Courseiva

CCNA Network Assurance Questions

75 of 87 questions · Page 1/2 · Network Assurance · Answers revealed

1
MCQmedium

A network engineer is deploying Cisco SD-Access and needs to ensure that fabric edge nodes can register with the fabric control plane node. Which protocol is used for this registration and for endpoint location mapping?

A.BGP
B.VXLAN
C.LISP
D.IS-IS
AnswerC

LISP (Locator/ID Separation Protocol) is used in Cisco SD-Access for endpoint location mapping. Fabric edge nodes register endpoint EIDs with the control plane node, which maintains a mapping of EIDs to RLOCs. This allows the fabric to route traffic based on endpoint identity. LISP is the correct protocol for this function.

Why this answer

In Cisco SD-Access, LISP is the control plane protocol that enables fabric edge nodes to register endpoints with the control plane node. The control plane node maintains a mapping database of endpoint identifiers to routing locators. VXLAN, BGP, and IS-IS serve other roles in the fabric, such as data plane encapsulation and underlay routing.

Exam trap

The trap here is confusing the data plane protocol (VXLAN) with the control plane protocol (LISP), assuming that the encapsulation protocol also handles registration.

2
MCQhard

A network administrator is troubleshooting a Cisco SD-WAN deployment where a branch site is experiencing intermittent connectivity to a SaaS application. The administrator suspects that the issue is related to the application-aware routing policy not correctly identifying the application. Which component of Cisco SD-WAN is responsible for identifying applications in the data plane?

A.vBond orchestrator
B.vSmart controller
C.vManage NMS
D.vEdge router
AnswerD

The vEdge router is responsible for data plane forwarding and application identification. It uses deep packet inspection (DPI) or Cisco NBAR to classify traffic into applications, which is essential for application-aware routing policies. This classification allows the router to make informed path selection decisions based on application performance requirements.

Why this answer

Application identification in Cisco SD-WAN is performed by the vEdge router, which uses deep packet inspection (DPI) or Cisco NBAR to recognize applications. This classification is critical for application-aware routing, as it enables the router to apply policies that steer traffic based on application performance. The vEdge router then forwards traffic accordingly, ensuring that SaaS applications receive appropriate treatment.

Exam trap

The trap here is assuming that centralized controllers like vSmart or vManage perform application identification, but this function is distributed to the data plane on vEdge routers.

3
MCQeasy

A network administrator is using Cisco DNA Center Assurance to monitor the health of a campus network. The administrator wants to receive alerts when a switch's health score drops below a threshold. Which Assurance feature should be configured to generate these alerts?

A.Assurance Issues and Notifications
B.Sensor-driven tests
C.Network Health Dashboard
D.Path Trace
AnswerA

Cisco DNA Center Assurance allows administrators to define issues and configure notifications based on health score thresholds. By setting up assurance issues, the system can trigger alerts via email, syslog, or webhook when a switch's health score falls below a specified value. This is the correct feature for proactive alerting.

Why this answer

To generate alerts when a switch's health score drops below a threshold, the administrator must configure Assurance Issues and Notifications in Cisco DNA Center. This feature allows defining specific health score conditions and setting up notification channels such as email or webhooks. The Network Health Dashboard is for visualization, Path Trace for troubleshooting, and Sensor-driven tests for proactive monitoring, none of which provide threshold-based alerting directly.

Exam trap

The trap here is assuming that the Network Health Dashboard or Sensor-driven tests automatically send alerts, when in fact alerting requires explicit configuration of Assurance Issues and Notifications.

4
MCQhard

A network administrator is deploying a new QoS policy to prioritize voice traffic across a WAN link. The policy must ensure that voice packets are not dropped even during congestion, and that bandwidth is guaranteed for voice. Which queuing mechanism should be used for the voice class?

A.Weighted Random Early Detection (WRED)
B.Low Latency Queuing (LLQ)
C.Class-Based Weighted Fair Queuing (CBWFQ)
D.First-In, First-Out (FIFO) queuing
AnswerB

LLQ combines a strict-priority queue with a guaranteed bandwidth allocation, so voice packets are serviced first and never dropped during congestion while their reserved bandwidth is protected. CBWFQ alone offers no strict priority, so latency-sensitive voice could still be delayed.

Why this answer

LLQ is the correct choice because it combines strict priority queuing with CBWFQ, ensuring that voice traffic is placed into a strict priority queue that is serviced before any other queues. This guarantees low latency and prevents voice packet drops during congestion by allowing the priority queue to be policed to a configured bandwidth limit, while still providing bandwidth guarantees for the voice class.

Exam trap

Cisco often tests the distinction between CBWFQ and LLQ, where candidates mistakenly choose CBWFQ because it offers bandwidth guarantees, but fail to recognize that only LLQ provides the strict priority queuing required for real-time voice traffic to avoid drops and delay.

How to eliminate wrong answers

Option A is wrong because WRED is a congestion avoidance mechanism that drops packets proactively based on queue depth, not a queuing mechanism that guarantees bandwidth or provides strict priority; it would drop voice packets during congestion, violating the requirement. Option C is wrong because CBWFQ provides bandwidth guarantees and fair queuing for classes but does not include a strict priority queue, so voice traffic would experience delay and jitter during congestion, leading to potential drops. Option D is wrong because FIFO queuing offers no differentiation or priority, causing voice packets to be treated the same as all other traffic, resulting in drops and delay during congestion.

5
MCQhard

A network engineer is designing a multicast network for IPTV. Which protocol is used by routers to discover which multicast groups are of interest to directly connected hosts?

A.Rendezvous Point (RP)
B.Internet Group Management Protocol (IGMP)
C.Protocol Independent Multicast (PIM)
D.Multicast Source Discovery Protocol (MSDP)
AnswerB

IGMP is the end-system to router protocol that lets hosts on a directly connected subnet announce their interest in a specific multicast group, which is exactly what an IPTV receiver must do to request a channel. Routers send general queries and process membership reports to maintain an active group list on each interface. IGMPv3 further supports source-specific joins (S,G), enabling explicit control over which IPTV streams are received. Without IGMP, the first-hop router would have no way to know that a host wants multicast traffic.

Why this answer

IGMP is the protocol used between hosts and their directly connected routers to signal membership in multicast groups. When a host wants to receive traffic for a specific IPTV multicast stream, it sends an IGMP membership report, and the router uses this information to build its multicast forwarding state for that subnet. Without IGMP, the router would have no way of knowing which groups are of interest to local hosts.

Exam trap

Cisco often tests the distinction between host-to-router signaling (IGMP) and router-to-router multicast routing (PIM), so candidates mistakenly choose PIM when the question explicitly asks about discovering groups of interest to directly connected hosts.

How to eliminate wrong answers

Option A is wrong because a Rendezvous Point (RP) is a router in a PIM-SM domain that acts as a meeting point for multicast sources and receivers, not a protocol for discovering host group interest. Option C is wrong because PIM is a multicast routing protocol used between routers to build distribution trees, not a protocol for hosts to report group membership to their first-hop router. Option D is wrong because MSDP is used to exchange active source information between different PIM-SM domains (e.g., between RPs), not for host-to-router group discovery.

6
MCQeasy

A network technician is troubleshooting a switch that is experiencing high CPU utilization. The technician runs the command 'show processes cpu sorted' and notices that the process 'ARP Input' is consuming a large percentage of CPU. Which action should the technician take to mitigate this issue?

A.Implement ARP rate limiting or ARP policing on the affected interfaces.
B.Enable Dynamic ARP Inspection (DAI) on all VLANs.
C.Configure a static ARP entry for the affected hosts.
D.Increase the ARP cache timeout to reduce ARP requests.
AnswerA

ARP rate limiting or policing limits the number of ARP packets processed by the switch's CPU, preventing excessive ARP traffic from overwhelming the control plane. This directly reduces the load on the ARP Input process. It is an effective mitigation for high CPU caused by ARP storms or ARP-based attacks. Configuring this on interfaces facing untrusted hosts can protect the switch.

Why this answer

High CPU utilization from the ARP Input process is typically caused by a large number of ARP packets being sent to the switch's CPU. Implementing ARP rate limiting or policing on interfaces can control the rate at which ARP packets are processed, preventing the CPU from being overwhelmed. Other options like static ARP entries or increasing cache timeout do not address the volume of ARP traffic.

Enabling DAI can worsen the CPU load. Therefore, ARP rate limiting is the most effective mitigation.

Exam trap

The trap here is thinking that security features like Dynamic ARP Inspection reduce CPU load, but they actually add processing overhead.

7
MCQmedium

A network administrator is analyzing syslog messages from a Cisco Catalyst switch and notices the message %SW_MATM-4-MACFLAP_NOTIF: Host 0000.1111.2222 in vlan 10 is flapping between port Gi1/0/1 and port Gi1/0/2. What is the most likely cause of this message?

A.A loop exists in VLAN 10 due to a misconfigured spanning tree.
B.A device with MAC address 0000.1111.2222 is connected to both Gi1/0/1 and Gi1/0/2, possibly via a loop or a dual-homed connection.
C.The switch has a software bug causing incorrect MAC address learning.
D.The MAC address 0000.1111.2222 is configured as a static MAC address on two different ports.
AnswerB

This is the most likely cause. The switch is learning the same MAC address on two different ports, which indicates the device is either connected to both ports (e.g., via a loop or a misconfigured NIC teaming) or there is a loop in the network. The switch detects the flapping and generates the syslog message to alert the administrator.

Why this answer

The %SW_MATM-4-MACFLAP_NOTIF message indicates that the switch has detected the same MAC address being learned on two different ports within a short period. This is most commonly caused by a loop or a device connected to multiple ports, leading to inconsistent MAC address table entries. The administrator should investigate the physical connections and spanning tree topology.

Exam trap

The trap here is immediately blaming spanning tree without considering that a dual-homed device or duplicate MAC can also cause the same symptom.

8
MCQmedium

A network administrator is troubleshooting a network performance issue and suspects a duplex mismatch on a switch port. Which command should be used to verify the duplex settings on a Cisco switch interface?

A.show interfaces GigabitEthernet0/1
B.show running-config interface GigabitEthernet0/1
C.show interfaces status
D.show controllers GigabitEthernet0/1
AnswerA

The show interfaces GigabitEthernet0/1 command displays detailed information about the specified interface, including the configured and operational duplex mode. This is the correct command to verify duplex settings, as it shows both the hardware and configured duplex, and can indicate mismatches.

Why this answer

The show interfaces command provides comprehensive details about an interface, including duplex mode, speed, and error statistics. It shows both the configured duplex and the operational duplex, which is essential for detecting a mismatch. When a duplex mismatch occurs, the interface may show late collisions and other errors.

The other commands either lack detail or do not show operational duplex.

Exam trap

The trap here is relying on the running configuration, which only shows configured duplex and not the actual operational duplex, potentially missing a mismatch.

9
MCQmedium

Refer to the exhibit. Which OSPF route type is the default route?

A.External type 2 (E2)
B.Inter-area (IA)
C.NSSA external type 2 (N2)
D.External type 1 (E1)
AnswerA

When OSPF redistributes a default route, the default metric-type is 2 (E2), which means the route's metric remains fixed at the ASBR-advertised value (20) and does not include the internal cost of reaching that ASBR. This is why a default route injected via redistribute or default-information originate is normally seen as an E2 route unless metric-type 1 is explicitly selected.

Why this answer

The exhibit shows a default route (0.0.0.0/0) being redistributed into OSPF from another routing protocol or static route. By default, OSPF redistributes routes as External Type 2 (E2), meaning the metric does not include the internal cost to the ASBR. The route is not an NSSA type because the area is not configured as a not-so-stubby area, and it is not an inter-area route because it originates outside the OSPF domain.

Exam trap

Cisco often tests the default OSPF metric type for redistributed routes (E2) and the fact that a default route can be an external route, not just an inter-area or NSSA type, leading candidates to confuse it with N2 or IA when the area type is not explicitly stated.

How to eliminate wrong answers

Option B is wrong because Inter-area (IA) routes are prefixes learned from another OSPF area, not redistributed external routes; a default route redistributed into OSPF is external, not inter-area. Option C is wrong because NSSA external type 2 (N2) routes only appear in not-so-stubby areas (NSSA) and are translated to type 5 LSAs by the ABR; the exhibit does not indicate an NSSA configuration. Option D is wrong because External type 1 (E1) routes include the internal cost to the ASBR in their metric, but OSPF defaults to E2 for redistributed routes unless explicitly configured with the 'metric-type 1' keyword.

10
MCQeasy

A network engineer is implementing QoS on a WAN link to prioritize voice traffic. Which queuing mechanism provides the lowest latency for real-time traffic?

A.Low Latency Queuing (LLQ)
B.Weighted Random Early Detection (WRED)
C.Class-Based Weighted Fair Queuing (CBWFQ)
D.First-In, First-Out (FIFO)
AnswerA

Low Latency Queuing (LLQ) is correct because it integrates a strict priority queue (PQ) with CBWFQ. The LLQ scheduler always empties the priority class before servicing any other CBWFQ class, which guarantees that real-time packets like voice are dequeued first and experience minimal, jitter-free delay. To prevent the PQ from starving other classes, LLQ applies a policer to priority-class traffic, dropping or shaping excess packets while still meeting the latency objective for admitted real-time flows.

Why this answer

LLQ is correct because it combines strict priority queuing with CBWFQ, ensuring that voice traffic (marked with EF or CS5) is dequeued before any other traffic class. This strict priority mechanism guarantees the lowest possible latency for real-time traffic, as packets in the priority queue are always transmitted first, regardless of congestion on the WAN link.

Exam trap

The trap here is that candidates often confuse CBWFQ with LLQ, assuming that CBWFQ's bandwidth allocation provides low latency, but CBWFQ lacks a strict priority queue and cannot guarantee the sub-10ms jitter required for real-time voice traffic.

How to eliminate wrong answers

Option B is wrong because WRED is a congestion avoidance mechanism that drops packets probabilistically before the queue is full, but it does not provide any latency guarantee or priority treatment for real-time traffic. Option C is wrong because CBWFQ provides bandwidth guarantees for different traffic classes but does not include a strict priority queue; all classes share the link based on weights, which can introduce jitter and delay for voice. Option D is wrong because FIFO is a simple first-come-first-served queuing mechanism with no differentiation or priority, leading to unpredictable latency and packet loss for real-time traffic during congestion.

11
MCQhard

A network engineer is troubleshooting a Cisco SD-WAN deployment where some branches experience intermittent packet loss. The engineer suspects that the issue is related to the control plane connections between vEdge routers and the vSmart controller. Which command should be used on a vEdge router to verify the status of the control connections?

A.show bfd sessions
B.show interface
C.show control connections
D.show omp sessions
AnswerC

The 'show control connections' command displays the state of control plane connections between the vEdge router and vSmart controllers, including uptime, local and remote IPs, and status. This directly helps verify if the control plane is stable, which is crucial for diagnosing intermittent packet loss due to control plane issues.

Why this answer

The 'show control connections' command on a vEdge router provides detailed information about the control plane connections to vSmart controllers, including state, uptime, and any errors. Since the engineer suspects control plane instability causing intermittent packet loss, this command is the most direct way to verify the status and health of those connections.

Exam trap

The trap here is assuming that OMP session status alone is sufficient to diagnose control plane issues, when the underlying control connection state must also be verified.

12
MCQmedium

A network administrator is troubleshooting a BGP routing issue where routes from an eBGP neighbor are not being installed in the routing table. The 'show ip bgp' output shows the routes are received but not valid. What is the most likely cause?

A.The AS-path contains the local AS number.
B.The next-hop IP address is not reachable.
C.BGP synchronization is enabled.
D.The maximum-prefix limit has been exceeded.
AnswerB

Correct. For a BGP route to be considered valid and installed in the routing table, the next-hop IP address must be reachable via an IGP or static route. If the next hop is not reachable, the route will appear in the 'show ip bgp' output but be marked as not valid.

Why this answer

For a BGP route to be considered valid and installed in the routing table, the next-hop IP address must be reachable via an IGP or a static route. If the next hop is not reachable, the route will appear in the 'show ip bgp' output but will be marked as not valid (often with a 'r' for received but not valid). This is the most common cause when routes are received from an eBGP neighbor but not installed.

Exam trap

Cisco often tests the distinction between routes being received in the BGP table versus being installed in the routing table, and the trap here is that candidates confuse synchronization (a deprecated feature) with the next-hop reachability requirement, which is the immediate cause of the 'not valid' status.

How to eliminate wrong answers

Option A is wrong because if the AS-path contains the local AS number, BGP would reject the route due to loop prevention (the route would be marked as invalid or not received at all), but the question states routes are received. Option C is wrong because BGP synchronization is disabled by default in modern IOS versions and, even if enabled, it would affect the route's validity only if the prefix is not present in the IGP, but the next-hop reachability check is more fundamental. Option D is wrong because exceeding the maximum-prefix limit would cause the BGP session to be torn down or the neighbor to be shut down, not simply mark routes as not valid while keeping them in the BGP table.

13
MCQeasy

Refer to the exhibit. An administrator needs to ensure that traffic to 192.168.1.0/24 is forwarded via a different path than traffic to 192.168.2.0/24, even though both routes are learned via OSPF with the same metric. Which action should the administrator take?

A.Configure policy-based routing to match 192.168.1.0/24 and set the next hop to 10.0.0.1.
B.Add a static route for 192.168.1.0/24 with a lower administrative distance than OSPF.
C.Use the 'distance ospf' command to change the OSPF administrative distance for all routes.
D.Adjust the OSPF cost on the interface to 10.0.0.2.
AnswerB

A static route to 192.168.1.0/24 with administrative distance 1 creates a more trustworthy entry than OSPF's default AD of 110, so the router prefers the static route for that exact prefix. This is the precise, surgical fix: it overrides OSPF only for this subnet while leaving all other OSPF-learned routes untouched, and it does not depend on the metrics of the two equal-cost OSPF paths.

Why this answer

Adding a static route for 192.168.1.0/24 with a lower administrative distance (e.g., 1) than OSPF (default 110) forces the router to prefer the static route over the OSPF-learned route, even though the OSPF metric is the same. This allows traffic to 192.168.1.0/24 to use a different next-hop (e.g., 10.0.0.1) while traffic to 192.168.2.0/24 continues using the OSPF-learned path via 10.0.0.2, achieving the desired path differentiation without altering OSPF metrics or using complex PBR.

Exam trap

Cisco often tests the misconception that policy-based routing (PBR) is the only way to force traffic to a different next-hop, when in fact a simple static route with a lower administrative distance can achieve the same result more efficiently and is a common technique for path selection without altering routing protocol metrics.

How to eliminate wrong answers

Option A is wrong because policy-based routing (PBR) matches traffic based on source/destination and sets the next hop, but it does not change the routing table; it overrides the forwarding decision for matched packets, which is unnecessary complexity when a simple static route can achieve the same result with less overhead. Option C is wrong because using the 'distance ospf' command changes the administrative distance for all OSPF routes globally, affecting both 192.168.1.0/24 and 192.168.2.0/24 equally, so it cannot differentiate the path for only one prefix. Option D is wrong because adjusting the OSPF cost on the interface to 10.0.0.2 would change the metric for all routes learned via that interface, potentially altering the path for both prefixes and not specifically isolating 192.168.1.0/24 to a different next-hop.

14
MCQeasy

A network engineer is troubleshooting a Connectivity issue between two data center switches. The engineer suspects a physical layer problem and wants to verify the cable and interface status. Which command should be used to check the status of all interfaces, including the link state and speed?

A.show running-config interface
B.show ip interface brief
C.show mac address-table
D.show interfaces status
AnswerD

The 'show interfaces status' command provides a summary of all interfaces, including their status (connected/notconnect), VLAN, duplex, speed, and type. This is ideal for quickly verifying physical layer connectivity and interface configuration on Cisco switches, as it displays the operational state and speed of each port.

Why this answer

The 'show interfaces status' command is the correct choice because it provides a concise summary of all switch ports, including operational status, speed, duplex, and VLAN assignment. This allows the engineer to quickly identify any ports that are down or operating at incorrect speeds, which are common symptoms of physical layer problems.

Exam trap

The trap here is assuming that 'show ip interface brief' provides the same information as 'show interfaces status', but the former is limited to Layer 3 and lacks speed/duplex details.

15
MCQmedium

A network administrator is using the Cisco DNA Center Assurance application to troubleshoot a user's slow wireless experience. The administrator notices that the client's onboarding time is high and wants to see a detailed timeline of the client's onboarding process, including association, authentication, and DHCP phases. Which Cisco DNA Center Assurance feature provides this information?

A.Path Trace
B.Application Health Dashboard
C.Network Health Dashboard
D.Client 360 view
AnswerD

The Client 360 view in Cisco DNA Center Assurance provides a comprehensive, detailed timeline of a specific client's onboarding and connectivity events. It includes granular data on association, authentication, DHCP, and other phases, allowing the administrator to pinpoint delays. This is exactly the tool needed to analyze the onboarding process step by step.

Why this answer

The Client 360 view is designed to provide a holistic, detailed view of a single client's experience, including a timeline of onboarding phases. It allows administrators to drill down into specific events like association, authentication, and DHCP, which is essential for troubleshooting slow onboarding. Other dashboards and tools offer aggregate or path-based data, not per-client onboarding details.

Exam trap

The trap here is confusing aggregate health dashboards or path tracing tools with the per-client detailed timeline available in Client 360.

16
MCQmedium

A network engineer is troubleshooting intermittent packet loss on a WAN circuit connecting a branch office to headquarters. The engineer suspects the provider is not honoring the committed rate. Which tool should be used to measure one-way delay, jitter, and packet loss between the two sites and generate threshold-based alerts?

A.Cisco DNA Center Assurance with SWIM
B.IP SLA with UDP jitter operation
C.Embedded Packet Capture on the WAN interface
D.NetFlow export to a collector
AnswerB

UDP jitter operations in Cisco IP SLA send packets at a defined interval and measure round-trip latency, one-way delay, jitter, and packet loss, with configurable thresholds that trigger alerts or actions. This directly addresses the need to characterize the provider's handling of the committed rate across the WAN.

Why this answer

The correct tool is the one that actively generates synthetic traffic and reports latency, jitter, and loss with thresholds. IP SLA UDP jitter operations are purpose-built for this and integrate with tracking objects to trigger alerts or failover, which matches the engineer's need to verify the provider's adherence to the committed rate.

Exam trap

The trap here is confusing passive monitoring tools like NetFlow or packet capture with active performance measurement that can quantify one-way delay and jitter.

17
MCQmedium

A network administrator is troubleshooting a network issue using Cisco DNA Center Assurance. The administrator wants to identify which network devices are experiencing the highest number of errors, such as CRC errors and interface flaps. Which Assurance dashboard should the administrator use?

A.Client Health
B.Network Health
C.Application Health
D.Path Trace
AnswerB

The Network Health dashboard in Cisco DNA Center Assurance provides an overview of device and link health, including error counters such as CRC errors and interface flaps. It highlights devices with the most issues, allowing administrators to quickly identify problematic areas. This is the appropriate dashboard for finding devices with high error rates.

Why this answer

The Network Health dashboard in Cisco DNA Center Assurance aggregates health metrics for network devices and links, including error counters like CRC errors and interface flaps. It ranks devices by health and highlights those with the most issues, enabling administrators to quickly pinpoint and address problems. This makes it the right choice for identifying devices with high error rates.

Exam trap

The trap here is assuming that Client Health or Application Health would show device-level error statistics, when they focus on clients and applications respectively.

18
MCQmedium

A network engineer is troubleshooting a Cisco Catalyst 9300 switch that is experiencing intermittent packet drops. The engineer suspects a hardware forwarding issue and needs to verify the status of the switch's forwarding ASIC and its associated resources. Which command should the engineer use to display the current ASIC and forwarding resource utilization?

A.show mac address-table
B.show platform resources
C.show platform hardware fed switch active fwd-asic resource
D.show interfaces counters errors
AnswerC

This command displays detailed forwarding ASIC resource utilization, including TCAM, packet buffer, and other hardware forwarding resources, on the active switch of a Catalyst 9000 series switch. It is the correct choice for verifying ASIC status and resource usage when troubleshooting hardware forwarding issues, as it provides granular per-ASIC data that can identify resource exhaustion or errors.

Why this answer

The correct command is 'show platform hardware fed switch active fwd-asic resource', which provides detailed information about the forwarding ASIC resources on the active switch. This includes TCAM and packet buffer utilization, which are essential for identifying hardware forwarding issues. The other commands focus on general system resources, interface errors, or MAC address tables, none of which directly address ASIC resource utilization.

Exam trap

The trap here is confusing general platform resource commands with those that specifically target forwarding ASIC resources, which are distinct on Catalyst 9000 series switches.

19
MCQeasy

A network administrator is using Cisco DNA Center to monitor the health of network devices. The administrator wants to see a summary of the overall network health and any issues that need attention. Which Cisco DNA Center feature provides this information?

A.Assurance
B.Policy
C.Provision
D.Design
AnswerA

The Assurance feature in Cisco DNA Center provides comprehensive monitoring, health dashboards, and issue detection. It uses telemetry and analytics to show network health, client health, and application health, and it highlights problems that need attention. This is the correct feature for the administrator's requirement.

Why this answer

Cisco DNA Center Assurance is designed to give network administrators a holistic view of network health. It collects data from devices and uses machine learning to detect anomalies and provide insights. The health dashboard summarizes the status of network devices, clients, and applications, and lists issues with recommended actions.

The other features are related to configuration and policy, not monitoring.

Exam trap

The trap here is mixing up the automation and assurance functions of Cisco DNA Center; Design, Policy, and Provision are for configuration, while Assurance is for monitoring.

20
Multi-Selectmedium

Which TWO STP features are used to improve convergence time after a topology change?

Select 2 answers
A.UplinkFast
B.BackboneFast
C.Root Guard
D.BPDU Guard
E.PortFast
AnswersA, B

This is a Cisco proprietary STP enhancement that accelerates convergence after a direct link failure on a switch port that was in a blocking state. When a root port fails, UplinkFast immediately transitions a designated alternate port to forwarding state without waiting for the normal MAX Age + Forward Delay timers (typically 30-50 seconds). It works by caching a multicast frame from the root to verify the alternate path, but the primary effect is fast failover to a redundant uplink, often within 1-5 seconds. This directly improves convergence time.

Why this answer

UplinkFast is correct because it enables a switch to immediately use an alternate root port when its current root port fails, bypassing the usual 30-second listening and learning delay. This is achieved by artificially lowering the bridge priority of the switch to trigger a topology change notification, allowing the backup port to transition directly to forwarding. BackboneFast is correct because it reduces convergence time by detecting indirect link failures in the backbone and allowing a switch to expire its Max Age timer (default 20 seconds) immediately, rather than waiting for the full timer to expire, thus speeding up the transition to a new root port.

Exam trap

Cisco often tests the distinction between features that improve convergence (UplinkFast, BackboneFast) versus features that provide security or edge-port behavior (Root Guard, BPDU Guard, PortFast), leading candidates to mistakenly select PortFast because it also speeds up initial port transition, but it does not react to topology changes.

21
MCQmedium

A network engineer is using Cisco DNA Center Assurance to monitor the health of a wireless network. The engineer notices that a particular access point is reporting a high number of client disconnects. Which feature in DNA Center Assurance would best help identify the root cause of these disconnects?

A.Network Health Dashboard
B.Client 360
C.Device 360
D.Application Health
AnswerB

Client 360 provides detailed information about a specific client's connectivity experience, including disconnect reasons, onboarding issues, and RF statistics. By selecting the affected clients, the engineer can see the exact cause of disconnects, such as authentication failures or roaming problems, making it the best tool for root cause analysis.

Why this answer

Client 360 in Cisco DNA Center Assurance offers detailed client-level analytics, including disconnect reasons and historical data, which is essential for troubleshooting client disconnects. The Network Health Dashboard and Device 360 provide broader views, while Application Health is unrelated to client connectivity issues. Thus, Client 360 is the correct tool for root cause analysis.

Exam trap

The trap here is assuming that Device 360 provides per-client disconnect details, when it actually focuses on the device's overall health.

22
MCQeasy

A network administrator is examining the output of the show interfaces command on a switch and notices a high number of CRC errors on a Gigabit Ethernet port. What is the most likely cause of these errors?

A.Duplex mismatch
B.VLAN mismatch
C.Speed mismatch
D.Cable interference or damage
AnswerD

CRC errors indicate that frames are being corrupted during transmission, which is commonly caused by cable interference, damage, or poor quality cabling. The CRC checksum fails when bits are altered, so the issue is likely at the physical layer. This is the most probable cause.

Why this answer

CRC errors are a physical layer symptom indicating frame corruption. The most common cause is cable interference, damage, or faulty connectors. While duplex mismatch can cause errors, it typically manifests as late collisions and FCS errors, not CRC errors.

Therefore, cable issues are the most likely cause.

Exam trap

The trap here is attributing CRC errors to duplex mismatch, when in fact CRC errors are more directly indicative of physical layer problems such as bad cabling.

23
Multi-Selecthard

A network administrator is using Cisco DNA Center Assurance to troubleshoot a user's poor voice quality. The administrator wants to identify whether the issue is related to the network or the application. Which two Assurance features should be used to gather relevant data? (Choose two.)

Select 2 answers
A.Application Health
B.Network Health Dashboard
C.Client 360
D.Path Trace
E.Sensor Test
AnswersA, C

Application Health provides detailed metrics on application performance, including network latency, jitter, and packet loss for specific applications like voice. It can help determine if the voice quality issue is due to the application itself or the network path. By analyzing application-specific data, the administrator can isolate whether the problem is within the application or the underlying network.

Why this answer

To troubleshoot poor voice quality, the administrator should use Application Health to get application-specific performance metrics such as jitter and packet loss, and Client 360 to examine the specific client's connectivity and RF conditions. Together, these features provide a comprehensive view of both the application and the client's network experience. Other features like the Network Health Dashboard or Sensor Test offer broader or synthetic data, which may not pinpoint the issue for a specific user.

Thus, Application Health and Client 360 are the correct choices.

Exam trap

The trap here is assuming that the Network Health Dashboard provides application-level details, but it only shows device health, not voice quality metrics.

24
MCQhard

A network administrator is using Cisco DNA Center Assurance to monitor a campus network. The administrator notices that a particular client device is experiencing intermittent connectivity drops. The administrator wants to view the historical trend of the client's connectivity and identify the root cause. Which Cisco DNA Center Assurance feature should the administrator use?

A.Client 360
B.Application Health dashboard
C.Path Trace
D.Network Health dashboard
AnswerA

Client 360 in Cisco DNA Center Assurance provides a comprehensive view of a specific client's connectivity, including historical trends, onboarding information, and detailed event timeline. It allows the administrator to drill down into the client's connectivity issues, view past sessions, and identify root causes such as authentication failures or RF problems. This is the correct tool for troubleshooting a single client's intermittent drops.

Why this answer

Client 360 is the Cisco DNA Center Assurance feature designed to provide detailed, historical, and real-time information about a specific client device. It includes connectivity trends, event timelines, and root cause analysis for client issues. The Network Health dashboard, Application Health dashboard, and Path Trace serve different purposes: overall network health, application performance, and flow path analysis, respectively.

Therefore, Client 360 is the correct choice for troubleshooting intermittent connectivity of a single client.

Exam trap

The trap here is confusing Client 360 with Path Trace; Path Trace is for flow analysis, while Client 360 is for client-centric historical troubleshooting.

25
MCQhard

A network engineer is troubleshooting a Cisco SD-WAN deployment where a branch site is experiencing intermittent connectivity to the data center. The engineer suspects that the issue is related to the Bidirectional Forwarding Detection (BFD) configuration on the WAN Edge routers. Which Cisco SD-WAN component is responsible for establishing BFD sessions between WAN Edge routers?

A.WAN Edge routers
B.vSmart
C.vBond
D.vManage
AnswerA

WAN Edge routers are responsible for establishing BFD sessions with each other. BFD is used to detect link failures and measure quality metrics such as latency, jitter, and packet loss. These sessions are established over the data plane, typically over IPsec tunnels or direct links. The WAN Edge routers send BFD packets periodically and use the results to make routing decisions. Therefore, they are the component that establishes and maintains BFD sessions.

Why this answer

In Cisco SD-WAN, BFD sessions are established between WAN Edge routers to monitor the health of the data plane tunnels. These sessions are used to detect failures and measure performance metrics. The WAN Edge routers are responsible for sending and receiving BFD packets.

The other components (vManage, vBond, vSmart) are part of the management, orchestration, and control planes and do not establish BFD sessions. Thus, the WAN Edge routers are the correct answer.

Exam trap

The trap here is assuming that the control plane component vSmart establishes BFD sessions because it manages routing; actually, BFD is a data plane function handled by WAN Edge routers.

26
MCQmedium

A network engineer is configuring a Switched Port Analyzer (SPAN) session on a Cisco Catalyst switch to capture traffic from a specific VLAN. Which configuration command is required to monitor all traffic on VLAN 10 and send it to a destination port?

A.monitor session 1 source interface vlan 10
B.monitor session 1 destination vlan 10
C.monitor session 1 source vlan 10
D.monitor session 1 filter vlan 10
AnswerC

This command configures the SPAN session to use VLAN 10 as the source, capturing all traffic within that VLAN. It is the correct first step to monitor VLAN traffic. The destination is then configured separately with the monitor session destination command.

Why this answer

To monitor all traffic on VLAN 10, the correct command is 'monitor session 1 source vlan 10'. This sets the source VLAN for the SPAN session. The destination port is then configured separately.

Other options either use incorrect syntax or confuse source and destination roles.

Exam trap

The trap here is confusing the source and destination configuration, or using incorrect syntax like 'interface vlan' when 'vlan' alone is required for VLAN-based SPAN.

27
MCQmedium

A network engineer has configured a Cisco IOS IP SLA operation with an ICMP echo probe to monitor reachability of a remote branch router. The engineer wants to automatically remove a static route from the routing table when the probe fails. Which feature should be configured to achieve this?

A.Embedded Event Manager (EEM) applet that triggers on IP SLA failure and removes the route
B.Policy-Based Routing (PBR) with a route map that matches the IP SLA state
C.Floating static route with a higher administrative distance that is always present
D.IP SLA tracking object with a threshold and a static route referencing the track object
AnswerD

Configuring a tracking object (track 1 ip sla 1 reachability) and associating it with the static route (ip route 10.1.1.0 255.255.255.0 192.168.1.2 track 1) allows the router to remove the route when the IP SLA operation fails. This provides automatic failover based on reachability.

Why this answer

The correct solution is to create an IP SLA tracking object and reference it in the static route. When the IP SLA operation fails, the track object goes down, and the static route is removed from the routing table. This provides automatic failover without manual intervention.

Other options either do not remove the route or require additional scripting.

Exam trap

The trap here is assuming that IP SLA alone can modify the routing table; it requires object tracking to influence route installation.

28
Multi-Selecthard

Which THREE are common causes of high CPU utilization on a Cisco Catalyst switch? (Choose three.)

Select 3 answers
A.Broadcast storms
B.Excessive hardware switching of packets
C.Low memory conditions
D.Frequent STP topology changes
E.ACL logging with 'log' keyword
AnswersA, D, E

A broadcast storm floods every port with endlessly circulating frames, forcing the switch CPU to process enormous volumes of broadcast traffic and replicate frames across the broadcast domain. This software-path processing load, rather than normal hardware switching, is what drives control-plane CPU utilisation upward.

Why this answer

Broadcast storms (A) are a classic cause of high CPU utilization on a Catalyst switch because flooded broadcast frames are punted to the CPU for processing and replication to all ports in the VLAN, overwhelming the control plane. Frequent STP topology changes (D) drive high CPU because each TCN forces the switch to recompute the spanning-tree topology, flush MAC address entries, and process BPDUs, consuming significant control-plane cycles. ACL logging with the 'log' keyword (E) is correct because every matching packet is punted to the CPU to generate a syslog message, and a high volume of matches can saturate the CPU.

Excessive hardware switching of packets (B) is not a cause of high CPU since hardware (ASIC) switching is designed to forward packets at wire speed without involving the CPU. Low memory conditions (C) affect memory, not CPU utilization, and are not a common cause of high CPU on a Catalyst switch.

Exam trap

Cisco often tests the distinction between control plane (CPU-processed) and data plane (ASIC-switched) traffic; the trap here is assuming hardware switching tasks consume CPU cycles, when in fact they are offloaded to dedicated hardware.

29
MCQhard

A network administrator is configuring a Cisco IOS XE device to send syslog messages to a remote server. The administrator wants to ensure that only messages with severity level 4 and higher (i.e., more severe) are sent. Which command should be used?

A.logging monitor 4
B.logging console 4
C.logging trap 4
D.logging buffered 4
AnswerC

The 'logging trap 4' command sets the syslog severity level for messages sent to the syslog server to level 4 (warnings). This means only messages with severity 4 and higher (0-4) will be sent, which matches the requirement. It is the correct command to limit syslog messages to the specified severity.

Why this answer

The 'logging trap' command specifically controls the severity level of messages sent to remote syslog servers. Setting it to 4 ensures that only messages with severity 4 and higher (more severe) are sent. The other commands control console, buffer, and monitor logging, which are local destinations and do not affect remote syslog.

Exam trap

The trap here is confusing the different logging destinations and using 'logging console' or 'logging buffered' instead of 'logging trap' for remote syslog.

30
MCQhard

A network administrator is troubleshooting a connectivity issue between two switches connected via a trunk link. The trunk is configured with 802.1Q encapsulation. The administrator suspects that the native VLAN is mismatched. Which command displays the native VLAN configuration on a Cisco Catalyst switch?

A.show interfaces trunk
B.show running-config interface GigabitEthernet0/1
C.show vlan brief
D.show spanning-tree interface GigabitEthernet0/1
AnswerA

The show interfaces trunk command displays the trunk interfaces, their mode, encapsulation, and the native VLAN. It explicitly lists the native VLAN in the output, allowing the administrator to quickly verify if it matches on both ends. This is the most direct command to check the native VLAN configuration on a trunk port.

Why this answer

The show interfaces trunk command is specifically designed to display trunk interface details, including the native VLAN. It provides a concise summary that makes it easy to compare native VLAN settings between switches. While the running configuration also contains the native VLAN setting, show interfaces trunk is the most direct and efficient command for this purpose, especially when checking multiple trunks.

Exam trap

The trap here is thinking show vlan brief shows native VLAN information; it only shows VLAN-to-port assignments for access ports.

31
Drag & Dropmedium

Drag and drop the steps for the DHCP DORA process in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

DHCP uses Discover, Offer, Request, Acknowledge (DORA) for dynamic address assignment.

32
MCQeasy

A network engineer is troubleshooting a connectivity issue and wants to verify the path that packets take from a Cisco IOS XE router to a remote destination. Which command provides a hop-by-hop listing of the path, including latency information for each hop?

A.traceroute
B.show ip interface brief
C.ping
D.show ip route
AnswerA

The traceroute command sends packets with incrementally increasing Time-to-Live (TTL) values and records the ICMP Time Exceeded messages returned by each hop. This provides a list of routers along the path and round-trip time for each hop. It is the standard tool for path discovery and latency measurement on Cisco IOS XE.

Why this answer

Traceroute is designed to discover the path to a destination by leveraging the TTL field in IP packets. Each router that decrements the TTL to zero sends an ICMP Time Exceeded message, allowing the source to build a list of hops. It also records round-trip times, making it ideal for diagnosing latency and path issues.

Exam trap

The trap here is confusing ping with traceroute; ping only tests end-to-end reachability, while traceroute reveals the intermediate hops.

33
MCQmedium

A network engineer is configuring a Cisco IOS router to export NetFlow data to a collector. The engineer wants to ensure that only ingress traffic on GigabitEthernet0/0 is monitored and that the NetFlow cache is optimized for high traffic volumes. Which configuration step is required to enable NetFlow on the interface?

A.ip route-cache flow
B.ip flow-export version 9
C.ip flow ingress
D.ip flow-export destination
AnswerC

The 'ip flow ingress' command enables NetFlow accounting for ingress traffic on the interface. It is the correct command to start capturing flow data for incoming packets. This is a fundamental step in configuring NetFlow on a Cisco IOS router, and it must be applied to the interface that will be monitored.

Why this answer

To enable NetFlow on a specific interface for ingress traffic, the 'ip flow ingress' command must be configured in interface configuration mode. This command activates NetFlow accounting for packets entering the interface, allowing the router to collect flow statistics. The global export commands only define where and how to send the data, but the interface command is what starts the capture.

Exam trap

The trap here is thinking that global NetFlow export commands automatically enable flow capture on interfaces, but interface-level configuration is mandatory.

34
MCQhard

A network administrator is using Cisco DNA Center Assurance to monitor the health of wireless clients. The administrator notices that some clients are experiencing poor performance, but the Assurance dashboard shows them as 'Good'. Which action should the administrator take to troubleshoot the issue?

A.Verify that the wireless controller is registered with Cisco DNA Center.
B.Check the overall network health dashboard for any global alerts.
C.Restart the Cisco DNA Center Assurance service.
D.Review the client's detailed health metrics, including RSSI, SNR, and retry rates.
AnswerD

Cisco DNA Center Assurance provides detailed client health metrics beyond the overall health score. By drilling down into a specific client's details, you can view RSSI, SNR, retry rates, and other RF parameters that may indicate poor performance despite an overall 'Good' status. This granular data helps identify the root cause of the issue.

Why this answer

Cisco DNA Center Assurance client health scores are composite metrics that may not reflect all RF issues. When clients report poor performance but show 'Good' health, the administrator should examine detailed client metrics such as RSSI, SNR, and retry rates to uncover hidden problems. The other options are either too broad or unnecessary.

Exam trap

The trap here is assuming that the overall client health score in Assurance is sufficient to diagnose all performance issues, when in fact detailed metrics are needed.

35
MCQmedium

A network administrator is using Cisco DNA Center Assurance to monitor a campus network. The administrator wants to receive alerts when the onboarding time for wireless clients exceeds a defined threshold. Which Cisco DNA Center Assurance feature should be configured to accomplish this?

A.Assurance Issues
B.Assurance Health Rules
C.Network Health Dashboard
D.Issues and Alerts
AnswerB

Assurance Health Rules (also known as Health Rules) in Cisco DNA Center allow administrators to define custom thresholds and conditions for various health metrics, including onboarding time. By configuring a health rule, the administrator can specify a threshold and have Cisco DNA Center generate an alert when that threshold is exceeded. This is the correct feature for proactive, threshold-based alerting.

Why this answer

Cisco DNA Center Assurance Health Rules enable the creation of custom thresholds for a wide range of metrics, including client onboarding time. When the defined threshold is breached, an alert is triggered. Other dashboards and issue lists are either passive or based on predefined logic and do not support user-defined thresholds for this purpose.

Exam trap

The trap here is confusing the monitoring dashboards and predefined issue detection with the configurable Health Rules that actually allow custom thresholds and alert generation.

36
MCQhard

A network engineer is analyzing network traffic using Cisco IOS Embedded Packet Capture (EPC) on a Cisco ISR router. The engineer wants to capture only TCP packets with a source port of 80 and a destination IP address of 10.1.1.1. Which EPC configuration is required to achieve this?

A.Define a class map that matches tcp source eq 80 and destination host 10.1.1.1, then apply it to the capture point.
B.Define an access list that permits tcp any eq 80 host 10.1.1.1, then reference it in the capture point with 'access-list'.
C.Define a flow record with match ipv4 source port 80 and destination address 10.1.1.1, then apply it to the capture point.
D.Define a capture buffer with 'filter' option specifying tcp port 80 and host 10.1.1.1.
AnswerB

EPC uses an access list to filter captured traffic. The access list 'permit tcp any eq 80 host 10.1.1.1' matches TCP packets with source port 80 and destination IP 10.1.1.1. This access list is then applied to the capture point using the 'access-list' keyword. This is the correct method to filter specific traffic in EPC, as it leverages standard ACL syntax to define match criteria.

Why this answer

EPC uses an access list to filter packets. The access list 'permit tcp any eq 80 host 10.1.1.1' matches the required traffic, and it is applied to the capture point with the 'access-list' keyword. Other options involve features like class maps or flow records that are not used by EPC for filtering.

The capture buffer only defines storage, not filtering.

Exam trap

The trap here is confusing EPC filtering with QoS or NetFlow mechanisms, such as class maps or flow records, which are not applicable to EPC.

37
Multi-Selectmedium

Which TWO statements are true about IP SLA? (Choose two.)

Select 2 answers
A.IP SLA is only supported on ASR routers.
B.IP SLA can be used with tracking objects to trigger route changes.
C.IP SLA can measure jitter between two devices.
D.IP SLA uses actual user traffic for measurements.
E.IP SLA can only measure round-trip time, not one-way delay.
AnswersB, C

IP SLA operations can be tied to Cisco tracking objects using the 'track' command, where the tracked object state changes based on probe reachability or response-time thresholds. When the probe fails consecutive times, the tracking object transitions to 'down', which can trigger a floating static route, policy-based routing, or other route manipulation to redirect traffic. This creates a dynamic failover or convergence mechanism driven by synthetic traffic rather than solely by physical link state.

Why this answer

IP SLA can be combined with tracking objects and the 'track' command to influence routing decisions. When an IP SLA probe fails or falls below a threshold, the tracked object changes state, which can trigger a route change (e.g., via a static route with a higher administrative distance or a PBR policy). This allows the network to react to network performance or reachability issues automatically.

Exam trap

Cisco often tests the misconception that IP SLA uses real user traffic (Option D) or that it is limited to RTT (Option E), when in fact it generates synthetic probes and can measure one-way delay with proper time synchronization.

38
MCQhard

A network engineer is analyzing traffic flows on a Cisco Nexus switch and needs to collect NetFlow data. The engineer wants to export flow records to an external collector at 192.168.100.50 on port 2055. Which configuration step is required to enable NetFlow export?

A.Use the 'netflow export destination 192.168.100.50 2055' command in global configuration mode and enable NetFlow on the management interface.
B.Configure a flow exporter with the destination 192.168.100.50 and transport UDP 2055, then apply a flow monitor to the interface.
C.Enable NetFlow on the interface with the 'ip flow ingress' command and specify the collector with 'ip flow-export destination 192.168.100.50 2055'.
D.Configure a NetFlow collector group with the destination 192.168.100.50 and port 2055, then enable NetFlow on the VLAN interface.
AnswerB

On Cisco Nexus switches, NetFlow is configured using flow exporters, flow records, and flow monitors. The flow exporter defines the collector's IP address and UDP port. The flow monitor references the exporter and record, and is applied to an interface. This enables the export of flow data to the specified collector.

Why this answer

On Cisco Nexus switches, NetFlow export requires defining a flow exporter that specifies the collector's IP address and UDP port. A flow record defines the match and collect fields, and a flow monitor ties them together. The flow monitor is then applied to the interface.

This modular approach is different from traditional IOS routers.

Exam trap

The trap here is applying IOS NetFlow commands like 'ip flow ingress' to a Nexus switch, which uses NX-OS and a different configuration model.

39
MCQhard

A network administrator is troubleshooting high CPU utilization on a Catalyst 9300 switch. The output of 'show processes cpu sorted' shows the 'IP Input' process consuming 45% CPU. Which tool should be used to identify the specific packets causing the issue?

A.Use extended ping from the switch to generate traffic.
B.Configure a SPAN session to capture all traffic to the CPU.
C.Check CDP neighbors to see if any devices are flooding.
D.Enable IP traffic export (NetFlow) on the switch.
AnswerD

NetFlow (IP traffic export) samples and exports flow records containing source/destination IP addresses, Layer 4 ports, protocol numbers, and packet/byte counts to a NetFlow collector. By analyzing these exported records, the administrator can pinpoint exactly which flows are contributing to the saturated 'IP Input' process, such as specific hosts generating large volumes of routed traffic. This local, low-overhead mechanism is specifically designed for flow-level visibility and is the correct tool for this troubleshooting scenario.

Why this answer

The 'IP Input' process handles incoming IP packets that require CPU processing, such as routing protocol updates, management traffic, or packets destined to the switch itself. Enabling IP traffic export (NetFlow) on the switch allows the administrator to analyze traffic flows and identify the specific source/destination IP addresses, ports, and protocols consuming CPU cycles, without overwhelming the CPU further. NetFlow provides granular visibility into the types of packets being processed, making it the correct tool for this scenario.

Exam trap

The trap here is that candidates often confuse SPAN (traffic mirroring) with a diagnostic tool, but SPAN does not provide built-in traffic analysis and can worsen CPU load, whereas NetFlow is designed for flow-level analysis without adding significant overhead.

How to eliminate wrong answers

Option A is wrong because extended ping generates ICMP echo requests from the switch, which would add to the CPU load rather than help diagnose the existing high utilization, and it does not capture or analyze the packets already causing the issue. Option B is wrong because configuring a SPAN session to capture all traffic to the CPU would mirror the traffic to a monitoring port, but it does not provide a built-in analysis mechanism on the switch; it requires an external analyzer and could further increase CPU load due to the mirroring process. Option C is wrong because CDP neighbors only provide information about directly connected Cisco devices and their capabilities; checking CDP cannot identify the specific packets causing high CPU utilization, as CDP is a Layer 2 discovery protocol unrelated to IP packet processing.

40
MCQhard

A network administrator is using Cisco DNA Center Assurance to troubleshoot a client connectivity issue. The client is associated to a wireless controller but cannot reach the default gateway. The administrator notices that the client's onboarding status shows 'DHCP failed'. Which Assurance feature should the administrator use to trace the client's path and identify where DHCP packets are being dropped?

A.Path Trace
B.Application Experience
C.Sensor-driven tests
D.Network Time Travel
AnswerA

Path Trace in Cisco DNA Center Assurance visually traces the path of a client's traffic through the network, showing each hop and any drops. It can simulate DHCP requests and responses, highlighting where packets are discarded. This directly addresses the need to identify where DHCP packets are being dropped for the client, making it the correct tool.

Why this answer

Path Trace in Cisco DNA Center Assurance is designed to trace the exact path of a client's traffic, including DHCP, through the network. It shows each device and interface the traffic traverses and identifies where packets are dropped. This makes it the ideal tool for troubleshooting a client's DHCP failure by pinpointing the drop location.

Other features like Time Travel or Application Experience provide different types of analysis but not hop-by-hop path tracing.

Exam trap

The trap here is confusing Path Trace with Network Time Travel or Sensor-driven tests, which provide historical or simulated data rather than real-time hop-by-hop path analysis for a specific client.

41
Multi-Selectmedium

A network engineer is using Cisco DNA Center Assurance to monitor and troubleshoot a network. The engineer wants to use the Assurance features to proactively detect issues and receive recommendations. Which two statements are true about Cisco DNA Center Assurance capabilities? (Choose two.)

Select 2 answers
A.It can automatically apply configuration changes to remediate issues without human intervention.
B.It integrates with Cisco Identity Services Engine (ISE) to provide client authentication details.
C.It provides real-time monitoring of network devices but does not offer historical data analysis.
D.It uses machine learning to correlate network events and identify root causes.
E.It requires the use of Cisco DNA Center appliances only; virtual deployments are not supported.
AnswersB, D

Cisco DNA Center Assurance integrates with Cisco ISE to pull client authentication and authorization information. This integration allows Assurance to show detailed client onboarding and policy compliance data. By correlating network and identity data, engineers can troubleshoot issues related to authentication and access. This is a valid and important capability.

Why this answer

Cisco DNA Center Assurance uses machine learning to correlate events and identify root causes, enabling proactive issue detection. It also integrates with Cisco ISE to provide client authentication details, enhancing troubleshooting for identity-related issues. These two capabilities are fundamental to Assurance's value proposition.

The other statements are false: Assurance does provide historical data, does not automatically remediate without human intervention, and supports virtual deployments.

Exam trap

The trap here is assuming that Assurance automatically remediates issues; it provides recommendations but requires human action for changes.

42
MCQmedium

A network engineer is deploying Cisco DNA Center Assurance to monitor a campus fabric. The engineer needs to verify that the fabric underlay and overlay health scores are being calculated correctly. Which data source does Cisco DNA Center Assurance primarily use to compute the fabric health score?

A.Syslog messages forwarded to the DNA Center syslog collector
B.SNMP polling of fabric edge nodes every 5 minutes
C.NetFlow records exported from fabric edge switches
D.Streaming telemetry from fabric nodes via the network data platform
AnswerD

Cisco DNA Center Assurance uses streaming telemetry from fabric nodes, collected by the Network Data Platform (NDP), to compute health scores. This provides near-real-time data on underlay and overlay performance, including latency, packet loss, and fabric control plane status. The NDP aggregates and analyzes this data to generate the health score.

Why this answer

Cisco DNA Center Assurance computes fabric health scores using streaming telemetry collected by the Network Data Platform. This telemetry includes underlay and overlay performance metrics, control plane status, and client health. The NDP processes this data to generate real-time health scores, enabling proactive monitoring and troubleshooting.

Other data sources like SNMP, syslog, or NetFlow supplement assurance but are not the primary basis for fabric health scoring.

Exam trap

The trap here is assuming that SNMP polling or NetFlow is the primary data source for DNA Center Assurance health scores, when in fact streaming telemetry via the Network Data Platform is the foundation.

43
Multi-Selecthard

A network engineer is using NetFlow to monitor traffic on a Cisco router. The engineer wants to export NetFlow data to a collector for analysis. Which two commands are required to configure NetFlow export on the router? (Choose two.)

Select 2 answers
A.ip flow-export destination 192.168.1.100 2055
B.ip flow-export version 9
C.ip flow ingress
D.ip flow-cache timeout active 1
E.ip flow-top-talkers
AnswersA, B

The ip flow-export destination command specifies the IP address and port of the NetFlow collector. This is required to send NetFlow data to an external collector. Without this command, the router would not know where to export the flow records, so it is essential for NetFlow export configuration.

Why this answer

To export NetFlow data, the router must be configured with the destination collector address and port, and the export version. The ip flow-export destination command specifies where to send the data, and the ip flow-export version command specifies the format. These two commands are essential for the export process.

Enabling NetFlow on interfaces is also needed, but that is not part of the export configuration commands.

Exam trap

The trap here is thinking that enabling NetFlow on an interface is part of the export configuration; interface commands are separate from export commands.

44
MCQmedium

A network engineer is troubleshooting why a newly added Cisco Catalyst 9300 switch is not appearing in Cisco DNA Center's topology view, even though it is reachable via SSH from the management network. The switch has been configured with the correct SNMP community string. Which protocol must be enabled on the switch for Cisco DNA Center to discover and monitor it?

A.NETCONF
B.Syslog
C.IP SLA
D.SNMP
AnswerD

Cisco DNA Center uses SNMP to discover and monitor network devices. Even if SSH is reachable and the community string is correct, SNMP must be enabled on the switch for DNA Center to poll device information such as interfaces, CPU, and topology data. Without SNMP, the device will not appear in the topology view or be monitored.

Why this answer

Cisco DNA Center relies on SNMP to discover and monitor network devices. Although SSH may be used for CLI-based configuration, SNMP is the protocol that provides the management data for topology and health monitoring. Without SNMP enabled and correctly configured, the switch will not be discovered, regardless of SSH reachability or correct community strings.

Exam trap

The trap here is assuming that SSH access alone is sufficient for Cisco DNA Center to discover and monitor a device, when SNMP is the required protocol for discovery and assurance.

45
MCQhard

A network engineer is troubleshooting why a Cisco Catalyst 9300 switch is not exporting flow data to a NetFlow collector. The engineer verified that the flow record and exporter are correctly configured and that the collector is reachable. Which additional configuration is required on the switch to enable Flexible NetFlow?

A.Apply the flow monitor to an interface in the ingress direction.
B.Add the collector IP address to the flow record using the collect counter bytes command.
C.Enable NetFlow version 9 globally with the ip flow-export version 9 command.
D.Configure a flow sampler to reduce CPU overhead.
AnswerA

Flexible NetFlow requires a flow monitor to be applied to an interface to activate flow accounting. Without applying the monitor, no flows are tracked or exported, even if the record and exporter are correctly defined. The ingress direction is typical for capturing incoming traffic, and this step is mandatory for the feature to function.

Why this answer

Flexible NetFlow requires three main components: a flow record, a flow exporter, and a flow monitor. The monitor ties the record and exporter together and must be applied to an interface to activate flow accounting. Without applying the monitor, no flows are processed or exported, regardless of other configurations.

The other options are either incorrect commands or optional features.

Exam trap

The trap here is assuming that defining the flow record and exporter is sufficient, overlooking the mandatory step of applying the flow monitor to an interface.

46
MCQmedium

A network engineer has configured an IP SLA operation on a Cisco router to monitor the reachability of a remote server. The engineer wants to ensure that the operation sends ICMP echo requests every 30 seconds and that the router tracks the operation's state to influence a static route. Which command is required to associate the IP SLA operation with the static route?

A.ip route 10.1.1.0 255.255.255.0 192.168.1.1 track 1
B.ip route 10.1.1.0 255.255.255.0 192.168.1.1 sla 1
C.ip route 10.1.1.0 255.255.255.0 192.168.1.1 ip sla 1
D.ip route 10.1.1.0 255.255.255.0 192.168.1.1 monitor 1
AnswerA

This command creates a static route to 10.1.1.0/24 via next-hop 192.168.1.1 and associates it with tracked object 1. The track object is linked to the IP SLA operation, so if the operation fails, the route is removed from the routing table. This is the correct way to tie IP SLA state to a static route.

Why this answer

To associate an IP SLA operation with a static route, the engineer must use the 'track' keyword in the static route configuration. The tracked object is created separately and linked to the IP SLA operation. This allows the static route to be withdrawn if the IP SLA operation fails, providing reliable path failover based on reachability.

Exam trap

The trap here is assuming that IP SLA can be directly referenced in a static route statement without using a tracked object; the correct method is to use the 'track' keyword.

47
Multi-Selectmedium

Which TWO statements about Cisco DNA Center's Assurance capabilities are correct?

Select 2 answers
A.It uses streaming telemetry to collect data for real-time analytics.
B.It supports only wired networks and not wireless.
C.It is a fully cloud-based solution with no on-premises components.
D.It only displays network device health scores and does not provide path tracing.
E.It can proactively detect potential issues based on historical trends.
AnswersA, E

Streaming telemetry pushes continuous, model-driven data from network devices to Cisco DNA Center, enabling near real-time analytics rather than polling-based SNMP collection. This satisfies the stem's Assurance requirement for live health monitoring, rapid fault detection and granular visibility into device and client performance across the fabric.

Why this answer

Option A is correct because Cisco DNA Center Assurance relies on streaming telemetry (model-driven telemetry pushed from devices) rather than legacy SNMP polling, enabling near real-time analytics and faster issue detection. Option E is correct because Assurance applies machine learning and baseline analytics to historical data, allowing it to proactively identify trends and predict potential problems before they impact users. Option B is incorrect because Assurance covers both wired and wireless networks, including wireless client onboarding and RF health monitoring.

Option C is incorrect because DNA Center is typically deployed as an on-premises appliance (with cloud-managed options like DNA Center in the cloud, but not exclusively cloud-based). Option D is incorrect because Assurance provides far more than health scores, including path trace, client 360 views, and network topology analysis.

Exam trap

The trap here is that candidates often assume DNA Center is purely cloud-based or only supports wired networks, but Cisco deliberately tests the hybrid deployment model and the unified wired/wireless assurance scope.

48
MCQmedium

A network engineer is troubleshooting intermittent connectivity issues between two switches connected via a trunk link. The engineer notices that the port counters show a high number of CRC errors and runts on one side. Which action should the engineer take first?

A.Check the cable and connectors for damage or loose connections.
B.Increase the MTU size on the interface.
C.Configure the interface with a different duplex setting.
D.Disable Dynamic Trunking Protocol (DTP) on the interface.
AnswerA

CRC errors and runts are statistical counters that typically indicate frame corruption at the data-link layer, almost always rooted in physical-layer problems. Faulty patch cables, damaged RJ-45 connectors, improper termination, or electromagnetic interference near the cable can cause bit-level corruption that the NIC detects as cyclic redundancy check failures. Runts—frames shorter than 64 bytes—frequently accompany this condition when transceivers detect a signal loss or electrical anomaly mid-frame. Therefore, inspecting the physical path from the switchport through the patch panel to the end device is the first and most effective troubleshooting step.

Why this answer

CRC errors and runts on a trunk link typically indicate a Layer 1 physical-layer issue, such as faulty cabling, damaged connectors, or poor termination. The first and most logical step is to inspect and test the physical cable and connectors, as this is the most common root cause and the easiest to verify before making configuration changes.

Exam trap

Cisco often tests the principle that Layer 1 issues must be resolved first before considering Layer 2 or Layer 3 changes, and the trap here is that candidates jump to configuration changes (like duplex or DTP) instead of verifying the physical medium.

How to eliminate wrong answers

Option B is wrong because increasing the MTU size would not resolve CRC errors or runts; it could actually exacerbate the problem by allowing larger frames that are more susceptible to corruption on a faulty physical link. Option C is wrong because duplex mismatch usually causes alignment errors, late collisions, or FCS errors, not specifically CRC errors and runts; moreover, modern switches with auto-negotiation rarely have duplex issues unless manually misconfigured. Option D is wrong because disabling DTP addresses trunk negotiation and VLAN tagging issues, not physical-layer errors like CRC and runts.

49
MCQeasy

A network engineer is configuring a Cisco Catalyst switch to send flow data to a NetFlow collector for traffic analysis. The engineer wants to ensure that only ingress traffic on a specific interface is exported. Which command is required to enable NetFlow on that interface?

A.ip flow egress
B.ip route-cache flow
C.ip flow-export destination
D.ip flow ingress
AnswerD

The 'ip flow ingress' command enables NetFlow for ingress traffic on the interface. It tells the switch to capture flow data for packets entering that interface and export it to the configured collector. This is the correct command to meet the requirement of exporting only ingress traffic from a specific interface.

Why this answer

To enable NetFlow for ingress traffic on a specific interface, the 'ip flow ingress' command must be applied in interface configuration mode. This command activates flow capture for packets entering the interface. The other options either enable egress flow, use an outdated method, or configure the export destination rather than enabling flow capture.

Exam trap

The trap here is mixing up the interface-level command to enable NetFlow with the global command to define the collector destination.

50
MCQmedium

A network administrator needs to validate that the path taken by packets from a branch router to a remote server matches the expected primary path. The administrator wants to collect per-hop latency and packet loss statistics along that path. Which tool should be used?

A.Cisco IOS Embedded Event Manager (EEM) with a Tcl script
B.IP SLA with a path-echo operation
C.IOS IP SLA with an ICMP echo operation
D.Cisco Discovery Protocol (CDP) neighbor details
AnswerB

A path-echo operation in IP SLA sends a series of packets with incrementing TTLs to discover the path and collect per-hop latency and loss statistics. This directly matches the requirement to validate the path and gather hop-by-hop performance data. It provides detailed information about each hop, including packet loss and round-trip time per hop, making it the correct tool.

Why this answer

IP SLA path-echo is designed to trace the path to a destination and collect per-hop latency and packet loss. Unlike simple ICMP echo, it provides hop-by-hop details, which are necessary to validate that traffic follows the expected primary path. The other options either lack hop-by-hop granularity or are not performance-monitoring tools.

Exam trap

The trap here is confusing IP SLA path-echo with basic ICMP echo, which only measures end-to-end reachability and does not provide per-hop statistics.

51
Multi-Selectmedium

A network administrator is implementing NetFlow on a Cisco IOS XE router to monitor traffic. Which two statements about NetFlow are true? (Choose two.)

Select 2 answers
A.NetFlow can export flow data to a collector using UDP.
B.NetFlow requires SNMP to be enabled on the router.
C.NetFlow can be configured to export only ingress or egress traffic on an interface.
D.NetFlow collects packet payload data for deep packet inspection.
E.NetFlow export uses TCP port 2055 by default.
AnswersA, C

NetFlow version 5, 9, and IPFIX can use UDP as the transport protocol for exporting flow records to a collector. UDP is commonly used because it is lightweight and the loss of some flow records is acceptable for monitoring purposes. However, some versions like NetFlow v9 can also use SCTP, but UDP is a valid option. This statement is true.

Why this answer

The two true statements are that NetFlow can export flow data using UDP and that it can be configured to export only ingress or egress traffic on an interface. NetFlow does not require SNMP, does not collect payload data, and does not use TCP port 2055 by default.

Exam trap

The trap here is assuming NetFlow uses TCP for reliable export or that it captures payloads, which it does not.

52
Multi-Selecthard

A network administrator is analyzing the output of 'show ip sla statistics' on a Cisco router. Which two statements correctly describe the information provided by this command? (Choose two.)

Select 2 answers
A.It displays the number of successes and failures for the IP SLA operation.
B.It lists the IP addresses of all intermediate hops along the path.
C.It displays the configured threshold and timeout values for the operation.
D.It provides a detailed packet-by-packet capture of the probe traffic.
E.It shows the round-trip time (RTT) for the most recent operation.
AnswersA, E

The 'show ip sla statistics' command provides a summary of the operation's results, including the number of successes and failures. This helps administrators quickly assess the reliability of the monitored path or service. It is a key piece of information for validating SLA compliance.

Why this answer

The 'show ip sla statistics' command provides operational results such as success/failure counts and the latest RTT. It does not show packet captures, hop-by-hop details, or configuration parameters. Thus, the statements about successes/failures and RTT are correct.

Exam trap

The trap here is assuming that 'show ip sla statistics' displays configuration details or hop-by-hop information, when it only shows aggregated performance results.

53
MCQhard

A network administrator is using Cisco DNA Center Assurance to monitor a campus network. The administrator notices that a specific client device is experiencing poor performance. Which feature in DNA Center Assurance provides a detailed timeline of events, including onboarding, authentication, and application usage for a specific client?

A.Path Trace
B.Client 360
C.Application Health dashboard
D.Network Health dashboard
AnswerB

Client 360 is a feature in Cisco DNA Center Assurance that provides a comprehensive view of a specific client device. It includes a detailed timeline of events such as onboarding, authentication, DHCP, DNS, and application usage. This allows administrators to troubleshoot client-specific issues by correlating events over time. It is the correct tool for this scenario because it gives a holistic view of the client's network experience.

Why this answer

Client 360 in Cisco DNA Center Assurance provides a holistic view of a specific client, including a detailed timeline of onboarding, authentication, DHCP, DNS, and application usage. This is essential for troubleshooting client-specific performance issues because it correlates all relevant events in one place. The other options provide broader infrastructure or application views but lack the per-client event timeline needed here.

Exam trap

The trap here is confusing Client 360 with Path Trace; Path Trace shows the network path but not the client's event timeline.

54
MCQmedium

A network engineer has configured a Cisco IOS IP SLA operation using ICMP echo to monitor reachability to a remote branch router. The engineer wants to correlate the results with syslog messages and SNMP traps to detect when the branch becomes unreachable. Which IP SLA configuration step is required to generate these notifications?

A.Configure the ip sla monitor operation with the tag command to enable logging.
B.Enable IP SLA responder on the remote branch router and configure the operation to use the responder.
C.Configure an IP SLA reaction with a threshold and an action such as logging or SNMP trap.
D.Configure the ip sla schedule command with the life forever option to ensure continuous monitoring.
AnswerC

This is correct because IP SLA reactions define what happens when a monitored threshold is breached. By specifying a reaction condition (e.g., timeout) and an action (e.g., logging, SNMP trap), the device generates syslog messages and SNMP traps when the SLA operation fails or exceeds the threshold. This directly enables correlation with monitoring systems.

Why this answer

To generate syslog messages and SNMP traps based on IP SLA results, you must configure a reaction that specifies a threshold and an action. The reaction monitors the operation's return code or metrics and triggers the defined action when the condition is met. Without a reaction, the operation collects data silently, and no notifications are sent.

Exam trap

The trap here is assuming that scheduling an IP SLA operation or using a responder automatically generates alerts, when in fact reactions are required to produce notifications.

55
MCQhard

A company has a network with multiple VLANs connected via a Layer 3 switch acting as the gateway for all VLANs. The network uses Rapid PVST+ for spanning tree. Recently, the network team added a new access switch to VLAN 100. After the switch was connected, users in VLAN 100 experienced intermittent connectivity, and the Layer 3 switch logs show 'SPANTREE-2-ROOTGUARD_BLOCK' messages for the port connected to the new switch. The new switch is intended to provide additional access ports for VLAN 100. The network team ensured that the new switch's configuration is correct for VLAN 100 access. What is the most likely cause of the issue, and what action should be taken to resolve it?

A.Change the port configuration on the new switch to access mode for VLAN 100.
B.Disable Root Guard on the Layer 3 switch port connected to the new switch.
C.Configure the new switch with a higher bridge priority (e.g., 28672) to prevent it from becoming the root bridge.
D.Remove the new switch from the network because it is causing a BPDU attack.
AnswerC

Configuring the new switch with a higher bridge priority (e.g., 28672) ensures that its BPDUs are inferior to those of the current root bridge, so Root Guard on the Layer 3 switch port will no longer block the port. Since bridge priority is the first criterion in root bridge election, setting a value like 28672 (higher than the current root's priority) makes the new switch a non-root candidate. This resolves the root guard blocking while keeping the new switch operational and preserving the intended spanning-tree topology.

Why this answer

The issue is that the new switch, intended as an access switch, has a lower bridge priority (or default priority of 32768) than the existing root bridge for VLAN 100. When connected, it becomes the new root bridge, causing topology changes and intermittent connectivity. Root Guard on the Layer 3 switch port detects this superior BPDU and blocks the port to protect the root bridge position.

Configuring the new switch with a higher bridge priority (e.g., 28672) ensures it cannot become the root bridge, resolving the Root Guard blocks.

Exam trap

Cisco often tests the misconception that Root Guard is the problem and should be disabled, when in fact the root cause is the new switch's bridge priority being too low, and the correct fix is to adjust the priority on the new switch.

How to eliminate wrong answers

Option A is wrong because the port is already configured as an access port for VLAN 100 (the team verified correct configuration), and changing it again would not address the root bridge election issue. Option B is wrong because disabling Root Guard would allow the new switch to become the root bridge, causing the same intermittent connectivity and potential instability; Root Guard is a protective feature, not the cause. Option D is wrong because the new switch is not causing a BPDU attack; it is simply sending superior BPDUs due to its default bridge priority, which is a normal behavior that Root Guard is designed to protect against.

56
MCQhard

A network administrator is using Cisco DNA Center Assurance to monitor a campus network. The administrator notices that the health score for a particular building has dropped significantly. Which feature of Cisco DNA Center Assurance should the administrator use to identify the root cause of the issue by analyzing network events and device performance metrics over time?

A.AI Network Analytics
B.Assurance Issues
C.Network Health Dashboard
D.Path Trace
AnswerA

AI Network Analytics in Cisco DNA Center uses machine learning to analyze historical network data, including device performance metrics and events, to identify anomalies and root causes. It can correlate data over time, detect trends, and provide insights into why a health score dropped, making it the appropriate tool for this scenario.

Why this answer

AI Network Analytics leverages machine learning to process large volumes of historical data, including device performance metrics and network events, to identify the root cause of health score degradation. Unlike dashboards or path trace tools that provide current state or connectivity views, AI Network Analytics correlates past and present data to uncover underlying issues, making it the correct choice for deep root cause analysis.

Exam trap

The trap here is confusing the high-level health dashboard with deep analytics; the dashboard shows symptoms, while AI Network Analytics provides the machine learning-driven root cause analysis needed to understand why a health score dropped.

57
MCQhard

A network engineer is using Cisco DNA Center Assurance to monitor a network with Cisco SD-Access fabric. The engineer notices that the fabric health score is consistently low, but individual device health scores are high. Which component of the fabric should the engineer investigate first?

A.Underlay network devices
B.Fabric control plane nodes
C.Wireless LAN controllers
D.Fabric edge nodes
AnswerB

In a Cisco SD-Access fabric, the control plane nodes (running LISP) are critical for overlay reachability. If the fabric health score is low while device health scores are high, the issue likely lies in the fabric control plane, such as LISP map-server/ map-resolver problems or inconsistent fabric domain configurations. This can cause overlay connectivity issues without affecting individual device health.

Why this answer

In Cisco SD-Access, the fabric health score reflects the health of the overlay and control plane. If individual device health scores are high but fabric health is low, the issue is likely with fabric control plane nodes (LISP map-server/map-resolver) or overlay tunnels. These components are critical for fabric operation but may not affect individual device health scores.

Investigating control plane nodes first is the logical step to identify misconfigurations or failures in the fabric overlay.

Exam trap

The trap here is focusing on underlay or edge devices because they are more tangible, but the fabric health score specifically highlights control plane and overlay issues that don't degrade individual device health.

58
MCQmedium

A network engineer is deploying Cisco DNA Center Assurance to monitor a campus network. The engineer wants to leverage machine learning to baseline normal behavior and detect anomalies without manually defining thresholds. Which capability should be enabled?

A.Network Time Travel
B.Path Trace
C.AI Network Analytics
D.Sensor-driven tests
AnswerC

AI Network Analytics in Cisco DNA Center uses machine learning to establish a dynamic baseline of normal network behavior and detect anomalies without manual thresholds. It continuously learns from telemetry and surfaces deviations, directly matching the engineer's goal of automated anomaly detection.

Why this answer

AI Network Analytics is the Cisco DNA Center Assurance feature that applies machine learning to create baselines and detect anomalies without manual thresholds. It continuously analyzes telemetry to identify deviations, which aligns with the engineer's goal of automated, threshold-free monitoring.

Exam trap

The trap here is confusing historical or diagnostic tools like Time Travel or Path Trace with the machine-learning baselining engine that actually performs anomaly detection.

59
MCQhard

A network administrator is using Cisco DNA Center Assurance to monitor the health of a wireless network. The administrator notices that a particular client device is experiencing frequent disconnects. Which Assurance feature should be used to view a chronological list of events related to that specific client, including association, authentication, and roaming events?

A.Sensor Test
B.Network Health Dashboard
C.Client 360
D.Application Health
AnswerC

Client 360 provides a comprehensive view of a specific client, including its connectivity history, onboarding events, and performance metrics. It shows a timeline of association, authentication, and roaming events, making it ideal for troubleshooting intermittent disconnects. The administrator can see exactly when the client disconnected and what happened during the process, enabling root cause analysis.

Why this answer

Client 360 in Cisco DNA Center Assurance offers a detailed, per-client view that includes a timeline of events such as association, authentication, and roaming. This feature allows the administrator to pinpoint when and why a client disconnected. Other Assurance features like the Network Health Dashboard or Application Health provide aggregate or application-level views, not the granular client event history required.

Therefore, Client 360 is the correct choice for troubleshooting a specific client's disconnects.

Exam trap

The trap here is confusing the Network Health Dashboard with Client 360; the dashboard shows overall health, but only Client 360 provides the detailed event timeline for a single client.

60
MCQeasy

A network administrator is troubleshooting a Cisco Catalyst switch and suspects a Layer 2 loop. The administrator wants to verify the Spanning Tree Protocol (STP) topology and identify the root bridge. Which command should be used?

A.show mac address-table
B.show spanning-tree
C.show interfaces trunk
D.show cdp neighbors
AnswerB

The 'show spanning-tree' command displays the STP topology, including the root bridge, root port, designated ports, and port states. It is the primary command to verify STP operation and detect loops. On a Cisco Catalyst switch, this command provides detailed information for each VLAN, helping the administrator identify the root bridge and any blocked ports.

Why this answer

To verify STP topology and identify the root bridge, the 'show spanning-tree' command is the correct choice. It provides detailed output for each VLAN, including the root bridge ID, root path cost, and port roles. This allows the administrator to confirm the expected topology and detect any loops or misconfigurations.

Exam trap

The trap here is confusing MAC address table output with STP topology information; seeing the same MAC on multiple ports suggests a loop but does not confirm STP status.

61
MCQeasy

A network administrator is using Cisco DNA Center to monitor a campus network. The administrator wants to receive an alert when a switch's CPU utilization exceeds 80% for more than 5 minutes. Which feature should be configured?

A.Issue definitions with custom severity
B.Assurance health score thresholds
C.Syslog forwarding to an external server
D.Assurance custom threshold rules
AnswerD

Assurance custom threshold rules in Cisco DNA Center allow you to define alerts based on specific metric thresholds, such as CPU utilization exceeding 80% for a sustained period. This directly matches the administrator's need to be notified when the condition persists for more than 5 minutes.

Why this answer

Custom threshold rules in Cisco DNA Center Assurance are designed to trigger alerts when a monitored metric crosses a defined threshold for a specified duration. Configuring a rule for CPU utilization above 80% for 5 minutes directly fulfills the administrator's requirement, unlike health score or issue-based features.

Exam trap

The trap here is assuming health scores or issue definitions can enforce a specific metric threshold, when only custom threshold rules provide that granular control.

62
MCQeasy

Refer to the exhibit. An engineer notices that interface resets have occurred. What is the most likely cause of the interface resets?

A.Cable or hardware issue causing link flapping
B.CRC errors due to noise
C.Collisions on the link
D.Interface is administratively down
AnswerA

Interface resets occur when the interface goes down and comes back up, typically due to physical layer problems like faulty cables, damaged connectors, or hardware issues causing link flapping. This distinguishes resets from other errors.

Why this answer

Interface resets typically indicate that the interface has gone down and come back up, which is most commonly caused by a physical layer issue such as a faulty cable, damaged connector, or hardware problem that leads to link flapping. When the link flaps, the interface counters increment the 'resets' field, reflecting the number of times the interface has been reset due to a loss of carrier or a link state change. This is distinct from errors like CRC or collisions, which do not directly cause the interface to reset.

Exam trap

The trap here is that candidates often confuse interface resets with CRC errors or collisions, but Cisco specifically tests that resets are caused by physical layer issues (link flapping) rather than data-link layer errors.

How to eliminate wrong answers

Option B is wrong because CRC errors are caused by noise or signal integrity issues and are counted separately in the 'input errors' field; they do not directly cause the interface to reset. Option C is wrong because collisions are normal on half-duplex links and are tracked in collision counters, but they do not trigger interface resets. Option D is wrong because an administratively down interface is manually disabled via the 'shutdown' command and would show 'administratively down' in the show interface output, not resets.

63
Multi-Selectmedium

A network administrator is using Cisco DNA Center Assurance to monitor the health of a wireless network. The administrator wants to identify the root cause of poor wireless client experience. Which two actions can be taken within Cisco DNA Center Assurance to troubleshoot this issue? (Choose two.)

Select 2 answers
A.Use the Path Trace tool to visualize the path between a client and a destination.
B.Use the Application Health dashboard to monitor application performance.
C.Use the Network Health dashboard to view overall network device health.
D.Use the Client Health dashboard to view detailed metrics for a specific wireless client.
E.Use the Intelligent Capture feature to analyze wireless packet captures.
AnswersD, E

The Client Health dashboard in Cisco DNA Center Assurance provides detailed metrics such as onboarding time, connectivity, and throughput for individual clients. This allows the administrator to pinpoint issues affecting a specific wireless client, making it a key tool for troubleshooting poor client experience.

Why this answer

To troubleshoot poor wireless client experience, the administrator should use the Client Health dashboard for detailed per-client metrics and Intelligent Capture for deep packet-level analysis. These tools together provide the necessary visibility into wireless-specific issues such as RF conditions and client onboarding problems.

Exam trap

The trap here is confusing general network monitoring dashboards with client-specific troubleshooting tools, overlooking that only Client Health and Intelligent Capture offer the granular wireless client data needed.

64
MCQhard

A network engineer is configuring an IP SLA operation to monitor the reachability of a critical server at 10.1.1.1. The engineer wants to generate a syslog message and trigger a track object if the response time exceeds 100 ms. Which IP SLA operation type should be used?

A.HTTP
B.ICMP Echo
C.UDP Jitter
D.TCP Connect
AnswerB

ICMP Echo is the correct choice because it measures round-trip time and reachability to a destination. The engineer can set a threshold of 100 ms and configure a reaction to trigger when the threshold is exceeded, which can then be tracked. This operation type is specifically designed for this purpose.

Why this answer

ICMP Echo is the most suitable IP SLA operation for monitoring basic reachability and round-trip time to a server. It allows configuration of a threshold and reactions, which can trigger syslog messages and track objects when the threshold is exceeded, directly meeting the engineer's requirements.

Exam trap

The trap here is selecting a more complex operation like UDP Jitter or TCP Connect when the requirement is simply to monitor reachability and response time with a threshold.

65
MCQmedium

A network engineer is troubleshooting a connectivity problem between two hosts on the same VLAN. The engineer suspects a duplex mismatch on the switch port. Which command should be used to verify the duplex settings on a Cisco Catalyst switch interface?

A.show controllers ethernet-controller
B.show interfaces gigabitEthernet 0/1
C.show interfaces counters errors
D.show interfaces status
AnswerB

The show interfaces gigabitEthernet 0/1 command provides detailed information about the interface, including duplex, speed, and error counters. This allows the engineer to confirm the operational duplex mode and detect a mismatch. It is the most direct way to verify duplex settings on a specific interface.

Why this answer

To verify duplex settings on a Cisco Catalyst switch interface, the show interfaces command with the specific interface is the most appropriate because it displays the operational duplex, speed, and error counters. This allows the engineer to quickly identify a duplex mismatch, which often results in late collisions and performance degradation.

Exam trap

The trap here is assuming that summary commands like show interfaces status provide enough detail to diagnose duplex mismatches, when they actually lack the granular error counters needed.

66
Multi-Selectmedium

A network engineer is analyzing the output of the show processes cpu sorted command on a Cisco Catalyst 9300 switch and notices that the CPU utilization is consistently high. Which two methods can help identify the cause of high CPU utilization? (Choose two.)

Select 2 answers
A.Use the show interfaces counters errors command to check for interface errors.
B.Use the show processes cpu history command to view CPU utilization over time.
C.Use the show tech-support command to collect all diagnostic information.
D.Use the show processes cpu sorted command to identify the top CPU-consuming processes.
E.Use the show platform resources command to view hardware resource utilization.
AnswersB, D

The show processes cpu history command displays a graphical representation of CPU utilization over the past 60 seconds, 60 minutes, and 72 hours. This helps correlate high CPU with specific events or times, such as a spike during a network storm or a scheduled task. It provides historical context that can identify patterns and narrow down the cause of sustained high CPU.

Why this answer

The show processes cpu history command provides historical CPU utilization graphs, helping correlate spikes with events. The show processes cpu sorted command lists processes by CPU usage, directly identifying the top consumers. Together, they allow an engineer to pinpoint which process is causing high CPU and when it occurs.

The other commands provide additional context but are not the primary methods for identifying the cause of high CPU.

Exam trap

The trap here is thinking show tech-support directly identifies the cause; it collects data but does not analyze it for you.

67
Multi-Selecthard

A network engineer is using Cisco DNA Center Assurance to troubleshoot a wireless client that frequently disconnects. The engineer wants to identify the root cause by examining relevant assurance data. Which two types of information are available in the Client 360 view to help diagnose the issue? (Choose two.)

Select 2 answers
A.Wireless controller CPU utilization
B.RF statistics for the client
C.Application response time
D.Client onboarding history
E.Switch interface error counters
AnswersB, D

RF statistics for the client, such as RSSI, SNR, and channel utilization, are available in Client 360. These metrics help determine if the disconnections are due to poor signal quality, interference, or coverage gaps. By analyzing RF trends over time, the engineer can correlate disconnects with RF conditions.

Why this answer

Client 360 in Cisco DNA Center Assurance provides a comprehensive view of a specific client's connectivity, including onboarding history and RF statistics. Onboarding history reveals the steps and failures during connection attempts, while RF statistics show signal quality and interference. Together, they enable the engineer to diagnose why the client disconnects, such as authentication failures or poor coverage.

Exam trap

The trap here is assuming that Client 360 includes device-level metrics like controller CPU or switch interface counters, when it actually provides client-centric data such as onboarding events and RF statistics.

68
Multi-Selecthard

A network engineer is deploying Cisco DNA Center Assurance and wants to ensure that the system can accurately monitor and troubleshoot network issues. Which two statements about Cisco DNA Center Assurance are true? (Choose two.)

Select 2 answers
A.Assurance requires SNMP polling for all device monitoring.
B.Assurance uses streaming telemetry to collect data from network devices.
C.Assurance provides a graphical view of the network topology and device health.
D.Assurance requires manual configuration of each device to enable monitoring.
E.Assurance can only monitor wired devices, not wireless.
AnswersB, C

Cisco DNA Center Assurance leverages streaming telemetry to gather near real-time data from network devices. This allows for continuous monitoring and rapid detection of issues. Streaming telemetry is more efficient than polling and provides granular data for analysis. This is a key feature of Assurance.

Why this answer

Cisco DNA Center Assurance uses streaming telemetry for real-time data collection and provides a graphical topology view of network health. These features enable proactive monitoring and rapid troubleshooting. The other statements are false: Assurance does not require SNMP polling for all devices, it supports both wired and wireless, and it does not require manual per-device configuration for monitoring.

Exam trap

The trap here is assuming that Assurance relies solely on SNMP polling or requires manual configuration, when it actually uses streaming telemetry and automated onboarding.

69
Multi-Selectmedium

A network engineer is deploying IP SLA to monitor network performance. The engineer needs to configure an IP SLA operation that measures jitter and packet loss between two Cisco routers. Which two statements are true about configuring IP SLA for this purpose? (Choose two.)

Select 2 answers
A.The ip sla responder command must be configured on the destination router.
B.The operation type udp-jitter is used to measure jitter and packet loss.
C.The ip sla schedule command is optional and only needed for historical data collection.
D.The operation can be configured using the icmp-echo operation type to measure jitter.
E.The ip sla responder command must be configured on the source router.
AnswersA, B

For UDP jitter operations, the destination router must have the ip sla responder command enabled to provide accurate measurements. The responder allows the destination to timestamp incoming packets and return them, enabling the source to calculate jitter and packet loss. Without it, the operation may still function in some cases, but the responder is required for precise jitter and loss statistics, making this statement correct.

Why this answer

To measure jitter and packet loss with IP SLA, the engineer should use the udp-jitter operation type and configure the ip sla responder on the destination router. The responder ensures accurate timestamping and response, while scheduling is mandatory to start the operation. The icmp-echo operation does not measure jitter, and the responder belongs on the destination, not the source.

Exam trap

The trap here is assuming that any IP SLA operation can measure jitter or that the responder is configured on the source router, when in fact udp-jitter and a destination responder are required.

70
MCQhard

A network administrator is using Cisco DNA Center Assurance to monitor a campus network. The administrator notices that a particular client device is experiencing poor performance. The administrator wants to see detailed information about the client's connectivity, including the path taken through the network and any issues encountered. Which Cisco DNA Center Assurance feature should the administrator use?

A.Application Health dashboard
B.Path Trace
C.Network Health dashboard
D.Client 360
AnswerD

Client 360 provides a comprehensive view of a specific client's experience, including onboarding, connectivity, and application performance. It shows the path taken through the network, including switches and access points, and highlights issues like onboarding failures or poor signal quality. This is the ideal tool for troubleshooting individual client performance.

Why this answer

Client 360 in Cisco DNA Center Assurance offers a detailed, client-centric view that includes onboarding, connectivity, and application experience. It displays the network path taken by the client and any issues encountered, such as authentication failures or roaming problems. This makes it the appropriate feature for troubleshooting a specific client's performance.

Exam trap

The trap here is confusing Path Trace with Client 360; Path Trace is for on-demand path simulation, while Client 360 provides ongoing client monitoring.

71
MCQmedium

A network engineer is troubleshooting a routing loop between two OSPF areas. To verify the path that packets are taking, the engineer decides to use the Cisco IOS Embedded Event Manager (EEM) to generate a syslog message when the OSPF neighbor state changes. Which EEM applet configuration is required to trigger on the OSPF neighbor state change?

A.event tag ospf-neighbor timer watchdog time 60
B.event tag ospf-neighbor cli pattern "show ip ospf neighbor"
C.event tag ospf-neighbor syslog pattern "%OSPF-5-ADJCHG"
D.event tag ospf-neighbor snmp oid 1.3.6.1.2.1.14.10.1.6
AnswerC

This applet uses a syslog event detector that matches the OSPF adjacency change syslog message. When the router logs a %OSPF-5-ADJCHG message, the EEM applet triggers. This is a common method to monitor OSPF neighbor state changes without polling. The pattern must match the exact syslog text, and the tag is used to associate actions.

Why this answer

The correct configuration uses a syslog event detector to match the OSPF adjacency change message. When OSPF neighbor state changes, the router generates a %OSPF-5-ADJCHG syslog message. An EEM applet with a syslog event detector and the appropriate pattern will trigger actions based on that message.

This provides immediate, event-driven monitoring without polling. The other options either use inappropriate event detectors or incorrect syntax for this purpose.

Exam trap

The trap here is confusing the CLI event detector with the syslog event detector; the CLI detector triggers on command input, not on syslog messages.

72
MCQeasy

A network engineer is analyzing traffic patterns using Cisco IOS IP Service Level Agreements (IP SLA). The engineer wants to measure the round-trip time (RTT) for HTTP traffic to a web server at 10.1.1.1. Which IP SLA operation type should be configured?

A.icmp-echo
B.http
C.tcp-connect
D.udp-jitter
AnswerB

The HTTP operation type in IP SLA sends HTTP requests to a specified URL and measures the response time. It can be configured to use GET or RAW operations and can measure the time to establish a TCP connection, send the request, and receive the response. This directly measures HTTP traffic RTT, which is what the engineer wants. It is the correct choice for measuring HTTP performance.

Why this answer

The HTTP IP SLA operation is designed to measure the response time of HTTP requests. It sends a request to a web server and measures the time to receive the response. This provides the RTT for HTTP traffic.

Other operation types like ICMP echo, TCP connect, or UDP jitter do not measure application-layer HTTP performance. Therefore, the HTTP operation is the correct choice.

Exam trap

The trap here is confusing TCP connect with HTTP; TCP connect only measures the handshake, not the full HTTP request/response cycle.

73
Multi-Selectmedium

A network engineer is analyzing the output of 'show ip sla statistics' on a Cisco IOS router. The engineer notices that the SLA operation is returning 'Timeout' for several probes. Which two statements are true about the potential causes of this issue? (Choose two.)

Select 2 answers
A.The timeout value may be set too low for the network latency.
B.The target device may be unreachable due to a routing issue.
C.The source interface may not have a valid IP address configured.
D.The SLA operation may be using an unsupported protocol type.
E.The SLA operation may be configured with an incorrect frequency.
AnswersA, B

If the timeout value is set lower than the actual round-trip time, the probe will time out even if the response eventually arrives. This is common in high-latency networks. Adjusting the timeout to accommodate network conditions can resolve the timeouts.

Why this answer

Timeouts in IP SLA statistics indicate that the probe packets are not receiving a response within the configured timeout period. This can be caused by the target being unreachable due to routing or ACL issues, or by the timeout value being too low relative to network latency. Both conditions prevent the successful completion of the probe, leading to timeouts.

Exam trap

The trap here is confusing timeout with other failures like 'unreachable' or 'error', and assuming that configuration errors like frequency or unsupported protocol cause timeouts, when they typically cause different symptoms.

74
MCQhard

A network administrator is using Cisco DNA Center Assurance to monitor the health of a wireless network. The administrator notices that a particular client device shows a poor health score. Which Cisco DNA Center Assurance feature should the administrator use to determine the root cause of the poor health score?

A.Path Trace
B.Network Health dashboard
C.Application Health dashboard
D.Client 360
AnswerD

Client 360 provides a detailed view of a specific client's connectivity, including onboarding, authentication, association, and performance metrics. It shows the client's health score, issues, and the ability to drill down into specific events and path trace. This is the correct tool to determine why a client has a poor health score, as it aggregates data from multiple sources and provides root cause analysis.

Why this answer

Client 360 in Cisco DNA Center Assurance provides a comprehensive view of a specific client's network experience, including onboarding, authentication, and performance. It aggregates data and presents a health score with detailed metrics and events. To determine the root cause of a poor health score, the administrator should use Client 360, which offers drill-down capabilities and suggested actions.

Other dashboards provide broader or different scopes of information.

Exam trap

The trap here is assuming that the Network Health dashboard provides client-level root cause analysis, when it actually focuses on device and network health.

75
MCQeasy

A network administrator is troubleshooting a performance issue in a large enterprise campus network. The network consists of Cisco Catalyst 9300 switches acting as access switches and Cisco Catalyst 9500 switches as distribution. Users on VLAN 10 report intermittent slow file transfers to a server on VLAN 20. The administrator has verified that there are no errors on the links, CPU utilization is normal, and STP topology is stable. The administrator suspects a possible QoS issue. Upon checking the QoS configuration on the access switch, the administrator finds that the default QoS configuration is in place, which trusts the CoS value at the port level. The connected devices are IP phones and PCs; the IP phones mark voice traffic with CoS 5. The server on VLAN 20 is connected to a distribution switch. Which action should the administrator take to most likely resolve the issue?

A.Apply a policy map that polices voice traffic to 128 kbps to free bandwidth for data.
B.Disable QoS entirely on all switches to eliminate any potential QoS-related drops.
C.Configure auto QoS for VoIP on the access ports to ensure proper classification and queuing.
D.Configure trust DSCP on the access ports to prioritize all traffic based on DSCP values.
AnswerC

Auto QoS for VoIP on access ports dynamically configures the necessary trust boundaries, classification, and egress queuing to properly handle voice traffic. It typically sets the ingress port to trust CoS for the connected IP phone, marks voice traffic appropriately, and places it in the priority queue to minimize latency and drop risk. This is the correct remediation because it matches the network behavior to the requirements of voice—ensuring priority without manual, error-prone configuration.

Why this answer

Auto QoS for VoIP automatically configures the necessary class maps, policy maps, and trust settings to properly classify and queue voice traffic (CoS 5) while ensuring data traffic is not starved. The default QoS configuration trusts CoS at the port level, but without proper queuing and scheduling, voice and data may compete for buffers, causing intermittent slow file transfers. Auto QoS sets up strict priority queuing for voice and allocates bandwidth for data, resolving the performance issue without manual misconfiguration.

Exam trap

Cisco often tests the misconception that simply trusting CoS or DSCP values is sufficient to prioritize traffic, when in fact trust alone does not configure the egress queuing and scheduling policies needed to prevent congestion and ensure bandwidth allocation.

How to eliminate wrong answers

Option A is wrong because policing voice traffic to 128 kbps would drop voice packets that exceed this rate, degrading voice quality, and does not address the root cause of data traffic being starved due to improper queuing. Option B is wrong because disabling QoS entirely removes all prioritization, which can cause both voice and data to be treated equally, potentially worsening the performance issue for file transfers during congestion. Option D is wrong because configuring trust DSCP on access ports would trust DSCP markings from PCs and IP phones, but the default QoS configuration already trusts CoS; changing to DSCP trust may not align with the existing CoS markings from IP phones and could lead to misclassification, while still lacking proper queuing policies.

Page 1 of 2 · 87 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Network Assurance questions.