Courseiva

CCNA Infrastructure Questions

29 of 179 questions · Page 3/3 · Infrastructure · Answers revealed

151
MCQmedium

A network engineer is deploying a VXLAN EVPN fabric. The underlay is a routed Layer 3 network using OSPF. Hosts in the same subnet are attached to leaf switches that are not directly connected. The engineer must ensure that the fabric provides optimal forwarding for East-West traffic without tromboning through a centralized gateway. Which VXLAN component should be configured to accomplish this?

A.Anycast distributed gateway with the same MAC and IP on all leaf switches
B.OSPF area 0 with stub areas on all leaf switches to reduce LSAs
C.Static VXLAN tunnel endpoints mapped to each leaf switch's loopback address
D.VXLAN Network Identifier (VNI) mapping to a single centralized gateway
AnswerA

An anycast distributed gateway configures the same gateway IP and MAC on every leaf switch, so each leaf can route traffic locally for its directly attached hosts. This avoids sending traffic to a centralized gateway and prevents suboptimal tromboning. It is the standard VXLAN EVPN design for optimal East-West forwarding.

Why this answer

An anycast distributed gateway places the same gateway IP and MAC on every leaf switch, allowing each leaf to route traffic for its local hosts. This eliminates the need to send traffic to a centralized gateway, providing optimal East-West forwarding. It is a key feature of VXLAN EVPN fabrics for efficient inter-subnet routing.

Exam trap

The trap here is assuming that any gateway configuration will automatically optimize East-West traffic, when in fact only a distributed anycast gateway avoids tromboning.

152
MCQmedium

A network engineer is configuring a Cisco Wireless LAN Controller (WLC) to support a new WLAN that requires 802.1X authentication with EAP-TLS. The engineer must ensure that the WLC forwards authentication requests to an external RADIUS server. Which configuration is required on the WLC?

A.Enable PSK on the WLAN and configure a pre-shared key.
B.Define a RADIUS server on the WLC and set the WLAN security to 802.1X with the RADIUS server selected.
C.Set the WLAN security to 802.1X and enable the local EAP server on the WLC.
D.Configure the WLAN with Web Policy authentication and a local net user.
AnswerB

For 802.1X with EAP-TLS, the WLC must act as a RADIUS client and forward EAP messages to an external RADIUS server. Configuring the server on the WLC and selecting it in the WLAN's security settings enables this. The WLC does not terminate EAP-TLS; it passes the authentication to the RADIUS server.

Why this answer

To support 802.1X with EAP-TLS, the WLC must be configured with an external RADIUS server and the WLAN must use 802.1X security referencing that server. The WLC then relays EAP messages between the client and the RADIUS server, which performs certificate-based authentication. This is the standard deployment for enterprise wireless with EAP-TLS.

Exam trap

The trap here is assuming the WLC can locally terminate EAP-TLS, when it typically proxies EAP to an external RADIUS server for certificate validation.

153
MCQhard

A multinational organization has a BGP-based MPLS VPN network. The CE router at a branch office is connected to two PE routers (PE1 and PE2) in the service provider network. The branch uses eBGP to exchange routes with the PEs. The network administrator notices that the branch can reach some destinations but not others. The BGP table on the CE shows routes with next-hop set to the PE loopback addresses, but those loopbacks are not reachable. The CE has a default route pointing to the PEs. What is the most likely cause of the issue?

A.The next-hop addresses of the BGP routes are not reachable.
B.The default route on the CE is overriding the BGP routes.
C.The routes have an AS path that is too long.
D.The CE is not advertising its routes to the PEs.
AnswerA

In BGP, the route is only installed into the IP routing table if the next-hop IP address is reachable via an existing IGP or static route. In an MPLS VPN, the PE advertises VPN routes to the remote PE with the next-hop set to the loopback address of the advertising PE. If that loopback is not in the IGP routing table of the receiving PE or the CE, the BGP route remains in the BGP table but is not installed, causing the CE to see no usable routes.

Why this answer

The CE router learns BGP routes from the PE routers with next-hop addresses set to the PE loopback interfaces. For these routes to be installed in the routing table, the CE must have a route to the next-hop IP address. Since the CE only has a default route pointing to the PEs and the PE loopbacks are not directly connected or reachable via any specific route, the BGP routes remain hidden (not installed) because the next-hop is unreachable.

This is the most likely cause of partial reachability.

Exam trap

Cisco often tests the BGP next-hop reachability rule, where candidates mistakenly think a default route satisfies the next-hop check, but BGP requires a specific route to the next-hop address (not a default route) for the route to be installed in the routing table.

How to eliminate wrong answers

Option B is wrong because a default route does not override BGP routes; BGP routes have a lower administrative distance (20 for eBGP) and would be preferred over a default route if the next-hop were reachable. Option C is wrong because a long AS path would affect route selection only if multiple paths exist, but it does not prevent routes from being installed when the next-hop is unreachable. Option D is wrong because the issue is about receiving routes from PEs, not about the CE advertising routes; the CE is receiving BGP routes but cannot install them due to next-hop unreachability.

154
MCQmedium

A network administrator is deploying a new branch office that requires a dynamic routing protocol supporting unequal-cost load balancing and fast convergence. The topology includes Cisco routers only. Which routing protocol should be implemented?

A.BGP
B.OSPF
C.EIGRP
D.RIPv2
AnswerC

EIGRP supports unequal-cost load balancing through the variance command, allowing traffic to be distributed across multiple paths with different metrics. It also converges quickly using the feasible successor mechanism, making it suitable for this branch office scenario. OSPF and BGP do not natively support unequal-cost load balancing, and RIP has slow convergence.

Why this answer

EIGRP is the only protocol among the choices that inherently supports unequal-cost load balancing via the variance feature and provides fast convergence through its feasible successor mechanism. OSPF and BGP support only equal-cost multipath, and RIPv2 lacks both features, making EIGRP the correct choice for this scenario.

Exam trap

The trap here is assuming that OSPF or BGP can perform unequal-cost load balancing because they support equal-cost multipath.

155
MCQmedium

A network engineer is configuring a Cisco Wireless LAN Controller (WLC) to authenticate corporate users using 802.1X with a RADIUS server. The requirement is to ensure that only users with valid credentials can access the wireless network, and that the RADIUS server is reachable. Which WLC configuration step is required to enable 802.1X authentication?

A.Enable MAC filtering on the WLC and add the MAC addresses of authorized users.
B.Configure the WLAN with WPA2 Enterprise security and specify the RADIUS server IP address and shared secret.
C.Configure the WLAN with WPA2 Personal security and specify a pre-shared key.
D.Configure the WLAN with Open security and enable web authentication using the RADIUS server.
AnswerB

To enable 802.1X authentication on a WLC, the WLAN must be configured with WPA2 Enterprise security, which uses 802.1X/EAP. The RADIUS server details, including IP address and shared secret, must be specified so the WLC can communicate with the authentication server. This configuration ensures that clients authenticate via the RADIUS server before gaining network access.

Why this answer

802.1X authentication on a Cisco WLC requires the WLAN to be configured with WPA2 Enterprise security. This setting enables the use of EAP, which relays authentication to a RADIUS server. The RADIUS server IP address and shared secret must be configured so the WLC can communicate with the server.

This ensures that only users with valid credentials, as verified by the RADIUS server, can access the wireless network.

Exam trap

The trap here is confusing WPA2 Personal (PSK) with WPA2 Enterprise (802.1X); only Enterprise mode uses a RADIUS server for per-user authentication.

156
MCQmedium

A network engineer is configuring a new Cisco Catalyst switch that will participate in a VTP domain. The engineer wants to ensure the switch can create, modify, and delete VLANs for the domain while also receiving updates. The switch must not overwrite the existing VLAN database on other switches in the domain. Which VTP mode should be configured?

A.VTP client mode
B.VTP server mode
C.VTP transparent mode
D.VTP off mode
AnswerB

VTP server mode allows the switch to create, modify, and delete VLANs for the entire VTP domain. The switch can also receive and process VTP advertisements from other servers, but it will not overwrite the existing VLAN database unless its configuration revision number is higher. By default, a new switch has a revision number of 0, so it will not overwrite existing databases. This meets all requirements.

Why this answer

VTP server mode enables a switch to create, modify, and delete VLANs for the entire VTP domain. It also receives VTP advertisements from other servers and clients. A new switch with a default revision number of 0 will not overwrite the existing VLAN database unless its revision number is higher.

Therefore, server mode satisfies the need to manage VLANs domain-wide while safely receiving updates.

Exam trap

The trap here is assuming that a VTP server will automatically overwrite other switches' VLAN databases, when in fact it only does so if its configuration revision number is higher than the existing one.

157
MCQmedium

A network engineer is deploying Cisco SD-Access and needs to provide fabric edge nodes with a mapping database for endpoint locations. The fabric uses LISP for control plane and VXLAN for data plane encapsulation. Which component is responsible for maintaining the endpoint-to-edge-node mapping and responding to map requests?

A.Fabric Edge Node
B.Fabric Border Node
C.Fabric Intermediate Node
D.Control Plane Node
AnswerD

The Control Plane Node (CPN) runs the LISP map server and map resolver. It maintains the endpoint ID-to-RLOC mapping database and responds to map-requests from fabric edge nodes. When an edge node needs to locate an endpoint, it queries the CPN, which returns the RLOC of the edge node where the endpoint is attached.

Why this answer

In Cisco SD-Access, the Control Plane Node runs the LISP map server and map resolver, maintaining the endpoint-to-RLOC mapping database. Fabric edge nodes query this node to resolve endpoint locations. The Control Plane Node is the central authority for the LISP control plane, enabling scalable endpoint mobility and policy enforcement.

Exam trap

The trap here is assuming that fabric edge nodes maintain the endpoint mapping database, but they only register endpoints and query the Control Plane Node for resolution.

158
MCQhard

A network engineer is deploying Cisco SD-Access and needs to integrate a new fabric site with an existing traditional network. The requirement is to allow endpoints in the fabric to communicate with external networks while preserving their fabric-assigned IP addresses and providing policy enforcement. Which component is responsible for this integration?

A.Fabric control plane node
B.Fabric edge node
C.Fabric border node
D.Fabric intermediate node
AnswerC

The fabric border node connects the SD-Access fabric to external networks (traditional L3 networks, data centers, or other fabric sites). It performs route redistribution between the fabric's LISP/VXLAN domains and external routing protocols, and can enforce policy via SGT propagation. It preserves endpoint IP addresses by advertising fabric prefixes externally and importing external routes into the fabric.

Why this answer

The fabric border node is the component that connects the SD-Access fabric to external networks. It handles route redistribution between the fabric and external routing domains, preserves endpoint IP addresses, and can enforce policy using SGTs. Edge, control plane, and intermediate nodes have different roles and do not provide external integration.

Exam trap

The trap here is confusing the roles of fabric nodes, particularly assuming the control plane node handles external routing or that edge nodes perform border functions.

159
MCQmedium

A network engineer at a large enterprise is deploying a new branch office. The branch has two Cisco Catalyst switches, SW1 and SW2, that must participate in the same Layer 2 domain. SW1 is configured as the VTP server with domain 'CORP' and version 2. SW2 is a new switch with a higher VTP revision number and the same domain and password, but it has an empty VLAN database. The engineer connects SW2 to SW1 via a trunk link. What will happen to the VLAN database on SW1?

A.SW1 will not synchronize because VTP version 2 requires the same configuration revision number.
B.SW1 will overwrite SW2's VLAN database because SW1 is the VTP server.
C.SW1 will synchronize its VLAN database to SW2's database, potentially deleting VLANs.
D.SW1 will reject SW2's advertisement because SW2 is not a VTP server.
AnswerC

VTP uses the highest revision number within the same domain and password to determine which database is most current. SW2 has a higher revision number, so SW1 will accept SW2's advertisement and overwrite its own VLAN database with SW2's, which is empty. This can wipe out all VLANs on SW1 and disrupt the network.

Why this answer

VTP uses the configuration revision number to determine which switch has the most recent VLAN database. When SW2 with a higher revision number connects, SW1 accepts SW2's advertisement and replaces its own VLAN database, even though SW1 is the server. This can cause VLANs to be deleted, so it is critical to reset the revision number on new switches before connecting them to the production network.

Exam trap

The trap here is assuming that a VTP server will always overwrite clients; in reality, the highest revision number wins regardless of server or client role.

160
MCQhard

A network administrator is implementing VXLAN with a distributed anycast gateway in a Cisco SD-Access fabric. The fabric has two border nodes and four edge nodes. The administrator wants to ensure that traffic from a wired endpoint in VLAN 10 can reach a wireless endpoint in the same VLAN that is roaming between access points. Which component is responsible for mapping the endpoint's IP address to its location in the fabric?

A.The fabric intermediate node acts as a LISP proxy ETR to provide the mapping.
B.The fabric edge node caches the mapping and shares it directly with other edge nodes via LISP pub-sub.
C.The fabric border node performs the mapping using the LISP map-server function.
D.The fabric control plane node maintains the mapping in its LISP map-server database.
AnswerD

In Cisco SD-Access, the control plane node runs the LISP map-server and map-resolver functions. It maintains the endpoint-to-location mappings in its database. When an edge node needs to resolve an endpoint's location, it queries the control plane node, which returns the RLOC (routing locator) of the edge node where the endpoint is attached.

Why this answer

In Cisco SD-Access, the control plane node hosts the LISP map-server and map-resolver, maintaining the database of endpoint-to-RLOC mappings. Edge nodes register endpoints and query the control plane to resolve destinations. This centralized mapping enables seamless mobility and policy enforcement across the fabric.

Exam trap

The trap here is confusing the roles of border and control plane nodes, assuming the border node handles endpoint mapping when it actually handles external connectivity.

161
MCQhard

A network administrator is configuring a VXLAN EVPN fabric. The administrator wants to optimize the forwarding of broadcast, unknown unicast, and multicast (BUM) traffic by using a multicast group per VLAN. Which VXLAN feature should be configured on the VTEPs to achieve this?

A.Multicast underlay with PIM Sparse Mode
B.Ingress replication
C.EVPN Integrated Routing and Bridging (IRB)
D.Anycast VTEP
AnswerA

In VXLAN, BUM traffic can be replicated using multicast in the underlay. By mapping each VLAN to a unique multicast group address, VTEPs can efficiently forward BUM traffic only to interested VTEPs. Configuring PIM Sparse Mode in the underlay enables this multicast replication. This approach optimizes BUM traffic by avoiding unicast head-end replication and leverages the underlay multicast capabilities.

Why this answer

Using a multicast underlay with PIM Sparse Mode allows each VLAN to be mapped to a unique multicast group, so BUM traffic is replicated only to VTEPs that have joined that group. This optimizes bandwidth and reduces unnecessary flooding. Ingress replication and anycast VTEP do not provide per-VLAN multicast group mapping.

EVPN IRB is for routing, not BUM optimization.

Exam trap

The trap here is assuming that any VXLAN feature like ingress replication or anycast VTEP can optimize BUM traffic, but only multicast underlay with PIM Sparse Mode supports per-VLAN multicast groups.

162
MCQhard

A network engineer is implementing VXLAN with a Cisco Nexus 9000 series switch acting as a VTEP. The underlay network is OSPF, and the overlay uses BGP EVPN. The engineer notices that VM traffic between two hosts on different VTEPs is not being encapsulated. Which action should be taken to ensure VXLAN traffic is properly encapsulated and forwarded?

A.Ensure that the underlay OSPF cost is equal on all links to allow ECMP for VXLAN traffic.
B.Configure a VRF for the overlay and redistribute the VRF routes into OSPF.
C.Enable VXLAN feature and configure the NVE interface with a source interface and a VNI mapping to the VLAN.
D.Configure a VXLAN tunnel interface with the source interface as the loopback0 and the destination as the remote VTEP's loopback0.
AnswerC

To enable VXLAN encapsulation, the `feature nv overlay` and `feature vn-segment-vlan-based` must be enabled, and an NVE interface must be configured with a source interface (usually a loopback) and a VNI mapped to the VLAN. The NVE interface is the VTEP, and without it, VXLAN encapsulation does not occur.

Why this answer

VXLAN encapsulation requires the NVE interface to be configured with a source interface and VNI-to-VLAN mapping. Enabling the VXLAN features and configuring the NVE interface are essential steps. Without these, the switch will not encapsulate traffic, even if the underlay and overlay routing are correct.

Exam trap

The trap here is confusing underlay routing issues with overlay encapsulation; the lack of encapsulation is due to missing NVE configuration, not OSPF or BGP.

163
MCQmedium

A network engineer is implementing a first-hop redundancy protocol on a pair of Cisco switches. The design requires that the virtual IP address be the same as one of the physical interface addresses, and that the standby group use a virtual MAC address of 0000.0c07.acXX. Which protocol meets these requirements?

A.VRRP
B.SLB
C.GLBP
D.HSRP
AnswerD

HSRP uses a virtual MAC address of 0000.0c07.acXX, where XX is the group number in hexadecimal. It also allows the virtual IP address to be the same as one of the physical interface addresses on the active router. This matches the requirements exactly, making HSRP the correct choice.

Why this answer

HSRP is a Cisco-proprietary first-hop redundancy protocol that uses the virtual MAC address 0000.0c07.acXX and permits the virtual IP to be the same as a physical interface IP. VRRP and GLBP use different MAC address formats. Therefore, HSRP uniquely satisfies both conditions in the scenario.

Exam trap

The trap here is mixing up the virtual MAC address formats of HSRP, VRRP, and GLBP; only HSRP uses the 0000.0c07.acXX prefix.

164
MCQhard

A network engineer is configuring a Cisco IOS router to establish a site-to-site VPN using IPsec. The engineer wants to ensure that the VPN tunnel only carries traffic for the subnet 10.1.1.0/24 to 10.2.2.0/24. Which configuration element is required to define the interesting traffic?

A.ISAKMP policy
B.crypto map
C.IPsec transform set
D.crypto ACL (extended access list)
AnswerD

The crypto ACL, typically an extended access list, defines the interesting traffic that should be encrypted and sent through the VPN tunnel. It specifies the source and destination subnets, such as permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255. This ACL is referenced by the crypto map.

Why this answer

The crypto ACL, an extended access list, defines the interesting traffic that should be protected by IPsec. It specifies the source and destination addresses and ports. The crypto map then references this ACL to apply the IPsec policies.

Without the crypto ACL, the router would not know which packets to encrypt and send through the tunnel.

Exam trap

The trap here is confusing the roles of the various IPsec components; the crypto ACL defines interesting traffic, while the crypto map applies the policies.

165
MCQhard

A network engineer is implementing VXLAN with a distributed anycast gateway in a Cisco SD-Access fabric. The fabric uses LISP for control plane and VXLAN for data plane. Which component is responsible for mapping endpoint IP addresses to fabric edge nodes?

A.Fabric edge node
B.Fabric intermediate node
C.Fabric border node
D.Control plane node
AnswerD

The control plane node in a Cisco SD-Access fabric runs the LISP Map-Server and Map-Resolver functions. It maintains the mapping database of endpoint IP addresses to fabric edge nodes (RLOCs). When an edge node needs to reach an endpoint, it sends a Map-Request to the control plane node, which responds with the Map-Reply containing the RLOC of the edge node where the endpoint is located. This enables VXLAN encapsulation and forwarding.

Why this answer

In Cisco SD-Access, the control plane node runs LISP Map-Server and Map-Resolver. It maintains the mapping of endpoint IP addresses to the RLOC of the fabric edge node where the endpoint is connected. When an edge node needs to forward traffic to an endpoint, it queries the control plane node to obtain the mapping, enabling VXLAN encapsulation.

The border and intermediate nodes do not perform this mapping function.

Exam trap

The trap here is confusing the roles of fabric nodes; the control plane node is the one that provides the mapping service, not the edge or border nodes.

166
MCQhard

A network engineer is implementing VXLAN with an Ethernet VPN (EVPN) control plane in a data center. The underlay is a Layer 3 IP network. The engineer wants to ensure that the VXLAN tunnel endpoints (VTEPs) can discover each other and that the fabric supports multihoming with all-active forwarding. Which technology should be used?

A.VXLAN with static unicast flooding and no control plane
B.VXLAN with PIM-SM multicast underlay
C.VXLAN with OSPF as the underlay routing protocol
D.VXLAN with EVPN as the control plane
AnswerD

EVPN provides a standards-based control plane for VXLAN, enabling automatic VTEP discovery, MAC address learning, and support for multihoming with all-active forwarding. EVPN uses BGP to distribute MAC and IP reachability information, and it supports Ethernet Segment (ES) multihoming, which allows a host to connect to multiple VTEPs with all links active. This matches the requirements for dynamic discovery and all-active multihoming.

Why this answer

EVPN is the correct choice because it provides a scalable control plane for VXLAN, enabling automatic VTEP discovery and MAC learning via BGP. It also supports multihoming with all-active forwarding through Ethernet Segment configurations, which allows a device to connect to multiple VTEPs simultaneously. Other options either lack a control plane or do not support the required multihoming capabilities.

Exam trap

The trap here is confusing underlay routing protocols like OSPF or multicast with the overlay control plane, or assuming that static VXLAN can provide dynamic discovery and multihoming.

167
MCQmedium

A network engineer is configuring a Cisco IOS router to act as a DHCP relay agent for a remote subnet 10.10.10.0/24. The DHCP server is located at 172.16.1.100. The engineer issues the command 'ip helper-address 172.16.1.100' on interface GigabitEthernet0/0, which is the gateway for that subnet. However, clients on the subnet are not receiving IP addresses. What is the most likely cause?

A.The 'service dhcp' command is disabled globally on the router.
B.The DHCP server is not reachable from the router because a route to 172.16.1.100 is missing.
C.The 'ip helper-address' command must be configured on the interface facing the DHCP server, not the client-facing interface.
D.The DHCP server is configured to use a different subnet mask than the clients require.
AnswerB

For DHCP relay to work, the router must have a route to the DHCP server's IP address. If no route exists, the router cannot forward the relayed packets, and clients will not receive addresses. This is a common oversight when configuring relay agents in a new environment.

Why this answer

The 'ip helper-address' command relays DHCP broadcasts to a specified server, but the router must have a route to that server. Without a route to 172.16.1.100, the relayed packets are dropped, and clients cannot obtain addresses. Ensuring IP reachability to the DHCP server is essential for successful relay operation.

Exam trap

The trap here is assuming that configuring the helper address alone is sufficient, overlooking the need for a route to the DHCP server.

168
MCQhard

A network engineer is implementing a first-hop redundancy protocol on a pair of Cisco switches. The requirement is to provide sub-second failover for IPv4 hosts and to load-balance traffic between the two switches for different VLANs. Which protocol should be used to meet these requirements?

A.ICMP Router Discovery Protocol (IRDP)
B.Hot Standby Router Protocol (HSRP) version 1
C.Virtual Router Redundancy Protocol (VRRP) version 3
D.Gateway Load Balancing Protocol (GLBP)
AnswerD

GLBP provides both sub-second failover and automatic load balancing across multiple gateways. It uses an Active Virtual Gateway (AVG) and up to four Active Virtual Forwarders (AVFs) to share traffic. Different hosts can be assigned different virtual MAC addresses, distributing the load. This meets the requirements for sub-second failover and load balancing across VLANs without manual per-VLAN group configuration.

Why this answer

GLBP is designed to provide both redundancy and load balancing. It elects an Active Virtual Gateway that assigns virtual MAC addresses to up to four Active Virtual Forwarders, allowing multiple switches to share the traffic load while providing sub-second failover. HSRP and VRRP can provide redundancy but require manual configuration for load balancing, and IRDP lacks the necessary features.

Exam trap

The trap here is assuming that HSRP or VRRP can automatically load-balance traffic across multiple switches without additional configuration, but only GLBP provides native load-balancing capabilities.

169
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate management users against a RADIUS server. The engineer wants to ensure that if the RADIUS server is unreachable, the router falls back to local authentication using the local username database. Which configuration should be applied?

A.aaa authentication login default group radius local
B.aaa authentication login default group radius enable
C.aaa authentication login default group radius none
D.aaa authentication login default local group radius
AnswerA

This command configures AAA authentication for login to first use the RADIUS server group and then fall back to the local database if the RADIUS server is unreachable. The 'local' keyword ensures that local authentication is attempted as a backup, providing resilience.

Why this answer

The correct configuration uses 'group radius' followed by 'local' to ensure that RADIUS is tried first and local authentication is used only as a fallback when the RADIUS server is unreachable. This provides both centralized authentication and resilience.

Exam trap

The trap here is reversing the order of methods or using 'enable' or 'none' as fallback, which do not provide local database fallback.

170
MCQmedium

A network engineer is implementing a REST API script to retrieve interface statistics from a Cisco IOS XE device. The engineer wants to use the most efficient method that supports HTTP/2 and streaming telemetry. Which API should be used?

A.NETCONF over SSH
B.SNMPv3
C.RESTCONF
D.gRPC
AnswerD

gRPC is a high-performance RPC framework that uses HTTP/2 for transport, supports streaming, and is used for model-driven telemetry on Cisco IOS XE. It allows efficient, real-time streaming of telemetry data and supports bidirectional streaming. This makes it the best choice for retrieving interface statistics with streaming telemetry and HTTP/2 benefits.

Why this answer

gRPC is the only option that natively uses HTTP/2 and supports streaming telemetry. It is designed for efficient, high-performance telemetry collection from Cisco IOS XE devices. NETCONF and RESTCONF are not optimized for streaming, and SNMPv3 is a polling protocol.

Therefore, gRPC is the correct choice.

Exam trap

The trap here is assuming that RESTCONF or NETCONF can handle streaming telemetry, but they are not designed for high-frequency streaming; gRPC is the protocol for that.

171
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate OSPF neighbors using MD5 cryptographic authentication on an interface. The engineer enters the following commands: interface GigabitEthernet0/0, ip ospf authentication message-digest, ip ospf message-digest-key 1 md5 Cisco123. However, the OSPF adjacency with the neighbor router is not forming. Which additional configuration is required on the neighbor router to establish the adjacency?

A.Configure the neighbor with the command area 0 authentication message-digest.
B.Configure the neighbor with the command ip ospf authentication-key Cisco123.
C.Configure the same key ID and password on the neighbor's interface with ip ospf message-digest-key 1 md5 Cisco123.
D.Configure the neighbor with the command ip ospf authentication null.
AnswerC

For OSPF MD5 authentication to succeed, both routers must have the same key ID and password configured on their interfaces. The neighbor must have the identical message-digest-key command with the same key number and MD5 password. Without this matching configuration, authentication will fail, and the adjacency will not form.

Why this answer

OSPF MD5 authentication requires both neighbors to have the same key ID and password configured on their interfaces. The engineer configured MD5 on one router, so the neighbor must have the identical 'ip ospf message-digest-key' command. Without matching keys, authentication fails and the adjacency does not form.

Exam trap

The trap here is assuming that enabling MD5 authentication on one side is sufficient, or confusing plain text authentication with MD5 authentication.

172
MCQeasy

A network administrator is configuring a Cisco IOS router to authenticate management users against a centralized TACACS+ server. The administrator wants to ensure that if the TACACS+ server is unreachable, a locally configured user can still log in. Which command should be used to define the authentication method list for login?

A.aaa authorization exec default group tacacs+ local
B.aaa authentication login default group radius local
C.aaa authentication login default group tacacs+ none
D.aaa authentication login default group tacacs+ local
AnswerD

This method list tells the router to try TACACS+ first, then fall back to the local user database if the server does not respond. The local keyword ensures that a locally configured username and password can be used during an outage. This meets the requirement for centralized authentication with a local fallback.

Why this answer

The aaa authentication login default command defines the method list for login authentication. Listing group tacacs+ before local ensures the router attempts TACACS+ first and falls back to the local database only if the server is unreachable. This provides both centralized control and a reliable local backup for management access.

Exam trap

The trap here is using the none keyword as a fallback, which bypasses authentication entirely instead of using local credentials.

173
Multi-Selectmedium

A network engineer is implementing VXLAN in a data center to support a large number of tenants. The engineer must ensure that the VXLAN overlay supports Layer 2 connectivity over a Layer 3 underlay. Which two statements are true about VXLAN? (Choose two.)

Select 2 answers
A.VXLAN encapsulates Layer 2 frames in UDP packets for transport over a Layer 3 network.
B.VXLAN uses a 24-bit VNI to identify up to 16 million segments.
C.VXLAN uses a 12-bit VLAN ID to identify segments.
D.VXLAN requires a multicast underlay for all broadcast, unknown unicast, and multicast traffic.
E.VXLAN tunnel endpoints (VTEPs) must be configured with the same IP address on all devices.
AnswersA, B

VXLAN encapsulates original Layer 2 frames within UDP packets, typically using UDP port 4789. This encapsulation allows Layer 2 connectivity to be extended over a routed Layer 3 underlay, which is essential for data center interconnect and overlay networks. The use of UDP provides a standard transport that can traverse IP networks.

Why this answer

VXLAN uses a 24-bit VNI, allowing up to 16 million segments, and encapsulates Layer 2 frames in UDP packets for transport over a Layer 3 underlay. These two characteristics enable scalable multi-tenancy and Layer 2 extension across routed networks. The other statements are false: multicast is not mandatory, VTEPs require unique IPs, and VXLAN does not use 12-bit VLAN IDs.

Exam trap

The trap here is confusing VXLAN's VNI size with VLAN IDs or assuming multicast is mandatory for VXLAN, when it is only one of several replication methods.

174
MCQmedium

A network engineer is configuring a VXLAN EVPN fabric on Cisco Nexus switches. The fabric must support Layer 2 extension across multiple leaf switches while maintaining optimal forwarding for Layer 3 traffic. Which control plane component is responsible for advertising MAC and IP address bindings to all leaf switches?

A.PIM sparse mode
B.Cisco Fabric Services (CFS)
C.MP-BGP EVPN address family
D.OSPFv3 with address families
AnswerC

MP-BGP EVPN is the control plane that distributes MAC and IP bindings via EVPN routes such as Type 2 and Type 5. It enables all leaf switches to learn remote MAC/IP addresses and provides optimal forwarding without relying on flood-and-learn. This matches the requirement for a scalable, efficient VXLAN EVPN fabric.

Why this answer

MP-BGP EVPN is the standard control plane for VXLAN EVPN fabrics. It advertises MAC and IP bindings using EVPN route types, enabling leaf switches to learn remote endpoints and forward traffic optimally without flooding. The other protocols listed are either underlay routing, multicast, or fabric management tools and do not provide the required EVPN address family.

Exam trap

The trap here is assuming that any routing protocol or multicast mechanism can distribute MAC and IP bindings, when only MP-BGP EVPN provides that capability in a VXLAN EVPN fabric.

175
MCQhard

A network engineer is implementing QoS on a Cisco IOS router. The engineer wants to ensure that VoIP traffic is prioritized and that excess VoIP traffic is dropped when the interface is congested. Which QoS mechanism should be used?

A.Weighted Random Early Detection (WRED) on the VoIP class.
B.Class-Based Weighted Fair Queuing (CBWFQ) with a bandwidth guarantee.
C.Traffic shaping on the VoIP class.
D.Low Latency Queuing (LLQ) with a policer.
AnswerD

LLQ provides a strict priority queue for VoIP traffic, ensuring low latency and jitter. When combined with a policer, it can limit the amount of traffic that enters the priority queue, dropping excess VoIP packets during congestion. This meets the requirement to prioritize and drop excess VoIP traffic.

Why this answer

For VoIP, LLQ provides a strict priority queue to minimize latency and jitter. To prevent excess VoIP traffic from starving other queues, a policer is applied to the priority queue, dropping packets that exceed the configured rate. This combination ensures VoIP is prioritized and excess traffic is dropped during congestion.

Exam trap

The trap here is thinking that CBWFQ or shaping can handle VoIP prioritization, but only LLQ with a policer provides both strict priority and drop of excess traffic.

176
MCQmedium

A network engineer is deploying a new branch office with a single Cisco Catalyst 9300 switch. The branch has three VLANs: VLAN 10 (users), VLAN 20 (voice), and VLAN 30 (management). The engineer needs to route traffic between these VLANs directly on the switch without using an external router. Which feature should be configured on the switch to enable inter-VLAN routing?

A.Configure 802.1Q trunking to an external router and enable Router-on-a-Stick.
B.Configure a routed port on the switch and connect it to each VLAN's subnet.
C.Enable private VLANs to isolate traffic between VLANs.
D.Configure Switch Virtual Interfaces (SVIs) for each VLAN and enable IP routing.
AnswerD

SVIs are logical Layer 3 interfaces associated with VLANs. Creating an SVI for each VLAN and enabling IP routing allows the multilayer switch to route traffic between VLANs internally. This is the standard method for inter-VLAN routing on a Catalyst switch, eliminating the need for an external router and providing high-performance routing.

Why this answer

Inter-VLAN routing on a multilayer switch is achieved by creating a Switch Virtual Interface (SVI) for each VLAN and enabling IP routing. SVIs act as default gateways for hosts in each VLAN, and the switch routes packets between them. This method is efficient, scalable, and does not require an external router, making it ideal for the branch office scenario.

Exam trap

The trap here is assuming that a routed port can belong to multiple VLANs or that Router-on-a-Stick is required for inter-VLAN routing on a multilayer switch.

177
MCQmedium

A network architect is designing a controller-based wireless deployment for a large campus. The requirement is to provide seamless roaming for voice clients across Layer 3 boundaries while keeping the client IP address unchanged. Which Cisco SD-Access fabric feature should be used to meet this requirement?

A.Configure the fabric to use VXLAN with Layer 2 flooding and enable ARP proxy on the edge nodes.
B.Deploy a dedicated WLC in each building and configure inter-controller roaming with mobility groups.
C.Configure the fabric edge nodes to run HSRP on the anycast gateway and enable preemption for fast failover.
D.Enable IP mobility on the fabric edge nodes and configure the fabric control plane to track client locations.
AnswerD

Cisco SD-Access fabric supports IP mobility, which allows a client to roam across Layer 3 boundaries while keeping its IP address. The fabric control plane node (using LISP) tracks endpoint locations, and the edge nodes encapsulate traffic in VXLAN. When a client roams, the new edge node registers the client's new location, and the fabric forwards traffic to the correct edge, ensuring seamless roaming without IP address change.

Why this answer

In Cisco SD-Access, IP mobility is the feature that enables seamless roaming across Layer 3 boundaries while preserving the client IP address. The fabric control plane node tracks endpoint locations, and edge nodes use VXLAN encapsulation to forward traffic to the correct edge. This is essential for voice clients that require uninterrupted connectivity during roaming.

Exam trap

The trap here is assuming that traditional WLC mobility groups or Layer 2 flooding are sufficient for seamless Layer 3 roaming in an SD-Access fabric.

178
MCQmedium

A network administrator is configuring a Cisco IOS router to authenticate management users via TACACS+. The router must use the TACACS+ server at 10.1.1.100 with the shared secret 'Cisco123'. The administrator wants to ensure that if the TACACS+ server is unreachable, authentication falls back to the local database. Which configuration is required?

A.aaa authentication login default group tacacs+ none
B.aaa authentication login default group tacacs+ enable
C.aaa authentication login default local group tacacs+
D.aaa authentication login default group tacacs+ local
AnswerD

This command configures AAA authentication for login using the default method list. It specifies that the TACACS+ group should be tried first, and if the server is unreachable, the local database is used as a fallback. This meets the requirement for fallback authentication. The 'group tacacs+' keyword refers to the TACACS+ servers defined with the 'tacacs server' command.

Why this answer

The correct command is 'aaa authentication login default group tacacs+ local'. It configures the default method list to attempt TACACS+ authentication first, and if the TACACS+ server is unreachable, it falls back to the local username and password database. This provides redundancy while maintaining individual user accountability.

Exam trap

The trap here is the order of methods in the AAA authentication command; placing 'local' before 'group tacacs+' changes the fallback behavior and may inadvertently allow local credentials to be used even when the TACACS+ server is available.

179
MCQhard

Refer to the exhibit. R1 has two equal-cost OSPF E2 routes to 10.1.1.0/24 via two different next hops. However, when tracing to 10.1.1.1, all traffic uses the path through 10.0.1.2. What is the most likely reason?

A.One route has a higher administrative distance.
B.A default route is overriding the specific route.
C.The route via 10.0.2.2 is an E1 route.
D.OSPF E2 routes do not factor interface cost; but the router uses the interface cost as a tie-breaker for equal-cost routes.
AnswerD

OSPF E2 routes advertise the external metric from the ASBR and intentionally discard the internal cost accumulated along the path, so two E2 routes with the same metric appear equal. However, Cisco IOS and many other implementations avoid a random choice by applying a tie-breaking rule: when the E2 metric and AD are identical, the router compares the OSPF interface cost (or the cost to the ASBR) and prefers the path with the lower cost. In the exhibit, the two E2 routes have equal external metrics, but the route via the interface with lower cost is installed, while the other is held as a candidate. Thus, the apparent equal-cost routes are not truly equal for forwarding because interface cost breaks the tie.

Why this answer

OSPF E2 routes do not include the internal cost to the ASBR; the cost shown in the routing table is the external metric only. When two E2 routes have the same external metric, Cisco IOS uses the interface cost as a tie-breaker to select the best next hop. In this scenario, the interface to 10.0.1.2 has a lower cost than the interface to 10.0.2.2, so all traffic is forwarded via 10.0.1.2.

Exam trap

Cisco often tests the subtle tie-breaking behavior for OSPF E2 routes, where candidates mistakenly assume that equal-cost E2 routes will always be load-balanced, ignoring the interface cost tie-breaker that Cisco IOS applies.

How to eliminate wrong answers

Option A is wrong because administrative distance is a per-protocol preference and both routes are OSPF E2 routes, so they share the same AD (110 by default). Option B is wrong because a default route would only be used if no specific route to 10.1.1.0/24 existed; the router has two specific routes and will use them, not a default. Option C is wrong because if the route via 10.0.2.2 were an E1 route, it would include the internal cost to the ASBR, making its total metric higher than the E2 route, and it would not be considered equal-cost; the question states both are equal-cost E2 routes.

← PreviousPage 3 of 3 · 179 questions total

Ready to test yourself?

Try a timed practice session using only Infrastructure questions.