confuse Area ID with Router ID because both are numerical identifiers used in OSPF configuration, and the term 'ID' suggests uniqueness.

C

Students might think Hello timers are used for identification because they are a key part of OSPF neighbor discovery, but their purpose is timing, not identification.

D

Students may confuse wildcard masks with Router IDs because both involve IP addressing concepts, and wildcard masks are often used in OSPF configuration alongside network statements.

557
Drag & Dropmedium

Drag and drop the following troubleshooting steps into the correct order to diagnose a client connectivity issue using the OSI bottom-up method.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The OSI bottom-up method starts at physical layer and moves up. This ensures that lower-layer issues are resolved before higher-layer troubleshooting, preventing wasted effort on symptoms caused by underlying problems.

Exam trap

The exam trap is that candidates may confuse bottom-up with top-down troubleshooting or think that checking the network layer first is more efficient. Remember: bottom-up always starts at the physical layer and proceeds sequentially upward.

Why candidates pick the wrong answer

B

Candidates might confuse bottom-up with top-down troubleshooting, especially if they are more familiar with application-layer issues.

C

Candidates might think that checking the network layer first is efficient because it is often the source of connectivity issues, but this violates the bottom-up methodology.

D

Candidates might overlook the data link layer because they focus on IP (network layer) issues, but bottom-up requires checking each layer sequentially.

558
Multi-Selecthard

A network team deploys an AI-assisted operations platform that analyzes streaming telemetry from switches and routers. The team wants the platform to detect degradation before users report trouble. Which two data characteristics most directly improve the platform's ability to detect anomalies early? (Choose two.)

Select 2 answers
A.High-frequency, model-driven telemetry pushed from devices at short intervals.
B.Consistent timestamping and synchronized clocks across all monitored devices.
C.Polling each device every 30 minutes with SNMP for CPU and memory counters.
D.Storing telemetry only after manual review by a network engineer.
E.Collecting data from a single core switch to reduce pipeline complexity.
AnswersA, B

Model-driven telemetry streams structured data at short intervals, giving the analytics engine a dense time series. Dense sampling exposes subtle shifts such as rising queue drops or creeping latency well before a threshold breach, which is precisely the early-warning behavior the team wants from the AI platform.

Why this answer

Early anomaly detection depends on data that is both frequent and time-aligned. Short-interval, model-driven telemetry supplies the granular time series needed to see subtle degradation, while synchronized timestamps let the platform correlate events across devices. Coarse polling, manual gating, and single-device collection all starve the analytics engine of the density and context it needs.

Exam trap

The trap here is treating telemetry volume alone as sufficient, when synchronized timing and high sampling frequency are what actually make early correlation possible.

559
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure Rapid PVST+ with a designated root bridge, PortFast, and BPDU Guard on access ports.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Set the spanning-tree mode to Rapid PVST+: This enables Rapid PVST+ globally, a prerequisite for the root primary command to function correctly. 2. Configure the switch as the root bridge for VLAN 1: Lowers the bridge priority to guarantee this switch becomes the root, defining the STP topology. 3.

Enter interface configuration mode for the access ports: Prepares the specific ports where PortFast and BPDU Guard are applied. 4. Enable PortFast on the interfaces: Allows immediate transition to forwarding state, bypassing listening/learning phases. 5. Enable BPDU Guard on the interfaces: Protects the network by err-disabling the port if a BPDU is received, which should occur only after PortFast is enabled on access ports.

560
Multi-Selecthard

A trunk link between two switches is up, but hosts in VLAN 30 on opposite switches cannot communicate. VLAN 10 works across the same trunk. Which two causes are the most likely?

Select 2 answers
A.VLAN 30 is not allowed on the trunk on one side
B.VLAN 30 may not exist in the VLAN database on the affected switch
C.The trunk native VLAN should always be 30
D.PortFast must be disabled on the access ports in VLAN 30
AnswersA, B

A trunk port has an allowed VLAN list, and both ends must include VLAN 30 in that list for its traffic to cross the link. If one switch's trunk configuration omits VLAN 30 (via the allowed vlan command), the trunk remains up and carries other VLANs, but frames tagged with VLAN 30 are discarded at that port. This mismatch is a frequent cause of a single VLAN failing while the trunk itself appears operational.

Why this answer

When one VLAN fails but others work across the same trunk, the problem is likely VLAN-specific. VLAN 30 may not exist on one switch or may not be allowed on the trunk. Option C is incorrect because the native VLAN does not need to be 30; a native VLAN mismatch would typically cause connectivity issues on all VLANs, not just VLAN 30.

Option D is incorrect because PortFast only affects the speed at which an access port enters the forwarding state and does not impact communication across an already-up trunk.

Exam trap

Don't assume trunk issues affect all VLANs equally; check for VLAN-specific settings.

Why the other options are wrong

C

The native VLAN ID is not required to match the VLAN that is having connectivity issues; native VLAN is used for untagged traffic on the trunk and does not affect communication for specific VLANs like VLAN 30.

D

PortFast is used on access ports to speed up the transition to forwarding state and is unrelated to inter-VLAN communication across a trunk. Disabling PortFast would not resolve connectivity issues for VLAN 30 hosts on different switches.

When would these options actually be correct?

C

This option would be correct if the question stated that hosts in VLAN 30 cannot communicate because the native VLAN mismatch on the trunk is causing the trunk to be down or not forwarding traffic for any VLAN.

D

In a scenario where a host in VLAN 30 cannot get an IP address via DHCP and the issue is that PortFast is not enabled on the access port, causing spanning-tree delays that prevent DHCP from working. The question would specify that other VLANs work and the trunk is fine.

Why candidates pick the wrong answer

C

Candidates may confuse the native VLAN with the VLAN that is having problems, or think that setting the native VLAN to the problematic VLAN ID is a troubleshooting step.

D

Candidates may confuse PortFast with features that affect VLAN connectivity, or think that disabling PortFast could fix issues related to VLAN propagation or trunking, due to a misunderstanding of spanning-tree operations.

561
Multi-Selecthard

A network engineer is deploying a new access layer switch stack in a building. The design requires that the switches share a single management IP address, that a failed stack member does not take down the entire stack, and that the stack operates with the highest available throughput between members. Which two statements about Cisco StackWise technology support these requirements? (Choose two.)

Select 2 answers
A.StackWise requires all members to run different IOS versions to provide redundancy.
B.StackWise uses a ring topology with redundant paths so that a single member or cable failure does not break the stack.
C.StackWise creates a single logical switch with one management IP address and a unified configuration.
D.StackWise provides a single management IP only when the stack is configured as a VSS pair.
E.StackWise member switches must be connected only through their uplink ports to form the stack ring.
AnswersB, C

StackWise cables form a ring, providing redundant paths between members. If one cable or member fails, traffic can traverse the remaining path, which supports the requirement that a failed member does not bring down the whole stack. This resiliency is a core benefit of the ring topology used by StackWise.

Why this answer

StackWise presents multiple switches as one logical device with a single management IP and shared configuration, and its ring cabling provides redundant paths so one failed member or cable does not break the stack. These two properties directly address the requirements for simplified management and resiliency in the access layer deployment.

Exam trap

The trap here is mixing StackWise with VSS or assuming stacking uses ordinary uplink ports, when StackWise relies on dedicated stacking cables and its own master election.

562
Matchingmedium

Drag and drop the items on the left to match the descriptions on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Enables a port as an 802.1Q trunk port

The VLAN that carries untagged frames on a trunk link

Open standard for VLAN tagging on Ethernet frames

Process of forwarding traffic between different VLANs

Displays a summary of VLANs and their assigned ports

Why these pairings

VLANs segment a switch into multiple broadcast domains. 802.1Q trunking encapsulates frames with a VLAN tag, while the native VLAN carries untagged traffic. 'switchport mode trunk' configures a trunk port, 'show vlan brief' lists VLAN assignments, and inter-VLAN routing enables communication between VLANs typically using a router or Layer 3 switch.

563
MCQhard

A switch port is configured with `switchport voice vlan 150` and `switchport access vlan 20`. Which statement best explains the design purpose?

A.It separates voice and data traffic on the same edge port by assigning them to different VLANs.
B.It turns the port into a routed WAN interface.
C.It forces the phone to use CAPWAP before receiving power.
D.It makes VLAN 150 the native VLAN on all trunks automatically.
AnswerA

The `switchport voice vlan 150` command marks the port as a Cisco Unified Communications access port, so it instructs an attached IP phone to tag its voice frames with VLAN 150 while the PC behind the phone remains untagged on the data VLAN. As a result, voice and data traffic share the same physical cable but are isolated into separate Layer 2 broadcast domains, allowing distinct QoS policies, subnets, and security controls to be applied independently.

Why this answer

The design purpose is to let the switch support a phone and an attached workstation on the same physical access port while placing their traffic into different VLANs. In practical terms, the phone can use the voice VLAN while the user's data traffic uses the access VLAN. This is a common enterprise edge design for IP telephony.

The key idea is role separation on one port, not trunking the port as a normal inter-switch link.

Exam trap

Avoid confusing voice VLAN configurations with trunking or prioritization settings.

Why the other options are wrong

B

The commands `switchport voice vlan 150` and `switchport access vlan 20` are used on a Layer 2 switch port, not a routed interface. A routed WAN interface would require `no switchport` and an IP address configuration, which is not present here.

C

CAPWAP (Control and Provisioning of Wireless Access Points) is a protocol used for wireless LAN controller and access point communication, not for voice VLAN configuration. The voice VLAN feature is unrelated to CAPWAP.

D

The `switchport voice vlan` command only affects the specific access port where it is configured, not all trunk ports. The native VLAN on trunks is configured separately with `switchport trunk native vlan`.

When would these options actually be correct?

B

In a different scenario, a question might ask about the configuration of a switch port in a router-on-a-stick setup, where the context involves routing between VLANs. In that case, a response indicating that the port is configured as a routed WAN interface could be correct if it explicitly states that the port is configured for inter-VLAN routing.

C

If the question were about the configuration of a wireless access point that requires a specific protocol for power delivery and management, such as CAPWAP, then this option could be correct. For example, a question might ask about the setup of a VoIP phone connected to a wireless network that utilizes CAPWAP for device management.

D

In a different question, if it asked about the behavior of a switch when configuring a trunk port with 'switchport trunk native vlan 150', this option would be correct as it would indicate that VLAN 150 is set as the native VLAN for all trunk links.

Why candidates pick the wrong answer

B

Students might confuse the term 'voice VLAN' with a WAN interface because both involve voice traffic, but the commands clearly indicate a switchport configuration, not a routed port.

C

The acronym 'CAPWAP' might be associated with Cisco's voice or wireless technologies, leading students to incorrectly link it to IP phone configuration.

D

Students may think that setting a voice VLAN on an access port automatically propagates to trunks, confusing the scope of the command with global or trunk-specific settings.

564
MCQhard

Inside hosts can reach the internet only one at a time. What is the most likely NAT issue?

A.The NAT statement is missing the overload keyword
B.The access list should deny the inside subnet
C.The inside and outside interface roles are reversed in the exhibit
D.NAT cannot be used with RFC1918 addresses
AnswerA

The NAT configuration lacks the overload keyword, which enables Port Address Translation (PAT). Without overload, the router performs one-to-one dynamic NAT, mapping each inside host to a unique public IP address. If only one public IPv4 address is available, only one host can be translated at a time, producing the one-at-a-time connectivity behavior described. Adding overload lets many inside hosts share that single public address by multiplexing on source port.

Why this answer

Without overload, dynamic NAT uses one public address per internal session mapping. PAT with overload is what lets many inside hosts share a single outside interface address at the same time.

Exam trap

A frequent exam trap is assuming that reversing the inside and outside interface roles causes the symptom of only one host accessing the internet at a time. While interface roles are critical for NAT operation, reversing them typically prevents translation altogether rather than limiting it to a single host. Another trap is thinking that the ACL should deny the inside subnet to fix the issue, but denying the inside subnet in the ACL stops all translations, causing no internet access.

The real cause is missing the overload keyword, which is essential for PAT to allow multiple hosts to share one public IP simultaneously.

Why the other options are wrong

B

Denying the inside subnet in the ACL would prevent any NAT translation from occurring, which would block all inside hosts from reaching the internet, not just limit access to one at a time.

C

Reversing inside and outside interface roles typically stops NAT from functioning entirely rather than allowing only one host at a time. The symptom points more directly to missing overload.

D

NAT is specifically designed to translate RFC1918 private IP addresses to public IP addresses. Saying NAT cannot be used with RFC1918 addresses is incorrect and contradicts common practice.

When would these options actually be correct?

B

In a different scenario where the question states that internal hosts should not be allowed to access the internet at all, an access list denying the inside subnet would be the correct answer. This would be relevant in a security-focused question where restricting access is the goal.

C

In a different scenario, if a question presented a network diagram where the interfaces were explicitly labeled as inside and outside but were incorrectly configured in the NAT settings, then this option could be correct. For example, if the NAT configuration was applied to the outside interface instead of the inside, it would cause NAT to fail.

D

In a different exam scenario where the question specifies that NAT is being configured for public IP addresses only, and the context indicates that the use of private addresses is not allowed, this option could be correct. For example, if the question states that only public IPs are permitted for NAT, then option D would be valid.

Why candidates pick the wrong answer

B

A student might think that the access list controls which hosts can use NAT, and incorrectly assume that denying the subnet would limit access to one host at a time. However, the symptom of 'one at a time' is classic for missing overload, not access list misconfiguration.

C

Students often confuse interface roles in NAT configuration. The symptom of limited connectivity might lead them to suspect a misconfiguration of inside/outside interfaces, but the 'one at a time' behavior is a hallmark of missing overload, not reversed interfaces.

D

A student might recall that RFC1918 addresses are private and not routable on the internet, and mistakenly think that NAT cannot be used with them. However, NAT is the solution that allows these addresses to communicate with the internet.

565
MCQhard

Two static routes exist for the 203.0.113.0/24 network: one pointing to ISP-A with an administrative distance of 10, and another pointing to ISP-B with an administrative distance of 5. Packets for that subnet are leaving through ISP-B. What explains this behavior?

A.The ISP-B route has a lower administrative distance.
B.Static routes with a higher next-hop IP are preferred.
C.The router always prefers the route configured last.
D.The route names force policy-based routing.
AnswerA

Cisco routers select the best route by administrative distance first for identical prefixes. The ISP-B static route has AD 5 while ISP-A has AD 10, so ISP-B is deemed more trustworthy and wins, causing packets to bypass the intended ISP-A link. This precedence overrides any other preferences like configuration order or next-hop address.

Why this answer

The route via ISP-B has a lower administrative distance, so it wins for the identical /24 prefix. For routes to the same destination and mask, the router compares AD before considering anything else between different route sources.

Exam trap

A frequent exam trap is assuming that the next-hop IP address or the order in which static routes are configured affects route selection. Candidates might incorrectly believe that a higher next-hop IP or the last configured route is preferred, but Cisco routers do not use these factors in route preference. Another common mistake is thinking that route names or descriptions influence routing decisions or enforce policy-based routing, which they do not.

The key is to remember that administrative distance is the primary factor in route selection when multiple routes to the same prefix exist.

Why the other options are wrong

B

This option is incorrect because the next-hop IP address does not influence route preference. Cisco routers do not consider the numeric value of the next-hop IP when selecting routes.

C

This option is incorrect because the router does not prefer routes based on the order they were configured. Route selection depends on administrative distance and metrics, not configuration sequence.

D

This option is incorrect because route names or descriptions are only for human readability and do not enforce policy-based routing. Policy-based routing requires explicit configuration beyond naming.

When would these options actually be correct?

B

In a different scenario where a question states that a router has multiple static routes to the same destination with different next-hop IPs, and the exam asks which route would be preferred, this option could be correct if the context specifies that the next-hop IP is a determining factor in the selection process.

C

In a different scenario where a router is configured to prefer the most recently added static route over existing routes with the same administrative distance, a question could ask about the behavior of routes when multiple static routes exist. In this case, the last configured route would indeed be preferred.

D

In a different scenario where a question specifies that routes are being selected based on named policies or configurations that directly influence routing decisions, such as in a policy-based routing setup, this option could be correct.

Why candidates pick the wrong answer

B

Students might mistakenly think that higher IP addresses are preferred due to some ordering or because of a misunderstanding of how routers compare routes, but IP address values are irrelevant to route preference.

C

Some students might confuse the order of operations in routing tables or think that the last configured route overwrites previous ones, but routing decisions are based on metrics and AD, not configuration sequence.

D

Students might assume that route names have functional significance, similar to how interface names or ACL names can be used in policy, but route names are only for administrative identification.

566
Matchingmedium

Match each access-control term to its most accurate meaning.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Verification of identity

Determination of allowed actions

Limiting access to only what is necessary

Credential store maintained on the device itself

Why these pairings

AAA is a framework for controlling access. Authentication verifies identity, authorization grants permissions, and accounting logs activities. Identification is the initial claim, and auditing is the review of logs.

Exam trap

The exam often tests the distinction between authentication (verifying identity) and authorization (granting permissions). Many candidates mix these up. Also, remember that accounting is about logging, not access decisions.

When would these options actually be correct?

B

If the question were 'Match each access-control term to its most accurate meaning' and the option was paired with a definition like 'The process of determining what resources a user can access', then Authorization would be correct. Alternatively, if the question asked for the term that means 'verifying identity', then this option would be correct if labeled as Authentication.

C

In a question asking 'Which AAA component tracks user actions and resource usage?', Accounting would be correct as it involves logging and auditing.

D

In a question asking 'Which term describes the process of a user claiming an identity, such as providing a username?', Identification would be the correct answer.

Why candidates pick the wrong answer

B

Candidates often confuse Authentication and Authorization because both terms are related to access control and start with 'A'. They may memorize definitions without distinguishing the subtle difference between verifying identity (Authentication) and granting permissions (Authorization).

C

Candidates often confuse the terms 'accounting' and 'authorization' because both are part of AAA and involve access control, leading to misassignment of their definitions.

D

Candidates may confuse identification with accounting because both involve user-related actions, but identification is about stating who you are, while accounting tracks what you did.

567
Drag & Drophard

Drag and drop the following steps into the correct order to configure a Cisco IOS-XE router as a DHCP server for a local subnet and enable a DHCP relay agent on a different interface to forward client requests to that server.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The DHCP server must be configured first on the local subnet, then the relay agent on the remote interface to forward requests; verification ensures both server and relay function correctly.

Exam trap

Do not confuse the order of configuration: the DHCP server must be configured first, then the relay agent. Verification should be performed after both are configured to test end-to-end functionality.

Why candidates pick the wrong answer

B

Candidates might think the relay agent should be configured first to prepare the path, but the server must be ready to respond.

C

Candidates might believe in incremental verification, but the final verification should encompass both components.

D

Candidates might think the relay agent should be set up first to handle traffic, but the server must exist first.

568
PBQhard

You are connected to SW1. The network has experienced a spanning-tree topology change, and the new root bridge is not the intended core switch. Configure SW1 with a root primary priority, enable PortFast and BPDU Guard on interface GigabitEthernet0/3 (an edge port connected to a server), and verify that a specific port in the topology is blocking. Then, after a BPDU violation occurs on G0/3, recover the interface from err-disable state without reloading the switch.

Network Topology
G0/0G0/0G0/1G0/0G0/2G0/0G0/3SW1SW2SW3SW4Server

Hints

  • •Use 'spanning-tree vlan 1 root primary' to set priority to 24576.
  • •PortFast and BPDU Guard are configured under the interface.
  • •To recover from err-disable, you can use 'shutdown' and 'no shutdown' on the interface.
A.spanning-tree vlan 1 root primary; interface GigabitEthernet0/3; spanning-tree portfast; spanning-tree bpduguard enable; interface GigabitEthernet0/3; shutdown; no shutdown
B.spanning-tree vlan 1 priority 4096; interface GigabitEthernet0/3; spanning-tree portfast; spanning-tree bpduguard enable; interface GigabitEthernet0/3; errdisable recovery cause bpduguard
C.spanning-tree vlan 1 root secondary; interface GigabitEthernet0/3; spanning-tree portfast; spanning-tree bpduguard enable; interface GigabitEthernet0/3; no shutdown
D.spanning-tree vlan 1 root primary; interface GigabitEthernet0/3; spanning-tree portfast; spanning-tree bpdufilter enable; interface GigabitEthernet0/3; shutdown; no shutdown
AnswerA
solution
! SW1
configure terminal
spanning-tree vlan 1 root primary
interface GigabitEthernet0/3
spanning-tree portfast
spanning-tree bpduguard enable
end
configure terminal
interface GigabitEthernet0/3
shutdown
no shutdown
end

Why this answer

The current root bridge has priority 32769, but the intended root should be SW1 with a lower priority. First, configure SW1 as root primary using 'spanning-tree vlan 1 root primary' or manually set priority to 24576. For edge port Gi0/3, enable PortFast with 'spanning-tree portfast' and BPDU Guard with 'spanning-tree bpduguard enable'.

After the BPDU violation, the port is err-disabled. To recover, first shut down and then no shut the interface, or use 'errdisable recovery cause bpduguard' and wait for the recovery interval, but the most direct method is to manually bounce the interface.

Exam trap

Watch out for confusing root primary vs root secondary, BPDU Guard vs BPDU filter, and the correct method to recover an err-disabled port. Manual shutdown/no shutdown is immediate, while errdisable recovery relies on a timer.

Why the other options are wrong

B

The priority value 4096 is not used by the root primary command; it sets priority to 24576. Additionally, errdisable recovery does not immediately recover the port; it requires a timer.

C

Root secondary makes the switch a secondary root, not primary. An err-disabled port requires a shutdown before no shutdown to clear the error state.

D

BPDU filter does not trigger err-disable on BPDU reception; it silently drops BPDUs. BPDU Guard is needed to protect edge ports.

Why candidates pick the wrong answer

B

Candidates may think any low priority works and that errdisable recovery is the only way to recover, but manual shutdown/no shutdown is faster and more direct.

C

Candidates might confuse root secondary with root primary, and think no shutdown alone can recover an err-disabled port, but the port must be cycled.

D

Candidates may confuse BPDU filter with BPDU Guard, as both are related to BPDU handling on PortFast ports, but they serve different purposes.

569
Matchingmedium

Match each Layer 2 protection feature to its most accurate purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Limits and controls MAC address use on a switch port

Disables an edge port if a BPDU is received

Helps block rogue DHCP activity and build trusted bindings

Validates ARP traffic using trusted information

Why these pairings

Storm Control limits excessive traffic. Port Security limits MAC addresses. DHCP Snooping blocks unauthorized DHCP servers.

DAI validates ARP packets. IP Source Guard filters IP traffic based on DHCP snooping. 802.1X authenticates devices before granting access.

When would these options actually be correct?

B

If the question asked 'Which feature authenticates devices before granting network access?' or 'Match each security feature to its purpose: 802.1X — Authenticates devices before granting network access.'

C

In a question asking 'Which feature validates ARP packets to prevent ARP spoofing attacks?', the correct answer would be Dynamic ARP Inspection (DAI), not Storm Control.

D

In a question asking 'Match each security feature to its purpose,' where the options include 'DHCP Snooping: Filters IP traffic based on DHCP snooping bindings' and 'Storm Control: Limits excessive traffic,' this option would be wrong. However, if the question were 'Which feature filters IP traffic based on DHCP snooping bindings?' the correct answer would be 'IP Source Guard,' not Storm Control.

Why candidates pick the wrong answer

B

Candidates may confuse storm control with other security features like port security or 802.1X, assuming all Layer 2 protections involve authentication.

C

Candidates may confuse Storm Control with security features like DAI because both deal with controlling traffic, but they serve different purposes.

D

Candidates may confuse Storm Control with other security features like DHCP Snooping or IP Source Guard, especially when they all deal with traffic filtering and storm prevention concepts.

570
Multi-Selecteasy

Which two statements correctly describe syslog severity levels?

Select 2 answers
A.Level 0 is the most severe
B.Level 7 is debugging
C.Higher numbers always mean more critical issues
D.Severity levels are used only by NTP
E.Syslog has only four severity levels
AnswersA, B

Severity level 0 is 'emergency' and is indeed the most severe, indicating that the system is unusable and requires immediate attention. It is assigned the highest priority, meaning any message with this level should be processed and reported before all others. The severity scale decreases numerically as urgency increases, so 0 outranks 1 ('alert'), 2 ('critical'), and every other level up to 7.

Why this answer

Syslog uses numbered severity levels where lower numbers indicate more critical events. Level 0 (Emergency) is the most severe, and Level 7 (Debugging) is the least. Option D is incorrect because severity levels are a syslog function, not specific to NTP.

Option E is wrong because syslog defines eight severity levels (0–7), not four.

Exam trap

A common mistake is assuming that higher syslog severity numbers mean more critical issues, but the opposite is true—lower numbers indicate higher severity.

Why the other options are wrong

D

Severity levels are a fundamental part of the syslog protocol and are not limited to or used only by NTP.

E

Syslog defines eight severity levels (0 through 7), not four.

When would these options actually be correct?

C

This option would be correct if the question described a different logging system where severity increases with number, such as some custom logging frameworks or Windows Event Viewer where higher levels indicate more critical events.

D

If the question asked 'Which protocol uses syslog severity levels exclusively for its own logging?' then D would be correct, as NTP does utilize syslog for its event logging.

E

This option would be correct if the question asked about syslog facility codes or another protocol with only four severity levels, such as SNMP traps (which have 0–3).

Why candidates pick the wrong answer

C

Candidates may intuitively think that higher numbers represent greater severity, similar to scales like earthquake magnitude or test scores, without knowing that syslog reverses this convention.

D

Candidates may associate syslog with NTP because NTP is a common protocol that generates syslog messages, leading to the mistaken belief that severity levels are NTP-specific.

E

Candidates may confuse syslog severity levels with other logging systems that have fewer levels, or they might misremember the number of levels due to common oversimplifications in study materials.

571
MCQhard

Refer to the exhibit. A network administrator notices that newly connected devices on the 192.168.1.0/24 subnet are failing to obtain IP addresses via DHCP and are instead assigning themselves APIPA addresses. The administrator issues the show ip dhcp pool command on the router and receives the output shown. What is the most likely cause of this issue?

A.DHCP snooping is blocking DHCP Offer messages on the VLAN.
B.The DHCP pool has an address conflict, causing all addresses to be marked as ineligible.
C.The lease time is set to 7 days, causing old devices to hold IP addresses long after disconnecting.
D.The pool's subnet mask is incorrectly configured as /24 instead of /25, limiting available addresses.
AnswerC

The lease time is set to 7 days, and this long lease duration is why the pool remains exhausted even if some of the 253 bound clients have disconnected. DHCP does not reclaim an address when a client goes offline; it only frees the address when the lease expires or the client explicitly releases it. With a 7-day lease, any device that disconnects ahead of expiration still holds its IP address for up to a full week, starving new clients that request an address during that window. This matches the exhibit: 254 total addresses, 253 currently bound, and a 'Lease expiration' of 7 days.

Why this answer

A 7-day lease time means that IP addresses assigned to devices are held for a full week, even after those devices disconnect from the network. If the subnet is small (e.g., 192.168.1.0/24 provides 254 usable addresses) and many devices have come and gone, the DHCP pool can become exhausted, leaving no available addresses for new devices. When DHCP fails, clients fall back to APIPA (169.254.x.x) addresses per RFC 3927.

Exam trap

Cisco often tests the concept that a long lease time can exhaust a DHCP pool even if the subnet is large, tricking candidates into thinking the issue is a subnet mask mismatch or a security feature like DHCP snooping.

Why the other options are wrong

A

Candidates often prematurely blame security features when DHCP fails, ignoring the pool statistics right in front of them.

B

A common mistake is assuming that conflicts always fill up a pool, but the zero value directly disproves this.

D

Misunderstanding subnet sizing often leads candidates to blame the mask, but the exhibit confirms the mask is appropriate for the pool size.

572
MCQmedium

In a controller-based network architecture, what is a southbound API typically used for?

A.To communicate from the controller to network devices
B.To provide dashboards to end users in a browser
C.To translate DNS names into IP addresses
D.To synchronize switch clocks with NTP
AnswerA

Southbound APIs such as NETCONF, RESTCONF, and OpenFlow provide the control channel from the SDN controller down to routers and switches. They enable the controller to program forwarding tables, apply QoS policies, and gather operational telemetry from the infrastructure layer. This directionality is the defining characteristic of a southbound interface.

Why this answer

Southbound APIs are used by the controller to communicate with and program network devices or the infrastructure below it.

Exam trap

A frequent exam trap is mistaking southbound APIs for functions unrelated to device management, such as providing user dashboards (option B), translating DNS names (option C), or synchronizing clocks with NTP (option D). These options describe roles outside the scope of southbound APIs. Southbound APIs specifically enable the controller to communicate with and program network devices, not to serve end-user interfaces or perform network services like DNS or time synchronization.

Confusing these roles can lead to selecting incorrect answers, as the exam expects precise understanding of the controller’s interaction layers.

Why the other options are wrong

B

Incorrect. Providing dashboards to end users is a function related to northbound APIs or management applications, not southbound APIs that interface with network devices.

C

Incorrect. DNS name resolution is unrelated to southbound APIs, which focus on device communication and management rather than network services like DNS.

D

Incorrect. Synchronizing switch clocks with NTP is a network service function independent of southbound APIs, which do not handle time synchronization tasks.

When would these options actually be correct?

B

If the question were to ask about the purpose of a user interface in a network management system, or specifically about how network monitoring tools present data to users, then option B could be correct as it would relate to the functionality of dashboards.

C

If the exam question asked about the functions of a network service that resolves domain names, or if it specified a scenario involving DNS management in a network architecture, then option C could be correct.

D

If the exam question asked about the functions of network management protocols or time synchronization methods in a network environment, then option D could be correct, as it would pertain to how devices maintain accurate time for logging and coordination.

Why candidates pick the wrong answer

B

Students might confuse the direction of APIs, thinking that 'southbound' refers to any interface that provides output to users, similar to how a dashboard displays information. However, the correct distinction is that southbound APIs go downward to the infrastructure, while northbound APIs go upward to applications.

C

Students might associate 'API' with any network service and incorrectly think that DNS resolution could be an API function. However, DNS is a distinct protocol and not part of the controller-to-device communication channel.

D

Students might think that because NTP involves communication between a server and network devices, it could be considered a southbound API. However, NTP is a standard protocol and not an API used in software-defined networking (SDN) architectures.

573
MCQhard

Based on the exhibit, why is traffic to host 198.51.100.70 using the OSPF route instead of the static route?

A.Because the OSPF /26 route is more specific than the static /24 route.
B.Because OSPF always overrides static routing, regardless of prefix length.
C.Because the static route must have an administrative distance of 255 to be considered.
D.Because the destination 198.51.100.70 is outside both listed routes.
AnswerA

The OSPF route to 198.51.100.64/26 is chosen because it provides the longest prefix match for the destination 198.51.100.70, which falls within the .64 through .127 range. Although the static /24 route also contains this address, the /26 has more bits set in its network mask, making it more specific in the forwarding table. For traffic matching both a longer and a shorter prefix, routers always prefer the longer prefix, so the OSPF route is used.

Why this answer

The traffic uses the OSPF route because it is the more specific match. In practical terms, the router evaluates destination-prefix specificity before comparing route source preference. The static route points to a broader /24, while the OSPF entry points to a narrower /26 that still contains the destination. Because longest-prefix match comes first, the /26 route wins.

This is a good reminder that static routes do not automatically beat dynamic routes when the prefixes are different. Specificity matters first, then source preference only when the prefix length is the same.

Exam trap

A frequent exam trap is believing that static routes always take precedence over OSPF routes because static routes have a lower administrative distance. This misconception ignores the fundamental routing principle of longest-prefix match, which prioritizes the most specific subnet mask regardless of route source. Candidates may incorrectly select the static route simply because it is static, missing that the OSPF route’s /26 mask is more specific than the static /24.

This leads to incorrect answers and confusion about route selection behavior in Cisco routers.

Why the other options are wrong

B

Incorrect because OSPF does not always override static routes. Administrative distance matters only when prefix lengths are equal, and longest-prefix match takes precedence over route source.

C

Incorrect because the static route does not have an administrative distance of 255; it is valid and installed in the routing table. The issue is the static route’s broader prefix, not its administrative distance.

D

Incorrect because the destination IP 198.51.100.70 falls within both the /24 static route and the /26 OSPF route. The router chooses based on prefix specificity, not exclusion from the routes.

When would these options actually be correct?

B

In a different exam scenario where the question states that OSPF routes are configured with a higher administrative distance than static routes, this option would be correct. For example, if the static route had an administrative distance of 1 and the OSPF route had an administrative distance of 110, OSPF would not override the static route.

C

In a different scenario where the question specifies that a static route has been configured with an administrative distance of 255, the option could be correct if the question asks why the static route is not being used at all, as it would be ignored due to its unreachable status.

D

In a different question setup where the static route is defined as 198.51.100.0/24 and the OSPF route is not configured correctly, leading to a scenario where the destination is indeed outside the defined routes, this option could be correct. For example, if the static route was incorrectly configured to point to a different subnet entirely.

Why candidates pick the wrong answer

B

Students may confuse the concept of administrative distance with route selection priority, thinking that a dynamic protocol like OSPF always takes precedence over static routes. However, static routes usually have a lower AD and are preferred unless overridden by a longer prefix match.

C

Test-takers might think that a static route must have a specific AD to be considered, or they may confuse the concept of administrative distance with prefix length. They might also recall that routes with AD 255 are not installed, but that is not the case here.

D

A student might misread the exhibit or incorrectly calculate the subnet ranges, thinking that 198.51.100.70 is outside the /26 range. They might also confuse the destination IP with the network address or broadcast address, leading to the mistaken belief that it is not covered.

574
MCQmedium

A router is configured as follows: interface g0/1 ip address 172.16.1.1 255.255.255.0 ip helper-address 10.20.20.10 Hosts on 172.16.1.0/24 are not receiving addresses from the DHCP server at 10.20.20.10. The server is reachable by ping from the router. What is the purpose of the ip helper-address command in this scenario?

A.It converts DHCP unicast replies into broadcasts on the client segment
B.It forwards certain UDP broadcasts, including DHCP requests, to a remote server
C.It provides DNS resolution for DHCP clients before they receive an address
D.It creates a static route to the DHCP server
AnswerB

Correct. This is correct. The command relays certain UDP broadcasts, including DHCP client requests, to a server on another subnet. That is why DHCP can work even when the server is not local to the client VLAN.

Why this answer

The ip helper-address command exists to solve a broadcast-boundary problem. DHCP clients begin by sending broadcast traffic because they do not yet have a valid IP configuration. Routers normally do not forward broadcasts between subnets, so if the DHCP server lives on a different network, the client request would stop at the router.

The helper-address function listens for that local broadcast and relays it as unicast traffic to the remote DHCP server. In plain language, it lets a client on one VLAN ask a DHCP server on another VLAN for an address. The command is not a routing statement and it is not a DNS feature.

It is a relay mechanism for broadcast-based UDP services such as DHCP.

Exam trap

A frequent exam trap is confusing the ip helper-address command as a feature that converts DHCP unicast replies into broadcasts on the client segment. In reality, the router forwards DHCP client broadcasts as unicast to the server, not the other way around. Another mistake is assuming the command creates static routes or provides DNS resolution, which it does not.

Misunderstanding these functions leads to incorrect troubleshooting and answer choices, especially when the DHCP server is reachable by ping but clients still fail to get addresses due to missing broadcast relay.

Why the other options are wrong

A

Option A incorrectly states that the ip helper-address converts DHCP unicast replies into broadcasts. The command actually relays client broadcast requests as unicast to the server, not the reverse. This reverses the direction of the relay function and misunderstands the broadcast boundary issue.

C

Option C incorrectly claims the command provides DNS resolution for DHCP clients before they receive an address. DNS resolution is unrelated to the ip helper-address function, which only relays UDP broadcasts like DHCP requests and does not perform name resolution.

D

Option D mistakenly suggests that the command creates a static route to the DHCP server. Routing and static routes are separate functions; the ip helper-address does not affect routing tables but only relays broadcast traffic as unicast.

When would these options actually be correct?

A

In a scenario where a router is configured to handle DHCP requests but needs to convert unicast replies from the DHCP server back into broadcast packets for clients on the same subnet, this option would be correct. For example, if the question specified that the DHCP server only responds with unicast replies and clients are configured to expect broadcasts.

C

In a different scenario, if a question asked about a feature that allows DHCP clients to resolve DNS names before receiving an IP address, and if the context involved a DHCP server that also provided DNS services, this option could be correct.

D

In a different scenario where a question asks about configuring a router to direct traffic to a specific network segment, a candidate might need to create a static route to ensure packets reach a remote DHCP server. Here, the context would involve routing decisions rather than DHCP configurations.

Why candidates pick the wrong answer

A

Students may confuse the helper-address function with the concept of broadcasting, thinking that the router needs to broadcast the server's reply to reach the client. However, the router already knows the client's MAC address from the original request and can send a unicast reply.

C

Students might associate 'helper' with general assistance, including DNS, especially since DHCP often provides DNS server information. However, the helper-address command is specifically for broadcast relay, not DNS resolution.

D

Students may think that because the router needs to send packets to the server, a route must be created. However, the helper-address command relies on existing routing; it does not add routes. The confusion arises from mixing routing with broadcast forwarding.

575
MCQhard

Refer to the exhibit. A network engineer is troubleshooting an issue where syslog messages at severity 6 (informational) and severity 7 (debugging) are not being sent to the syslog server at 192.168.100.50, even though the device appears to generate these messages locally. Based on the exhibit, what is the most likely cause?

A.The logging buffer is full, preventing new informational and debug messages from being sent to the syslog server.
B.The syslog server IP address 192.168.100.50 is unreachable from the router.
C.The trap logging level is set to errors (severity 3), filtering out informational and debug messages.
D.Console logging is disabled, so only severity 3 and lower messages appear.
AnswerC

The 'Trap logging: level errors (3)' line in the exhibit explicitly limits syslog messages sent to the syslog server to severity 0–3. Informational (6) and debug (7) are higher in numeric value (less severe) and are dropped by this filter.

Why this answer

The exhibit shows that the logging trap level is configured to 'errors' (severity 3). This means only syslog messages with a severity of 0 (emergencies) through 3 (errors) are sent to the syslog server. Informational (severity 6) and debugging (severity 7) messages are filtered out because they are below the configured trap threshold.

This directly explains why those messages are not reaching the server, even though they are generated locally.

Exam trap

Cisco often tests the distinction between different logging destinations (console, monitor, buffer, trap) and their independent severity thresholds, so candidates mistakenly assume that if messages appear locally (e.g., in the buffer), they must also be sent to the syslog server.

Why the other options are wrong

A

Candidates may associate local buffer behavior with remote logging, but the buffer is just local storage, independent of trap forwarding.

B

A reachability problem would affect all severities equally, not selectively filter only informational and debug messages.

D

Candidates may confuse console and trap logging, but each destination has its own independent severity level.

576
Matchingmedium

Match each security control or idea to its most accurate purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Secures remote management sessions

Provides authentication, authorization, and accounting framework

Limits access to only what is necessary

Centralizes visibility into device events and messages

Why these pairings

A firewall controls incoming and outgoing network traffic based on predetermined security rules, acting as a barrier between trusted and untrusted networks. Option A correctly describes this function. Option B, detecting and alerting on suspicious activity, is the role of an Intrusion Detection System (IDS).

Option C, preventing and blocking intrusions in real time, is the function of an Intrusion Prevention System (IPS). Option D, authenticating users and managing access rights, pertains to AAA (Authentication, Authorization, and Accounting) frameworks.

Exam trap

Candidates often confuse the roles of firewalls, IDS, and IPS. Firewalls filter traffic based on rules but do not inherently detect or block intrusions; that is the job of IDS and IPS.

When would these options actually be correct?

B

This option would be correct if the question asked to match 'Intrusion Detection System (IDS)' or 'Network-based IDS' to its purpose, as IDS monitors network traffic for suspicious activity and generates alerts.

C

If the question asked 'Match each security control to its most accurate purpose' and the option was 'Intrusion Prevention System (IPS): Prevents and blocks intrusions in real time', then this description would be correct.

D

In a question asking to match 'Authentication, Authorization, and Accounting (AAA)' or 'Identity and Access Management (IAM)' to its purpose, this option would be correct.

Why candidates pick the wrong answer

B

Candidates may confuse firewalls with IDS/IPS because both are security devices that inspect traffic, leading them to attribute detection capabilities to firewalls.

C

Candidates may confuse firewalls with next-generation firewalls (NGFW) or IPS, assuming firewalls provide real-time intrusion prevention, when in fact they primarily filter traffic based on static rules.

D

Candidates may confuse firewalls with access control systems because both enforce security policies, but firewalls control network traffic while AAA manages user permissions.

577
MCQmedium

Exhibit: An administrator wants inside hosts in 192.168.10.0/24 to reach the internet using one public IP address on the edge router. Which feature is being used?

A.Static NAT
B.Policy-based routing
C.PAT overload
D.Port security
AnswerC

PAT overload, enabled with the overload keyword on an ip nat inside source rule, maps multiple private IP addresses from 192.168.10.0/24 to a single public address by tracking unique TCP/UDP port numbers. This allows all inside hosts to share the outside interface's IP, which is exactly what the administrator needs to provide internet access without public IP exhaustion. The overload keyword distinguishes it from static NAT by enabling many-to-one translation.

Why this answer

When many inside private addresses share one public address and are differentiated by Layer 4 port numbers, the router is using PAT. Cisco documentation often calls this NAT overload.

Exam trap

Be careful not to confuse the different types of NAT. Remember, PAT is specifically for sharing one public IP among many devices using port numbers.

Why the other options are wrong

A

Static NAT requires a one-to-one mapping between an inside local address and an inside global address, which would consume multiple public IPs if multiple hosts need internet access. It does not allow multiple inside hosts to share a single public IP.

B

Policy-based routing (PBR) is used to override the routing table based on policies (e.g., source/destination IP, protocol), not to perform address translation. It does not modify IP addresses or enable multiple hosts to share a single public IP.

D

Port security is a switchport security feature that restricts MAC addresses allowed on a port to prevent unauthorized access. It does not perform IP address translation or enable internet access for multiple hosts.

When would these options actually be correct?

A

In a scenario where the question states that a specific internal host needs to be consistently reachable from the internet using a fixed public IP, Static NAT would be the correct answer. For example, if the question specified that a web server with IP 192.168.10.10 should always be accessible via the public IP 203.0.113.5, Static NAT would apply.

B

If the question were framed to ask about directing specific types of traffic from the 192.168.10.0/24 network based on criteria such as source IP or application type, then policy-based routing would be the correct answer. For example, 'An administrator wants to route HTTP traffic from 192.168.10.0/24 through a different gateway than other traffic.'

D

If the question were about securing a network by limiting the number of devices that can connect to a switch port, or if it asked how to prevent unauthorized devices from accessing the network, then port security would be the correct answer.

Why candidates pick the wrong answer

A

Students may confuse static NAT with dynamic NAT or PAT because all involve address translation, but static NAT is typically used for servers that need consistent public addresses, not for many hosts sharing one IP.

B

The term 'policy' might lead students to think it involves some form of access control or translation, but PBR is purely a routing mechanism, not a NAT feature.

D

The word 'port' in port security might be confused with the port numbers used in PAT, but port security deals with physical switch ports and MAC addresses, not TCP/UDP port translation.

578
PBQhard

You are connected to R1, a branch router connected to a central NTP server at 203.0.113.10 and a syslog server at 198.51.100.20. Configure R1 as an NTP client using its Loopback0 interface (192.168.1.1/32) as the source, and ensure syslog messages of severity 'informational' and above are sent to the syslog server. Currently, R1 shows 'Clock is unsynchronized, stratum 16'. Identify and fix the NTP issue, then apply the syslog configuration.

Network Topology
G0/010.0.0.2/30linkR1R2

Hints

  • •NTP shows stratum 16 and uses a local pseudo-clock — the server is configured but not used.
  • •Check if the NTP source interface is set to a reachable IP.
  • •Syslog is only sending warnings and above — change the trap level to allow informational.
A.Configure 'ntp source Loopback0' and 'logging trap informational'.
B.Configure 'ntp server 203.0.113.10 source Loopback0' and 'logging trap warnings'.
C.Configure 'ntp source Loopback0' and 'logging trap debugging'.
D.Configure 'ntp source Loopback0' and 'logging host 198.51.100.20' without changing the trap level.
AnswerA
solution
! R1
configure terminal
ntp source Loopback0
logging trap informational
end
write memory

Why this answer

The NTP client was configured but the source interface was not specified, causing the router to use a default source that may not be reachable. Additionally, the syslog trap level was set to 'warnings' (severity 4), which filters out informational (severity 6) messages. To fix: configure 'ntp source Loopback0' to use a consistent source IP, and change 'logging trap informational' to allow all messages severity 6 and above.

Exam trap

Trap: Candidates may confuse the 'ntp server' command syntax with the global 'ntp source' command, or assume the default syslog trap level already includes informational messages. Remember: NTP source is set globally, and syslog trap levels must be explicitly configured to match the required severity.

Why the other options are wrong

B

The specific factual error: The 'ntp server' command does not have a 'source' parameter; source is set globally. Also, 'logging trap warnings' does not meet the requirement to send informational messages.

C

The specific factual error: 'logging trap debugging' sends all messages, including debugging (severity 7), which is unnecessary and can cause excessive log traffic. The requirement is for informational and above, which is severity 6, not 7.

D

The specific factual error: The default trap level may not be 'informational'; it is often 'warnings' or 'debugging' depending on the IOS version. The requirement to send informational messages necessitates explicit configuration of 'logging trap informational'.

Why candidates pick the wrong answer

B

Candidates might think the source can be specified per NTP server command, and may confuse 'warnings' as a higher severity that includes informational, but it actually excludes it.

C

Candidates might think 'debugging' is the highest level and therefore includes everything, but the correct level for informational and above is 'informational' (severity 6).

D

Candidates might assume the default trap level already includes informational messages, but in many IOS versions the default is 'warnings' (severity 4), which excludes informational (severity 6).

579
Drag & Dropmedium

Which of the following sequences correctly orders the steps to plan, configure, and apply an extended ACL that permits HTTP traffic from the 192.168.1.0/24 subnet to the server at 10.0.0.1, and deny all other IP traffic, applied inbound on interface GigabitEthernet0/1?

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First enter global config, then create ACL with permit statement, then deny all, then enter interface, then apply ACL inbound.

Exam trap

Be careful with the order of ACL entries: always place more specific permits before general denies. Also, remember that ACLs must be created before they can be applied, and the direction (inbound/outbound) must match the requirement.

Why candidates pick the wrong answer

B

Candidates might think they can apply the ACL first and then define it, but Cisco IOS requires the ACL to exist before application.

C

Candidates might think they need to deny everything first and then permit specific traffic, but ACLs use a first-match approach.

D

Candidates may confuse inbound and outbound directions, especially if they think about traffic flow from the source perspective.

580
MCQhard

A network engineer configures an EtherChannel between two switches. Switch A's interface is set with channel-group 1 mode active, while Switch B's identical interface is set with channel-group 1 mode auto. When verifying with show etherchannel summary, the engineer observes that the port-channel interface is down and the physical interfaces are not bundled. What is the most likely cause of the problem?

A.The LACP system priority on the active side must be lower than the auto side.
B.The mode 'auto' is a PAgP negotiation mode that is incompatible with the LACP active mode.
C.LACP requires one side to be active and the other passive; two active interfaces will not bundle.
D.The physical interfaces must be shut down and then re-enabled after configuring LACP for the bundle to form.
AnswerB

The mode 'auto' is one of the two PAgP negotiation modes (the other being 'desirable'), whereas LACP uses 'active' and 'passive'. PAgP and LACP are entirely separate protocols with different frame formats and state machines, so an interface set to 'auto' cannot form an EtherChannel with an interface set to 'active'. To create a bundle with LACP, both sides must use LACP modes, such as active/active or active/passive, not PAgP modes.

Why this answer

'active' is an LACP mode that initiates negotiations, while 'auto' is a PAgP mode that passively waits for PAgP packets. Since LACP and PAgP are incompatible protocols, the interfaces will never negotiate a bundle, leaving the port-channel down. The engineer must use matching protocol modes (e.g., both LACP active/passive or both PAgP desirable/auto) for EtherChannel to form.

Exam trap

Cisco often tests the confusion between LACP and PAgP mode keywords, especially the similarity between 'active' (LACP) and 'auto' (PAgP), leading candidates to assume they are compatible or to focus on priority or interface state rather than protocol mismatch.

Why the other options are wrong

A

LACP priority is not required for basic negotiation and does not cause a failure to bundle.

C

Active/active LACP successfully negotiates, so this is not the cause.

D

Bouncing interfaces is not required to trigger LACP negotiation.

581
MCQhard

What is the best explanation for why a router chooses the OSPF route to 10.50.0.0/16 instead of the RIP route?

A.Because OSPF has a lower administrative distance than RIP for the same prefix.
B.Because RIP routes are never installed when OSPF is running.
C.Because OSPF always has a longer prefix than RIP.
D.Because the RIP metric is lower than the OSPF metric.
AnswerA

Cisco IOS selects the route with the lowest administrative distance when multiple routing protocols offer the same destination and prefix length. OSPF's default administrative distance is 110, while RIP's is 120, so OSPF is considered more trustworthy and its route is installed in the routing table. Because both routes share the same /16 prefix, prefix length cannot break the tie, and the lower AD for OSPF becomes the decisive factor.

Why this answer

The router chooses the OSPF route because when the prefix length is the same, source preference is considered, and OSPF has a lower administrative distance than RIP. In practical terms, both routes describe the same destination size, so longest-prefix match does not separate them. The router then trusts the OSPF source more than RIP by default.

This is a classic administrative-distance comparison question and a very important route-selection concept.

Exam trap

A frequent exam trap is believing that RIP routes are never installed when OSPF is running or that the router always prefers the route with the lowest metric regardless of protocol. This is incorrect because RIP routes can remain in the routing table alongside OSPF routes. The router actually uses administrative distance, not metric, to choose between routes learned from different protocols.

Confusing metric with administrative distance leads to wrong answers, especially when both protocols advertise the same prefix length. Remember, cross-protocol route selection depends on administrative distance, not metric comparison.

Why the other options are wrong

B

Option B is incorrect because RIP routes can still be installed in the routing table even when OSPF is running; the router does not automatically suppress RIP routes.

C

Option C is wrong because both OSPF and RIP routes shown have the same prefix length (/16), so prefix length does not influence the choice here.

D

Option D is incorrect because cross-protocol route selection is based on administrative distance, not metric comparison; RIP's metric being lower does not make it preferred over OSPF.

When would these options actually be correct?

B

In a scenario where the question specifies that RIP is configured but not allowed to run simultaneously with OSPF due to network policy or configuration settings, this option could be correct. For instance, if the exam question states that RIP is disabled when OSPF is active, then this answer would be valid.

C

In a scenario where a question specifies that OSPF is the only routing protocol running on the router, and it asks why no RIP routes are present, this option could be correct, as it would imply that RIP routes cannot be installed without the protocol being active.

D

In a scenario where a question specifies that OSPF is configured to ignore RIP routes due to a specific policy or configuration, such as route filtering or administrative settings that prevent RIP from being used, this option would be correct.

Why candidates pick the wrong answer

B

Students might think OSPF overrides RIP entirely because OSPF is more advanced, but routing protocols operate independently and routes are selected per prefix based on AD.

C

Test-takers may confuse the concept of longest prefix match with administrative distance, thinking a more specific route always wins, but here both are equally specific.

D

Students often assume lower metric always means better route, but cross-protocol selection ignores metrics and relies on AD first.

582
PBQhard

You are connected to R1 via the console. R1 and R2 are directly connected via their GigabitEthernet0/0 interfaces. The link between them is down. Your task is to diagnose and fix the issue: R1's interface is configured for 100 Mbps full-duplex, but R2 is using auto-negotiation. Additionally, the link requires a Gigabit Ethernet connection over a distance of 5 km. Configure R1's interface to match R2's settings (auto-negotiation) and then select and install the correct SFP module to support the 5 km distance requirement.

Network Topology
G0/010.0.0.1/30G0/010.0.0.2/30SFP linkR1R2

Hints

  • •Check the current speed and duplex settings on R1's interface.
  • •Auto-negotiation requires both sides to be set to 'auto' to succeed.
  • •For distances up to 5 km, use a 1000BASE-LX SFP (single-mode fiber).
A.Configure R1 with 'no speed', 'no duplex', and 'negotiation auto' on GigabitEthernet0/0, then replace the SFP module with a 1000BASE-LX SFP.
B.Configure R1 with 'speed 1000' and 'duplex full' on GigabitEthernet0/0, then replace the SFP module with a 1000BASE-SX SFP.
C.Configure R1 with 'no speed', 'no duplex', and 'negotiation auto' on GigabitEthernet0/0, then replace the SFP module with a 1000BASE-SX SFP.
D.Configure R1 with 'speed 100' and 'duplex full' on GigabitEthernet0/0, then replace the SFP module with a 1000BASE-LX SFP.
AnswerA
solution
! R1
configure terminal
interface gigabitethernet 0/0
no speed 100
no duplex full
negotiation auto
end

Why this answer

The link is down because R1 is forcing speed 100 and full-duplex while R2 is using auto-negotiation. When one side is hard-coded and the other is set to auto, auto-negotiation fails and the link does not come up. The fix is to enable auto-negotiation on R1 by removing the manual speed and duplex settings with the 'no speed' and 'no duplex' commands, and then using 'negotiation auto'.

For the 5 km distance, a standard 1000BASE-SX SFP (550 m) is insufficient; a 1000BASE-LX SFP (up to 10 km) is required. The candidate must also replace the SFP module with a compatible LX SFP.

Exam trap

Students often forget that auto-negotiation must be enabled on both sides for Gigabit Ethernet; hard-coding one side breaks the link. Also, they may confuse SFP types: SX for short range, LX for long range. Always verify distance requirements when selecting fiber optics.

Why the other options are wrong

B

The specific factual error is that hard-coding speed and duplex on one side while the other uses auto-negotiation prevents the link from coming up, and 1000BASE-SX cannot reach 5 km.

C

The specific factual error is that 1000BASE-SX is designed for short-range multimode fiber, not long distances.

D

The specific factual error is that GigabitEthernet interfaces can operate at 100 Mbps, but the SFP module requires 1000 Mbps; additionally, the speed/duplex mismatch prevents the link from coming up.

Why candidates pick the wrong answer

B

Candidates might think that setting the same speed (1000 Mbps) will work, but they overlook the duplex mismatch issue and the distance limitation of SX.

C

Candidates may correctly identify the auto-negotiation issue but fail to consider the distance requirement, assuming any Gigabit SFP will work.

D

Candidates might think that matching the original speed (100 Mbps) is necessary, but the question states the link requires Gigabit Ethernet, and the SFP module must be used at its rated speed.

583
MCQmedium

Why is RIP rarely chosen for large modern enterprise networks?

A.It does not support IPv4
B.It scales poorly due to slow convergence and hop-count limitations
C.It cannot run on routers and only works on switches
D.It requires link-state advertisements
AnswerB

RIP's maximum hop count of 15 (with 16 considered unreachable) makes it impossible to use in networks with paths longer than 15 routers, and its distance-vector algorithm relies on periodic full-table updates and split horizon, causing slow convergence that scales poorly as network diameter grows. In large enterprise networks, route propagation and reconvergence times become unacceptably slow, and the hop limit itself is a hard scalability barrier.

Why this answer

RIP is simple but has important scalability limits, including a maximum metric of 15 and relatively slow convergence compared with more modern protocols such as OSPF and EIGRP.

Exam trap

Don't confuse RIP's limitations with features of other protocols; remember RIP's maximum hop count and distance-vector nature.

Why the other options are wrong

A

RIP supports both IPv4 and IPv6 (RIPng). The statement is factually incorrect because RIP has been used for IPv4 routing since its inception.

C

RIP is a routing protocol that runs on routers, not switches. While some multilayer switches can run routing protocols, RIP is not exclusive to switches.

D

RIP is a distance-vector protocol, not a link-state protocol. It uses hop count as its metric and exchanges entire routing tables, not link-state advertisements (LSAs) like OSPF.

When would these options actually be correct?

A

If the exam question asked about routing protocols that do not support IPv4 at all, or if it specifically focused on protocols that are exclusively designed for IPv6, then this option would be correct as RIP would not be applicable in those scenarios.

C

If the exam question asked about protocols that are exclusively designed for Layer 2 devices, or if it specified a scenario where only switches are being configured for routing, then this option could be correct. For example, a question could ask which protocols are not applicable to routers in a Layer 2-only network.

D

In a question asking about the characteristics of link-state routing protocols, stating that RIP requires link-state advertisements would be correct. For example, if the question specified which protocols utilize link-state advertisements, this option would accurately describe RIP's absence of that feature.

Why candidates pick the wrong answer

A

Students might confuse RIP's age or simplicity with a lack of IPv4 support, or think that only newer protocols support IPv4.

C

A test-taker might think RIP is only for switches because it is simpler and sometimes used in small networks where switches might perform routing, but that is not accurate.

D

Students often confuse distance-vector and link-state protocols. They might incorrectly associate RIP with LSAs because both are routing protocols, but the mechanism is different.

584
MCQmedium

Which DHCP message does the client send to formally accept an offered address?

A.DISCOVER
B.OFFER
C.REQUEST
D.ACK
AnswerC

The DHCPREQUEST is the client's formal acceptance message. After receiving a DHCPOFFER, the client sends this broadcast to bind the offered lease, effectively saying 'I accept this configuration.' The server only commits the lease upon receiving the DHCPREQUEST, making it the definitive acceptance step in the DHCP handshake.

Why this answer

In the DORA process, the client sends DHCPREQUEST after receiving an offer. The server then responds with DHCPACK if the lease is granted.

Exam trap

Be careful not to confuse the direction of messages in the DHCP process. Remember which messages are client-initiated and which are server responses.

Why the other options are wrong

A

The DISCOVER message is used by the client to locate available DHCP servers, not to accept an offered address. It is the first step in the DORA process.

B

The OFFER message is sent by the DHCP server to propose an IP address to the client, not by the client to accept it. The client cannot send an OFFER.

D

The ACK message is sent by the DHCP server to confirm the lease after receiving the REQUEST, not by the client. The client does not send ACK.

When would these options actually be correct?

A

If the question asked which DHCP message is used to initiate the IP address allocation process, then 'DISCOVER' would be the correct answer. This would be in the context of a question focused on the initial steps of the DHCP handshake.

B

If the question were to ask which message is sent by the server to propose an IP address to the client, then OFFER would be the correct answer. This would involve a scenario focusing on the DHCP server's role in the address allocation process.

D

If the question asked which DHCP message is sent by the server to confirm the acceptance of an IP address after the client sends a REQUEST, then 'ACK' would be the correct answer. This scenario focuses on the server's response rather than the client's action.

Why candidates pick the wrong answer

A

Students might think DISCOVER is the acceptance message because it is the first client message, but acceptance occurs later with REQUEST.

B

The word 'OFFER' might be misinterpreted as the client's acceptance of an offer, but in DHCP, the server makes the offer.

D

Students may confuse ACK as a client acknowledgment because it is a common term for acknowledgment, but in DHCP, the server sends ACK to finalize the lease.

585
PBQhard

You are connected to WLC-1 via the management interface (192.168.1.100/24). The wireless network 'CustomerNet' uses WPA3-Personal, but clients are failing to associate. The SSID is hidden and the correct VLAN is 30. Configure the WLAN and SSID parameters to allow successful client associations and verify the configuration.

Network Topology
Cisco APWLC-1Clients

Hints

  • •Remember to create the interface before assigning it to the WLAN.
  • •WPA3-Personal uses a pre-shared key (PSK) but the command is 'security wpa3'.
  • •The SSID broadcast must be enabled ('broadcast-ssid enable') for clients to discover it.
A.Create a new interface 'vlan30' with VLAN 30, then create a new WLAN with SSID 'CustomerNet', set security to WPA3-Personal, enable SSID broadcast, and assign the 'vlan30' interface.
B.Modify the existing GuestNet WLAN: change security to WPA3-Personal, enable SSID broadcast, and change the interface to 'guest' (VLAN 20).
C.Create a new WLAN with SSID 'CustomerNet', set security to WPA2-PSK, enable SSID broadcast, and assign the 'guest' interface (VLAN 20).
D.Modify the GuestNet WLAN: change security to WPA3-Personal, keep SSID broadcast disabled, and change the interface to a new interface mapped to VLAN 30.
AnswerA
solution
! WLC-1
config terminal
interface customer
vlan 30
ip address 192.168.30.1 255.255.255.0
exit
wlan 3
ssid CustomerNet
broadcast-ssid enable
security wpa3
security wpa akm psk set-key ascii 0 CiscoSecure123
interface customer
no shutdown
end

Why this answer

The GuestNet WLAN (ID 2) currently uses WPA2 with PSK, but clients expect WPA3-Personal. Additionally, the SSID is hidden (broadcast disabled) and the interface is set to guest (VLAN 20) instead of the required VLAN 30. To fix, create a new WLAN (or modify WLAN 2) to use WPA3-Personal, enable SSID broadcast, and assign it to a new interface mapped to VLAN 30.

Configure the interface first, then apply to the WLAN.

Exam trap

A common trap is to assume that modifying the existing WLAN is sufficient, but you must also ensure the correct VLAN interface exists and is assigned. Additionally, candidates often forget that a hidden SSID must be broadcast for clients to discover it, especially when clients are failing to associate.

Why the other options are wrong

B

The specific factual error is that the interface remains set to 'guest' (VLAN 20) instead of being changed to VLAN 30 as required.

C

The specific factual errors are using WPA2-PSK (clients expect WPA3-Personal) and assigning the wrong VLAN (20 instead of 30).

D

The specific factual error is that the SSID broadcast remains disabled, which means clients cannot see the SSID and will not attempt to associate.

Why candidates pick the wrong answer

B

Candidates might think modifying the existing WLAN is sufficient and overlook the VLAN requirement, assuming the guest interface is acceptable.

C

Candidates may confuse WPA2 and WPA3 or think that WPA2 is backward compatible, and may not realize the VLAN mismatch.

D

Candidates may think that hiding the SSID is a security feature and should be kept, not realizing that the clients are failing to associate because they cannot find the network.

586
MCQmedium

Why is a default route often called a route of last resort?

A.Because it is used only when no more specific route matches the destination.
B.Because it always has the lowest bandwidth.
C.Because it must be learned from OSPF only.
D.Because it is more specific than every other route.
AnswerA

The router evaluates more specific prefixes first; the default route 0.0.0.0/0 has the shortest prefix length, so it is consulted only after every longer, more specific match fails. That fallback behaviour is why it is termed the route of last resort.

Why this answer

Ly identifies the default route as a route of last resort because it is used only when no more specific route matches the destination. Option B is incorrect because bandwidth is not a defining characteristic of a default route; it is simply a fallback path. Option C is wrong because default routes can be configured statically or learned via any routing protocol (e.g., OSPF, EIGRP, RIP), not exclusively OSPF.

Option D is false because the default route is the least specific route (0.0.0.0/0), not more specific than any other route.

Exam trap

A common exam trap is assuming the default route is learned only via OSPF or that it always has the lowest bandwidth, when in fact it is simply the least specific route used as a fallback.

Why the other options are wrong

B

Bandwidth is not a defining characteristic of a default route; the route is chosen based on prefix length and administrative distance, not bandwidth.

C

Default routes can be statically configured or learned from any routing protocol (including OSPF, EIGRP, RIP), so they are not OSPF-specific.

D

The default route (0.0.0.0/0) is the least specific route, not more specific; specificity is determined by the subnet mask length.

When would these options actually be correct?

B

In a different question, if asked about the characteristics of routing protocols or how to optimize network performance, an option stating that a default route has the lowest bandwidth could be correct if it specifically refers to a scenario where it is intentionally configured to limit traffic flow.

C

If the exam question specified that a default route must be configured in an OSPF environment and that OSPF is the only routing protocol in use, then this option would be correct. For example, a question could ask about the requirements for a default route in a purely OSPF network.

D

This option would be correct in a question asking for the characteristics of a specific type of route that is more specific than all others, such as a static route with a defined subnet mask that matches a particular destination more closely than any default route.

Why candidates pick the wrong answer

B

Students might confuse the concept of a default route with a route that has a low metric or cost, thinking that 'last resort' implies a poor-quality path. However, the term 'last resort' refers to the order of matching, not the quality of the route.

C

Students may recall that OSPF can generate a default route using the 'default-information originate' command, leading them to incorrectly assume that OSPF is the only source. However, default routes are commonly configured statically or learned via other protocols.

D

The phrase 'route of last resort' might be misinterpreted as meaning the route is more specific or important, but in routing, 'last resort' means it is used only when no other route matches, which is the opposite of being more specific.

587
MCQhard

Based on the exhibit, which command is the best next step to verify whether the floating static route becomes active after the primary route is lost?

A.show ip route
B.show vlan brief
C.show spanning-tree
D.show power inline
AnswerA

The 'show ip route' command is the correct next step because it displays the IPv4 routing table, directly showing whether the default route (0.0.0.0/0) has been installed. It will reveal the administrative distance and next-hop IP for both the primary and backup routes, allowing you to confirm if failover occurred after the primary route disappeared. This is the definitive way to verify routing-table state and default-route failover.

Why this answer

The best next step is to examine the routing table directly after removing or losing the primary route. In practical terms, the purpose of a floating static route is to appear when the better route disappears. The clearest way to verify that behavior is to inspect the route table for the default route after the failure condition.

This is a simulation-style verification question. It is not asking how to configure the route, but how to confirm failover actually happened.

Exam trap

A common exam trap is selecting commands unrelated to routing table verification, such as "show vlan brief" or "show spanning-tree." These commands provide information about VLAN configurations or Spanning Tree Protocol status but do not show whether a floating static route has become active. Candidates may mistakenly think these outputs indicate network failover status, but only the routing table output confirms if the backup route is installed after the primary route fails. Misunderstanding the purpose of these commands leads to incorrect answers.

Why the other options are wrong

B

"Show vlan brief" shows VLAN status and port assignments but does not provide any information about routing or route failover, so it cannot verify if the floating static route is active.

C

"Show spanning-tree" displays Spanning Tree Protocol information related to Layer 2 loop prevention, which is unrelated to routing table contents or route failover verification.

D

"Show power inline" displays Power over Ethernet (PoE) status and power consumption on switch ports, which has no relevance to routing or verifying floating static route activation.

When would these options actually be correct?

B

In a different question scenario where the focus is on VLAN configurations, such as verifying the operational status of VLANs on a switch after a network change, 'show vlan brief' would be the correct command to use to ensure that all VLANs are up and functioning as expected.

C

If the question were focused on verifying the status of a network topology and ensuring there are no loops or issues in the spanning tree, then 'show spanning-tree' would be the correct command to use. For example, a question might ask about troubleshooting connectivity issues in a switched network environment.

D

If the exam question asked about verifying the power status of devices connected to PoE ports after a network outage, 'show power inline' would be the correct command to check if the devices are receiving power.

Why candidates pick the wrong answer

B

Students might confuse VLAN configuration with routing, especially in a switched environment, or think that VLAN information is relevant to verifying connectivity after a link failure.

C

Students may associate STP with redundancy and failover, mistakenly thinking it can verify route failover, or they may confuse Layer 2 loop prevention with Layer 3 path redundancy.

D

Students might be tempted by the word 'inline' or think that power status could indicate link status, but it has no bearing on routing protocol or static route activation.

588
MCQhard

A network engineer notices that after issuing the no shutdown command on interface GigabitEthernet0/0 of a router, the interface remains down. The output of show interfaces GigabitEthernet0/0 displays 'GigabitEthernet0/0 is down, line protocol is down'. The physically connected switch port is also administratively down. What is the most likely cause?

A.The connected switch port is administratively down.
B.Mismatched encapsulation types on the router and switch.
C.Speed and duplex mismatch between the router and switch.
D.Incorrect native VLAN configuration on the trunk link.
AnswerA

An administratively down switch port is placed in the shutdown state, which disables all physical-layer signaling and removes carrier from the cable. The router consequently senses no layer 1 presence on its interface, so the line protocol cannot transition to up even if the router's own configuration is otherwise sound. This is the direct and definitive cause of the line protocol being down, as no handshake or frame exchange can occur.

Why this answer

The output 'GigabitEthernet0/0 is down, line protocol is down' indicates that both Layer 1 and Layer 2 are down. Since the directly connected switch port is administratively down, the router interface detects no carrier and remains down/down even after the local no shutdown command. Therefore, option A is the most likely cause.

Exam trap

Cisco does test the distinction between local and remote administrative shutdown, but the resulting state would be 'down/down', not 'up/down'. Students should understand that 'up/down' implies Layer 1 is functional, which cannot happen if the remote port is shut down.

Why the other options are wrong

B

Candidates often attribute line protocol down to encapsulation issues, missing the clear indication that the switch port is shut down.

C

Duplex mismatch is a common cause of interface issues, so candidates may assume it without considering the explicitly stated admin-down condition.

D

Candidates may recall VLAN mismatch as a cause for line protocol down on trunk links, forgetting that the scenario gives a clear admin-down state.

589
Drag & Drophard

Drag and drop the following steps into the correct order for an agentic AI system to remediate a network performance issue using Cisco IOS-XE CLI commands.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The agent first enters configuration mode, then diagnoses the interface, applies QoS, enables monitoring, and finally verifies the changes.

Exam trap

The trap is that candidates may confuse the order of diagnosis and action, or think monitoring should be enabled first. Remember: diagnose first, then act, then monitor, then verify.

Why candidates pick the wrong answer

B

Candidates might think monitoring should be enabled first to collect baseline data, but in remediation, the agent first diagnoses and applies changes, then enables monitoring to verify.

C

Candidates might mistakenly think QoS can be applied directly from privileged EXEC mode, or they may confuse the order of diagnosis and action.

D

Candidates might think that since the issue is known (performance), QoS can be applied immediately, but proper troubleshooting requires diagnosis first.

590
PBQhard

You are connected to R1. Configure DHCP services so that hosts on VLAN 10 (192.168.10.0/24) can obtain IP addresses from R1. Additionally, configure the switch SW1 to prevent rogue DHCP server attacks on that VLAN. The current configuration has a misconfigured helper-address and an excluded-address range that is too broad.

Network Topology
G0/0.10192.168.10.1/24SW1R1Hosts

Hints

  • •The helper-address should point to the DHCP server itself, not an external address.
  • •The excluded-address range is too wide; leave room for hosts to get IPs.
  • •On the switch, only the port connecting to the legitimate DHCP server should be trusted.
A.On R1, change the helper-address to 192.168.10.1 and the excluded-address range to 192.168.10.1 192.168.10.10. On SW1, enable DHCP snooping globally and for VLAN 10, and set interface G0/1 as trusted.
B.On R1, change the helper-address to 192.168.10.255 and the excluded-address range to 192.168.10.1 192.168.10.10. On SW1, enable DHCP snooping globally and for VLAN 10, and set all ports as trusted.
C.On R1, change the helper-address to 192.168.10.1 and the excluded-address range to 192.168.10.1 192.168.10.254. On SW1, enable DHCP snooping globally and for VLAN 10, and set interface G0/1 as untrusted.
D.On R1, change the helper-address to 192.168.10.1 and the excluded-address range to 192.168.10.1 192.168.10.10. On SW1, enable DHCP snooping globally and for VLAN 10, and set interface G0/1 as untrusted.
AnswerA
solution
! R1
configure terminal
no ip dhcp excluded-address 192.168.10.1 192.168.10.254
ip dhcp excluded-address 192.168.10.1 192.168.10.10
interface GigabitEthernet0/0.10
no ip helper-address 10.0.0.2
ip helper-address 192.168.10.1
end

! SW1
configure terminal
ip dhcp snooping
ip dhcp snooping vlan 10
interface GigabitEthernet0/1
ip dhcp snooping trust
interface GigabitEthernet0/2
no ip dhcp snooping limit rate 10
ip dhcp snooping limit rate 15
end

Why this answer

The helper-address on R1's subinterface points to 10.0.0.2 instead of the DHCP server's IP (R1 itself, which is the server). The excluded-address range excludes all addresses in the subnet, preventing any host from getting an IP. The fix: change helper-address to 192.168.10.1 (loopback or interface IP of R1), and narrow the excluded range to the first 10 addresses (or just the gateway).

On SW1, enable DHCP snooping globally and for VLAN 10, and mark the port facing R1 (G0/1) as trusted; other ports should be untrusted to block rogue servers.

Exam trap

Watch out for two common traps: (1) The helper-address must be the DHCP server's unicast IP, not a broadcast address. (2) DHCP snooping trusted ports are for server connections; untrusted ports are for clients. Misplacing these will break DHCP or security.

Why the other options are wrong

B

The helper-address must be a unicast IP address of the DHCP server, not a broadcast address. Additionally, only ports connected to legitimate DHCP servers should be trusted; all other ports must be untrusted to block rogue servers.

C

The excluded-address range should only reserve a few addresses (e.g., for the gateway and static assignments), not the entire subnet. The port connected to the DHCP server must be trusted to allow DHCP server messages; untrusted ports block such messages.

D

DHCP snooping requires that ports connected to legitimate DHCP servers be configured as trusted. Untrusted ports are for client-facing ports where rogue servers might appear; they drop DHCP server messages.

Why candidates pick the wrong answer

B

Candidates might think the broadcast address is acceptable because DHCP uses broadcasts, but the helper-address must be a specific server IP. Also, they may mistakenly believe that trusting all ports simplifies configuration without understanding the security risk.

C

Candidates may think excluding a large range is safe or that the server port should be untrusted to prevent attacks, but this would block legitimate DHCP offers from the server.

D

Candidates may confuse the roles of trusted and untrusted ports, thinking that the server port should be untrusted to be more secure, but this breaks DHCP functionality.

591
PBQhard

You are managing a Cisco WLC (WLC-1) with IP 10.10.10.10. A wireless client reports it can see the SSID 'CorpNet' but fails to associate. The SSID is configured for WPA3, but the client only supports WPA2. Additionally, the WLAN is mapped to VLAN 100, but the AP is on VLAN 10, causing a mismatch. Your task: reconfigure the WLAN to use WPA2-PSK with AES encryption, correct the VLAN assignment to 10, and ensure the SSID is hidden. Also, verify that management access via the WLC web UI is restricted to the 192.168.1.0/24 subnet.

Network Topology
APWLC-1Client

Hints

  • •The client cannot join because WPA3 is required but the client only supports WPA2.
  • •The WLAN is on VLAN 100, but the AP is on VLAN 10 — this mismatch prevents client traffic from being properly bridged.
  • •Management access is open to all; restrict it to the subnet that contains your admin workstation.
A.Change security to WPA2-PSK with AES, disable PMF, map WLAN to management interface (VLAN 10), disable SSID broadcast, restrict HTTP/HTTPS access to 192.168.1.0/24.
B.Change security to WPA2-PSK with TKIP, enable PMF, map WLAN to VLAN 100, enable SSID broadcast, restrict HTTP access to 192.168.1.0/24.
C.Change security to WPA3-PSK with AES, disable PMF, map WLAN to VLAN 10, disable SSID broadcast, restrict HTTP/HTTPS access to 10.10.10.0/24.
D.Change security to WPA2-PSK with AES, enable PMF, map WLAN to VLAN 10, enable SSID broadcast, restrict HTTP/HTTPS access to 192.168.1.0/24.
AnswerA
solution
! WLC-1
config wlan 1
no security wpa3
security wpa2
security wpa2 akm psk
security wpa2 encryption aes
no security wpa3 pmf
interface VLAN10
no broadcast-ssid
end
config management
management http subnet 192.168.1.0 255.255.255.0
management https subnet 192.168.1.0 255.255.255.0
end

Why this answer

The client cannot associate because the WLAN requires WPA3 (PMF required) but the client only supports WPA2. Also, the WLAN is mapped to VLAN 100, but the AP is on VLAN 10, causing a VLAN mismatch that prevents client traffic from reaching the correct subnet. The SSID is broadcast (visible), and management access is open to all subnets.

To fix: change the WLAN security to WPA2-PSK with AES, disable PMF, map the WLAN to the management interface (VLAN 10), disable SSID broadcast, and restrict HTTP/HTTPS access to subnet 192.168.1.0/24.

Exam trap

The exam trap is that candidates may overlook the VLAN mismatch or the requirement to disable PMF when switching from WPA3 to WPA2. Also, they might forget to restrict both HTTP and HTTPS, or confuse the management subnet with the WLC IP address. Always verify client capabilities and VLAN assignments.

Why the other options are wrong

B

The specific factual error: TKIP is deprecated and not used with WPA2-PSK; PMF must be disabled for WPA2-only clients; VLAN 100 is incorrect; SSID broadcast should be disabled; HTTPS access must also be restricted.

C

The specific factual error: WPA3-PSK requires PMF and is incompatible with WPA2-only clients; the allowed subnet for management is 192.168.1.0/24, not 10.10.10.0/24.

D

The specific factual error: PMF is not supported by all WPA2 clients and can cause association issues; SSID broadcast should be disabled to hide the SSID.

Why candidates pick the wrong answer

B

Candidates pick this because they may confuse TKIP with AES, think PMF is optional, forget to change VLAN, or assume only HTTP needs restriction.

C

Candidates pick this because they might think WPA3 is backward compatible or confuse the WLC management IP with the allowed subnet.

D

Candidates pick this because they may think PMF is optional and always safe to enable, or they forget to disable SSID broadcast.

592
MCQhard

A network engineer notices that hosts in the 192.168.2.0/24 network connected to router R1's GigabitEthernet0/1 interface cannot reach the Internet. R1 has a standard ACL 10 configured as 'access-list 10 permit 192.168.1.0 0.0.0.255' and applied inbound on interface GigabitEthernet0/0, which connects to the 192.168.1.0/24 LAN. What is the most likely cause?

A.The implicit deny at the end of ACL 10 is blocking all outbound traffic from the 192.168.2.0/24 network.
B.The ACL is filtering return traffic from the Internet that enters G0/0, because it is applied inbound on that interface instead of outbound.
C.The router is not performing inter-VLAN routing between the 192.168.1.0 and 192.168.2.0 networks.
D.The ACL is missing a permit statement for the 192.168.2.0/24 network to allow traffic from that subnet.
AnswerB

Inbound ACLs on G0/0 inspect packets arriving from the Internet. The ACL permits only source 192.168.1.0/24, so return packets from Internet hosts with random source IPs are denied by the implicit deny, breaking connectivity for 192.168.2.0/24 hosts.

Why this answer

ACL 10 is applied inbound on GigabitEthernet0/0, which connects to the 192.168.1.0/24 LAN. When traffic from the Internet returns to hosts in the 192.168.2.0/24 network, it enters G0/0 inbound and is evaluated against ACL 10, which only permits source addresses from 192.168.1.0/24. The implicit deny at the end of the ACL then blocks all return traffic destined for 192.168.2.0/24, preventing those hosts from reaching the Internet.

Exam trap

The trap here is that candidates often assume ACLs filter outbound traffic from the local network, but Cisco tests the nuance that an inbound ACL on the WAN-facing interface filters return traffic, not the original outbound traffic.

Why the other options are wrong

A

Misunderstanding of ACL direction leads candidates to think that the implicit deny blocks any traffic leaving the interface.

C

Confusing ACL filtering with routing functionality; ACLs do not prevent the router from routing between connected subnets unless they explicitly deny the traffic on the appropriate interface and direction.

D

Candidates often try to add a permit for the source subnet of the initiating traffic, neglecting the direction of the ACL. Because the ACL is inbound on the egress interface, outbound traffic is not filtered.

593
PBQhard

You are connected to R1. The link between R1's GigabitEthernet0/0 and R2's GigabitEthernet0/0 should operate at 1 Gbps full duplex, but the interface is showing errors and only negotiating at 100 Mbps half duplex. Diagnose and fix the fault, then verify the link is stable at the correct speed and duplex.

Network Topology
Gi0/010.1.1.1/30Gi0/010.1.1.2/30Cat6 cableR1R2

Hints

  • •The interface is manually forced to 100 Mbps half duplex; check the duplex and speed configuration.
  • •Auto-negotiation requires both 'duplex' and 'speed' to be in default (no explicit command).
  • •CRC errors indicate a duplex mismatch; R2 is likely set to auto-negotiate.
A.Remove the manual speed and duplex settings on R1's GigabitEthernet0/0 with 'no speed' and 'no duplex' to allow auto-negotiation.
B.Change the duplex setting to 'full' and speed to '1000' on R1's GigabitEthernet0/0.
C.Replace the cable between R1 and R2 with a crossover cable.
D.Configure R2's GigabitEthernet0/0 with 'speed 100' and 'duplex half' to match R1's settings.
AnswerA
solution
! R1
enable
configure terminal
interface gigabitEthernet 0/0
no duplex
no speed
end
copy running-config startup-config

Why this answer

The interface was manually configured with 'duplex half' and 'speed 100', which forced the link to 100 Mbps half duplex, causing CRC errors due to duplex mismatch. The correct fix is to remove these manual settings and allow auto-negotiation, or explicitly set both sides to 'speed 1000' and 'duplex full'. Since the remote side (R2) is set to auto (default), the simplest correction is to use 'no duplex' and 'no speed' on R1 to re-enable auto-negotiation.

After the commands are applied, the interface should show 'Full-duplex, 1000Mb/s' and CRC errors should stop incrementing.

Exam trap

The exam trap is that candidates may think manually setting the correct speed and duplex is always the best approach, but they must consider the remote device's configuration. Auto-negotiation is the default and preferred method for Gigabit Ethernet; manual settings should be used consistently on both ends.

Why the other options are wrong

B

The specific factual error is that manually setting speed and duplex on one side while the other side is set to auto can lead to a mismatch; auto-negotiation is required for proper link establishment.

C

The specific factual error is that Auto-MDIX eliminates the need for crossover cables on modern interfaces; cable type is not the cause of the problem.

D

The specific factual error is that matching the incorrect settings does not achieve the desired speed and duplex; it only prevents errors at a lower performance level.

Why candidates pick the wrong answer

B

Candidates pick this because they know that 1 Gbps full duplex is the desired setting and think explicitly configuring it will fix the issue, but they overlook the importance of consistent configuration on both ends.

C

Candidates pick this because they recall that duplex mismatches can sometimes be caused by incorrect cable types, but in this scenario the cable is not the issue.

D

Candidates pick this because they think consistency between both ends is the only requirement, ignoring the performance goal of 1 Gbps full duplex.

594
MCQhard

You are verifying OSPF operation on router R1. After confirming that OSPF is configured on the correct interfaces, which command should you use next to directly check whether R1 has established a neighbor adjacency with another OSPF router?

A.show ip ospf neighbor
B.show vlan brief
C.show spanning-tree
D.show mac address-table
AnswerA

show ip ospf neighbor is the correct next step because it directly lists all OSPF neighbors, their Router IDs, interface, and the current adjacency state (such as FULL/DR or 2WAY). This command verifies that the router has successfully formed an OSPF neighbor relationship and detects any state mismatches, making it the definitive tool for OSPF adjacency troubleshooting.

Why this answer

The command show ip ospf neighbor directly displays the OSPF neighbor table, showing whether an adjacency has formed, the neighbor's Router ID, and the current state (e.g., FULL). This is the quickest verification step after confirming configurations. The other commands are unrelated to OSPF: show vlan brief displays VLAN assignments, show spanning-tree shows STP topology, and show mac address-table shows the MAC address table.

None of these provide any OSPF neighbor information and would only delay troubleshooting.

Exam trap

Avoid confusing route visibility with neighbor status; they are related but distinct concepts.

Why the other options are wrong

B

Displays VLAN port membership; irrelevant to OSPF verification.

C

Shows STP topology; does not provide OSPF neighbor status.

D

Displays the switch's MAC address table; no OSPF information.

When would these options actually be correct?

B

In a question focused on verifying VLAN configurations or troubleshooting Layer 2 connectivity issues, 'show vlan brief' would be the correct command to check if the VLANs are properly set up and operational.

C

In a different scenario where the question asks for a command to troubleshoot Layer 2 connectivity issues or to verify the status of STP on a switch, 'show spanning-tree' would be the correct answer, as it provides insights into the spanning tree status and potential issues affecting VLANs.

D

If the exam question asked about verifying MAC address learning on a switch or troubleshooting Layer 2 connectivity issues, then 'show mac address-table' would be the correct command to use in that context.

Why candidates pick the wrong answer

B

A student might think that since OSPF runs over IP, checking VLANs could be relevant if OSPF is configured on a VLAN interface (SVI). However, this command does not show OSPF-specific neighbor state or adjacency information.

C

A student might confuse STP with OSPF because both involve 'neighbor' concepts (STP has designated/root ports, OSPF has neighbor states). However, STP does not show OSPF adjacency details.

D

A student might think that since OSPF packets are encapsulated in Ethernet frames, checking the MAC table could help verify that OSPF hello packets are being received. However, the MAC table does not indicate OSPF neighbor state or adjacency formation.

595
MCQmedium

Exhibit: R1 can ping 10.1.23.2 but cannot ping 192.168.3.10 behind R3. The routing table on R1 lacks 192.168.3.0/24. What is the best next check?

A.Verify whether the remote LAN is being advertised into the routing process
B.Replace the Ethernet cable between R1 and R2
C.Change the OSPF router ID on R1 immediately
D.Disable CEF so the route can be learned
AnswerA

The symptom that R1 can ping the next-hop address 10.1.23.2 but not 192.168.3.10 indicates that reachability to the remote host is blocked at the routing layer, not the link layer. Since OSPF neighbors are up (the next hop responds), the most likely cause is that the subnet containing 192.168.3.10 is not being injected into the OSPF domain—either because there is no network statement under the OSPF process on the router that owns that LAN, because the interface is configured as passive-interface, or because an outbound distribute-list is filtering the route. Verifying the OSPF database for the 192.168.3.0/24 prefix directly confirms whether the route is being advertised.

Why this answer

Because the directly connected next router is reachable, the problem is likely missing routing information for the remote LAN. The best next check is whether R3 is advertising 192.168.3.0/24 or whether that network is present in the routing domain at all.

Exam trap

A frequent exam trap is to confuse physical connectivity with routing issues. Because R1 can ping 10.1.23.2 (likely the next-hop router), candidates might mistakenly try to fix cables or interfaces instead of checking routing advertisements. Another trap is to focus on router ID changes or disabling features like CEF, which do not affect route learning.

The key mistake is ignoring the routing table contents and assuming that reachability to the next-hop router guarantees full path reachability. This leads to wasted time and incorrect troubleshooting steps.

Why the other options are wrong

B

Replacing the Ethernet cable between R1 and R2 is unnecessary because R1 can already ping 10.1.23.2, indicating that the physical link and Layer 3 connectivity to the next-hop router are functioning correctly.

C

Changing the OSPF router ID on R1 is irrelevant here because the problem is not related to router ID conflicts or OSPF neighbor relationships but to missing route advertisements for the remote LAN.

D

Disabling CEF (Cisco Express Forwarding) will not help because CEF does not prevent routes from being learned or advertised; it only affects packet forwarding efficiency, so this option does not address the root cause.

When would these options actually be correct?

B

This would be correct in a scenario where R1 cannot ping R2's directly connected interface (e.g., 10.1.23.2) and there is evidence of physical connectivity issues, such as link lights off or interface down/down. The question would explicitly state that Layer 1/2 is suspected.

C

In a scenario where OSPF adjacencies fail to form due to duplicate router IDs, changing the router ID on one router (and restarting OSPF) would be the correct step to resolve the adjacency issue and allow route exchange.

D

In a scenario where a router has a route in the routing table but packets are not being forwarded correctly (e.g., due to CEF polarization or a CEF-related bug), disabling CEF might be a troubleshooting step to verify if CEF is causing the forwarding failure. For example, if R1 can ping 10.1.23.2 but traffic to 192.168.3.10 fails despite the route being present, disabling CEF could isolate the issue.

Why candidates pick the wrong answer

B

Candidates often jump to physical layer troubleshooting when connectivity fails, especially if they overlook that partial reachability (ping to R2 works) already rules out a cable problem. The temptation is to assume any connectivity issue could be caused by a faulty cable.

C

Candidates may think that a router ID mismatch or misconfiguration prevents route learning, but here the problem is that the route is not being advertised, not an OSPF neighbor issue.

D

Candidates may confuse CEF with routing table population, thinking that disabling CEF forces the router to use process switching and thus learn routes via routing protocols. However, CEF does not affect route learning; it only affects how packets are forwarded after routes are learned.

596
MCQmedium

A network administrator needs to configure a Cisco router to act as a DHCP server for a small LAN. The router should lease addresses from the 192.168.10.0/24 network, exclude addresses 192.168.10.1 through 192.168.10.10 for static devices, and set the default gateway to 192.168.10.1. Which command is required to exclude the static addresses from the DHCP pool?

A.ip dhcp excluded-address 192.168.10.1 192.168.10.10
B.ip dhcp pool excluded 192.168.10.1 192.168.10.10
C.exclude-address 192.168.10.1 192.168.10.10
D.ip dhcp excluded-address 192.168.10.1 255.255.255.0
AnswerA

The ip dhcp excluded-address command, entered in global configuration mode, specifies a range of addresses that the DHCP server will not assign to clients. Using the start and end addresses excludes the entire range 192.168.10.1 through 192.168.10.10, which are reserved for static devices such as the router and servers.

Why this answer

The ip dhcp excluded-address command is used in global configuration mode to prevent the DHCP server from assigning specific addresses. It takes a starting and ending IP address, and any address in that range is excluded from all DHCP pools. This is the correct way to reserve addresses for static devices like routers, servers, and printers.

Exam trap

The trap here is confusing the global excluded-address command with a pool-level command, or using a subnet mask instead of an end address.

597
Multi-Selectmedium

Which two statements accurately describe longest-prefix match?

Select 2 answers
A.The most specific matching route is preferred over broader matching routes.
B.A /24 is more specific than a /16.
C.The default route is always preferred over a matching specific route.
D.Administrative distance replaces the need for longest-prefix match.
E.A /16 is more specific than a /24.
AnswersA, B

Longest-prefix match (LPM) is the fundamental forwarding decision rule used by routers: when multiple routing table entries match a destination IP address, the router chooses the route with the longest subnet mask, because that route identifies the smallest, most precise address range. This ensures that a host route (/32) or a /26 will always beat a less specific /16 or default route, guaranteeing predictable path selection toward the most exact destination.

Why this answer

Longest-prefix match means the router prefers the most specific route that matches the destination. In plain language, if several routes could all work, the router chooses the one that describes the destination range most precisely. That is why a /25 wins over a /24, and a /24 wins over a /16, when all of them match the same destination.

This is a foundational routing rule. The wrong answers usually confuse route specificity with route-source trust or assume the default route is considered first. The two correct answers are the ones that keep the focus on specificity.

Exam trap

A frequent exam trap is assuming that the default route (0.0.0.0/0) is preferred over more specific routes. Many candidates mistakenly believe the default route is always the first choice, but in reality, it is the least specific and only used when no other matching route exists. Another trap is confusing administrative distance with longest-prefix match; administrative distance only applies when choosing between routes learned from different sources, not when selecting the most specific prefix.

Misunderstanding these concepts can lead to incorrect answers about routing behavior in Cisco devices.

Why the other options are wrong

C

Option C is incorrect because the default route is the least specific and is only used when no other matching route exists, not preferred over specific routes.

D

Option D is incorrect as administrative distance is a separate concept used to select between routes from different protocols, not to replace longest-prefix match.

E

Option E is incorrect because a /16 is less specific than a /24; the longer the prefix length, the more specific the route.

When would these options actually be correct?

C

In a question that asks about routing behavior in a scenario where a network is configured to prioritize default routes for certain traffic types, such as in a failover situation, this option could be correct. For example, if a default route is explicitly configured to take precedence over specific routes for redundancy purposes.

D

In a question that asks about route selection criteria in a routing protocol where administrative distance is the sole factor for determining route preference, this option could be correct. For example, if the question specifies that the longest-prefix match is not applicable and only administrative distance is considered, then this statement would hold true.

E

If the exam question were to ask which subnet mask is less specific in a routing context, or if it specifically stated that the context was reversed or misinterpreted, then option E could be correct. For example, a question could state, 'Which of the following is true if we consider broader ranges?'

Why candidates pick the wrong answer

C

Students may think the default route is a catch-all and thus preferred, but they forget that longest-prefix match prioritizes specificity over generality.

D

Students might confuse AD with prefix length because both influence route selection, but AD compares trustworthiness of routing sources, not specificity of prefixes.

E

Students may incorrectly associate larger subnet masks with less specificity, or they might reverse the relationship between prefix length and specificity.

598
Matchingmedium

Match each automation term to the best description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Data modeling language for structured network data

Lightweight text format for structured data exchange

Programmatic interface exposed by a system

Credential presented to authenticate or authorize a request

Why these pairings

In Ansible, a Playbook is a YAML file that defines automation tasks, making option A correct. A Module is a reusable unit of code that performs a specific task, such as managing files or installing software, matching option B. An Inventory is a list of managed nodes (hosts) that Ansible targets, aligning with option C.

A Role is a structured way to group tasks, variables, and files for reuse, which corresponds to option D. These terms are central to Ansible automation and should not be confused with data modeling languages or APIs.

Exam trap

A common mistake is confusing a Playbook with a Role: a Playbook is a top-level workflow that may use multiple Roles, while a Role is a modular collection of related configuration items.

599
Multi-Selectmedium

Which THREE of the following best describe how agentic AI is used in network automation, specifically regarding AI agents, tool-calling, and closed-loop remediation workflows?

Select 3 answers
A.AI agents can autonomously decide which network troubleshooting steps to perform and invoke appropriate tools via APIs.
B.AI agents only monitor network traffic and alert humans for any remediation actions.
C.Tool-calling in agentic AI allows the agent to execute network commands or scripts to collect data and implement changes.
D.A closed-loop remediation workflow continuously monitors network state, detects anomalies, triggers an AI agent to diagnose, and applies corrective actions automatically.
E.Closed-loop remediation always requires a human to approve each corrective action before it is executed.
AnswersA, C, D

AI agents can autonomously decide which network troubleshooting steps to perform by reasoning over available telemetry, hypotheses, and tool outputs. For example, an agent might determine that a recurring BGP flap warrants inspecting neighbor states via `show bgp summary`, then use RESTCONF to modify the `hold-time` timer and re-verify adjacency. This iterative decision-making loop—choose a diagnostic, execute via API, interpret results, and adapt—enables goal-driven troubleshooting without human prescripting of every step.

Why this answer

Options A, C, and D are correct because agentic AI in network automation involves autonomous decision-making (A), tool-calling to execute network commands or gather data (C), and closed-loop remediation that continuously monitors, diagnoses, and applies fixes automatically (D). Options B and E are incorrect because they contradict the autonomous nature of agentic AI: B describes a passive monitoring system with human-only remediation, and E states that closed-loop remediation always requires human approval, which is not true for full closed-loop automation.

Exam trap

Cisco often tests the distinction between passive monitoring and active autonomous remediation; the trap here is that candidates may confuse agentic AI with simple alerting systems, forgetting that agentic AI must include decision-making and tool execution, not just notification.

Why the other options are wrong

B

This option describes traditional monitoring systems that only alert humans, not agentic AI which takes autonomous actions. Agentic AI agents do not just alert; they actively diagnose and remediate issues.

E

Closed-loop remediation implies full automation without manual approval; requiring human approval breaks the loop and defeats the purpose of autonomous remediation. The workflow is designed to act automatically.

Why candidates pick the wrong answer

B

Students may confuse agentic AI with standard monitoring tools that generate alerts, but agentic AI goes beyond alerting to autonomous action.

E

Students might think human oversight is always required for safety, but closed-loop automation is specifically designed to operate without manual intervention.

600
Matchingmedium

Drag and drop the PDU names on the left to the correct OSI model layers on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Application Layer (Layer 7)

Transport Layer (Layer 4)

Network Layer (Layer 3)

Data Link Layer (Layer 2)

Physical Layer (Layer 1)

Why these pairings

In the OSI model, each layer processes a specific Protocol Data Unit (PDU). The Application layer (Layer 7) uses 'Message', the Transport layer (Layer 4) uses 'Segment', the Network layer (Layer 3) uses 'Packet', the Data Link layer (Layer 2) uses 'Frame', the Physical layer (Layer 1) uses 'Bit', and the Session layer (Layer 5) uses 'Data'. This pairing follows the correct OSI terminology as shown in Option A.

Exam trap

Be careful not to swap the PDU names for Transport (segment) and Network (packet). Also, remember that 'Message' is the Application layer PDU, not 'Data'.

Why candidates pick the wrong answer

B

Candidates pick this because they may confuse 'data' as a generic term for all layers or misremember the Session layer's PDU.

C

Candidates pick this because they may confuse the terms 'packet' and 'segment' or think of IP packets as segments.

D

Candidates pick this because they may think 'data' is a catch-all for upper layers or recall that Session layer sometimes handles data exchange.

Page 7

Page 8 of 20

Page 9