Courseiva

Cisco CCNP ENARSI 300-410 (300-410) — Questions 826–900

1401 questions total · 19pages · All types, answers revealed

Page 11

Page 12 of 19

Page 13
826
MCQmedium

A network engineer is troubleshooting a router that is experiencing intermittent packet loss. The engineer checks the logs and sees that an EEM applet is being triggered frequently. The applet is configured to run a script that modifies the routing table. The engineer suspects the applet is causing the packet loss. What should the engineer do to verify the root cause?

A.Check the EEM applet's script for errors.
B.Use the 'show event manager statistics' command to see how often the applet is triggered.
C.Temporarily disable the EEM applet and monitor the packet loss.
D.Increase the logging level to debug to see more details.
AnswerC

Disabling the EEM applet isolates the suspected trigger, so any change in packet loss confirms or eliminates it as the cause. This controlled test satisfies the need to verify the root cause rather than merely correlating frequent applet execution with the intermittent loss.

Why this answer

To verify if the EEM applet is causing the packet loss, the engineer should temporarily disable the applet and monitor whether the packet loss stops. This isolation test directly correlates the applet's activity with the symptom. If packet loss ceases when the applet is disabled, it confirms the applet as the root cause.

Exam trap

The trap is choosing diagnostic commands that provide information but do not definitively prove causation, whereas the best method is to isolate the suspected cause by disabling it.

How to eliminate wrong answers

Option A is wrong because checking the script for errors might reveal syntax issues but does not confirm that the applet is causing the packet loss; the script could be error-free yet still disruptive. Option B is wrong because seeing how often the applet is triggered provides frequency data but does not establish causation; frequent triggering alone doesn't prove it causes packet loss. Option D is wrong because increasing logging to debug may provide more details but could also add overhead and not directly test the applet's impact.

827
Drag & Drophard

Drag and drop the steps to troubleshoot VRF-Lite adjacency or connectivity failures into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Start by checking if the VRF is defined correctly with show vrf. Then verify interface assignment to the correct VRF. Next, confirm that the IP address on the interface is in the VRF context.

After that, test basic connectivity with ping using the VRF keyword. Finally, examine routing protocol adjacency status within the VRF.

828
Multi-Selecthard

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS-XE router to protect the route processor from excessive traffic. The administrator creates a class-map to match all management traffic (SSH, SNMP, TACACS+) and a policy-map to police that traffic to 1 Mbps. After applying the service-policy to the control-plane, the administrator notices that some legitimate SNMP polling is being dropped. Which two actions can the administrator take to resolve this issue while maintaining protection against DoS attacks? (Choose two.)

Select 2 answers
A.Increase the police rate for the management class to accommodate the SNMP polling volume.
B.Remove the police action and use a bandwidth guarantee instead.
C.Apply the service-policy to the data plane interfaces instead of the control plane.
D.Enable SNMPv3 authentication to reduce the volume of SNMP traffic.
E.Configure a separate class-map for SNMP and assign a higher police rate to that class.
AnswersA, E

Increasing the policer rate allows more management traffic to pass while still enforcing a limit, providing protection against excessive traffic. This is a valid tuning step when legitimate traffic exceeds the configured rate. It maintains CoPP's protective function while reducing false positives. This action directly addresses the drops without disabling protection.

Why this answer

The legitimate SNMP polling is being dropped because the policer rate is too low for the combined management traffic. Increasing the overall rate or creating a separate class with a higher rate for SNMP will allow legitimate traffic while still policing excess. Both actions maintain protection against DoS by keeping policing in place.

Exam trap

The trap here is thinking that any change to CoPP must involve removing or disabling policing to stop drops.

829
MCQmedium

A network engineer runs the following command on Router R1: R1# show ipv6 nd raguard policy Interface Policy Role State Gi0/0/0 RA_GUARD router ACTIVE Gi0/0/1 RA_GUARD host ACTIVE Gi0/0/2 (default) host ACTIVE Based on this output, which statement is correct?

A.Interface Gi0/0/0 is allowed to send Router Advertisements.
B.Interface Gi0/0/1 is allowed to send Router Advertisements.
C.Interface Gi0/0/2 is allowed to send Router Advertisements.
D.All interfaces are blocked from sending Router Advertisements.
AnswerA

Gi0/0/0 is configured with the router role, so RA guard permits Router Advertisement and redirect messages to ingress there. The host role on Gi0/0/1 and the default host policy on Gi0/0/2 block RAs, satisfying the requirement that only the uplink-facing interface accepts advertisements from the legitimate router.

Why this answer

The 'show ipv6 nd raguard policy' output shows that interface Gi0/0/0 is configured with the RA_GUARD policy in the 'router' role and is ACTIVE. In IPv6 RA Guard, a port in the 'router' role is explicitly permitted to send Router Advertisements (RAs), while ports in the 'host' role are blocked from sending RAs. Therefore, only Gi0/0/0 is allowed to send RAs, making option A correct.

Exam trap

Cisco often tests the misconception that all interfaces with an active RA Guard policy are blocked, but the key differentiator is the 'role' (router vs. host), not just the policy being active.

How to eliminate wrong answers

Option B is wrong because interface Gi0/0/1 has the RA_GUARD policy with the 'host' role, which blocks it from sending Router Advertisements. Option C is wrong because interface Gi0/0/2 uses the default policy with the 'host' role, which also blocks it from sending Router Advertisements. Option D is wrong because interface Gi0/0/0 is in the 'router' role and is allowed to send Router Advertisements, so not all interfaces are blocked.

830
MCQeasy

A network engineer runs the following command to troubleshoot an IPsec Site-to-Site VPN issue: R1# show crypto isakmp sa detail IPv4 Crypto ISAKMP SA C-id Local Remote I-VRF Status Encr Hash Auth DH Lifetime Cap. 1001 192.168.1.1 192.168.2.2 ACTIVE des sha pre 2 23:59:21 1002 192.168.1.1 192.168.2.2 ACTIVE 3des sha pre 2 23:58:15 IPv6 Crypto ISAKMP SA What does this output indicate?

A.The IPsec VPN is functioning correctly with two redundant ISAKMP SAs.
B.There are two active ISAKMP SAs between the peers, which suggests a configuration error such as multiple ISAKMP policies or aggressive mode issues.
C.The ISAKMP SA is using DES encryption, which is weak and should be upgraded.
D.The ISAKMP SA lifetime is about 24 hours, which is the default.
AnswerB

Two ACTIVE ISAKMP SAs for the same peer pair indicate duplicate Phase 1 negotiations, typically caused by mismatched or multiple ISAKMP policies, or aggressive mode behaviour. This satisfies the stem's constraint of identifying a configuration error from the duplicated SA entries.

Why this answer

The output shows two active ISAKMP SAs between the same peers (192.168.1.1 and 192.168.2.2) with different encryption algorithms (DES and 3DES). Under normal operation, only one ISAKMP SA should exist per peer pair. Having multiple SAs indicates a configuration error, such as multiple ISAKMP policies that both match, or aggressive mode causing duplicate SAs.

This is not a sign of redundancy; ISAKMP SAs are not redundant by design.

Exam trap

Cisco often tests the misconception that multiple active ISAKMP SAs between the same peers are normal or provide redundancy, when in fact they indicate a configuration error that can break the VPN tunnel.

How to eliminate wrong answers

Option A is wrong because ISAKMP SAs are not designed for redundancy; having two active SAs between the same peers indicates a misconfiguration, not a functional redundancy feature. Option C is wrong because while DES is indeed weak, the output shows both DES and 3DES SAs, and the question asks what the output indicates—the core issue is the duplicate SAs, not the encryption strength. Option D is wrong because the lifetimes shown (23:59:21 and 23:58:15) are close to 24 hours, which is the default for ISAKMP, but this is not the key finding; the presence of two SAs is the abnormal condition.

831
MCQmedium

Which OSPF LSA type is used to advertise external routes and is flooded throughout the entire OSPF domain?

A.Type 1 (Router LSA)
B.Type 3 (Summary LSA)
C.Type 4 (ASBR Summary LSA)
D.Type 5 (AS-external LSA)
AnswerD

Type 5 AS-external LSAs advertise routes redistributed into OSPF from outside the domain, such as from BGP or static routes. They are flooded throughout the entire OSPF domain, except into stub areas, satisfying the stem's requirement for domain-wide external route advertisement.

Why this answer

Type 5 (AS-external LSA) is correct because it is originated by an ASBR to advertise external routes redistributed into OSPF from another routing domain. These LSAs are flooded throughout the entire OSPF domain, including all areas, and their flooding scope is AS-wide, as defined in RFC 2328.

Exam trap

Cisco often tests the distinction between Type 3 and Type 5 LSAs, where candidates mistakenly think Type 3 LSAs carry external routes because they are also 'summary' LSAs, but Type 3 LSAs only carry inter-area routes, not external routes.

How to eliminate wrong answers

Option A is wrong because Type 1 (Router LSA) describes the state and cost of a router's interfaces within a single area and is flooded only within that area, not the entire OSPF domain. Option B is wrong because Type 3 (Summary LSA) is generated by an ABR to advertise inter-area routes and is flooded only within a single area, not the entire domain. Option C is wrong because Type 4 (ASBR Summary LSA) is also generated by an ABR to advertise the location of an ASBR to other areas, but its flooding scope is limited to a single area, not the entire OSPF domain.

832
MCQmedium

A network engineer is configuring Policy-Based Routing (PBR) on a Cisco IOS XE router. The engineer wants to forward traffic matching a specific ACL to a next-hop IP address, but only if the next-hop is reachable. Which command should be used in the route map to specify the next-hop and enable tracking?

A.set ip next-hop 10.1.1.1
B.set ip default next-hop 10.1.1.1
C.set ip next-hop verify-availability 10.1.1.1 1 track 1
D.set ip next-hop recursive 10.1.1.1
AnswerC

The set ip next-hop verify-availability command allows PBR to verify the reachability of the next-hop using a tracking object. The syntax includes the next-hop IP, a sequence number, and the track keyword followed by the tracking object number. If the tracked object is up, the next-hop is used; if down, the route map is not applied, and normal routing takes over. This meets the requirement of forwarding only if the next-hop is reachable.

Why this answer

To conditionally forward traffic based on next-hop reachability in PBR, the set ip next-hop verify-availability command is used. It references a tracking object that monitors the next-hop. If the track is up, the next-hop is used; if down, the route map is skipped, and normal routing applies.

This provides the required conditional forwarding.

Exam trap

The trap here is assuming that set ip next-hop alone will verify reachability; it does not, and requires the verify-availability keyword with a track object.

833
MCQmedium

A network engineer runs the following command to troubleshoot DHCPv6 relay on router R1: R1# debug ipv6 dhcp relay Output: IPv6 DHCP relay: Received SOLICIT message from FE80::1 on GigabitEthernet0/0 IPv6 DHCP relay: Forwarding SOLICIT to server 2001:DB8:2::1 via GigabitEthernet0/1 IPv6 DHCP relay: Received ADVERTISE message from server 2001:DB8:2::1 via GigabitEthernet0/1 IPv6 DHCP relay: Forwarding ADVERTISE to client FE80::1 via GigabitEthernet0/0 IPv6 DHCP relay: Received REQUEST message from FE80::1 on GigabitEthernet0/0 IPv6 DHCP relay: Forwarding REQUEST to server 2001:DB8:2::1 via GigabitEthernet0/1 IPv6 DHCP relay: Received REPLY message from server 2001:DB8:2::1 via GigabitEthernet0/1 IPv6 DHCP relay: Forwarding REPLY to client FE80::1 via GigabitEthernet0/0 What does this output indicate?

A.The DHCPv6 relay agent is not functioning because messages are not being forwarded.
B.The DHCPv6 relay agent is successfully forwarding messages between the client and server.
C.The DHCPv6 server is unreachable because no REPLY is received.
D.The DHCPv6 client is using a global unicast address as its link-local address.
AnswerB

The debug trace shows SOLICIT and ADVERTISE, then REQUEST and REPLY, each relayed in both directions between client FE80::1 and server 2001:DB8:2::1. Complete four-message exchange confirms the relay agent is forwarding correctly, satisfying the troubleshooting scenario.

Why this answer

The debug output shows a complete DHCPv6 four-message exchange (SOLICIT-ADVERTISE-REQUEST-REPLY) being relayed between the client (FE80::1) and the server (2001:DB8:2::1). Each message is received on one interface and forwarded out the other, confirming the relay agent is functioning correctly. Therefore, option B is correct.

Exam trap

Cisco often tests the ability to interpret debug output by showing a successful message flow, leading candidates to incorrectly assume a failure because they expect an error message or because they misread the link-local address as a global address.

How to eliminate wrong answers

Option A is wrong because the debug output clearly shows messages being forwarded in both directions, proving the relay agent is functioning. Option C is wrong because the output includes a REPLY message from the server, indicating the server is reachable and responding. Option D is wrong because FE80::1 is a link-local address (fe80::/10), not a global unicast address, and the client correctly uses it as its link-local address for DHCPv6 communication.

834
MCQmedium

A network engineer is configuring OSPFv3 on a dual-stack router. The router must form an adjacency with a neighbor over a link that supports both IPv4 and IPv6. The interface is configured with 'ipv6 ospf 1 area 0' and the router ID is manually set to 10.1.1.1. After applying the configuration, the engineer notices that the OSPFv3 adjacency remains in EXSTART state. What is the most likely cause?

A.The router ID is not unique in the OSPFv3 domain.
B.The OSPFv3 process is not configured with an IPv6 address family.
C.The neighbor router is using a different OSPFv3 process ID.
D.The IPv6 MTU on the interface does not match the neighbor's interface MTU.
AnswerD

In OSPFv3, the EXSTART state is reached after the neighbor is seen in the Hello packet, but before database description packets are exchanged. A mismatch in interface MTU prevents the routers from agreeing on the initial database description sequence, causing the adjacency to remain in EXSTART. This is a common issue when IPv6 MTU is not consistent across the link, especially with tunneling or different link types.

Why this answer

The EXSTART state in OSPFv3 indicates that the routers have exchanged Hello packets and are attempting to negotiate the master/slave relationship for database description exchange. A mismatch in interface MTU prevents the successful exchange of database description packets, leaving the adjacency stuck in EXSTART. Ensuring consistent MTU on both sides resolves the issue.

Exam trap

The trap here is assuming that EXSTART is caused by a router ID conflict or process ID mismatch, when it is typically an MTU mismatch.

835
MCQmedium

A network engineer configures a Cisco IOS router with the command 'ip dhcp excluded-address 10.10.10.1 10.10.10.20'. The DHCP pool is defined as 'ip dhcp pool LAN' with network 10.10.10.0 /24. Which statement accurately describes the effect of the excluded-address command?

A.The router will reserve addresses 10.10.10.1 through 10.10.10.20 for DHCP clients only, preventing static assignment on other devices.
B.The router will exclude the entire 10.10.10.0 /24 subnet from DHCP, so no addresses will be assigned from that pool.
C.The router will not assign addresses 10.10.10.1 through 10.10.10.20 to DHCP clients, but those addresses can still be manually configured on other devices.
D.The router will assign addresses 10.10.10.1 through 10.10.10.20 only to clients that match a specific MAC address in a manual binding.
AnswerC

The excluded-address range prevents the DHCP server from offering those specific IP addresses in the pool. It does not reserve them for any particular device; they remain available for static assignment. This is commonly used to avoid conflicts with gateways, servers, or printers that are manually configured.

Why this answer

The excluded-address command removes a range of addresses from dynamic DHCP allocation, ensuring they are not offered to clients. Those addresses can still be statically configured on other devices, such as routers, switches, or servers. This prevents IP address conflicts while allowing manual assignment where needed.

Exam trap

The trap here is assuming that excluded addresses are reserved for DHCP clients or that they become unavailable for static configuration.

836
MCQhard

A network engineer is troubleshooting an MPLS L3VPN where customer routes are not being propagated between PE routers. The engineer verifies that the MP-BGP session between the PEs is established and that VRFs are configured correctly. Which of the following is the most likely cause for the missing routes?

A.The route targets are not properly configured for import/export.
B.The MPLS LDP session between the PEs is down.
C.The PE routers are not configured with unique route distinguishers.
D.The BGP session is not configured with the correct address-family.
AnswerA

In MPLS L3VPN, route targets (RTs) control the import and export of VPNv4 routes between VRFs. If the export RT on one PE does not match the import RT on the remote PE, the routes will not be imported into the remote VRF, even though the MP-BGP session is up and the routes are exchanged. This is a common misconfiguration and directly causes missing customer routes.

Why this answer

In MPLS L3VPN, route targets are extended BGP communities that determine which VRFs import and export routes. For a route to be installed in a remote VRF, the export RT attached to the route by the originating PE must match an import RT configured on the receiving PE's VRF. If they do not match, the route is discarded.

This is a frequent issue when VRFs are newly configured or when RTs are changed. Verifying RT configuration on both PEs is essential.

Exam trap

The trap here is assuming that an established MP-BGP session and correct VRF configuration guarantee route propagation, overlooking the role of route targets.

837
MCQhard

An engineer configures mutual redistribution between OSPF and EIGRP on a router. After a few minutes, the router's CPU spikes and routes start flapping. Which is the most likely explanation?

A.The redistribution is creating a routing loop because there is no route tagging or filtering to prevent re-redistribution.
B.The seed metric is not configured, so the routes are not redistributed.
C.The administrative distance is set too low, causing the router to prefer the wrong route.
D.The OSPF process ID is the same on both routers.
AnswerA

Without route tags or distribute-lists, each protocol re-advertises routes learned from the other, so prefixes oscillate between domains and never converge. The CPU spike and flapping stem from this mutual feedback loop, not from timers or metrics.

Why this answer

Mutual redistribution without route tagging or filtering causes the redistributed routes to be re-injected back into the original routing protocol, creating a routing loop. This loop leads to continuous route updates, CPU spikes, and route flapping as the router repeatedly processes and advertises the same prefixes.

Exam trap

Cisco often tests the concept that mutual redistribution inherently causes loops unless explicit filtering or tagging is applied, and candidates mistakenly focus on missing metrics or administrative distance instead of the re-redirection loop.

How to eliminate wrong answers

Option B is wrong because a missing seed metric would prevent redistribution from EIGRP into OSPF (OSPF requires a metric), but it would not cause a routing loop or flapping; the routes simply would not be redistributed. Option C is wrong because setting administrative distance too low could cause route preference issues but does not directly create the feedback loop of mutual redistribution; the core problem is re-redistribution, not AD. Option D is wrong because the OSPF process ID is locally significant and does not need to match between routers; mismatched process IDs do not cause redistribution loops or flapping.

838
MCQmedium

A network engineer runs the following command to troubleshoot an EIGRP issue: R1# show ip eigrp neighbors detail IP-EIGRP neighbors for process 100 H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num 0 10.1.2.2 Gi0/0 13 00:12:34 12 200 0 145 Version 12.4/1.2, Retrans: 0, Retries: 0, Prefixes: 5 Topology-ids from peer - 0 Stub Peer Advertising (CONNECTED STATIC) Routes Suppressing queries What does this output indicate?

A.The neighbor is a stub router that only advertises connected and static routes, and it does not participate in query propagation.
B.The neighbor is a normal EIGRP peer that forwards all routes and queries.
C.The neighbor is not forming an adjacency due to a version mismatch.
D.The neighbor is using a different autonomous system number.
AnswerA

The line "Stub Peer Advertising (CONNECTED STATIC) Routes" confirms the peer is configured as a stub router, and "Suppressing queries" shows it will not propagate queries. This satisfies the scenario's requirement to identify stub behaviour and query suppression.

Why this answer

The output shows 'Stub Peer Advertising (CONNECTED STATIC) Routes' and 'Suppressing queries', which indicates the neighbor is configured as an EIGRP stub router. A stub router advertises only connected and static routes (as specified) and does not participate in query propagation, meaning it will not forward queries from other routers, reducing the query domain and improving convergence.

Exam trap

Cisco often tests the distinction between a normal EIGRP peer and a stub peer by hiding the 'Suppressing queries' line in the output, leading candidates to overlook the stub behavior and incorrectly assume the peer is a normal router forwarding all routes.

How to eliminate wrong answers

Option B is wrong because the output explicitly shows 'Suppressing queries' and 'Stub Peer Advertising', which means the neighbor is not a normal EIGRP peer that forwards all routes and queries; normal peers do not suppress queries. Option C is wrong because the output shows 'Version 12.4/1.2', indicating a successful version match between the peers; a version mismatch would prevent adjacency formation and would not show neighbor details. Option D is wrong because the output shows 'IP-EIGRP neighbors for process 100', confirming both routers are using the same autonomous system number (100); a different AS would prevent adjacency.

839
MCQhard

Router R8 is configured with SNMP and IP SLA. The IP SLA operation sends SNMP traps to the NMS when a threshold is crossed. The configuration includes: ip sla 1, icmp-echo 192.168.1.1, threshold 100, timeout 1000, frequency 10, ip sla schedule 1 life forever start-time now, snmp-server enable traps ip sla. However, the NMS receives no traps when the threshold is crossed. The IP SLA operation shows 'Over threshold' in show ip sla statistics. What is the root cause?

A.The IP SLA operation is missing the 'ip sla reaction-configuration' command to trigger SNMP traps when the threshold is exceeded.
B.The NMS is not configured to receive IP SLA traps.
C.The SNMP community string is incorrect for trap sending.
D.The IP SLA operation is not scheduled correctly.
AnswerA

Thresholds alone only mark the operation as over threshold in statistics; SNMP traps require ip sla reaction-configuration with a reaction type such as timeout or threshold and the action of sending traps. Without it, no trap is generated despite the over-threshold state.

Why this answer

The 'ip sla reaction-configuration' command is required to define the condition (e.g., threshold violation) that triggers an SNMP trap. Without this command, the IP SLA operation can detect and report 'Over threshold' in statistics, but it has no mechanism to generate an SNMP trap to the NMS. The 'snmp-server enable traps ip sla' command only enables the router to send IP SLA traps globally; it does not link a specific reaction to the threshold event.

Exam trap

Cisco often tests the distinction between enabling SNMP traps globally ('snmp-server enable traps ip sla') and configuring the specific reaction that triggers those traps ('ip sla reaction-configuration'), leading candidates to overlook the missing reaction command.

How to eliminate wrong answers

Option B is wrong because the NMS's ability to receive traps is not configured on the router; the router's SNMP trap configuration (destination, community) is independent of the NMS's readiness. Option C is wrong because the SNMP community string for trap sending is not mentioned in the scenario, and the issue is specifically about the missing reaction-configuration, not authentication. Option D is wrong because the IP SLA operation is scheduled correctly with 'ip sla schedule 1 life forever start-time now', and the statistics show it is running and detecting the threshold crossing.

840
MCQmedium

Consider the following partial configuration on router R4: interface GigabitEthernet0/0 ip address 192.168.2.1 255.255.255.0 ipv6 address 2001:db8:1::1/64 ipv6 ospf 1 area 0 ! interface GigabitEthernet0/1 ip address 10.0.0.1 255.255.255.0 ipv6 address 2001:db8:2::1/64 ipv6 ospf 1 area 0 ! ipv6 router ospf 1 router-id 4.4.4.4 What is the effect of this configuration?

A.OSPFv3 will not form adjacencies because the router-id must be an IPv6 address.
B.OSPFv3 will only form adjacency on GigabitEthernet0/0 because the router-id is not configured under the interface.
C.OSPFv3 will form adjacencies on both interfaces as intended because the router-id is correctly set and OSPFv3 is enabled on each interface.
D.OSPFv3 will not form any adjacency because the network type is not specified.
AnswerC

OSPFv3 enables per interface via ipv6 ospf 1 area 0, and the router-id is explicitly set under ipv6 router ospf 1. Both GigabitEthernet interfaces therefore run OSPFv3 in area 0 and will form adjacencies as intended.

Why this answer

OSPFv3 (OSPF for IPv6) uses a 32-bit router-id, which can be an IPv4 address (like 4.4.4.4) or any arbitrary 32-bit value, and does not require an IPv6 address. The configuration enables OSPFv3 process 1 under the global 'ipv6 router ospf 1' command, sets the router-id, and activates OSPFv3 on both interfaces with 'ipv6 ospf 1 area 0', allowing adjacencies to form normally on both GigabitEthernet0/0 and GigabitEthernet0/1.

Exam trap

Cisco often tests the misconception that OSPFv3 requires an IPv6 router-id, when in fact it uses a 32-bit router-id (like an IPv4 address), and candidates may also incorrectly assume that OSPFv3 needs per-interface router-id configuration or explicit network type statements.

How to eliminate wrong answers

Option A is wrong because OSPFv3 does not require the router-id to be an IPv6 address; it uses a 32-bit router-id (typically an IPv4 address or a custom value), as defined in RFC 5340. Option B is wrong because the router-id is configured globally under the OSPFv3 process and does not need to be configured per interface; both interfaces will form adjacencies as long as OSPFv3 is enabled on them. Option D is wrong because OSPFv3 defaults to the broadcast network type on Ethernet interfaces, and no explicit network type specification is required for adjacency formation.

841
Multi-Selecthard

Which THREE symptoms indicate a BGP route dampening issue that is causing routes to be suppressed? (Choose THREE.)

Select 3 answers
A.The BGP neighbor state flaps between Established and Idle.
B.The show ip bgp command displays the route with a 'd' status code.
C.The route is present in the BGP table but missing from the IP routing table.
D.The show ip bgp dampened-paths command shows the suppressed routes.
E.The show ip prefix-list command indicates that routes are being filtered.
AnswersB, C, D

Dampening marks suppressed routes with the 'd' status code in the BGP table, distinguishing them from valid or history entries. Seeing 'd' confirms the prefix is dampened and withheld from advertisement until the penalty decays.

Why this answer

Option B is correct because in Cisco IOS the 'd' status code next to a prefix in 'show ip bgp' explicitly means the route is dampened (penalized and suppressed by BGP route dampening). Option C is correct because a dampened route remains in the BGP table but is not installed into the IP routing table (RIB), so it appears in BGP but is absent from 'show ip route'. Option D is correct because 'show ip bgp dampened-paths' is the dedicated command that lists suppressed/dampened prefixes along with their penalty values and reuse/flap timers.

Option A is not specific to dampening: neighbor state flapping between Established and Idle indicates a session/transport problem (e.g., hold-timer expiry, TCP failure), not route suppression. Option E is unrelated: 'show ip prefix-list' displays prefix-list configuration used for route filtering, which is a policy mechanism distinct from dampening.

Exam trap

The trap is confusing session-level flapping (neighbor up/down) with route-level dampening — candidates pick option A because 'flapping' appears in both, but dampening suppresses routes, not BGP sessions.

842
MCQeasy

A network engineer runs the following command to troubleshoot a Route Redistribution issue: R1# show ip route summary And sees the following output: Route Source Networks Subnets Replicates Overhead Memory (bytes) connected 2 0 0 0 512 static 1 0 0 0 256 ospf 1 5 0 0 0 1280 eigrp 100 3 0 0 0 768 bgp 65000 2 0 0 0 512 internal 1 0 0 0 256 Total 14 0 0 0 3584 What does this output indicate?

A.The router has 14 routes total, with OSPF contributing the most routes.
B.The router is not redistributing any routes because the counts are low.
C.BGP is the only protocol with external routes.
D.EIGRP has 3 routes, all of which are redistributed from OSPF.
AnswerA

The summary counts 14 total routes across all sources, and OSPF's five networks exceed EIGRP's three, BGP's two and the other entries. It confirms redistribution populated the routing table, though the zero Subnets column shows only classful networks are present.

Why this answer

The 'show ip route summary' output lists the number of routes per source: connected (2), static (1), OSPF 1 (5), EIGRP 100 (3), BGP 65000 (2), and internal (1), totaling 14 routes. OSPF contributes the most routes (5), which matches option A exactly. The 'Subnets', 'Replicates', and 'Overhead' columns are all zero, indicating no classful subnetting anomalies or replication overhead in this table.

Exam trap

300-410 often tests the misconception that route counts in 'show ip route summary' reveal redistribution relationships — candidates must remember the summary only counts routes per protocol and says nothing about their origin or redistribution path.

How to eliminate wrong answers

Option B is wrong because the output shows routes from multiple protocols (OSPF, EIGRP, BGP, static, connected), which proves redistribution or at least multi-protocol routing is occurring — low counts do not indicate absence of redistribution. Option C is wrong because the output does not distinguish internal vs external routes per protocol; BGP showing 2 routes does not mean they are the only external routes, and EIGRP/OSPF external routes would still be counted under their respective protocol totals. Option D is wrong because the output does not show route origins — EIGRP's 3 routes could be native, redistributed from OSPF, or from other sources; the summary only counts routes per protocol, not their provenance.

843
MCQhard

A network administrator is deploying IPv6 First Hop Security features on a Cisco Catalyst switch. The goal is to prevent rogue DHCPv6 servers from assigning addresses to clients. The administrator configures DHCPv6 Guard on the switch. Which additional configuration is necessary to ensure that DHCPv6 Guard operates correctly?

A.Apply an IPv6 access list to block DHCPv6 server traffic.
B.Enable RA Guard on all switch ports.
C.Enable IPv6 snooping globally.
D.Configure a DHCPv6 relay agent on the switch.
AnswerC

DHCPv6 Guard relies on IPv6 snooping to function. IPv6 snooping builds a binding table that tracks legitimate DHCPv6 servers and clients. Without IPv6 snooping enabled, DHCPv6 Guard cannot inspect DHCPv6 messages or enforce policies. Therefore, enabling IPv6 snooping globally is a prerequisite for DHCPv6 Guard to operate correctly and block rogue servers.

Why this answer

DHCPv6 Guard requires IPv6 snooping to be enabled because it uses the snooping binding table to validate DHCPv6 server messages. Without IPv6 snooping, DHCPv6 Guard cannot inspect or filter DHCPv6 packets. The other options either do not address the requirement or are unrelated features.

Thus, enabling IPv6 snooping globally is the necessary additional configuration.

Exam trap

The trap here is assuming that DHCPv6 Guard can operate independently, when it actually depends on IPv6 snooping.

844
MCQhard

An engineer configures a DMVPN Phase 2 network with IPsec protection. Spoke-to-spoke tunnels form, but traffic between spokes is not being forwarded directly; it still goes through the hub. The engineer verifies that NHRP registrations are successful and that the spoke-to-spoke IPsec sessions are established. What is the most likely explanation?

A.The hub router is not configured with the 'no ip split-horizon' command for EIGRP or the 'neighbor' command for OSPF, preventing spoke-to-spoke route propagation.
B.The IPsec transform set on the spokes uses different encryption algorithms, preventing the spoke-to-spoke tunnel from passing traffic.
C.The NHRP authentication string is mismatched between spokes, causing NHRP resolution to fail.
D.The spoke routers have a static default route pointing to the hub, overriding the dynamic routes.
AnswerA

In DMVPN Phase 2, the hub must disable split horizon (EIGRP) or use a network type that allows route propagation (OSPF) so that spokes learn each other's subnets. Without this, spokes only have a default route via the hub, so traffic goes through the hub.

Why this answer

In a DMVPN Phase 2 network, spoke-to-spoke traffic requires that each spoke learns the remote spoke's prefix via the hub. For EIGRP, the hub must disable split horizon with 'no ip split-horizon eigrp <as>' to propagate routes learned from one spoke to other spokes. Without this, the hub advertises only its own routes, so spokes lack the necessary routing information to forward traffic directly, causing it to be sent through the hub despite working NHRP and IPsec.

Exam trap

Cisco often tests the subtle distinction between NHRP resolution success and actual routing table propagation—candidates assume that if NHRP and IPsec are working, traffic must flow directly, but they overlook the hub's routing protocol configuration that prevents spoke-to-spoke route advertisement.

How to eliminate wrong answers

Option B is wrong because mismatched IPsec transform sets would prevent the spoke-to-spoke IPsec session from establishing, but the scenario states that spoke-to-spoke IPsec sessions are already established. Option C is wrong because mismatched NHRP authentication would cause NHRP registrations and resolutions to fail, but the scenario confirms NHRP registrations are successful. Option D is wrong because a static default route pointing to the hub does not override dynamic routes for specific spoke prefixes; spokes would still use the dynamically learned routes for direct forwarding if they exist.

845
MCQmedium

A network engineer is configuring uRPF on a Cisco IOS router. The router has two interfaces: GigabitEthernet0/0 (WAN) and GigabitEthernet0/1 (LAN). The engineer wants to prevent spoofed packets from entering the WAN interface while allowing asymmetric routing. Which uRPF mode should be configured on GigabitEthernet0/0?

A.Feasible path uRPF
B.VRF mode
C.Strict mode
D.Loose mode
AnswerD

Loose mode uRPF checks that the source address is reachable via any interface in the routing table, not necessarily the receiving interface. This allows asymmetric routing because the return path can be different. It still provides spoofing protection by ensuring the source is routable, making it the correct choice for this scenario.

Why this answer

Loose mode uRPF allows asymmetric routing because it only checks that the source address is present in the routing table, regardless of the incoming interface. Strict mode would require the source to be reachable via the same interface, which would break asymmetric routing. Therefore, loose mode is correct.

Exam trap

The trap here is assuming that strict mode is always better for spoofing prevention, but it can break legitimate asymmetric routing.

846
MCQeasy

A network engineer is configuring a Cisco IOS router to use IPsec VPN with IKEv2. The engineer wants to ensure that the router prefers a specific transform set that includes AES-256 encryption and SHA-256 hashing for integrity. Which command correctly defines the IKEv2 proposal with these parameters?

A.crypto ikev2 policy POLICY1 encryption aes-256 hash sha256 group 14
B.crypto isakmp policy 10 encryption aes 256 hash sha256 authentication pre-share group 14
C.crypto ikev2 proposal PROPOSAL1 encryption aes-cbc-256 integrity sha256 group 14
D.crypto ikev2 profile PROFILE1 encryption aes-cbc-256 integrity sha256 group 14
AnswerC

This command sequence correctly defines an IKEv2 proposal with AES-CBC-256 encryption, SHA-256 integrity, and Diffie-Hellman group 14. IKEv2 proposals are configured under crypto ikev2 proposal, and the syntax matches the required parameters. This is the correct way to specify encryption and integrity algorithms for IKEv2.

Why this answer

IKEv2 proposals define the encryption, integrity, and Diffie-Hellman group parameters. The correct command is crypto ikev2 proposal, followed by encryption aes-cbc-256, integrity sha256, and group 14. This proposal can then be referenced in an IKEv2 policy.

The other options use incorrect commands or syntax for IKEv2.

Exam trap

The trap here is confusing IKEv1 and IKEv2 configuration syntax, or misplacing algorithm definitions under a policy or profile instead of a proposal.

847
MCQeasy

Which RFC defines the IPv6 Neighbor Discovery Protocol that is the basis for many First Hop Security features?

A.RFC 4861
B.RFC 2460
C.RFC 4291
D.RFC 4443
AnswerA

RFC 4861 specifies IPv6 Neighbor Discovery, defining router solicitation, router advertisement, neighbour solicitation and neighbour advertisement messages. First Hop Security features such as RA Guard and IPv6 snooping build directly on these message types and their processing rules.

Why this answer

RFC 4861 defines the IPv6 Neighbor Discovery Protocol (NDP), which is the foundation for IPv6 First Hop Security (FHS) features. NDP replaces ARP in IPv6 and provides address resolution, router discovery, neighbor unreachability detection, and redirect functions, all of which are leveraged by FHS mechanisms like RA Guard, DHCPv6 Guard, and Source Address Validation Improvement (SAVI).

Exam trap

Cisco often tests the distinction between the RFC that defines the protocol itself (RFC 4861 for NDP) versus RFCs that define supporting technologies like ICMPv6 (RFC 4443) or addressing (RFC 4291), leading candidates to confuse the foundational RFC with related but separate standards.

How to eliminate wrong answers

Option B is wrong because RFC 2460 defines the IPv6 base protocol specification (header format, extension headers, etc.), not Neighbor Discovery. Option C is wrong because RFC 4291 defines the IPv6 addressing architecture, including address types and scopes, not NDP. Option D is wrong because RFC 4443 defines ICMPv6 for IPv6, which is used by NDP for messaging but is not the defining RFC for the Neighbor Discovery Protocol itself.

848
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate administrative SSH logins against an external TACACS+ server. The engineer wants to ensure that if the TACACS+ server becomes unreachable, local authentication is used as a fallback. Which configuration accomplishes this?

A.aaa authentication login default group tacacs+ local
B.aaa authentication login default group radius local
C.aaa authentication login default local group tacacs+
D.aaa authentication login default group tacacs+ none
AnswerA

This command configures the default method list to first attempt TACACS+ authentication and then fall back to the local username database if the TACACS+ server is unreachable. The 'group tacacs+' keyword specifies the TACACS+ server group, and 'local' provides the backup method. This is the correct way to ensure administrative access is not lost when the external server fails.

Why this answer

The correct command is 'aaa authentication login default group tacacs+ local'. It configures the default method list to try TACACS+ first and then the local database if the server is unreachable. This ensures administrative SSH logins are authenticated externally when possible, but local fallback maintains access during server outages.

The order of methods is critical: listing 'local' first would bypass the TACACS+ server.

Exam trap

The trap here is assuming that any fallback method is acceptable, but the order of methods in the AAA authentication command determines which is primary and which is backup.

849
MCQhard

A network engineer configures Flexible NetFlow on a router to monitor traffic on a trunk interface with multiple VLANs. The flow monitor is applied to the physical interface. The engineer notices that all flows show the same VLAN ID in the collector, even though traffic from different VLANs is present. What is the most likely cause?

A.The flow record does not include any VLAN match fields.
B.The trunk interface is not configured with 'switchport trunk encapsulation dot1q'.
C.The flow monitor is applied only to the physical interface, not the subinterfaces.
D.The collector does not support VLAN fields.
AnswerA

Flexible NetFlow only exports fields defined in the flow record. Without a match on dot1q vlan-id or a similar VLAN field, the record cannot distinguish VLANs, so every flow reports identical or absent VLAN data despite trunk traffic.

Why this answer

Flexible NetFlow only exports fields that are explicitly included in the flow record; if the record lacks VLAN match fields such as dot1q VLAN ID or S-VLAN/C-VLAN, the collector will not receive per-VLAN data and all flows appear to share the same (or no) VLAN ID. The fix is to add the appropriate VLAN fields to the flow record's match statement. The physical interface application is not the root cause because subinterface traffic still traverses the physical interface.

Exam trap

300-410 often tests whether candidates know that Flexible NetFlow exports only fields defined in the flow record, so candidates who blame interface application or encapsulation pick the wrong cause instead of the missing VLAN match field.

How to eliminate wrong answers

Option B is wrong because trunk encapsulation configuration affects whether VLAN tags are carried, not whether NetFlow exports VLAN IDs; if encapsulation were wrong, traffic would not flow at all. Option C is wrong because applying the flow monitor to the physical interface does capture traffic from all subinterfaces; the missing piece is the VLAN field in the record, not the application point. Option D is wrong because standard NetFlow collectors support VLAN fields; the limitation is in the exported record, not the collector.

850
Multi-Selectmedium

Which TWO commands would a network engineer use to verify the NHRP registration status of a spoke router in a DMVPN Phase 2 network? (Choose TWO.)

Select 2 answers
A.show dmvpn
B.show ip nhrp
C.show crypto isakmp sa
D.show ip route
E.show ip eigrp neighbors
AnswersA, B

The show dmvpn command lists all DMVPN tunnels with peer state, uptime and NBMA addresses, showing whether each spoke has reached the UP state after NHRP registration. It directly verifies registration status in the Phase 2 network.

Why this answer

The 'show dmvpn' command displays the current DMVPN tunnel status, including the NHRP registration state of each peer. The 'show ip nhrp' command shows the NHRP cache entries, which include the registration status and mapping information. The other commands either do not show NHRP registration details or are for different purposes.

851
Multi-Selectmedium

Which TWO statements are true regarding the use of VRF-Lite in a Cisco Enterprise network? (Choose TWO.)

Select 2 answers
A.VRF-Lite enables multiple virtual routing tables on a single router, providing traffic separation without MPLS.
B.VRF-Lite supports dynamic routing protocols such as OSPF and EIGRP within each VRF.
C.VRF-Lite requires MPLS to exchange VPNv4 routes between routers.
D.VRF-Lite can automatically encrypt traffic between VRFs using IPsec.
E.VRF-Lite can only be used with static routing.
AnswersA, B

VRF-Lite creates independent routing and forwarding tables on one physical router, each with its own interfaces and routes. Traffic between VRFs stays isolated without MPLS labels or VPNv4 address families, satisfying the question's requirement for separation without MPLS.

Why this answer

VRF-Lite allows multiple routing tables on a single router, enabling traffic separation without MPLS. It relies on static routes or dynamic routing protocols like OSPF, EIGRP, or BGP within each VRF. The incorrect options: MPLS is not required for VRF-Lite; VRF-Lite does not support MPLS VPNv4 route exchange (that requires MPLS); and VRF-Lite does not inherently provide encryption.

852
MCQhard

A network administrator is deploying 802.1X on a Cisco Catalyst switch. The switch is configured as an authenticator, and the RADIUS server is reachable. However, some devices such as printers do not support 802.1X supplicant software. The administrator wants these devices to be automatically placed into a restricted VLAN with limited access. Which feature should be configured on the switch ports to achieve this?

A.MAB (MAC Authentication Bypass)
B.Critical VLAN
C.802.1X supplicant mode
D.Web Auth
AnswerA

MAB allows the switch to use the MAC address of the connecting device as the username and password for RADIUS authentication. When a device does not support 802.1X, the switch can fall back to MAB after a timeout. The RADIUS server can then assign the device to a specific VLAN based on its MAC address, such as a restricted VLAN. This is the standard method for non-802.1X devices.

Why this answer

MAC Authentication Bypass (MAB) enables the switch to authenticate devices that do not support 802.1X by using their MAC addresses as credentials. The RADIUS server can then authorize and assign a VLAN, such as a restricted VLAN, based on the MAC address. This is the correct feature to support printers and similar devices while maintaining network access control.

Exam trap

The trap here is confusing Critical VLAN with MAB; Critical VLAN is for when the RADIUS server is down, not for devices lacking supplicant support.

853
MCQhard

A network engineer runs the following command to troubleshoot a Route Redistribution issue: R1# show ip bgp vpnv4 vrf CUSTOMER routes And sees the following output: Network Next Hop Metric LocPrf Weight Path Route Distinguisher: 100:1 (default for vrf CUSTOMER) *> 192.168.10.0/24 10.1.1.2 0 100 0 65001 i *> 192.168.20.0/24 10.1.1.2 0 100 0 65001 i What does this output indicate?

A.The VRF CUSTOMER has two routes learned via BGP from AS 65001.
B.The routes are redistributed from OSPF into BGP within the VRF.
C.The VRF is not receiving any routes because of a redistribution issue.
D.The routes are locally originated within the VRF.
AnswerA

Two prefixes appear under Route Distinguisher 100:1 with next hop 10.1.1.2 and AS path 65001, confirming both were learned from that neighbour. The asterisks and greater-than sign mark them as valid, best routes within VRF CUSTOMER.

Why this answer

The output shows two prefixes (192.168.10.0/24 and 192.168.20.0/24) inside the VRF CUSTOMER's VPNv4 table, each with an AS path of '65001 i' and next hop 10.1.1.2. The trailing 'i' indicates the origin is IGP (network statement or redistribution with origin i), and the AS path shows the routes were received from eBGP peer in AS 65001. Therefore the VRF has two BGP-learned routes from AS 65001.

Exam trap

The trap here is confusing the origin code 'i' (IGP) with OSPF redistribution — candidates see 'i' and assume OSPF was involved, when it simply means the route originated as an internal IGP in the source AS.

How to eliminate wrong answers

Option B is wrong because there is no evidence of OSPF redistribution — the origin code 'i' simply means the route originated as an IGP inside AS 65001, not that OSPF was redistributed locally; if OSPF were redistributed into BGP the origin would typically be '?' (incomplete). Option C is wrong because the output clearly shows two valid best routes marked with '*>' (valid and best), so routes are being received, not missing. Option D is wrong because locally originated routes would show an empty AS path or 'Local' weight with no AS number, whereas here the AS path '65001 i' proves the routes came from an external BGP peer.

854
MCQeasy

Which statement about PBR and the 'set ip precedence' command is correct?

A.It sets the DSCP value.
B.It can only be used with 'set ip next-hop'.
C.It modifies the IP header of the packet.
D.It is used for load-balancing.
AnswerC

The 'set ip precedence' action rewrites the three-bit Precedence field inside the packet's IPv4 Type of Service header, so downstream devices can classify and queue it. It changes the IP header itself, not the Layer 2 frame or any MPLS or DSCP marking.

Why this answer

The 'set ip precedence' command in PBR modifies the IP Precedence field in the Type of Service (ToS) byte of the IP header. This is used for marking packets for QoS purposes. It does not set DSCP, which uses a different set of bits in the ToS byte.

Exam trap

300-410 often tests the confusion between IP Precedence and DSCP, and candidates may incorrectly think 'set ip precedence' sets DSCP; remember that IP Precedence uses the first 3 bits of the ToS byte, while DSCP uses the first 6 bits.

How to eliminate wrong answers

Option A is wrong because 'set ip precedence' sets the IP Precedence value (3 bits), not the DSCP value (6 bits). Option B is wrong because 'set ip precedence' can be used with other set commands like 'set ip next-hop' or 'set interface', not exclusively. Option D is wrong because 'set ip precedence' is used for packet marking for QoS, not for load-balancing; load-balancing is typically achieved through other mechanisms like 'set ip next-hop' with multiple next-hops.

855
MCQeasy

Which of the following is true about the SPAN source interface configuration?

A.By default, both ingress and egress traffic are monitored.
B.By default, only ingress traffic is monitored.
C.By default, only egress traffic is monitored.
D.The direction must always be specified; there is no default.
AnswerB

SPAN monitors only ingress traffic on a source interface by default, so egress frames are not copied unless you explicitly configure both directions. This default satisfies the scenario's constraint, since the question asks what is true without additional configuration. Enabling egress requires the `both` keyword, which changes the monitored traffic scope.

Why this answer

A SPAN source interface can be configured to monitor both ingress and egress traffic, or either direction. By default, only ingress traffic is monitored if no direction is specified.

856
MCQhard

A network engineer is implementing DMVPN Phase 3 with IPsec tunnel protection. The hub router must be configured to support NHRP redirect. Which command is required on the hub's tunnel interface?

A.ip nhrp shortcut
B.ip nhrp network-id 1
C.ip nhrp redirect
D.ip nhrp map multicast dynamic
AnswerC

The ip nhrp redirect command enables the hub to send NHRP redirect messages to spokes when it receives traffic on the same tunnel interface. This is essential for Phase 3 DMVPN, allowing spokes to learn a better path and build direct tunnels. Without it, spokes continue to route through the hub.

Why this answer

The ip nhrp redirect command on the hub's tunnel interface is required for DMVPN Phase 3. It allows the hub to inform spokes about a better path when traffic is received on the same interface, prompting the spoke to initiate a direct tunnel. Without this command, the hub cannot send redirect messages, and spoke-to-spoke tunnels will not form dynamically.

Exam trap

The trap here is confusing the commands used on the hub versus the spokes; ip nhrp shortcut is for spokes, while ip nhrp redirect is for the hub.

857
MCQhard

A network engineer is troubleshooting IPv6 BGP path selection on Router R1. Router R1 is receiving a prefix from two different BGP peers, but it is not selecting the expected best path. Router R1 has the following relevant configuration: router bgp 65000 address-family ipv6 unicast neighbor 2001:DB8:1::2 route-map SET_LOCAL_PREF in neighbor 2001:DB8:2::2 route-map SET_MED in ! route-map SET_LOCAL_PREF permit 10 set local-preference 200 ! route-map SET_MED permit 10 set metric 50 ! The output of show bgp ipv6 unicast 2001:DB8:3::/64 on Router R1 indicates that the path from 2001:DB8:1::2 has local preference 200, but the path from 2001:DB8:2::2 is selected. What is the root cause?

A.The route-map SET_LOCAL_PREF is not actually affecting the received prefix (for example, it is applied in the wrong direction or the neighbor is not matched), so the higher local preference is never set.
B.The MED value of 50 is lower than the default, causing it to be preferred over local preference.
C.The prefix is not being advertised by the neighbor with the higher local preference route-map.
D.The BGP table has a route from an iBGP peer with a lower IGP metric to the next-hop, overriding the local preference.
AnswerA

Incorrect. The configuration shows the route-map is applied inbound, so it does affect the received prefix. The path from that neighbor has local pref 200, but it is not selected, indicating another factor.

Why this answer

Local preference is the first BGP path-selection attribute compared after weight, and it is evaluated before AS path, origin, MED, and IGP metric to next-hop. The route-map SET_LOCAL_PREF is configured with 'set local-preference 200' and applied inbound to neighbor 2001:DB8:1::2. If it were taking effect, that path would have local preference 200 and would be preferred over the other path (default local preference 100).

Since the path from 2001:DB8:2::2 is selected instead, the local-preference route-map is not actually affecting the received prefix. The most consistent cause is that the route-map is misapplied or otherwise ineffective, so the higher local preference is never set. IGP metric to next-hop (option D) is only considered much later in the decision process, after local preference, and cannot override a higher local preference.

Exam trap

Candidates may jump to later BGP attributes such as MED or IGP metric to next-hop. However, local preference is evaluated first and dominates those attributes. If the expected local-preference change is not reflected in the BGP table, the route-map direction or application is the likely fault.

How to eliminate wrong answers

Option B is wrong because MED is compared only after local preference, AS path length, origin code, and IGP metric to next-hop; a lower MED (50) cannot override a higher local preference (200) in the BGP best path selection algorithm. Option C is wrong because the prefix is being advertised by both neighbors, as indicated by the show output showing paths from both 2001:DB8:1::2 and 2001:DB8:2::2; the issue is not that the prefix is missing from one neighbor. Option D is wrong because IGP metric to next-hop is compared after local preference, AS path, origin, and MED; even if the IGP metric is lower for the path from 2001:DB8:2::2, it would not override a higher local preference unless all preceding steps are equal.

858
MCQmedium

Examine the following CoPP configuration on a Cisco IOS-XE router: !--- ACL to match traffic access-list 100 permit tcp any any eq 22 access-list 100 permit tcp any any eq 23 access-list 100 permit icmp any any echo ! !--- Class-map class-map match-all COPP-MGMT match access-group 100 ! !--- Policy-map policy-map COPP-POLICY class COPP-MGMT police 8000 conform-action transmit exceed-action drop class class-default police 64000 conform-action transmit exceed-action drop ! !--- Apply to control-plane control-plane service-policy input COPP-POLICY What is the effect of this configuration?

A.SSH, Telnet, and ICMP echo packets are rate-limited to 8000 bps; all other control-plane traffic is rate-limited to 64000 bps.
B.Only SSH and Telnet are rate-limited to 8000 bps; ICMP echo is not affected because it is matched by a different class.
C.All control-plane traffic is rate-limited to 64000 bps, because the class-default overrides the COPP-MGMT class.
D.The configuration is invalid because the class-map must be named 'COPP-CLASS' to be used in the policy-map.
AnswerA

The class-map matches SSH, Telnet, and ICMP echo, and its police action caps that traffic at 8000 bps, dropping excess. The class-default police statement rate-limits all remaining control-plane traffic to 64000 bps, so management protocols are throttled more tightly than other control-plane packets.

Why this answer

The CoPP configuration matches SSH (TCP/22), Telnet (TCP/23), and ICMP echo (ping) traffic via ACL 100 and class-map COPP-MGMT, then applies a police rate of 8000 bps to that class. All other control-plane traffic falls into class-default and is policed at 64000 bps. The 'conform-action transmit exceed-action drop' statements enforce rate-limiting, not blocking, so the correct effect is that SSH, Telnet, and ICMP echo are rate-limited to 8000 bps, while all other control-plane traffic is rate-limited to 64000 bps.

Exam trap

Cisco often tests the misconception that ICMP echo is not matched by ACL 100 because it uses the 'echo' keyword rather than a port number, but 'echo' is a valid ICMP type that matches ping requests, so candidates may incorrectly assume only TCP traffic is affected.

How to eliminate wrong answers

Option B is wrong because ICMP echo is explicitly matched by ACL 100 (permit icmp any any echo) and falls into the COPP-MGMT class, so it is rate-limited to 8000 bps, not unaffected. Option C is wrong because class-default does not override the COPP-MGMT class; CoPP processes packets sequentially through the policy-map, matching the first class first, so COPP-MGMT traffic is policed at 8000 bps before class-default is considered. Option D is wrong because there is no requirement that a class-map be named 'COPP-CLASS'; the class-map name 'COPP-MGMT' is arbitrary and valid as long as it matches the name used in the policy-map.

859
MCQmedium

Examine this configuration snippet: ``` router rip distance 120 ``` Which statement is true about the effect of this command?

A.It changes the administrative distance for RIP routes to 120, which is the same as the default, so no change occurs.
B.It changes the administrative distance for RIP routes to 120, which is lower than the default of 130.
C.It changes the administrative distance for RIP routes to 120, but only for routes learned from RIP neighbors.
D.It changes the administrative distance for RIP routes to 120, but only for routes with a hop count greater than 1.
AnswerA

RIP default AD is 120, so setting it to 120 has no effect.

Why this answer

The `distance` command under RIP sets the administrative distance for all RIP routes to 120, overriding the default of 120? Actually default is 120, so this command would have no effect if set to the same value.

860
MCQmedium

Given this configuration on Router R3: ``` interface Tunnel0 no ip address ipv6 address 2001:DB8:5::1/64 tunnel source 192.168.1.1 tunnel destination 192.168.2.2 tunnel mode ipv6ip ``` What is missing or incorrect?

A.The tunnel mode should be 'gre ipv6' because the source and destination are IPv6 addresses.
B.The tunnel interface must have an IPv4 address.
C.The tunnel source should be an interface, not an IP address.
D.The configuration is correct and will function as an IPv6 over IPv4 tunnel.
AnswerD

'tunnel mode ipv6ip' is the IPv4-transport mode that carries IPv6 packets inside an IPv4 header, using the configured IPv4 source 192.168.1.1 and destination 192.168.2.2. The IPv6 address on Tunnel0 provides the overlay addressing, so the configuration is valid.

Why this answer

The configuration uses 'tunnel mode ipv6ip', which is a valid manual IPv6-over-IPv4 tunnel. The source and destination are IPv4 addresses, as required for this tunnel mode. No changes are needed; the tunnel will function correctly for IPv6 over IPv4 transport.

Exam trap

Candidates often mistakenly think that 'gre ipv6' is required for IPv6 over IPv4 tunnels, but 'ipv6ip' is a valid mode for manual tunnels. The presence of IPv4 source/destination does not necessitate GRE; it is the correct setup for 'ipv6ip'.

How to eliminate wrong answers

Option A is wrong because the tunnel mode 'ipv6ip' is the correct mode for an IPv6-over-IPv4 manual tunnel when the source and destination are IPv4 addresses; 'gre ipv6' is used only when the transport is IPv6. Option B is wrong because a tunnel interface does not require an IPv4 address; it only needs an IPv6 address (as configured) and the underlying transport addresses are specified via tunnel source/destination. Option C is wrong because the tunnel source can be either an interface name or an IP address; using an IP address is perfectly valid and commonly used.

Option D is correct because the configuration is valid for an IPv6-over-IPv4 manual tunnel (RFC 4213), with IPv4 source/destination and IPv6 address on the tunnel interface.

861
Multi-Selecthard

Which TWO statements correctly describe the behavior of Control Plane Policing (CoPP) when applied to a Cisco IOS router? (Choose TWO.)

Select 2 answers
A.CoPP policies are applied using the Modular QoS CLI (MQC) and can be attached to the control-plane interface with the 'service-policy input' command.
B.CoPP can be applied to the aggregate control plane or separately to the IPv4, IPv6, and MPLS control plane subinterfaces.
C.CoPP policies are applied using the 'policy-map' command under the interface configuration mode for each physical interface.
D.CoPP polices all traffic that enters the router, including traffic that is process-switched after being forwarded.
E.CoPP uses the 'class-map' command to match traffic based on ACLs, NBAR, or DSCP values, and the 'police' command to enforce rate limits.
AnswersA, B

Correct. CoPP uses MQC class-maps and policy-maps, and is applied under the control-plane configuration with 'service-policy input'.

Why this answer

CoPP uses the Modular QoS CLI (MQC) framework, where a policy-map is created with class-maps and actions, and then applied to the control-plane interface using the 'service-policy input' command. This attaches the policy to the control plane, filtering traffic destined to the router's CPU before it is process-switched.

Exam trap

Cisco often tests the distinction between CoPP applying to the control plane (CPU-bound traffic) versus applying to all traffic entering the router, and the trap here is that candidates mistakenly think CoPP polices all forwarded traffic, when it only polices traffic destined to the control plane.

862
MCQeasy

Which statement about PBR and the 'match ip address' command is correct?

A.It can only match on source IP addresses.
B.It can reference a named or numbered ACL.
C.It can match on MAC addresses.
D.It matches packets before routing table lookup.
AnswerB

The match ip address route-map command accepts either a named or numbered standard or extended ACL, which defines the traffic classification criteria PBR uses. This flexibility lets engineers reference existing ACLs rather than creating new objects.

Why this answer

The 'match ip address' command references an access-list (standard or extended) to match packets based on source/destination IP addresses.

863
MCQmedium

Which statement about the SPAN destination port behavior is correct?

A.The SPAN destination port operates in full-duplex mode by default.
B.The SPAN destination port can participate in Spanning Tree Protocol (STP) if configured.
C.The SPAN destination port is automatically placed in a forwarding state and does not run STP.
D.The SPAN destination port can be used as a normal switch port after removing the SPAN configuration.
AnswerC

A SPAN destination port is excluded from the normal switching and Spanning Tree topology: it is placed in a forwarding state immediately and does not participate in STP, so mirrored traffic is not disrupted by topology convergence or blocked by STP states.

Why this answer

The SPAN destination port is designed to receive a copy of traffic from source ports or VLANs. By default, it does not participate in normal switching, including Spanning Tree Protocol (STP). It is placed in a forwarding state and does not run STP to avoid interfering with the mirrored traffic.

This behavior ensures that the destination port can receive mirrored packets without being blocked by STP or causing loops.

Exam trap

The trap here is assuming that SPAN destination ports behave like normal switch ports, leading candidates to think they participate in STP or can be easily repurposed. The exam tests the specific behavior that SPAN destination ports are excluded from STP and operate in a forwarding state by default.

How to eliminate wrong answers

Option A is wrong because the SPAN destination port typically operates in half-duplex mode or as a unidirectional port, not full-duplex by default. Option B is wrong because the SPAN destination port does not participate in STP; it is excluded from STP to prevent topology changes. Option D is wrong because after removing SPAN configuration, the port may require additional configuration to become a normal switch port; it is not automatically restored to normal switching behavior without manual intervention.

864
MCQhard

A network engineer runs the following command on Router R1: R1# show flow monitor FLOW-MONITOR-1 cache format table Cache type: Normal Cache size: 1000 Current entries: 0 High Watermark: 0 Flows added: 0 Flows aged: 0 - Active timeout (1800 secs) 0 - Inactive timeout (15 secs) 0 - Event aged 0 - Watermark aged 0 - Emergency aged 0 R1# show flow interface GigabitEthernet0/1 Interface GigabitEthernet0/1 FNF: monitor Monitor: FLOW-MONITOR-1 direction: Input traffic-statistics: enabled Based on both outputs, what is the most likely problem?

A.The flow monitor is attached, but no traffic is flowing through the interface.
B.The flow monitor is not attached to the interface.
C.The cache size is too small.
D.The flow exporter is misconfigured.
AnswerA

The monitor is bound to GigabitEthernet0/1 in the input direction with traffic-statistics enabled, yet every counter reads zero, including flows added and the high watermark. That pattern means the cache has never received a single packet, so no traffic is traversing the interface.

Why this answer

The 'show flow monitor ... cache format table' output shows Current entries: 0, Flows added: 0, and all aging counters at 0, meaning no flows have ever been recorded. The 'show flow interface' output confirms the monitor FLOW-MONITOR-1 is attached to GigabitEthernet0/1 in the Input direction with traffic-statistics enabled. Since the monitor is properly attached but no flows exist, the most likely cause is that no traffic is traversing the interface.

Exam trap

The trap is assuming that an empty flow cache means the monitor isn't attached — candidates must cross-check 'show flow interface' to confirm attachment before concluding the problem is traffic-related.

How to eliminate wrong answers

Option B is wrong because the 'show flow interface' output explicitly shows 'FNF: monitor' with 'Monitor: FLOW-MONITOR-1' and 'direction: Input', proving the flow monitor is attached. Option C is wrong because a cache size of 1000 is not inherently too small; the cache shows 0 current entries and 0 flows added, so size is irrelevant when no flows exist. Option D is wrong because the flow exporter is a separate configuration used to export records to a collector; the absence of cached flows is not caused by exporter misconfiguration — flows would still be cached locally even without an exporter.

865
Multi-Selecthard

Which TWO statements about IPsec transform sets and security associations (SAs) are true? (Choose TWO.)

Select 2 answers
A.A transform set can specify ESP encryption and ESP authentication simultaneously.
B.In tunnel mode, the original IP header is preserved and a new IP header is added.
C.Transport mode adds a new IP header to the packet.
D.The command 'crypto ipsec security-association lifetime' sets the IKE SA lifetime.
E.A single IPsec SA provides bidirectional secure communication.
AnswersA, B

A transform set may combine one ESP encryption algorithm with one ESP authentication algorithm, such as esp-aes and esp-sha256-hmac, because ESP provides both confidentiality and integrity as separate transform types. This satisfies the stem's requirement that a single set specify ESP encryption and ESP authentication simultaneously.

Why this answer

Option A is correct because an IPsec transform set is precisely the construct that bundles the security protocols and algorithms for a single SA proposal, and it commonly pairs an ESP encryption algorithm (e.g., esp-aes) with an ESP authentication algorithm (e.g., esp-sha256-hmac) so the payload is both encrypted and integrity-protected. Option B is correct because in tunnel mode the entire original IP packet (original IP header plus payload) is encapsulated and a brand-new outer IP header is prepended, which is what allows site-to-site VPN endpoints to route the encapsulated traffic across an untrusted network. Option C is wrong because transport mode does not add a new IP header; it inserts the IPsec header between the original IP header and the transport-layer payload, leaving the original IP header intact.

Option D is wrong because 'crypto ipsec security-association lifetime' configures the lifetime of the IPsec SA (data SA), whereas IKE SA lifetimes are configured with 'crypto isakmp policy' / 'crypto ikev2 policy' lifetime settings. Option E is wrong because an IPsec SA is unidirectional, so secure bidirectional communication requires a pair of SAs, one for each direction.

Exam trap

Cisco often tests the misconception that a single SA is bidirectional, but in reality, IPsec SAs are unidirectional and must be paired for two-way communication.

866
MCQmedium

A network engineer runs the following command to verify DMVPN tunnel status: R1# show ip nhrp detail 10.0.0.2/32 via Tunnel0 Created: 00:10:15, Expire: 01:49:45 Type: dynamic, Flags: unique registered NBMA: 192.168.1.2 (no socket) What does this output indicate?

A.The spoke 10.0.0.2 has registered with the hub and its NBMA address is 192.168.1.2.
B.The spoke 10.0.0.2 is using a static NBMA mapping.
C.The NHRP entry is about to expire and needs re-registration.
D.The spoke has not registered; the entry is incomplete.
AnswerA

The "unique registered" flag confirms the spoke has successfully registered its protocol address with the hub, and the NBMA field shows its public address as 192.168.1.2. The "(no socket)" entry merely reflects that no active data path is currently open, which does not invalidate the registration itself.

Why this answer

The output shows a dynamic NHRP cache entry for a spoke (10.0.0.2) with NBMA address 192.168.1.2, indicating the spoke has registered and the entry is valid.

867
MCQhard

An engineer configures an EEM applet to monitor DMVPN tunnel events using the event syslog pattern 'NHRP-3-REGISTRATION'. The applet is supposed to send an email when a spoke registers with the NHS. The DMVPN network uses Phase 2 with spoke-to-spoke tunnels. A spoke registers successfully, but the EEM applet does not trigger. Which is the most likely explanation?

A.Successful NHRP registration generates a syslog message with severity 6 (informational), not severity 3 (error).
B.The EEM applet must be configured with 'event nhrp' to capture NHRP events.
C.The DMVPN Phase 2 does not generate syslog messages for spoke registration.
D.The NHS must be configured with 'ip nhrp registration no-syslog' to suppress messages.
AnswerA

The applet's pattern matches severity 3, but successful NHRP registration logs at severity 6 (informational), so the syslog event never fires. EEM pattern matching is case-sensitive and severity-specific; the literal 'NHRP-3-REGISTRATION' string only appears on registration failures, not successful spoke registrations.

Why this answer

The EEM applet uses 'event syslog pattern NHRP-3-REGISTRATION', which matches syslog messages with facility NHRP and severity level 3 (error). However, a successful NHRP registration generates a syslog message with severity 6 (informational), typically 'NHRP-6-REGISTRATION' or similar. Since the pattern specifies severity 3, the applet never matches the actual informational message, so it does not trigger.

Exam trap

The trap here is assuming that the syslog pattern matches any NHRP registration message regardless of severity, when in fact the severity digit in the pattern is a strict filter that excludes informational messages.

How to eliminate wrong answers

Option B is wrong because there is no 'event nhrp' EEM event type; EEM supports syslog, SNMP, timer, and other event types, but not a dedicated NHRP event. Option C is wrong because DMVPN Phase 2 does generate syslog messages for spoke registration; the issue is the severity level, not the absence of messages. Option D is wrong because 'ip nhrp registration no-syslog' is not a valid command; NHRP registration syslog messages are generated by default and cannot be suppressed with that syntax.

868
MCQmedium

A network engineer runs the following command to troubleshoot DHCPv6 address assignment on router R1: R1# show ipv6 dhcp binding Output: Client: FE80::21A:2BFF:FE3C:4D01 DUID: 0003000121A2B3C4D5E6 Username: unassigned VRF: default IA NA: IA ID 0x00040001, T1 302400, T2 483840 Address: 2001:DB8:1::100 Preferred lifetime 604800, valid lifetime 2592000 Expires at Mar 01 2025 12:00 PM (2592000 seconds) IA PD: IA ID 0x00040002, T1 302400, T2 483840 Prefix: 2001:DB8:1::/48 Preferred lifetime 604800, valid lifetime 2592000 Expires at Mar 01 2025 12:00 PM (2592000 seconds) What does this output indicate?

A.The DHCPv6 server has assigned only an IPv6 address to the client.
B.The DHCPv6 server has assigned both an IPv6 address and a prefix delegation to the client.
C.The DHCPv6 client is using stateless autoconfiguration (SLAAC) because no address is shown.
D.The DHCPv6 server has a pool with only one prefix available.
AnswerB

The binding shows an IA NA entry with an assigned address (2001:DB8:1::100) plus an IA PD entry with a delegated prefix (2001:DB8:1::/48), confirming the server provided both address assignment and prefix delegation to the same client.

Why this answer

The output shows both an IA_NA (Identity Association for Non-temporary Address) with an IPv6 address (2001:DB8:1::100) and an IA_PD (Identity Association for Prefix Delegation) with a prefix (2001:DB8:1::/48). This confirms that the DHCPv6 server has assigned both a global unicast address and a delegated prefix to the client, making option B correct.

Exam trap

Cisco often tests the distinction between IA_NA (address assignment) and IA_PD (prefix delegation), and candidates may overlook the IA_PD section, assuming only an address was assigned.

How to eliminate wrong answers

Option A is wrong because the output clearly includes an IA_PD section with a delegated prefix, not just an IPv6 address. Option C is wrong because SLAAC does not use DHCPv6 binding entries; the output shows DHCPv6-assigned addresses and prefixes, not stateless autoconfiguration. Option D is wrong because the output shows only one prefix assigned to this client, but it does not indicate the total number of prefixes available in the pool; the pool could have many prefixes.

869
MCQmedium

What is the default behavior of an IPv4 ACL regarding the order of evaluation when multiple entries match a packet?

A.The most specific entry is used regardless of order.
B.The first matching entry in the list is applied.
C.All matching entries are evaluated and the most permissive action is taken.
D.The last matching entry in the list overrides earlier ones.
AnswerB

IPv4 ACLs are evaluated top-down, and processing stops at the first entry whose criteria match the packet. Later entries, even if more specific, are never examined, so ordering entries correctly is essential to obtain the intended permit or deny result.

Why this answer

Cisco IOS processes IPv4 ACL entries in sequential order, from top to bottom. When a packet matches an entry, the associated permit or deny action is applied immediately, and no further entries are evaluated. This first-match rule is fundamental to ACL design and troubleshooting.

Exam trap

Cisco often tests the misconception that ACLs use longest-prefix matching like routing tables, but ACLs strictly use first-match order, not specificity.

How to eliminate wrong answers

Option A is wrong because ACLs do not use longest-prefix or most-specific matching; they use first-match logic, regardless of specificity. Option C is wrong because ACL evaluation stops at the first match; it does not continue to evaluate all entries or combine actions. Option D is wrong because the first matching entry is applied, not the last; later entries are never reached if a match occurs earlier.

870
MCQhard

What is the default retransmission timeout for SNMP informs on a Cisco IOS device?

A.5 seconds
B.30 seconds
C.60 seconds
D.10 seconds
AnswerB

Cisco IOS defaults to a 30-second timeout for inform acknowledgments.

Why this answer

The default retransmission timeout for SNMP informs on Cisco IOS devices is 30 seconds, as specified by the Cisco SNMP configuration. This timeout controls how long the device waits for an acknowledgment (inform response) before retransmitting the inform request. Option B is correct because Cisco IOS uses a default timeout of 30 seconds for inform operations, which is distinct from the 5-second default for SNMP get/set requests.

Exam trap

Cisco often tests the distinction between default timeouts for SNMP informs (30 seconds) versus SNMP get/set requests (5 seconds), leading candidates to mistakenly choose 5 seconds.

How to eliminate wrong answers

Option A is wrong because 5 seconds is the default timeout for SNMP get and set requests, not for informs. Option C is wrong because 60 seconds is not a default SNMP timeout value on Cisco IOS; it may be a user-configured value but is not the default. Option D is wrong because 10 seconds is not the default retransmission timeout for SNMP informs; it is sometimes used for other SNMP operations like traps or for specific vendor implementations, but not for Cisco IOS informs.

871
MCQmedium

Given the following partial configuration on a router: ip access-list standard FILTER_SNMP permit 192.168.1.0 0.0.0.255 deny any ! snmp-server community public RO FILTER_SNMP snmp-server location DataCenter snmp-server contact admin@example.com What is the effect of this configuration?

A.Only SNMP requests from the 192.168.1.0/24 network are allowed with the community string 'public'.
B.SNMP requests from any source are allowed because the ACL is not applied correctly.
C.The community string 'public' allows read-write access.
D.The ACL is applied outbound, so SNMP responses are filtered.
AnswerA

The standard ACL FILTER_SNMP is applied to the community string, so only hosts within 192.168.1.0/24 matching the permit statement can query SNMP with 'public'; the trailing deny any blocks all other source addresses from using that community.

Why this answer

The configuration applies the standard ACL 'FILTER_SNMP' to the SNMP community string 'public' with read-only (RO) access. The ACL permits only the 192.168.1.0/24 network, so SNMP requests (e.g., GET, GETNEXT) from that subnet are allowed, while all other sources are denied. This is the intended effect of using an ACL to restrict SNMP access by source IP.

Exam trap

Cisco often tests the distinction between applying an ACL to an SNMP community versus applying it to an interface; the trap here is that candidates may think the ACL filters outbound SNMP responses or that the ACL is not applied correctly, but in reality, it filters incoming SNMP requests based on source IP.

How to eliminate wrong answers

Option B is wrong because the ACL is correctly applied to the SNMP community string via the 'snmp-server community public RO FILTER_SNMP' command, which filters incoming SNMP requests. Option C is wrong because the 'RO' keyword explicitly grants read-only access, not read-write (RW). Option D is wrong because the ACL is applied to incoming SNMP requests, not outbound responses; standard ACLs on SNMP communities filter the source of the request, not the direction of the response.

872
MCQhard

A network engineer is deploying a GET VPN solution using Cisco IOS routers. The key server must be configured to rekey group members. Which protocol does GET VPN use to distribute encryption keys and policies to group members?

A.Group Domain of Interpretation (GDOI)
B.Group Key Management Protocol (GKMP)
C.Multicast Group Management Protocol (MGMP)
D.Internet Key Exchange version 2 (IKEv2)
AnswerA

GDOI is the protocol used by GET VPN to distribute encryption keys and policies from the key server to group members. It operates over UDP port 848 and allows the key server to push rekey messages, ensuring all group members share the same security policy and keys. GDOI is essential for the scalable any-to-any communication that GET VPN provides.

Why this answer

GET VPN uses the Group Domain of Interpretation (GDOI) protocol to distribute encryption keys and policies from the key server to group members. GDOI enables scalable group key management, allowing the key server to send rekey messages to all members. IKEv2 is for point-to-point VPNs, and the other options are not used for GET VPN key distribution.

Exam trap

The trap here is confusing IKEv2, which is used for point-to-point IPsec, with GDOI, which is specifically for group key management in GET VPN.

873
MCQhard

A router configured as a DHCPv4 server uses a pool with 'bootfile' and 'next-server' options for PXE boot. Clients receive the DHCP offer with the correct bootfile, but they fail to download it. Which is the most likely explanation?

A.The 'next-server' is configured with a hostname, but the client does not have DNS resolution capabilities at boot time.
B.The 'bootfile' name is case-sensitive, and the client is requesting a different case.
C.The DHCP server is not configured with the 'option 150' for TFTP server.
D.The client's subnet does not have a route to the TFTP server, but the DHCP server cannot control that.
AnswerA

PXE clients use the next-server value during early boot, before any DNS resolver is available, so a hostname cannot be resolved. Configuring an IP address instead lets the client reach the TFTP server and download the bootfile.

Why this answer

During PXE boot, the client does not yet have an IP address or DNS resolver configured. When the DHCP server specifies a hostname in the 'next-server' option, the client cannot resolve that hostname to an IP address to initiate the TFTP download. The client requires the TFTP server's IP address directly, not a DNS name, at this stage of the boot process.

Exam trap

Cisco often tests the distinction between hostname and IP address in DHCP options, where candidates assume DNS is available during PXE boot, but the client's firmware lacks DNS resolution at that stage.

How to eliminate wrong answers

Option B is wrong because the 'bootfile' name is case-sensitive on the TFTP server, but the client requests the exact filename provided in the DHCP offer; the issue is not about case mismatch but about the inability to reach the server. Option C is wrong because 'option 150' is a Cisco-specific option for TFTP server address in VoIP deployments, not for PXE boot; PXE boot uses the standard 'next-server' (siaddr) field and 'bootfile' option. Option D is wrong because while a missing route could cause the failure, the DHCP server can control the TFTP server address via the 'next-server' option, and the question states the client receives the correct bootfile, implying the DHCP server is functioning; the core issue is the client's inability to resolve the hostname, not routing.

874
MCQhard

A network engineer runs the following command to troubleshoot Flexible NetFlow cache usage: R1# show flow monitor FLOW-MONITOR-1 statistics Cache type: Normal Cache size: 1000 Current entries: 900 High Watermark: 950 Flows added: 50000 Flows aged: 49100 - Active timeout ( 1800 secs): 40000 - Inactive timeout ( 15 secs): 9000 - Event aged: 100 - Watermark aged: 0 - Emergency aged: 0 What does this output indicate?

A.The cache is mostly empty and flows are aging normally.
B.The cache is nearly full, with many long-lived flows causing active timeout aging. No watermark or emergency aging has occurred yet.
C.Emergency aging is occurring because the cache is full.
D.Watermark aging has occurred, indicating the cache size needs to be increased.
AnswerB

Current entries at 900 of 1000 show the cache nearing capacity. Active timeout aged 40000 flows, indicating many long-lived flows, while watermark and emergency counters remain zero, so no forced eviction has occurred. Inactive timeout aged the shorter flows.

Why this answer

The output shows Current entries at 900 out of a Cache size of 1000 (90% full), with a High Watermark of 950, indicating the cache is nearly full. Active timeout aging accounts for 40,000 of the 49,100 aged flows, meaning many flows are long-lived and hitting the 1800-second active timeout. Watermark aged and Emergency aged are both 0, confirming no watermark or emergency aging has occurred yet.

Exam trap

300-410 often tests whether candidates can interpret NetFlow cache statistics — the trap is misreading 'High Watermark' as evidence of watermark aging when it is actually just a peak-usage counter, and confusing active timeout aging with emergency aging.

How to eliminate wrong answers

Option A is wrong because 900/1000 entries means the cache is 90% full, not mostly empty, and the high active timeout count indicates long-lived flows rather than 'normal' aging. Option C is wrong because Emergency aged is 0, so emergency aging is not occurring — the cache has not reached the point where emergency aging is triggered. Option D is wrong because Watermark aged is 0, meaning watermark aging has not occurred; the high watermark of 950 is a record of the highest usage, not evidence that watermark aging happened.

875
MCQeasy

A network engineer runs the following command to troubleshoot an IPsec Site-to-Site VPN issue: R1# show crypto ipsec transform-set Transform set combined-des-sha: { esp-des esp-sha-hmac } will negotiate = { Tunnel, }, Transform set myset: { esp-3des esp-sha-hmac } will negotiate = { Tunnel, }, Transform set strong: { esp-aes 256 esp-sha-hmac } will negotiate = { Tunnel, }, What does this output indicate?

A.All transform sets are using strong encryption and are acceptable for production.
B.The transform set 'combined-des-sha' uses DES, which is not recommended due to security vulnerabilities.
C.The transform sets are not configured correctly because they do not specify the mode.
D.The transform set 'strong' is not supported because it uses AES 256.
AnswerB

The output lists transform sets and their proposals; combined-des-sha negotiates ESP with DES encryption and SHA-HMAC. DES uses a 56-bit key, which is cryptographically weak, so its presence is flagged as a security concern rather than a functional fault.

Why this answer

The output shows three transform sets, including 'combined-des-sha', which uses DES (Data Encryption Standard) with a 56-bit key. DES is considered cryptographically weak and has been deprecated due to known vulnerabilities, such as susceptibility to brute-force attacks. Cisco recommends using AES or 3DES as a minimum for production IPsec VPNs, making option B correct.

Exam trap

Cisco often tests the candidate's awareness of deprecated or weak cryptographic algorithms (like DES) versus strong ones (like AES), and the trap here is assuming that all listed transform sets are equally valid or that the missing mode keyword indicates a misconfiguration.

How to eliminate wrong answers

Option A is wrong because not all transform sets use strong encryption; 'combined-des-sha' uses DES, which is insecure and not recommended for production. Option C is wrong because the transform sets do specify the mode implicitly; the output shows 'will negotiate = { Tunnel, }', indicating that the default tunnel mode is used, and the configuration is valid without explicitly stating the mode in the output. Option D is wrong because AES 256 is fully supported by Cisco IOS and is a strong, recommended encryption algorithm for IPsec.

876
MCQhard

An engineer configures a route-map to filter OSPF routes using a distribute-list. The distribute-list is applied inbound on an OSPF interface. Unexpectedly, the router still installs the filtered routes. Which is the most likely explanation?

A.The distribute-list is applied to the wrong direction; it should be outbound to filter routes being advertised.
B.The route is also learned via another OSPF neighbor that is not filtered by the distribute-list.
C.The distribute-list uses an ACL that does not match the route exactly, so the route is permitted.
D.The distribute-list is applied after the route is already installed in the routing table, so it has no effect.
AnswerB

OSPF can learn the same prefix from multiple neighbors, and each received route is independently evaluated against any distribute-list applied to that specific incoming interface. If the route is also learned via another OSPF neighbor on a different interface that has no distribute-list, that copy is installed in the routing table without restriction. This is exactly why the route appears despite the filter: the distribute-list only blocks reception on one interface, not the entire OSPF process.

Why this answer

When a distribute-list is applied inbound on an OSPF interface, it filters routes received from that specific neighbor only. If the same route is also learned from another OSPF neighbor (or via a different OSPF process) that is not covered by the distribute-list, the router will still install that route from the unfiltered source. This is because OSPF installs the best route based on metric, regardless of the filtering applied to a single neighbor.

Exam trap

Cisco often tests the misconception that a distribute-list applied inbound on one interface will globally prevent a route from being installed, when in fact it only filters routes from that specific neighbor, and the route may still be installed from another neighbor.

How to eliminate wrong answers

Option A is wrong because the distribute-list applied inbound on an interface filters routes received from that neighbor, which is the correct direction to prevent installation; applying it outbound would affect routes being advertised to others, not incoming routes. Option C is wrong because if the ACL does not match the route exactly, the route would be denied (if the ACL is used in a permit/deny context) or permitted only if the ACL explicitly permits it; a non-matching ACL entry typically results in an implicit deny, which would filter the route, not permit it. Option D is wrong because a distribute-list applied inbound on an OSPF interface is processed before the route is installed in the routing table; it filters the route during the OSPF update processing, so it does have effect if applied correctly.

877
MCQmedium

Analyze the following partial configuration: access-list 101 permit tcp any any eq 179 access-list 101 permit udp any any eq 646 access-list 101 permit ospf any any ! class-map match-all COPP-BGP match access-group 101 ! policy-map COPP-POLICY class COPP-BGP police 48000 conform-action transmit exceed-action drop class class-default police 128000 conform-action transmit exceed-action drop ! interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ! control-plane service-policy input COPP-POLICY Which statement is true?

A.The ACL matches OSPF, BGP, and LDP traffic, and all are rate-limited to 48000 bps.
B.The ACL is missing 'permit eigrp any any' to include EIGRP traffic.
C.The class-map must use 'match-all' to match all protocols simultaneously, but the ACL uses 'permit' which is OR logic, so the class-map will not work.
D.The policy-map should be applied to the interface, not the control-plane.
AnswerA

Correct. The ACL permits OSPF (protocol 89), BGP (TCP 179), and LDP (UDP 646). The class-map matches all three and applies the 48000 bps policer.

Why this answer

The ACL permits TCP port 179 (BGP), UDP port 646 (LDP), and OSPF (protocol 89). The class-map COPP-BGP matches all three protocols via the match-all keyword, and the policy-map applies a police rate of 48000 bps to this class. Since the policy is applied to the control-plane input, all matched traffic (BGP, LDP, OSPF) is rate-limited to 48000 bps.

Exam trap

Cisco often tests the misconception that 'match-all' in a class-map requires all protocols in the ACL to be matched simultaneously, but in reality, 'match-all' applies to the match statements within the class-map, not to the individual entries within the referenced ACL.

How to eliminate wrong answers

Option B is wrong because EIGRP is not included in the ACL, but the question does not require EIGRP; the ACL is intentionally limited to BGP, LDP, and OSPF, and the statement about missing EIGRP is irrelevant to the correctness of the configuration. Option C is wrong because the class-map uses 'match-all' correctly—it requires all match criteria to be met, but since there is only one match (match access-group 101), the 'match-all' behaves the same as 'match-any'; the ACL's 'permit' statements are OR logic within the ACL itself, but the class-map only references the entire ACL, so the class-map works as intended. Option D is wrong because CoPP is specifically designed to be applied to the control-plane, not to an interface; applying it to an interface would police all traffic, not just traffic destined to the control plane.

878
MCQmedium

A network engineer is troubleshooting an IPsec site-to-site VPN between two routers. The tunnel interface is up/up, but traffic from the local LAN to the remote LAN is not passing. The engineer checks the crypto map and sees it is applied to the outside interface. What is the most likely cause of the traffic failure?

A.The crypto map is not applied to the tunnel interface.
B.The access list in the crypto map does not match the LAN-to-LAN traffic.
C.The IPsec transform set is missing the esp-aes encryption algorithm.
D.The IKE phase 1 proposal is mismatched between the two routers.
AnswerB

Correct because the crypto map uses an access list to define which traffic is encrypted; if it does not match the actual LAN subnets, traffic will be sent unencrypted and may be dropped by the remote router.

Why this answer

The crypto map's access list (the 'match address' ACL) defines which traffic is considered interesting and therefore encrypted/tunneled. If the tunnel is up/up but LAN-to-LAN traffic isn't passing, the most common cause is that the ACL doesn't match the actual source/destination subnet pairs, so the router either doesn't encrypt the traffic or drops it as non-interesting. The tunnel interface being up only confirms IKE/IPsec SA establishment, not that the correct traffic is being selected.

Exam trap

The trap here is assuming that 'tunnel up/up' means the IPsec configuration is fully correct — candidates overlook that the crypto ACL is a separate traffic-selection mechanism that can be misconfigured even when IKE and IPsec SAs are established.

How to eliminate wrong answers

Option A is wrong because crypto maps are applied to the physical outside interface (the IPsec peer-facing interface), not to the tunnel interface — applying a crypto map to a tunnel interface is not how Cisco IPsec site-to-site VPNs are configured. Option C is wrong because a missing esp-aes in the transform set would prevent Phase 2 SA negotiation entirely, so the tunnel would not come up/up. Option D is wrong because an IKE Phase 1 mismatch would prevent the tunnel from ever reaching up/up state, since Phase 1 must succeed before Phase 2 and the tunnel interface can report up.

879
MCQmedium

Which statement correctly describes the behavior of the 'subnets' keyword when redistributing into OSPF?

A.It causes OSPF to redistribute only classful network routes.
B.It allows OSPF to redistribute subnetted routes in addition to classful networks.
C.It changes the metric of redistributed routes to the interface cost.
D.It is required only when redistributing BGP routes into OSPF.
AnswerB

The 'subnets' keyword removes OSPF's default classful redistribution restriction, permitting routes with non-classful masks to enter the domain. Without it, only networks matching their classful boundary are advertised. This satisfies the stem's requirement to redistribute subnetted routes alongside classful ones, which is essential in VLSM-addressed networks.

Why this answer

The 'subnets' keyword in OSPF redistribution (e.g., 'redistribute connected subnets') instructs OSPF to include subnetted routes in the redistribution process. Without it, OSPF only redistributes classful network routes (major networks) and ignores any routes with a subnet mask longer than the classful default. This is a Cisco-specific behavior that ensures more specific routes are advertised into OSPF.

Exam trap

The trap here is confusing the default classful redistribution behavior with the effect of the 'subnets' keyword, leading candidates to select option A instead of B.

How to eliminate wrong answers

Option A is wrong because it describes the default behavior without the 'subnets' keyword, not the effect of the keyword itself. Option C is wrong because the 'subnets' keyword does not alter the metric of redistributed routes; metric modification is done via the 'metric' or 'metric-type' keywords. Option D is wrong because the 'subnets' keyword is not exclusive to BGP redistribution; it is used for any redistribution source (connected, static, EIGRP, etc.) when subnetted routes need to be included.

880
MCQeasy

In IPsec site-to-site VPN, what is the purpose of the 'match address' command under a crypto map?

A.It specifies the peer IP address for the tunnel.
B.It defines the encryption and authentication algorithms.
C.It identifies the traffic that will be encrypted and sent through the tunnel.
D.It sets the lifetime for the IPsec SA.
AnswerC

The `match address` command references an extended ACL that defines the interesting traffic permitted into the IPsec tunnel. Only packets matching the ACL's source/destination pairs are encrypted and forwarded through the site-to-site VPN, satisfying the requirement to select which traffic the crypto map protects.

Why this answer

The 'match address' command under a crypto map references an access list (ACL) that defines which traffic should be protected by IPsec. When a packet matches a permit entry in that ACL, it triggers the IPsec process to encrypt and tunnel the traffic to the remote peer. This is the fundamental mechanism for selecting interesting traffic in a site-to-site VPN.

Exam trap

Cisco often tests the distinction between 'match address' (traffic selection) and 'set peer' (tunnel endpoint), leading candidates to confuse the purpose of these two commands under a crypto map.

How to eliminate wrong answers

Option A is wrong because the peer IP address for the tunnel is specified using the 'set peer' command under the crypto map, not 'match address'. Option B is wrong because encryption and authentication algorithms are defined using the 'set transform-set' command, which references an IPsec transform set. Option D is wrong because the lifetime for the IPsec SA is set using the 'set security-association lifetime' command, either globally or under the crypto map, not by 'match address'.

881
MCQhard

What is the default OSPF network type for a serial interface configured with HDLC encapsulation on Cisco routers?

A.Broadcast
B.Non-broadcast (NBMA)
C.Point-to-point
D.Point-to-multipoint
AnswerC

HDLC serial links default to the point-to-point OSPF network type, which suppresses DR/BDR election and sends multicast hellos every 10 seconds. This satisfies the stem's HDLC encapsulation constraint, since Cisco assigns point-to-point automatically to serial interfaces rather than broadcast, non-broadcast or point-to-multipoint.

Why this answer

On Cisco routers, a serial interface using HDLC encapsulation defaults to the OSPF network type point-to-point. This is because HDLC is a synchronous framing protocol that inherently implies a direct, single-neighbor link, so OSPF automatically sets the network type to point-to-point, which requires no DR/BDR election and uses multicast Hello packets (224.0.0.5).

Exam trap

The trap here is that candidates often confuse the default OSPF network type for serial interfaces with the default for Ethernet (broadcast) or Frame Relay (NBMA), forgetting that HDLC encapsulation forces a point-to-point OSPF network type.

How to eliminate wrong answers

Option A is wrong because broadcast network type is the default for Ethernet interfaces (e.g., GigabitEthernet), not for serial interfaces with HDLC; broadcast expects multi-access capabilities like ARP and DR/BDR election. Option B is wrong because non-broadcast (NBMA) is the default for Frame Relay or ATM interfaces, where neighbors must be statically configured and DR/BDR election occurs; HDLC does not use NBMA. Option D is wrong because point-to-multipoint is a non-default OSPF network type used for hub-and-spoke topologies (e.g., Frame Relay with subinterfaces) and requires manual configuration; it is never assigned automatically to a serial HDLC link.

882
MCQmedium

A network engineer runs the following command on Router R1: R1# show ipv6 interface tunnel 0 Tunnel0 is up, line protocol is up IPv6 is enabled, link-local address is FE80::A8BB:CCFF:FE00:1 No global unicast address is configured Joined group address(es): FF02::1 FF02::2 FF02::1:FF00:1 MTU is 1480 bytes ICMP error messages limited to one every 100 milliseconds ICMP redirects are enabled ICMP unreachables are sent ND DAD is enabled, number of DAD attempts: 1 ND reachable time is 30000 milliseconds ND advertised reachable time is 0 milliseconds ND advertised retransmit interval is 0 milliseconds ND router advertisements are sent every 200 seconds ND router advertisements live for 1800 seconds Hosts use stateless autoconfiguration for addresses. Based on this output, what is a likely problem?

A.The tunnel interface is down.
B.The tunnel is not configured with a global IPv6 address, which may prevent routing of IPv6 traffic.
C.The MTU is too small for IPv6.
D.IPv6 is not enabled on the tunnel.
AnswerB

Without a global unicast address, the tunnel interface cannot source or terminate routable IPv6 traffic, so packets arriving from remote tunnel endpoints are dropped. The output explicitly states "No global unicast address is configured", meaning only the link-local FE80:: address exists, which is insufficient for forwarding IPv6 traffic across the tunnel.

Why this answer

The output shows that the tunnel interface has no global unicast address configured, only a link-local address. Without a global IPv6 address, the router cannot route IPv6 traffic beyond the local link, as global reachability requires a globally routable address. This is a common misconfiguration in IPv6 tunneling scenarios where the tunnel source and destination are set but the interface itself lacks a global IPv6 address.

Exam trap

Cisco often tests the misconception that a link-local address alone is sufficient for IPv6 routing, but in fact, global unicast addresses are required for traffic to be routable beyond the local segment.

How to eliminate wrong answers

Option A is wrong because the output clearly states 'Tunnel0 is up, line protocol is up', so the interface is not down. Option C is wrong because the MTU of 1480 bytes is typical for IPv6 tunnels (e.g., GRE or IPv6-in-IPv4) and is not too small; IPv6 requires a minimum MTU of 1280 bytes, so 1480 is sufficient. Option D is wrong because the output explicitly says 'IPv6 is enabled' and shows the link-local address and joined multicast groups, confirming IPv6 is operational on the tunnel.

883
MCQmedium

A network engineer runs the following command to troubleshoot a Route Summarization issue: R1# show ip bgp 10.0.0.0/16 BGP routing table entry for 10.0.0.0/16, version 2 Paths: (1 available, best #1, table default) Advertised to update-groups: 1 Refresh Epoch 1 Local, (aggregated by 65000 1.1.1.1) 10.1.1.2 from 10.1.1.2 (2.2.2.2) Origin IGP, metric 0, localpref 100, valid, external, best Atomic-aggregate What does this output indicate?

A.The route 10.0.0.0/16 is an aggregate route, and the atomic-aggregate attribute indicates that the AS path may be incomplete.
B.The route is a normal BGP learned route without summarization.
C.The route is suppressed and not advertised to neighbors.
D.The route is learned via redistribution from OSPF.
AnswerA

The aggregated by 65000 notation and Atomic-aggregate attribute confirm this is a summary route. Atomic-aggregate signals that the aggregate lacks the AS path information of its more specific component routes, so the path may be incomplete.

Why this answer

This output shows the BGP table entry for prefix 10.0.0.0/16. The path is marked as 'aggregated', indicating it is a summary route. The 'Atomic-aggregate' attribute suggests that the route is an aggregate and may have lost some AS path information.

884
MCQmedium

A network engineer runs the following command to verify IPv6 access-list hits: R1# show ipv6 access-list FILTER | include matches permit ipv6 2001:DB8:1::/48 any sequence 10 (10 matches) deny ipv6 2001:DB8:2::/48 any sequence 20 (5 matches) permit ipv6 any any sequence 30 (100 matches) What does this output indicate?

A.5 packets from 2001:DB8:2::/48 have been denied, and 110 packets have been permitted.
B.All packets from 2001:DB8:2::/48 have been permitted.
C.The access list has been applied to an interface but not used.
D.The access list is invalid because of the order of entries.
AnswerA

The match counters confirm the deny entry dropped five packets sourced from 2001:DB8:2::/48, while the two permit statements passed 10 and 100 packets respectively, totalling 110 permitted. This directly satisfies the stem's request to verify per-sequence IPv6 ACL hit counts.

Why this answer

The output shows the hit counts for each ACL entry: sequence 10 has permitted 10 packets from 2001:DB8:1::/48, sequence 30 has permitted 100 packets from any source, and sequence 20 has denied 5 packets from 2001:DB8:2::/48. The total permitted packets are 10 + 100 = 110, and the denied count is 5, matching the statement in A.

Exam trap

Cisco often tests the misconception that hit counts on a deny entry mean the traffic was permitted, but in reality, the hit count indicates how many packets matched that deny rule and were dropped.

How to eliminate wrong answers

Option B is wrong because the hit count of 5 on the deny entry (sequence 20) indicates that packets from 2001:DB8:2::/48 were explicitly denied, not permitted. Option C is wrong because the non-zero hit counts (10, 5, 100) prove the ACL has been actively used on an interface, not just applied without traffic. Option D is wrong because the order of entries is valid: the more specific permit for 2001:DB8:1::/48 comes first, followed by a deny for 2001:DB8:2::/48, and a catch-all permit at the end; this is a standard and correct ACL design.

885
MCQmedium

What is the default LDP keepalive timer value on Cisco IOS-XE routers?

A.180 seconds
B.120 seconds
C.60 seconds
D.300 seconds
AnswerA

Cisco IOS-XE LDP sessions send keepalive messages every 180 seconds by default, satisfying the question's request for the default timer value. This interval is independent of the separate LDP hold time, which defaults to 180 seconds as well but governs session teardown rather than message frequency.

Why this answer

The default LDP keepalive timer is 180 seconds, which is used to maintain the LDP session if no other messages are exchanged.

886
MCQmedium

A network engineer is troubleshooting a DMVPN phase 2 network where the hub router is not learning the loopback interface routes from the spokes via EIGRP. The spokes have EIGRP configured on the tunnel interface and are advertising their loopback0 interface. The hub's EIGRP neighbor relationship with the spokes is established. However, the hub's routing table does not contain the loopback routes. The engineer checks the spoke's EIGRP configuration and sees that the loopback interface is not included in any network statement. What is the most likely cause?

A.The spoke's EIGRP network statement does not include the loopback subnet.
B.The hub's EIGRP is configured with a distribute-list that filters the loopback routes.
C.The tunnel interface on the spoke has 'no ip split-horizon' configured.
D.The loopback interface on the spoke is in a different VRF than the tunnel interface.
AnswerA

EIGRP advertises only interfaces matched by a network statement. The loopback0 subnet is absent from any network statement on the spoke, so it is never placed into EIGRP and cannot be advertised to the hub, despite the neighbour adjacency being up.

Why this answer

The hub is not learning the loopback routes because the spoke's EIGRP configuration does not include the loopback subnet in any network statement. EIGRP only advertises interfaces that are explicitly matched by a network command. Since the loopback is not included, it is not advertised to the hub.

Exam trap

300-410 often tests the assumption that EIGRP automatically advertises all connected interfaces, when in fact it only advertises those matched by network statements, leading candidates to overlook missing network commands.

How to eliminate wrong answers

Option B is wrong because a distribute-list on the hub would filter incoming routes, but the question states the hub's EIGRP neighbor relationship is established and the engineer is checking the spoke's configuration; there is no mention of a distribute-list. Option C is wrong because 'no ip split-horizon' on the tunnel interface affects route advertisement between spokes, not the advertisement of the loopback to the hub. Option D is wrong because the loopback being in a different VRF would prevent EIGRP from advertising it, but the question does not indicate VRFs are in use, and the most direct cause given the configuration check is the missing network statement.

887
MCQmedium

A network engineer runs the following command on Router R1: R1# show crypto map Crypto Map "VPN-MAP" 10 ipsec-isakmp Peer = 10.1.1.2 Extended IP access list 100 access-list 100 permit ip 10.1.1.0 0.0.0.255 192.168.1.0 0.0.0.255 Current peer: 10.1.1.2 Security association lifetime: 4608000 kilobytes/3600 seconds PFS (Y/N): N Transform sets={ESP-AES256-SHA,} Interfaces using crypto map VPN-MAP: Tunnel0 Based on this output, which statement is correct?

A.The crypto map is applied to interface Tunnel0 and uses ACL 100 to define interesting traffic.
B.Perfect Forward Secrecy (PFS) is enabled.
C.The crypto map uses dynamic IPsec peer discovery.
D.The crypto map is not applied to any interface.
AnswerA

The output explicitly lists Tunnel0 under interfaces using crypto map VPN-MAP, and ACL 100 defines the interesting traffic matching 10.1.1.0/24 to 192.168.1.0/24. Both facts are directly stated, confirming the crypto map's application point and traffic selector.

Why this answer

The output clearly shows that the crypto map 'VPN-MAP' is applied to interface Tunnel0, as indicated by the 'Interfaces using crypto map VPN-MAP: Tunnel0' line. It also shows that ACL 100 is used to define interesting traffic, with the permit statement matching source 10.1.1.0/24 to destination 192.168.1.0/24. Therefore, the statement that the crypto map is applied to Tunnel0 and uses ACL 100 is correct.

Exam trap

The trap is misreading the PFS line — candidates might see 'PFS (Y/N): N' and incorrectly assume it means 'Yes' or overlook it entirely, leading them to pick option B. Always double-check the exact value shown in the output.

How to eliminate wrong answers

Option B is wrong because the output explicitly states 'PFS (Y/N): N', meaning Perfect Forward Secrecy is disabled, not enabled. Option C is wrong because the crypto map shows a static peer address (Peer = 10.1.1.2) and does not indicate dynamic peer discovery; dynamic peer discovery would typically be configured with a dynamic crypto map or a peer with 'dynamic' keyword. Option D is wrong because the output lists 'Interfaces using crypto map VPN-MAP: Tunnel0', confirming it is applied to an interface.

888
Multi-Selecthard

An engineer must configure a Cisco IOS router to log messages to a syslog server at 192.168.1.100 with a severity level of 3 (errors) and above, while also ensuring that console messages are limited to severity 5 (notifications) and above. Which TWO configuration changes are required? (Choose TWO.)

Select 2 answers
A.Configure 'logging host 192.168.1.100' and 'logging trap errors'.
B.Configure 'logging console debugging' to ensure all messages are seen on console.
C.Configure 'logging console notifications'.
D.Configure 'logging buffered errors' to store logs locally.
E.Configure 'logging source-interface Loopback0' to use a specific source IP.
AnswersA, C

'logging host 192.168.1.100' defines the syslog destination, and 'logging trap errors' sets the syslog severity filter to level 3, so errors and above are sent. Together they satisfy the requirement to forward severity 3 and higher to the server.

Why this answer

Option A is correct because 'logging host 192.168.1.100' defines the syslog server destination and 'logging trap errors' sets the syslog severity threshold to level 3 (errors), so messages at severity 3 and above are sent to the server. Option C is correct because 'logging console notifications' sets the console logging severity to level 5 (notifications), which limits console output to severity 5 and above as required. Option B is incorrect because 'logging console debugging' sets the console to level 7, which would show all messages rather than limiting them to severity 5 and above.

Option D is incorrect because 'logging buffered errors' configures local buffered logging, not the syslog server or console severity requirements. Option E is incorrect because 'logging source-interface Loopback0' only sets the source IP for syslog messages and is not required by the stated scenario.

Exam trap

Cisco often tests the distinction between 'logging trap' (for syslog server) and 'logging console' (for console output), and candidates may confuse 'logging console debugging' as a way to limit messages when it actually enables all messages.

889
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology. The hub router is a Cisco IOS XE device running a recent release. The engineer notices that spoke-to-spoke traffic is still traversing the hub even though the spokes have established direct tunnels. Which technology must be enabled on the hub to allow spoke routers to dynamically discover a direct path to other spokes?

A.Enable OSPF point-to-multipoint on the hub.
B.Enable NHRP redirect on the hub.
C.Enable NHRP shortcut on the hub.
D.Enable IPsec tunnel protection on the hub.
AnswerB

NHRP redirect on the hub informs the originating spoke that a better path exists to the destination spoke. The hub sends an NHRP redirect message to the source spoke, which then initiates an NHRP resolution for the destination spoke's NBMA address. This enables the spoke to build a direct tunnel, bypassing the hub for subsequent packets.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to notify a source spoke that a more optimal path exists to a destination spoke. The spoke must have NHRP shortcut enabled to act on the redirect and initiate direct tunnel creation. Together, they allow dynamic spoke-to-spoke tunnels without preconfiguration.

Exam trap

The trap here is confusing NHRP redirect (hub) with NHRP shortcut (spoke), assuming either alone enables direct spoke-to-spoke tunnels.

890
Multi-Selectmedium

A network engineer is configuring a Cisco IOS router to act as a DHCP server for a subnet 10.10.10.0/24. The engineer wants to ensure that the router provides the default gateway, DNS server, and domain name to DHCP clients. Which three commands must be configured in the DHCP pool? (Choose three.)

Select 3 answers
A.dns-server 8.8.8.8
B.lease 0 8
C.network 10.10.10.0 255.255.255.0
D.default-router 10.10.10.1
E.domain-name example.com
AnswersA, D, E

The dns-server command in DHCP pool configuration provides the IP address of the DNS server to clients. This is necessary for name resolution. The scenario explicitly requires the router to provide the DNS server address, so this command must be configured. Multiple DNS servers can be specified in a single command.

Why this answer

The correct commands are default-router, dns-server, and domain-name. These respectively provide the default gateway, DNS server address, and domain name to DHCP clients. The network command defines the pool's subnet but does not supply those options, and the lease command sets lease duration, which is not requested.

Exam trap

The trap here is selecting the network command because it is essential for the pool, but the question specifically asks for the commands that provide the gateway, DNS, and domain name, not the subnet definition.

891
MCQhard

A network administrator is troubleshooting an IPsec VPN between two Cisco routers. The VPN tunnel is up, but only small pings succeed; larger packets fail. The administrator suspects an MTU or fragmentation issue. Which action is most likely to resolve the problem while maintaining security?

A.Adjust the tunnel interface MTU and TCP MSS clamping on the tunnel interface.
B.Enable path MTU discovery (PMTUD) on the tunnel and rely on ICMP unreachable messages.
C.Increase the IP MTU on the physical interface to accommodate larger packets.
D.Disable IPsec encryption on the tunnel to eliminate overhead.
AnswerA

Lowering the tunnel interface MTU and configuring TCP MSS clamping ensures that packets are sized appropriately before encryption and encapsulation, preventing fragmentation or drops. This maintains security because the packets are still encrypted and encapsulated correctly. It is a standard best practice for IPsec VPNs to account for the additional overhead of IPsec and GRE headers, especially when the underlying path has a lower MTU.

Why this answer

IPsec and GRE encapsulation add overhead, reducing the effective MTU. When large packets are sent, they may exceed the path MTU and get dropped if fragmentation is not allowed. Adjusting the tunnel interface MTU and configuring TCP MSS clamping ensures that TCP sessions negotiate a smaller MSS, preventing fragmentation and packet loss while keeping the VPN secure.

Exam trap

The trap here is assuming that enabling PMTUD alone will fix the issue, but ICMP filtering often breaks PMTUD, making manual MTU and MSS adjustments necessary.

892
MCQmedium

A network engineer runs the following command to troubleshoot an EIGRP issue: R1# debug eigrp packets hello *Mar 1 00:05:23.123: EIGRP: received packet with MD5 authentication, key id = 1 *Mar 1 00:05:23.123: EIGRP: int GigabitEthernet0/0, src 10.1.1.2 dst 224.0.0.10, seq 0, ttl 1, opcode = 1 (Hello) *Mar 1 00:05:23.123: EIGRP: authentication failed for packet from 10.1.1.2, key id = 1, integrity check failed What does this output indicate?

A.The EIGRP neighbor relationship is up, but authentication is failing intermittently.
B.The MD5 key ID or key string does not match between R1 and 10.1.1.2, preventing neighbor formation.
C.EIGRP is using plain-text authentication and the key is incorrect.
D.The neighbor 10.1.1.2 is not configured for EIGRP authentication.
AnswerB

The debug output shows the Hello packet arrived with MD5 authentication and key id 1, but the integrity check failed. That mismatch in key string or key ID between R1 and 10.1.1.2 blocks authentication, so the neighbour adjacency cannot form.

Why this answer

The debug output shows an EIGRP packet with MD5 authentication was received from 10.1.1.2, but the integrity check failed. This indicates that the MD5 key ID or key string configured on R1 does not match the one on the neighbor, which prevents the neighbor relationship from forming. The 'integrity check failed' message is a definitive sign of an authentication mismatch, not an intermittent issue.

Exam trap

Cisco often tests the distinction between authentication failure due to a mismatch (which prevents neighbor formation) versus intermittent packet loss or misconfiguration of the authentication mode (e.g., confusing MD5 with plain-text).

How to eliminate wrong answers

Option A is wrong because the neighbor relationship cannot be up if authentication fails; the 'integrity check failed' message means the packet is discarded, so no adjacency is established. Option C is wrong because the debug output explicitly states 'MD5 authentication', not plain-text authentication, and the failure is due to an integrity check, not a plain-text key mismatch. Option D is wrong because the debug output shows that the neighbor 10.1.1.2 is sending packets with MD5 authentication (key id = 1), so it is configured for EIGRP authentication; the issue is a mismatch between the two devices.

893
MCQhard

An engineer configures a distribute-list on an OSPF router to filter routes. However, the routes are still being advertised to neighbors. Which is the most likely explanation?

A.The distribute-list filters routes in the routing table, not the LSAs sent in OSPF updates.
B.The distribute-list is applied to the wrong interface.
C.The distribute-list uses an incorrect prefix-list.
D.The OSPF process needs to be restarted for the distribute-list to take effect.
AnswerA

OSPF distribute-lists applied to routing updates filter routes entering the local routing table, not the link-state advertisements flooded to neighbours. Because LSAs are synchronised via the link-state database, neighbours still receive and install the routes.

Why this answer

In OSPF, a distribute-list applied under the OSPF process filters routes from being installed in the local routing table (or from being redistributed), but it does not filter LSAs from being flooded to neighbors. OSPF is a link-state protocol; once an LSA is originated, it is flooded throughout the area regardless of local distribute-list filtering. Therefore, routes still appear in neighbors' LSAs and can be installed if the SPF calculation permits.

Exam trap

The trap is assuming that OSPF distribute-lists filter routing updates like in EIGRP or RIP. Candidates must remember that OSPF is link-state and distribute-lists only affect local RIB installation, not LSA flooding.

How to eliminate wrong answers

Option B is wrong because applying a distribute-list to the wrong interface would affect only that interface's filtering, but the core issue is that OSPF distribute-lists do not filter LSAs. Option C is wrong because an incorrect prefix-list would simply filter the wrong routes, but the fundamental limitation remains that LSAs are not filtered. Option D is wrong because OSPF does not require a process restart for distribute-list changes to take effect; the command is applied immediately, but it only affects local route installation.

894
Multi-Selecthard

Which TWO statements about DHCPv6 stateless autoconfiguration (SLAAC) are true? (Choose TWO.)

Select 2 answers
A.SLAAC requires the 'A' flag to be set in Router Advertisements.
B.When using SLAAC, DHCPv6 can still be used to provide DNS server information.
C.The 'M' flag in Router Advertisements must be set for SLAAC to operate.
D.The command 'ipv6 nd other-config-flag' sets the 'M' flag in Router Advertisements.
E.SLAAC can only be used on Ethernet interfaces.
AnswersA, B

The autonomous address-configuration flag in the Router Advertisement tells hosts to form addresses themselves using the advertised prefix and interface identifier. Without this flag set, hosts will not perform SLAAC and must obtain addresses through stateful DHCPv6 instead.

Why this answer

Option A is correct because in IPv6 stateless address autoconfiguration (SLAAC), hosts form their global unicast addresses by combining a Router Advertisement prefix with an interface identifier, and the prefix is only usable for autoconfiguration when the Autonomous ('A') flag is set in the RA prefix information option. Option B is correct because SLAAC only supplies addressing and default gateway information; additional parameters such as DNS server addresses (RDNSS) can be delivered via DHCPv6 in stateless mode, which is why the 'O' (Other-config) flag exists to tell hosts to query DHCPv6 for other configuration. Option C is wrong because the 'M' (Managed) flag indicates that addresses should be obtained via stateful DHCPv6, not SLAAC; SLAAC does not require it.

Option D is wrong because 'ipv6 nd other-config-flag' sets the 'O' flag, not the 'M' flag (the 'M' flag is set with 'ipv6 nd managed-config-flag'). Option E is wrong because SLAAC is defined for IPv6 generally and works over any multicast-capable link type, not only Ethernet.

Exam trap

Cisco often tests the confusion between the 'M' (Managed) flag and the 'O' (Other Configuration) flag, as well as the misconception that SLAAC requires DHCPv6 or is restricted to specific interface types, leading candidates to incorrectly select options C or E.

895
MCQeasy

Which EIGRP packet type is used to acknowledge receipt of a reliable packet?

A.Hello
B.Update
C.Reply
D.Ack
AnswerD

EIGRP uses a dedicated Ack packet to confirm receipt of reliable packets such as Update, Query and Reply, without carrying routing data itself. This satisfies the stem's requirement for the packet type that acknowledges receipt, distinguishing it from Hello, which is unreliable and never acknowledged.

Why this answer

D is correct because the EIGRP Ack (Acknowledgement) packet is a special packet used exclusively to confirm the reliable delivery of EIGRP packets such as Update, Query, and Reply. Ack packets are sent as unicast to the source router and contain no data, serving only as a delivery confirmation. This mechanism ensures that EIGRP's Reliable Transport Protocol (RTP) can guarantee ordered and guaranteed delivery of critical routing information.

Exam trap

Cisco often tests the distinction between packet types that are sent reliably versus unreliably, and the trap here is that candidates confuse the Reply packet (which is a response to a Query) with an acknowledgment, when in fact Reply packets are data-carrying reliable packets that themselves require an Ack.

How to eliminate wrong answers

Option A is wrong because Hello packets are used for neighbor discovery and maintenance, not for acknowledging reliable packets; they are sent unreliably (multicast) and do not confirm receipt of any specific packet. Option B is wrong because Update packets carry routing information and are themselves sent reliably, requiring an Ack in response; they do not serve as acknowledgments. Option C is wrong because Reply packets are sent in response to Query packets during route computation and are also sent reliably, requiring their own acknowledgment; they do not function as generic acknowledgments.

896
MCQmedium

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP-IN Class-map: CoPP-EIGRP (match-all) 200 packets, 12000 bytes 5 minute offered rate 1000 bps, drop rate 0000 bps Match: access-group 150 police: cir 16000 bps, bc 3000 bytes, be 3000 bytes conformed 200 packets, 12000 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop R1# show ip eigrp neighbors EIGRP-IPv4 neighbors for process 100 H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num 0 10.1.1.2 Gi0/0 13 00:10:00 1 200 0 5 Based on this output, which statement is correct?

A.EIGRP packets are being dropped, causing neighbor flapping.
B.EIGRP traffic is being rate-limited but no packets are dropped.
C.The police rate is set to 8000 bps.
D.The EIGRP neighbor is not established.
AnswerB

The police counters show 200 conformed packets transmitted and zero exceeded or violated, so no drops occurred. EIGRP remains established with an active neighbour, confirming traffic is rate-limited to the 16000 bps CIR yet fully delivered, satisfying the statement that rate-limiting causes no packet loss.

Why this answer

The output shows that the CoPP policy 'CoPP-IN' matches EIGRP packets (via access-group 150) and applies a police rate of 16,000 bps. The 'conformed' counter shows 200 packets transmitted, while 'exceeded' and 'violated' counters are zero, indicating no packets have been dropped. The 'show ip eigrp neighbors' output confirms the neighbor is established with an uptime of 10 minutes, so EIGRP traffic is being rate-limited but not dropped, making option B correct.

Exam trap

Cisco often tests the misconception that a police rate being applied automatically means packets are being dropped, but the key is to check the actual packet counters (conformed/exceeded/violated) to determine if drops have occurred.

How to eliminate wrong answers

Option A is wrong because the 'exceeded' and 'violated' counters are zero, meaning no EIGRP packets have been dropped, and the neighbor uptime of 10 minutes with no flapping indicates stable adjacency. Option C is wrong because the police rate is explicitly set to 16,000 bps (cir 16000 bps), not 8,000 bps. Option D is wrong because the 'show ip eigrp neighbors' output clearly shows an established neighbor (10.1.1.2, interface Gi0/0, uptime 00:10:00).

897
Multi-Selectmedium

A network administrator is configuring IPsec VPN on a Cisco IOS router using IKEv2. The administrator wants to ensure that the IKEv2 proposal includes encryption and integrity algorithms that are considered secure. Which two algorithms should be included in the IKEv2 proposal? (Choose two.)

Select 2 answers
A.3DES for encryption
B.SHA-256 for integrity
C.MD5 for integrity
D.DES for encryption
E.AES-CBC-256 for encryption
AnswersB, E

SHA-256 is a secure hash algorithm used for integrity protection in IKEv2. It provides strong authentication and is recommended over older algorithms like SHA-1. In Cisco IOS, it is configured using `integrity sha256` within the IKEv2 proposal. Including SHA-256 ensures that the integrity of IKEv2 messages is protected with a modern, secure algorithm.

Why this answer

For a secure IKEv2 proposal, encryption and integrity algorithms must be strong. AES-CBC-256 provides robust encryption, and SHA-256 offers secure integrity protection. These are both recommended in modern Cisco IOS configurations. 3DES and DES are weak encryption algorithms, and MD5 is an insecure integrity algorithm.

Therefore, the correct choices are AES-CBC-256 and SHA-256.

Exam trap

The trap here is selecting legacy algorithms like 3DES or MD5 due to familiarity, when they are considered insecure and not recommended for new deployments.

898
MCQmedium

What is the default action for a CoPP policy-map class that does not have an explicit 'police' command?

A.Drop all packets in that class
B.Transmit all packets in that class
C.Log all packets in that class
D.Apply the default aggregate policer
AnswerB

A class without an explicit police command has no policer attached, so CoPP applies no rate limiting; packets matching that class are forwarded normally. The default action is therefore to transmit all packets in that class, with no drop or marking applied.

Why this answer

In Control Plane Policing (CoPP), if a class within a policy-map does not contain an explicit 'police' command, the default action is to transmit all packets matching that class. This is because CoPP operates on a permit-by-default model; only classes with a configured policer will have traffic rate-limited or dropped. The absence of a police action means no restriction is applied, so packets are allowed through to the control plane.

Exam trap

Cisco often tests the misconception that CoPP classes without a police command will drop traffic by default, similar to how an ACL ends with an implicit deny; the trap here is that CoPP uses a permit-by-default model for classes without explicit policing.

How to eliminate wrong answers

Option A is wrong because CoPP does not drop packets by default; dropping only occurs when a policer is configured and the traffic exceeds the specified rate. Option C is wrong because logging is not a default action in CoPP; logging must be explicitly configured using the 'log' keyword within a police action or via separate ACL logging. Option D is wrong because there is no default aggregate policer in CoPP; aggregate policers must be explicitly defined and referenced in the policy-map.

899
MCQmedium

A network engineer is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The engineer wants to ensure that the VPN tunnel only comes up when there is interesting traffic matching an extended ACL. The ACL is defined as: access-list 100 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255. The crypto map is applied to interface GigabitEthernet0/0. Which command is required to complete the configuration so that the router considers traffic matching the ACL as interesting?

A.match address 100
B.crypto map mymap 10 ipsec-isakmp
C.crypto isakmp policy 10
D.set peer 203.0.113.2
AnswerA

Within the crypto map configuration, the match address command specifies the extended ACL that defines interesting traffic. This ACL determines which packets are encrypted and sent through the tunnel. Here, match address 100 tells the router that traffic between 10.1.1.0/24 and 10.2.2.0/24 should be protected by IPsec, triggering the tunnel when such traffic is encountered.

Why this answer

The match address command within the crypto map entry binds the extended ACL to the crypto map, designating the traffic that should be protected by IPsec. In this scenario, the ACL 100 defines the interesting traffic between the two subnets. Without this command, the router would not know which packets to encrypt and tunnel, and the VPN would not initiate as intended.

Exam trap

The trap here is confusing the creation of the crypto map with the assignment of interesting traffic, assuming that defining the ACL alone is enough or that the peer command triggers the tunnel.

900
MCQmedium

A network engineer runs the following command to verify MPLS L3VPN operation: R1# show ip route vrf CUSTOMER-A summary Output: Route Source Networks Subnets Overhead Memory (bytes) connected 2 0 48 288 static 1 0 24 144 ospf 100 5 2 168 1008 bgp 65000 10 3 312 1872 External: 10, Internal: 0, Local: 0 Total 18 5 552 3312 What does this output indicate?

A.The VRF has 23 total routes
B.The VRF has 10 BGP routes
C.The VRF is using OSPF as the only IGP
D.The VRF has no external BGP routes
AnswerA

18 networks + 5 subnets = 23 total routes.

Why this answer

The 'Total' row shows 18 networks and 5 subnets, giving 23 total routes in the VRF. The summary output aggregates route sources, and the total line combines all route entries across connected, static, OSPF, and BGP sources. Therefore the VRF contains 23 routes in total.

Exam trap

The trap here is reading only the 'Networks' column and ignoring the 'Subnets' column, which leads candidates to undercount total routes — 300-410 frequently tests whether you can correctly sum both columns.

How to eliminate wrong answers

Option B is wrong because the BGP line shows 10 networks and 3 subnets, totaling 13 BGP routes, not 10 — the 'Networks' column alone does not represent total routes. Option C is wrong because the output clearly shows BGP 65000 routes in addition to OSPF 100, so OSPF is not the only routing protocol. Option D is wrong because the BGP section explicitly states 'External: 10', meaning there are 10 external BGP routes, contradicting the claim of none.

Page 11

Page 12 of 19

Page 13