Courseiva

CCNA Network Fundamentals Questions

50 of 125 questions · Page 2/2 · Network Fundamentals · Answers revealed

76
Multi-Selecthard

An engineer is troubleshooting a network issue where a client cannot reach a server. The client uses HTTPS. Which TWO factors are essential for a successful TLS handshake?

Select 2 answers
A.The server must have a valid digital certificate
B.The handshake uses UDP for faster negotiation
C.The client must present a certificate to the server
D.The client must have a public key to encrypt the session
E.The server's private key is used to decrypt the pre-master secret
AnswersA, E

The certificate proves the server's identity.

Why this answer

The server must present a valid digital certificate during the TLS handshake to prove its identity to the client. This certificate contains the server's public key and is signed by a trusted Certificate Authority (CA), enabling the client to verify the server's authenticity before proceeding with encrypted communication.

Exam trap

Cisco often tests the misconception that the client must always present a certificate or that the handshake uses UDP, when in reality client certificates are optional and TLS relies on TCP.

77
Multi-Selectmedium

Which TWO of the following are benefits of using UDP over TCP for real-time applications?

Select 2 answers
A.Lower latency due to no connection setup
B.Guaranteed delivery of all packets
C.Reduced overhead from smaller header size
D.In-order packet delivery
E.Congestion control to avoid network overload
AnswersA, C

UDP is connectionless, so it skips the TCP three-way handshake before transmitting. Real-time applications such as voice and video avoid that setup delay, reducing latency and satisfying the stem's requirement for timely delivery over reliability.

Why this answer

Option A is correct because UDP is connectionless: it performs no three-way handshake (SYN/SYN-ACK/ACK) before sending data, so there is no round-trip setup delay, which directly reduces latency for real-time traffic such as VoIP or live video. Option C is correct because the UDP header is only 8 bytes (source port, destination port, length, checksum) versus TCP's minimum 20-byte header, so UDP imposes less per-packet overhead and leaves more bandwidth for payload. Option B is incorrect because guaranteed delivery is a TCP feature provided by sequence numbers and acknowledgments with retransmission; UDP offers best-effort delivery with no retransmission.

Option D is incorrect because in-order delivery is also a TCP function achieved via sequence numbers and reassembly, whereas UDP datagrams may arrive out of order. Option E is incorrect because congestion control (slow start, congestion avoidance, etc.) is implemented by TCP, while UDP has no built-in congestion control and relies on the application or protocols like RTP/QUIC to manage it.

Exam trap

Cisco often tests the misconception that 'reliable' means 'better' for all applications, but candidates must recognize that real-time apps prioritize low latency over reliability, making UDP's lack of guarantees a feature, not a flaw.

78
MCQhard

A network engineer is troubleshooting an issue where a client cannot reach a web server at 203.0.113.10. The engineer runs a traceroute from the client and sees that the path stops at a router with IP 198.51.100.1, which is the last hop before the destination. The engineer suspects that the router is dropping packets due to an ACL. Which command should the engineer use on the router to verify if an ACL is blocking traffic to the web server?

A.show ip interface
B.show ip route 203.0.113.10
C.show ip access-lists
D.debug ip packet
AnswerC

The show ip access-lists command displays the configured ACLs and their entries, including match counters if the ACL has been applied and is counting matches. By examining the ACL entries, the engineer can see if there is a deny statement that would block traffic from the client to the web server. The match counters can also indicate if packets are hitting a particular entry, which helps confirm if the ACL is the cause of the problem.

Why this answer

To verify if an ACL is blocking traffic, the engineer should examine the ACL configuration and match counters. The show ip access-lists command provides this information, allowing the engineer to see if a deny entry is matching the traffic in question. Other commands like show ip route or show ip interface do not show ACL contents, and debug ip packet is too disruptive for routine troubleshooting.

Exam trap

The trap here is assuming that show ip interface will reveal ACL contents, when it only shows that an ACL is applied, not its rules or match statistics.

79
MCQhard

A network engineer is tasked with segmenting a large broadcast domain into smaller ones using VLANs. In the OSI model, at which layer does a VLAN operate?

A.Layer 2 - Data Link
B.Layer 4 - Transport
C.Layer 1 - Physical
D.Layer 3 - Network
AnswerA

VLAN tags are carried in the Ethernet frame header, so segmentation of a broadcast domain occurs at Layer 2, the Data Link layer. Layer 3 handles logical IP addressing and routing between VLANs, not the broadcast domain boundary itself.

Why this answer

VLANs operate at Layer 2 (Data Link) of the OSI model because they segment broadcast domains by tagging Ethernet frames with VLAN IDs (802.1Q). This allows logical separation of networks without regard to physical location, and switches use MAC addresses to forward frames within VLANs. Layer 2 is where framing, MAC addressing, and VLAN tagging occur.

Exam trap

200-901 often tests the OSI layer of VLANs, and candidates might incorrectly choose Layer 3 because VLANs can be routed, but the segmentation itself is Layer 2.

How to eliminate wrong answers

Option B is wrong because Layer 4 (Transport) handles end-to-end communication and protocols like TCP/UDP, not VLAN segmentation. Option C is wrong because Layer 1 (Physical) deals with raw bit transmission and physical media, not logical segmentation. Option D is wrong because Layer 3 (Network) handles IP routing between networks; VLANs can be routed at Layer 3, but VLANs themselves are a Layer 2 concept.

80
MCQmedium

An application uses UDP. Which characteristic is true about this application's communication?

A.It guarantees packet delivery
B.It retransmits lost packets
C.It is connectionless
D.It performs a three-way handshake
AnswerC

UDP operates without establishing a session before transmission, so no handshake, sequencing or acknowledgement occurs between endpoints. This connectionless behaviour directly satisfies the stem's constraint: an application using UDP sends datagrams independently, with no prior path negotiation or state maintained between sender and receiver.

Why this answer

UDP is a connectionless transport protocol, meaning it does not establish a dedicated end-to-end connection before sending data. This characteristic allows for low-latency, best-effort delivery without the overhead of connection setup, which is ideal for applications like DNS queries or streaming media where speed is prioritized over reliability.

Exam trap

Cisco often tests the misconception that all transport protocols provide reliability, leading candidates to associate UDP with features like guaranteed delivery or retransmission, when in fact those are exclusive to TCP.

How to eliminate wrong answers

Option A is wrong because UDP does not guarantee packet delivery; it is a best-effort protocol that provides no acknowledgment or retransmission mechanisms. Option B is wrong because UDP does not retransmit lost packets; retransmission is a feature of TCP, which uses sequence numbers and acknowledgments to ensure reliable delivery. Option D is wrong because a three-way handshake is a connection-establishment process used by TCP (SYN, SYN-ACK, ACK), not by UDP, which sends datagrams without prior setup.

81
MCQmedium

A network engineer is configuring a wireless network for a new office. To maximize performance and minimize interference, the engineer decides to use the 5 GHz band. Which of the following is a key advantage of 5 GHz over 2.4 GHz?

A.Less interference and more channels
B.Better range through walls
C.Larger coverage area
D.Higher compatibility with older devices
AnswerA

The 5 GHz band offers more non-overlapping channels and avoids congestion from microwave ovens, Bluetooth, and cordless phones that crowd 2.4 GHz. This directly maximises performance and minimises interference as the scenario requires, though at the cost of shorter range.

Why this answer

5 GHz offers more non-overlapping channels and less interference from common devices like microwaves and Bluetooth.

82
Multi-Selectmedium

A developer is designing a system that requires high reliability and ordered data delivery. The developer chooses TCP. Which THREE features are provided by TCP?

Select 3 answers
A.Flow control using window size
B.Multicast support
C.Simple header with minimal overhead
D.Connection-oriented communication using a three-way handshake
E.Sequencing and retransmission of lost packets
AnswersA, D, E

TCP's sliding window mechanism lets the receiver advertise how much data it can buffer, so a fast sender cannot overwhelm a slower receiver. This directly satisfies the high-reliability requirement in the stem by preventing buffer overflow and packet loss during transmission.

Why this answer

TCP provides flow control using a sliding window mechanism (Option A), where the receiver advertises a window size in each segment to prevent the sender from overwhelming its buffer. TCP is connection-oriented (Option D): it establishes a session via the three-way handshake (SYN, SYN-ACK, ACK) before data transfer, which underpins its reliability guarantees. TCP also performs sequencing and retransmission (Option E): each byte is numbered with a sequence number, and unacknowledged segments are retransmitted after a timeout or duplicate ACKs, ensuring ordered, loss-free delivery.

Option B is incorrect because multicast is not a TCP feature; TCP is strictly unicast, and multicast delivery is handled by UDP-based or specialized protocols. Option C is incorrect because TCP uses a relatively large 20-byte (minimum) header with many fields, whereas UDP has the simple 8-byte header with minimal overhead.

Exam trap

200-901 often tests the features of TCP vs. UDP, and candidates might incorrectly attribute multicast or low overhead to TCP, which are UDP characteristics.

83
MCQmedium

A developer is writing a Python script using requests to retrieve a large JSON payload from an API. The server responds with headers including Content-Encoding: gzip, and the response body appears as binary data. The script must automatically decompress the payload to parse it as JSON. Which requests library behavior should the developer rely on?

A.The developer must set the Accept-Encoding header to identity to force the server to send uncompressed JSON.
B.The response.content attribute automatically decodes gzip-encoded bodies before returning them.
C.The response.json() method requires the developer to pass a decompression parameter set to True.
D.The requests library automatically decompresses gzip-encoded responses when accessing response.text or response.json().
AnswerD

The requests library inspects the Content-Encoding header and transparently decompresses gzip (and deflate) bodies when you use response.text or response.json(). This allows the developer to parse the JSON payload without manual intervention. The raw compressed bytes are only visible via response.content, so using the higher-level accessors triggers the automatic decompression needed for this scenario.

Why this answer

The requests library automatically decompresses gzip-encoded responses when the developer accesses response.text or response.json(). This behavior is driven by the Content-Encoding header and allows seamless parsing of JSON payloads without manual gzip handling. Using response.content returns raw compressed bytes, so the higher-level accessors are necessary for this scenario.

Exam trap

The trap here is assuming that response.content always returns decoded text, when it actually returns raw bytes that may still be compressed.

84
MCQmedium

An engineer is troubleshooting a VoIP call quality issue. The call uses UDP and experiences packet loss. Which characteristic of UDP most likely contributes to the problem?

A.Ordered delivery guarantee
B.Connection-oriented setup
C.No retransmission of lost packets
D.Flow control mechanism
AnswerC

UDP provides no retransmission mechanism, so datagrams dropped in transit are never recovered, producing gaps that degrade VoIP audio. TCP would retransmit lost segments, but UDP's fire-and-forget design leaves loss concealment entirely to the application codec.

Why this answer

UDP is a connectionless transport protocol that does not provide retransmission of lost packets. In VoIP, packet loss directly degrades call quality because lost audio data is never resent, leading to gaps or distortion in the conversation.

Exam trap

Cisco often tests the misconception that UDP's lack of reliability is always a flaw, but the trap here is that candidates may incorrectly attribute the problem to UDP's lack of ordered delivery or flow control, when the core issue is the absence of retransmission for lost packets.

How to eliminate wrong answers

Option A is wrong because UDP does not guarantee ordered delivery; it is a best-effort protocol that may deliver packets out of order, and VoIP codecs typically handle sequencing at the application layer. Option B is wrong because UDP is connectionless and does not use a connection-oriented setup like TCP's three-way handshake; this lack of setup reduces latency but contributes to packet loss. Option D is wrong because UDP has no built-in flow control mechanism; flow control is a TCP feature that manages data transmission rates to prevent congestion, and its absence in UDP means the sender can overwhelm the network.

85
MCQhard

A network automation engineer is using `ncclient` to configure a Cisco IOS XE device via NETCONF. The engineer wants to retrieve the running configuration using the `<get-config>` operation with a source of `<running/>`. Which XML element must be included in the RPC to specify the data store?

A.`<target><running/></target>`
B.`<source><running/></source>`
C.`<config><running/></config>`
D.`<filter><running/></filter>`
AnswerB

In NETCONF, the `<get-config>` RPC requires a `<source>` element that identifies the configuration datastore to retrieve. The `<running/>` element inside `<source>` specifies the running configuration. This is defined in RFC 6241 and is mandatory for `<get-config>`. Without it, the server cannot determine which datastore to query. The engineer must include this exact structure to retrieve the running config successfully.

Why this answer

The NETCONF `<get-config>` operation requires a `<source>` element to identify the configuration datastore to retrieve. The `<running/>` element within `<source>` selects the running configuration. Other elements like `<target>` are used for editing, `<config>` for edit payloads, and `<filter>` for narrowing results.

The engineer must use `<source><running/></source>` to correctly specify the datastore for retrieval.

Exam trap

The trap here is mixing up the `<source>` and `<target>` elements, where source is used for reading with `<get-config>` and target is used for writing with `<edit-config>`.

86
MCQhard

A network automation engineer must ensure that a Python script running on a management workstation can resolve internal service names such as `inventory.corp.local` and `billing.corp.local`. The workstation currently resolves public names correctly but fails on the internal ones. The engineer inspects `/etc/resolv.conf` and sees a single `nameserver 8.8.8.8` entry. Which change most directly resolves the problem?

A.Add a `search corp.local` line and point the nameserver at the internal DNS server.
B.Increase the DNS timeout value so the public resolver has more time to answer.
C.Enable DNSSEC validation on the workstation's resolver library.
D.Add static entries for both service names to the local hosts file.
AnswerA

Internal names like inventory.corp.local are only authoritative on the corporate DNS infrastructure, which a public resolver such as 8.8.8.8 cannot see. Replacing the nameserver with the internal resolver lets the workstation query the zone that actually holds those records, and the search domain allows short names to be expanded automatically.

Why this answer

The workstation is pointing at a public recursive resolver that has no authority over the private corp.local zone, so internal names return no answer. Pointing the client at the corporate DNS server that hosts the zone, plus adding the search domain for short-name expansion, restores resolution for all internal services rather than a hand-picked few.

Exam trap

The trap here is assuming any working nameserver can resolve any name, when a public resolver has no records for a private internal zone and will simply return an empty or negative answer.

87
MCQmedium

A developer is building a Python application that must discover the IP address of a service registered in DNS. The application needs to resolve a domain name to an IPv4 address. Which DNS record type should the application query?

A.AAAA
B.A
C.CNAME
D.PTR
AnswerB

An A record maps a domain name to an IPv4 address. When an application needs to resolve a hostname to an IPv4 address, it queries for the A record. This is the standard and correct record type for IPv4 address resolution. The scenario specifically asks for an IPv4 address, so the A record is the right choice.

Why this answer

To resolve a domain name to an IPv4 address, the correct DNS record type is A. AAAA records are for IPv6, CNAME records provide aliases, and PTR records are for reverse lookups. The application needs forward resolution to an IPv4 address, which is exactly what an A record provides.

Exam trap

The trap here is mixing up A and AAAA records, or thinking that a CNAME directly returns an IP address, when it only points to another name.

88
MCQhard

A network engineer is analyzing a packet capture and notices that a TCP session between a client and server is experiencing performance issues. The capture shows that the client sends a segment with the Push (PSH) flag set, but the server's acknowledgment does not immediately follow; instead, the server waits and sends a single acknowledgment for multiple segments. Which TCP mechanism is the server using to optimize network efficiency?

A.TCP delayed acknowledgment
B.TCP slow start
C.TCP selective acknowledgment (SACK)
D.TCP window scaling
AnswerA

Delayed acknowledgment is a TCP optimization where the receiver waits for a short period or until it has received multiple segments before sending an ACK. This reduces the number of ACK packets and improves network efficiency. The scenario describes the server waiting and then sending a single acknowledgment for multiple segments, which is exactly how delayed ACK works. It is commonly used to reduce overhead, especially for interactive traffic.

Why this answer

The server is using delayed acknowledgment, a TCP feature where the receiver delays sending an ACK to potentially combine acknowledgments for multiple segments, reducing overhead. This is distinct from congestion control or window management mechanisms. The behavior described—waiting and then sending a single ACK for multiple segments—is characteristic of delayed ACK, which is commonly enabled by default in many TCP stacks.

Exam trap

The trap here is confusing delayed acknowledgment with congestion control algorithms like slow start, which also affect TCP performance but in a different way.

89
MCQhard

A network operations team is deploying a new application that requires guaranteed bandwidth and low latency between two data centers. The team decides to use MPLS Layer 3 VPN. Which component of MPLS is responsible for forwarding packets based on labels rather than traditional IP routing lookups?

A.Label Edge Router (LER)
B.Autonomous System Boundary Router (ASBR)
C.Route Reflector
D.Label Switch Router (LSR)
AnswerD

The Label Switch Router (LSR) is a core MPLS device that forwards packets based on labels. It examines the incoming label, looks up the next-hop in its Label Forwarding Information Base (LFIB), swaps the label, and forwards the packet. This label-based forwarding is faster and more efficient than traditional IP routing lookups.

Why this answer

In MPLS, the Label Switch Router (LSR) is the device that forwards packets based on labels. It uses the Label Forwarding Information Base (LFIB) to determine the outgoing interface and new label. This allows MPLS networks to make forwarding decisions without examining the IP header, enabling traffic engineering and VPNs.

The LERs handle label imposition and disposition at the edges.

Exam trap

The trap here is confusing the roles of edge and core MPLS devices; the LER assigns labels, but the LSR is the one that forwards based on labels.

90
MCQmedium

Which wireless standard operates in both 2.4 GHz and 5 GHz bands and is commonly known as Wi-Fi 6?

A.802.11n
B.802.11ac
C.802.11ax
D.802.11g
AnswerC

802.11ax, marketed as Wi-Fi 6, operates in both the 2.4 GHz and 5 GHz bands, satisfying the dual-band requirement in the stem. Unlike 802.11ac, which is 5 GHz only, 802.11ax supports concurrent dual-band operation, delivering higher throughput and improved efficiency in dense environments.

Why this answer

The IEEE 802.11ax standard, marketed as Wi-Fi 6, is designed to operate in both the 2.4 GHz and 5 GHz frequency bands. It introduces efficiency improvements like OFDMA and MU-MIMO to better handle dense environments. Unlike 802.11ac, which is limited to 5 GHz, 802.11ax supports dual-band operation, making it backward compatible with older devices on both bands.

Exam trap

The trap here is confusing Wi-Fi generations: candidates often mix up 802.11ac (Wi-Fi 5) with 802.11ax (Wi-Fi 6) or forget that 802.11ac is 5 GHz only, leading them to pick 802.11ac for dual-band support.

How to eliminate wrong answers

Option A is wrong because 802.11n (Wi-Fi 4) operates in both 2.4 GHz and 5 GHz but is not known as Wi-Fi 6. Option B is wrong because 802.11ac (Wi-Fi 5) operates only in the 5 GHz band, not 2.4 GHz. Option D is wrong because 802.11g operates only in the 2.4 GHz band and is an older standard predating Wi-Fi 4.

91
MCQmedium

In an SDN architecture, which layer is responsible for making decisions about where traffic should be forwarded?

A.Data plane
B.Application plane
C.Management plane
D.Control plane
AnswerD

The control plane holds the centralised logic that computes forwarding decisions, programming them down to the data plane via southbound APIs. The data plane merely executes those instructions, which is the SDN separation of concerns.

Why this answer

In SDN architecture, the control plane is responsible for making forwarding decisions by maintaining the network topology and computing paths for traffic flows. It communicates these decisions to the data plane via southbound protocols like OpenFlow or NETCONF, ensuring that packets are forwarded according to the desired policies.

Exam trap

Cisco often tests the distinction between the control plane and management plane, where candidates mistakenly think that configuration (management plane) is the same as making forwarding decisions, but the control plane is the one that dynamically determines traffic paths.

How to eliminate wrong answers

Option A is wrong because the data plane (or forwarding plane) is responsible only for the actual forwarding of packets based on flow tables or forwarding information bases (FIBs), not for making routing decisions. Option B is wrong because the application plane contains network applications (e.g., load balancers, firewalls) that express high-level policies, but it does not directly make per-packet forwarding decisions; it relies on the control plane to translate those policies into forwarding rules. Option C is wrong because the management plane handles administrative tasks such as configuration, monitoring, and fault management (e.g., via CLI, SNMP, or REST APIs), but it does not dynamically decide traffic paths in real time.

92
MCQmedium

An engineer is troubleshooting a connectivity issue between two devices on different VLANs. The switch connecting the devices is configured with 802.1Q trunking. At which OSI layer do VLANs operate?

A.Layer 2
B.Layer 4
C.Layer 1
D.Layer 3
AnswerA

VLAN tags and 802.1Q trunk encapsulation are defined in Ethernet frames, so VLANs operate at Layer 2 of the OSI model. This satisfies the stem's requirement to identify the layer governing inter-VLAN connectivity across the trunked switch.

Why this answer

VLANs operate at Layer 2 (the Data Link layer) of the OSI model because they segment a single physical switch into multiple logical broadcast domains using 802.1Q tags inserted into Ethernet frames. The 802.1Q tag adds a 12-bit VLAN ID field to the Ethernet frame header, which is a Layer 2 construct. Routing between VLANs requires a Layer 3 device (router or Layer 3 switch), but the VLAN membership and tagging itself is strictly a Layer 2 function.

Exam trap

The trap here is confusing the layer where VLANs are defined (Layer 2 tagging) with the layer required to route between them (Layer 3), causing candidates to pick Layer 3.

How to eliminate wrong answers

Option B is wrong because Layer 4 (Transport) deals with TCP/UDP ports and end-to-end connections, not broadcast domain segmentation. Option C is wrong because Layer 1 (Physical) concerns cables, signaling, and bit transmission — VLANs are logical, not physical, constructs. Option D is wrong because Layer 3 handles IP addressing and routing between VLANs, but the VLAN itself is defined by Layer 2 frame tagging, not by IP subnets.

93
MCQmedium

Which DNS record type is used to verify domain ownership for email security (SPF)?

A.A record
B.CNAME record
C.MX record
D.TXT record
AnswerD

TXT records carry arbitrary text, which SPF publishes as a v=spf1 string listing authorised sending hosts. Domain owners add this record so receivers can verify mail legitimacy, satisfying the stem's ownership-verification requirement for email security.

Why this answer

TXT record is correct because SPF (Sender Policy Framework) is published as a DNS TXT record containing a list of authorized mail servers for a domain. Receiving mail servers query the TXT record to verify that the sending IP is authorized, helping prevent email spoofing. SPF records follow the format v=spf1 followed by mechanisms like ip4, include, and -all.

Exam trap

The trap is assuming MX records handle email authentication because they are email-related — MX records only route inbound mail, while TXT records carry SPF, DKIM, and DMARC policies.

How to eliminate wrong answers

Option A is wrong because A records map a hostname to an IPv4 address and have no role in email authentication or domain ownership verification. Option B is wrong because CNAME records create an alias from one hostname to another and cannot coexist with other record types at the same name, making them unsuitable for SPF. Option C is wrong because MX records specify where to deliver email for a domain, not which servers are authorized to send on its behalf.

94
MCQhard

In a wireless network using 802.11ac, which frequency band does the standard primarily operate in to achieve higher throughput?

A.5 GHz
B.2.4 GHz
C.6 GHz
D.Both 2.4 GHz and 5 GHz
AnswerA

802.11ac operates in the 5 GHz band, which offers wider channels and less interference than 2.4 GHz, enabling the higher throughput and modulation rates the standard specifies. The 2.4 GHz band is handled by 802.11b/g/n instead.

Why this answer

5 GHz is correct because 802.11ac (Wi-Fi 5) was designed to operate exclusively in the 5 GHz band, which offers wider channels (up to 160 MHz) and less interference compared to 2.4 GHz. This enables the higher throughput and multi-user MIMO capabilities that define 802.11ac. The standard does not define operation in 2.4 GHz or 6 GHz.

Exam trap

The trap is assuming 802.11ac is dual-band like 802.11n — ac is 5 GHz only, and 6 GHz belongs to Wi-Fi 6E, not ac.

How to eliminate wrong answers

Option B is wrong because 2.4 GHz is used by 802.11b/g/n, not 802.11ac; the 2.4 GHz band is congested and limited to 20/40 MHz channels, which cannot support 802.11ac's throughput targets. Option C is wrong because 6 GHz operation was introduced with Wi-Fi 6E (802.11ax amendment), not 802.11ac. Option D is wrong because 802.11ac does not operate in 2.4 GHz at all — dual-band operation is a characteristic of 802.11n, not ac.

95
MCQeasy

Which transport layer protocol is used by HTTP and guarantees reliable delivery?

A.TCP
B.ICMP
C.IP
D.UDP
AnswerA

TCP provides connection-oriented, reliable delivery through sequence numbers, acknowledgements and retransmission of lost segments, which HTTP requires. UDP, by contrast, is connectionless and offers no delivery guarantee. This satisfies the stem's requirement for a transport layer protocol guaranteeing reliable delivery for HTTP traffic.

Why this answer

HTTP relies on TCP (Transmission Control Protocol) as its transport layer protocol because TCP provides reliable, connection-oriented data delivery. TCP ensures that all HTTP requests and responses are delivered in order, without loss or duplication, by using acknowledgments, retransmissions, and sequence numbers. This reliability is essential for HTTP, which expects complete and correct data transfer for web pages and resources.

Exam trap

Cisco often tests the distinction between transport layer protocols by pairing HTTP with TCP, but the trap here is that candidates may confuse HTTP's use of TCP with other protocols like UDP (used by DNS or VoIP) or think IP provides reliability, when in fact IP only handles routing and fragmentation without delivery guarantees.

How to eliminate wrong answers

Option B (ICMP) is wrong because ICMP is a network layer protocol used for error reporting and diagnostic functions (e.g., ping), not for transporting application data like HTTP. Option C (IP) is wrong because IP is a network layer protocol responsible for addressing and routing packets, not for reliable delivery at the transport layer. Option D (UDP) is wrong because UDP is a transport layer protocol that provides connectionless, unreliable delivery without acknowledgments or retransmissions, making it unsuitable for HTTP's requirement of guaranteed delivery.

96
MCQeasy

Which DNS record type is used to map a domain name to an IPv6 address?

A.A
B.AAAA
C.CNAME
D.MX
AnswerB

AAAA records map a hostname to a 128-bit IPv6 address, the direct counterpart to A records for IPv4. Resolvers query AAAA when the client requests IPv6, so it satisfies the requirement to resolve a domain name to an IPv6 address.

Why this answer

The AAAA (quad-A) record is the DNS resource record type defined in RFC 3596 to map a fully qualified domain name to a 128-bit IPv6 address. Unlike the A record, which stores a 32-bit IPv4 address, the AAAA record holds the longer IPv6 address, enabling clients to resolve hostnames to IPv6 destinations.

Exam trap

Cisco often tests the AAAA record by pairing it with the A record as a distractor, expecting candidates to remember that IPv6 uses four 'A's (AAAA) while IPv4 uses a single 'A', and that CNAME and MX serve entirely different purposes unrelated to address mapping.

How to eliminate wrong answers

Option A is wrong because the A record maps a domain name to a 32-bit IPv4 address, not an IPv6 address. Option C is wrong because the CNAME record creates an alias from one domain name to another canonical name, it does not store any IP address. Option D is wrong because the MX record specifies the mail exchange server responsible for accepting email on behalf of a domain, and it contains a hostname, not an IP address.

97
MCQmedium

A developer is writing a Python script to interact with a REST API. The API requires a JSON payload to create a new resource. Which HTTP method should be used?

A.POST
B.PATCH
C.PUT
D.GET
AnswerA

POST submits a payload to the collection endpoint, creating a new resource, and the JSON body travels in the request. GET, PUT and DELETE cannot create a resource this way, so POST matches the API's create requirement.

Why this answer

POST is correct because the HTTP POST method is used to create a new resource on the server, with the resource representation sent in the request body as JSON. POST is neither safe nor idempotent, meaning repeated identical requests may create multiple resources. This matches the requirement to create a new resource via a REST API.

Exam trap

The trap is choosing PUT because it can also create resources — but PUT requires the client to specify the URI and is idempotent, whereas POST is the correct method when the server assigns the new resource's identifier.

How to eliminate wrong answers

Option B is wrong because PATCH is used to apply partial modifications to an existing resource, not to create a new one. Option C is wrong because PUT is used to create or replace a resource at a known URI and is idempotent — while PUT can create, the question specifies creating a new resource where the server assigns the identifier, which is POST's role. Option D is wrong because GET is a safe, idempotent method used only to retrieve representations and must never have side effects like resource creation.

98
MCQmedium

A developer is building a Python application that must connect to a REST API hosted on a server. The API requires a persistent connection and the ability to send multiple requests without re-establishing a TCP handshake each time. The developer wants to minimize latency. Which HTTP feature should the application leverage?

A.HTTP persistent connections (keep-alive)
B.HTTP pipelining
C.HTTP/2 multiplexing
D.HTTP cookies
AnswerA

HTTP persistent connections, also known as keep-alive, allow multiple HTTP requests and responses to be sent over a single TCP connection. This avoids the overhead of establishing a new TCP handshake for each request, reducing latency and improving performance for applications that make frequent API calls to the same server.

Why this answer

Persistent connections, enabled by the Connection: keep-alive header in HTTP/1.1, allow a client to reuse an existing TCP connection for multiple requests. This reduces latency by eliminating repeated TCP and TLS handshakes. While HTTP/2 multiplexing also improves efficiency, it requires server support and is not the basic feature described.

The other options do not directly address the need for connection reuse.

Exam trap

The trap here is confusing HTTP pipelining with persistent connections; pipelining is an extension that still requires keep-alive and is not the primary mechanism for connection reuse.

99
MCQeasy

A network administrator is configuring a new subnet on a Cisco switch. The subnet uses the address 192.168.10.0/24. The administrator needs to assign an IP address to the switch's management interface so it can be reached from a remote management station on the same subnet. Which of the following IP addresses should be assigned to the switch?

A.192.168.11.1
B.192.168.10.255
C.192.168.10.1
D.192.168.10.0
AnswerC

192.168.10.1 is a valid host address within the 192.168.10.0/24 subnet. It is commonly used as the default gateway or management address on network devices. Since it is not the network address or the broadcast address, it can be assigned to the switch's management interface and reached from other hosts on the same subnet.

Why this answer

For a device to be reachable on the same subnet as a management station, it must be assigned a valid host address within that subnet. In 192.168.10.0/24, the addresses 192.168.10.0 and 192.168.10.255 are reserved as the network and broadcast addresses, respectively. Any other address, such as 192.168.10.1, is a usable host address. 192.168.11.1 is in a different subnet and would require routing.

Exam trap

The trap here is forgetting that the first and last addresses of a subnet are reserved for the network and broadcast addresses, and cannot be assigned to hosts.

100
MCQmedium

A network administrator is configuring a switch and needs to ensure that devices connected to the same VLAN can communicate with each other. The administrator wants to verify that the switch is correctly forwarding frames within the VLAN. Which of the following best describes the switch's primary function in this scenario?

A.It translates IP addresses to MAC addresses for communication.
B.It routes packets between different VLANs using IP addresses.
C.It forwards frames based on MAC addresses within the same VLAN.
D.It broadcasts all frames to every port to ensure delivery.
AnswerC

A switch operates at Layer 2 and forwards frames based on destination MAC addresses. Within a VLAN, it maintains a MAC address table and forwards frames only to the port where the destination MAC is known, thereby enabling communication between devices in the same VLAN while isolating traffic from other VLANs.

Why this answer

A switch's primary function is to forward frames based on MAC addresses within a VLAN. It learns source MAC addresses and builds a MAC address table, then forwards frames only to the port where the destination MAC is known, enabling efficient communication within the same VLAN while isolating traffic from other VLANs.

Exam trap

The trap here is confusing the role of a Layer 2 switch with that of a router or a Layer 3 switch, which are required for inter-VLAN routing.

101
MCQhard

A network engineer configures an HTTP/2 server. Which feature of HTTP/2 reduces overhead by compressing headers using HPACK?

A.Server push
B.Binary framing layer
C.HPACK
D.Multiplexed streams
AnswerC

HPACK is the header compression scheme defined specifically for HTTP/2, encoding header fields into a compact indexed format and eliminating redundant transfers across streams. This directly satisfies the stem's requirement to reduce overhead by compressing headers, unlike HTTP/1.1's uncompressed plaintext headers.

Why this answer

HPACK is the header compression mechanism specified for HTTP/2 (RFC 7541). It reduces overhead by encoding HTTP headers into a compact binary format using static and dynamic tables, eliminating redundant header data across requests. This directly addresses the question's focus on reducing overhead through header compression.

Exam trap

Cisco often tests the distinction between features that improve performance (multiplexing, server push) versus the specific mechanism for header compression (HPACK), leading candidates to confuse multiplexing or binary framing with compression.

How to eliminate wrong answers

Option A is wrong because server push is a feature that allows the server to send resources proactively before the client requests them, but it does not involve header compression. Option B is wrong because the binary framing layer is the foundation of HTTP/2 that encodes frames into binary format for efficient parsing, but it is not responsible for header compression; HPACK operates within this layer. Option D is wrong because multiplexed streams enable multiple concurrent requests and responses over a single TCP connection, reducing head-of-line blocking, but they do not compress headers.

102
MCQhard

A developer is building a real-time video streaming application that must minimize delay, even if some packets are lost. Which transport protocol is most appropriate, and why?

A.TCP, because it provides flow control to avoid congestion.
B.UDP, because it guarantees packet delivery.
C.TCP, because it ensures all packets arrive in order.
D.UDP, because it has lower overhead and no retransmission delay.
AnswerD

UDP omits handshaking, acknowledgements and retransmission, so lost packets are not resent and latency stays low. That satisfies the streaming constraint of minimising delay at the cost of occasional loss, which TCP's reliability mechanisms would worsen.

Why this answer

UDP is the correct choice because it has minimal overhead (8-byte header vs TCP's 20+ bytes), no handshake, and no retransmission logic, so lost packets do not stall the stream. For real-time video, a late packet is worse than a lost one, so UDP's fire-and-forget model minimizes delay. Application-layer protocols like RTP/WebRTC build on UDP to handle ordering and loss recovery selectively.

Exam trap

200-901 often tests the misconception that 'UDP guarantees delivery' or that 'TCP is always better because it's reliable' — candidates must recognize that reliability is the wrong optimization for real-time media.

How to eliminate wrong answers

Option A is wrong because TCP's flow control and congestion control introduce delay and head-of-line blocking, which is exactly what a real-time stream must avoid. Option B is wrong because UDP does not guarantee packet delivery — it is a connectionless, best-effort protocol; the statement is factually inverted. Option C is wrong because TCP's in-order delivery and retransmission cause head-of-line blocking, where a single lost segment delays all subsequent data, increasing latency.

103
MCQmedium

In the context of SDN, which API is used between the SDN controller and the network devices to configure forwarding behavior?

A.Northbound API
B.Eastbound API
C.Southbound API
D.REST API
AnswerC

The southbound API sits below the controller, translating its forwarding decisions into device-level configuration. OpenFlow is the canonical example, programming match-action flow tables on switches. This satisfies the stem's requirement for the interface used to configure forwarding behaviour on network devices.

Why this answer

The southbound API is the interface between the SDN controller and the underlying network devices (switches, routers), used to program forwarding tables and configure behavior. Protocols like OpenFlow, NETCONF, and P4 are typical southbound interfaces. The controller translates northbound application intent into southbound device instructions.

Exam trap

200-901 often tests the northbound vs. southbound direction confusion — candidates must remember that southbound points down to devices, northbound points up to applications.

How to eliminate wrong answers

Option A is wrong because the northbound API is the interface between SDN applications and the controller, exposing network abstractions to applications, not configuring devices. Option B is wrong because 'eastbound/westbound' APIs refer to controller-to-controller communication in multi-controller SDN architectures, not controller-to-device. Option D is wrong because REST API is a generic architectural style that can be used for northbound APIs (e.g., ONOS REST) but is not the specific SDN term for controller-to-device configuration.

104
MCQhard

An engineer sees that a DNS query for 'www.example.com' returns a CNAME record. What does this mean?

A.The domain has multiple IP addresses
B.The domain uses IPv6
C.The IP address is directly provided
D.The domain is an alias for another domain
AnswerD

A CNAME record points the queried name at a canonical name rather than an address, so resolution continues against that target. The queried domain therefore acts purely as an alias, holding no A or AAAA record of its own.

Why this answer

A CNAME (Canonical Name) record maps an alias domain name to another canonical domain name. When a DNS query for 'www.example.com' returns a CNAME record, it means 'www.example.com' is an alias for another domain (e.g., 'example.com'), and the resolver must perform a second query to obtain the actual A or AAAA record. This is defined in RFC 1035 and is used to simplify domain management.

Exam trap

Cisco often tests the misconception that a CNAME record directly provides an IP address, when in fact it only provides an alias that requires further resolution.

How to eliminate wrong answers

Option A is wrong because multiple IP addresses for a domain are indicated by multiple A or AAAA records, not by a CNAME record. Option B is wrong because IPv6 support is indicated by AAAA records, not CNAME records. Option C is wrong because a CNAME record does not directly provide an IP address; it redirects the query to another domain name, which then must be resolved to an IP address via an A or AAAA record.

105
MCQmedium

A network administrator is configuring a new subnet for a branch office that requires 50 usable host addresses. The corporate network uses the 192.168.10.0/24 block. Which subnet mask should be used to meet the requirement with minimal waste?

A.255.255.255.128 (/25)
B.255.255.255.0 (/24)
C.255.255.255.192 (/26)
D.255.255.255.224 (/27)
AnswerC

A /26 mask yields 64 addresses, leaving 62 usable hosts after reserving network and broadcast addresses, which satisfies the 50-host requirement with minimal waste. A /27 would provide only 30 usable hosts, insufficient here, while a /25 wastes 126 addresses.

Why this answer

A /26 subnet mask (255.255.255.192) provides 2^(32-26) = 64 total addresses, of which 62 are usable (subtracting network and broadcast addresses). This meets the requirement of 50 usable hosts with minimal waste, as the next smaller mask (/27) only offers 30 usable addresses, which is insufficient.

Exam trap

The trap here is that candidates often forget to subtract the two reserved addresses (network and broadcast) from the total host count, leading them to incorrectly select a /27 mask (which has 32 total addresses but only 30 usable) thinking it is sufficient for 50 hosts.

How to eliminate wrong answers

Option A is wrong because a /25 mask (255.255.255.128) provides 126 usable addresses, which far exceeds the requirement of 50 and wastes 76 addresses, contradicting the 'minimal waste' condition. Option B is wrong because a /24 mask (255.255.255.0) provides 254 usable addresses, which is the original subnet size and wastes 204 addresses, failing the minimal waste requirement. Option D is wrong because a /27 mask (255.255.255.224) provides only 30 usable addresses (2^5 - 2 = 30), which is insufficient for the required 50 hosts.

106
MCQeasy

A developer is writing a Python script that will call a REST API. The API documentation states that the service listens on TCP port 443 and requires an encrypted channel. The developer wants to confirm from the command line that the remote host is reachable on that specific port before writing any code. Which command best accomplishes this?

A.nslookup api.example.com
B.nc -vz api.example.com 443
C.traceroute api.example.com
D.ping api.example.com
AnswerB

Netcat with the verbose and zero-I/O scan flags opens a TCP connection to the specified host and port, reporting whether the three-way handshake succeeds. This directly answers the question of whether the API's listening port is reachable from the client, which is exactly the precondition the Python script depends on.

Why this answer

Testing a specific TCP port requires a tool that performs a TCP handshake against that port. Netcat's verbose zero-I/O scan does exactly that, confirming the API's listener is reachable before the developer invests time in code. Ping, traceroute, and nslookup validate different layers and cannot prove the service port is open.

Exam trap

The trap here is treating a successful ping as proof that a service is reachable, when ICMP success only shows the host responds to echo requests, not that TCP port 443 is accepting connections.

107
Multi-Selecthard

Which THREE of the following are characteristics of HTTP/2 compared to HTTP/1.1?

Select 3 answers
A.Header compression using HPACK
B.Binary framing layer
C.Plaintext headers for debugging
D.Requires multiple TCP connections for parallel requests
E.Multiplexed streams over a single TCP connection
AnswersA, B, E

HPACK reduces header overhead.

Why this answer

HPACK compression reduces header overhead by encoding header fields, which is a key improvement over HTTP/1.1's uncompressed headers. This minimizes latency and bandwidth usage, especially for repeated headers like cookies and user-agent.

Exam trap

Cisco often tests the misconception that HTTP/2 is purely a performance upgrade without structural changes, leading candidates to incorrectly select plaintext headers or assume multiple TCP connections are still required.

108
MCQeasy

An engineer is troubleshooting a network issue and needs to verify the MAC address of the next-hop router on a directly connected segment. Which layer of the OSI model does the engineer need to examine to find this information?

A.Data Link layer (Layer 2)
B.Transport layer (Layer 4)
C.Physical layer (Layer 1)
D.Network layer (Layer 3)
AnswerA

MAC addresses are used at Layer 2 for local network communication.

Why this answer

The MAC address of the next-hop router is found in the Data Link layer (Layer 2) header of a frame. When a device sends an IP packet to a next-hop router on the same segment, it encapsulates the packet in a frame with the destination MAC address of that router's interface. To verify this address, you examine Layer 2 information, such as by using the `show arp` command on Cisco devices to view the MAC-to-IP mapping.

Exam trap

Cisco often tests the misconception that MAC addresses belong to the Network layer because they are used in routing decisions, but the trap is that MAC addresses are strictly a Data Link layer construct used for local segment delivery, not for end-to-end path determination.

How to eliminate wrong answers

Option B is wrong because the Transport layer (Layer 4) handles end-to-end communication, segmentation, and port numbers (e.g., TCP/UDP), not MAC addresses. Option C is wrong because the Physical layer (Layer 1) deals with raw bit transmission, electrical signals, and media specifications, not addressing or frame headers. Option D is wrong because the Network layer (Layer 3) uses logical IP addresses for routing and packet forwarding, but the MAC address is a Layer 2 identifier used for delivery on the local segment.

109
MCQmedium

A developer is troubleshooting an application that uses HTTP/2. The developer notices that multiple requests are being sent concurrently over a single TCP connection, and the responses are being received out of order. Which HTTP/2 feature allows this behavior?

A.Binary framing
B.Multiplexing
C.Server push
D.Header compression
AnswerB

Multiplexing in HTTP/2 allows multiple request and response messages to be interleaved on a single TCP connection. Each stream is independent, and responses can be received out of order. This eliminates head-of-line blocking at the HTTP level and improves performance by allowing parallel transfers without opening multiple connections.

Why this answer

HTTP/2 multiplexing allows multiple request and response messages to be interleaved on a single TCP connection. Each stream is independent, and responses can be received out of order, eliminating head-of-line blocking at the HTTP level and improving performance by enabling parallel transfers without opening multiple connections.

Exam trap

The trap here is confusing multiplexing with other HTTP/2 features like header compression or server push, which serve different purposes and do not enable concurrent streams.

110
MCQhard

Which DNS record type is used to verify domain ownership for email security protocols like SPF and DKIM?

A.CNAME
B.TXT
C.MX
D.NS
AnswerB

TXT records hold arbitrary text and carry the SPF policy string and DKIM public key, letting receivers verify sending authorisation and message signatures. No other record type accommodates these free-form verification values at the domain level.

Why this answer

SPF and DKIM records are stored as TXT records in DNS. SPF records specify which mail servers are authorized to send email for a domain, while DKIM records contain a public key used to verify email signatures. Both are implemented via TXT records, not other record types.

Exam trap

Cisco often tests the misconception that SPF or DKIM use a dedicated record type like SPF or DKIM, when in fact both rely on TXT records, and candidates may incorrectly choose MX or CNAME due to their association with email or aliasing.

How to eliminate wrong answers

Option A is wrong because CNAME records create an alias for a domain name and cannot contain the arbitrary text data required for SPF or DKIM policies. Option C is wrong because MX records specify mail exchange servers for routing email, not for storing authentication or verification data. Option D is wrong because NS records delegate a domain to authoritative name servers and have no role in email security protocol verification.

111
MCQhard

A developer is designing a microservices architecture where services need to discover each other using DNS. The team wants to map a service name 'payment-service.example.com' to its IPv6 address. Which DNS record type should be used?

A.PTR record
B.AAAA record
C.A record
D.CNAME record
AnswerB

AAAA records map a hostname to an IPv6 address, exactly matching the requirement to resolve 'payment-service.example.com' to its IPv6 address. The A record serves the same purpose for IPv4 only, so it cannot satisfy the IPv6 constraint.

Why this answer

The AAAA record (Quad-A) is the correct DNS record type for mapping a hostname to an IPv6 address, as defined in RFC 3596. Since the requirement is specifically to resolve 'payment-service.example.com' to an IPv6 address, the AAAA record is the appropriate choice.

Exam trap

Cisco often tests the distinction between A and AAAA records, and the trap here is that candidates may confuse the AAAA record with the A record or incorrectly think a CNAME can resolve to an IP address directly.

How to eliminate wrong answers

Option A is wrong because a PTR record is used for reverse DNS lookups (mapping an IP address to a hostname), not for forward resolution of a hostname to an IPv6 address. Option C is wrong because an A record maps a hostname to an IPv4 address, not an IPv6 address. Option D is wrong because a CNAME record creates an alias from one hostname to another canonical hostname, and does not directly provide an IP address mapping.

112
Multi-Selecthard

A network engineer is analyzing traffic and needs to identify which applications use UDP. Which three applications commonly use UDP as their transport protocol? (Choose three.)

Select 3 answers
A.DHCP
B.SSH
C.SMTP
D.DNS
E.NTP
AnswersA, D, E

DHCP relies on UDP because clients broadcast discovery packets before obtaining an IP address, so no unicast session exists. UDP's connectionless, low-overhead delivery on ports 67/68 lets the four-step DORA exchange complete without TCP handshake delays, satisfying the requirement to identify applications that commonly use UDP.

Why this answer

DHCP (A) is correct because it uses UDP ports 67 (server) and 68 (client) for its broadcast-based DORA process, since UDP's connectionless nature suits the initial address assignment before a client has an IP. DNS (D) is correct because standard DNS queries and responses use UDP port 53 for lightweight, fast lookups, falling back to TCP only for large responses or zone transfers. NTP (E) is correct because it uses UDP port 123 for time synchronization, where occasional packet loss is acceptable and the low overhead of UDP is preferred.

SSH (B) is not correct because it relies on TCP port 22 for reliable, ordered, connection-oriented sessions. SMTP (C) is not correct because it uses TCP port 25 (and 587/465) to guarantee reliable delivery of mail messages.

Exam trap

Cisco often tests the distinction between control plane protocols (like DHCP, DNS, NTP) that use UDP for efficiency versus management or data transfer protocols (like SSH, SMTP) that require TCP's reliability, leading candidates to mistakenly associate all 'important' traffic with TCP.

113
MCQmedium

A network automation script on a Cisco IOS XE device needs to retrieve the current running configuration and then compare it against a known-good baseline stored on a Git server. The script must use a protocol that encrypts all data in transit and supports programmatic, structured retrieval of the configuration without screen-scraping. Which approach should the script use?

A.Use NETCONF over SSH on port 830 with the <get-config> operation and source <running/>.
B.Use SSH on port 22 and parse the output of the show running-config command.
C.Use SNMPv3 with authPriv to walk the ifTable and reconstruct the configuration.
D.Use Telnet on port 23 and parse the output of the show running-config command.
AnswerA

NETCONF over SSH encrypts the session and exposes configuration as structured XML, so the script can retrieve the running datastore with <get-config> and parse it reliably. It avoids parsing CLI text and matches the requirement for programmatic, structured retrieval over an encrypted transport, which is exactly what the scenario demands for automated comparison.

Why this answer

NETCONF over SSH provides an encrypted, standards-based transport on port 830 and represents configuration as structured XML in datastores. The <get-config> operation with a running source returns the device configuration in a machine-parseable form, avoiding the fragility of CLI scraping. This satisfies both the encryption requirement and the need for reliable, programmatic retrieval for baseline comparison.

Exam trap

The trap here is assuming that SSH alone makes a CLI-scraping approach acceptable, when the structured, programmatic retrieval requirement rules out parsing show running-config.

114
MCQeasy

Which of the following is a non-overlapping channel in the 2.4 GHz Wi-Fi band?

A.Channel 3
B.Channel 6
C.Channel 12
D.Channel 9
AnswerB

In the 2.4 GHz band, only channels 1, 6 and 11 are conventionally non-overlapping, each separated by five 5 MHz steps so their 22 MHz-wide signals do not overlap. Channel 6 sits between 1 and 11, satisfying the stem's non-overlapping requirement.

Why this answer

In the 2.4 GHz Wi-Fi band, channels are spaced 5 MHz apart, but each channel is 22 MHz wide. To avoid overlap, channels must be separated by at least 5 channels (25 MHz). The only non-overlapping channels in North America are 1, 6, and 11.

Channel 6 is one of these, making it the correct answer.

Exam trap

The trap here is assuming that any channel number that is a multiple of 3 (like 3, 6, 9, 12) is non-overlapping, but only 1, 6, and 11 are truly non-overlapping in the 2.4 GHz band.

How to eliminate wrong answers

Option A (Channel 3) is wrong because it overlaps with channels 1 through 6; it is not a standard non-overlapping channel. Option C (Channel 12) is wrong because it overlaps with channels 10 through 14 and is not part of the non-overlapping set (1, 6, 11) in North America. Option D (Channel 9) is wrong because it overlaps with channels 7 through 11 and is not a non-overlapping channel.

115
MCQmedium

A network administrator configures a switch port to belong to VLAN 10. Which OSI layer is primarily involved in VLAN tagging?

A.Layer 1 (Physical)
B.Layer 3 (Network)
C.Layer 2 (Data Link)
D.Layer 4 (Transport)
AnswerC

VLAN tagging inserts 802.1Q tags into Ethernet frames, which are Layer 2 constructs. The switch examines these tags to segregate broadcast domains, so VLAN membership is determined at the Data Link layer rather than Layer 3.

Why this answer

VLAN tagging is defined in IEEE 802.1Q, which operates at Layer 2 (Data Link) of the OSI model. The 802.1Q tag is inserted into the Ethernet frame header, and switches use this tag to make forwarding decisions within the same broadcast domain. Therefore, VLAN tagging is primarily a Layer 2 function.

Exam trap

200-901 often tests the OSI layer of common protocols — candidates sometimes confuse VLAN tagging with Layer 3 because VLANs are often used for subnetting, but tagging itself is strictly Layer 2.

How to eliminate wrong answers

Option A is wrong because Layer 1 deals with physical signaling, cabling, and bit transmission — it has no concept of VLAN tags. Option B is wrong because Layer 3 handles IP routing and logical addressing; while inter-VLAN routing occurs at Layer 3, the tagging itself is a Layer 2 encapsulation. Option D is wrong because Layer 4 deals with TCP/UDP ports and segmentation, which are unrelated to VLAN tagging.

116
Multi-Selecthard

A network engineer is troubleshooting a connectivity issue between two hosts on different subnets. The engineer suspects a problem with the default gateway configuration. Which two statements about default gateways are correct? (Choose two.)

Select 2 answers
A.The default gateway is used to forward packets destined for remote networks.
B.The default gateway is only used for DNS resolution.
C.The default gateway must be on the same subnet as the host.
D.A host can have multiple default gateways configured for redundancy without any additional protocols.
E.The default gateway must be a router; a Layer 3 switch cannot serve as a default gateway.
AnswersA, C

When a host determines that the destination IP is not on its local subnet, it forwards the packet to the default gateway. The gateway then routes the packet toward the destination. This is the primary function of a default gateway in IP networking.

Why this answer

The default gateway must be on the same subnet as the host so that the host can reach it via ARP. It is used to forward packets destined for remote networks. Layer 3 switches can act as gateways, and multiple gateways require redundancy protocols for automatic failover.

The gateway is not limited to DNS traffic.

Exam trap

The trap here is thinking that a default gateway can be on a different subnet or that a host can automatically use multiple gateways without a redundancy protocol.

117
MCQmedium

Which HTTP method is idempotent and used to update a resource by sending the full representation?

A.PUT
B.DELETE
C.POST
D.GET
AnswerA

PUT is idempotent: repeating the same request yields the same resource state. It replaces the target resource entirely with the enclosed representation, unlike PATCH, which applies partial modifications, or POST, which is neither idempotent nor a full replacement.

Why this answer

PUT is idempotent because making the same request multiple times results in the same server state. It requires the client to send a full representation of the resource, replacing any existing resource at that URI. This aligns with RFC 7231, which defines PUT as a method that creates or replaces the target resource with the enclosed representation.

Exam trap

Cisco often tests the confusion between PUT and PATCH, where candidates mistakenly think PUT can be used for partial updates, but the question specifically asks for 'full representation,' making PUT the only correct choice.

How to eliminate wrong answers

Option B (DELETE) is wrong because while DELETE is idempotent, it is used to remove a resource, not update it by sending a full representation. Option C (POST) is wrong because POST is not idempotent; it is designed to submit data for processing (e.g., creating a subordinate resource) and repeated requests may create multiple resources. Option D (GET) is wrong because GET is idempotent and safe, but it is used to retrieve a resource, not update it.

118
Multi-Selectmedium

An engineer is comparing TCP and UDP for a new telemetry service that sends small, frequent datagrams from thousands of IoT sensors to a collector. The design prioritizes low overhead and does not require retransmission of lost readings. Which two characteristics apply to UDP in this scenario? (Choose two.)

Select 2 answers
A.It provides no delivery guarantee, so lost datagrams are simply not retransmitted.
B.It uses a smaller header than TCP, reducing per-datagram overhead.
C.It guarantees in-order delivery of datagrams to the application.
D.It performs a three-way handshake before data transmission to establish state.
E.It automatically adjusts its congestion window in response to network loss.
AnswersA, B

UDP is a best-effort transport with no acknowledgments or retransmission timers. For thousands of sensors sending frequent small readings where the design explicitly tolerates loss, this fire-and-forget behavior eliminates the overhead and latency that TCP's reliability mechanisms would add, which matches the stated priorities.

Why this answer

UDP's value in high-volume telemetry is its minimal overhead and connectionless, best-effort model. The small fixed header reduces cost per datagram, and the absence of acknowledgments and retransmissions means lost readings are simply dropped, which the design accepts. Ordering, reliability, and congestion control are all absent and would have to be added at the application layer if required.

Exam trap

The trap here is assuming that a transport used for many sensors must be reliable, when UDP deliberately omits retransmission and ordering to keep overhead low for loss-tolerant data.

119
MCQmedium

A network administrator is configuring a new subnet for a branch office that requires at least 50 usable host addresses. Which subnet mask would meet this requirement while minimizing address waste?

A.255.255.255.0 (/24)
B.255.255.255.128 (/25)
C.255.255.255.224 (/27)
D.255.255.255.192 (/26)
AnswerD

A /26 mask leaves 6 host bits, yielding 62 usable addresses after reserving network and broadcast, which satisfies the 50-host minimum. Smaller masks such as /25 waste 64 addresses unnecessarily, while /27 provides only 30 usable hosts and fails the requirement.

Why this answer

A /26 subnet provides 62 usable hosts (2^6 - 2 = 62), which is the smallest subnet meeting the requirement of 50 hosts.

120
MCQhard

In the context of SDN, which API allows a network controller to communicate with the forwarding plane of network devices?

A.Eastbound API
B.Northbound API
C.REST API
D.Southbound API
AnswerD

Southbound APIs sit between the controller and the forwarding plane, carrying instructions such as OpenFlow flow-mod messages that program device forwarding tables. Northbound APIs instead expose controller capabilities upward to applications, so only the southbound interface satisfies the stem's requirement to reach network devices directly.

Why this answer

The Southbound API is used by an SDN controller to communicate with the forwarding plane (data plane) of network devices, such as switches and routers. It allows the controller to program the forwarding behavior of these devices. Northbound APIs are used for communication with applications, and eastbound/westbound APIs are used for controller-to-controller communication.

Exam trap

200-901 often tests SDN API directions, and candidates may confuse northbound and southbound. The trap is remembering that southbound goes down to the devices, while northbound goes up to applications.

How to eliminate wrong answers

Option A is wrong because Eastbound API is used for communication between SDN controllers, not with the forwarding plane. Option B is wrong because Northbound API is used for communication between the SDN controller and applications, not the forwarding plane. Option C is wrong because REST API is a general API style that can be used for northbound or southbound, but it is not specific to the controller-forwarding plane communication; the question asks for the API type, and Southbound is the correct term.

121
MCQhard

A network engineer is designing a subnetting scheme for a company that requires 5 subnets from the 192.168.1.0/24 network. What subnet mask should be used, and how many usable hosts per subnet will be available?

A.255.255.255.192 with 62 usable hosts per subnet
B.255.255.255.224 with 30 usable hosts per subnet
C.255.255.255.240 with 14 usable hosts per subnet
D.255.255.255.248 with 6 usable hosts per subnet
AnswerB

Borrowing three host bits gives 2^3 = 8 subnets, satisfying the five-subnet requirement, with mask 255.255.255.224. Each subnet then has 2^5 - 2 = 30 usable host addresses after reserving the network and broadcast addresses.

Why this answer

To get 5 subnets from 192.168.1.0/24, you need to borrow 3 bits (2^3 = 8 subnets, which covers 5). Borrowing 3 bits extends the prefix from /24 to /27, giving a subnet mask of 255.255.255.224. Each /27 subnet has 32 addresses, and after subtracting the network and broadcast addresses, 30 usable host addresses remain.

Exam trap

The trap is forgetting to subtract 2 for the network and broadcast addresses, or miscalculating the borrowed bits; candidates often pick /26 (4 subnets) thinking it's enough for 5, or choose a mask that gives too few hosts.

How to eliminate wrong answers

Option A is wrong because 255.255.255.192 is a /26 mask, which yields only 4 subnets (2^2) — insufficient for 5 — and provides 62 usable hosts. Option C is wrong because 255.255.255.240 is a /28 mask, which yields 16 subnets but only 14 usable hosts per subnet; while it meets the subnet count, it wastes address space and does not match the minimum-borrow requirement for exactly 5 subnets. Option D is wrong because 255.255.255.248 is a /29 mask, yielding 32 subnets with only 6 usable hosts each — far more subnets than needed and too few hosts for typical use.

122
MCQmedium

A network engineer captures traffic between a client and a server. The client sends a TCP segment with the SYN flag set. The server responds with a segment that has both SYN and ACK flags set. Which field in the server's response acknowledges the client's initial sequence number?

A.The window size field, set to the number of bytes the server can receive.
B.The acknowledgment number field, set to the client's initial sequence number plus one.
C.The urgent pointer field, set to indicate out-of-band data.
D.The sequence number field, set to the server's own initial sequence number.
AnswerB

In the TCP three-way handshake, the server's SYN-ACK segment acknowledges the client's SYN by setting the acknowledgment number to the client's initial sequence number (ISN) plus one. The plus-one accounts for the SYN flag consuming one sequence number. This field is what tells the client that the server received the SYN and expects the next byte from the client to be that value, completing the second step of the handshake.

Why this answer

During the TCP three-way handshake, the server's SYN-ACK segment acknowledges the client's SYN by placing the client's initial sequence number plus one in the acknowledgment number field. This confirms receipt of the SYN and establishes the client's sequence space. The sequence number field carries the server's own ISN, while window size and urgent pointer serve flow control and urgent data handling, respectively.

Exam trap

The trap here is confusing the sequence number field, which carries the sender's own ISN, with the acknowledgment number field, which confirms the peer's sequence number during the handshake.

123
MCQmedium

A network engineer is using a REST API to retrieve a list of network devices from a controller. The API requires authentication using a token. Which HTTP header should be used to include the token in the request?

A.Authorization
B.Accept
C.Content-Type
D.User-Agent
AnswerA

The Authorization header is used to carry credentials for authenticating the client with the server. For token-based authentication, the token is typically included as 'Bearer <token>'. This is the standard way to send authentication information in HTTP requests, and it is expected by most REST APIs.

Why this answer

For token-based authentication in REST APIs, the token is sent in the Authorization header, typically using the Bearer scheme. This header is designed to carry credentials and is processed by the server to validate the client's identity. Other headers like Content-Type and Accept serve different purposes and do not authenticate the request.

Exam trap

The trap here is confusing the Authorization header with other headers like Content-Type, which specify data format rather than credentials.

124
MCQmedium

A developer is writing a Python script that must retrieve the current operational state of a Cisco IOS XE device through its RESTCONF API. The device uses YANG models, and the script must read interface statistics without altering the configuration. Which HTTP method should the script use, and what is the correct URL structure?

A.Use POST with the URL https://<device>/restconf/data/ietf-interfaces:interfaces
B.Use PUT with the URL https://<device>/restconf/data/ietf-interfaces:interfaces
C.Use GET with the URL https://<device>/restconf/operations/ietf-interfaces:interfaces
D.Use GET with the URL https://<device>/restconf/data/ietf-interfaces:interfaces
AnswerD

GET is the correct HTTP method for retrieving data without side effects. In RESTCONF, the /restconf/data path accesses the datastore, and the module-qualified name ietf-interfaces:interfaces identifies the YANG container. A GET returns the configured and operational state of interfaces, matching the requirement to read statistics without altering configuration.

Why this answer

RESTCONF uses HTTP methods that map to CRUD operations: GET reads data, POST creates, PUT replaces, and DELETE removes. To read interface statistics without modifying configuration, the script must use GET against the data resource identified by the module-qualified YANG container. The URL must include /restconf/data and the correct module prefix to locate the interfaces container in the datastore.

Exam trap

The trap here is assuming that any HTTP method can read data as long as the URL points to the interfaces container, when only GET is safe and idempotent for retrieval.

125
MCQeasy

A developer is using the Python requests library to call a REST API on a Cisco DNA Center controller. The API requires a token for authentication. The developer writes code to obtain the token and then call the network-device endpoint. Which HTTP header must be included in the second request to authenticate using the token?

A.Authorization: Bearer <token>
B.Cookie: JSESSIONID=<token>
C.Authorization: Basic <base64-encoded-credentials>
D.X-Auth-Token: <token>
AnswerD

Cisco DNA Center uses a custom header X-Auth-Token to carry the authentication token obtained from the /dna/system/api/v1/auth/token endpoint. After a successful login, the response includes a Token field, which must be placed in the X-Auth-Token header for subsequent API calls. This is the correct way to authenticate to DNA Center's REST API.

Why this answer

Cisco DNA Center's REST API uses a token-based authentication mechanism. After obtaining the token from the authentication endpoint, the developer must include it in the X-Auth-Token header of subsequent requests. This header is specific to DNA Center and differs from standard Authorization headers used by other APIs.

Exam trap

The trap here is assuming that all token-based APIs use the standard Authorization: Bearer header, when Cisco DNA Center specifically requires the X-Auth-Token header.

← PreviousPage 2 of 2 · 125 questions total

Ready to test yourself?

Try a timed practice session using only Network Fundamentals questions.