350-601 Network Practice Question
An engineer is troubleshooting a vPC consistency check failure. Which parameter must be identical on both vPC peer switches to avoid a consistency check violation for a vPC member port?
⚠ Common exam trap
Many exam-takers confuse vPC consistency check parameters with STP or MTU settings, but Cisco specifically tests that the allowed VLAN list on the port channel must match, while other parameters like STP guard or MTU are not part of the Type-1 consistency check.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Allowed VLAN list on the port channel
In a vPC environment, the allowed VLAN list on the port channel must be identical on both peer switches for a vPC member port. If the lists differ, the vPC consistency check fails, causing the port to be suspended or placed in a consistency-check failure state. This ensures that both peers forward the same set of VLANs across the vPC, preventing asymmetric forwarding and potential loops.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Allowed VLAN list on the port channel
Why this is correct
Mismatched allowed VLANs cause consistency check failure and may suspend the vPC.
- ✗
STP root guard setting
Why it's wrong here
Root guard is not a consistency check parameter.
- ✗
MTU size
Why it's wrong here
MTU is not part of vPC consistency checks.
- ✗
Spanning-tree port type
Why it's wrong here
Port type can differ; consistency checks focus on VLAN and interface parameters.
Visual reference
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-601 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-601 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-601 exam.