Courseiva

Cisco CCNP ENARSI 300-410 (300-410) — Questions 976–1050

1401 questions total · 19pages · All types, answers revealed

Page 13

Page 14 of 19

Page 15
976
MCQeasy

What is the default behavior of an EEM applet when a 'set' action modifies a variable that is used in a subsequent 'if' condition?

A.The variable is evaluated at the start of the applet, so the 'if' condition uses the original value.
B.The variable is evaluated at the time the 'if' condition is executed, so it uses the updated value.
C.The 'set' action cannot modify a variable that is used in an 'if' condition.
D.The applet will fail if a variable is modified after being used in an 'if' condition.
AnswerB

EEM applets execute actions sequentially, so a 'set' action updates the variable before any later 'if' condition runs. The condition therefore reads the newly assigned value rather than the original, satisfying the stem's sequential-execution constraint.

Why this answer

EEM (Embedded Event Manager) applets execute actions sequentially, and variables are evaluated at the time the 'if' condition is reached, not at applet start. So if a 'set' action modifies a variable before an 'if' condition that references it, the 'if' sees the updated value. This is standard procedural execution order in EEM.

Exam trap

The trap is assuming variables are captured at applet start (like a compiled snapshot) — EEM is interpreted and evaluates variables lazily, so the updated value is used.

How to eliminate wrong answers

Option A is wrong because EEM does not snapshot variables at applet start — evaluation is lazy and occurs when the condition is executed. Option C is wrong because 'set' actions can absolutely modify variables used in later 'if' conditions; this is a common pattern. Option D is wrong because modifying a variable after it has been used in an 'if' is perfectly valid — the applet does not fail.

977
MCQhard

A network engineer runs the following command on Router R1: R1# show ip nat translations Pro Inside global Inside local Outside local Outside global tcp 192.0.2.10:80 10.0.0.10:80 203.0.113.5:12345 203.0.113.5:12345 tcp 192.0.2.10:80 10.0.0.11:80 203.0.113.5:67890 203.0.113.5:67890 R1# show ip nat statistics Total active translations: 2 (0 static, 2 dynamic; 2 extended) Outside interfaces: GigabitEthernet0/1 Inside interfaces: GigabitEthernet0/0 Hits: 50 Misses: 0 CEF Translated packets: 50, CEF Punted packets: 0 Expired translations: 0 Dynamic mappings: -- Inside Source [Id] ip nat inside source list ACL1 interface GigabitEthernet0/1 overload refcount 2 Based on this output, what is the problem?

A.PAT is not assigning unique source ports; both translations use port 80, which will cause conflicts.
B.The NAT pool is misconfigured because it uses the interface address.
C.The inside and outside interfaces are swapped.
D.Static NAT is interfering with dynamic NAT.
AnswerA

In PAT, the router should change the source port to a unique value. Both translations showing the same inside global port 80 indicates a problem.

Why this answer

The output shows two dynamic NAT translations mapping different inside local hosts (10.0.0.10 and 10.0.0.11) to the same inside global IP address (192.0.2.10) and the same source port (80). PAT (Port Address Translation) should assign unique source ports to differentiate the sessions, but here both translations use port 80, which will cause conflicts when return traffic arrives because the router cannot determine which inside host should receive the packet. This indicates a misconfiguration or a bug where PAT is not performing port overload correctly.

Exam trap

Cisco often tests the misconception that PAT always works automatically without verifying unique port assignments, leading candidates to overlook the duplicate port issue in the translation output.

How to eliminate wrong answers

Option B is wrong because the NAT pool is not misconfigured; the configuration uses 'ip nat inside source list ACL1 interface GigabitEthernet0/1 overload', which correctly uses the interface address for PAT, and the output shows translations are active. Option C is wrong because the interfaces are correctly assigned: GigabitEthernet0/1 is the outside interface and GigabitEthernet0/0 is the inside interface, as shown in the statistics output. Option D is wrong because there are no static NAT entries (0 static translations), so static NAT cannot be interfering with dynamic NAT.

978
MCQhard

R1 and R2 are iBGP peers. R1 has: neighbor 10.1.1.2 route-map RM_SET in. The route-map RM_SET sets community 100:100. R2 advertises a prefix 172.16.1.0/24 with community 200:200. R1 receives the prefix and the community is changed to 100:100. However, R1's BGP table shows the prefix with community 100:100, but R1 does not propagate this prefix to its other iBGP peer R3. R3 has no special configuration. What is the root cause?

A.iBGP split-horizon rule prevents R1 from advertising routes learned from an iBGP peer to another iBGP peer.
B.The community 100:100 is being filtered by R3's inbound policy.
C.The route-map RM_SET should have been applied outbound on R2 instead.
D.R1 must have a network statement for 172.16.1.0/24 to advertise it.
AnswerA

BGP's iBGP split-horizon rule forbids re-advertising a route learned from one iBGP peer to another iBGP peer, so R1 cannot pass the prefix to R3. Full-mesh iBGP peering or a route reflector is required to relay it.

Why this answer

By default, iBGP learned routes are not advertised to other iBGP peers to prevent loops, unless the router is a route reflector or confederation. R1 is not a route reflector, so it will not advertise the prefix learned from R2 to R3. The community manipulation is irrelevant to the propagation issue.

The root cause is that iBGP split-horizon prevents R1 from advertising the prefix to R3.

979
MCQhard

A network engineer runs the following command to troubleshoot SNMPv3: R1# show snmp user User name: admin Engine ID: 800000090300001122334455 Storage-type: nonvolatile Authentication Protocol: SHA Privacy Protocol: AES128 Group: admin-group User name: monitor Engine ID: 800000090300001122334455 Storage-type: nonvolatile Authentication Protocol: MD5 Privacy Protocol: DES Group: monitor-group What does this output indicate?

A.Two SNMPv3 users are configured: 'admin' with SHA/AES128 and 'monitor' with MD5/DES.
B.SNMPv3 is not configured because no users are shown.
C.Both users use the same authentication and privacy protocols.
D.The users are in the same SNMP group.
AnswerA

The output lists two distinct SNMPv3 user entries, each with its own authentication and privacy protocols: admin uses SHA with AES128, while monitor uses MD5 with DES. Both share the same engine ID, confirming they belong to the local agent.

Why this answer

The output from 'show snmp user' displays two SNMPv3 users: 'admin' with SHA authentication and AES128 privacy, and 'monitor' with MD5 authentication and DES privacy. This confirms that both users are configured with different security levels, making option A correct.

Exam trap

Cisco often tests the ability to read the 'show snmp user' output carefully, where candidates may overlook the different groups or security protocols and assume all users share the same settings.

How to eliminate wrong answers

Option B is wrong because the output clearly shows two SNMPv3 users, indicating SNMPv3 is configured. Option C is wrong because 'admin' uses SHA/AES128 while 'monitor' uses MD5/DES, which are different authentication and privacy protocols. Option D is wrong because the users belong to different groups: 'admin' is in 'admin-group' and 'monitor' is in 'monitor-group'.

980
MCQmedium

A network engineer runs the following command on Router R1: R1# show crypto isakmp sa dst src state conn-id slot status 10.1.1.2 10.1.1.1 MM_NO_STATE 1 0 ACTIVE Based on this output, what is the problem?

A.The IPsec SA is established and working correctly.
B.The IKE phase 1 negotiation has failed; the pre-shared key may be mismatched.
C.The tunnel is up but no interesting traffic is triggering the IPsec SA.
D.The ISAKMP SA is in MM_ACTIVE state, meaning phase 1 is complete.
AnswerB

MM_NO_STATE means main mode has not progressed past the first exchange, so IKE phase 1 never completed. Mismatched pre-shared keys are a common cause, as the peers cannot authenticate and the SA stalls in this state.

Why this answer

The MM_NO_STATE indicates that the IKE phase 1 negotiation has not progressed past the initial state. This typically means the peer is not responding to the ISAKMP proposals, often due to mismatched pre-shared keys or access-list blocking UDP port 500.

981
MCQmedium

A network engineer runs the following command to troubleshoot an IP SLA issue: R1# show ip sla history 10 Point by Point History Entry = 10 Life = 1 Time of Event = 12:34:56.789 UTC Mon Mar 1 2021 Start Time = 12:34:56.789 UTC Mon Mar 1 2021 Completion Time = 12:34:57.001 UTC Mon Mar 1 2021 Return Code = OK RTT = 12 ms Life = 2 Time of Event = 12:35:56.789 UTC Mon Mar 1 2021 Start Time = 12:35:56.789 UTC Mon Mar 1 2021 Completion Time = 12:35:57.001 UTC Mon Mar 1 2021 Return Code = OK RTT = 14 ms Life = 3 Time of Event = 12:36:56.789 UTC Mon Mar 1 2021 Start Time = 12:36:56.789 UTC Mon Mar 1 2021 Completion Time = 12:36:57.001 UTC Mon Mar 1 2021 Return Code = OK RTT = 11 ms What does this output indicate?

A.The IP SLA operation has experienced multiple timeouts.
B.The IP SLA operation shows a history of successful probes with low RTT values.
C.The IP SLA operation has failed because the RTT values are inconsistent.
D.The IP SLA operation is not configured because no history is shown.
AnswerB

Each history entry shows Return Code = OK with round-trip times of 11-14 ms, confirming the operation completed successfully on every probe. There are no timeouts or failures, so the IP SLA operation is functioning normally with consistently low latency.

Why this answer

This output shows historical data for IP SLA operation 10. Each entry shows a successful probe with RTT around 11-14 ms, indicating consistent performance over time.

982
MCQmedium

A network engineer runs the following command on Router R1: R1# show bfd neighbors detail IPv4 Sessions NeighborAddr LD/RD Int State Holdown(mult) Intf 10.1.1.2 1/3 Gi0/0 Up 3000(3) Gi0/0 Session state is UP and not using echo function. OurAddr: 10.1.1.1 Handle: 1 Local Diag: 0, Demand mode: 0, Poll bit: 0 MinTxInt: 1000000, MinRxInt: 1000000, Multiplier: 3 Received MinRxInt: 1000000, Received Multiplier: 3 Holddown (hits): 3000(0) Rx Count: 100, Tx Count: 100 Based on this output, what is the BFD session's detection time?

A.The detection time is 3000 ms.
B.The detection time is 1000 ms.
C.The detection time is 1500 ms.
D.The detection time is 9000 ms.
AnswerA

Detection time equals the negotiated transmit interval multiplied by the multiplier. Both peers advertise 1000000 microseconds (1000 ms) with a multiplier of 3, giving 3000 ms, which matches the Holdown field shown in the neighbour table.

Why this answer

The detection time is the holddown timer, which is the negotiated transmit interval multiplied by the multiplier. The negotiated transmit interval is 1000 ms (maximum of local MinTxInt and received MinRxInt), and the multiplier is 3, so the detection time is 3000 ms.

983
Multi-Selecthard

Which TWO statements about the behavior of administrative distance in Cisco IOS are correct? (Choose TWO.)

Select 2 answers
A.The default administrative distance for an EIGRP summary route is 5.
B.The default administrative distance for OSPF is 90.
C.The distance command applied under a routing protocol can modify the AD for all routes, including connected and static routes, learned via that protocol.
D.The show ip route command displays the administrative distance of each route in the routing table.
E.When two different routing protocols provide routes to the same destination, the route with the higher administrative distance is installed in the routing table.
AnswersA, D

EIGRP summary routes carry an administrative distance of 5, making them more trusted than internal EIGRP routes (90) or external EIGRP routes (170). This ensures the summary is preferred when competing with its component routes.

Why this answer

Option A is correct because Cisco IOS assigns an EIGRP summary route a default administrative distance of 5, which is lower (more preferred) than internal EIGRP's AD of 90, reflecting the summary's trusted status. Option D is correct because the show ip route command output includes the administrative distance and metric in brackets, e.g., [90/30720], for each route in the routing table. Option B is incorrect because OSPF's default administrative distance is 110, not 90 (90 is internal EIGRP).

Option C is incorrect because the distance command under a routing protocol only changes the AD for routes learned by that protocol; it cannot alter connected or static route distances. Option E is incorrect because when two protocols offer routes to the same destination, the route with the lower administrative distance is preferred and installed, not the higher one.

Exam trap

Candidates often misremember OSPF's AD as 90 (confusing with EIGRP) or think the distance command affects all route types; the exam tests precise default values and command scope.

984
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology. Spokes should be able to communicate directly with each other without traffic traversing the hub. The hub router interface is already configured with 'ip nhrp network-id 1' and 'ip nhrp map multicast dynamic'. Which additional command must be configured on the hub to allow spoke-to-spoke direct tunnels?

A.ip nhrp shortcut
B.ip nhrp network-id 1
C.ip nhrp map multicast dynamic
D.ip nhrp redirect
AnswerD

The 'ip nhrp redirect' command on the hub enables NHRP redirect messages, which inform the originating spoke that a shorter path exists to the destination spoke. This allows the spoke to initiate a direct tunnel, achieving Phase 3 behavior. Without it, spokes continue to route through the hub.

Why this answer

In DMVPN Phase 3, the hub uses 'ip nhrp redirect' to notify spokes of a better path to another spoke. The spoke then uses 'ip nhrp shortcut' to create a direct tunnel. The hub must have 'ip nhrp redirect' configured to enable this behavior.

The other options are either already configured or belong on the spoke.

Exam trap

The trap here is confusing the hub-side command 'ip nhrp redirect' with the spoke-side command 'ip nhrp shortcut', or assuming that multicast mapping alone enables spoke-to-spoke tunnels.

985
MCQhard

A network engineer configures EEM to monitor memory usage on R1. R1 has: event manager applet MEM-MONITOR event snmp oid 1.3.6.1.4.1.9.9.48.1.1.1.6.1 get-type exact entry-op gt entry-val 90 poll-interval 10 action 1.0 cli command "enable" action 2.0 cli command "show processes memory" action 3.0 syslog msg "High memory usage detected". After a few days, the engineer notices that the applet never triggers, even though memory usage exceeds 90%. Router R2 shows: memory usage is at 95%, but no syslog from EEM. What is the root cause?

A.The SNMP OID is for free memory, and the condition checks if free memory is greater than 90%, which is not met when memory is low.
B.The poll-interval of 10 seconds is too short and causes the applet to be suppressed.
C.The SNMP community string is not configured, so the OID cannot be polled.
D.The applet requires 'event manager applet MEM-MONITOR trigger' to start.
AnswerA

The OID returns free memory; the applet triggers only when free memory >90%, which never happens when memory is high.

Why this answer

The SNMP OID used (1.3.6.1.4.1.9.9.48.1.1.1.6.1) is for the free memory, not used memory. The applet checks if free memory is greater than 90%, which is false when memory is low. The correct OID should be for used memory or the comparison operator should be 'lt' for free memory below 10%.

986
Drag & Dropmedium

Drag and drop the steps to establish a DMVPN Phase 2 spoke-to-spoke tunnel into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

In DMVPN Phase 2, spoke-to-spoke tunnels are built dynamically. First, the spoke must have a valid NHRP registration to the hub. When traffic from one spoke to another triggers an NHRP resolution request, the hub forwards it to the target spoke, which replies.

The spoke then initiates a direct mGRE tunnel, and finally, the spoke-to-spoke IPsec session is established.

987
MCQmedium

Which of the following statements about MPLS L3VPN label operations is true?

A.The ingress PE pushes two labels: the outer IGP label and the inner VPN label.
B.The egress PE uses the IGP label to determine the VRF.
C.The P routers swap the VPN label as they forward the packet.
D.The ingress PE pushes only one label (the VPN label) and uses the IP destination for forwarding.
AnswerA

In MPLS L3VPN, the ingress PE imposes a two-label stack: the outer label is the IGP or transport label used to reach the egress PE, while the inner VPN label identifies the destination VRF. This label stacking is the defining operation.

Why this answer

In MPLS L3VPN, the PE router assigns a per-VRF label (VPN label) for each prefix in the VRF. When forwarding a packet from the CE, the ingress PE pushes an IGP label (for the egress PE) and the VPN label. The egress PE pops the IGP label and uses the VPN label to identify the VRF and forward to the correct CE.

988
MCQeasy

In a VRF-Lite scenario with OSPF, what is the default network type on a physical Ethernet interface?

A.Point-to-point
B.Broadcast
C.Non-broadcast
D.Point-to-multipoint
AnswerB

Physical Ethernet interfaces default to the broadcast network type in OSPF, electing a DR and BDR and using multicast hellos. Point-to-point applies only to serial links or explicit configuration, so no DR election occurs here.

Why this answer

By default, OSPF sets the network type to broadcast on Ethernet interfaces, which enables DR/BDR election.

989
MCQhard

A network engineer is troubleshooting a router that has been running for 200 days. The router experiences a sudden reboot, and after reload, the configuration is missing. 'show startup-config' returns 'startup-config is not present'. The engineer checks the boot variable: 'boot system flash:ios-image.bin'. What is the most likely cause of the configuration loss?

A.The router's NVRAM has a hardware failure and lost the configuration.
B.The engineer did not execute 'copy running-config startup-config' before the reboot.
C.The 'boot system' command points to a TFTP server that also contains a configuration file, overwriting the local startup-config.
D.The router's configuration register is set to 0x2142, ignoring startup-config.
AnswerB

The running-config is stored in volatile RAM and is lost on reload, while the startup-config resides in NVRAM. If the engineer never executed 'copy running-config startup-config' (or 'write memory') during the 200 days of uptime, the startup-config file would remain empty or nonexistent. After reboot, the router loads with no saved configuration, causing 'show startup-config' to report that the file is not present, exactly as shown.

Why this answer

The router's startup configuration is stored in NVRAM, and if the engineer never executed 'copy running-config startup-config' (or equivalent 'write memory'), the running configuration exists only in RAM. Upon reboot, the router loads the IOS image from flash as specified by the 'boot system flash:ios-image.bin' variable, but NVRAM contains no saved startup configuration, resulting in 'startup-config is not present'. This is a classic operational oversight where changes are made to the running configuration but not saved to NVRAM.

Exam trap

Cisco often tests the distinction between a missing startup configuration (due to failure to save) and a configuration that is present but ignored (due to the configuration register), so candidates must recognize that 'startup-config is not present' indicates an empty NVRAM, not a register override.

How to eliminate wrong answers

Option A is wrong because a hardware failure in NVRAM would typically cause a checksum error or corruption message, not a clean 'startup-config is not present' response; the router would also likely fail to boot or show other symptoms. Option C is wrong because the 'boot system' command only specifies the IOS image location; it does not point to a TFTP server for configuration files, and even if a TFTP configuration were used, it would not overwrite the local startup-config unless explicitly configured via 'boot network' or 'service config'. Option D is wrong because a configuration register of 0x2142 causes the router to ignore the startup configuration during boot, but the startup-config file itself remains intact in NVRAM; 'show startup-config' would still display the configuration, not return 'startup-config is not present'.

990
MCQmedium

Which BGP attribute is considered the highest priority (most preferred) in the BGP best path selection process?

A.Local preference
B.AS path length
C.Weight
D.MED
AnswerC

Weight is a Cisco-proprietary attribute local to the router and evaluated before all other attributes, including local preference and AS path. Higher weight wins, so it is checked first in the best path selection algorithm, making it the most preferred attribute.

Why this answer

C is correct because the Weight attribute is Cisco-proprietary and is evaluated first in the BGP best path selection process. It has the highest priority, with a higher weight being preferred, and it is local to the router only.

Exam trap

Cisco often tests the order of BGP path selection attributes, and the trap here is that candidates confuse Local Preference as the highest priority because it is the first well-known mandatory attribute, forgetting that the Cisco-proprietary Weight is evaluated first.

How to eliminate wrong answers

Option A is wrong because Local Preference is evaluated after Weight; it is the second step in the BGP best path selection and is used to influence outbound traffic from an AS. Option B is wrong because AS path length is evaluated after Local Preference (step 4) and is used to prefer shorter paths, not as the highest priority. Option D is wrong because MED (Multi-Exit Discriminator) is evaluated after AS path length (step 5) and is used to influence inbound traffic to an AS, not as the highest priority.

991
MCQeasy

A network engineer runs the following command on Router R1: R1# show ip access-lists Extended IP access list 150 10 permit ip 10.0.0.0 0.255.255.255 any (500 matches) 20 deny ip any any (100 matches) Based on this output, which statement is correct?

A.Traffic from 10.0.0.0/8 is denied.
B.Traffic not from 10.0.0.0/8 is denied.
C.All traffic is permitted.
D.The ACL has no effect.
AnswerB

The wildcard mask 0.255.255.255 matches only the first octet, so 10.0.0.0/8 is permitted by sequence 10. Sequence 20 then denies all remaining traffic, including any source outside that range. The 100 deny matches confirm non-10.x traffic was dropped, satisfying the implicit deny behaviour explicitly.

Why this answer

The ACL 150 has a permit entry for source 10.0.0.0/8 (wildcard 0.255.255.255) followed by a deny any any. Traffic matching the permit (from 10.0.0.0/8) is allowed, while all other traffic is denied by the implicit deny or the explicit deny entry. Thus, traffic not from the 10.0.0.0/8 network is denied, making option B correct.

Exam trap

Cisco often tests the misconception that an ACL with a permit entry followed by a deny entry permits all traffic, when in fact the deny explicitly blocks everything not matching the earlier permit.

How to eliminate wrong answers

Option A is wrong because the ACL permits traffic from 10.0.0.0/8 (500 matches), not denies it. Option C is wrong because the ACL includes an explicit deny ip any any (100 matches), which blocks all traffic not matching the permit, so not all traffic is permitted. Option D is wrong because the ACL is applied (matches are shown) and actively filters traffic, so it has an effect.

992
MCQhard

In MPLS, what is the default label distribution control mode for LDP on Cisco IOS-XE?

A.Ordered Label Distribution Control mode
B.Independent Label Distribution Control mode
C.Liberal Label Retention mode
D.Conservative Label Retention mode
AnswerB

Cisco IOS-XE defaults to Independent mode, where each LSR advertises label bindings for prefixes it knows without waiting for downstream labels. This satisfies the stem's default requirement, unlike Ordered mode, which requires a downstream binding before advertising upstream.

Why this answer

The default label distribution control mode for LDP on Cisco IOS-XE is Independent Label Distribution Control mode. In this mode, each LSR can distribute label bindings to its neighbors independently, without waiting for a label binding from its downstream neighbor. This is the default behavior on Cisco IOS-XE.

Exam trap

300-410 often tests whether candidates confuse label distribution control modes (Independent vs. Ordered) with label retention modes (Liberal vs. Conservative), leading to incorrect answers.

How to eliminate wrong answers

Option A is wrong because Ordered Label Distribution Control mode requires an LSR to wait for a label binding from its downstream neighbor before distributing a label binding upstream; this is not the default on IOS-XE. Option C is wrong because Liberal Label Retention mode is a label retention mode, not a label distribution control mode; it controls how labels are retained, not distributed. Option D is wrong because Conservative Label Retention mode is also a label retention mode, not a distribution control mode.

993
MCQeasy

A network engineer runs the following command on Router R1: R1# show ip route vrf RED 192.168.1.0 Routing entry for 192.168.1.0/24 Known via "connected", distance 0, metric 0 (connected, via interface) Routing Descriptor Blocks: * directly connected, via GigabitEthernet0/2 Route metric is 0, traffic share count is 1 Based on this output, which statement is correct?

A.The route is learned via OSPF.
B.The route is a static route.
C.The route is directly connected via GigabitEthernet0/2.
D.The route has a metric of 1.
AnswerC

The output explicitly lists the routing descriptor block as directly connected via GigabitEthernet0/2, with distance 0 and metric 0, confirming the route is a connected interface route within VRF RED rather than a learned or redistributed prefix.

Why this answer

The output shows 'Known via "connected", distance 0, metric 0 (connected, via interface)' and 'directly connected, via GigabitEthernet0/2', which unambiguously identifies a directly connected route in the VRF RED routing table. Connected routes have an administrative distance of 0 and a metric of 0, and are installed when an interface with an IP address in that subnet is up.

Exam trap

The trap is misreading the 'Known via' field or the distance value — candidates may assume any route in a VRF is learned dynamically, but 'connected' with distance 0 is definitive.

How to eliminate wrong answers

Option A is wrong because OSPF-learned routes would show 'Known via "ospf"' with an administrative distance of 110, not 'connected' with distance 0. Option B is wrong because static routes show 'Known via "static"' with a default administrative distance of 1 (or 0 for floating static with explicit distance), not 'connected'. Option D is wrong because the output explicitly states 'metric 0' and 'Route metric is 0', so a metric of 1 is contradicted by the command output.

994
MCQmedium

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 192.168.1.0/24 subnet is encrypted and sent through the tunnel, while other traffic is sent unencrypted. Which configuration element is required to define the interesting traffic?

A.transform set
B.crypto map
C.ISAKMP policy
D.access-list
AnswerD

An access list (ACL) is used to define which traffic is considered interesting and should be encrypted. For example, an ACL permitting IP traffic from 192.168.1.0/24 to the remote subnet will match that traffic for encryption. The crypto map references this ACL to determine what to protect.

Why this answer

In Cisco IOS IPsec configuration, an access list (ACL) is used to define interesting traffic that should be encrypted and sent through the VPN tunnel. The ACL specifies the source and destination subnets. The crypto map then references this ACL to apply IPsec to matching traffic.

Other components like transform set and ISAKMP policy handle encryption algorithms and key exchange, but not traffic selection.

Exam trap

The trap here is confusing the role of the crypto map with the ACL; the crypto map references the ACL but does not itself define the traffic.

995
Multi-Selecthard

Which TWO statements about IPsec site-to-site VPN troubleshooting using 'show crypto session' and 'show crypto ipsec sa' are correct? (Choose TWO.)

Select 2 answers
A.'show crypto session' displays the IKEv2 SA status and the IPsec SA status.
B.'show crypto ipsec sa' shows the number of packets that have been encrypted and decrypted.
C.'show crypto isakmp sa' is the correct command to view IKEv2 SAs.
D.The 'pkts encaps' counter in 'show crypto ipsec sa' increments on the inbound SA.
E.'show crypto map' displays the current packet count for each IPsec SA.
AnswersA, B

'show crypto session' reports both IKEv2 SA and IPsec SA status per peer, letting you confirm Phase 1 and Phase 2 are up in one command. This satisfies the stem's requirement for troubleshooting site-to-site VPNs, since a down IKEv2 SA or missing IPsec SA immediately localises the failure to negotiation or traffic-selector mismatch.

Why this answer

Option A is correct because 'show crypto session' reports both the IKE (IKEv2) SA state and the IPsec SA state for each peer, giving a quick view of whether the control-plane tunnel and data-plane SAs are up. Option B is correct because 'show crypto ipsec sa' includes per-SA counters such as '#pkts encaps' and '#pkts decaps', which reflect the number of packets encrypted (encapsulated) and decrypted (decapsulated). Option C is wrong because 'show crypto isakmp sa' displays ISAKMP/IKEv1 SAs, not IKEv2 SAs; IKEv2 SAs are viewed with 'show crypto ikev2 sa'.

Option D is wrong because the 'pkts encaps' counter increments on the outbound SA as packets are encrypted, while inbound traffic increments the decapsulation counter. Option E is wrong because 'show crypto map' displays crypto map configuration and matching details, not per-SA packet counters.

Exam trap

Cisco often tests the distinction between IKEv1 and IKEv2 commands, so the trap here is that candidates mistakenly use 'show crypto isakmp sa' for IKEv2 SAs, not realizing that IKEv2 has its own dedicated 'show crypto ikev2 sa' command.

996
MCQeasy

What is the default administrative distance for OSPF routes in Cisco IOS?

A.90
B.100
C.110
D.120
AnswerC

OSPF's default administrative distance in Cisco IOS is 110, ranking it less trustworthy than EIGRP's 90 but more than RIP's 120. This value governs route selection when multiple protocols offer the same prefix, satisfying the stem's request for OSPF's default.

Why this answer

OSPF has a default administrative distance (AD) of 110 in Cisco IOS. This value is used by the router to select the best route when multiple routing protocols provide a route to the same destination, with lower AD values being preferred. OSPF's AD of 110 is higher than that of static routes (1) and EIGRP (90/170), but lower than RIP (120) and IS-IS (115).

Exam trap

Cisco often tests the default administrative distances of OSPF, EIGRP, and RIP together, and the trap here is confusing OSPF's AD of 110 with EIGRP's AD of 90 or RIP's AD of 120, especially since OSPF is commonly associated with link-state protocols that are often considered more reliable than distance-vector protocols like RIP.

How to eliminate wrong answers

Option A is wrong because 90 is the default administrative distance for EIGRP internal routes, not OSPF. Option B is wrong because 100 is not a standard default administrative distance for any common routing protocol in Cisco IOS; it is sometimes used for iBGP or as a custom value. Option D is wrong because 120 is the default administrative distance for RIP, not OSPF.

997
MCQmedium

A network engineer is configuring a Cisco IOS XE router to mitigate spoofed source addresses on a WAN-facing interface using Unicast Reverse Path Forwarding. The WAN provider uses asymmetric routing, where return traffic from the provider occasionally arrives on a different interface than the one used for outbound traffic. The engineer wants to avoid dropping legitimate packets while still providing anti-spoofing protection. Which uRPF mode should the engineer configure on the WAN interface?

A.Loose mode
B.Strict mode
C.VRF-aware strict mode
D.Feasible path mode
AnswerA

Loose mode checks only that the source address is reachable via any route in the routing table, not necessarily the receiving interface. This preserves anti-spoofing protection for addresses that are completely unknown while allowing legitimate traffic that arrives over a different path than the outbound route. It is the appropriate choice when asymmetric routing exists on the WAN link.

Why this answer

Loose mode verifies that the source address exists in the routing table without requiring the packet to arrive on the same interface as the reverse route. This allows asymmetric traffic to pass while still dropping packets with completely unknown source addresses, providing useful anti-spoofing protection. Strict and feasible path modes would drop legitimate asymmetric traffic, and VRF-aware mode does not change the fundamental same-interface requirement.

Exam trap

The trap here is assuming that strict mode is always the best anti-spoofing choice, when asymmetric routing requires loose mode to avoid dropping legitimate traffic.

998
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub router. Spoke routers are behind dynamic NAT and cannot receive inbound connections. The engineer needs to ensure that spoke-to-spoke traffic flows directly without traversing the hub. Which technology must be enabled on the hub to achieve this?

A.IPsec transport mode
B.NHRP redirect
C.NHRP shortcut
D.Multipoint GRE with dynamic routing
AnswerB

NHRP redirect allows the hub to inform the originating spoke that a shorter path exists to the destination spoke, enabling direct spoke-to-spoke tunnels. When the hub receives a packet from one spoke destined to another, it sends an NHRP redirect message to the source spoke, which then initiates an NHRP resolution for the destination spoke's public address and builds a direct tunnel. This is a key feature of DMVPN Phase 3.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to notify a spoke that a better path exists to another spoke. The spoke then uses NHRP shortcut to resolve the destination's public address and establish a direct tunnel. Without NHRP redirect on the hub, spokes continue to send traffic through the hub even if they are capable of direct communication.

Exam trap

The trap here is confusing NHRP shortcut with NHRP redirect; shortcut is configured on spokes, but redirect must be enabled on the hub to trigger the process.

999
MCQmedium

A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue: R1# debug ip packet 110 IP packet debugging is on for access list 110 *Mar 1 00:15:22.345: IP: s=10.1.1.1 (GigabitEthernet0/0), d=10.2.2.2, len 100, proto TCP, flags 0x2, sport 12345, dport 23, access list 110: matched line 10 deny tcp host 10.1.1.1 host 10.2.2.2 eq 23 *Mar 1 00:15:22.346: IP: s=10.1.1.1 (GigabitEthernet0/0), d=10.2.2.2, len 100, proto TCP, flags 0x10, sport 12345, dport 23, access list 110: matched line 10 deny tcp host 10.1.1.1 host 10.2.2.2 eq 23 What does this output indicate?

A.Telnet traffic from 10.1.1.1 to 10.2.2.2 is being denied by ACL 110.
B.Telnet traffic from 10.1.1.1 to 10.2.2.2 is being permitted by ACL 110.
C.ACL 110 is applied outbound on GigabitEthernet0/0.
D.ACL 110 has no line 10.
AnswerA

The debug output shows packets from 10.1.1.1 to 10.2.2.2 with destination port 23 (Telnet) matching line 10 of ACL 110, whose action is deny. Both the SYN and the reset flag entries confirm the Telnet session is blocked.

Why this answer

The debug output shows packets with source IP 10.1.1.1 and destination IP 10.2.2.2, protocol TCP, destination port 23 (Telnet), and the log explicitly states 'matched line 10 deny tcp host 10.1.1.1 host 10.2.2.2 eq 23'. This confirms that ACL 110 is denying Telnet traffic from 10.1.1.1 to 10.2.2.2. The flags 0x2 (SYN) and 0x10 (ACK) indicate the initial and subsequent packets of the Telnet session are both being denied.

Exam trap

The trap here is that candidates may misinterpret the 'matched line 10 deny' as a permit action or assume the ACL is applied outbound based on the source interface, but the debug only shows the packet's ingress interface and the ACL match result, not the ACL's application direction.

How to eliminate wrong answers

Option B is wrong because the debug output clearly shows 'deny' on line 10, not 'permit', so Telnet traffic is being blocked, not permitted. Option C is wrong because the debug output shows the source interface as GigabitEthernet0/0, but the ACL could be applied inbound or outbound; the debug does not specify the direction, and the 's=10.1.1.1 (GigabitEthernet0/0)' indicates the packet entered on that interface, but the ACL could be applied inbound or outbound on another interface. Option D is wrong because the debug output explicitly states 'matched line 10', proving that line 10 exists in ACL 110.

1000
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate management users via TACACS+ against an ISE server. The engineer wants to ensure that if the TACACS+ server becomes unreachable, the router will fall back to using the local username database for authentication. The TACACS+ server is already configured with the address 10.1.1.100 and a shared secret. Which additional configuration is required on the router to achieve this fallback?

A.aaa authentication login default group tacacs+ local
B.aaa authentication login default group tacacs+ none
C.tacacs-server timeout 5
D.tacacs-server directed-request
AnswerA

This command configures the default login authentication method list to first use TACACS+ and then fall back to the local username database if the TACACS+ server is unreachable. The 'local' keyword at the end ensures that local authentication is attempted only if the TACACS+ group does not respond, which is exactly the desired behavior for failover.

Why this answer

The correct configuration is to define an AAA authentication method list that includes both TACACS+ and local. The command 'aaa authentication login default group tacacs+ local' ensures that the router first attempts authentication via TACACS+; if the server is unreachable, it then checks the local username database. This provides the required fallback and maintains security by not allowing unauthenticated access.

Exam trap

The trap here is confusing the 'none' keyword with fallback to local; 'none' means no authentication, not local database fallback.

1001
MCQhard

A network engineer runs the following command to troubleshoot IPsec IKE phase 1: R1# debug crypto isakmp ISAKMP: (0:0:N/A:0) Starting aggressive mode exchange ISAKMP: (0:0:N/A:0) processing SA payload ISAKMP: (0:0:N/A:0) Checking ISAKMP transform 1 against priority 1 policy ISAKMP: (0:0:N/A:0) encryption 3DES ISAKMP: (0:0:N/A:0) hash SHA ISAKMP: (0:0:N/A:0) group 2 ISAKMP: (0:0:N/A:0) auth pre-share ISAKMP: (0:0:N/A:0) life type in seconds ISAKMP: (0:0:N/A:0) life duration (basic) of 86400 ISAKMP: (0:0:N/A:0) atts are not acceptable What does this output indicate?

A.IKE phase 1 is successful; the transform set is accepted.
B.IKE phase 1 fails due to transform set mismatch.
C.IKE phase 1 fails due to authentication failure.
D.IKE phase 1 fails due to lifetime mismatch.
AnswerB

The debug shows the responder comparing its priority 1 ISAKMP policy against the initiator's proposed transform (3DES, SHA, group 2, pre-share, 86400s). The message 'atts are not acceptable' means no attribute set matched, so phase 1 fails on transform mismatch.

Why this answer

The debug output shows that the ISAKMP transform (3DES, SHA, group 2, pre-share) is being checked against the local policy, and the message 'atts are not acceptable' indicates a mismatch. This means the proposed transform set does not match any configured IKE policy on the responder, causing IKE phase 1 to fail. The failure is specifically due to a transform set mismatch, not authentication or lifetime issues.

Exam trap

Cisco often tests the distinction between transform set mismatch and authentication failure, where candidates mistakenly assume that any failure in IKE phase 1 is due to authentication, but the debug message 'atts are not acceptable' specifically points to a proposal mismatch.

How to eliminate wrong answers

Option A is wrong because the debug output explicitly states 'atts are not acceptable', which means the transform set is rejected, not accepted. Option C is wrong because authentication failure would occur later in the exchange (after SA parameters are agreed upon) and would show different debug messages, such as 'auth mode mismatch' or 'no suitable peer found'. Option D is wrong because the lifetime value of 86400 seconds is displayed without any indication of mismatch; the debug output does not flag the lifetime as unacceptable, and lifetime mismatches are typically negotiated or cause a different error message.

1002
MCQeasy

In EIGRP, what is the default administrative distance of a summary route created with the 'ip summary-address eigrp' command?

A.5
B.90
C.170
D.1
AnswerA

EIGRP summary routes created with 'ip summary-address eigrp' are advertised with an administrative distance of 5, unlike internal EIGRP routes (90) or external EIGRP routes (170). This low value ensures the summary is preferred, satisfying the question's default-value constraint.

Why this answer

By default, EIGRP summary routes have an administrative distance of 5, which is lower than the default distance of 90 for internal EIGRP routes.

1003
MCQeasy

What is the maximum number of actions that can be configured in a single EEM applet?

A.128
B.255
C.512
D.Unlimited
AnswerB

An EEM applet supports a maximum of 255 action statements within its single event block. This hard limit defines how many CLI commands or operations one applet can chain together when triggered, so 255 is the documented ceiling.

Why this answer

In Cisco IOS Embedded Event Manager (EEM), a single applet can contain a maximum of 255 actions. This limit is defined by the EEM applet action numbering range, which goes from 1 to 255. Exceeding this limit requires splitting the logic into multiple applets or using Tcl policies, which do not have the same restriction.

Exam trap

300-410 often tests the specific numeric limit of EEM applet actions, catching candidates who assume a higher or unlimited number based on general scripting capabilities.

How to eliminate wrong answers

Option A is wrong because 128 is not the maximum; it is a common power-of-two value that candidates may assume. Option C is wrong because 512 exceeds the actual limit and is not supported. Option D is wrong because EEM applets have a hard limit of 255 actions, not unlimited; Tcl policies are the alternative for more complex logic.

1004
MCQmedium

An engineer is troubleshooting why the NMS is receiving duplicate SNMP traps from router R9 for the same event. The router has two 'snmp-server host' commands pointing to the same NMS IP address but with different community strings: 'public' and 'private'. The NMS is configured to process traps from both communities. What is the most likely cause?

A.The router sends one trap per 'snmp-server host' command, resulting in duplicate traps for the same event.
B.The NMS is configured to listen on two different ports, causing duplicate reception.
C.The router has an SNMP trap filter that is misconfigured, causing the same trap to be sent twice.
D.The engineer enabled both 'snmp-server enable traps' and 'snmp-server enable informs', causing duplicate notifications.
AnswerA

Each snmp-server host command creates a separate notification destination entry, so the router generates one trap per matching command for the same event. Two commands pointing at the same NMS IP therefore produce duplicate traps, which the NMS processes from both communities.

Why this answer

Each 'snmp-server host' command creates a separate trap destination entry in the router's SNMP configuration. When a trap-generating event occurs, the router sends a trap to each configured destination. Since both commands point to the same NMS IP address but with different community strings ('public' and 'private'), the router sends two identical traps (one with each community string) for the same event, causing the NMS to receive duplicates.

Exam trap

Cisco often tests the misconception that multiple 'snmp-server host' commands with the same IP but different communities are redundant or that the router deduplicates them, when in fact each command generates a separate trap transmission.

How to eliminate wrong answers

Option B is wrong because SNMP traps are sent to UDP port 162 by default, and the NMS listening on two different ports would not cause duplicate reception unless the router is configured to send to different ports, which is not stated. Option C is wrong because SNMP trap filters control which traps are sent or suppressed, not the duplication of traps; a misconfigured filter would either block or allow traps, not send the same trap twice. Option D is wrong because 'snmp-server enable traps' and 'snmp-server enable informs' enable different notification types (traps vs. informs), but informs require acknowledgment and are not sent as duplicates of traps; the scenario specifies traps, not informs.

1005
MCQmedium

When an SNMP agent sends an InformRequest, what is the default behavior regarding acknowledgment?

A.The agent does not expect any acknowledgment; it is fire-and-forget.
B.The agent expects a Response PDU from the manager; if not received, it retransmits.
C.The manager sends an acknowledgment at the transport layer only.
D.The agent sends the inform multiple times by default regardless of acknowledgment.
AnswerB

InformRequest is the acknowledged variant of a trap: the agent retains the PDU and waits for a Response from the manager, retransmitting at intervals until confirmation arrives or retries are exhausted. Traps, by contrast, are unacknowledged.

Why this answer

An SNMP InformRequest is a confirmed notification: the agent expects a Response PDU from the manager to acknowledge receipt. If the agent does not receive this response within a timeout period, it will retransmit the InformRequest. This is defined in RFC 3416 and distinguishes InformRequests from Traps, which are unacknowledged.

Exam trap

Cisco often tests the distinction between Traps (unacknowledged) and Informs (acknowledged), and the trap here is that candidates confuse the transport-layer acknowledgment (TCP ACK) with the SNMP application-layer Response PDU, leading them to pick option C.

How to eliminate wrong answers

Option A is wrong because an InformRequest is not fire-and-forget; it requires an acknowledgment via a Response PDU, unlike a Trap. Option C is wrong because the acknowledgment occurs at the SNMP application layer via a Response PDU, not merely at the transport layer (e.g., TCP ACK). Option D is wrong because the agent does not send the inform multiple times by default; retransmission only occurs if the expected Response PDU is not received within the configured timeout.

1006
MCQhard

A network engineer runs the following command to troubleshoot BFD session flapping: R1# debug bfd packet *Mar 1 00:15:23.456: BFD: [R1-to-R3] received async packet from 10.5.5.2, state UP, diag 0 *Mar 1 00:15:23.457: BFD: [R1-to-R3] sending async packet, state UP *Mar 1 00:15:23.458: BFD: [R1-to-R3] received echo packet from 10.5.5.2, state UP *Mar 1 00:15:23.459: BFD: [R1-to-R3] echo packet lost, no echo received for 300 ms *Mar 1 00:15:23.460: BFD: [R1-to-R3] state UP -> DOWN (echo failure) What does this output indicate?

A.BFD session is UP and stable.
B.BFD session went DOWN because of echo timeout, indicating possible path issue.
C.BFD async packets are failing, causing session down.
D.BFD session is flapping due to misconfigured multiplier.
AnswerB

The debug shows echo packets failing while async control packets remain UP, so the session transitions UP to DOWN specifically on echo timeout. That points to a forwarding-path problem affecting echo traffic rather than a control-plane failure.

Why this answer

The debug output shows the BFD session transitioning from UP to DOWN specifically due to an echo failure — the echo packet sent to 10.5.5.2 was not returned within the 300 ms echo interval. This indicates the forwarding path for echo packets is broken even though async control packets are still being received, which is the classic signature of a unidirectional or return-path forwarding problem. The session is not stable and the cause is echo timeout, not async packet loss or multiplier misconfiguration.

Exam trap

The trap here is confusing async control packet failure with echo packet failure — candidates see 'BFD session down' and assume the control packets are the problem, when the log clearly shows async packets succeeding and only echo packets failing.

How to eliminate wrong answers

Option A is wrong because the log explicitly shows 'state UP -> DOWN (echo failure)', so the session is not stable. Option C is wrong because the async packets are being received and sent successfully ('received async packet... state UP' and 'sending async packet, state UP'); it is the echo packets that fail, not the async control packets. Option D is wrong because there is no evidence of multiplier misconfiguration — the failure is a single echo timeout at 300 ms, and the log attributes the down event to echo failure, not to a detect-multiplier expiry.

1007
MCQmedium

Consider the following EIGRP configuration on Router R4: router eigrp 300 variance 2 network 172.16.0.0 What is the purpose of the variance command?

A.It sets the maximum number of equal-cost paths to 2.
B.It allows load balancing over paths with metrics up to twice the best metric.
C.It enables unequal-cost load balancing with a factor of 2.
D.It sets the EIGRP metric weight for delay to 2.
AnswerB

EIGRP variance multiplies the feasible successor's metric against the successor's metric; a value of 2 permits unequal-cost paths whose metric is no more than twice the best metric to be installed, enabling load balancing across them.

Why this answer

The variance command in EIGRP allows unequal-cost load balancing by instructing the router to include routes in the routing table whose metric is less than or equal to the best metric multiplied by the variance value. With variance 2, any feasible successor route with a metric up to twice the best metric (i.e., ≤ best_metric × 2) will be installed and used for load balancing, provided it satisfies the feasibility condition (reported distance < feasible distance). Only option B accurately describes this behavior; option C is tempting but less precise because unequal-cost load balancing also requires feasible successors.

Exam trap

Cisco often tests the distinction between 'variance' (which enables unequal-cost load balancing) and 'maximum-paths' (which limits the number of paths), leading candidates to mistakenly think variance controls the number of paths.

How to eliminate wrong answers

Option A is wrong because the variance command does not set the maximum number of equal-cost paths; that is the purpose of the 'maximum-paths' command (default is 4, maximum 16). Option D is wrong because the variance command does not set EIGRP metric weights; metric weights are configured with the 'metric weights' command (or 'metric tos k1 k2 k3 k4 k5'), and the delay component is controlled by the 'delay' interface command or the 'k3' weight, not by variance.

1008
MCQhard

An engineer configures unicast Reverse Path Forwarding (uRPF) in strict mode on an interface connected to a service provider. The router has a default route pointing to the ISP. Traffic from the ISP is being dropped by uRPF. Which is the most likely explanation?

A.Strict mode uRPF does not use the default route for verification unless the 'allow-default' option is enabled.
B.The interface is configured with the wrong IP address, causing uRPF to fail.
C.uRPF should be configured in loose mode to work with default routes.
D.The router has multiple default routes, causing uRPF to fail.
AnswerA

Strict mode uRPF verifies the source against the routing table and discards packets whose source is reachable only via the default route. Enabling 'allow-default' permits that verification, so ISP traffic sourced from addresses covered solely by the default route is dropped without it.

Why this answer

Strict mode uRPF verifies that the source IP of an incoming packet is reachable via the same interface it arrived on, using the routing table. By default, strict uRPF does not consider the default route (0.0.0.0/0) as a valid return path, so traffic from the ISP whose return path is only the default route fails the check and is dropped. Enabling the 'allow-default' option (or using loose mode) permits the default route to satisfy the RPF check.

Exam trap

The trap here is assuming strict uRPF automatically trusts the default route — candidates forget that strict mode ignores 0.0.0.0/0 unless 'allow-default' is explicitly configured.

How to eliminate wrong answers

Option B is wrong because an incorrect interface IP would break connectivity entirely, not selectively drop ISP traffic via uRPF — uRPF failures are specifically about the source address's return path, not the interface's own address. Option C is wrong because loose mode is not required for default routes; strict mode works fine with default routes once 'allow-default' is enabled, so switching modes is not the correct fix. Option D is wrong because multiple default routes do not inherently break uRPF — the RPF check uses the best route to the source; having multiple defaults is a routing design issue, not the uRPF failure cause.

1009
MCQeasy

Which IP SLA operation type uses ICMP to discover the path (hops) between source and destination?

A.ICMP Echo
B.ICMP Path Echo
C.UDP Jitter
D.TCP Connect
AnswerB

ICMP Path Echo uses ICMP echo requests with incrementing TTL values to discover each hop along the path, satisfying the requirement to identify the route between source and destination. Unlike basic ICMP Echo, which only tests reachability to the final target, Path Echo maps intermediate devices hop by hop.

Why this answer

The ICMP Path Echo operation (type 10) uses ICMP Echo requests with increasing TTL values to trace the path from source to destination, similar to traceroute.

1010
MCQmedium

A network engineer is troubleshooting an IPsec site-to-site VPN between two Cisco routers. Phase 1 is up, but Phase 2 fails to establish. The engineer suspects a mismatch in the transform set. Which command should be used to verify the transform set configured for the crypto map on the local router?

A.show crypto map
B.show crypto ipsec transform-set
C.show crypto isakmp sa
D.show crypto ipsec sa
AnswerA

The show crypto map command displays the crypto map configuration, including the transform set, peer, and ACL. It shows the transform set name configured for each crypto map entry, which is exactly what the engineer needs to verify. This command works regardless of Phase 2 status and is the correct choice for checking configuration.

Why this answer

To verify the transform set configured in a crypto map, the show crypto map command is used. It displays the crypto map entries, including the transform set name, peer, and ACL. This allows the engineer to confirm the local configuration and compare it with the remote peer to identify mismatches.

Exam trap

The trap here is selecting show crypto ipsec sa, which only shows active SAs and would be empty if Phase 2 fails, rather than checking the configuration with show crypto map.

1011
Multi-Selecthard

Which TWO configuration steps are required to enable a Cisco IOS router as a stateful DHCPv6 server for clients on interface GigabitEthernet0/0? (Choose TWO.)

Select 2 answers
A.Configure a DHCPv6 pool with the 'ipv6 dhcp pool POOL_NAME' command and define an address prefix.
B.Apply the DHCPv6 pool to the interface using 'ipv6 dhcp server POOL_NAME' under the interface configuration.
C.Configure the interface with 'ipv6 dhcp client POOL_NAME'.
D.Set the 'ipv6 nd managed-config-flag' on the interface.
E.Enable IPv6 on the interface with 'ipv6 enable'.
AnswersA, B

Stateful DHCPv6 requires a pool created with 'ipv6 dhcp pool' containing an address prefix, since the server assigns addresses rather than relying on SLAAC. This defines the address space the router leases to clients on GigabitEthernet0/0.

Why this answer

Option A is correct because a stateful DHCPv6 server must first define a pool using the global configuration command 'ipv6 dhcp pool POOL_NAME' and then specify the addresses to hand out, typically with an 'address prefix' statement (and other parameters such as DNS via 'dns-server'). Option B is correct because the pool must be bound to the client-facing interface with the interface configuration command 'ipv6 dhcp server POOL_NAME', which activates the router as a DHCPv6 server on GigabitEthernet0/0. Option C is wrong because 'ipv6 dhcp client POOL_NAME' is not valid IOS syntax and would configure the router as a client, not a server.

Option D is wrong because 'ipv6 nd managed-config-flag' only tells hosts via Router Advertisement to use DHCPv6 for addressing; it is a client-guidance step, not a required server configuration step. Option E is wrong because 'ipv6 enable' merely activates IPv6 on the interface with a link-local address and is not the mechanism that enables the DHCPv6 server function.

Exam trap

Cisco often tests the distinction between server-side and client-side DHCPv6 commands, and the trap here is that candidates confuse 'ipv6 dhcp server' (server) with 'ipv6 dhcp client' (client) or think that enabling IPv6 on the interface alone is sufficient for DHCPv6 operation.

1012
Multi-Selecthard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against DoS attacks. The engineer has created a class-map to match malicious traffic and a policy-map to police it. Which two statements are true regarding the application and behavior of CoPP? (Choose two.)

Select 2 answers
A.CoPP automatically drops all traffic that exceeds the configured rate, regardless of the exceed-action specified in the policy.
B.The class-default class in a CoPP policy-map must always have a police action configured to drop all unmatched traffic.
C.CoPP uses a token bucket algorithm to enforce rate limits, where the first value is the committed information rate and the second is the burst size.
D.CoPP policies are applied to the control plane using the service-policy command under the control-plane configuration mode.
E.CoPP can be applied to a specific interface to police traffic entering that interface before it reaches the control plane.
AnswersC, D

CoPP, like other policing mechanisms, uses a token bucket algorithm. The police command specifies the committed information rate (CIR) and the burst size. The CIR is the average rate, and the burst size allows for temporary bursts above the CIR. Packets exceeding the burst are dropped or marked according to the exceed-action.

Why this answer

CoPP is applied to the control plane via the service-policy command under control-plane configuration mode, and it uses a token bucket algorithm with a committed information rate and burst size. The other statements are false: CoPP is not applied to interfaces, class-default does not require a police action, and the exceed-action determines the fate of excess traffic.

Exam trap

The trap here is assuming CoPP can be applied to interfaces or that class-default must be policed, or misunderstanding the token bucket parameters and exceed-action behavior.

1013
MCQeasy

A network administrator is configuring a site-to-site VPN on a Cisco IOS router using IPsec. The administrator wants to ensure that only traffic from the 192.168.1.0/24 subnet is encrypted and sent over the VPN tunnel. Which configuration component is used to define the interesting traffic?

A.ISAKMP policy
B.transform set
C.access list
D.crypto map
AnswerC

An access list (ACL) is used to define interesting traffic for IPsec VPNs. The ACL specifies which source and destination IP addresses and protocols should be encrypted and sent through the tunnel. In this scenario, an ACL permitting traffic from 192.168.1.0/24 to the remote subnet would be referenced by the crypto map.

Why this answer

An access list is used to define interesting traffic for an IPsec VPN. It specifies the source and destination addresses and protocols that should be encrypted. The crypto map references this ACL to determine which packets to encrypt and send through the tunnel.

The transform set and ISAKMP policy define security parameters but do not select traffic.

Exam trap

The trap here is confusing the role of the crypto map with the ACL; the crypto map references the ACL but does not define the traffic itself.

1014
MCQmedium

A network engineer is configuring a site-to-site IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which crypto ACL configuration achieves this?

A.access-list 100 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255 access-list 100 deny ip any any
B.access-list 100 permit ip any any
C.access-list 100 deny ip any any access-list 100 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
D.access-list 100 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
AnswerD

This ACL permits IP traffic from 10.1.1.0/24 to 10.2.2.0/24. In IPsec, the crypto ACL defines the traffic to be encrypted. By permitting only this specific traffic, all other traffic is implicitly denied and thus not encrypted, matching the requirement.

Why this answer

The correct crypto ACL is a single permit statement for the specific source and destination subnets. Because ACLs have an implicit deny at the end, all other traffic is not matched and therefore not encrypted. This precisely meets the requirement to encrypt only the specified traffic.

Exam trap

The trap here is adding an explicit deny any any or using permit any any, misunderstanding that the implicit deny already handles non-matching traffic and that permit any any would encrypt everything.

1015
MCQhard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect against DoS attacks. The engineer wants to rate-limit ARP packets destined to the route processor to 1000 packets per second, with a burst of 2000 packets. Which CoPP policy configuration accomplishes this?

A.class-map match-all ARP-CLASS match protocol arp policy-map COPP-POLICY class ARP-CLASS police 1000 2000 conform-action transmit exceed-action drop control-plane service-policy input COPP-POLICY
B.class-map match-all ARP-CLASS match protocol arp policy-map COPP-POLICY class ARP-CLASS police 1000 2000 conform-action transmit exceed-action drop interface GigabitEthernet0/0 service-policy input COPP-POLICY
C.class-map match-all ARP-CLASS match access-group 101 access-list 101 permit arp any any policy-map COPP-POLICY class ARP-CLASS police 1000 2000 conform-action transmit exceed-action drop control-plane service-policy input COPP-POLICY
D.class-map match-any ARP-CLASS match protocol arp policy-map COPP-POLICY class ARP-CLASS police 1000 2000 conform-action transmit exceed-action drop control-plane service-policy output COPP-POLICY
AnswerA

This configuration correctly defines a class-map to match ARP protocol, a policy-map to police ARP traffic at 1000 pps with a burst of 2000, and applies it to the control plane using 'service-policy input' under 'control-plane' mode. This is the standard CoPP implementation to protect the route processor.

Why this answer

The correct configuration uses a class-map with 'match protocol arp', a policy-map with 'police 1000 2000', and applies the policy to the control plane with 'service-policy input COPP-POLICY'. This effectively rate-limits ARP packets destined to the route processor. The other options misapply the service policy to an interface, use an invalid access list for ARP, or apply it in the wrong direction.

Exam trap

The trap here is applying the CoPP service policy to an interface instead of the control plane, or using the wrong direction.

1016
Multi-Selecthard

An engineer is troubleshooting an EIGRP network where routes from router R1 are not being installed in the routing table of router R2, although R2 sees them in the EIGRP topology table. Which TWO configuration issues could cause this problem? (Choose TWO.)

Select 2 answers
A.R2 has a static route with administrative distance 150 for the same prefix, and EIGRP's default administrative distance is 90.
B.R2 has an OSPF route with administrative distance 110 for the same prefix, and the EIGRP route is external with administrative distance 170.
C.The 'variance' command is configured on R2 with a value of 2, but the EIGRP route has a feasible successor with a higher metric.
D.R2 has an 'offset-list' configured that increases the metric of the route from R1 by 1000, making it less preferred than a route from another neighbor.
E.The 'maximum-paths' command on R2 is set to 1, and there is already one EIGRP route for the same prefix in the routing table.
AnswersB, D

EIGRP external routes carry administrative distance 170, higher than OSPF's 110. When both protocols offer the same prefix, the router installs the lower-distance OSPF route, so the EIGRP entry stays in the topology table but never enters the routing table.

Why this answer

Option B is correct because EIGRP external routes have a default administrative distance of 170, which is higher (less preferred) than OSPF's 110, so R2 would keep the OSPF route in the routing table even though the EIGRP route appears in the topology table. Option D is correct because an offset-list applied to EIGRP increments the reported/advertised metric for matching routes, and if that inflated metric makes the path from R1 worse than an alternate path from another neighbor, R2 will not install the R1 route as the best route. Option A is not correct because a static route with AD 150 is less preferred than EIGRP's internal AD of 90, so EIGRP would still win and be installed.

Option C is not correct because variance only enables unequal-cost load balancing via feasible successors; a higher-metric feasible successor not being used does not prevent the successor route itself from being installed. Option E is not correct because maximum-paths limits how many equal-cost paths are installed, but it does not prevent the first/best EIGRP route for a prefix from being placed in the routing table.

1017
MCQmedium

Examine the following EEM applet configuration: !--- event manager applet LOGIN_ALERT event syslog occurs 1 period 60 action 1.0 syslog msg "Login event detected" !--- What is the problem with this configuration?

A.The 'event syslog occurs' command is missing the required 'pattern' keyword.
B.The period of 60 seconds is too short and will cause high CPU usage.
C.The 'syslog msg' action cannot be used in the same applet as 'event syslog occurs'.
D.The applet will trigger on every syslog message, which is not the intended behavior.
AnswerA

The 'event syslog occurs' event requires a 'pattern' keyword to specify which syslog message triggers the applet. Without it, the EEM cannot match any log line, so the applet never fires despite the action being validly defined.

Why this answer

The 'event syslog occurs' event detector in EEM requires a 'pattern' keyword to specify the syslog message string to match; without it, the applet is incomplete and will not compile or will not trigger as intended. The correct syntax is 'event syslog pattern <regex>' (optionally with 'occurs' and 'period' for rate-based triggering). The configuration shown is missing that mandatory pattern argument.

Exam trap

300-410 often tests EEM syntax completeness — candidates focus on the 'occurs/period' rate-limiting keywords and overlook that 'pattern' is mandatory, assuming the applet is valid because the rate syntax looks correct.

How to eliminate wrong answers

Option B is wrong because a 60-second period is a valid and common value for rate-based syslog triggers — it does not inherently cause high CPU usage; EEM is event-driven and lightweight. Option C is wrong because 'action syslog msg' is a valid action that can be combined with any event detector, including 'event syslog occurs'; there is no incompatibility. Option D is wrong because the applet will not trigger on every syslog message — without a pattern, it fails to register properly; and even with 'occurs 1 period 60', it triggers only when the specified pattern occurs, not on all messages.

1018
MCQhard

Which statement about the default behavior of 'auto-summary' in EIGRP for DMVPN tunnel interfaces in IOS-XE is correct?

A.Auto-summary is enabled by default and summarizes routes at classful boundaries.
B.Auto-summary is disabled by default, preventing classful summarization.
C.Auto-summary is enabled by default but only for tunnel interfaces.
D.Auto-summary is disabled by default but can be enabled only for DMVPN.
AnswerB

Auto-summary is disabled by default on EIGRP, so classful summarisation at major network boundaries does not occur. This satisfies the DMVPN requirement for carrying discontiguous or overlapping tunnel subnets, since spoke and hub prefixes are advertised precisely rather than collapsed into a classful summary that would blackhole traffic.

Why this answer

In modern IOS-XE versions (15.x and later), auto-summary is disabled by default for EIGRP. This is a change from older IOS versions where it was enabled by default. Disabling auto-summary is essential in DMVPN to prevent incorrect summarization at classful boundaries.

1019
MCQhard

A router has CoPP configured with a class-map that matches BGP traffic (TCP port 179) and polices it to 500 pps. The router has multiple iBGP peers. After applying the policy, some BGP sessions flap, but others remain stable. The flapping peers are those with higher latency. Which is the most likely explanation?

A.CoPP drops BGP packets based on source IP, and high-latency peers have different source IPs.
B.High-latency peers generate more TCP retransmissions, which are more likely to be dropped by the police rate, causing session flaps.
C.BGP uses UDP for keepalives, and CoPP only polices TCP.
D.The CoPP policy is applied to the wrong control plane; it should be applied to the forwarding plane.
AnswerB

CoPP polices matched BGP traffic to 500 pps. Higher-latency peers retransmit TCP segments more often, so their packet rate exceeds the policed threshold and drops mount, causing keepalive or update loss and session flaps, while low-latency peers stay under the limit.

Why this answer

B is correct because high-latency BGP peers experience more TCP retransmissions due to delayed acknowledgments. The CoPP policer drops packets exceeding 500 pps, and these retransmissions increase the packet rate for those sessions, making them more likely to exceed the policer and be dropped. Dropping BGP TCP segments (including keepalives) causes the BGP hold timer to expire, leading to session flaps.

Exam trap

Cisco often tests the misconception that CoPP drops packets based on source IP or that BGP uses UDP for keepalives, leading candidates to overlook the impact of TCP retransmissions from high-latency peers on policer thresholds.

How to eliminate wrong answers

Option A is wrong because CoPP class-maps match on protocol and port (TCP/179), not source IP; it does not differentiate per peer IP unless an ACL is explicitly used in the class-map. Option C is wrong because BGP uses TCP for all its messages, including keepalives and updates, not UDP; CoPP policing TCP/179 correctly targets BGP traffic. Option D is wrong because CoPP is applied to the control plane (via 'service-policy input' under 'control-plane' configuration), not the forwarding plane; the forwarding plane handles data traffic, not BGP control traffic.

1020
MCQhard

A network administrator is troubleshooting an OSPFv3 network. Router R1 is not forming an adjacency with Router R2 over a point-to-point link. The administrator verifies that the interfaces are up, IPv6 addresses are configured, and OSPFv3 is enabled on both interfaces. The output of 'show ipv6 ospf interface' on R1 shows that the interface is in the 'LOOPBACK' state. What is the most likely reason for this state?

A.There is a duplicate router ID on the network, and R1 has detected its own router ID in a hello packet from R2.
B.The interface is configured as a passive interface under the OSPFv3 process.
C.The interface is configured as a loopback interface instead of a point-to-point interface.
D.The OSPFv3 process is not enabled on the interface, causing it to be placed in the LOOPBACK state.
AnswerA

In OSPFv3, if a router receives a hello packet with its own router ID, it transitions the interface to the LOOPBACK state to prevent adjacency formation. This typically happens when two routers are misconfigured with the same router ID. The LOOPBACK state is a clear indicator of a duplicate router ID conflict on the link, and the adjacency will not form until the conflict is resolved.

Why this answer

The LOOPBACK state on an OSPFv3 interface indicates that the router has received a hello packet containing its own router ID. This is a safeguard against duplicate router IDs. When two routers on the same link share the same router ID, they will not form an adjacency, and the interface will remain in LOOPBACK state.

The administrator should check the router ID configuration on both routers and ensure they are unique.

Exam trap

The trap here is confusing the LOOPBACK state with the loopback interface type or with a passive interface, rather than recognizing it as a duplicate router ID detection mechanism.

1021
MCQmedium

A network engineer runs the following command to troubleshoot a BGP Troubleshooting issue: R1# show bgp ipv4 unicast 192.168.1.0/24 BGP routing table entry for 192.168.1.0/24, version 12 Paths: (1 available, best #1, table default) Advertised to update-groups: 1 Refresh Epoch 1 65001, (received & used) 10.1.1.2 from 10.1.1.2 (10.1.1.2) Origin IGP, metric 0, localpref 100, valid, external, best Community: 100:200 What does this output indicate?

A.The prefix 192.168.1.0/24 has a community attribute of 100:200, which may affect routing decisions.
B.The prefix 192.168.1.0/24 is not installed in the routing table.
C.The prefix 192.168.1.0/24 is being filtered due to the community value.
D.The community 100:200 indicates the prefix is from a confederation.
AnswerA

The output lists Community: 100:200 on the single external path, confirming the prefix carries that community attribute. Communities can influence routing decisions through matching route-maps or policies, so the statement correctly identifies the attribute present in this BGP table entry.

Why this answer

The output line 'Community: 100:200' confirms that the prefix 192.168.1.0/24 carries the BGP community attribute 100:200. Communities are transitive optional attributes used to tag routes so that route-maps and policies on this or downstream routers can match them and influence selection, filtering, or propagation. The route is also marked 'valid, external, best', so it is installed and usable — the community is simply metadata that may drive routing decisions.

Exam trap

The trap here is assuming that any displayed attribute implies a filtering or forwarding action; candidates must distinguish a route that is merely tagged with a community from one that is actually being filtered or rejected by a community-based policy.

How to eliminate wrong answers

Option B is wrong because the path is explicitly flagged 'valid' and 'best' and the header shows 'table default', meaning the prefix is installed in the BGP table and eligible for the RIB, not absent. Option C is wrong because nothing in the output shows a filter action — a filtered route would not appear as 'best' or 'received & used'; the community is displayed, not blocking the route. Option D is wrong because confederation membership is signaled by the AS_CONFED_SEQUENCE/AS_CONFED_SET path attributes and confederation identifiers in the AS path, not by a 100:200 community value, which is just an arbitrary tag.

1022
Multi-Selecthard

Which TWO statements about BGP route reflectors are true? (Choose TWO.)

Select 2 answers
A.A route reflector modifies the NEXT_HOP attribute to its own address when reflecting routes.
B.A route reflector adds its own cluster ID to the cluster-list attribute when reflecting a route.
C.A route reflector reflects routes received from a non-client to all other non-clients.
D.A route reflector reflects routes received from a client to all clients and non-clients.
E.A route reflector always sets the originator-id attribute to the router ID of the route reflector.
AnswersB, D

The cluster-list attribute carries the cluster ID of the route reflector, letting other reflectors detect loops between clusters. Adding its own cluster ID on reflection satisfies the loop-prevention requirement, since clients do not re-advertise routes learned from the reflector.

Why this answer

Option B is correct because when a route reflector reflects a route, it prepends its cluster ID to the CLUSTER_LIST attribute (creating it if absent), which allows loop prevention within the cluster. Option D is correct because a route reflector reflects routes learned from a client to all other clients and to all non-clients (with the exception of the route's originator), which is the core behavior that eliminates the need for a full IBGP mesh. Option A is wrong because the route reflector does not rewrite NEXT_HOP to its own address; NEXT_HOP is typically preserved (or changed per normal BGP rules), not set to the reflector.

Option C is wrong because routes received from a non-client are reflected only to clients and the originator, not to other non-clients. Option E is wrong because the ORIGINATOR_ID is set to the router ID of the router that first injected the route into the IBGP mesh, not to the route reflector's own router ID.

1023
MCQmedium

A network engineer runs the following command to troubleshoot a Device Access Control issue: R1# show policy-map control-plane input class class-default Class-map: class-default (match-any) 140225 packets, 12345678 bytes 5 minute offered rate 1000 bps, drop rate 0 bps Match: any police: cir 1000000 bps, bc 31250 bytes conformed 140225 packets, 12345678 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop What does this output indicate?

A.The CoPP policy is policing traffic to 1 Mbps, and all traffic so far has been within the limit and transmitted.
B.The CoPP policy is dropping all traffic because the CIR is too low.
C.The CoPP policy is not matching any traffic because the class-default does not match any packets.
D.The CoPP policy is only policing traffic that exceeds the CIR, but all traffic is being transmitted.
AnswerA

The control-plane policing policy enforces a committed information rate of 1,000,000 bps, matching the stem's Device Access Control scenario. Conformed packets total 140,225 with zero exceeded or violated, confirming every packet stayed within the configured rate and was transmitted rather than dropped.

Why this answer

The output shows that the class-default class in the CoPP policy has a police configuration with a CIR of 1,000,000 bps (1 Mbps). All 140,225 packets have been counted as conforming, with zero exceeded or violated packets, and the conform action is 'transmit'. This means all traffic has been within the policed rate and has been forwarded without drops.

Exam trap

Cisco often tests the interpretation of police counters in CoPP output, where candidates mistakenly think that a police configuration always drops traffic or that class-default does not match traffic, when in fact the counters clearly show conformed packets and zero drops.

How to eliminate wrong answers

Option B is wrong because the output shows zero exceeded and zero violated packets, indicating no traffic is being dropped; the CIR is not too low for the current traffic load. Option C is wrong because the class-default class uses 'match any', and the packet count of 140,225 proves that traffic is being matched and policed. Option D is wrong because the police configuration applies to all traffic in the class, not just traffic that exceeds the CIR; the output shows all traffic is conforming and being transmitted, not that only exceeding traffic is policed.

1024
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip eigrp topology 10.0.0.0 255.255.252.0 IP-EIGRP (AS 100): Topology entry for 10.0.0.0/22 State: Passive, Origin: Internal, Metric [90/2172416], Tag 0 Number of successors: 1 FD is 2172416, Serno: 5 Route is Summary Advertised by R2 (via Serial0/0/0) Reply status: 0 Based on this output, what is true about the route 10.0.0.0/22?

A.The route is a summary route generated by R1.
B.The route is a summary route learned from R2.
C.The route is an external route redistributed into EIGRP.
D.The route is in active state and being queried.
AnswerB

The output explicitly flags "Route is Summary" and "Advertised by R2 (via Serial0/0/0)", confirming R1 learned this 10.0.0.0/22 entry as a summary rather than a specific prefix. The "Origin: Internal" field further shows the summary originated within AS 100, satisfying the stem's requirement to identify the route's nature and source.

Why this answer

The output shows 'Route is Summary' and 'Advertised by R2', indicating that the summary route was learned from R2, not generated locally by R1. The 'Advertised by' field identifies the neighbor that advertised the route.

Exam trap

The trap is misinterpreting 'Route is Summary' as meaning the local router generated it; candidates must check the 'Advertised by' field to see if it was learned from a neighbor.

How to eliminate wrong answers

Option A is wrong because if R1 generated the summary, the output would not show 'Advertised by R2'; it would show 'Route is Summary' but with a different origin indicator (e.g., 'Summary' with no external advertiser, or 'Advertised by' would be absent or 'Connected'). Option C is wrong because the output shows 'Origin: Internal', meaning the route originated within the EIGRP AS, not redistributed (which would show 'Origin: External'). Option D is wrong because the state is 'Passive', not 'Active'; active state indicates the route is being queried.

1025
Multi-Selecthard

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive control-plane traffic. After applying the CoPP policy, the administrator notices that OSPF adjacencies are flapping and that SNMP polling from the management station is failing. The administrator wants to correct the CoPP policy without disabling protection entirely. Which two actions should the administrator take? (Choose two.)

Select 2 answers
A.Increase the rate limit or mark the OSPF and SNMP traffic as conforming in the class maps.
B.Apply the CoPP policy to all interfaces instead of the control plane.
C.Remove the CoPP policy from the control plane and rely on interface ACLs instead.
D.Verify that the class maps correctly match the OSPF and SNMP traffic using the proper access control lists or protocol keywords.
E.Disable CEF switching on the router to reduce control-plane load.
AnswersA, D

If OSPF and SNMP packets are being dropped or delayed, the policer rate for those classes is likely too low. Increasing the rate limit or adjusting the conform action to transmit allows legitimate control-plane traffic to pass while still policing other traffic. This directly addresses the flapping adjacencies and failed SNMP polls without removing CoPP protection.

Why this answer

CoPP failures for specific protocols usually stem from either incorrect classification or insufficient rate limits. Verifying that class maps match OSPF and SNMP traffic ensures they are placed in the correct class, and increasing the rate limit or adjusting the conform action for those classes allows legitimate traffic to pass. Together these correct the symptoms while preserving control-plane protection.

Exam trap

The trap here is assuming that removing CoPP or applying it elsewhere will fix protocol issues, when the real fix is correcting classification and rate limits.

1026
MCQhard

A network engineer is configuring a Cisco IOS router for IPv6 First Hop Security. The requirement is to prevent rogue DHCPv6 servers from assigning addresses to clients on a VLAN. The engineer has already enabled IPv6 snooping on the VLAN. Which additional feature should be configured to meet this requirement?

A.IPv6 ND Inspection
B.IPv6 DHCPv6 Guard
C.IPv6 Destination Guard
D.IPv6 Source Guard
AnswerB

DHCPv6 Guard filters DHCPv6 server messages on untrusted ports, allowing only authorized servers to respond to client requests. Enabling it on the VLAN prevents rogue DHCPv6 servers from assigning addresses. Since IPv6 snooping is already enabled, adding DHCPv6 Guard provides the necessary protection against rogue servers, fulfilling the requirement.

Why this answer

DHCPv6 Guard is specifically designed to block DHCPv6 server messages on untrusted ports, ensuring that only authorized DHCPv6 servers can assign addresses. With IPv6 snooping already enabled, configuring DHCPv6 Guard on the VLAN provides the necessary protection against rogue servers. Other First Hop Security features address different threats and do not fulfill this requirement.

Exam trap

The trap here is confusing DHCPv6 Guard with other IPv6 First Hop Security features like Source Guard or ND Inspection, which address different attack vectors.

1027
MCQhard

An engineer enables unicast RPF (uRPF) in strict mode on an interface. Afterward, some legitimate traffic from a BGP neighbor is dropped. The neighbor has two paths to the router, and traffic may arrive on a different interface than the return path. What is the most likely explanation?

A.Strict uRPF drops packets if the source IP is not reachable via the receiving interface, which fails in asymmetric routing scenarios.
B.The uRPF 'allow-default' option was not configured, so default routes are ignored.
C.The neighbor's BGP updates have a source IP that is not in the routing table.
D.Loose mode should be used instead, but strict mode was configured by mistake.
AnswerA

Strict uRPF checks that the packet's source is reachable through the receiving interface's routing table. With two paths and asymmetric routing, return traffic may use a different interface, so legitimate BGP-sourced packets fail the check and are dropped.

Why this answer

Strict unicast RPF checks that the source IP of each incoming packet is reachable through the same interface on which the packet arrived, using the FIB. In an asymmetric routing scenario where the BGP neighbor has two paths and return traffic leaves via a different interface than the one receiving the packet, the reverse lookup fails and strict uRPF drops the legitimate traffic. This is the classic failure mode of strict mode in multihomed or load-balanced designs.

Exam trap

The trap is conflating strict uRPF with a simple reachability check; candidates forget that strict mode demands interface symmetry, which breaks in asymmetric routing topologies even when the source is perfectly reachable.

How to eliminate wrong answers

Option B is wrong because 'allow-default' only permits the default route to satisfy the reverse lookup; it does not address the core asymmetric-path problem, and the scenario never mentions default routes. Option C is wrong because if the neighbor's source IP were truly absent from the routing table, BGP peering itself would fail — the issue is the interface mismatch, not a missing route. Option D is wrong because it merely restates that strict mode was configured; the question asks for the explanation of why traffic is dropped, and loose mode would be a remediation, not the cause.

1028
MCQmedium

A network engineer is troubleshooting BGP route summarization on a border router that advertises a summary route 172.16.0.0/16 to an ISP neighbor. The engineer notices that the ISP is receiving the summary route but also receiving the more specific routes (172.16.1.0/24, 172.16.2.0/24), causing suboptimal routing. What should the engineer do to ensure only the summary route is advertised?

A.Configure the 'network' command for the summary route and remove the network statements for the specific subnets.
B.Use the 'aggregate-address 172.16.0.0 255.255.0.0 summary-only' command under the BGP process.
C.Apply a route-map to the neighbor to filter out the specific routes using an ACL.
D.Configure the 'summary-address' command under the BGP process.
AnswerB

The `summary-only` keyword suppresses all more-specific component routes from being advertised, leaving only 172.16.0.0/16. Without it, `aggregate-address` creates the summary but still advertises the contributing /24s, which is exactly the leak the ISP is seeing. This satisfies the requirement that only the summary route be sent.

Why this answer

In BGP, to suppress more specific routes when advertising a summary, the engineer must use the 'aggregate-address' command with the 'summary-only' keyword.

1029
MCQmedium

A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue: R1# show ip access-lists 160 Extended IP access list 160 10 permit tcp 10.0.0.0 0.255.255.255 any eq 22 20 permit tcp 172.16.0.0 0.15.255.255 any eq 22 30 permit tcp 192.168.0.0 0.0.255.255 any eq 22 40 deny ip any any What does this output indicate?

A.The ACL permits SSH from private IP ranges and denies all other traffic.
B.The ACL permits all traffic from private IP ranges.
C.The ACL denies SSH from private IP ranges.
D.The ACL is applied inbound on an interface and is blocking all traffic.
AnswerA

The wildcard masks 0.255.255.255, 0.15.255.255 and 0.0.255.255 match the 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16 private ranges respectively, each permitting only TCP port 22. The trailing deny ip any any then drops every remaining packet, satisfying the implicit-deny requirement explicitly.

Why this answer

The ACL permits TCP traffic to destination port 22 (SSH) from the three private IP ranges (10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16) using wildcard masks that match the respective network prefixes. The final explicit deny ip any any statement blocks all other traffic, so only SSH from private IP ranges is permitted.

Exam trap

Cisco often tests the distinction between 'permit all traffic' and 'permit specific traffic (e.g., SSH only)', leading candidates to overlook the port-specific 'eq 22' and incorrectly assume the ACL permits all traffic from the private ranges.

How to eliminate wrong answers

Option B is wrong because the ACL only permits TCP traffic to port 22, not all traffic; it specifically filters by destination port. Option C is wrong because the permit statements allow SSH from private IP ranges, not deny it. Option D is wrong because the output shows only the ACL content, not its application direction or interface; the ACL could be applied inbound or outbound, and the deny ip any any does not inherently indicate it is blocking all traffic—it only blocks traffic not matching earlier permits.

1030
Drag & Dropmedium

Drag and drop the steps to verify and validate the operational state of Control Plane Policing (CoPP) into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Verification starts with confirming the policy is applied globally, then checking per-class statistics for drops, using show commands to examine packet counters, testing reachability to the control plane, and finally reviewing logs for any CoPP-related messages. This ensures the policy is working as intended.

1031
MCQeasy

Which EIGRP packet type is used to confirm receipt of a reliable update?

A.Hello
B.ACK
C.Update
D.Reply
AnswerB

EIGRP uses the ACK packet to acknowledge reliable packets such as Updates, Queries and Replies. It is a hello packet with the acknowledgement field populated and the init flag clear, sent as a unicast to confirm receipt without requiring further acknowledgement.

Why this answer

In EIGRP, reliable updates (Update, Query, Reply) require acknowledgment. The ACK packet is a Hello packet with the Acknowledgment field set, and it is used to confirm receipt of a reliable update. It is not a separate packet type but a function of the Hello packet.

Exam trap

300-410 often tests the confusion between Hello and ACK, since ACK is a Hello with a flag, and candidates may think ACK is a separate packet type or that Hello acknowledges updates.

How to eliminate wrong answers

Option A is wrong because Hello packets are used for neighbor discovery and keepalives, not for acknowledging updates, although an ACK is technically a Hello with the ACK field set. Option C is wrong because Update packets carry routing information and require acknowledgment; they do not confirm receipt. Option D is wrong because Reply packets are sent in response to Queries, not to acknowledge updates.

1032
MCQmedium

A network engineer runs the following command to troubleshoot a Route Summarization issue: R1# show ip ospf database summary 10.0.0.0 OSPF Router with ID (1.1.1.1) (Process ID 1) Summary Net Link States (Area 0) LS age: 100 Options: (No TOS-capability, DC) LS Type: Summary Links(Network) Link State ID: 10.0.0.0 (summary Network Number) Advertising Router: 2.2.2.2 LS Seq Number: 80000001 Checksum: 0x1234 Length: 28 Network Mask: /16 TOS: 0 Metric: 20 What does this output indicate?

A.The summary route 10.0.0.0/16 is being advertised by router 2.2.2.2 as a Type 3 LSA into Area 0.
B.The summary route is a Type 5 external LSA from an ASBR.
C.The summary route is a Type 1 router LSA from router 2.2.2.2.
D.The summary route is not installed because the metric is too high.
AnswerA

The output shows a Summary Net Link State advertisement, which is a Type 3 LSA, with Link State ID 10.0.0.0 and mask /16, originated by Advertising Router 2.2.2.2 and flooded into Area 0. This confirms the summarised inter-area route.

Why this answer

This output shows the OSPF database entry for a summary route 10.0.0.0/16. The LS Type is Summary Links, indicating it is a Type 3 LSA generated by an ABR (advertising router 2.2.2.2). The metric of 20 suggests it is a summary route injected into Area 0.

1033
MCQeasy

An engineer is configuring a GRE tunnel between two Cisco routers. The tunnel source is a physical interface, and the tunnel destination is the remote router's physical interface. After configuration, the tunnel interface is up, but no traffic passes through it. The engineer verifies that the physical interfaces are up and IP connectivity exists between the tunnel endpoints. What is the most likely cause?

A.There is no route to the remote network through the tunnel.
B.The tunnel destination is not reachable.
C.The tunnel keepalive is misconfigured.
D.The tunnel interface is missing an IP address.
AnswerA

Even if the tunnel interface is up, traffic will not pass unless there is a route directing traffic destined for the remote network out the tunnel interface. Without such a route, packets will follow the default route or be dropped. This is a common oversight: the tunnel is operational, but the routing table lacks an entry pointing to the tunnel for the remote subnets. Thus, no traffic passes.

Why this answer

A GRE tunnel can be up, but without a route directing traffic into the tunnel, no data will traverse it. The tunnel interface's up state only indicates that the tunnel source and destination are reachable and the tunnel is operational. Routing is still required to forward traffic.

Therefore, the absence of a route to the remote network via the tunnel is the most likely cause.

Exam trap

The trap here is assuming that a tunnel being up automatically means traffic will flow, overlooking the need for routing to direct traffic into the tunnel.

1034
MCQmedium

Which statement about IPv6 uRPF loose mode is true?

A.It requires the source address to be reachable via the same interface.
B.It only verifies that the source address exists in the FIB.
C.It drops packets with link-local source addresses.
D.It is enabled by default on all interfaces.
AnswerB

Loose mode checks only that the source address is present in the FIB, regardless of the incoming interface. It does not verify the return path points back through the receiving interface, which is the strict-mode behaviour, so reachability alone satisfies the check.

Why this answer

In IPv6 unicast Reverse Path Forwarding (uRPF) loose mode, the router checks the FIB (Forwarding Information Base) to verify that the source address of an incoming packet exists in the routing table. It does not require the source address to be reachable via the same interface, which is the key distinction from strict mode. This allows loose mode to be used in asymmetric routing scenarios where the return path may not match the ingress interface.

Exam trap

The trap here is that candidates often confuse loose mode with strict mode, assuming loose mode still requires interface-level reachability, when in fact it only checks for the source address's existence in the FIB.

How to eliminate wrong answers

Option A is wrong because requiring the source address to be reachable via the same interface is the behavior of uRPF strict mode, not loose mode. Option C is wrong because uRPF loose mode does not specifically drop packets with link-local source addresses; link-local addresses are typically dropped by default in IPv6 due to RFC 4291, not by uRPF. Option D is wrong because uRPF is not enabled by default on any interface; it must be explicitly configured using the 'ipv6 verify unicast source reachable-via any' command for loose mode.

1035
MCQmedium

Which statement correctly describes the behavior of IPv6 Unicast Reverse Path Forwarding (uRPF) in strict mode?

A.It verifies that the source address is in the routing table, but does not check the incoming interface.
B.It checks that the source address is reachable via the same interface and that the route is a connected route.
C.It verifies that the source address is reachable via the same interface and that the route points back to that interface.
D.It only checks that the source address is not a multicast or link-local address.
AnswerC

Strict uRPF checks the source address against the routing table and requires the return path to the source to exit through the same interface the packet arrived on. This reverse-path match on the identical ingress interface is the defining constraint of strict mode, unlike loose mode.

Why this answer

IPv6 uRPF strict mode requires that the source address of an incoming packet is reachable via the exact same interface on which the packet arrived, and that the best matching route in the FIB points back to that interface. This prevents spoofed traffic by ensuring the source is topologically correct from the router's perspective, as defined in RFC 3704.

Exam trap

Cisco often tests the distinction between strict and loose mode, and the trap here is that candidates confuse 'route points back to that interface' with 'route is a connected route,' leading them to incorrectly select Option B.

How to eliminate wrong answers

Option A is wrong because strict mode does check the incoming interface; it requires the source address to be reachable via that specific interface, not just present in the routing table. Option B is wrong because strict mode does not require the route to be a connected route; it only requires the route to point back to the incoming interface, which can be a static or dynamic route. Option D is wrong because uRPF strict mode does not filter based on address type (multicast or link-local); it performs a reachability check on the source address, and multicast/link-local sources are typically dropped by other mechanisms or are not routable.

1036
MCQhard

A network engineer is implementing MPLS Layer 3 VPN on a Cisco IOS-XE router. The engineer needs to configure the PE router to exchange VPNv4 routes with other PE routers. Which address family must be configured under the BGP routing process to enable VPNv4 route exchange?

A.address-family ipv6 vpnv4
B.address-family ipv4 vrf
C.address-family vpnv4
D.address-family ipv4 unicast
AnswerC

The VPNv4 address family is specifically designed for MPLS Layer 3 VPNs. Configuring 'address-family vpnv4' under BGP enables the PE router to exchange VPNv4 routes with other PE routers. These routes include the route distinguisher and route target extended communities, allowing the receiving PE to import the route into the correct VRF.

Why this answer

In MPLS Layer 3 VPN, PE routers exchange VPNv4 routes using the VPNv4 address family under BGP. This address family carries the route distinguisher and extended communities (like route targets) that identify the VPN membership. Configuring 'address-family vpnv4' is essential for the PE routers to exchange customer routes and maintain separate routing tables.

Exam trap

The trap here is confusing the VRF-specific IPv4 address family with the VPNv4 address family; VPNv4 is required for PE-to-PE route exchange.

1037
MCQhard

A network engineer is troubleshooting an MPLS L3VPN where customer routes are not being advertised between PE routers. The engineer verifies that the VRFs are configured correctly and that MPLS forwarding is operational. Which MP-BGP configuration is required to exchange VPNv4 routes between PE routers?

A.neighbor x.x.x.x activate
B.address-family ipv4 unicast
C.address-family vpnv4 unicast
D.neighbor x.x.x.x send-community extended
AnswerC

The address-family vpnv4 unicast configuration under BGP enables the exchange of VPNv4 routes between PE routers. This address family carries the VPN label and route targets, allowing PEs to import and export routes into VRFs. Without activating this address family, BGP will not advertise VPNv4 prefixes, and customer routes will not be propagated across the MPLS core.

Why this answer

To exchange VPNv4 routes between PE routers, MP-BGP must be configured with the address-family vpnv4 unicast. This address family carries the VPN-specific attributes, including route targets and the VPN label. Once activated, BGP can advertise and receive VPNv4 prefixes, allowing PEs to import routes into the correct VRFs.

The other options are either for different address families or are supporting commands that do not by themselves enable VPNv4 route exchange.

Exam trap

The trap here is assuming that standard IPv4 BGP or just neighbor activation is sufficient, without configuring the specific VPNv4 address family.

1038
MCQhard

A network administrator is implementing MPLS Layer 3 VPNs. The customer edge (CE) router is connected to the provider edge (PE) router via a single link and runs OSPF with the PE. The administrator wants to prevent the customer's OSPF routes from being redistributed into the provider's IGP and to keep the customer's OSPF topology separate. Which OSPF process configuration on the PE router achieves this?

A.Configure a separate OSPF process for the customer VRF and use distribute-list to filter routes.
B.Configure OSPF with the capability vrf-lite command under the routing process.
C.Configure the OSPF process within the VRF and do not redistribute it into the provider's OSPF process.
D.Configure OSPF with the domain-id command to match the provider's OSPF domain.
AnswerC

In MPLS L3VPN, the PE router maintains separate OSPF processes for each VRF. By not redistributing the customer's OSPF routes into the provider's global OSPF process, the customer's routes remain isolated. The PE redistributes them into MP-BGP for transport across the MPLS core. This separation prevents the customer's OSPF topology from mixing with the provider's IGP.

Why this answer

To keep the customer's OSPF separate, the PE router runs a VRF-specific OSPF process that is not redistributed into the provider's global OSPF. Customer routes are instead redistributed into MP-BGP for VPNv4 transport. This ensures isolation and prevents the customer's routes from entering the provider's IGP.

Exam trap

The trap here is thinking that filtering with distribute-list or using domain-id prevents redistribution; in reality, the key is to not redistribute the VRF OSPF into the provider's OSPF at all.

1039
MCQhard

An engineer configures OSPFv3 with multiple areas. On the ABR, routes from area 1 are not being advertised into area 0. Which is the most likely explanation?

A.The ABR does not have a direct interface in area 0.
B.The ABR has a higher router ID than the other routers.
C.The OSPFv3 process is configured with the 'no-redistribution' command.
D.The ABR is configured as a stub router.
AnswerA

OSPFv3 requires an interface in the backbone area for an ABR to generate inter-area routes. Without a direct area 0 interface, the router cannot form the required backbone adjacency, so area 1 prefixes are never translated into area 0 LSAs.

Why this answer

For a router to function as an OSPFv3 Area Border Router (ABR), it must have at least one interface in the backbone area (area 0). Without a direct interface in area 0, the router cannot generate Type 3 summary LSAs for area 1 into area 0, so routes from area 1 will not be advertised into the backbone. This is a fundamental OSPF topology requirement, not a configuration option.

Exam trap

The trap here is assuming that any router with interfaces in multiple areas automatically becomes an ABR and advertises routes between them, but OSPF strictly requires a connection to area 0 for inter-area routing.

How to eliminate wrong answers

Option B is wrong because router ID priority only affects DR/BDR election on broadcast networks and has no impact on inter-area route advertisement. Option C is wrong because 'no-redistribution' is not a valid OSPFv3 process command; redistribution is controlled by 'redistribute' commands under router configuration, and even if it existed, it would affect external routes, not inter-area routes. Option D is wrong because stub router configuration only sets the router's link-state advertisement (LSA) metric to maximum to discourage transit traffic; it does not prevent the router from being an ABR or advertising inter-area routes.

1040
Multi-Selectmedium

Which TWO configuration steps are required to implement IPv6 traffic filtering using a named ACL on a Cisco router? (Choose TWO.)

Select 2 answers
A.Create the ACL using the ipv6 access-list command.
B.Apply the ACL to the interface using the ipv6 traffic-filter command.
C.Create the ACL using the access-list command.
D.Apply the ACL to the interface using the ip access-group command.
E.Apply the ACL to the interface using the ipv6 access-group command.
AnswersA, B

Named IPv6 ACLs are created with the ipv6 access-list command, which enters ACL configuration mode and defines the permit or deny entries. Without this, no filter exists to apply, so it is the mandatory first step for implementing IPv6 traffic filtering on the router.

Why this answer

The `ipv6 access-list` command is the standard Cisco IOS command used to create a named IPv6 ACL, which supports filtering based on IPv6 headers, extension headers, and upper-layer protocols. Option B is correct because the `ipv6 traffic-filter` command is the interface-level command that applies the named IPv6 ACL to filter inbound or outbound IPv6 traffic, analogous to `ip access-group` for IPv4.

Exam trap

Cisco often tests the distinction between IPv4 and IPv6 ACL commands, and the trap here is that candidates mistakenly apply the IPv4 `ip access-group` command or the non-existent `ipv6 access-group` command instead of the correct `ipv6 traffic-filter` command.

1041
Multi-Selecthard

Which TWO statements about the use of 'mpls ldp autoconfig' in an MPLS L3VPN environment are true? (Choose TWO.)

Select 2 answers
A.It automatically enables LDP on all interfaces that are part of the OSPF or IS-IS process.
B.It can be overridden on a specific interface by configuring 'no mpls ip' under that interface.
C.It automatically enables LDP on loopback interfaces to facilitate BGP next-hop reachability.
D.It configures LDP on all interfaces, including those not running the IGP, as long as they are IP-enabled.
E.It is required for the PE-CE routing protocol to exchange labels with the CE router.
AnswersA, B

Correct. The command enables LDP on all interfaces running the IGP, reducing manual configuration.

Why this answer

The 'mpls ldp autoconfig' command is used under an OSPF or IS-IS process to automatically enable LDP on all interfaces participating in that IGP. It simplifies configuration but can be overridden per interface. It does not affect BGP sessions, nor does it enable LDP on loopback interfaces by default (loopbacks are not typically used for LDP label exchange).

It does not enable MPLS on core interfaces automatically if they are not part of the IGP process.

1042
MCQmedium

A network engineer runs the following command on Router CE1: CE1# show ip route vrf CUSTOMER_B 10.20.20.0 24 Routing Table: CUSTOMER_B Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2 i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static route Gateway of last resort is not set 10.0.0.0/24 is subnetted, 1 subnets B 10.20.20.0 [20/0] via 10.1.1.2, 00:02:34 Based on this output, what is the problem?

A.The route is not being installed in the routing table.
B.The route is functioning correctly.
C.The VRF is not configured correctly.
D.The next hop is unreachable.
AnswerB

The BGP entry shows a valid path to 10.20.20.0/24 in the CUSTOMER_B VRF, with next hop 10.1.1.2 and no route distinguisher or RD mismatch errors. Administrative distance 20 and metric 0 are normal for eBGP, so no fault exists.

Why this answer

The output shows a BGP route to 10.20.20.0/24 via 10.1.1.2 with an administrative distance of 20 and metric 0, and it has been in the routing table for 2 minutes and 34 seconds. The route is installed and functioning correctly. There is no indication of a problem.

Exam trap

300-410 often tests the ability to interpret show command output. Candidates may overthink and assume there is a problem when the output actually shows a healthy route. The trap is to second-guess the output and look for hidden issues.

How to eliminate wrong answers

Option A is wrong because the route is clearly installed in the routing table, as shown by the 'B' code and the entry. Option C is wrong because the VRF CUSTOMER_B is configured correctly; the command successfully displayed the routing table for that VRF. Option D is wrong because there is no evidence that the next hop is unreachable; the route is present and no error is indicated.

1043
Multi-Selectmedium

A network security engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect against denial-of-service attacks. The engineer wants to classify and police traffic destined to the route processor. Which two types of traffic should be considered for policing? (Choose two.)

Select 2 answers
A.ARP requests and replies
B.Management traffic (e.g., SSH, SNMP)
C.User data traffic transiting the router
D.IPsec encrypted traffic
E.Routing protocol updates (e.g., OSPF, EIGRP)
AnswersB, E

Management traffic such as SSH and SNMP is destined to the router itself and is essential for administration. However, it can also be exploited in DoS attacks. Policing this traffic ensures that a flood of management packets does not overwhelm the route processor, while still permitting legitimate administrative access. Therefore, it is a key consideration for CoPP.

Why this answer

CoPP is used to protect the route processor from excessive traffic that could cause high CPU utilization. The most critical types of traffic to police are those destined to the control plane, such as routing protocol updates and management traffic (SSH, SNMP, etc.). These are essential for network operation but can be exploited in DoS attacks.

Transit traffic, ARP, and IPsec data traffic are not primary control plane traffic and should be handled by other mechanisms.

Exam trap

The trap here is assuming that all traffic passing through the router should be policed by CoPP, but CoPP only applies to traffic destined to the route processor, not transit traffic.

1044
MCQhard

An engineer configures DMVPN Phase 2 with spoke-to-spoke tunnels. Spokes can ping each other's physical interfaces, but cannot establish a direct tunnel. NHRP registration is successful. Which is the most likely explanation?

A.The hub is not configured with 'ip nhrp redirect' and the spokes are not configured with 'ip nhrp shortcut'.
B.The spokes have different NHRP authentication strings, causing NHRP resolution to fail.
C.The tunnel interface on the spokes is configured with 'tunnel mode gre multipoint' but the hub uses 'tunnel mode gre ip'.
D.The spokes are using different IPsec transform sets, causing the IPsec tunnel to fail.
AnswerA

In Phase 2 DMVPN, the hub must send NHRP Redirect messages to inform a spoke that the destination is reachable via another spoke's direct tunnel. The spoke must have 'ip nhrp shortcut' enabled to process these redirects and send a Resolution Request to build a direct tunnel. Without these commands, the spoke continues forwarding traffic through the hub, so spoke-to-spoke tunnels never form even though registration succeeds.

Why this answer

In DMVPN Phase 2, spoke-to-spoke tunnels require NHRP redirect and shortcut mechanisms to dynamically build direct tunnels. The hub must be configured with 'ip nhrp redirect' to send redirect messages to spokes, and spokes must have 'ip nhrp shortcut' to install the NHRP-learned /32 host routes for direct traffic. Without these, spokes will forward traffic through the hub even though they can ping each other's physical interfaces, preventing the establishment of a direct tunnel.

Exam trap

Cisco often tests the misconception that successful NHRP registration alone guarantees spoke-to-spoke tunnels, when in fact the redirect and shortcut commands are mandatory for Phase 2 dynamic tunnel establishment.

How to eliminate wrong answers

Option B is wrong because if NHRP registration is successful, the authentication strings must match; mismatched authentication would cause registration to fail, not just tunnel establishment. Option C is wrong because DMVPN Phase 2 requires the hub to use 'tunnel mode gre multipoint' (mGRE) to support multiple spokes, and spokes can use either 'tunnel mode gre multipoint' or 'tunnel mode gre ip'; the hub using 'tunnel mode gre ip' would prevent spoke registration entirely. Option D is wrong because IPsec transform set mismatches would cause IPsec negotiation to fail, but the question states NHRP registration is successful, and IPsec is not required for basic DMVPN Phase 2 spoke-to-spoke tunnels (though often used for encryption).

1045
MCQhard

An engineer configures CoPP on a router that is a route reflector for iBGP. The policy includes a class-map matching BGP traffic and polices it to 500 pps. After deployment, some iBGP prefixes are missing from the route reflector's table, but the BGP sessions are up. Which is the most likely explanation?

A.CoPP drops BGP keepalive packets, causing the session to reset.
B.CoPP drops BGP update packets from specific clients due to rate limiting, so those prefixes are not learned.
C.The route reflector is configured to ignore certain prefixes.
D.CoPP only affects eBGP, not iBGP.
AnswerB

CoPP polices control-plane traffic to 500 pps, so excess BGP update packets are dropped rather than the session failing. TCP retransmits keep sessions up, but dropped updates mean some prefixes never reach the route reflector's table.

Why this answer

B is correct because CoPP polices BGP traffic to 500 pps, and if BGP update packets from specific iBGP clients exceed this rate, they are dropped. Since BGP keepalives are small and infrequent, the session remains up, but the dropped updates prevent the route reflector from learning certain prefixes, leading to missing routes in the table.

Exam trap

Cisco often tests the misconception that CoPP drops only keepalives or that session state is the sole indicator of BGP health, but the trap here is that BGP sessions can remain up while updates are dropped, leading to missing prefixes without session flaps.

How to eliminate wrong answers

Option A is wrong because CoPP drops BGP keepalive packets only if they exceed the policer rate, but keepalives are small and typically sent at a low interval (e.g., 60 seconds by default), so they rarely hit the 500 pps limit; if they were dropped, the session would reset, but the scenario states sessions are up. Option C is wrong because the route reflector is not configured to ignore prefixes; the question does not mention any prefix filtering, and CoPP is the only change. Option D is wrong because CoPP applies to all control plane traffic, including iBGP, as it matches based on class-maps that can specify BGP regardless of the AS; there is no distinction between eBGP and iBGP in CoPP classification.

1046
MCQmedium

A network engineer runs the following command to verify MPLS LDP route filtering: R1# show mpls ldp bindings 192.168.10.0 255.255.255.0 lib entry: 192.168.10.0/24, rev 6 local binding: label: 21 remote binding: lsr: 2.2.2.2:0, label: 22 remote binding: lsr: 3.3.3.3:0, label: 23 What does this output indicate?

A.The prefix 192.168.10.0/24 has a local label of 21 and remote labels from two neighbors.
B.The prefix 192.168.10.0/24 is being filtered by a route-map.
C.The LDP session with 2.2.2.2 is down.
D.The prefix 192.168.10.0/24 is not in the routing table.
AnswerA

The output confirms LDP has assigned local label 21 to 192.168.10.0/24 and received remote bindings 22 and 23 from neighbours 2.2.2.2 and 3.3.3.3, satisfying the verification requirement that both local and remote label mappings exist for the prefix.

Why this answer

The output shows a local binding with label 21 for 192.168.10.0/24 and two remote bindings from LSRs 2.2.2.2:0 (label 22) and 3.3.3.3:0 (label 23). This confirms the prefix has a local label assigned and remote labels learned from two LDP neighbors, indicating active LDP sessions with both peers.

Exam trap

300-410 often tests the misconception that any prefix in the LIB output implies it is being forwarded; the trap is that LIB entries can exist without being installed in the LFIB if the next-hop or label binding is missing.

How to eliminate wrong answers

Option B is wrong because if the prefix were filtered by a route-map, the local or remote bindings would be absent or the prefix would not appear in the LIB output. Option C is wrong because an LDP session with 2.2.2.2 is clearly up, as evidenced by the remote binding from lsr 2.2.2.2:0. Option D is wrong because LDP only advertises labels for prefixes present in the routing table, so the presence of bindings implies the prefix is in the RIB.

1047
MCQmedium

snmp-server community MyCommunity RO 10\naccess-list 10 permit 192.168.1.0 0.0.0.255 What is the effect of this configuration?

A.SNMP read-only access is allowed only from the 192.168.1.0/24 subnet.
B.SNMP read-write access is allowed from any host.
C.SNMP access is allowed from any host, but only read-only.
D.The community string is encrypted in the configuration.
AnswerA

The access-list 10 permits only 192.168.1.0/24, and the snmp-server community command applies that list to the MyCommunity string with RO. SNMP read-only queries using that community are therefore accepted solely from hosts within that subnet.

Why this answer

The configuration `snmp-server community MyCommunity RO 10` sets the community string to 'MyCommunity' with read-only (RO) privileges and applies access-list 10. The `access-list 10 permit 192.168.1.0 0.0.0.255` restricts SNMP access to only the 192.168.1.0/24 subnet. Therefore, only hosts in that subnet can query the SNMP agent with read-only access.

Exam trap

Cisco often tests the distinction between 'RO' and 'RW' in the community string command, and candidates may overlook that the access list is applied to the community, not globally, leading them to think access is unrestricted or that the community string is encrypted.

How to eliminate wrong answers

Option B is wrong because the community string is configured with 'RO' (read-only), not 'RW' (read-write), and the access list restricts access to the 192.168.1.0/24 subnet, not any host. Option C is wrong because the access list explicitly limits SNMP access to the 192.168.1.0/24 subnet, not any host. Option D is wrong because the community string 'MyCommunity' is displayed in plaintext in the configuration; SNMPv2c community strings are not encrypted by default, and no encryption mechanism (like SNMPv3) is configured here.

1048
MCQmedium

A network engineer runs the following command on Router R2: R2# show ip route 192.168.10.0 Routing entry for 192.168.10.0/24 Known via "ospf 1", distance 110, metric 20 Redistributing via ospf 1 Last update from 10.0.0.1 on GigabitEthernet0/1, 00:00:10 ago Routing Descriptor Blocks: * 10.0.0.1, from 10.0.0.1, 00:00:10 ago, via GigabitEthernet0/1 Route metric is 20, traffic share count is 1 Based on this output, what is the most likely origin of this route?

A.The route is an OSPF intra-area route.
B.The route is an OSPF inter-area route.
C.The route is an OSPF external route, likely redistributed.
D.The route is an OSPF NSSA external route.
AnswerC

The metric of 20 is the default for OSPF external type 2 routes, indicating redistribution.

Why this answer

The metric of 20 is the default metric for OSPF external routes of type E2 (external type 2). The administrative distance of 110 is the default for OSPF routes. This combination indicates the route was redistributed into OSPF from another protocol.

1049
MCQmedium

A network engineer is deploying a GET VPN solution across an MPLS L3VPN service provider network. The design requires that all group members use identical encryption keys and that the key server remain the single point of rekey distribution. The engineer must choose the protocol the key server uses to push rekey messages to group members. Which protocol should be configured for this purpose?

A.IKEv2 with a hub-and-spoke profile on the key server
B.Group Domain of Interpretation (GDOI)
C.IPsec SA negotiation using ISAKMP aggressive mode
D.NHRP with a next-hop server mapping
AnswerB

GDOI is the protocol the key server uses in GET VPN to distribute the Group Security Association, including the rekey messages carrying updated keys and policies. Group members register with the key server over GDOI, receive the shared keys, and then encrypt traffic directly between themselves without per-pair tunnels. This matches the requirement for identical keys pushed from a single key server.

Why this answer

GET VPN uses the Group Domain of Interpretation so that a key server can distribute a shared Group Security Association and push rekey messages to all group members. Members register with the key server, obtain the same keys and policies, and then encrypt traffic directly with one another over the provider network without building point-to-point tunnels. This preserves the any-to-any model and keeps rekeying centralized on the key server.

Exam trap

The trap here is assuming that any key-distribution need is solved by IKE, when GET VPN specifically relies on GDOI for group key and rekey delivery.

1050
MCQmedium

A network engineer runs the following command on Router R1: R1# show ipv6 dhcp guard policy Interface Policy Role State Gi0/0/0 DHCP_GUARD server ACTIVE Gi0/0/1 DHCP_GUARD client ACTIVE Gi0/0/2 (default) client ACTIVE Based on this output, which statement is correct?

A.Interface Gi0/0/0 is trusted to send DHCPv6 replies.
B.Interface Gi0/0/1 is trusted to send DHCPv6 replies.
C.Interface Gi0/0/2 is trusted to send DHCPv6 replies.
D.All interfaces are blocked from sending DHCPv6 replies.
AnswerA

Gi0/0/0 carries the server role, so DHCPv6 Guard permits it to forward server-originated Advertise and Reply messages; client-role interfaces have those dropped. This satisfies the stem's requirement to identify which interface is trusted for DHCPv6 replies.

Why this answer

The output shows that interface Gi0/0/0 has the role 'server' and is ACTIVE under the DHCPv6 guard policy. In DHCPv6 guard, a port with the role 'server' is trusted to send DHCPv6 replies (advertise and reply messages), while ports with the role 'client' are blocked from sending such messages. Therefore, only Gi0/0/0 is allowed to send DHCPv6 replies.

Exam trap

Cisco often tests the misconception that the 'client' role allows sending replies, when in fact only the 'server' role permits DHCPv6 server messages, and the 'client' role strictly blocks them.

How to eliminate wrong answers

Option B is wrong because interface Gi0/0/1 has the role 'client', meaning it is untrusted and blocked from sending DHCPv6 replies. Option C is wrong because interface Gi0/0/2 uses the default policy with role 'client', which also blocks it from sending DHCPv6 replies. Option D is wrong because interface Gi0/0/0 is explicitly trusted (role 'server') and can send DHCPv6 replies, so not all interfaces are blocked.

Page 13

Page 14 of 19

Page 15