Courseiva

Cisco CCNP ENARSI 300-410 (300-410) — Questions 676–750

1401 questions total · 19pages · All types, answers revealed

Page 9

Page 10 of 19

Page 11
676
Multi-Selecteasy

Which TWO configuration steps are required to implement Policy-Based Routing (PBR) on a Cisco router? (Choose TWO.)

Select 2 answers
A.Create a route-map with match and set commands.
B.Apply the route-map to an interface using the 'ip policy route-map' command.
C.Configure an access-list to match the traffic.
D.Enable CEF globally.
E.Use the 'ip local policy route-map' command.
AnswersA, B

PBR requires a route-map defining the match criteria identifying traffic and the set clauses specifying the next-hop or interface. Without this policy definition, the router has no instructions to deviate from destination-based forwarding, so creating the route-map is an essential configuration step before it can be applied.

Why this answer

Option A is correct because PBR is defined inside a route-map, where 'match' statements identify the traffic (typically via an ACL or prefix-list) and 'set' statements define the forwarding action such as 'set ip next-hop' or 'set interface'. Option B is correct because the route-map must be attached to the ingress interface with the interface-level command 'ip policy route-map <name>' for PBR to take effect on transit traffic. Option C is not required as a separate step because the ACL is referenced within the route-map's match statement rather than configured as an independent mandatory configuration element.

Option D is not required because Cisco Express Forwarding is enabled by default on modern Cisco IOS platforms and is not a PBR-specific configuration step. Option E is incorrect for this scenario because 'ip local policy route-map' applies PBR to router-generated (locally sourced) traffic, not to traffic being routed through an interface.

Exam trap

300-410 often tests the confusion between 'ip policy route-map' (for transit traffic on an interface) and 'ip local policy route-map' (for router-generated traffic); candidates may pick the local policy command or think CEF must be manually enabled, but the two required steps are route-map creation and interface application.

677
Multi-Selectmedium

A network engineer is configuring a Cisco IOS XE router to act as an IPv6 DHCP server for a LAN segment. The router must provide IPv6 addresses and other configuration parameters to hosts. Which two tasks must the engineer perform to enable stateful DHCPv6 operation on the router? (Choose two.)

Select 2 answers
A.Enable IPv6 unicast routing globally with the ipv6 unicast-routing command.
B.Configure an IPv6 DHCP pool with the address prefix and other parameters.
C.Configure a DHCPv6 relay destination on the interface pointing to itself.
D.Configure a static IPv6 address on the interface using the eui-64 keyword.
E.Enable the DHCPv6 server functionality with the ipv6 dhcp server command on the interface.
AnswersB, E

A DHCPv6 pool defines the address prefix, DNS servers, domain name, and other options that clients receive. Without a pool, the router has no address space or parameters to assign, so stateful DHCPv6 cannot function. This is a fundamental configuration step for a DHCPv6 server.

Why this answer

To enable stateful DHCPv6 on a Cisco IOS XE router, you must create a DHCPv6 pool that defines the address prefix and options, and then enable the DHCPv6 server on the interface with the ipv6 dhcp server command referencing that pool. These two steps allow the router to assign addresses and parameters to clients. The other options are either unrelated or would not contribute to server functionality.

Exam trap

The trap here is thinking that enabling IPv6 unicast routing or configuring an eui-64 address is required for DHCPv6 server operation, when the essential steps are defining a pool and activating the server on the interface.

678
MCQeasy

Which EEM action type is used to modify the configuration of the device?

A.action syslog
B.action cli
C.action snmp-trap
D.action mail
AnswerB

The action cli applet action executes CLI commands on the device, including configuration-mode commands when the applet enters config mode. This makes it the mechanism for applying configuration changes in response to an EEM event.

Why this answer

The EEM action type 'action cli' is used to execute CLI commands on the device, which is how an EEM policy modifies the device configuration. When an event triggers the policy, the 'action cli' statements run the specified commands in configuration or exec mode, allowing the policy to change settings, apply ACLs, or shut down interfaces. This is the action type designed for configuration modification.

Exam trap

The trap is mixing up notification actions (syslog, snmp-trap, mail) with configuration actions; the exam tests that only 'action cli' can modify the device configuration.

How to eliminate wrong answers

Option A is wrong because 'action syslog' generates a syslog message; it does not modify the device configuration. Option C is wrong because 'action snmp-trap' sends an SNMP trap to a management station; it is a notification action, not a configuration action. Option D is wrong because 'action mail' sends an email notification; it also does not change the device configuration.

679
MCQmedium

A network engineer runs the following command to verify MPLS forwarding: R1# show mpls forwarding-table 192.168.1.0 255.255.255.0 detail Output: Local Outgoing Prefix Bytes Label Outgoing Next Hop Label Label or Tunnel Id Switched interface 101 201 192.168.1.0/24 0 Gi0/0 10.0.0.2 MAC/Encaps: 14/18, MTU: 1500, Label Stack {201} No output feature configured What does this output indicate?

A.Packets with label 101 will be swapped to label 201 and forwarded to 10.0.0.2
B.Packets with label 101 will be popped and forwarded as IP packets
C.The prefix 192.168.1.0/24 is directly connected
D.The label stack has two labels
AnswerA

The local label 101 maps to outgoing label 201, with next hop 10.0.0.2 out Gi0/0, confirming label swapping rather than PHP or pop. This satisfies the stem by matching the forwarding-table entry's Local Label, Outgoing Label and Next Hop fields exactly.

Why this answer

The output shows the MPLS forwarding table entry for prefix 192.168.1.0/24. The local label is 101, outgoing label is 201, next hop is 10.0.0.2 via GigabitEthernet0/0. The label stack contains only label 201.

680
MCQmedium

In a standard IPv4 ACL, what is the default wildcard mask if none is explicitly configured?

A.0.0.0.0 (host match)
B.255.255.255.255 (any match)
C.The mask is mandatory; configuration is rejected without it.
D.The mask is derived from the source address class.
AnswerA

When no wildcard mask is specified in a standard IPv4 ACL statement, Cisco IOS assumes 0.0.0.0, which matches only the exact host address given. This contrasts with the 255.255.255.255 wildcard that would match any address.

Why this answer

In a standard IPv4 ACL, if no wildcard mask is explicitly configured, the default wildcard mask is 0.0.0.0, which means the ACL matches only the exact source IP address (a host match). This is because the access-list command treats the source address as a host address when no mask is provided, effectively applying a host wildcard mask.

Exam trap

Cisco often tests the misconception that a missing wildcard mask defaults to 'any' (255.255.255.255) or that the mask is mandatory, when in fact the default is a host match (0.0.0.0).

How to eliminate wrong answers

Option B is wrong because 255.255.255.255 (any match) is not the default; it would match all source addresses, which is not the behavior when no mask is given. Option C is wrong because the mask is not mandatory; Cisco IOS accepts the command without a wildcard mask and defaults to 0.0.0.0. Option D is wrong because the mask is not derived from the source address class; ACLs do not use classful behavior, and the default is always 0.0.0.0 regardless of the address class.

681
MCQmedium

An engineer is troubleshooting a route redistribution issue between OSPF and EIGRP. R1 runs both protocols and redistributes OSPF into EIGRP. The engineer notices that OSPF routes redistributed into EIGRP have an AD of 170, but some routes from OSPF are not being redistributed. What is the most likely cause?

A.The OSPF routes have a higher metric than the EIGRP routes.
B.The OSPF routes are not in the routing table because they are overridden by a static route with AD 1.
C.The redistribute ospf 1 metric 10000 command is missing.
D.The OSPF routes are external type 2, which are not redistributed by default.
AnswerB

Redistribution only advertises routes present in the routing table. A static route with administrative distance 1 is preferred over the OSPF-learned route, so that prefix never enters the table and cannot be redistributed into EIGRP, explaining why some OSPF routes are missing.

Why this answer

Route redistribution only advertises routes that are present in the routing table. If an OSPF route is overridden by a static route with AD 1 (static routes have AD 1 by default, which is better than OSPF's 110), the OSPF route is not installed in the RIB. Consequently, the redistribution process has nothing to redistribute for that prefix, and it will not appear in EIGRP.

This is a classic redistribution gotcha: the source protocol must have the route in its routing table for redistribution to work.

Exam trap

300-410 often tests the misconception that redistribution pulls routes from the protocol database — candidates forget that only routes present in the routing table can be redistributed, so an AD conflict can silently block redistribution.

How to eliminate wrong answers

Option A is wrong because metric comparison between OSPF and EIGRP is irrelevant — redistribution does not compare metrics across protocols; it uses the configured seed metric. Option C is wrong because a missing `redistribute ospf 1 metric 10000` command would prevent all OSPF routes from being redistributed, not just 'some' routes — and the question states some routes are redistributed successfully. Option D is wrong because OSPF external type 2 routes are redistributed by default when you issue `redistribute ospf` — there is no default exclusion of E2 routes.

682
MCQeasy

Which OSPF packet type is used to send link-state advertisements (LSAs) and is acknowledged by the receiver?

A.Hello (type 1)
B.Database Description (type 2)
C.Link State Request (type 3)
D.Link State Update (type 4)
AnswerD

Link State Update packets carry LSAs to neighbouring routers, and each LSU transmission is acknowledged by the receiver using Link State Acknowledgment packets. This reliable flooding mechanism distinguishes type 4 from Link State Request and Database Description packets.

Why this answer

OSPF Link State Update (LSU) packets, type 4, are used to send link-state advertisements (LSAs) to neighboring routers. The receiver acknowledges receipt of LSUs with Link State Acknowledgment (LSAck) packets, ensuring reliable flooding of LSAs. This reliable flooding mechanism is fundamental to OSPF's link-state database synchronization.

Exam trap

The trap is confusing the packet types—candidates may pick Hello or DBD because they are more familiar, but the key is that LSUs carry LSAs and are acknowledged, while Hello and DBD serve different purposes in neighbor discovery and database synchronization.

How to eliminate wrong answers

Option A is wrong because Hello packets (type 1) are used to discover and maintain neighbor relationships, not to send LSAs. Option B is wrong because Database Description (DBD) packets (type 2) are used to summarize the link-state database during adjacency formation, not to send full LSAs. Option C is wrong because Link State Request (LSR) packets (type 3) are used to request specific LSAs from a neighbor, not to send them.

683
MCQhard

An engineer configures a DMVPN Phase 2 network. Spoke-to-spoke tunnels are established, but traffic between spokes is not using the direct tunnel. What is the most likely explanation?

A.The spoke routers have a default route via the hub, so they send traffic to the hub instead of initiating NHRP resolution for a direct tunnel.
B.The hub has 'no ip nhrp redirect' configured, which disables spoke-to-spoke tunnel setup.
C.The spokes have 'ip nhrp shortcut' enabled, which forces all traffic through the hub.
D.The tunnel mode is set to 'tunnel mode gre multipoint' on the spokes, which is incorrect.
AnswerA

With a default route pointing at the hub, spoke traffic is forwarded to the hub rather than triggering NHRP resolution for a direct spoke-to-spoke tunnel. This routing behaviour explains why the direct tunnel is bypassed.

Why this answer

In DMVPN Phase 2, spoke-to-spoke direct tunnels require the spoke to resolve the remote spoke's NBMA address via NHRP. If a spoke has a default route pointing to the hub, its routing table sends all non-local traffic to the hub instead of triggering NHRP resolution for the destination spoke, so traffic traverses hub-and-spoke paths even though direct tunnels could form. Removing the default route (or using specific routes plus NHRP shortcut) restores direct spoke-to-spoke forwarding.

Exam trap

The trap is blaming NHRP commands (redirect, shortcut) when the real cause is a routing table default route that pre-empts NHRP resolution — candidates who focus only on NHRP configuration miss the routing interaction.

How to eliminate wrong answers

Option B is wrong because 'no ip nhrp redirect' on the hub disables the redirect message that tells a spoke to optimize its path, but the question states spoke-to-spoke tunnels are already established — the issue is traffic not using them, which points to routing, not redirect. Option C is wrong because 'ip nhrp shortcut' on spokes enables the use of NHRP-resolved shortcuts; it does not force traffic through the hub — the statement inverts the command's actual effect. Option D is wrong because 'tunnel mode gre multipoint' is the correct and required tunnel mode for DMVPN (mGRE) on hub and spokes; it is not an error.

684
MCQeasy

A network engineer runs the following command on Router R6: R6# show ip route 10.0.0.0 Routing entry for 10.0.0.0/8 Known via "eigrp 100", distance 90, metric 28160 Redistributing via eigrp 100 Last update from 192.168.1.1 on GigabitEthernet0/0, 00:00:10 ago Routing Descriptor Blocks: * 192.168.1.1, from 192.168.1.1, 00:00:10 ago, via GigabitEthernet0/0 Route metric is 28160, traffic share count is 1 Additionally, an OSPF route for the same prefix is learned with distance 110. Which route will be installed in the routing table?

A.The OSPF route will be installed because it has a lower metric.
B.The EIGRP route will be installed because it has a lower administrative distance.
C.Both routes will be installed for load balancing.
D.Neither route will be installed due to a conflict.
AnswerB

EIGRP's administrative distance of 90 beats OSPF's 110, so the EIGRP route wins the tie for the same 10.0.0.0/8 prefix. Cisco IOS compares administrative distance before metrics when routes from different protocols compete, and the lower value is preferred regardless of the metric shown.

Why this answer

EIGRP internal routes have a default administrative distance of 90, which is lower than OSPF's default distance of 110. Therefore, the EIGRP route will be preferred and installed in the routing table.

685
Multi-Selectmedium

A network engineer is implementing Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate IP spoofing. The router has two interfaces: GigabitEthernet0/0 (WAN) and GigabitEthernet0/1 (LAN). The engineer wants to apply strict mode uRPF on the WAN interface and loose mode uRPF on the LAN interface. Which two commands are required to accomplish this? (Choose two.)

Select 2 answers
A.interface GigabitEthernet0/0, then ip verify unicast source reachable-via rx
B.interface GigabitEthernet0/1, then ip verify unicast source reachable-via any
C.interface GigabitEthernet0/0, then ip verify unicast source reachable-via any
D.interface GigabitEthernet0/1, then ip verify unicast source reachable-via rx
E.ip verify unicast source reachable-via rx allow-default
AnswersA, B

This command enables strict mode uRPF on the WAN interface. Strict mode checks that the source IP address is reachable via the same interface the packet was received on. This is appropriate for WAN interfaces where symmetric routing is expected, and it helps prevent spoofed packets from entering the network.

Why this answer

The correct commands are to enable strict mode uRPF on the WAN interface with ip verify unicast source reachable-via rx, and loose mode uRPF on the LAN interface with ip verify unicast source reachable-via any. These configurations match the requirement of strict on WAN and loose on LAN, providing effective anti-spoofing while accommodating asymmetric routing on the LAN.

Exam trap

The trap here is mixing up the keywords rx and any, which correspond to strict and loose modes respectively.

686
MCQhard

A network administrator is configuring a Cisco IOS router as a DHCP server. The router has two interfaces: GigabitEthernet0/0 with IP 192.168.1.1/24 and GigabitEthernet0/1 with IP 10.0.0.1/24. The administrator wants the router to assign addresses from the 192.168.1.0/24 subnet to clients on GigabitEthernet0/0. Which command must be configured in the DHCP pool to ensure that the router only assigns addresses from the correct subnet?

A.network 192.168.1.0 255.255.255.0
B.ip dhcp pool 192.168.1.0
C.default-router 192.168.1.1
D.ip dhcp excluded-address 10.0.0.1 10.0.0.254
AnswerA

The network command in DHCP pool configuration specifies the subnet and mask for the pool. This ensures that the router only assigns addresses from the 192.168.1.0/24 range to clients on that segment. Without this command, the pool would not know which addresses to offer, and the DHCP server would not function correctly for that subnet.

Why this answer

The network command is essential in a DHCP pool to define the subnet and mask from which addresses are assigned. It ensures that the router only offers addresses from the 192.168.1.0/24 range. The other options either set client parameters, exclude irrelevant addresses, or create a pool without defining its subnet.

Exam trap

The trap here is thinking that naming the pool after the subnet or excluding other subnets will define the address range, when the network command is the only one that specifies the pool's subnet.

687
MCQmedium

A network engineer runs the following command to troubleshoot a SPAN issue: R1# show monitor session 1 detail Session 1 --------- Type : Local Session Source Ports : Both : Gi0/0 Destination Ports : Gi0/1 Encapsulation : Native Ingress : Disabled What does this output indicate?

A.The session is correctly configured to send traffic from Gi0/0 to Gi0/1.
B.The session is misconfigured because the destination port should have ingress enabled.
C.The session is misconfigured because the source port must be a VLAN.
D.The session is misconfigured because encapsulation must be set to 'replicate'.
AnswerA

The output shows a local session with Gi0/0 as the source (both directions) and Gi0/1 as the destination, using native encapsulation with ingress disabled. That combination is a valid, functioning SPAN configuration, so traffic from Gi0/0 is copied to Gi0/1.

Why this answer

The output shows a valid local SPAN session: source Gi0/0 (both directions) is copied to destination Gi0/1 with native encapsulation. Ingress on the destination is disabled by default and is not required for a working SPAN session, so the configuration is correct.

Exam trap

The trap is treating optional SPAN parameters (ingress, encapsulation type, VLAN source) as mandatory, causing candidates to flag a correctly configured session as misconfigured.

How to eliminate wrong answers

Option B is wrong because ingress on the destination port is not required for SPAN — it is an optional feature for injecting traffic into the source VLAN, not a requirement for monitoring. Option C is wrong because a source port can be a physical interface (as shown); VLAN sources are an alternative, not a mandate. Option D is wrong because 'replicate' is not a valid encapsulation value for SPAN — valid values are 'native' (default) or 'dot1q' for trunk destinations.

688
MCQmedium

A network engineer runs the following command on Router R1: R1# show mpls ldp neighbor Peer LDP Ident: 10.0.0.2:0; Local LDP Ident 10.0.0.1:0 TCP connection: 10.0.0.2.646 - 10.0.0.1.52868 State: Oper; Msgs sent/rcvd: 123/120; Downstream Up time: 02:15:30 LDP discovery sources: GigabitEthernet0/0, Src IP addr: 192.168.1.2 Addresses bound to peer LDP Ident: 10.0.0.2 192.168.1.2 Based on this output, which statement is correct?

A.The LDP session is down because the state is 'Oper'.
B.The LDP session is established and operational.
C.The LDP neighbor is using upstream label distribution.
D.The LDP session is using TCP port 179.
AnswerB

The State field shows Oper, meaning the LDP session completed discovery and TCP establishment and is exchanging label messages. The peer LDP identifier, bound addresses and 02:15:30 uptime confirm an active, operational adjacency over GigabitEthernet0/0, so the session is fully established.

Why this answer

The output shows a single LDP neighbor with state 'Oper' (operational), indicating the LDP session is up. The 'Downstream' mode is default. The peer LDP Ident is 10.0.0.2:0, and the local LDP Ident is 10.0.0.1:0.

The addresses bound include the peer's router-id and the interface IP. No problems are indicated.

689
Multi-Selectmedium

Which THREE symptoms indicate a problem with SNMP trap delivery from a Cisco router? (Choose THREE.)

Select 3 answers
A.The NMS does not receive traps, but other SNMP operations (gets) work.
B.The 'show snmp' command shows increasing 'SNMP queue overflow' counters.
C.Syslog messages show '%SNMP-3-AUTHFAIL' for the trap receiver.
D.The router CPU utilization is consistently above 90%.
E.The NMS can ping the router successfully.
AnswersA, B, C

Indicates a specific issue with trap generation or delivery, not general SNMP connectivity.

Why this answer

SNMP traps are sent as unsolicited UDP packets from the router to the NMS, while SNMP get operations use a separate request-response mechanism. If gets succeed but traps fail, the issue is typically with trap configuration (e.g., wrong target IP, community string mismatch, or UDP port 162 blocked) rather than general SNMP or network connectivity.

Exam trap

Cisco often tests the distinction between SNMP trap delivery issues and general SNMP or network problems, leading candidates to mistakenly select high CPU or ping success as relevant symptoms when they are not specific to trap delivery.

690
MCQhard

A network engineer runs the following command to verify OSPF SPF calculations: R1# show ip ospf statistics OSPF Router with ID (1.1.1.1) (Process ID 1) Area 0: SPF algorithm executed 12 times SPF calculation time (in msec): Total: 12, Average: 1.0 Minimum: 0, Maximum: 2 Last SPF due to: LSA change Number of LSA changes: 5 Number of LSA deletions: 2 Number of LSA additions: 3 Number of LSA updates: 0 Area 1: SPF algorithm executed 3 times SPF calculation time (in msec): Total: 3, Average: 1.0 Minimum: 0, Maximum: 1 Last SPF due to: LSA change Number of LSA changes: 2 Number of LSA deletions: 0 Number of LSA additions: 2 Number of LSA updates: 0 What does this output indicate?

A.The router has not performed any SPF calculations.
B.Area 0 has experienced more network changes than Area 1, as indicated by higher SPF runs and LSA changes.
C.The SPF calculation time is too high, indicating a performance issue.
D.The last SPF was triggered by a timer expiry.
AnswerB

Area 0 shows 12 SPF executions against Area 1's 3, with five LSA changes versus two. Higher SPF runs and LSA counts directly evidence more frequent topology changes in Area 0, satisfying the comparison the stem asks about.

Why this answer

The output shows Area 0 executed the SPF algorithm 12 times with 5 LSA changes (2 deletions, 3 additions), while Area 1 executed SPF only 3 times with 2 LSA changes. More SPF runs and more LSA changes in Area 0 directly indicate greater topology churn in that area. The 'Last SPF due to: LSA change' line confirms the trigger was an LSA event, not a timer.

Exam trap

The trap is reading 'SPF calculation time' and assuming any nonzero value indicates a performance problem, when in fact the exam wants you to compare relative SPF run counts and LSA change counts between areas to infer topology churn.

How to eliminate wrong answers

Option A is wrong because the output explicitly states 'SPF algorithm executed 12 times' in Area 0 and 3 times in Area 1, so SPF calculations clearly occurred. Option C is wrong because the SPF calculation times are extremely low (total 12 ms, average 1.0 ms, max 2 ms), which indicates healthy performance, not a problem. Option D is wrong because the output states 'Last SPF due to: LSA change,' meaning the trigger was a link-state advertisement change, not a timer expiry.

691
MCQmedium

Which EIGRP packet type is used to confirm receipt of an update during reliable transport in a VRF-Lite configuration?

A.Hello
B.Update
C.ACK
D.Query
AnswerC

The ACK packet confirms receipt of EIGRP updates during reliable transport, operating within VRF-Lite exactly as in non-VRF deployments. It satisfies the stem by providing the acknowledgement mechanism that guarantees delivery of update, query, and reply packets.

Why this answer

EIGRP uses Reliable Transport Protocol (RTP) for Update, Query, and Reply packets, and the ACK packet is the mechanism that confirms receipt of those reliable packets. In a VRF-Lite configuration the same RTP behavior applies per-VRF, so an ACK is still the packet type that acknowledges an Update. Hello packets are unreliable and are not acknowledged, which is why ACK is the correct answer.

Exam trap

The trap is confusing which EIGRP packets are reliable — candidates may pick Update or Query because they know those use RTP, forgetting that ACK is the packet that actually confirms receipt.

How to eliminate wrong answers

Option A is wrong because Hello packets are sent unreliably (no RTP sequence/acknowledgement) and are used only for neighbor discovery and keepalive, not for confirming receipt of an Update. Option B is wrong because Update packets carry route information and are themselves the reliable packets that must be acknowledged — they do not confirm receipt of another Update. Option D is wrong because Query packets are sent reliably to request route information during diffusing computation (DUAL), and they also require an ACK; they do not serve as the acknowledgement itself.

692
MCQeasy

A network administrator is setting up a site-to-site VPN between two Cisco routers using IPsec. The administrator wants to ensure that the VPN tunnel uses strong encryption and hashing algorithms. Which of the following should be configured to define the encryption and hashing algorithms used for the IPsec SA?

A.Transform set
B.ISAKMP policy
C.IKEv2 profile
D.Crypto map
AnswerA

A transform set defines the encryption and hashing algorithms (e.g., esp-aes 256 and esp-sha-hmac) that will be used to protect the data. It is referenced by the crypto map or IPsec profile. This is the correct place to specify the algorithms for the IPsec SA. The transform set ensures both peers agree on the security parameters.

Why this answer

The transform set is used to define the encryption and hashing algorithms for the IPsec SA. It is referenced by the crypto map or IPsec profile. The ISAKMP policy defines Phase 1 parameters, while the crypto map and IKEv2 profile are used for other purposes.

Therefore, the transform set is the correct answer.

Exam trap

The trap here is confusing IKE Phase 1 parameters (defined in ISAKMP policy) with IPsec Phase 2 parameters (defined in transform set).

693
Multi-Selectmedium

Which TWO symptoms indicate that syslog messages are not being sent to the remote syslog server? (Choose TWO.)

Select 2 answers
A.The 'show logging' command shows messages in the local buffer.
B.The syslog server receives messages from other devices but not from this router.
C.The 'show log' command returns no output.
D.The 'show logging' output does not list the syslog server IP address under 'Logging to'.
E.Debug output appears on the console but not on the syslog server.
AnswersB, D

The server accepting messages from other devices proves the collector, network path and port are functional, isolating the fault to this router's logging configuration. This satisfies the stem's requirement for a symptom indicating messages are not being sent from this specific device, rather than a server-side or transport failure.

Why this answer

Option B is correct because if the remote syslog server is receiving messages from other devices but not from this specific router, it directly indicates that this router's syslog messages are not reaching the server, isolating the fault to the router's logging configuration or connectivity. Option D is correct because the 'show logging' output includes a 'Logging to' section that lists configured remote syslog hosts; if the syslog server's IP address is absent there, no remote logging destination is configured, so messages cannot be sent to it. Option A does not indicate a problem, since messages appearing in the local buffer is normal and can coexist with successful remote logging.

Option C is not a valid symptom because 'show log' is not a standard Cisco IOS command for verifying syslog destinations, and no output would not specifically prove remote syslog failure. Option E is not a reliable indicator because debug output appearing on the console is expected behavior and does not by itself show that syslog messages are failing to reach the remote server.

Exam trap

The trap is confusing local logging symptoms with remote syslog symptoms; candidates may pick options that only indicate local logging is working or not working, rather than focusing on remote syslog configuration.

694
MCQeasy

A network engineer runs the following command to verify Flexible NetFlow record configuration: R1# show flow record FLOW-RECORD-1 flow record FLOW-RECORD-1 match ipv4 source address match ipv4 destination address match ip protocol collect counter bytes collect counter packets collect timestamp sys-uptime first collect timestamp sys-uptime last What does this output indicate?

A.The record collects only packet counts, not byte counts.
B.The record matches on source and destination IP addresses and protocol, and collects byte/packet counters and timestamps.
C.The record does not include any timestamp information.
D.The record matches on TCP flags.
AnswerB

The record's match fields define the flow key from IPv4 source, destination and protocol, while collect statements gather byte and packet counters plus first and last sys-uptime timestamps. This combination determines what traffic is tracked and which statistics are exported.

Why this answer

The output shows the definition of a Flexible NetFlow record. It matches on source IP, destination IP, and protocol, and collects byte and packet counters along with timestamps for the first and last packet of the flow.

695
MCQmedium

Router R4 has the following DHCPv6 configuration: ipv6 dhcp pool DHCP6_POOL2 address prefix 2001:db8:2::/64 dns-server 2001:db8::1 ! interface GigabitEthernet0/1 ipv6 address 2001:db8:2::1/64 ipv6 dhcp server DHCP6_POOL2 ipv6 nd managed-config-flag no shutdown What is the effect of this configuration?

A.Hosts will use DHCPv6 to obtain both their IPv6 address and other configuration parameters like DNS.
B.Hosts will use SLAAC for addressing and DHCPv6 for DNS only.
C.The DHCPv6 pool is missing a domain-name, so it will not provide any configuration.
D.The ipv6 nd managed-config-flag command is incompatible with the DHCPv6 server and will cause an error.
AnswerA

The managed-config-flag in Router Advertisements tells hosts to use DHCPv6 for addressing, and the pool supplies both a prefix from 2001:db8:2::/64 and the DNS server, so hosts obtain address and configuration parameters via DHCPv6 rather than SLAAC.

Why this answer

The configuration uses the `ipv6 nd managed-config-flag` command, which sets the Managed Address Configuration flag (M flag) in Router Advertisement (RA) messages. When the M flag is set to 1, hosts are instructed to use DHCPv6 (stateful DHCPv6) to obtain their IPv6 addresses, not SLAAC. Additionally, the DHCPv6 pool provides DNS server information, so hosts will use DHCPv6 for both addressing and other configuration parameters like DNS.

This matches option A.

Exam trap

Cisco often tests the distinction between the M flag (managed-config-flag) and the O flag (other-config-flag), where candidates mistakenly think the M flag only affects DNS or that SLAAC is still used for addressing when the M flag is set.

How to eliminate wrong answers

Option B is wrong because the `ipv6 nd managed-config-flag` sets the M flag to 1, which tells hosts to use DHCPv6 for addressing, not SLAAC; SLAAC is used when the M flag is 0 and the O flag (Other Configuration flag) may be set for DHCPv6-only DNS. Option C is wrong because a DHCPv6 pool does not require a domain-name to function; it can provide an address prefix and DNS server without a domain name, and the configuration will still work. Option D is wrong because the `ipv6 nd managed-config-flag` command is fully compatible with the DHCPv6 server configuration; it is designed to work together to signal hosts to use stateful DHCPv6.

696
MCQmedium

A network engineer runs the following command to verify IPv6 uRPF drops: R1# show ipv6 traffic | include verify 0 verify source drops, 0 verify source suppressed drops What does this output indicate?

A.No IPv6 packets have been dropped by uRPF checks.
B.uRPF is not configured on any interface.
C.uRPF is dropping all packets.
D.The router is not processing IPv6 traffic.
AnswerA

The verify source drops counters increment only when uRPF discards a packet whose source address fails the reverse-path check. Both values read zero, confirming that no IPv6 packet has been dropped by unicast RPF on this router.

Why this answer

The output shows '0 verify source drops' and '0 verify source suppressed drops', which are the counters for IPv6 unicast Reverse Path Forwarding (uRPF) drops. Since both counters are zero, no IPv6 packets have been dropped by uRPF checks. This does not necessarily mean uRPF is not configured; it simply indicates that no packets have failed the uRPF verification process.

Exam trap

Cisco often tests the misconception that zero counters mean the feature is not configured, when in fact the feature may be configured and simply not dropping any packets.

How to eliminate wrong answers

Option B is wrong because the counters being zero do not prove that uRPF is not configured; uRPF could be configured and passing all traffic, or it could be configured with 'allow-default' or 'allow-none' options that suppress drops. Option C is wrong because zero drops indicate no packets are being dropped, not that all packets are dropped. Option D is wrong because the router is clearly processing IPv6 traffic (the command itself shows IPv6 traffic statistics), and zero drops do not imply a lack of IPv6 traffic processing.

697
MCQmedium

Which statement correctly describes the behavior of the 'logging synchronous' command on a Cisco IOS device?

A.It disables all syslog messages on the console line.
B.It causes syslog messages to be displayed only after a carriage return.
C.It changes the severity level of messages sent to the console.
D.It enables logging to a synchronous serial interface.
AnswerB

Syslog messages are held until the user presses Enter, preventing interruption.

Why this answer

The 'logging synchronous' command on a Cisco IOS device ensures that syslog messages are displayed only after the user presses Enter (carriage return). This prevents log messages from interrupting the user's command input, making the console session more readable.

Exam trap

300-410 often tests the exact behavior of 'logging synchronous', and candidates may confuse it with commands that disable logging or change severity levels, leading to incorrect answers.

How to eliminate wrong answers

Option A is wrong because 'logging synchronous' does not disable syslog messages; it only controls their display timing. Option C is wrong because it does not change the severity level of messages sent to the console; that is done with the 'logging console' command. Option D is wrong because it does not enable logging to a synchronous serial interface; the command is unrelated to serial interfaces.

698
MCQeasy

A network engineer is configuring a site-to-site IPsec VPN between two Cisco routers. The engineer wants to use a pre-shared key for authentication. Which command is used to configure the pre-shared key on the router?

A.crypto ipsec key MYKEY
B.crypto isakmp key MYKEY address 192.168.1.1
C.crypto isakmp policy 10 authentication pre-share
D.crypto map MYMAP 10 set peer 192.168.1.1
AnswerB

The 'crypto isakmp key' command is used to configure a pre-shared key for IKE authentication. It specifies the key string and the peer's IP address. In this scenario, the peer is 192.168.1.1. This command is part of the ISAKMP policy configuration and is required for Phase 1 authentication when using pre-shared keys. It must be configured on both peers with matching keys.

Why this answer

Pre-shared key authentication in IKE is configured using the 'crypto isakmp key' command, which specifies the key and the peer address. This command is separate from the ISAKMP policy that defines the authentication method. Both peers must have the same pre-shared key for Phase 1 to succeed.

The key is used during the IKE authentication exchange.

Exam trap

The trap here is confusing the ISAKMP policy command that sets the authentication method with the command that actually configures the pre-shared key.

699
MCQeasy

A network engineer is configuring EIGRP on a Cisco router. The router has two interfaces: GigabitEthernet0/0 with IP address 10.1.1.1/24 and GigabitEthernet0/1 with IP address 10.2.2.1/24. The engineer wants to advertise both networks into EIGRP AS 100. Which configuration command is required to enable EIGRP on the interfaces?

A.network 10.1.1.0 0.0.0.255 and network 10.2.2.0 0.0.0.255
B.network 10.0.0.0
C.ipv6 eigrp 100 on each interface
D.network 10.0.0.0 0.255.255.255
AnswerA

EIGRP uses the network command with a wildcard mask to specify which interfaces participate in EIGRP. To advertise both 10.1.1.0/24 and 10.2.2.0/24, you need two network statements: one for each subnet. The wildcard mask 0.0.0.255 matches the /24 subnet. This configuration enables EIGRP on both interfaces and advertises the connected networks. This is the correct and specific way to achieve the goal.

Why this answer

To enable EIGRP for IPv4 on interfaces, you use the network command under router eigrp with a wildcard mask. Each network statement specifies a range of addresses; the wildcard mask 0.0.0.255 matches a /24 subnet. Two statements are needed to cover both 10.1.1.0/24 and 10.2.2.0/24.

The other options are either too broad, invalid syntax, or for IPv6.

Exam trap

The trap here is using a single network statement with a classful mask or no wildcard mask, which either enables EIGRP on too many interfaces or is invalid syntax.

700
MCQmedium

Examine this OSPF configuration on router R5: router ospf 1 network 10.0.0.0 0.255.255.255 area 0 passive-interface default no passive-interface GigabitEthernet0/0 What is the effect of the passive-interface default command?

A.All interfaces except GigabitEthernet0/0 will be passive; GigabitEthernet0/0 will send and receive OSPF hellos.
B.All interfaces are passive, including GigabitEthernet0/0, because the no passive-interface command is ignored.
C.Only interfaces with network statements will be affected; other interfaces remain active.
D.The configuration is invalid because passive-interface default cannot be used with OSPF.
AnswerA

The passive-interface default command sets every interface passive, suppressing OSPF hello transmission and reception. The no passive-interface GigabitEthernet0/0 exception restores normal adjacency formation on that interface, letting it send and receive hellos while all others remain silent.

Why this answer

The `passive-interface default` command sets all OSPF-enabled interfaces to passive mode by default, meaning they will not send or receive OSPF hello packets. The subsequent `no passive-interface GigabitEthernet0/0` explicitly overrides this default for that interface, making it active. Therefore, all interfaces except GigabitEthernet0/0 become passive, while GigabitEthernet0/0 participates fully in OSPF by sending and receiving hellos.

Exam trap

The trap here is assuming that `passive-interface default` makes all interfaces passive without exception, ignoring the subsequent `no passive-interface` override; candidates must remember that the `no` form explicitly re-enables OSPF on the specified interface.

How to eliminate wrong answers

Option B is wrong because the `no passive-interface` command is not ignored; it explicitly overrides the default passive setting for the specified interface. Option C is wrong because `passive-interface default` affects all OSPF-enabled interfaces, not just those with network statements; interfaces without network statements are not running OSPF and thus are unaffected, but the command's scope is all OSPF interfaces. Option D is wrong because `passive-interface default` is a valid OSPF configuration command on Cisco routers; it is commonly used to set all interfaces passive and then selectively enable specific ones.

701
MCQmedium

A network engineer runs the following command on Router R1: R1# show mpls ldp neighbor Peer LDP Ident: 192.168.1.2:0, Local LDP Ident: 192.168.0.1:0 TCP connection: 192.168.1.2.646 - 192.168.0.1.49876 State: Oper; Msgs sent/rcvd: 100/105; Downstream on demand Up time: 00:10:30 LDP discovery sources: GigabitEthernet0/0, Src IP addr: 192.168.1.2 Addresses bound to peer LDP Ident: 192.168.1.2 10.1.1.2 Based on this output, what is the state of the LDP session?

A.The LDP session is down due to a TCP connection issue.
B.The LDP session is operational and exchanging label information.
C.The LDP session is in the process of being established.
D.The LDP session is using downstream on demand mode, which is a problem.
AnswerB

The session shows State: Oper, confirming the TCP connection on port 646 is established and label messages are flowing (100 sent, 105 received). The "Downstream on demand" mode indicates labels are advertised only upon request, satisfying the operational state requirement in the output.

Why this answer

The output shows 'State: Oper', which means the LDP session is operational. The 'Downstream on demand' label distribution mode is a valid mode (RFC 5036) and does not indicate a problem. The session is exchanging label information, as evidenced by the 'Oper' state and the presence of peer addresses.

Exam trap

Cisco often tests the misconception that 'Downstream on demand' is a problem or that any mention of 'downstream' implies a failure, when in fact it is a standard operational mode for LDP.

How to eliminate wrong answers

Option A is wrong because the TCP connection is established (TCP connection: 192.168.1.2.646 - 192.168.0.1.49876) and the state is 'Oper', not down. Option C is wrong because the state is 'Oper', not 'Initialized' or 'OpenRec', which would indicate an ongoing establishment process. Option D is wrong because 'Downstream on demand' is a valid label distribution mode per RFC 5036; it is not inherently a problem and is commonly used in MPLS LDP configurations.

702
MCQhard

A network engineer runs the following command to troubleshoot a VRF-Lite CoPP issue: R1# show policy-map control-plane input class CoPP-ACL vrf CUSTOMER_I Output: Class-map: CoPP-ACL (match-all) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: access-group 100 police: cir 8000 bps, bc 1500 bytes, be 1500 bytes conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop What does this output indicate?

A.The CoPP policy is dropping all packets that match access-group 100.
B.The CoPP policy is rate-limiting traffic to 8000 bps, but no traffic has matched the class yet.
C.The CoPP policy has matched many packets and is dropping them due to exceeding the rate.
D.The CoPP policy is not applied to the control plane for this VRF.
AnswerB

Zero matched packets alongside a configured 8000 bps policer confirms the class-map is bound and active but no traffic has hit access-group 100 in the VRF. The counters show no conformed, exceeded or violated traffic, so drops are not occurring.

Why this answer

The output shows '0 packets, 0 bytes' matched and a 5-minute offered rate of 0 bps, meaning no traffic has hit the class-map yet. The police stanza confirms the policy is configured to rate-limit matching traffic to a CIR of 8000 bps with a 1500-byte burst, but since no packets have matched access-group 100, no conform/exceed/violate counters have incremented. This indicates the CoPP policy is armed and applied, but simply idle.

Exam trap

The trap here is confusing '0 packets matched' with 'policy not working' — candidates see zero counters and assume the policy is dropping or unapplied, when in fact zero counters simply mean no traffic has matched the class yet.

How to eliminate wrong answers

Option A is wrong because the drop counters (exceeded/violated) are both 0, so nothing is being dropped — the class has simply not matched any traffic. Option C is wrong because the match counters show 0 packets, contradicting the claim that many packets were matched and dropped. Option D is wrong because the command itself successfully scopes the policy to 'vrf CUSTOMER_I' on the control plane input, proving the policy is applied to that VRF's control plane.

703
MCQeasy

A network engineer runs the following command to troubleshoot an Administrative Distance issue: R1# show ip route 172.16.0.0 255.255.0.0 Routing entry for 172.16.0.0/16 Known via "ospf 1", distance 110, metric 20, type intra area Last update from 10.1.1.2 on GigabitEthernet0/0, 00:00:05 ago Routing Descriptor Blocks: * 10.1.1.2, from 2.2.2.2, 00:00:05 ago, via GigabitEthernet0/0 Route metric is 20, traffic share count is 1 What does this output indicate?

A.The route is an OSPF intra-area route with administrative distance 110, which is the default for OSPF.
B.The route is an OSPF external route with administrative distance 110.
C.The route has an administrative distance of 20 because it is an OSPF route.
D.The route is preferred over an EIGRP route with AD 90.
AnswerA

OSPF's default administrative distance of 110 applies to this intra-area route, as confirmed by the "distance 110" and "type intra area" fields in the output. The metric of 20 reflects the cumulative cost to 172.16.0.0/16, and the route was learned via OSPF process 1 on GigabitEthernet0/0.

Why this answer

The output shows an OSPF intra-area route with administrative distance 110, which is the default for OSPF. The metric is 20, and the route is learned from neighbor 2.2.2.2.

704
MCQeasy

In a standard IPv4 ACL, what is the range of valid numbers for the access-list number?

A.1-99 and 1300-1999
B.100-199 and 2000-2699
C.1-99 only
D.1-199
AnswerA

Standard numbered IPv4 ACLs occupy the ranges 1-99 and 1300-1999, with the expanded range added for additional ACLs. This satisfies the question's requirement by naming the exact valid numbers for standard ACLs, distinct from extended ACL ranges.

Why this answer

Standard IPv4 ACLs use access-list numbers 1-99 and 1300-1999 to filter traffic based solely on source IP address. The expanded range 1300-1999 was introduced to provide additional standard ACL identifiers beyond the original 1-99, allowing more granular control without overlapping with extended ACL ranges.

Exam trap

Cisco often tests the expanded standard ACL range (1300-1999) to catch candidates who only memorize the original 1-99 range, assuming standard ACLs are limited to that smaller set.

How to eliminate wrong answers

Option B is wrong because 100-199 and 2000-2699 are the valid ranges for extended IPv4 ACLs, not standard ACLs. Option C is wrong because it omits the expanded standard ACL range 1300-1999, which is also valid per Cisco IOS. Option D is wrong because 100-199 is reserved for extended ACLs, and standard ACLs do not include numbers 100-199.

705
Multi-Selectmedium

Which TWO configuration steps are required to successfully redistribute OSPF routes into EIGRP on a Cisco router? (Choose TWO.)

Select 2 answers
A.Enter EIGRP router configuration mode using the 'router eigrp <as-number>' command.
B.Configure a route-map under OSPF to match OSPF routes for redistribution.
C.Use the 'redistribute eigrp <as-number>' command under OSPF router configuration mode.
D.Set a seed metric for EIGRP using the 'default-metric' command or specify metric in the redistribute command.
E.Issue the 'default-information originate' command under OSPF to advertise redistributed routes.
AnswersA, D

Redistribution requires EIGRP to be running first, so entering EIGRP router configuration mode with 'router eigrp <as-number>' establishes the process that will receive the redistributed OSPF routes. Without this step, no EIGRP routing instance exists to accept them.

Why this answer

Option A is correct because redistribution into EIGRP must be configured from within EIGRP router configuration mode, entered with the 'router eigrp <as-number>' command, where the 'redistribute ospf <process-id>' statement is then issued. Option D is correct because EIGRP requires a seed metric for redistributed routes; without it the routes are not installed, so you must supply bandwidth, delay, reliability, load, and MTU either via the 'default-metric' command or inline with the redistribute command. Option B is not required because a route-map is optional filtering, not a mandatory step for OSPF-to-EIGRP redistribution.

Option C is wrong because 'redistribute eigrp' under OSPF router configuration mode performs the reverse direction (EIGRP into OSPF), not OSPF into EIGRP. Option E is wrong because 'default-information originate' only injects a default route into OSPF and is unrelated to redistributing OSPF routes into EIGRP.

706
MCQhard

A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco IOS routers. The tunnel is up, but traffic is not passing. The administrator suspects a routing issue. Which command should be used to verify that the crypto ACL matches the traffic being sent?

A.show access-lists
B.show crypto ipsec sa
C.show crypto isakmp sa
D.show crypto map
AnswerA

'show access-lists' displays the configured ACLs and their hit counters. By examining the crypto ACL referenced in the crypto map, you can see if the counters are incrementing for the interesting traffic. If the counters are not incrementing, the ACL may not match the traffic, indicating a mismatch. This is a key step in troubleshooting IPsec VPNs when the tunnel is up but traffic is not flowing.

Why this answer

When an IPsec tunnel is up but traffic is not passing, a common cause is a mismatch between the crypto ACL and the actual traffic. The crypto ACL defines interesting traffic that should be encrypted. By using 'show access-lists', you can see if the ACL's permit entries are being hit by the traffic.

If counters are not incrementing, the traffic is not matching the ACL, and you need to adjust it.

Exam trap

The trap here is assuming that 'show crypto ipsec sa' alone can confirm ACL matches, but it only shows encrypted packets, not the ACL hit counters.

707
MCQeasy

A network engineer is configuring a static route on a Cisco IOS router to reach a remote network. The engineer wants the route to be used only if the primary path fails and to be removed from the routing table when the primary path is available. Which type of static route should be configured?

A.Default static route
B.Recursive static route
C.Floating static route
D.Directly connected static route
AnswerC

A floating static route is configured with a higher administrative distance than the primary route, so it is only installed in the routing table when the primary route fails. This makes it a backup path. It is commonly used for redundancy in WAN links, where a secondary link should only be used if the primary goes down.

Why this answer

A floating static route is designed to be a backup by setting a higher administrative distance than the primary route. It remains inactive until the primary route is removed from the routing table, at which point it becomes active. This provides redundancy without manual intervention, exactly matching the scenario's requirement.

Exam trap

The trap here is confusing a floating static route with a default static route; the default route is always used as a last resort, while a floating static route is conditional on the primary route's failure.

708
MCQhard

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP class-map: MANAGEMENT (match-all) 100 packets, 5000 bytes 5 minute offered rate 0 bps police: 8000 bps, 1500 limit, 1500 extended limit conformed 95 packets, 4750 bytes; action: transmit exceeded 5 packets, 250 bytes; action: drop conformed 0 bps, exceed 0 bps class-map: ROUTING (match-all) 200 packets, 10000 bytes 5 minute offered rate 0 bps police: 16000 bps, 3000 limit, 3000 extended limit conformed 200 packets, 10000 bytes; action: transmit exceeded 0 packets, 0 bytes; action: drop conformed 0 bps, exceed 0 bps Based on this output, what is happening to traffic matching the MANAGEMENT class?

A.All management traffic is being transmitted without any drops.
B.Some management traffic is being dropped because it exceeds the configured police rate.
C.The management traffic is being rate-limited but no packets are dropped.
D.The police rate is too high, causing all traffic to be dropped.
AnswerB

The MANAGEMENT class shows 95 conformed packets transmitted and 5 exceeded packets dropped, so policing at 8000 bps with a 1500-byte limit is discarding traffic above the configured rate. This directly satisfies the stem's question about what is happening to that class.

Why this answer

The output shows that the MANAGEMENT class has a police rate of 8000 bps. Out of 100 packets, 5 packets were exceeded and dropped because they exceeded this configured rate. This confirms that some management traffic is being dropped due to policing, making option B correct.

Exam trap

Cisco often tests the distinction between 'policing' (which drops excess traffic) and 'shaping' (which buffers excess traffic), and candidates may mistakenly think that a policer only rate-limits without dropping packets.

How to eliminate wrong answers

Option A is wrong because the output clearly shows 5 packets were dropped (exceeded action: drop), so not all management traffic is transmitted. Option C is wrong because packets are indeed dropped (5 exceeded packets), not just rate-limited without drops. Option D is wrong because the police rate is not too high; only 5 packets were dropped, not all traffic, and the conformed count shows most traffic is transmitted.

709
MCQmedium

Which of the following is true regarding the default behavior of NAT in Cisco IOS when handling ICMP traffic?

A.ICMP traffic is not translated by NAT unless explicitly configured.
B.ICMP NAT entries use the same timeout as TCP entries by default.
C.ICMP NAT entries timeout after 60 seconds by default.
D.ICMP NAT entries are permanent and do not time out.
AnswerC

Cisco IOS creates ICMP NAT translations with a 60-second timeout by default, unlike TCP's 86400-second and UDP's 300-second defaults. This shorter timer reflects ICMP's connectionless nature, so idle echo entries are removed quickly to conserve translation table space.

Why this answer

C is correct because Cisco IOS NAT uses a default timeout of 60 seconds for ICMP NAT entries. When an ICMP packet is translated, the router creates a NAT translation entry, and if no subsequent traffic matches that entry within 60 seconds, the entry is removed. This behavior is independent of TCP or UDP timeouts and is specific to ICMP.

Exam trap

Cisco often tests the misconception that ICMP NAT entries are permanent or use the same timeout as TCP, when in fact they have a distinct and much shorter default timeout of 60 seconds.

How to eliminate wrong answers

Option A is wrong because ICMP traffic is translated by NAT by default; no explicit configuration is required for ICMP to be subject to NAT. Option B is wrong because ICMP NAT entries do not use the same timeout as TCP entries; TCP entries default to 86400 seconds (24 hours) while ICMP defaults to 60 seconds. Option D is wrong because ICMP NAT entries are not permanent; they time out after 60 seconds of inactivity by default, though the timeout can be adjusted with the 'ip nat translation icmp-timeout' command.

710
MCQmedium

A network engineer is troubleshooting an IPv6 connectivity issue between two sites connected via a 6to4 tunnel. The tunnel is configured on both routers and shows as up/up, but the engineer cannot ping the IPv6 address of the remote tunnel endpoint. The engineer checks the routing table and sees no route to the remote IPv6 prefix. What is the most likely cause of this problem?

A.The tunnel source interface is configured with a private IPv4 address, causing the 6to4 prefix to be invalid.
B.The tunnel mode is incorrectly set to ipv6ip instead of 6to4.
C.The tunnel destination is misconfigured with the remote router's IPv6 address instead of its IPv4 address.
D.The IPv6 address on the tunnel interface is not in the 2002::/16 range.
AnswerA

A 6to4 tunnel forms its 2002::/16 IPv6 prefix from the router's IPv4 tunnel source. Private or RFC 1918 addresses like 10.0.0.1 or 192.168.1.1 cannot be embedded into a publicly valid 2002:V4ADDR::/16 prefix, so the router cannot derive or advertise a routable 6to4 prefix. This makes the source address the root cause of the tunnel failure, whereas other configuration aspects are irrelevant or secondary.

Why this answer

For a 6to4 tunnel, the IPv6 address on the tunnel interface must be derived from the tunnel source's public IPv4 address using the 2002:IPv4-address::/48 prefix format. If the tunnel source interface has a private IPv4 address (e.g., 10.0.0.1), the resulting 6to4 prefix (2002:0a00:0001::/48) is non-routable over the public Internet because private addresses are not globally unique. This causes the remote router to have no route to the invalid prefix, breaking connectivity even though the tunnel interface is up/up.

Exam trap

Cisco often tests the misconception that a 6to4 tunnel only requires the tunnel to be up/up, but the real issue is the routability of the derived 2002::/48 prefix when the source IPv4 address is private.

How to eliminate wrong answers

Option B is wrong because setting the tunnel mode to 'ipv6ip' creates a manually configured IPv6-over-IPv4 tunnel, which requires explicit IPv4 destination and static routes, but the question describes a 6to4 tunnel that uses automatic address derivation; the mode mismatch would not cause a missing route to the remote IPv6 prefix in the same way. Option C is wrong because the tunnel destination in a 6to4 tunnel is not configured at all (it is derived from the destination IPv6 address), so misconfiguring it with the remote router's IPv6 address would be syntactically incorrect or ignored, but the core issue is the invalid source address, not the destination. Option D is wrong because while 6to4 addresses must be in the 2002::/16 range, the problem states the engineer cannot ping the remote tunnel endpoint and sees no route to the remote IPv6 prefix; if the local IPv6 address were outside 2002::/16, the tunnel might still be up but the remote router would not have a route back, but the most likely cause given the missing route is the private source address making the prefix non-routable.

711
MCQeasy

A network administrator is configuring a Cisco IOS XE router to support MPLS L3VPN. The administrator needs to enable MPLS forwarding on an interface that connects to the service provider core. Which command should be applied to the interface?

A.tag-switching ip
B.mpls ip
C.mpls label protocol ldp
D.mpls ldp router-id loopback0
AnswerB

The 'mpls ip' command enables MPLS forwarding on the interface, allowing it to send and receive labeled packets. This is essential for the interface to participate in the MPLS core. It is the correct command to enable MPLS on a core-facing interface in an MPLS L3VPN deployment.

Why this answer

The 'mpls ip' command is the standard way to enable MPLS forwarding on an interface in Cisco IOS XE. It allows the interface to forward labeled packets, which is required for MPLS L3VPN. The other commands either set global parameters or use deprecated syntax, and do not directly enable MPLS forwarding on the interface.

Exam trap

The trap here is selecting 'tag-switching ip' as an alternative to 'mpls ip'; while functionally similar, it is deprecated and not the correct command for current Cisco IOS XE.

712
Multi-Selecthard

Which TWO statements about Flexible NetFlow flow monitors and flow exporters are true? (Choose TWO.)

Select 2 answers
A.A flow monitor can reference only one flow record, but multiple flow monitors can reference the same flow record.
B.A flow exporter can be referenced by only one flow monitor to avoid export conflicts.
C.The default export format for Flexible NetFlow is NetFlow version 5.
D.The flow monitor is applied to an interface using the 'ip flow-export' command.
E.A flow exporter can be referenced by multiple flow monitors simultaneously.
AnswersA, E

A flow monitor binds exactly one flow record, defining which fields are captured, while that same record can be reused by any number of monitors. This satisfies the stem's constraint by confirming the one-to-one monitor-to-record relationship alongside the many-to-one record reuse permitted across monitors.

Why this answer

Option A is correct because a Flexible NetFlow flow monitor is configured with exactly one flow record via the 'record' command, but that same flow record can be reused by any number of flow monitors. Option E is correct because a flow exporter is a reusable configuration object that can be referenced by multiple flow monitors at the same time, allowing several monitors to send data to the same destination. Option B is false because there is no restriction limiting a flow exporter to a single flow monitor.

Option C is false because Flexible NetFlow defaults to NetFlow version 9 export format, not version 5. Option D is false because a flow monitor is applied to an interface with the 'ip flow monitor <name> input/output' command, while 'ip flow-export' is used for traditional NetFlow export configuration.

Exam trap

300-410 often tests the relationships between flow records, monitors, and exporters; candidates may incorrectly assume a one-to-one relationship between exporter and monitor, or confuse the default export version with NetFlow v5.

713
MCQmedium

Examine the following configuration on a PE router: ip vrf CUSTOMER-E rd 400:1 route-target export 400:1 route-target import 400:2 ! interface GigabitEthernet0/5 ip vrf forwarding CUSTOMER-E ip address 10.4.4.1 255.255.255.252 ! router bgp 65000 neighbor 10.0.0.1 remote-as 65000 neighbor 10.0.0.1 update-source Loopback0 ! address-family vpnv4 neighbor 10.0.0.1 activate neighbor 10.0.0.1 send-community extended exit-address-family ! address-family ipv4 vrf CUSTOMER-E neighbor 10.4.4.2 remote-as 65003 neighbor 10.4.4.2 activate neighbor 10.4.4.2 route-map SET-COMMUNITY in exit-address-family ! route-map SET-COMMUNITY permit 10 set community 100:100 What is the effect of the route-map on the incoming routes from the CE?

A.The route-map will set the standard community 100:100 on the routes received from the CE, but the RT is still determined by the route-target export command.
B.The route-map will override the route-target export and set the RT to 100:100.
C.The route-map will cause the BGP session to reset because the community format is incorrect.
D.The route-map will have no effect because the community is not sent to the CE.
AnswerA

The route-map sets the standard community 100:100 on routes learned from the CE, but standard communities do not control VPN import or export. The route-target export 400:1 command still determines the extended community RT attached.

Why this answer

The route-map SET-COMMUNITY is applied inbound on the BGP session with the CE, so it sets the standard community 100:100 on routes received from the CE. However, the route-target (RT) for the VRF is determined by the route-target export command under the VRF configuration, not by the standard community set by the route-map. The RT is a BGP extended community used for VPN route distribution, and it is separate from standard communities.

Exam trap

The trap is confusing standard communities with extended communities (route targets); candidates may think that setting a community via route-map changes the RT, but they are distinct BGP attributes.

How to eliminate wrong answers

Option B is wrong because the route-map sets a standard community, not an extended community, and it does not override the route-target export; the RT is still applied based on the VRF configuration. Option C is wrong because the community format 100:100 is valid for a standard community (AS:NN), and it does not cause a BGP session reset. Option D is wrong because the route-map is applied inbound on routes received from the CE, so it does affect the routes; the community is set on the PE's BGP table, even if it is not sent back to the CE.

714
MCQmedium

A network engineer is configuring OSPFv3 on a router that connects to an IPv6 network. The router must form an adjacency with a neighbor on the same segment, but the engineer notices that the router is not sending any OSPFv3 Hello packets. The interface is up, and IPv6 unicast routing is enabled globally. Which of the following is the most likely cause?

A.The OSPFv3 process is not enabled on the interface.
B.The interface is configured as passive.
C.The OSPFv3 network type is set to point-to-multipoint.
D.The OSPFv3 router ID is not configured.
AnswerA

OSPFv3 requires that the interface be explicitly enabled for OSPFv3 using the 'ipv6 ospf <process-id> area <area-id>' interface configuration command. Without this, the router will not send Hello packets on that interface even if the OSPFv3 process is running. Other options are incorrect because they either do not prevent Hello generation or are not applicable.

Why this answer

For OSPFv3 to operate on an interface, the interface must be explicitly enabled for OSPFv3 using the 'ipv6 ospf' command under interface configuration. Simply enabling IPv6 unicast routing and configuring an OSPFv3 process is not sufficient. Without interface enablement, no Hello packets are sent, and no adjacency can form.

This is a common oversight when transitioning from OSPFv2, where network statements are used.

Exam trap

The trap here is assuming that enabling IPv6 unicast routing and creating an OSPFv3 process automatically enables OSPFv3 on all interfaces, as OSPFv2 does with network statements.

715
MCQmedium

What is the default SNMP trap queue length on Cisco IOS?

A.10
B.100
C.Unlimited
D.5
AnswerA

Cisco IOS caps the SNMP trap queue at 10 traps by default; once full, newly generated traps are discarded until space frees. This default satisfies the question's constraint, which asks specifically for the out-of-the-box queue length rather than a configurable maximum.

Why this answer

The default SNMP trap queue length on Cisco IOS is 10. This value defines the maximum number of SNMP traps that can be queued in the trap buffer before they are sent to the configured SNMP trap receivers. If the queue is full and a new trap is generated, the oldest trap is dropped to make room for the new one.

Exam trap

Cisco often tests the default SNMP trap queue length as a specific numeric value, and the trap here is that candidates confuse it with other default SNMP parameters (like the default SNMP community string or default SNMP version) or assume a larger value like 100 is the default due to common practice in production networks.

How to eliminate wrong answers

Option B (100) is wrong because the default SNMP trap queue length is 10, not 100; 100 is a common value used in some other network devices or configurations but not the Cisco IOS default. Option C (Unlimited) is wrong because the trap queue has a finite default size of 10; an unlimited queue would risk memory exhaustion and is not the default behavior. Option D (5) is wrong because while 5 might seem plausible as a small queue, the actual default is 10, and this value can be modified with the 'snmp-server queue-length' command.

716
MCQeasy

In OSPF, what is the default hello interval on a point-to-point network type?

A.10 seconds
B.30 seconds
C.5 seconds
D.40 seconds
AnswerA

OSPF sends hello packets every 10 seconds on point-to-point and broadcast network types, whereas non-broadcast and point-to-multipoint interfaces use 30 seconds. The 10-second value matches the point-to-point default, with the dead interval at four times that.

Why this answer

In OSPF, the default hello interval on a point-to-point network type is 10 seconds, matching the default for broadcast networks. The dead interval is 4 times the hello interval, so 40 seconds on point-to-point. These timers must match between OSPF neighbors on the same segment for adjacency to form.

Exam trap

The 300-410 exam often tests the confusion between hello and dead intervals — candidates must remember that point-to-point and broadcast default to 10/40 seconds, while NBMA and point-to-multipoint default to 30/120 seconds, and that mismatched timers prevent adjacency formation.

How to eliminate wrong answers

Option B is wrong because 30 seconds is the default hello interval for NBMA (non-broadcast multi-access) and point-to-multipoint network types, not point-to-point. Option C is wrong because 5 seconds is not a standard OSPF default hello interval on any common network type — it may be confused with other protocols or manually configured values. Option D is wrong because 40 seconds is the default dead interval on point-to-point and broadcast networks (4 × hello), not the hello interval itself — candidates often confuse the two timers.

717
MCQmedium

Consider this IP SLA configuration on router R6: ip sla 60 udp-echo 203.0.113.1 2000 source-ip 198.51.100.1 frequency 20 ip sla schedule 60 life forever start-time now What is the purpose of this configuration?

A.It tests UDP connectivity by sending a UDP packet and expecting a response.
B.It tests ICMP echo instead of UDP.
C.It measures jitter and packet loss.
D.It will only work if the destination is a Cisco router.
AnswerA

The udp-echo operation sends a UDP probe to 203.0.113.1 port 2000 from source 198.51.100.1 and measures whether a reply returns, testing round-trip UDP reachability. Frequency 20 and life forever schedule it repeatedly, matching the stem's connectivity-testing purpose.

Why this answer

The configuration sends UDP packets to destination 203.0.113.1 on port 2000, sourced from 198.51.100.1, every 20 seconds. It tests UDP connectivity and response time.

718
MCQhard

A network engineer runs the following command on Router R1: R1# show event manager history events Event History: No. Time Type Name 1 00:01:30 UTC Mar 1 syslog EIGRP_Neighbor_Down 2 00:01:31 UTC Mar 1 syslog OSPF_Neighbor_Flap 3 00:01:32 UTC Mar 1 syslog EIGRP_Neighbor_Down 4 00:01:33 UTC Mar 1 syslog OSPF_Neighbor_Flap Based on this output, what is the most likely problem?

A.The EEM policies are not configured correctly.
B.The router is experiencing network instability causing repeated neighbor state changes.
C.The EEM applet policies are disabled.
D.The syslog server is not reachable.
AnswerB

Repeated EIGRP and OSPF neighbour down and flap events within seconds indicate the routing adjacencies are repeatedly resetting. That pattern reflects underlying network instability, such as link flapping or interface errors, rather than a configuration or authentication fault.

Why this answer

The 'show event manager history events' command shows the last triggered events. The output shows repeated syslog events for EIGRP neighbor down and OSPF neighbor flap within a short timeframe, indicating a flapping condition. The correct answer is that the router is experiencing network instability causing repeated neighbor state changes.

719
MCQhard

A network administrator is configuring MPLS Layer 3 VPN on a Cisco IOS XE router. The router is a PE device connected to two CE routers in different VRFs. The administrator wants to prevent routes from one VRF from being leaked into another VRF. Which configuration step is essential to maintain VRF separation?

A.Configure route targets (RTs) for import and export on each VRF.
B.Enable OSPF as the PE-CE routing protocol and use different process IDs.
C.Assign a unique route distinguisher (RD) to each VRF.
D.Configure BGP neighbor statements with different autonomous system numbers.
AnswerA

Route targets control which routes are imported into and exported from a VRF. By assigning distinct RTs for import and export on each VRF, you ensure that routes from one VRF are not imported into another. This maintains VRF separation. Without proper RT configuration, routes could be leaked between VRFs if RTs are shared.

Why this answer

In MPLS Layer 3 VPN, VRF separation is achieved through the use of route targets (RTs). Each VRF is configured with import and export RTs. When a route is exported from a VRF, it is tagged with the export RT.

The receiving PE imports the route into a VRF only if the route's RT matches the VRF's import RT. Therefore, to prevent leaking, each VRF must have unique RTs that are not shared with other VRFs.

Exam trap

The trap here is confusing the role of the route distinguisher with that of the route target; the RD only makes prefixes unique, while RTs control import/export into VRFs.

720
MCQhard

An engineer is troubleshooting a DMVPN phase 2 deployment with IPv6 over mGRE tunnels. The spoke routers can ping the hub's tunnel IPv6 address, but cannot reach IPv6 networks behind other spokes. The engineer verifies that NHRP is configured and that the hub has a route to the spoke's internal networks. What is the most likely cause?

A.The spoke routers are missing a static route for the remote spoke's internal network pointing to the mGRE tunnel interface.
B.The NHRP authentication key is mismatched between the spokes.
C.The tunnel key is not configured on the mGRE interface.
D.The hub is not configured with 'ip nhrp redirect' and the spokes with 'ip nhrp shortcut'.
AnswerA

Correct because without a route to the remote spoke's network via the tunnel, the spoke will send traffic to the hub, which may not forward it correctly, or the spoke may use a default route that does not use the tunnel.

Why this answer

In a DMVPN Phase 2 deployment, spoke routers must have a route to remote spoke networks pointing to the mGRE tunnel interface. Without this static route, the spoke will not know to send traffic for the remote spoke's internal network over the tunnel, even though NHRP resolves the next-hop. The hub has a route to the spoke's internal networks, but that does not enable direct spoke-to-spoke communication without proper routing on the spokes themselves.

Exam trap

Cisco often tests the distinction between Phase 2 and Phase 3 DMVPN behavior, and the trap here is that candidates assume NHRP alone handles spoke-to-spoke routing, forgetting that a route pointing to the tunnel interface is required in Phase 2 for the spoke to initiate the NHRP resolution process.

How to eliminate wrong answers

Option B is wrong because an NHRP authentication key mismatch between spokes would prevent NHRP registration and resolution, causing the spoke to be unable to ping the hub's tunnel IPv6 address, which is not the case here. Option C is wrong because the tunnel key is used for security and to identify the mGRE tunnel, but its absence would not specifically prevent spoke-to-spoke reachability if NHRP is working and routes are present. Option D is wrong because 'ip nhrp redirect' and 'ip nhrp shortcut' are used in DMVPN Phase 3 to enable dynamic shortcut creation; in Phase 2, spoke-to-spoke traffic is forwarded via the hub by default, and the issue is a missing route, not the absence of redirect/shortcut.

721
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology on Cisco IOS routers. The hub router must dynamically learn spoke-to-spoke routes and allow direct spoke-to-spoke tunnels. Which command must be configured on the hub's tunnel interface to enable Phase 3 behavior?

A.ip nhrp map multicast dynamic
B.ip nhrp network-id 1
C.ip nhrp shortcut
D.ip nhrp redirect
AnswerD

The ip nhrp redirect command on the hub enables NHRP redirect messages, which notify spokes of a better path to another spoke, allowing direct spoke-to-spoke tunnels. This is a key requirement for DMVPN Phase 3. Without it, spokes continue to route through the hub. It works with ip nhrp shortcut on spokes to achieve dynamic spoke-to-spoke connectivity.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to inform spokes about a more optimal path to another spoke, and spokes use NHRP shortcut to install a direct route. The hub must have ip nhrp redirect configured on its tunnel interface. The other options are either spoke-side commands or general NHRP parameters that do not enable Phase 3 behavior.

Exam trap

The trap here is confusing the hub-side redirect command with the spoke-side shortcut command, which are complementary but configured on different routers.

722
MCQmedium

Which IPv6 access-list entry will deny traffic from any source to the destination prefix 2001:db8:1::/48?

A.deny ipv6 any 2001:db8:1::/48
B.deny ipv6 2001:db8:1::/48 any
C.deny ipv6 any host 2001:db8:1::1
D.deny ipv6 2001:db8:1::/48 2001:db8:1::/48
AnswerA

The entry deny ipv6 any 2001:db8:1::/48 uses any as the source and the /48 prefix as destination, matching all traffic destined to that prefix regardless of origin. This precisely satisfies the requirement to deny any source to that destination.

Why this answer

The IPv6 access-list entry 'deny ipv6 any 2001:db8:1::/48' uses the correct syntax: the source is 'any' (all traffic), and the destination is the prefix 2001:db8:1::/48, which matches all addresses within that /48 range. This entry denies traffic from any source to the entire destination prefix, as required by the question.

Exam trap

Cisco often tests the order of source and destination in ACL entries, where candidates mistakenly reverse them (as in Option B) or use a host keyword instead of a prefix (as in Option C), thinking it matches a range.

How to eliminate wrong answers

Option B is wrong because it reverses the source and destination: 'deny ipv6 2001:db8:1::/48 any' denies traffic from the prefix 2001:db8:1::/48 to any destination, which is the opposite of the requirement. Option C is wrong because it uses 'host 2001:db8:1::1', which matches only a single host address, not the entire /48 prefix. Option D is wrong because it specifies the same prefix for both source and destination, denying traffic from 2001:db8:1::/48 to itself, which does not deny traffic from any source to the destination prefix.

723
MCQhard

In BGP, what is the default administrative distance for routes learned from an eBGP peer?

A.20
B.200
C.120
D.110
AnswerA

External BGP routes carry a default administrative distance of 20 in Cisco IOS, making them more trusted than internal BGP (200) and OSPF (110). This value satisfies the stem's requirement for the default distance assigned to routes learned from an eBGP peer, reflecting eBGP's higher preference.

Why this answer

The default administrative distance for eBGP is 20, while iBGP has a default of 200.

724
MCQmedium

A network engineer is configuring a Cisco IOS XE router to send syslog messages to a remote server for security auditing. The engineer wants to ensure that the syslog messages are protected from eavesdropping and tampering. The router already has a CA trustpoint configured. Which command should the engineer use to enable secure syslog?

A.logging host 10.10.10.10 transport tcp port 6514
B.logging host 10.10.10.10 transport tls port 6514
C.logging host 10.10.10.10 transport udp port 514
D.logging host 10.10.10.10 transport tcp port 514
AnswerB

This command enables secure syslog over TLS by specifying the 'tls' transport and port 6514. The router will use the configured CA trustpoint to establish a TLS connection to the syslog server, ensuring confidentiality and integrity of the syslog messages. This meets the requirement for secure syslog.

Why this answer

The requirement is to protect syslog messages from eavesdropping and tampering, which necessitates encryption and integrity protection. Syslog over TLS (often called secure syslog) uses Transport Layer Security to encrypt and authenticate messages. The command 'logging host 10.10.10.10 transport tls port 6514' enables TLS transport, leveraging the existing CA trustpoint for certificate-based authentication.

Other transport methods like UDP or plain TCP do not provide encryption. Therefore, the correct configuration is to use the 'tls' transport option.

Exam trap

The trap here is assuming that specifying port 6514 alone enables TLS, but the transport must be explicitly set to 'tls' to activate encryption.

725
MCQmedium

A network administrator is configuring EIGRP on a router and wants to ensure that only a specific subnet is advertised out of an interface. The router has the following configuration: 'router eigrp 100', 'network 10.0.0.0', 'passive-interface GigabitEthernet0/0'. The administrator wants to advertise 10.1.1.0/24 out of GigabitEthernet0/0 while preventing other subnets from being advertised. Which configuration achieves this?

A.Remove the passive-interface command and configure a distribute-list outbound on GigabitEthernet0/0 to permit only 10.1.1.0/24.
B.Keep the passive-interface command and configure a distribute-list outbound on GigabitEthernet0/0 to permit only 10.1.1.0/24.
C.Remove the passive-interface command and configure a distribute-list inbound on GigabitEthernet0/0 to permit only 10.1.1.0/24.
D.Remove the passive-interface command and configure 'network 10.1.1.0 0.0.0.255' under router EIGRP.
AnswerA

Removing passive-interface allows EIGRP to send and receive Hellos on the interface, forming adjacencies. An outbound distribute-list filters which routes are advertised, permitting only the desired subnet. This combination ensures only 10.1.1.0/24 is advertised out of GigabitEthernet0/0 while other subnets are suppressed.

Why this answer

To advertise a specific subnet out of an interface while suppressing others, the interface must not be passive so that EIGRP can form adjacencies and send updates. Then, an outbound distribute-list can filter the advertised routes, permitting only the desired subnet. This approach gives granular control over which routes are sent out of the interface, meeting the administrator's requirement.

Exam trap

The trap here is confusing inbound and outbound distribute-lists, or forgetting that a passive interface cannot advertise at all.

726
MCQhard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive traffic. The engineer has created a class map named 'CRITICAL' that matches BGP traffic and a policy map named 'COPP-POLICY' that applies a police rate of 1000000 bps with a conform-action transmit and exceed-action drop. After applying the policy map to the control plane, the engineer notices that BGP sessions are flapping. Which action should the engineer take to resolve the issue?

A.Increase the police rate in the policy map to accommodate the BGP traffic.
B.Change the exceed-action to transmit and set a lower conform-action rate.
C.Remove the class map from the policy map and rely on default CoPP settings.
D.Apply the policy map to the data plane interfaces instead of the control plane.
AnswerA

BGP sessions may flap if the police rate is too low and legitimate BGP traffic is being dropped. Increasing the police rate allows more BGP traffic to be transmitted, preventing session flaps. The engineer should monitor the actual BGP traffic rate and adjust the policer accordingly.

Why this answer

The BGP sessions are flapping because the CoPP policer is dropping legitimate BGP traffic due to a rate limit that is too low. Increasing the police rate allows the necessary BGP traffic to pass, stabilizing the sessions. The other options either disable policing, apply it incorrectly, or remove protection, none of which address the root cause.

Exam trap

The trap here is assuming that any BGP flap under CoPP is due to a misconfiguration, but often it is simply an insufficient policer rate for the actual traffic volume.

727
MCQmedium

A network administrator is troubleshooting a DMVPN Phase 3 hub-and-spoke deployment where the hub uses mGRE and spokes use mGRE. Spoke-to-spoke traffic works, but the administrator notices that the spokes are installing host routes for other spokes in their routing tables. Which DMVPN Phase 3 feature is responsible for adding these specific host routes?

A.ip nhrp registration no-unique on the spokes
B.ip nhrp map multicast dynamic on the hub
C.NHRP shortcut on the spokes
D.NHRP redirect on the hub
AnswerC

With NHRP shortcut, the spoke installs a host route for the destination spoke tunnel address after successful NHRP resolution. This route points at the tunnel interface and allows the spoke to send traffic directly to the peer, bypassing the hub. The host routes observed in the routing table are the visible result of NHRP shortcut operation.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to inform a spoke that a better path exists, and the spokes use NHRP shortcut to resolve the destination and install a host route for the peer tunnel address. Those host routes are what let the spoke forward traffic directly to another spoke. Without NHRP shortcut on the spokes, the redirect messages would not result in usable direct paths.

Exam trap

The trap here is confusing the hub-side redirect trigger with the spoke-side shortcut that actually installs the host route in the routing table.

728
MCQmedium

In BGP, what is the effect of using a route-map with a set community command but without the additive keyword?

A.The specified community is added to the existing communities.
B.The existing communities are overwritten by the specified community.
C.The community attribute is not modified; the set command is ignored.
D.The route is denied if it already has communities.
AnswerB

Without the additive keyword, the set community command replaces the entire community attribute, discarding any communities already attached to the prefix. This satisfies the stem's scenario by overwriting existing values with only those specified, rather than appending them.

Why this answer

When set community is used without the additive keyword, it replaces any existing community attributes on the route with the specified community. With the additive keyword, the specified community is added to the existing communities.

729
MCQhard

R1 and R2 are eBGP peers. R1 advertises a summary route 10.0.0.0/8 via aggregate-address 10.0.0.0 255.0.0.0 summary-only. R2 receives the summary but also expects to receive more specific routes (e.g., 10.1.0.0/16) for traffic engineering. R2's BGP table shows only the summary, and the more specific routes are missing. R1's configuration includes: router bgp 65001, network 10.1.0.0 mask 255.255.0.0, and aggregate-address 10.0.0.0 255.0.0.0 summary-only. What is the root cause?

A.The summary-only keyword suppresses all more specific routes, including the network 10.1.0.0/16, from being advertised to R2.
B.The network 10.1.0.0/16 is not in the routing table of R1, so it cannot be advertised.
C.R2 must have a route-map to accept the more specific route.
D.The aggregate-address should be configured with the as-set keyword to include more specifics.
AnswerA

The summary-only keyword on aggregate-address suppresses advertisement of all component routes, so 10.1.0.0/16 is filtered from R2's BGP updates. Removing summary-only, or using suppress-map or unsuppress-map, restores the more specific prefixes required for traffic engineering.

Why this answer

The aggregate-address command with the summary-only keyword advertises only the aggregate 10.0.0.0/8 to BGP peers and suppresses all more-specific component routes (such as 10.1.0.0/16) from being advertised. This is the documented behavior of summary-only in Cisco IOS: it creates the aggregate and filters the contributing routes from outbound updates. Removing summary-only (or using suppress-map/as-set) would allow the more specifics to be advertised alongside the summary.

Exam trap

The trap here is confusing the as-set keyword (which affects AS_PATH loop prevention) with the summary-only keyword (which controls suppression of more-specific routes) — candidates often pick as-set thinking it 'includes' the more specifics.

How to eliminate wrong answers

Option B is wrong because the network 10.1.0.0/16 statement in R1's BGP config implies the route exists in R1's routing table (network statements only advertise prefixes already present in the IGP/RIB), so the more specific is present locally — it is being suppressed, not missing. Option C is wrong because R2 does not need a route-map to accept more specifics; the issue is on R1's outbound advertisement, not R2's inbound policy, and no filtering is shown on R2. Option D is wrong because as-set controls AS_PATH attribute construction for the aggregate (adding the AS numbers of contributing routes to prevent loops) — it does not unsuppress the more-specific routes; only removing summary-only or using a suppress-map does that.

730
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip sla statistics IPSLAs Latest Operation Statistics IPSLA operation id: 1 Type of operation: icmp-echo Latest RTT: 20 milliseconds Latest operation start time: 12:00:00 UTC Mon Mar 1 2021 Latest operation return code: OK Number of successes: 100 Number of failures: 0 Based on this output, which statement is correct?

A.The IP SLA probe is successfully reaching the target with no failures.
B.The IP SLA probe has failed 100 times.
C.The IP SLA probe is using UDP jitter.
D.The IP SLA probe is not configured because the operation ID is 1.
AnswerA

The return code OK, 100 successes and zero failures confirm the icmp-echo probe reaches its target successfully. Latest RTT of 20 milliseconds shows reachability with measurable latency, directly satisfying the scenario's requirement to verify probe success.

Why this answer

The output shows 100 successes and 0 failures for the ICMP echo operation, with a latest return code of OK, confirming that the IP SLA probe is successfully reaching the target without any failures. The 'Number of successes: 100' and 'Number of failures: 0' directly indicate a 100% success rate for the probe.

Exam trap

Cisco often tests the ability to interpret the 'Number of successes' and 'Number of failures' fields correctly, where candidates may mistakenly associate the count with failures instead of successes, or confuse the operation type (ICMP echo vs. UDP jitter) based on the operation ID alone.

How to eliminate wrong answers

Option B is wrong because the output shows 100 successes, not 100 failures; the 'Number of failures: 0' explicitly contradicts this claim. Option C is wrong because the 'Type of operation: icmp-echo' clearly indicates ICMP echo, not UDP jitter, which would require a different operation type (e.g., 'udp-jitter'). Option D is wrong because operation ID 1 is present and has statistics, meaning the IP SLA probe is configured and active; an unconfigured operation would not display any statistics.

731
MCQeasy

Which default administrative distance is assigned to a directly connected interface route?

A.0
B.1
C.5
D.110
AnswerA

A directly connected interface route carries a default administrative distance of 0, the lowest value Cisco assigns. This reflects its status as the most trustworthy source: the router knows the destination is reachable on a locally attached link, so no competing route from another protocol should ever override it.

Why this answer

Directly connected routes have a default administrative distance of 0, indicating the highest preference.

732
MCQmedium

A network engineer runs the following command to troubleshoot Control Plane Policing (CoPP): R1# show policy-map control-plane input class class-default Class-map: class-default (match-any) 140091 packets, 12345678 bytes 5 minute offered rate 1000 bps, drop rate 0 bps Match: any police: cir 8000 bps, bc 1500 bytes conformed 140091 packets, 12345678 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop What does this output indicate?

A.CoPP is dropping all traffic to the control plane.
B.CoPP is rate-limiting traffic to 8000 bps and not dropping any packets.
C.CoPP is not configured; the class-default shows no action.
D.CoPP is dropping packets due to exceeding the rate.
AnswerB

The police statement shows a committed information rate of 8000 bps with zero exceeded and zero violated packets, meaning all 140091 packets conformed and were transmitted. CoPP is rate-limiting to 8000 bps without dropping traffic.

Why this answer

The output shows that the class-default policy-map for control-plane input has a police statement with a CIR of 8000 bps. The counters indicate 140,091 packets conformed and transmitted, with zero packets exceeded or violated. Since the drop rate is 0 bps and no packets have been dropped, CoPP is rate-limiting traffic to 8000 bps without any drops occurring.

Exam trap

Cisco often tests the misconception that a police statement with a CIR automatically means packets are being dropped, but the actual drop counters must be checked to confirm drops are occurring.

How to eliminate wrong answers

Option A is wrong because the output shows zero dropped packets (exceeded and violated counters are 0), so CoPP is not dropping all traffic. Option C is wrong because the class-default clearly shows a police action with a CIR of 8000 bps and transmit/drop actions, indicating CoPP is configured. Option D is wrong because the exceeded and violated packet counts are 0, meaning no packets have exceeded the configured rate and no drops have occurred.

733
MCQmedium

A network engineer is configuring a Cisco IOS router to act as a DHCP relay agent. The router interface GigabitEthernet0/0 is connected to a subnet with DHCP clients, and the DHCP server is located at 192.168.100.10. Which command must be applied to the interface to forward DHCP requests to the server?

A.ip dhcp relay information option
B.ip dhcp pool RELAY_POOL
C.ip forward-protocol udp 67
D.ip helper-address 192.168.100.10
AnswerD

The 'ip helper-address' command configures the interface to forward UDP broadcasts, including DHCP requests, to the specified server address. It is the standard method for DHCP relay. When applied to the client-facing interface, the router will relay DHCP Discover messages to the server, allowing clients on that subnet to obtain addresses.

Why this answer

The 'ip helper-address' command on the client-facing interface is required to relay DHCP requests to a remote server. It forwards UDP broadcasts (including DHCP) to the specified IP address. Other commands either modify relay behavior or are for server configuration.

This command is the fundamental step for DHCP relay.

Exam trap

The trap here is thinking that enabling option 82 or specifying UDP forwarding alone is sufficient, but the 'ip helper-address' command is what actually forwards the requests.

734
Drag & Dropmedium

Drag and drop the steps to verify and validate route redistribution operational state into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Verification of redistribution starts with checking the routing table for redistributed routes, then examining the specific protocol database, followed by verifying the redistribution configuration, then checking for administrative distance issues, and finally using traceroute to validate the path. This order confirms routes are present, correctly sourced, and reachable.

735
Drag & Dropmedium

Drag and drop the steps to configure an ERSPAN session for remote traffic capture into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, you must define the source interface and traffic direction. Next, specify the ERSPAN ID and destination IP address. Then, configure the ERSPAN origin IP address on the source switch.

After that, enable the ERSPAN session globally. Finally, verify the session is active.

736
MCQhard

An engineer applies an IPv6 ACL to filter traffic between two VLANs on a switch using a router-on-a-stick configuration. The ACL is applied inbound on the subinterface. Traffic from VLAN 10 to VLAN 20 is permitted, but return traffic from VLAN 20 to VLAN 10 is dropped. Which is the most likely explanation?

A.The ACL is applied only on the VLAN 10 subinterface, so return traffic from VLAN 20 is not filtered but the ACL on VLAN 10 drops it because the source address matches a deny entry.
B.The ACL on the VLAN 20 subinterface is missing a permit entry for the return traffic, or the ACL is applied outbound on VLAN 10, which does not affect incoming return traffic.
C.The router has 'ipv6 unicast-routing' disabled, preventing inter-VLAN routing.
D.The ACL uses 'deny ipv6 any any' which blocks all traffic, but the permit statement for VLAN 10 to VLAN 20 is placed after the deny, causing it to be ignored.
AnswerB

This is correct: the failure is caused by asymmetric IPv6 ACL application. Forward traffic from VLAN 10 to VLAN 20 is permitted by the ACL on VLAN 10, but return traffic from VLAN 20 is either dropped by an inbound ACL on VLAN 20 that lacks a permit for that flow, or never checked because the only filter is outbound on VLAN 10, which cannot inspect the packet as it arrives on VLAN 20. To fix it, add an explicit permit for the return direction on the VLAN 20 inbound ACL or an outbound permit on VLAN 10.

Why this answer

In a router-on-a-stick configuration, traffic from VLAN 10 to VLAN 20 is permitted by the inbound ACL on the VLAN 10 subinterface. However, return traffic from VLAN 20 to VLAN 10 must traverse the VLAN 20 subinterface inbound (or the VLAN 10 subinterface outbound). If the ACL is applied inbound only on the VLAN 10 subinterface, return traffic from VLAN 20 is not inspected unless an ACL is also applied inbound on the VLAN 20 subinterface or outbound on the VLAN 10 subinterface.

The most likely cause is that the ACL on the VLAN 20 subinterface is missing a permit entry for the return traffic, or the ACL is applied outbound on VLAN 10, which does not affect incoming return traffic.

Exam trap

Cisco often tests the misconception that an ACL applied inbound on one subinterface controls all traffic between VLANs, when in fact it only filters traffic entering that specific subinterface, and return traffic must be permitted by an ACL on the opposite subinterface or by an outbound ACL.

How to eliminate wrong answers

Option A is wrong because if the ACL is applied only inbound on the VLAN 10 subinterface, return traffic from VLAN 20 to VLAN 10 would not be filtered by that ACL (since it enters via the VLAN 20 subinterface); the ACL on VLAN 10 would only filter traffic entering VLAN 10, not traffic leaving VLAN 10. Option C is wrong because if 'ipv6 unicast-routing' were disabled, no inter-VLAN routing would occur at all, but the scenario states that traffic from VLAN 10 to VLAN 20 is permitted, proving routing is functional. Option D is wrong because a 'deny ipv6 any any' placed after a permit statement would not block traffic that matches the permit; Cisco ACLs process entries sequentially and stop at the first match, so the permit would be applied before reaching the deny.

737
Multi-Selecthard

Which TWO statements about MPLS label stack operations in a Layer 3 VPN (L3VPN) are true? (Choose TWO.)

Select 2 answers
A.A P router (core router) performs label swapping only on the top label in the label stack.
B.The ingress PE router imposes two labels: an outer LDP label and an inner VPN label.
C.The P router pops the inner VPN label before forwarding the packet to the egress PE.
D.The egress PE router swaps the VPN label with a new label before forwarding to the CE.
E.The P router uses the inner VPN label to make forwarding decisions.
AnswersA, B

P routers forward solely on the top label, swapping it per the LFIB and leaving inner labels untouched. The inner VPN label is only examined by the egress PE, so core forwarding stays label-stack agnostic.

Why this answer

Option A is correct because a P (provider core) router in an MPLS L3VPN only processes the top label of the stack for its label-switching (LFIB) lookup, performing a swap operation on that outer label without examining the inner VPN label. Option B is correct because the ingress PE router imposes a two-label stack: the outer label is distributed by LDP (or RSVP-TE) for transport across the provider core, and the inner label is the VPN label (typically MP-BGP/VRF label) that identifies the destination VRF at the egress PE. Option C is incorrect because the penultimate P router (PHP) or the egress PE pops the outer transport label, not the inner VPN label; the VPN label is removed only at the egress PE after VRF lookup.

Option D is incorrect because the egress PE removes the VPN label and performs an IP lookup in the VRF table before forwarding the packet to the CE; it does not swap the VPN label for a new label. Option E is incorrect because P routers forward based solely on the top (outer) label and never inspect the inner VPN label, which is only meaningful to the egress PE.

Exam trap

The trap is confusing the roles of the P router and the egress PE, and thinking that P routers process the inner VPN label or that the egress PE swaps labels instead of popping.

738
MCQhard

A network engineer runs the following command to verify OSPF database on a DMVPN hub: R1# show ip ospf database router 2.2.2.2 OSPF Router with ID (1.1.1.1) (Process ID 1) Router Link States (Area 0) LS age: 100 Options: (No TOS-capability, DC) LS Type: Router Links Link State ID: 2.2.2.2 Advertising Router: 2.2.2.2 LS Seq Number: 80000001 Checksum: 0x1234 Length: 48 Number of Links: 1 Link connected to: a Transit Network (Link ID) Designated Router address: 10.0.0.1 (Link Data) Router Interface address: 10.0.0.2 Number of MTID metrics: 0 TOS 0 Metrics: 10 What does this output indicate?

A.The router 2.2.2.2 is advertising a stub network via Tunnel0.
B.The router 2.2.2.2 is connected to the DR at 10.0.0.1 over the DMVPN tunnel with cost 10.
C.The router 2.2.2.2 is the DR for the DMVPN network.
D.The OSPF database is empty; no LSAs have been received.
AnswerB

The Router LSA shows a single link to a Transit Network, with the DR at 10.0.0.1 and the advertising router's interface address 10.0.0.2, carrying TOS 0 metric 10. This confirms 2.2.2.2 reaches the DR across the DMVPN tunnel at cost 10.

Why this answer

The output shows a Router LSA (Type 1) for router 2.2.2.2 with one link: a transit network whose Designated Router is 10.0.0.1 and whose local interface address is 10.0.0.2, with a TOS 0 metric (cost) of 10. This indicates 2.2.2.2 is attached to a multi-access transit network (the DMVPN tunnel) via 10.0.0.2, with the DR at 10.0.0.1, and the link cost is 10.

Exam trap

The trap is misreading the Link ID as the router's own address rather than the DR's address — candidates must remember that on transit network links, the Link ID field carries the DR's interface IP, not the advertising router's.

How to eliminate wrong answers

Option A is wrong because a stub network link would show 'Link connected to: a Stub Network' with a network/subnet mask as the Link ID, not a transit network with a DR address. Option C is wrong because the DR is 10.0.0.1, not 2.2.2.2 — 2.2.2.2 is the advertising router and a DROther on that segment. Option D is wrong because the output clearly shows a populated Router LSA with LS age, sequence number, checksum, and link details — the database is not empty.

739
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate administrative SSH logins against an external TACACS+ server. The engineer wants to ensure that if the TACACS+ server becomes unreachable, a locally configured fallback account can still be used. The TACACS+ server IP is 10.1.1.100 and the shared key is 'Cisco123'. Which configuration snippet correctly implements this requirement?

A.aaa new-model aaa authentication login default group tacacs+ tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123
B.aaa new-model aaa authentication login default group tacacs+ local tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123
C.aaa new-model aaa authentication login default group tacacs+ local tacacs-server host 10.1.1.100 key Cisco123
D.aaa new-model aaa authentication login default local group tacacs+ tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123
AnswerB

This configuration enables AAA with 'aaa new-model', sets the default login authentication method list to try TACACS+ first and then fall back to the local user database, and defines the TACACS+ server with its IP and key. The 'local' keyword ensures that if the TACACS+ server is unreachable, the router will use local authentication, meeting the requirement.

Why this answer

The correct configuration enables AAA, defines a TACACS+ server, and sets the default login authentication method list to 'group tacacs+ local'. This ensures that the router first attempts to authenticate against the TACACS+ server and, if that server is unreachable, falls back to the local user database. The other options either omit the fallback, use deprecated commands, or reverse the authentication order.

Exam trap

The trap here is assuming that simply enabling AAA and configuring a TACACS+ server automatically provides local fallback, when the method list must explicitly include 'local' as a secondary method.

740
MCQeasy

A network engineer is configuring a GRE tunnel between two Cisco routers. The tunnel source is a physical interface, and the tunnel destination is a loopback interface on the remote router. The engineer notices that the tunnel interface is up, but line protocol is down. What is the most likely cause?

A.The tunnel key is mismatched.
B.The tunnel destination is not reachable.
C.The tunnel mode is set to GRE multipoint.
D.The tunnel source and destination are reversed.
AnswerB

For a GRE tunnel to come up, the tunnel destination must be reachable via the underlay network. If the destination is not reachable, the tunnel interface will show up, but line protocol will be down. The engineer should verify routing to the tunnel destination and ensure that the loopback interface is advertised and reachable. This is a common issue when the underlay routing is misconfigured.

Why this answer

A GRE tunnel interface will show up/up only if the tunnel source is valid and the tunnel destination is reachable. If the destination is unreachable, the interface remains up but the line protocol goes down. The fix is to ensure that the underlay network has a route to the tunnel destination, often by advertising the loopback interface into the routing protocol or configuring a static route.

Exam trap

The trap here is assuming that a mismatched tunnel key or reversed endpoints cause the line protocol to drop, when in fact reachability of the tunnel destination is the key factor.

741
MCQmedium

Which MPLS label is used for the Router Alert function, and what is its purpose?

A.Label 1; used to alert the router to examine the packet in the control plane.
B.Label 0; used to alert the router to examine the packet.
C.Label 2; used to alert the router to examine the packet.
D.Label 3; used to alert the router to examine the packet.
AnswerA

Label 1 is the Router Alert label per RFC 3032.

Why this answer

MPLS label 1 is reserved for the Router Alert Label. When a packet carries this label, it indicates that the router should examine the packet in the control plane, typically for protocols like RSVP-TE or LDP that require hop-by-hop processing. This is defined in RFC 3032.

Exam trap

The trap is confusing the reserved MPLS labels, especially label 1 with label 0 or 3, which have different purposes.

How to eliminate wrong answers

Option B is wrong because label 0 is the IPv4 Explicit NULL label, used to preserve QoS markings. Option C is wrong because label 2 is the IPv6 Explicit NULL label. Option D is wrong because label 3 is the Implicit NULL label, used for penultimate hop popping.

742
MCQmedium

A network engineer runs the following command to troubleshoot an EEM issue: R1# show event manager history events Event History: Event Type : syslog Time : Mar 1 00:05:23 Pattern : OSPF-5-ADJCHG Trigger count : 1 Event Type : timer Time : Mar 1 00:06:00 Timer Type : absolute Timer Name : MY-TIMER Trigger count : 1 What does this output indicate?

A.Two events have triggered EEM applets: a syslog event matching 'OSPF-5-ADJCHG' and an absolute timer named 'MY-TIMER'.
B.Two EEM applets are currently registered: one for syslog and one for timer.
C.The OSPF-5-ADJCHG syslog event triggered an applet that executed a timer.
D.The timer event is a countdown timer that triggered after 5 minutes and 23 seconds.
AnswerA

The history output lists two triggered events: a syslog event matching the OSPF-5-ADJCHG pattern and an absolute timer named MY-TIMER, each with a trigger count of one. This directly satisfies the stem's request to interpret the displayed event history.

Why this answer

The output shows the event history for EEM. It lists events that have triggered EEM applets. Each entry shows the event type (syslog, timer, etc.), the time it occurred, specific details (pattern for syslog, timer type and name for timer), and the number of times that event triggered an applet.

This helps in troubleshooting which events are being matched.

743
MCQeasy

What is the default administrative distance for OSPFv3 internal routes?

A.90
B.110
C.115
D.120
AnswerB

OSPFv3 internal routes carry a default administrative distance of 110, matching OSPFv2's value for the same protocol family. Cisco assigns this distance so OSPFv3 routes are preferred over IS-IS (115) and RIP (120), but less trusted than EIGRP (90) and static routes (1).

Why this answer

OSPFv3, like OSPFv2, uses a default administrative distance of 110 for all internal routes (intra-area and inter-area). This value is hard-coded in Cisco IOS and is not configurable per-route type; it distinguishes OSPF routes from other routing protocols. Option B is correct because 110 is the standard AD for OSPF (both versions) internal routes.

Exam trap

Cisco often tests the misconception that OSPFv3 might have a different administrative distance than OSPFv2, or that the AD changes for IPv6 protocols, but in reality, the default AD values are identical for both IPv4 and IPv6 versions of the same protocol.

How to eliminate wrong answers

Option A is wrong because 90 is the default administrative distance for EIGRP (both IPv4 and IPv6), not OSPFv3. Option C is wrong because 115 is not a default AD for any common routing protocol; it is sometimes used for IS-IS level-2 routes in certain implementations but not for OSPFv3. Option D is wrong because 120 is the default administrative distance for RIP (both RIPv2 and RIPng), not OSPFv3.

744
MCQhard

A network administrator is deploying DMVPN Phase 3 with IKEv2 IPsec protection. The hub router is configured with a multipoint GRE tunnel interface and NHRP. Spoke routers register with the hub and can communicate directly with each other. The administrator wants to ensure that spoke-to-spoke traffic is encrypted. Which statement about the IPsec configuration is true?

A.IPsec must be configured on the physical interfaces of the spokes.
B.A single IPsec profile on the hub and spokes can protect both hub-to-spoke and spoke-to-spoke traffic.
C.IPsec encryption for spoke-to-spoke traffic requires a separate IPsec profile on each spoke.
D.Spoke-to-spoke traffic bypasses IPsec encryption because it does not traverse the hub.
AnswerB

In DMVPN Phase 3, a single IPsec profile applied to the tunnel interface on all routers can secure both hub-to-spoke and spoke-to-spoke traffic. The dynamic multipoint tunnels are established on demand, and the same IPsec profile is used because the tunnel interface is the encryption endpoint. This simplifies configuration and is a key advantage of DMVPN with IPsec.

Why this answer

In DMVPN Phase 3, the same IPsec profile applied to the multipoint GRE tunnel interface on all routers (hub and spokes) protects all traffic, including spoke-to-spoke. When a spoke initiates a direct tunnel to another spoke, the IPsec session is established using the same profile. This uniform configuration is a primary benefit of DMVPN, allowing scalable and secure any-to-any connectivity.

Exam trap

The trap here is thinking that spoke-to-spoke traffic, because it bypasses the hub, also bypasses IPsec encryption, when in fact the encryption is applied at the tunnel interface on each spoke.

745
MCQmedium

Consider the following DHCPv6 configuration on router R2: ipv6 dhcp pool DHCP6_POOL dns-server 2001:db8::1 domain-name example.com ! interface GigabitEthernet0/0 ipv6 address 2001:db8:1::1/64 ipv6 dhcp server DHCP6_POOL ipv6 nd other-config-flag no shutdown What is the effect of this configuration?

A.Hosts on this subnet will use SLAAC to obtain their IPv6 address and then use DHCPv6 to get DNS and domain information.
B.Hosts will obtain both their IPv6 address and DNS information from the DHCPv6 pool.
C.The DHCPv6 pool is missing the address prefix, so it will not provide any configuration to clients.
D.The ipv6 nd other-config-flag command is ignored because the DHCPv6 server is configured on the interface.
AnswerA

The `ipv6 nd other-config-flag` setting instructs hosts to use stateless address autoconfiguration for their IPv6 address, while the DHCPv6 pool supplies only DNS server and domain-name details. This satisfies the stem's requirement that address assignment remains SLAAC-based, with DHCPv6 restricted to other configuration parameters.

Why this answer

The configuration uses the `ipv6 nd other-config-flag` command, which sets the 'Other Configuration' flag (O-flag) in Router Advertisement (RA) messages. This tells hosts to use Stateless Address Autoconfiguration (SLAAC) for their IPv6 address (based on the prefix in the RA) and then use DHCPv6 (stateless DHCPv6) only to obtain additional parameters like DNS server and domain name, as defined in the DHCPv6 pool.

Exam trap

Cisco often tests the distinction between the M-flag (stateful DHCPv6) and O-flag (stateless DHCPv6), and the trap here is that candidates confuse the `other-config-flag` with the `managed-config-flag`, leading them to incorrectly think DHCPv6 provides addresses when it only provides other parameters.

How to eliminate wrong answers

Option B is wrong because it describes stateful DHCPv6, where both the IPv6 address and other parameters are obtained from the DHCPv6 server; however, the `ipv6 nd other-config-flag` (O-flag) explicitly instructs hosts to use SLAAC for addressing, not DHCPv6 for addresses. Option C is wrong because a DHCPv6 pool does not require an `address prefix` for stateless DHCPv6; the pool only needs to provide options like DNS and domain name, and the prefix for SLAAC is advertised via Router Advertisements. Option D is wrong because the `ipv6 nd other-config-flag` command is not ignored; it is fully functional and works in conjunction with the DHCPv6 server configuration to signal stateless DHCPv6 to clients.

746
MCQmedium

A network engineer is configuring EIGRP for IPv6 on a Cisco IOS XE router. The router has two interfaces: GigabitEthernet0/0 (2001:DB8:1::1/64) and GigabitEthernet0/1 (2001:DB8:2::1/64). The engineer wants to enable EIGRP for IPv6 on both interfaces and ensure that the router forms adjacencies. Which configuration is required?

A.Enable IPv6 unicast routing globally, configure an EIGRP for IPv6 routing process, and use the network command under the routing process to advertise the interfaces.
B.Enable IPv6 unicast routing globally, create an EIGRP for IPv6 routing process, and enable EIGRP on each interface with the ipv6 eigrp command.
C.Enable IPv6 unicast routing globally, configure EIGRP for IPv6 with the no shutdown command under the routing process, and assign IPv6 addresses to interfaces.
D.Enable IPv6 unicast routing globally, configure EIGRP for IPv6, and enable EIGRP on interfaces using the ipv6 router eigrp command under each interface.
AnswerB

EIGRP for IPv6 requires IPv6 unicast routing to be enabled globally. The routing process is created with ipv6 router eigrp AS number, and then EIGRP must be enabled on each interface using ipv6 eigrp AS number. This allows the interfaces to participate in EIGRP for IPv6 and form adjacencies with neighbors.

Why this answer

EIGRP for IPv6 requires IPv6 unicast routing to be enabled globally, creation of an EIGRP for IPv6 routing process, and explicit enabling of EIGRP on each interface using the ipv6 eigrp command. Unlike IPv4 EIGRP, there is no network command; interfaces must be enabled individually. This ensures the router can form adjacencies and exchange IPv6 routing information.

Exam trap

The trap here is assuming EIGRP for IPv6 uses the network command like IPv4 EIGRP; it does not, and interfaces must be enabled individually.

747
MCQmedium

A network engineer is implementing MPLS Layer 3 VPN on a Cisco IOS XE router. The engineer wants to ensure that customer routes are advertised with the correct route distinguisher (RD) and route target (RT) extended communities. Which BGP address family must be configured to exchange VPNv4 routes between PE routers?

A.address-family ipv4 vrf CUSTOMER
B.address-family ipv4 multicast
C.address-family ipv4 unicast
D.address-family vpnv4 unicast
AnswerD

The address-family vpnv4 unicast is used on PE routers to exchange VPNv4 routes with other PE routers. It carries the RD and RT extended communities along with the customer prefixes. This address family must be activated on the PE-PE BGP session to propagate MPLS VPN routing information. Without it, VPNv4 routes are not exchanged, and MPLS VPN connectivity fails.

Why this answer

MPLS Layer 3 VPN uses BGP VPNv4 address family to exchange customer routes between PE routers. The VPNv4 address family carries the RD and RT extended communities that identify the VPN and control import/export. It must be activated on the PE-PE BGP session.

The VRF address family is used for PE-CE routing and for assigning RDs and RTs, but not for exchanging VPNv4 routes.

Exam trap

The trap here is confusing the VRF address family, used for PE-CE routing, with the VPNv4 address family, used for PE-PE route exchange.

748
MCQmedium

A network engineer runs the following command on Router P1: P1# show mpls ldp neighbor Peer LDP Ident: 10.0.0.2:0, Local LDP Ident: 10.0.0.1:0 TCP connection: 10.0.0.2.646 - 10.0.0.1.48632 State: Oper, Msgs sent/rcvd: 120/118, Downstream Up time: 00:12:34 LDP discovery sources: GigabitEthernet0/0, Src IP addr: 10.1.1.2 Addresses bound to peer LDP Ident: 10.0.0.2 192.168.1.1 Based on this output, which statement is correct?

A.The LDP session is down.
B.The LDP session is up and functioning correctly.
C.The router is not receiving label bindings from the neighbor.
D.The LDP router ID is misconfigured.
AnswerB

The session shows State: Oper with 120 messages sent and 118 received, confirming the TCP connection is established and label advertisements are flowing. Oper state with incrementing message counters indicates the LDP session between the peers is up and functioning.

Why this answer

The output shows 'State: Oper', which indicates the LDP session is in the Operational state — the normal, fully-established state for an LDP session. The TCP connection is present (10.0.0.2.646 - 10.0.0.1.48632), messages are being exchanged (120 sent / 118 received), and the uptime of 00:12:34 confirms the session has been stable. All of these indicators confirm the LDP session is up and functioning correctly.

Exam trap

The trap here is that candidates see 'Downstream' and assume it means the session is down, when it actually refers to the direction of label binding advertisement (downstream label distribution).

How to eliminate wrong answers

Option A is wrong because 'State: Oper' means the session is operational, not down — a down session would show 'State: Non-existent' or no peer entry at all. Option C is wrong because the presence of an active TCP connection with 120/118 messages exchanged and the 'Downstream' designation confirms label bindings are being received from the peer. Option D is wrong because the LDP router ID (10.0.0.2:0) is a valid, properly formatted LDP identifier derived from a loopback or highest IP, and there is no indication of misconfiguration.

749
MCQmedium

A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue: R1# show ip access-lists 130 Extended IP access list 130 10 deny ip host 10.1.1.1 host 10.2.2.2 20 permit ip any any Then the engineer runs: R1# debug ip packet 130 IP packet debugging is on for access list 130 *Mar 1 00:20:10.123: IP: s=10.1.1.1 (GigabitEthernet0/0), d=10.2.2.2, len 100, proto ICMP, access list 130: matched line 10 deny ip host 10.1.1.1 host 10.2.2.2 What does this output indicate?

A.ICMP traffic from 10.1.1.1 to 10.2.2.2 is being denied by ACL 130.
B.ICMP traffic from 10.1.1.1 to 10.2.2.2 is being permitted by ACL 130.
C.ACL 130 is applied outbound on GigabitEthernet0/0.
D.ACL 130 is not matching any packets.
AnswerA

The debug output shows the packet matched line 10, which denies IP traffic from host 10.1.1.1 to host 10.2.2.2. Because the protocol is ICMP and the source and destination match the deny statement, that ICMP traffic is being dropped.

Why this answer

The debug output explicitly shows that the packet with source 10.1.1.1 and destination 10.2.2.2 matched line 10 of ACL 130, which is a deny statement. Since the ACL is evaluated sequentially and the first match is a deny, the ICMP traffic is denied. The debug message confirms the match, so option A is correct.

Exam trap

Cisco often tests the misconception that a debug message showing a packet matched an ACL line implies the packet was permitted, when in fact the action (deny or permit) is determined by the matched line's action.

How to eliminate wrong answers

Option B is wrong because the debug output shows the packet matched line 10 (deny), not line 20 (permit), so the traffic is denied, not permitted. Option C is wrong because the debug output does not indicate the direction (inbound or outbound) of the ACL application; the interface shown (GigabitEthernet0/0) is the source interface of the packet, not where the ACL is applied. Option D is wrong because the debug output explicitly states 'matched line 10', proving that ACL 130 is matching packets.

750
MCQhard

A network engineer is troubleshooting an MPLS L3 VPN where OSPF is used as the PE-CE routing protocol. The customer reports that routes from one site are not being learned at another site. The engineer checks the PE routers and finds that the OSPF routes are present in the VRF routing table but not in the MP-BGP table. What is the most likely cause?

A.The route target configuration is incorrect.
B.The OSPF process is not configured with the correct VRF.
C.The OSPF routes are not being redistributed into BGP.
D.The BGP router ID is not unique.
AnswerC

For OSPF routes from a VRF to be advertised across the MPLS VPN to other PEs, they must be redistributed into MP-BGP. If redistribution is not configured, the routes remain only in the VRF routing table and are not exported as VPNv4 routes. This is the most likely cause when routes are present in the VRF but missing from MP-BGP.

Why this answer

When OSPF routes are present in the VRF routing table but not in MP-BGP, the most likely cause is that redistribution from OSPF into BGP is not configured. MP-BGP only advertises routes that are explicitly redistributed or network statements are used. Without redistribution, the routes remain local to the VRF and are not propagated as VPNv4 routes.

Other issues like route target or VRF configuration would manifest differently.

Exam trap

The trap here is assuming a route target or VRF misconfiguration when the routes are missing from MP-BGP; the first step is to check redistribution into BGP.

Page 9

Page 10 of 19

Page 11