Courseiva

CCNA Devnet Network Fundamentals Questions

75 of 125 questions · Page 1/2 · Devnet Network Fundamentals topic · Answers revealed

1
MCQhard

In an SDN architecture, which API is used by the controller to communicate with network devices to install forwarding rules?

AnswerA

The southbound API connects the SDN controller downward to forwarding devices, programming flow tables and installing forwarding rules. This satisfies the requirement to communicate with network devices, whereas northbound APIs face applications and management planes.

Why this answer

In SDN, the southbound API is the interface between the controller and the network devices (switches, routers). It allows the controller to install forwarding rules, such as flow entries in OpenFlow switches, enabling centralized control of the data plane.

Exam trap

Cisco often tests the distinction between northbound and southbound APIs; the trap here is confusing the REST API (commonly northbound) with the southbound API that directly programs device forwarding tables.

How to eliminate wrong answers

Option B (REST API) is wrong because REST APIs are typically used as northbound APIs for applications to communicate with the SDN controller, not for the controller to program network devices. Option C (East-West API) is wrong because east-west APIs are used for communication between multiple SDN controllers in a distributed control plane, not for device rule installation. Option D (Northbound API) is wrong because northbound APIs allow applications and orchestration tools to interact with the controller, abstracting the underlying network; they do not directly install forwarding rules on devices.

2
MCQmedium

A network administrator is configuring DNS for a corporate domain. An MX record is required to specify the mail server responsible for handling email. Which of the following is a correct example of an MX record?

A.mail.example.com. A 192.0.2.1
B.example.com. MX 10 mail.example.com.
C.example.com. CNAME mail.example.com.
D.example.com. TXT "v=spf1 include:_spf.google.com ~all"
AnswerB

The record maps the domain to mail.example.com with preference 10, the standard MX syntax of priority followed by mail exchanger. This satisfies the requirement to name the mail server handling email for the corporate domain, since MX records exist solely to direct SMTP delivery.

Why this answer

An MX record specifies the mail server responsible for handling email for a domain, using the format: domain. MX priority mailserver. The priority value (10) indicates preference, with lower values being higher priority.

This record directs email delivery to mail.example.com for the example.com domain.

Exam trap

Cisco often tests the distinction between record types by presenting an A or CNAME record as a distractor, exploiting the common misconception that any record pointing to a mail server is sufficient for email routing.

How to eliminate wrong answers

Option A is wrong because it uses an 'A' record type, which maps a hostname to an IPv4 address, not a mail exchanger; MX records require the 'MX' type and a priority value. Option C is wrong because a CNAME record creates an alias for a hostname, but MX records cannot point to a CNAME per RFC 2181; they must point directly to an A or AAAA record. Option D is wrong because a TXT record stores text data like SPF policies, not mail server routing information; MX records are specifically for mail exchange.

3
Multi-Selecthard

A network engineer is analyzing traffic patterns and wants to identify characteristics of UDP that affect real-time applications such as VoIP and video streaming. Which two characteristics of UDP make it suitable for these applications? (Choose two.)

Select 2 answers
A.Ordered delivery of packets
B.Guaranteed delivery of packets
C.Low overhead due to a minimal header
D.Connectionless communication
E.Built-in congestion control
AnswersC, D

UDP has a fixed 8-byte header, which is much smaller than TCP's minimum 20-byte header. This reduces overhead and processing time, making it ideal for real-time applications where speed is critical and small delays are unacceptable. The minimal header contributes to lower latency and higher throughput.

Why this answer

UDP is suitable for real-time applications because it has low overhead from a minimal header and is connectionless, which reduces latency. These characteristics allow VoIP and video streaming to prioritize speed over reliability, as retransmissions would cause unacceptable delays.

Exam trap

The trap here is assuming that UDP provides reliability features like guaranteed delivery or ordered delivery, which it does not; those are TCP characteristics.

4
MCQmedium

An application requires reliable, ordered delivery of data with error checking. Which transport protocol should be used, and what is a key characteristic of this protocol?

A.TCP, because it uses a 3-way handshake to establish a connection
B.TCP, because it has lower overhead than UDP
C.UDP, because it is connectionless and low-overhead
D.UDP, because it provides flow control
AnswerA

TCP satisfies the ordered, error-checked delivery requirement through sequence numbers, acknowledgements and retransmission of lost segments. The three-way handshake (SYN, SYN-ACK, ACK) establishes that reliable connection before data flows, directly meeting the stem's demand for dependable, in-order transport rather than best-effort delivery.

Why this answer

TCP (Transmission Control Protocol) is the correct choice because it provides reliable, ordered delivery of data with error checking. Its key characteristic is the 3-way handshake (SYN, SYN-ACK, ACK) used to establish a connection before data transfer, ensuring both endpoints are synchronized and ready for reliable communication.

Exam trap

Cisco often tests the misconception that TCP has lower overhead than UDP, or that UDP provides reliability or flow control, leading candidates to confuse the characteristics of connection-oriented vs. connectionless protocols.

How to eliminate wrong answers

Option B is wrong because TCP has higher overhead than UDP due to its connection establishment, acknowledgments, and sequencing mechanisms, not lower overhead. Option C is wrong because UDP is connectionless and low-overhead, but it does not provide reliable, ordered delivery or error checking—it offers no guarantees for delivery or ordering. Option D is wrong because UDP does not provide flow control; flow control is a feature of TCP, implemented via sliding window and advertised window mechanisms.

5
MCQhard

During a TCP three-way handshake, which sequence of flags is sent from the client to initiate the connection?

A.SYN-ACK
B.SYN
C.ACK
D.FIN
AnswerB

The client begins the three-way handshake by transmitting a single TCP segment with the SYN flag set, carrying its initial sequence number. This synchronises sequence numbers and requests a connection before the server replies with SYN-ACK. Only after the client's final ACK does the connection become established, satisfying the initiation requirement.

Why this answer

The client sends a SYN segment to start the handshake.

6
MCQmedium

An application needs to discover the MAC address of another device on the same local network. Which protocol does it use?

AnswerC

ARP broadcasts a request containing the target IPv4 address, and the owning device replies with its MAC address. This resolves layer-3 to layer-2 addressing within the same broadcast domain, which is exactly what the application needs.

Why this answer

ARP (Address Resolution Protocol) is used to map an IP address to a MAC address on a local network.

7
MCQeasy

In the OSI model, which layer is responsible for logical addressing and routing of packets between networks?

A.Layer 1 (Physical)
B.Layer 3 (Network)
C.Layer 4 (Transport)
D.Layer 2 (Data Link)
AnswerB

Layer 3 provides logical addressing through IP addresses and determines packet forwarding between networks via routing protocols and routing tables. This satisfies the question's requirement, distinguishing it from Layer 2, which handles physical MAC addressing and local frame delivery.

Why this answer

Layer 3 (Network) of the OSI model handles logical addressing (IP addresses) and routing of packets between different networks via routers. Layer 2 uses physical MAC addresses for local delivery, and Layer 4 handles end-to-end transport (TCP/UDP ports and segmentation). Thus Layer 3 is the correct answer.

Exam trap

The trap here is confusing Layer 2 MAC addressing with Layer 3 logical addressing, or assuming Layer 4 handles routing because it deals with end-to-end communication.

How to eliminate wrong answers

Option A is wrong because Layer 1 (Physical) deals with raw bit transmission over media, not addressing or routing. Option C is wrong because Layer 4 (Transport) provides end-to-end delivery, flow control, and port-based multiplexing (TCP/UDP), not logical addressing or routing. Option D is wrong because Layer 2 (Data Link) uses MAC addresses for node-to-node delivery within the same broadcast domain and does not route between networks.

8
Multi-Selecteasy

Which TWO of the following protocols use UDP as the transport layer protocol? (Choose two.)

Select 2 answers
AnswersA, C

DNS queries use UDP on port 53 for standard resolution, avoiding TCP's handshake overhead for small request-response exchanges. This connectionless transport matches the protocol's need for fast, lightweight lookups, though it falls back to TCP for large responses.

Why this answer

DNS (A) is correct because standard DNS queries and responses use UDP on port 53, since the small request/response exchange benefits from UDP's low overhead and the application handles retransmission itself. DHCP (C) is correct because DHCP operates over UDP, using ports 67 (server) and 68 (client) for its broadcast-based DORA (Discover, Offer, Request, Acknowledge) message exchange. HTTP (B) is not correct because HTTP uses TCP, typically on port 80 or 443, to guarantee ordered and reliable delivery of web content.

SMTP (D) is not correct because SMTP uses TCP on port 25 (or 587/465) to reliably transfer mail between servers. SSH (E) is not correct because SSH uses TCP on port 22 to provide a reliable, encrypted interactive session.

Exam trap

The trap is assuming DNS is TCP-only because of zone transfers, or forgetting that DHCP is UDP — candidates often pick HTTP or SMTP by reflex when asked about 'common protocols.'

9
MCQmedium

In the TCP three-way handshake, which sequence of flags is exchanged to establish a connection?

A.SYN, ACK, SYN-ACK
B.ACK, SYN, SYN-ACK
C.SYN-ACK, SYN, ACK
D.SYN, SYN-ACK, ACK
AnswerD

The SYN, SYN-ACK, ACK exchange establishes a TCP connection by synchronising sequence numbers in both directions. The client sends SYN, the server replies SYN-ACK acknowledging it while sending its own SYN, then the client returns ACK. This satisfies the stem's requirement for the exact flag sequence of the three-way handshake.

Why this answer

The TCP three-way handshake begins with the client sending a SYN packet to the server, the server responds with a SYN-ACK acknowledging the client's SYN and sending its own SYN, and the client completes with an ACK. This sequence establishes a reliable, bidirectional connection and synchronizes sequence numbers. The correct order is SYN, SYN-ACK, ACK.

Exam trap

200-901 often tests the exact flag order of the handshake, so candidates who confuse the server's SYN-ACK with a separate ACK pick option A.

How to eliminate wrong answers

Option A is wrong because SYN, ACK, SYN-ACK reverses the server's response — the server sends a single SYN-ACK, not a separate ACK then SYN-ACK. Option B is wrong because ACK, SYN, SYN-ACK starts with an ACK, which is not how a new connection is initiated. Option C is wrong because SYN-ACK, SYN, ACK has the server initiating with SYN-ACK before the client sends SYN, which is backwards.

10
MCQeasy

Which transport protocol is connection-oriented and ensures reliable delivery through acknowledgments and retransmissions?

A.IP
C.TCP
D.UDP
AnswerC

TCP establishes a session via a three-way handshake before data transfer, then uses sequence numbers, acknowledgments and retransmission of lost segments to guarantee ordered, reliable delivery. This connection-oriented design directly satisfies the stem's requirement for acknowledged, retransmitted transport, unlike connectionless UDP.

Why this answer

TCP is connection-oriented: it establishes a session via the three-way handshake (SYN, SYN-ACK, ACK), then guarantees reliable, ordered delivery using sequence numbers, acknowledgments, and retransmission of lost segments. These mechanisms ensure data arrives intact and in order.

Exam trap

The trap is conflating application-layer protocols like HTTP with transport-layer reliability — candidates must recognize that HTTP's reliability is inherited from TCP, not inherent to HTTP itself.

How to eliminate wrong answers

Option A is wrong because IP is a connectionless, best-effort network-layer protocol that provides no reliability, ordering, or acknowledgment — it merely routes packets. Option B is wrong because HTTP is an application-layer protocol that relies on TCP (or QUIC) for transport; it does not itself provide reliability or acknowledgments. Option D is wrong because UDP is connectionless and unreliable — it sends datagrams without handshakes, acknowledgments, or retransmission, making it suitable for latency-sensitive traffic like VoIP and DNS.

11
Multi-Selecthard

A DevOps engineer is automating network configuration using REST APIs. The engineer needs to choose between NETCONF and OpenFlow as southbound protocols. Which TWO statements are correct?

Select 2 answers
A.OpenFlow allows the controller to install flow entries in switches
B.NETCONF provides real-time packet forwarding control
C.Both protocols are used exclusively for northbound APIs
D.OpenFlow is primarily used for configuration management
E.NETCONF uses YANG data models and XML encoding
AnswersA, E

OpenFlow is a southbound protocol where the controller pushes match-action flow entries directly into switch flow tables, governing forwarding behaviour. This programmatic control of forwarding matches the automation scenario, distinguishing it from NETCONF's configuration-focused role.

Why this answer

Option A is correct because OpenFlow is a southbound protocol in SDN in which the controller pushes flow entries (match/action rules) into the flow tables of OpenFlow-enabled switches to dictate forwarding behavior. Option E is correct because NETCONF is a configuration protocol that models device data with YANG and encodes messages in XML over SSH (port 830), making it well suited for automated configuration management. Option B is wrong because NETCONF handles configuration and state retrieval, not real-time per-packet forwarding control, which is OpenFlow's role.

Option C is wrong because both NETCONF and OpenFlow are southbound protocols, not northbound APIs. Option D is wrong because OpenFlow is primarily a forwarding-plane control protocol, whereas configuration management is NETCONF's domain.

12
MCQmedium

A developer runs `python -c "import requests; r=requests.get('https://api.example.com/v1/status'); print(r.json())"` on a Linux host. The command returns a JSON payload instantly, but when the same request is sent to `http://api.example.com/v1/status` the client hangs and later times out with no response. Which network-layer behavior best explains why the HTTPS URL succeeds while the HTTP URL fails?

A.HTTP/1.1 requires a three-way handshake that TCP port 443 avoids by using UDP.
B.TCP port 80 is filtered by an intermediate device, while TCP port 443 is permitted.
C.The server's default gateway is missing, so replies to port 80 are dropped.
D.The DNS A record for api.example.com resolves only for TLS connections.
AnswerB

The client hangs on port 80 and times out, which is the classic signature of silently dropped TCP SYN segments on an ACL or firewall policy. Because the same hostname and application reach the service over 443, routing and name resolution are already proven correct, so the only variable left is the destination port being filtered between client and server.

Why this answer

The only difference between the two attempts is the destination port: 443 succeeds and 80 times out. When a TCP connection times out rather than receiving an immediate RST, an intermediate firewall or ACL is silently discarding the SYN. Because the hostname resolved and the encrypted session completed, name resolution and routing are functioning, leaving port-level filtering as the cause.

Exam trap

The trap here is assuming HTTPS is inherently more reliable or uses a different transport, when the real difference is that port 80 is being silently blocked while port 443 is allowed.

13
MCQeasy

A developer runs a Python script that uses the requests library to call a REST API endpoint. The script receives an HTTP 401 Unauthorized response. The developer confirms the URL is correct and the server is reachable. Which action should the developer take to resolve the issue?

A.Verify that the API endpoint URL includes the correct query parameters.
B.Change the HTTP method from GET to POST.
C.Increase the request timeout value in the Python script.
D.Include a valid authentication token in the request's Authorization header.
AnswerD

A 401 Unauthorized response indicates that the request lacks valid authentication credentials for the target resource. The developer must supply a proper token, such as a Bearer token, in the Authorization header. Adding the header allows the server to authenticate the client and return a successful response, assuming the token has the required permissions.

Why this answer

An HTTP 401 Unauthorized status means the request lacks valid authentication credentials. The developer must provide a valid token or credentials, typically in the Authorization header. Changing the method, query parameters, or timeout does not address the authentication failure, so including a valid token is the correct resolution.

Exam trap

The trap here is assuming that a 401 error is caused by an incorrect URL or method rather than missing or invalid authentication credentials.

14
Multi-Selectmedium

Which TWO of the following are southbound protocols in SDN?

Select 2 answers
B.NETCONF
D.OpenFlow
AnswersB, D

NETCONF is a southbound protocol: the SDN controller uses it to configure and retrieve state from managed network devices. It runs over SSH and exchanges XML-encoded configuration data, sitting below the controller in the architecture, which satisfies the stem's southbound requirement.

Why this answer

NETCONF (B) is correct because it is a southbound protocol used between an SDN controller and managed network devices, allowing configuration data to be retrieved, edited, and committed via YANG-modeled operations over SSH. OpenFlow (D) is correct because it is the classic southbound protocol that lets an SDN controller program the forwarding tables of switches in the data plane. OSPF (A) is a routing protocol used between routers to exchange topology information, not a controller-to-device SDN southbound interface.

SNMP (C) is a network management protocol for monitoring and managing devices, but it is not the standard SDN southbound control protocol. REST (E) is typically a northbound API style used by applications to communicate with the SDN controller, not a southbound protocol.

Exam trap

The trap is confusing northbound with southbound — REST and SNMP are commonly (mis)selected as southbound, but REST is northbound and SNMP is a management protocol, not a controller-to-data-plane SDN interface.

15
MCQeasy

What is the primary function of a switch in a network?

A.Forward frames based on MAC addresses
B.Amplify wireless signals
C.Forward packets based on IP addresses
D.Convert data to electrical signals
AnswerA

Forwarding frames by MAC address is the defining function of a Layer 2 switch, satisfying the stem's requirement for the primary role. It builds a MAC address table from source addresses and forwards each frame only out the port leading to the destination, rather than flooding every port as a hub does.

Why this answer

Switches operate at Layer 2 and forward frames based on MAC addresses within a LAN.

16
MCQmedium

Which DNS record type is used to verify domain ownership for email security (SPF) and is stored as a text string?

A.TXT record
B.CNAME record
C.A record
D.MX record
AnswerA

TXT records hold arbitrary text strings, which is exactly how SPF policies are published: a domain owner adds a TXT record containing the authorised sending hosts. This satisfies the stem's requirement for verifying domain ownership for email security while being stored as text.

Why this answer

TXT records store arbitrary text strings and are the record type used for SPF (Sender Policy Framework), DKIM, and domain verification. SPF is published as a TXT record containing a list of authorized sending hosts, allowing receiving mail servers to verify that email originates from approved sources.

Exam trap

200-901 often tests whether candidates confuse MX records (which route inbound mail) with TXT records (which store SPF/DKIM/DMARC policies), causing them to pick MX when the question mentions email security.

How to eliminate wrong answers

Option B is wrong because a CNAME record creates an alias from one domain name to another — it cannot store the text string required for SPF. Option C is wrong because an A record maps a hostname to an IPv4 address; it has no text payload capability. Option D is wrong because an MX record specifies mail exchange servers for a domain — it directs where email should be delivered, not which hosts are authorized to send email on behalf of the domain.

17
Multi-Selecthard

A network engineer is deploying a new application that requires low-latency, high-throughput communication between two data centers. The engineer decides to use UDP instead of TCP for the application's transport protocol. Which two characteristics of UDP make it suitable for this scenario? (Choose two.)

Select 2 answers
A.UDP guarantees packet ordering and delivery.
B.UDP provides reliable delivery through acknowledgments and retransmissions.
C.UDP has a smaller header size compared to TCP, reducing bandwidth overhead.
D.UDP performs congestion control to avoid network congestion.
E.UDP has lower overhead because it does not establish a connection before sending data.
AnswersC, E

The UDP header is 8 bytes, while the TCP header is at least 20 bytes. This smaller header reduces per-packet overhead, which can improve efficiency for high-throughput applications. In scenarios where many small packets are sent, the reduced overhead can lead to better bandwidth utilization and lower latency.

Why this answer

UDP is suitable for low-latency, high-throughput communication because it is connectionless, avoiding the overhead of establishing and maintaining a connection, and it has a smaller header size, reducing per-packet overhead. These characteristics make UDP ideal for real-time applications where speed is critical and some packet loss is tolerable. The other options describe features of TCP or incorrectly attribute reliability and congestion control to UDP.

Exam trap

The trap here is assuming that UDP provides reliability or ordering, which are TCP features, or that its lack of congestion control is always beneficial without considering network conditions.

18
MCQeasy

A network administrator needs to assign IP addresses to devices on a subnet with a /25 prefix. How many usable host addresses are available?

A.254
B.126
C.64
D.128
AnswerB

A /25 prefix leaves 7 host bits (32 − 25), giving 2⁷ = 128 total addresses. Subtracting the network and broadcast addresses yields 126 usable host addresses, satisfying the subnet's requirement. This matches the standard formula 2^h − 2, where h is the number of host bits available.

Why this answer

A /25 subnet has 7 bits for hosts (32-25=7), giving 2^7 = 128 total addresses, minus 2 (network and broadcast) = 126 usable hosts.

19
Multi-Selecthard

Which THREE of the following are features of HTTP/2?

Select 3 answers
A.Header compression (HPACK)
B.Plain text headers
C.Persistent connections
D.Binary framing
E.Multiplexed streams
AnswersA, D, E

HPACK compresses request and response header fields using static and dynamic tables plus Huffman coding, cutting the repeated header overhead that plagued HTTP/1.1. This satisfies HTTP/2's requirement for reduced latency over many concurrent streams, since headers previously dominated each request's bytes.

Why this answer

HTTP/2 introduces HPACK header compression (option A), which reduces overhead by compressing header fields using a static table, a dynamic table, and Huffman encoding, making it a defining feature of the protocol. It also uses binary framing (option D), splitting communication into binary-encoded frames (HEADERS, DATA, SETTINGS, etc.) instead of HTTP/1.1's textual format, which enables more efficient parsing and processing. Multiplexed streams (option E) allow many concurrent request/response exchanges over a single TCP connection, eliminating HTTP/1.1's head-of-line blocking at the application layer.

Option B is incorrect because HTTP/2 headers are binary-encoded, not plain text, and option C is incorrect because persistent connections already existed in HTTP/1.1 and are not a new or distinguishing feature of HTTP/2.

20
Multi-Selecthard

An organization is planning to implement HTTPS for their web services. Which three statements accurately describe the HTTPS protocol? (Choose three.)

Select 3 answers
A.HTTPS uses UDP as the transport protocol.
B.HTTPS uses TLS to encrypt HTTP traffic.
C.HTTPS is stateless after the initial handshake.
D.HTTPS uses a certificate to verify the server's identity.
E.HTTPS negotiates a symmetric session key for encryption.
AnswersB, D, E

HTTPS secures HTTP by layering Transport Layer Security beneath it, so all request and response data is encrypted in transit. This satisfies the stem's requirement to describe the protocol accurately: TLS provides confidentiality and integrity, preventing eavesdropping or tampering between client and server.

Why this answer

HTTPS uses TLS for encryption, involves certificate verification, and negotiates a symmetric session key. It does not use UDP typically (TCP is used) and it is not stateless after the handshake.

21
MCQeasy

What is the primary benefit of using HTTP/2 over HTTP/1.1?

A.It is connectionless
B.It uses plain text for headers
C.It eliminates the need for TLS
D.It supports multiplexing
AnswerD

HTTP/2 introduces binary framing with streams, letting many concurrent requests and responses share one TCP connection. HTTP/1.1 requires separate connections or serialised pipelining, so head-of-line blocking delays later requests. Multiplexing removes that per-connection queueing, which is the primary performance gain.

Why this answer

HTTP/2 introduces binary framing with a multiplexing layer that allows many concurrent request/response streams to share a single TCP connection. This eliminates HTTP/1.1's head-of-line blocking at the application layer and reduces the need for multiple parallel connections or domain sharding. Multiplexing is the headline feature that delivers HTTP/2's performance gains over HTTP/1.1.

Exam trap

The trap here is confusing HTTP/2's TCP-based multiplexing with HTTP/3's connectionless QUIC transport — candidates who see 'connectionless' may incorrectly associate it with modern HTTP performance features.

How to eliminate wrong answers

Option A is wrong because HTTP/2, like HTTP/1.1, runs over TCP and is connection-oriented; 'connectionless' describes UDP-based protocols such as HTTP/3 (QUIC), not HTTP/2. Option B is wrong because HTTP/2 uses a binary framing layer, not plain-text headers — HPACK compresses headers into binary form, which is a key efficiency gain over HTTP/1.1's plain-text headers. Option C is wrong because HTTP/2 does not eliminate TLS; while the spec technically permits cleartext h2c, all major browsers require TLS (h2 over ALPN), so TLS remains essential.

22
MCQmedium

A network automation engineer is using the NETCONF protocol to configure a Cisco IOS XE device. The engineer sends an <edit-config> RPC with a candidate datastore, but the configuration does not take effect until a <commit> operation is performed. Which NETCONF capability must be supported by the device to allow this workflow?

A.urn:ietf:params:netconf:capability:candidate:1.0
B.urn:ietf:params:netconf:capability:rollback-on-error:1.0
C.urn:ietf:params:netconf:capability:confirmed-commit:1.0
D.urn:ietf:params:netconf:capability:writable-running:1.0
AnswerA

The candidate datastore capability allows a device to support a candidate configuration that can be edited and then committed to the running datastore. This matches the workflow described, where changes are made to a candidate and only applied after a commit. Without this capability, the device would not support the candidate datastore, and the <edit-config> targeting candidate would fail.

Why this answer

The candidate datastore capability enables a two-step configuration process where changes are made to a candidate datastore and then applied to the running datastore via a commit. This is exactly the workflow described. The other capabilities provide additional features like confirmed commit, direct running edits, or error rollback, but they are not the fundamental requirement for using a candidate datastore.

Exam trap

The trap here is confusing the candidate datastore capability with related features like confirmed-commit or rollback-on-error, which are not required to use a candidate datastore.

23
Multi-Selecthard

Which THREE of the following are true about HTTP/2 compared to HTTP/1.1? (Select three.)

Select 3 answers
A.Text-based protocol
B.Requires TLS/SSL encryption
C.Header compression using HPACK
D.Server push capability
E.Multiplexing multiple streams over a single connection
AnswersC, D, E

HTTP/2 compresses request and response header fields with HPACK, which uses static and dynamic tables plus Huffman coding. HTTP/1.1 sends headers as uncompressed plaintext on every request, so repetitive headers waste bandwidth that HPACK eliminates.

Why this answer

Option C is correct because HTTP/2 introduces HPACK (RFC 7541), a header compression scheme that uses static and dynamic tables plus Huffman encoding to shrink repetitive header fields, which HTTP/1.1 sends uncompressed as plain text on every request. Option D is correct because HTTP/2 adds server push, allowing the server to proactively send resources (e.g., via PUSH_PROMISE frames) that the client will likely need, a feature absent from HTTP/1.1. Option E is correct because HTTP/2 multiplexes many concurrent streams over one TCP connection using binary framing, eliminating HTTP/1.1's head-of-line blocking at the request level and its need for multiple parallel connections.

Option A is wrong because HTTP/2 is a binary protocol, whereas HTTP/1.1 is text-based. Option B is wrong because HTTP/2 does not mandate TLS; it can run over cleartext TCP (h2c), although browsers only implement it over TLS.

24
MCQhard

A network engineer is analyzing a packet capture and notices that a host is sending a TCP segment with the SYN flag set and the ACK flag not set. The destination port is 443. Which of the following best describes what the host is attempting to do?

A.The host is terminating an existing TCP connection to port 443.
B.The host is acknowledging a previous SYN-ACK and completing the three-way handshake.
C.The host is initiating a TCP connection to a server on port 443.
D.The host is responding to an incoming connection request on port 443.
AnswerC

A TCP segment with the SYN flag set and the ACK flag not set is the first step of the three-way handshake, used to initiate a connection. The destination port 443 indicates the host is attempting to connect to an HTTPS service. This is the standard behavior for a client opening a TCP connection to a web server.

Why this answer

The SYN flag without ACK is used to initiate a TCP connection. When a host sends a segment with SYN set and ACK not set to port 443, it is starting the three-way handshake to establish a connection to an HTTPS server. The server would respond with a SYN-ACK, and the client would complete the handshake with an ACK.

This is fundamental TCP behavior.

Exam trap

The trap here is confusing the initial SYN with other TCP flags or handshake steps, such as SYN-ACK or ACK, which have different flag combinations.

25
MCQmedium

In Software-Defined Networking (SDN), which interface is used for communication between the controller and the network devices (e.g., switches) to forward traffic?

B.Control plane
D.East-West API
AnswerC

The southbound API connects the SDN controller to underlying switches, letting it push flow rules and forwarding instructions directly to the data plane. This satisfies the stem's requirement for controller-to-device communication, whereas northbound interfaces serve applications and management layers instead.

Why this answer

The southbound API (e.g., OpenFlow, NETCONF) is used to communicate between the SDN controller and the data plane devices.

26
Multi-Selectmedium

Which TWO of the following are characteristics of UDP compared to TCP? (Select two.)

Select 2 answers
A.Ordered data delivery
B.Reliable delivery with retransmission
C.Connection-oriented communication
D.Lower overhead
E.No flow control or congestion control
AnswersD, E

UDP's eight-byte header, versus TCP's minimum twenty bytes, cuts per-packet overhead, satisfying the stem's comparison of protocol characteristics. Omitting handshakes, acknowledgements and congestion control further reduces processing and bandwidth cost, which suits latency-sensitive traffic that tolerates loss.

Why this answer

Option D (Lower overhead) is correct because UDP has a fixed 8-byte header containing only source port, destination port, length, and checksum, with no sequence/acknowledgment fields, handshake, or connection state, whereas TCP's 20-byte (or larger) header and connection tracking add significant overhead. Option E (No flow control or congestion control) is correct because UDP simply sends datagrams without windowing, slow-start, or congestion-avoidance algorithms, so it does not throttle the sender based on receiver capacity or network congestion. Options A, B, and C are TCP characteristics: TCP provides ordered delivery via sequence numbers, reliable delivery with acknowledgments and retransmission, and connection-oriented communication via the three-way handshake, none of which UDP offers.

27
MCQeasy

A developer is using a REST API to retrieve data from a network controller. The API requires the client to include an API key in the HTTP request header for authentication. Which HTTP header is typically used to carry the API key?

A.User-Agent
B.Content-Type
C.Accept
D.Authorization
AnswerD

The Authorization header is the standard HTTP header used to carry credentials for authenticating a client with a server. When using an API key, it is common to include it in the Authorization header, often with a scheme like Bearer or Basic. This header is designed specifically for authentication and is the correct choice for passing an API key.

Why this answer

The Authorization header is the standard HTTP header for transmitting authentication credentials. API keys are commonly placed in this header, often with a prefix like Bearer. Other headers like Content-Type, Accept, and User-Agent serve different purposes such as content negotiation or client identification, and are not used for authentication.

Exam trap

The trap here is assuming that an API key must be sent in a custom header, when the standard Authorization header is the conventional and expected location.

28
MCQmedium

A network engineer is designing a subnet that needs to support 30 usable hosts. Which subnet mask should be used?

A.255.255.255.240 (/28)
B.255.255.255.0 (/24)
C.255.255.255.224 (/27)
D.255.255.255.192 (/26)
AnswerC

A /27 mask leaves five host bits, yielding 32 addresses minus network and broadcast, so exactly 30 usable hosts. It is the smallest subnet satisfying the stated requirement without waste, whereas /28 would provide only 14 usable addresses.

Why this answer

(255.255.255.224, /27) provides 5 host bits, yielding 2^5 = 32 total addresses per subnet. Subtracting the network and broadcast addresses leaves exactly 30 usable hosts, meeting the requirement precisely.

Exam trap

Cisco often tests the formula 2^n - 2 for usable hosts, and the trap here is that candidates may forget to subtract the network and broadcast addresses, or they may confuse the number of host bits with the subnet mask value (e.g., thinking /28 supports 16 usable hosts instead of 14).

How to eliminate wrong answers

Option A is wrong because 255.255.255.240 (/28) provides only 4 host bits, giving 2^4 - 2 = 14 usable hosts, which is insufficient for 30 hosts. Option B is wrong because 255.255.255.0 (/24) provides 8 host bits, yielding 2^8 - 2 = 254 usable hosts, which is far more than needed and wastes address space. Option D is wrong because 255.255.255.192 (/26) provides 6 host bits, giving 2^6 - 2 = 62 usable hosts, which exceeds the requirement but is not the most efficient choice for exactly 30 hosts.

29
MCQmedium

A network administrator is configuring subnetting for a new branch office that requires 50 usable host addresses per subnet. The available network is 192.168.10.0/24. What subnet mask should be used to meet the requirement with minimal waste?

A.255.255.255.128 (/25)
B.255.255.255.224 (/27)
C.255.255.255.192 (/26)
D.255.255.255.240 (/28)
AnswerC

A /26 mask yields 64 addresses, giving 62 usable hosts, which satisfies the 50-host requirement with minimal waste. Smaller masks like /25 waste over 70 addresses; larger masks like /27 provide only 30 usable hosts, falling short.

Why this answer

A /26 mask provides 62 usable hosts (2^(32-26)-2=62), which is the smallest subnet that supports 50 hosts.

30
MCQhard

A network administrator is configuring a switch and needs to segment traffic into multiple broadcast domains while also allowing communication between them. Which device or feature should be used to achieve this?

A.Port mirroring on a switch
B.STP on a switch
C.EtherChannel on a switch
D.VLANs on a switch
AnswerD

VLANs (Virtual LANs) logically segment a switch into multiple broadcast domains. Each VLAN is a separate broadcast domain. To allow communication between VLANs, a Layer 3 device (like a router or a Layer 3 switch) is required. The scenario asks for segmentation into broadcast domains, which VLANs provide.

Why this answer

VLANs are used to logically segment a switch into multiple broadcast domains. Each VLAN represents a separate broadcast domain, and devices within a VLAN can communicate at Layer 2. To enable communication between VLANs, inter-VLAN routing is needed.

STP, EtherChannel, and port mirroring do not create broadcast domains; they serve other purposes.

Exam trap

The trap here is assuming that any switch feature can segment broadcast domains, but only VLANs (and routers) can do that; features like STP or EtherChannel do not.

31
MCQhard

A network engineer is analyzing a packet capture and observes that a host sends a TCP segment with the SYN flag set, then receives a segment with both SYN and ACK flags set, and finally sends a segment with only the ACK flag set. Which TCP mechanism is being demonstrated?

A.TCP window scaling negotiation
B.TCP connection termination
C.TCP selective acknowledgment
D.TCP three-way handshake
AnswerD

The sequence of SYN, SYN-ACK, and ACK is the standard TCP three-way handshake used to establish a connection. The first host sends a SYN to initiate, the second host responds with SYN-ACK to acknowledge and synchronize, and the first host completes with an ACK. This ensures both sides are ready to communicate and agree on initial sequence numbers. The capture clearly shows this exact exchange.

Why this answer

The three segments with SYN, SYN-ACK, and ACK flags are the definitive signature of the TCP three-way handshake. This process synchronizes sequence numbers and establishes a reliable connection before data transfer begins. Other TCP mechanisms such as termination, window scaling, or selective acknowledgment involve different flags or options and occur at different stages.

Exam trap

The trap here is confusing the SYN-ACK segment as part of connection termination or as a separate mechanism, when it is actually the second step of the three-way handshake.

32
MCQeasy

A network engineer is configuring a switch and needs to assign an IP address to a VLAN interface for management purposes. The engineer wants to ensure that devices on different VLANs can communicate through the switch. Which feature must be enabled on the switch to allow inter-VLAN routing?

A.Link Aggregation Control Protocol (LACP)
B.Spanning Tree Protocol (STP)
C.Port mirroring
D.IP routing
AnswerD

Enabling IP routing on a Layer 3 switch allows it to route packets between VLANs. Each VLAN interface (SVI) acts as a default gateway for hosts in that VLAN, and the switch uses its routing table to forward traffic between subnets. This is the standard method for inter-VLAN routing on modern switches.

Why this answer

Inter-VLAN routing requires a Layer 3 device to forward packets between subnets. On a Layer 3 switch, enabling IP routing allows the switch to route between VLAN interfaces (SVIs). Each SVI is configured with an IP address and acts as the gateway for hosts in that VLAN.

Without IP routing, the switch would only forward frames within the same VLAN.

Exam trap

The trap here is assuming that any switch feature that involves multiple VLANs, like trunking or STP, can enable inter-VLAN communication; only Layer 3 routing accomplishes that.

33
MCQeasy

At which layer of the OSI model do switches operate when forwarding frames based on MAC addresses?

A.Layer 1 (Physical)
B.Layer 3 (Network)
C.Layer 2 (Data Link)
D.Layer 4 (Transport)
AnswerC

Switches forward frames using MAC addresses contained in Ethernet headers, which reside at Layer 2, the Data Link layer. This satisfies the scenario's forwarding basis, distinguishing switches from Layer 3 routers that forward on IP addresses.

Why this answer

Switches operate at Layer 2 (Data Link layer) because they use MAC addresses to forward frames.

34
MCQmedium

Which TCP flag is set in the second step of the three-way handshake?

A.ACK
B.SYN and ACK
C.SYN
D.FIN
AnswerB

The second handshake step has the server responding to the client's initial SYN with its own sequence number while acknowledging the client's, so both SYN and ACK flags are set. This synchronises sequence numbers in both directions.

Why this answer

The TCP three-way handshake begins with the client sending a SYN segment to initiate a connection. In the second step, the server responds with a SYN-ACK segment, which both acknowledges the client's SYN (using the ACK flag) and synchronizes its own sequence number (using the SYN flag). This combined flag is essential for establishing a reliable, bidirectional connection.

Exam trap

Cisco often tests the misconception that the second step uses only an ACK flag, confusing it with the third step where the client sends an ACK to complete the handshake.

How to eliminate wrong answers

Option A is wrong because the ACK flag alone is used in later stages of the handshake (e.g., the third step) or in subsequent data transfers, not in the second step where both synchronization and acknowledgment are required. Option C is wrong because a pure SYN flag is only sent in the first step by the client to initiate the connection; the server must also acknowledge that SYN, so a standalone SYN in the second step would leave the client's initial sequence number unacknowledged. Option D is wrong because the FIN flag is used to gracefully terminate a connection, not to establish one; it appears in the four-way teardown process.

35
MCQmedium

An organization has a web server that needs to be reachable via both 'www.example.com' and 'example.com'. Which DNS record type should be used to make 'example.com' an alias for 'www.example.com'?

A.A record
B.MX record
C.NS record
D.CNAME record
AnswerD

A CNAME record maps one DNS name to another canonical name, so querying example.com returns www.example.com's records. This satisfies the stem's requirement for an alias rather than a duplicate A record, letting both hostnames resolve to the same web server without maintaining separate IP entries.

Why this answer

A CNAME record creates an alias that points to the canonical name. The A record points to an IP address, not another domain.

36
MCQeasy

A web application uses HTTPS to secure communications between client and server. What does HTTPS add on top of HTTP to provide encryption and authentication?

A.SSH
C.SSL/TLS
D.VPN
AnswerC

SSL/TLS operates between HTTP and TCP, encrypting the request and response payloads and authenticating the server via its certificate. Plain HTTP provides neither confidentiality nor identity verification, so layering TLS satisfies the encryption and authentication requirement.

Why this answer

HTTPS is HTTP layered over SSL/TLS, which provides encryption (confidentiality), integrity, and server authentication via X.509 certificates. TLS negotiates a session key using asymmetric cryptography, then encrypts the HTTP payload with symmetric ciphers. This is what distinguishes HTTPS from plain HTTP.

Exam trap

200-901 often tests the layering confusion — candidates may pick IPsec or VPN because they associate 'encryption' with network-layer tunnels rather than the application-layer TLS that actually secures HTTPS.

How to eliminate wrong answers

Option A is wrong because SSH is a separate protocol for secure remote shell access and file transfer — it is not used to secure HTTP traffic. Option B is wrong because IPsec operates at the network layer (Layer 3) to secure IP packets, typically for VPNs, not for application-layer HTTP encryption. Option D is wrong because a VPN tunnels traffic at the network layer but does not itself provide the application-layer encryption and certificate-based authentication that define HTTPS.

37
Multi-Selecteasy

A DevOps team is deploying a microservices application that requires both reliable data transfer and low-latency real-time communication. Which two protocols should be used for these respective requirements? (Choose two.)

Select 2 answers
AnswersC, E

TCP is reliable and connection-oriented, suitable for reliable data transfer.

Why this answer

TCP (Transmission Control Protocol) is correct for reliable data transfer because it provides connection-oriented communication with sequencing, acknowledgments, and retransmission of lost packets, ensuring data arrives intact and in order. This makes it ideal for microservices that need guaranteed delivery, such as database transactions or order processing.

Exam trap

Cisco often tests the distinction between transport-layer protocols (TCP/UDP) and application-layer protocols (HTTP), so candidates mistakenly pick HTTP for reliability instead of recognizing that HTTP relies on TCP underneath.

38
MCQeasy

A network engineer is configuring a new Cisco switch and needs to assign an IP address to a VLAN interface so that the switch can be managed remotely over the network. The engineer enters the commands: interface vlan 10, then ip address 192.168.10.2 255.255.255.0, then no shutdown. However, the interface remains down. What is the most likely cause?

A.The switch does not have any physical ports assigned to VLAN 10, so the VLAN interface is down.
B.The no shutdown command must be issued from global configuration mode, not interface configuration mode.
C.The IP address is incorrectly configured because the subnet mask should be in CIDR notation.
D.VLAN 10 has not been created on the switch.
AnswerA

A VLAN interface (SVI) remains in a down state until the VLAN is active, which requires at least one physical port to be up and assigned to that VLAN, or the VLAN to be manually activated. Without an active port in VLAN 10, the SVI cannot come up. The engineer must assign an access port to VLAN 10 and ensure it is connected and up.

Why this answer

A VLAN interface (SVI) on a Cisco switch remains down until the VLAN is active, which requires at least one physical port to be up and assigned to that VLAN. Simply creating the SVI and assigning an IP address is not enough. The engineer must assign an access port to VLAN 10 and ensure it is operational to bring the SVI up.

Exam trap

The trap here is assuming that configuring an SVI is sufficient for it to come up, ignoring the dependency on active physical ports in the VLAN.

39
MCQeasy

Which of the following is a private IPv4 address range as defined by RFC 1918?

A.192.167.0.0/16
B.169.254.0.0/16
C.10.0.0.0/8
D.172.32.0.0/12
AnswerC

10.0.0.0/8 falls within the RFC 1918 private address space, alongside 172.16.0.0/12 and 192.168.0.0/16. These ranges are non-routable on the public internet, satisfying the stem's requirement for a private IPv4 range. The /8 prefix covers 10.0.0.0 through 10.255.255.255.

Why this answer

The private IPv4 ranges are 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. 169.254.0.0/16 is link-local (APIPA).

40
MCQeasy

Which layer of the OSI model uses MAC addresses to deliver frames within the same network segment?

A.Layer 2 (Data Link)
B.Layer 1 (Physical)
C.Layer 3 (Network)
D.Layer 4 (Transport)
AnswerA

MAC addressing and frame delivery occur at the Data Link layer, which encapsulates packets into frames and uses hardware addresses to forward them between nodes on the same segment. Layer 2 therefore satisfies the stem's requirement for intra-segment delivery, unlike Layer 3's logical IP routing.

Why this answer

Layer 2 (Data Link) uses MAC addresses for local delivery.

41
MCQmedium

Which IP address is a valid host address in the 192.168.1.0/24 network?

A.192.168.1.128
B.192.168.2.1
C.192.168.1.255
D.192.168.1.0
AnswerA

192.168.1.128 falls within the 192.168.1.0/24 subnet range, satisfying the network constraint. Unlike the network address (192.168.1.0) or broadcast address (192.168.1.255), it is assignable to a host device. The /24 mask leaves 254 usable host addresses, and .128 sits comfortably inside that pool.

Why this answer

In 192.168.1.0/24, usable host addresses range from 192.168.1.1 through 192.168.1.254. The address 192.168.1.128 falls within this range and is not the network or broadcast address, so it is a valid host address. It is a normal unicast address that can be assigned to a device.

Exam trap

The trap is forgetting that the first and last addresses in any subnet are reserved — candidates often pick the broadcast (.255) or network (.0) address as a valid host.

How to eliminate wrong answers

Option B is wrong because 192.168.2.1 belongs to a different subnet (192.168.2.0/24) and is outside the 192.168.1.0/24 range entirely. Option C is wrong because 192.168.1.255 is the directed broadcast address for the /24 network and cannot be assigned to a host. Option D is wrong because 192.168.1.0 is the network address that identifies the subnet itself and is reserved, not assignable to a host.

42
MCQmedium

A developer runs a Python script that calls a REST API on a remote server. The script hangs indefinitely with no response. The developer opens a terminal and runs `curl -v https://api.example.com/status`. The output shows that the TCP three-way handshake completes, but the TLS handshake never starts. Which of the following is the most likely cause?

A.The server is not listening on port 443, so the TCP handshake should have failed.
B.A network device is intercepting the connection and terminating it before TLS negotiation.
C.A firewall is blocking outbound TCP port 80.
D.The client is using an outdated version of TLS that the server does not support.
AnswerB

When the TCP handshake completes but the TLS handshake never begins, an inline device such as a firewall, proxy, or intrusion prevention system may be accepting the TCP connection on behalf of the server and then dropping or resetting it before TLS negotiation. This behavior is typical of a device performing TCP proxy or deep packet inspection without proper TLS passthrough.

Why this answer

The key symptom is that the TCP three-way handshake succeeds but the TLS handshake never initiates. This indicates that something between the client and server is completing the TCP connection and then preventing the TLS negotiation from starting. A transparent proxy or firewall that terminates TCP connections without forwarding them can cause this exact behavior.

The other options either contradict the observed TCP success or describe failures that would occur after TLS begins.

Exam trap

The trap here is assuming that a successful TCP handshake guarantees the application-layer protocol will proceed, when an inline device can intercept and terminate the connection after TCP establishment.

43
MCQhard

A network engineer is subnetting the network 192.168.1.0/24 into subnets that each support at least 50 hosts. What subnet mask should be used?

A.255.255.255.192 (/26)
B.255.255.255.224 (/27)
C.255.255.255.240 (/28)
D.255.255.255.128 (/25)
AnswerA

A /26 mask leaves six host bits, giving 62 usable addresses, which satisfies the minimum of 50 hosts per subnet. A /27 would provide only 30 usable addresses, so 255.255.255.192 is the smallest mask that meets the requirement.

Why this answer

To support at least 50 hosts, you need 6 host bits (2^6 - 2 = 62 usable addresses). A /26 subnet mask (255.255.255.192) provides exactly 6 host bits, meeting the requirement. The original /24 network is borrowed with 2 subnet bits, yielding 4 subnets of 64 addresses each.

Exam trap

Cisco often tests the distinction between the number of host bits needed versus the number of subnet bits, and the trap here is that candidates may choose /25 because it supports more hosts, overlooking that /26 is the minimum mask that meets the 50-host requirement and is the correct answer per the question's wording.

How to eliminate wrong answers

Option B (255.255.255.224, /27) is wrong because it provides only 5 host bits (2^5 - 2 = 30 usable addresses), which is insufficient for 50 hosts. Option C (255.255.255.240, /28) is wrong because it provides only 4 host bits (2^4 - 2 = 14 usable addresses), far below the requirement. Option D (255.255.255.128, /25) is wrong because although it provides 7 host bits (126 usable addresses), it uses only 1 subnet bit, creating only 2 subnets; the question asks for subnets that each support at least 50 hosts, and while /25 meets the host count, it is not the most efficient choice and the correct answer is the smallest mask that satisfies the host requirement, which is /26.

44
MCQeasy

A developer is configuring a new application server and needs to allow HTTP traffic from web clients. Which port should be opened on the firewall to permit standard unencrypted HTTP traffic?

A.Port 80
B.Port 22
C.Port 53
D.Port 443
AnswerA

Port 80 is the default port for HTTP (Hypertext Transfer Protocol) used for unencrypted web traffic. Web servers listen on port 80 for standard HTTP requests. Opening this port on the firewall allows clients to access web content over HTTP, matching the requirement.

Why this answer

HTTP by default uses TCP port 80 for unencrypted communication. When a client makes an HTTP request to a web server, it connects to port 80 unless another port is specified. Therefore, to allow standard HTTP traffic, the firewall must permit inbound connections on port 80.

Exam trap

The trap here is mixing up port 80 (HTTP) with port 443 (HTTPS) or other common ports like 22 (SSH) and 53 (DNS).

45
MCQhard

In Software-Defined Networking (SDN), the control plane is separated from the data plane. Which of the following best describes the function of the southbound API?

A.Interface between applications and the controller
B.Interface between the controller and network devices
C.Communication between two controllers
D.Interface between the control plane and management plane
AnswerB

The southbound API connects the SDN controller downward to the physical and virtual network devices, carrying forwarding instructions such as OpenFlow flow-table entries. This directly satisfies the stem's separation of control and data planes, since the controller programmes devices through this interface.

Why this answer

Southbound API is used by the SDN controller to communicate with network devices (e.g., switches, routers) to enforce forwarding rules.

46
MCQhard

In the OSI model, which layer is responsible for session management, including establishing, maintaining, and terminating connections between applications?

A.Layer 4 (Transport)
B.Layer 7 (Application)
C.Layer 5 (Session)
D.Layer 6 (Presentation)
AnswerC

Layer 5 (Session) governs dialogue control between applications, establishing, maintaining and terminating sessions — exactly the session management the stem requires. It sits above Transport (Layer 4), which handles end-to-end delivery, and below Presentation (Layer 6), which handles formatting, so connection lifecycle management belongs here.

Why this answer

The Session layer (Layer 5) manages sessions between applications. The Transport layer handles end-to-end communication.

47
MCQeasy

A network engineer is troubleshooting connectivity issues and wants to verify the path that packets take from a source to a destination IP address. Which OSI layer is primarily responsible for packet forwarding and routing?

A.Layer 4 - Transport
B.Layer 3 - Network
C.Layer 1 - Physical
D.Layer 2 - Data Link
AnswerB

Layer 3 handles logical addressing and routing, with routers forwarding packets hop-by-hop using IP addresses and routing tables. This satisfies the engineer's need to verify the packet path, since traceroute relies on Layer 3 forwarding decisions rather than Layer 2 switching.

Why this answer

The Network layer (Layer 3) is responsible for packet forwarding and routing, using logical IP addresses to determine the best path from source to destination. Protocols like IP (IPv4/IPv6) and routing protocols (e.g., OSPF, BGP) operate at this layer to make forwarding decisions. The traceroute command is a common tool that leverages Layer 3 TTL (Time-to-Live) fields to map the path packets take.

Exam trap

Cisco often tests the distinction between Layer 2 switching (MAC-based forwarding within a LAN) and Layer 3 routing (IP-based forwarding between networks), and the trap here is that candidates confuse the Data Link layer's local forwarding with the Network layer's path determination.

How to eliminate wrong answers

Option A is wrong because Layer 4 (Transport) handles end-to-end communication, segmentation, and reliability (e.g., TCP/UDP), not packet forwarding or routing. Option C is wrong because Layer 1 (Physical) deals with the physical transmission of raw bits over a medium (e.g., cables, signals) and has no awareness of paths or addresses. Option D is wrong because Layer 2 (Data Link) is responsible for node-to-node delivery within a single network segment using MAC addresses, not for routing across multiple networks.

48
MCQeasy

An application developer is using a protocol that does not require a connection setup and has minimal header overhead. Which transport protocol is being used?

AnswerB

UDP is connectionless, requiring no handshake before transmission, and its header carries only source port, destination port, length and checksum — eight bytes versus TCP's larger header. This satisfies both constraints: no connection setup and minimal header overhead.

Why this answer

UDP (User Datagram Protocol) is a connectionless transport-layer protocol that does not require a handshake (no SYN/SYN-ACK/ACK) and has minimal header overhead (only 8 bytes, compared to TCP's 20 bytes). This makes it ideal for applications like DNS queries, streaming media, or real-time communications where low latency is more critical than guaranteed delivery.

Exam trap

Cisco often tests the distinction between transport-layer and application-layer protocols, so candidates mistakenly choose HTTP (an application protocol) instead of recognizing that the question explicitly asks for the transport protocol.

How to eliminate wrong answers

Option A is wrong because TCP requires a three-way handshake to establish a connection and has a larger header (20–60 bytes) with fields for sequence numbers, acknowledgments, and flow control, contradicting the 'no connection setup' and 'minimal header overhead' criteria. Option C is wrong because HTTP is an application-layer protocol, not a transport-layer protocol; it relies on TCP (or rarely UDP via HTTP/3) for transport, so it does not itself define connection setup or header overhead at the transport level. Option D is wrong because ICMP (Internet Control Message Protocol) is a network-layer protocol used for error reporting and diagnostics (e.g., ping), not a transport-layer protocol; it has no concept of port numbers or connection setup, but it is not a transport protocol.

49
MCQhard

An HTTP/2 connection uses multiple concurrent streams over a single TCP connection. Which feature of HTTP/2 enables this?

A.Binary framing layer
B.Multiplexing
C.Server push
D.Header compression (HPACK)
AnswerB

Multiplexing allows multiple request/response streams to be interleaved concurrently over one TCP connection, each identified by a stream ID. This removes HTTP/1.1's head-of-line blocking at the connection level and is the specific HTTP/2 feature enabling concurrent streams.

Why this answer

Multiplexing is the HTTP/2 feature that allows multiple concurrent streams to share a single TCP connection. This eliminates head-of-line blocking at the application layer by enabling the interleaving of frames from different streams, so a slow response on one stream does not block others.

Exam trap

Cisco often tests the distinction between the enabling mechanism (binary framing) and the resulting capability (multiplexing), so candidates mistakenly choose 'binary framing layer' because it sounds technical, but it is the foundation, not the feature that directly enables concurrency.

How to eliminate wrong answers

Option A is wrong because the binary framing layer is the mechanism that encodes frames into binary format, but it does not itself enable concurrency; multiplexing uses the framing layer to interleave streams. Option C is wrong because server push is a feature that allows the server to proactively send resources to the client, but it does not enable multiple concurrent streams. Option D is wrong because header compression (HPACK) reduces overhead by compressing HTTP headers, but it has no role in enabling concurrent streams.

50
MCQmedium

A developer is writing a script that uses a REST API to configure network devices via NETCONF. Which layer of the SDN architecture does NETCONF belong to?

C.Application layer
D.Control layer
AnswerB

NETCONF carries configuration and state data between the SDN controller and managed network devices, sitting below the controller. This places it in the southbound interface layer, distinct from northbound APIs that expose controller capabilities to applications.

Why this answer

NETCONF is a network management protocol used to install, manipulate, and delete the configuration of network devices. In the SDN architecture, the southbound interface is the layer that connects the control plane to the data plane, and NETCONF operates as a southbound protocol by carrying configuration data from a controller or management system down to network devices.

Exam trap

Cisco often tests the distinction between the protocol itself (NETCONF) and the architectural layer it belongs to, leading candidates to mistakenly select 'Control layer' because they associate NETCONF with the controller, rather than recognizing it as a southbound interface protocol.

How to eliminate wrong answers

Option A is wrong because the northbound interface is the API layer that connects the SDN controller to applications and business logic, not to network devices; NETCONF does not operate at this level. Option C is wrong because the application layer contains the business applications and services that consume northbound APIs, not the protocols that directly configure devices. Option D is wrong because the control layer is the SDN controller itself, which uses southbound protocols like NETCONF to communicate with devices, but NETCONF is not the control layer; it is a protocol used by that layer.

51
MCQeasy

Which OSI layer is responsible for routing packets across different networks?

A.Layer 1 (Physical)
B.Layer 3 (Network)
C.Layer 4 (Transport)
D.Layer 2 (Data Link)
AnswerB

Layer 3 handles logical addressing and path selection between distinct networks, so routers forward packets hop by hop using IP addresses. Layer 2 switches only forward within one broadcast domain, which is why routing across different networks is a Network layer function.

Why this answer

The Network layer (Layer 3) is responsible for logical addressing and routing packets between different networks. Protocols like IP (IPv4/IPv6) use routing tables and algorithms (e.g., OSPF, BGP) to determine the best path for forwarding packets across multiple hops. Without Layer 3, traffic could not leave a local broadcast domain.

Exam trap

Cisco often tests the distinction between Layer 2 switching (MAC-based, same network) and Layer 3 routing (IP-based, between networks), and the trap here is confusing the Data Link layer's local forwarding with the Network layer's internetwork routing.

How to eliminate wrong answers

Option A is wrong because Layer 1 (Physical) handles raw bit transmission over physical media (e.g., voltages, frequencies, cables) and has no concept of addressing or routing. Option C is wrong because Layer 4 (Transport) provides end-to-end communication, segmentation, and reliability (e.g., TCP/UDP), but does not perform network-level routing between different subnets. Option D is wrong because Layer 2 (Data Link) uses MAC addresses to forward frames within a single network segment or VLAN, and relies on Layer 3 to route across different networks.

52
MCQmedium

A developer is writing a script that uses the Cisco SD-WAN vManage REST API to retrieve a list of devices. The script uses the GET method to https://vmanage.example.com/dataservice/device. The API returns a 401 Unauthorized status code. Which of the following should the developer do to resolve the issue?

A.Ensure the request URL includes the correct query parameters for device filtering.
B.Include a valid authentication token in the request header.
C.Verify that the vManage server's TLS certificate is trusted by the client.
D.Change the HTTP method to POST.
AnswerB

A 401 Unauthorized response means the request lacks valid authentication credentials. The vManage API requires a session token or basic authentication. The developer should obtain a token by authenticating to the /j_security_check endpoint or using basic auth, then include it in the request header, typically as a cookie (JSESSIONID) or an Authorization header. This will allow the request to succeed.

Why this answer

The 401 Unauthorized status code indicates that the request lacks valid authentication credentials. For the Cisco SD-WAN vManage API, developers must authenticate first, usually by obtaining a session token, and then include that token in subsequent requests. Without it, the API rejects the request.

The other options address different issues such as method, TLS, or query parameters, which would produce different error codes.

Exam trap

The trap here is assuming that a 401 error is related to the request format or URL, when it specifically indicates missing or invalid authentication credentials.

53
Multi-Selectmedium

Which TWO of the following are characteristics of TLS (Transport Layer Security) used in HTTPS? (Choose two.)

Select 2 answers
A.It supports multiplexing of multiple streams.
B.It uses asymmetric encryption to exchange a symmetric session key.
C.It is an application layer protocol like HTTP.
D.It uses port 443 by default.
E.It provides server (and optionally client) certificate verification.
AnswersB, E

TLS performs an asymmetric handshake (for example, ECDHE with RSA or ECDSA signatures) to authenticate the server and negotiate a shared symmetric session key, which then encrypts bulk traffic. This hybrid approach satisfies HTTPS's need for both secure key exchange and efficient confidentiality.

Why this answer

Option B is correct because the TLS handshake uses asymmetric cryptography (e.g., RSA key transport or ECDHE for key agreement) to securely establish a shared symmetric session key, which is then used for bulk data encryption with algorithms like AES-GCM. Option E is correct because TLS authenticates the server via an X.509 certificate signed by a trusted CA, and can optionally authenticate the client through client certificates during mutual TLS. Option A is incorrect because stream multiplexing is a feature of HTTP/2 and QUIC, not TLS itself.

Option C is incorrect because TLS is a session/presentation-layer security protocol that runs between TCP and application protocols like HTTP, not an application-layer protocol. Option D is incorrect because port 443 is the default port for HTTPS, not an inherent characteristic of TLS, which can run over any port.

54
MCQhard

Which wireless security standard provides the strongest encryption and is recommended for enterprise networks as of 2023?

A.WEP
B.TKIP
AnswerC

WPA3 mandates SAE (Simultaneous Authentication of Equals), replacing WPA2's PSK handshake and providing forward secrecy plus 192-bit Enterprise mode. That stronger encryption and resistance to offline dictionary attacks make it the recommended enterprise standard, satisfying the 2023 requirement.

Why this answer

WPA3 is the latest standard with stronger encryption (SAE) and is recommended for modern networks.

55
Multi-Selectmedium

An administrator is configuring DNS records for a company's domain. Which three DNS record types are most commonly used to map hostnames to IP addresses or aliases? (Choose three.)

Select 3 answers
A.AAAA
B.CNAME
C.A
D.MX
E.PTR
AnswersA, B, C

AAAA records map a hostname to an IPv6 address, satisfying the requirement to resolve names to IP addresses. Where A records handle IPv4, AAAA provides the 128-bit equivalent, making it one of the standard hostname-to-address mappings alongside A and CNAME.

Why this answer

Option A (AAAA) is correct because an AAAA record maps a hostname to an IPv6 address, directly fulfilling the hostname-to-IP mapping purpose. Option B (CNAME) is correct because a Canonical Name record creates an alias from one hostname to another hostname, which is the alias-mapping function described in the question. Option C (A) is correct because an A record maps a hostname to an IPv4 address, the most fundamental hostname-to-IP mapping.

Option D (MX) is not correct here because MX records designate mail exchangers for email delivery, not hostname-to-IP or alias mapping. Option E (PTR) is not correct because PTR records provide reverse DNS lookups, mapping IP addresses back to hostnames rather than hostnames to IP addresses.

Exam trap

Cisco often tests the distinction between forward-mapping records (A, AAAA, CNAME) and service-specific or reverse records (MX, PTR), leading candidates to mistakenly include MX or PTR when the question explicitly asks for hostname-to-IP or alias mapping.

56
MCQmedium

In HTTP/2, which feature allows multiple concurrent requests and responses to be interleaved on a single connection, improving performance?

A.Header compression (HPACK)
B.Server push
C.Multiplexing
D.Binary framing
AnswerC

HTTP/2 multiplexing lets many request/response streams share one TCP connection, interleaving frames so no stream blocks another. This removes HTTP/1.1's head-of-line queuing per connection, directly satisfying the stem's requirement for concurrent, interleaved exchanges on a single connection.

Why this answer

HTTP/2 multiplexing allows multiple streams to be sent concurrently over a single TCP connection, reducing head-of-line blocking.

57
MCQmedium

A network application requires reliable, ordered delivery of data and uses a three-way handshake to establish a connection. Which transport protocol is being used?

A.UDP
C.TCP
D.IP
AnswerC

TCP guarantees reliable, ordered delivery through sequence numbers, acknowledgements and retransmission, and establishes connections via the three-way SYN, SYN-ACK, ACK handshake. This satisfies the stem's explicit requirements for both ordered reliable delivery and handshake-based connection establishment, which connectionless UDP cannot provide.

Why this answer

TCP is a connection-oriented protocol that provides reliable, ordered delivery and uses a three-way handshake (SYN, SYN-ACK, ACK) to establish a connection.

58
MCQmedium

A developer is creating a REST API client that needs to authenticate using credentials passed in the HTTP header. Which header should be used?

A.Authorization
B.Host
C.Content-Type
D.Cookie
AnswerA

The Authorization header carries credentials, typically as a Bearer token or Basic scheme, in the HTTP request. It satisfies the stem's requirement for passing credentials in the header, unlike Content-Type or Accept, which describe payload format and response preferences.

Why this answer

The Authorization header is the standard HTTP header used to transmit credentials (such as Basic, Bearer, or Digest tokens) to authenticate a REST API client. RFC 7235 defines this header as the mechanism for carrying authentication information from the client to the server, making it the correct choice for passing credentials in the HTTP header.

Exam trap

The trap here is that candidates often confuse the Cookie header with the Authorization header because both can carry tokens, but Cisco tests the specific RFC-defined purpose of the Authorization header for direct credential transmission in REST APIs.

How to eliminate wrong answers

Option B (Host) is wrong because the Host header specifies the target domain and port of the request, as defined in RFC 7230, and has no role in authentication. Option C (Content-Type) is wrong because it indicates the media type of the request body (e.g., application/json) and is used for content negotiation, not for passing credentials. Option D (Cookie) is wrong because while cookies can carry session tokens, they are designed for state management and are not the standard header for direct credential transmission in REST API authentication; the Authorization header is the explicit and preferred method.

59
MCQeasy

A developer is writing a script that must resolve a hostname to an IPv4 address before making an HTTP request. The script uses a DNS resolver library and needs to query for the appropriate record type. Which DNS record type should the script query to obtain the IPv4 address?

A.A
B.CNAME
C.MX
D.AAAA
AnswerA

An A record maps a hostname to an IPv4 address. Querying for an A record returns the IPv4 address needed to establish the HTTP connection. This is the standard record type for IPv4 resolution and directly answers the scenario's requirement.

Why this answer

The A record is the DNS record type that maps a hostname to an IPv4 address. When a script needs to resolve a hostname to an IPv4 address for an HTTP request, it should query for an A record. Other record types serve different purposes, such as AAAA for IPv6, CNAME for aliases, and MX for mail routing.

Exam trap

The trap here is mixing up A and AAAA records, or assuming that a CNAME directly returns an IP address, when only the A record provides IPv4 resolution.

60
MCQmedium

An application requires reliable, ordered delivery of data. Which transport protocol should be used?

A.UDP
C.TCP
D.IP
AnswerC

TCP establishes a connection, sequences segments, acknowledges receipt and retransmits lost data, guaranteeing ordered, reliable delivery. UDP offers neither ordering nor delivery guarantees. The stem's requirement for reliable, ordered delivery therefore maps directly to TCP's transport-layer mechanisms.

Why this answer

TCP is the correct choice because it is a connection-oriented transport-layer protocol that guarantees reliable, ordered delivery of data through mechanisms such as sequence numbers, acknowledgments, and retransmissions. UDP does not provide reliability or ordering, HTTP is an application-layer protocol that itself relies on TCP for reliability, and IP is a network-layer protocol that offers best-effort delivery with no guarantees.

Exam trap

The trap here is confusing protocol layers — candidates may pick HTTP thinking it guarantees delivery, or IP thinking it routes data reliably, when only TCP provides transport-layer reliability and ordering.

How to eliminate wrong answers

Option A is wrong because UDP is a connectionless transport protocol that provides no reliability, ordering, or retransmission — it is used for speed-sensitive traffic like DNS or streaming. Option B is wrong because HTTP is an application-layer protocol, not a transport protocol, and it depends on TCP underneath for reliable delivery. Option D is wrong because IP operates at the network layer and provides best-effort, connectionless delivery with no ordering or reliability guarantees.

61
MCQmedium

An application requires reliable, ordered delivery of data with flow control and retransmission of lost segments. Which transport layer protocol should the developer choose and what is a key characteristic of this protocol?

A.TCP; it uses a three-way handshake for connection establishment
B.UDP; it provides ordered delivery through sequence numbers
C.TCP; it has lower overhead than UDP
D.UDP; it uses a three-way handshake for connection establishment
AnswerA

TCP's sequence numbers and acknowledgements guarantee ordered delivery, while windowing provides flow control and unacknowledged segments are retransmitted — exactly the reliability the application demands. The three-way handshake establishes the connection state these mechanisms depend on before any data flows.

Why this answer

TCP is the correct transport protocol because it provides reliable, ordered delivery with flow control and retransmission of lost segments, and a defining characteristic is that it establishes connections via the three-way handshake (SYN, SYN-ACK, ACK). UDP provides none of these guarantees, and TCP actually has higher overhead than UDP, not lower.

Exam trap

The trap is the false pairing of UDP with TCP-like features (sequence numbers, handshakes) or the misconception that TCP has lower overhead — candidates must remember TCP trades overhead for reliability.

How to eliminate wrong answers

Option B is wrong because UDP does not provide ordered delivery or sequence numbers — it is connectionless and best-effort, leaving ordering and reliability to the application. Option C is wrong because TCP has higher overhead than UDP due to its handshake, headers (20+ bytes vs 8), acknowledgments, and state management, not lower. Option D is wrong because UDP does not perform a three-way handshake — that is a TCP-specific connection establishment mechanism.

62
MCQeasy

A network engineer is analyzing a packet capture of a TCP session establishment between a client and a server. The engineer observes a packet with the SYN flag set and another with both the SYN and ACK flags set. Which flag will be set in the next packet sent by the client to complete the three-way handshake?

A.RST
B.PSH
C.FIN
D.ACK
AnswerD

The three-way handshake consists of SYN, SYN-ACK, and ACK. The client initiates with SYN, the server responds with SYN-ACK, and the client completes the handshake by sending an ACK. This ACK acknowledges the server's SYN and establishes the connection, allowing data transfer to begin.

Why this answer

The three-way handshake is a fundamental TCP connection establishment process. The client sends a SYN packet, the server responds with a SYN-ACK packet, and the client completes the handshake by sending an ACK packet. This final ACK acknowledges the server's SYN and confirms that both sides are ready to exchange data.

Exam trap

The trap here is confusing the final ACK of the three-way handshake with other TCP control flags like FIN or RST, which serve entirely different purposes in connection management.

63
MCQeasy

A developer runs `curl -I http://api.example.com/health` and receives `HTTP/1.1 301 Moved Permanently` with a `Location: https://api.example.com/health` header. They want to follow the redirect automatically and print the final response body. Which curl option should they add?

A.`-v`
B.`-L`
C.`-X GET`
D.`-k`
AnswerB

The `-L` flag instructs curl to follow HTTP 3xx redirects by reissuing the request to the URL in the Location header. Because the original request used `-I` (HEAD), curl will still issue HEAD requests on the redirect chain, so it will not print a body; to see the final body, the developer should also drop `-I` or use `-o`/`-O` with `-L`. In this scenario, adding `-L` is the correct mechanism to resolve the 301 automatically.

Why this answer

Following an HTTP redirect requires curl to recognize the 3xx status and reissue the request to the URL in the Location header. The `-L` flag enables exactly that behavior. Other flags alter TLS verification, verbosity, or the request method, but none of them cause curl to traverse the redirect chain.

Combining `-L` with a method that returns a body is what produces the final content.

Exam trap

The trap here is assuming that any curl flag that changes request behavior, such as forcing a method or disabling certificate checks, will also resolve a 301 redirect, when only the redirect-following flag does that.

64
Multi-Selectmedium

A developer is writing a Python script to interact with a REST API. The script must handle HTTP responses correctly. Which two HTTP status code ranges indicate a successful request and a client error, respectively? (Choose two.)

Select 2 answers
A.2xx
B.3xx
C.1xx
D.4xx
E.5xx
AnswersA, D

2xx status codes indicate success. The request was successfully received, understood, and accepted. For example, 200 OK means the request succeeded. This range is used when the client's request was valid and the server fulfilled it.

Why this answer

HTTP status codes are grouped into five classes. 2xx codes indicate successful request handling, such as 200 OK. 4xx codes indicate client errors, such as 404 Not Found or 400 Bad Request. 1xx, 3xx, and 5xx represent informational, redirection, and server error responses, respectively. Therefore, the correct ranges for success and client error are 2xx and 4xx.

Exam trap

The trap here is confusing 5xx (server error) with 4xx (client error), or thinking that 3xx indicates success.

65
Multi-Selectmedium

Which TWO of the following are valid private IPv4 address ranges? (Select two.)

Select 2 answers
A.172.15.0.0/12
B.10.0.0.0/8
C.172.32.0.0/12
D.169.254.0.0/16
E.192.168.0.0/16
AnswersB, E

10.0.0.0/8 sits within the RFC 1918 private addressing space, spanning 10.0.0.0 to 10.255.255.255. It satisfies the stem's requirement for a valid private IPv4 range, unlike public or reserved blocks. Organisations use it for internal networks, with NAT handling external traffic.

Why this answer

Option B, 10.0.0.0/8, is correct because RFC 1918 designates the entire 10.0.0.0/8 block as a private IPv4 range, giving roughly 16.7 million addresses for internal use. Option E, 192.168.0.0/16, is also correct because RFC 1918 reserves 192.168.0.0/16 for private networks, commonly used in home and small-office LANs. The third RFC 1918 range, 172.16.0.0/12, covers 172.16.0.0 through 172.31.255.255, which is why option A (172.15.0.0/12) and option C (172.32.0.0/12) fall outside the private block and are invalid.

Option D, 169.254.0.0/16, is not a private range but the APIPA/link-local block (RFC 3927), automatically self-assigned when DHCP fails, so it does not qualify.

Exam trap

The trap here is confusing the 172.16.0.0/12 private range with adjacent public ranges like 172.15.0.0/12 or 172.32.0.0/12, or mistaking the link-local 169.254.0.0/16 for a private range.

66
MCQmedium

A DNS AAAA record is used to resolve a hostname to what type of address?

A.Mail exchange server
B.IPv4 address
C.Canonical name alias
D.IPv6 address
AnswerD

An AAAA record maps a hostname to a 128-bit IPv6 address, satisfying the stem's requirement for the address family returned by this record type. It mirrors the A record's role for IPv4 but uses four times the bits, which is why the mnemonic quadruples the letter.

Why this answer

A DNS AAAA record maps a hostname to an IPv6 address, analogous to how an A record maps to an IPv4 address. The four A's in 'AAAA' correspond to the 128-bit IPv6 address being four times the 32-bit IPv4 size, making it the standard record type for IPv6 resolution.

Exam trap

The trap is confusing AAAA with A records or with CNAME — candidates must remember AAAA is exclusively for IPv6, while A is for IPv4 and CNAME is an alias.

How to eliminate wrong answers

Option A is wrong because mail exchange servers are specified by MX records, which direct email delivery to mail servers. Option B is wrong because IPv4 addresses are resolved via A records, not AAAA records. Option C is wrong because canonical name aliases are defined by CNAME records, which point one hostname to another hostname rather than to an IP address.

67
MCQmedium

A developer's application opens a TCP connection to a REST API, sends a request, and receives a response. The developer then wants to reuse the same connection for several subsequent requests to the same host instead of opening a new socket each time. Which HTTP behavior makes this reuse possible?

A.Persistent connections keep the TCP socket open for multiple request/response exchanges.
B.The server sends a 101 Switching Protocols response to upgrade the socket.
C.The client multiplexes requests by interleaving them in a single HTTP/1.0 stream.
D.HTTP cookies are exchanged so the server can correlate successive sockets.
AnswerA

HTTP keep-alive, the default in HTTP/1.1, allows a single TCP connection to carry multiple sequential request/response pairs. Reusing the established socket avoids repeating the three-way handshake and TCP slow start for each call, which lowers latency and resource consumption when a client makes several requests to the same server.

Why this answer

Persistent connections, the default in HTTP/1.1, let a client send multiple requests over one TCP socket. This avoids re-establishing the connection and re-entering TCP slow start for every call, which is the reuse the developer wants. Cookies, protocol upgrades, and HTTP/1.0 behavior do not provide this transport-level efficiency.

Exam trap

The trap here is confusing application-layer session state, such as cookies, with transport-layer connection reuse, when only persistent connections keep the TCP socket open across requests.

68
MCQmedium

A developer is writing a script to interact with a REST API. The API documentation states that the base URL is https://api.example.com/v1/ and that the resource for users is /users. The developer needs to retrieve a list of all users. Which HTTP request should the developer send to the correct endpoint?

A.PUT https://api.example.com/v1/users
B.GET https://api.example.com/v1/users
C.GET https://api.example.com/v1/user
D.POST https://api.example.com/v1/users
AnswerB

The correct endpoint is formed by combining the base URL and the resource path. A GET request to /v1/users retrieves the collection of users. This follows RESTful conventions where GET is used to retrieve data without side effects. The full URL includes the base and the resource, resulting in the correct endpoint.

Why this answer

RESTful APIs use HTTP methods semantically: GET for retrieval, POST for creation, PUT for update, DELETE for removal. To list users, a GET request to the users collection endpoint is correct. The base URL and resource path must be concatenated properly, and the plural form /users indicates the collection.

The other methods would cause unintended actions or target the wrong resource.

Exam trap

The trap here is using POST or PUT for retrieval; these methods alter state or create resources, whereas GET is safe and idempotent for fetching data.

69
MCQmedium

A developer is building a Python script that must resolve a hostname to an IPv4 address and then connect to a specific TCP port. The script uses `socket.getaddrinfo(host, port, family=socket.AF_INET, type=socket.SOCK_STREAM)`. What does the returned list contain?

A.A dictionary mapping address families to lists of IPv4 addresses.
B.A single string containing the IPv4 address in dotted-decimal notation.
C.Tuples of (family, type, proto, canonname, sockaddr) for each address that matches the criteria.
D.A list of `ipaddress.IPv4Address` objects representing resolved addresses.
AnswerC

`socket.getaddrinfo` returns a list of 5-tuples: address family, socket type, protocol, canonical name, and a socket address tuple. With `family=socket.AF_INET` and `type=socket.SOCK_STREAM`, it filters for IPv4 TCP endpoints. Each sockaddr is a (host, port) pair for IPv4. This structure lets a client iterate over candidates and attempt connections without manually parsing DNS responses or constructing sockaddr structures.

Why this answer

`socket.getaddrinfo` resolves a host and service into a list of 5-tuples containing family, type, protocol, canonical name, and socket address. When filtered with `AF_INET` and `SOCK_STREAM`, the results are IPv4 TCP endpoints ready for socket creation. This design supports multiple addresses and protocol independence, which is why developers use it instead of the simpler but less flexible `gethostbyname`.

Exam trap

The trap here is assuming that hostname resolution returns just an IP string or a custom object, when `getaddrinfo` actually returns structured tuples designed for direct socket creation.

70
Multi-Selecthard

Which THREE of the following are benefits of using an SDN (Software-Defined Networking) architecture compared to traditional networking? (Choose three.)

Select 3 answers
A.Reduced need for network engineers.
B.Automation of network configuration changes.
C.Faster deployment of new network services.
D.Centralized control and visibility of the network.
E.Built-in encryption for all network traffic.
AnswersB, C, D

SDN separates the control plane from the data plane, letting a controller push configuration programmatically via APIs. This replaces per-device CLI changes, so network configuration changes are automated across the fabric rather than performed manually, satisfying the benefit of reduced manual effort and human error.

Why this answer

Option B is correct because SDN's centralized controller exposes northbound APIs (e.g., REST) that let orchestration tools push configuration programmatically, enabling automation of network configuration changes instead of manual CLI work on each device. Option C is correct because that same programmable control plane allows new services and policies to be provisioned in software via the controller rather than waiting on per-device hardware configuration, so new network services deploy faster. Option D is correct because SDN logically centralizes the control plane in a controller, giving a single, network-wide view and centralized control and visibility over all data-plane devices.

Option A is not a benefit—SDN changes the skill set required but does not inherently reduce the need for network engineers. Option E is not a benefit—SDN does not provide built-in encryption for all traffic; encryption is handled by separate mechanisms such as IPsec, TLS, or MACsec.

Exam trap

Cisco often tests the misconception that SDN eliminates the need for network engineers entirely, but the correct understanding is that SDN automates tasks and centralizes control, not that it removes the human role in network design and troubleshooting.

71
Multi-Selectmedium

A developer is writing a Python script that uses the requests library to interact with a REST API. The script must handle common HTTP status codes appropriately. Which two actions should the developer take to ensure robust error handling? (Choose two.)

Select 2 answers
A.Always assume the response is JSON and parse it without checking the Content-Type header.
B.Disable SSL verification to avoid certificate errors.
C.Check the response.status_code attribute and branch logic based on the code.
D.Set the timeout parameter to a very high value to avoid connection errors.
E.Use response.raise_for_status() to automatically raise an exception for 4xx and 5xx responses.
AnswersC, E

Checking the status_code allows the script to handle different HTTP responses explicitly. For example, a 200 indicates success, while 404 means the resource was not found, and 500 indicates a server error. By branching logic, the developer can implement retries for 5xx errors or display user-friendly messages for 4xx errors. This is a fundamental practice for robust API interaction.

Why this answer

To robustly handle HTTP errors, the developer should check the status code and branch logic accordingly, and use raise_for_status() to raise exceptions for 4xx and 5xx responses. These practices allow the script to respond appropriately to different error conditions, such as retrying or logging. Other options either introduce risks or do not address error handling effectively.

Exam trap

The trap here is thinking that increasing timeout or disabling SSL verification makes the script more robust, when they actually introduce fragility or security risks.

72
MCQmedium

A developer is troubleshooting an HTTP API call that returns a 404 status code. Which of the following is the most likely cause?

A.The server is unavailable due to maintenance
B.The requested URL endpoint does not exist
C.The server encountered an internal error
D.The client lacks proper authentication
AnswerB

HTTP 404 means the server received and understood the request but found no resource matching that URI. The endpoint path is wrong or removed, so the server cannot map it to a handler. This directly satisfies the stem's 404 symptom, unlike authentication or server errors.

Why this answer

HTTP 404 Not Found is a client-side error indicating the server could not find the requested resource at the specified URL. The most likely cause is that the endpoint path is incorrect, misspelled, removed, or not mapped to any route on the server. The server itself is reachable and processed the request, but no matching resource exists, which is precisely what 404 signifies.

Exam trap

200-901 often tests whether candidates can map HTTP status codes to their correct semantic category, so candidates confuse 404 with 401/403 (auth) or 500 (server error) and pick a plausible-sounding but wrong cause.

How to eliminate wrong answers

Option A is wrong because server unavailability due to maintenance typically produces a 503 Service Unavailable or a connection timeout, not a 404, since the server would not be able to respond with a resource-not-found status. Option C is wrong because an internal server error is represented by 500 Internal Server Error, which indicates the server encountered an unexpected condition while processing a valid request, not that the resource is missing. Option D is wrong because lack of proper authentication yields 401 Unauthorized (or 403 Forbidden for authorization failures), meaning the resource may exist but access is denied, which is distinct from the resource not being found.

73
MCQmedium

A network engineer is troubleshooting a connectivity issue between two subnets. The engineer uses the traceroute command and observes that packets are reaching the destination but with high latency. Which of the following is the most likely cause of the high latency?

A.Network congestion causing packets to be queued at intermediate devices.
B.Incorrect subnet mask configuration on the source device.
C.A routing loop causing packets to traverse multiple hops repeatedly.
D.A firewall blocking ICMP packets, causing retransmissions.
AnswerA

Network congestion occurs when the volume of traffic exceeds the capacity of a link or device, causing packets to be buffered and delayed. This results in increased latency without necessarily causing packet loss. Traceroute would show increased round-trip times at the congested hop, while packets still reach the destination.

Why this answer

Network congestion causes packets to be queued at intermediate devices, increasing latency. Traceroute would show higher round-trip times at the congested hop, but packets still reach the destination. This is a common cause of high latency without packet loss.

Exam trap

The trap here is attributing high latency to routing loops or misconfigurations, which would typically cause packet loss or unreachability rather than just increased latency.

74
MCQeasy

At which layer of the OSI model do MAC addresses operate?

A.Layer 2 – Data Link
B.Layer 1 – Physical
C.Layer 4 – Transport
D.Layer 3 – Network
AnswerA

MAC addresses are burned into network interface hardware and used for frame delivery within a single broadcast domain. The Data Link layer, Layer 2, encapsulates packets into frames and uses these 48-bit addresses for hop-to-hop addressing, unlike Layer 3's logical IP addressing.

Why this answer

MAC addresses operate at Layer 2 (Data Link) of the OSI model because they are used for local network addressing and frame delivery between directly connected devices. The Data Link layer encapsulates packets into frames and uses MAC addresses to identify source and destination interfaces on the same network segment, as defined by IEEE 802 standards.

Exam trap

Cisco often tests the confusion between Layer 2 MAC addresses and Layer 3 IP addresses, where candidates mistakenly associate MAC addresses with routing or network-layer functions instead of local data-link delivery.

How to eliminate wrong answers

Option B is wrong because Layer 1 (Physical) deals with raw bit transmission over physical media, such as voltages, cables, and connectors, not addressing. Option C is wrong because Layer 4 (Transport) uses port numbers (e.g., TCP/UDP) to identify applications and manage end-to-end communication, not MAC addresses. Option D is wrong because Layer 3 (Network) uses logical IP addresses (e.g., IPv4 or IPv6) for routing between networks, while MAC addresses are used for local delivery within a broadcast domain.

75
MCQhard

A network administrator is configuring a wireless network and wants to minimize interference. In the 2.4 GHz band, which set of channels are non-overlapping?

A.1, 5, 9, 13
B.1, 3, 5, 7, 9, 11
C.1, 6, 11
D.2, 7, 12
AnswerC

In the 2.4 GHz band each channel is 22 MHz wide but spaced only 5 MHz apart, so channels 1, 6 and 11 are the only set separated enough to avoid overlapping spectrum and minimise interference.

Why this answer

In the 2.4 GHz ISM band, the available channels are spaced 5 MHz apart, but each Wi-Fi channel is 20 MHz wide, so adjacent channels overlap. Only channels 1, 6, and 11 are spaced far enough apart (25 MHz between centers) to avoid overlapping in North America, making them the standard non-overlapping set. Using these three channels allows multiple access points to operate in close proximity with minimal co-channel interference.

Exam trap

200-901 often tests the memorized fact that 1, 6, and 11 are the non-overlapping 2.4 GHz channels, so candidates who assume any evenly spaced set (like 1, 5, 9, 13) works, or who forget the 20 MHz channel width, pick a wrong option.

How to eliminate wrong answers

Option A is wrong because channels 1, 5, 9, and 13 are only 20 MHz apart, so their 20 MHz-wide signals still overlap, causing adjacent-channel interference; also channel 13 is not usable in North America. Option B is wrong because channels 1, 3, 5, 7, 9, and 11 are spaced only 10 MHz apart, guaranteeing heavy overlap and interference between neighboring channels. Option D is wrong because channels 2, 7, and 12 are offset from the standard non-overlapping set and still overlap with each other and with channels 1, 6, and 11, and channel 12 is restricted in some regions.

Page 1 of 2 · 125 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Devnet Network Fundamentals questions.