Courseiva

Cisco CCNP ENARSI 300-410 (300-410) — Questions 1–75

1401 questions total · 19pages · All types, answers revealed

Page 1 of 19

Page 2
1
Multi-Selectmedium

Which TWO statements about NetFlow version 9 and Flexible NetFlow are true? (Choose TWO.)

Select 2 answers
A.NetFlow version 9 uses a fixed-format packet structure for flow export.
B.Flexible NetFlow is built upon the NetFlow version 9 template architecture.
C.Flexible NetFlow can only export data using NetFlow version 9.
D.NetFlow version 9 supports user-defined flow records through templates.
E.Flexible NetFlow only supports IPv4 traffic monitoring.
AnswersB, D

Flexible NetFlow reuses NetFlow version 9's template-based export architecture, where flow records are defined by templates sent to the collector. This shared template mechanism is the foundation on which Flexible NetFlow's configurable records and caches are built.

Why this answer

Option B is correct because Flexible NetFlow is Cisco's implementation that directly builds on the NetFlow version 9 export architecture, reusing its template-based mechanism to define and export flow data. Option D is correct because NetFlow version 9 introduced templates that allow user-defined flow records, enabling customizable field sets (such as IPv6 fields, MPLS labels, or BGP attributes) rather than a fixed record layout. Option A is incorrect because NetFlow version 9 does not use a fixed-format packet structure; that describes NetFlow version 5, whereas version 9 uses templates to define record formats dynamically.

Option C is incorrect because Flexible NetFlow can export data using multiple protocols, including NetFlow version 9 and IPFIX (NetFlow version 10), not exclusively version 9. Option E is incorrect because Flexible NetFlow supports both IPv4 and IPv6 traffic monitoring, along with other protocols such as MPLS and multicast.

Exam trap

The trap here is confusing NetFlow v5's fixed-format structure with v9's template-based flexibility, and assuming Flexible NetFlow is limited to v9 export or IPv4 only, when it actually supports multiple export protocols and IPv6.

2
Multi-Selectmedium

Which TWO configuration steps are required to apply an IPv4 extended access list to an interface in Cisco IOS? (Choose TWO.)

Select 2 answers
A.Configure the ACL using access-list or ip access-list commands.
B.Apply the ACL to the interface with the ip access-group command.
C.Create the ACL directly under the interface configuration mode.
D.Use the access-class command on the interface.
E.Enable the ACL with the ip inspect command.
AnswersA, B

The ACL must be defined first with permit/deny entries.

Why this answer

An IPv4 extended ACL must first be defined using either the numbered `access-list` command or the named `ip access-list extended` command before it can be applied. Option B is correct because the `ip access-group` command is the only way to bind a configured ACL to an interface in Cisco IOS, specifying the direction (in or out) and optionally the VLAN filter.

Exam trap

Cisco often tests the distinction between `ip access-group` (for interfaces) and `access-class` (for VTY lines), leading candidates to mistakenly choose `access-class` when the question specifies an interface.

3
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip policy Interface Route-map GigabitEthernet0/0 PBR-TEST R1# show route-map PBR-TEST route-map PBR-TEST, permit, sequence 10 Match clauses: ip address (access-lists): 110 Set clauses: ip next-hop 192.168.100.1 Policy routing matches: 0 packets, 0 bytes R1# show access-lists 110 Extended IP access list 110 10 permit tcp 10.0.0.0 0.255.255.255 any eq 80 20 permit tcp 10.0.0.0 0.255.255.255 any eq 443 R1# show ip route 192.168.100.1 Routing entry for 192.168.100.1/32 Known via "ospf 1", distance 110, metric 20 Last update from 10.1.1.2 on GigabitEthernet0/1 Based on this output, what is the most likely reason for zero policy routing matches?

A.The next-hop 192.168.100.1 is not reachable.
B.The access list 110 is not matching any traffic arriving on GigabitEthernet0/0.
C.The route map sequence number is too high.
D.The route map needs to be applied globally.
AnswerB

Zero matches occur because access list 110 permits only TCP ports 80 and 443 from 10.0.0.0/8; if hosts on GigabitEthernet0/0 send other protocols or ports, no packets satisfy the match clause, so the route-map never triggers.

Why this answer

The output shows that the route map PBR-TEST is applied to GigabitEthernet0/0 and matches access list 110, but zero packets have matched. The most likely reason is that no traffic arriving on GigabitEthernet0/0 matches the access list criteria (TCP ports 80 or 443 from 10.0.0.0/8). The next-hop is reachable via OSPF, so that is not the issue.

The route map sequence and application are correct.

Exam trap

The trap is assuming the next-hop is unreachable because of the zero matches, but the routing table shows it is reachable — candidates must focus on the match criteria and interface traffic.

How to eliminate wrong answers

Option A is wrong because the show ip route output confirms that 192.168.100.1 is reachable via OSPF with a valid route, so the next-hop is not the problem. Option C is wrong because the sequence number (10) is standard and does not affect matching; sequence numbers only determine order of evaluation within the route map. Option D is wrong because the route map is already applied to the interface via the ip policy command, as shown by show ip policy; applying it globally is not required for PBR.

4
MCQhard

A network engineer runs the following command on Router R1: R1# show ip eigrp topology 10.10.10.0/24 EIGRP-IPv4 Topology Entry for AS(100)/ID(192.168.1.1) for 10.10.10.0/24 State: Passive, Reply status: 0, Originating router: 192.168.1.1 Routing Descriptor Blocks: 0.0.0.0 (Null0) from 0.0.0.0, Send flag: 0x0 Composite metric: (2560000000/0), Route is Internal Vector metric: Minimum bandwidth: 100000 Kbit Total delay: 100 microseconds Reliability: 255/255 Load: 1/255 Minimum MTU: 1500 Hop count: 0 Based on this output, what is the problem?

A.The route is a local summary route pointing to Null0, which is normal for EIGRP summarization.
B.The route has a metric of 2560000000, indicating a network failure.
C.The hop count of 0 means the route is not reachable.
D.The route is in Active state, indicating a problem.
AnswerA

The Null0 entry with hop count 0 and no next hop is EIGRP's automatic summary route for 10.10.10.0/24, generated locally on the originating router. It is expected behaviour, not a fault, so no adjacency or metric problem exists here.

Why this answer

The output shows a Null0 summary route in EIGRP, which is normal when manual summarization is configured. The route is in Passive state with a composite metric of 2560000000/0, indicating it is a local summary route installed to prevent routing loops. This is expected behavior, not a problem.

Exam trap

Cisco often tests the misconception that a Null0 route or a high metric indicates a failure, when in fact it is a normal and necessary part of EIGRP summarization to prevent black holes.

How to eliminate wrong answers

Option B is wrong because a metric of 2560000000 is the default composite metric for a Null0 summary route in EIGRP, not an indicator of network failure. Option C is wrong because a hop count of 0 is normal for a locally originated summary route, meaning the route is directly connected to the router, not unreachable. Option D is wrong because the route is explicitly in Passive state, which indicates a stable route; Active state would indicate a query in progress or a problem.

5
MCQhard

A network engineer is configuring a Cisco IOS XE router to act as a DHCPv6 relay agent. The router is connected to a LAN segment with DHCPv6 clients and must forward DHCPv6 messages to a DHCPv6 server at 2001:DB8::100. The engineer has configured the interface with ipv6 address 2001:DB8:1::1/64 and ipv6 enable. Which command is required to enable DHCPv6 relay on the interface?

A.ipv6 dhcp server 2001:DB8::100
B.ipv6 helper-address 2001:DB8::100
C.ipv6 nd managed-config-flag
D.ipv6 dhcp relay destination 2001:DB8::100
AnswerD

The ipv6 dhcp relay destination command configures the interface as a DHCPv6 relay agent and specifies the destination DHCPv6 server address. This command is applied to the interface facing the clients. The router will then forward DHCPv6 messages from clients to the specified server and relay responses back. Without this command, the router will not relay DHCPv6 messages, and clients will not receive addresses from the remote server.

Why this answer

To configure a Cisco IOS XE router as a DHCPv6 relay agent, you must use the ipv6 dhcp relay destination command on the interface facing the clients. This command specifies the DHCPv6 server address to which client messages are forwarded. It is the direct analog to the IPv4 ip helper-address command, but with IPv6-specific syntax.

Without it, the router will not relay DHCPv6 messages, and clients will not receive addresses from the remote server. The other options either configure the router as a server or set RA flags, neither of which enables relay.

Exam trap

The trap here is assuming the IPv6 relay command follows the IPv4 ip helper-address pattern, but Cisco IOS XE uses ipv6 dhcp relay destination instead.

6
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using MD5. The engineer enters the following commands: interface GigabitEthernet0/0 ip ospf authentication message-digest ip ospf message-digest-key 1 md5 C1sco123 After applying the configuration, the OSPF neighbor relationship fails to form. Which action must the engineer take to resolve the issue?

A.Configure the ip ospf authentication-key command with the same password.
B.Change the key ID to 0 on both routers to match the default key.
C.Configure the same MD5 key and key ID on the neighboring router's interface.
D.Enable OSPF authentication globally using the area authentication command.
AnswerC

OSPF MD5 authentication requires that both neighbors use the same key ID and key string on their interfaces. The local configuration is correct, but without matching credentials on the neighbor, authentication fails and the adjacency will not form. Therefore, configuring the matching key on the neighboring router's interface resolves the issue.

Why this answer

OSPF MD5 authentication requires that both neighbors have the same key ID and key string configured on their interfaces. The local router is correctly configured for MD5, but the neighbor lacks the matching key, causing authentication to fail. Configuring the identical key on the neighbor's interface will allow the adjacency to form.

Exam trap

The trap here is assuming that enabling OSPF authentication on one side is sufficient, when in fact both neighbors must have matching credentials.

7
Drag & Dropmedium

Drag and drop the steps to troubleshoot suboptimal routing due to incorrect Administrative Distance values into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order begins by identifying the routing table entries to see which routes are preferred, then checking the AD values of the competing protocols, verifying the configuration of the protocol with the lower AD, adjusting the AD on the desired protocol to make it preferred, and finally confirming the routing table update.

8
MCQmedium

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate IP spoofing. The router has two interfaces: GigabitEthernet0/0 connecting to the internet (untrusted) and GigabitEthernet0/1 connecting to the internal network (trusted). The engineer wants to enable strict uRPF on the untrusted interface. Which command should be applied to GigabitEthernet0/0?

A.ip verify unicast source reachable-via any
B.ip verify unicast source reachable-via rx
C.ip verify unicast reverse-path
D.ip verify unicast source reachable-via rx allow-default
AnswerB

The command ip verify unicast source reachable-via rx enables strict uRPF, which checks that the source IP address of incoming packets is reachable via the same interface the packet was received on. This is the correct configuration for the untrusted interface to prevent spoofed source addresses.

Why this answer

Strict uRPF is enabled with the command ip verify unicast source reachable-via rx on the interface. It ensures that the source IP address of incoming packets is reachable via the same interface, effectively dropping packets with spoofed source addresses that would not be routed back out that interface.

Exam trap

The trap here is confusing strict and loose uRPF modes, or using the deprecated command syntax, which may not be supported or may behave differently.

9
Multi-Selecthard

A network administrator is deploying a site-to-site VPN using Cisco IOS GET VPN (Group Encrypted Transport VPN) on a service provider MPLS network. The administrator must ensure that the group members can communicate securely while maintaining any-to-any connectivity and minimizing tunnel overhead. Which two statements about GET VPN are true? (Choose two.)

Select 2 answers
A.GET VPN encapsulates packets in a new IP header, adding significant overhead.
B.GET VPN uses IKEv2 to establish point-to-point tunnels between all group members.
C.GET VPN requires a key server to distribute encryption keys and policies to group members.
D.GET VPN uses a group security association (GSA) to encrypt traffic between group members without point-to-point tunnels.
E.GET VPN provides encryption only for unicast traffic, not multicast.
AnswersC, D

The key server is a central component that manages group policies, generates and distributes keys, and authenticates group members. It uses the Group Domain of Interpretation (GDOI) protocol to securely send the GSA to members. Without a key server, group members cannot obtain the necessary keys to encrypt or decrypt traffic, making it a mandatory element in GET VPN deployments.

Why this answer

GET VPN uses a group security association managed by a key server, allowing any-to-any secure communication without per-peer tunnels. The key server distributes policies and keys via GDOI. This design preserves the original IP header for routing and supports both unicast and multicast, making it ideal for MPLS networks.

Exam trap

The trap here is assuming GET VPN uses point-to-point tunnels or encapsulates packets with a new IP header, when it actually uses a group SA and preserves the original header.

10
MCQeasy

Which BGP message type is used to advertise, withdraw, and update routes?

A.OPEN
B.UPDATE
C.NOTIFICATION
D.KEEPALIVE
AnswerB

The UPDATE message carries path attributes and Network Layer Reachability Information, performing route advertisement and withdrawal between BGP peers. Withdrawals are encoded as unreachable routes within the same message type, so it handles all three functions named in the stem.

Why this answer

The BGP UPDATE message is the only message type that carries routing information — it advertises new routes (NLRI), withdraws previously advertised routes, and includes path attributes. OPEN, KEEPALIVE, and NOTIFICATION serve session establishment and maintenance, not route propagation.

Exam trap

300-410 often tests basic BGP message-type functions, and candidates confuse KEEPALIVE (session maintenance) with UPDATE (route exchange) — the key is that only UPDATE carries NLRI.

How to eliminate wrong answers

Option A is wrong because OPEN is used only at session establishment to negotiate BGP parameters (version, AS number, hold time, capabilities) — it carries no routes. Option C is wrong because NOTIFICATION is sent to signal an error condition and tear down the session, not to exchange routes. Option D is wrong because KEEPALIVE is a periodic heartbeat (default 60 seconds) to maintain the session, carrying no NLRI.

11
MCQhard

A network engineer is troubleshooting an OSPFv2 issue where a router R1 is not receiving a specific route for 10.0.0.0/8 from a neighbor R2. The adjacency is FULL, and 'show ip ospf database' on R1 shows the LSA for 10.0.0.0/8 as a type 5 LSA. However, the route is not in the routing table. 'show ip route 10.0.0.0' shows no route. What is the most likely cause?

A.The router R1 has a distribute-list applied to the OSPF process that filters the route 10.0.0.0/8.
B.The route is a type 5 LSA, but the router is in a stub area.
C.The router has a higher administrative distance for OSPF routes, causing it to prefer another routing protocol.
D.The route has a metric of 16777214, which is considered infinite.
AnswerA

A distribute-list filters routes when installing them into the routing table, so the type 5 LSA still appears in the OSPF database while the route is suppressed. This matches the FULL adjacency and populated LSDB with an empty routing table.

Why this answer

A distribute-list applied to the OSPF process on R1 can filter the route even though the LSA is present in the OSPF database. The LSA is received and stored (so it appears in 'show ip ospf database'), but the distribute-list prevents it from being installed in the routing table, which matches the symptom of a type 5 LSA present but no route.

Exam trap

300-410 often tests the misconception that if an LSA is in the OSPF database, the route must be in the routing table, ignoring filtering mechanisms like distribute-lists that act at route installation.

How to eliminate wrong answers

Option B is wrong because a stub area does not accept type 5 LSAs at all — the LSA would not appear in the database, contradicting the scenario. Option C is wrong because administrative distance only matters when multiple protocols offer the same prefix; the question states no route exists at all, so AD is not the cause. Option D is wrong because a metric of 16777214 (LSInfinity) would mean the route is unreachable, but the question does not indicate that metric; also, such an LSA would typically not be installed, but the more direct cause given the presence of the LSA is a distribute-list.

12
MCQhard

A network engineer is implementing CoPP on a Cisco router to protect the control plane from DoS attacks. The engineer wants to rate-limit ICMP echo requests destined to the router's management IP address. Which CoPP policy component is responsible for defining the traffic classification?

A.Class map
B.Access control list (ACL)
C.Policy map
D.Service policy
AnswerA

The class map is used to classify traffic by matching specific criteria, such as protocol type, source/destination IP, or port numbers. In this scenario, to rate-limit ICMP echo requests, the engineer would create a class map that matches ICMP echo-request packets. Therefore, the class map is the component that defines the traffic classification for CoPP.

Why this answer

The correct answer is the class map, which defines the traffic classification by matching specific packet characteristics. In CoPP, class maps are used to identify traffic of interest, such as ICMP echo requests. The policy map then applies actions like policing to those classes.

The service policy attaches the policy map to the control plane, and ACLs can be used within class maps for matching but are not the classification component themselves.

Exam trap

The trap here is confusing the role of the class map with that of the policy map, thinking the policy map defines classification when it actually defines actions.

13
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate a branch office VPN client with a digital certificate. The certificate is issued by an external CA, and the engineer must ensure that the router can validate the certificate chain. Which command is required to install the CA certificate?

A.crypto pki authenticate name
B.crypto pki import name certificate
C.crypto pki enroll name
D.crypto pki trustpoint name
AnswerA

The crypto pki authenticate command retrieves and installs the CA certificate, which is necessary for the router to validate client certificates. It authenticates the CA by obtaining its self-signed certificate and installing it into the router's certificate store. This step is mandatory before the router can trust certificates issued by that CA, enabling proper certificate chain validation for the VPN client.

Why this answer

To validate certificates issued by an external CA, the router must first obtain the CA's own certificate. The crypto pki authenticate command performs this by retrieving the CA certificate and installing it as a trusted certificate. This step is a prerequisite for any PKI operations that rely on that CA, such as verifying client certificates during VPN authentication.

Exam trap

The trap here is confusing authentication with enrollment, assuming that requesting a router certificate also installs the CA certificate.

14
MCQeasy

What is the default timeout value (in milliseconds) for an IP SLA operation?

A.5000 ms
B.1000 ms
C.10000 ms
D.60000 ms
AnswerA

Cisco IP SLA operations default to a 5000 ms timeout, the interval the router waits for a response before declaring the probe timed out. This applies unless overridden with the timeout command under the ip sla configuration.

Why this answer

The default timeout for an IP SLA operation in Cisco IOS is 5000 milliseconds (5 seconds). This value applies to the operation's response wait time before the probe is considered failed, and it is configurable via the 'timeout' command under ip sla configuration. Knowing this default matters when tuning SLA probes for latency-sensitive monitoring.

Exam trap

The trap here is confusing IP SLA's default timeout (5000 ms) with its default frequency (60 s) or with the threshold value, causing candidates to select 1000 ms or 60000 ms.

How to eliminate wrong answers

Option B is wrong because 1000 ms is the default frequency (interval) for some SLA operations, not the timeout. Option C is wrong because 10000 ms is a common manually configured timeout, not the default. Option D is wrong because 60000 ms (60 seconds) is far longer than the default and would cause probes to hang excessively before failing.

15
Multi-Selecthard

Which TWO configuration steps are required to enable IPv6 RA Guard on a Cisco switch interface? (Choose TWO.)

Select 2 answers
A.Create an RA Guard policy using the 'ipv6 nd raguard policy POLICY_NAME' command.
B.Apply the RA Guard policy to the interface with the 'ipv6 nd raguard attach-policy POLICY_NAME' command.
C.Enable IPv6 routing globally with 'ipv6 unicast-routing'.
D.Configure 'ipv6 nd raguard' directly on the interface without a policy.
E.Enable DHCPv6 Guard on the same interface to complement RA Guard.
AnswersA, B

Creating the RA Guard policy with `ipv6 nd raguard policy POLICY_NAME` is mandatory because the feature cannot be attached to an interface without a defined policy. The policy holds the device-role and host-access parameters that determine which Router Advertisement messages are filtered, satisfying the stem's requirement for enabling RA Guard on the interface.

Why this answer

Option A is correct because RA Guard on Cisco switches requires first defining a policy in global configuration mode with the 'ipv6 nd raguard policy POLICY_NAME' command, which creates the policy container where device-role and other parameters are set. Option B is correct because the policy must then be bound to the specific Layer 2 switch interface using the interface-level command 'ipv6 nd raguard attach-policy POLICY_NAME' for the filtering to take effect. Option C is not required because RA Guard is a Layer 2 security feature that filters ICMPv6 Router Advertisement messages at the switch port and does not depend on the switch having IPv6 unicast routing enabled.

Option D is incorrect because there is no direct interface command 'ipv6 nd raguard' that enables the feature without an associated policy. Option E is incorrect because DHCPv6 Guard is a separate feature that filters DHCPv6 server/client messages and is not a prerequisite for RA Guard.

Exam trap

Cisco often tests that RA Guard requires both a policy creation and an interface attachment, leading candidates to mistakenly think a simple interface command or global routing enablement is sufficient.

16
MCQhard

A network engineer runs the following command on Router R1: R1# show snmp statistics SNMP packets input: 150 Bad SNMP version errors: 0 Unknown community name: 25 Illegal operation for community name: 0 Encoding errors: 0 Number of requested variables: 300 Number of altered variables: 0 Get-request PDUs: 120 Get-next PDUs: 30 Set-request PDUs: 0 SNMP packets output: 200 Too big errors: 0 No such name errors: 10 Bad values errors: 0 General errors: 0 Response PDUs: 200 Trap PDUs: 0 Based on this output, which statement is correct?

A.There are 25 SNMP requests with invalid community strings.
B.The router has sent 150 trap PDUs.
C.There were 10 set requests that failed due to bad values.
D.The router received 200 SNMP packets.
AnswerA

The counter "Unknown community name: 25" increments when an inbound SNMP packet carries a community string the router does not recognise. That directly evidences 25 requests rejected for invalid community strings, distinct from the ten "no such name" errors returned for missing OIDs.

Why this answer

The 'Unknown community name: 25' counter indicates that 25 incoming SNMP packets contained a community string that did not match any configured community on Router R1. This means those requests were rejected due to invalid community strings, making option A correct.

Exam trap

Cisco often tests the distinction between input and output packet counters, tricking candidates into confusing the total input (150) with the total output (200) or misinterpreting specific error counters like 'Unknown community name' as a different type of failure.

How to eliminate wrong answers

Option B is wrong because the output shows 'Trap PDUs: 0', meaning no traps were sent, not 150. Option C is wrong because 'Bad values errors: 0' indicates no set requests failed due to bad values; the 'Set-request PDUs: 0' further confirms no set requests were received. Option D is wrong because the router received 150 SNMP packets (SNMP packets input: 150), not 200; the 200 refers to SNMP packets output.

17
MCQhard

A large enterprise network uses EIGRP with route summarization. Router R1 has the following configuration: interface GigabitEthernet0/0, ip summary-address eigrp 100 10.0.0.0 255.255.252.0. Router R2 shows: show ip route eigrp includes 10.0.0.0/22 but not 10.0.3.0/24. What is the root cause?

A.The summary address is misconfigured; it should be 10.0.0.0/24.
B.R2 has a route filter blocking 10.0.3.0/24.
C.The EIGRP summary address suppresses more specific routes within its range.
D.R1's interface is down, preventing route advertisement.
AnswerC

The summary 10.0.0.0/22 installed on R1 automatically creates a discard route and suppresses the component 10.0.3.0/24 from being advertised, satisfying EIGRP's summarisation behaviour. R2 therefore receives only the aggregate, which is expected, not a fault.

Why this answer

The EIGRP `ip summary-address` command on R1 creates a summary route (10.0.0.0/22) that is advertised to R2, and by default EIGRP suppresses the advertisement of all more specific routes that fall within the summary range (10.0.0.0/22 includes 10.0.3.0/24). This is the intended behavior of EIGRP route summarization: the summary route replaces the component routes to reduce routing table size and update overhead.

Exam trap

Cisco often tests the misconception that EIGRP summarization simply advertises a summary route in addition to the more specific routes, when in fact the default behavior is to suppress all component routes within the summary range.

How to eliminate wrong answers

Option A is wrong because the summary address 10.0.0.0/22 is correctly configured to cover the range 10.0.0.0–10.0.3.255; changing it to /24 would only cover 10.0.0.0/24 and would not suppress 10.0.3.0/24. Option B is wrong because there is no evidence of a route filter; the absence of 10.0.3.0/24 is a direct result of the summary address suppression, not a filter. Option D is wrong because if R1's interface were down, R2 would not see the 10.0.0.0/22 summary route either, but the output shows 10.0.0.0/22 is present in R2's routing table.

18
MCQmedium

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast 10.5.5.0/24 BGP routing table entry for 10.5.5.0/24, version 12 Paths: (1 available, best #1, table default) Advertised to update-groups: 1 Refresh Epoch 1 65007 10.1.17.7 from 10.1.17.7 (10.7.7.7) Origin IGP, metric 0, localpref 100, valid, external, best rx pathid: 0, tx pathid: 0x0 Based on this output, what does the 'r' in the status codes indicate if present? (Not shown here, but the engineer notices a similar route with 'r' status.)

A.The route is suppressed by a route-map.
B.The route is not valid due to next-hop unreachability.
C.The route is a RIB-failure, meaning it is not installed in the routing table because another route with a lower administrative distance exists.
D.The route is dampened.
AnswerC

The 'r' code marks a RIB-failure: BGP selected the path as best, but the route was rejected for installation into the IP routing table because a route with a lower administrative distance already exists for that prefix.

Why this answer

In Cisco BGP show output, the status code 'r' stands for RIB-failure, meaning the route was selected as best by BGP but was not installed in the IP routing table because another route (typically with a lower administrative distance, such as a static or IGP route) already occupies that prefix. The BGP route remains in the BGP table and is still advertised to peers, but it is not used for forwarding. This is a common troubleshooting scenario when a static route shadows a BGP-learned prefix.

Exam trap

The trap here is confusing the BGP status codes 'r', 's', 'd', and 'i' — candidates often pick 'suppressed' or 'dampened' because they sound similar, but only 'r' means the route lost RIB installation to a lower-AD route.

How to eliminate wrong answers

Option A is wrong because suppression by a route-map is indicated by the status code 's' (suppressed), not 'r'. Option B is wrong because next-hop unreachability is shown by the status code 'i' (invalid) or by the absence of 'valid' in the path entry. Option D is wrong because route dampening is indicated by the status code 'd' (damped), which appears when a flapping route has been penalized.

19
Multi-Selectmedium

Which TWO statements about MPLS label imposition (push) are true? (Choose TWO.)

Select 2 answers
A.Label imposition occurs at the ingress LSR.
B.Label imposition occurs at the egress LSR.
C.The imposed label is determined by the Forwarding Equivalence Class (FEC).
D.The imposed label is always the top label in a label stack.
E.Label imposition is performed using the 'tag-switching' command.
AnswersA, C

Label imposition happens at the ingress label switching router, where the edge device classifies incoming packets and pushes the MPLS shim header before forwarding into the provider core. This satisfies the stem's requirement that push operations occur at the network edge, not on transit or egress routers deeper within the MPLS domain.

Why this answer

Label imposition occurs at the ingress LSR, which pushes a label onto an unlabeled IP packet. The label is based on the FEC (Forwarding Equivalence Class) derived from the IP destination. The egress LSR pops the label, not imposes it.

20
MCQmedium

A network engineer is implementing Zone-Based Policy Firewall (ZPFW) on a Cisco IOS router. The router has three interfaces: inside, outside, and DMZ. The engineer wants to allow HTTP traffic from the inside zone to the DMZ zone, and block all other traffic from inside to DMZ. Which configuration is required?

A.Configure a class-map that matches HTTP and apply it as an inspect action in the global policy.
B.Define a zone pair from inside to DMZ, apply a policy-map that inspects HTTP and drops all other traffic.
C.Apply an ACL on the inside interface permitting HTTP to the DMZ and denying all other traffic.
D.Create a zone pair from DMZ to inside and apply a policy-map that permits HTTP return traffic.
AnswerB

Zone-Based Policy Firewall uses zone pairs to define traffic flows between zones. To allow HTTP from inside to DMZ and block other traffic, a zone pair must be created from inside to DMZ, and a policy-map applied that permits HTTP and implicitly drops all other traffic. This meets the requirement.

Why this answer

In ZPFW, traffic between zones is controlled by zone pairs. A zone pair from inside to DMZ with a policy-map that inspects HTTP and implicitly drops other traffic will allow only HTTP and block the rest. Other options either do not use ZPFW correctly or apply the policy in the wrong direction.

Exam trap

The trap here is forgetting that ZPFW requires a zone pair to define the direction of traffic; applying a policy-map without a zone pair has no effect.

21
MCQeasy

In BGP, what is the default administrative distance for eBGP routes?

A.20
B.200
C.120
D.110
AnswerA

eBGP routes carry a default administrative distance of 20, making them preferred over iBGP (200), OSPF (110) and RIP (120). This low value reflects eBGP's trustworthiness as an exterior gateway protocol learned from directly connected external peers.

Why this answer

Cisco IOS assigns eBGP routes a default administrative distance of 20, making them more trusted than OSPF (110), RIP (120), and iBGP (200). This low AD ensures that when the same prefix is learned via eBGP and an IGP, the eBGP route is preferred in the routing table. The value 20 is a Cisco-specific default and is configurable via the 'distance bgp' command.

Exam trap

The trap is confusing eBGP's AD (20) with iBGP's AD (200) — candidates often swap these two values under exam pressure.

How to eliminate wrong answers

Option B is wrong because 200 is the default administrative distance for iBGP routes, not eBGP. Option C is wrong because 120 is the default AD for RIP. Option D is wrong because 110 is the default AD for OSPF.

22
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip ospf database summary 172.16.0.0 OSPF Router with ID (1.1.1.1) (Process ID 1) Summary Net Link States (Area 0) LS age: 100 Options: (No TOS-capability, DC) LS Type: Summary Links(Network) Link State ID: 172.16.0.0 (Summary Network Number) Advertising Router: 2.2.2.2 LS Seq Number: 80000001 Checksum: 0x1234 Length: 28 Network Mask: /20 TOS: 0 Metric: 10 Based on this output, what does this LSA represent?

A.It is a router LSA from R1.
B.It is a summary route for 172.16.0.0/20 advertised by ABR 2.2.2.2.
C.It is an external route from ASBR.
D.It is a network LSA for the 172.16.0.0 network.
AnswerB

The Type 3 summary LSA carries Link State ID 172.16.0.0 with Network Mask /20, giving the prefix 172.16.0.0/20. Advertising Router 2.2.2.2 identifies the ABR that generated it, and the Summary Net Link States (Area 0) heading confirms inter-area propagation into Area 0.

Why this answer

This is a Type 3 Summary LSA, which is used to advertise inter-area routes. The Advertising Router is 2.2.2.2, an ABR.

23
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip access-lists Extended IP access list 170 10 permit icmp any any echo (100 matches) 20 permit icmp any any echo-reply (80 matches) 30 deny ip any any (10 matches) Based on this output, which statement is correct?

A.All ICMP traffic is permitted.
B.Only ICMP echo and echo-reply are permitted; all other IP traffic is denied.
C.The ACL permits all IP traffic.
D.The ACL is not applied.
AnswerB

The access list permits ICMP echo and echo-reply, then explicitly denies all remaining IP traffic via the final deny ip any any entry. Only those two ICMP message types pass; every other protocol is dropped.

Why this answer

The ACL 170 explicitly permits only ICMP echo (type 8) and echo-reply (type 0) traffic, as shown by the match counters. The final deny ip any any statement blocks all other IP traffic, including other ICMP types and non-ICMP IP protocols. Therefore, only ICMP echo and echo-reply are permitted; all other IP traffic is denied, making option B correct.

Exam trap

Cisco often tests the misconception that an ACL with only two permit statements for specific ICMP types permits all ICMP traffic, but the explicit or implicit deny ip any any at the end blocks all other ICMP types and non-ICMP IP traffic.

How to eliminate wrong answers

Option A is wrong because the ACL does not permit all ICMP traffic; it only permits ICMP echo and echo-reply, while other ICMP types (e.g., destination unreachable, time-exceeded) are denied by the final deny ip any any statement. Option C is wrong because the ACL explicitly denies all IP traffic with the last statement, so it does not permit all IP traffic. Option D is wrong because the show ip access-lists output displays match counters (100 and 80 matches), which indicate the ACL is applied to an interface and actively processing traffic; an unapplied ACL would show zero matches.

24
MCQeasy

A network engineer runs the following command on Router R1: R1# show ip sla statistics 1 IPSLAs Latest Operation Statistics IPSLA operation id: 1 Type of operation: icmp-echo Latest RTT: 10 milliseconds Latest operation start time: 00:15:30 UTC Mon Mar 1 2021 Latest operation return code: OK Number of successes: 100 Number of failures: 0 Operation time to live: Forever Based on this output, which statement is correct?

A.The IP SLA operation has failed 100 times.
B.The IP SLA operation is successful and has a low RTT.
C.The IP SLA operation type is udp-jitter.
D.The IP SLA operation has expired.
AnswerB

The output confirms 100 successes with zero failures, so the icmp-echo probe is completing reliably. A latest RTT of 10 milliseconds satisfies the low-latency expectation, and the OK return code verifies each operation finished within its configured timeout threshold.

Why this answer

The output shows an IP SLA operation of type icmp-echo with a return code 'OK', 100 successes, and 0 failures. This indicates the operation is functioning correctly.

25
MCQmedium

A network engineer runs the following command on Router R1: R1# show mpls ldp neighbor Peer LDP Ident: 192.168.2.2:0, Local LDP Ident: 192.168.1.1:0 TCP connection: 10.1.1.2.646 - 10.1.1.1.646 State: Oper; Msgs sent/rcvd: 100/100; Downstream Up time: 00:45:00 LDP discovery sources: GigabitEthernet0/0, Src IP addr: 10.1.1.2 Addresses bound to peer LDP Ident: 10.1.1.2 192.168.2.2 Based on this output, what is the state of the LDP session?

A.The LDP session is operational and exchanging label information.
B.The LDP session is in a down state due to a TCP reset.
C.The LDP session is in initialization state because no labels have been exchanged.
D.The LDP session is using UDP instead of TCP.
AnswerA

The session shows State: Oper with 100 messages sent and received, confirming both peers actively exchange label mappings over the TCP connection on port 646. The 45-minute uptime and populated peer address bindings further evidence a stable, fully established LDP adjacency satisfying the operational requirement.

Why this answer

The output shows 'State: Oper', which indicates the LDP session is operational. The 'Downstream' label distribution mode and the fact that messages have been sent and received (100/100) confirm that the session is actively exchanging label information. This matches the correct answer that the LDP session is operational and exchanging label information.

Exam trap

Cisco often tests the distinction between LDP discovery (UDP) and session establishment (TCP), and the trap here is that candidates may confuse the 'Oper' state with an initialization state or incorrectly assume UDP is used for the entire LDP process.

How to eliminate wrong answers

Option B is wrong because the state is 'Oper' (operational), not down; a TCP reset would show a different state like 'Down' or 'Initialized'. Option C is wrong because the 'Oper' state indicates the session is fully established and labels are being exchanged, not in an initialization state where no labels have been exchanged. Option D is wrong because LDP uses TCP (port 646) for session establishment and label exchange, as shown in the output (TCP connection: 10.1.1.2.646 - 10.1.1.1.646); UDP is used only for LDP discovery (hello messages).

26
MCQhard

A network engineer is configuring an MPLS L3VPN on a Cisco IOS XE PE router. The customer edge (CE) router uses eBGP to peer with the PE router. The engineer wants to ensure that the CE can advertise its routes to the PE and that the PE can propagate them to other PE routers via MP-BGP. The engineer has configured the VRF, the PE-CE eBGP session, and MP-BGP on the PE. However, the routes from the CE are not appearing in the MP-BGP table. Which configuration step is most likely missing on the PE router?

A.The PE router must be configured with 'neighbor <CE-IP> remote-as <AS>' under the global BGP configuration.
B.The PE router must be configured with 'router bgp <AS>' and 'address-family vpnv4 unicast' to enable MP-BGP.
C.The PE router must have 'ip vrf forwarding CUSTOMER' applied to the interface facing the CE.
D.The VRF must be enabled for IPv4 unicast address family under the BGP router configuration.
AnswerD

In Cisco IOS XE, when using MP-BGP for MPLS L3VPN, each VRF must have an address family configured under the BGP process. Specifically, the 'address-family ipv4 vrf CUSTOMER' command must be present, and the eBGP neighbor must be activated within that address family. Without this, BGP will not exchange routes for that VRF, even if the global BGP session is up.

Why this answer

In MPLS L3VPN, the PE router must configure a separate BGP address family for each VRF to exchange routes with CE routers. The 'address-family ipv4 vrf CUSTOMER' command under 'router bgp' activates the VRF context, and the eBGP neighbor must be activated within that address family. Without this, routes from the CE are not imported into BGP and thus not propagated via MP-BGP to other PEs.

Exam trap

The trap here is focusing on the global BGP neighbor configuration or the VPNv4 address family, while overlooking the necessity of the per-VRF IPv4 address family for CE peering.

27
MCQmedium

Consider the following EIGRP configuration on Router R1: router eigrp 100 network 10.0.0.0 passive-interface default no passive-interface GigabitEthernet0/0 What is the effect of this configuration?

A.EIGRP will form neighbor adjacencies on all interfaces.
B.EIGRP will form neighbor adjacencies only on GigabitEthernet0/0.
C.EIGRP will not form any neighbor adjacencies.
D.EIGRP will form neighbor adjacencies on all interfaces except GigabitEthernet0/0.
AnswerB

Passive-interface default suppresses EIGRP hello packets on every interface, preventing adjacency formation there. The no passive-interface GigabitEthernet0/0 exception re-enables hellos solely on that interface, so neighbours can only be discovered and adjacencies formed on GigabitEthernet0/0, satisfying the stem's configuration exactly.

Why this answer

The 'passive-interface default' command sets all interfaces to passive by default, preventing EIGRP from sending or receiving hello packets on them. The 'no passive-interface GigabitEthernet0/0' command then overrides this default for that specific interface, allowing EIGRP to send and receive hellos and thus form neighbor adjacencies only on GigabitEthernet0/0.

Exam trap

Cisco often tests the interaction between 'passive-interface default' and 'no passive-interface', where candidates mistakenly think the default command blocks all adjacencies permanently or confuse which interfaces are enabled versus disabled.

How to eliminate wrong answers

Option A is wrong because 'passive-interface default' makes all interfaces passive, so adjacencies are not formed on all interfaces. Option C is wrong because the 'no passive-interface GigabitEthernet0/0' command explicitly allows adjacency formation on that interface, so some adjacencies are formed. Option D is wrong because it reverses the logic: the 'no passive-interface' command enables, not disables, adjacency formation on GigabitEthernet0/0, so adjacencies are formed on that interface, not on all others.

28
MCQmedium

A network engineer runs the following command to verify BFD operation: R1# show bfd neighbors detail IPv4 Sessions NeighAddr LD/RD RH/RS State Int 10.1.1.2 1/2 Up Up Gi0/0 Session state is UP and not using echo function. Session type: single-hop Local Diag: 0, Demand mode: 0, Poll bit: 0 MinTxInt: 1000000, MinRxInt: 1000000, Multiplier: 3 Received MinRxInt: 1000000, Received Multiplier: 3 Holddown (hits): 0 (0), Hello (hits): 1000/5 Rx Count: 1000, Rx Interval (ms) min/max/avg: 900/1100/1000 Tx Count: 1000, Tx Interval (ms) min/max/avg: 900/1100/1000 What does this output indicate?

A.BFD session is using echo mode for fast failure detection.
B.BFD session is down and not sending hellos.
C.BFD session is operating with async mode, intervals at 1 second.
D.BFD session has a holddown timer of 3 seconds.
AnswerC

The absence of the echo function and the MinTxInt/MinRxInt values of 1000000 microseconds confirm asynchronous mode with 1-second intervals. Multiplier 3 gives a 3-second detection time, matching the stated async operation and interval values in the output.

Why this answer

The output shows a BFD session in UP state with consistent transmit and receive intervals around 1000 ms, no echo function, and a multiplier of 3. The session is healthy.

29
MCQmedium

A network engineer is configuring a Cisco IOS XE router to support First Hop Redundancy Protocol (FHRP) for a group of hosts on VLAN 10. The design requires that the virtual IP address and virtual MAC address remain the same even if the active router changes. The engineer decides to use Virtual Router Redundancy Protocol (VRRP) version 2. Which statement about VRRPv2 is true?

A.VRRPv2 allows preemption to be disabled only on the master router.
B.VRRPv2 supports IPv6 natively without any additional configuration.
C.VRRPv2 uses multicast address 224.0.0.2 for hello packets.
D.VRRPv2 uses a virtual MAC address of 0000.0c07.acXX, where XX is the group ID in hexadecimal.
AnswerD

VRRPv2 uses a virtual MAC address derived from the VRRP group ID. The format is 0000.0c07.acXX, where XX is the group ID in hexadecimal. This ensures that the virtual MAC remains consistent regardless of which router is the master. The virtual IP and MAC are maintained during failover, providing seamless redundancy. This is a key characteristic of VRRP, distinguishing it from HSRP, which uses a different MAC format.

Why this answer

VRRPv2 uses the virtual MAC address 0000.0c07.acXX, where XX is the VRRP group ID in hexadecimal. This ensures a consistent virtual MAC for hosts, regardless of which physical router is master. The other statements are incorrect: VRRPv2 does not support IPv6 (that requires VRRPv3), it uses multicast 224.0.0.18 (not 224.0.0.2), and preemption can be disabled on any router, not just the master.

Exam trap

The trap here is mixing up VRRPv2 details with HSRP, such as the multicast address and MAC address format.

30
MCQmedium

A network engineer is troubleshooting a dual-stack Cisco IOS XE router that runs OSPFv3 for IPv6 and OSPFv2 for IPv4. IPv4 adjacencies form and routes are exchanged, but no OSPFv3 adjacencies form and no IPv6 routes appear. The engineer verifies that the interfaces have IPv6 addresses and that `ipv6 unicast-routing` is enabled. Which configuration step is most likely missing?

A.Configure an IPv6 address on the OSPFv3 process using the `ipv6 address` command under `router ospfv3`.
B.Configure an OSPFv3 router ID with the `router-id` command under the OSPFv3 process.
C.Enable IPv6 unicast routing globally with the `ipv6 unicast-routing` command.
D.Enable OSPFv3 on the interfaces by adding them to an OSPFv3 process with the `ipv6 ospf 1 area 0` interface command.
AnswerD

OSPFv3 does not automatically enable on interfaces when the process is created; each interface must be explicitly enabled with `ipv6 ospf <process-id> area <area-id>` or by using `ipv6 ospf area` under the interface. Without this command, the router will not send or process OSPFv3 hellos, so no adjacency forms even though IPv6 addressing and unicast routing are configured correctly.

Why this answer

OSPFv3 requires explicit interface activation; creating the process and enabling global IPv6 routing are not enough. The `ipv6 ospf <process-id> area <area-id>` interface command enables OSPFv3 on that link and triggers hello packets. Without it, no OSPFv3 neighbor relationships form, even though IPv6 addressing and forwarding are correctly configured.

This is a common oversight when migrating from OSPFv2, where network statements under the process can enable interfaces indirectly.

Exam trap

The trap here is assuming OSPFv3 is enabled on interfaces simply because the OSPFv3 process exists and IPv6 routing is globally enabled.

31
MCQeasy

What is the default behavior of an IPv4 access control list (ACL) when no explicit permit or deny statement matches a packet?

A.The packet is permitted.
B.The packet is denied.
C.The packet is logged and then permitted.
D.The ACL is ignored and the packet is forwarded.
AnswerB

An IPv4 ACL carries an implicit deny any at its end. When no configured statement matches the packet, that hidden final entry drops it, so traffic not explicitly permitted is discarded. This default protects the interface without any manual deny rule.

Why this answer

By default, IPv4 ACLs have an implicit deny any statement at the end. If a packet does not match any explicit permit or deny entry, the implicit deny any is applied, causing the packet to be dropped. This behavior is fundamental to ACL security, ensuring that only explicitly permitted traffic is allowed.

Exam trap

Cisco often tests the misconception that an ACL with no matching entries will permit traffic by default, or that the ACL is simply ignored, when in fact the implicit deny any silently drops all unmatched packets.

How to eliminate wrong answers

Option A is wrong because the default behavior is to deny, not permit; an ACL does not permit unmatched packets. Option C is wrong because logging is not a default action for unmatched packets; logging is only performed if explicitly configured with a log keyword on a permit or deny statement. Option D is wrong because the ACL is never ignored; the implicit deny any is always present and enforced, so unmatched packets are dropped, not forwarded.

32
MCQmedium

A network engineer is implementing policy-based routing (PBR) on a Cisco IOS router. The engineer wants to route traffic from the 10.1.1.0/24 subnet to a next-hop of 192.168.1.1, while all other traffic uses the default routing table. Which configuration correctly implements this?

A.route-map PBR permit 10 match ip address 10 set ip next-hop 192.168.1.1 ! interface GigabitEthernet0/0 ip policy route-map PBR ! access-list 10 permit 10.1.1.0 0.0.0.255
B.route-map PBR permit 10 match ip address 10 set ip default next-hop 192.168.1.1 ! interface GigabitEthernet0/0 ip policy route-map PBR ! access-list 10 permit 10.1.1.0 0.0.0.255
C.route-map PBR permit 10 match ip address 10 set ip next-hop 192.168.1.1 ! interface GigabitEthernet0/0 ip route-cache policy ! access-list 10 permit 10.1.1.0 0.0.0.255
D.route-map PBR permit 10 match ip address 10 set interface GigabitEthernet0/1 ! interface GigabitEthernet0/0 ip policy route-map PBR ! access-list 10 permit 10.1.1.0 0.0.0.255
AnswerA

This configuration creates a route map that matches traffic from the 10.1.1.0/24 subnet (via access list 10) and sets the next-hop to 192.168.1.1. The route map is applied to the interface with the ip policy route-map command. This correctly implements policy-based routing for the specified subnet, while other traffic will follow the normal routing table.

Why this answer

Policy-based routing (PBR) allows you to override the normal routing table based on criteria such as source IP address. The correct configuration uses a route map with a match statement for the source subnet and a set statement to define the next-hop. The route map is then applied to the interface with the ip policy route-map command.

The set ip next-hop command ensures that matched traffic is forwarded to the specified next-hop, while other traffic uses the default routing table.

Exam trap

The trap here is confusing set ip next-hop with set ip default next-hop; the latter only applies when there is no explicit route in the routing table.

33
MCQmedium

A network engineer is troubleshooting a route redistribution issue between OSPF and EIGRP. Routers R1 (OSPF) and R2 (EIGRP) are redistributing routes into each other. The engineer notices that some OSPF external routes are not appearing in the EIGRP topology table on R2, although the redistribution is configured. The show ip eigrp topology command on R2 does not list the missing prefixes. What is the most likely cause?

A.The redistribute ospf command under EIGRP is missing the match internal keyword.
B.The redistribute ospf command under EIGRP is missing the match external keyword.
C.The OSPF process on R1 has a route filter blocking external routes.
D.EIGRP has a lower administrative distance than OSPF, causing route suppression.
AnswerB

Correct: Without match external, OSPF external routes are not redistributed into EIGRP.

Why this answer

When redistributing OSPF routes into EIGRP, by default only internal OSPF routes (routes within the OSPF domain) are redistributed. To include OSPF external routes (routes redistributed into OSPF from other protocols), the 'match external' keyword must be specified in the redistribute command. Since the missing prefixes are OSPF external routes, the most likely cause is that the redistribute command under EIGRP is missing the 'match external' keyword.

Exam trap

The trap is assuming that 'redistribute ospf' redistributes all OSPF routes by default. In reality, only internal routes are redistributed unless 'match external' is specified. Candidates often overlook this default behavior.

How to eliminate wrong answers

Option A is wrong because 'match internal' is the default and would only redistribute internal OSPF routes; it would not help include external routes. Option C is wrong because if OSPF had a route filter blocking external routes, those routes would not be in the OSPF database at all, but the issue is that they are not appearing in EIGRP topology, implying they are present in OSPF but not redistributed. Option D is wrong because administrative distance affects route selection when the same prefix is learned from multiple sources, but it does not prevent redistribution into EIGRP; the routes would still be in the EIGRP topology table.

34
MCQhard

An engineer configures unicast Reverse Path Forwarding (uRPF) in strict mode on an interface. Traffic from a legitimate source IP is being dropped. The network has asymmetric routing. Which is the most likely explanation?

A.The router receives the packet on an interface that is not the best return path to the source IP, causing strict uRPF to drop it.
B.The source IP is not in the routing table at all.
C.The uRPF configuration is missing the 'allow-default' option.
D.The router is using loose mode instead of strict mode.
AnswerA

Strict uRPF performs a two-part check: first, the source IP must exist in the FIB, and second, the inbound interface must be the exact interface used to reach the source IP. When traffic arrives on an interface that is not the best return path (e.g., due to asymmetric routing with equal-cost paths or policy-based routing), the router sees the source as unreachable via that interface and silently drops the packet. Even though the source is legitimate and routable, strict mode is intolerant of any interface mismatch, making this the correct explanation for the drop.

Why this answer

Strict uRPF verifies that the source IP of an incoming packet is reachable via the exact interface on which the packet arrived. In asymmetric routing, the return path to the source may use a different interface, causing the router to see the incoming interface as not matching the best return path in the FIB. This mismatch triggers a drop, even though the source IP is legitimate and reachable.

Exam trap

Cisco often tests the distinction between strict and loose uRPF modes, and the trap here is that candidates assume any uRPF drop means the source is unreachable, when in fact asymmetric routing causes strict mode to drop legitimate traffic that would pass in loose mode.

How to eliminate wrong answers

Option B is wrong because if the source IP were not in the routing table at all, strict uRPF would also drop the packet, but the question states the source IP is legitimate and the network has asymmetric routing — the issue is interface mismatch, not absence of a route. Option C is wrong because the 'allow-default' option is used in loose mode to permit packets whose source matches a default route; strict mode does not use this option, and its absence is not the cause of drops in asymmetric routing. Option D is wrong because loose mode would actually accept the packet as long as the source IP has any route in the FIB, regardless of the incoming interface; the problem described (drops with asymmetric routing) is a classic symptom of strict mode, not loose mode.

35
MCQmedium

A network engineer is configuring a Cisco IOS XE router as a Dynamic Multipoint VPN (DMVPN) Phase 3 hub. The hub must support spoke-to-spoke direct tunnels while allowing the hub to remain in the data path for initial spoke-to-spoke communication. The engineer has configured the tunnel interface with 'ip nhrp redirect' on the hub. Which additional command must be configured on the spoke routers to enable them to dynamically create direct tunnels to other spokes?

A.ip nhrp map multicast dynamic
B.ip nhrp holdtime 300
C.ip nhrp shortcut
D.ip nhrp network-id 100
AnswerC

The ip nhrp shortcut command on the spoke enables it to intercept transit traffic that the hub redirects. When the hub sends an NHRP redirect message, the spoke creates a shortcut entry in its NHRP mapping table and can then establish a direct tunnel to the destination spoke. Without this command, the spoke continues to forward all traffic through the hub.

Why this answer

In DMVPN Phase 3, the hub uses ip nhrp redirect to inform a spoke that a better path exists. The spoke must have ip nhrp shortcut configured to act on that redirect, install a shortcut route, and initiate a direct tunnel to the destination spoke. This combination allows dynamic spoke-to-spoke tunnels while the hub remains involved only for initial resolution.

Exam trap

The trap here is confusing hub-side commands like ip nhrp redirect with spoke-side commands needed to create shortcuts, or assuming that basic NHRP configuration alone enables Phase 3 behavior.

36
MCQmedium

A network engineer runs the following command to troubleshoot a BGP Troubleshooting issue: R1# show bgp neighbors 10.1.1.2 received-routes BGP table version is 14, local router ID is 1.1.1.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.0.0.0/24 10.1.1.2 0 100 0 65001 i *> 192.168.1.0/24 10.1.1.2 0 100 0 65001 i Total number of prefixes 2 What does this output indicate?

A.R1 is receiving two routes from neighbor 10.1.1.2, both from AS 65001.
B.R1 is sending two routes to neighbor 10.1.1.2.
C.R1 is receiving two routes, but one is filtered out by inbound policy.
D.R1 is receiving two routes, but the neighbor is not reachable.
AnswerA

The output lists two prefixes, 10.0.0.0/24 and 192.168.1.0/24, each with next hop 10.1.1.2 and AS path "65001 i". The received-routes keyword confirms these are inbound advertisements accepted from that neighbour, satisfying the stem's requirement to identify what R1 receives from 10.1.1.2.

Why this answer

The command 'show bgp neighbors 10.1.1.2 received-routes' displays all routes received from the specified neighbor before any inbound filtering. The output shows two prefixes, both with next hop 10.1.1.2, and the AS path indicates they originated from AS 65001. The status codes show '*' for valid and '>' for best, meaning both are valid and best.

Therefore, R1 is receiving two routes from neighbor 10.1.1.2, both from AS 65001.

Exam trap

The trap is confusing 'received-routes' with 'advertised-routes' or 'routes'. Candidates might think the command shows routes sent to the neighbor or routes after filtering. Also, they might misinterpret the status codes and think a route is filtered when it is actually valid.

How to eliminate wrong answers

Option B is wrong because 'received-routes' shows routes received from the neighbor, not sent to the neighbor; to see sent routes, use 'show bgp neighbors <ip> advertised-routes'. Option C is wrong because the output shows both routes as valid and best, with no indication of filtering; if a route were filtered, it would not appear in the received-routes output (or would be marked as filtered if using 'show bgp neighbors <ip> routes'). Option D is wrong because the neighbor is reachable; otherwise, the routes would not be received, and the output would show no routes or an error.

37
MCQeasy

What is the default maximum hop count for RIP routes in Cisco IOS?

A.15
B.16
C.255
D.10
AnswerA

RIP treats 15 as the maximum usable metric, counting each router traversed as one hop. A route reaching 16 is marked unreachable, which bounds the protocol's diameter and prevents count-to-infinity loops. Cisco IOS applies this default without configuration.

Why this answer

RIP uses hop count as its metric, with a maximum valid hop count of 15. A hop count of 16 is considered infinity, meaning the destination is unreachable. This limit prevents routing loops but restricts RIP to small networks.

The default maximum hop count in Cisco IOS is 15, as defined in RFC 1058 and 2453.

Exam trap

The trap is confusing the maximum hop count (15) with the infinity value (16). Candidates might think 16 is the maximum because it's the next number, but it actually signifies an unreachable route.

How to eliminate wrong answers

Option B is wrong because 16 represents infinity in RIP, not the maximum hop count. Option C is wrong because 255 is the maximum for other protocols like IGRP/EIGRP, not RIP. Option D is wrong because 10 is not a standard RIP limit; it might be confused with other metrics.

38
MCQeasy

Which of the following is a valid 'set' action in a PBR route-map?

A.set metric 100
B.set ip next-hop 10.0.0.1
C.set tag 5
D.set community 100:100
AnswerB

`set ip next-hop 10.0.0.1` is a valid PBR route-map set action, redirecting matched traffic to the specified next-hop address rather than following the routing table. It satisfies the stem's requirement for a legitimate set clause, unlike invalid commands such as `set ip next-hop verify-availability` used without a tracking object.

Why this answer

In Cisco PBR (Policy-Based Routing) route-maps, 'set ip next-hop 10.0.0.1' is a valid set action that specifies the next-hop IP address for matching packets, overriding the normal routing table lookup. This is one of the most commonly used PBR set commands and is supported in route-map configuration mode.

Exam trap

300-410 often tests whether candidates can distinguish PBR route-map set actions (like 'set ip next-hop') from routing-protocol route-map set actions (like 'set metric', 'set tag', 'set community'), catching those who assume all route-map commands are interchangeable.

How to eliminate wrong answers

Option A is wrong because 'set metric 100' is not a valid PBR route-map command — metric is a routing protocol attribute set via redistribution or route-map in routing protocol context, not in PBR. Option C is wrong because 'set tag 5' is used in route redistribution route-maps for routing protocols (like OSPF or EIGRP), not in PBR route-maps. Option D is wrong because 'set community 100:100' is a BGP-specific command used in BGP route-maps, not in PBR.

39
MCQmedium

An engineer is troubleshooting a network where R1 and R2 are running iBGP, and R1 learns the prefix 192.168.1.0/24 from R2 with an AD of 200. R1 also learns the same prefix via OSPF from R3 with AD 110. The engineer notices that R1 uses the iBGP route. What configuration change would cause this?

A.The engineer applied the distance bgp 20 200 200 command, which lowers eBGP AD but not iBGP.
B.The engineer applied the distance 150 0.0.0.0 255.255.255.255 under the OSPF process, raising OSPF AD to 150.
C.The engineer applied the distance bgp 20 100 200 command, lowering iBGP AD to 100.
D.The OSPF route is a type 5 LSA, which has a higher AD than type 3 LSAs.
AnswerC

The distance bgp 20 100 200 command sets the iBGP administrative distance to 100, which is lower than OSPF's 110, so the iBGP route to 192.168.1.0/24 becomes preferred over the OSPF path learned from R3.

Why this answer

The `distance bgp 20 100 200` command changes the administrative distance (AD) for BGP routes: the first value (20) is for external BGP (eBGP), the second (100) is for internal BGP (iBGP), and the third (200) is for locally originated routes. By setting the iBGP AD to 100, it becomes lower than OSPF's default AD of 110, so R1 prefers the iBGP route over the OSPF route. This directly explains why R1 uses the iBGP route despite OSPF's normally lower AD.

Exam trap

The trap here is that candidates may forget the default AD values or misremember the order of parameters in the `distance bgp` command, leading them to pick an option that sets iBGP AD higher than OSPF instead of lower.

How to eliminate wrong answers

Option A is wrong because `distance bgp 20 200 200` sets the iBGP AD to 200, which is higher than OSPF's 110, so the OSPF route would still be preferred. Option B is wrong because raising OSPF's AD to 150 would make OSPF less preferred, but the question states the engineer notices R1 uses the iBGP route; this change would also cause that, but it is not the configuration change described in the correct answer, and the command syntax `distance 150 0.0.0.0 255.255.255.255` under OSPF would set the AD for all OSPF routes to 150, which is a valid alternative but not the one that matches the scenario of lowering iBGP AD. Option D is wrong because OSPF type 5 LSAs (external routes) have the same default AD as other OSPF routes (110), not a higher AD; AD is not influenced by LSA type.

40
MCQmedium

In EIGRP, what is the default behavior of auto-summary in IOS-XE versions 15.0 and later?

A.Auto-summary is enabled by default.
B.Auto-summary is disabled by default.
C.Auto-summary is enabled only for EIGRP named mode.
D.Auto-summary is disabled only for EIGRP classic mode.
AnswerB

Auto-summary is disabled by default from IOS 15.0 onward, satisfying the question's version constraint. EIGRP therefore advertises subnet prefixes with their actual masks rather than collapsing them to classful boundaries, preventing the misleading routes and black holes that classful summarisation caused in discontiguous networks.

Why this answer

Starting with Cisco IOS 15.0(1)M and IOS-XE 15.x, EIGRP auto-summary is disabled by default for both classic and named modes. This change aligned EIGRP with modern classless routing behavior and prevents the suboptimal routing caused by summarizing at classful boundaries.

Exam trap

The trap is remembering the old default (enabled) from legacy IOS and applying it to 15.0+, or assuming named mode changed the default — candidates must recall that 15.0 flipped auto-summary to disabled for both modes.

How to eliminate wrong answers

Option A is wrong because auto-summary was enabled by default only in older IOS releases prior to 15.0; the question explicitly targets 15.0 and later where the default flipped to disabled. Option C is wrong because auto-summary default behavior is the same in classic and named modes — it is disabled in both, not enabled only for named mode. Option D is wrong because the default is disabled in both classic and named modes, not disabled only for classic mode; this option invents an asymmetry that does not exist.

41
MCQmedium

A network engineer is troubleshooting an issue where IPv6 traffic is being forwarded incorrectly on a switch. The switch is configured with IPv6 Source Guard on access ports. A legitimate host on port Fa0/1 with IPv6 address 2001:db8:1::10 is unable to send traffic to the default gateway. The engineer checks the IPv6 binding table and sees that the host's entry is missing. What is the most likely cause?

A.The host is using a static IPv6 address, and ND snooping is not enabled on the VLAN, so the binding was never learned.
B.The host's MAC address is not in the MAC address table for VLAN 1.
C.The switch is running IPv6 First Hop Security in monitor mode, which logs violations but does not drop traffic.
D.The default gateway router is not sending Router Advertisements, so the host cannot form a default route.
AnswerA

IPv6 Source Guard validates traffic by consulting the neighbor discovery (ND) snooping binding table, which records IPv6-to-MAC mappings learned from Neighbor Advertisements and Solicitations. If ND snooping is disabled on the VLAN, no binding entries are ever populated, even for hosts using statically configured IPv6 addresses. Because the switch has no record of this host's source IPv6 address, IPv6 Source Guard classifies the traffic as invalid and silently drops it, preventing forwarding despite the host being correctly configured.

Why this answer

IPv6 Source Guard relies on the IPv6 binding table, which is populated by IPv6 Neighbor Discovery (ND) snooping. If the host uses a static IPv6 address and ND snooping is not enabled on the VLAN, the switch never learns the binding, so IPv6 Source Guard drops the traffic as unauthorized. Enabling ND snooping allows the switch to inspect Neighbor Solicitation and Advertisement messages to build the binding table dynamically.

Exam trap

Cisco often tests the dependency of IPv6 Source Guard on ND snooping, and the trap here is that candidates assume IPv6 Source Guard works independently or that static addresses are automatically learned, when in fact the binding table must be populated either dynamically via ND snooping or manually.

How to eliminate wrong answers

Option B is wrong because the MAC address table is irrelevant to IPv6 Source Guard; the issue is the missing IPv6 binding, not Layer 2 forwarding. Option C is wrong because monitor mode logs violations but does not drop traffic, yet the symptom is that traffic is being dropped (forwarded incorrectly), indicating a blocking action. Option D is wrong because the host's inability to reach the default gateway is due to Source Guard dropping its packets, not because the host lacks a default route; Router Advertisements may still be sent and received, but the traffic is blocked at the switch.

42
MCQeasy

A network engineer runs the following command on Router PE3: PE3# show ip vrf interfaces Interface IP-Address VRF Protocol Gi0/0 10.1.1.1 CUSTOMER_C up Gi0/1 10.2.2.1 CUSTOMER_D up Based on this output, which statement is correct?

A.Both interfaces are correctly assigned to VRFs and are operational.
B.Interface Gi0/0 is down.
C.VRF CUSTOMER_C has no routes.
D.The router has no VRF configuration.
AnswerA

Both interfaces appear in the VRF interface table with unique IP addresses and Protocol status "up", confirming each is bound to its respective VRF (CUSTOMER_C and CUSTOMER_D) and forwarding traffic. This satisfies the stem's requirement that the interfaces are assigned and operational.

Why this answer

The output shows both Gi0/0 and Gi0/1 assigned to VRFs (CUSTOMER_C and CUSTOMER_D respectively) with the Protocol column reading 'up', which confirms the interfaces are operational and correctly bound to their VRFs. This is the expected healthy state for VRF-lite or MPLS PE interfaces.

Exam trap

300-410 often tests whether candidates over-read command output — the trap is inferring route or configuration state from a command that only shows interface bindings and protocol status.

How to eliminate wrong answers

Option B is wrong because the Protocol column for Gi0/0 shows 'up', directly contradicting the claim that the interface is down. Option C is wrong because the command 'show ip vrf interfaces' displays interface-to-VRF bindings and protocol state — it does not report routing table contents, so no conclusion about routes can be drawn. Option D is wrong because the output clearly shows two VRFs (CUSTOMER_C and CUSTOMER_D) configured and bound to interfaces, proving VRF configuration exists.

43
MCQhard

DMVPN network with hub R1 and spoke R2. R1 has: interface Tunnel0 ip address 172.16.1.1 255.255.255.0 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint ip nhrp network-id 1 ip nhrp authentication cisco123 R2 has: interface Tunnel0 ip address 172.16.1.2 255.255.255.0 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint ip nhrp network-id 1 ip nhrp nhs 172.16.1.1 ip nhrp authentication cisco123 R2 shows: R2# show dmvpn Legend: Attrb -> S: Static, D: Dynamic, I: Incomplete NHRP domain: 1 Interface: Tunnel0, IPv4 NHRP Details Type:Spoke, NHC:172.16.1.2, NBMA:10.2.2.2 (no NHRP mappings) R2# ping 172.16.1.1 source 172.16.1.2 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 172.16.1.1, timeout is 2 seconds: ..... Success rate is 0 percent (0/5) What is the root cause?

A.The hub R1 is missing the 'ip nhrp map multicast dynamic' command.
B.The authentication string is mismatched between hub and spoke.
C.The tunnel mode on R2 should be 'tunnel mode gre ip' instead of multipoint.
D.The NHRP network ID must be different on hub and spoke.
AnswerA

Without this command, the hub does not accept NHRP registrations from spokes, so the spoke cannot build a mapping.

Why this answer

The NHRP authentication strings do not match: R1 has 'cisco123', R2 has 'cisco123'? They match. But the output shows no NHRP mappings. The issue is that the spoke R2 has not registered with the hub.

This could be due to a mismatch in NHRP network ID, but they match. Another possibility is that the hub's tunnel interface is not configured with 'ip nhrp map multicast dynamic' to accept registrations. Without that, the hub does not add the spoke to its NHRP database, and the spoke cannot resolve the hub's NBMA address.

The ping fails because the spoke has no NHRP mapping for the hub.

44
MCQmedium

What is missing from this RSPAN configuration on a switch? monitor session 1 source interface GigabitEthernet1/0/1 both monitor session 1 destination remote vlan 100 Assume VLAN 100 exists but is not configured as an RSPAN VLAN.

A.The 'remote-span' command under VLAN 100.
B.An IP address on the destination interface.
C.A destination interface on the source switch.
D.The 'no shutdown' command on VLAN 100.
AnswerA

Without the `remote-span` keyword under VLAN 100, the switch treats it as an ordinary VLAN, so the destination remote vlan command cannot forward mirrored traffic across the trunk to the destination switch. Enabling `remote-span` designates it as the dedicated RSPAN VLAN, satisfying the stem's stated constraint.

Why this answer

For RSPAN to work, the VLAN used as the destination remote VLAN must be configured with the 'remote-span' command. Without it, the session will not function correctly.

45
MCQeasy

What is the default EIGRP hello interval on a point-to-point serial interface with bandwidth 1544 Kbps?

A.5 seconds
B.60 seconds
C.10 seconds
D.30 seconds
AnswerA

Incorrect. The 5-second hello interval applies only to interfaces with bandwidth greater than 1544 Kbps, not exactly 1544 Kbps.

Why this answer

EIGRP hello intervals depend on interface type and bandwidth. On point-to-point serial interfaces (and multipoint interfaces with bandwidth greater than T1), the default hello interval is 5 seconds. On multipoint interfaces with bandwidth of T1 (1544 Kbps) or lower, the default is 60 seconds.

Since the question specifies a point-to-point serial interface at 1544 Kbps, the correct default is 5 seconds.

Exam trap

The trap is assuming that low bandwidth (T1 or lower) always means a 60-second hello interval. In reality, the 60-second interval applies only to multipoint interfaces at T1 or lower; point-to-point serial interfaces use 5 seconds regardless of bandwidth.

How to eliminate wrong answers

Option A is wrong because 5 seconds is the default hello interval on multipoint interfaces and on point-to-point interfaces with bandwidth greater than T1 (e.g., 10 Mbps or higher). Option C is wrong because 10 seconds is not a default EIGRP hello interval for any standard interface type. Option D is wrong because 30 seconds is not an EIGRP default hello value; it is sometimes confused with other protocol timers.

46
MCQmedium

Which statement correctly describes the behavior of PBR when the next-hop specified in a 'set ip next-hop' command is unreachable?

A.The packet is dropped immediately.
B.The router sends an ICMP unreachable message.
C.The router uses the routing table to forward the packet.
D.The router uses the default route if configured.
AnswerC

When the configured next-hop is unreachable, policy-based routing falls back to the routing information base rather than dropping the packet. The router performs a recursive lookup and forwards using the best matching route, satisfying the stem's scenario of an unreachable set ip next-hop target.

Why this answer

When the next-hop specified by 'set ip next-hop' is unreachable, PBR does not drop the packet by default. Instead, the router falls back to the normal routing table lookup for the destination and forwards the packet accordingly. This fallback behavior preserves connectivity when the PBR next-hop fails.

Exam trap

The trap is assuming PBR drops packets when the next-hop is unreachable, when in fact the default behavior is to fall back to the routing table.

How to eliminate wrong answers

Option A is wrong because PBR does not drop packets on unreachable next-hop unless 'set ip next-hop verify-availability' with tracking is configured and the track fails. Option B is wrong because the router does not generate ICMP unreachable for PBR next-hop failures; it silently falls back. Option D is wrong because the fallback is to the routing table in general, not specifically to the default route — the default route is only used if it is the best match in the RIB.

47
MCQhard

An EIGRP network is experiencing a stuck-in-active (SIA) condition for a route 192.168.1.0/24. R1 has the following configuration: router eigrp 100 network 10.0.0.0 distribute-list prefix PL-FILTER in. R2 shows: 'show ip eigrp topology 192.168.1.0/24' is in active state, and 'show ip eigrp events' shows that R1 sent a query but never received a reply. R1's prefix-list PL-FILTER permits only 10.0.0.0/8. What is the root cause?

A.The distribute-list inbound on R1 filters the EIGRP query for 192.168.1.0/24, preventing R1 from replying and causing SIA on R2.
B.The EIGRP K-values are mismatched between R1 and R2.
C.The route 192.168.1.0/24 is not in R1's topology table, so it cannot reply.
D.The EIGRP timers on R1 are set too high, causing a delay in reply.
AnswerA

EIGRP distribute-lists applied inbound also filter queries. Since the prefix 192.168.1.0/24 is not permitted by PL-FILTER, R1 drops the query and does not send a reply, leaving R2 in active state.

Why this answer

The distribute-list prefix PL-FILTER in on R1 filters incoming routes, but it also affects queries. When R2 sends a query for 192.168.1.0/24, R1 receives it but the distribute-list filters the query (since the prefix is not permitted), so R1 does not process it and does not send a reply. This causes R2 to wait indefinitely for a reply, leading to an SIA condition.

The distribute-list should be applied outbound or should permit the necessary prefixes to allow queries to be processed.

48
MCQhard

MPLS network: LDP neighbors are down between R1 and R2. R1 shows: show mpls ldp neighbor includes nothing. R2 has: interface GigabitEthernet0/0, mpls ip, but R1 has no mpls ip on its interface. What is the root cause?

A.R1 and R2 are in different MPLS domains.
B.R1's interface lacks the mpls ip command, preventing LDP hello transmission.
C.LDP router IDs are not reachable.
D.The label distribution protocol is set to TDP instead of LDP.
AnswerB

LDP discovers neighbours by exchanging hello messages on interfaces where MPLS is enabled. Without the mpls ip command on R1's interface, no hellos are sent or received, so no neighbour session forms and show mpls ldp neighbor returns nothing — exactly the stem's symptom.

Why this answer

The root cause is that R1's interface is missing the 'mpls ip' command. This command is required on each interface to enable MPLS forwarding and to send LDP hello messages (UDP port 646) to neighbors. Without it, R1 cannot discover R2 as an LDP neighbor, so the LDP session never forms, and 'show mpls ldp neighbor' returns nothing on R1.

Exam trap

Cisco often tests the specific requirement of the 'mpls ip' interface command for LDP neighbor discovery, leading candidates to incorrectly focus on reachability or protocol version issues when the problem is a missing interface-level command.

How to eliminate wrong answers

Option A is wrong because MPLS domains are not a standard concept; LDP operates within a single routing domain (e.g., OSPF or IS-IS area), and mismatched domains would not prevent LDP hellos if interfaces are correctly configured. Option C is wrong because LDP router IDs not being reachable would prevent the TCP session from establishing after hellos are exchanged, but here no hellos are sent at all due to the missing 'mpls ip' command. Option D is wrong because TDP is a Cisco proprietary protocol (pre-standard) that is not used in modern IOS; even if TDP were configured, it would still require the 'mpls ip' command on the interface to send TDP hellos.

49
MCQmedium

A network engineer is troubleshooting PBR on a Cisco router where traffic from subnet 172.16.1.0/24 should be forwarded to next-hop 10.10.10.2. The route map 'PBR-172' is applied to interface GigabitEthernet0/0. The engineer notices that the PBR policy is not working at all. The engineer checks the route map configuration and sees 'match ip address 110' and 'set ip next-hop 10.10.10.2'. The engineer also checks the ACL 110 and confirms it matches 172.16.1.0/24. The engineer then checks the interface configuration and sees 'ip policy route-map PBR-172' applied. What should the engineer do next to isolate the issue?

A.Check if the next-hop 10.10.10.2 is reachable via the routing table.
B.Add the 'set ip default next-hop' command to the route map.
C.Change the route map to use 'set interface' instead of 'set ip next-hop'.
D.Apply the route map to the outgoing interface instead of the incoming interface.
AnswerA

A recursive lookup must resolve 10.10.10.2 through the routing table before the set clause takes effect; if that next hop is unreachable, the route map fails and traffic falls back to normal destination-based forwarding. Verifying reachability isolates whether the PBR failure stems from the next-hop rather than the ACL or interface binding.

Why this answer

For PBR with 'set ip next-hop', the router must be able to resolve the next-hop address via the routing table (RIB) before the policy can take effect. If 10.10.10.2 is not reachable through a valid route, the route map match succeeds but the set action is silently skipped, and traffic falls back to normal destination-based forwarding — making PBR appear completely broken. Verifying next-hop reachability is therefore the correct next diagnostic step.

Exam trap

The trap here is assuming that a matching ACL and an applied route map are sufficient for PBR to work — candidates forget that 'set ip next-hop' requires the next-hop to be resolvable in the routing table, so they chase ACL or interface-application issues instead.

How to eliminate wrong answers

Option B is wrong because 'set ip default next-hop' only applies when there is no explicit route to the destination in the RIB; it is used as a fallback, not as a fix for an unreachable next-hop, and would not make PBR work if the next-hop itself cannot be resolved. Option C is wrong because 'set interface' is an alternative PBR action (typically used for point-to-point links) and does not address the underlying reachability problem; switching actions would not fix a missing route to 10.10.10.2. Option D is wrong because PBR is applied to the incoming interface to intercept traffic before the routing decision — applying it to the outgoing interface is not how Cisco PBR works and would not match the source subnet as intended.

50
MCQmedium

Which loop prevention mechanism is used by default in RIP within a VRF-Lite configuration?

A.Split horizon
B.Route poisoning
C.Hold-down timer
D.TTL expiry
AnswerA

Split horizon is enabled by default on RIP interfaces, preventing a route from being advertised back out the interface it was learned on. Within a VRF-Lite configuration, each VRF maintains independent RIP routing instances, so split horizon operates per-VRF to block two-router loops without additional configuration.

Why this answer

RIP uses split horizon as a default loop prevention mechanism, and this behavior is preserved within VRF-Lite configurations because VRF-Lite simply partitions the routing table without changing RIP's protocol behavior. Split horizon prevents a router from advertising a route back out the interface it learned it from.

Exam trap

The trap is assuming VRF-Lite changes RIP's default loop prevention behavior — VRF-Lite isolates routing tables but does not alter protocol defaults, so split horizon remains the default.

How to eliminate wrong answers

Option B is wrong because route poisoning is a triggered mechanism (advertising a route with an infinite metric when it fails), not a default loop prevention mechanism in RIP. Option C is wrong because hold-down timers are used to prevent routing loops after a route failure, but they are not the default loop prevention mechanism — they are a timer-based stabilization feature. Option D is wrong because TTL expiry is an IP header function, not a RIP loop prevention mechanism; RIP uses hop count with a maximum of 15.

51
MCQmedium

In OSPFv3, what is the purpose of the link-local address in the neighbor adjacency process?

A.The link-local address is used as the router ID for OSPFv3.
B.The link-local address is used as the source address for OSPFv3 packets and for next-hop resolution.
C.The link-local address is only used for DR/BDR election.
D.The link-local address is not used in OSPFv3; global unicast addresses are used instead.
AnswerB

OSPFv3 runs over IPv6, so its packets use the interface link-local address as source, and that same address serves as the next-hop for routes learned across the link. This is the mechanism underpinning neighbour adjacency formation.

Why this answer

In OSPFv3, the link-local address (fe80::/10) is used as the source address for OSPFv3 packets and for next-hop resolution. OSPFv3 uses link-local addresses for neighbor discovery and adjacency formation, and all OSPFv3 control packets are sent from the link-local address. This is a key difference from OSPFv2, which uses the interface's global IPv4 address.

The link-local address ensures that OSPFv3 operates independently of global unicast addressing.

Exam trap

300-410 often tests the misconception that OSPFv3 uses global unicast addresses for neighbor adjacency, when in fact link-local addresses are used for all OSPFv3 control traffic and next-hop resolution.

How to eliminate wrong answers

Option A is wrong because the router ID in OSPFv3 is still a 32-bit value, typically derived from an IPv4 address or manually configured; it is not the link-local address. Option C is wrong because the link-local address is used for all OSPFv3 packet sourcing and next-hop resolution, not just for DR/BDR election. Option D is wrong because OSPFv3 does use link-local addresses; in fact, they are mandatory for OSPFv3 operation, and global unicast addresses are not used for OSPFv3 control packets.

52
MCQmedium

A router has the following BFD configuration for a static route: ip route 10.0.0.0 255.255.255.0 192.168.1.2 bfd map 192.168.1.2 10.0.0.0 255.255.255.0 interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 bfd interval 100 min_rx 100 multiplier 3 ! What is the purpose of the 'bfd map' command in this context?

A.It maps the BFD session to the interface, enabling BFD for all static routes using that interface.
B.It creates a BFD session to the next-hop 192.168.1.2 and associates it with the static route to 10.0.0.0/24.
C.It maps the BFD session to the OSPF process, which is incorrect for static routes.
D.It is used to configure BFD for multiple static routes simultaneously.
AnswerB

The 'bfd map' command binds a BFD session to the specified next-hop and prefix, so the static route to 10.0.0.0/24 is withdrawn if that BFD neighbour fails. This provides sub-second failure detection for the static route.

Why this answer

For static routes, BFD must be explicitly mapped to the next-hop and destination prefix. The 'bfd map' command associates a BFD session with a static route so that if BFD detects a failure, the static route is removed from the routing table.

53
MCQhard

An engineer configured IP SLA 40 with a UDP echo probe to monitor a remote server port 80. The IP SLA is used in a track object for a backup static route. The engineer observes that the IP SLA state is 'Timeout' even though the server is reachable via ping from the router. What is the most likely cause?

A.The router's firewall is blocking UDP packets to the server.
B.The server is not running a UDP service on port 80; HTTP uses TCP, so the UDP probe will fail.
C.The IP SLA frequency is set too high, causing the router to miss responses.
D.The track object is misconfigured with the wrong IP SLA number.
AnswerB

A UDP echo probe sends UDP datagrams to the target port and expects replies. Port 80 runs TCP HTTP, not a UDP service, so no response returns and the probe times out despite ICMP ping succeeding. The protocol mismatch causes the failure.

Why this answer

UDP echo probes require a service listening on the specified port. If the server does not have a UDP service on port 80 (HTTP uses TCP), the probe will timeout.

54
MCQmedium

A network engineer is configuring OSPF on a router with three interfaces: Gi0/0 (10.1.1.1/24), Gi0/1 (10.2.2.1/24), and Gi0/2 (10.3.3.1/24). The engineer wants to prevent OSPF from forming adjacencies on Gi0/2 while still advertising the 10.3.3.0/24 network into OSPF. Which configuration accomplishes this?

A.Configure the Gi0/2 interface with the ip ospf database-filter all out command.
B.Configure the Gi0/2 interface as passive with the passive-interface Gi0/2 command under router ospf.
C.Configure the Gi0/2 interface with the ip ospf network point-to-point command.
D.Configure a distribute-list on Gi0/2 to filter OSPF hellos.
AnswerB

The passive-interface command under router ospf suppresses OSPF hello packets on the specified interface, preventing adjacency formation, but the network connected to that interface is still advertised as a stub network into OSPF. This meets the requirement of no adjacencies while still advertising 10.3.3.0/24. It is the standard method for this scenario and does not affect other interfaces.

Why this answer

The passive-interface command is designed to stop OSPF from sending and processing hello packets on an interface, which prevents neighbor adjacencies. However, the network prefix associated with that interface is still advertised as a stub network into OSPF, allowing other routers to reach it. This exactly matches the requirement to suppress adjacencies while still advertising the subnet.

Exam trap

The trap here is confusing LSA filtering with hello suppression; database-filter and distribute-lists affect LSAs, not hellos, so they do not stop adjacency formation.

55
MCQhard

A router has CoPP configured with a class-map that matches OSPF traffic and polices it to 2000 pps. The router is also configured with an OSPF distribute-list in to filter routes. After applying CoPP, OSPF neighbors form, but routes from a specific neighbor are missing. The distribute-list permits all routes. Which is the most likely explanation?

A.The distribute-list is applied incorrectly and blocks all routes.
B.CoPP drops OSPF LSU packets, preventing route installation, while hello packets still form the adjacency.
C.OSPF uses TCP, and CoPP only polices UDP.
D.The CoPP policy is applied to the wrong control plane subinterface.
AnswerB

CoPP polices matched OSPF traffic at 2000 pps; hello packets are small and infrequent so the adjacency still forms, but larger LSU packets exceed the policer and get dropped. Without LSAs, the router never installs those routes, and the permissive distribute-list is irrelevant.

Why this answer

OSPF uses Hello packets to establish and maintain neighbor adjacencies, but route information is exchanged via Link State Update (LSU) packets. The CoPP policy matches OSPF traffic and polices it to 2000 pps, which can drop LSU packets if the rate is exceeded, preventing route installation while allowing enough Hello packets to keep the adjacency up. The distribute-list permits all routes, so it is not the cause of the missing routes.

Exam trap

Cisco often tests the distinction between OSPF neighbor formation (Hello packets) and route exchange (LSU packets), leading candidates to assume that if neighbors are up, all OSPF traffic is passing correctly.

How to eliminate wrong answers

Option A is wrong because the distribute-list is explicitly stated to permit all routes, so it cannot be blocking routes. Option C is wrong because OSPF does not use TCP; it uses IP protocol 89 directly, and CoPP class-maps typically match on protocol or port, not just UDP. Option D is wrong because the question states CoPP is configured and neighbors form, indicating the policy is applied to the correct control plane subinterface; if it were wrong, neighbors would likely not form at all.

56
MCQmedium

What is the problem with this NAT configuration? interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ip nat inside ! interface GigabitEthernet0/1 ip address 203.0.113.1 255.255.255.0 ! ip nat inside source list 1 interface GigabitEthernet0/1 overload access-list 1 permit 192.168.1.0 0.0.0.255

A.The ACL is too permissive; it should only permit specific hosts.
B.The interface GigabitEthernet0/1 is missing the 'ip nat outside' command.
C.The 'overload' keyword is unnecessary for this configuration.
D.The inside interface should be GigabitEthernet0/1.
AnswerB

NAT translation requires both an inside and an outside interface designation. GigabitEthernet0/1 holds the global address in the overload statement but lacks 'ip nat outside', so translations cannot be built and the configuration is incomplete.

Why this answer

The configuration is missing the 'ip nat outside' command on interface GigabitEthernet0/1. For NAT to function, Cisco IOS requires that the inside interface be marked with 'ip nat inside' and the outside interface with 'ip nat outside'. Without this, the router does not know which interface is the external (outside) interface, and the NAT translation will not be applied to outgoing packets.

Exam trap

The trap here is that candidates often assume that simply configuring the NAT statement and ACL is enough, overlooking the mandatory interface-level 'ip nat outside' command, which Cisco explicitly tests in the 300-410 exam to ensure understanding of NAT operation fundamentals.

How to eliminate wrong answers

Option A is wrong because the ACL is correctly configured to permit the entire 192.168.1.0/24 subnet, which is the intended inside network for dynamic NAT overload (PAT); being more restrictive is not required and would break connectivity for valid hosts. Option C is wrong because the 'overload' keyword is necessary for Port Address Translation (PAT), which allows multiple inside hosts to share the single public IP address of GigabitEthernet0/1; without it, only one inside host could be translated at a time. Option D is wrong because the inside interface is correctly identified as GigabitEthernet0/1 (the LAN side), and the outside interface should be GigabitEthernet0/1 (the WAN side), not the other way around.

57
MCQmedium

A company has a Cisco IOS XE router configured with IP SLA and Object Tracking to monitor the reachability of a primary ISP. The router should fail over to a backup ISP when the primary path becomes unreachable. The engineer wants to ensure that the failover occurs quickly and that the primary path is restored when it becomes available again. Which configuration element is required to achieve this behavior?

A.A floating static route with a higher administrative distance to the backup ISP
B.A route map that matches the primary ISP's next-hop and sets the local preference
C.An IP SLA operation with a track object that is referenced by a static route to the primary ISP
D.A static route with a lower administrative distance pointing to the backup ISP
AnswerC

IP SLA operations can monitor reachability by sending probes such as ICMP echoes. The track object tracks the state of the SLA operation. When the tracked object goes down, any static route referencing that object is removed from the routing table, allowing the backup route to be used. When the SLA recovers, the primary route is reinstalled. This provides fast failover and automatic restoration, meeting the requirements.

Why this answer

IP SLA with object tracking allows the router to monitor the primary ISP's reachability. The track object is referenced in the static route to the primary ISP, so when the SLA fails, the route is removed and the backup route (which could be a floating static or a default route) takes over. When the SLA recovers, the primary route is reinstated.

This provides the required fast failover and automatic restoration.

Exam trap

The trap here is thinking that a floating static route alone provides reachability-based failover; it does not without tracking.

58
MCQeasy

An engineer applies a CoPP policy to a router to protect the control plane from a DDoS attack. The policy includes a class-map matching UDP traffic to port 123 (NTP) and polices it to 1000 bps. After the policy is applied, the engineer notices that the router's clock is not synchronizing with its NTP server. The NTP server is reachable via ping. What is the most likely cause?

A.The CoPP policy is dropping NTP packets because the police rate is too low.
B.The NTP server is not responding because of the DDoS attack.
C.The CoPP class-map is not matching NTP packets because it uses the wrong port number.
D.The router's NTP configuration has a wrong server IP address.
AnswerA

Policing NTP to 1000 bps is far below what synchronisation requires; NTP exchanges several packets per poll, so the policer drops excess, preventing clock sync even though ICMP ping succeeds because it is not matched by the NTP class.

Why this answer

The CoPP policy is policing NTP traffic (UDP port 123) to only 1000 bps. NTP synchronization requires a steady exchange of packets, and a 1000 bps rate is extremely low—likely insufficient to allow the NTP packets through, causing them to be dropped. Since the NTP server is reachable via ping (ICMP is not affected by this CoPP policy), the issue is clearly that the police rate is too restrictive for NTP traffic.

Exam trap

Cisco often tests the misconception that a CoPP policy will only drop malicious traffic, but the trap here is that an overly restrictive police rate can inadvertently drop legitimate control-plane traffic like NTP, even when the class-map and port numbers are correctly configured.

How to eliminate wrong answers

Option B is wrong because the NTP server is reachable via ping, indicating it is responding and not under a DDoS attack that would prevent replies. Option C is wrong because the class-map explicitly matches UDP port 123, which is the correct port for NTP; if it were wrong, NTP would not be affected at all. Option D is wrong because if the server IP address were incorrect, the router would not be able to ping it successfully, but the NTP server is reachable via ping.

59
MCQeasy

A network engineer runs the following command to verify DHCPv4 server bindings on router R1: R1# show ip dhcp binding Output: Bindings from all pools not associated with VRF: IP address Client-ID/ Lease expiration Type Hardware address/ User name 192.168.1.10 0050.7966.6800 Mar 01 2025 12:00 PM Automatic 192.168.1.11 0063.6973.636f.2d30 Mar 01 2025 01:00 PM Automatic 192.168.1.12 0100.1a.2b.3c.4d.5e Mar 01 2025 02:00 PM Automatic What does this output indicate?

A.The DHCP server has three static bindings configured.
B.The DHCP server has dynamically assigned three IP addresses to clients.
C.The DHCP server is out of IP addresses because all bindings are in use.
D.The DHCP server is using relay agents because the client IDs are long hexadecimal strings.
AnswerB

The "Automatic" type and populated lease expirations confirm dynamic allocation from the pool, satisfying the stem's request to verify DHCPv4 bindings. Each entry pairs a leased address with a client identifier, showing three active dynamic leases rather than static reservations or manual bindings.

Why this answer

The output shows three DHCP bindings with a 'Type' of 'Automatic', which indicates that the IP addresses were dynamically assigned by the DHCP server based on the pool configuration. The 'Client-ID' field contains the MAC address or client identifier provided by the client during the DORA process, confirming dynamic allocation rather than static mapping.

Exam trap

Cisco often tests the distinction between 'Automatic' (dynamic) and 'Static' (manual) bindings in the DHCP binding table, leading candidates to mistakenly think all bindings are static when they see client IDs that look like MAC addresses.

How to eliminate wrong answers

Option A is wrong because static bindings would appear with a 'Type' of 'Static', not 'Automatic', and would typically be configured using the 'ip dhcp pool' command with a 'hardware-address' statement. Option C is wrong because the output only shows three bindings; there is no indication that the pool is exhausted, as the pool may have additional available addresses. Option D is wrong because the client IDs shown are standard MAC addresses or DHCP client identifiers (e.g., the long hex string '0063.6973.636f.2d30' is a Cisco client ID, not an indication of relay agent usage); relay agents are identified by the 'giaddr' field in the DHCP packet, not by the client ID format.

60
MCQhard

A network engineer is troubleshooting a Cisco IOS router that is configured for AAA authorization. The engineer notices that users are not being authorized for certain commands even though the TACACS+ server is reachable and the user is authenticated. The configuration includes 'aaa authorization exec default group tacacs+ local' and 'aaa authorization commands 15 default group tacacs+ local'. Which issue is most likely causing the problem?

A.The 'aaa new-model' command is not enabled.
B.The TACACS+ server is not configured to return the correct AV pairs for command authorization.
C.The local database does not have the necessary privilege level configured for the user.
D.The 'aaa authorization commands 15' command requires the 'if-authenticated' keyword to work.
AnswerB

For command authorization, the TACACS+ server must return authorization attributes that specify which commands are permitted. If the server does not have the correct command sets configured or returns an empty attribute, the router will deny the commands. The local fallback is only used if the server is unreachable, not if it returns a deny. Thus, the server configuration is the likely cause.

Why this answer

Command authorization relies on the TACACS+ server to provide authorization attributes that define which commands the user is allowed to execute. If the server is reachable and the user is authenticated but commands are denied, the server is likely not configured to return the proper AV pairs for command authorization. The local fallback is not used because the server is responding, so the issue is with the server's authorization configuration.

Exam trap

The trap here is assuming local fallback will occur for authorization failures when the server is reachable; fallback only happens if the server is unreachable.

61
MCQeasy

A network engineer is configuring a Cisco IOS XE router to support IPv6. The engineer wants to enable IPv6 routing and assign an IPv6 address to an interface. Which command must be configured globally to enable IPv6 routing?

A.ipv6 routing
B.ipv6 unicast-routing
C.ipv6 address autoconfig
D.ipv6 enable
AnswerB

The ipv6 unicast-routing command enables IPv6 unicast routing globally on the router. Without it, the router will not forward IPv6 packets, even if interfaces have IPv6 addresses. This command is essential for any IPv6 routing configuration. It allows the router to participate in IPv6 routing protocols and forward IPv6 traffic between interfaces.

Why this answer

To enable IPv6 routing globally on a Cisco IOS XE router, the engineer must configure the ipv6 unicast-routing command in global configuration mode. This command allows the router to forward IPv6 packets and participate in IPv6 routing protocols. The other options are either interface-level commands or invalid syntax.

Without this command, the router will not route IPv6 traffic, even if interfaces are configured with IPv6 addresses.

Exam trap

The trap here is confusing interface-level IPv6 enabling commands with the global command required to enable IPv6 routing.

62
MCQeasy

A network administrator is configuring a point-to-point GRE tunnel between two Cisco routers. The administrator wants to verify that the tunnel is operational and that the correct encapsulation is being used. Which command should be used to display the tunnel interface status, including the encapsulation and tunnel source/destination?

A.show interfaces tunnel 0
B.show ip interface brief
C.show crypto ipsec sa
D.show ip route
AnswerA

The show interfaces tunnel 0 command displays detailed information about the tunnel interface, including its status, encapsulation (GRE/IP), source and destination addresses, and other parameters. This command is essential for verifying that the tunnel is up and configured correctly. It provides the necessary details to confirm operational status and encapsulation type.

Why this answer

The show interfaces tunnel 0 command provides comprehensive details about the tunnel interface, including its operational status, encapsulation type (GRE), and the configured tunnel source and destination. This allows the administrator to verify that the tunnel is up and correctly configured. The other commands do not provide the necessary tunnel-specific information.

Exam trap

The trap here is assuming that show ip interface brief provides enough detail, but it only shows IP addresses and status, not encapsulation or tunnel endpoints.

63
MCQmedium

A network engineer runs the following command to verify IPv6 uRPF on an interface: R1# show ipv6 interface GigabitEthernet0/0 | include verify|suppress IPv6 verify source: strict IPv6 verify source suppress: disabled What does this output indicate?

A.Strict uRPF is enabled, and no suppression is configured, so all incoming packets are subject to strict verification.
B.Loose uRPF is enabled with suppression.
C.uRPF is disabled on this interface.
D.Suppression is enabled, so uRPF checks are bypassed.
AnswerA

The verify source line reports strict mode, meaning the router checks that the source address is reachable via the receiving interface and drops failures. Suppress being disabled confirms no prefix is exempt, so every inbound packet undergoes that strict reverse-path check.

Why this answer

The output shows 'IPv6 verify source: strict' and 'IPv6 verify source suppress: disabled'. This confirms that strict unicast Reverse Path Forwarding (uRPF) is enabled on the interface, meaning every incoming packet's source address is checked against the routing table to ensure the best return route uses the same incoming interface. Because suppression is disabled, no packets bypass this verification, so all incoming packets are subject to strict uRPF checks.

Exam trap

Cisco often tests the distinction between 'strict' and 'loose' uRPF modes, and the trap here is that candidates may confuse the 'suppress' keyword with disabling uRPF entirely, when in fact it only controls whether certain packets are exempt from the check.

How to eliminate wrong answers

Option B is wrong because the output explicitly states 'strict', not 'loose', and suppression is disabled, not enabled. Option C is wrong because the output clearly shows 'IPv6 verify source: strict', which means uRPF is enabled, not disabled. Option D is wrong because suppression is disabled, so uRPF checks are enforced, not bypassed.

64
MCQmedium

A network engineer configures the following on a router: ``` router eigrp 100 distance 150 10.0.0.0 0.255.255.255 ``` What is the intended effect?

A.It sets the administrative distance for all EIGRP routes to 150.
B.It sets the administrative distance to 150 for routes learned from any neighbor whose source IP matches the wildcard mask 0.255.255.255.
C.It sets the administrative distance to 150 for all routes in the routing table with destination 10.0.0.0/8.
D.It sets the administrative distance to 150 for EIGRP external routes only.
AnswerB

The distance command's second parameter is a wildcard mask applied to the neighbour's source IP, not the route prefix. With 0.255.255.255, any neighbour in 10.0.0.0/8 has its EIGRP routes assigned administrative distance 150, making them less preferred than other sources.

Why this answer

The EIGRP distance command syntax is distance <admin-distance> <source-ip> <wildcard-mask>. Here, 150 is the administrative distance, 10.0.0.0 is the source IP, and 0.255.255.255 is the wildcard mask, meaning any neighbor whose source IP is in 10.0.0.0/8 will have its routes assigned an AD of 150. This is used to prefer another routing protocol for routes learned from specific EIGRP neighbors.

Exam trap

The trap is misreading the command as applying to destination networks or all EIGRP routes; candidates must recognize the source-IP/wildcard parameters and that it affects only routes from matching neighbors.

How to eliminate wrong answers

Option A is wrong because setting AD for all EIGRP routes requires the distance eigrp command without a source IP/wildcard, not this syntax. Option C is wrong because the command does not filter by destination prefix; it filters by the neighbor's source IP. Option D is wrong because external EIGRP routes are set with distance eigrp external, not with this source-based distance command.

65
MCQmedium

What is the default EIGRP hold time multiplier relative to the hello interval?

A.Hold time equals hello interval
B.Hold time is twice the hello interval
C.Hold time is three times the hello interval
D.Hold time is four times the hello interval
AnswerC

EIGRP derives hold time from the hello interval by a fixed multiplier of three, so a 5-second hello yields a 15-second hold time. This default ratio governs how long a router waits before declaring a neighbour down.

Why this answer

By default, EIGRP sets the hold time to three times the hello interval. This ensures that a few missed hellos do not immediately cause neighbor loss.

66
MCQmedium

A network engineer runs the following command to troubleshoot SNMP access lists: R1# show snmp access Access-list: 10 Community: public View: v1default Access-list: 20 Community: private View: v1default What does this output indicate?

A.SNMP access is controlled by ACLs: ACL 10 for 'public' and ACL 20 for 'private'.
B.No ACLs are applied to SNMP, so all access is allowed.
C.The router uses SNMPv3 exclusively.
D.The 'public' community has read-write access.
AnswerA

The output maps each SNMP community string to an access list: ACL 10 governs 'public' and ACL 20 governs 'private', both using the v1default view. This confirms SNMP access is filtered by those ACLs rather than by views alone.

Why this answer

The 'show snmp access' output displays the configured SNMP access control entries, which map community strings to access control lists (ACLs). In this case, ACL 10 is associated with the 'public' community and ACL 20 with the 'private' community, meaning SNMP access is restricted based on these ACLs. This is the standard method for controlling SNMPv1/v2c access, as the router uses the ACL to permit or deny SNMP requests from specific source IP addresses.

Exam trap

Cisco often tests the distinction between what 'show snmp access' reveals (ACL-to-community mapping) versus what it does not reveal (read-write permissions), leading candidates to incorrectly assume that the 'public' community has read-write access or that no ACLs are applied.

How to eliminate wrong answers

Option B is wrong because the output explicitly shows ACLs 10 and 20 are applied to the 'public' and 'private' communities, respectively, so access is not allowed without ACL filtering. Option C is wrong because SNMPv3 does not use community strings or ACL-based access control in the same way; it uses user-based security models (USM) with authentication and encryption, and the output shows community strings, indicating SNMPv1/v2c. Option D is wrong because the output does not indicate read-write access for 'public'; the 'View: v1default' suggests a default view, but the actual access level (read-only or read-write) is determined by the SNMP community configuration, which is not shown in this output.

67
MCQhard

A network engineer configures an IPv6 over IPv4 GRE tunnel with IPsec using a crypto map. The tunnel works for unicast traffic, but OSPFv3 over the tunnel fails to form adjacency. The engineer checks the crypto map and sees that it only matches traffic with a specific access-list. What is the most likely explanation?

A.The crypto map access-list must include IPv6 protocol 89 (OSPF) to encrypt OSPFv3 packets; otherwise, they are sent in the clear and may be dropped.
B.OSPFv3 cannot be encrypted with IPsec; it requires a separate encryption mechanism.
C.The GRE tunnel interface must be configured with 'tunnel protection ipsec' instead of a crypto map.
D.The crypto map is applied to the physical interface instead of the tunnel interface.
AnswerA

OSPFv3 uses IPv6 protocol 89. If the access-list does not match this protocol, OSPFv3 packets are not protected and may be discarded by the remote IPsec policy.

Why this answer

OSPFv3 uses IPv6 protocol number 89 for its packets. When a crypto map is applied with an access-list that only matches specific traffic (e.g., unicast data), OSPFv3 packets (protocol 89) are not matched and are sent unencrypted. If the IPsec peer is configured to drop unencrypted traffic or if the GRE tunnel requires all traffic to be encrypted, OSPFv3 adjacency fails.

Adding protocol 89 to the access-list ensures OSPFv3 packets are encrypted and processed correctly.

Exam trap

Cisco often tests the misconception that OSPFv3 cannot be encrypted with IPsec or that the crypto map must be applied to the tunnel interface, when the real issue is that the access-list used by the crypto map must explicitly include the OSPFv3 protocol (89) to encrypt routing updates.

How to eliminate wrong answers

Option B is wrong because OSPFv3 can be encrypted with IPsec; in fact, IPsec is commonly used to protect OSPFv3 routing updates over tunnels. Option C is wrong because 'tunnel protection ipsec' is a valid alternative to a crypto map, but using a crypto map is also correct; the issue is the access-list not matching OSPFv3, not the method of applying IPsec. Option D is wrong because the crypto map is correctly applied to the physical interface (the tunnel source/destination) to protect GRE-encapsulated traffic; applying it to the tunnel interface would not encrypt the outer IP headers.

68
MCQmedium

What is the default administrative distance for a route learned via the Enhanced Interior Gateway Routing Protocol (EIGRP) summary route?

A.90
B.170
C.5
D.1
AnswerC

EIGRP assigns administrative distance 5 to summary routes, distinguishing them from internal routes (90) and external routes (170). This low value ensures the summary is trusted over other sources, reflecting its origin as a locally configured aggregate rather than a learned path.

Why this answer

EIGRP summary routes have a default administrative distance of 5, which is lower than the standard EIGRP internal distance of 90 and EIGRP external distance of 170.

69
MCQhard

A router is configured with uRPF (Unicast Reverse Path Forwarding) in strict mode on an interface that belongs to a VRF. The network uses asymmetric routing for load balancing. The engineer notices that legitimate traffic from a customer is being dropped. Which is the most likely explanation?

A.The uRPF strict mode requires that the source IP address be reachable via the same interface, but asymmetric routing causes the return path to use a different interface.
B.The uRPF loose mode is configured instead of strict mode, which only checks that a route exists for the source IP, not the interface.
C.The VRF has a default route that points to the incoming interface, causing uRPF to always succeed.
D.The 'ip verify unicast source reachable-via any' command is used, which is the loose mode, not strict.
AnswerA

Strict uRPF verifies the source address is reachable via the same interface the packet arrived on. Asymmetric routing sends return traffic through a different interface, so the reverse-path lookup fails and legitimate customer packets are dropped despite valid forwarding.

Why this answer

Strict uRPF requires that the router's reverse-path lookup for the packet's source IP resolve out the same interface the packet arrived on. With asymmetric routing, the return path to the customer is via a different interface than the one receiving the traffic, so the strict check fails and the packet is dropped. This is the classic failure mode of strict uRPF in multi-path or load-balanced designs.

Exam trap

The trap here is confusing strict and loose uRPF behavior — candidates often assume loose mode is the default or that any route existence satisfies strict mode, when strict mode specifically requires the ingress interface to match the reverse path.

How to eliminate wrong answers

Option B is wrong because the scenario explicitly states strict mode is configured; if loose mode were in use, only route existence would be checked and the asymmetric path would not cause drops. Option C is wrong because a default route pointing to the incoming interface would actually make the strict check succeed, not fail, and would not explain the drops. Option D is wrong because 'ip verify unicast source reachable-via any' is the loose mode command, and the question states strict mode is in use, so this option contradicts the premise.

70
MCQhard

A network engineer enables IPv6 First Hop Security with 'ipv6 dhcp guard' on a switch port connected to a legitimate DHCPv6 server. Clients on other ports receive DHCPv6 replies, but the server's port is being err-disabled repeatedly. The engineer checks the logs and sees DHCPv6 server advertisements being dropped. What is the most likely cause?

A.The port is not configured as 'trusted' for DHCPv6 Guard, causing all server advertisements to be dropped.
B.The DHCPv6 server is sending messages with an invalid DUID.
C.DHCPv6 Guard only works with stateful DHCPv6, not stateless.
D.The switch is running an older IOS version that does not support DHCPv6 Guard.
AnswerA

DHCPv6 Guard requires explicit trust for server ports.

Why this answer

When 'ipv6 dhcp guard' is enabled on a switch port, all DHCPv6 server advertisements (REPLY and ADVERTISE messages) are dropped by default unless the port is explicitly configured as 'trusted'. Since the server's port is untrusted, the switch drops the legitimate server's advertisements, causing the port to be err-disabled due to repeated violations. Configuring 'ipv6 dhcp guard trust' on the server-facing port resolves this issue.

Exam trap

Cisco often tests the default untrusted behavior of DHCPv6 Guard, where candidates mistakenly assume that enabling the feature on a port automatically allows server traffic, rather than requiring an explicit 'trust' keyword.

How to eliminate wrong answers

Option B is wrong because an invalid DUID would cause the DHCPv6 server to reject client messages or fail to form a binding, but it would not cause the switch to drop advertisements or err-disable the port; DHCPv6 Guard operates independently of DUID validity. Option C is wrong because DHCPv6 Guard works with both stateful and stateless DHCPv6; it filters all DHCPv6 server messages (REPLY and ADVERTISE) regardless of the DHCPv6 mode. Option D is wrong because the question states that the feature is enabled and logs show advertisements being dropped, which confirms the switch supports DHCPv6 Guard; an older IOS version would simply not have the command available or would not enforce the feature.

71
MCQeasy

A network engineer runs the following command to troubleshoot a BGP prefix issue: R1# show bgp ipv4 unicast 192.168.10.0/24 BGP routing table entry for 192.168.10.0/24, version 5 Paths: (1 available, best #1, table default) Advertised to update-groups: 1 Refresh Epoch 1 Local 10.1.1.2 from 10.1.1.2 (2.2.2.2) Origin IGP, metric 0, localpref 100, valid, external, best rx pathid: 0, tx pathid: 0x0 What does this output indicate?

A.The prefix is learned via eBGP and is the best path.
B.The prefix is learned via iBGP and is not the best path.
C.The prefix is suppressed and not advertised to peers.
D.The prefix is invalid due to missing next-hop reachability.
AnswerA

The output shows "Local" origin with "valid, external, best", confirming the prefix arrived via eBGP from peer 10.1.1.2 and holds the best-path status in the BGP table. This satisfies the troubleshooting constraint: the route is installed and advertised, so the issue lies elsewhere, not in BGP path selection.

Why this answer

The output shows the prefix 192.168.10.0/24 is learned from neighbor 10.1.1.2 with the path type 'external', indicating eBGP. The line 'valid, external, best' confirms it is the best path, making option A correct.

Exam trap

Cisco often tests the distinction between eBGP and iBGP by using the 'external' or 'internal' keyword in the show output, and the trap here is that candidates may misread 'external' as 'iBGP' or overlook the 'best' flag, assuming the prefix is not the best path.

How to eliminate wrong answers

Option B is wrong because the output explicitly states 'external', not iBGP, and 'best' indicates it is the best path, not non-best. Option C is wrong because there is no indication of suppression (e.g., no 'suppressed' flag or 'advertise-to-all' missing), and the prefix is advertised to update-group 1. Option D is wrong because the prefix is marked 'valid' and 'best', meaning the next-hop is reachable; if the next-hop were missing, the prefix would be marked 'invalid' or 'not synchronized'.

72
MCQhard

A network engineer is implementing policy-based routing (PBR) on a Cisco router. The goal is to route traffic from a specific subnet to a next-hop IP address that is not directly connected. Which configuration is required to achieve this?

A.A route map that matches the source subnet and sets the interface to the next-hop interface.
B.A route map that matches the source subnet and sets the next-hop IP address, and a static route to the next-hop IP address.
C.A route map that matches the source subnet and sets the default next-hop IP address.
D.A route map that matches the source subnet and sets the next-hop IP address.
AnswerB

When using PBR with 'set ip next-hop', the next-hop IP address must be reachable via a route in the routing table. If the next-hop is not directly connected, you need a static route to that next-hop. This ensures that the router can forward the packet to the next-hop. Without the static route, the PBR action would fail because the next-hop is not resolvable.

Why this answer

PBR with 'set ip next-hop' requires that the next-hop IP address be reachable. If it is not directly connected, a static route must be present to resolve the next-hop. The other options either do not address the reachability requirement or use incorrect syntax.

Exam trap

The trap here is forgetting that PBR next-hop must be reachable via the routing table, and assuming that PBR can override routing without a route to the next-hop.

73
MCQmedium

A network engineer is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which type of ACL should be used in the crypto map to match this traffic?

A.A standard ACL that permits the 10.1.1.0/24 subnet.
B.An extended ACL that permits IP traffic from 10.1.1.0/24 to 10.2.2.0/24 and denies all other traffic.
C.A named ACL that permits all IP traffic.
D.An extended ACL that denies IP traffic from 10.1.1.0/24 to 10.2.2.0/24 and permits all other traffic.
AnswerB

This is correct because the crypto ACL defines interesting traffic that should be encrypted. It must permit the specific source/destination subnet pair and implicitly deny everything else. The implicit deny ensures other traffic is not encrypted, and the ACL is used to match traffic for the VPN.

Why this answer

The crypto ACL must permit the specific traffic that should be encrypted and implicitly deny all other traffic. An extended ACL that permits IP traffic from 10.1.1.0/24 to 10.2.2.0/24 and denies all other traffic achieves this. Standard ACLs cannot match destination addresses, and denying the desired traffic or permitting all traffic would be incorrect.

Exam trap

The trap here is confusing the direction of the ACL: the crypto ACL permits interesting traffic, not denies it.

74
MCQmedium

A network engineer runs the following command to troubleshoot an EEM issue: R1# show event manager policy active No. Class Type Version Time Created Name 1 applet system 1.0 Mar 1 00:00:12 2025 TRACK-INTERFACE Event Type: syslog (pattern OSPF-5-ADJCHG) Action: cli command 'show ip route' What does this output indicate?

A.The EEM applet 'TRACK-INTERFACE' is active and will execute 'show ip route' when a syslog message matching 'OSPF-5-ADJCHG' is generated.
B.The EEM applet 'TRACK-INTERFACE' is currently executing and has run 'show ip route'.
C.The EEM applet 'TRACK-INTERFACE' has been triggered and the output of 'show ip route' is displayed.
D.The EEM applet 'TRACK-INTERFACE' is inactive and needs to be enabled.
AnswerA

The active policy list confirms the applet is registered and running. Its syslog event type with pattern OSPF-5-ADJCHG triggers the configured CLI action, so 'show ip route' runs whenever a matching OSPF adjacency-change syslog message appears.

Why this answer

The output shows the EEM applet 'TRACK-INTERFACE' is active (registered) with a syslog event pattern 'OSPF-5-ADJCHG' and an action to run 'show ip route'. This means it will execute that CLI command when a matching syslog message is generated. The 'policy active' command lists registered policies, not execution history.

Exam trap

The trap is assuming 'policy active' means the policy is currently executing; it actually means the policy is registered and enabled, not that it has fired.

How to eliminate wrong answers

Option B is wrong because 'show event manager policy active' does not indicate current execution; it only shows registration. Option C is wrong because the output does not display the result of 'show ip route'; that would require 'show event manager history events' or actual execution logs. Option D is wrong because the policy is listed as active, so it is enabled, not inactive.

75
MCQmedium

A network engineer is implementing policy-based routing (PBR) on a Cisco router. The goal is to forward traffic from a specific subnet to a next-hop IP address that is not directly connected, but reachable via a recursive lookup. The engineer configures a route-map with 'set ip next-hop recursive <IP>'. However, traffic is not being forwarded as expected. Which of the following is the most likely reason?

A.The 'set ip next-hop recursive' command is not supported in PBR.
B.The next-hop IP address is reachable via the default route only.
C.The route-map is not applied to the correct interface.
D.The next-hop IP address is not resolvable via a route in the RIB.
AnswerD

The 'set ip next-hop recursive' command requires that the specified next-hop IP address be resolvable through a route in the routing table (RIB). If there is no route to that next-hop, the recursive lookup fails, and the PBR policy is not applied. The router will then fall back to normal destination-based routing. Thus, the most likely reason is that the next-hop address is not present in the RIB.

Why this answer

For 'set ip next-hop recursive' to work, the specified next-hop address must be resolvable via a route in the routing table. If no such route exists, the recursive lookup fails, and the PBR policy is skipped. The router then uses the normal routing table.

Therefore, the absence of a route to the next-hop is the most likely cause of the failure.

Exam trap

The trap here is assuming that 'set ip next-hop recursive' can resolve any IP address, even if it is not in the routing table, when in fact it requires a RIB entry.

Page 1 of 19

Page 2