Courseiva

Cisco CCNP ENARSI 300-410 (300-410) — Questions 901–975

1401 questions total · 19pages · All types, answers revealed

Page 12

Page 13 of 19

Page 14
901
MCQhard

A network engineer is troubleshooting a DMVPN Phase 3 network where spoke-to-spoke communication is not working. The hub is configured with ip nhrp redirect, and spokes are configured with ip nhrp shortcut. The routing protocol is OSPF, and the hub is configured with ip nhrp map multicast dynamic. The engineer notices that when a spoke pings another spoke's LAN IP, the first few pings fail, but subsequent pings succeed. However, the engineer wants to eliminate the initial packet loss. Which of the following is the most likely cause of the initial packet loss?

A.The hub is not configured with no ip next-hop-self for OSPF, causing the spokes to use the hub as the next hop and delaying direct tunnel establishment.
B.The hub is not configured with ip nhrp redirect, so the first packets are dropped while NHRP resolution occurs.
C.The spokes are not configured with ip nhrp shortcut, so they cannot build direct tunnels.
D.The initial packet loss is expected because the spoke must first send an NHRP resolution request and receive a reply before building the direct tunnel.
AnswerD

In DMVPN Phase 3, when a spoke needs to reach another spoke's network, it initially sends packets to the hub. The hub forwards them and sends an NHRP redirect to the source spoke. The source spoke then sends an NHRP resolution request for the destination spoke's NBMA address, waits for a reply, and then builds a direct tunnel. During this process, the first few packets may be dropped or delayed. This is a normal behavior and not a configuration error.

Why this answer

The initial packet loss in DMVPN Phase 3 spoke-to-spoke communication is a normal occurrence. When a spoke first attempts to reach another spoke, it does not have a direct tunnel. It sends packets to the hub, which forwards them and simultaneously sends an NHRP redirect to the source spoke.

The source spoke then initiates NHRP resolution to learn the destination spoke's NBMA address. Until the resolution completes and the direct tunnel is built, packets may be dropped or delayed. This is inherent to the on-demand nature of Phase 3.

The other options suggest configuration errors that would prevent direct tunnels from working at all, but the scenario indicates they eventually work.

Exam trap

The trap here is assuming that initial packet loss indicates a misconfiguration, when it is actually expected behavior in DMVPN Phase 3.

902
MCQhard

A network administrator is troubleshooting a DMVPN Phase 3 configuration on a Cisco IOS router. The hub router is configured with a multipoint GRE tunnel interface and NHRP. Spoke routers are unable to establish direct spoke-to-spoke tunnels; all traffic between spokes is going through the hub. The administrator verifies that NHRP registration is successful and that the hub has a mapping for each spoke. Which configuration change on the hub is required to enable spoke-to-spoke direct communication?

A.Configure the tunnel interface with ip nhrp shortcut.
B.Configure the tunnel interface with ip nhrp map multicast dynamic.
C.Configure the tunnel interface with ip nhrp network-id 100.
D.Configure the tunnel interface with ip nhrp redirect.
AnswerD

In DMVPN Phase 3, the ip nhrp redirect command on the hub enables the hub to send NHRP redirect messages to spokes when it receives traffic that could be sent directly between spokes. This prompts the originating spoke to send an NHRP resolution request for the destination spoke's public IP, allowing a direct tunnel to be built. Without this, spoke-to-spoke traffic continues to traverse the hub.

Why this answer

In DMVPN Phase 3, spoke-to-spoke direct tunnels are facilitated by NHRP redirects from the hub and NHRP shortcuts on spokes. The hub must be configured with ip nhrp redirect to send redirect messages when it detects traffic between spokes that could be direct. This triggers the originating spoke to request the destination spoke's NBMA address and build a direct tunnel, offloading traffic from the hub.

Exam trap

The trap here is confusing the roles of ip nhrp redirect and ip nhrp shortcut, or applying the shortcut command on the hub instead of the spokes.

903
MCQmedium

A router is configured to send syslog messages to two servers: 10.1.1.100 and 10.1.1.200. The engineer notices that only server 10.1.1.100 is receiving messages. The configuration shows 'logging host 10.1.1.100' and 'logging host 10.1.1.200'. Both servers are reachable via ping. What is the most likely cause?

A.The syslog service on 10.1.1.200 is not running or is blocked by a firewall.
B.The router can only send to one syslog server at a time.
C.The 'logging host 10.1.1.200' command is missing the 'transport udp' keyword.
D.The second server is configured with a different severity level using 'logging trap' under the host.
AnswerA

Both hosts are configured and reachable at the network layer, so routing is not the fault. Syslog is UDP-based and fire-and-forget, meaning the router cannot detect a non-listening daemon or blocked port 514 on 10.1.1.200, which silently drops the messages.

Why this answer

The router is configured to send syslog messages to two servers, and both are reachable via ping. If only one server receives messages, the most likely cause is that the syslog service on the second server is not running or is blocked by a firewall. Ping only tests ICMP reachability, not UDP port 514, so a firewall blocking syslog traffic would not be detected by ping.

Exam trap

The trap is assuming that ping success guarantees syslog delivery, ignoring that ping tests ICMP while syslog uses UDP port 514, which may be blocked by a firewall or the service may be down.

How to eliminate wrong answers

Option B is wrong because Cisco routers can send syslog messages to multiple servers simultaneously; there is no limitation to a single server. Option C is wrong because the 'logging host' command does not require a 'transport udp' keyword; UDP is the default transport, and the command syntax is valid without it. Option D is wrong because 'logging trap' is a global command that sets the severity level for all syslog servers; it cannot be configured per host under the 'logging host' command.

904
MCQeasy

A network engineer is configuring a Cisco router to act as a DHCPv6 server for a dual-stack network. The engineer wants to provide IPv6 addresses to clients and also supply them with DNS server addresses. Which DHCPv6 message type should the server use to send the DNS server information to the clients?

A.Solicit
B.Advertise
C.Information-request
D.Reply
AnswerD

The Reply message is used by the DHCPv6 server to provide configuration information, including IPv6 addresses and DNS server addresses, to the client. It is sent in response to a Request, Renew, Rebind, or Information-request message. This is the correct message type for delivering DNS server information.

Why this answer

In DHCPv6, the server uses the Reply message to deliver configuration parameters, including DNS server addresses, to clients. Clients request this information via Information-request or as part of address assignment, and the server responds with a Reply. The other message types serve different purposes in the DHCPv6 protocol exchange.

Exam trap

The trap here is confusing the Information-request message, which is sent by the client, with the Reply message, which is sent by the server to deliver the requested information.

905
MCQmedium

Consider the following configuration on a router running BGP and OSPF: ``` router bgp 65000 distance bgp 20 200 200 ``` What is the effect of this command?

A.It sets the administrative distance for eBGP routes to 20, iBGP routes to 200, and local BGP routes to 200.
B.It sets the administrative distance for all BGP routes to 20.
C.It sets the administrative distance for eBGP routes to 200 and iBGP routes to 20.
D.It sets the administrative distance for BGP routes to 20 for routes learned from AS 65000.
AnswerA

The distance bgp command takes three arguments in order: external, internal and local BGP routes. Setting 20 200 200 therefore gives eBGP routes an administrative distance of 20, while iBGP and locally originated BGP routes both use 200.

Why this answer

The `distance bgp` command sets AD for BGP routes: external (eBGP) to 20, internal (iBGP) to 200, and local to 200.

906
MCQmedium

A network engineer is troubleshooting a DMVPN Phase 3 deployment on a Cisco IOS XE router. The hub router is configured with 'ip nhrp redirect' and the spoke routers with 'ip nhrp shortcut'. However, spoke-to-spoke traffic is still traversing the hub. Which action should the engineer take to enable direct spoke-to-spoke communication?

A.Configure 'ip nhrp network-id' with the same value on all routers.
B.Configure 'ip nhrp map multicast dynamic' on the hub.
C.Ensure that the spoke routers have a route to the spoke networks via the tunnel interface and that NHRP resolution is working.
D.Enable 'ip nhrp authentication' on all routers.
AnswerC

For DMVPN Phase 3 shortcuts to work, spokes must have a route to the destination spoke network pointing to the tunnel interface, and NHRP must resolve the destination NBMA address. The hub uses redirect messages to inform spokes of a better path, and spokes use shortcut to install a direct NHRP entry. Without proper routing and NHRP, shortcuts fail.

Why this answer

Spoke-to-spoke shortcuts in DMVPN Phase 3 require that spokes have a route to the destination network via the tunnel interface and that NHRP resolution succeeds. The hub uses NHRP redirect to tell the spoke that a better path exists, and the spoke uses NHRP shortcut to install a direct entry. Without these, traffic continues through the hub.

Exam trap

The trap here is assuming that enabling NHRP redirect and shortcut alone is sufficient, without verifying that routing and NHRP resolution are correctly configured.

907
Multi-Selecthard

Which TWO statements correctly describe the behavior of BGP conditional route injection? (Choose TWO.)

Select 2 answers
A.The injected route is automatically redistributed into connected and static routes.
B.The condition for injection is defined by an exist-map, which must match a less specific prefix in the BGP table.
C.The inject-map specifies the more specific prefix to be injected along with optional attributes.
D.The 'show ip bgp neighbors' command displays the number of injected prefixes per neighbor.
E.The injected prefix must be learned from the neighbor specified in the inject-map.
AnswersB, C

Conditional injection uses an exist-map to test a condition route. That map matches a less specific prefix already present in the BGP table; injection proceeds only while that covering route exists, tying the trigger to a broader aggregate.

Why this answer

Option B is correct because conditional route injection uses an exist-map that references a less specific (covering) prefix which must already be present in the BGP table for the injection to occur. Option C is correct because the inject-map defines the more specific prefix (or prefixes) to be conditionally injected, along with any optional BGP attributes such as community or local preference. Option A is wrong because conditional injection does not automatically redistribute connected or static routes; it injects a specific prefix defined in the inject-map.

Option D is wrong because 'show ip bgp neighbors' does not display a count of injected prefixes per neighbor; verification is done with commands like 'show ip bgp injected-paths' or 'show ip bgp'. Option E is wrong because the injected prefix does not need to be learned from the neighbor referenced in the inject-map; the exist-map only requires the less specific prefix to exist in the BGP table.

Exam trap

The trap is confusing exist-map and inject-map roles — candidates often swap them, thinking the inject-map defines the condition and the exist-map defines the prefix, which reverses the actual behavior.

908
MCQmedium

A network engineer runs the following command to debug MPLS LDP label advertisements: R1# debug mpls ldp labels Output: *Mar 1 00:01:23.456: LDP: Sent label mapping for 192.168.1.0/24, label 101 *Mar 1 00:01:23.789: LDP: Received label mapping for 192.168.2.0/24, label 201 *Mar 1 00:01:24.012: LDP: Sent label mapping for 10.0.0.0/8, label 102 *Mar 1 00:01:24.345: LDP: Received label mapping for 10.0.0.0/8, label 202 What does this output indicate?

A.LDP label bindings are being exchanged between R1 and its LDP neighbor
B.R1 is only receiving label mappings, not sending any
C.The LDP session is down
D.R1 is using implicit null label for 10.0.0.0/8
AnswerA

The debug confirms R1 and its LDP peer are exchanging label bindings: R1 advertises local labels (101, 102) for its prefixes while receiving remote mappings (201, 202) for the same or different destinations. This bidirectional mapping satisfies the stem's requirement to verify LDP label advertisement between neighbours.

Why this answer

The debug output shows R1 sending and receiving label mappings for various prefixes, indicating that LDP label bindings are being exchanged with its LDP neighbor. This is normal LDP operation for establishing label-switched paths.

Exam trap

300-410 often tests the interpretation of LDP debug output, and candidates may misread 'Sent' and 'Received' as session issues or implicit null usage.

How to eliminate wrong answers

Option B is wrong because the output clearly shows both 'Sent' and 'Received' messages. Option C is wrong because if the LDP session were down, no label mappings would be exchanged. Option D is wrong because implicit null is not indicated; explicit labels (101, 102, 201, 202) are being advertised.

909
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip eigrp traffic EIGRP-IPv4 Traffic Statistics for AS(100) Hellos sent/received: 5000/4995 Updates sent/received: 150/148 Queries sent/received: 10/8 Replies sent/received: 8/10 Acks sent/received: 300/298 Input queue high water mark: 10 Input queue drops: 0 SIA-Queries sent/received: 0/0 SIA-Replies sent/received: 0/0 Hello process ID: 123 PDM process ID: 124 Socket queue: 0/2000/10/0 (current/max/highest/drops) Input queue: 0/2000/10/0 (current/max/highest/drops) Based on this output, which statement is correct?

A.The EIGRP process is operating normally with no signs of issues.
B.There is a problem because more queries were sent than replies received.
C.The input queue drops of 0 indicate that the router is not processing EIGRP packets.
D.The SIA-Queries count of 0 indicates that the network has experienced stuck-in-active events.
AnswerA

Zero input queue drops, zero SIA queries and replies, and balanced Hello, Update, Query, Reply and Ack counters across sent and received all confirm stable adjacency and reliable transport. No stuck-in-active condition or queue congestion exists, so the EIGRP process is healthy.

Why this answer

The output shows normal EIGRP operation: Hellos are exchanged nearly equally (5000 sent vs 4995 received), Updates, Queries, Replies, and Acks are balanced, and both input queue drops and SIA counters are zero. This indicates stable neighbor relationships and no packet loss or stuck-in-active events, confirming the EIGRP process is functioning without issues.

Exam trap

Cisco often tests the misconception that an imbalance in query/reply counts automatically indicates a problem, when in fact small differences are normal and only significant, persistent mismatches with other symptoms (like SIA events) indicate trouble.

How to eliminate wrong answers

Option B is wrong because a slightly higher number of queries sent (10) than replies received (8) is normal in EIGRP; replies may be in transit or aggregated, and the difference is negligible without other signs of trouble. Option C is wrong because input queue drops of 0 indicate that the router is successfully processing all incoming EIGRP packets, not that it is failing to process them. Option D is wrong because SIA-Queries and SIA-Replies counts of 0 indicate that no stuck-in-active events have occurred, which is a healthy condition, not evidence of SIA events.

910
MCQmedium

What is the default CoPP behavior for traffic that does not match any class in the policy-map?

A.Dropped
B.Transmitted
C.Logged and dropped
D.Routed to the management plane
AnswerB

Cisco's Control Plane Policing default class treats unmatched traffic as conforming, so packets are forwarded rather than dropped. This satisfies the stem because the policy-map only polices explicitly classified classes, leaving all other control-plane traffic transmitted by default.

Why this answer

By default, Control Plane Policing (CoPP) uses a class-default in the policy-map that implicitly permits (transmits) all traffic not explicitly matched by a user-defined class. This default behavior ensures that only traffic matching a class with a 'drop' action is policed, preventing unintentional denial of service from misconfigured policies.

Exam trap

Cisco often tests the misconception that CoPP drops all unmatched traffic by default, similar to how ACLs have an implicit deny at the end, but CoPP's class-default actually permits traffic unless explicitly configured to drop.

How to eliminate wrong answers

Option A is wrong because CoPP does not drop unmatched traffic by default; it transmits it via the implicit class-default. Option C is wrong because logging and dropping is not a default action; logging requires explicit configuration (e.g., 'log' keyword under police) and is not applied to unmatched traffic. Option D is wrong because unmatched traffic is not routed to the management plane; it is forwarded to the control plane for normal processing (e.g., routing protocol packets) or punted to the CPU based on existing forwarding logic, not redirected to a separate plane.

911
MCQmedium

A network engineer runs the following command to troubleshoot BFD with static routes: R1# show ip route 10.8.8.0/24 Routing entry for 10.8.8.0/24 Known via "static", distance 1, metric 0 Routing Descriptor Blocks: * 10.9.9.2, via GigabitEthernet0/3 Route metric is 0, traffic share count is 1 BFD enabled, BFD state: UP What does this output indicate?

A.Static route is installed with BFD tracking, and BFD session is UP.
B.Static route is not using BFD.
C.BFD state is DOWN, so the static route is removed.
D.Static route is using BFD only for IPv6.
AnswerA

The route is installed from a static source with BFD tracking attached, and the session state shows UP, confirming the neighbour is reachable and the route is actively forwarding. BFD failure would withdraw the route.

Why this answer

The output shows that BFD is enabled for the static route and the BFD state is UP, meaning the next hop is reachable and BFD is providing fast failure detection.

912
MCQmedium

A network engineer runs the following command to verify MPLS L3VPN operation: R1# show bgp ipv4 unicast 10.1.1.0/24 Output: BGP routing table entry for 10.1.1.0/24, version 10 Paths: (1 available, best #1, table default) Advertised to update-groups: 1 Refresh Epoch 1 Local 0.0.0.0 from 0.0.0.0 (10.0.0.1) Origin incomplete, metric 0, localpref 100, weight 32768, valid, sourced, best What does this output indicate?

A.The route is locally originated and is the best path
B.The route is learned from a BGP peer
C.The route has an MPLS label
D.The route is in a VRF
AnswerA

The 'Local' origin with weight 32768, valid, sourced and best flags shows the prefix was injected on this router rather than learned from a peer, and BGP selected it as the active path. This confirms local origination and best-path selection.

Why this answer

The output shows 'Local' origin, '0.0.0.0 from 0.0.0.0', 'weight 32768', and 'sourced, best', which are all indicators that the route was locally originated on this router (e.g., via a network statement or redistribution) and is currently the best path. The 'best #1' and 'valid, sourced, best' confirm it is selected for the BGP table. There is no peer address or AS path, which rules out learning from a BGP neighbor.

Exam trap

The trap is misreading '0.0.0.0 from 0.0.0.0' as a missing or invalid peer — candidates unfamiliar with BGP output may think the route is broken, when in fact it is the standard signature of a locally originated route.

How to eliminate wrong answers

Option B is wrong because a route learned from a BGP peer would show the peer's IP address in the 'from' field and include an AS path; here 'from 0.0.0.0' and 'Local' indicate local origination. Option C is wrong because the output contains no MPLS label information — labels would appear in the VRF or LFIB output, not in this BGP table entry. Option D is wrong because the output says 'table default', meaning the route is in the global/default BGP table, not a VRF-specific table (which would show a VRF name or RD).

913
MCQhard

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 192.168.1.0/24 subnet to the 10.0.0.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which configuration element is used to define this traffic?

A.transform set
B.ISAKMP policy
C.ACL
D.crypto map
AnswerC

An extended ACL is used to define the interesting traffic that should be encrypted by IPsec. In this scenario, the ACL would permit IP traffic from 192.168.1.0/24 to 10.0.0.0/24. This ACL is referenced in the crypto map. Traffic matching the ACL is encrypted; traffic not matching is sent unencrypted. Thus, the ACL is the configuration element that defines the traffic.

Why this answer

In Cisco IOS IPsec configuration, an extended ACL is used to identify the traffic that should be encrypted. The ACL specifies the source and destination addresses and ports. This ACL is then referenced in the crypto map, which applies the IPsec policies to matching traffic.

Traffic that does not match the ACL is not encrypted and is routed normally. Therefore, the ACL is the configuration element that defines the traffic to be protected.

Exam trap

The trap here is confusing the ACL with the crypto map; while the crypto map references the ACL, it is the ACL that actually defines the traffic selection.

914
MCQhard

A network engineer runs the following command to troubleshoot an MPLS LDP issue: R1# debug mpls ldp transport LDP: Transport connection to 2.2.2.2:0 via TCP (passive) LDP: Connection from 2.2.2.2:0 to 1.1.1.1:646 LDP: Transport connection to 2.2.2.2:0 via TCP (active) LDP: Connection from 1.1.1.1:646 to 2.2.2.2:0 LDP: Hold timer expired for peer 2.2.2.2:0 LDP: Closing transport connection to 2.2.2.2:0 What does this output indicate?

A.LDP session is established and stable.
B.LDP session is flapping due to hold timer expiration.
C.LDP session is down because of authentication failure.
D.LDP session is down because of a transport address mismatch.
AnswerB

The log shows the TCP transport connection being opened, then closed after the hold timer expires, so the LDP session repeatedly re-establishes and drops. This confirms flapping caused by hold timer expiry rather than a configuration mismatch.

Why this answer

The output shows the LDP hold timer expiring for peer 2.2.2.2, followed by the transport connection being closed. This indicates the LDP session is repeatedly going up and down (flapping) because the hold timer expires before the session can stabilize, often due to network congestion, high CPU, or mismatched hello/hold timers. Option B correctly identifies this flapping behavior caused by hold timer expiration.

Exam trap

Cisco often tests the distinction between session flapping due to hold timer expiration versus session failure due to authentication or address mismatch, and the trap here is that candidates may see 'transport connection' messages and incorrectly assume the session is up, missing the critical 'Hold timer expired' line.

How to eliminate wrong answers

Option A is wrong because the hold timer expiration and connection closure indicate the session is not established or stable; a stable session would show 'LDP: Session up' or similar. Option C is wrong because authentication failure would produce debug messages like 'LDP: MD5 authentication failed' or 'LDP: Bad TLV', not hold timer expiration. Option D is wrong because a transport address mismatch would cause the connection to never establish or show 'LDP: Transport address mismatch' in debugs, not a hold timer expiration after a successful TCP connection.

915
MCQmedium

A network engineer is deploying BGP on a Cisco IOS XE router. The router must advertise the network 10.10.0.0/16 to an external peer, but the engineer notices that the prefix is not being advertised even though the network command is configured. The routing table shows that 10.10.0.0/16 is present as two separate /24 routes via OSPF. What is the most likely cause?

A.The BGP router ID is not reachable, preventing advertisement.
B.The BGP neighbor is configured with a send-community attribute that filters the prefix.
C.The OSPF routes are not being redistributed into BGP.
D.The network command requires an exact match in the routing table.
AnswerD

BGP network statements only advertise a prefix if there is an exact matching route in the IP routing table. Here, only 10.10.1.0/24 and 10.10.2.0/24 exist, not 10.10.0.0/16, so BGP will not originate the aggregate. To advertise the /16, the engineer must either create a summary route (e.g., a static route to Null0) or use the aggregate-address command.

Why this answer

BGP network statements require an exact match in the routing table to originate a prefix. The routing table contains only the more specific /24 routes, so the /16 is not advertised. To resolve this, the engineer must create a matching route, such as a static route to Null0, or use the aggregate-address command with the summary-only option.

The other options do not address the fundamental requirement of an exact match.

Exam trap

The trap here is assuming that a BGP network statement will automatically summarize or advertise a supernet even when only more specific routes exist in the routing table.

916
MCQhard

A network engineer notices that IPv6 hosts on a segment are not receiving Router Advertisements, even though Router R1 has IPv6 unicast-routing enabled and an IPv6 address on the interface. Router R1 has the following relevant configuration: interface GigabitEthernet0/0 ipv6 address 2001:DB8:1::1/64 ipv6 nd suppress-ra ! Router R2, connected to the same segment, shows: no IPv6 neighbors in the neighbor cache for R1's link-local address. What is the root cause?

A.The interface is in a down state due to a Layer 1 issue, preventing RA generation.
B.The 'ipv6 nd suppress-ra' command is configured, which prevents Router Advertisements from being sent.
C.Router R2 has IPv6 routing disabled, so it cannot process RAs from R1.
D.The IPv6 address on R1 is not in the same subnet as the hosts, causing RA filtering.
AnswerB

The 'ipv6 nd suppress-ra' command on GigabitEthernet0/0 disables Router Advertisement transmission on that interface, so hosts never receive RAs and cannot autoconfigure or learn the default gateway. R2's empty neighbour cache confirms no RA or NS exchange occurred with R1's link-local address.

Why this answer

The 'ipv6 nd suppress-ra' command explicitly disables the sending of Router Advertisements (RAs) on the interface. Even though IPv6 unicast-routing is enabled and an IPv6 address is configured, R1 will not transmit RAs, which prevents IPv6 hosts from autoconfiguring their addresses and default routes via SLAAC or DHCPv6. This is the direct root cause of the hosts not receiving RAs.

Exam trap

Cisco often tests the 'ipv6 nd suppress-ra' command as a direct countermeasure to RA generation, and the trap here is that candidates assume IPv6 unicast-routing alone is sufficient for RA generation, overlooking the explicit suppression command.

How to eliminate wrong answers

Option A is wrong because the interface is not in a down state; if it were, the IPv6 address would not be active and the neighbor cache issue would be different, but the problem explicitly states R1 has an IPv6 address on the interface. Option C is wrong because Router R2's ability to process RAs is irrelevant; the issue is that R1 is not sending RAs at all, not that R2 cannot receive them. Option D is wrong because RA filtering based on subnet mismatch is not a standard behavior; RAs are sent to the all-nodes multicast address (FF02::1) regardless of the configured subnet, and the hosts are on the same segment as R1's interface.

917
MCQmedium

A network engineer runs the following command on Router R1: R1# show bfd neighbors detail IPv4 Sessions NeighborAddr LD/RD Int State Holdown(mult) Intf 10.1.1.2 1/3 Gi0/0 Up 1500(3) Gi0/0 Session state is UP and not using echo function. OurAddr: 10.1.1.1 Handle: 1 Local Diag: 0, Demand mode: 0, Poll bit: 0 MinTxInt: 1000000, MinRxInt: 1000000, Multiplier: 3 Received MinRxInt: 1000000, Received Multiplier: 3 Holddown (hits): 1500(0) Rx Count: 120, Tx Count: 150 Based on this output, which statement is correct?

A.The BFD session is down because the holddown timer is incorrect.
B.The BFD session is up and the holddown timer is 1500 ms, which is correct based on the configured multiplier and MinRxInt.
C.The BFD session is using echo mode, which is why the holddown timer is 1500 ms.
D.The BFD session is up but the multiplier is set to 1, causing the holddown timer to be 1500 ms.
AnswerB

The holddown timer is calculated as MinRxInt * Multiplier = 1000000 microseconds * 3 = 3000000 microseconds = 3000 ms, but the output shows 1500 ms. This is a known behavior where the holddown timer displayed is half of the actual holddown time due to a software implementation detail. The session is up.

Why this answer

The output shows BFD session details. The Holddown value of 1500 ms is calculated as MinRxInt * Multiplier (1000 ms * 3 = 3000 ms), but the output shows 1500 ms. This discrepancy indicates a misconfiguration or a bug, but the key point is that the session is UP and the holddown timer is 1500 ms, which is half of the expected value.

However, the correct interpretation is that the BFD session is established and operating, and the holddown timer is 1500 ms as shown.

918
MCQhard

A service provider is deploying MPLS Traffic Engineering (TE) with RSVP-TE to ensure bandwidth guarantees for critical traffic. The network engineer has configured an MPLS TE tunnel on a Cisco IOS XE router. The tunnel must be able to signal an explicit path that includes a specific link with a reserved bandwidth of 50 Mbps. Which RSVP-TE object is used to carry the explicit route information in the Path message?

A.LABEL_REQUEST object
B.RSVP_HOP object
C.SESSION object
D.EXPLICIT_ROUTE object
AnswerD

The EXPLICIT_ROUTE object (ERO) is used in RSVP-TE Path messages to specify the explicit path that the TE tunnel should take. It contains a list of hops (usually IP addresses or autonomous system numbers) that the tunnel must traverse. In this scenario, the engineer needs to include a specific link in the path, and the ERO is the correct object to carry that information.

Why this answer

In RSVP-TE, the EXPLICIT_ROUTE object (ERO) is used to specify the explicit path for a TE tunnel. It is included in the Path message and contains the list of hops that the tunnel must traverse. The SESSION object identifies the session, the RSVP_HOP object provides previous hop information, and the LABEL_REQUEST object requests label bindings.

Only the EXPLICIT_ROUTE object carries the explicit route information needed to signal a path that includes a specific link.

Exam trap

The trap here is confusing the LABEL_REQUEST object, which requests labels, with the EXPLICIT_ROUTE object, which actually carries the explicit path information in the Path message.

919
MCQmedium

What is the default maximum number of NAT translations that can be created in Cisco IOS?

A.512 translations
B.1024 translations
C.Unlimited, limited only by available memory
D.4096 translations
AnswerC

Cisco IOS NAT creates translations dynamically, bounded only by available router memory and platform resources, not by a fixed licence or configuration ceiling. This satisfies the stem's request for the default maximum, since no hard-coded translation limit exists unless you explicitly configure ip nat translation max-entries.

Why this answer

Cisco IOS does not impose a fixed upper limit on the number of NAT translations; instead, translations are dynamically allocated from router memory. The only constraint is the available DRAM and the size of the NAT translation table, making option C correct.

Exam trap

Cisco often tests the misconception that NAT has a hard-coded default limit (like 512 or 1024) to trick candidates who memorize arbitrary numbers instead of understanding that NAT is memory-bound.

How to eliminate wrong answers

Option A is wrong because 512 is not a default limit; it is a common misconception based on older platforms or arbitrary thresholds. Option B is wrong because 1024 is not a default maximum; it may appear in some documentation as a recommended limit but is not enforced by IOS. Option D is wrong because 4096 is not a default maximum; it is a value sometimes associated with hardware-specific limits or licensing, not a global IOS default.

920
MCQmedium

A network engineer is troubleshooting PAT (overload) on a Cisco router. The inside network uses 192.168.1.0/24, and the outside interface has IP 198.51.100.1. The engineer configured 'ip nat inside source list 1 interface GigabitEthernet0/0 overload'. Traffic from inside hosts works initially, but after a few minutes, new connections fail. 'Show ip nat translations' shows many entries with the same outside global IP but different ports. 'Show ip nat statistics' indicates that the number of translations is near 500. What is the most likely cause?

A.The NAT pool is not configured with overload.
B.The outside interface is flapping, causing translations to be cleared.
C.The router has run out of available port numbers for PAT.
D.The access list is denying some inside hosts.
AnswerC

Correct because PAT uses a limited port range (usually 1024-65535), and with many sessions, ports can be exhausted, preventing new translations.

Why this answer

The router is using PAT (Port Address Translation) with overload, which maps multiple inside local IP addresses to a single outside global IP (198.51.100.1) by using unique source port numbers. With approximately 500 active translations and the router nearing the default limit of around 500 PAT entries (or the available port range of 1024–65535 being exhausted), new connections fail because no unique port numbers are available to assign. This is the classic symptom of PAT port exhaustion.

Exam trap

Cisco often tests the distinction between NAT pool exhaustion (running out of IP addresses) and PAT port exhaustion (running out of port numbers), and candidates may mistakenly think the problem is with the access list or interface stability when the real issue is the finite number of available PAT ports.

How to eliminate wrong answers

Option A is wrong because the command 'ip nat inside source list 1 interface GigabitEthernet0/0 overload' already configures overload (PAT) on the interface, so a separate NAT pool is not required and the pool is not the issue. Option B is wrong because an interface flapping would clear all translations abruptly, not cause gradual exhaustion with many entries still visible in 'show ip nat translations'. Option D is wrong because the access list (list 1) is used to define which inside hosts are eligible for NAT; if it were denying some hosts, those hosts would never get translations, but the problem is that existing translations are working and new connections from all hosts are failing after port exhaustion.

921
MCQmedium

Which BGP attribute is used as the first tie-breaker when selecting the best path in a VRF-Lite environment?

A.Local preference
B.Weight
C.AS path length
D.MED
AnswerB

Weight is Cisco-proprietary and evaluated before local preference, so it acts as the first tie-breaker in best-path selection. Within VRF-Lite, weight remains locally significant per router, making it the earliest attribute compared when choosing the best path.

Why this answer

In Cisco IOS BGP best-path selection, weight is the first attribute evaluated, and it is locally significant to the router. A higher weight is preferred. This applies in VRF-Lite environments as well because weight is a per-router, per-neighbor attribute evaluated before local preference, AS path, and MED.

Therefore weight is the first tie-breaker.

Exam trap

The trap is confusing the order of BGP attributes—candidates often pick local preference because it is well-known, but weight always precedes it in Cisco's best-path algorithm, and the question specifies 'first tie-breaker.'

How to eliminate wrong answers

Option A is wrong because local preference is evaluated after weight in the BGP best-path algorithm—it is the second tie-breaker, not the first. Option C is wrong because AS path length is evaluated after weight and local preference; shorter AS path wins, but it is not the first tie-breaker. Option D is wrong because MED (Multi-Exit Discriminator) is evaluated much later in the process, after AS path, origin, and other attributes, and it is used to influence inbound traffic from external ASes.

922
MCQmedium

A network engineer is configuring a Cisco IOS router to send syslog messages to a remote syslog server at 10.1.1.100. The router's loopback0 interface is 192.168.1.1. The engineer wants syslog messages to be sourced from the loopback0 interface. Which command must be configured?

A.logging host 10.1.1.100 transport udp port 514
B.logging source-interface loopback0
C.logging origin-id ip
D.logging facility local6
AnswerB

This command sets the source IP address for syslog messages to the loopback0 interface's IP address. It ensures that the syslog server sees a consistent and stable source address, which is especially useful for logging correlation and filtering. The loopback interface is always up, so the source address remains reachable even if physical interfaces flap.

Why this answer

The logging source-interface command configures the router to use the specified interface's IP address as the source for syslog packets. Using loopback0 provides a stable, always-up source address, which simplifies syslog server configuration and ensures logs are consistently attributed to the router regardless of which physical interface sends the traffic.

Exam trap

The trap here is confusing the command that sets the source IP address in the packet header with the command that only adds origin information to the message payload.

923
MCQmedium

A network engineer is configuring a Cisco IOS XE router as a DHCPv6 server for a dual-stack network. The router must provide IPv6 addresses and other configuration parameters to clients on VLAN 20. The engineer has configured a DHCPv6 pool named POOL1 with the address prefix 2001:DB8:20::/64 and the DNS server 2001:DB8::53. The clients are not receiving IPv6 addresses. Which additional configuration is required on the router's VLAN 20 interface to ensure DHCPv6 clients can obtain addresses?

A.ipv6 address dhcp
B.ipv6 nd managed-config-flag
C.ipv6 dhcp server POOL1
D.ipv6 nd other-config-flag
AnswerC

To enable the router to act as a DHCPv6 server on an interface, the ipv6 dhcp server <pool-name> command must be configured on that interface. This binds the DHCPv6 pool to the interface and allows the router to respond to DHCPv6 solicit messages from clients. Without this command, the router will not process DHCPv6 requests on VLAN 20, even though the pool exists. This is the missing piece to make the server operational.

Why this answer

To make a Cisco IOS XE router act as a DHCPv6 server on an interface, you must bind the DHCPv6 pool to that interface using the ipv6 dhcp server command. The pool configuration alone defines the parameters, but the interface must be explicitly enabled to serve DHCPv6. Without this command, the router will not listen for or respond to DHCPv6 client requests on VLAN 20.

Therefore, the correct answer is the interface-level command that activates the server function.

Exam trap

The trap here is confusing the router's role as a DHCPv6 server with a DHCPv6 client; the ipv6 address dhcp command is for client operation, not for serving addresses.

924
MCQeasy

Which statement about the Next Hop Resolution Protocol (NHRP) in DMVPN is correct regarding the purpose of NHRP Registration Request packets?

A.They are used to resolve the NBMA address of a destination tunnel IP address.
B.They are used to register the spoke's tunnel IP and NBMA address with the hub.
C.They are used to purge outdated NHRP cache entries on the hub.
D.They are used to establish an IPsec security association between spokes.
AnswerB

NHRP Registration Request packets are sent by spokes to the next-hop server (hub) to bind the spoke's tunnel IP address to its NBMA address, allowing the hub to map tunnel endpoints to physical addresses for dynamic spoke-to-spoke resolution.

Why this answer

NHRP Registration Request packets are sent by spokes to the hub to register their tunnel IP address and NBMA (Non-Broadcast Multiple Access) address. This allows the hub to maintain a mapping of tunnel IPs to NBMA addresses, enabling dynamic tunnel establishment between spokes.

Exam trap

300-410 often tests the confusion between NHRP Registration and Resolution messages, where candidates mistakenly think Registration resolves addresses instead of registering them.

How to eliminate wrong answers

Option A is wrong because resolving the NBMA address of a destination is done via NHRP Resolution Request, not Registration Request. Option C is wrong because purging outdated cache entries is handled by NHRP Purge Request/Reply messages. Option D is wrong because IPsec security associations are established via IKE, not NHRP.

925
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. Spokes are behind dynamic NAT and register with the hub using their public IP addresses. The engineer wants to ensure that spoke-to-spoke traffic can be established directly without traversing the hub. Which NHRP configuration is required on the hub to support this?

A.ip nhrp network-id 1
B.ip nhrp shortcut
C.ip nhrp redirect
D.ip nhrp map multicast dynamic
AnswerC

The ip nhrp redirect command on the hub enables the hub to send a redirect message to the originating spoke when it detects that traffic is being routed through the hub to another spoke. This allows the spoke to initiate a direct NHRP resolution for the destination spoke's NBMA address, enabling spoke-to-spoke tunnels. Without redirect, spokes would continue to use the hub for all inter-spoke traffic.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to inform spokes that a more optimal path exists directly to another spoke. The hub sends an NHRP redirect message to the source spoke, which then triggers an NHRP resolution for the destination spoke's NBMA address. The spoke then establishes a direct tunnel.

The hub must have ip nhrp redirect enabled, while spokes typically have ip nhrp shortcut to act on the redirect.

Exam trap

The trap here is confusing the roles of NHRP redirect and shortcut: redirect is configured on the hub to signal spokes, while shortcut is configured on spokes to create direct tunnels.

926
MCQmedium

An engineer applies the following configuration to an interface: interface GigabitEthernet0/5 ipv6 dhcp guard attach-policy DHCP_GUARD ipv6 snooping database file nvram:ipv6-snoop.db Which statement is true?

A.The DHCP guard policy is applied to the interface, and the snooping database is stored in NVRAM.
B.The DHCP guard policy is applied only if the snooping database is present.
C.The interface will not forward any DHCP messages until the database is populated.
D.The snooping database is used to validate DHCP server messages.
AnswerA

The `ipv6 dhcp guard attach-policy DHCP_GUARD` command binds the guard policy to GigabitEthernet0/5, enforcing server-message filtering there, while `ipv6 snooping database file nvram:ipv6-snoop.db` persists the snooping bindings to NVRAM rather than flash. Both statements match the interface configuration exactly.

Why this answer

The 'ipv6 dhcp guard attach-policy DHCP_GUARD' command applies the DHCP Guard policy to the interface, and the 'ipv6 snooping database file nvram:ipv6-snoop.db' command configures the snooping database to be stored in NVRAM. These two commands operate independently; the DHCP Guard policy is enforced immediately upon attachment, regardless of the database's presence or population state.

Exam trap

Cisco often tests the independence of First Hop Security features; the trap here is assuming that the snooping database must be present or populated for DHCP Guard to function, when in fact DHCP Guard operates based on the policy configuration alone.

How to eliminate wrong answers

Option B is wrong because the DHCP Guard policy is applied immediately when attached to the interface; it does not depend on the snooping database being present. Option C is wrong because the interface will forward DHCP messages normally; DHCP Guard only drops messages that violate the policy (e.g., unauthorized DHCP server messages), and the database does not need to be populated for forwarding to occur. Option D is wrong because the snooping database is used to store IPv6 snooping entries (e.g., bindings learned from ND and DHCP), not to validate DHCP server messages; validation is performed by the DHCP Guard policy itself based on the configured policy rules.

927
MCQhard

A network administrator is configuring a Cisco IOS router to use AAA authorization for administrative commands. The administrator wants to ensure that users are authorized for specific commands based on their user role. The TACACS+ server is configured with command authorization sets. Which AAA authorization method should the administrator configure to enforce command authorization?

A.aaa authorization auth-proxy default group tacacs+ local
B.aaa authorization network default group tacacs+ local
C.aaa authorization exec default group tacacs+ local
D.aaa authorization commands 15 default group tacacs+ local
AnswerD

This command enables authorization for commands at privilege level 15. When a user attempts to execute a command, the router sends an authorization request to the TACACS+ server, which checks the command against the configured command sets. This enforces per-command authorization based on the user's role. It is the correct method to achieve command authorization.

Why this answer

To enforce command authorization, the router must be configured to send authorization requests for each command entered by the user. The 'aaa authorization commands' command, specifying the privilege level (e.g., 15) and the method list (e.g., default) with TACACS+ as the first method, enables this functionality. The TACACS+ server must be configured with command sets that define which commands are permitted or denied.

Other authorization methods like exec, network, or auth-proxy serve different purposes and do not provide per-command authorization.

Exam trap

The trap here is confusing exec authorization, which controls session establishment and privilege level, with commands authorization, which controls individual command execution.

928
Multi-Selecthard

Which TWO configuration steps are required to implement Control Plane Policing (CoPP) on a Cisco IOS-XE router? (Choose TWO.)

Select 2 answers
A.Apply the policy map to a physical interface using the 'service-policy input' command.
B.Create a policy map that defines a police action for the classified traffic.
C.Create a class map to match the traffic that should be policed.
D.Configure a 'shape average' command in the policy map to limit traffic rate.
E.Apply the policy map to the control plane using the 'service-policy input' command under the interface configuration mode.
AnswersB, C

A policy map with a 'police' command is required to specify the rate and action for CoPP.

Why this answer

A policy map is required to define the police action (e.g., 'police rate 10000 conform-action transmit exceed-action drop') that enforces rate limiting on the classified traffic. Without a policy map specifying the policing parameters, CoPP cannot apply any QoS action to the control plane traffic. Option C is correct because a class map is necessary to classify the specific traffic types (e.g., SSH, BGP, ICMP) that should be subjected to policing, using match statements based on access lists or protocol headers.

Exam trap

Cisco often tests the distinction between applying the policy map under 'control-plane' configuration mode versus under a physical interface, as candidates mistakenly use 'interface GigabitEthernet0/0' instead of 'control-plane' to attach the CoPP policy.

929
MCQmedium

A network engineer configures a DMVPN spoke with the following: interface Tunnel0 ip address 10.0.0.3 255.255.255.0 ip nhrp network-id 100 ip nhrp nhs 10.0.0.1 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint ip nhrp map 10.0.0.1 192.168.1.1 ip nhrp map multicast 192.168.1.1 ! What will happen when the spoke tries to send traffic to another spoke (10.0.0.4)?

A.The spoke will send traffic directly to 10.0.0.4 if it has a cached NHRP mapping, otherwise through the hub.
B.The spoke will always send traffic through the hub because of the static multicast map.
C.The spoke will send traffic directly to 10.0.0.4 without using the hub.
D.The spoke will drop the traffic because it does not have a route to 10.0.0.4.
AnswerA

The spoke holds a static mapping only for the hub, so traffic to 10.0.0.4 initially goes through the hub. Once NHRP resolution returns 10.0.0.4's NBMA address, the spoke installs a shortcut and sends traffic directly, matching Phase 3 behaviour.

Why this answer

In DMVPN, a spoke can send traffic directly to another spoke if it has a cached NHRP mapping for that spoke's NBMA address. If no mapping exists, the spoke sends the packet to the hub (NHS), which then redirects it to the destination spoke and may send an NHRP resolution reply to the source spoke. The static multicast map only affects multicast traffic, not unicast.

Thus, option A correctly describes the behavior.

Exam trap

300-410 often tests the assumption that DMVPN spokes always communicate through the hub, confusing the role of static multicast maps with unicast traffic handling.

How to eliminate wrong answers

Option B is wrong because the static multicast map (ip nhrp map multicast) only influences multicast traffic; unicast traffic can still go directly if an NHRP mapping exists. Option C is wrong because the spoke does not automatically know the NBMA address of 10.0.0.4; it must either have a cached mapping or go through the hub to obtain it. Option D is wrong because the spoke has a route to 10.0.0.4 via the tunnel interface (since it's in the same subnet), so it will not drop the traffic; it will forward it appropriately.

930
MCQmedium

A network engineer runs the following command on Router R1: R1# show snmp trap SNMP Trap: enabled Trap receiver: 192.168.1.100 Community: PUBLIC Version: 2c UDP port: 162 Enable traps: snmp, interface, bgp Trap receiver: 192.168.1.200 Community: PRIVATE Version: 2c UDP port: 162 Enable traps: snmp, ospf Based on this output, which statement is correct?

A.BGP traps will be sent to 192.168.1.100 but not to 192.168.1.200.
B.Both receivers will receive OSPF traps.
C.The traps are sent using SNMPv3.
D.Interface traps are sent to 192.168.1.200.
AnswerA

The output lists bgp under the enable traps for receiver 192.168.1.100 only; receiver 192.168.1.200 enables snmp and ospf. Trap generation is filtered per receiver, so BGP traps reach the first host and never the second.

Why this answer

The output shows that traps are configured per receiver. The first receiver (192.168.1.100) has 'Enable traps: snmp, interface, bgp', while the second receiver (192.168.1.200) has 'Enable traps: snmp, ospf'. Since BGP is not listed for the second receiver, BGP traps will only be sent to 192.168.1.100, making option A correct.

Exam trap

Cisco often tests the misconception that all trap receivers receive the same set of traps, but in reality, trap enablement can be configured per receiver, and the 'show snmp trap' output clearly shows which traps are enabled for each host.

How to eliminate wrong answers

Option B is wrong because OSPF traps are only enabled for the second receiver (192.168.1.200), not for the first receiver (192.168.1.100), so both receivers will not receive OSPF traps. Option C is wrong because the output explicitly shows 'Version: 2c' for both receivers, indicating SNMPv2c is used, not SNMPv3. Option D is wrong because interface traps are enabled only for the first receiver (192.168.1.100), not for 192.168.1.200.

931
MCQmedium

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP-IN Class-map: CoPP-ICMP (match-all) 100 packets, 6000 bytes 5 minute offered rate 500 bps, drop rate 500 bps Match: access-group 100 police: cir 8000 bps, bc 1500 bytes, be 1500 bytes conformed 50 packets, 3000 bytes; actions: transmit exceeded 25 packets, 1500 bytes; actions: drop violated 25 packets, 1500 bytes; actions: drop Based on this output, what is the most likely impact on the router?

A.All ICMP packets are being transmitted without drops.
B.ICMP traffic is being rate-limited, causing some ping requests to fail.
C.The police rate is set to 16000 bps.
D.The class-default is matching ICMP traffic.
AnswerB

The police configuration caps ICMP at 8000 bps, and the output shows exceeded and violated packets being dropped rather than transmitted. Because conformed traffic alone is forwarded, excess ping requests are discarded, matching the rate-limiting impact described.

Why this answer

The output shows that ICMP traffic matching access-group 100 is being policed with a CIR of 8000 bps. Out of 100 packets, 50 were conformed (transmitted), 25 exceeded (dropped), and 25 violated (dropped). This results in a 50% packet loss, causing some ping requests to fail.

The drop rate equals the offered rate (500 bps) because the policer is dropping half the traffic. Therefore, option B is correct.

Exam trap

Candidates may misinterpret the 'conformed' counter as meaning all traffic is transmitted, but the exceeded and violated counters indicate actual drops. In this case, 50 packets were transmitted and 50 dropped, so the ICMP traffic is rate-limited, not completely blocked.

How to eliminate wrong answers

Option A is wrong because the drop rate is 500 bps, meaning packets are being dropped, not all transmitted. Option C is wrong because the police rate is explicitly set to 8000 bps (CIR), not 16000 bps. Option D is wrong because the class-map is CoPP-ICMP, not class-default; class-default would only match traffic not classified by other class-maps.

932
MCQeasy

What is the default BGP hold timer value in an MPLS L3VPN deployment on Cisco IOS-XE?

A.60 seconds
B.90 seconds
C.120 seconds
D.180 seconds
AnswerD

Cisco IOS-XE defaults the BGP hold timer to 180 seconds, with the keepalive timer derived as one third of that, giving 60 seconds. MPLS L3VPN deployments do not alter these defaults, so peers tear down a session only after 180 seconds of silence.

Why this answer

The default BGP hold timer is 180 seconds, meaning a peer is declared dead if no keepalive or update is received within that interval.

933
MCQmedium

A network administrator is configuring a Cisco IOS router to authenticate administrative logins using TACACS+ with a fallback to local authentication. The TACACS+ server is reachable, but the administrator wants to ensure that if the TACACS+ server becomes unreachable, local authentication is used. The router currently has the following configuration: aaa new-model aaa authentication login default group tacacs+ local tacacs server TAC1 address ipv4 10.1.1.1 key cisco What additional configuration is required to ensure that the router falls back to local authentication when the TACACS+ server does not respond?

A.Configure aaa authentication login default group tacacs+ local
B.Configure tacacs server TAC1 with the timeout 5 command
C.No additional configuration is required; the existing configuration already provides fallback to local authentication.
D.Configure aaa authentication login default group tacacs+ local-case
AnswerC

The existing AAA authentication list 'default' includes 'group tacacs+' followed by 'local'. In Cisco IOS, methods are attempted in order. If the TACACS+ servers are unreachable, the router will automatically fall back to the next method, which is local authentication. Therefore, the configuration already meets the requirement, and no further commands are needed.

Why this answer

The AAA authentication method list specifies the order of authentication methods. When 'group tacacs+' is followed by 'local', the router tries TACACS+ first. If the TACACS+ server does not respond (e.g., timeout), the router proceeds to the next method, local authentication.

Thus, the existing configuration already ensures fallback. The other options either do not enable fallback or are redundant.

Exam trap

The trap here is assuming that additional commands like 'local-case' or timeout settings are required to enable fallback, when the 'local' keyword already provides that behavior.

934
MCQhard

A network engineer runs the following command on Router R1: R1# show event manager policy registered No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 EIGRP_Neighbor_Down R1# show ip eigrp neighbors IP-EIGRP neighbors for process 100 H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num 0 192.168.1.2 Gi0/0 13 00:02:00 40 200 0 5 Based on this output, what is the most likely problem?

A.The EIGRP neighbor is down.
B.The EEM policy has been triggered.
C.The EIGRP neighbor is up, and the EEM policy is ready to trigger if it goes down.
D.The EEM policy is misconfigured.
AnswerC

The neighbour table shows a healthy adjacency: hold time 13 seconds, uptime two minutes, and no retransmissions queued. The registered EEM applet is armed and waiting, so no fault currently exists; it triggers only when the neighbour drops.

Why this answer

The 'show ip eigrp neighbors' output shows a neighbor with an uptime of 00:02:00 and a hold time of 13 seconds, meaning the adjacency is currently up and stable. The EEM applet named EIGRP_Neighbor_Down is registered and waiting; it has not fired because the neighbor has not gone down. Therefore the neighbor is up and the policy is armed to trigger only if the adjacency fails.

Exam trap

300-410 often tests whether candidates can distinguish a registered-but-idle EEM policy from a triggered one, so examinees see the policy name 'EIGRP_Neighbor_Down' and wrongly assume the neighbor is actually down.

How to eliminate wrong answers

Option A is wrong because the neighbor table clearly lists an active neighbor with a valid uptime and hold timer, indicating the adjacency is up. Option B is wrong because a triggered EEM policy would generate syslog output or an action, and the registered policy is simply listed as available, not executed. Option D is wrong because the policy is registered successfully and appears in the registry with a valid creation timestamp — nothing in the output indicates a configuration error.

935
MCQhard

A network engineer configures CoPP to protect the control plane, but after redistributing routes, some legitimate routing updates are dropped. Router R1 config: control-plane service-policy input COPP ! class-map match-all ROUTING match access-group name ROUTING ! policy-map COPP class ROUTING police 100000 15000 15000 conform-action transmit exceed-action drop ! access-list ROUTING permit tcp any any eq bgp access-list ROUTING permit udp any any eq 520 access-list ROUTING permit ospf any any R1# show policy-map control-plane input Class-map: ROUTING (match-all) 100 packets, 10000 bytes 5 minute offered rate 0 bps drop rate 0 bps Match: access-group name ROUTING police: cir 100000 bps, bc 15000 bytes, be 15000 bytes conformed 90 packets, 9000 bytes; actions: transmit exceeded 10 packets, 1000 bytes; actions: drop What is the root cause?

A.The CoPP police rate is too low for the volume of routing updates during redistribution, causing drops.
B.The access-list is missing EIGRP protocol, causing EIGRP packets to be dropped.
C.The class-map is match-all, which requires all conditions to match, but only one ACL is present.
D.The policy-map is applied to the input of the control-plane, but redistribution uses output.
AnswerA

The police counters show 10 packets exceeded the configured rate and were dropped, while offered rate sits at 0 bps. The 100000 bps CIR is insufficient for the burst of routing updates triggered by redistribution, so legitimate BGP, OSPF or RIP traffic is discarded.

Why this answer

The output shows that 10 packets were exceeded and dropped by the policer. The CoPP policy is configured with a committed information rate (CIR) of 100000 bps (100 kbps), which is relatively low for routing updates during redistribution. When routes are redistributed, there can be a burst of routing protocol packets (BGP, OSPF, etc.) that exceeds this rate, causing the policer to drop legitimate updates.

The root cause is that the police rate is too low for the volume of routing updates.

Exam trap

The trap is assuming that the access-list is incomplete or that the class-map configuration is wrong, when the statistics clearly show drops due to the policer; candidates might overlook the low CIR value and focus on other details.

How to eliminate wrong answers

Option B is wrong because the access-list does not need to include EIGRP; the question states that redistribution is causing drops, and the output shows drops in the ROUTING class, which includes BGP, OSPF, and RIP (UDP 520). EIGRP is not mentioned as being used, and even if it were, the drops are due to rate limiting, not missing EIGRP. Option C is wrong because 'match-all' with a single ACL is fine; it simply means all conditions in the class-map must match, but there is only one condition (the ACL), so it matches if the ACL permits.

Option D is wrong because CoPP is applied to the control-plane input, which is correct for traffic destined to the router itself; redistribution generates routing updates that are sent from the router, but the control-plane policy affects incoming routing protocol packets, not outgoing. The drops are on input, as shown by the policy-map statistics.

936
MCQhard

In BFD multihop sessions, what is the default value for the TTL (or hop limit) in outgoing BFD Control packets on Cisco IOS-XE?

A.1
B.64
C.128
D.255
AnswerD

BFD multihop Control packets default to a TTL of 255 on Cisco IOS-XE, satisfying the stem's request for the default hop limit. This high value lets multihop sessions traverse multiple routed hops while remaining distinguishable from single-hop BFD, which uses TTL 254 for authentication and loop prevention.

Why this answer

For BFD multihop sessions, Cisco IOS-XE defaults to a TTL of 255, as per RFC 5883, to ensure the packet can traverse multiple hops.

937
MCQmedium

A network engineer runs the following command on Router R1: R1# show event manager policy registered No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 OSPF_Neighbor_Down R1# show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 10.1.1.2 1 FULL/DR 00:00:36 192.168.1.2 GigabitEthernet0/0 Based on this output, what is the most likely conclusion?

A.The OSPF neighbor is down.
B.The EEM policy has been triggered.
C.The EEM policy is registered but not yet triggered because the OSPF neighbor is up.
D.The EEM policy is misconfigured.
AnswerC

The EEM applet OSPF_Neighbor_Down is registered and awaiting its trigger event, while the neighbour table shows 10.1.1.2 in FULL/DR state with 36 seconds of dead time remaining. Since the adjacency is established rather than down, the policy's syslog or SNMP trigger condition has not fired, satisfying the stem's requirement to explain the absence of policy execution.

Why this answer

The output shows the EEM policy 'OSPF_Neighbor_Down' is registered (listed in 'show event manager policy registered'), but the OSPF neighbor table shows the neighbor 10.1.1.2 in FULL/DR state with a Dead Time of 36 seconds, meaning the neighbor is up and stable. Therefore, the EEM policy has not been triggered because its triggering condition (OSPF neighbor down) has not occurred. The policy is simply waiting for the event.

Exam trap

The trap is assuming that a registered EEM policy means it has executed — candidates must distinguish between policy registration (armed) and policy triggering (fired), and correlate with the actual neighbor state.

How to eliminate wrong answers

Option A is wrong because the OSPF neighbor state is FULL/DR, which is the fully adjacent state — the neighbor is up, not down. Option B is wrong because there is no evidence the EEM policy has been triggered; if it had, we would expect to see syslog messages or actions taken, and the neighbor would likely be in a different state or flapping. Option D is wrong because the policy is registered successfully and there is no indication of misconfiguration — the output shows a valid registration entry, and the neighbor being up simply means the trigger condition hasn't fired.

938
MCQmedium

A network engineer runs the following command on Router R1: R1# show dmvpn Legend: Attrb -> S: Static, D: Dynamic, I: Incomplete N: NATed, L: Local, X: No Socket #Ent -> Number of NHRP entries with same NBMA peer NHS Status: E => Expecting Replies, R => Responding, W => Waiting UpDn Time -> Up or Down Time for a Tunnel ========================================================================== Interface: Tunnel0, IPv4 NHRP Details Type:Hub, NHRP Peers:2, # Ent Peer NBMA Addr Peer Tunnel Addr State UpDn Tm Attrb ----- --------------- ---------------- ----- -------- ----- 1 10.1.1.2 172.16.0.2 UP 00:02:15 D 1 10.1.1.3 172.16.0.3 UP 00:01:45 D Based on this output, which statement is correct?

A.Router R1 is a spoke with two hub peers.
B.Router R1 is a hub with two dynamically registered spokes.
C.The NHRP peers are static and not dynamic.
D.One spoke is experiencing a registration failure.
AnswerB

The Type field shows Hub, and both NHRP peer entries carry the D (Dynamic) attribute, meaning the spokes registered with R1 automatically rather than being statically configured. Two such peers confirm two dynamically registered spokes.

Why this answer

The output shows that Router R1 is a hub (Type: Hub) with two NHRP peers that are dynamically registered (Attrb: D). The peers have tunnel addresses 172.16.0.2 and 172.16.0.3, and both are in UP state. Therefore, R1 is a hub with two dynamically registered spokes.

Exam trap

300-410 often tests the interpretation of show dmvpn output; candidates may misread the Type or Attrb fields, or assume that 'D' means down instead of dynamic.

How to eliminate wrong answers

Option A is wrong because the Type is Hub, not Spoke. Option C is wrong because the Attrb column shows 'D' for Dynamic, not 'S' for Static. Option D is wrong because both peers are in UP state, indicating successful registration, not failure.

939
MCQmedium

A network engineer runs the following command to troubleshoot an MPLS L3VPN issue: R1# show bgp neighbors 10.0.0.2 advertised-routes Output: BGP table version is 10, local router ID is 10.0.0.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.1.1.0/24 0.0.0.0 0 32768 i *> 10.2.2.0/24 0.0.0.0 0 32768 i Total number of prefixes 2 What does this output indicate?

A.R1 is advertising two local prefixes to BGP neighbor 10.0.0.2
B.R1 is receiving two prefixes from BGP neighbor 10.0.0.2
C.R1 has no BGP routes
D.R1 is using OSPF to learn these prefixes
AnswerA

The advertised-routes keyword lists prefixes R1 has sent to neighbour 10.0.0.2, and both entries show weight 32768 with empty AS path, marking them as locally originated. This confirms R1 advertises two local prefixes, matching the option.

Why this answer

The command 'show bgp neighbors 10.0.0.2 advertised-routes' displays the routes that R1 is advertising TO neighbor 10.0.0.2, not routes received from it. The output shows two prefixes (10.1.1.0/24 and 10.2.2.0/24) with next hop 0.0.0.0, weight 32768, and origin 'i' (IGP) — these are locally originated routes in R1's BGP table being advertised to the neighbor. The 'Total number of prefixes 2' confirms two routes are being sent.

Exam trap

The trap is confusing 'advertised-routes' with 'received-routes' — candidates who skim the command often assume it shows what the router learned, but the keyword explicitly indicates outbound advertisements.

How to eliminate wrong answers

Option B is wrong because routes received FROM a neighbor are shown with 'show bgp neighbors 10.0.0.2 received-routes' (or 'routes'), not 'advertised-routes' — the command name explicitly indicates the direction of the routes. Option C is wrong because the output clearly shows two valid best routes (marked with '>') in the BGP table, so R1 does have BGP routes. Option D is wrong because the origin code 'i' indicates the routes were originated via IGP (interior) and injected into BGP, but the output does not show OSPF learning — the next hop 0.0.0.0 and weight 32768 indicate locally originated/redistributed routes, not OSPF-learned ones.

940
MCQeasy

Which default administrative distance is assigned to routes learned via the Open Shortest Path First (OSPF) protocol?

A.90
B.110
C.115
D.120
AnswerB

OSPF's default administrative distance is 110, making it preferred over IS-IS (115) and RIP (120) but less trusted than EIGRP (90) or static routes (1). This value determines route selection when multiple protocols offer a path to the same destination.

Why this answer

OSPF routes have a default administrative distance of 110, as defined by Cisco IOS.

941
MCQeasy

A network engineer runs the following command on Router R1: R1# show bfd neighbors detail IPv4 Sessions NeighborAddr LD/RD Int State Holdown(mult) Intf 10.1.1.2 1/3 Gi0/0 Up 3000(3) Gi0/0 Session state is UP and not using echo function. OurAddr: 10.1.1.1 Handle: 1 Local Diag: 0, Demand mode: 0, Poll bit: 0 MinTxInt: 1000000, MinRxInt: 1000000, Multiplier: 3 Received MinRxInt: 1000000, Received Multiplier: 3 Holddown (hits): 3000(0) Rx Count: 100, Tx Count: 100 Based on this output, what is the BFD session's local discriminator?

A.The local discriminator is 1.
B.The local discriminator is 3.
C.The local discriminator is 10.1.1.1.
D.The local discriminator is 10.1.1.2.
AnswerA

In the LD/RD column, the value before the slash is the local discriminator and the value after is the remote discriminator. The entry 1/3 therefore shows a local discriminator of 1, uniquely identifying this router's BFD session.

Why this answer

The local discriminator is the LD value shown in the output. In this case, it is 1.

942
MCQmedium

A network engineer runs the following command to troubleshoot a BGP Troubleshooting issue: R1# show bgp neighbors 10.1.1.2 advertised-routes BGP table version is 14, local router ID is 1.1.1.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.0.0.0/24 0.0.0.0 0 32768 i *> 192.168.1.0/24 0.0.0.0 0 32768 i Total number of prefixes 2 What does this output indicate?

A.R1 is receiving two routes from neighbor 10.1.1.2.
B.R1 is advertising two routes to neighbor 10.1.1.2, both originated locally.
C.R1 is advertising two routes, but one is suppressed due to dampening.
D.R1 is advertising two routes, but the neighbor is not receiving them due to filtering.
AnswerB

The output lists two prefixes under advertised-routes for neighbour 10.1.1.2, satisfying the stem's troubleshooting aim of confirming outbound advertisements. Both carry next hop 0.0.0.0, weight 32768 and empty AS path, which are the markers of locally originated networks rather than routes learned from another peer.

Why this answer

The command 'show bgp neighbors 10.1.1.2 advertised-routes' displays the prefixes that the local router (R1) is sending to the specified neighbor. Both entries show next hop 0.0.0.0 and weight 32768, which are characteristics of locally originated routes (network statements or redistribution) in the BGP table, confirming R1 is advertising two locally originated prefixes to 10.1.1.2.

Exam trap

The trap is confusing 'advertised-routes' (outbound from local router) with 'received-routes' (inbound from neighbor), leading candidates to misinterpret the direction of the BGP session.

How to eliminate wrong answers

Option A is wrong because 'advertised-routes' shows outbound advertisements from R1 to the neighbor, not routes received from the neighbor; received routes would be shown with 'show bgp neighbors 10.1.1.2 received-routes' (requires soft-reconfiguration inbound). Option C is wrong because the status codes column shows '*' and '>' for both prefixes, with no 'd' (damped) indicator, so neither route is suppressed by dampening. Option D is wrong because the output only reflects what R1 is advertising; it does not indicate whether the neighbor is filtering or receiving them — that would require checking the neighbor's inbound policy or 'show bgp neighbors' on the remote side.

943
MCQmedium

Examine the following EIGRP configuration on Router R6: interface GigabitEthernet0/2 ip hello-interval eigrp 100 15 ip hold-time eigrp 100 45 What is the effect of these commands?

A.EIGRP will send hello packets every 15 seconds and wait 45 seconds before declaring a neighbor down.
B.EIGRP will send hello packets every 45 seconds and wait 15 seconds.
C.EIGRP will use the default hello interval of 5 seconds and hold time of 15 seconds.
D.EIGRP will not form neighbor adjacencies because the hold time is not a multiple of the hello interval.
AnswerA

The hello-interval command sets the periodic hello timer to 15 seconds, and the hold-time command sets the hold timer to 45 seconds, after which the router declares the neighbour down if no hello is received.

Why this answer

The commands set a non-default hello interval of 15 seconds and a hold time of 45 seconds for EIGRP AS 100 on GigabitEthernet0/2. EIGRP uses the hello interval to determine how often it sends hello packets, and the hold time is the duration the router waits without receiving a hello before declaring the neighbor down. Option A correctly describes this behavior.

Exam trap

The trap here is that candidates often assume the hold time must be a multiple of the hello interval (e.g., 3x), but Cisco does not enforce this mathematically—only that the hold time is greater than the hello interval to avoid premature neighbor loss.

How to eliminate wrong answers

Option B is wrong because it reverses the values: the hello interval is 15 seconds, not 45, and the hold time is 45 seconds, not 15. Option C is wrong because the commands explicitly override the default hello interval (5 seconds on high-speed interfaces) and hold time (15 seconds) with the configured values. Option D is wrong because EIGRP does not require the hold time to be a multiple of the hello interval; the hold time must simply be greater than the hello interval to prevent flapping, and 45 is greater than 15, so adjacency can form.

944
MCQmedium

An engineer is troubleshooting an EIGRP issue where a router is not learning any routes from a neighbor, but the neighbor adjacency is up. The engineer checks the EIGRP topology table on the local router and sees that the neighbor is listed, but no routes from that neighbor are present. The engineer also verifies that the neighbor has routes to advertise. What is the most likely cause?

A.The neighbor is configured as an EIGRP stub router.
B.The local router has a distribute-list out applied to the neighbor.
C.The EIGRP metric weights are different on the two routers.
D.The local router has a route-map applied to the EIGRP process that is filtering all routes.
AnswerA

An EIGRP stub router advertises only its connected, summary or static routes, so the adjacency stays up while the local router receives no routes from it. That matches the topology table showing the neighbour but no learned prefixes.

Why this answer

When an EIGRP neighbor adjacency is up but no routes are received from the neighbor, the most likely cause is that the neighbor is configured as an EIGRP stub router. A stub router advertises only a default route or its directly connected and summary routes, depending on the stub setting, and does not advertise all learned routes. Since the engineer confirmed the neighbor has routes to advertise, the stub configuration on the neighbor would prevent those routes from being sent, even though the adjacency remains established.

Exam trap

Cisco often tests the distinction between conditions that prevent adjacency formation (like mismatched K values or AS numbers) versus conditions that allow adjacency but suppress route advertisement (like stub configuration), leading candidates to incorrectly select metric weight mismatches when the adjacency is already up.

How to eliminate wrong answers

Option B is wrong because a distribute-list out applied to the neighbor would filter routes on the local router before sending them, not affect routes received from the neighbor; the issue is about not learning routes, not about sending them. Option C is wrong because mismatched EIGRP metric weights (K values) prevent the neighbor adjacency from forming entirely, but the adjacency is up, so this cannot be the cause. Option D is wrong because a route-map applied to the EIGRP process on the local router would filter routes after they are received, but the topology table shows no routes from the neighbor at all, indicating the routes are not being advertised by the neighbor, not that they are being filtered inbound.

945
MCQeasy

A network administrator is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The administrator wants to ensure that uRPF is applied in strict mode on an interface that connects to an ISP. Which command correctly enables strict uRPF on the interface?

A.ip verify unicast source reachable-via tx
B.ip verify unicast reverse-path
C.ip verify unicast source reachable-via rx
D.ip verify unicast source reachable-via any
AnswerC

This command enables strict uRPF, which checks that the source IP address is reachable via the same interface the packet was received on. It is the correct syntax for strict mode on Cisco IOS and is suitable for ISP-facing interfaces where symmetric routing is expected.

Why this answer

Strict uRPF is enabled with the command 'ip verify unicast source reachable-via rx', which ensures the source address is reachable via the same interface the packet arrived on. This is the correct choice for an ISP-facing interface to prevent spoofed source addresses.

Exam trap

The trap here is confusing strict and loose uRPF modes: 'rx' enables strict mode, while 'any' enables loose mode.

946
MCQhard

A large enterprise network is experiencing intermittent BGP session resets between R1 and R2. R1 has the following relevant configuration: event manager applet BGP-MONITOR event syslog pattern "%BGP-3-NOTIFICATION" action 1.0 cli command "enable" action 2.0 cli command "clear ip bgp *" action 3.0 syslog msg "BGP session cleared by EEM". Router R2 shows: BGP neighbor 10.1.1.1 has been up for 0:00:05, state Established. What is the root cause?

A.The EEM applet is triggered by the BGP notification and clears all BGP sessions, causing a reset loop.
B.The BGP keepalive timer is set too low on R1.
C.The syslog pattern is incorrect and matches unrelated messages.
D.There is an MTU mismatch between R1 and R2.
AnswerA

The EEM applet matches the %BGP-3-NOTIFICATION syslog pattern and runs 'clear ip bgp *', tearing down every BGP session. Each reset generates further notifications, retriggering the applet, so sessions never stabilise — explaining R2's five-second uptime.

Why this answer

The root cause is that the EEM applet BGP-MONITOR is triggered by the syslog pattern '%BGP-3-NOTIFICATION', and its action clears all BGP sessions with 'clear ip bgp *'. This creates a feedback loop: a BGP notification triggers the applet, which clears all BGP sessions, causing new BGP notifications, which trigger the applet again, leading to intermittent session resets. The output showing R2's BGP neighbor up for only 5 seconds confirms frequent resets.

Exam trap

The trap is overlooking the feedback loop created by an EEM applet that clears BGP sessions in response to BGP notifications — candidates may focus on timer or MTU issues, but the self-inflicted reset loop is the key.

How to eliminate wrong answers

Option B is wrong because a low keepalive timer would cause more frequent keepalive messages, but the symptom of session resets every few seconds is more consistent with an active clearing action than timer expiry; also, no timer configuration is shown. Option C is wrong because the syslog pattern '%BGP-3-NOTIFICATION' is a valid and specific pattern for BGP notification messages; even if it matched unrelated messages, the primary issue is the action that clears all BGP sessions, creating a loop. Option D is wrong because an MTU mismatch typically causes sessions to stall or fail during large packet exchanges, not the rapid, repeated resets observed; moreover, the EEM applet's clear command is the direct cause.

947
MCQmedium

A network engineer is troubleshooting an IPv4 Network Address Translation (NAT) configuration on a Cisco IOS router. The router is configured with NAT overload (PAT) using the command ip nat inside source list 1 interface GigabitEthernet0/0 overload. Inside hosts cannot reach the Internet. The engineer verifies that interface GigabitEthernet0/0 is up and has an IP address, and that access list 1 permits the inside subnet. Which additional configuration is most likely missing?

A.The ip nat inside command on the LAN interface and ip nat outside on the WAN interface.
B.The ip nat inside source static command to create a static translation.
C.The ip route 0.0.0.0 0.0.0.0 GigabitEthernet0/0 command to provide a default route.
D.The ip nat pool command to define a pool of public addresses.
AnswerA

For NAT to function, interfaces must be designated as inside or outside using the ip nat inside and ip nat outside commands. Without these, the router does not know which interfaces to translate. Even if the NAT statement and access list are correct, missing interface designations will prevent translation, causing connectivity failure.

Why this answer

NAT requires interfaces to be marked as inside or outside. Without these designations, the router cannot determine which traffic to translate. The NAT statement and access list alone are insufficient.

The other options are either unnecessary for PAT or not directly related to the NAT configuration issue.

Exam trap

The trap here is focusing on the NAT statement and access list while overlooking the fundamental requirement of interface designations.

948
MCQeasy

A network engineer is configuring a GRE tunnel between two Cisco routers. The tunnel source is GigabitEthernet0/0 on Router A with IP 192.168.1.1, and the tunnel destination is 192.168.2.1 on Router B. After configuration, the tunnel interface is up, but no traffic passes through. What is the most likely cause?

A.The tunnel source and destination are in different subnets.
B.The tunnel mode is set to GRE/IPv4, which is not supported.
C.The tunnel interface is missing an IP address.
D.The tunnel destination is not reachable via the underlay network.
AnswerD

For a GRE tunnel to pass traffic, the tunnel destination IP address must be reachable through the underlay network. If the destination is not reachable, the tunnel interface may still show up if keepalives are not configured, but packets will be dropped because they cannot be encapsulated and sent. Ensuring reachability via a route or directly connected network is essential.

Why this answer

A GRE tunnel requires the tunnel destination to be reachable via the underlay network. If the destination is not reachable, the tunnel interface may appear up, but encapsulated packets cannot be delivered, resulting in no traffic flow. Other options are either incorrect or would cause different symptoms.

Ensuring underlay reachability and proper routing is essential for GRE tunnel operation.

Exam trap

The trap here is assuming that a tunnel interface being up means the tunnel is fully operational, when in fact it can be up even if the underlay destination is unreachable.

949
MCQeasy

A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue: R1# show ip interface GigabitEthernet0/1 | include access list Outgoing access list is 140 Inbound access list is not set Then the engineer runs: R1# show ip access-lists 140 Extended IP access list 140 10 deny icmp any any 20 permit ip any any What does this output indicate?

A.ACL 140 is applied outbound on GigabitEthernet0/1, denying ICMP and permitting all other traffic.
B.ACL 140 is applied inbound on GigabitEthernet0/1, blocking ICMP.
C.ACL 140 is not applied to any interface.
D.ACL 140 is applied both inbound and outbound.
AnswerA

The 'show ip interface' output confirms ACL 140 filters traffic leaving GigabitEthernet0/1, since only the outgoing list is set. The ACL's deny icmp any any entry drops all ICMP, while permit ip any any allows every other protocol through.

Why this answer

The output of 'show ip interface GigabitEthernet0/1 | include access list' shows 'Outgoing access list is 140', confirming ACL 140 is applied outbound on that interface. The ACL contains two entries: 'deny icmp any any' (sequence 10) and 'permit ip any any' (sequence 20). Access control lists are processed top-down, so for any outgoing traffic, the first matching entry determines the action.

ICMP traffic matches the deny icmp entry first and is therefore blocked. All other IP traffic does not match the first entry but matches the permit ip any any and is permitted. Thus, ACL 140 denies ICMP and permits all other IP traffic outbound.

Exam trap

Cisco often tests the misconception that 'permit ip any any' overrides all previous deny statements, but in reality, ACLs are processed top-down and the first matching entry determines the action, so the deny icmp entry still blocks ICMP despite the later permit all.

How to eliminate wrong answers

Option B is wrong because the 'show ip interface' output explicitly states 'Inbound access list is not set', so ACL 140 is not applied inbound. Option C is wrong because the output shows 'Outgoing access list is 140', confirming the ACL is applied outbound on the interface. Option D is wrong because the output shows only an outbound ACL; there is no inbound ACL applied, so it is not applied both inbound and outbound.

950
MCQmedium

A network engineer runs the following command to troubleshoot an ERSPAN issue: R1# show monitor session 3 detail Session 3 --------- Type : ERSPAN Source Session Source Ports : Both : Gi0/0 Destination IP : 10.1.1.1 ERSPAN ID : 100 What does this output indicate?

A.The session is correctly configured as an ERSPAN source session.
B.The session is misconfigured because the destination must be a VLAN, not an IP.
C.The session is misconfigured because the source port must be a VLAN.
D.The session is misconfigured because the ERSPAN ID must match on both source and destination.
AnswerA

The output confirms an ERSPAN source session: source port Gi0/0, destination IP 10.1.1.1, and ERSPAN ID 100 are all present, which are the required parameters for encapsulating mirrored traffic in GRE for remote delivery. No error or missing field appears.

Why this answer

The output shows a valid ERSPAN source session configuration: it specifies a source port (Gi0/0), a destination IP (10.1.1.1), and an ERSPAN ID (100). ERSPAN encapsulates mirrored traffic in GRE and sends it to a destination IP address, so the presence of a destination IP is correct and expected. The session type is explicitly 'ERSPAN Source Session', confirming the intended role.

No misconfiguration is evident from the displayed parameters.

Exam trap

The trap here is confusing ERSPAN with RSPAN or local SPAN, leading candidates to incorrectly think the destination must be a VLAN or that the ERSPAN ID must match on both ends.

How to eliminate wrong answers

Option B is wrong because ERSPAN destinations are IP addresses (the remote monitoring station), not VLANs; VLANs are used for local SPAN or RSPAN destination sessions. Option C is wrong because the source port for a SPAN or ERSPAN session is a physical or logical interface, not a VLAN; VLANs can be sources in VLAN-based SPAN, but the output clearly shows a port source. Option D is wrong because the ERSPAN ID (also called session ID) is a local identifier for the source session and does not need to match any value on the destination device; it is used to distinguish multiple ERSPAN streams, but the destination simply receives the GRE-encapsulated packets.

951
MCQmedium

Examine the following EEM applet configuration: !--- event manager applet BACKUP_CONFIG event timer watchdog time 86400 action 1.0 cli command "enable" action 2.0 cli command "copy running-config tftp://192.168.1.100/backup.cfg" !--- What is the effect of this configuration?

A.The applet will copy the running configuration to the TFTP server every 24 hours.
B.The applet will copy the startup configuration instead of the running configuration.
C.The applet will fail because the TFTP server IP address is not reachable.
D.The applet will only trigger once because the watchdog timer is a one-shot timer.
AnswerA

The watchdog timer with a time of 86400 seconds triggers the applet once daily, satisfying the 24-hour backup interval. Action 2.0 then executes the CLI copy command, pushing the running configuration to the TFTP server at 192.168.1.100. The enable action ensures privileged EXEC rights for the copy.

Why this answer

The EEM applet uses 'event timer watchdog time 86400', which triggers every 86400 seconds (24 hours) on a recurring basis. The actions enable privileged mode and copy the running-config to the TFTP server, so the effect is a daily backup of the running configuration.

Exam trap

300-410 often tests EEM timer semantics, so candidates confuse 'watchdog' (recurring) with 'countdown' (one-shot) and assume the applet runs only once.

How to eliminate wrong answers

Option B is wrong because the copy command explicitly specifies 'running-config' as the source, not 'startup-config'. Option C is wrong because the applet does not verify reachability; it will attempt the copy, and failure would only occur if the TFTP server is actually unreachable, which is not stated. Option D is wrong because the watchdog timer is a recurring timer, not a one-shot timer; it fires every 86400 seconds until the applet is removed.

952
MCQmedium

A network engineer is configuring a Cisco IOS router to support a new branch office that requires dynamic IPv4 addressing for clients. The router is already configured with a DHCP pool named BRANCH_POOL. The engineer notices that clients are not receiving IP addresses. Which command, when applied globally, is required to enable the DHCP service on the router?

A.ip helper-address 10.1.1.1
B.ip dhcp pool BRANCH_POOL
C.ip dhcp relay information option
D.service dhcp
AnswerD

The 'service dhcp' command in global configuration mode enables the DHCP server and relay agent functionality on the router. By default, this service is enabled, but it may have been disabled. Without it, the router will not process DHCP requests even if a pool is configured. This command is essential to activate the DHCP service.

Why this answer

The DHCP service on a Cisco IOS router must be enabled globally with the 'service dhcp' command. Although it is enabled by default, it can be disabled, preventing the router from responding to DHCP requests. Configuring a pool alone is insufficient.

The correct command activates the service, allowing the router to lease addresses from the configured pool.

Exam trap

The trap here is assuming that configuring a DHCP pool automatically enables the DHCP service, but the service must be globally enabled with 'service dhcp'.

953
Multi-Selecthard

Which TWO statements about the 'show policy-map control-plane' command output are true? (Choose TWO.)

Select 2 answers
A.The output displays the number of packets that matched each class in the CoPP policy.
B.The output includes the number of packets dropped by each class due to policing.
C.The output shows the routing table entries that are affected by the CoPP policy.
D.The output displays the CoPP policy applied to each physical interface.
E.The output includes the ARP cache entries that are protected by CoPP.
AnswersA, B

Correct. The command shows per-class packet and byte counters for matched traffic.

Why this answer

The 'show policy-map control-plane' command output displays per-class packet statistics, including the number of packets that matched each class in the Control Plane Policing (CoPP) policy. This allows administrators to verify which traffic types are being classified and how much traffic is hitting the control plane.

Exam trap

Cisco often tests the distinction between CoPP (control plane-wide policy) and per-interface QoS policies, leading candidates to incorrectly assume that 'show policy-map control-plane' shows interface-level details.

954
MCQmedium

Router R6 has the following DHCPv6 configuration: ipv6 dhcp pool DHCP6_POOL3 address prefix 2001:db8:3::/64 lifetime 3600 600 dns-server 2001:db8::1 ! interface GigabitEthernet0/2 ipv6 address 2001:db8:3::1/64 ipv6 dhcp server DHCP6_POOL3 ipv6 nd managed-config-flag no shutdown What is the effect of the lifetime parameters 3600 and 600?

A.The preferred lifetime is 3600 seconds and the valid lifetime is 600 seconds, which is invalid because the valid lifetime must be greater than or equal to the preferred lifetime.
B.The preferred lifetime is 600 seconds and the valid lifetime is 3600 seconds, which is a typical configuration.
C.The lifetimes are applied to the DNS server address, not the address prefix.
D.The configuration is valid and will work as expected.
AnswerA

In IPv6, the preferred lifetime and valid lifetime are configured in that order, so the command specifies preferred=3600 seconds and valid=600 seconds. RFC 4862 mandates that the valid lifetime must be greater than or equal to the preferred lifetime, because a prefix should remain valid at least as long as it is preferred. Here the preferred lifetime exceeds the valid lifetime, which makes the configuration invalid and will be rejected by the router.

Why this answer

In the `ipv6 dhcp pool` configuration, the `lifetime` command specifies the preferred lifetime first (3600 seconds) and the valid lifetime second (600 seconds). According to RFC 4862, the valid lifetime must be greater than or equal to the preferred lifetime; otherwise, the configuration is invalid and will be rejected by the router. This mismatch causes the DHCPv6 pool to fail to apply the prefix.

Exam trap

The trap here is that Cisco tests whether candidates know the correct order of the preferred and valid lifetime parameters in the `lifetime` command, as many mistakenly assume the valid lifetime comes first or that the router will accept an invalid lifetime relationship.

How to eliminate wrong answers

Option B is wrong because it reverses the order of the lifetimes: the preferred lifetime is 3600 seconds (first value) and the valid lifetime is 600 seconds (second value), not the other way around. Option C is wrong because the `lifetime` command applies exclusively to the address prefix defined in the pool, not to the DNS server address; DNS server lifetimes are not configurable in this context. Option D is wrong because the configuration is invalid due to the valid lifetime being shorter than the preferred lifetime, so the router will not accept it and the DHCPv6 pool will not function as expected.

955
MCQeasy

An engineer is troubleshooting an EIGRP issue where a router is not learning a specific route from a neighbor, but other routes from the same neighbor are being learned. The engineer checks the EIGRP topology table and sees that the route is not present. The engineer also checks the neighbor's routing table and confirms that the route exists. What is the most likely cause?

A.A distribute-list in is applied on the local router that filters the specific route.
B.The neighbor is configured as a stub router.
C.The route is a summary route that is being suppressed by the 'summary-address' command.
D.The EIGRP metric for the route is too high, so it is not considered feasible.
AnswerA

An inbound distribute-list filters routes before they enter the local EIGRP topology table, so the prefix is silently dropped while other routes from the same neighbour pass. The neighbour's own routing table still holds the route, matching the observed asymmetry.

Why this answer

A distribute-list in applied on the local router can filter specific incoming routes from an EIGRP neighbor while allowing others. Since the neighbor has the route in its routing table and other routes from the same neighbor are learned, the most likely cause is an inbound filter that explicitly denies that particular prefix.

Exam trap

Cisco often tests the distinction between inbound and outbound filtering, and candidates may mistakenly think a stub router or metric issue causes selective route absence, but only a distribute-list in can filter a single route from an otherwise fully functional neighbor relationship.

How to eliminate wrong answers

Option B is wrong because a stub router advertises only a default route or connected/summary routes, but the neighbor still has the specific route in its routing table, so stub configuration would not cause selective filtering of one route. Option C is wrong because a summary route suppressed by the 'summary-address' command would affect the advertisement from the local router, not the learning of a specific route from a neighbor. Option D is wrong because EIGRP metric values do not prevent a route from being learned; if the route is not feasible due to metric, it would appear in the topology table as an active or stuck-in-active state, not be completely absent.

956
MCQhard

What is the default behavior of BGP synchronization in Cisco IOS-XE?

A.Enabled by default
B.Disabled by default
C.Enabled only for iBGP
D.Disabled only for eBGP
AnswerB

BGP synchronization is disabled by default in Cisco IOS-XE, so routes learned via IBGP need not await matching IGP entries before advertisement to EBGP peers. This satisfies the stem's default-behaviour constraint: no explicit `no synchronization` command is required, unlike legacy IOS where it was enabled.

Why this answer

In Cisco IOS and IOS-XE, BGP synchronization is disabled by default. Historically it was enabled to prevent advertising iBGP-learned routes until they were confirmed via IGP, but modern designs (especially with full iBGP meshes or route reflectors) made it obsolete, so Cisco disabled it by default. Administrators must explicitly enable it with the synchronization command under router bgp if needed.

Exam trap

300-410 often tests the outdated belief that BGP synchronization is enabled by default, when in fact Cisco disabled it by default in modern IOS/IOS-XE releases.

How to eliminate wrong answers

Option A is wrong because synchronization has not been enabled by default in modern IOS/IOS-XE — that was the behavior in very old IOS versions and is a common outdated belief. Option C is wrong because synchronization is not selectively enabled for iBGP; it is a global BGP process setting that is off by default regardless of iBGP or eBGP. Option D is wrong because synchronization is not 'disabled only for eBGP' — it is disabled globally for the entire BGP process by default, and it never applied to eBGP-learned routes in the first place.

957
Drag & Dropmedium

Drag and drop the steps to configure a GRE tunnel for IPv6 over IPv4 into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order follows the standard GRE tunnel configuration workflow for IPv6 over IPv4: first create the tunnel interface with 'interface tunnel0', then assign an IPv6 address to the tunnel, set the tunnel source, set the tunnel destination. Note that option E is incorrect because the correct command for IPv6 over IPv4 is 'tunnel mode gre ip', not 'tunnel mode gre ipv6'. Therefore, the correct steps are A, B, C, D only.

958
MCQmedium

A router running Cisco IOS XE has a VRF-aware DMVPN phase 3 tunnel interface. The network administrator wants to ensure that spoke-to-spoke traffic is switched directly between spokes when a route to the destination is present in the NHRP database. Which configuration on the hub is required to enable this behavior?

A.ip nhrp network-id 1
B.ip nhrp shortcut
C.ip nhrp redirect
D.ip nhrp map multicast dynamic
AnswerC

The ip nhrp redirect command on the hub enables NHRP redirect messages to be sent to spokes when traffic arrives at the hub for a destination that is reachable via another spoke. This allows the ingress spoke to learn an optimal path and initiate a direct spoke-to-spoke tunnel, which is a key feature of DMVPN Phase 3.

Why this answer

In DMVPN Phase 3, spoke-to-spoke traffic optimization relies on the hub sending NHRP redirect messages to the ingress spoke. The hub must be configured with ip nhrp redirect to generate these messages when it receives traffic destined for a network reachable via another spoke. The spoke then uses ip nhrp shortcut to install a direct route, but the hub-side command is ip nhrp redirect.

Exam trap

The trap here is confusing the hub-side command ip nhrp redirect with the spoke-side command ip nhrp shortcut, which must be applied on different devices to achieve the same feature.

959
MCQhard

A network engineer is implementing BGP on a Cisco IOS XE router. The router is peering with an ISP and receives a full BGP table. The engineer wants to influence inbound traffic from the ISP by making a specific prefix more preferred. The engineer has configured a route map that sets the MED to 50 for the prefix 203.0.113.0/24 and applies it outbound to the ISP. However, the ISP still prefers a different path. Which BGP attribute should the engineer manipulate to influence inbound traffic more effectively?

A.WEIGHT
B.ORIGIN
C.LOCAL_PREF
D.AS_PATH
AnswerD

AS_PATH is a well-known mandatory attribute that can influence inbound traffic by making the path appear longer. By prepending additional AS numbers to the AS_PATH for a specific prefix, the engineer can make that path less preferred by the ISP. This is a common method to influence inbound traffic when MED is not honored, as MED is optional and often not considered across different autonomous systems.

Why this answer

To influence inbound traffic from an ISP, the most effective method is to manipulate the AS_PATH attribute by prepending additional AS numbers. This makes the path appear longer and less preferred. MED is often not honored by ISPs because it is an optional attribute and is only considered between autonomous systems that agree to use it.

LOCAL_PREF and WEIGHT are used for outbound traffic and are not advertised externally. ORIGIN is not typically used for this purpose.

Exam trap

The trap here is assuming that MED will always influence inbound traffic, but MED is often ignored by ISPs; AS_PATH prepending is more reliable.

960
MCQeasy

A network engineer runs the following command to troubleshoot an IPsec Site-to-Site VPN issue: R1# show crypto engine connections active Crypto Engine Connections ID Type Algorithm Encrypt Decrypt LastSeqNo 1 IPsec ESP-3DES+SHA 0 0 0 2 IPsec ESP-3DES+SHA 0 0 0 3 IPsec ESP-AES+SHA 0 0 0 What does this output indicate?

A.The IPsec VPN is actively encrypting and decrypting traffic.
B.The IPsec SAs are established but no traffic is flowing, possibly due to routing or ACL issues.
C.The crypto engine is overloaded and cannot process packets.
D.The IPsec SAs are using the wrong transform set.
AnswerB

Encrypt and decrypt counters of zero across all three IPsec SAs prove the tunnels negotiated successfully but carry no packets. Because the SAs exist, the fault lies beyond phase 2 — typically routing or an ACL blocking interesting traffic from matching.

Why this answer

The output shows three IPsec Security Associations (SAs) with zero encrypted and zero decrypted packets, and a LastSeqNo of 0. This indicates the SAs are established (the tunnels are up) but no traffic is being processed through them. The most common causes are routing issues preventing traffic from reaching the tunnel interface, or ACLs that do not match the interesting traffic for encryption.

Exam trap

Cisco often tests the misconception that a non-zero number of SAs in 'show crypto engine connections active' automatically means traffic is flowing, when in fact the Encrypt/Decrypt counters must be checked to confirm actual data processing.

How to eliminate wrong answers

Option A is wrong because the Encrypt and Decrypt counters are both 0, which means no traffic is being encrypted or decrypted; active encryption would show non-zero counts. Option C is wrong because the crypto engine is not overloaded; an overloaded engine would typically show high packet counts or errors, not all zeros. Option D is wrong because the output does not indicate a transform set mismatch; mismatched transform sets would prevent SA establishment entirely, but here the SAs are listed (ID 1, 2, 3), meaning Phase 2 negotiation succeeded.

961
Multi-Selectmedium

Which TWO commands verify the operational status of a local SPAN session on a Cisco IOS-XE switch? (Choose TWO.)

Select 2 answers
A.show monitor session 1
B.show monitor
C.show spanning-tree
D.show interfaces
E.show vlan
AnswersA, B

"show monitor session 1" displays the operational details of that specific session, including type, source ports, destination port, encapsulation and ingress state. It directly confirms whether the local SPAN session is active and correctly bound.

Why this answer

Option A, `show monitor session 1`, is correct because on Cisco IOS-XE switches this command displays the details of a specific local SPAN session, including its source ports/VLANs, destination port, direction, and whether the session is operational. Option B, `show monitor`, is also correct because it lists all configured SPAN sessions and their status, allowing verification of the local SPAN session without specifying a session number. Option C, `show spanning-tree`, is incorrect because it displays Spanning Tree Protocol topology and port states, not SPAN session status.

Option D, `show interfaces`, is incorrect because it shows interface statistics and line/protocol status, not SPAN configuration or operational state. Option E, `show vlan`, is incorrect because it displays VLAN membership and assignment information, not SPAN session details.

962
MCQeasy

What is the default OSPF reference bandwidth used in the cost calculation formula on Cisco IOS?

A.10 Mbps
B.100 Mbps
C.1000 Mbps
D.1 Gbps
AnswerB

Cisco IOS defaults the OSPF reference bandwidth to 100 Mbps, so interface cost equals 100,000,000 divided by interface bandwidth in bits per second. This default makes any link of 100 Mbps or faster cost 1 unless reference bandwidth is raised.

Why this answer

Cisco IOS uses a default OSPF reference bandwidth of 100 Mbps (10^8) in the cost formula cost = reference bandwidth / interface bandwidth. This default dates back to when Fast Ethernet was the fastest common link, and it means any interface 100 Mbps or faster yields a cost of 1 unless the reference bandwidth is changed.

Exam trap

The trap is confusing the OSPF default reference bandwidth (100 Mbps) with the common manually configured value (1000 Mbps or higher) — candidates who have seen 'auto-cost reference-bandwidth 1000' in labs often pick 1000 Mbps as the default.

How to eliminate wrong answers

Option A is wrong because 10 Mbps was the reference for older metrics like IGRP, not the OSPF default reference bandwidth. Option C is wrong because 1000 Mbps (1 Gbps) is a common value administrators manually set with 'auto-cost reference-bandwidth 1000' to differentiate Gigabit links, but it is not the default. Option D is wrong because 1 Gbps is the same as option C expressed differently and is also a manual configuration, not the IOS default.

963
MCQhard

A network administrator is deploying MPLS Layer 3 VPNs with Cisco IOS XE routers. The administrator wants to ensure that customer routes are not leaked into the global routing table and that each VPN instance maintains separate routing and forwarding tables. Which of the following must be configured on the PE routers to achieve this isolation?

A.BGP route reflectors with confederation
B.OSPF sham links with domain ID
C.MPLS LDP with explicit-null and penultimate hop popping
D.VRF definition with route distinguisher (RD) and route target (RT) import/export policies
AnswerD

A VRF (Virtual Routing and Forwarding) instance creates separate routing and forwarding tables per VPN. The route distinguisher (RD) makes the customer prefix unique within the MPLS domain, while route targets (RTs) control import and export of routes between VRFs. This combination ensures isolation and proper route leaking only where intended. Without VRFs, customer routes would mix with the global table or with other customers' routes, violating the isolation requirement.

Why this answer

To isolate customer routes in MPLS L3VPN, the PE router must have VRF instances. Each VRF has its own routing table, and the RD makes prefixes unique. RTs control which routes are imported into which VRF, enabling controlled route leaking.

This architecture ensures that customer routes remain separate from the global table and from other customers. The other options are related to MPLS or BGP scaling but do not provide the required isolation.

Exam trap

The trap here is assuming that MPLS LDP or BGP route reflectors alone provide VPN isolation; they do not, VRFs are required.

964
MCQhard

A network engineer is configuring VRF-lite on a Cisco IOS router to segment traffic for two customers. The engineer creates VRF CUSTA and assigns interface GigabitEthernet0/1 to it. The engineer then configures a static route within VRF CUSTA to reach 10.10.10.0/24 via next-hop 192.168.1.1. However, the route does not appear in the VRF CUSTA routing table. Which command is missing?

A.The `ip route vrf CUSTA 10.10.10.0 255.255.255.0 GigabitEthernet0/1` command must be used to specify the outgoing interface.
B.The `ip route 10.10.10.0 255.255.255.0 192.168.1.1` command must be configured under the VRF configuration mode.
C.The `ip route vrf CUSTA 10.10.10.0 255.255.255.0 192.168.1.1 global` command must be used to leak the route into the global table.
D.The `ip route vrf CUSTA 10.10.10.0 255.255.255.0 192.168.1.1` command must be configured in global configuration mode.
AnswerD

Static routes for a VRF must be configured with the `ip route vrf <vrf-name>` syntax in global configuration mode. Without the `vrf` keyword, the route is installed in the global routing table, not the VRF. This command correctly places the route into the VRF CUSTA routing table.

Why this answer

In VRF-lite, static routes for a VRF must be configured with the `ip route vrf <vrf-name>` command in global configuration mode. Without the `vrf` keyword, the route is placed in the global routing table instead of the VRF. The correct syntax ensures the route is installed in the VRF's routing table.

Exam trap

The trap here is assuming that configuring a static route while in VRF context or using the interface assignment is sufficient, when the `vrf` keyword is mandatory in the global `ip route` command.

965
MCQeasy

A network engineer is configuring a Cisco IOS router to run OSPFv3 for IPv6. The router must form an adjacency with a neighbor on a broadcast network. Which command is required to enable OSPFv3 on an interface?

A.ipv6 ospf 1 area 0
B.ospfv3 1 ipv6 area 0
C.ipv6 ospf area 0
D.ipv6 router ospf 1
AnswerA

This command, issued in interface configuration mode, enables OSPFv3 for IPv6 on the interface and assigns it to area 0. It is the standard method to activate OSPFv3 on an interface in Cisco IOS. Without this command, the interface will not participate in OSPFv3 and no adjacency will form.

Why this answer

To enable OSPFv3 on an interface for IPv6, the command `ipv6 ospf 1 area 0` is used in interface configuration mode. This activates OSPFv3 on the interface and associates it with the specified area. The global command `ipv6 router ospf 1` is also needed to configure the router ID and other parameters, but the interface-level command is essential for adjacency formation.

Exam trap

The trap here is confusing the global OSPFv3 configuration command with the interface-level command that actually enables the protocol on the interface.

966
MCQeasy

A network engineer is troubleshooting a BGP route advertisement issue. Router R1 (AS 65001) is an eBGP peer of R2 (AS 65002). R1 is advertising the prefix 10.0.0.0/8 to R2. R2 has an iBGP session with R3 (AS 65002). R3's BGP table shows the prefix 10.0.0.0/8 with next-hop 10.1.1.1 (R1's interface). However, R3 does not install this route in its routing table. The output of 'show ip route 10.0.0.0' on R3 shows no route. The engineer checks the routing table on R3 and sees that the interface connected to 10.1.1.0/24 is down. What is the most likely cause?

A.The next-hop 10.1.1.1 is not reachable because the directly connected interface is down.
B.The route is not installed because BGP synchronization is enabled.
C.The route is not installed because the prefix is being filtered by an inbound route-map on R3.
D.The route is not installed because the administrative distance of the route is too high.
AnswerA

iBGP does not rewrite next-hop by default, so R3 retains 10.1.1.1. BGP validates the next-hop against the routing table before bestowing best-path status; with the connected interface down, that address is unresolvable and the route stays unusable.

Why this answer

R3 does not install the route because the next-hop 10.1.1.1 is not reachable; the interface connected to 10.1.1.0/24 is down. BGP requires a valid next-hop to install a route in the routing table. Since the directly connected interface is down, the next-hop is unreachable, and the route is not installed.

Exam trap

The trap is assuming that BGP route installation depends on administrative distance or synchronization, when the most common cause is next-hop reachability. Candidates must check the next-hop reachability first.

How to eliminate wrong answers

Option B is wrong because BGP synchronization is largely obsolete and disabled by default on modern Cisco IOS; even if enabled, it would not be the cause if the next-hop is unreachable. Option C is wrong because a route-map filtering would prevent the route from being in the BGP table, but the question states the BGP table shows the prefix. Option D is wrong because administrative distance is not the issue; the route is not even considered because the next-hop is unreachable.

967
MCQhard

An engineer configures iBGP between two PE routers in an MPLS L3VPN. The PE routers are in the same AS and are directly connected. The engineer configures 'neighbor x.x.x.x next-hop-self' on the route reflector (RR) but notices that the RR is not sending the VPNv4 routes to the client PE with the next-hop set to itself. The client PE receives the routes but the next-hop remains the original PE. What is the most likely explanation?

A.The 'next-hop-self' command is not applied to the route-reflector client session; it must be applied to the client's neighbor statement on the RR, but it is ignored for reflected routes.
B.The 'next-hop-self' command is only applicable to eBGP sessions, not iBGP.
C.The 'next-hop-self' command requires the 'soft-reconfiguration inbound' to be configured to take effect.
D.The 'next-hop-self' command is overridden by the 'next-hop-unchanged' command on the route reflector.
AnswerA

Correct. 'next-hop-self' is not effective for routes reflected by a route reflector; the RR preserves the original next-hop.

Why this answer

In BGP, the 'next-hop-self' command is only effective for eBGP sessions or for iBGP sessions when the neighbor is not a route-reflector client. When a route reflector sends a route to a client, it does not change the next-hop attribute by default, even if 'next-hop-self' is configured. This is because the route reflector is expected to preserve the next-hop as learned from the original router.

To change the next-hop on a route reflector, the engineer must use 'neighbor x.x.x.x next-hop-self' on the RR for the client, but this command is ignored for routes that are reflected from another iBGP speaker. This is a known edge case that can cause reachability issues if the client cannot reach the original next-hop.

968
MCQhard

An engineer configures a route map to filter OSPF routes using a distribute-list in OSPF process 1. The distribute-list references a prefix-list that permits only the 10.0.0.0/8 network. After applying the distribute-list in, the engineer notices that the OSPF neighbor state remains stuck in EXSTART/EXCHANGE. Which is the most likely explanation?

A.The distribute-list is applied incorrectly; it should be applied out instead of in.
B.The distribute-list filters LSAs during the exchange, causing the neighbor to be stuck.
C.There is an MTU mismatch between the OSPF neighbors, preventing the exchange of Database Description packets.
D.The prefix-list is misconfigured; it should permit 10.0.0.0/8 with a ge 24 operator.
AnswerC

OSPF neighbours exchange Database Description packets during EXSTART, and these packets carry the interface MTU. A mismatch causes the routers to reject each other's DBD packets, so the adjacency stalls in EXSTART/EXCHANGE regardless of the distribute-list filtering.

Why this answer

OSPF distribute-list in only filters routes in the routing table, not LSAs. It does not affect the exchange of LSAs during adjacency formation. The adjacency stall is unrelated to the distribute-list; the issue is likely an MTU mismatch between the interfaces.

969
MCQhard

A network engineer is implementing Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The router has two interfaces: GigabitEthernet0/0 connected to the Internet, and GigabitEthernet0/1 connected to the internal network. The engineer wants to ensure that packets coming from the Internet are dropped if their source IP address is not reachable via the same interface. However, the internal network uses asymmetric routing, so strict uRPF cannot be used on the internal interface. Which configuration should be applied to GigabitEthernet0/0 to achieve the goal?

A.ip verify unicast source reachable-via rx allow-default
B.ip verify unicast source reachable-via tx
C.ip verify unicast source reachable-via rx
D.ip verify unicast source reachable-via any
AnswerC

The 'ip verify unicast source reachable-via rx' command enables strict uRPF, which checks that the source IP address is reachable via the same interface the packet was received on. This is appropriate for the Internet-facing interface to drop spoofed packets. The internal interface would need a different mode due to asymmetric routing.

Why this answer

Strict uRPF is configured with the 'ip verify unicast source reachable-via rx' command, which verifies that the source IP address is reachable via the same interface the packet was received on. This is ideal for the Internet-facing interface to prevent spoofing. Loose mode ('any') would not meet the requirement, and the other options include modifiers or incorrect keywords.

Exam trap

The trap here is confusing strict and loose uRPF modes; strict mode uses 'rx' and checks the same interface, while loose mode uses 'any' and checks any interface.

970
MCQeasy

A network engineer is configuring a static route on a Cisco IOS router to reach the network 10.1.1.0/24 via the next-hop 192.168.1.1. The engineer wants the route to be removed from the routing table if the next-hop becomes unreachable. Which command should be used?

A.ip route 10.1.1.0 255.255.255.0 192.168.1.1
B.ip route 10.1.1.0 255.255.255.0 192.168.1.1 permanent
C.ip route 10.1.1.0 255.255.255.0 192.168.1.1 track 1
D.ip route 10.1.1.0 255.255.255.0 192.168.1.1 name TRACK
AnswerC

The track keyword associates the static route with a tracked object (in this case, object 1). If the tracked object goes down, the route is removed from the routing table. This provides next-hop reachability tracking. The engineer must also configure a track object to monitor the next-hop, typically using ICMP echo or a route reachability check. This is the correct way to conditionally install a static route based on next-hop availability.

Why this answer

To remove a static route when the next-hop becomes unreachable, the track keyword must be used. It associates the route with a tracked object that monitors the next-hop. The permanent keyword does the opposite, keeping the route installed.

The name keyword only labels the route. A standard static route without tracking remains in the table even if the next-hop fails. Therefore, the track option is correct.

Exam trap

The trap here is confusing the permanent keyword with tracking; permanent keeps the route despite failures, while track removes it based on object state.

971
MCQeasy

What is the maximum hop count for a route in RIPv2 by default?

A.15
B.16
C.255
D.32
AnswerA

RIPv2 caps valid routes at 15 hops; a metric of 16 is defined as infinity and marks the destination unreachable. This satisfies the stem's default maximum hop count, since no configuration changes the limit — it is fixed by the protocol's distance-vector design.

Why this answer

RIP uses a maximum hop count of 15, with 16 considered unreachable, to prevent routing loops.

972
MCQeasy

Which DHCPv6 option carries the DNS recursive name server information?

A.Option 6 (Domain Name Server)
B.Option 23 (DNS Recursive Name Server)
C.Option 24 (Domain Search List)
D.Option 21 (SIP Server Domain Name)
AnswerB

DHCPv6 Option 23 carries the DNS recursive name server information, satisfying the stem's requirement for the option that supplies resolver addresses to IPv6 clients. It lists one or more IPv6 addresses of recursive DNS servers, distinct from Option 24, which provides the domain search list rather than resolver addresses.

Why this answer

DHCPv6 Option 23 (DNS Recursive Name Server) is specifically defined in RFC 3646 to carry the IPv6 addresses of DNS recursive name servers to DHCPv6 clients. This is the standard mechanism for IPv6 hosts to learn DNS server addresses via DHCPv6, analogous to DHCPv4 Option 6 for IPv4.

Exam trap

Cisco often tests the distinction between DHCPv4 Option 6 and DHCPv6 Option 23, trapping candidates who assume the same option number applies to both protocols.

How to eliminate wrong answers

Option A is wrong because DHCPv6 Option 6 does not exist; Option 6 is a DHCPv4 option (Domain Name Server) that carries IPv4 DNS server addresses, not IPv6. Option C is wrong because DHCPv6 Option 24 (Domain Search List) carries the domain search list for DNS resolution, not the recursive name server addresses. Option D is wrong because DHCPv6 Option 21 (SIP Server Domain Name) is used to provide SIP server domain names, not DNS recursive name server information.

973
MCQhard

A network architect is designing a FlexVPN solution using IKEv2 between a hub and multiple spokes. The hub must authenticate spokes using certificates, and spokes must authenticate the hub. The architect wants to ensure that the hub can verify the revocation status of spoke certificates in real time. Which mechanism should be implemented?

A.Configure CRL checking on the hub.
B.Configure OCSP on the hub.
C.Enable certificate enrollment using SCEP.
D.Use pre-shared keys with certificate mapping.
AnswerB

OCSP (Online Certificate Status Protocol) allows the hub to query an OCSP responder in real time to check the revocation status of a spoke's certificate during IKEv2 authentication. This meets the real-time requirement. Cisco IOS supports OCSP for IKEv2, enabling immediate revocation checks.

Why this answer

OCSP provides real-time certificate revocation status by allowing the hub to query an OCSP responder during IKEv2 authentication. CRL checking is periodic and may not reflect recent revocations. SCEP is for enrollment, and pre-shared keys are a different authentication method.

Therefore, OCSP is the correct choice for real-time revocation checking.

Exam trap

The trap here is equating CRL with real-time revocation; CRLs are downloaded periodically and can be stale, whereas OCSP queries the responder immediately.

974
MCQmedium

A network engineer runs the following command on Router R1: R1# show snmp host Host: 192.168.1.100 Port: 162 Timeout: 1.5 seconds Retries: 3 Version: 2c Community: PUBLIC Host: 192.168.1.200 Port: 162 Timeout: 3 seconds Retries: 5 Version: 3 User: admin Security level: authPriv Based on this output, which statement is correct?

A.SNMP traps sent to 192.168.1.200 will be encrypted.
B.Both hosts use the same SNMP version.
C.The host at 192.168.1.100 uses SNMPv3 with user 'admin'.
D.Traps to 192.168.1.200 will be sent with community string 'admin'.
AnswerA

SNMPv3 with authPriv enforces both authentication (SHA/MD5) and privacy (AES/DES) on notifications, so traps to 192.168.1.200 are encrypted. The 192.168.1.100 host uses SNMPv2c, which transmits community strings and payloads in cleartext, satisfying the stem's requirement to identify which destination is cryptographically protected.

Why this answer

The SNMPv3 security level 'authPriv' for the host at 192.168.1.200 means authentication and privacy (encryption) are both enabled. SNMPv3 with authPriv uses the User-based Security Model (USM) to encrypt the entire SNMP packet payload, including the trap data, using protocols like AES or DES. This ensures that traps sent to 192.168.1.200 are encrypted.

Exam trap

Cisco often tests the distinction between SNMPv2c community strings and SNMPv3 users/security levels, leading candidates to mistakenly associate a community string or user with the wrong host or version.

How to eliminate wrong answers

Option B is wrong because the output shows Host 192.168.1.100 uses SNMP version 2c, while Host 192.168.1.200 uses SNMP version 3, so they do not use the same SNMP version. Option C is wrong because Host 192.168.1.100 is configured with SNMPv2c and community string 'PUBLIC', not SNMPv3 with user 'admin'; the user 'admin' is only associated with Host 192.168.1.200. Option D is wrong because SNMPv3 does not use community strings; traps to 192.168.1.200 are sent with the user 'admin' and security level authPriv, not a community string.

975
MCQmedium

A network engineer configures NetFlow on a router using the legacy 'ip flow-export' commands. After applying 'ip route-cache flow' on an interface, 'show ip flow export' shows packets being sent, but the collector reports that all flows have a source IP of the router's management interface instead of the actual source IPs. What is the most likely cause?

A.The 'ip flow-export source' command is set to the management interface, which becomes the source IP of export packets.
B.The router is performing NAT on the flow data before exporting.
C.The flow record is configured to match the router's interface IP as the source.
D.The collector is misconfigured to display the export packet source instead of the flow source.
AnswerA

The 'ip flow-export source' command fixes the source IP of export packets to the named interface, so all records reaching the collector appear to originate from the management address rather than the original flow endpoints. Removing or changing that source restores the true exporter address.

Why this answer

The 'ip flow-export source <interface>' command sets the source IP address of the NetFlow export packets themselves (the UDP packets sent to the collector). If it is configured to the management interface, every export packet will show that IP as the source — which is exactly what the collector is reporting. This is a configuration issue on the export transport, not a problem with the flow records.

Exam trap

300-410 often tests the distinction between the source IP inside the flow record (monitored traffic) and the source IP of the export packet (transport) — candidates pick NAT or collector misconfiguration instead of the 'ip flow-export source' command.

How to eliminate wrong answers

Option B is wrong because NAT translates the actual traffic being monitored, not the NetFlow export packets — and the symptom (all flows showing the router's management IP) is about export packet source, not translated flow data. Option C is wrong because flow records capture the source/destination of the monitored traffic; the router's interface IP is not inserted as the flow source unless the export source is misconfigured. Option D is wrong because the collector is correctly displaying what it receives — the export packets genuinely have the management interface as their source IP due to the 'ip flow-export source' setting.

Page 12

Page 13 of 19

Page 14