mediumMultiple Choice
CCNP Practice Question: Configures IP SLA 20 to monitor the response time…
A network engineer configures IP SLA 20 to monitor the response time of a DNS server at 10.1.1.1 using DNS query for 'example.com'. The operation is used to influence routing decisions. The engineer notices that the IP SLA operation shows 'State: Active' and 'Latest RTT: 50 ms', but the DNS server is actually down and not responding to any queries. What is the most likely reason?
⚠ Common exam trap
Cisco often tests the misconception that IP SLA DNS probes always generate live queries to the server, when in fact the router's DNS resolver may serve cached responses, leading to false-positive results.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IP SLA DNS probe is using a cached DNS response from the router's DNS resolver, so it does not actually query the server.
IP SLA DNS probes rely on the router's local DNS resolver. If the resolver has a cached response for 'example.com', the probe will return the cached RTT without actually querying the DNS server. This explains why the operation shows 'Active' and a 50 ms RTT even though the DNS server is down.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The IP SLA DNS probe is using a cached DNS response from the router's DNS resolver, so it does not actually query the server.
Why this is correct
The IP SLA DNS probe is designed to send a DNS query to a specified server and measure the response time. If the router's DNS resolver has caching enabled and has previously resolved the queried name, it may answer from its local cache without ever transmitting the query to the configured DNS server. This results in a successful probe with a low RTT (e.g., 50 ms) even when the actual DNS server is unreachable, because the reply comes from the router itself. To avoid this, the DNS name used in the probe must be unique or DNS caching must be disabled to force an end-to-end query.
- ✗
The IP SLA DNS probe must be configured with a 'timeout' value lower than 50 ms to detect the failure.
Why it's wrong here
The statement suggests setting a timeout lower than 50 ms to detect failure, but that would only cause false failures because the RTT is exactly 50 ms for a valid cached response. The real problem is not that the probe is too slow; it is that the probe is answered from the router's cache, so it never touches the network. Lowering the timeout below the observed RTT would make the probe time out even when the server is healthy, which is not a legitimate detection of the server's actual reachability. The timeout parameter determines how long the router waits for a reply; it cannot force the probe to bypass the local DNS cache.
- ✗
The DNS server is responding to the probe but not to other queries because the probe uses a different port.
Why it's wrong here
This claim is incorrect because IP SLA DNS probes and standard DNS queries both use the same default destination port, UDP 53. The server does not treat traffic from an IP SLA probe differently based on source port, and the probe uses the identical DNS packet format as a normal query. If the server were reachable and responding to the probe, it would also respond to any other DNS query sent to the same destination IP and port. The reason the probe succeeds while other queries fail is that the probe's response is generated locally by the router's cache, not by the server.
- ✗
The IP SLA operation is configured with a 'frequency' that is too low, causing the probe to be sent before the server times out.
Why it's wrong here
The frequency parameter in IP SLA controls the interval between successive probes, not the behavior of any individual probe. A low frequency (e.g., a long interval) means probes are sent less often, but each probe still goes out and waits for a response according to its configured timeout. The server does not need to be "ready" at a certain time; it either answers or it does not. Since the probe in question is receiving a cached response, the frequency setting is irrelevant—changing it will not cause the probe to actually reach the DNS server or expose the server's unavailability.
Visual reference
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.