mediumMultiple Choice
CCNP Practice Question: Runs the following command on switch SW5: SW5#…
A network engineer runs the following command on switch SW5:
SW5# show cts sxp connections
SXP Connections:
Peer IP Source IP Conn Status Duration
10.1.1.1 10.1.1.2 Up 2d3h 10.1.1.3 10.1.1.2 Down 0d0h
Based on this output, what can be concluded?
⚠ Common exam trap
Cisco often tests the ability to read the output of 'show cts sxp connections' accurately, where the trap is that candidates may assume all connections are up or misinterpret the 'Down' status as 'Up' due to not carefully checking the 'Conn Status' column.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SXP connection to 10.1.1.1 has been up for 2 days and 3 hours.
The command 'show cts sxp connections' displays the status of SXP (Security Group Tag Exchange Protocol) connections. The output shows that the connection to peer 10.1.1.1 has a status of 'Up' and a duration of '2d3h', meaning it has been established for 2 days and 3 hours. Option B correctly identifies this fact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Both SXP connections are operational.
Why it's wrong here
The claim that both SXP connections are operational is false because the output from the SXP connection table explicitly shows the peer at 10.1.1.3 with a status of 'Down'. Only the peer at 10.1.1.1 is shown as 'Up', so the statement that both are operational directly contradicts the displayed state. In SXP, a 'Down' status indicates that the TCP connection (typically on port 64999) is not established or has failed, so only one connection is active.
- ✓
The SXP connection to 10.1.1.1 has been up for 2 days and 3 hours.
Why this is correct
The SXP connection to 10.1.1.1 is correctly identified as being up for 2 days and 3 hours because the output shows the status 'Up' with a duration of '2d3h' for that peer. This specifically indicates the SXP TCP session has been established and stable for that period without interruption. The presence of a duration counter confirms the connection is actively maintained, making this the only true statement among the options.
- ✗
The switch is using 802.1X for authentication.
Why it's wrong here
The switch using 802.1X for authentication cannot be concluded from this output because the command shown is 'show sxp connections', which only displays SXP peer status and related counters. 802.1X status would be verified with commands like 'show dot1x all' or 'show authentication sessions', which are not present in the output. The output also contains no reference to EAP, port-control, or RADIUS, so assuming 802.1X is unsupported by the given information.
- ✗
The SXP connection to 10.1.1.3 is up.
Why it's wrong here
The SXP connection to 10.1.1.3 is not up because the output explicitly lists the peer 10.1.1.3 with the status 'Down'. A down state in SXP means the TCP connection to that peer is not currently active, possibly due to a timeout, network issue, or configuration mismatch. Therefore, the statement that this connection is up is false, and only the peer at 10.1.1.1 is operationally up.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.