Courseiva

CCNA 200-301 v2 (200-301) — Questions 601–675

1450 questions total · 20pages · All types, answers revealed

Page 8

Page 9 of 20

Page 10
601
MCQhard

A network technician is troubleshooting a router-on-a-stick configuration. R1 has sub-interface G0/0.10 with encapsulation dot1q 10 and IP 192.168.10.1/24, and sub-interface G0/0.20 with encapsulation dot1q 20 and IP 192.168.20.1/24. Hosts in VLAN 10 cannot reach hosts in VLAN 20. The physical interface G0/0 is up and no shutdown. Both sub-interfaces show up/up. What should the technician do next?

A.Verify the switch port connected to R1 is configured as a trunk and allows VLANs 10 and 20.
B.Verify the encapsulation dot1Q numbers on the sub-interfaces match the VLAN assignments.
C.Verify the default gateway settings on hosts in VLANs 10 and 20.
D.Check the physical interface G0/0 for interface errors or duplex mismatches.
AnswerA

This directly addresses the most probable cause: a missing or misconfigured trunk on the switch side. Even with router sub-interfaces up/up, the link must be a trunk carrying the correct VLANs for inter-VLAN routing to function.

Why this answer

The router-on-a-stick configuration requires the switch port connecting to R1 to be configured as a trunk port that permits VLANs 10 and 20. Even though the router sub-interfaces are correctly configured with encapsulation dot1q and IP addresses, if the switch port is in access mode or does not allow the specific VLANs, frames from VLAN 10 or 20 will be dropped by the switch, preventing inter-VLAN routing. The next logical step is to verify the switch port configuration with commands like 'show interfaces trunk' or 'show running-config interface <port>'.

Exam trap

Cisco often tests the misconception that as long as the router sub-interfaces are up/up and have correct encapsulation, inter-VLAN routing should work, leading candidates to overlook the switch trunk configuration as the root cause.

Why the other options are wrong

B

Candidates may think the encapsulation numbers might be swapped, but the stem confirms they are correctly assigned to the respective VLAN IDs.

C

Many candidates jump to end-host configuration, assuming the router is fully reachable because interfaces are up/up, but the trunk is the prerequisite for any communication between VLANs.

D

Candidates might think any communication loss warrants a physical layer check, but here the symptoms point strongly toward a Layer 2 trunking issue.

602
PBQhard

You are connected to R1. The network currently uses a static default route pointing to ISP1 (198.51.100.1) via GigabitEthernet0/0. However, the backup link to ISP2 (203.0.113.1) via Serial0/0/0 has a floating static default route with an administrative distance of 130. The backup route is not taking over when the primary link fails. Configure the floating static route correctly so that it becomes active when the primary route is lost, and verify that the routing table shows the backup default route with the appropriate next-hop.

Network Topology
G0/0198.51.100.2/30198.51.100.1S0/0/0203.0.113.2/30203.0.113.1R1ISP1ISP2

Hints

  • •Examine the primary static route configuration for any unusual keywords.
  • •A static route with the 'permanent' keyword remains in the routing table even if the interface goes down.
  • •The floating static route has a higher AD (130) so it will only be used when the primary route is absent.
A.Remove the primary static route and reconfigure it without the 'permanent' keyword, then verify the backup route appears in the routing table.
B.Change the administrative distance of the floating static route to 1 so it is preferred over the primary route.
C.Add the 'permanent' keyword to the floating static route to ensure it remains in the routing table.
D.Configure a static route with a next-hop of 203.0.113.1 and an administrative distance of 130, but also add the 'track' command to monitor the primary link.
AnswerA
solution
! R1
conf t
no ip route 0.0.0.0 0.0.0.0 198.51.100.1 permanent
ip route 0.0.0.0 0.0.0.0 198.51.100.1
end

Why this answer

The primary static default route was configured with the 'permanent' keyword, which keeps the route in the routing table even when the GigabitEthernet0/0 interface goes down. This prevents the floating static route (AD 130) from becoming active. The solution is to remove the primary route (no ip route 0.0.0.0 0.0.0.0 198.51.100.1 permanent) and reconfigure it without the 'permanent' keyword.

After that, when the primary link fails, the route is removed, and the backup route (AD 130) enters the routing table. Option A is correct. Option B would make the backup preferred over the primary, which is not the intended behavior.

Option C (adding permanent to the backup) would not help and could cause issues. Option D (track) is an alternative but not the required configuration here.

Exam trap

Be careful: The 'permanent' keyword on a static route keeps it in the routing table even if the interface is down. This can prevent floating static routes from becoming active. Always check for 'permanent' when troubleshooting backup route issues.

Why the other options are wrong

B

The specific factual error: Administrative distance determines route preference; a lower AD is preferred. Setting the backup to AD 1 would make it the primary route, not a backup.

C

The specific factual error: The 'permanent' keyword prevents route removal when the interface goes down, which is not the solution here. The backup route needs to become active when the primary fails, not be forced to stay.

D

The specific factual error: The track command is used to conditionally remove a static route based on reachability, but it is not necessary if the primary route is correctly configured without 'permanent'. The existing backup route should work once the primary route is removed.

Why candidates pick the wrong answer

B

Candidates might think lowering the AD will force the backup to be used, but they overlook that it would then always be preferred, not just during failure.

C

Candidates may think 'permanent' makes routes more reliable, but they misunderstand its effect on route removal during interface failure.

D

Candidates may think tracking is required for floating static routes to work, but in this scenario the primary route's 'permanent' keyword is the issue.

603
MCQhard

Based on the exhibit, what is the most likely reason the PPP link is down?

A.The serial interfaces use different encapsulations.
B.PPP requires CAPWAP on both routers.
C.The routers must run BGP before PPP can establish.
D.Serial links can use only OSPF, not PPP.
AnswerA

PPP and HDLC are distinct Layer 2 encapsulation protocols for serial WAN links. Cisco default is HDLC; if one end is configured with encapsulation ppp and the other remains HDLC, the link cannot negotiate LCP or exchange frames, so the line protocol stays down. This mismatch is the most likely cause because the physical layer (Layer 1) is up but the data link cannot establish.

Why this answer

The PPP link is down because the two ends are configured for different encapsulations. In practical terms, one side is using PPP and the other is using HDLC, so the devices are not speaking the same data-link protocol on the serial link. Until those encapsulations match, the link cannot come up correctly at the data-link layer.

This is a classic WAN troubleshooting pattern that fits well into simulation-style exam coverage.

Exam trap

A frequent exam trap is to assume that routing protocols such as BGP or OSPF must be configured before a PPP link can establish, or that PPP requires additional protocols like CAPWAP. This is incorrect because PPP operates at Layer 2 and must first establish the data link before any routing protocol can function. Another common mistake is to believe that serial links cannot use PPP and only support OSPF or other routing protocols, which confuses encapsulation with routing.

The key is to recognize that mismatched encapsulation protocols like PPP versus HDLC prevent the link from coming up, regardless of routing configuration.

Why the other options are wrong

B

Incorrect because CAPWAP is a wireless protocol unrelated to serial link encapsulation. PPP does not require CAPWAP for operation on serial interfaces.

C

Incorrect because routing protocols like BGP are Layer 3 protocols and do not affect the Layer 2 establishment of a PPP link. The link must be up before routing protocols can run.

D

Incorrect because serial links can use PPP encapsulation. Cisco routers default to HDLC, but PPP is a supported and common WAN encapsulation protocol.

When would these options actually be correct?

B

In a different question scenario where the context involves wireless access points and their management, stating that 'PPP requires CAPWAP on both routers' could be correct if the question specifically addresses the need for CAPWAP to manage PPP connections in a wireless environment.

C

In a different scenario where the question specifies that a PPP connection is being used to transport BGP routing information between two routers, and the exam asks about prerequisites for establishing that connection, this option could be correct if it stated that BGP must be configured first.

D

In a different scenario where the question specifies that only OSPF is allowed for routing over serial links, this option would be correct. For example, if the exam question stated that the network design mandates OSPF exclusively for serial connections, then this answer would be valid.

Why candidates pick the wrong answer

B

Students might confuse CAPWAP with other control protocols or think that PPP requires some form of control protocol to operate, but PPP's control is handled by LCP and NCP, not CAPWAP.

C

Some students might think that because BGP is often used over serial links, it must be required for PPP to work. However, PPP can operate with any Layer 3 protocol, including static routes, OSPF, or no routing at all.

D

Students might think that because OSPF is commonly used on serial links, it is the only option. However, OSPF is a routing protocol, not an encapsulation, and PPP is a valid and widely used encapsulation for serial links.

604
MCQhard

An engineer is deploying a new Cisco Catalyst 9300 switch in a campus wiring closet. The uplink to the distribution switch uses a 1000BASE-LX SFP module. After connecting the fiber, the interface shows 'up/up' but the engineer notices that the 'input errors' counter is incrementing rapidly, with many CRC errors, runts, and giants being reported. What is the most likely cause of these input errors?

A.Replace the SFP with a 1000BASE-SX module.
B.Check the fiber distance and ensure it is within the 5 km limit for 1000BASE-LX; if over, use a single-mode fiber extender.
C.Configure the interface with 'speed 100' and 'duplex full' to match the SFP capabilities.
D.Replace the fiber patch cable with a CAT6a copper cable and use a 1000BASE-T SFP.
AnswerB

1000BASE-LX SFP modules are rated for a maximum distance of 5km over single-mode fiber using 1310nm light. If the actual fiber distance exceeds this, the received optical signal power falls below the receiver sensitivity, producing bit errors and CRC errors on the interface. The correct action is to verify the link distance and either use a fiber extender/repeater or upgrade to a longer-reach optic such as 1000BASE-ZX (up to 70km) to regain a positive link budget.

Why this answer

The 1000BASE-LX standard uses long-wavelength laser optics (1300 nm) over single-mode fiber with a maximum distance of 5 km. Exceeding this limit causes signal attenuation and dispersion, generating bit errors that corrupt the frame check sequence (FCS). Cisco IOS counts these as CRC errors.

Runts (frames shorter than 64 bytes) and giants (frames longer than 1518 bytes) also appear because the damaged frames are misinterpreted. Option B correctly identifies the distance limit as the root cause and recommends verifying it or using a fiber extender. Options A and D propose incorrect media, and option C would break the link since 1000BASE-LX operates at fixed 1000/full speed.

Exam trap

Learners often misdiagnose runts and giants as a duplex mismatch, but when CRC errors are present alongside them, the issue is a physical-layer impairment—such as excessive fiber distance—rather than a configuration error.

Why the other options are wrong

A

1000BASE-SX uses multimode fiber with a maximum 550 m distance, which is far shorter than 1000BASE-LX and would not resolve a distance issue.

C

The SFP is fixed at 1000 Mbps full-duplex; manually setting 'speed 100' and 'duplex full' would cause a speed mismatch and prevent the link from coming up.

D

Copper cabling (CAT6a) and a 1000BASE-T SFP are limited to 100 m and cannot solve a fiber distance problem.

Why candidates pick the wrong answer

A

Students may confuse SX and LX, thinking that SX is a common fix for fiber issues, or they may assume that any SFP will work on any fiber. However, SX is for multimode, while LX is for single-mode, and the question implies single-mode fiber is in use.

C

Students often associate input errors with speed/duplex mismatches, which is a common cause on copper interfaces. However, on fiber, speed is fixed, and duplex is always full, so this is not applicable.

D

Students might think that copper is more reliable or that changing media type can fix errors, but the problem is specific to fiber distance limitations.

605
MCQhard

Which switch security feature uses DHCP snooping bindings to validate ARP packets and help stop ARP spoofing?

A.PortFast
B.Dynamic ARP Inspection
C.UDLD
D.HSRP preemption
AnswerB

Dynamic ARP Inspection (DAI) validates ARP packets in a VLAN by cross-referencing the sender IP and MAC address against the DHCP snooping binding table, which is built from DHCP message exchanges. DAI intercepts all ARP requests and replies on untrusted interfaces and drops any packet whose IP-to-MAC mapping is not present or valid in that table. This direct reliance on DHCP snooping bindings is the precise mechanism that mitigates ARP spoofing, making DAI the correct answer.

Why this answer

Dynamic ARP Inspection compares ARP information to trusted bindings, often learned through DHCP snooping, to block forged ARP packets.

Exam trap

A common exam trap is selecting PortFast, UDLD, or HSRP preemption as the answer because these features are well-known switch security or stability mechanisms. However, PortFast only speeds up STP port transitions and does not inspect ARP packets. UDLD focuses on detecting unidirectional links and does not validate ARP traffic.

HSRP preemption deals with gateway redundancy and has no role in ARP security. The key to avoiding this trap is recognizing that only Dynamic ARP Inspection uses DHCP snooping bindings to validate ARP packets and stop ARP spoofing.

Why the other options are wrong

A

PortFast is a feature that allows switch ports to bypass the usual STP listening and learning states to quickly transition to forwarding. It does not perform any ARP packet validation or security checks, so it cannot prevent ARP spoofing.

C

UDLD (Unidirectional Link Detection) is designed to detect and disable unidirectional links between switches to prevent network loops or blackholes. It does not inspect or validate ARP packets and thus does not stop ARP spoofing.

D

HSRP preemption is a feature related to first-hop redundancy protocols that allows a higher priority router to take over as the active gateway. It does not provide any ARP packet validation or protection against ARP spoofing.

When would these options actually be correct?

A

If the question asked about features that enhance the speed of port activation or reduce network downtime during link changes, PortFast would be the correct answer. For example, a question might ask which feature enables faster connectivity for end devices in a network.

C

If the question asked about a feature that detects and mitigates unidirectional links or loops in a network, such as 'Which feature helps identify unidirectional links to prevent network issues?', then UDLD would be the correct answer.

D

If the question asked about features related to router redundancy and failover mechanisms, specifically in the context of HSRP, then HSRP preemption would be the correct answer. For example, a question could ask which feature allows a backup router to regain active status when it becomes the highest priority router.

Why candidates pick the wrong answer

A

Students might confuse PortFast with security features because it is often enabled on access ports for faster connectivity, but its purpose is unrelated to ARP validation.

C

UDLD sounds like a security feature because it detects link issues, but its focus is on physical layer problems, not ARP validation.

D

Students might associate HSRP with security because it provides redundancy, but preemption is about router role assignment, not ARP validation.

606
MCQmedium

A network technician is troubleshooting a connectivity issue between two hosts on different subnets. During the analysis, the technician captures packets and observes that the data link layer frames are being stripped and rebuilt at each router hop. Which layer of the OSI model is responsible for encapsulating the original data into segments before transmission from the source host?

A.Network layer
B.Transport layer
C.Data Link layer
D.Application layer
AnswerB

The Transport layer is the exact location where upper-layer application data is broken into smaller units and a transport header is appended, producing TCP segments or UDP datagrams. It manages end-to-end communications, including flow control and reliability, using port numbers and, in TCP, sequence and acknowledgment numbers. This segmentation function is the defining responsibility of Layer 4.

Why this answer

The Transport layer (Layer 4) is responsible for encapsulating the original data into segments. Protocols such as TCP (RFC 793) or UDP (RFC 768) add a header containing source and destination port numbers, sequence numbers, and other control information to form a segment. This segmentation occurs at the source host before the data is passed down to the Network layer for routing.

Exam trap

Cisco often tests the distinction between encapsulation layers by describing a Layer 2 behavior (frame stripping/rebuilding) in the scenario to mislead candidates into selecting the Data Link layer, when the question specifically asks about the layer that creates segments at the source host.

Why the other options are wrong

A

The Network layer (Layer 3) encapsulates segments into packets and adds logical addressing (IP addresses) for routing across networks, but it does not perform the initial segmentation of data into segments.

C

The Data Link layer (Layer 2) encapsulates packets into frames and adds physical addressing (MAC addresses) for delivery on a local network segment, but it does not perform segmentation of data into segments.

D

The Application layer (Layer 7) provides the interface for applications to generate data, but it does not perform segmentation or encapsulation into segments. Segmentation occurs at the Transport layer.

Why candidates pick the wrong answer

A

Students often confuse the Network layer with the Transport layer because both deal with addressing and encapsulation, but the Network layer works with packets, not segments.

C

Since the question mentions frames being stripped and rebuilt at each router hop, students might mistakenly think the Data Link layer is responsible for the initial segmentation, but that is the Transport layer's role.

D

Students may think that because applications generate data, the Application layer is responsible for all encapsulation, but the OSI model assigns segmentation to the Transport layer.

607
MCQeasy

What metric does RIP use to choose the best path?

A.Bandwidth
B.Cost
C.Hop count
D.Delay
AnswerC

RIP (Routing Information Protocol) uses hop count as its sole metric, which is the number of routers (hops) a packet must traverse to reach the destination network. Each router that forwards the packet increments the hop count, and RIP considers a route with the fewest hops as the best path, regardless of link speed or reliability. This simple metric is why RIP is suitable for small networks but can choose suboptimal paths in larger, more complex topologies.

Why this answer

RIP uses hop count as its metric. Lower hop count paths are preferred, up to the protocol maximum of 15 usable hops.

Exam trap

Don't confuse RIP's hop count metric with metrics used by other protocols like OSPF or EIGRP.

Why the other options are wrong

A

RIP does not use bandwidth as a metric; it relies solely on hop count. Bandwidth is used by EIGRP in its composite metric calculation, not by RIP.

B

Cost is the metric used by OSPF, not RIP. RIP uses hop count as its sole metric, making cost an incorrect choice for this question.

D

Delay is not a metric used by RIP; RIP only considers hop count. Delay is a component in the EIGRP composite metric, but not in RIP.

When would these options actually be correct?

A

If the question were about a routing protocol that uses bandwidth as a metric, such as Enhanced Interior Gateway Routing Protocol (EIGRP), then 'bandwidth' would be the correct answer. For example, a question could ask, 'Which metric does EIGRP use to determine the best path?'

B

If the question asked about a routing protocol that uses cost as its metric, such as OSPF or EIGRP, then 'Cost' would be the correct answer. For example, 'What metric does OSPF use to choose the best path?' would make this option valid.

D

If the question asked which metric is used by a routing protocol that considers performance factors such as latency, then 'Delay' would be the correct answer. For example, a question about OSPF or EIGRP, which can factor in delay as part of their metric calculations, would make this option valid.

Why candidates pick the wrong answer

A

Students may confuse RIP with other dynamic routing protocols like EIGRP or OSPF that consider bandwidth, leading them to think RIP also uses bandwidth.

B

The term 'cost' is a generic routing metric term, and students might mistakenly associate it with RIP without knowing that OSPF specifically uses cost based on bandwidth.

D

Delay is a common factor in network performance, and students might think RIP includes it as a metric, confusing RIP with more advanced protocols like EIGRP.

608
MCQhard

An IP phone connected to switch port Gi0/4 is working and receiving calls, but the PC connected to the phone's data port cannot obtain an IP address. The technician confirms that interface Gi0/4 has switchport mode access and shows switchport access vlan 10 and switchport voice vlan 100. What should the technician do next?

A.Verify the DHCP scope for VLAN 10 on the DHCP server.
B.Verify that CDP is enabled on the IP phone.
C.Verify the QoS trust state on the switch port.
D.Verify the IP phone's passthrough mode for the PC port.
AnswerD

The IP phone acts as a switch; if the phone's PC port is not configured to pass traffic untagged on the correct VLAN (passthrough mode), the PC's frames will be dropped or placed in the wrong VLAN. Checking this setting directly addresses the path from PC to switch.

Why this answer

The PC connected to the IP phone's data port cannot obtain an IP address because the phone's internal switch (passthrough mode) is likely not forwarding traffic from the PC port to the upstream switch. The switch port is correctly configured with access VLAN 10 for data and voice VLAN 100 for voice, so the issue is not with the switch configuration but with the phone's ability to pass data traffic. Verifying the IP phone's passthrough mode ensures the PC port is enabled and forwarding frames to the switch.

Exam trap

Cisco often tests the misconception that a working phone implies all features are functional, but the PC port is a separate logical path that can be independently disabled or misconfigured.

Why the other options are wrong

A

Assumes the switch port configuration alone guarantees proper VLAN delivery to the PC, ignoring the phone's role as a transparent bridge.

B

Confuses the mechanism for voice VLAN assignment with the requirement for data passthrough; CDP's role is only for the phone's own voice VLAN, not for the PC's data VLAN.

C

Misapplies QoS as a potential cause for a connectivity issue; it is a quality-of-service feature and does not block DHCP or initial network access.

609
Matchingmedium

Match each operations or assurance technology to its most accurate purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Centralized event and message reporting

Monitoring and management information exchange

Visibility into traffic flows and conversations

Clock synchronization for consistent timing

Why these pairings

Each technology serves a specific assurance purpose: Syslog provides centralized event and message reporting, SNMP enables monitoring and management information exchange, NetFlow offers visibility into traffic flows and conversations, and NTP ensures clock synchronization for consistent timing across network devices.

Exam trap

Be careful not to confuse the functions of NetFlow (flow analysis) and IP SLA (performance measurement), or SNMP (management) and Syslog (logging). Also, remember that SPAN is for local mirroring and RSPAN for remote mirroring; the 'R' stands for remote.

When would these options actually be correct?

B

This option would be correct if the question asked to match technologies with their opposites or if the definitions were intentionally swapped (e.g., 'Which option has all mappings reversed?').

C

If the question asked to match technologies with purposes in a reversed or scrambled order where Syslog is used for flow analysis (e.g., in a hypothetical scenario where Syslog captures flow data) and IP SLA for device management (e.g., managing device configurations), then this option could be correct.

D

If the question were 'Match each technology to its secondary or less common purpose' where NetFlow is used for performance baselining and IP SLA for traffic flow analysis in a specific vendor implementation, this option could be correct.

Why candidates pick the wrong answer

B

Candidates may confuse the purposes of NetFlow and SNMP, or misremember that SNMP can be used for traffic monitoring, leading them to swap the two.

C

Candidates may confuse the functions of Syslog and NetFlow, or misremember that SPAN is for remote mirroring, leading to a plausible but incorrect matching.

D

Candidates may confuse the purposes of NetFlow and IP SLA because both can be used for network monitoring and troubleshooting, leading to swapping their primary functions.

610
MCQeasy

Which OSI layer is responsible for end-to-end segmentation, port numbers, and reliability functions such as acknowledgments?

A.Network
B.Data Link
C.Transport
D.Session
AnswerC

At the transport layer, protocols such as TCP and UDP perform end-to-end segmentation, breaking application data into segments that can be reassembled at the destination. The transport header carries source and destination port numbers, which identify the specific application processes at each end of the communication session. TCP also adds reliability mechanisms like sequencing and acknowledgments, making it the definitive layer for this function.

Why this answer

The Transport layer (Layer 4) is responsible for end-to-end segmentation, port numbers for identifying applications, and reliability functions like acknowledgments and retransmission. The Network layer (Layer 3) handles logical addressing and routing between networks. The Data Link layer (Layer 2) manages local frame delivery and error detection.

The Session layer (Layer 5) controls dialog management and synchronization, not segmentation or ports.

Exam trap

Don't confuse the Transport Layer's end-to-end functions with the Network Layer's routing or the Data Link Layer's local communication roles.

Why the other options are wrong

A

The Network layer provides logical addressing and routing, not end-to-end segmentation or port numbers.

B

The Data Link layer handles local frame delivery and error detection, not end-to-end reliability or port numbers.

D

The Session layer manages dialog control and synchronization, not segmentation, port numbers, or reliability acknowledgments.

When would these options actually be correct?

A

If the question asked which OSI layer is responsible for logical addressing and routing of packets across networks, the correct answer would be Network. This would focus on the functions of the Network layer in facilitating communication between different devices on separate networks.

B

If the question asked about the layer responsible for framing, MAC addressing, and physical addressing in a local network context, then the Data Link layer would be the correct answer, as it manages these functions between directly connected devices.

D

If the question asked which OSI layer is responsible for managing sessions and maintaining communication between applications, then the correct answer would be the Session layer, as it focuses on the control and management of ongoing sessions.

Why candidates pick the wrong answer

A

Students often confuse the network layer with the transport layer because both deal with end-to-end delivery, but the network layer focuses on path determination and addressing, not on reliability or port numbers.

B

Since the data link layer provides error detection (e.g., CRC), some students might mistakenly think it also handles reliability functions like acknowledgments, but those are transport layer functions.

D

Because the session layer deals with managing communication sessions, some students might incorrectly associate it with reliability functions, but those are handled by the transport layer.

611
MCQhard

A network engineer notices that an NMS at 10.1.1.200 cannot poll a router that has SNMPv2c configured with community string 'public'. What is causing this issue?

A.SNMPv2c is not enabled on the router.
B.The SNMP community 'public' has an access list that only permits host 10.1.1.100.
C.The NMS is using the wrong community string.
D.The router's SNMP agent is not listening on the interface facing 10.1.1.200.
AnswerB

The community string 'public' has an access control list applied that restricts source addresses to 10.1.1.100 only. When the NMS at 10.1.1.200 sends an SNMP poll, the router checks the source IP against the ACL bound to the community string; because 10.1.1.200 is not permitted, the router silently discards the request. This explains why the NMS receives no response, even though the community string matches and the SNMP agent is running.

Why this answer

SNMPv2c community strings can be restricted by an access control list (ACL) that specifies which source IP addresses are allowed to poll the router. If the ACL only permits host 10.1.1.100, then the NMS at 10.1.1.200 will be denied access even though the community string 'public' is correct. This is a common configuration for security, but it prevents polling from unauthorized hosts.

Exam trap

Cisco often tests the misconception that SNMP community strings are the only authentication mechanism, leading candidates to overlook the ACL restriction that can silently block polling from specific hosts.

Why the other options are wrong

A

Many believe SNMP requires an additional global command to start; on Cisco IOS, a community string entry enables the agent.

C

Polling failures are often attributed to community string errors, but when the string matches, an ACL restriction produces identical symptoms.

D

Candidates may assume the agent must be bound to an interface, but Cisco IOS SNMP agents respond on any interface unless limited by an ACL or VRF.

612
MCQeasy

A network technician is connecting a new access switch to an existing distribution switch. The access switch will carry multiple VLANs. The technician wants to ensure that the link becomes a trunk automatically if the other side is set to desirable mode. Which command should be configured on the access switch port?

A.switchport mode dynamic auto
B.switchport mode dynamic desirable
C.switchport mode access
D.switchport nonegotiate
AnswerA

Dynamic auto mode allows the port to become a trunk if the other side initiates trunking. If the distribution switch is set to desirable mode, it will actively attempt to form a trunk, and the access switch port in dynamic auto mode will respond and become a trunk. This meets the requirement of automatic trunk formation.

Why this answer

The switchport mode dynamic auto command places the port in a passive trunking state where it will become a trunk if the other side actively negotiates. When the distribution switch is set to dynamic desirable, it will initiate trunking, and the access switch will respond. This allows the link to form a trunk automatically without manual intervention.

Exam trap

The trap here is confusing dynamic auto with dynamic desirable, or thinking that nonegotiate still allows automatic trunking.

613
Multi-Selectmedium

Which two statements accurately describe JSON arrays?

Select 2 answers
A.A JSON array is an ordered list of items.
B.A JSON array is typically enclosed in square brackets.
C.A JSON array is the same thing as an OSPF area.
D.A JSON array must always contain exactly one item.
E.A JSON array replaces the need for all keys in structured data.
AnswersA, B

A JSON array is an ordered list of items because the sequence of elements is preserved and can be accessed by a zero-based index. This ordering is fundamental to how arrays represent collections, allowing operations such as iteration, sorting, and indexing in the exact sequence they were defined.

Why this answer

JSON arrays are ordered lists enclosed in square brackets. In plain language, they are commonly used when an API needs to return multiple similar items such as interfaces, VLANs, or routes. Each element in the array might be a simple value or a more complex object. Arrays are therefore a normal structure for lists in automation and API payloads.

The wrong answers usually confuse arrays with objects or claim properties they do not have. The two correct answers are the ones that preserve the ideas of list structure and square-bracket notation.

Exam trap

A frequent exam trap is mistaking JSON arrays for networking concepts like OSPF areas or assuming they must contain exactly one item. Candidates might confuse arrays with objects or routing constructs, leading to incorrect answers. Another pitfall is thinking arrays replace keys in structured data, which is false because arrays and keys serve different purposes.

This confusion arises from mixing data structure syntax with network protocol terminology. Understanding that JSON arrays are simply ordered lists enclosed in square brackets helps avoid these traps and ensures clarity when working with automation payloads in Cisco environments.

Why the other options are wrong

C

Option C is incorrect because JSON arrays are data structures for organizing information, whereas OSPF areas are routing domains; they are unrelated concepts in networking and automation.

D

Option D is incorrect because JSON arrays can contain any number of items, including zero or many, not just exactly one item; this flexibility is important in API responses and configurations.

E

Option E is incorrect because arrays do not replace keys; keys are used in JSON objects to define named values, while arrays represent ordered collections without keys.

When would these options actually be correct?

C

If the exam question asked about the relationship between data structures and networking concepts, and specifically inquired about how different data structures can be represented in networking configurations, then this option could be correct in a context where OSPF areas are represented in a JSON format.

D

In a hypothetical exam question that states, 'What is the minimum number of items required in a JSON array for it to be considered valid?' the correct answer could be 'one item,' making option D correct in that context.

E

In a different question asking about data representation methods, if the context involves discussing how JSON can simplify data structures by using arrays instead of objects, one might argue that arrays can reduce the need for keys in certain scenarios, such as when dealing with homogeneous data types.

Why candidates pick the wrong answer

C

A student might confuse the term 'array' with 'area' due to similar spelling, or mistakenly think that JSON arrays are used in OSPF configuration. However, OSPF areas are defined using network statements, not JSON.

D

A student might think arrays always have multiple items, but the requirement of 'exactly one' is a misinterpretation. They may confuse arrays with single-value objects or think that arrays are only used when there is more than one item.

E

A student might think that because arrays can hold multiple values, they eliminate the need for keys. However, keys are essential for labeling data, and arrays are just one way to structure data within JSON.

614
MCQeasy

A network administrator is configuring a Cisco switch. The switch has a management VLAN 99 with IP address 10.10.99.5/24 and default gateway 10.10.99.1. The administrator wants to verify that the switch can reach a server at 10.10.99.100. Which command should be used on the switch to test reachability?

A.show ip route
B.show ip interface brief
C.traceroute 10.10.99.100
D.ping 10.10.99.100
AnswerD

The ping command on a Cisco switch sends ICMP echo requests to the specified IP address and reports replies, directly testing reachability. Since the switch has an IP address in the same subnet as the server, the ping will be sourced from VLAN 99 interface and should succeed if connectivity exists. This is the standard method to verify Layer 3 connectivity from a switch.

Why this answer

To verify reachability to a specific IP address from a Cisco switch, the ping command is the correct tool. It sends ICMP echo requests and waits for replies, providing immediate feedback on whether the destination is reachable. Other commands like show ip interface brief or show ip route only display configuration or routing information and do not test actual connectivity.

Exam trap

The trap here is confusing the display of routing or interface information with an active connectivity test.

615
MCQmedium

A network team wants centralized logging and also wants log timestamps from different devices to line up accurately. Which combination best supports that goal?

A.Syslog and NTP
B.DHCP and STP
C.PAT and EtherChannel
D.ARP and CDP
AnswerA

Syslog is the standard protocol for sending event messages to a central log server, enabling consolidated monitoring and troubleshooting. NTP synchronizes clocks across all networked devices, ensuring that log timestamps are consistent and can be accurately correlated during forensic analysis. Together, they form the foundational pair for centralized logging with reliable time alignment.

Why this answer

The right combination is Syslog plus NTP. In plain language, Syslog gives the team a central place to collect and review device messages, while NTP makes sure the timestamps on those messages are consistent across the network. Centralized logs are useful on their own, but without synchronized clocks, incident timelines can become confusing and misleading.

This pairing is a common operational best practice. Syslog handles the collection side, and NTP handles the time-correlation side. Other services such as DHCP, STP, or NAT do not solve this combination of requirements. The best answer is the one that recognizes that centralized logging and time synchronization are complementary, not competing, services.

Exam trap

Don't confuse network management protocols like DHCP or NAT with logging and time synchronization functions.

Why the other options are wrong

B

DHCP dynamically assigns IP addresses and STP prevents loops in Layer 2 networks; neither provides centralized logging or time synchronization. Without NTP, timestamps from different devices would not align, making log correlation impossible.

C

PAT (a form of NAT) translates private IP addresses to public ones, and EtherChannel bundles multiple links for redundancy and bandwidth; neither offers centralized logging or time synchronization. These technologies are unrelated to the goal.

D

ARP resolves IP addresses to MAC addresses, and CDP discovers directly connected Cisco devices; neither provides centralized logging or time synchronization. These protocols are for neighbor discovery and Layer 2 resolution, not for log management.

When would these options actually be correct?

B

If the question were about ensuring devices on a network receive IP addresses and maintain loop-free connectivity, then a question asking for protocols that support network stability and address assignment could make this option correct.

C

In a scenario where the question asks about optimizing bandwidth and managing multiple IP addresses for a group of devices, a question could focus on load balancing and IP address management, making PAT and EtherChannel the correct answer.

D

If the exam question asked about enhancing network device discovery and neighbor information sharing, then ARP and CDP could be the correct answer. For example, a question focused on improving network topology visibility would make this option valid.

Why candidates pick the wrong answer

B

Students might think DHCP and STP are fundamental network services that could somehow contribute to logging or time accuracy, but they serve completely different purposes and do not address the requirements.

C

Test-takers might confuse PAT with logging due to the term 'address translation' or think EtherChannel's link aggregation could help with log transport, but they do not provide the required functionality.

D

Students might think CDP's device discovery could help identify logging sources or that ARP is involved in network communication for logs, but they do not fulfill the specific requirements of centralized logging and accurate timestamps.

616
PBQhard

You are connected to R1. The network has R1, R2, and a multilayer switch MLS1. Configure IPv4 and IPv6 addressing on R1's interfaces so that R1 can ping both R2 (198.51.100.2) and MLS1 (203.0.113.2) via IPv4. Additionally, configure IPv6 on G0/1 using EUI-64 with prefix 2001:db8:1::/64 and verify that R1 can ping the IPv6 address of MLS1 (2001:db8:1::2). The current configuration has incorrect subnet masks and missing IPv6 settings, causing reachability failures.

Hints

  • •The subnet mask on both interfaces is too large; it should be /30.
  • •IPv6 is not enabled on G0/1 yet; use the 'ipv6 address' command with EUI-64.
  • •After changing the mask, the ping should work because the devices will be on the same subnet.
A.Change the subnet mask on G0/0 to 255.255.255.252, change G0/1 to 255.255.255.252, then configure IPv6 on G0/1 with the EUI-64 address using the prefix 2001:db8:1::/64.
B.Change the subnet mask on G0/0 to 255.255.255.0, change G0/1 to 255.255.255.0, then configure IPv6 on G0/1 with the EUI-64 address using the prefix 2001:db8:1::/64.
C.Change the subnet mask on G0/0 to 255.255.255.252, change G0/1 to 255.255.255.252, then configure IPv6 on G0/1 with the static address 2001:db8:1::1/64.
D.Change the subnet mask on G0/0 to 255.255.255.252, change G0/1 to 255.255.255.252, then configure IPv6 on G0/1 with the EUI-64 address using the prefix 2001:db8:1::/32.
AnswerA
solution
! R1
interface GigabitEthernet0/0
ip address 198.51.100.1 255.255.255.252
exit
interface GigabitEthernet0/1
ip address 203.0.113.1 255.255.255.252
ipv6 address 2001:db8:1::/64 eui-64
exit

Why this answer

The interfaces on R1 were configured with subnet masks that were not /30, which is required for these point-to-point links. With an incorrect mask, R1 does not consider the neighboring IPs (198.51.100.2 and 203.0.113.2) as directly connected, preventing ARP resolution and IPv4 reachability. Additionally, IPv6 was missing on G0/1.

To fix, change the subnet mask on G0/0 to 255.255.255.252, change G0/1 to 255.255.255.252, then configure IPv6 on G0/1 with the EUI-64 address using the prefix 2001:db8:1::/64. After these changes, pings succeed.

Exam trap

This question tests your understanding of subnet masks and their impact on Layer 3 reachability. A common trap is to focus only on IPv6 and forget that incorrect IPv4 subnet masks can prevent ARP resolution, even if IPv6 is configured correctly. Also, pay close attention to the exact requirements: EUI-64 and the correct prefix length.

Why the other options are wrong

B

The specific factual error is that /24 masks are too large for point-to-point links and do not match the expected subnets for R2 and MLS1.

C

The specific factual error is that the IPv6 address should be configured with the EUI-64 keyword, not a static address.

D

The specific factual error is that the prefix length must be /64 as specified in the question; a /32 prefix is incorrect for this scenario.

Why candidates pick the wrong answer

B

Candidates might think that keeping the /24 mask is fine because they are focusing only on IPv6, or they may not realize that the /24 mask causes R1 to believe the remote addresses are on different subnets.

C

Candidates might think that any IPv6 address in the same subnet will work, or they may be more comfortable with static addressing and overlook the EUI-64 requirement.

D

Candidates might confuse the prefix length with the network prefix or think that a shorter prefix is acceptable, not realizing that EUI-64 requires a /64 prefix.

617
MCQhard

R1 and R2 are directly connected and running OSPF. They can ping each other, the area matches, and the timers match, but they still do not become neighbors. What is the most likely cause?

A.The OSPF authentication keys do not match.
B.The subnet mask is too small for OSPF to operate.
C.The routers must use different process IDs.
D.The interfaces must be configured as switch trunks.
AnswerA

This is the correct cause. In OSPF, if MD5 authentication is enabled but the configured authentication keys (or key IDs) do not match between the two routers, all OSPF hello packets are silently dropped. The routers remain reachable at Layer 3 via ping because IP forwarding does not depend on OSPF authentication, but they will never form a neighbor adjacency or exchange routing information.

Why this answer

The most likely cause is a mismatch in OSPF authentication keys. Even though the routers have IP connectivity, matching area IDs, and identical timers, OSPF adjacency requires that authentication parameters also match. If authentication is enabled on both sides but the keys differ, OSPF packets are silently rejected, preventing neighbor formation.

Exam trap

A frequent exam trap is to overlook OSPF authentication mismatches when routers have IP connectivity and matching area IDs. Candidates may incorrectly assume that because the routers can ping each other and timers match, adjacency must form. However, if OSPF authentication keys differ, routers silently reject OSPF packets, preventing neighbor formation.

This trap exploits the misconception that IP reachability alone ensures OSPF adjacency, ignoring the critical role of matching authentication parameters in the OSPF neighbor negotiation process.

Why the other options are wrong

B

This is incorrect because OSPF operates normally on /30 subnets commonly used for point-to-point links. Subnet mask size does not prevent OSPF adjacency.

C

This is incorrect because OSPF process IDs are locally significant identifiers and do not need to match between routers to form neighbors.

D

This is incorrect because OSPF runs over routed interfaces and does not require interfaces to be configured as switch trunks, which are used for VLAN tagging.

When would these options actually be correct?

B

In a different scenario where the question states that R1 and R2 are configured with OSPF but are on different subnets due to a misconfigured subnet mask, leading to a lack of reachability, this option would be correct. For example, if R1 is on 192.168.1.0/30 and R2 is on 192.168.1.4/30, they cannot form an OSPF neighbor relationship.

C

In a different scenario, if the question stated that R1 and R2 are in the same area but have different OSPF process IDs, then this option would be correct, as OSPF routers must have the same process ID to form a neighbor relationship.

D

In a different scenario where the question specifies that R1 and R2 are connected via a switch and need to establish OSPF over multiple VLANs, the interfaces would need to be configured as switch trunks to allow OSPF traffic across those VLANs. If the trunking is misconfigured, OSPF neighbors would not form.

Why candidates pick the wrong answer

B

Students may confuse OSPF's requirement for matching subnet masks on the same link (which is true for OSPF network type broadcast) with the mask being too small. However, a /30 mask is perfectly valid and commonly used for point-to-point links.

C

Students often confuse OSPF process IDs with EIGRP autonomous system numbers, which must match. This leads to the mistaken belief that OSPF process IDs must also match.

D

Some students may think that OSPF requires trunking because they have seen OSPF configured on VLAN interfaces or subinterfaces, but that is different from configuring a physical interface as a trunk port.

618
MCQhard

A switchport on one side of a link is configured as a trunk, but the peer side is configured as an access port. The physical link is up, but VLAN traffic behaves unexpectedly. What is the most likely cause?

A.The two ends disagree on whether the link is a trunk or an access port.
B.The switches must both use the same hostname.
C.The native VLAN must be set to 1 on both sides first.
D.The ports need OSPF enabled.
AnswerA

A switchport in trunk mode encapsulates frames with 802.1Q tags and expects to receive tagged frames, while an access port transmits and receives only untagged frames in a single VLAN. When one end is a trunk and the other is an access port, the access port will drop tagged frames or treat them as invalid, and the trunk port may not accept the untagged frames sent by the access side. This role mismatch prevents proper VLAN segmentation and causes the link to fail at Layer 2.

Why this answer

The most likely cause is a switchport mode mismatch. In practical terms, one side expects the link to carry multiple VLANs with tagging behavior, while the other side treats it as a normal one-VLAN endpoint-style access connection. The physical interface can still come up, but the two ends do not agree on how the traffic should be handled.

This is a classic Layer 2 troubleshooting pattern. The link may not be fully down, but the configuration disagreement causes logical forwarding problems.

Exam trap

Be cautious of assuming all VLAN issues are due to allowed lists or STP. Consider mode mismatches when the link is physically up but traffic is disrupted.

Why the other options are wrong

B

OSPF is a Layer 3 routing protocol used for exchanging routes between routers, not for resolving Layer 2 switchport mismatches. This issue is purely about trunk/access configuration, which is unrelated to OSPF.

C

While native VLAN mismatch can cause issues on a trunk link, the primary problem here is that one side is configured as access, not trunk. Even if native VLAN is set to 1 on both sides, the access port will still not process tagged frames correctly.

D

Hostnames are purely for identification and have no impact on switchport operation or VLAN tagging. The trunk/access mismatch is a Layer 2 configuration issue independent of hostnames.

When would these options actually be correct?

B

In a different scenario where a question asks about the importance of hostname consistency for management or monitoring purposes in a network, option B could be correct. For example, if the exam question focused on network management tools that rely on hostname resolution, having the same hostname could be crucial.

C

In a different question, if the scenario involved two switches configured as trunks but with different native VLANs, then specifying that the native VLAN must be set to 1 on both sides could be correct. This would be relevant if the question focused on ensuring consistent native VLAN settings for proper communication.

D

In a different scenario where the question asks about routing protocols and their necessity for inter-VLAN communication, option D could be correct if the exam context involves enabling OSPF on interfaces to facilitate routing between VLANs across different switches.

Why candidates pick the wrong answer

B

Students may confuse Layer 2 and Layer 3 concepts, thinking that enabling a routing protocol could fix connectivity issues. However, OSPF has no effect on VLAN tagging or trunk negotiation.

C

Native VLAN is a common source of trunk problems, so test-takers may focus on that detail. However, the root cause is the trunk/access role mismatch, not the native VLAN value.

D

Some students might think that matching hostnames is required for switch interoperability, but this is incorrect. Hostnames are only used for CLI identification and logging.

619
MCQmedium

A switch port and a host NIC have a duplex mismatch. Which symptom is most likely?

A.Increased late collisions and poor performance
B.Incorrect VLAN tagging on trunks
C.OSPF area mismatch errors
D.A change in the subnet mask on the host
AnswerA

A duplex mismatch occurs when one side of an Ethernet link runs full-duplex while the other runs half-duplex. The half-duplex side fails to sense the full-duplex side's transmission, so both transmit simultaneously, producing late collisions after the 64-byte collision window. These late collisions corrupt frames, forcing retransmissions that degrade throughput, increase latency, and cause poor performance.

Why this answer

A duplex mismatch often causes collisions, frame errors, and degraded throughput, especially on the half-duplex side. It is a classic physical/link layer performance problem.

Exam trap

Don't confuse duplex mismatch symptoms with total connectivity loss or latency-only issues; focus on error and collision symptoms.

Why the other options are wrong

B

VLAN tagging on trunks is a Layer 2 function that deals with VLAN identification using 802.1Q tags. Duplex mismatch is a physical-layer issue affecting how data is sent and received (simultaneous vs. one direction at a time) and has no impact on VLAN tagging.

C

OSPF area mismatch errors are Layer 3 routing protocol issues that prevent OSPF neighbors from forming. Duplex mismatch is a Layer 1/2 problem that affects frame delivery and collision detection, not routing protocol adjacency.

D

A change in subnet mask is a Layer 3 IP configuration change that affects network/host identification. Duplex mismatch is a physical-layer issue and does not alter IP addressing or subnet masks.

When would these options actually be correct?

B

In a scenario where a question asks about VLAN tagging issues on a trunk link, specifically mentioning misconfigured VLANs or mismatched VLAN IDs between switches, option B would be the correct answer. This could involve a situation where traffic is being incorrectly tagged due to VLAN misconfigurations.

C

If the question were about OSPF configuration issues, such as identifying the cause of routing problems in a network with multiple OSPF areas, then an option mentioning OSPF area mismatch errors would be correct. For example, a question could ask what symptoms indicate a misconfigured OSPF area in a multi-area setup.

D

In a question about network configuration issues, if it asks about the effects of modifying the subnet mask on a host's ability to communicate with other devices, option D would be correct if it leads to communication failures due to incorrect subnetting.

Why candidates pick the wrong answer

B

Students might confuse 'mismatch' in general, thinking any mismatch (duplex or VLAN) causes similar symptoms. However, VLAN tagging errors lead to connectivity issues within specific VLANs, not collisions.

C

Both involve mismatches, and students might think any mismatch causes performance problems. However, OSPF area mismatches result in routing table incompleteness, not collisions.

D

Students might think that any misconfiguration (duplex or subnet) leads to poor performance. However, subnet mask changes cause reachability issues, not collisions.

620
Multi-Selectmedium

Which TWO interface errors are most likely caused by a mismatch in duplex settings between two connected switches?

Select 2 answers
A.Runts
B.Giants
C.CRC errors
D.Input errors
E.Output errors
F.Flaps
AnswersA, C

Runts are Ethernet frames smaller than the minimum 64-byte size, and they are a classic symptom of duplex mismatch. When one end operates at half duplex and the other at full duplex, the half-duplex end may sense a collision (or late collision) and abort its transmission prematurely, leaving a truncated frame that the full-duplex receiver counts as a runt. Thus, a high rate of runts on an interface strongly suggests that the peer is running at a different duplex setting than the local switch port.

Why this answer

A duplex mismatch occurs when one switch operates at full duplex while the other operates at half duplex. On the half-duplex side, frames arriving while the interface is transmitting are considered collisions, causing the frame to be truncated into fragments (runts). On the full-duplex side, the switch does not detect collisions but may receive incomplete frames, which are counted as runts if they are less than 64 bytes.

CRC errors also spike because the truncated or corrupted frames fail the Frame Check Sequence (FCS) validation.

Exam trap

Cisco often tests the distinction between runts and giants, where candidates mistakenly think giants are caused by duplex mismatch, but giants are actually linked to jumbo frames or faulty hardware, not duplex negotiation issues.

Why the other options are wrong

B

Giants are frames exceeding the maximum size (typically 1518 bytes) and are caused by MTU misconfiguration, faulty NICs, or software errors, not by duplex mismatch. Duplex mismatch does not affect frame size; it causes collisions and CRC errors.

D

Input errors is a broad counter that includes runts, CRC errors, frame errors, and others. While duplex mismatch can contribute to some input errors, it is not a specific error type. The question asks for 'interface errors' most likely caused by duplex mismatch, and input errors is too generic.

E

Output errors include collisions, late collisions, and underruns. While collisions can occur due to duplex mismatch, output errors are not exclusively caused by duplex mismatch; they can result from other issues like cable faults or interface congestion. The question asks for errors 'most likely' caused by duplex mismatch, and runts and CRC errors are more directly linked.

F

Flaps refer to an interface repeatedly going up and down, typically due to physical layer issues like loose cables, faulty transceivers, or power fluctuations. Duplex mismatch does not cause interface flaps; it causes errors on the link but the interface remains up.

Why candidates pick the wrong answer

B

Students might confuse giants with runts, thinking both are size-related errors caused by duplex issues. However, giants are associated with oversized frames, not collisions.

D

Since runts and CRC errors are input errors, a test-taker might think 'input errors' is a direct answer. However, the question expects specific error types, not a category.

E

Collisions are a known symptom of duplex mismatch, and collisions are counted as output errors. However, the presence of collisions alone does not make 'output errors' the best answer, as the question requires two specific errors.

F

Students might think that any interface problem is a 'flap', but flaps are specifically about link state changes, not error counters. The term 'flap' is often misused in casual conversation.

621
MCQhard

A network administrator configures OSPF on two routers, R1 and R2, connected via their Serial0/0/0 interfaces (IP addresses 10.1.1.1/30 and 10.1.1.2/30). They verify that both routers use the same OSPF process ID and area 0, but R1's 'show ip ospf neighbor' shows no adjacencies. Given the partial exhibit from R1, what is the most likely cause of the adjacency failure and its correct solution?

A.Configure 'no passive-interface Serial0/0/0' under router ospf 1 on R1.
B.Replace the network statement with 'network 10.1.1.0 0.0.0.255 area 0' to cover a larger range.
C.Change the OSPF process ID on R1 to match R2, using 'router ospf 100' and re-entering the network command.
D.Issue 'clear ip ospf process' on R1 to restart OSPF and reattempt neighbor discovery.
AnswerA

In OSPF, the passive-interface command suppresses both outgoing and incoming Hello packets on the specified interface, so no neighbor relationship can be established on that link. Because Serial0/0/0 has been marked passive under the OSPF process, R1 never sends or processes Hellos even though the network statement includes that IP. Issuing no passive-interface Serial0/0/0 in router configuration mode re-enables Hello traffic on exactly that interface, allowing R1 and R2 to form a full OSPF adjacency. This is the only option that directly addresses the root cause of the missing neighbor.

Why this answer

The most likely cause is that R1's Serial0/0/0 interface is configured as a passive interface under OSPF. When an interface is set as passive, OSPF does not send Hello packets out of it, preventing neighbor discovery and adjacency formation. The solution is to use the 'no passive-interface Serial0/0/0' command under router ospf 1 on R1, which allows Hello packets to be transmitted and the adjacency to establish.

Exam trap

Cisco often tests the misconception that OSPF process IDs must match between routers, leading candidates to choose option C, when in fact process IDs are locally significant and only area IDs and authentication must match.

Why the other options are wrong

B

A larger wildcard mask does not override the passive-interface setting; adjacency still fails.

C

Adjacency depends on area and authentication, not on the router-local process ID; passive-interface is the real issue.

D

The root cause is a configuration that blocks hellos, not a transient state; the reset is ineffective.

622
Multi-Selectmedium

Which TWO statements correctly describe the configuration and effect of Root Guard and BPDU Guard on a Cisco switch?

Select 2 answers
A.Root Guard is configured on a per-port basis and causes the port to become root-inconsistent if a superior BPDU is received.
B.BPDU Guard prevents loops by disabling a trunk port that receives a BPDU from an unauthorized switch.
C.Root Guard places a port in errdisable state when a superior BPDU is received.
D.BPDU Guard is commonly enabled on ports where PortFast is configured to prevent unexpected BPDUs from causing a bridging loop.
E.Both Root Guard and BPDU Guard filter BPDUs to prevent them from being processed by the switch CPU.
AnswersA, D

Root Guard is configured per interface, usually on designated ports, to enforce the current root bridge location. When a port receives a superior BPDU, Root Guard changes the port to a root-inconsistent state, which is a blocking state for all traffic. This prevents an unauthorized switch from taking over as root, and the port resumes normal forwarding automatically after the superior BPDUs cease. It does not require errdisable or manual recovery, as it is not a security violation.

Why this answer

Root Guard is configured per interface using the 'spanning-tree guard root' command. When a port with Root Guard enabled receives a superior BPDU (one that would cause the switch to become a non-root bridge), the port is placed into a root-inconsistent state, effectively blocking traffic on that port and preventing the switch from accepting a new root bridge from that direction. This protects the spanning-tree topology from unauthorized or misconfigured switches attempting to become the root bridge.

Option D is correct because BPDU Guard is commonly enabled on ports with PortFast (typically access ports connected to end devices). When a BPDU is received on such a port, BPDU Guard places the port into errdisable state, preventing potential bridging loops that could result from an unauthorized switch connecting to the network. Option B is incorrect because BPDU Guard does not prevent loops by disabling a trunk port; it is typically used on access ports (often with PortFast) and disables the port upon receiving any BPDU, not just on trunk ports.

Option C is incorrect because Root Guard places the port into root-inconsistent state (not errdisable) when a superior BPDU is received; BPDU Guard uses errdisable. Option E is incorrect because neither Root Guard nor BPDU Guard filters BPDUs; Root Guard reacts to superior BPDUs by blocking the port, and BPDU Guard reacts to any BPDU by disabling the port. Both features allow BPDUs to be processed but then take action based on the received BPDUs.

Exam trap

Cisco often tests the distinction between the states triggered by Root Guard (root-inconsistent) versus BPDU Guard (errdisable), and candidates frequently confuse the two, assuming both place the port into errdisable or that Root Guard uses errdisable.

Why the other options are wrong

B

BPDU Guard does not prevent loops by disabling a trunk port; it is typically used on access ports with PortFast and disables the port upon receiving any BPDU.

C

Root Guard places the port into root-inconsistent state, not errdisable; errdisable is the state used by BPDU Guard.

E

Neither Root Guard nor BPDU Guard filters BPDUs; they both process received BPDUs and then take action (root-inconsistent for Root Guard, errdisable for BPDU Guard).

Why candidates pick the wrong answer

B

Students may confuse BPDU Guard with Loop Guard because both deal with BPDUs and loop prevention. The mention of 'trunk port' and 'unauthorized switch' might lead them to think BPDU Guard is used on trunks, but BPDU Guard is specifically for access ports.

C

Both Root Guard and BPDU Guard react to BPDUs, and students may mistakenly think both use errdisable. The term 'errdisable' is commonly associated with port security violations, so it's easy to confuse with Root Guard's action.

E

The word 'Guard' might imply protection by filtering, and students may think both features prevent BPDUs from reaching the CPU. However, they are reactive mechanisms, not filters. BPDU Filter is a separate feature that actually prevents BPDU transmission and reception.

623
Multi-Selectmedium

Which TWO statements accurately describe OSPFv3 configuration and verification for IPv6?

Select 2 answers
A.OSPFv3 uses IPv6 link-local addresses for neighbor discovery and next-hop addresses.
B.The 'network' command under 'ipv6 router ospf' is used to advertise subnets into OSPFv3.
C.The 'ipv6 ospf <process-id> area <area-id>' command is used to enable OSPFv3 on an interface.
D.The 'ipv6 router ospf <process-id>' command is used on an interface to enable OSPFv3.
E.The 'show ipv6 ospf neighbor' command displays the OSPFv3 link-state database.
AnswersA, C

OSPFv3 routers build neighbor adjacencies and exchange hello packets using their IPv6 link-local addresses, so those addresses appear as the neighbor address and as the next hop for routes learned from that neighbor. On point-to-point and broadcast links, the link-local address is always used for forwarding to an adjacent router, even if global unicast addresses are also configured on the interface. This design lets OSPFv3 operate without depending on IPv4-mapped global addresses and avoids renumbering issues.

Why this answer

OSPFv3 uses IPv6 link-local addresses for neighbor discovery and next-hop addresses. Option C is correct because the 'ipv6 ospf <process-id> area <area-id>' interface command enables OSPFv3 on that interface. Option B is incorrect: OSPFv3 does not use the 'network' command; instead, it relies on interface-level configuration.

Option D is incorrect: 'ipv6 router ospf <process-id>' is a global configuration command to enter OSPFv3 router configuration mode, not an interface command. Option E is incorrect: 'show ipv6 ospf neighbor' displays neighbor adjacencies, not the link-state database; use 'show ipv6 ospf database' for that.

Exam trap

Cisco often tests the misconception that OSPFv3 uses the same 'network' command as OSPFv2, when in fact OSPFv3 requires interface-level configuration with the 'ipv6 ospf <process-id> area <area-id>' command.

Why the other options are wrong

D

'ipv6 router ospf <process-id>' is a global configuration command, not an interface command; enabling OSPFv3 on an interface requires the 'ipv6 ospf <process-id> area <area-id>' command.

E

'show ipv6 ospf neighbor' displays OSPFv3 neighbor adjacencies, not the link-state database; to view the LSDB, use 'show ipv6 ospf database'.

Why candidates pick the wrong answer

B

Students familiar with OSPFv2 may mistakenly think the 'network' command also applies to OSPFv3, but OSPFv3 uses a different configuration model.

D

The command name includes 'router ospf', which might lead students to think it is used on interfaces, but it is actually a global command.

E

Students may confuse 'neighbor' with 'database' because both are OSPF show commands, but they serve different purposes.

624
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure IPv4 and IPv6 static routes, a default route, and a floating static route with a higher administrative distance, then verify with show ip route and show ipv6 route.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order for configuring static routes as described is: first enter global configuration mode, then configure IPv4 static routes, then IPv6 static routes, then the default route and floating static route with higher AD, and finally verify with show commands. This sequence ensures that specific routes are configured before the default route and that IPv4 routes precede IPv6 routes as implied by the stem. Only option A follows this order; options B, C, and D deviate by placing the default/floating route before specific routes or configuring IPv6 before IPv4.

Exam trap

Do not confuse the order of configuration with the order of route preference. The default route is not configured first; it is configured after specific routes. Also, while IPv4 and IPv6 can be configured in any order, the question expects IPv4 before IPv6 based on the stem.

Why candidates pick the wrong answer

B

Candidates might think default routes are configured first because they are 'default', but the order in configuration does not affect functionality; however, best practice is to configure specific routes first.

C

Candidates might think IPv6 should be configured first because it is newer or because they want to emphasize IPv6, but the standard practice is to configure IPv4 first.

D

Candidates might be confused about the order of default routes and IPv6, leading them to choose this option as a mix of plausible but incorrect steps.

625
PBQhard

You are connected to SW1. A LACP EtherChannel between SW1 and SW2 has already been configured using interfaces GigabitEthernet0/1 and GigabitEthernet0/2 with channel-group 1 mode active on both sides and assigned to VLAN 100. However, the channel is not forming because of a speed/duplex mismatch. The correct interface settings for this network are speed 1000 and duplex full. Interface GigabitEthernet0/1 is already configured with these settings. Only interface GigabitEthernet0/2 needs to be corrected. Identify the configuration change needed to resolve the mismatch and verify the EtherChannel is up with 'show etherchannel summary'.

Network Topology
Gi0/1Gi0/1EtherChannelSW1SW2

Hints

  • •Check the speed and duplex settings on both member interfaces.
  • •LACP requires all ports in the channel to have identical configuration.
  • •Use the 'show interfaces status' command to quickly see speed/duplex mismatches.
A.Configure interface GigabitEthernet0/2 with 'speed 1000' and 'duplex full', then verify the EtherChannel is up.
B.Configure interface GigabitEthernet0/1 with 'speed 100' and 'duplex half', then verify the EtherChannel is up.
C.Configure interface GigabitEthernet0/2 with 'speed auto' and 'duplex auto', then verify the EtherChannel is up.
D.Configure interface GigabitEthernet0/2 with 'channel-group 1 mode active' and 'switchport access vlan 100', then verify the EtherChannel is up.
AnswerA
solution
! SW1
interface GigabitEthernet0/2
speed 1000
duplex full
end
show etherchannel summary

Why this answer

The EtherChannel is not forming because GigabitEthernet0/2 is configured with speed 100 and duplex half, while GigabitEthernet0/1 is speed 1000 and duplex full. LACP requires all member ports to have identical speed and duplex settings. To fix this, configure GigabitEthernet0/2 with speed 1000 and duplex full, matching GigabitEthernet0/1.

After correction, the ports should bundle in Port-channel1 and show as bundled (P) in 'show etherchannel summary'.

Exam trap

The trap is that candidates may overlook the speed/duplex mismatch and focus only on the LACP mode or VLAN configuration. Always verify that all physical parameters match before troubleshooting EtherChannel formation.

Why the other options are wrong

B

The specific factual error is that the question implies the correct configuration should use speed 1000 and duplex full, not downgrade to 100/half. Also, LACP requires identical settings, but the goal is to match the higher speed.

C

The specific factual error is that auto-negotiation does not guarantee matching settings when one side is manually configured. The mismatch would persist.

D

The specific factual error is that the question explicitly states a speed/duplex mismatch prevents the channel from forming, and this option does not correct that mismatch.

Why candidates pick the wrong answer

B

Candidates might think that making both ports match is sufficient, regardless of the speed/duplex values, but they overlook that the intended configuration is speed 1000/full.

C

Candidates might think 'auto' is a safe default that will negotiate correctly, but they forget that the other port is statically configured, leading to potential mismatch.

D

Candidates might focus on the LACP configuration and VLAN assignment, forgetting that speed/duplex consistency is a prerequisite for EtherChannel formation.

626
PBQhard

You are connected to a multilayer switch SW1 via console. SW1 has an IP phone and an access point connected to interfaces GigabitEthernet0/1 and GigabitEthernet0/2 respectively. Configure the access ports so that the IP phone receives a voice VLAN (VLAN 110) and PoE priority critical, and the access point receives PoE priority high. Verify your configuration using show interfaces switchport and show power inline.

Network Topology
G0/1G0/2SW1IP PhoneAccess Point

Hints

  • •Voice VLAN is configured under the access port interface with the 'switchport voice vlan' command.
  • •PoE priority is set per interface using 'power inline priority'.
  • •Use 'show interfaces switchport' to verify voice VLAN assignment.
A.interface GigabitEthernet0/1 switchport mode access switchport access vlan 10 switchport voice vlan 110 power inline priority critical ! interface GigabitEthernet0/2 switchport mode access power inline priority high
B.interface GigabitEthernet0/1 switchport mode trunk switchport trunk allowed vlan 10,110 power inline priority critical ! interface GigabitEthernet0/2 switchport mode access power inline priority high
C.interface GigabitEthernet0/1 switchport mode access switchport access vlan 110 switchport voice vlan 10 power inline priority critical ! interface GigabitEthernet0/2 switchport mode access power inline priority high
D.interface GigabitEthernet0/1 switchport mode access switchport access vlan 10 switchport voice vlan 110 power inline priority high ! interface GigabitEthernet0/2 switchport mode access power inline priority critical
AnswerA
solution
! SW1
interface GigabitEthernet0/1
switchport voice vlan 110
power inline priority critical
exit
interface GigabitEthernet0/2
power inline priority high
end

Why this answer

The IP phone requires a voice VLAN configured with the switchport voice vlan command. PoE priority is set per interface using power inline priority. For the phone, the priority is critical; for the AP, it is high.

Verification with show interfaces switchport confirms voice VLAN, and show power inline shows priority settings.

Exam trap

The exam trap is mixing up the voice VLAN and access VLAN assignments, or confusing PoE priority levels. Remember that the voice VLAN is configured with switchport voice vlan, not as the access VLAN. Also, note that IP phones typically use access ports with voice VLAN, not trunks.

PoE priority critical is reserved for critical devices like phones, while high is for other important devices like APs.

Why the other options are wrong

B

The specific factual error is using trunk mode for an IP phone port instead of access mode with voice VLAN.

C

The specific factual error is reversing the VLAN assignments: the access VLAN should be data, and the voice VLAN should be voice.

D

The specific factual error is swapping the PoE priority values: the phone should be critical, the AP high.

Why candidates pick the wrong answer

B

Candidates might think that because the phone uses two VLANs (data and voice), a trunk is required, but Cisco IP phones use CDP to negotiate the voice VLAN on an access port.

C

Candidates may confuse which VLAN is for data and which is for voice, especially if the question does not specify the data VLAN number.

D

Candidates might assume the AP needs higher priority because it serves multiple clients, but the question explicitly states the phone gets critical.

627
MCQhard

Refer to the exhibit. A network engineer expects SW1 to be the root bridge for VLAN 1, but the show spanning-tree vlan 1 output on SW2 shows that SW2 is the root. What is the most likely cause of this issue?

A.SW1 is configured with a priority of 32769 but has a higher MAC address than SW2.
B.Spanning tree is disabled on SW1 for VLAN 1.
C.SW1 has a bridge priority of 4096, but BPDU guard is configured on SW2's port to SW1, causing the port to be err-disabled.
D.The trunk link between SW1 and SW2 is down.
AnswerD

The missing root port and the fact that SW2 sees itself as root confirm that SW2 is not receiving any BPDUs from SW1. This is exactly the behavior when the inter-switch trunk is physically down, breaking the spanning-tree topology.

Why this answer

If the trunk link between SW1 and SW2 is down, SW2 will not receive BPDUs from SW1. Without BPDUs, SW2 assumes it is the root bridge for VLAN 1 (since every switch defaults to root for its own VLANs). This explains why SW2's show spanning-tree output shows itself as root, even if SW1 has a lower bridge priority.

Exam trap

Cisco often tests the misconception that a lower priority always guarantees root bridge status, but the trap here is that a failed link prevents BPDU exchange, causing the switch with the higher bridge ID to become root by default.

Why the other options are wrong

A

Candidates focus on the matching priority numbers and overlook the missing root port that indicates a complete loss of BPDUs.

B

Candidates may assume no BPDUs means STP is off, but the intended root designation suggests STP is on and a physical disconnect is the primary suspect.

C

Candidates recall that BPDU guard can block ports, but they fail to differentiate between a missing port due to err-disable and a missing port due to a physically down link, which looks identical in this output.

628
PBQhard

You are connected to R1, a Cisco IOS-XE router acting as the network's DNS client. The network uses a local DNS server at 203.0.113.10 for internal name resolution. Users report that the hostname 'fileserver.courseiva.local' cannot be resolved, while other names work fine. Diagnose and fix the DNS resolution failure so that 'fileserver.courseiva.local' resolves correctly.

Network Topology
G0/010.0.0.1/30G0/010.0.0.2/30linkG0/010.0.0.2/30203.0.113.10/24linkR2R1DNS Server

Hints

  • •Check if the DNS server is reachable and if other names resolve.
  • •The NXDOMAIN status means the domain name does not exist in the DNS zone.
  • •The router configuration appears correct; the problem is on the DNS server.
A.Add an A record for 'fileserver' on the DNS server.
B.Configure the 'ip domain-lookup' command on R1 to enable DNS resolution.
C.Change the DNS server address on R1 to 8.8.8.8.
D.Add a static host entry on R1 using 'ip host fileserver.courseiva.local 192.0.2.10'.
AnswerA
solution
! R1

Why this answer

The DNS server is reachable (ping successful) and resolves other names (e.g., webserver.courseiva.local) correctly. However, 'fileserver.courseiva.local' returns NXDOMAIN, indicating the A record is missing from the DNS zone. Since the router is not the DNS server, the fix must be applied on the DNS server itself — not on R1.

The candidate should understand that the problem is a missing DNS record, not a router configuration issue. The solution involves adding an A record for 'fileserver' (with the appropriate IP address) on the DNS server. On R1, verify connectivity to the DNS server and confirm that the domain lookup and name-server settings are correct, which they are.

No router CLI changes are needed.

Exam trap

Candidates often confuse client-side DNS configuration issues with server-side record problems. Remember: if some names resolve but others don't, the DNS server is reachable and functional; the missing record is the culprit. Do not change router settings unnecessarily.

Why the other options are wrong

B

The specific factual error is that 'ip domain-lookup' is a global command that enables DNS resolution; if it were disabled, no names would resolve.

C

The specific factual error is that the DNS server is functioning for other records; the problem is specific to one hostname, not the server address.

D

The specific factual error is that static entries bypass DNS but do not address the root cause; the DNS server should have the record for all clients.

Why candidates pick the wrong answer

B

Candidates may think the router's DNS client is misconfigured, but the symptom of partial resolution points to a server-side issue.

C

Candidates might assume the DNS server is faulty and try a public DNS server, but that would not resolve internal names and is unnecessary.

D

Candidates may see this as a quick fix on the router, but the question asks to 'diagnose and fix' the DNS resolution failure, implying a proper solution on the DNS server.

629
Multi-Selectmedium

Which two statements accurately describe a controller-based WLAN compared with a set of independently managed APs?

Select 2 answers
A.It centralizes management and policy across multiple access points.
B.It can improve consistency when deploying WLAN settings across many APs.
C.It removes the need for access points entirely.
D.It replaces the need for DHCP on all client devices.
E.It is the same thing as WPA3.
AnswersA, B

In a controller-based WLAN, the controller (WLC) acts as the central point for enforcing security policies, QoS, access control lists, and radio parameters across all attached access points. This centralized model gives administrators a single interface to apply and manage network-wide policies, rather than configuring each AP individually, which is a fundamental architectural benefit over autonomous AP deployments.

Why this answer

A controller-based WLAN centralizes operational control and helps apply policies more consistently across many APs. In practical terms, this improves scalability and reduces the burden of touching each AP individually when changes are needed. The APs still provide the radio service, but they are coordinated under a shared management model.

This question is about architecture, not about claiming that a controller replaces APs or that it removes all other network services.

Exam trap

A common exam trap is assuming that a controller-based WLAN eliminates the need for access points or other network services like DHCP. Some candidates mistakenly believe the controller replaces APs entirely, but APs remain essential for providing wireless connectivity. Others confuse controller-based management with wireless security protocols such as WPA3, which are unrelated concepts.

Misunderstanding these distinctions can lead to incorrect answers by conflating architecture roles with security features or network services.

Why the other options are wrong

C

Option C is incorrect because access points are still required to provide the actual wireless radio connectivity; the controller does not replace APs.

D

Option D is incorrect since DHCP or other IP configuration methods are still needed for client devices; the controller does not replace these network services.

E

Option E is incorrect because WPA3 is a wireless security standard and does not relate to the architectural concept of controller-based WLAN management.

When would these options actually be correct?

C

If the exam question stated that a specific wireless technology or architecture eliminated the need for physical access points in a theoretical scenario, such as a fully integrated mesh network solution that operates without traditional APs, then this option could be correct.

D

In a scenario where the question asks about a theoretical network architecture that utilizes a different technology, such as a completely virtualized WLAN solution that operates without traditional access points, this option could be correct.

E

In a question asking about the relationship between WLAN security protocols and access point management, if it stated that a certain security standard (like WPA3) could replace the need for physical access points in a theoretical scenario, this option could be correct.

Why candidates pick the wrong answer

C

The term 'controller-based' might lead some to think the controller handles all wireless functions, but APs are still needed for the actual RF communication.

D

Students might confuse the controller's ability to provide IP addresses via DHCP proxy or internal DHCP server with eliminating the need for DHCP entirely, but DHCP remains essential for IP address assignment.

E

Both terms involve wireless networking, and students might mistakenly associate 'controller' with security or think that WPA3 requires a controller, but they are independent technologies.

630
Multi-Selecthard

Which two practices most improve safety when automating network changes? (Choose two.)

Select 2 answers
A.Testing changes in a lab or staging environment first
B.Running scripts directly in production without validation
C.Using version control and peer review for automation code
D.Disabling backups so changes apply faster
AnswersA, C

Testing changes in a lab or staging environment first isolates automation from production traffic, allowing you to validate syntax, reachability, and expected behavior before they impact live services. This reduces the blast radius of a faulty script by catching errors in a controlled environment where failures are reversible. Staging also lets you verify rollback procedures and confirm that the change aligns with the intended network policy without risking production availability.

Why this answer

Testing and validation reduce risk before wide deployment, and version control with review/rollback supports controlled operations.

Exam trap

Avoid assuming that immediate deployment without testing is safe. Always prioritize testing and controlled deployments.

Why the other options are wrong

B

Running scripts directly in production without validation bypasses all safety checks, increasing the likelihood of misconfigurations that can cause outages or security breaches. This practice directly contradicts the principle of minimizing risk during network changes.

D

Disabling backups removes the ability to restore the network to a known good state after a failed change, significantly increasing risk. Backups are a fundamental safety net, and disabling them for speed is never justified.

When would these options actually be correct?

B

In a hypothetical exam question focused on rapid deployment in a highly controlled environment, where the candidate is asked about scenarios with minimal risk due to extensive monitoring and rollback capabilities, this option could be seen as acceptable.

D

In a hypothetical exam scenario focused on rapid deployment in a highly controlled environment, a question might ask about optimizing change processes where backups are managed separately and not needed for immediate rollback. In this case, disabling backups could be deemed acceptable for speed under strict conditions.

Why candidates pick the wrong answer

B

Students might think that running scripts directly is faster and more efficient, especially in urgent situations. However, they overlook the high potential for catastrophic errors that could have been prevented with proper testing.

D

A student might incorrectly assume that disabling backups speeds up the change process and that backups are unnecessary if the change is simple. However, this ignores the reality that even simple changes can have unforeseen consequences.

631
PBQhard

You are connected to SW1. Two switches, SW1 and SW2, are connected via four GigabitEthernet links. Configure LACP EtherChannel between them using interfaces GigabitEthernet0/1 through GigabitEthernet0/4 on SW1. Set the channel-group mode to active on SW1. The port-channel interface must be configured as a trunk, allowing VLANs 10, 20, 30. However, the EtherChannel is not forming. The current configuration is shown below. Identify and fix the issue, then verify the EtherChannel is operational.

Network Topology
Gi0/1-4Gi0/1-44x linksSW1SW2

Hints

  • •Compare the Layer 2/Layer 3 status of the port-channel interface with the member interfaces.
  • •Check the 'show etherchannel summary' flags: 'SD' means Layer 3 and down; 'SU' means Layer 2 and up.
  • •The port-channel interface must match the operational mode (Layer 2) of the member switchports.
A.Remove 'no switchport' and IP address from Port-channel1, then configure 'switchport mode trunk' and 'switchport trunk allowed vlan 10,20,30'.
B.Change the channel-group mode on the member interfaces from active to passive.
C.Add the 'switchport nonegotiate' command to the member interfaces.
D.Configure the member interfaces with 'channel-group 1 mode on' instead of active.
AnswerA
solution
! SW1
interface Port-channel1
no ip address 192.168.1.1 255.255.255.0
no no switchport
switchport mode trunk
switchport trunk allowed vlan 10,20,30

Why this answer

The EtherChannel is not forming because the Port-channel1 interface is configured as a Layer 3 interface (no switchport, IP address), while the member interfaces are Layer 2 switchports (switchport mode trunk). This mismatch prevents the channel from bundling. To fix this, configure Port-channel1 as a Layer 2 trunk interface with the same allowed VLANs.

The solution: remove the no switchport command and the IP address, then apply switchport mode trunk and switchport trunk allowed vlan 10,20,30. After correction, the ports should bundle and the show etherchannel summary will show the ports as bundled (P) and the port-channel as Layer 2 (S).

Exam trap

The exam trap is that candidates often focus on LACP modes or trunk negotiation but overlook the Layer 2/Layer 3 mismatch between the port-channel interface and member interfaces. Always ensure the port-channel interface is configured as either Layer 2 or Layer 3 to match the member ports.

Why the other options are wrong

B

The specific factual error: The problem is a Layer 2/Layer 3 mismatch, not the LACP mode. Active mode is valid and commonly used.

C

The specific factual error: 'switchport nonegotiate' affects trunk negotiation, not EtherChannel bundling.

D

The specific factual error: The mode change does not fix the interface type mismatch; the port-channel must be Layer 2 to match the member ports.

Why candidates pick the wrong answer

B

Candidates might think that LACP negotiation requires one side active and one passive, but active-active is also valid. They may overlook the port-channel interface configuration.

C

Candidates may confuse DTP with LACP or think that disabling negotiation helps, but it does not address the root cause.

D

Candidates might think that using 'mode on' bypasses negotiation issues, but it does not resolve configuration inconsistencies between the port-channel and member interfaces.

632
MCQmedium

An ACL entry reads: access-list 25 permit 192.168.8.0 0.0.0.15 Which address range does this statement match?

A.192.168.8.0 through 192.168.8.15
B.192.168.8.0 through 192.168.8.31
C.192.168.8.0 through 192.168.8.7
D.Only host 192.168.8.15
AnswerA

The wildcard mask 0.0.0.15 (binary 00000000.00000000.00000000.00001111) fixes the first 28 bits and allows the last 4 bits of the fourth octet to vary. Because the network portion is 192.168.8.0, these 4 variable bits produce every address from .0 (00000000) to .15 (00001111), inclusive. Thus this ACL entry matches exactly the 16 addresses 192.168.8.0 through 192.168.8.15.

Why this answer

A wildcard of 0.0.0.15 means the last 4 bits can vary, which corresponds to a block size of 16 addresses. Starting at 192.168.8.0, the range is 192.168.8.0 through 192.168.8.15.

Exam trap

Be careful not to confuse the block size determined by the wildcard mask with a full subnet or miscalculate the starting address.

Why the other options are wrong

C

This range uses a wildcard mask of 0.0.0.7, not 0.0.0.15.

When would these options actually be correct?

B

If the question were modified to read 'access-list 25 permit 192.168.8.0 0.0.0.31', then option B would be correct, as it would match the entire range from 192.168.8.0 to 192.168.8.31.

C

This option would be correct if the question specified that the ACL was intended to match only the addresses within the range of 192.168.8.8 to 192.168.8.15, perhaps in a context where a specific subnet mask was applied to limit the range.

D

In a different question, if the ACL entry specified 'access-list 25 permit 192.168.8.15 0.0.0.0', then option D would be correct, as it would permit only the host address 192.168.8.15.

Why candidates pick the wrong answer

B

Students often confuse wildcard masks with subnet masks, thinking that 0.0.0.15 corresponds to a /27 subnet (255.255.255.224) which has 32 addresses, but wildcard masks are the inverse of subnet masks.

C

A test-taker might mistakenly think the wildcard mask indicates the starting point or that the range is centered around the given address, leading to an incorrect starting offset.

D

Students may see the last octet .15 in the wildcard mask and incorrectly assume it matches only the host with that specific value, confusing the wildcard mask with a host address.

633
MCQmedium

A router learns the same prefix from both OSPF and EIGRP. Which route is installed by default?

A.The OSPF route because OSPF is link-state
B.The EIGRP route because it has the lower administrative distance
C.The route with the lower metric value regardless of protocol
D.Both routes are always installed
AnswerB

The EIGRP route is installed because EIGRP has an administrative distance of 90, while OSPF uses 110. When a router receives the same prefix from different routing protocols, the lower AD is selected as the best path. Protocol-specific metrics are never compared across protocols; AD is the first tie-breaker.

Why this answer

When identical prefixes are learned from different routing protocols, the router compares administrative distance first. EIGRP internal routes use AD 90, while OSPF uses AD 110.

Exam trap

Remember that lower administrative distance values indicate higher preference. Don't confuse protocol complexity with route preference.

Why the other options are wrong

A

The type of routing protocol (link-state vs. distance vector) does not determine route preference when comparing routes from different protocols. Route selection is based on administrative distance, not protocol characteristics.

C

Metrics are only comparable within the same routing protocol. Different protocols use different metrics (e.g., OSPF uses cost, EIGRP uses composite metric), so they cannot be directly compared. Administrative distance is used to choose between protocols.

D

By default, a router installs only the best route (lowest AD) for a given prefix into the routing table. Both routes are not installed unless features like equal-cost multipath or policy routing are configured, which is not the case here.

When would these options actually be correct?

A

In a different scenario where the question specifies that OSPF is configured with a lower administrative distance than EIGRP, or if both protocols are configured with the same administrative distance, then the OSPF route would be installed by default due to its link-state nature.

C

If the exam question specified that the router should select the route based on the lowest metric value without considering administrative distances, then this option would be correct. For example, a question might ask which route would be chosen if both protocols had the same administrative distance.

D

If the exam question specified a scenario where a router is configured to use a specific routing policy that allows multiple routes to be installed for the same prefix, such as with route redistribution or a specific configuration that permits equal-cost multipath (ECMP), then this option would be correct.

Why candidates pick the wrong answer

A

Students may think that link-state protocols like OSPF are inherently more reliable or preferred over distance-vector protocols like EIGRP, but this is not how route selection works.

C

Students often confuse metric and administrative distance, thinking that a lower metric always wins regardless of protocol, but metric comparison is only valid within the same protocol.

D

Some students may think that multiple routes to the same destination are always installed for redundancy, but the routing table only contains the best route unless explicitly configured otherwise.

634
MCQhard

R1 and R2 are connected via a GigabitEthernet link in the same IPv4 subnet, and both routers have OSPF configured in the same area. However, R1 is not learning any OSPF routes from R2. What is the most likely cause?

A.GigabitEthernet0/0 is configured as a passive OSPF interface on R1.
B.The routers must use different OSPF process IDs to exchange routes.
C.The routers are in different IPv4 subnets.
D.OSPF can advertise routes only across serial links.
AnswerA

GigabitEthernet0/0 being configured as a passive OSPF interface on R1 suppresses all OSPF hello packets on that link. Because R1 never sends hellos, it cannot establish a two-way neighbor relationship with R2; OSPF adjacency cannot form, and no OSPF routes are exchanged. This explains why R1 has no routes from R2 even though the physical link is operational.

Why this answer

The most likely reason is that one side has the interface configured as passive, which prevents OSPF hello packets from being sent on that interface. In practical terms, the network statement alone does not guarantee neighbor formation. OSPF still needs active neighbor discovery on the link. If the interface is passive, the router advertises the connected network into OSPF but does not attempt to form an adjacency there.

This is a realistic routing troubleshooting pattern because the configuration can look mostly correct until you inspect the passive-interface setting.

Exam trap

A frequent exam trap is to incorrectly believe that OSPF process IDs must match between routers to exchange routes or that OSPF only works on serial links. Candidates may also overlook the passive-interface setting, assuming that the presence of correct network statements guarantees neighbor formation. The passive-interface command disables hello packets, which are essential for OSPF adjacency.

This subtle configuration detail often causes confusion because the router still advertises the network but refuses to form neighbors, leading to missing routes despite seemingly correct OSPF setup.

Why the other options are wrong

B

Incorrect because OSPF process IDs are locally significant and do not need to match between routers for adjacency or route exchange.

C

Incorrect because both routers' interfaces are in the same subnet 10.20.12.0/24, so subnet mismatch is not the cause of missing routes.

D

Incorrect because OSPF supports multiple link types including Ethernet; it is not limited to serial links only.

When would these options actually be correct?

B

In a different scenario where the question specifies that R1 and R2 are configured with different OSPF process IDs, this option would be correct. For example, if the question asked why R1 cannot learn routes from R2 when both routers are configured with distinct OSPF process IDs, this option would accurately explain the situation.

C

In a different scenario, if the question stated that R1 and R2 are configured in separate OSPF areas and are indeed in different IPv4 subnets, this option would be correct. The question would need to focus on the inability of OSPF to exchange routes across different subnets without proper routing protocols or configurations.

D

In a different exam scenario where the question specifies that OSPF is only configured on serial interfaces and the routers are connected via Ethernet, this option could be correct. The question would need to clarify that OSPF is restricted to serial links due to specific network design constraints.

Why candidates pick the wrong answer

B

Students often confuse OSPF process IDs with other routing protocols like EIGRP, where the autonomous system number must match. They may incorrectly assume that OSPF process IDs must be consistent across routers.

C

Subnet mismatch is a common OSPF neighbor issue, and test-takers may jump to this conclusion without verifying the actual IP addresses and subnet masks in the exhibit.

D

Some older OSPF implementations or exam scenarios emphasize serial links, leading students to believe OSPF is limited to serial connections. However, OSPF is widely used on Ethernet networks.

635
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure a Cisco switch with an IPv4 management address 192.168.1.10/24, an IPv6 address 2001:db8:1::1/64, and a default gateway 192.168.1.1.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
6Step 6
7Step 7

Why this order

Correct order:

Enter global configuration mode – all subsequent configuration commands require this mode.

Enter interface configuration mode for VLAN 1 – the management SVI must be selected to apply IP settings.

Assign the IPv4 address 192.168.1.10 255.255.255.0 – sets the switch's management IPv4 address and subnet mask.

Enable the interface with the no shutdown command – activates the SVI so it can send and receive traffic.

Assign the IPv6 address 2001:db8:1::1/64 – enables IPv6 processing and statically configures a global unicast address.

Exit interface configuration mode to return to global configuration mode – required because the default gateway command is a global configuration command, not an interface subcommand.

Set the default gateway to 192.168.1.1 using the ip default-gateway command – provides the next-hop router for IPv4 traffic leaving the local subnet.

636
MCQhard

A network engineer is configuring a Cisco router to provide DHCP services to a remote subnet. The router interface connected to that subnet is GigabitEthernet0/1 with IP address 192.168.20.1/24. The DHCP pool must exclude the first 10 addresses for static devices. Which configuration correctly sets up the DHCP pool?

A.ip dhcp pool LAN, network 192.168.20.0 255.255.255.0, default-router 192.168.20.1, exclude 192.168.20.1 192.168.20.10
B.ip dhcp pool LAN, network 192.168.20.0 255.255.255.0, default-router 192.168.20.1, ip dhcp excluded-address 192.168.20.1 192.168.20.10
C.ip dhcp excluded-address 192.168.20.1 192.168.20.10, then ip dhcp pool LAN, network 192.168.20.0 255.255.255.0, default-router 192.168.20.1
D.ip dhcp excluded-address 192.168.20.0 192.168.20.10, then ip dhcp pool LAN, network 192.168.20.0 255.255.255.0, default-router 192.168.20.1
AnswerC

The ip dhcp excluded-address command reserves the range 192.168.20.1 through 192.168.20.10 from being leased. The pool then defines the network 192.168.20.0/24 and the default gateway 192.168.20.1. This combination correctly provides DHCP service while protecting the first ten addresses for static assignment, matching the stated requirement.

Why this answer

DHCP exclusions are configured globally with ip dhcp excluded-address before defining the pool, and the pool itself specifies the network and default router. The correct sequence reserves 192.168.20.1 through 192.168.20.10, defines the 192.168.20.0/24 network, and sets the gateway. The other options misuse the exclude keyword, exclude the network address unnecessarily, or place a global command inside pool mode.

Exam trap

The trap here is placing the excluded-address command inside the DHCP pool, when it is actually a global configuration command.

637
Multi-Selectmedium

Which TWO statements correctly describe how a router selects the best path for a destination network when multiple routing table entries exist?

Select 2 answers
A.Routes with the longest prefix length (most specific) are preferred over routes with a shorter prefix.
B.If two routes have the same prefix length, the route with the higher administrative distance is selected.
C.When the administrative distance is identical, the router compares the metric and selects the route with the lowest metric.
D.A directly connected route has an administrative distance of 1, making it more trustworthy than any dynamic route.
E.Dynamic routes are always preferred over directly connected routes because they can adapt to network changes.
AnswersA, C

Routers perform a longest prefix match, meaning they compare the number of matching bits in the destination address with each route's subnet mask or prefix length. A more specific route, such as a /24 covering 192.168.1.0/24, is preferred over a less specific route like a /16 covering 192.168.0.0/16, because it identifies the destination network with greater precision. This rule is applied first, even before considering administrative distance or metric, because a longer match indicates a more exact route to the destination and, in classless routing, is always the most efficient forwarding decision.

Why this answer

Routers select the best path by first applying the longest prefix match rule (most specific subnet mask), so option A is correct. If two routes have the same prefix length, the router then compares administrative distance (AD) and prefers the lower AD; option B is incorrect because it says higher AD is selected. When AD is equal, the router uses metric and chooses the lowest metric, making option C correct.

Option D is false because directly connected routes have an AD of 0, not 1, and they are indeed more trustworthy than dynamic routes but not due to AD 1. Option E is wrong because directly connected routes are always preferred over dynamic routes regardless of adaptability.

Exam trap

Cisco often tests the exact administrative distance values (e.g., directly connected = 0, static = 1) and the correct comparison order (prefix length first, then AD, then metric) to catch candidates who confuse AD with metric or misremember default values.

Why the other options are wrong

B

The router selects the route with the lower administrative distance, not higher. Administrative distance is a measure of trustworthiness; a lower value indicates a more reliable source. For example, a static route (AD 1) is preferred over an OSPF route (AD 110).

D

Directly connected routes have an administrative distance of 0, not 1. An AD of 0 is the most trustworthy and cannot be overridden by any dynamic route. The value 1 is used for static routes.

E

Directly connected routes have an AD of 0, which is lower than any dynamic routing protocol (e.g., OSPF AD 110, EIGRP AD 90). Therefore, directly connected routes are always preferred over dynamic routes, not the other way around.

Why candidates pick the wrong answer

B

Students may confuse administrative distance with metric, thinking that a higher value indicates a better path. They might also misremember the rule, thinking that 'higher' means 'better' in all contexts.

D

Students often confuse the AD values for directly connected (0) and static routes (1). They may also think that a value of 1 is the most trustworthy because it is the smallest positive integer.

E

Students might think that dynamic routes are more intelligent and adaptive, so they should be preferred. They may also overlook the fact that directly connected routes are inherently more reliable because they are directly attached to the router.

638
MCQhard

A user on VLAN 10 reports that they cannot ping the default gateway at 192.168.10.1 from their PC with IP 192.168.10.50/24. The switch interface connecting to the PC is up/up, and the PC shows a valid IP configuration. What is the most likely cause of this connectivity failure?

A.Change the switchport mode to trunk to allow VLAN 10 traffic.
B.Configure an SVI for VLAN 10 with an IP address in the 192.168.10.0/24 subnet.
C.Change the PC's IP address to a different subnet, such as 192.168.20.0/24.
D.Recreate VLAN 10 and reassign the port to it.
AnswerB

The switch must provide a Layer 3 interface in VLAN 10 to serve as the default gateway for PCs in the 192.168.10.0/24 subnet. An SVI (interface vlan 10) with an IP address from that subnet creates a routable interface on the multilayer switch. This allows hosts in VLAN 10 to send traffic to other subnets, as their default gateway points to that SVI. Without this SVI, the PC has no gateway to route its traffic beyond its local segment.

Why this answer

The PC and default gateway are on the same subnet (192.168.10.0/24), but the switch lacks a Layer 3 interface for VLAN 10. Without an SVI (Switch Virtual Interface) configured with an IP address in that subnet, the switch cannot route traffic to the gateway or respond to ARP requests from the PC, breaking connectivity even though the access port is up/up.

Exam trap

Cisco often tests the misconception that a VLAN alone provides Layer 3 connectivity, when in fact an SVI or a separate router-on-a-stick configuration is required for inter-VLAN routing and default gateway functionality.

Why the other options are wrong

A

A trunk port is used to carry multiple VLANs between switches, not to connect an end device like a PC. Configuring the switchport as trunk would break connectivity because the PC expects an access port.

C

Changing the PC's IP subnet would not resolve the issue because the PC would still need a default gateway on its new subnet. The root cause is the missing SVI on the switch, not the PC's IP address.

D

Recreating VLAN 10 and reassigning the port does not address the missing SVI. The VLAN already exists and the port is correctly assigned; the issue is at Layer 3, not Layer 2.

Why candidates pick the wrong answer

A

Students may confuse trunking with allowing VLAN traffic, thinking that setting the port to trunk will enable VLAN 10 traffic to pass, but trunking is for inter-switch links, not end devices.

C

A student might think the PC is on the wrong subnet if it cannot ping the gateway, but the PC's IP is correctly within the 192.168.10.0/24 subnet. Changing subnets would only create additional problems.

D

Students may assume that the VLAN configuration is corrupted or the port assignment is incorrect, leading them to recreate the VLAN. However, the problem is the lack of a gateway, not a VLAN issue.

639
MCQmedium

A network engineer is troubleshooting a connectivity issue between two hosts on different VLANs. The engineer captures traffic on an IOS-XE router's GigabitEthernet0/1 interface using embedded packet capture (EPC). The output shows ARP requests from Host A (192.168.1.10) but no ARP replies from Host B (192.168.2.20). What is the most likely cause of this issue?

A.The router's interface is configured as an access port instead of a trunk.
B.The router's interface does not have an IP address configured in the VLAN 2 subnet.
C.Host A is in a different VLAN than the router's interface.
D.The router's interface has a duplex mismatch with the switch.
AnswerB

For inter-VLAN routing, the router must have an IP address in each VLAN's subnet to act as the default gateway and respond to ARP requests. Without an IP in VLAN 2, it cannot reply to ARP requests for 192.168.2.20.

Why this answer

The router's GigabitEthernet0/1 interface must have an IP address in the same subnet as Host B (192.168.2.20) to act as the default gateway for VLAN 2. Without an IP address in the VLAN 2 subnet, the router cannot respond to ARP requests for that subnet, so Host A's ARP requests for Host B go unanswered. This is the most likely cause because the router performs inter-VLAN routing only when it has an interface (or subinterface) with an IP address in the destination VLAN's subnet.

Exam trap

Cisco often tests the misconception that a router automatically routes between VLANs if it is connected to a switch via a trunk, but the router must have an IP address in each VLAN's subnet to respond to ARP and forward traffic.

Why the other options are wrong

A

The router's interface is a routed port, not a switchport; access/trunk concepts apply to switch interfaces. Even if it were a switch interface, the issue is about ARP replies, which require Layer 3 addressing, not trunking.

C

ARP requests are Layer 2 broadcasts; if the router's interface is in the same VLAN as Host A, it will receive the request. The problem is that the router does not reply, indicating it lacks an IP in the destination subnet.

D

Duplex mismatch causes CRC errors and collisions, but ARP requests would still be received and could be replied to. The capture shows clean ARP requests with no replies, pointing to a Layer 3 issue, not physical layer.

Why candidates pick the wrong answer

A

Students often confuse router interfaces with switch interfaces and may think that VLAN tagging is required for inter-VLAN routing, but in this scenario the router is likely using router-on-a-stick or routed interfaces.

C

Test-takers may think that VLAN mismatch prevents the router from seeing the ARP request, but the capture shows the request is received; the issue is at Layer 3.

D

Duplex mismatch is a common troubleshooting topic, and students may jump to physical layer issues without considering the specific symptom of missing ARP replies.

640
MCQmedium

Why is centralized logging especially useful when combined with NTP?

A.Because synchronized clocks make centralized log timelines easier to analyze accurately.
B.Because NTP assigns the Syslog server its IP address.
C.Because Syslog replaces authentication when NTP is present.
D.Because centralized logging blocks unauthorized traffic automatically.
AnswerA

Synchronised clocks via NTP ensure that log timestamps across all network devices share a common time reference, eliminating drift that would otherwise scatter events from the same incident across different points in a centralised log timeline. This temporal alignment satisfies the constraint of accurate forensic reconstruction, as analysts can correlate events from routers, switches, and servers without manual offset correction.

Why this answer

Centralized logging is much more useful when device clocks are synchronized because the timestamps can be correlated properly. In practical terms, collecting messages in one place is valuable, but if one router thinks it is 9:00 and another thinks it is 9:17, the event sequence becomes confusing. NTP solves that time-alignment problem.

This is a common operations best practice. Syslog provides the central visibility, and NTP makes the timeline trustworthy.

Exam trap

A common exam trap is to mistakenly believe that NTP provides IP addressing or security functions such as blocking unauthorized traffic. Some may also incorrectly assume that syslog replaces authentication mechanisms when NTP is present. These misconceptions arise because candidates confuse the distinct roles of NTP and syslog.

NTP strictly synchronizes time, while syslog collects logs. Neither assigns IP addresses nor enforces access control. Understanding this separation is crucial to avoid selecting incorrect answers that attribute unrelated functions to NTP or centralized logging.

Why the other options are wrong

B

Option B is incorrect because NTP does not assign IP addresses to syslog servers or any devices. IP addressing is handled by DHCP or manual configuration, not by NTP.

C

Option C is incorrect because syslog does not replace authentication mechanisms. NTP and syslog are unrelated to access control or authentication processes in Cisco networks.

D

Option D is incorrect because centralized logging improves visibility into network events but does not block unauthorized traffic. Traffic enforcement is managed by firewalls, ACLs, or other security features.

When would these options actually be correct?

B

In a different question asking about the role of NTP in network device configuration, one might state that NTP can help in dynamic environments where devices are assigned IP addresses by DHCP, ensuring that time synchronization occurs correctly across all devices, including the Syslog server.

C

In a different exam context, if the question asked about a hypothetical logging system that integrates NTP with a specific authentication protocol, and the focus was on how time synchronization could enhance security measures, this option might be correct. For example, if the question specified that NTP could enhance the security of log messages by ensuring they are timestamped accurately for authentication purposes, then this could be valid.

D

In a different question context, if the focus were on a security system that integrates centralized logging with a firewall, and the question asked about features of that system, option D could be correct if it specified that the logging system has capabilities to block unauthorized traffic based on log analysis.

Why candidates pick the wrong answer

B

Students might confuse NTP with DHCP or other protocols that provide network configuration. The acronym 'NTP' might be mistakenly associated with network setup tasks beyond time sync.

C

Test-takers might think that because both Syslog and NTP are network services, they could have overlapping functions. The idea of 'replacing' authentication with logging is a common misconception.

D

Students may think that because logs can be used to detect threats, the logging system itself can take action. However, logging is passive and requires separate mechanisms for enforcement.

641
MCQmedium

A router learns 203.0.113.0/24 through OSPF and 203.0.113.0/25 through a static route. Which route is used for traffic destined to 203.0.113.10?

A.The OSPF /24 route
B.The static /25 route
C.Both routes equally
D.Neither route because the prefixes overlap
AnswerB

The static /25 route is selected because forwarding decisions use longest-prefix match, not administrative distance. Even though OSPF has a higher administrative distance (110) compared to static's 1, that comparison applies only when two routes have identical prefix lengths. Since 203.0.113.0/25 is more specific than the /24 and also matches the destination address, the router installs and uses this route for all traffic within that /25 range. This is why the static /25 correctly wins.

Why this answer

Routers prefer the most specific matching route first. The /25 route is more specific than the /24 and includes 203.0.113.10.

Exam trap

Remember that the most specific route (longest prefix) is always preferred, regardless of the routing protocol.

Why the other options are wrong

A

The OSPF /24 route is less specific than the static /25 route. The longest prefix match rule dictates that the /25 route is preferred for destination 203.0.113.10, which falls within the /25 range.

C

Equal-cost load balancing only applies when multiple routes have the same prefix length and metric. Here, the prefix lengths differ (/24 vs /25), so the longest prefix match selects the /25 route exclusively.

D

Overlapping routes are common in routing tables and do not cause a problem. The router always selects the most specific match (longest prefix) for forwarding, so both routes can coexist.

When would these options actually be correct?

A

If the question stated that the OSPF /24 route had a higher administrative distance than the static route, or if the static route was removed from the routing table, then the OSPF /24 route would be the correct choice for traffic to 203.0.113.10.

C

In a different scenario where both routes had the same administrative distance, such as when comparing two static routes, a question might ask which route would be used if both were equally preferred. In that case, both routes could be considered equally valid for traffic destined to the same IP.

D

In a scenario where a question specifies that both routes are equally preferred due to equal administrative distances or if the router is configured to treat overlapping routes differently, this option could be correct. For example, if the question states that the router uses a round-robin method for load balancing between equal-cost paths, then both routes would be used.

Why candidates pick the wrong answer

A

Students may think that OSPF, as a dynamic routing protocol, is preferred over static routes, or they may overlook the longest prefix match rule and assume administrative distance decides the winner.

C

Students might confuse the concept of equal-cost multipath (ECMP) with overlapping routes of different lengths, assuming both routes could be used simultaneously.

D

Students may think that overlapping prefixes create a conflict or error, similar to overlapping IP addresses on interfaces, but routing protocols handle overlapping prefixes without issue.

642
MCQhard

A switch port connected to a user PC should be placed in VLAN 20 and must not negotiate trunking. Which configuration is the most appropriate?

A.switchport mode access switchport access vlan 20
B.switchport mode trunk switchport trunk native vlan 20
C.switchport mode dynamic desirable switchport trunk allowed vlan 20
D.no switchport ip address 192.168.20.1 255.255.255.0
AnswerA

This is the correct configuration for a host port. `switchport mode access` unconditionally sets the interface as a nontrunking Layer 2 access port, disabling Dynamic Trunking Protocol (DTP) and preventing the port from becoming a trunk. The `switchport access vlan 20` command then statically assigns the port to VLAN 20, so the connected PC’s untagged frames are carried in that VLAN, exactly matching the requirement.

Why this answer

The most appropriate configuration is to force the interface into access mode and assign it to VLAN 20. In practical terms, a normal user-facing switch port is supposed to carry one VLAN only. There is no reason to rely on dynamic trunk negotiation for a desktop or laptop connection. Explicit access-port configuration is cleaner, more predictable, and safer.

This is a common switching best-practice question. The wrong answers usually leave room for unwanted trunking behavior or move the interface into a completely different role. The right answer combines the correct port role with the correct VLAN membership.

Exam trap

Avoid assuming 'auto' mode is always safe; it can lead to unintended trunking.

Why the other options are wrong

B

This configuration makes the port a trunk port, which is used to carry multiple VLANs between switches, not for a single user PC. The 'switchport trunk native vlan 20' command sets the native VLAN for untagged traffic on the trunk, but the port still actively negotiates trunking via DTP, violating the requirement to not negotiate trunking.

C

The 'switchport mode dynamic desirable' command actively attempts to form a trunk with the connected device via DTP, which contradicts the requirement to not negotiate trunking. Additionally, 'switchport trunk allowed vlan 20' only restricts which VLANs are allowed on the trunk, but the port is still in trunking mode, not an access port.

D

The 'no switchport' command converts the Layer 2 switch port into a Layer 3 routed interface, which cannot be assigned to a VLAN. This configuration is used for routing between VLANs or connecting to routers, not for connecting a user PC to a specific VLAN.

When would these options actually be correct?

B

This option would be correct in a scenario where the question specifies that the switch port is intended to connect to another switch or a device that requires trunking, and the native VLAN needs to be set to 20 for proper communication between VLANs.

C

In a different question setup where a switch port needs to connect to another switch and allow multiple VLANs, configuring the port as a trunk with 'switchport mode trunk' and specifying 'switchport trunk native vlan 20' would be appropriate to manage VLAN traffic effectively.

D

This option would be correct in a scenario where the question asks for the configuration of a router interface that needs to be assigned an IP address in VLAN 20 for inter-VLAN routing. In that case, the interface would not be a switchport but rather a routed interface.

Why candidates pick the wrong answer

B

A student might confuse 'native VLAN' with 'access VLAN' and think that setting the native VLAN to 20 on a trunk port achieves the same result as assigning VLAN 20 to an access port. They may also overlook that trunk ports are designed for inter-switch links, not end-user connections.

C

Students may think that 'dynamic desirable' is a safe mode that only becomes a trunk if the other side agrees, but it still initiates DTP negotiation. They might also incorrectly assume that 'trunk allowed vlan 20' limits the port to a single VLAN, similar to an access port.

D

A student might think that assigning an IP address to the port is necessary for the PC to communicate, but on a Layer 2 switch, VLAN membership is handled at Layer 2, not by IP addressing. They may also confuse this with configuring a switch virtual interface (SVI) for VLAN 20, which is done on a different interface.

643
MCQmedium

A router has two static routes to the same destination network: one with administrative distance 1 and another with administrative distance 200. Both routes are configured with the same next-hop address. What will the router do with these routes?

A.Install only the route with administrative distance 200.
B.Reject both routes due to a conflict.
C.Install only the route with administrative distance 1.
D.Install both routes and load-balance traffic between them.
AnswerC

The router selects the route with the lowest administrative distance. Administrative distance 1 is lower than 200, so the route with distance 1 is installed in the routing table. The other route remains in the configuration but is not used unless the primary route fails. This is the correct behavior.

Why this answer

When multiple static routes to the same destination exist, the router installs the one with the lowest administrative distance. Administrative distance 1 is preferred over 200, so the route with distance 1 is used. The other route acts as a backup and is only installed if the primary route becomes unavailable.

Load balancing does not occur because the distances differ.

Exam trap

The trap here is thinking that both routes are installed and load-balanced; load balancing requires equal administrative distance and metric.

644
MCQhard

A host is configured with IP address 192.168.50.94/27. Which subnet contains that host?

A.192.168.50.32/27
B.192.168.50.64/27
C.192.168.50.96/27
D.192.168.50.0/27
AnswerB

A /27 prefix length defines a subnet mask of 255.255.255.224, creating a block of 32 addresses. The host address 192.168.50.94 falls within the range 192.168.50.64–192.168.50.95, where 192.168.50.64 is the network address and 192.168.50.95 is the broadcast address. This satisfies the constraint that the host’s IP must lie between the subnet’s network and broadcast addresses.

Why this answer

A /27 subnet has a block size of 32. In simple terms, the fourth-octet ranges are 0–31, 32–63, 64–95, 96–127, and so on. Because 94 falls inside the 64–95 range, the network address for the host’s subnet is 192.168.50.64/27.

This kind of question tests whether you can move from prefix length to block size and then place the host inside the correct interval. The most common mistake is choosing a nearby boundary like 96 or 32 without calculating the actual block that contains the address.

Exam trap

Always calculate the subnet range using the block size derived from the prefix length to avoid choosing incorrect boundaries.

Why the other options are wrong

A

The subnet 192.168.50.32/27 covers addresses 192.168.50.32 to 192.168.50.63. The host address 192.168.50.94 is outside this range, so it does not belong to this subnet.

C

The subnet 192.168.50.96/27 covers addresses 192.168.50.96 to 192.168.50.127. The host address 192.168.50.94 is below this range, so it does not belong to this subnet.

D

The subnet 192.168.50.0/27 covers addresses 192.168.50.0 to 192.168.50.31. The host address 192.168.50.94 is far above this range, so it does not belong to this subnet.

When would these options actually be correct?

A

If the question asked which subnet contains the IP address 192.168.50.40, then option A (192.168.50.32/27) would be correct, as this subnet would encompass the host IP within its range.

C

If the question asked which subnet contains the IP address 192.168.50.96, then option C would be correct, as that address would belong to the subnet 192.168.50.96/27, which covers addresses from 192.168.50.96 to 192.168.50.127.

D

If the question asked which subnet contains the network address of a different host, such as one configured with an IP address in the range of 192.168.50.0 to 192.168.50.31, then option D would be correct as it would represent the subnet for that specific host.

Why candidates pick the wrong answer

A

Students might mistakenly think that because 94 is close to 64, it could be in the .32 subnet, but they forget to calculate the broadcast address correctly.

C

Students may incorrectly think that because 94 is close to 96, it could be in the .96 subnet, but they overlook that the subnet starts at .96, not .95.

D

Students might choose this option if they incorrectly calculate the subnet mask or assume the host is in the first subnet without proper calculation.

645
PBQhard

You are connected to R1, a Cisco ISR 4321 running IOS-XE. Configure SNMPv2c with a read-only community string 'public' and SNMPv3 with user 'admin' using SHA authentication and AES encryption. Ensure SNMP traps are sent to the management server at 203.0.113.10. Additionally, configure NetFlow export to destination 203.0.113.20 on UDP port 2055 using version 9. Verify your configuration with appropriate show commands. The current running-config is incomplete; you must add the missing commands.

Network Topology
G0/0192.168.1.1/24Management NetworkR1Server

Hints

  • •SNMPv3 user configuration requires both auth and priv algorithms and passwords.
  • •For SNMP traps, specify the trap receiver IP and community string.
  • •NetFlow export configuration uses global commands; no interface-level configuration is needed for basic export setup.
A.snmp-server community public ro snmp-server user admin snmp-group v3 auth sha cisco priv aes 128 cisco snmp-server host 203.0.113.10 traps version 2c public ip flow-export destination 203.0.113.20 2055 ip flow-export version 9
B.snmp-server community public ro snmp-server user admin snmp-group v3 auth sha cisco priv aes 128 cisco snmp-server host 203.0.113.10 traps version 3 auth public ip flow-export destination 203.0.113.20 2055 ip flow-export version 9
C.snmp-server community public ro snmp-server user admin snmp-group v3 auth md5 cisco priv des56 cisco snmp-server host 203.0.113.10 traps version 2c public ip flow-export destination 203.0.113.20 2055 ip flow-export version 9
D.snmp-server community public ro snmp-server user admin snmp-group v3 auth sha cisco priv aes 128 cisco snmp-server host 203.0.113.10 traps version 2c public ip flow-export destination 203.0.113.20 2055 ip flow-export version 5
AnswerA
solution
! R1
snmp-server user admin auth sha cisco priv aes 128 cisco
snmp-server host 203.0.113.10 traps version 2c public
ip flow-export destination 203.0.113.20 2055
ip flow-export version 9

Why this answer

The initial config has only a basic SNMPv2c community string. To meet requirements: enable SNMPv3 with a user 'admin' using SHA authentication and AES 128-bit encryption. The correct command requires a group name and the 'v3' keyword, e.g., 'snmp-server user admin snmp-group v3 auth sha cisco priv aes 128 cisco'.

Configure SNMP trap destination with 'snmp-server host 203.0.113.10 traps version 2c public'. For NetFlow, use 'ip flow-export destination 203.0.113.20 2055' and 'ip flow-export version 9'. Verify with 'show snmp' and 'show ip cache flow'.

Option B incorrectly uses version 3 traps with a community string; version 3 requires a security name. Option C uses insecure MD5/DES56 instead of SHA/AES. Option D uses NetFlow version 5 instead of version 9.

Exam trap

Forgetting to include a group name and the 'v3' keyword in the 'snmp-server user' command is a common syntax error that will cause the configuration to be rejected on real devices.

Why the other options are wrong

B

The trap host line uses 'version 3' and a community string ('public'), but SNMPv3 traps require a security name (the user) and an authentication level, not a community.

C

The SNMPv3 user is configured with MD5 and DES56, while the requirement is SHA authentication and AES 128‑bit encryption.

D

The NetFlow export version is set to 5 instead of the required version 9.

Why candidates pick the wrong answer

B

Candidates may mistakenly think that the community string 'public' can be used with SNMPv3 traps, or they may confuse the syntax between SNMPv2c and SNMPv3 trap configuration.

C

Candidates may confuse the default or older SNMPv3 security algorithms (MD5 and DES) with the more secure SHA and AES, or they may not know the exact keywords for SHA and AES.

D

Candidates may default to version 5 because it is older and simpler, or they may not remember that version 9 is the required format for modern NetFlow export.

646
MCQhard

Refer to the exhibit. A network engineer is troubleshooting connectivity to server 10.10.10.130. The routing table contains both a static route and an OSPF route for overlapping prefixes. The engineer examines the specific routing entry for 10.10.10.130. Based on the output, why does the router choose the route via 10.1.1.2 instead of the OSPF route via 10.2.2.2 (for 10.10.10.0/24)?

A.The static route has a lower administrative distance (1) than the OSPF route (110).
B.The OSPF route is inactive because its next-hop 10.2.2.2 is down.
C.The static route has a longer prefix length (/26) than the OSPF route (/24), making it a more specific match.
D.The router prefers the static route because it has a metric of 0, which is better than the OSPF metric.
AnswerC

The deciding factor is longest prefix match, which is the first rule in IP route selection. The static route's mask of /26 matches 64 addresses, while the OSPF route's /24 matches 256 addresses; for any destination inside the /26, the static route is a longer, more specific match. Longest prefix match is evaluated before administrative distance or metric, so the /26 static route is preferred even though OSPF has a higher AD and a different metric.

Why this answer

The router selects the route via 10.1.1.2 because the static route has a prefix length of /26, which is longer (more specific) than the OSPF route's /24. When multiple routes to the same destination exist, the router uses the most specific match (longest prefix) regardless of administrative distance or metric. Since 10.10.10.130 falls within the 10.10.10.128/26 range, the /26 route is preferred over the /24 route.

Exam trap

Cisco often tests the longest prefix match rule by presenting overlapping routes with different administrative distances, leading candidates to incorrectly assume that lower AD always wins, when in fact prefix length is evaluated first.

Why the other options are wrong

A

This reflects a common misunderstanding that AD is the sole tie-breaker between routes from different sources, ignoring prefix length priority.

B

Candidates might assume that if the OSPF route is not used, it must be inactive; however, the exhibit does not show this.

D

Candidates may mistake metric for the primary selection criterion, not realizing prefix length dominates all other route comparison steps.

647
Multi-Selectmedium

Which three of the following are characteristics of DHCP snooping on a Cisco switch? (Choose three.)

Select 3 answers
.It differentiates trusted and untrusted ports to filter DHCP messages.
.It builds and maintains a DHCP snooping binding database.
.It prevents DHCP starvation attacks by rate-limiting DHCP messages on untrusted ports.
.It encrypts DHCP traffic between the client and the server.
.It replaces the DHCP server's IP address with a static route.
.It requires all DHCP servers to be connected to untrusted ports.

Why this answer

DHCP snooping is a security feature that filters untrusted DHCP messages by differentiating trusted and untrusted ports. It builds and maintains a DHCP snooping binding database to track valid IP-to-MAC address assignments. Additionally, it prevents DHCP starvation attacks by rate-limiting DHCP messages on untrusted ports, typically using the 'ip dhcp snooping limit rate' command.

Exam trap

Cisco often tests that DHCP snooping's rate-limiting feature specifically targets DHCP starvation attacks, not rogue server attacks, and that the binding database is used for both IP source guard and dynamic ARP inspection integration.

648
Multi-Selectmedium

Which TWO statements accurately describe characteristics of copper and fiber optic cabling used in modern Ethernet networks?

Select 2 answers
A.Copper UTP cables can reliably transmit data up to 500 meters without a repeater.
B.Fiber optic cables are immune to electromagnetic interference (EMI).
C.Multi-mode fiber typically uses laser-based transmitters for short-range communication.
D.Single-mode fiber is designed for long-distance transmission with a narrow core.
E.Fiber optic cabling is generally less expensive per meter than copper cabling.
AnswersB, D

Fiber optic cables transmit data as pulses of light through a glass or plastic core, so they are completely unaffected by electromagnetic interference, radio-frequency interference, or electrical crosstalk from nearby power cables and machinery. This immunity makes single-mode and multi-mode fiber the preferred medium in industrial environments, data centers, and other settings where electrical noise would corrupt copper signals.

Why this answer

Fiber optic cables transmit data as light pulses through glass or plastic cores, which are completely unaffected by electromagnetic interference (EMI), unlike copper cables that rely on electrical signals and are susceptible to EMI. Option D is correct because single-mode fiber uses a narrow core (typically 9 microns) and laser transmitters to support long-distance transmission (up to tens of kilometers) with low signal loss. Option A is wrong because copper UTP cables are limited to 100 meters without a repeater, not 500 meters.

Option C is wrong because multi-mode fiber typically uses LED or VCSEL transmitters for short-range communication, while laser-based transmitters are used with single-mode fiber. Option E is wrong because fiber optic cabling is generally more expensive per meter than copper cabling, though installation and equipment costs may differ.

Exam trap

Cisco often tests the distinction between multi-mode and single-mode fiber transmitters, where candidates mistakenly associate laser-based transmitters with multi-mode fiber instead of correctly identifying them with single-mode fiber's long-distance, narrow-core design.

Why the other options are wrong

A

Copper UTP cables have a maximum segment length of 100 meters for Ethernet, not 500 meters without a repeater.

C

Multi-mode fiber typically uses LED or VCSEL transmitters, not laser-based transmitters; lasers are used with single-mode fiber for long distances.

E

Fiber optic cabling is generally more expensive per meter than copper cabling, not less expensive.

Why candidates pick the wrong answer

A

Students may confuse the 100-meter limit with the maximum distance for other technologies like telephone lines or mistakenly think UTP can reach longer distances without repeaters.

C

The term 'laser' in VCSEL may lead students to think multi-mode uses lasers, but VCSELs are low-power and distinct from the lasers used in single-mode transceivers.

E

Students might think fiber is cheaper because it can transmit over longer distances without repeaters, but the initial cost of fiber and optics is higher than copper.

649
Multi-Selectmedium

Which THREE statements about STP and Rapid PVST+ are correct?

Select 3 answers
A.Rapid PVST+ creates a separate spanning-tree instance for each VLAN, enabling per-VLAN load balancing.
B.PortFast should be configured on trunk ports to quickly transition them to forwarding state.
C.Rapid PVST+ uses a proposal/agreement process to quickly transition ports to forwarding.
D.BPDU Guard places a port in the error-disabled state if a BPDU is received, protecting against unexpected switches.
E.To make a switch the root bridge, you should assign it the highest bridge priority value among all switches.
AnswersA, C, D

Rapid PVST+ (Per-VLAN Spanning Tree Plus) is Cisco's enhanced implementation of RSTP that maintains an independent spanning-tree instance for every VLAN on a trunk. Because each VLAN has its own root bridge and forwarding topology, different VLANs can be assigned to different upstream switches, allowing traffic from multiple VLANs to be load-balanced across parallel redundant links without creating loops. This per-VLAN approach improves link utilization compared to classic STP, which forces all VLANs to share a single logical topology.

Why this answer

Option A is correct because Rapid PVST+ (Rapid Per-VLAN Spanning Tree Plus) runs a separate 802.1w-based spanning-tree instance for every VLAN, which allows different VLANs to use different root bridges and forwarding paths, enabling per-VLAN load balancing. Option C is correct because Rapid PVST+ uses the RSTP proposal/agreement handshake (via BPDUs with the proposal and agreement flags) to rapidly synchronize ports and move them to forwarding without relying on the slow 802.1D timers. Option D is correct because BPDU Guard, typically combined with PortFast on access ports, error-disables a port if it receives a BPDU, preventing an unauthorized or misconfigured switch from affecting the topology.

Option B is incorrect because PortFast is intended for access (edge) ports connected to end hosts, not trunk ports; enabling it on a trunk could cause loops or topology instability. Option E is incorrect because the root bridge is elected by the lowest bridge priority (default 32768), so to become root a switch must be given the lowest priority value, not the highest.

Exam trap

Cisco often tests the misconception that PortFast can be applied to trunk ports or that it accelerates STP convergence on trunks, but PortFast is only for edge ports and does not participate in the spanning-tree algorithm.

Why the other options are wrong

B

PortFast is unsafe on trunk ports; it is intended only for edge access ports.

E

The root bridge is determined by the lowest bridge priority, not the highest.

650
PBQhard

You are connected to R1. The network has two routers: R1 (192.168.1.0/24 LAN) and R2 (Internet gateway). R1's inside LAN (192.168.1.0/24) must be translated to the public IP 203.0.113.1 using PAT (NAT overload) for Internet access. Additionally, the server at 192.168.1.100 must be reachable from the Internet via static NAT to 203.0.113.5. The current configuration is broken. Identify and fix the issues so that both PAT and static NAT work correctly.

Network Topology
G0/0192.168.1.1/24G0/1203.0.113.2/29S0/0/010.0.0.1/30inside hostsLANR1InternetWANR2

Hints

  • •Check which interfaces are marked as inside and outside — the public IP interface should be outside.
  • •The ACL used for PAT must match the inside local network, not a different subnet.
  • •The PAT command must include the keyword 'overload' to enable port address translation.
A.Change ACL 10 to permit 192.168.1.0 0.0.0.255, change G0/1 to 'ip nat outside', and ensure the PAT command includes 'overload'.
B.Change ACL 10 to permit 192.168.1.0 0.0.0.255, change G0/1 to 'ip nat inside', and ensure the PAT command includes 'overload'.
C.Change ACL 10 to permit 192.168.1.0 0.0.0.255, change G0/1 to 'ip nat outside', and remove the 'overload' keyword from the PAT command.
D.Change ACL 10 to permit 192.168.1.0 0.0.0.255, change G0/1 to 'ip nat inside', and remove the 'overload' keyword from the PAT command.
AnswerA
solution
! R1
configure terminal
no ip nat inside source list 10 interface GigabitEthernet0/1
ip nat inside source list 10 interface GigabitEthernet0/1 overload
no access-list 10
access-list 10 permit 192.168.1.0 0.0.0.255
interface GigabitEthernet0/1
no ip nat inside
ip nat outside
end

Why this answer

The configuration had three issues: 1) ACL 10 permitted 10.0.0.0/8 instead of the actual inside subnet 192.168.1.0/24, so no traffic matched PAT. 2) The PAT command was missing the 'overload' keyword, which is required for Port Address Translation; without it, the device attempts one-to-one dynamic NAT. 3) The interface facing the public network (G0/1) was incorrectly configured as 'ip nat inside' instead of 'ip nat outside'. The fix is to correct the ACL to permit 192.168.1.0 0.0.0.255, ensure the PAT command includes 'overload', and change G0/1 to 'ip nat outside'.

Exam trap

A common trap is confusing inside and outside interface designations. Remember: the interface facing the private network is 'ip nat inside', and the interface facing the public network is 'ip nat outside'. Also, PAT requires the 'overload' keyword; without it, you get dynamic NAT (one-to-one).

Why the other options are wrong

B

The specific factual error is that the interface with the public IP (203.0.113.1) must be configured as 'ip nat outside', not 'ip nat inside'. Marking it as inside would cause asymmetric NAT behavior and break translation.

C

The specific factual error is that PAT requires the 'overload' keyword. Without it, the router performs dynamic NAT (one-to-one translation), which would not support multiple hosts sharing a single public IP.

D

The specific factual errors are: (1) the interface with the public IP must be 'ip nat outside', and (2) PAT requires the 'overload' keyword. Both are violated here.

Why candidates pick the wrong answer

B

Candidates might think both interfaces should be 'inside' because they are both on the router, but the outside interface is the one facing the public network.

C

Candidates might think 'overload' is optional or that it causes issues with static NAT, but both can coexist; the keyword is necessary for PAT.

D

Candidates might think that removing 'overload' simplifies the configuration and that both interfaces can be 'inside', but this misunderstands NAT interface roles and the need for PAT.

651
Multi-Selectmedium

Which TWO DNS record types are most commonly used together to verify both forward and reverse DNS mappings for an IPv6 address?

Select 2 answers
A.A record
B.AAAA record
C.CNAME record
D.PTR record
E.MX record
AnswersB, D

An AAAA record is the forward-DNS record that maps a hostname to a 128-bit IPv6 address, analogous to an A record for IPv4. It is commonly used for hostname-to-address resolution, not for address-to-hostname resolution. Since the question requires reverse mapping from an IPv6 address back to a name, an AAAA record does not fulfill that purpose.

Why this answer

The AAAA record (Quad-A record) maps a domain name to an IPv6 address, making it the standard type for forward IPv6 lookups. The PTR record performs the reverse mapping—from an IPv6 address back to a domain name. Administrators routinely check both records with tools like nslookup or dig to ensure forward and reverse DNS consistency, which is critical for services such as email and security logging.

The other options (A, CNAME, MX) do not directly provide a domain-to-IPv6 mapping or its reverse verification.

Exam trap

Cisco often tests the misconception that an A record can be used for IPv6 addresses, but the A record is strictly for IPv4 (RFC 1035), while the AAAA record is the correct type for IPv6 (RFC 3596).

Why the other options are wrong

A

An A record maps a hostname to an IPv4 address, not an IPv6 address. Since the question specifically asks about IPv6, this record type is incorrect.

C

A CNAME record creates an alias from one domain name to another, not a direct mapping to an IP address. It does not provide the IP address itself, so it cannot verify the mapping to an IPv6 address.

E

MX records specify mail exchange servers for a domain and are used for email routing, not for mapping domain names to IP addresses. They do not provide IPv6 address mappings.

Why candidates pick the wrong answer

A

Students often confuse A and AAAA records because both are used for forward DNS resolution. The similar naming and purpose (mapping names to IPs) make A records a common distractor.

C

CNAME records are commonly used and can indirectly point to an IPv6 address via the target domain's AAAA record. Students may think that querying a CNAME will reveal the IPv6 address, but it only returns the canonical name.

E

MX records are a well-known DNS record type, and students might think they are used for general IP mapping due to their importance in email delivery. However, they are unrelated to IPv6 address verification.

652
Drag & Dropmedium

Which of the following shows the correct order of steps to troubleshoot a suspected duplex mismatch and CRC errors on a Cisco IOS-XE interface?

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The proper troubleshooting flow requires moving through the correct configuration hierarchy: from privileged EXEC mode you first enter global configuration mode. Then you specify the affected interface to enter interface configuration mode, where the duplex and speed settings are applied. After making the changes, you exit all configuration modes back to privileged EXEC and use show commands to verify the interface status.

Option A follows this exact sequence. Option B is wrong because it tries to enter interface configuration without global config. Option C mistakenly attempts to set duplex/speed globally, which is not allowed.

Option D not only omits global config but also exits to the wrong mode, leaving you in global configuration instead of privileged EXEC for verification.

Exam trap

A common trap is to forget that you must enter global configuration mode before interface configuration mode. Another trap is to think that duplex and speed can be set globally, but they are interface-specific. Always remember the correct hierarchy: privileged EXEC -> global config -> interface config.

Why candidates pick the wrong answer

B

Candidates might think they can jump directly to interface configuration mode from privileged EXEC mode, but the 'configure terminal' command is required first.

C

Candidates might confuse global configuration with interface-specific configuration, thinking that settings can be applied globally.

D

Candidates might think they can go directly to interface config and then exit to global config, but the correct flow is global -> interface -> exit (to privileged EXEC) -> verify.

653
Drag & Dropmedium

Select the correct sequence of steps to retrieve a specific interface's configuration via RESTCONF and apply a change to the interface description.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for using RESTCONF to modify an interface description is: first retrieve the current configuration with a GET request, parse the JSON or XML response, modify the description field, apply the change with a PUT or PATCH request, and finally verify the change with another GET request. This sequence is correctly described only in option A. Options B, C, and D are incorrect because they either apply changes before retrieving the configuration, modify before retrieving, or verify before applying, which would not work as intended.

Exam trap

The key trap is confusing the order of operations: you must retrieve before modifying, and apply before verifying. Candidates often mix up the sequence, especially placing verification too early or modification before retrieval.

Why candidates pick the wrong answer

B

Candidates might think they can directly apply a change without first retrieving the current configuration, but RESTCONF requires the full configuration to be sent in the PUT request.

C

Candidates might think they need to verify the current state before applying a change, but the verification step is to confirm the change was applied correctly.

D

Candidates might think they can directly push a new configuration without first reading the existing one, but RESTCONF typically requires a read-modify-write pattern.

654
MCQhard

An IPv6 host successfully reaches neighbors on its local segment, but it cannot reach remote IPv6 destinations. The host has a global unicast address and a correct prefix length. Which missing item is the strongest suspect?

A.A usable default router or next-hop route for off-link IPv6 traffic
B.A NAT rule translating IPv6 to IPv4
C.A VLAN trunk on the host NIC
D.A second global unicast address on the same interface
AnswerA

IPv6 hosts on a local segment can communicate with neighbors using Neighbor Discovery (ND) and link-local addresses, but any traffic destined beyond that segment must be forwarded by a router. Without a default router learned via ICMPv6 Router Advertisement or a manually configured static route, the host has no way to choose a next hop for off-link destinations. Thus the host would successfully reach on-link neighbors yet fail to reach anything outside the local segment.

Why this answer

The strongest suspect is the absence of a usable default router learned through IPv6 router advertisements or equivalent configuration. While local connectivity works because the host can communicate on its own link, remote IPv6 destinations require a next hop off the local segment. Option B is wrong because IPv6-to-IPv4 NAT is unnecessary for native IPv6 communication and would not be the primary cause of off-link failure.

Option C is wrong because a VLAN trunk on the host NIC is for carrying multiple VLANs, not for enabling off-link routing. Option D is wrong because a second global unicast address does not provide a default route; it only adds another local address.

Exam trap

Don't confuse local connectivity success with overall network configuration correctness. Always check for a default route when remote communication fails.

Why the other options are wrong

B

NAT rules are not required for native IPv6 communication and would not be the first suspect when a host cannot reach remote IPv6 destinations.

C

A VLAN trunk on the host NIC relates to Layer 2 segmentation, not to providing a default route for off-link IPv6 traffic.

D

A second global unicast address on the same interface does not supply the missing default route needed to reach off-link destinations.

When would these options actually be correct?

B

In a question where a network is transitioning from IPv4 to IPv6 and requires NAT64 to allow IPv6 hosts to communicate with IPv4 servers, a NAT rule translating IPv6 to IPv4 would be the correct answer. The question would specify that IPv6 hosts need to access IPv4 resources, making NAT essential.

C

In a different scenario where the question specifies that a host is configured to communicate with multiple VLANs and needs to reach devices on different VLANs, a misconfigured VLAN trunk could indeed prevent communication with remote devices. In such a case, the correct answer would focus on VLAN configurations affecting Layer 3 connectivity.

D

In a different scenario where a question asks about the configuration of multiple global unicast addresses on an interface, and the context involves load balancing or specific routing requirements, having a second global unicast address could be correct if it allows for proper routing or redundancy in a multi-homed setup.

Why candidates pick the wrong answer

B

Students familiar with IPv4 NAT might assume a similar translation is needed for IPv6, but IPv6 has a vast address space and does not rely on NAT for basic off-link communication.

C

A test-taker might confuse VLAN trunking with the need for a default gateway, especially if they recall that VLANs separate broadcast domains and routing is needed between them.

D

Some might think that multiple addresses could help with reachability, but IPv6 hosts can have multiple addresses (e.g., privacy extensions) without affecting routing. The core issue remains the lack of a default router.

655
PBQhard

You are connected to the Cisco WLC (WLC-1) via its management IP 192.168.1.10. The wireless network 'CorpNet' is configured but clients cannot associate. Troubleshoot and resolve the issue: clients report 'Association failed' and the SSID is not visible in site surveys. Ensure that after your fix, the SSID is broadcast, WPA3 is used, and the WLAN is mapped to VLAN 20. Also, verify the WLC management interface is accessible over HTTPS.

Network Topology
switchWLC-1clients

Hints

  • •Check if the WLAN is enabled and broadcasting the SSID.
  • •Verify that the WLAN is mapped to a user VLAN, not the management interface.
  • •Ensure HTTPS is enabled for web management access.
A.Enable the WLAN, set Broadcast SSID to Enabled, create a dynamic interface for VLAN 20 and map the WLAN to it, and enable the HTTPS server.
B.Enable the WLAN, set Broadcast SSID to Enabled, change the interface to the management interface, and enable the HTTPS server.
C.Enable the WLAN, keep Broadcast SSID Disabled for security, create a dynamic interface for VLAN 20 and map the WLAN to it, and enable the HTTPS server.
D.Enable the WLAN, set Broadcast SSID to Enabled, create a dynamic interface for VLAN 20 and map the WLAN to it, but leave HTTPS disabled for security.
AnswerA
solution
! WLC-1
config wlan 1 enable
config wlan 1 broadcast-ssid enable
config wlan 1 interface vlan20
config interface create vlan20 20
config interface address vlan20 192.168.20.1 255.255.255.0
config wlan 1 interface vlan20
ip http secure-server

Why this answer

The WLAN was disabled, the SSID was hidden (Broadcast SSID Disabled), and it was incorrectly mapped to the management interface instead of a user VLAN. Additionally, HTTPS access was disabled. The solution: enable the WLAN, enable SSID broadcast, change the interface to a VLAN 20 interface (e.g., create a dynamic interface 'vlan20' with VLAN 20), and enable the HTTPS server for management access.

Note: On an AireOS WLC, the correct commands use `config wlan enable <wlan_id>`, `config wlan broadcast-ssid enable <wlan_id>`, and `config network secureweb enable` for HTTPS.

Exam trap

This question tests your ability to identify multiple misconfigurations simultaneously. Common traps: confusing management interface with user VLANs, thinking hidden SSID is acceptable when broadcast is required, and overlooking the HTTPS requirement. Also, ensure you use AireOS-specific commands, not IOS commands like `ip http secure-server`.

Always verify all requirements in the question.

Why the other options are wrong

B

The specific factual error: The management interface is for WLC management traffic, not client data. Client traffic should be on a separate user VLAN.

C

The specific factual error: Broadcast SSID must be enabled for the SSID to be visible. Disabling it hides the SSID, which contradicts the requirement to make it visible.

D

The specific factual error: HTTPS must be enabled for management access. Disabling it would block HTTPS connections to the WLC.

Why candidates pick the wrong answer

B

Candidates might think the management interface is the only interface available or confuse it with a VLAN interface.

C

Candidates may believe hiding the SSID improves security and is acceptable, but the question explicitly requires the SSID to be broadcast.

D

Candidates might disable HTTPS thinking it reduces attack surface, but the question explicitly requires HTTPS access.

656
Multi-Selectmedium

Which TWO statements correctly describe the configuration and verification of IPv4 and IPv6 parameters for host connectivity, including default gateway, DNS, and subnet masks?

Select 2 answers
A.The subnet mask determines the DNS server address used by the host.
B.The default gateway must be on the same subnet as the host's IP address.
C.IPv6 hosts can only obtain their IP address via DHCPv6.
D.The command 'ipconfig /all' displays both IPv4 and IPv6 configuration details.
E.A host can reach any remote network if its default gateway is configured with any IP address.
AnswersB, D

For a host to deliver a frame to the default gateway, the gateway's IP must be in the same network/subnet as the host's interface, because the host uses ARP (or NDP for IPv6) to resolve the gateway's MAC address on the local link. If the gateway were on a different subnet, the host would not be able to reach it without another router on the local segment.

Why this answer

A host's default gateway must be on the same subnet to be reachable at Layer 2; otherwise, a circular dependency occurs. Option D is correct because the 'ipconfig /all' command displays both IPv4 and IPv6 configuration details, including IP address, subnet mask, default gateway, and DNS servers. Option A is wrong because the subnet mask determines the network and host portions of an IP address, not the DNS server address.

Option C is wrong because IPv6 hosts can obtain their IP address via SLAAC, DHCPv6, or static configuration; the phrase 'can only' makes it incorrect. Option E is wrong because the default gateway must be reachable (on the same subnet) and configured with an IP address that belongs to a router interface on that subnet, not just any IP address.

Exam trap

Cisco often tests the misconception that IPv6 hosts require DHCPv6 for address assignment, when in fact SLAAC is a common and valid method, and the question's wording 'can only' is the trap that eliminates Option C.

Why the other options are wrong

A

The subnet mask is used to determine the network portion of an IP address and the host portion, not the DNS server address. DNS server addresses are configured separately, either manually or via DHCP.

C

IPv6 hosts can obtain their IP address via Stateless Address Autoconfiguration (SLAAC), which does not require DHCPv6. DHCPv6 is optional and used for stateful configuration or to provide additional parameters.

E

The default gateway must be on the same subnet as the host's IP address; otherwise, the host cannot send Ethernet frames to it because the gateway's MAC address would not be reachable via ARP. An arbitrary IP address would not work.

Why candidates pick the wrong answer

A

Students might confuse the subnet mask with other configuration parameters, thinking it influences DNS server assignment because both are part of IP configuration.

C

Students familiar with IPv4 DHCP might assume IPv6 also requires a similar server-based address assignment, overlooking SLAAC as an alternative.

E

Students might think any IP address can serve as a default gateway, not realizing the necessity of Layer 2 adjacency for frame delivery.

657
MCQhard

Two switches should form an EtherChannel with LACP. One side is set to active and the other is set to passive. If the remaining interface settings match, what is the expected result?

A.The EtherChannel should form successfully.
B.The EtherChannel fails because both sides must be active.
C.The interfaces automatically become routed ports.
D.The switches delete the port-channel automatically.
AnswerA

In LACP, an interface configured as active actively sends LACP PDUs, while passive only responds to incoming PDUs. When one switch is active and the other passive, the active side's PDUs trigger the passive side to reply, allowing both devices to exchange port attributes and form a stable EtherChannel. The active/passive configuration is explicitly supported by the IEEE 802.3ad standard and is a common deployment for connecting to switches that do not support the active mode.

Why this answer

The EtherChannel should form successfully. In practical terms, active mode initiates LACP negotiation and passive mode listens and responds. Because one side is actively starting the negotiation, the bundle can come up if the interfaces also match in operational settings such as speed, duplex, switchport mode, and VLAN characteristics.

This is a classic LACP pairing question. Active/passive works. Passive/passive is the combination that usually fails to start the bundle.

Exam trap

Remember, LACP requires only one side to be active; passive mode will still respond.

Why the other options are wrong

B

LACP allows an active port to form a bundle with a passive port; the passive side simply waits for LACP packets from the active side. Therefore, both sides do not need to be active.

C

LACP mode does not change the Layer 2 or Layer 3 status of interfaces; it only controls the negotiation of EtherChannel bundling. Interfaces remain as switchports unless explicitly configured as routed ports.

D

LACP negotiation failure does not automatically delete the port-channel interface or its configuration. The port-channel remains, but the member ports will not bundle and will operate as individual ports.

When would these options actually be correct?

B

In a different scenario, if the question specified that both switches were configured to active mode without any passive configuration, then this option would be correct, as both sides must be active for the EtherChannel to establish.

C

If the question specified that the switches were configured to operate in a mode that requires routed ports, such as in a Layer 3 EtherChannel scenario, then this option would be correct. In that case, the interfaces would indeed become routed ports to facilitate Layer 3 communication.

D

This option would be correct in a scenario where the configuration of the switches is incorrect or incompatible, leading to a situation where the port-channel cannot be established, thus triggering an automatic deletion of the port-channel configuration.

Why candidates pick the wrong answer

B

Students often confuse LACP with PAgP, where desirable/auto pairing is similar, or mistakenly think that passive means the link will never form, but LACP passive can still respond to active requests.

C

Some might think that because LACP is a Layer 2 protocol, it could affect the interface mode, but it does not. The confusion may arise from the fact that EtherChannel can be configured on Layer 3 interfaces, but LACP itself does not convert them.

D

Students might think that if negotiation fails, the switch cleans up the configuration to avoid errors, but Cisco switches do not automatically remove configured port-channels; manual intervention is required.

658
Multi-Selectmedium

Which TWO statements correctly describe the configuration and verification of IPv4 and IPv6 parameters for host connectivity?

Select 2 answers
A.On a Windows host, the default gateway IPv4 address must be on the same subnet as the host's IPv4 address.
B.The IPv6 default gateway can be any global unicast address on the internet.
C.The subnet mask is used to define the host portion of an IPv4 address.
D.A DNS server address can be statically configured on a host or obtained dynamically via DHCP.
E.Configuring a DNS server is mandatory for a host to communicate with any other device on the same subnet.
AnswersA, D

On a Windows host, and on any IPv4 host, the default gateway address must reside on the same subnet as the host's own IPv4 address because the host must deliver Ethernet frames directly to the gateway using its MAC address, obtained via ARP. If the gateway were on a different subnet, the host would need to use another router to reach it, which contradicts the purpose of the default gateway as the immediate next hop. The host validates this by applying its own subnet mask to the gateway address and will reject it if it ends up in a different network.

Why this answer

For a host to reach outside its subnet, the default gateway's IP must be in the same subnet; otherwise the host cannot ARP for the gateway's MAC and traffic will fail. Option D is correct because DNS server addresses can be set manually or assigned via DHCP. Option B is wrong because IPv6 gateways must be on the same local link, not any global unicast address on the internet.

Option C is wrong because the subnet mask defines the network/subnet portion of an IPv4 address, not the host portion. Option E is wrong because DNS is used for name resolution; local IP communication on the same subnet works without DNS.

Exam trap

Cisco often tests the misconception that a default gateway can be any routable address, but the trap here is that both IPv4 and IPv6 default gateways must be on the same local subnet as the host for Layer 2 reachability.

Why the other options are wrong

B

An IPv6 default gateway must be on the same local link, not just any globally routable address.

C

The subnet mask identifies the network bits, not the host bits; the host portion is the inverse of the mask.

E

DNS resolves names to IPs; hosts on the same subnet can communicate with IP addressing alone, making DNS optional.

Why candidates pick the wrong answer

B

Students may confuse IPv6's large address space with the idea that any global unicast address could be used as a gateway, but they overlook that the gateway must be directly connected to the host's link.

C

The phrase 'determines the host portion' is ambiguous; students might think the mask directly sets the host bits, but it actually separates the address into network and host parts.

E

Students may think DNS is essential for all network communication because many applications rely on domain names, but they forget that direct IP communication does not require DNS.

659
MCQhard

A switch receives BPDUs on a user-facing port configured as an edge port, but instead of just blocking the port role it fully error-disables it. Which protection feature most likely explains that behavior?

A.BPDU Guard
B.Root guard
C.Port security
D.DHCP snooping
AnswerA

BPDU Guard is a security feature designed for edge or access ports, typically used with PortFast. When a port configured with BPDU Guard receives any BPDU, it immediately transitions to the err-disabled state, because an unexpected BPDU indicates that a switch or bridge is connected to an end-user segment. This prevents the possibility of a bridging loop caused by a rogue switch and does not require manual intervention beyond the initial configuration, though recovery can be automatic if err-disable timeout is set.

Why this answer

BPDU Guard most likely explains that behavior. In practical terms, BPDU Guard is used to protect ports that are expected to face ordinary endpoints, not other switches. If BPDUs appear on such a port, the device treats that as a serious topology-policy violation and shuts the port down.

This is different from features that merely influence spanning-tree role choice without fully error-disabling the interface.

Exam trap

Be careful not to confuse BPDU Guard with other spanning tree protection features that do not disable ports upon receiving BPDUs.

Why the other options are wrong

B

Root guard does not error-disable a port; instead, it places the port into a root-inconsistent state if a superior BPDU is received, preventing the port from becoming a root port. It is used to enforce the root bridge location, not to disable ports upon BPDU reception.

C

Port security restricts the number of MAC addresses learned on a port and can error-disable the port if a violation occurs (e.g., too many MAC addresses). It does not react to BPDUs; its focus is on MAC address learning, not spanning-tree BPDUs.

D

DHCP snooping is a security feature that filters DHCP messages and can error-disable a port if a DHCP violation occurs (e.g., rogue DHCP server). It does not inspect or react to BPDUs, which are layer 2 spanning-tree frames.

When would these options actually be correct?

B

In a scenario where a switch port is configured to prevent a non-root bridge from becoming the root bridge, a question could ask about the behavior of a port receiving BPDUs on a non-edge port. In that case, root guard would be the correct answer as it would block the port to maintain the intended topology.

C

If the question were about a switch port configured with port security that had a violation due to exceeding the allowed number of MAC addresses, and the switch subsequently error-disabled the port, then 'Port security' would be the correct answer.

D

In a scenario where the question asks about a switch port that is configured to prevent rogue DHCP servers and is receiving DHCP packets from an unauthorized source, DHCP snooping would be the correct answer if the port was shut down due to this violation.

Why candidates pick the wrong answer

B

Students may confuse root guard with BPDU Guard because both involve BPDU processing and protection. However, root guard's behavior is to keep the port operational but in a special state, not to error-disable it.

C

Port security is a common feature that causes error-disable, so test-takers might assume it applies here. However, the trigger for port security is MAC address violations, not BPDU reception.

D

DHCP snooping is another feature that can cause error-disable, leading to confusion. But its trigger is DHCP-related, not BPDU-related, so it is not applicable here.

660
MCQhard

A host address is 172.16.8.70/26. What is the network address of its subnet?

A.172.16.8.0
B.172.16.8.64
C.172.16.8.70
D.172.16.8.128
AnswerB

For a /26 prefix, the subnet mask is 255.255.255.192, which creates block sizes of 64 addresses in the fourth octet. The host address .70 lies in the range 64–127, so the network address is found by zeroing the host bits: 70 AND 192 = 64. Thus, 172.16.8.64 is the correct network address for this host.

Why this answer

A /26 uses blocks of 64 addresses. In plain language, the fourth-octet subnet ranges are 0–63, 64–127, 128–191, and 192–255. Since the host address ends in 70, it belongs to the 64–127 block. That means the network address of the subnet is 172.16.8.64.

This is a standard subnetting calculation. The key is to identify the correct block based on the prefix and then choose the first address in that block as the network address.

Exam trap

A frequent exam trap is mistaking the host IP address for the network address or selecting the wrong subnet block based on the subnet mask. Candidates often pick 172.16.8.0 because it looks like a common network address or 172.16.8.128 assuming it’s the next block, but these do not contain the host 172.16.8.70 under a /26 mask. The trap arises from not calculating subnet ranges correctly or misunderstanding how subnet masks segment the address space into fixed blocks.

This mistake leads to incorrect subnet identification and can cause routing or addressing errors in real networks.

Why the other options are wrong

A

172.16.8.0 is incorrect because the /26 subnet blocks cover 0–63, 64–127, etc., and the host address 70 does not fall within the 0–63 range. Selecting this ignores the actual subnet boundaries defined by the mask.

C

172.16.8.70 is incorrect because this is the host address itself, not the network address. The network address must be the first address in the subnet block, not a host address within it.

D

172.16.8.128 is incorrect because this subnet block starts at 128, which is above the host address 70. The host does not belong to this subnet, so this cannot be the network address.

When would these options actually be correct?

A

If the question asked for the network address of the subnet for a host address of 172.16.8.70 with a subnet mask of /24, then 172.16.8.0 would be the correct answer, as it represents the beginning of that subnet.

C

If the question asked for the specific host address within the subnet or if it was framed to identify a host's IP address rather than the network address, then 172.16.8.70 would be the correct answer.

D

In a different question, if the subnet mask were changed to /25, the network address would be 172.16.8.128. For example, a question asking for the network address of the subnet containing the host 172.16.8.130 with a /25 mask would make this option correct.

Why candidates pick the wrong answer

A

Students often mistakenly assume that the network address is always the first address of the entire /16 or /24 network, ignoring the subnetting. They might think 172.16.8.0 is the network address because it is the first address in the 172.16.8.0/24 range.

C

A student might confuse the host address with the network address, especially if they are not careful about the distinction between the two. They might think that the given IP address itself is the network address.

D

Students sometimes miscalculate the subnet boundaries, especially when the host address is near the boundary. They might incorrectly think that 70 is close to 128 and choose 172.16.8.128 without performing the proper calculation.

661
Drag & Dropmedium

Drag and drop the following steps into the correct order to sequence the DNS resolution process from a client query to receiving an A-record response, followed by the diagnostic workflow using nslookup and dig to identify a missing or incorrect A-record.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The standard DNS resolution sequence ends with the client receiving the A-record. Troubleshooting uses nslookup first for basic checks, then dig +trace for detailed path analysis.

Exam trap

Do not confuse the client's initial query destination (configured DNS server, not root) and remember the troubleshooting order: nslookup before dig +trace. Also, avoid inserting extra steps like explicit cache returns.

Why candidates pick the wrong answer

B

Candidates may think the client directly queries root servers, or they may confuse the order of troubleshooting tools.

C

Candidates might think dig +trace is more powerful and should be used first, but nslookup is simpler and should be the initial diagnostic step.

D

Candidates may overcomplicate the process by explicitly including cache behavior, but the question expects the standard iterative resolution steps without extra detail.

662
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure a switch port for data and voice traffic.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order is: 1) Enter interface configuration mode, because all port-specific commands must be applied under the interface. 2) Set the port as an access port with 'switchport mode access'—a voice VLAN can only be assigned on an access port. 3) Assign the data VLAN with 'switchport access vlan' to ensure proper Layer 2 forwarding for data traffic. 4) Assign the voice VLAN with 'switchport voice vlan' so the IP phone's voice frames are tagged with the voice VLAN. 5) Enable PortFast with 'spanning-tree portfast' to immediately transition the port to forwarding, preventing DHCP timeouts for the phone and host.

663
MCQhard

A network engineer is troubleshooting a router that is not forwarding traffic to a remote network. The router has a static route configured for that network, but the next-hop address is not directly connected and is not reachable via any other route. What is the most likely cause of the problem?

A.The static route is configured with a wildcard mask instead of a subnet mask.
B.The static route has an administrative distance that is too low.
C.The router needs to have IP routing enabled to use static routes.
D.The static route is not installed in the routing table because the next-hop is unreachable.
AnswerD

For a static route with a next-hop address to be installed, the router must be able to resolve the next-hop via a directly connected network or another route. If the next-hop is unreachable, the route is not installed, and traffic is not forwarded. This is the most likely cause.

Why this answer

A static route with a next-hop address requires that the next-hop be reachable through a directly connected network or another route. If it is not reachable, the route is not installed in the routing table, and traffic is not forwarded. The other options are less likely because administrative distance, mask type, and IP routing are not the primary causes of this specific symptom.

Exam trap

The trap here is assuming that a configured static route is automatically active; it must have a reachable next-hop to be installed.

664
Matchingmedium

Drag and drop the syslog severity levels and NTP concepts on the left to their correct descriptions on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Emergency: system is unusable

Debugging: detailed debug messages

Reference clock (e.g., atomic clock or GPS)

Unsynchronized or maximum usable stratum

Configures an IOS-XE device as an NTP client

Displays NTP synchronization state and stratum

Why these pairings

Syslog severity levels range from 0 (Emergency) to 7 (Debug), with 0 being the most critical. NTP stratum indicates clock accuracy: stratum 0 is the reference clock, stratum 1 is directly connected to a reference, and so on up to stratum 15, which is the maximum usable synchronized stratum. Stratum 16 means the device is unsynchronized.

The ntp server command configures a device as a client, and show ntp status displays synchronization state and current stratum.

Exam trap

Be careful not to confuse the severity order of syslog levels: lower numbers (0) are more severe, higher numbers (7) are less severe. Also, remember that NTP stratum numbers work inversely to accuracy: lower stratum numbers indicate higher accuracy, with Stratum 0 being the most accurate reference clock.

Why candidates pick the wrong answer

B

Candidates might think Stratum 0 is the lowest level in the hierarchy and thus a client, but in NTP, lower stratum numbers indicate higher accuracy, and Stratum 0 is the top.

C

Candidates may confuse the highest number (7) with the most severe, but in syslog, lower numbers are more severe.

D

Candidates might pick this if they have multiple misconceptions, such as thinking higher syslog numbers are more severe and that Stratum 0 is a client.

665
MCQmedium

Which rule does a router apply first when selecting a route for a destination packet?

A.Lowest metric across all protocols
B.Oldest route in the routing table
C.Longest prefix match
D.Default route if one exists
AnswerC

A router's IP forwarding logic first identifies all routes whose prefix matches the destination address's network portion. It then selects the route with the longest subnet mask because that prefix is the most specific representation of the destination, even if that route has a higher metric. This rule is non-negotiable and precedes any metric or administrative-distance comparison.

Why this answer

Routers first look for the most specific matching prefix. Administrative distance and metrics matter when competing routes exist for the same destination prefix length.

Exam trap

Remember, prefix length is the primary factor in route selection, not administrative distance or metrics.

Why the other options are wrong

A

The router first uses the longest prefix match to select a route; metrics are only compared among routes from the same routing protocol or when administrative distance is equal. Comparing metrics across different protocols is not the first step.

B

Route age is not a primary selection criterion; routers use longest prefix match first, then administrative distance, then metric. Older routes are not preferred over newer ones in the selection process.

D

A default route is only used when no other route matches the destination; the router first checks for more specific matches using the longest prefix match. The default route is the least preferred.

When would these options actually be correct?

A

In a question focused on route selection across multiple routing protocols where the lowest metric is explicitly defined as the primary selection criterion, such as in a scenario comparing OSPF and EIGRP routes, this option would be correct.

B

If the exam question asked which route a router would choose when all other metrics are equal, and the only differentiating factor is the age of the routes, then selecting the oldest route could be considered correct in that specific context.

D

If the exam question asked which route a router would select when no specific routes exist for a destination, then option D would be correct. In this scenario, the router would use the default route as a fallback to forward packets.

Why candidates pick the wrong answer

A

Students often confuse the order of route selection, thinking that lower metric is always preferred, but metric comparison occurs only after the longest prefix match and administrative distance checks.

B

Some might think that older routes are more stable or trusted, but route age is irrelevant for forwarding decisions; it is only used in some routing protocols for tie-breaking (e.g., OSPF) but not as the first rule.

D

Students may think that a default route is a catch-all and thus applied first, but in reality, it is the last resort after all other routes have been evaluated.

666
MCQeasy

A switchport should allow only one learned MAC address and shut down if a different device is connected later. Which port security violation mode and limit combination best fits that goal?

A.maximum 1 with violation shutdown
B.maximum 10 with violation protect
C.maximum 1 with violation restrict and no logging
D.maximum unlimited with violation shutdown
AnswerA

This is the only configuration that meets the stated requirement exactly: port-security with a maximum of 1 restricts the interface to a single learned MAC address, and the shutdown violation mode immediately places the port into the err-disabled state if a second address is seen, effectively blocking all traffic on the port until an administrator manually re-enables it. Because both criteria—one learned MAC and automatic shutdown—are satisfied, this is the correct answer.

Why this answer

The usual setup is maximum 1 MAC address with violation mode shutdown. That way the port is disabled when an unauthorized device appears.

Exam trap

Be careful not to confuse the different port security violation modes. Only shutdown mode disables the port upon a violation.

Why the other options are wrong

B

The maximum limit of 10 MAC addresses is too high for the requirement of allowing only one learned MAC address. Additionally, protect mode drops frames from unknown MACs but does not shut down the port, so the port remains active even after a violation.

C

Restrict mode does not shut down the port; it only logs and drops frames from unknown MACs. The requirement explicitly states the port should shut down, which restrict does not achieve.

D

Setting the maximum to unlimited defeats the purpose of limiting MAC addresses to one. Even though violation mode is shutdown, the port will never trigger a violation because there is no limit, so it will never shut down due to port security.

When would these options actually be correct?

B

In a different scenario where the requirement is to allow multiple devices for redundancy, a question might ask for a configuration that permits up to 10 MAC addresses while using 'protect' mode to prevent traffic disruption. This would be suitable in environments where device changes are frequent but should not cause immediate shutdowns.

C

This option would be correct in a scenario where the requirement is to limit the number of MAC addresses to one, but the organization prefers to log the violations and continue allowing traffic from the first learned MAC address without shutting down the port.

D

In a different scenario where the requirement is to allow any number of devices to connect without restriction, and the goal is to shut down the port only after a specific security threshold is reached, option D would be appropriate. For example, a question might ask for a configuration that allows multiple devices but requires shutdown after a certain security incident.

Why candidates pick the wrong answer

B

Students might confuse protect mode with shutdown mode, thinking it also disables the port. The term 'protect' sounds secure, but it only drops traffic without disabling the port.

C

Students may think restrict is a stricter action than it actually is, or they may overlook the 'no logging' part and assume restrict includes shutdown.

D

Students might focus only on the violation mode 'shutdown' and ignore the maximum limit, thinking that shutdown alone ensures the port will be disabled. However, without a limit, no violation occurs.

667
MCQhard

A router has routes to 192.168.100.0/24 and 192.168.100.128/25. Which route is used for traffic to 192.168.100.140?

A.192.168.100.0/24
B.192.168.100.128/25
C.The default route
D.Neither route, because the prefixes overlap
AnswerB

192.168.100.140 falls inside 192.168.100.128/25, whose range spans .128 to .255. Longest-prefix match governs route selection, so the /25 wins over the broader /24 despite both covering the destination. The more specific mask satisfies the forwarding decision.

Why this answer

The /25 route is used because it is the most specific matching prefix. In practical terms, 192.168.100.140 falls inside the upper half of the /24, which is exactly what the 192.168.100.128/25 route describes. Even though the /24 also matches, the router always prefers the narrower route when both are valid.

This is a direct longest-prefix-match question. It reinforces that specificity is checked before broader route-source preferences matter.

Exam trap

A frequent exam trap is assuming that the less specific route (192.168.100.0/24) will be used simply because it covers the entire subnet range or because it might have a better administrative distance. Candidates might also think overlapping prefixes cause routing conflicts that prevent either route from being used. However, Cisco routers resolve overlapping routes by always selecting the longest prefix match, which is the most specific subnet.

Ignoring this rule leads to incorrect answers and misunderstanding of routing behavior.

Why the other options are wrong

A

The 192.168.100.0/24 route is less specific than the 192.168.100.128/25 route. Although it matches the destination IP, the router prefers the more specific /25 route, so this option is incorrect.

C

The default route is only used when no more specific routes match the destination IP. Since both /24 and /25 routes match, the default route is not used, making this option incorrect.

D

Although the prefixes overlap, this is a normal and expected behavior in routing. The router resolves overlapping prefixes using longest prefix match, so traffic is forwarded correctly. Therefore, this option is incorrect.

When would these options actually be correct?

A

In a scenario where the question asks which route would be used for traffic to an IP address like 192.168.100.50, the option 192.168.100.0/24 would be correct, as it encompasses the entire /24 subnet and is the only applicable route for that address.

C

In a different question context where no specific routes are defined for the destination IP, and the router has only a default route configured (0.0.0.0/0), the default route would be the only option available for routing traffic to any unknown destination.

D

In a scenario where the question states that both routes are configured with the same prefix length and the router is set to prefer the longest prefix match, a question could ask which route is used for a specific address, leading to confusion about overlapping routes. In that case, if both routes were truly overlapping, the answer could be 'neither' due to ambiguity.

Why candidates pick the wrong answer

A

Students might think that because 192.168.100.140 falls within the /24 range, the /24 route would be used, forgetting that a more specific (longer prefix) route takes precedence.

C

Students may confuse the concept of default route with a catch-all, thinking it might be used when there are overlapping routes, but the longest prefix match rule always applies first.

D

Some students might think overlapping routes cause ambiguity or errors, but routers are designed to handle them by selecting the most specific prefix.

668
MCQhard

Based on the exhibit, why is the static route not being used for 172.18.9.10?

A.Because the connected /24 route is more specific than the static /16 route.
B.Because static routes are never used when a connected network exists anywhere in the table.
C.Because connected routes always have administrative distance 255.
D.Because static routes work only for default routing.
AnswerA

The router uses the longest-prefix match rule when selecting a route, so the /24 connected route is preferred over the /16 static route because it is more specific. The static /16 route remains in the routing table and will be used for other destinations in the 172.16.0.0/16 range that are not covered by the /24. Thus, the static route is not used for that particular subnet because of the /24's longer mask.

Why this answer

The static route is not being used because the connected route is the more specific match. In practical terms, route selection starts with prefix specificity. The static route covers a broad /16, but the destination 172.18.9.10 also falls inside a connected /24. The /24 wins because it is more specific.

This is a classic routing interpretation question because it tests whether you apply longest-prefix logic before thinking about route source preference.

Exam trap

A common exam trap is assuming that static routes are always preferred over connected routes or that connected routes have a higher administrative distance. Candidates might overlook the longest-prefix match rule and focus only on administrative distance or route type. This leads to the incorrect conclusion that the static /16 route should be used for 172.18.9.10, ignoring that the connected /24 route is more specific and therefore preferred.

Misunderstanding this concept causes errors in interpreting routing tables and route selection behavior.

Why the other options are wrong

B

This is incorrect because static routes are still used when no connected route matches the destination. The presence of any connected route does not prevent static routes from being used if they are more specific or the only match.

C

This is wrong because connected routes have an administrative distance of 0, not 255. The issue here is route specificity, not administrative distance values.

D

This is incorrect because static routes can be configured for any prefix length, not just default routes. They are valid for specific subnets and are commonly used for precise routing control.

When would these options actually be correct?

B

In a different scenario where a question asks if static routes are ever ignored when a connected route exists, and the context specifies that no other routing metrics apply, this option could be correct. For instance, if the question states that static routes are completely disregarded in the presence of any connected routes, option B would be accurate.

C

In a different scenario where the question states that all routes, including connected routes, have an administrative distance of 255, this option would be correct. For example, if the exam asks why a static route is preferred over a connected route with an artificially high administrative distance, then option C would apply.

D

In a question where the context specifies that only default routes are being considered for routing decisions, and no other static routes are present, this option could be correct. For example, if the question states that all other routes are dynamic or connected, and only a default static route is configured, then it would be accurate to say static routes work only for default routing.

Why candidates pick the wrong answer

B

Students might think that connected routes always take precedence over static routes, but that is not true; the decision is based on prefix length and administrative distance, not simply the presence of a connected network.

C

Test-takers may confuse administrative distance values or think that connected routes have a high AD, but in reality, they are the most preferred. The mention of 255 might be associated with routes that are not installed.

D

Some students may think static routes are only for default routes because they often see 'ip route 0.0.0.0 0.0.0.0' in examples, but static routes can be used for any destination.

669
MCQmedium

Exhibit: A script sends an HTTP GET request to a controller API endpoint. What is the usual purpose of the GET method?

A.Retrieve information from the resource
B.Create a brand-new resource
C.Replace the entire resource configuration
D.Delete the resource
AnswerA

The HTTP GET method is defined as a safe, idempotent request that retrieves a representation of the resource identified by the URI without altering server state. In the context of a controller API, GET is specifically used to read current configuration, status, or data. A successful GET returns a 200 OK response with the payload, making it the correct method for retrieval.

Why this answer

In REST-style APIs, GET is normally used to retrieve data from a resource. It is not the standard method for creating or replacing resources.

Exam trap

Be careful not to confuse GET with other HTTP methods like POST, PUT, or DELETE, which have different purposes.

Why the other options are wrong

B

Creating a new resource is typically done using the POST method, not GET. GET is designed for safe and idempotent retrieval of data, not for creating resources.

C

Replacing the entire resource configuration is the purpose of the PUT method, which is idempotent and used for updates. GET is not intended for modifying resources.

D

Deleting a resource is performed using the DELETE method. GET is a safe method that should not have side effects like deletion.

When would these options actually be correct?

B

In a different exam scenario, if the question asked about the HTTP POST method and its purpose in a RESTful API context, option B would be correct, as POST is used to create new resources on the server.

C

In a different question, if the context were about the HTTP PUT method and the question asked about its purpose, then option C would be correct as PUT is used to replace the entire resource configuration at the specified URI.

D

In a different question, if it asked about the purpose of the DELETE method in an API context, option D would be correct, as it would pertain to the action of removing a specified resource from the server.

Why candidates pick the wrong answer

B

Students might confuse GET with POST because both are common HTTP methods, but they serve different purposes. The word 'get' might be misinterpreted as 'obtain a new resource' rather than 'retrieve existing data'.

C

Some might think GET can be used to 'get' a new configuration by replacing it, but this is incorrect. The similarity in naming between 'GET' and 'PUT' can cause confusion.

D

Students might associate 'GET' with any action that retrieves or removes data, but DELETE is specifically for removal. The word 'get' might be loosely interpreted as 'get rid of'.

670
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure an LACP EtherChannel on Cisco IOS-XE switches.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First, enter global config mode. Then create the port-channel interface. Next, configure the channel-group mode on each physical interface to active for LACP.

Finally, verify the configuration.

Exam trap

A common trap is to configure the channel-group mode on physical interfaces before creating the port-channel interface, or to forget that global configuration mode is the first step. Always remember the sequence: global config -> port-channel interface -> physical interface channel-group -> verification.

Why candidates pick the wrong answer

B

Candidates might think that creating the port-channel interface is the first step, but they forget that global config mode is required first.

C

Candidates might think that configuring the physical interfaces first is correct, but the port-channel interface must be created first.

D

Candidates might think that creating the port-channel interface is the first step and that verification can be done earlier, but the sequence is incorrect.

671
MCQhard

A router is performing PAT for inside users. Which detail allows multiple inside sessions to share one public IPv4 address at the same time?

A.Use of transport-layer port numbers to distinguish sessions
B.Replacement of all MAC addresses with broadcast addresses
C.Automatic conversion of every subnet into a /32
D.Requirement that every inside host use the same private IP address
AnswerA

PAT (Port Address Translation) relies on the TCP or UDP port numbers to differentiate multiple simultaneous sessions from different inside hosts that all share the same public IP address. When a host sends a packet, the router assigns a unique source port, stores the mapping in its NAT table, and later uses that port to reverse the translation and deliver the response to the correct private host.

Why this answer

PAT works because it uses transport-layer port numbers to keep different conversations distinct even when they share the same public IP address. In plain language, the router rewrites and tracks port information so that return traffic can be matched back to the correct inside host and application session. That is what makes one public address usable for many simultaneous internal users.

This is a key difference between PAT and simple static NAT. Static NAT creates a fixed one-to-one relationship, while PAT creates many simultaneous translations differentiated by port values. The correct answer is the one that identifies port-based tracking as the reason the design scales beyond a single host.

Exam trap

Remember, PAT uses port numbers to differentiate sessions, not MAC addresses, IP addresses, or VLAN IDs.

Why the other options are wrong

B

PAT does not replace MAC addresses with broadcast addresses; MAC addresses are used for local network segment communication and are not involved in NAT/PAT operations. Broadcast addresses are used for sending packets to all hosts on a subnet, which would not help in distinguishing individual sessions.

C

PAT does not convert subnets into /32 addresses; it translates private IP addresses and port numbers to a single public IP address with different port numbers. Changing subnet masks to /32 would imply host-specific routing, which is not how PAT functions.

D

PAT does not require all inside hosts to use the same private IP address; in fact, each host typically has a unique private IP address. PAT translates these unique private addresses to the same public IP but with different port numbers to maintain session uniqueness.

When would these options actually be correct?

B

In a different context, a question could ask about the effects of broadcast traffic on a network, where replacing MAC addresses with broadcast addresses might be a method to ensure that all devices receive a message, making this option correct in that scenario.

C

In a different context, a question could ask about the implications of subnetting in a network design where each host must be uniquely identifiable, and the correct answer would be that converting every subnet into a /32 ensures that each device has a unique address, suitable for certain routing scenarios.

D

In a different scenario where the question asks about a network configuration that enforces strict IP address management, such as a highly controlled environment where multiple devices must share a single private IP for security reasons, this option could be correct. The question might specify that all devices are configured to use the same private IP for internal routing.

Why candidates pick the wrong answer

B

Students might confuse the concept of address translation with MAC address manipulation or think that broadcasting is used to reach all hosts, but PAT operates at Layer 3 and Layer 4, not Layer 2.

C

The idea of using a /32 mask might be tempting because PAT effectively makes the public IP address appear as a single host address, but the mechanism is port-based translation, not subnet mask manipulation.

D

A student might think that since PAT uses one public IP, all inside hosts must have the same private IP, but that would cause address conflicts. PAT relies on unique private addresses combined with port numbers for translation.

672
Multi-Selectmedium

Which single OSI model layer is responsible for both end‑to‑end reliable data delivery and segmenting data into smaller units?

Select 1 answer
A.Transport layer (Layer 4)
B.Data Link layer (Layer 2)
C.Network layer (Layer 3)
D.Session layer (Layer 5)
E.Transport layer (Layer 4) and Network layer (Layer 3)
AnswersA

The Transport layer (Layer 4) is correct: it accepts data from the Session layer, divides it into segments, and is responsible for end-to-end delivery. TCP, a Transport layer protocol, provides reliable delivery via sequence numbers, acknowledgments, timeouts, and retransmissions, while UDP is a simpler, unreliable transport alternative. This layer is uniquely positioned to ensure that the entire message arrives intact and in order across the network.

Why this answer

The Transport layer (Layer 4) is the only OSI layer responsible for both end‑to‑end reliable data delivery (via protocols like TCP) and segmenting data into smaller units (segments). The Network layer (Layer 3) handles routing and packetizing but does not provide reliability. Therefore, only the Transport layer fulfills both requirements.

Exam trap

Candidates may think the Network layer also performs both functions because it segments data into packets and provides end‑to‑end delivery, but reliability is strictly a Transport layer function. The question asks for a single layer, so combining Transport and Network is incorrect.

Why the other options are wrong

B

The Data Link layer handles framing and error detection on a single link, not end‑to‑end reliability or segmentation across the entire network.

C

The Network layer provides routing and logical addressing but does not guarantee delivery or perform segmentation of data from applications.

D

The Session layer manages dialog control between applications, not data segmentation or reliable transport mechanisms.

When would these options actually be correct?

E

In real enterprise networks, the Transport layer (Layer 4) ensures end-to-end reliable delivery (e.g., TCP) and segments data into segments. The Network layer (Layer 3) provides logical addressing and routing of packets, which is essential for end-to-end delivery across multiple networks. Together, they directly support end-to-end communication, though segmentation is exclusively a Transport layer function.

Why candidates pick the wrong answer

B

Students might confuse the Data Link layer's framing with segmentation, as both involve breaking data into smaller units. However, framing occurs at Layer 2 and is for local delivery, while segmentation at Layer 4 is for end-to-end transport.

C

Students might think the Network layer handles segmentation because it deals with packets, but packets are the PDU of Layer 3 and are created from segments. The actual segmentation occurs at Layer 4.

D

Students might associate 'session' with end-to-end communication and mistakenly think the Session layer handles reliable delivery. However, reliability is a Transport layer responsibility.

673
MCQhard

Users in VLAN 60 on switch SW2 cannot reach the default gateway located on switch SW1. The trunk between SW1 and SW2 is operational and allows VLAN 60. What is the most likely reason for this issue?

A.VLAN 60 does not exist locally on SW2.
B.The native VLAN must be changed to 60 on both switches.
C.VLAN 60 is not allowed on the trunk link.
D.The default gateway must be configured as a loopback on SW2.
AnswerA

This is the most likely reason: SW2 has not been created with VLAN 60, so it does not have a spanning-tree instance or a switch virtual interface for that VLAN. Even if the trunk port with SW1 allows VLAN 60 and receives tagged frames, those frames are discarded because the VLAN is not present in SW2's VLAN database. Consequently, users in VLAN 60 cannot communicate through SW2, and no access port or SVI can be assigned to that VLAN.

Why this answer

VLAN 60 has not been created locally on SW2, even though the trunk can carry its traffic. A switch never processes VLAN traffic for a VLAN it doesn't know about; it discards tagged frames from the trunk destined for that VLAN and prevents access ports from assigning frames to it. (A) is correct. (B) is incorrect because native VLAN configuration only affects untagged frames—changing it to 60 is unnecessary for tagged VLAN 60 traffic. (C) is incorrect because the trunk is already configured to allow VLAN 60, so trunk filtering isn't the problem. (D) is incorrect because a default gateway is simply an IP address on a router or Layer 3 switch interface (like SVIs) and does not require a loopback on SW2.

Exam trap

Don't assume trunk configuration alone resolves VLAN issues; ensure VLANs exist on all relevant switches.

Why the other options are wrong

B

Native VLAN configuration does not affect tagged VLAN 60 traffic—native VLAN only matters for untagged frames.

C

The trunk is stated to allow VLAN 60, so VLAN filtering is not the problem; a student might misread the premise.

D

The default gateway resides on SW1, not SW2; configuring a loopback on SW2 does not create a gateway for VLAN 60.

When would these options actually be correct?

B

In a different scenario where the question asks about VLAN configuration issues related to untagged traffic, changing the native VLAN to 60 could be necessary to ensure that devices on VLAN 60 can communicate properly with devices on other VLANs that are also configured to use the same native VLAN.

C

In a different scenario, if the question specified that only PPP encapsulation is allowed for VLANs on a trunk link, then this option could be correct. For example, if the question stated that VLANs are only operational when PPP is configured on the trunk, then this option would apply.

D

In a different scenario where the question specifies that the network design requires the default gateway to be a loopback interface for redundancy or routing purposes, this option could be correct. For instance, if the exam question states that SW2 must use a loopback interface for routing protocols, then this option would be valid.

Why candidates pick the wrong answer

B

Students often confuse the native VLAN with the VLAN that carries user traffic. They might think that setting the native VLAN to 60 would allow VLAN 60 traffic to pass, but native VLAN is only for untagged frames and does not affect tagged VLAN forwarding.

C

Test-takers might confuse PPP with a protocol that can carry multiple VLANs, but PPP is a layer 2 protocol for point-to-point links and does not support VLANs. The mention of 'PPP' might be mistaken for 'P' in '802.1Q' or a similar acronym.

D

Students might think that a loopback interface can serve as a default gateway because it is always up. However, the default gateway must be on the same subnet as the hosts and reachable via the VLAN. Configuring a loopback on SW2 would not provide connectivity to SW1's gateway.

674
MCQhard

After a hub was connected to interface Gi0/10, the interface immediately entered errdisable state. The following syslog message was generated: '%PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occurred on interface Gi0/10.' What is the strongest explanation for why Gi0/10 shut down?

A.Port security detected more MAC addresses than allowed on the interface.
B.The interface received a superior BPDU and became the root port.
C.The hub forced the interface to become a routed port.
D.DHCP snooping always shuts a port when a hub is attached.
AnswerA

Port security is explicitly configured to allow only one secure MAC address, and the violation message indicates that additional MAC addresses were seen on the interface. When a hub connects, multiple end devices share that single physical port, causing the switch to detect more source MACs than the configured maximum. This triggers the port-security violation and puts the interface into an error-disabled state, matching the exhibit.

Why this answer

The strongest explanation is a port-security violation caused by the switch seeing more secure MAC addresses than the interface allows. In practical terms, a hub or unmanaged device can cause multiple end hosts to appear behind one access port. If the interface is configured with a maximum of one secure MAC address, additional learned MACs trigger the violation action.

This is a realistic access-layer security scenario because the port does not fail randomly. It fails because the observed behavior violates the configured policy.

Exam trap

Remember that port security specifically deals with MAC address limits, not broadcast storms or spanning-tree issues.

Why the other options are wrong

B

The exhibit shows a port-security violation message, not an STP topology change. A superior BPDU would cause a root port election, not a port shutdown due to security policy.

C

Connecting a hub does not change the interface type; a switchport remains a Layer 2 interface unless explicitly configured with 'no switchport'. The exhibit shows a Layer 2 security violation, not a routed port conversion.

D

DHCP snooping does not automatically shut down a port when a hub is attached; it filters DHCP messages and can disable ports only if a DHCP server is detected on an untrusted port. The exhibit clearly shows a port-security violation message.

When would these options actually be correct?

B

In a different question, if the scenario described involved a switch that was configured to participate in a spanning tree topology and received a superior BPDU from another switch, this option would be correct. The question would need to focus on spanning tree behavior rather than port security.

C

In a different scenario, if the question specified that the interface was configured to operate as a routed port and the hub was connected, causing a configuration change or a specific routing protocol behavior, this option could be correct. For example, if the exam asked about a network where the hub's behavior led to a routing protocol conflict, this could apply.

D

In a different question, if the scenario involved a network where DHCP snooping was explicitly configured to shut down ports upon detecting unauthorized devices, then this option could be correct. For instance, a question could describe a network with strict DHCP snooping policies and ask about the behavior of a port when a hub is connected.

Why candidates pick the wrong answer

B

Students often confuse STP events with port security because both can cause a port to change state. The term 'superior BPDU' sounds plausible for a port going down, but the actual cause is a security violation.

C

Some students might think that hubs introduce Layer 1 issues that could force a port to become routed, but this is not a standard behavior. The concept of routed ports is often misunderstood.

D

DHCP snooping and port security are both security features that can cause port shutdowns, leading to confusion. Students may incorrectly attribute the shutdown to DHCP snooping without reading the violation message.

675
PBQhard

You are connected to the multilayer switch MLS1 in a branch network. The DHCP server on router R1 is supposed to serve the 192.168.20.0/24 VLAN 20, but clients in VLAN 20 are not receiving IP addresses. Additionally, a rogue DHCP server has been detected on VLAN 20. Configure MLS1 to enable DHCP snooping on VLAN 20, set the trust state on the uplink port to R1, and limit the rate of DHCP packets on access ports. Then, on R1, correct the DHCP configuration so that the pool for VLAN 20 uses the correct default-router (192.168.20.1) and DNS server (8.8.8.8), and ensure that the excluded-address range is not too large (exclude only the first 10 addresses). Verify the solution.

Network Topology
G0/010.0.0.2/30G0/010.0.0.1/30linkG0/1 access VLAN 20192.168.20.0/24linkSiMLS1R1Clients

Hints

  • •On MLS1, DHCP snooping must be globally enabled and then applied to VLAN 20.
  • •The uplink to R1 must be trusted; access ports should have rate limiting to prevent DHCP starvation.
  • •On R1, the excluded-address range was too broad; only exclude the first 10 addresses. The default-router and DNS server were incorrect.
A.On MLS1: ip dhcp snooping, ip dhcp snooping vlan 20, interface Gig0/0 ip dhcp snooping trust, interface Gig0/1 ip dhcp snooping limit rate 10. On R1: ip dhcp excluded-address 192.168.20.1 192.168.20.10, ip dhcp pool VLAN20 network 192.168.20.0 255.255.255.0 default-router 192.168.20.1 dns-server 8.8.8.8
B.On MLS1: ip dhcp snooping vlan 20, interface Gig0/0 ip dhcp snooping trust, interface Gig0/1 ip dhcp snooping limit rate 10. On R1: ip dhcp excluded-address 192.168.20.1 192.168.20.254, ip dhcp pool VLAN20 network 192.168.20.0 255.255.255.0 default-router 192.168.20.1 dns-server 8.8.8.8
C.On MLS1: ip dhcp snooping vlan 20, interface Gig0/0 ip dhcp snooping trust, interface Gig0/1 ip dhcp snooping limit rate 10. On R1: ip dhcp excluded-address 192.168.20.1 192.168.20.10, ip dhcp pool VLAN20 network 192.168.20.0 255.255.255.0 default-router 192.168.10.1 dns-server 4.4.4.4
D.On MLS1: ip dhcp snooping vlan 20, interface Gig0/0 ip dhcp snooping trust, interface Gig0/1 ip dhcp snooping limit rate 10. On R1: ip dhcp excluded-address 192.168.20.1 192.168.20.10, ip dhcp pool VLAN20 network 192.168.20.0 255.255.255.0 default-router 192.168.20.1 dns-server 8.8.8.8, but no ip dhcp snooping enabled globally on MLS1
AnswerA
solution
! R1
configure terminal
ip dhcp excluded-address 192.168.20.1 192.168.20.10
ip dhcp pool VLAN20_POOL
default-router 192.168.20.1
dns-server 8.8.8.8
end

! MLS1
ip dhcp snooping
ip dhcp snooping vlan 20
interface GigabitEthernet0/0
ip dhcp snooping trust
exit
interface GigabitEthernet0/1
ip dhcp snooping limit rate 10
end

Why this answer

The problem had three faults: First, the DHCP pool on R1 had a wrong default-router (192.168.10.1 instead of 192.168.20.1) and an incorrect DNS server (4.4.4.4 instead of 8.8.8.8). Second, the excluded-address range was too large (excluding all addresses from .1 to .254 effectively blocked all dynamic assignments; corrected to exclude only .1 through .10). Third, DHCP snooping was disabled on MLS1, allowing a rogue DHCP server.

To enable DHCP snooping, both the global `ip dhcp snooping` command and the VLAN-specific `ip dhcp snooping vlan 20` command are required. With snooping enabled, the uplink port Gig0/0 was set as trusted and the access port Gig0/1 was configured with rate limiting to prevent DHCP starvation attacks.

Exam trap

Watch for three separate issues: DHCP pool misconfiguration (default-router, DNS, excluded range), DHCP snooping not enabled globally, and the need to set trust on the uplink. Candidates often forget the global 'ip dhcp snooping' command or misconfigure the excluded range.

Why the other options are wrong

B

The excluded-address range is too large; it should only exclude the first 10 addresses (1-10) to allow dynamic allocation from .11 onward.

C

The default-router must be the gateway for VLAN 20 (192.168.20.1), and the DNS server should be 8.8.8.8 as specified.

D

The global 'ip dhcp snooping' command is required to activate the feature; omitting it leaves DHCP snooping disabled entirely.

Why candidates pick the wrong answer

B

Candidates might think excluding a large range is safe, but it blocks all usable addresses, leaving no addresses for DHCP clients.

C

Candidates may confuse VLAN 20 with VLAN 10 or use a different DNS server, but the question explicitly states the correct values.

D

Candidates might think enabling snooping on a VLAN is sufficient, but Cisco requires the global enable first.

Page 8

Page 9 of 20

Page 10