Courseiva

CCNA Architecture Questions

67 of 142 questions · Page 2/2 · Architecture · Answers revealed

76
MCQmedium

A network architect is designing a new branch office that requires a controller-based wireless solution. The branch has a single Cisco Catalyst 9800-CL appliance and needs to support 802.1X authentication with dynamic VLAN assignment for employee SSIDs. Which deployment mode should the architect use for the access points to meet these requirements with minimal configuration on the APs?

A.FlexConnect mode with central switching enabled for the employee SSIDs
B.Sniffer mode with the APs capturing 802.11 frames for analysis
C.Local mode with the APs managed by the Catalyst 9800-CL controller
D.Monitor mode with the APs dedicated to spectrum analysis and rogue detection
AnswerC

In local mode, the AP establishes a CAPWAP tunnel to the Catalyst 9800-CL and the controller handles all client authentication, including 802.1X and dynamic VLAN assignment. This centralizes configuration and keeps the APs simple, matching the requirement for minimal AP configuration. Local mode is the standard controller-based deployment for branch offices with centralized management.

Why this answer

Local mode is the correct choice because it keeps the APs lightweight and relies on the Catalyst 9800-CL controller for all client authentication and VLAN assignment. This centralizes the complex configuration on the controller, reducing AP-side setup. The other modes either add unnecessary complexity for survivability or do not serve client traffic at all.

Exam trap

The trap here is assuming that FlexConnect is always required for branch offices, when local mode is sufficient if WAN survivability is not a requirement.

77
MCQmedium

A network architect is designing a Cisco SD-WAN fabric for a retail chain with 200 branch sites. The design must provide a single control-plane protocol that distributes routing and policy information between the SD-WAN controllers and the WAN Edge devices, while keeping data-plane traffic direct between branches. Which technology should the architect select for the control plane?

A.Intermediate System-to-Intermediate System (IS-IS)
B.Locator/ID Separation Protocol (LISP)
C.Cisco Overlay Management Protocol (OMP)
D.Border Gateway Protocol (BGP) with route reflectors
AnswerC

OMP is the SD-WAN control-plane protocol that runs between WAN Edge devices and the vSmart controller over DTLS/TLS. It advertises TLOCs, service-side routes, and centralized policy, enabling the controller to orchestrate fabric reachability without hairpinning data traffic. This matches the requirement of a single control plane with direct branch-to-branch data forwarding, so it is the correct choice.

Why this answer

Cisco SD-WAN uses OMP as the single control-plane protocol between the vSmart controller and WAN Edge devices. OMP carries TLOC, route, and policy information, allowing the controller to make forwarding decisions while data traffic flows directly between branches. BGP and IS-IS are underlay or service-side protocols, and LISP belongs to SD-Access, so they do not meet the stated design requirement.

Exam trap

The trap here is assuming that any routing protocol carrying prefixes between WAN Edge devices can serve as the SD-WAN fabric control plane, when only OMP provides TLOC and centralized policy distribution.

78
MCQeasy

A network administrator is deploying a Cisco Wireless LAN Controller (WLC) and access points in a branch office. The administrator wants to ensure that all management traffic between the WLC and APs is encrypted and that APs can discover the WLC across a Layer 3 network. Which protocol should be used for AP-to-WLC communication?

A.SNMPv3 with AES encryption for AP management and discovery.
B.LWAPP with IPsec encryption between AP and WLC.
C.Mobility Express with HTTPS management and no CAPWAP tunnel.
D.CAPWAP with DTLS encryption enabled on the management interface.
AnswerD

CAPWAP (Control and Provisioning of Wireless Access Points) is the standard protocol for AP-to-WLC communication. It uses DTLS to encrypt control and data traffic, and it supports Layer 3 discovery via broadcast, DHCP option 43, or DNS. Enabling DTLS ensures management traffic is encrypted, and CAPWAP operates across Layer 3 networks, satisfying both requirements.

Why this answer

CAPWAP is the current protocol for AP-to-WLC communication, and it supports DTLS encryption for control and data traffic. It also enables Layer 3 discovery through options like DHCP option 43 or DNS. LWAPP is deprecated, Mobility Express is for controller-less setups, and SNMPv3 is for management polling, not AP tunneling.

Therefore, CAPWAP with DTLS is the correct choice.

Exam trap

The trap here is selecting LWAPP because it sounds similar, but it is an older protocol that lacks native DTLS encryption and is not used in modern deployments.

79
MCQhard

A network engineer is deploying a Cisco Wireless LAN Controller (WLC) in a large campus with 500 access points. The engineer must ensure that the WLC can handle the expected client load and that APs can join the controller securely. Which protocol does the AP use to discover and join the WLC, and what is the default secure management protocol for the WLC GUI?

A.LWAPP for AP join; HTTP for WLC GUI
B.DTLS for AP join; HTTPS for WLC GUI
C.CAPWAP for AP join; HTTP for WLC GUI
D.CAPWAP for AP join; HTTPS for WLC GUI
AnswerD

Access points use CAPWAP (Control and Provisioning of Wireless Access Points) to discover and join a WLC, encapsulating control and data traffic. The WLC GUI is accessed via HTTPS by default, providing secure management. This combination meets the requirement for secure AP join and management in a large campus deployment.

Why this answer

Access points use CAPWAP to discover and join a WLC, establishing both control and data tunnels. The control channel is secured with DTLS, while the data channel may also be encrypted. The WLC GUI is accessed via HTTPS by default, ensuring secure management.

This pairing is standard for Cisco wireless deployments and satisfies the need for secure AP join and management.

Exam trap

The trap here is confusing the secure transport protocol (DTLS) with the discovery and join protocol (CAPWAP), or assuming HTTP is the default for WLC management.

80
MCQmedium

A company is migrating its branch WAN to a Cisco SD-WAN solution. The design team wants to use a single overlay that supports both point-to-point and multipoint traffic, and they want to avoid running separate tunnels for unicast and multicast. Which Cisco SD-WAN technology should they enable on the overlay?

A.Cisco SD-WAN multicast with replication using a rendezvous point
B.Cisco SD-WAN Direct Internet Access with NAT
C.Cisco SD-WAN Application-Aware Routing with BFD probes
D.Cisco SD-WAN TLOC extension between two transports
AnswerA

Cisco SD-WAN supports multicast over the overlay by replicating traffic through the fabric with a rendezvous point, allowing one overlay to carry both unicast and multicast. This meets the goal of a single overlay without separate tunnels for each traffic type.

Why this answer

Multicast support in Cisco SD-WAN uses overlay replication coordinated by a rendezvous point, letting the same fabric carry unicast and multicast without parallel tunnel types. Application-Aware Routing, TLOC extension, and Direct Internet Access serve different purposes and do not deliver multipoint transport across the overlay.

Exam trap

The trap here is confusing overlay path-selection or offload features with the mechanism that actually replicates multicast traffic across the SD-WAN fabric.

81
MCQmedium

A company is deploying a WAN with MPLS VPN and wants to ensure that customer traffic is isolated from other customers. Which technology is used to maintain separation in the MPLS core?

A.VLAN tagging
B.MPLS labels
C.IPsec tunnels
D.Virtual Routing and Forwarding (VRF)
AnswerD

Virtual Routing and Forwarding (VRF) creates separate, independent IP routing tables and associated forwarding tables on the Provider Edge (PE) router. Each VRF instance contains its own set of routes, interfaces, and routing protocol processes, ensuring that customer A's routing information is completely invisible to customer B. This table separation is how an MPLS L3VPN achieves routing isolation, even though both customers share the same physical backbone. When combined with route distinguishers (RDs) and route targets (RTs), VRF controls the import and export of routes into the VPN, thereby maintaining strict logical isolation across a shared MPLS core.

Why this answer

VRF (Virtual Routing and Forwarding) is the technology used in MPLS VPN to maintain customer traffic separation within the MPLS core. Each customer is assigned a unique VRF on the Provider Edge (PE) router, which maintains a separate routing table and forwarding instance, ensuring that traffic from one customer never crosses into another customer's routing domain. This separation is enforced at Layer 3, independent of the MPLS label switching that occurs in the core.

Exam trap

Cisco often tests the misconception that MPLS labels alone provide customer separation, but labels are only a forwarding mechanism; the actual isolation comes from VRF instances on the PE routers.

How to eliminate wrong answers

Option A is wrong because VLAN tagging (802.1Q) operates at Layer 2 and is used for segmenting traffic within a LAN or between switches, not for isolating customer traffic across an MPLS WAN core. Option B is wrong because MPLS labels are used for forwarding packets through the core based on label-switched paths (LSPs), but they do not inherently provide customer separation; labels are assigned per FEC and can be shared across customers without VRF. Option C is wrong because IPsec tunnels provide encryption and authentication for secure communication over untrusted networks, but they do not provide routing isolation or separate forwarding tables; they are a security mechanism, not a Layer 3 isolation technology.

82
MCQmedium

A network architect is designing a campus fabric using Cisco SD-Access to centralize policy enforcement and simplify segmentation. The design must support endpoint groups for IoT devices and employees, with traffic policy applied consistently across wired and wireless. Which control plane component is responsible for maintaining the mapping between endpoint identifiers and their location in the fabric?

A.VXLAN tunnel endpoints
B.Cisco Identity Services Engine
C.LISP map-server and map-resolver
D.Cisco DNA Center fabric controller
AnswerC

LISP is the control plane protocol in SD-Access. The map-server registers endpoint EID-to-RLOC mappings from fabric edge nodes, and the map-resolver answers map requests from ingress tunnel routers. This enables scalable endpoint mobility and policy enforcement based on endpoint groups, exactly as required for IoT and employee segmentation across wired and wireless.

Why this answer

In Cisco SD-Access, the LISP control plane maintains the endpoint identifier to routing locator mappings. The map-server registers these mappings from fabric edge nodes, while the map-resolver responds to queries from ingress tunnel routers. This separation of control and data plane allows scalable endpoint mobility and consistent policy enforcement across wired and wireless fabric devices.

Exam trap

The trap here is confusing the SD-Access data plane encapsulation (VXLAN) with the control plane protocol (LISP) that actually holds the endpoint-to-location mappings.

83
MCQeasy

A network administrator is configuring a new Cisco Catalyst switch and needs to ensure that the management VLAN interface is reachable from a remote subnet. The switch currently has no default gateway configured. Which command should be used to allow the switch to communicate with devices on other subnets?

A.ip route 0.0.0.0 0.0.0.0 192.168.1.1
B.ip default-gateway 192.168.1.1
C.ip gateway 192.168.1.1
D.default-router 192.168.1.1
AnswerB

The 'ip default-gateway' command is used on Layer 2 switches to specify a default gateway for management traffic. When the switch is not performing routing, it needs a default gateway to reach remote subnets. This command sets the gateway of last resort for the management interface. Without it, the switch can only communicate with devices on the same subnet, so this is the correct solution for the scenario.

Why this answer

On a Layer 2 switch, the management interface (such as VLAN 1 or a management VLAN SVI) requires a default gateway to communicate with remote subnets. The 'ip default-gateway' command provides this functionality. Unlike a router, a Layer 2 switch does not run a routing protocol or maintain a routing table for management traffic, so a default route is not applicable.

The correct command is 'ip default-gateway'.

Exam trap

The trap here is confusing the switch's management default gateway command with a router's default route command.

84
MCQhard

An enterprise is using OSPF in a multi-area design. Area 1 is a regular area, and Area 2 is a totally stubby area. Which LSA types are present in Area 2?

A.Type 1, Type 2, Type 3 (including default)
B.Type 1, Type 2, Type 3, Type 5
C.Type 1, Type 2, Type 4, Type 5
D.Type 1, Type 2, Type 3 (including default), Type 4
AnswerA

In a totally stubby area, the ABR suppresses Type 4 (ASBR-summary) and Type 5 (AS-external) LSAs, and also replaces all Type 3 inter-area summaries with a single default route. This leaves only Type 1 (router) and Type 2 (network) LSAs for intra-area topology, plus the injected Type 3 default LSA for any traffic leaving the area. Therefore, the allowed LSA set is exactly Type 1, Type 2, and the default Type 3.

Why this answer

In a totally stubby area, the ABR blocks Type 4 and Type 5 LSAs and replaces all Type 3 inter-area routes with a single default route (Type 3 LSA with link-state ID 0.0.0.0). Therefore, only Type 1 (router), Type 2 (network), and the default Type 3 LSAs are present. This matches option A.

Exam trap

Cisco often tests the distinction between a standard stub area (which allows Type 3 summaries but blocks Type 4 and Type 5) and a totally stubby area (which additionally blocks all Type 3 summaries except the default), causing candidates to confuse the LSA types allowed in each.

How to eliminate wrong answers

Option B is wrong because Type 5 (AS-external) LSAs are blocked in a totally stubby area; they are only present in a standard stub area if not using the 'no-summary' keyword. Option C is wrong because Type 4 (ASBR-summary) LSAs are also blocked in a totally stubby area, and Type 5 LSAs are blocked as well. Option D is wrong because Type 4 LSAs are not present in a totally stubby area; the ABR does not advertise the ASBR location into the area.

85
MCQmedium

An engineer is troubleshooting intermittent connectivity issues between two data center switches. The link is a 10GE LACP port-channel. Which misconfiguration could cause packet loss?

A.MTU size is set to 1500 on one switch and 9000 on the other.
B.Auto-negotiation is disabled on both ends.
C.Spanning-tree BPDU guard is enabled on the port-channel.
D.One switch is configured with active LACP and the other with passive LACP.
AnswerA

Mismatched MTU sizes break the link's ability to carry full-size frames consistently. A 9000-byte jumbo frame sent toward the 1500-byte interface is dropped or fragmented, causing intermittent packet loss on the LACP port-channel, especially for large transfers.

Why this answer

An MTU mismatch between two switches in a port-channel can cause packet fragmentation or drops. With LACP, both sides must have matching MTU settings to ensure proper frame forwarding. If one switch has an MTU of 1500 and the other 9000 (jumbo frames), packets exceeding 1500 bytes will be dropped by the switch with the smaller MTU, causing intermittent packet loss.

In contrast, an active/passive LACP configuration is valid and commonly used; it does not cause packet loss if both sides are properly configured. Passive-passive would prevent the port-channel from forming, but that is not the case here.

Exam trap

The trap is that many candidates assume active/passive LACP is a misconfiguration, but it is actually valid. Instead, MTU mismatches are a common source of packet loss in port-channels. Always verify MTU settings when troubleshooting intermittent connectivity.

How to eliminate wrong answers

Option A is wrong because MTU mismatch does not cause packet loss on a port-channel; it causes fragmentation issues or dropped oversized frames, but the link itself remains operational and LACP will still form. Option B is wrong because auto-negotiation is not required on 10GE fiber links (e.g., 10GBASE-SR/LR) where speed and duplex are fixed; disabling it on both ends is standard practice and does not cause packet loss. Option C is wrong because BPDU guard is a spanning-tree feature that err-disables a port upon receiving a BPDU, but it does not cause intermittent packet loss; it either shuts the port down or leaves it operational, not a flapping or loss condition.

86
MCQmedium

A network architect is designing a new branch office that requires a controller-based wireless solution with centralized management, but the branch has limited bandwidth and must continue forwarding client traffic locally even if the WAN link to the headquarters controller fails. The branch has a single Cisco Catalyst 9800-L controller and several Cisco Catalyst 9100 access points. Which deployment mode should the architect choose for the access points?

A.Local mode with CAPWAP control and data tunnels to the controller
B.Sniffer mode with packet capture to a remote server
C.FlexConnect mode with local switching enabled on the access points
D.Monitor mode with dedicated air monitoring on all access points
AnswerC

FlexConnect mode allows the access point to switch client traffic locally at the branch while still being managed by the controller. If the WAN link fails, the AP enters standalone mode and continues to serve clients with local switching, meeting the requirement for local forwarding and reduced WAN bandwidth usage. This is the correct choice for branch survivability.

Why this answer

FlexConnect with local switching allows the access point to forward client traffic locally at the branch, reducing WAN bandwidth consumption and providing survivability if the controller becomes unreachable. The controller still manages the AP for configuration and control plane functions, but data traffic does not need to traverse the WAN. This matches the branch requirements for centralized management and local forwarding.

Exam trap

The trap here is assuming that any controller-based deployment tunnels all client traffic to the controller, overlooking FlexConnect local switching for branch survivability.

87
MCQmedium

A network engineer is comparing first-hop redundancy options for a campus access layer. The requirement is to provide gateway redundancy for IPv6 hosts while also allowing load sharing between two routers, and the solution must use an open standard rather than a Cisco-proprietary protocol. Which FHRP should the engineer select?

A.Proxy Address Resolution Protocol (Proxy ARP)
B.Gateway Load Balancing Protocol (GLBP)
C.Hot Standby Router Protocol (HSRP) version 2
D.Virtual Router Redundancy Protocol (VRRP) version 3
AnswerD

VRRPv3 is an open standard defined by the IETF and supports both IPv4 and IPv6. It allows multiple routers to share a virtual IP and can be configured for load sharing across groups. Since the scenario requires IPv6 gateway redundancy with an open standard, VRRPv3 satisfies all stated conditions.

Why this answer

VRRPv3 is an IETF open standard that supports IPv6 and allows multiple routers to participate in gateway redundancy, with load sharing achievable through multiple virtual router groups. It is the only listed option that is both open standard and suited to IPv6 first-hop redundancy with load sharing.

Exam trap

The trap here is assuming that any FHRP supporting IPv6 also satisfies the open-standard requirement, when HSRP and GLBP remain Cisco-proprietary.

88
MCQmedium

A network administrator is configuring a Cisco Wireless LAN Controller (WLC) for a new office. The office has a mix of corporate laptops and guest devices. The administrator wants to ensure that guest devices can only access the Internet and are isolated from the corporate network. Which WLC feature should be configured to achieve this?

A.FlexConnect local switching
B.Guest WLAN with a dedicated interface and ACL
C.Dynamic VLAN assignment
D.Access Control Lists (ACLs) on the WLC
AnswerB

Creating a separate guest WLAN mapped to a dedicated interface (e.g., a DMZ VLAN) and applying an ACL that permits only Internet-bound traffic is the standard method for guest isolation. This ensures guest devices cannot reach corporate subnets. The WLC supports this through interface mapping and ACLs applied to the WLAN.

Why this answer

To isolate guest traffic, the administrator should create a separate guest WLAN and map it to a dedicated interface, such as a DMZ VLAN. Then, an ACL can be applied to that WLAN to restrict traffic to only Internet-bound destinations. This prevents guests from accessing corporate resources.

Other options like dynamic VLAN or FlexConnect do not inherently provide the required isolation.

Exam trap

The trap here is thinking that dynamic VLAN assignment alone provides guest isolation, when actually a separate WLAN with a dedicated interface and ACL is needed.

89
MCQmedium

A network architect is designing a new branch office that must support wired and wireless users with a single unified policy and automated onboarding for guests. The design requires centralized management, fabric-based segmentation, and the ability to enforce group-based policies without manual VLAN provisioning at the branch. Which Cisco architecture should be used?

A.Cisco ACI
B.Cisco SD-Access
C.Cisco SD-WAN
D.Cisco Catalyst Center with traditional VLANs
AnswerB

Cisco SD-Access is a campus fabric architecture that uses LISP for control plane, VXLAN for data plane, and Cisco TrustSec for group-based policy. It provides centralized management via Cisco DNA Center, automated fabric provisioning, and consistent policy for wired and wireless users, including guest onboarding, which matches the requirements exactly.

Why this answer

Cisco SD-Access is the campus fabric solution that integrates wired and wireless into a single policy domain using LISP, VXLAN, and TrustSec. It centralizes management through Cisco DNA Center and enables automated onboarding and group-based segmentation without manual VLAN configuration, making it the correct architecture for the branch requirements.

Exam trap

The trap here is assuming that Catalyst Center automation alone delivers fabric segmentation, when SD-Access specifically provides the fabric overlay and group-based policy.

90
MCQmedium

A network engineer is configuring a Cisco wireless LAN controller (WLC) to support a new wireless network for guests. The requirement is that guest clients must be isolated from the corporate network and only have internet access. Which feature should be configured on the WLC?

A.Radio Resource Management (RRM)
B.FlexConnect local switching
C.Quality of Service (QoS) profile
D.Guest anchor controller
AnswerD

A guest anchor controller is a dedicated WLC that handles guest traffic separately from the corporate network. Guest clients are tunneled from the foreign controller to the anchor controller, which typically resides in a DMZ. This provides isolation and ensures that guest traffic only has internet access, not corporate network access. This is the standard design for guest wireless.

Why this answer

To isolate guest wireless traffic from the corporate network and provide only internet access, a guest anchor controller is used. The guest anchor controller is typically placed in a DMZ and handles all guest traffic, while the foreign controller tunnels guest client traffic to the anchor. This design ensures that guest clients cannot reach internal corporate resources.

Exam trap

The trap here is assuming that FlexConnect local switching provides guest isolation, when it actually just changes the data path for wireless traffic.

91
MCQmedium

A network engineer is deploying a new Cisco wireless network using a 9800 Series Wireless Controller. The engineer wants to ensure that the management interface is properly configured for out-of-band management. Which interface type should be configured with an IP address for management access?

A.Virtual interface
B.Redundancy management interface
C.Service port
D.Management interface
AnswerD

The management interface on a Cisco 9800 Series Wireless Controller is used for out-of-band management, including device access via SSH, HTTPS, and SNMP. It must be configured with an IP address, subnet mask, and default gateway. This interface is separate from data interfaces and is essential for administrative access to the controller.

Why this answer

The management interface on a Cisco 9800 Series Wireless Controller is specifically designed for out-of-band management. It requires an IP address, subnet mask, and default gateway to allow administrators to access the controller via SSH, HTTPS, or SNMP. Other interfaces like the redundancy management interface, service port, and virtual interface serve different purposes and are not used for primary management access.

Exam trap

The trap here is assuming that the service port or virtual interface can be used for management access, when they serve different roles.

92
MCQeasy

A network administrator is configuring a Cisco Catalyst 9000 switch to support a new wireless deployment. The wireless LAN controller is integrated into the switch, and the administrator needs to ensure that the switch can manage access points and provide centralized control. Which feature should be enabled on the switch?

A.Cisco Mobility Express
B.Cisco Embedded Wireless Controller
C.Cisco DNA Center
D.Cisco SD-Access
AnswerB

The Cisco Embedded Wireless Controller is a feature on Catalyst 9000 switches that provides integrated wireless controller functionality. It allows the switch to manage access points directly without needing an external WLC. This meets the requirement for centralized control and AP management. Enabling this feature allows the switch to act as a wireless controller, simplifying the deployment and reducing hardware footprint.

Why this answer

The Cisco Embedded Wireless Controller is a feature available on Catalyst 9000 switches that integrates wireless controller capabilities directly into the switch. This allows the switch to manage access points and provide centralized control without an external WLC. The other options are either separate products or features not integrated into the switch.

Therefore, enabling the Embedded Wireless Controller is the correct choice.

Exam trap

The trap here is confusing Cisco DNA Center or SD-Access with the embedded wireless controller feature on Catalyst 9000 switches.

93
MCQmedium

A network architect is designing a Fabric-enabled campus with Cisco SD-Access and must choose the optimal underlay routing protocol. The fabric will use VXLAN data-plane encapsulation, and the architect wants minimal configuration on the intermediate underlay devices while supporting fast convergence and equal-cost multipath. Which underlay routing approach should be recommended?

A.Enable RIPng on all underlay devices to provide simple hop-count-based routing.
B.Use Cisco SD-Access fabric with an IS-IS underlay automatically enabled by the fabric provisioning workflow.
C.Deploy eBGP between all underlay switches using unique autonomous system numbers per device.
D.Configure OSPFv2 in a single area on all underlay devices, including the fabric edge and border nodes.
AnswerB

In Cisco SD-Access, the recommended underlay for a Fabric-enabled campus is IS-IS, which is automatically configured by the fabric provisioning workflow through Cisco DNA Center. IS-IS supports fast convergence and ECMP, and the automated deployment minimizes manual configuration on intermediate underlay switches, matching the stated requirement for minimal configuration.

Why this answer

Cisco SD-Access uses an IS-IS underlay that is automatically provisioned by Cisco DNA Center, reducing manual configuration on intermediate devices while supporting fast convergence and ECMP. OSPFv2 and eBGP require explicit per-device configuration and are not the automated fabric underlay. RIPng is unsuitable due to hop limits and slow convergence.

Exam trap

The trap here is assuming any dynamic routing protocol works equally well as an SD-Access underlay, when the automated fabric workflow specifically deploys IS-IS for minimal configuration.

94
MCQeasy

A network administrator is deploying a new branch office that requires a redundant default gateway for hosts on VLAN 10. The administrator wants to use a Cisco-proprietary protocol that provides sub-second failover and supports load sharing between two routers. Which First Hop Redundancy Protocol should be used?

A.Hot Standby Router Protocol (HSRP)
B.Virtual Router Redundancy Protocol (VRRP)
C.Gateway Load Balancing Protocol (GLBP)
D.Intermediate System to Intermediate System (IS-IS)
AnswerC

GLBP is a Cisco-proprietary First Hop Redundancy Protocol that provides both redundancy and load sharing. It uses an Active Virtual Gateway (AVG) and up to four Active Virtual Forwarders (AVFs). The AVG assigns virtual MAC addresses to each AVF, and hosts are distributed across the AVFs for load balancing. Failover is sub-second, and if an AVF fails, another AVF takes over its virtual MAC address.

Why this answer

Gateway Load Balancing Protocol (GLBP) is the correct choice because it is Cisco-proprietary and provides both redundancy and load sharing. Unlike HSRP, which has a single active router, GLBP uses an Active Virtual Gateway to distribute traffic across multiple Active Virtual Forwarders, each with its own virtual MAC address. This allows hosts to share the load while maintaining sub-second failover.

Exam trap

The trap here is assuming that HSRP provides load sharing by default, when in fact it requires multiple groups and is not inherently load-balancing.

95
MCQmedium

A network engineer is designing a new branch office that must support wired and wireless users with unified policy enforcement and automation. The company wants to minimize manual configuration and ensure consistent security policies across all access ports. Which Cisco architecture should the engineer recommend?

A.Cisco SD-WAN
B.Cisco SD-Access
C.Cisco ACI
D.Cisco TrustSec
AnswerB

SD-Access uses a fabric with VXLAN encapsulation and Cisco Identity Services Engine (ISE) for policy, enabling consistent security and automation across wired and wireless. It provides a single policy plane and reduces manual configuration through fabric provisioning, matching the requirement for unified policy and minimal manual effort.

Why this answer

Cisco SD-Access is a campus fabric architecture that integrates wired and wireless access with centralized policy using Cisco ISE and VXLAN. It automates fabric provisioning and enforces consistent security policies across all access ports, directly addressing the need for unified policy and minimal manual configuration in a branch office.

Exam trap

The trap here is confusing campus fabric automation with WAN or data center architectures that also provide policy but not for unified campus access.

96
Matchingmedium

Match each First Hop Redundancy Protocol (FHRP) to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Cisco proprietary, active/standby

Open standard, active/standby

Cisco proprietary, active/active load balancing

Obsolete, uses ICMP advertisements

Another name for ICMP Router Discovery

Why these pairings

FHRPs provide default gateway redundancy. HSRP is Cisco proprietary, active/standby, preemption disabled by default. VRRP is open standard, preemption enabled.

GLBP allows load balancing among multiple routers.

97
MCQeasy

A network engineer is deploying a new branch office that connects to the headquarters over an MPLS Layer 3 VPN provided by a service provider. The branch has a single CE router running eBGP with the provider PE router. The engineer wants to advertise the branch LAN prefix into the MPLS VPN while keeping the branch routing table simple. Which approach is appropriate?

A.Configure the CE router to redistribute the LAN prefix into eBGP toward the PE router.
B.Configure the CE router to run OSPF with the PE router and redistribute the LAN prefix into OSPF.
C.Configure a static route on the PE router pointing to the branch LAN prefix.
D.Configure the CE router to send the LAN prefix using MPLS label distribution to the PE router.
AnswerA

In an MPLS Layer 3 VPN, the CE router exchanges routes with the provider PE router using eBGP. Redistributing the branch LAN prefix into BGP advertises it to the PE, which places it into the correct VRF and propagates it across the provider backbone to other sites in the same VPN. This keeps the branch routing table simple because the CE only needs a default or summarized route toward the PE.

Why this answer

In an MPLS Layer 3 VPN, the customer edge router exchanges routes with the provider edge router using a PE-CE routing protocol such as eBGP. Redistributing the branch LAN prefix into eBGP advertises it to the PE, which imports it into the correct VRF and propagates it to other VPN sites, keeping the branch routing table simple with a default route toward the provider.

Exam trap

The trap here is thinking the customer must configure the provider PE router or use MPLS label distribution, when the customer only controls the CE side.

98
MCQmedium

A network engineer is designing a wireless network for a large auditorium that must support high-density client access. The engineer plans to use Cisco Catalyst 9800 Series Wireless Controllers and Wi-Fi 6 access points. Which feature should be enabled to improve airtime efficiency and reduce overhead for many concurrent clients?

A.802.11r
B.MU-MIMO
C.Band steering
D.OFDMA
AnswerD

OFDMA (Orthogonal Frequency-Division Multiple Access) is a key feature of Wi-Fi 6 that allows multiple clients to be served simultaneously within the same channel by allocating subsets of subcarriers. This improves airtime efficiency and reduces overhead in high-density environments by enabling parallel transmissions to multiple clients. In an auditorium with many concurrent clients, OFDMA significantly enhances capacity and performance.

Why this answer

OFDMA is a Wi-Fi 6 feature that partitions a channel into smaller resource units, allowing simultaneous transmission to multiple clients. This reduces contention and overhead, making it ideal for high-density environments like auditoriums. By enabling OFDMA, the network can serve many clients more efficiently, improving overall throughput and user experience.

Exam trap

The trap here is confusing MU-MIMO with OFDMA, assuming that MU-MIMO alone solves high-density efficiency, when OFDMA specifically addresses subcarrier-level multiplexing for many concurrent clients.

99
MCQhard

A network engineer is designing a campus network that must support rapid convergence and load balancing across multiple links. The design uses Cisco StackWise Virtual technology on a pair of Catalyst 9000 switches. The engineer wants to ensure that the control plane remains active on both switches and that traffic can be forwarded by both switches simultaneously. Which statement accurately describes the StackWise Virtual operation?

A.Both switches share a single control plane and a single management IP address, and both forward traffic.
B.Only one switch performs routing, while the other switch only performs Layer 2 switching.
C.One switch is active, and the other is standby; only the active switch forwards traffic.
D.The switches operate independently with separate control planes, and a First Hop Redundancy Protocol (FHRP) is required for gateway redundancy.
AnswerA

StackWise Virtual combines two physical switches into a single logical switch with one control plane and one management IP. Both switches actively forward traffic, and the control plane is distributed, allowing both to process control protocols. This provides active-active forwarding and simplified management, meeting the design goals.

Why this answer

StackWise Virtual creates a single logical switch from two physical switches, with one control plane and one management IP. Both switches actively forward traffic, providing active-active operation and eliminating the need for FHRP. This design supports rapid convergence and load balancing across links.

Exam trap

The trap here is assuming StackWise Virtual operates like a traditional active-standby high-availability pair, when in fact both switches are active and forward traffic.

100
MCQhard

An enterprise campus uses Cisco Catalyst 9000 switches in a StackWise Virtual configuration at the distribution layer. The network team wants dual-homed access switches to use all uplinks simultaneously while avoiding spanning-tree blocking, and they want the distribution pair to appear as a single logical device to routing peers. Which statement describes how StackWise Virtual supports this design?

A.The pair presents one control plane and a single management IP, and Multichassis EtherChannel allows access switches to use all uplinks without STP blocking.
B.The two chassis elect an active and standby supervisor, and only the active chassis forwards traffic at any time.
C.The pair requires VSS with a virtual switch domain and PAgP to form the virtual switch link between the two chassis.
D.The pair operates as two independent Layer 3 gateways that share a virtual IP using HSRP on each VLAN interface.
AnswerA

StackWise Virtual merges two Catalyst 9000 chassis into one logical switch with a unified control plane, one management address, and one configuration. Multichassis EtherChannel, an MEC, lets a downstream access switch bundle uplinks to both chassis into one port-channel, so all links forward and spanning tree sees a single logical neighbor. This satisfies both the bandwidth and the single-logical-device requirements in the distribution pair.

Why this answer

StackWise Virtual combines two Catalyst 9000 chassis into one logical switch with a shared control plane, one management IP, and one configuration. Multichassis EtherChannel lets downstream switches bundle uplinks to both chassis into a single port-channel, so all links actively forward while spanning tree sees one logical device, and routing peers see a single next hop.

Exam trap

The trap here is assuming that only the active chassis forwards traffic in StackWise Virtual, when both chassis actively forward data-plane traffic.

101
MCQmedium

A network engineer is designing a QoS policy for a campus network. The requirement is that voice traffic must be guaranteed strict priority treatment over all other traffic types, even during congestion. Which queuing mechanism should be configured on the egress interfaces to meet this requirement?

A.Class-Based Weighted Fair Queuing (CBWFQ)
B.Low Latency Queuing (LLQ)
C.First-In, First-Out (FIFO) queuing
D.Weighted Random Early Detection (WRED)
AnswerB

LLQ combines strict priority queuing with CBWFQ. It designates one or more classes as priority queues, which are serviced before any other queues. This ensures that voice traffic receives strict priority treatment and minimal delay and jitter, even during congestion. LLQ also includes a policer to limit the priority queue bandwidth, preventing starvation of other traffic. It directly satisfies the requirement for strict priority for voice.

Why this answer

LLQ is the Cisco IOS queuing mechanism that provides strict priority to designated classes, such as voice, while using CBWFQ for other classes. The priority queue is serviced first, ensuring minimal delay and jitter for voice even under congestion. A policer limits the priority queue to prevent it from starving other queues.

CBWFQ, WRED, and FIFO do not provide strict priority scheduling, so LLQ is the correct choice.

Exam trap

The trap here is confusing CBWFQ with LLQ; CBWFQ provides weighted bandwidth guarantees but not strict priority, which is essential for voice traffic.

102
MCQhard

A network engineer is deploying Cisco SD-Access and needs to ensure that endpoint traffic is encapsulated and forwarded between fabric edge nodes. The design uses an overlay that carries Layer 2 and Layer 3 traffic over a Layer 3 underlay. Which protocol does Cisco SD-Access use for the data plane encapsulation in this fabric?

A.LISP with a locator/ID separation header
B.VXLAN with a Group Policy Option (GPO) header
C.OTV with an adjacency server
D.GRE with a fabric header
AnswerB

Cisco SD-Access uses VXLAN as the data plane encapsulation, and it adds a Group Policy Option header to carry security group tag information. This allows the fabric to enforce group-based policies without requiring traditional ACLs on every device, which is a core part of the SD-Access architecture.

Why this answer

Cisco SD-Access fabric data plane uses VXLAN encapsulation, enhanced with a Group Policy Option header. This header carries the source group tag, enabling scalable group-based policy enforcement. The control plane uses LISP for endpoint location mapping, but the actual packet encapsulation for endpoint traffic is VXLAN, making it the correct choice for the data plane.

Exam trap

The trap here is confusing the control plane protocol (LISP) with the data plane encapsulation (VXLAN), since both are central to SD-Access but serve different roles.

103
MCQhard

A network engineer is designing a Cisco SD-WAN fabric with two data centers and 200 branch sites. The requirement is that branch sites use direct internet access for SaaS applications while business-critical traffic to the data centers traverses a secure IPsec tunnel. Which Cisco SD-WAN feature should the engineer use to define and enforce these traffic steering policies?

A.Application-aware routing with centralized data policy
B.TLOC extension between WAN edge routers at each branch
C.BFD-based path selection with static routes
D.Control plane and data plane separation with OMP
AnswerA

Cisco SD-WAN centralized data policy lets the engineer define traffic steering rules based on application, source, destination, and other match criteria, and then apply actions such as directing traffic over a specific VPN or out the local internet connection. Application-aware routing continuously measures path characteristics to select the best path. Together they satisfy the requirement to send SaaS traffic directly to the internet while forcing critical traffic through IPsec tunnels to the data centers.

Why this answer

Cisco SD-WAN centralized data policy is the mechanism for defining traffic steering rules based on application and other match criteria. Combined with application-aware routing, which measures path performance, the engineer can direct SaaS traffic out the local internet connection and force business-critical traffic through IPsec tunnels to the data centers. This combination directly addresses the stated requirement.

Exam trap

The trap here is assuming that OMP or BFD alone can steer traffic by application, when application-based forwarding requires centralized data policy plus application-aware routing.

104
MCQmedium

A network architect is designing a new branch office that must support a single physical link carrying traffic for multiple tenants while keeping each tenant's routing and forwarding isolated. The design requires that the branch device maintain separate routing tables and forwarding instances per tenant, all on the same physical interface using 802.1Q encapsulation. Which architecture component should be implemented on the branch router to meet these requirements?

A.Multiprotocol Label Switching (MPLS) L3VPN on the branch router
B.Policy-Based Routing (PBR) with route maps
C.Generic Routing Encapsulation (GRE) tunnels per tenant
D.Virtual Routing and Forwarding (VRF) with 802.1Q subinterfaces
AnswerD

VRF provides separate routing and forwarding tables on a single device, and combining it with 802.1Q subinterfaces allows traffic from multiple tenants to be tagged and mapped to distinct VRFs on the same physical link. This satisfies the isolation and shared-link requirements exactly as described.

Why this answer

VRF is the Cisco IOS XE feature that creates separate routing and forwarding tables on one device. When paired with 802.1Q subinterfaces, each tenant's VLAN tag maps to a specific VRF, allowing a single physical link to carry isolated tenant traffic. This directly fulfills the requirement for per-tenant routing isolation on a shared branch link.

Exam trap

The trap here is assuming that any encapsulation or tunneling technology automatically provides separate routing tables, when only VRF creates distinct RIBs and FIBs on the device.

105
MCQmedium

A network architect is deploying a Cisco SD-WAN fabric with a single data center and 40 branch sites. The design requires that all branch sites use a single IPsec tunnel to reach the data center VPN concentrator, and that traffic between branches must transit the data center rather than form direct site-to-site tunnels. Which Cisco SD-WAN topology should the architect select?

A.Hub-and-spoke
B.Point-to-point
C.Full mesh
D.Partial mesh
AnswerA

With a hub-and-spoke topology, each branch (spoke) establishes tunnels only to the data center (hub), and inter-branch traffic is hairpinned through the hub. This matches the requirement that all branches use a single IPsec tunnel to the VPN concentrator and that branch-to-branch traffic transits the data center.

Why this answer

The requirement that every branch hold one tunnel to the data center and that branch-to-branch traffic be hairpinned through the hub is the defining characteristic of a hub-and-spoke SD-WAN topology. Full and partial mesh topologies deliberately create direct spoke-to-spoke tunnels, which would bypass the VPN concentrator and contradict the stated design.

Exam trap

The trap here is assuming that more direct tunnels always improve performance, when the design explicitly requires all inter-branch traffic to transit the data center.

106
Multi-Selectmedium

A company is deploying an MPLS VPN to connect multiple branch sites to a central data center. The network engineer must ensure that customer traffic is isolated from other customers and that routing information is kept separate. Which two statements are correct about MPLS Layer 3 VPNs? (Choose two.)

Select 2 answers
A.Route targets are used to identify the VRF on the PE router that a packet belongs to.
B.Customer edge routers must run MP-BGP with the provider edge routers to exchange VPN routes.
C.VRF instances on PE routers provide logical separation of customer routing tables.
D.The MPLS label stack consists of only a single label for all VPN traffic.
E.MP-BGP is used to distribute customer routes across the MPLS backbone.
AnswersC, E

VRF (Virtual Routing and Forwarding) instances create separate routing and forwarding tables on PE routers. Each customer is assigned its own VRF, so routes from one customer are not leaked into another's table. This logical separation is fundamental to MPLS Layer 3 VPNs and ensures traffic isolation. The VRF also allows overlapping IP address spaces between customers, which is a key benefit of MPLS VPNs.

Why this answer

MPLS Layer 3 VPNs rely on VRF instances on PE routers to separate customer routing tables and MP-BGP to distribute VPNv4 routes across the provider backbone. Route targets control route import/export, but they do not identify the VRF for packet forwarding. The label stack typically has two labels.

CE routers do not run MP-BGP; they run standard routing protocols with the PE. Thus, the correct statements are about VRF separation and MP-BGP route distribution.

Exam trap

The trap here is confusing route targets with the mechanism that identifies the VRF for packet forwarding; route targets control route distribution, not packet classification.

107
MCQeasy

A network engineer is planning a new branch office network. The branch will have a single Cisco IOS router that connects to the internet via a GigabitEthernet interface. The engineer wants to configure NAT to allow internal hosts to access the internet. Which NAT type should be configured to allow multiple internal hosts to share the single public IP address?

A.Static NAT
B.Dynamic NAT
C.NAT64
D.Port Address Translation (PAT)
AnswerD

PAT, also known as NAT overload, allows multiple internal hosts to share a single public IP address by translating both IP addresses and port numbers. Each internal host's connections are tracked using unique source port numbers, enabling thousands of simultaneous connections through one public IP. This is the correct choice for the scenario.

Why this answer

Port Address Translation (PAT), or NAT overload, is designed to allow many internal hosts to share a single public IP address. It uses unique source port numbers to distinguish between sessions, making it the most efficient use of a single public IP. This is the standard method for branch offices with a single internet connection.

Exam trap

The trap here is confusing dynamic NAT with PAT; dynamic NAT still requires a pool of public addresses and does not allow overloading a single address.

108
MCQhard

A network designer is planning a QoS policy for a campus network that carries voice, video, and critical business applications. The design must ensure that voice traffic receives priority treatment with minimal latency and jitter, while preventing starvation of other traffic. Which queuing mechanism should be used on the egress interfaces to meet these requirements?

A.Class-Based Weighted Fair Queuing (CBWFQ)
B.Weighted Random Early Detection (WRED)
C.First-In, First-Out (FIFO) queuing
D.Low Latency Queuing (LLQ)
AnswerD

LLQ provides a strict priority queue for voice traffic while also supporting other queues with guaranteed bandwidth. This ensures voice gets minimal latency and jitter, and the policer on the priority queue prevents starvation of other traffic. It is the recommended mechanism for meeting strict voice requirements in a campus QoS design.

Why this answer

Low Latency Queuing (LLQ) combines a strict priority queue with class-based weighted fair queuing for other traffic. The priority queue is typically used for voice, ensuring minimal delay and jitter, while a policer limits its bandwidth to prevent starvation of other classes. This makes LLQ the correct choice for meeting strict voice QoS requirements.

Exam trap

The trap here is selecting CBWFQ because it provides bandwidth guarantees, but it lacks the strict priority scheduling that voice traffic requires to minimize latency and jitter.

109
MCQeasy

A network administrator is configuring a new Cisco Catalyst switch and needs to ensure that the management VLAN interface is reachable from a remote subnet. The switch is at its default configuration. Which command must be applied to the management VLAN interface to allow remote management from a different subnet?

A.ip name-server 10.1.1.1
B.ip route 0.0.0.0 0.0.0.0 10.1.1.1
C.ip routing
D.ip default-gateway 10.1.1.1
AnswerD

The 'ip default-gateway' command is used on a Layer 2 switch to specify a default gateway for management traffic when the switch is not running a routing protocol. This allows the management VLAN interface to communicate with remote subnets, enabling remote management from a different subnet.

Why this answer

On a Layer 2 switch, the management VLAN interface requires a default gateway to communicate with devices on other subnets. The 'ip default-gateway' command specifies that gateway, allowing the switch to be managed remotely from a different subnet without enabling full IP routing.

Exam trap

The trap here is confusing the default gateway command for Layer 2 switches with the default route command used on Layer 3 devices, which leads to incorrect configuration on a switch.

110
MCQmedium

A network architect is designing a Cisco SD-WAN fabric for a company with 50 branch sites. The company wants to ensure that business-critical traffic (such as VoIP and ERP) is prioritized over best-effort traffic (such as guest internet) across the overlay. The architect plans to use the vManage controller to define an application-aware routing policy. Which component of the Cisco SD-WAN solution is responsible for enforcing the application-aware routing policy on the data plane?

A.vManage
B.vEdge router
C.vBond orchestrator
D.vSmart controller
AnswerB

The vEdge router (or cEdge in Cisco SD-WAN) is the data plane device that actually enforces application-aware routing policies. It inspects traffic, classifies applications, and applies the forwarding decisions defined in the policy. Since the question asks where the policy is enforced, the vEdge router is the correct component because it sits in the forwarding path and executes the policy.

Why this answer

In Cisco SD-WAN, application-aware routing policies are defined centrally on vManage, but they are enforced by the data plane devices—vEdge routers (or cEdge routers). These devices inspect traffic, identify applications, and apply the policy actions such as preferred path or SLA-based forwarding. The vSmart controller distributes policy information, but it does not process user traffic.

Therefore, the vEdge router is the correct answer.

Exam trap

The trap here is assuming that the management or control plane component (vManage or vSmart) enforces the policy, when in fact enforcement happens at the data plane edge device.

111
MCQhard

A network engineer is designing a QoS policy for a WAN edge router. The requirement is to ensure that VoIP traffic receives strict priority treatment and that excess VoIP traffic is policed to prevent starvation of other traffic. Which QoS mechanism should be used?

A.Low Latency Queuing (LLQ)
B.Class-Based Weighted Fair Queuing (CBWFQ)
C.Weighted Random Early Detection (WRED)
D.Traffic Shaping
AnswerA

Low Latency Queuing (LLQ) provides strict priority queuing for delay-sensitive traffic like VoIP. It includes a policer that limits the priority queue to a configured bandwidth, preventing it from starving other queues. This matches the requirement for strict priority treatment with policing of excess VoIP traffic, making it the correct choice.

Why this answer

Low Latency Queuing (LLQ) combines strict priority queuing with a policer. The priority queue ensures VoIP packets are transmitted before other traffic, minimizing delay and jitter. The policer limits the amount of traffic that can enter the priority queue, preventing VoIP from consuming all bandwidth and starving other applications.

This dual behavior exactly matches the requirement for strict priority treatment with excess VoIP policing.

Exam trap

The trap here is assuming that CBWFQ provides strict priority, when it actually only guarantees bandwidth without prioritizing delay-sensitive traffic.

112
MCQmedium

A network architect is designing a Cisco SD-Access fabric for a large campus. The architect needs to ensure that the fabric can scale to support thousands of endpoints and that the control plane uses a dedicated protocol for endpoint registration and location. Which component of the SD-Access architecture provides this control plane function?

A.Cisco Identity Services Engine
B.Cisco DNA Center
C.VXLAN tunnel endpoints
D.LISP map server and map resolver
AnswerD

In Cisco SD-Access, the control plane is based on LISP (Locator/ID Separation Protocol). The map server and map resolver (often co-located on control plane nodes) maintain the mapping of endpoint identifiers (EIDs) to routing locators (RLOCs). This enables scalable endpoint registration and location without flooding, which is essential for large fabrics supporting thousands of endpoints.

Why this answer

The SD-Access fabric uses LISP as its control plane protocol. The map server and map resolver maintain the endpoint ID-to-routing locator mappings, allowing fabric edge nodes to register endpoints and query for their locations. This design eliminates the need for flooding and supports large-scale deployments.

DNA Center, VXLAN VTEPs, and ISE serve different roles: management, data forwarding, and policy/identity, respectively.

Exam trap

The trap here is confusing the management platform (DNA Center) with the control plane protocol (LISP), or assuming that VXLAN handles endpoint registration.

113
MCQhard

A network engineer is designing a Cisco SD-Access fabric for a campus network. The fabric must support both wired and wireless clients, and the engineer wants to ensure that traffic from wired endpoints is encapsulated and forwarded through the fabric without requiring the endpoints to change their IP addresses. Which component of the SD-Access architecture is responsible for encapsulating traffic from wired endpoints and forwarding it to the fabric edge?

A.Control plane node
B.Fabric edge node
C.Fabric intermediate node
D.Fabric border node
AnswerB

The fabric edge node is responsible for encapsulating traffic from wired endpoints using VXLAN and forwarding it to the fabric. It acts as the first-hop router for endpoints and registers them with the control plane node. This component is essential for wired client integration in SD-Access, as it provides the anycast gateway and encapsulation functions.

Why this answer

In Cisco SD-Access, the fabric edge node is the device that connects wired endpoints to the fabric. It encapsulates traffic from wired endpoints into VXLAN and forwards it to the destination fabric edge node based on the control plane mapping. This allows endpoints to keep their IP addresses and be part of a virtual network without re-addressing.

Exam trap

The trap here is confusing the role of the fabric edge node with that of the border node, assuming that any fabric device can encapsulate endpoint traffic.

114
Multi-Selecthard

A network architect is evaluating Cisco StackWise Virtual technology for a pair of Cisco Catalyst 9000 switches that will act as a single logical entity at the distribution layer. Which two statements accurately describe Cisco StackWise Virtual? (Choose two.)

Select 2 answers
A.Each switch in the StackWise Virtual pair maintains an independent control plane and separate management IP address.
B.It requires that both switches run different IOS XE versions to provide software redundancy.
C.The StackWise Virtual Link can be formed using any two 1 Gigabit Ethernet ports on the switches.
D.It supports Multichassis EtherChannel (MEC) so that access switches can dual-home to both stack members.
E.It combines two physical switches into one logical switch using a StackWise Virtual Link between them.
AnswersD, E

StackWise Virtual supports Multichassis EtherChannel, allowing a downstream access switch to form a port-channel with one link to each stack member. Because the two switches operate as one logical device, the port-channel is seen as a single EtherChannel, providing loop-free redundancy and active-active forwarding without relying on spanning tree to block a link.

Why this answer

Cisco StackWise Virtual combines two Catalyst 9000 switches into one logical switch via a StackWise Virtual Link, presenting a single control plane and management IP. It enables Multichassis EtherChannel so downstream devices can dual-home with active-active forwarding. The SVL requires high-speed ports, both switches must run the same IOS XE version, and the pair shares one control plane rather than maintaining independent ones.

Exam trap

The trap here is assuming that StackWise Virtual is simply two independent switches with a redundant link, when it actually merges them into one logical switch with a single control plane and requires matching software and high-speed SVL ports.

115
MCQeasy

A network engineer is designing a campus network and needs to ensure high availability for the core layer. Which design best practice should be implemented?

A.Use a single distribution switch to simplify management.
B.Deploy two core switches configured with VSS or StackWise.
C.Configure the core layer for Layer 2 switching only.
D.Use spanning-tree PortFast on all core switch ports.
AnswerB

VSS or StackWise combines two physical core switches into one logical device, providing stateful failover and sub-second convergence between the chassis. This approach enables active-active traffic forwarding and allows downstream switches to use Cross-Stack EtherChannel (MEC), so both links carry traffic rather than one being blocked by spanning tree. Because the pair appears as a single switch, routing protocols and STP see one node, which simplifies configuration and improves redundancy compared to a standalone pair running HSRP.

Why this answer

Deploying two core switches with VSS (Virtual Switching System) or StackWise provides both redundancy and active-active load balancing at the core layer. VSS virtualizes two physical switches into a single logical switch, eliminating the need for Spanning Tree Protocol (STP) on inter-switch links and enabling sub-second failover. This design ensures high availability by removing single points of failure and maximizing throughput between distribution and core layers.

Exam trap

Cisco often tests the misconception that the core layer should remain Layer 2 for simplicity, but in modern campus designs, the core must route at Layer 3 to avoid STP convergence delays and support ECMP load balancing.

How to eliminate wrong answers

Option A is wrong because using a single distribution switch creates a single point of failure, violating high-availability requirements for the core layer. Option C is wrong because the core layer should route traffic at Layer 3 to enable fast convergence and load balancing; restricting it to Layer 2 switching forces STP dependency and suboptimal path utilization. Option D is wrong because PortFast is an access-layer feature designed to bypass STP listening/learning on end-host ports; applying it to core switch ports (which connect to other switches) would risk bridging loops and network instability.

116
MCQmedium

A network engineer is designing a QoS policy for a Cisco Catalyst switch. The policy must ensure that voice traffic receives strict priority scheduling, while video and critical data traffic are guaranteed a minimum bandwidth. The engineer decides to use Modular QoS CLI (MQC) to create a policy map. Which queuing mechanism should be configured within the policy map to provide strict priority for voice traffic?

A.shape average
B.priority
C.police
D.bandwidth remaining percent
AnswerB

The priority command in an MQC policy map enables strict priority queuing, which means that traffic in this class is serviced before any other queues as long as the queue is not empty. It also allows configuration of a policer to limit the priority traffic. This is the correct mechanism to ensure voice traffic receives strict priority scheduling, as required.

Why this answer

In MQC, the priority command within a policy map enables strict priority queuing, ensuring that voice traffic is scheduled before other classes. The bandwidth remaining percent command allocates minimum bandwidth but not strict priority; shape average shapes traffic; and police enforces rate limits. Only priority provides the strict priority behavior required for voice.

Exam trap

The trap here is confusing the priority command with bandwidth guarantees; the priority command provides strict priority, while bandwidth remaining percent only guarantees a minimum share after priority traffic is served.

117
MCQhard

A network architect is designing a QoS policy for a Cisco Catalyst switch that must prioritize voice traffic over all other traffic, while ensuring that bulk data transfers do not starve other applications. The design requires strict priority for voice and a guaranteed minimum bandwidth for business-critical applications. Which two mechanisms should be used together to meet these requirements?

A.Priority Queuing (PQ) and Custom Queuing (CQ)
B.Low Latency Queuing (LLQ) and Class-Based Weighted Fair Queuing (CBWFQ)
C.Class-Based Marking and Policing
D.Weighted Random Early Detection (WRED) and First-In First-Out (FIFO) queuing
AnswerB

LLQ provides a strict priority queue for voice, ensuring low latency and jitter. CBWFQ provides guaranteed bandwidth for other classes, such as business-critical applications, preventing starvation. Together, they meet the requirements by prioritizing voice while allocating minimum bandwidth to other traffic classes.

Why this answer

LLQ and CBWFQ are used together to provide strict priority for voice traffic while guaranteeing bandwidth for other classes. LLQ places voice in a priority queue with a policed rate to prevent starvation, and CBWFQ allocates minimum bandwidth to business-critical applications, ensuring they are not starved by bulk data.

Exam trap

The trap here is confusing congestion avoidance mechanisms like WRED with queuing mechanisms, or assuming that legacy queuing methods provide the same integrated functionality as LLQ and CBWFQ.

118
MCQmedium

A network architect is designing a Cisco SD-WAN fabric for a company with 30 branch sites and two data centers. The architect wants to ensure that control plane information is exchanged securely and that data plane traffic can be forwarded even if the control plane is temporarily unavailable. Which component should be deployed to meet these requirements?

A.Cisco vEdge routers
B.Cisco vSmart
C.Cisco vBond
D.Cisco vManage
AnswerA

Cisco vEdge routers (or cEdge routers) are the data plane components at branch and data center sites. They establish secure control connections to vSmart and vBond, and they forward data plane traffic based on policies and routes received. They can continue forwarding traffic using cached control information if the control plane is temporarily unavailable, satisfying the scenario.

Why this answer

The data plane in Cisco SD-WAN is handled by vEdge/cEdge routers, which forward traffic and maintain secure connections to the control plane. They can continue forwarding based on last-known routing and policy information if the control plane is disrupted. The management plane (vManage), orchestration plane (vBond), and control plane (vSmart) do not forward production data traffic, so they cannot meet the requirement for continued data plane forwarding.

Exam trap

The trap here is assuming that the control plane component (vSmart) also forwards data traffic, when in fact SD-WAN separates control, data, management, and orchestration planes.

119
MCQeasy

A network engineer is configuring a Cisco IOS switch and needs to assign a specific port to VLAN 20 as an access port. The port is currently in VLAN 1 and is administratively up. Which sequence of interface configuration commands correctly places the port into VLAN 20 as an access port?

A.switchport mode access followed by switchport access vlan 20
B.vlan 20 followed by switchport mode access
C.switchport mode dynamic auto followed by switchport access vlan 20
D.switchport access vlan 20 followed by switchport mode trunk
AnswerA

Entering interface configuration mode and issuing switchport mode access sets the port to access mode, and switchport access vlan 20 assigns it to VLAN 20. This is the standard Cisco IOS method to configure a static access port. The VLAN must exist in the VLAN database, but the command sequence itself is correct for placing the port into VLAN 20.

Why this answer

To place an interface into a specific VLAN as an access port on a Cisco IOS switch, the engineer enters interface configuration mode, sets the port to access mode with switchport mode access, and assigns the VLAN with switchport access vlan 20. This ensures the port carries untagged traffic for VLAN 20 only.

Exam trap

The trap here is confusing the global vlan command that creates a VLAN with the interface-level switchport access vlan command that assigns a port to an existing VLAN.

120
MCQmedium

A network architect is designing a new branch office that requires a switch to be managed centrally without a dedicated physical controller appliance on-site. The switch must support fabric capabilities and be onboarded using Plug and Play. Which Cisco Catalyst switch platform should be selected?

A.Cisco Catalyst 9200
B.Cisco Nexus 9000
C.Cisco Catalyst 2960-X
D.Cisco ASR 1000
AnswerA

The Catalyst 9200 supports SD-Access fabric edge and can be onboarded via Cisco DNA Center Plug and Play without a local controller. It is designed for branch deployments requiring fabric capabilities, making it the correct choice for this scenario.

Why this answer

The Catalyst 9200 is a fixed access switch that supports SD-Access fabric edge and can be discovered and onboarded by Cisco DNA Center using Plug and Play, eliminating the need for a local controller. The other platforms either lack fabric support or are designed for different roles.

Exam trap

The trap here is assuming any Catalyst switch supports SD-Access fabric, but older models like the 2960-X do not.

121
MCQmedium

A network architect is designing a Cisco SD-Access fabric for a hospital campus. The fabric must support wired and wireless clients, and the architect wants to ensure that all fabric edge nodes use a consistent mapping of endpoint IP addresses to fabric locations. Which control plane component is responsible for maintaining the endpoint-to-edge-node mapping database?

A.Fabric intermediate node
B.Fabric border node
C.Cisco DNA Center
D.Fabric control plane node
AnswerD

The fabric control plane node runs LISP and maintains the endpoint-to-edge-node mapping database, known as the map-server and map-resolver. When a fabric edge node needs to locate an endpoint, it queries the control plane node, which returns the RLOC of the edge node where the endpoint is attached. This ensures consistent mapping across all fabric edge nodes.

Why this answer

In Cisco SD-Access, the control plane node is the LISP map-server and map-resolver that stores endpoint identifiers (EIDs) and their routing locators (RLOCs). Fabric edge nodes register endpoints with the control plane node and query it for location resolution. This design centralizes endpoint reachability information, ensuring that every edge node has a consistent view of where endpoints are attached.

Exam trap

The trap here is assuming that DNA Center, as the management platform, also provides the real-time endpoint location database, when that role belongs to the fabric control plane node running LISP.

122
MCQmedium

An engineer is deploying a Cisco SD-WAN solution using Cisco vManage. The company requires that the WAN edge devices authenticate to the controllers using certificates signed by an enterprise PKI rather than the default Cisco-signed certificates. Which component must be configured to issue and manage these certificates?

A.Cisco vBond orchestrator
B.Cisco vManage
C.Cisco vSmart controller
D.An external certificate authority (CA) server
AnswerD

In Cisco SD-WAN, when using enterprise PKI, an external CA server (such as Microsoft Certificate Services or a third-party CA) signs the device certificates. The WAN edge devices generate a CSR, which is sent to the CA; the CA returns a signed certificate that the device uses to authenticate to the controllers. This satisfies the requirement for certificates signed by an enterprise PKI.

Why this answer

Cisco SD-WAN supports two certificate options: the default Cisco-signed certificates or enterprise PKI. For enterprise PKI, an external CA must sign the device certificates. The vManage, vSmart, and vBond components do not issue certificates; they only validate them during control plane establishment.

Therefore, an external CA server is required to meet the enterprise PKI requirement.

Exam trap

The trap here is assuming that vManage, as the management component, also acts as the certificate authority for enterprise PKI.

123
MCQhard

A network architect is designing a QoS policy for a campus network. The architect needs to ensure that voice traffic is prioritized over all other traffic types, even during congestion. Which queuing mechanism should be used on the egress interface to provide strict priority to voice traffic?

A.Low Latency Queuing (LLQ)
B.Class-Based Weighted Fair Queuing (CBWFQ)
C.Weighted Random Early Detection (WRED)
D.First-In, First-Out (FIFO) queuing
AnswerA

LLQ provides strict priority queuing for delay-sensitive traffic such as voice. It combines priority queuing with CBWFQ. The priority queue is serviced first, and voice traffic is placed in this queue, ensuring it is transmitted before other traffic even during congestion. LLQ also includes a policer to limit the priority queue bandwidth, preventing starvation of other queues.

Why this answer

Low Latency Queuing (LLQ) provides strict priority queuing, which ensures that voice traffic is serviced before all other traffic. LLQ is an extension of CBWFQ that includes a priority queue for delay-sensitive traffic. The priority queue is policed to prevent bandwidth starvation of other queues.

CBWFQ, WRED, and FIFO do not offer strict priority and are not suitable for voice traffic prioritization.

Exam trap

The trap here is confusing CBWFQ with LLQ; CBWFQ alone does not provide strict priority, but LLQ adds a priority queue to CBWFQ for voice traffic.

124
MCQhard

A network engineer is deploying a Cisco SD-Access fabric for a campus network. The fabric consists of border nodes, control plane nodes, edge nodes, and an intermediate node. The engineer needs to ensure that endpoints in the fabric can communicate with external networks such as the data center and the internet. Which component of the SD-Access architecture is responsible for providing connectivity between the fabric and external networks?

A.Control plane node
B.Edge node
C.Border node
D.Intermediate node
AnswerC

Border nodes in Cisco SD-Access provide connectivity between the fabric and external networks, such as the data center, internet, or legacy networks. They perform the role of LISP proxy tunnel routers (PxTRs) and can also run BGP or other routing protocols to exchange routes with external devices. In this scenario, the border node is the correct component because it is specifically designed to handle external traffic entering and leaving the fabric.

Why this answer

In Cisco SD-Access, border nodes are responsible for connecting the fabric to external networks. They act as the gateway between the fabric and outside networks, performing functions such as LISP proxy and route redistribution. Control plane nodes handle endpoint registration, edge nodes connect endpoints, and intermediate nodes connect multiple fabric sites.

Thus, the border node is the correct component for providing external connectivity.

Exam trap

The trap here is confusing the roles of border nodes and intermediate nodes, or assuming that control plane nodes handle external routing.

125
MCQmedium

A network engineer is configuring a Cisco IOS XE router to support Network Address Translation (NAT) for a small office. The router has an inside interface GigabitEthernet0/0/0 and an outside interface GigabitEthernet0/0/1. The engineer wants to translate all inside hosts to the outside interface IP address using PAT. Which configuration snippet correctly implements this?

A.ip nat inside source static 192.168.1.10 203.0.113.1; interfaces marked inside/outside; no access-list needed
B.ip nat inside source list 1 interface GigabitEthernet0/0/1 overload; interface GigabitEthernet0/0/0: ip nat inside; interface GigabitEthernet0/0/1: ip nat outside; access-list 1 permit 192.168.1.0 0.0.0.255
C.ip nat inside source list 1 pool MYPOOL overload; ip nat pool MYPOOL 203.0.113.1 203.0.113.1 netmask 255.255.255.0; interfaces marked inside/outside; access-list 1 permit 192.168.1.0 0.0.0.255
D.ip nat outside source list 1 interface GigabitEthernet0/0/0 overload; interfaces marked inside/outside; access-list 1 permit any
AnswerB

This configuration uses PAT overload by referencing the outside interface in the ip nat inside source command, which translates all inside hosts to the outside interface IP. The access list defines the inside subnet, and the interfaces are marked correctly as inside and outside. This is the standard method for PAT to a single outside address, matching the requirement.

Why this answer

The correct PAT configuration for translating all inside hosts to the outside interface IP uses the ip nat inside source list command with the interface keyword and overload. The access list defines the inside subnet, and interfaces are marked inside and outside. Static NAT, NAT pools, and outside source NAT do not meet the specific requirement of translating all inside hosts to the outside interface IP.

Exam trap

The trap here is confusing static NAT or pool-based NAT with PAT to an interface, when the scenario explicitly requires translating all inside hosts to the outside interface IP.

126
MCQmedium

A network architect at a large university is designing a new campus network that must support seamless roaming for thousands of wireless clients across multiple buildings. The design requires a centralized control plane with a distributed data plane to avoid traffic tromboning. Which Cisco architecture should the architect implement?

A.Cisco Digital Network Architecture (DNA) Center with traditional campus switching
B.Cisco Application Centric Infrastructure (ACI) with spine-leaf topology
C.Cisco Software-Defined WAN (SD-WAN) with vManage and vSmart controllers
D.Cisco SD-Access with fabric-enabled switches and a fabric controller
AnswerD

Cisco SD-Access uses a fabric with a centralized control plane (LISP) and distributed data plane (VXLAN), enabling seamless mobility and preventing traffic tromboning by allowing edge nodes to forward traffic directly. This matches the requirement for centralized control and distributed data plane.

Why this answer

Cisco SD-Access fabric provides a centralized control plane using LISP and a distributed data plane using VXLAN, which enables seamless roaming and avoids traffic tromboning by allowing edge nodes to forward traffic directly. This architecture is specifically designed for campus networks requiring mobility and scalability.

Exam trap

The trap here is confusing SD-Access with SD-WAN, as both are Cisco SDN solutions but target different network domains.

127
MCQhard

A network engineer is implementing Cisco SD-Access for a campus network. The fabric uses LISP for control plane and VXLAN for data plane. The engineer needs to ensure that endpoints in the same VLAN but on different fabric edge nodes can communicate. Which Cisco SD-Access component is responsible for mapping endpoint EIDs to RLOCs?

A.Fabric border node
B.Fabric edge node
C.Intermediate node
D.Control plane node
AnswerD

The control plane node in SD-Access runs LISP map-server and map-resolver functions. It maintains the mapping database of endpoint EIDs to RLOCs (fabric edge node locators). When an edge node needs to reach an endpoint, it queries the control plane node, which resolves the EID to the correct RLOC. This enables communication across fabric edge nodes.

Why this answer

In Cisco SD-Access, the control plane node provides LISP map-server and map-resolver services. It stores the EID-to-RLOC mappings for all endpoints registered by fabric edge nodes. When an edge node needs to send traffic to an endpoint on another edge node, it queries the control plane node to resolve the destination RLOC, enabling VXLAN encapsulation and forwarding.

This centralizes mapping and supports mobility.

Exam trap

The trap here is assuming that fabric edge nodes resolve EIDs locally; in reality, they query the control plane node for mappings.

128
MCQmedium

A network engineer is deploying a Cisco SD-WAN solution using vManage, vSmart, and vBond controllers. The engineer needs to ensure that the data plane is secure and that tunnels are established between WAN edge devices. Which component is responsible for orchestrating the control plane and distributing policies to WAN edge devices?

A.vManage
B.vBond orchestrator
C.WAN edge device
D.vSmart controller
AnswerD

The vSmart controller is the centralized control plane component in Cisco SD-WAN. It distributes routing and policy information to WAN edge devices using the Overlay Management Protocol (OMP). This enables secure tunnel establishment and consistent policy enforcement across the fabric, making it the correct answer for orchestrating the control plane.

Why this answer

In Cisco SD-WAN, the vSmart controller is the control plane component. It uses the Overlay Management Protocol (OMP) to distribute routing information and policies to WAN edge devices. The vBond orchestrator handles authentication and discovery, while vManage provides management.

The vSmart controller is specifically responsible for orchestrating the control plane and policy distribution.

Exam trap

The trap here is confusing the management plane role of vManage with the control plane role of vSmart, since both are central to SD-WAN operations but perform different functions.

129
MCQhard

An engineer is troubleshooting a network where OSPF neighbors are stuck in the EXSTART state. What is the most likely cause?

A.Dead timer mismatch
B.Authentication misconfiguration
C.Mismatched OSPF area IDs
D.MTU mismatch between the routers
AnswerD

During the EXSTART/EXCHANGE phase, OSPF routers exchange database description (DBD) packets that can be as large as the interface MTU; if one router's MTU is lower, the larger DBD packet will be dropped or fragmented, and the neighbor will never leave EXSTART because it keeps waiting for a valid DBD sequence. The interface MTU mismatch is a classic cause of OSPF adjacencies stuck in EXSTART, as the router with the smaller MTU silently discards the oversized multicast packets. This can be diagnosed by checking the 'show ip ospf neighbor' state and by ensuring both ends have the same MTU or by enabling 'ip ospf mtu-ignore' as a workaround.

Why this answer

The EXSTART state in OSPF indicates that routers have formed a bidirectional communication (2-Way state) and are now attempting to exchange Database Description (DBD) packets to negotiate the master/slave relationship and the initial sequence number. An MTU mismatch between the routers is the most common cause of neighbors being stuck in EXSTART because the router with the smaller MTU will drop DBD packets that exceed its interface MTU, preventing the exchange from progressing to the Loading state.

Exam trap

Cisco often tests the EXSTART state as a symptom of MTU mismatch, but candidates frequently confuse it with authentication or area ID mismatches, which actually prevent adjacency formation at earlier stages like INIT or 2-Way.

How to eliminate wrong answers

Option A is wrong because a dead timer mismatch typically causes neighbors to be stuck in the INIT or 2-Way state, not EXSTART, as the routers will fail to receive Hello packets within the dead interval. Option B is wrong because authentication misconfiguration usually prevents OSPF neighbors from forming adjacency at all, often resulting in the INIT state or no neighbor relationship, not EXSTART. Option C is wrong because mismatched OSPF area IDs prevent the formation of any adjacency beyond the 2-Way state, as routers will not exchange Hello packets with mismatched area IDs, and they will not reach EXSTART.

130
MCQhard

A network architect is designing a Cisco SD-Access fabric for a large enterprise. The fabric will use VXLAN encapsulation and a Layer 3 underlay. The architect must ensure that the fabric supports the separation of policy from topology and allows endpoints to be assigned to virtual networks. Which Cisco SD-Access component is responsible for maintaining the mapping between endpoint IP addresses and their fabric locators, and for providing the control plane that enables fabric edge nodes to resolve endpoint locations?

A.Fabric border node
B.Fabric intermediate node
C.Fabric edge node
D.Control plane node
AnswerD

The control plane node in Cisco SD-Access maintains the mapping database of endpoint IP addresses to fabric locators (such as VTEP addresses) and provides the control plane that fabric edge nodes use to resolve endpoint locations. It uses LISP to register and query endpoint information, enabling separation of policy from topology. This directly matches the requirement described.

Why this answer

In Cisco SD-Access, the control plane node hosts the LISP map-server and map-resolver functions, maintaining the endpoint-to-locator mapping database. Fabric edge nodes query this node to resolve endpoint locations. This design separates policy from topology and supports virtual network assignment.

The other components either connect endpoints, handle external traffic, or forward underlay packets, but none maintain the mapping database.

Exam trap

The trap here is confusing the control plane node with the fabric border node, because both are central fabric components, but only the control plane node maintains the endpoint mapping database and provides LISP-based resolution.

131
MCQhard

A network engineer is implementing Cisco SD-Access and needs to ensure that endpoints in a virtual network can communicate with a shared service that resides in a different virtual network. The shared service must be reachable from multiple virtual networks without duplicating the service. Which SD-Access component should be configured to provide this inter-VN communication?

A.Control plane node
B.Fusion router
C.Fabric edge node
D.Fabric border node
AnswerB

The fusion router is used in SD-Access to provide inter-VN routing and to connect to shared services that reside outside the fabric or in a different VN. It allows multiple virtual networks to reach a common service without duplicating it. It is typically connected to the border node and runs VRF-aware routing to leak routes between VNs.

Why this answer

The fusion router is specifically designed to enable inter-VN communication and shared services in Cisco SD-Access. It connects to the fabric border node and uses VRF leaking to allow endpoints in different virtual networks to reach common services. Fabric edge nodes, border nodes, and control plane nodes have different roles and do not provide this function.

The fusion router ensures that shared services are not duplicated across VNs.

Exam trap

The trap here is confusing the border node's role of external connectivity with the fusion router's role of inter-VN routing and shared services.

132
MCQhard

A network engineer is designing a network that uses Cisco SD-Access with a fabric that includes a border node and control plane node. The engineer must ensure that traffic from external networks can reach endpoints within the fabric. Which function does the border node provide in this architecture?

A.It provides connectivity between the fabric and external networks, such as WAN or data center.
B.It maintains the mapping of endpoint IP addresses to fabric edge nodes.
C.It enforces security policies between endpoints within the same virtual network.
D.It acts as the default gateway for all endpoints in the fabric.
AnswerA

The border node in Cisco SD-Access provides connectivity between the fabric and external networks. It handles traffic entering and leaving the fabric, performing functions such as VXLAN-to-VLAN translation and routing to external networks. This allows external users to reach fabric endpoints.

Why this answer

The border node in Cisco SD-Access provides connectivity between the fabric and external networks, handling traffic entering and leaving the fabric. It performs VXLAN-to-VLAN translation and routing, enabling external users to reach fabric endpoints. This is distinct from the control plane node's mapping function and the edge node's policy enforcement.

Exam trap

The trap here is confusing the border node's external connectivity role with the control plane node's mapping role or the edge node's gateway role.

133
MCQmedium

A network engineer is designing a QoS policy for a WAN edge router. The router must prioritize voice traffic with a strict priority queue and ensure that call signaling traffic is not starved. Which queuing mechanism should the engineer configure to meet these requirements?

A.Class-Based Weighted Fair Queuing (CBWFQ)
B.Low Latency Queuing (LLQ)
C.First-In, First-Out (FIFO) queuing
D.Weighted Random Early Detection (WRED)
AnswerB

LLQ combines a strict priority queue with CBWFQ for other traffic. Voice traffic can be placed in the priority queue to ensure minimal delay and jitter, while call signaling and other traffic are handled by CBWFQ with guaranteed bandwidth. This prevents the priority queue from starving other queues because LLQ includes a policer to limit the priority queue bandwidth.

Why this answer

LLQ is designed to provide strict priority queuing for delay-sensitive traffic like voice, while still offering bandwidth guarantees for other classes such as call signaling. The priority queue is policed to prevent starvation of other queues, ensuring that signaling traffic gets its share of bandwidth.

Exam trap

The trap here is assuming that CBWFQ alone can provide strict priority, when it actually provides weighted fair queuing without a priority queue.

134
MCQmedium

A network architect is designing a controller-based wireless deployment for a large campus. The customer wants centralized management, policy enforcement, and the ability to deploy a single wireless LAN controller that can handle up to 6,000 access points. Which Cisco platform should the architect recommend?

A.Cisco Mobility Express
B.Cisco 5520 Wireless Controller
C.Cisco Catalyst 9800-80 Wireless Controller
D.Cisco Catalyst 9800-L Wireless Controller
AnswerC

The Catalyst 9800-80 is a high-end appliance in the Catalyst 9800 series, supporting up to 6,000 access points and 64,000 clients. It provides centralized management, policy enforcement, and runs IOS-XE, making it ideal for large campus deployments. It meets the exact scalability requirement of the scenario.

Why this answer

The Catalyst 9800-80 is purpose-built for large-scale wireless deployments, supporting up to 6,000 access points and 64,000 clients. It offers centralized management, policy enforcement, and runs on IOS-XE, aligning with modern intent-based networking. The other options either lack the required scale or are designed for smaller environments.

Exam trap

The trap here is assuming that any Catalyst 9800 model can scale to 6,000 access points, when only the 9800-80 supports that capacity.

135
MCQeasy

A network administrator is configuring a Cisco Wireless LAN Controller (WLC) for a new office building. The company requires that guest users be isolated from internal users and that guest traffic be tunneled directly to the DMZ. Which feature should the administrator configure on the WLC?

A.Auto-anchor with dynamic VLAN assignment
B.FlexConnect with local switching
C.Mobility group with default settings
D.Guest anchor controller
AnswerD

A guest anchor controller allows guest traffic to be tunneled from the foreign controller to a designated anchor controller in the DMZ. This isolates guest traffic from internal networks and fulfills the requirement to tunnel guest traffic directly to the DMZ.

Why this answer

A guest anchor controller tunnels guest traffic from the foreign controller to an anchor controller in the DMZ, isolating guest traffic from internal networks. This is the standard Cisco WLC design for guest access, ensuring that guest traffic does not traverse internal networks and is directly routed to the DMZ.

Exam trap

The trap here is assuming that FlexConnect local switching or mobility groups alone can isolate guest traffic to the DMZ, but they do not provide the required tunneling.

136
MCQmedium

A network administrator is designing a campus network that must support a single management IP address for a pair of Catalyst 9000 switches acting as a collapsed core. The design requires that both switches actively forward traffic, that the control plane operate as one logical device, and that a single configuration file be maintained. Which technology meets these requirements?

A.Cisco StackWise Virtual
B.Cisco IOS-XE with HSRP and GLBP
C.Cisco StackWise with a StackWise cable
D.Virtual Port Channel with HSRP
AnswerA

StackWise Virtual combines two Catalyst 9000 switches into one logical entity with a single management IP and one configuration file. Both switches actively forward traffic in an active-active fashion using a virtual switch link, which exactly matches the requirement for one logical control plane and dual active forwarding in a collapsed core design.

Why this answer

StackWise Virtual merges two Catalyst 9000 switches into a single logical switch using a virtual switch link. It provides one management IP, one configuration file, and active-active forwarding, which is precisely what the collapsed core design requires. Classic StackWise is intended for different topologies, while vPC with HSRP and HSRP/GLBP keep separate control planes and configurations, so they do not meet the single logical device requirement.

Exam trap

The trap here is equating first-hop redundancy protocols such as HSRP with a true single-control-plane switch virtualization technology.

137
MCQmedium

A network architect is designing a Cisco SD-Access fabric for a hospital campus. The hospital requires that guest wireless users be allowed access only to the internet, while clinical staff devices must reach internal EHR servers. The fabric uses Cisco DNA Center and Cisco Identity Services Engine for policy. Which fabric component enforces the group-based policy between these user groups?

A.The Cisco DNA Center Intent API translating business intent into device configuration
B.The fabric control plane node running LISP map-server functions
C.The fabric intermediate node forwarding VXLAN-encapsulated traffic between edge nodes
D.The fabric edge node applying Cisco TrustSec group-based access control lists
AnswerD

Fabric edge nodes encapsulate traffic in VXLAN and enforce group-based policy using Cisco TrustSec security group tags and scalable group ACLs derived from ISE policy. When a guest wireless user tries to reach an EHR server, the ingress edge node drops the packet based on the source and destination security group tags. This directly delivers the required isolation between guest and clinical traffic in the SD-Access fabric.

Why this answer

Group-based policy in a Cisco SD-Access fabric is enforced at the fabric edge node using Cisco TrustSec security group tags and scalable group ACLs, with group membership and policy defined in Cisco Identity Services Engine. This lets the hospital block guest-to-EHR flows while permitting clinical staff access, without redesigning VLANs or subnets for each user category.

Exam trap

The trap here is assuming the controller or the underlay enforces user policy, when enforcement actually occurs on the fabric edge node through group-based ACLs.

138
MCQeasy

A network engineer is configuring a Cisco Catalyst switch to participate in a StackWise Virtual domain. The engineer needs to ensure that the two switches form a single logical entity and that the control plane is synchronized. Which statement correctly describes a requirement for StackWise Virtual operation?

A.The switches must be configured with different hostnames and separate management IP addresses to avoid conflicts.
B.The switches must use a dedicated StackWise cable and can be from different Catalyst switch families.
C.The switches must be connected via a standard 1 Gigabit Ethernet uplink and can run different software versions.
D.The switches must be connected by a StackWise Virtual Link using supported ports, and they must run the same software version.
AnswerD

StackWise Virtual requires a dedicated StackWise Virtual Link (SVL) between the two switches using supported high-bandwidth ports, and both switches must run identical software versions to form a single logical entity. This ensures control plane synchronization and consistent forwarding behavior, which is essential for the domain to operate correctly.

Why this answer

StackWise Virtual combines two physical switches into one logical switch. It requires a dedicated high-bandwidth StackWise Virtual Link using supported ports and identical software versions on both switches. This allows a single control plane, unified management, and simplified topology without Spanning Tree loops between the pair.

Exam trap

The trap here is assuming StackWise Virtual uses the same dedicated stacking cable as traditional StackWise, when it actually uses supported Ethernet ports for the virtual link.

139
MCQhard

An engineer is deploying Cisco SD-Access and wants to separate the roles of the underlay and the fabric overlay. The design must provide a Layer 3 routed underlay using IS-IS, and the fabric edge nodes must register endpoint information with a fabric control-plane node. Which node type in Cisco SD-Access is responsible for mapping endpoint identity to location and answering EID-to-RLOC queries from fabric edge nodes?

A.Fabric border node
B.Fabric wireless controller
C.Fabric control-plane node
D.Fabric intermediate node
AnswerC

The fabric control-plane node runs LISP map-server and map-resolver functions. Fabric edge nodes register endpoint EIDs with it, and it answers EID-to-RLOC map requests so that edge nodes can build VXLAN tunnels to the correct destination. In this design it is the component that owns identity-to-location mapping, satisfying the requirement stated in the scenario.

Why this answer

In Cisco SD-Access, the fabric control-plane node hosts the LISP map-server and map-resolver. Fabric edge nodes register endpoint identifiers with it, and it answers EID-to-RLOC queries, enabling VXLAN tunnel establishment between edge nodes. That responsibility matches the requirement to map endpoint identity to location.

Exam trap

The trap here is confusing the border node, which connects the fabric to outside networks, with the control-plane node, which owns LISP mapping and endpoint registration.

140
Multi-Selecteasy

Which THREE of the following are benefits of implementing a spine-leaf architecture in a data center?

Select 3 answers
A.Provides predictable latency for east-west traffic.
B.Eliminates the need for spanning-tree protocol.
C.Reduces the amount of cabling required.
D.Simplifies scalability by adding leaf switches without redesign.
E.Eliminates the need for firewall appliances.
AnswersA, B, D

Correct. Spine-leaf provides predictable latency for east-west traffic because every leaf-to-leaf path crosses exactly one spine switch, giving a consistent hop count of two (leaf-to-spine-to-leaf) regardless of which leaf pair communicates. This uniform topology yields low, bounded, and predictable latency, unlike hierarchical designs where traffic may traverse multiple aggregation and core layers with variable distances. It is a key reason spine-leaf suits latency-sensitive data center applications.

Why this answer

Spine-leaf architecture provides predictable latency for east-west traffic because every leaf switch connects to every spine switch, ensuring consistent hop count. It simplifies scalability: adding a new leaf switch requires connecting it to all spine switches without redesign. Additionally, spine-leaf eliminates the need for Spanning Tree Protocol (STP) because it uses Layer 3 routing between leaf and spine switches, removing Layer 2 loops.

Therefore, options A, B, and D are correct. Option C is incorrect because spine-leaf increases cabling due to full mesh connectivity. Option E is incorrect because firewall appliances are still required for security.

Exam trap

Cisco often tests the misconception that spine-leaf reduces cabling or eliminates all protocols like STP and firewalls, when in fact it increases cabling and only removes Layer 2 loops while still requiring routing protocols and security appliances.

141
MCQeasy

A network administrator is configuring a new VLAN 100 on a switch and wants to ensure that the VLAN is created and active. Which command is required to create a VLAN in the VLAN database?

A.interface vlan 100
B.name VLAN100
C.vlan 100
D.switchport access vlan 100
AnswerC

vlan 100 is the global configuration command that creates a new VLAN with ID 100 and immediately enters VLAN configuration mode. This is the required first step when establishing a new VLAN, as it adds the VLAN to the switch's local VLAN database. From this mode, you can set optional parameters such as the VLAN name, MTU, or other interface-specific settings. Issuing this command makes the VLAN available for subsequent operations like assigning access ports or creating an SVI.

Why this answer

The 'vlan 100' command is executed in global configuration mode to create a VLAN in the VLAN database on a Cisco IOS switch. This command creates the VLAN and places the switch into VLAN configuration mode, where optional parameters like name can be set. The VLAN is active immediately upon creation, provided the switch is in VTP server or transparent mode.

Exam trap

Cisco often tests the distinction between creating a VLAN with 'vlan <id>' versus creating an SVI with 'interface vlan <id>', leading candidates to confuse Layer 2 VLAN creation with Layer 3 interface configuration.

How to eliminate wrong answers

Option A is wrong because 'interface vlan 100' creates a Layer 3 switched virtual interface (SVI) for routing, not the VLAN itself. Option B is wrong because 'name VLAN100' is a subcommand used within VLAN configuration mode to assign a name to an existing VLAN, not to create the VLAN. Option D is wrong because 'switchport access vlan 100' assigns an access port to VLAN 100, but the VLAN must already exist or be dynamically created via VTP; it does not create the VLAN in the database.

142
MCQhard

A network architect is comparing Cisco StackWise Virtual and traditional StackWise for a new data center access layer. The requirement is that the two switches operate as one logical device while remaining physically separate, with each switch having its own control plane processes that are synchronized, and that the pair support Multichassis EtherChannel to downstream servers. Which statement correctly describes Cisco StackWise Virtual in this scenario?

A.StackWise Virtual requires a dedicated stacking cable and forms a single control plane with one master and one standby member
B.StackWise Virtual uses VSS with a Virtual Switch Link and requires one chassis to be active while the other is in hot standby
C.StackWise Virtual only supports single-chassis EtherChannel because each switch forwards independently
D.StackWise Virtual combines two switches into one logical entity using a StackWise Virtual Link, and each chassis maintains its own control plane that is synchronized with its peer
AnswerD

StackWise Virtual pairs two physical switches into a single logical device over a StackWise Virtual Link. Unlike classic StackWise with a master and members, both chassis run independent control planes that stay synchronized, and Multichassis EtherChannel to downstream devices is supported.

Why this answer

StackWise Virtual merges two chassis into one logical device through a StackWise Virtual Link while preserving independent, synchronized control planes on each switch. It supports Multichassis EtherChannel to downstream devices, which is exactly what the architect needs for the data center access layer.

Exam trap

The trap here is conflating StackWise Virtual with classic StackWise or VSS, which use different link types and control-plane models.

← PreviousPage 2 of 2 · 142 questions total

Ready to test yourself?

Try a timed practice session using only Architecture questions.