Courseiva

Cisco CCNP ENARSI 300-410 (300-410) — Questions 751–825

1401 questions total · 19pages · All types, answers revealed

Page 10

Page 11 of 19

Page 12
751
MCQeasy

A network engineer runs the following command to troubleshoot a Policy-Based Routing (PBR) issue: R1# show ip local policy Interface Route-map local PBR-LOCAL What does this output indicate?

A.Local PBR is enabled for packets originated by the router.
B.PBR is applied to all incoming interfaces.
C.The route-map PBR-LOCAL is not configured.
D.PBR is applied to all outgoing interfaces.
AnswerA

The 'show ip local policy' command displays the route map applied to locally generated traffic. The output confirms local PBR is active, meaning packets originated by the router itself are policy-routed, not transit traffic passing through interfaces.

Why this answer

The 'show ip local policy' command specifically displays the route-map applied to locally generated traffic (packets originated by the router itself, such as pings, SNMP, syslog, or management traffic). The output shows 'local' in the Interface column with route-map PBR-LOCAL, confirming that Local PBR is active and will be evaluated against any packets the router sources. This is distinct from interface PBR, which is applied with 'ip policy route-map' under an interface and affects transit traffic.

Exam trap

The trap here is confusing 'show ip local policy' (router-originated traffic) with 'show ip policy' (interface-applied PBR), causing candidates to assume the output describes interface-level PBR.

How to eliminate wrong answers

Option B is wrong because PBR applied to incoming interfaces is configured with 'ip policy route-map <name>' under each interface and verified with 'show ip policy' (which lists interfaces), not 'show ip local policy'. Option C is wrong because the command output explicitly shows the route-map name PBR-LOCAL bound to the local policy — if the route-map were missing, the binding would not appear. Option D is wrong because PBR is inherently an inbound/input policy mechanism on Cisco IOS; there is no 'outgoing interface' PBR application, and the output's 'local' keyword refers to router-originated traffic, not egress interfaces.

752
MCQhard

A network engineer is configuring MPLS Layer 3 VPN on a Cisco IOS XE router. The engineer wants to enable the router to distribute VPNv4 prefixes to its PE peers. Which command must be configured under the BGP routing process to enable the address family?

A.address-family ipv4 vrf
B.address-family ipv4 unicast
C.address-family vpnv6
D.address-family vpnv4
AnswerD

The address-family vpnv4 command enters the VPNv4 address family configuration mode. Within this mode, the engineer can activate neighbors and configure other VPNv4-specific parameters. Without this, the router cannot exchange VPNv4 prefixes with other PE routers. This is the correct command to enable the address family for MPLS L3VPN.

Why this answer

To enable the distribution of VPNv4 prefixes in MPLS L3VPN, the engineer must configure the address-family vpnv4 command under the BGP routing process. This enters the VPNv4 address family configuration mode, where neighbors can be activated and other parameters set. The other address families do not handle VPNv4 prefixes: ipv4 vrf is for VRF-specific routing, ipv4 unicast is for global IPv4, and vpnv6 is for IPv6 VPNs.

Exam trap

The trap here is confusing the VRF-specific IPv4 address family with the VPNv4 address family that is used between PE routers.

753
MCQhard

A network engineer configures an EEM applet to monitor redistribution events using the event syslog pattern 'IP-4-ROUTING'. The applet is intended to log when a route is redistributed from OSPF into EIGRP. The redistribution is configured without a seed metric for EIGRP, and the route is not redistributed. The EEM applet does not trigger. Which is the most likely explanation?

A.Redistribution into EIGRP without a seed metric fails silently, and no syslog message is generated.
B.The EEM applet must use 'event routing' to capture redistribution events.
C.The syslog pattern 'IP-4-ROUTING' is incorrect; it should be 'IP-5-ROUTING'.
D.The redistribution is blocked by route tagging, preventing the syslog.
AnswerA

EIGRP redistribution requires a seed metric; without one, routes are silently rejected and no syslog message fires. Since no IP-4-ROUTING event is generated, the EEM applet's syslog pattern never matches, so the applet does not trigger.

Why this answer

When redistributing routes into EIGRP without a seed metric (the default-metric command or a metric on the redistribute statement), EIGRP cannot compute a metric and the routes are not redistributed. Critically, this failure is silent — no syslog message is generated, so the EEM applet watching for 'IP-4-ROUTING' never fires. The absence of the log is the expected behavior, not an EEM misconfiguration.

Exam trap

300-410 often tests silent failures in routing protocols, so candidates assume a missing syslog means the EEM applet is misconfigured rather than recognizing the protocol never logged anything.

How to eliminate wrong answers

Option B is wrong because EEM does not have an 'event routing' trigger for redistribution; the applet correctly uses event syslog pattern, and the issue is that no syslog is emitted. Option C is wrong because 'IP-4-ROUTING' is a valid syslog facility/severity pattern (facility IP, severity 4), and changing the severity number would not create a message that was never generated. Option D is wrong because route tagging affects which routes are redistributed but does not suppress syslog messages; the root cause is the missing seed metric.

754
MCQmedium

A network engineer runs the following command to troubleshoot an EIGRP issue: R1# show ip eigrp topology 10.1.1.0/24 IP-EIGRP (AS 100): Topology entry for 10.1.1.0/24 State: Passive, Query origin flag: 1, 1 Successor(s), FD is 131072 Routing Descriptor Blocks: 10.1.2.2 (GigabitEthernet0/0), from 10.1.2.2, Send flag: 0x0 Composite metric: (131072/130816), Route is Internal Vector metric: Minimum bandwidth is 10000 Kbit Total delay is 100 microseconds Reliability is 255/255 Load is 1/255 Minimum MTU is 1500 Hop count is 1 10.1.3.3 (GigabitEthernet0/1), from 10.1.3.3, Send flag: 0x0 Composite metric: (131328/131072), Route is Internal Vector metric: Minimum bandwidth is 10000 Kbit Total delay is 200 microseconds Reliability is 255/255 Load is 1/255 Minimum MTU is 1500 Hop count is 2 What does this output indicate?

A.Only one path is available; the second path is a backup that is not used.
B.Both paths are feasible successors, but only the first is installed in the routing table.
C.Both paths are installed in the routing table for load balancing.
D.The route is in active state, indicating a query is in progress.
AnswerA

Correct. Only the first path is a successor and is installed. The second path is not a feasible successor (RD == FD), so it is not immediately usable; it is only a backup that requires a query to become active.

Why this answer

The output shows two paths for 10.1.1.0/24. The first path has a composite metric of (131072/130816), making the feasible distance (FD) 131072. The second path has a composite metric of (131328/131072), where the reported distance (131072) equals the FD.

For a path to be a feasible successor, the reported distance must be strictly less than the FD (RD < FD). Since the second path's reported distance equals the FD, it does not satisfy the feasibility condition and is not a feasible successor. Therefore, only the first path is a successor and is installed in the routing table.

The second path remains in the topology table but is not a feasible successor and will not be used for forwarding or as a backup unless a topology change causes it to satisfy the feasibility condition. Thus, option A is the best answer, though the term 'backup' in option A is imprecise because the second path is not a feasible successor.

Exam trap

Candidates often misread the topology table and assume that any path with a reported distance less than or equal to the FD is a feasible successor. However, the feasibility condition requires a strict inequality (RD < FD). Here, the second path's RD equals the FD, so it is not a feasible successor.

How to eliminate wrong answers

Option A is wrong because the second path is not a backup; it is a feasible successor that is maintained in the topology table but not used unless the successor fails. Option C is wrong because both paths are not installed in the routing table; only the successor is installed, and unequal-cost load balancing requires the 'variance' command, which is not configured here. Option D is wrong because the route state is 'Passive', not 'Active'; an Active state would indicate a query is in progress, but the output clearly shows 'State: Passive'.

755
MCQhard

In OSPFv3, which authentication method is supported by default?

A.MD5 authentication
B.Simple password authentication
C.IPsec authentication
D.No authentication is supported
AnswerC

OSPFv3 removes OSPFv2's built-in authentication fields and relies on IPsec (AH or ESP) via the ipv6 ospf authentication ipsec command. IPsec is therefore the default and only native mechanism available, since the protocol itself carries no authentication data.

Why this answer

OSPFv3 uses IPsec for authentication and encryption, as defined in RFC 4552. It does not support the simple password or MD5 authentication used in OSPFv2.

756
MCQmedium

Given the following configuration on Router R2: router eigrp 200 redistribute ospf 1 metric 10000 100 255 1 1500 default-metric 10000 100 255 1 1500 What is the effect of having both the 'metric' keyword in the redistribute command and the 'default-metric' command?

A.The 'metric' keyword is ignored; the default-metric is used for all redistributed routes.
B.Both metrics are applied, causing a conflict and potential routing issues.
C.The 'metric' keyword overrides the default-metric for routes redistributed from OSPF into EIGRP.
D.The default-metric command is not needed and can be removed without any effect.
AnswerC

The metric keyword supplies seed metrics directly on the redistribute command, so it takes precedence over the router-level default-metric for OSPF-derived routes. The default-metric only applies when no metric is specified, making the explicit values the ones actually used.

Why this answer

The 'metric' keyword in the redistribute command explicitly sets the seed metric for routes redistributed from OSPF into EIGRP. When both the 'metric' keyword and the 'default-metric' command are present, the 'metric' keyword takes precedence for that specific redistribution. The 'default-metric' command only applies when no metric is specified in the redistribute command.

Exam trap

300-410 often tests the precedence of explicit parameters over global defaults, so candidates must remember that the 'metric' keyword in a redistribute command overrides the 'default-metric' command for that specific redistribution.

How to eliminate wrong answers

Option A is wrong because the 'metric' keyword is not ignored; it overrides the default-metric for that redistribution. Option B is wrong because there is no conflict; the more specific 'metric' keyword takes precedence. Option D is wrong because the default-metric command is still needed for other redistributions that do not specify a metric; removing it could cause those redistributions to fail.

757
MCQmedium

A network engineer is configuring a site-to-site VPN between two Cisco IOS routers using IPsec. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet is encrypted and sent over the VPN, while all other traffic is sent unencrypted. Which configuration element defines the traffic to be encrypted?

A.crypto ACL
B.ISAKMP policy
C.crypto map
D.transform set
AnswerA

The crypto ACL (extended access list) defines which traffic is considered interesting and should be protected by IPsec. In this scenario, an ACL permitting IP traffic from 10.1.1.0/24 to the remote subnet would ensure that only that traffic is encrypted. The crypto map then references this ACL to match traffic that needs encryption.

Why this answer

The crypto ACL, an extended access list, is used to define interesting traffic that should be encrypted and sent through the IPsec tunnel. It specifies the source and destination subnets and protocols. The crypto map references this ACL to match packets that require IPsec protection.

Therefore, the crypto ACL is the configuration element that defines the traffic to be encrypted.

Exam trap

The trap here is confusing the role of the crypto map with the crypto ACL; the crypto map references the ACL but does not define the traffic itself.

758
MCQmedium

Which statement about PBR and the 'set interface' command is correct?

A.The 'set interface' command can only be used with point-to-point interfaces.
B.If the specified interface is down, the router uses the routing table.
C.The 'set interface' command requires a next-hop IP address to be specified.
D.The 'set interface' command forces the packet out the specified interface, and if the interface is down, the packet is dropped.
AnswerD

Policy-based routing with 'set interface' overrides the routing table, directing matched traffic out the named interface. Because forwarding depends on that interface being operational, a down interface causes the packet to be dropped rather than rerouted.

Why this answer

The 'set interface' command in a PBR route-map forces matched packets out a specific egress interface regardless of the routing table. Unlike 'set ip next-hop', which relies on recursive lookup and can fall back to the RIB if the next-hop is unreachable, 'set interface' is a hard directive: if the referenced interface is down or not up/up, the packet is dropped rather than being routed normally. This makes it useful for strict path selection but risky in environments with flapping links.

Exam trap

The trap is assuming 'set interface' behaves like 'set ip next-hop' and falls back to the routing table when the interface fails — in reality, it drops the packet, which is a common cause of silent traffic loss in PBR deployments.

How to eliminate wrong answers

Option A is wrong because 'set interface' works on any interface type — point-to-point, multipoint, Ethernet, or tunnel — there is no restriction to point-to-point links. Option B is wrong because 'set interface' does not fall back to the routing table when the interface is down; that fallback behavior applies to 'set ip next-hop' with the 'verify-availability' option or when the next-hop is unreachable, not to 'set interface'. Option C is wrong because 'set interface' and 'set ip next-hop' are mutually exclusive alternatives within a route-map sequence; you do not need to specify a next-hop IP when using 'set interface'.

759
MCQmedium

Examine this configuration: interface GigabitEthernet0/0 ip address 10.0.0.1 255.255.255.0 ip nat inside ! interface GigabitEthernet0/1 ip address 198.51.100.1 255.255.255.0 ip nat outside ! ip nat inside source static tcp 10.0.0.10 80 198.51.100.10 8080 extendable Which statement is true?

A.All traffic from 10.0.0.10 is translated to 198.51.100.10.
B.Incoming traffic to 198.51.100.10:8080 is forwarded to 10.0.0.10:80.
C.The 'extendable' keyword is invalid for static NAT.
D.This translation will not work unless 'ip nat inside source list' is also configured.
AnswerB

Static NAT with the `extendable` keyword maps the inside local address 10.0.0.10 port 80 to the inside global address 198.51.100.10 port 8080, so inbound connections arriving on the outside interface at 198.51.100.10:8080 are translated and forwarded to the internal web server at 10.0.0.10:80.

Why this answer

The configuration uses a static NAT with TCP port translation (also known as NAT with port forwarding). The command `ip nat inside source static tcp 10.0.0.10 80 198.51.100.10 8080 extendable` creates a one-to-one mapping between the inside local address/port (10.0.0.10:80) and the inside global address/port (198.51.100.10:8080). This means any incoming packet destined to 198.51.100.10 on TCP port 8080 will have its destination translated to 10.0.0.10 port 80, and the response traffic is reverse-translated.

Option B correctly describes this behavior.

Exam trap

Cisco often tests the misconception that static NAT translates all traffic from an inside host, when in fact a static NAT with port specification only translates traffic matching that specific protocol and port, leaving other traffic untranslated.

How to eliminate wrong answers

Option A is wrong because the static NAT entry is specific to TCP port 80 on the inside host; it does not translate all traffic from 10.0.0.10 — only traffic matching source IP 10.0.0.10 and source TCP port 80 is translated to 198.51.100.10:8080. Option C is wrong because the 'extendable' keyword is valid for static NAT; it allows multiple static NAT entries to share the same global address (e.g., different ports) without conflict, which is essential for PAT-style static translations. Option D is wrong because 'ip nat inside source list' is used for dynamic NAT or PAT with an ACL, but this is a static NAT configuration that does not require an ACL — the translation is explicitly defined by the static command.

760
MCQhard

BGP is used between two ISPs. Router R1 has: neighbor 10.0.0.2 route-map SET-MED in, route-map SET-MED permit 10, set metric 50. Router R2 shows: show ip bgp 172.16.0.0 includes MED 50 but the path is not preferred. What is the root cause?

A.The MED value is too low to influence path selection.
B.The route-map should be applied outbound, not inbound.
C.MED is only compared when paths are from the same neighboring AS.
D.The neighbor has a higher local preference overriding MED.
AnswerC

BGP compares MED only between paths originating from the same neighbouring autonomous system. R2 received the MED 50 route from a different AS than the competing path, so the attribute is ignored during best-path selection, leaving that route unpreferred despite the lower metric.

Why this answer

BGP's MED (Multi-Exit Discriminator) attribute is only compared between paths that originate from the same neighboring AS. In this scenario, even though R2 receives a route with MED 50 from R1, the path is not preferred because the competing path likely comes from a different neighboring AS, making the MED comparison invalid. MED is a non-transitive attribute that influences inbound traffic only when comparing multiple exit points from the same AS.

Exam trap

Cisco often tests the nuance that MED is only compared between paths from the same neighboring AS, leading candidates to mistakenly think MED always influences path selection or that the value itself is the issue.

How to eliminate wrong answers

Option A is wrong because a MED value of 50 is not inherently too low; MED is a metric where lower values are preferred, so a low MED would actually make the path more preferred, not less. Option B is wrong because applying the route-map inbound on R1 correctly sets the MED on routes received from R2; applying it outbound would affect routes sent to R2, which is not the intended behavior for influencing R2's path selection. Option D is wrong because while local preference does override MED in BGP path selection order, the question states the MED is 50 but the path is not preferred, and there is no evidence that local preference is configured or higher; the most direct root cause is the AS path comparison rule for MED.

761
MCQmedium

A network engineer is configuring MPLS Layer 3 VPN on a Cisco router. The engineer wants to ensure that the PE router can forward VPN traffic to the correct CE router based on the route target. Which of the following is required on the PE router?

A.A static route to the CE router with a next-hop of the CE interface.
B.A route reflector client configured for the VPNv4 address family.
C.An IGP configured with multiprotocol BGP extensions.
D.A VRF instance with a route distinguisher and route target configured.
AnswerD

On a PE router, an MPLS L3VPN requires a VRF instance per VPN. The VRF must have a route distinguisher (RD) to make the VPN routes unique, and one or more route targets (RT) to control import and export of routes into and out of the VRF. This allows the PE to forward traffic to the correct CE based on the RT. Without these, VPN routing and forwarding would not work.

Why this answer

MPLS L3VPN relies on VRFs to separate customer routing tables. Each VRF must have a route distinguisher to make prefixes unique and route targets to control import/export of routes. The PE router uses these to forward traffic to the correct CE.

Without a VRF with RD and RT, the PE cannot maintain separate VPN routing or forward based on VPN membership.

Exam trap

The trap here is focusing on BGP or IGP configurations while overlooking the fundamental VRF configuration with RD and RT.

762
Drag & Dropmedium

Drag and drop the steps to configure and verify Policy-Based Routing (PBR) into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, define the route map with a sequence number. Next, match the interesting traffic using an ACL or prefix list. Then, set the next-hop or interface.

Apply the route map under the interface in the inbound direction. Finally, verify with 'show route-map' or 'show ip policy'.

763
Multi-Selectmedium

Which TWO commands would a network engineer use to verify NAT translations and their statistics on a Cisco IOS router? (Choose TWO.)

Select 2 answers
A.show ip nat translations
B.show ip nat statistics
C.show ip nat verbose
D.show running-config | include nat
E.debug ip nat
AnswersA, B

Displays the live NAT translation table, showing each inside local, inside global, outside local and outside global mapping the router currently holds. This satisfies the stem's requirement to verify translations themselves, distinct from statistics, confirming address translation is actually occurring.

Why this answer

Option A, 'show ip nat translations', is correct because it displays the current NAT translation table entries, showing the inside local, inside global, outside local, and outside global addresses for active translations on the Cisco IOS router. Option B, 'show ip nat statistics', is correct because it provides NAT statistics such as total active translations, hits, misses, expired translations, and interface information, which directly satisfies the requirement to verify NAT statistics. Option C, 'show ip nat verbose', is not a valid Cisco IOS command, so it cannot be used to verify NAT translations or statistics.

Option D, 'show running-config | include nat', only filters the running configuration for lines containing 'nat' and shows configured NAT statements, not live translations or statistics. Option E, 'debug ip nat', is a real-time debugging command that displays NAT translation events as they occur, but it is used for troubleshooting packet-by-packet activity rather than verifying the translation table and statistics as requested.

Exam trap

Cisco often tests the distinction between verification commands (show) and troubleshooting commands (debug), and candidates mistakenly select 'debug ip nat' because they think it provides statistics, when in fact it is a real-time debugging tool that can impact router performance.

764
MCQhard

An engineer configures PBR on a router to route traffic from subnet 10.1.1.0/24 to next-hop 192.168.1.2. The route-map is applied inbound on interface GigabitEthernet0/0. The engineer also configures 'ip policy route-map' on the same interface. However, the engineer notices that PBR is not working for multicast traffic from that subnet. What is the most likely explanation?

A.PBR is not supported for multicast traffic; multicast uses its own forwarding mechanisms.
B.The ACL in the route-map is blocking multicast addresses.
C.The next-hop 192.168.1.2 is not a multicast-capable router.
D.The route-map is missing a 'set ip next-hop verify-availability' command.
AnswerA

Multicast traffic is handled by multicast routing, not PBR, unless explicitly configured.

Why this answer

PBR does not process multicast traffic by default. Multicast packets are forwarded using multicast routing protocols (e.g., PIM) and are not subject to PBR. To apply PBR to multicast, special configuration (e.g., 'ip multicast policy route-map') is required.

765
MCQhard

A network administrator is troubleshooting a site-to-site IPsec VPN between two Cisco IOS routers. IKEv1 Phase 1 completes and the peer is authenticated, but the administrator sees that no IPsec SA is installed and interesting traffic is dropped. The administrator confirms the transform sets, ACLs, and pre-shared keys match on both sides. Which configuration element should the administrator verify next on both routers?

A.The crypto map sequence numbers and the ACL referenced by each map
B.The IKEv1 Phase 1 lifetime values on each peer
C.The routing table entries for the remote protected subnet
D.The Phase 2 proposal parameters, including encryption, hash, and PFS group
AnswerD

Phase 2 requires both peers to agree on a matching IPsec proposal: encryption algorithm, hash or integrity algorithm, and, if perfect forward secrecy is configured, the Diffie-Hellman group. If any of these differ, the responder rejects the quick mode exchange and no IPsec SA is created even though Phase 1 is up. Verifying the proposal on both routers is the correct next step for this symptom.

Why this answer

When IKE Phase 1 succeeds but no IPsec SA appears, the failure is almost always in the Phase 2 exchange. Both peers must agree on identical IPsec proposal parameters: encryption, integrity or hash, and the PFS Diffie-Hellman group if enabled. A single mismatch in any of these causes the responder to reject quick mode, leaving Phase 1 up while interesting traffic is dropped.

Exam trap

The trap here is focusing on Phase 1 settings such as lifetime or identity, when a completed Phase 1 with no SA points squarely at mismatched Phase 2 proposal parameters.

766
MCQeasy

A network engineer runs the following command on Router R1: R1# show ipv6 dhcp interface GigabitEthernet0/1 GigabitEthernet0/1 is in server mode Using pool: POOL6 Preference value: 0 Hint from client: ignored Rapid-Commit: disabled Based on this output, which statement is correct?

A.The interface is configured as a DHCPv6 client.
B.The interface is configured as a DHCPv6 server using pool POOL6.
C.The interface is using rapid-commit for faster address assignment.
D.The interface is in DHCPv6 relay mode.
AnswerB

The output explicitly states "GigabitEthernet0/1 is in server mode" and "Using pool: POOL6", confirming the interface operates as a DHCPv6 server bound to that pool. This directly satisfies the stem's requirement to identify the interface's DHCPv6 role and its assigned address pool.

Why this answer

The command output explicitly states 'GigabitEthernet0/1 is in server mode' and 'Using pool: POOL6', which confirms that the interface is acting as a DHCPv6 server. The DHCPv6 server assigns IPv6 addresses and other configuration parameters from the specified pool to requesting clients.

Exam trap

Cisco often tests the ability to read the exact output of 'show ipv6 dhcp interface' and distinguish between server, client, and relay modes, where candidates may misinterpret 'server mode' as client mode or overlook the 'Rapid-Commit: disabled' line.

How to eliminate wrong answers

Option A is wrong because the output shows 'server mode', not client mode; a DHCPv6 client would show 'client mode' or 'in client mode'. Option C is wrong because the output shows 'Rapid-Commit: disabled', meaning rapid-commit is not enabled, so the interface is not using it for faster address assignment. Option D is wrong because the output does not indicate relay mode; a DHCPv6 relay interface would show 'relay mode' or similar, not 'server mode'.

767
MCQmedium

Consider the following configuration: ipv6 access-list BLOCK-ICMP deny icmp any any echo-request deny icmp any any echo-reply permit ipv6 any any interface GigabitEthernet0/2 ipv6 traffic-filter BLOCK-ICMP in Which statement is true?

A.The ACL blocks ICMP echo-request and echo-reply, but permits all other IPv6 traffic inbound.
B.The ACL blocks all ICMPv6 traffic because the deny statements are too broad.
C.The ACL must be applied outbound to filter echo-request.
D.The ACL is missing the 'log' keyword to be effective.
AnswerA

The ACL denies only ICMP echo-request and echo-reply, then the permit ipv6 any any statement matches every remaining IPv6 packet, including other ICMP types. Applied inbound with ipv6 traffic-filter, it therefore blocks those two message types while allowing all other inbound IPv6 traffic.

Why this answer

The IPv6 ACL explicitly denies ICMPv6 echo-request and echo-reply messages (types 128 and 129) while the final permit ipv6 any any statement allows all other IPv6 traffic. The ipv6 traffic-filter command applied inbound on GigabitEthernet0/2 filters traffic as it enters the interface, so only the specified ICMP types are blocked, and all other IPv6 traffic is permitted.

Exam trap

Cisco often tests the misconception that an ACL applied inbound cannot block echo-reply because it is a response, but in IPv6, echo-reply is a separate ICMP type that can be filtered inbound on the interface where it arrives.

How to eliminate wrong answers

Option B is wrong because the ACL does not block all ICMPv6 traffic; it only denies two specific ICMPv6 message types (echo-request and echo-reply), and the permit ipv6 any any statement allows all other ICMPv6 types and all other IPv6 traffic. Option C is wrong because the ACL can filter echo-request and echo-reply when applied inbound; ICMP echo-request is typically sent from a source to a destination, so applying the ACL inbound on the destination interface will block the incoming echo-request, and echo-reply is also blocked inbound on the source interface if needed. Option D is wrong because the 'log' keyword is optional and not required for the ACL to be effective; the ACL will deny or permit traffic based on the configured entries without logging.

768
MCQmedium

Given this configuration on router R1: crypto isakmp policy 10 encryption aes 256 authentication pre-share group 14 lifetime 86400 ! crypto isakmp key cisco123 address 192.168.1.2 ! crypto ipsec transform-set TSET esp-aes 256 esp-sha-hmac mode tunnel ! crypto map CMAP 10 ipsec-isakmp set peer 192.168.1.2 set transform-set TSET match address 101 ! interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 ! access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255 What will happen when traffic from 10.1.1.0/24 to 10.2.2.0/24 is generated?

A.The traffic will be dropped because the ACL denies it.
B.The traffic will be forwarded normally without encryption.
C.The router will attempt to establish an IPsec tunnel but fail because the crypto map is missing.
D.The router will create a dynamic crypto map entry automatically.
AnswerB

The crypto map CMAP is never applied to interface GigabitEthernet0/1, so no IPsec policy matches the traffic. Without the `crypto map CMAP` interface command, packets from 10.1.1.0/24 to 10.2.2.0/24 bypass encryption entirely and are routed in cleartext, satisfying the stem's missing-binding constraint.

Why this answer

The crypto map is not applied to any interface. Without the `crypto map CMAP` command under GigabitEthernet0/1, the router has no IPsec policy to enforce on that interface. Traffic matching access-list 101 will simply be forwarded normally as clear-text IP packets, since no encryption is triggered.

Exam trap

The trap here is that candidates often assume a crypto map is automatically applied to the interface it references (e.g., via the peer IP), but Cisco explicitly tests that the `crypto map` command under the interface is required for IPsec to function.

How to eliminate wrong answers

Option A is wrong because access-list 101 is a permit ACL used to identify interesting traffic for IPsec, not a deny ACL; it does not drop traffic. Option C is wrong because the crypto map is fully configured (with peer, transform-set, and match address), but it is not missing—it is simply not applied to any interface, so no tunnel establishment is attempted. Option D is wrong because dynamic crypto maps are used for responder-only scenarios (e.g., when the peer IP is unknown) and are not automatically created; a static crypto map must be explicitly applied to an interface.

769
MCQmedium

A network engineer runs the following command on Router R1: R1# show ipv6 snooping binding IPv6 Address MAC Address VLAN Interface State 2001:DB8:1::100 aaaa.bbbb.cccc 10 Gi0/0/0 ACTIVE 2001:DB8:1::101 aaaa.bbbb.cccd 10 Gi0/0/0 ACTIVE 2001:DB8:1::102 aaaa.bbbb.ccce 10 Gi0/0/1 ACTIVE 2001:DB8:1::103 aaaa.bbbb.cccf 10 Gi0/0/1 ACTIVE Based on this output, which statement is correct?

A.All entries are in the ACTIVE state, meaning they are valid bindings.
B.The binding for 2001:DB8:1::103 is invalid.
C.The table shows only IPv6 addresses from SLAAC.
D.There are no entries for VLAN 10.
AnswerA

ACTIVE state indicates the binding is valid and being used.

Why this answer

The ACTIVE state in IPv6 snooping binding indicates that the binding has been validated and is currently in use, meaning the IPv6 address, MAC address, VLAN, and interface combination is legitimate. Option A is correct because all four entries show ACTIVE, confirming they are valid bindings that have passed the First Hop Security (FHS) validation process, such as Duplicate Address Detection (DAD) or neighbor solicitation verification.

Exam trap

Cisco often tests the misconception that all ACTIVE entries are automatically valid without understanding that ACTIVE simply means the binding passed initial validation, but it does not guarantee the device is not malicious if the binding was spoofed before FHS was enabled.

How to eliminate wrong answers

Option B is wrong because the binding for 2001:DB8:1::103 is listed as ACTIVE, which means it is valid; there is no indication of invalidity in the output. Option C is wrong because the output does not specify the address configuration method (SLAAC, DHCPv6, or static); IPv6 snooping binding entries can come from any source, and the table only shows addresses, not how they were assigned. Option D is wrong because all entries explicitly show VLAN 10 in the VLAN column, so there are indeed entries for VLAN 10.

770
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip vrf CUSTOMER Name Default RD Interfaces CUSTOMER 65001:100 Gi0/0.100 Gi0/1.100 Based on this output, which statement is correct?

A.The VRF CUSTOMER is configured with two subinterfaces.
B.The VRF CUSTOMER has no route distinguisher configured.
C.The VRF CUSTOMER is not active because no routes are shown.
D.The VRF CUSTOMER is using OSPF as the routing protocol.
AnswerA

The output lists Gi0/0.100 and Gi0/1.100 under the Interfaces column for VRF CUSTOMER, and the dot-one-hundred notation confirms these are subinterfaces, not physical ports. Both are assigned to the same VRF, satisfying the scenario's requirement of two subinterfaces in that VRF.

Why this answer

The output of 'show ip vrf CUSTOMER' displays the VRF name, its default route distinguisher (RD) of 65001:100, and the interfaces assigned to it. The interfaces listed are Gi0/0.100 and Gi0/1.100, which are both subinterfaces (indicated by the .100 suffix). Therefore, the VRF CUSTOMER is correctly configured with two subinterfaces.

Exam trap

Cisco often tests the distinction between VRF configuration output and routing information; the trap here is that candidates may assume a VRF is inactive or misconfigured because no routes are shown, when in fact 'show ip vrf' only displays the VRF name, RD, and interface assignments.

How to eliminate wrong answers

Option B is wrong because the output clearly shows a default RD of 65001:100, so a route distinguisher is configured. Option C is wrong because the VRF is active; the absence of routes in this output is normal, as 'show ip vrf' only displays VRF configuration and interface assignments, not routing information. Option D is wrong because the output does not indicate any routing protocol; VRF configuration is independent of the routing protocol used (OSPF, EIGRP, BGP, etc.) and no protocol is shown here.

771
MCQmedium

A network engineer is configuring policy-based routing (PBR) on a Cisco IOS XE router. The engineer wants traffic from subnet 10.1.1.0/24 to be forwarded to next-hop 192.168.2.1, while all other traffic uses the default routing table. The engineer configures a route map and applies it to the ingress interface with `ip policy route-map PBR`. However, traffic from 10.1.1.0/24 is still following the default route. Which action should the engineer take to ensure PBR is applied?

A.Verify that the route map contains a match statement for the source subnet and a set statement for the next-hop, and that the route map is applied with the `ip policy route-map` command on the correct interface.
B.Enable `ip local policy route-map PBR` globally to apply the policy to all interfaces.
C.Apply the route map to the egress interface with the `ip policy route-map` command.
D.Configure a default route with a next-hop of 192.168.2.1 to override the existing default route.
AnswerA

PBR requires a route map with at least one match statement (e.g., `match ip address` referencing an ACL for 10.1.1.0/24) and a set statement (e.g., `set ip next-hop 192.168.2.1`). The route map must be applied to the ingress interface with `ip policy route-map PBR`. If the match or set is missing, or if applied to the wrong interface, PBR will not take effect. This option correctly identifies the necessary configuration elements.

Why this answer

PBR requires a route map with proper match and set statements, and it must be applied to the ingress interface where the traffic enters. If the route map lacks a match for the source subnet or a set for the next-hop, or if it is applied incorrectly, PBR will not override the default routing. Verifying these elements ensures that traffic from 10.1.1.0/24 is forwarded to 192.168.2.1 as intended.

Exam trap

The trap here is assuming that simply applying a route map is sufficient, without verifying the match/set statements and the correct ingress interface application.

772
MCQeasy

Which statement accurately describes the behavior of the ip nat inside source static command when configuring static NAT for a single inside host?

A.It dynamically allocates the global address from a pool and removes the entry after an idle timeout.
B.It creates a permanent mapping that remains in the NAT table until the configuration is removed.
C.It requires the use of an access list to define which traffic is translated.
D.It translates only TCP and UDP traffic by default.
AnswerB

Static NAT installs a fixed one-to-one entry in the translation table that persists indefinitely, unlike dynamic translations which age out after the timeout. The mapping survives until the engineer removes the ip nat inside source static command, satisfying the permanent-mapping requirement.

Why this answer

The `ip nat inside source static` command creates a permanent one-to-one mapping between an inside local IP address and an inside global IP address. This static entry remains in the NAT table indefinitely until the administrator explicitly removes it with the `no ip nat inside source static` command, making option B correct.

Exam trap

Cisco often tests the misconception that static NAT requires an access list or that it behaves like dynamic NAT with timeouts, leading candidates to incorrectly choose options A or C.

How to eliminate wrong answers

Option A is wrong because static NAT does not dynamically allocate addresses from a pool or use timeouts; dynamic NAT and PAT use pools and idle timeouts. Option C is wrong because static NAT does not require an access list; the mapping is defined directly by the command, whereas dynamic NAT uses an access list to identify traffic to be translated. Option D is wrong because static NAT translates all IP traffic, including ICMP and other protocols, not just TCP and UDP; PAT (overload) is what typically limits translation to TCP/UDP by default.

773
MCQmedium

A network engineer is troubleshooting an IPsec site-to-site VPN that stopped working after a recent configuration change. The engineer runs 'show crypto isakmp sa' and sees an active IKE SA, but 'show crypto ipsec sa' shows no IPsec SAs. What is the most likely cause?

A.The IPsec transform set on one router does not match the transform set on the other.
B.The pre-shared key is incorrect on one of the routers.
C.The tunnel interface is down.
D.The IKE proposal is mismatched.
AnswerA

Phase 1 succeeds, proving IKE negotiation works, but Phase 2 fails because the transform sets differ. Mismatched encryption or hash algorithms prevent IPsec SA creation, leaving no entries in 'show crypto ipsec sa' despite the active IKE SA.

Why this answer

An active IKE SA indicates that IKE phase 1 completed successfully, but no IPsec SAs means phase 2 failed. The most common cause is a mismatch in the IPsec transform set or the crypto map access list between the two routers.

774
MCQhard

An engineer configures iBGP between two routers in the same AS. The BGP session comes up, but the routes learned from the eBGP neighbor are not installed in the routing table. The IGP does not carry the BGP next-hop address. Which is the most likely explanation?

A.The BGP next-hop is not reachable because the IGP does not advertise it, and no static route exists.
B.The BGP synchronization rule is enabled, causing the route to be suppressed until the IGP learns it.
C.The next-hop-self command is missing on the eBGP neighbor, so the iBGP router sees the external next-hop.
D.The BGP table shows the route as valid, but the routing table does not install it due to administrative distance.
AnswerA

When an eBGP speaker advertises a route to an iBGP peer, the next hop remains the IP address of the external neighbor unless next-hop-self is configured. The iBGP router must have a route in its IGP (or a static route) to that exact next-hop address before BGP will consider the path valid and install it into the routing table. Because neither an IGP advertisement nor a static route exists for that address, BGP marks the path as unreachable and withholds it from the RIB, even though the prefix appears in the BGP table.

Why this answer

For a BGP route to be installed in the routing table, the next-hop address must be reachable via the IGP or a static route. Since the IGP does not carry the BGP next-hop address and no static route exists, the next-hop is unreachable, causing the route to remain in the BGP table but not be installed in the routing table.

Exam trap

Cisco often tests the distinction between BGP table validity and routing table installation, where candidates mistakenly think a valid BGP route automatically installs, ignoring the next-hop reachability requirement.

How to eliminate wrong answers

Option B is wrong because BGP synchronization is disabled by default in modern IOS versions (Cisco IOS 12.2(8)T and later) and is rarely used; even if enabled, it would require the IGP to have a route to the prefix, not the next-hop. Option C is wrong because the next-hop-self command is typically configured on an eBGP neighbor to change the next-hop to the router's own IP when advertising to iBGP peers, but its absence does not prevent route installation if the next-hop is reachable via IGP or static route. Option D is wrong because administrative distance (e.g., 200 for iBGP) affects route selection among different protocols but does not prevent installation of a valid route; the route is not installed due to next-hop unreachability, not administrative distance.

775
MCQeasy

What is the default administrative distance for routes learned via OSPF in Cisco IOS?

A.90
B.100
C.110
D.120
AnswerC

Cisco IOS assigns OSPF a default administrative distance of 110. This value ranks OSPF less trustworthy than connected, static, eBGP and EIGRP routes, but more trustworthy than IS-IS and RIP, governing route selection when sources overlap.

Why this answer

OSPF has a default administrative distance of 110, as defined in Cisco IOS. This is used for route selection when multiple routing protocols provide the same prefix.

776
MCQmedium

Consider the following BGP configuration with BFD: router bgp 65000 neighbor 10.1.1.2 remote-as 65001 neighbor 10.1.1.2 fall-over bfd ! interface GigabitEthernet0/0 ip address 10.1.1.1 255.255.255.252 bfd interval 200 min_rx 200 multiplier 4 ! What is the effect of the 'neighbor fall-over bfd' command?

A.BGP will use BFD to detect link failures, but the BGP hold timer still applies.
B.BGP will ignore the BFD session and continue using its own keepalive/hold mechanism.
C.BGP will use BFD for fast failure detection; if BFD goes down, BGP will reset the session immediately.
D.The 'fall-over bfd' command is only needed if BFD timers are less than 100 ms.
AnswerC

The fall-over bfd command ties BFD liveness to the BGP session, so a BFD failure triggers immediate session teardown rather than waiting for the BGP hold timer. This delivers sub-second failure detection for the 10.1.1.2 neighbour.

Why this answer

The 'neighbor fall-over bfd' command enables BGP to use BFD for fast failure detection. When BFD detects a failure, BGP will immediately tear down the peering session without waiting for the hold timer.

777
MCQmedium

Interface GigabitEthernet0/1 is configured as shown: interface GigabitEthernet0/1 ipv6 address 2001:db8:1::1/64 ipv6 nd raguard ipv6 nd prefix default no-autoconfig What is the effect of this configuration?

A.The interface drops all incoming Router Advertisements from other routers.
B.The interface sends RAs with the autonomous flag set to allow SLAAC.
C.The interface only allows RAs from a specific authorized router.
D.The interface drops all Neighbor Solicitations.
AnswerA

IPv6 RA guard on the interface inspects inbound Router Advertisement and Router Redirect messages and drops them when they arrive on an access port, blocking rogue routers from advertising prefixes or becoming default gateways. This satisfies the requirement to prevent other routers' RAs from reaching hosts on that segment.

Why this answer

The `ipv6 nd raguard` command enables Router Advertisement (RA) guard on the interface, which drops all incoming RAs from other routers to prevent rogue RA attacks. The `ipv6 nd prefix default no-autoconfig` command suppresses the autonomous flag in sent RAs, but the RA guard is the active security feature that blocks incoming RAs, making option A correct.

Exam trap

Cisco often tests the distinction between commands that affect outgoing RAs (like `ipv6 nd prefix default no-autoconfig`) versus those that filter incoming RAs (like `ipv6 nd raguard`), leading candidates to confuse the direction of the traffic being controlled.

How to eliminate wrong answers

Option B is wrong because `ipv6 nd prefix default no-autoconfig` clears the autonomous flag in sent RAs, preventing SLAAC, not setting it. Option C is wrong because RA guard drops all incoming RAs indiscriminately; it does not filter based on a specific authorized router—that would require a more advanced feature like RA guard with a device-tracking policy or IPv6 SAVI. Option D is wrong because RA guard specifically targets Router Advertisements, not Neighbor Solicitations; Neighbor Solicitations are handled by other IPv6 first-hop security features like ND inspection or DAI for IPv6.

778
Multi-Selecthard

Which THREE symptoms indicate that NAT is misconfigured or failing on a Cisco router? (Choose THREE.)

Select 3 answers
A.Inside hosts can ping the outside interface IP but cannot reach hosts beyond it.
B.Traffic flows in one direction only (e.g., inside-to-outside works, but return traffic fails).
C.The show ip nat translations output shows many translations with the same inside global address but different ports, and new connections fail.
D.The router's CPU utilization is high due to BGP process.
E.The show ip route command shows a default route pointing to the ISP next hop.
AnswersA, B, C

Reaching the outside interface proves routing and NAT translation of the router's own traffic work, yet failure beyond it points to missing or incorrect inside source translation for host traffic, or an upstream return-path problem.

Why this answer

Option A is correct because when inside hosts can ping the outside interface IP but cannot reach hosts beyond it, the router's interface is reachable but address translation is not occurring, so packets sourced from inside local addresses are not being translated to an inside global address and are dropped or unroutable on the outside. Option B is correct because NAT failures commonly produce asymmetric behavior: outbound packets may be translated and forwarded, but if the translation entry is missing, incorrect, or the return traffic cannot be mapped back to the inside local address, the reply is dropped, so only one direction of the flow succeeds. Option C is correct because seeing many translations sharing the same inside global address with different ports indicates PAT overload, and if new connections fail, the router has likely exhausted the available port range or the translation table, which is a classic NAT/PAT misconfiguration or capacity failure symptom.

Option D is not correct because high CPU from the BGP process is a routing protocol issue, not a direct NAT misconfiguration or failure symptom. Option E is not correct because a default route pointing to the ISP next hop is a normal, expected routing configuration and does not by itself indicate NAT is misconfigured or failing.

Exam trap

Cisco often tests the distinction between connectivity to the outside interface (which does not require NAT) and connectivity beyond it (which requires proper NAT translation), leading candidates to mistakenly think that successful pings to the outside interface imply full NAT functionality.

779
MCQeasy

A network engineer runs the following command on Router R1: R1# show event manager policy registered No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 EIGRP_Neighbor_Down R1# show event manager history events Event History: No. Time Type Name 1 00:01:30 UTC Mar 1 syslog EIGRP_Neighbor_Down Based on this output, which statement is correct?

A.The EIGRP neighbor down event has occurred once.
B.The EIGRP neighbor is currently down.
C.The EEM policy is disabled.
D.The EIGRP neighbor is flapping.
AnswerA

The history table records one syslog event matching the EIGRP_Neighbor_Down applet, confirming the trigger fired a single time. The registered policy shows the applet exists but does not itself indicate occurrences, so the single history entry is the evidence that the neighbour-down condition occurred once.

Why this answer

The 'show event manager history events' output lists exactly one syslog event matching the EIGRP_Neighbor_Down policy, indicating the event fired once. The registered policy confirms the applet exists and is active, so the single history entry means the trigger has occurred one time.

Exam trap

The trap is inferring current state or flapping from a history log — candidates read a single logged event as 'currently down' or 'flapping,' when the log only proves the event fired once in the past.

How to eliminate wrong answers

Option B is wrong because the history output records a past event occurrence, not the current neighbor state — the neighbor could have recovered since. Option C is wrong because the policy appears in 'show event manager policy registered,' which confirms it is registered and active, not disabled. Option D is wrong because a single history entry cannot demonstrate flapping; flapping would require multiple repeated events over time.

780
Multi-Selecthard

A network engineer is troubleshooting an MPLS Layer 3 VPN on Cisco IOS XE routers. A customer edge (CE) router is not receiving routes from the provider edge (PE) router. The engineer suspects a VRF configuration issue. Which two commands should the engineer use to verify the VRF routing table and the BGP VPNv4 address family? (Choose two.)

Select 2 answers
A.show vrf detail
B.show ip bgp summary
C.show bgp vpnv4 unicast all
D.show ip route vrf CUSTOMER
E.show mpls ldp neighbor
AnswersC, D

The `show bgp vpnv4 unicast all` command displays the BGP VPNv4 table, which contains routes from all VRFs. It shows the VPNv4 prefixes, their attributes, and the associated route distinguishers and route targets. This is critical to verify that the PE is receiving and advertising VPNv4 routes correctly. If routes are missing here, the issue may be with BGP configuration or route targets.

Why this answer

To troubleshoot MPLS L3VPN route propagation, the engineer must check both the VRF routing table and the BGP VPNv4 table. The `show ip route vrf CUSTOMER` command reveals whether routes are installed in the VRF, while `show bgp vpnv4 unicast all` shows the VPNv4 routes exchanged between PEs. Together, they help isolate whether the issue is with VRF configuration, route targets, or BGP VPNv4 peering.

Exam trap

The trap here is focusing on MPLS LDP or global BGP commands, which do not show VRF-specific or VPNv4 routing information needed for this issue.

781
MCQhard

A network administrator is deploying 802.1X on a Cisco Catalyst switch. The switch is configured as an authenticator, and a RADIUS server is used for authentication. The administrator wants to ensure that if the RADIUS server becomes unreachable, endpoints are placed into a guest VLAN with limited access. Which command must be configured on the switch to enable this behavior?

A.authentication host-mode multi-auth
B.authentication event fail action authorize vlan 100
C.authentication violation restrict
D.authentication event server dead action authorize vlan 100
AnswerD

This command, configured under interface configuration mode, instructs the switch to authorize the port into VLAN 100 when the RADIUS server is detected as dead. This provides the desired guest VLAN behavior, allowing limited access while the authentication server is unreachable.

Why this answer

To place endpoints into a guest VLAN when the RADIUS server is unreachable, the switch must be configured with the 'authentication event server dead action authorize vlan' command under the interface. This triggers the fallback VLAN assignment upon detecting the server as dead.

Exam trap

The trap here is confusing 'authentication event fail' with 'authentication event server dead'; the former handles bad credentials, while the latter handles server unavailability.

782
MCQmedium

A network engineer runs the following command to troubleshoot an MPLS L3VPN issue: R1# debug mpls ldp transport Output: *Mar 1 00:01:23.456: mpls_ldp_transport: LDP transport connection from 10.0.0.2:646 to 10.0.0.1:1025 *Mar 1 00:01:23.456: mpls_ldp_transport: LDP transport connection from 10.0.0.2:646 to 10.0.0.1:1025 is accepted *Mar 1 00:01:23.456: mpls_ldp_transport: LDP transport connection from 10.0.0.2:646 to 10.0.0.1:1025 is established *Mar 1 00:01:23.456: mpls_ldp_transport: LDP transport connection from 10.0.0.2:646 to 10.0.0.1:1025 is up What does this output indicate?

A.LDP session is being established between 10.0.0.1 and 10.0.0.2
B.LDP session is being torn down between 10.0.0.1 and 10.0.0.2
C.LDP is using UDP for transport
D.LDP label bindings are being exchanged
AnswerA

The debug output shows the LDP transport connection progressing through accepted, established and up states between 10.0.0.1 and 10.0.0.2, confirming the TCP session underpinning the LDP session is being established successfully between the two routers.

Why this answer

The debug output shows the LDP transport connection progressing through states: received, accepted, established, and up. This sequence confirms that a TCP-based LDP session is being successfully established between the LSRs at 10.0.0.1 and 10.0.0.2. The port numbers (646 for LDP, 1025 as the ephemeral source port) and the 'up' state indicate the session is operational.

Exam trap

The trap here is confusing LDP transport (TCP) with LDP discovery (UDP), or misinterpreting the debug output as a teardown when it actually shows establishment. Candidates might also think label bindings are exchanged immediately upon TCP connection, but they occur after session initialization.

How to eliminate wrong answers

Option B is wrong because the output shows the session being established, not torn down; teardown messages would include 'closing' or 'down' states. Option C is wrong because LDP uses TCP (port 646) for transport, not UDP; UDP is used only for LDP discovery via hello messages. Option D is wrong because label bindings are exchanged after the session is up, but this debug specifically shows transport connection establishment, not the binding exchange process.

783
MCQmedium

A network engineer runs the following command on Router R2: R2# show logging | include %SYS-5-CONFIG_I *Mar 1 00:10:15.123: %SYS-5-CONFIG_I: Configured from console by console *Mar 1 00:12:45.678: %SYS-5-CONFIG_I: Configured from console by console *Mar 1 00:15:30.001: %SYS-5-CONFIG_I: Configured from console by console *Mar 1 00:20:00.999: %SYS-5-CONFIG_I: Configured from console by console Based on this output, what is the most likely problem?

A.The router has a memory leak causing frequent reloads.
B.The router is being reconfigured repeatedly from the console, which could indicate unauthorized access or a script issue.
C.The logging buffer is full and messages are being overwritten.
D.The syslog server is not reachable, so messages are only logged locally.
AnswerB

Each %SYS-5-CONFIG_I message is generated whenever the running configuration is replaced, and the text "from console by console" identifies the console line as the source. Four entries within ten minutes indicate repeated console-driven reconfiguration, consistent with unauthorised access or an automated script.

Why this answer

The %SYS-5-CONFIG_I syslog message is generated whenever the running configuration is modified — in this case, 'Configured from console by console' indicates changes were made via the console line. Four such messages within ten minutes strongly suggest repeated reconfiguration, which could be unauthorized access, a misbehaving script, or a console session left open with automated commands. This is the most likely problem given the evidence.

Exam trap

300-410 often tests whether candidates can distinguish between syslog message types — specifically, recognizing that %SYS-5-CONFIG_I indicates configuration changes (not reloads, buffer issues, or syslog failures) and interpreting the 'from console' origin correctly.

How to eliminate wrong answers

Option A is wrong because a memory leak causing reloads would produce %SYS-5-RELOAD or %SYS-2-MALLOCFAIL messages, not %SYS-5-CONFIG_I configuration change notifications. Option C is wrong because a full logging buffer would generate %SYS-5-LOGGING_BUFFER_FULL or similar, and the output shows distinct timestamps, not overwritten messages. Option D is wrong because an unreachable syslog server would not prevent local logging; the messages shown are local console logs, and the issue is the repeated configuration changes, not syslog delivery.

784
MCQhard

A network administrator is troubleshooting a DMVPN Phase 3 hub-and-spoke network using mGRE and NHRP. Spoke-to-spoke communication is failing, but spoke-to-hub communication works. The administrator verifies that NHRP registrations are successful and that the hub is configured with 'ip nhrp redirect'. What is the most likely cause of the spoke-to-spoke failure?

A.The hub is missing 'ip nhrp map multicast dynamic'.
B.The hub is not configured with 'ip nhrp redirect'.
C.The spokes are not configured with 'ip nhrp shortcut'.
D.The spokes are not configured with 'ip nhrp network-id'.
AnswerC

In DMVPN Phase 3, the hub uses 'ip nhrp redirect' to inform spokes of a better path, but the spokes must have 'ip nhrp shortcut' to dynamically create a direct tunnel to the destination spoke. Without it, spokes continue to send traffic through the hub, and spoke-to-spoke communication fails to optimize.

Why this answer

In DMVPN Phase 3, spoke-to-spoke communication requires the hub to send NHRP redirect messages and the spokes to have 'ip nhrp shortcut' configured. The shortcut allows spokes to dynamically create direct tunnels upon receiving a redirect. Without it, spokes continue to route through the hub, and direct spoke-to-spoke communication does not occur.

Exam trap

The trap here is assuming that 'ip nhrp redirect' on the hub is sufficient; the spokes must also have 'ip nhrp shortcut'.

785
MCQmedium

A network engineer is troubleshooting a DHCPv4 issue where a router configured as a DHCP server is not assigning addresses to clients on a subnet that is reachable via a different router (relay). The relay router (R2) has 'ip helper-address 10.1.1.1' on its client-facing interface, and the DHCP server is at 10.1.1.1 (R1). The engineer sees that R2 is sending DHCP DISCOVER messages with giaddr set to the client-facing interface IP, but R1 is not responding. R1 has a DHCP pool for the client subnet. The engineer pings 10.1.1.1 from R2 successfully. What is the most likely cause?

A.The DHCP server does not have a route to the client subnet (the giaddr subnet).
B.The relay agent R2 is missing the 'ip dhcp relay information option' command.
C.The DHCP pool on R1 is missing the 'default-router' command.
D.The 'ip helper-address' on R2 should point to the server's loopback address, not the interface IP.
AnswerA

R1 replies to the DISCOVER by unicasting to the giaddr (the client-facing interface on R2). Without a route back to that subnet, R1 drops the reply, so no offer is sent. R2's successful ping to R1 proves only forward reachability.

Why this answer

For DHCP relay to work, the DHCP server must have a route back to the giaddr subnet (the client subnet) so it can send the DHCP OFFER to the relay agent. Since R1 has no route to the client subnet, it drops the request and never responds.

Exam trap

The trap is focusing on relay-side configuration (Option 82, helper-address) when the actual failure is server-side return routing to the giaddr subnet — candidates forget that DHCP is a bidirectional exchange.

How to eliminate wrong answers

Option B is wrong because 'ip dhcp relay information option' (Option 82) is optional and not required for basic relay operation — its absence would not prevent the server from responding. Option C is wrong because a missing 'default-router' would only affect the default gateway handed to clients, not whether the server responds at all. Option D is wrong because 'ip helper-address' correctly points to the server's reachable interface IP; using a loopback is not required and would not fix the routing issue.

786
MCQhard

Which of the following is a limitation of NAT as defined in RFC 2663?

A.NAT cannot translate UDP traffic.
B.NAT is incompatible with TCP traffic.
C.NAT breaks end-to-end IP connectivity and can interfere with application-layer protocols.
D.NAT requires all traffic to be encrypted.
AnswerC

NAT rewrites IP addresses and ports, so hosts lose globally unique, end-to-end addressability required by RFC 2663. Embedded addresses inside payloads, such as FTP or SIP, are not translated, breaking those application-layer protocols. This satisfies the stem's limitation constraint directly.

Why this answer

RFC 2663 defines NAT as a mechanism that modifies IP addresses and/or ports in packet headers, which inherently breaks the end-to-end IP connectivity model. This modification can interfere with application-layer protocols that embed IP addresses or port numbers in their payload, such as FTP, SIP, or DNS, because NAT does not automatically translate these embedded addresses.

Exam trap

Cisco often tests the misconception that NAT is transparent to all traffic, when in fact it breaks end-to-end connectivity and requires ALGs for protocols that embed addressing information in the payload.

How to eliminate wrong answers

Option A is wrong because NAT can translate UDP traffic; it is commonly used for DNS and VoIP traffic. Option B is wrong because NAT is fully compatible with TCP traffic; it is widely used for web browsing and email. Option D is wrong because NAT does not require traffic to be encrypted; it operates on plaintext IP headers and can work with both encrypted and unencrypted traffic.

787
MCQeasy

Which SNMPv2c PDU type is used by the manager to request a large amount of data efficiently, such as an entire routing table?

A.GetRequest
B.GetNextRequest
C.GetBulkRequest
D.SetRequest
AnswerC

GetBulkRequest retrieves large MIB tables in a single transaction by returning multiple variable bindings per request, unlike GetNextRequest which walks one object at a time, making it efficient for bulk data such as routing tables.

Why this answer

C is correct because SNMPv2c introduced the GetBulkRequest PDU specifically to allow a manager to retrieve large amounts of data, such as an entire routing table, in a single request. Unlike GetNextRequest, which requires repeated requests to walk through a MIB subtree, GetBulkRequest uses a non-repeaters and max-repetitions mechanism to fetch multiple variable bindings in one operation, significantly reducing network overhead and latency.

Exam trap

Cisco often tests the misconception that GetNextRequest is the most efficient way to retrieve large tables, but the trap here is that GetBulkRequest was specifically designed for bulk retrieval and is the correct answer when efficiency is explicitly mentioned.

How to eliminate wrong answers

Option A is wrong because GetRequest retrieves only the value of a single specific OID instance and cannot efficiently fetch multiple rows or a large table. Option B is wrong because GetNextRequest retrieves the next OID in lexicographic order, requiring multiple sequential requests to traverse an entire table, which is inefficient for large data sets like a routing table. Option D is wrong because SetRequest is used to modify the value of a managed object, not to retrieve data.

788
MCQmedium

A network engineer is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The engineer wants to ensure that traffic from the 10.1.1.0/24 subnet is encrypted when going to the 10.2.2.0/24 subnet, but all other traffic should be sent unencrypted. Which configuration element is required to match this traffic?

A.A standard ACL with source 10.1.1.0 0.0.0.255, applied to the crypto map.
B.An extended ACL with source 10.1.1.0 0.0.0.255 and destination 10.2.2.0 0.0.0.255, referenced in the crypto map.
C.A prefix list that permits the 10.1.1.0/24 and 10.2.2.0/24 prefixes, referenced in the crypto map.
D.A route map that matches the source and destination subnets, applied to the crypto map.
AnswerB

This extended ACL precisely defines the interesting traffic that should be encrypted by the IPsec VPN. The source and destination addresses with wildcard masks match the specified subnets. Referencing it in the crypto map ensures only this traffic triggers the VPN tunnel, while other traffic is sent unencrypted, as required.

Why this answer

IPsec site-to-site VPNs use extended ACLs to define which traffic is encrypted. The ACL must match source and destination addresses of the traffic that should be protected. The ACL is referenced in the crypto map with the match address command.

Other traffic not matched by the ACL is sent in clear text. Standard ACLs, route maps, and prefix lists are not used for this purpose.

Exam trap

The trap here is confusing ACL types or thinking that any traffic-matching mechanism can be used in a crypto map, when only extended ACLs are valid for defining IPsec interesting traffic.

789
MCQmedium

A network engineer is configuring a DMVPN Phase 3 spoke router. The spoke must establish a direct tunnel to another spoke when traffic requires it. The hub is already configured with 'ip nhrp redirect'. Which additional command must be configured on the spoke to enable it to request and receive shortcut replies from the hub?

A.ip nhrp shortcut
B.ip nhrp redirect
C.ip nhrp network-id 100
D.ip nhrp map multicast dynamic
AnswerA

On a DMVPN Phase 3 spoke, 'ip nhrp shortcut' enables the spoke to intercept traffic and send an NHRP resolution request to the hub for a remote spoke. The hub replies with a redirect, and the spoke installs a shortcut route, allowing direct spoke-to-spoke communication. Without this command, the spoke continues to forward traffic through the hub even if the hub is configured with 'ip nhrp redirect'.

Why this answer

In DMVPN Phase 3, the hub uses 'ip nhrp redirect' to notify spokes of a better path. The spoke must be configured with 'ip nhrp shortcut' to send NHRP resolution requests and install shortcut routes. This combination allows direct spoke-to-spoke tunnels, reducing latency and hub load.

Other commands like 'ip nhrp map multicast dynamic' are hub-side multicast features and do not enable shortcut switching.

Exam trap

The trap here is confusing the hub-side 'ip nhrp redirect' with the spoke-side 'ip nhrp shortcut', assuming that enabling redirect on the hub automatically enables shortcut switching on spokes.

790
Drag & Dropmedium

Drag and drop the steps for MPLS LDP label discovery and distribution into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

LDP label discovery and distribution begins with sending Hello messages to multicast 224.0.0.2 (UDP). Once a Hello is received, a LDP adjacency is formed directly, then a TCP connection on port 646 is established between the peers. After TCP is up, label mapping messages are exchanged.

Finally, the learned labels populate the Label Information Base (LIB). The correct order is: B (Hello), C (adjacency), A (TCP connection), D (label mapping), E (LIB). Note that adjacency is formed before the TCP connection because LDP uses a two-phase discovery process.

791
MCQmedium

Given this configuration: ip nat pool GLOBAL 203.0.113.1 203.0.113.10 prefix-length 28 ip nat inside source list 10 pool GLOBAL overload access-list 10 permit 10.0.0.0 0.255.255.255 What is the effect?

A.All inside hosts are translated to the first pool address only.
B.Each inside host gets a unique pool address without port translation.
C.Inside hosts matching ACL 10 are translated to addresses in the pool using PAT.
D.The prefix-length 28 is invalid; a netmask must be used instead.
AnswerC

The `overload` keyword enables PAT, allowing many inside hosts permitted by ACL 10 to share the pool's addresses via port multiplexing. The pool spans 203.0.113.1–203.0.113.10, so translations are limited to those ten addresses rather than the full /28 subnet.

Why this answer

The configuration uses `ip nat inside source list 10 pool GLOBAL overload`, which combines a NAT pool with the `overload` keyword to enable Port Address Translation (PAT). ACL 10 permits all 10.0.0.0/8 addresses, so inside hosts matching this ACL are translated to the pool addresses (203.0.113.1–203.0.113.10) with port multiplexing, allowing many hosts to share the same public IP. This is the standard Cisco PAT behavior, making option C correct.

Exam trap

The trap here is that candidates often confuse `overload` with static NAT or assume `prefix-length` is invalid, but Cisco explicitly tests the understanding that `overload` enables PAT and that `prefix-length` is a valid syntax for defining the subnet mask in NAT pools.

How to eliminate wrong answers

Option A is wrong because the `overload` keyword enables PAT, which allows multiple inside hosts to share any pool address, not just the first one; without `overload`, only the first address would be used for dynamic translation. Option B is wrong because the `overload` keyword explicitly enables port translation, preventing each host from getting a unique pool address; without `overload`, a one-to-one mapping would occur, but here PAT is active. Option D is wrong because `prefix-length 28` is a valid alternative to a netmask in Cisco NAT pool configuration; it specifies the subnet mask as a prefix length (e.g., /28 = 255.255.255.240), and the command is syntactically correct.

792
MCQmedium

A network engineer runs the following command to troubleshoot IPv6 source guard: R1# debug ipv6 source-guard *Mar 1 00:04:56.789: IPv6-Source-Guard: R1, Fa0/0, IPv6 packet from 2001:db8::5, src MAC 0011.2233.4455, dst 2001:db8::1 *Mar 1 00:04:56.789: IPv6-Source-Guard: R1, Fa0/0, Binding lookup: 2001:db8::5 not found in binding table *Mar 1 00:04:56.789: IPv6-Source-Guard: R1, Fa0/0, Packet dropped: source 2001:db8::5 not allowed What does this output indicate?

A.IPv6 source guard is dropping packets from sources not in the binding table, preventing spoofing.
B.IPv6 source guard is allowing the packet because the source MAC matches.
C.IPv6 source guard is not configured; the debug output is from default IPv6 forwarding.
D.IPv6 source guard is learning the binding from the packet and will allow future packets.
AnswerA

IPv6 source guard builds its binding table from DHCPv6 snooping and IPv6 ND inspection entries, then filters data traffic on the access port. The debug line "not found in binding table" confirms the source address 2001:db8::5 has no valid binding, so the packet is dropped, satisfying the anti-spoofing constraint in the stem.

Why this answer

The debug output shows that IPv6 source guard is actively dropping a packet from source address 2001:db8::5 because that address is not found in the binding table. This is the core function of IPv6 source guard: it filters traffic based on the source IPv6 address and MAC address, using the binding table (populated by DHCPv6 snooping or ND snooping) to prevent spoofing attacks. The packet is dropped because the source address is not allowed, confirming that option A is correct.

Exam trap

Cisco often tests the misconception that IPv6 source guard can dynamically learn bindings from any traffic, when in fact it requires a pre-built binding table from DHCPv6 snooping or ND snooping to function correctly.

How to eliminate wrong answers

Option B is wrong because IPv6 source guard does not allow a packet solely based on a matching source MAC; it requires the source IPv6 address to be present in the binding table, and the debug explicitly states the binding lookup failed, leading to a drop. Option C is wrong because the debug output clearly shows IPv6 source guard is configured and actively processing packets (it performs a binding lookup and drops the packet), not that it is unconfigured or using default forwarding. Option D is wrong because IPv6 source guard does not dynamically learn bindings from arbitrary packets; it relies on a pre-populated binding table from DHCPv6 snooping or IPv6 neighbor discovery snooping, and the debug shows no learning action—only a lookup failure and drop.

793
MCQhard

Router R6 is configured to send SNMP inform requests to the NMS at 192.168.1.1. Configuration: snmp-server host 192.168.1.1 informs version 2c public, snmp-server enable traps. The NMS receives no informs. R6's show snmp statistics shows InformRequestsSent: 0, and show snmp pending shows no pending. The NMS can poll R6 successfully. The network has a firewall between R6 and the NMS that allows UDP 162. What is the root cause?

A.The 'snmp-server host' command for informs requires the 'informs' keyword to be placed correctly, but the router may not support informs with v2c; informs are only supported with SNMPv3.
B.The NMS is not configured to send SNMP responses to informs.
C.The firewall is blocking UDP 162 from the NMS to the router.
D.The router's SNMP agent is not enabled due to a missing 'snmp-server' command.
AnswerA

SNMPv2c supports only traps, which are unacknowledged notifications; informs require an acknowledgment and are defined only for SNMPv3. Even if the 'informs' keyword were correctly placed in the 'snmp-server host' command, the v2c community configuration would make the router fall back to traps or generate an error, resulting in zero informs sent. The observed no-informs behavior is therefore the expected consequence of using v2c with an informs configuration.

Why this answer

SNMPv2c does not support informs; informs require SNMPv3 because they need acknowledgment (response) from the NMS, which is only defined in SNMPv3. The 'snmp-server host' command with the 'informs' keyword will be accepted syntactically on a router running v2c, but the router will never actually send informs because the underlying protocol does not support the acknowledgment mechanism. This explains why InformRequestsSent remains 0 and no pending informs exist, even though the NMS can be polled successfully.

Exam trap

Cisco often tests the misconception that the 'informs' keyword can be used with SNMPv2c because the CLI accepts the command without error, but the router will never actually send informs under v2c.

How to eliminate wrong answers

Option B is wrong because the NMS does not need to be configured to send SNMP responses to informs; the NMS must be configured to listen for informs and send back an acknowledgment (a response) as part of the SNMPv3 inform protocol, but the issue here is that the router never sends the inform in the first place due to v2c limitation. Option C is wrong because the firewall allows UDP 162 from the router to the NMS, and the NMS can poll the router successfully, indicating no firewall blockage; the problem is that no informs are sent at all. Option D is wrong because the 'snmp-server enable traps' command is present, and the NMS can poll R6 successfully, proving the SNMP agent is enabled and functioning.

794
MCQmedium

snmp-server ifindex persist What is the effect of this configuration?

A.Interface indices are preserved after a device reload.
B.Interface statistics are cleared on reload.
C.SNMP traps are sent for interface state changes.
D.The ifIndex is based on the interface name.
AnswerA

Without persistence, interface indices are reassigned on reload, breaking SNMP monitoring that references them. The ifindex persist command writes indices to non-volatile storage, so the same index maps to the same interface after a device reload.

Why this answer

The `snmp-server ifindex persist` command configures the router to save interface index (ifIndex) values in non-volatile memory (the private configuration or NVRAM) so that after a reload, each interface retains its original ifIndex. This is critical for SNMP management systems that rely on stable ifIndex values to correlate interface statistics across reboots, as the default behavior is to assign ifIndex values dynamically based on the order interfaces are discovered, which can change after a reload.

Exam trap

Cisco often tests the misconception that `snmp-server ifindex persist` affects SNMP trap generation or interface statistics, when in reality it only ensures the ifIndex values remain constant across reloads.

How to eliminate wrong answers

Option B is wrong because the command does not affect interface statistics clearing; statistics are cleared by `clear counters` or reload, but ifIndex persistence does not prevent or cause that. Option C is wrong because SNMP traps for interface state changes are controlled by `snmp-server enable traps` and interface-specific trap configuration, not by ifIndex persistence. Option D is wrong because ifIndex is always based on the interface name or internal ordering, but persistence does not change the mapping logic; it only preserves the existing mapping across reboots.

795
MCQeasy

Which IP SLA operation type uses ICMP Echo Request/Reply packets to measure round-trip time?

A.UDP Jitter
B.ICMP Echo
C.TCP Connect
D.HTTP
AnswerB

The ICMP Echo operation sends ICMP Echo Request packets and measures the time until Echo Reply returns, yielding round-trip time. Other IP SLA types, such as UDP Jitter or HTTP, use different protocols and cannot measure ICMP-based RTT.

Why this answer

The IP SLA ICMP Echo operation (type 1) uses ICMP Echo Request and Echo Reply messages to measure network latency and availability.

796
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip sla summary IPSLAs Latest Operation Summary Codes: * active, ^ inactive, ~ pending ID Type Destination Stats Return Code Last 1 icmp-echo 192.168.1.1 RTT=50ms OK 1s ago 2 icmp-echo 192.168.1.2 RTT=2000ms Over threshold 2s ago 3 icmp-echo 192.168.1.3 RTT=100ms OK 3s ago Based on this output, which statement is correct?

A.IP SLA operation 2 has failed because the destination is unreachable.
B.IP SLA operation 2 is experiencing high latency, exceeding the configured threshold.
C.IP SLA operation 1 is not active because it shows 'OK'.
D.IP SLA operation 3 has a pending status.
AnswerB

Operation 2 reports an RTT of 2000ms with the return code Over threshold, confirming the measured latency has breached its configured threshold value. Operations 1 and 3 return OK, so only operation 2 is affected.

Why this answer

The 'Return Code' column shows 'Over threshold' for ID 2, meaning the RTT exceeded the configured threshold. The other operations are OK. This output does not indicate failure or timeout unless the return code says so.

797
MCQeasy

A network engineer is troubleshooting a router that is not generating any syslog messages at all, even for critical events like interface flaps. The 'show logging' output shows 'Syslog logging: disabled'. What is the most likely cause?

A.The 'logging on' command is not configured.
B.The logging buffer is full and needs to be cleared.
C.The router has run out of memory to generate syslog messages.
D.The 'logging host' command is missing, so no destination is configured.
AnswerA

'Syslog logging: disabled' means the logging process itself is off, so no messages are generated regardless of severity. The 'logging on' global configuration command enables it; without it, interface flaps and other critical events produce nothing.

Why this answer

The 'show logging' output explicitly states 'Syslog logging: disabled', which means the global logging process itself is turned off. In Cisco IOS, syslog logging is enabled by default, but it can be disabled with 'no logging on'. Re-enabling it with 'logging on' restores the generation of syslog messages to all configured destinations (console, buffer, hosts).

Without this command, no messages are produced regardless of destination configuration.

Exam trap

The trap here is confusing the global logging state with destination configuration; candidates often assume a missing 'logging host' or full buffer disables all syslog generation, but the 'show logging' output explicitly points to the global 'logging on' command.

How to eliminate wrong answers

Option B is wrong because a full logging buffer only affects the display of buffered messages; it does not stop the router from generating syslog messages to console or remote hosts. Option C is wrong because memory exhaustion would typically cause other symptoms and would not specifically show 'Syslog logging: disabled' in 'show logging'. Option D is wrong because a missing 'logging host' only means no remote syslog server is configured; the router would still generate messages to console and buffer by default.

798
MCQmedium

A network engineer runs the following command on Router R1: R1# show ipv6 eigrp neighbors IPv6-EIGRP neighbors for process 100 H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num 0 FE80::A8BB:CCFF:FE00:2 Tunnel0 13 00:23:45 10 200 0 12 1 FE80::A8BB:CCFF:FE00:3 Tunnel1 12 00:22:10 15 200 0 15 Based on this output, which statement is correct?

A.EIGRP is not configured for IPv6.
B.The neighbors are using global unicast addresses.
C.EIGRP for IPv6 adjacencies are established over the tunnels.
D.The tunnels are using GRE encapsulation.
AnswerC

The neighbour table lists two adjacencies, each reachable via a tunnel interface (Tunnel0 and Tunnel1), with link-local next-hop addresses and non-zero uptime. This confirms EIGRP for IPv6 has formed neighbourships across the tunnel links, satisfying the scenario's requirement to verify adjacency establishment over those interfaces.

Why this answer

The output shows two IPv6 EIGRP neighbors with link-local addresses (FE80::/10) on interfaces Tunnel0 and Tunnel1, and the adjacency is established and exchanging routes (Seq Num increasing). This confirms that EIGRP for IPv6 adjacencies are formed over these tunnel interfaces, making option C correct.

Exam trap

Cisco often tests the misconception that EIGRP for IPv6 uses global unicast addresses for neighbor adjacencies, but the output clearly shows link-local addresses, and candidates may incorrectly assume the tunnels must be GRE without evidence from the command output.

How to eliminate wrong answers

Option A is wrong because the command 'show ipv6 eigrp neighbors' successfully displays neighbor entries, which proves EIGRP for IPv6 is configured and operational on the process 100. Option B is wrong because the neighbor addresses shown are link-local addresses (FE80::/10), not global unicast addresses; EIGRP for IPv6 always uses link-local addresses for neighbor adjacencies. Option D is wrong because the output does not provide any information about the encapsulation type (GRE, IPsec, or other); the tunnels could be using any IPv6 tunneling technique, and GRE is not confirmed by this output.

799
MCQmedium

Router R4 has the following configuration: ``` interface GigabitEthernet0/5 ip address 10.4.4.4 255.255.255.0 ip policy route-map PBR-DEFAULT ! route-map PBR-DEFAULT permit 10 set ip default next-hop 192.168.3.1 ``` What is the effect of this configuration?

A.All packets received on G0/5 are forwarded to 192.168.3.1 if they do not have a route in the routing table.
B.All packets received on G0/5 are forwarded to 192.168.3.1 regardless of the routing table.
C.The route-map is missing a match statement, so it does nothing.
D.The configuration is invalid because 'set ip default next-hop' requires an ACL.
AnswerA

The `set ip default next-hop` command applies policy routing only to packets lacking a specific routing-table entry, so traffic with no matching route is forwarded to 192.168.3.1. Packets that do have a route follow normal destination-based forwarding, satisfying the default-path constraint in the stem.

Why this answer

The `set ip default next-hop` command in a route-map applies policy-based routing only when the router has no explicit route in the routing table for the destination — it is a fallback, not an override. So packets received on G0/5 that lack a matching route entry are forwarded to 192.168.3.1, while packets with a valid route follow normal destination-based forwarding. Option A describes this conditional fallback behaviour accurately.

Exam trap

300-410 often tests the distinction between `set ip next-hop` (unconditional override) and `set ip default next-hop` (fallback only when no route exists), so candidates who miss the `default` keyword pick Option B.

How to eliminate wrong answers

Option B is wrong because it describes `set ip next-hop`, which unconditionally overrides the routing table for matched traffic — the `default` keyword changes the semantics to fallback-only. Option C is wrong because a route-map without a `match` statement matches all traffic by default; the absence of a match clause does not make the route-map inert. Option D is wrong because `set ip default next-hop` does not require an ACL — the `ip policy route-map` interface command applies the route-map to all packets on the interface, and matching can be refined with `match ip address` if desired, but it is not mandatory.

800
MCQmedium

A network engineer runs the following command on router R4: R4# show monitor session 9 Session 9 --------- Type : ERSPAN Source Session Status : Admin Disabled Source Ports : Both : Gi0/2 Destination IP : 192.168.2.20 Origin IP : 10.0.0.3 ERSPAN ID : 200 Based on this output, which statement is correct?

A.The ERSPAN session is configured but not currently active because it is administratively disabled.
B.The ERSPAN session is actively mirroring traffic from Gi0/2 to 192.168.2.20.
C.The ERSPAN session is using RSPAN because the status is disabled.
D.The ERSPAN session is misconfigured because the origin IP is missing.
AnswerA

The output shows Status: Admin Disabled, meaning the ERSPAN source session exists in configuration but has been shut down administratively. Because of that disabled state, no traffic is mirrored from Gi0/2 to destination IP 192.168.2.20, despite the session parameters being present.

Why this answer

The output explicitly shows 'Status : Admin Disabled', which means the ERSPAN source session has been configured but has not been activated by the administrator. In Cisco IOS, an ERSPAN session remains in this state until the 'no shutdown' command is issued under the monitor session configuration. Therefore, the session is not currently mirroring traffic, making option A the correct statement.

Exam trap

The trap here is that candidates might assume the session is active simply because it is configured, ignoring the 'Admin Disabled' status, or they might confuse ERSPAN with RSPAN due to the disabled state.

How to eliminate wrong answers

Option B is wrong because the status 'Admin Disabled' indicates the session is not active; if it were actively mirroring, the status would show 'Admin Enabled' or 'Up'. Option C is wrong because the session type is clearly 'ERSPAN Source Session', not RSPAN; RSPAN uses a VLAN to carry mirrored traffic, while ERSPAN encapsulates traffic in GRE. Option D is wrong because the origin IP is present in the output ('Origin IP : 10.0.0.3'), so there is no misconfiguration regarding a missing origin IP.

801
MCQmedium

What is the default timer value for the EEM environment variable 'timer watchdog'?

A.30 seconds
B.60 seconds
C.120 seconds
D.180 seconds
AnswerB

The EEM watchdog timer defaults to 60 seconds, the interval after which the watchdog policy fires if no other policy has run, satisfying the stem's request for the default value rather than a configured override.

Why this answer

The EEM 'timer watchdog' environment variable, when set, causes the EEM policy to be aborted if it runs longer than the specified time. Cisco IOS XE documentation specifies the default value as 60 seconds, and it can be tuned with the event manager environment timer_watchdog command. This prevents runaway policies from consuming CPU indefinitely.

Exam trap

300-410 often tests memorization of default timer values — candidates confuse the EEM timer watchdog default (60s) with other IOS timers like ARP (4 hours) or routing update intervals.

How to eliminate wrong answers

Option A is wrong because 30 seconds is not the documented default — it is a value an administrator could set manually but not the out-of-box behavior. Option C is wrong because 120 seconds is a common distractor value; while it can be configured, it is not the default. Option D is wrong because 180 seconds is also a configurable value but not the default — candidates often confuse it with other IOS timers such as routing or ARP timeouts.

802
MCQmedium

A network engineer is implementing Policy-Based Routing (PBR) on a Cisco IOS router. The engineer wants to route traffic from subnet 10.10.10.0/24 to a next-hop of 192.168.2.2, but only for HTTP traffic (TCP port 80). Which configuration sequence is required?

A.Create a route-map with a match statement for the source subnet and a set statement for the next-hop, then apply it globally with ip policy route-map.
B.Create a route-map with a match statement for the source subnet and a set statement for the next-hop, then apply it to the interface with ip policy route-map.
C.Create a standard ACL that permits the subnet, create a route-map that matches the ACL and sets the next-hop, then apply the route-map to the interface with ip policy route-map.
D.Create an extended ACL that permits TCP port 80 from the subnet, create a route-map that matches the ACL and sets the next-hop, then apply the route-map to the interface with ip policy route-map.
AnswerD

This sequence correctly implements PBR for HTTP traffic. The extended ACL matches source subnet and destination TCP port 80. The route-map uses match ip address to reference the ACL and set ip next-hop to specify the next-hop. Applying the route-map to the ingress interface with ip policy route-map activates PBR. This ensures only HTTP traffic from the subnet is policy-routed, while other traffic follows normal routing.

Why this answer

PBR requires an extended ACL to match traffic based on source, destination, and port. The route-map then matches the ACL and sets the next-hop. Finally, the route-map is applied to the ingress interface with ip policy route-map.

A standard ACL cannot match port numbers, and global application is not supported. Therefore, the sequence with an extended ACL and interface application is correct.

Exam trap

The trap here is forgetting that PBR matching for ports requires an extended ACL, and that the route-map must be applied to an interface, not globally.

803
MCQmedium

A network administrator is configuring IPsec VPN on a Cisco IOS router. The administrator wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. The administrator has configured the crypto ACL as follows: 'access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255'. However, after applying the crypto map, the administrator notices that all traffic, including traffic to other destinations, is being dropped. What is the most likely cause?

A.The ACL 101 is also applied as an interface ACL in the outbound direction, and its implicit deny is dropping all other traffic.
B.The crypto map is applied to the wrong interface or in the wrong direction.
C.The crypto ACL is missing a deny statement for other traffic, causing all non-matching traffic to be dropped by the implicit deny at the end of the ACL.
D.The IPsec transform set is misconfigured, causing all traffic to be dropped.
AnswerA

If ACL 101 is applied as an interface ACL on the outbound interface, the implicit deny at the end will drop all traffic that does not match the permit statement. The crypto ACL itself does not drop traffic, but if it is reused as an interface ACL, it will filter traffic. This is a common misconfiguration.

Why this answer

The most likely cause is that the crypto ACL is also applied as an interface ACL, and its implicit deny is dropping all traffic that does not match the permit statement. Crypto ACLs are not meant to filter traffic; they only identify interesting traffic for encryption. If the same ACL is used for interface filtering, it will drop non-matching traffic.

Exam trap

The trap here is assuming that the crypto ACL itself causes all non-matching traffic to be dropped; in reality, crypto ACLs do not filter traffic, but if reused as an interface ACL, the implicit deny will drop traffic.

804
MCQmedium

A network engineer runs the following command to troubleshoot an IPsec Site-to-Site VPN issue: R1# debug crypto isakmp *Mar 1 00:01:23.456: ISAKMP (0:0): received packet from 192.168.1.2 dport 500 sport 500 Global (N) NEW SA *Mar 1 00:01:23.457: ISAKMP: Created a peer struct for 192.168.1.2, peer port 500 *Mar 1 00:01:23.457: ISAKMP: New peer created peer = 0x12345678 peer_handle = 0x80000001 *Mar 1 00:01:23.457: ISAKMP: Locking peer struct 0x12345678, refcount 1 for crypto_isakmp_process_block *Mar 1 00:01:23.457: ISAKMP (0:0): SA request profile is (default) *Mar 1 00:01:23.457: ISAKMP: local port 500, remote port 500 *Mar 1 00:01:23.458: ISAKMP (0:0): found peer pre-shared-key matching 192.168.1.2 *Mar 1 00:01:23.458: ISAKMP (0:0): constructed NAT-T vendor ID *Mar 1 00:01:23.458: ISAKMP (0:0): sending packet to 192.168.1.2 my_port 500 peer_port 500 (I) MM_NO_STATE *Mar 1 00:01:23.458: ISAKMP (0:0): received packet from 192.168.1.2 dport 500 sport 500 Global (I) MM_NO_STATE *Mar 1 00:01:23.459: ISAKMP (0:0): processing SA payload. message ID = 0 *Mar 1 00:01:23.459: ISAKMP (0:0): Checking ISAKMP transform 1 against priority 1 policy *Mar 1 00:01:23.459: ISAKMP: encryption DES-CBC *Mar 1 00:01:23.459: ISAKMP: hash SHA *Mar 1 00:01:23.459: ISAKMP: default group 2 *Mar 1 00:01:23.459: ISAKMP: auth pre-share *Mar 1 00:01:23.459: ISAKMP (0:0): atts are not acceptable. Next transforms are not acceptable *Mar 1 00:01:23.460: ISAKMP (0:0): no offers accepted! What does this output indicate?

A.The ISAKMP SA is established successfully using pre-shared key authentication.
B.The ISAKMP transform set proposal is rejected due to a mismatch in encryption, hash, or DH group between peers.
C.The router is receiving the packet from an incorrect source IP address.
D.The router is unable to find a pre-shared key for the peer.
AnswerB

The responder's transform (DES, SHA, group 2) fails the initiator's policy check, producing 'atts are not acceptable' and 'no offers accepted'. Matching encryption, hash and DH group on both peers resolves the phase 1 failure.

Why this answer

The debug output shows that the router received an ISAKMP proposal from the peer (192.168.1.2) and checked it against its own configured policy. The line 'atts are not acceptable' followed by 'no offers accepted' indicates that the transform set attributes (encryption DES-CBC, hash SHA, DH group 2) did not match any of the router's ISAKMP policies. This is a classic proposal mismatch, preventing the ISAKMP SA from being established.

Exam trap

Cisco often tests the distinction between a pre-shared key mismatch (which would show 'no pre-shared key found') and a transform set mismatch (which shows 'atts are not acceptable'), leading candidates to incorrectly blame the PSK when the actual issue is the encryption/hash/DH group.

How to eliminate wrong answers

Option A is wrong because the debug clearly shows 'no offers accepted', meaning the ISAKMP SA was not established; successful establishment would show 'ISAKMP (0:0): SA has been created' or similar. Option C is wrong because the router correctly identifies the source IP as 192.168.1.2 and processes the packet; there is no indication of an incorrect source IP. Option D is wrong because the debug explicitly states 'found peer pre-shared-key matching 192.168.1.2', so the pre-shared key is present and matched.

805
MCQmedium

A network engineer runs the following command on Router R1: R1# show flow exporter EXPORTER-1 Flow Exporter EXPORTER-1: Description: Exports to collector Export protocol: NetFlow Version 9 Transport Configuration: Destination IP address: 192.168.1.100 Source IP address: 10.0.0.1 Transport Protocol: UDP Destination Port: 2055 Source Port: 0 Collector Configuration: VRFs: Default Options Configuration: Sampler: Not configured Export Statistics: Number of Flows exported: 0 Number of Packets exported: 0 Number of Source IP address unreachable: 0 Number of Packets dropped: 0 Based on this output, what is the most likely reason that no flows are being exported?

A.The destination port is incorrect; NetFlow version 9 requires port 9996.
B.The flow exporter is not referenced in any flow monitor applied to an interface.
C.The source IP address is not reachable from the destination.
D.The sampler is not configured, causing all packets to be dropped.
AnswerB

Export statistics show zero flows added, so the exporter itself is idle rather than failing. A flow exporter only receives records when a flow monitor referencing it is applied to an interface; without that binding, no cache entries exist to export, matching the zero counters.

Why this answer

The output shows that the flow exporter has no flows exported, and the export statistics are all zero. This indicates that the exporter is not actively exporting data, likely because it is not referenced in a flow monitor that is applied to an interface. Without a flow monitor, the exporter is not triggered to export any flows.

Exam trap

300-410 often tests the dependency between flow exporters, monitors, and interface application; candidates may focus on port numbers or sampler settings, missing that the exporter must be referenced in a flow monitor.

How to eliminate wrong answers

Option A is wrong because NetFlow version 9 can use various destination ports, and 2055 is a common UDP port for NetFlow; it is not incorrect. Option C is wrong because the output shows 'Number of Source IP address unreachable: 0', meaning there is no reachability issue. Option D is wrong because the sampler is not configured, but that does not cause packets to be dropped; it only means sampling is not applied, and the output shows 'Number of Packets dropped: 0'.

806
MCQmedium

A network engineer runs the following command to troubleshoot an IP SLA issue: R1# show ip sla statistics 10 detail Round Trip Time (RTT) for Index 10 Latest RTT: 12 ms Latest RTT (milliseconds): 12 Latest RTT (microseconds): 12000 Last operation start time: 12:34:56.789 UTC Mon Mar 1 2021 Last operation return code: OK Number of successes: 100 Number of failures: 0 Operation time to live: Forever Last operation response time: 12 ms Latest operation start time: 12:34:56.789 UTC Mon Mar 1 2021 Latest operation return code: OK Over thresholds occurred: FALSE Threshold (milliseconds): 5000 RTT Values: RTTAvg: 12 RTTMin: 10 RTTMax: 15 RTTNum: 100 RTTStdDev: 1 What does this output indicate?

A.The IP SLA operation has high jitter because the RTT standard deviation is 1 ms.
B.The IP SLA operation is experiencing packet loss because the number of failures is 0.
C.The IP SLA operation shows stable performance with low jitter and no threshold violations.
D.The IP SLA operation has exceeded the threshold because the RTTMax is 15 ms.
AnswerC

Latest RTT of 12 ms against a 5000 ms threshold, zero failures across 100 successes, and RTTStdDev of 1 ms with a 10-15 ms range show consistent latency and minimal jitter, so no threshold breach has occurred.

Why this answer

The output shows stable performance with low jitter (standard deviation of 1 ms) and no threshold violations (over thresholds occurred: FALSE, threshold is 5000 ms). The number of failures is 0, indicating no packet loss.

Exam trap

The trap is misinterpreting the statistics: candidates might think that a low standard deviation indicates high jitter, or that any RTT above a certain value is a threshold violation, but the threshold is explicitly given as 5000 ms.

How to eliminate wrong answers

Option A is wrong because a standard deviation of 1 ms indicates very low jitter, not high jitter. Option B is wrong because the number of failures is 0, which means there is no packet loss. Option D is wrong because the RTTMax is 15 ms, which is well below the threshold of 5000 ms, so the threshold has not been exceeded.

807
MCQhard

A network engineer runs the following command on Router R1: R1# show event manager policy registered No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 BGP_Neighbor_Down R1# show bgp neighbors 192.168.1.2 BGP neighbor is 192.168.1.2, remote AS 65002, external link BGP version 4, remote router ID 10.0.0.2 BGP state = Idle Last read 00:00:05, hold time is 180, keepalive interval is 60 seconds Neighbor sessions: 1 active, is not multisession capable Based on this output, what is the most likely conclusion?

A.The BGP neighbor is up and running.
B.The BGP neighbor is down, and the EEM policy may have been triggered.
C.The EEM policy is not registered.
D.The BGP session is established.
AnswerB

The neighbour sits in Idle state, meaning no TCP session or BGP peering is established with 192.168.1.2. The registered EEM applet BGP_Neighbor_Down monitors exactly this condition, so the transition to Idle plausibly triggered the policy, satisfying the stem's request for the most likely conclusion.

Why this answer

The BGP neighbor 192.168.1.2 shows 'BGP state = Idle', which means the session is not established and the neighbor is down. The registered EEM applet named BGP_Neighbor_Down strongly suggests an event manager policy was configured to react to this exact condition, so it may have been triggered. The combination of Idle state plus a matching EEM policy name points to a down neighbor with automation in play.

Exam trap

300-410 often tests whether candidates read BGP state output correctly — 'Idle' and 'Active' both mean the session is down, and only 'Established' means it is up; candidates who skim may assume a listed neighbor is automatically up.

How to eliminate wrong answers

Option A is wrong because 'Idle' is a non-established BGP state — the neighbor is not up. Option C is wrong because the 'show event manager policy registered' output explicitly lists the BGP_Neighbor_Down applet as registered. Option D is wrong because 'Established' is the only state indicating a working BGP session, and the output clearly shows Idle.

808
MCQmedium

Which two OSPF network types default to a hello interval of 30 seconds and a dead interval of 120 seconds on Cisco IOS? (Choose two.)

A.Broadcast
B.Point-to-point
C.Non-Broadcast (NBMA)
D.Point-to-multipoint
AnswerC, D

Correct: NBMA OSPF network type defaults to hello interval 30 seconds and dead interval 120 seconds.

Why this answer

On Cisco IOS, both the NBMA (Non-Broadcast Multi-Access) and point-to-multipoint OSPF network types default to a hello interval of 30 seconds and a dead interval of 120 seconds. Broadcast and point-to-point networks use 10 and 40 seconds, respectively. Therefore, both options C and D are correct.

Exam trap

Candidates often think only NBMA uses 30/120, but point-to-multipoint also uses these timers.

809
MCQeasy

A network engineer runs the following command to troubleshoot an EIGRP issue: R1# show ip eigrp traffic IP-EIGRP Traffic Statistics for process 100 Hellos sent/received: 500/495 Updates sent/received: 10/8 Queries sent/received: 2/1 Replies sent/received: 1/2 Acks sent/received: 8/10 Input queue high water mark: 2, Input queue depth: 0 Total packets sent: 521, received: 516 What does this output indicate?

A.The network is experiencing a high number of queries, indicating instability.
B.The EIGRP process is functioning normally with no signs of congestion or issues.
C.There is a problem with packet loss because more hellos were sent than received.
D.The router is not receiving acknowledgments for its updates.
AnswerB

Hello counters are near-symmetric, queries and replies are minimal, and the input queue depth is zero with a high water mark of two, showing no backlog. This confirms stable neighbour adjacencies and normal EIGRP operation without congestion.

Why this answer

The output shows a balanced exchange of EIGRP packets with no retransmissions, a low input queue depth of 0, and a high water mark of only 2. These metrics indicate the EIGRP process is stable, with no congestion, packet loss, or neighbor issues. The slight difference between hellos sent (500) and received (495) is normal due to timing or asymmetric paths and does not indicate a problem.

Exam trap

Cisco often tests the misconception that any asymmetry in hello packet counts indicates packet loss, when in fact EIGRP hellos are sent unreliably and a slight mismatch is normal due to timing differences or interface delays.

How to eliminate wrong answers

Option A is wrong because the query count (2 sent, 1 received) is very low, not high; a high number of queries would indicate route recomputation or instability, but these numbers show a stable topology. Option C is wrong because a small difference in hellos sent vs received is normal in EIGRP due to hello interval timing variations or asymmetric links, and does not indicate packet loss. Option D is wrong because the Ack counts (8 sent, 10 received) are balanced and consistent with the update and query/reply exchanges, showing that acknowledgments are being received properly.

810
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip eigrp interfaces detail Gi0/0 EIGRP-IPv4 Interfaces for AS(100) Interface: GigabitEthernet0/0 Peers: 1 Xmit Queue Un/Reliable: 0/0 Mean SRTT: 12 Pacing Time Un/Reliable: 0/10 Multicast Flow Timer: 50 Pending Routes: 0 Hello interval: 5 Hold time: 15 Split horizon: Enabled Next multicast: 0.0.0.0 Next broadcast: 0.0.0.0 Based on this output, what is the problem?

A.Split horizon is enabled, which is a normal and expected configuration.
B.Split horizon is disabled, which could cause routing loops.
C.The hold time of 15 seconds is too short and may cause instability.
D.The interface has no peers, indicating a problem.
AnswerA

Split horizon enabled is the default behaviour on EIGRP interfaces, so it cannot be the fault. Every other counter shown — Peers, SRTT, queue drops, pending routes — is healthy, meaning the output reveals no actual problem despite the question asking for one.

Why this answer

Split horizon is a default and expected behavior in EIGRP for most interface types, including GigabitEthernet. The output shows 'Split horizon: Enabled', which is normal and prevents routing loops by ensuring that routing information learned on an interface is not advertised back out of that same interface. There is no problem indicated by this setting.

Exam trap

The trap here is that candidates may mistakenly think split horizon is a problem or misconfiguration, when in fact it is a standard loop-prevention mechanism, and Cisco often tests this by showing a normal default value and asking if it indicates an issue.

How to eliminate wrong answers

Option B is wrong because the output explicitly shows 'Split horizon: Enabled', not disabled, so the premise of the option is factually incorrect. Option C is wrong because a hold time of 15 seconds with a hello interval of 5 seconds is the default for EIGRP on high-speed interfaces (hello=5, hold=15) and is not too short; it provides adequate time to detect neighbor failures without causing instability. Option D is wrong because the output shows 'Peers: 1', indicating that the interface does have an EIGRP neighbor, so there is no peer problem.

811
Multi-Selectmedium

Which THREE symptoms indicate a potential issue with NHRP registration in a DMVPN network? (Choose THREE.)

Select 3 answers
A.The spoke router does not receive an NHRP Registration Reply from the hub.
B.The hub router's NHRP cache does not contain an entry for the spoke.
C.The spoke router's tunnel interface shows 'UP/UP' but NHRP registration status is 'NOT REGISTERED'.
D.The spoke router's tunnel interface shows 'UP/DOWN'.
E.The spoke router's routing table shows routes learned from the hub.
AnswersA, B, C

A missing NHRP Registration Reply directly evidences failed registration: the spoke sent a Registration Request but the hub never acknowledged it, so no mapping is installed. This satisfies the stem's requirement for a registration-specific symptom, distinguishing it from tunnel or routing faults that occur after successful registration.

Why this answer

Option A is correct because a spoke initiates NHRP registration by sending an NHRP Registration Request to the hub's NBMA address, and the hub must respond with an NHRP Registration Reply; failure to receive that reply directly indicates the registration exchange is failing. Option B is correct because a successful registration causes the hub to install an NHRP cache entry mapping the spoke's tunnel IP to its NBMA address, so a missing entry confirms the spoke never successfully registered. Option C is correct because the tunnel interface can be UP/UP (mGRE is stateless and comes up regardless of NHRP), yet the NHRP registration status explicitly showing 'NOT REGISTERED' is a direct symptom of an NHRP registration problem.

Option D is not correct because an UP/DOWN tunnel interface points to a Layer 1/2 or tunnel source/destination reachability problem rather than an NHRP registration failure. Option E is not correct because routes learned from the hub indicate that routing adjacencies and reachability are working, which is not a symptom of failed NHRP registration.

Exam trap

300-410 often tests the confusion between tunnel interface status and NHRP registration status; candidates might think a tunnel being 'UP/UP' guarantees NHRP registration, but NHRP can still fail due to authentication or network ID mismatches.

812
MCQmedium

Examine the following partial configuration on a PE router: interface GigabitEthernet0/1 ip vrf forwarding CUSTOMER-A ip address 10.1.1.1 255.255.255.252 ! router bgp 65000 neighbor 192.168.1.1 remote-as 65000 neighbor 192.168.1.1 update-source Loopback0 ! address-family ipv4 vrf CUSTOMER-A neighbor 10.1.1.2 remote-as 65001 neighbor 10.1.1.2 activate exit-address-family What is the effect of this configuration?

A.The eBGP session between PE and CE will be established successfully.
B.The BGP session will fail because the neighbor must be configured under the global BGP process.
C.The BGP session will fail because the neighbor remote-as must match the AS of the PE router.
D.The BGP session will fail because the update-source is not specified for the VRF neighbor.
AnswerA

The VRF is defined, the interface is in the VRF, and the BGP neighbor is correctly configured under the VRF address-family. The neighbor IP is on the same subnet, so the eBGP session should come up.

Why this answer

The configuration shows that the eBGP session between the PE and CE router will be established successfully because the neighbor is configured under the VRF address family with the correct remote-as (65001) and activated. The PE router's interface is in VRF CUSTOMER-A with IP 10.1.1.1/30, and the CE neighbor is 10.1.1.2, which is reachable. The global BGP neighbor 192.168.1.1 is for iBGP and does not affect the VRF session.

Exam trap

300-410 often tests the confusion between global BGP and VRF address-family configuration, where candidates might think the neighbor must be configured globally or that update-source is mandatory for eBGP.

How to eliminate wrong answers

Option B is wrong because BGP neighbors for VRFs are configured under the address-family ipv4 vrf block, not globally; the global neighbor is for the global routing table. Option C is wrong because the remote-as for the CE neighbor must be the CE's AS (65001), not the PE's AS (65000); the configuration correctly uses 65001. Option D is wrong because update-source is not required for eBGP neighbors when the neighbor IP is directly connected on the interface; it is typically used for iBGP or when the neighbor is not on a directly connected subnet.

813
MCQmedium

Which statement correctly describes the behavior of the 'default-information originate' command in OSPF?

A.It always injects a default route into OSPF regardless of the routing table.
B.It injects a default route as a Type 3 LSA.
C.It injects a default route as a Type 5 LSA only if a default route exists in the routing table.
D.It injects a default route as a Type 7 LSA in all OSPF areas.
AnswerC

Without the always keyword, OSPF originates the default as a Type 5 LSA only when a default route already exists in the routing table. This conditional dependency is the exact behaviour the stem asks about, distinguishing it from unconditional origination.

Why this answer

The 'default-information originate' command in OSPF injects a default route (0.0.0.0/0) into the OSPF domain as a Type 5 External LSA, but only if a default route already exists in the routing table. Without an existing default route, the command has no effect unless the 'always' keyword is appended. This behavior ensures the router does not advertise a default path it cannot actually use.

Exam trap

300-410 often tests the misconception that 'default-information originate' always injects a default route; candidates forget the requirement for an existing default route unless the 'always' keyword is used.

How to eliminate wrong answers

Option A is wrong because the command does not always inject a default route; it requires a default route in the routing table unless the 'always' keyword is specified. Option B is wrong because a Type 3 LSA is a Summary LSA used for inter-area routes, not for external default routes originated by this command. Option D is wrong because Type 7 LSAs are used in NSSA areas for external routes; 'default-information originate' generates a Type 5 LSA in normal areas, and Type 7 only applies within NSSAs when configured differently.

814
MCQhard

A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco routers. The VPN tunnel is up, but traffic from the local LAN to the remote LAN is not passing. The administrator verifies that the crypto ACLs match on both peers and that routing is correct. Which of the following is the most likely cause?

A.The transform set is misconfigured with mismatched encryption algorithms.
B.The crypto map is applied to the wrong interface.
C.The IPsec SA lifetime is set to a lower value than the ISAKMP SA lifetime.
D.NAT is translating the traffic before it is encrypted, causing the IPsec peer to drop the packets.
AnswerD

If NAT is applied to the outbound interface before the crypto map, the source IP of the packets may be translated to the router's public IP, which does not match the crypto ACL. The IPsec peer will then drop the packets because they do not match the expected source subnet. This is a common issue when NAT and IPsec are configured on the same interface. The solution is to configure NAT exemption for the VPN traffic.

Why this answer

When NAT and IPsec are configured on the same router, outbound traffic may be translated by NAT before it is encrypted. If the translated source address does not match the crypto ACL, the remote peer will drop the packets because they do not match the interesting traffic. The tunnel remains up because Phase 1 and Phase 2 SAs are established, but data traffic fails.

The fix is to configure a NAT exemption (deny statement) for the VPN traffic in the NAT ACL.

Exam trap

The trap here is assuming that a successful tunnel establishment guarantees data flow; NAT can silently break IPsec by altering packets before encryption.

815
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip sla statistics 2 Round Trip Time (RTT) for Index 2 Latest RTT: No connection Latest RTT (milliseconds): No connection Latest RTT (microseconds): No connection Number of successes: 0 Number of failures: 100 Operation time to live: Forever Output: No connection Based on this output, which statement is correct?

A.The IP SLA operation is working correctly but the RTT is too high to measure.
B.The target device is not responding to ICMP echo requests, or there is a routing problem.
C.The IP SLA operation has been manually disabled.
D.The IP SLA responder is misconfigured on the source router.
AnswerB

Zero successes against 100 failures, with "No connection" reported, means no probe ever completed. The target is either not answering ICMP echo requests or is unreachable due to a routing fault, matching the stated symptom exactly.

Why this answer

The output shows 'No connection' for RTT and 'Output: No connection'. This indicates that the IP SLA operation cannot reach the target. The 100 failures confirm this.

This is a clear sign of a connectivity issue.

816
MCQhard

Management traffic is being dropped. Router R1 has: access-list 100 deny ip any any log, applied to VTY lines. Remote access via SSH fails, but console works. What is the root cause?

A.The ACL should permit SSH before the deny statement.
B.The VTY lines require transport input ssh, but the ACL is irrelevant.
C.The ACL is applied to the wrong interface.
D.The log keyword causes performance issues, not drops.
AnswerA

The ACL ends with an implicit or explicit deny, and no permit for TCP port 22 precedes it, so SSH traffic to the VTY lines is dropped. Console access bypasses VTY line ACLs, which is why it still works. Adding a permit for SSH before the deny resolves the failure.

Why this answer

The ACL `access-list 100 deny ip any any log` applied to VTY lines denies all IP traffic, including SSH, before any permit statement can match. Since SSH traffic is denied, remote access fails. The correct fix is to add a `permit tcp any any eq 22` statement before the deny to allow SSH management traffic.

Exam trap

The trap here is that candidates often think the ACL is applied to an interface (Option C) or that the `log` keyword causes the problem, when in fact the issue is the order of ACL entries—specifically, the missing permit for SSH before the global deny.

How to eliminate wrong answers

Option B is wrong because the VTY lines do require `transport input ssh` for SSH access, but the ACL is directly relevant—it is the cause of the drops, and without a permit for SSH, even with correct transport settings, traffic is denied. Option C is wrong because the ACL is correctly applied to VTY lines (using `access-class`), not to an interface; applying it to an interface would affect transit traffic, not management traffic. Option D is wrong because the `log` keyword does not cause drops; it only generates log messages for matched packets, and the drops are due to the `deny` action itself.

817
MCQmedium

Router R4 has the following configuration: !--- R4 configuration route-map SETTAG permit 10 match tag 100 set tag 200 ! route-map SETTAG permit 20 ! router bgp 65100 neighbor 10.0.0.1 route-map SETTAG in ! What is the effect of this configuration?

A.All routes from neighbor 10.0.0.1 are permitted; routes with tag 100 have their tag changed to 200.
B.Routes with tag 100 are denied; all other routes are permitted.
C.Only routes with tag 100 are permitted; all other routes are denied.
D.The route-map is misconfigured because sequence 20 has no match statement; it should have a match any statement.
AnswerA

Route-map entries are evaluated in sequence, so permit 10 matches tag 100 and rewrites it to 200, while permit 20 has no match clause and therefore permits every remaining route from 10.0.0.1 unchanged. Both entries permit, so no routes are dropped.

Why this answer

The route-map SETTAG has two sequences: sequence 10 matches tag 100 and sets tag 200, while sequence 20 has no match statement, which acts as a permit any. Therefore, all routes from neighbor 10.0.0.1 are permitted, and routes with tag 100 have their tag changed to 200.

Exam trap

300-410 often tests the misconception that a route-map sequence without a match statement is invalid or denies traffic, when it actually permits all unmatched routes.

How to eliminate wrong answers

Option B is wrong because there is no deny statement in the route-map; sequence 10 permits matched routes after setting the tag, and sequence 20 permits all others. Option C is wrong because sequence 20 permits all routes that do not match tag 100, so not only tag 100 routes are permitted. Option D is wrong because a route-map sequence with no match statement is valid and matches all routes — it does not require an explicit 'match any' statement.

818
MCQeasy

A network engineer runs the following command on Router R1: R1# show route-map TEST route-map TEST, permit, sequence 10 Match clauses: ip address (access-lists): 10 Set clauses: metric 50 route-map TEST, deny, sequence 20 Match clauses: ip address (access-lists): 20 Set clauses: Based on this output, what is the effect of this route-map when applied to a redistribution command?

A.All routes are redistributed with metric 50.
B.Routes matching ACL 10 are redistributed with metric 50; routes matching ACL 20 are denied; all other routes are also denied.
C.Routes matching ACL 20 are redistributed with default metric.
D.The route-map has no effect because set clauses are missing in sequence 20.
AnswerB

Sequence 10 permits ACL 10 matches and sets metric 50. Sequence 20 denies ACL 20 matches. Because an implicit deny terminates any route-map lacking a matching permit statement, all remaining routes are denied, satisfying the question's redistribution scenario.

Why this answer

Route-map TEST processes sequences in order. Sequence 10 permits routes matching ACL 10 and sets their metric to 50. Sequence 20 denies routes matching ACL 20.

Since there is no explicit permit for other routes, the implicit deny at the end of the route-map denies all unmatched routes. Thus, only routes matching ACL 10 are redistributed with metric 50.

Exam trap

Cisco often tests the implicit deny at the end of a route-map, leading candidates to forget that unmatched routes are denied, not permitted with default values.

How to eliminate wrong answers

Option A is wrong because not all routes are redistributed with metric 50; only routes matching ACL 10 are permitted and get metric 50, while routes matching ACL 20 are denied and all other routes are implicitly denied. Option C is wrong because routes matching ACL 20 are denied (sequence 20 is deny), not redistributed with any metric. Option D is wrong because a missing set clause in a deny sequence does not affect the route-map's operation; the deny action is still applied, and the implicit deny at the end handles unmatched routes.

819
MCQhard

What is the default number of packets sent per IP SLA UDP Jitter operation?

A.1
B.10
C.20
D.100
AnswerB

Cisco IP SLA UDP Jitter operations transmit 10 packets per operation by default, giving the sample needed to compute delay, jitter and packet loss statistics. The frequency parameter controls how often the operation runs, not the packet count.

Why this answer

The default number of packets sent per IP SLA UDP Jitter operation is 10. This is defined in the Cisco IOS IP SLA configuration, where the 'udp-jitter' operation type uses a default packet count of 10 for each probe. The jitter operation sends these packets at a configurable interval (default 20 ms) to measure delay, jitter, and packet loss.

Exam trap

300-410 often tests the default parameters of IP SLA operations, and candidates frequently confuse the default packet count for UDP jitter (10) with that of other operations like ICMP jitter (20) or with commonly configured values (100).

How to eliminate wrong answers

Option A is wrong because 1 packet is insufficient to calculate jitter, which requires multiple packets to measure delay variation; the default is not 1. Option C is wrong because 20 is the default number of packets for some other IP SLA operations (like ICMP jitter) but not for UDP jitter. Option D is wrong because 100 is a common user-configured value for more granular measurements, but it is not the default.

820
MCQmedium

A network engineer runs the following command on Router R1: R1# show crypto ipsec sa peer 10.1.1.2 interface: Tunnel0 Crypto map tag: VPN-MAP, local addr 10.1.1.1 protected vrf: (none) local ident (addr/mask/prot/port): (10.1.1.0/255.255.255.0/0/0) remote ident (addr/mask/prot/port): (192.168.1.0/255.255.255.0/0/0) current_peer 10.1.1.2 port 500 PERMIT, flags={origin_is_acl,} #pkts encaps: 100, #pkts encrypt: 100, #pkts digest: 100 #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0 #send errors 0, #recv errors 0 Based on this output, what is the problem?

A.The tunnel is working correctly; all packets are being encrypted and decrypted.
B.The remote peer is not sending traffic back; check routing on the remote router.
C.The local crypto ACL is misconfigured; it is not matching traffic.
D.The IPsec SA is not established; the tunnel is down.
AnswerB

Encapsulation counters increment while decapsulation stays at zero, proving R1 sends ESP but receives nothing. The tunnel and ACLs are fine; the remote peer is either not routing return traffic into the tunnel or lacks a matching policy, so its routing must be checked.

Why this answer

The outbound packet count (encaps) is 100, but inbound (decaps) is 0. This suggests that traffic is being sent through the tunnel but no responses are being received, possibly due to a routing issue on the remote side or a firewall blocking return traffic.

821
MCQhard

An engineer configures unicast Reverse Path Forwarding (uRPF) in strict mode on the outside interface of a router that terminates an IPsec site-to-site VPN. After the configuration, the VPN tunnel establishes, but traffic from the remote site is not forwarded correctly. The engineer verifies that the IPsec tunnel is up and that the routing table has the correct routes. What is the most likely explanation?

A.The IPsec tunnel uses transport mode, which does not encapsulate the original source IP, causing uRPF to see the remote router's physical IP as the source.
B.The return route for the remote site's physical IP points to the tunnel interface, but the packet arrives on the physical interface, so uRPF drops it because the source IP is not reachable via the incoming interface.
C.The uRPF configuration includes the 'allow-default' option, which allows packets with a default route, but the remote site's IP is not in the default route.
D.The IPsec transform set uses ESP with authentication, which changes the source IP of the packet.
AnswerB

The correct issue is a reverse-path forwarding mismatch on the physical interface. After decryption, the inner packet's source is the remote site's physical IP, and it arrives on the physical interface, such as GigabitEthernet0/0. Strict unicast RPF verifies that the route back to that source traverses the same physical interface; if the best route to the remote router's physical IP is via the tunnel interface, the source is considered asymmetric, and the packet is dropped. Thus, uRPF rejects the packet because the incoming interface is not the interface used to reach the source IP.

Why this answer

In strict mode, uRPF checks that the source IP address of an incoming packet is reachable via the exact interface on which the packet arrived. For IPsec site-to-site VPN traffic, the encapsulated (original) packet arrives on the physical outside interface, but the routing table's return route for the remote site's physical IP (the tunnel endpoint) points to the tunnel interface (e.g., a virtual tunnel interface or crypto map). Because the source IP is not reachable via the physical incoming interface, uRPF drops the packet, even though the IPsec tunnel is up and the routes are correct.

Exam trap

Cisco often tests the subtle interaction between uRPF strict mode and IPsec VPNs, where candidates mistakenly think the tunnel mode or encryption causes the issue, rather than the interface-specific reverse path check.

How to eliminate wrong answers

Option A is wrong because transport mode does not change the source IP of the original packet; it only encapsulates the IP payload, and uRPF checks the original source IP, not the outer IP header. Option C is wrong because the 'allow-default' option permits packets whose source IP matches a default route, but the remote site's IP is typically a specific address, not a default route, and the core issue is interface mismatch, not default route coverage. Option D is wrong because ESP with authentication (ESP auth) does not alter the source IP address of the packet; it only adds an authentication trailer to the ESP payload, leaving the IP header unchanged.

822
MCQhard

A network engineer runs the following command on Router R1: R1# show ip bgp neighbors 10.1.1.1 advertised-routes BGP table version is 10, local router ID is 1.1.1.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.0.0.0/8 0.0.0.0 0 32768 i *> 10.1.0.0/16 0.0.0.0 0 32768 i *> 10.1.1.0/24 0.0.0.0 0 32768 i *> 10.1.2.0/24 0.0.0.0 0 32768 i Based on this output, what is a problem with the BGP advertisements?

A.The router is not advertising any routes.
B.The router is advertising overlapping prefixes, including both summary and specific routes.
C.The router is only advertising the summary route.
D.The router is using incorrect next-hop.
AnswerB

Advertising both 10.0.0.0/8 and its more-specific components (10.1.0.0/16, 10.1.1.0/24, 10.1.2.0/24) creates overlapping prefixes. Receivers will prefer the longest match, so the /8 summary is effectively shadowed, wasting table space and risking inconsistent forwarding. Route aggregation or suppression of the specifics is required.

Why this answer

The output shows that R1 is advertising four prefixes: 10.0.0.0/8, 10.1.0.0/16, 10.1.1.0/24, and 10.1.2.0/24. These are overlapping because 10.0.0.0/8 encompasses 10.1.0.0/16, which in turn encompasses the two /24s. Advertising both summary and more-specific routes can cause suboptimal routing and increase BGP table size.

The correct answer identifies this as the problem.

Exam trap

The trap here is that candidates might see the next-hop 0.0.0.0 and incorrectly assume it is a problem, or they might overlook the overlapping prefixes because the output looks normal at first glance. 300-410 often tests the ability to interpret BGP show command output and identify subtle configuration issues like missing 'summary-only'.

How to eliminate wrong answers

Option A is wrong because the output clearly lists four networks under the 'Network' column, indicating that routes are being advertised. Option C is wrong because the output includes not only the summary route 10.0.0.0/8 but also the more specific routes 10.1.0.0/16, 10.1.1.0/24, and 10.1.2.0/24. Option D is wrong because the next-hop for all routes is 0.0.0.0, which is expected for locally originated BGP routes (weight 32768) and is not an error.

823
MCQmedium

A network engineer runs the following command to troubleshoot a Flexible NetFlow issue: R1# show flow monitor FLOW-MONITOR-1 cache format table Cache type: Normal Cache size: 1000 Current entries: 25 High Watermark: 50 Flows added: 1234 Flows aged: 1209 - Active timeout ( 1800 secs): 100 - Inactive timeout ( 15 secs): 1100 - Event aged: 9 - Watermark aged: 0 - Emergency aged: 0 What does the output indicate?

A.The cache is experiencing watermark aging, indicating memory pressure.
B.Most flows are being aged due to the active timeout, suggesting long-lived flows.
C.The majority of flows are being aged due to the inactive timeout, indicating many short-lived flows.
D.Emergency aging is occurring, which means the cache is full.
AnswerC

Inactive timeout accounts for 1100 of 1209 aged flows, so most entries expire after just 15 seconds of silence. That dominance directly evidences numerous short-lived flows, matching the inactive timeout constraint rather than active timeout or watermark ageing.

Why this answer

The output shows the current state of the Flexible NetFlow cache. The high number of flows aged due to inactive timeout (1100 out of 1209) indicates that most flows are short-lived. The cache is not full (25 out of 1000 entries used), and no watermark or emergency aging has occurred.

This is normal for traffic with many brief connections.

824
Multi-Selectmedium

A network administrator is configuring a Cisco IOS router to support MPLS Layer 3 VPN. The administrator needs to enable the provider edge (PE) router to exchange VPNv4 routes with other PE routers. Which two configurations are required on the PE router to enable MP-BGP for VPNv4? (Choose two.)

Select 2 answers
A.Enable MPLS LDP on the core-facing interfaces.
B.Configure a route target (RT) under the VRF definition.
C.Configure a route distinguisher (RD) under the VRF definition.
D.Activate the VPNv4 address family with 'address-family vpnv4' and activate the neighbor.
E.Enable BGP with the 'router bgp' command and configure the remote PE as a neighbor.
AnswersD, E

In Cisco IOS, to exchange VPNv4 routes, you must enter the VPNv4 address family configuration mode using 'address-family vpnv4' and then activate the neighbor with 'neighbor <ip> activate'. This enables the BGP session to carry VPNv4 routes, which include the route distinguisher and extended communities.

Why this answer

To enable MP-BGP for VPNv4 on a PE router, you must first configure a BGP session with the remote PE using 'router bgp' and 'neighbor' commands. Then, you must activate the VPNv4 address family with 'address-family vpnv4' and activate the neighbor. These two steps allow the exchange of VPNv4 routes.

Other configurations like RD, RT, and LDP are important for MPLS VPN but not for enabling MP-BGP itself.

Exam trap

The trap here is confusing the steps to enable MP-BGP with the overall MPLS VPN configuration, such as RD, RT, or LDP, which are not part of the MP-BGP enabling process.

825
MCQeasy

What is the default OSPF hello interval on a point-to-point serial interface?

A.10 seconds
B.30 seconds
C.40 seconds
D.20 seconds
AnswerA

OSPF sets the hello interval to 10 seconds on point-to-point serial interfaces, matching the default for broadcast and point-to-point networks. This satisfies the stem's constraint: the question asks specifically about a point-to-point serial link, not NBMA or non-broadcast, where the interval would instead be 30 seconds.

Why this answer

The default OSPF hello interval on a point-to-point serial interface is 10 seconds. This is because OSPF hello intervals are determined by the network type, and point-to-point networks use a 10-second hello interval. This matches the default for broadcast networks, while non-broadcast and point-to-multipoint networks use 30 seconds.

Exam trap

300-410 often tests the default OSPF hello intervals for different network types, and candidates frequently confuse the 10-second interval of point-to-point and broadcast with the 30-second interval of non-broadcast and point-to-multipoint.

How to eliminate wrong answers

Option B is wrong because 30 seconds is the default hello interval for non-broadcast and point-to-multipoint network types, not point-to-point. Option C is wrong because 40 seconds is not a standard OSPF hello interval for any common network type; it might be confused with other timers. Option D is wrong because 20 seconds is not a default OSPF hello interval; it is sometimes used in other protocols or as a custom value.

Page 10

Page 11 of 19

Page 12