Courseiva

Cisco CCNP ENARSI 300-410 (300-410) — Questions 1051–1125

1401 questions total · 19pages · All types, answers revealed

Page 14

Page 15 of 19

Page 16
1051
MCQmedium

A network engineer runs the following command to verify NAT translations: R1# show ip nat translations verbose Pro Inside global Inside local Outside local Outside global --- 10.2.2.2 10.1.1.1 192.168.1.1 192.168.1.1 create 00:00:15, use 00:00:05, flags: extended, timing-out What does the 'extended' flag indicate?

A.The translation is for a single port only.
B.The translation includes port information, typical of PAT.
C.The translation is static and never times out.
D.The translation is for a VPN tunnel.
AnswerB

The 'extended' flag confirms the entry maps IP addresses plus TCP or UDP port numbers, which is the defining behaviour of Port Address Translation. This satisfies the scenario's requirement to identify why a single inside global address can multiplex many inside local hosts through distinct port identifiers.

Why this answer

The 'extended' flag in the output of 'show ip nat translations verbose' indicates that the NAT translation includes Layer 4 port information, which is characteristic of Port Address Translation (PAT) or NAT overload. This allows multiple internal hosts to share a single public IP address by using unique port numbers, as opposed to a simple one-to-one translation without port multiplexing.

Exam trap

The trap here is that candidates often confuse the 'extended' flag with static NAT or assume it means a single-port translation, when in fact it specifically denotes PAT with port multiplexing, as seen in dynamic overload configurations.

How to eliminate wrong answers

Option A is wrong because the 'extended' flag specifically indicates that the translation includes port information for multiple sessions, not a single port only. Option C is wrong because the 'extended' flag does not imply static NAT; static NAT entries typically show the 'static' flag and do not time out, whereas this entry has a 'timing-out' flag indicating dynamic behavior. Option D is wrong because the 'extended' flag is unrelated to VPN tunnels; VPN-related translations would involve different flags or encapsulation contexts, not port-based NAT extensions.

1052
MCQmedium

Consider the following partial configuration on a Cisco IOS-XE router: ``` router eigrp 100 network 10.0.0.0 distance eigrp 90 170 ``` What is the effect of the `distance eigrp 90 170` command?

A.It sets the administrative distance for all EIGRP routes to 90.
B.It sets the administrative distance for EIGRP internal routes to 90 and external routes to 170.
C.It sets the administrative distance for EIGRP routes to 170 for all routes learned from neighbors with an AS of 100.
D.It sets the metric weights for EIGRP to 90 and 170.
AnswerB

The distance eigrp command takes two arguments: the administrative distance applied to internal EIGRP routes and the value applied to external EIGRP routes. Specifying 90 and 170 therefore sets internal routes to 90 and external routes to 170, matching EIGRP's defaults.

Why this answer

This command sets the administrative distance for EIGRP internal routes to 90 and external routes to 170.

1053
MCQmedium

A network engineer runs the following command to troubleshoot a Network Logging and Syslog issue: R1# debug ip ospf adj Output: OSPF: 2 Way Communication to 10.0.0.2 on GigabitEthernet0/0, state 2WAY OSPF: Send hello to 224.0.0.5 on GigabitEthernet0/0 OSPF: Rcv DBD from 10.0.0.2 on GigabitEthernet0/0 seq 0x1E opt 0x52 flag 0x7 len 32 OSPF: NBR negotiation done. We are the SLAVE OSPF: Exchange done with 10.0.0.2 on GigabitEthernet0/0 OSPF: Build router LSA for area 0, router ID 10.0.0.1 What does this output indicate?

A.The router is successfully forming an OSPF adjacency with neighbor 10.0.0.2.
B.The router is experiencing an OSPF authentication failure.
C.The router is stuck in the EXSTART state due to MTU mismatch.
D.The router is flooding LSAs to all neighbors.
AnswerA

The debug shows the neighbour reaching 2WAY, completing database descriptor negotiation as SLAVE, and finishing the Exchange state. Building the router LSA for area 0 confirms the adjacency progressed to Full, so OSPF is successfully forming with 10.0.0.2 on GigabitEthernet0/0.

Why this answer

The debug output shows the full OSPF adjacency progression: 2-Way state, DBD exchange with master/slave negotiation ('We are the SLAVE'), 'Exchange done', and router LSA generation. These messages confirm the neighbor relationship advanced past EXSTART/EXCHANGE into LOADING/FULL, indicating a successful adjacency formation. No authentication errors or MTU-related stalls appear in the output.

Exam trap

The trap here is that candidates see 'SLAVE' and assume something is wrong, or see '2WAY' and think the adjacency failed — but 2-WAY is a normal intermediate state and SLAVE is a normal DBD negotiation role, not an error condition.

How to eliminate wrong answers

Option B is wrong because authentication failures produce messages like 'OSPF: Rcv pkt from ... area 0 : Mismatched Authentication type' or 'Authentication failure', none of which appear here. Option C is wrong because an MTU mismatch causes the routers to remain stuck in EXSTART with repeated DBD packets and no 'Exchange done' message — here the exchange completed successfully. Option D is wrong because LSA flooding is a normal post-adjacency activity, not what the debug ip ospf adj output primarily demonstrates; the output is about adjacency state transitions, not flooding behavior.

1054
MCQeasy

A network engineer runs the following command to troubleshoot an IP SLA issue: R1# show ip sla application IP Service Level Agreements Version: 2.0 IP SLAs Responder: Disabled IP SLAs Low Memory: Disabled IP SLAs ICMP Echo: Enabled IP SLAs ICMP Jitter: Enabled IP SLAs HTTP: Disabled IP SLAs FTP: Disabled IP SLAs UDP Jitter: Enabled IP SLAs TCP Connect: Enabled IP SLAs DNS: Disabled IP SLAs DHCP: Disabled IP SLAs DLSw: Disabled IP SLAs VoIP: Disabled IP SLAs Metro Ethernet: Disabled IP SLAs Video: Disabled IP SLAs LSP: Disabled IP SLAs LSP Group: Disabled IP SLAs VPLS: Disabled IP SLAs MPLS: Disabled IP SLAs MPLS Group: Disabled IP SLAs LDP: Disabled IP SLAs LDP Group: Disabled IP SLAs BFD: Disabled What does this output indicate?

A.The IP SLA responder is enabled, allowing the device to respond to probes.
B.The device supports ICMP Echo, ICMP Jitter, UDP Jitter, and TCP Connect probes.
C.All IP SLA operations are disabled on this device.
D.The device is running low on memory and cannot support IP SLA.
AnswerB

The listing shows which IP SLA probe types the platform supports. ICMP Echo, ICMP Jitter, UDP Jitter and TCP Connect all read Enabled, confirming the device can run those four probe types; the remaining entries are Disabled.

Why this answer

The output of 'show ip sla application' lists the IP SLA features and their status. The lines 'IP SLAs ICMP Echo: Enabled', 'IP SLAs ICMP Jitter: Enabled', 'IP SLAs UDP Jitter: Enabled', and 'IP SLAs TCP Connect: Enabled' indicate that these probe types are supported and enabled on the device. Therefore, the device supports these probe types.

Exam trap

The trap is misinterpreting 'IP SLAs Responder: Disabled' as meaning all IP SLA operations are disabled, but the responder is only for responding to probes, not for initiating them.

How to eliminate wrong answers

Option A is wrong because the output shows 'IP SLAs Responder: Disabled', meaning the responder is not enabled. Option C is wrong because several IP SLA operations are listed as Enabled (e.g., ICMP Echo, UDP Jitter), so not all are disabled. Option D is wrong because 'IP SLAs Low Memory: Disabled' indicates that the low memory condition is not active; it does not mean the device is low on memory.

1055
MCQhard

A network engineer is troubleshooting a DHCPv6 prefix delegation issue on router R1 and runs the following command: R1# debug ipv6 dhcp detail Output: IPv6 DHCP: Received SOLICIT message from FE80::21A:2BFF:FE3C:4D01 on GigabitEthernet0/0 IPv6 DHCP: Using interface pool DHCP_POOL IPv6 DHCP: Sending ADVERTISE message to FE80::21A:2BFF:FE3C:4D01 IPv6 DHCP: Received REQUEST message from FE80::21A:2BFF:FE3C:4D01 IPv6 DHCP: Client requests prefix 2001:DB8:1::/48 IPv6 DHCP: Prefix 2001:DB8:1::/48 not available in pool DHCP_POOL IPv6 DHCP: Sending REPLY message with Status Code NoPrefixAvail What does this output indicate?

A.The DHCPv6 client successfully received the prefix 2001:DB8:1::/48.
B.The DHCPv6 server has a pool configured but the requested prefix is not in that pool or is already allocated.
C.The DHCPv6 client is using a relay agent because the SOLICIT was received on a different interface.
D.The DHCPv6 server is configured with a stateless configuration because it sent an ADVERTISE without a prefix.
AnswerB

The debug line "Prefix 2001:DB8:1::/48 not available in pool DHCP_POOL" and the NoPrefixAvail status confirm the server's pool exists but lacks that prefix, either because it was never configured within DHCP_POOL or is already leased to another requesting router.

Why this answer

The debug output shows the client sent a REQUEST for prefix 2001:DB8:1::/48, but the server responded with a REPLY containing the status code NoPrefixAvail. This indicates the requested prefix is either not defined in the DHCP_POOL or has already been allocated to another client, so the server cannot assign it.

Exam trap

Cisco often tests the misinterpretation of the NoPrefixAvail status code, where candidates assume the prefix was successfully assigned because they see a REPLY message, without reading the status code field.

How to eliminate wrong answers

Option A is wrong because the server sent a REPLY with NoPrefixAvail, not a successful assignment, so the client did not receive the prefix. Option C is wrong because the SOLICIT was received directly on GigabitEthernet0/0 from a link-local address (FE80::), which indicates a directly connected client, not a relay agent; relay agents would show a different source address and interface. Option D is wrong because the server sent an ADVERTISE with a prefix (the client later requests 2001:DB8:1::/48), and stateless DHCPv6 (DHCPv6 stateless) does not involve prefix delegation or the NoPrefixAvail status; this is a stateful prefix delegation exchange.

1056
MCQmedium

A network engineer runs the following command to verify MPLS LDP label bindings: R1# show mpls ldp bindings 192.168.1.0 255.255.255.0 Output: lib entry: 192.168.1.0/24, rev 8 local binding: label: 101 remote binding: lsr: 10.0.0.2:0, label: 201 remote binding: lsr: 10.0.0.3:0, label: 301 What does this output indicate?

A.The prefix 192.168.1.0/24 has a local label of 101 and two remote labels from LDP neighbors
B.The prefix 192.168.1.0/24 is not reachable via any LDP neighbor
C.Label 101 is the only label assigned to this prefix in the network
D.The LDP session with 10.0.0.2 is down
AnswerA

The lib entry shows one local label (101) assigned by this router plus two remote bindings (201, 301) advertised by LDP peers 10.0.0.2 and 10.0.0.3. This confirms label distribution for the prefix across the LDP session, matching the local-plus-remote binding structure.

Why this answer

The output shows a local binding (label 101) that R1 assigns to the prefix 192.168.1.0/24, plus two remote bindings from LDP neighbors 10.0.0.2:0 (label 201) and 10.0.0.3:0 (label 301). This indicates R1 has learned label bindings for that prefix from two LDP peers, confirming LDP sessions are up and the prefix is known via LDP.

Exam trap

300-410 often tests LDP binding output interpretation — candidates confuse local and remote bindings or assume a single label exists network-wide, missing that each LSR assigns its own local label.

How to eliminate wrong answers

Option B is wrong because the presence of remote bindings from two LSRs proves the prefix is reachable via LDP neighbors, not unreachable. Option C is wrong because label 101 is only R1's local binding; the remote bindings show other labels (201, 301) assigned by neighbors, so 101 is not the only label in the network. Option D is wrong because the LDP session with 10.0.0.2 is up — a remote binding from that LSR is present, which would not appear if the session were down.

1057
MCQmedium

A network engineer is implementing policy-based routing (PBR) on a Cisco IOS XE router. The router has two interfaces: GigabitEthernet0/0 (LAN) and GigabitEthernet0/1 (WAN). A route-map named PBR-MAP is applied to GigabitEthernet0/0 with the command `ip policy route-map PBR-MAP`. The route-map contains a match statement for access-list 101, which permits traffic from 10.1.1.0/24 to any destination. The set statement is `set ip next-hop 192.168.2.1`. However, traffic from 10.1.1.0/24 is still being routed according to the routing table instead of being forwarded to 192.168.2.1. Which action should the engineer take to ensure PBR is applied?

A.Enable PBR globally with the command `ip policy route-map PBR-MAP` in global configuration mode.
B.Configure a default route pointing to 192.168.2.1 to force all traffic through that next-hop.
C.Apply the route-map to the outbound direction on GigabitEthernet0/1 instead of inbound on GigabitEthernet0/0.
D.Verify that the access-list 101 is correctly configured and matches the traffic, and that the route-map is applied to the correct interface in the inbound direction.
AnswerD

PBR requires that the route-map be applied to the inbound interface where traffic enters, and the match conditions (e.g., ACL) must correctly identify the traffic. If the ACL is misconfigured or the policy is applied in the wrong direction, PBR will not take effect. Checking these ensures the policy is properly triggered for the specified traffic.

Why this answer

Policy-based routing requires the route-map to be applied to the inbound interface where traffic enters the router. The match conditions, such as an ACL, must correctly identify the traffic to be policy-routed. If the ACL is incorrect or the policy is not applied inbound, PBR will not override the routing table.

Verifying these elements ensures that the policy is triggered and the set action is applied.

Exam trap

The trap here is assuming that PBR can be enabled globally or applied outbound, when it must be applied inbound on the ingress interface.

1058
MCQhard

An engineer configures OSPFv2 on two routers with a direct Ethernet link. The routers are stuck in the EXSTART state. Which is the most likely explanation?

A.The interface MTU on one router is 1500, and on the other is 1400.
B.The OSPF hello and dead intervals are mismatched.
C.One router has OSPF authentication configured, and the other does not.
D.The OSPF network type is point-to-point on one router and broadcast on the other.
AnswerA

Mismatched interface MTUs cause OSPFv2 neighbours to stall in EXSTART because the database description packets exchanged during master/slave negotiation are padded to the interface MTU; the 1400-byte side rejects the larger 1500-byte DBD packets, so the routers never progress to EXCHANGE.

Why this answer

The most likely explanation for OSPFv2 being stuck in EXSTART on a direct Ethernet link is an MTU mismatch between the interfaces. During EXSTART, routers exchange DBD packets that include the MTU; if the MTU values differ, the routers will not proceed to EXCHANGE. A mismatch of 1500 vs. 1400 is a classic cause.

Exam trap

300-410 often tests the specific OSPF state and its causes, and candidates may choose hello interval mismatch or authentication mismatch, which actually cause earlier state failures, not EXSTART.

How to eliminate wrong answers

Option B is wrong because mismatched hello and dead intervals would prevent the adjacency from reaching EXSTART; it would typically be stuck in INIT or DOWN. Option C is wrong because authentication mismatch would also prevent adjacency formation, usually resulting in a DOWN state or authentication failure messages, not EXSTART. Option D is wrong because a network type mismatch (point-to-point vs. broadcast) can cause issues, but on a direct Ethernet link, the default network type is broadcast; if one is changed to point-to-point, it might still form an adjacency but with different behavior.

However, the most common and direct cause of EXSTART stuck is MTU mismatch, especially when the question specifies a direct Ethernet link and gives an MTU mismatch as an option.

1059
Multi-Selectmedium

Which TWO statements about Control Plane Policing (CoPP) are true? (Choose TWO.)

Select 2 answers
A.CoPP uses Modular QoS CLI (MQC) to define traffic classes and actions.
B.CoPP is applied directly to physical interfaces to protect the control plane.
C.CoPP can be used to rate-limit traffic destined to the CPU, such as routing protocol packets or management traffic.
D.CoPP operates at Layer 2 to filter Ethernet frames before they reach the CPU.
E.CoPP replaces the need for access control lists (ACLs) on the device.
AnswersA, C

CoPP is configured through MQC, using class-maps to identify control-plane traffic and policy-maps to apply policing actions, then attached via a service-policy. This matches the stem's requirement for a true statement: the mechanism is class-based policing applied to the control plane.

Why this answer

Control Plane Policing (CoPP) uses the Modular QoS CLI (MQC) to classify traffic into classes (e.g., routing protocol packets, management traffic) and apply actions such as rate-limiting or dropping. MQC provides a flexible, policy-based framework that allows you to define traffic classes with class maps and attach service policies to the control plane, rather than to physical interfaces.

Exam trap

Cisco often tests the misconception that CoPP is applied to physical interfaces (like an ACL) rather than to the control plane itself, and that it operates at Layer 2, when in fact it uses MQC for Layer 3/4 classification and is configured under the 'control-plane' global configuration mode.

1060
MCQhard

What is the default maximum number of paths that BGP can install in the routing table using the 'maximum-paths' command in Cisco IOS?

A.1
B.2
C.4
D.6
AnswerA

Cisco IOS defaults to installing only one best path per prefix, so eBGP and iBGP multipath load sharing stay disabled until you raise it. The stem asks for the default maximum-paths value, and that default is 1, matching this option.

Why this answer

In Cisco IOS, the default maximum number of paths that BGP can install in the routing table when using the maximum-paths command is 1. This means that by default, BGP will only install the best path, and not perform equal-cost multipath (ECMP) unless configured otherwise.

Exam trap

300-410 often tests default values, and candidates may assume that BGP supports multipath by default, but it does not; the default is 1.

How to eliminate wrong answers

Option B is wrong because 2 is not the default; it must be explicitly configured. Option C is wrong because 4 is not the default; it is a common configuration but not default. Option D is wrong because 6 is not the default; it is a possible value but not default.

1061
MCQmedium

A network engineer runs the following command on Router R4: R4# show logging | include %BGP-3-NOTIFICATION *Mar 1 00:01:05.123: %BGP-3-NOTIFICATION: sent to neighbor 10.0.0.2 4/0 (Hold Timer Expired) 0 bytes *Mar 1 00:02:10.456: %BGP-3-NOTIFICATION: received from neighbor 10.0.0.2 4/0 (Hold Timer Expired) 0 bytes *Mar 1 00:03:15.789: %BGP-3-NOTIFICATION: sent to neighbor 10.0.0.2 4/0 (Hold Timer Expired) 0 bytes Based on this output, what is the most likely problem?

A.The BGP neighbor has a mismatched autonomous system number.
B.There is a connectivity issue causing keepalive packets to be lost.
C.The BGP update interval is too short, causing excessive updates.
D.The router is configured with soft-reconfiguration inbound, causing memory issues.
AnswerB

Repeated Hold Timer Expired notifications in both directions show keepalives are not arriving within the negotiated hold time. This indicates a connectivity or packet-loss problem on the path between the peers, causing the BGP session to repeatedly time out.

Why this answer

The log shows BGP NOTIFICATION messages with error code 4/0, which is 'Hold Timer Expired.' This means the router did not receive a KEEPALIVE or UPDATE from neighbor 10.0.0.2 within the negotiated hold time (typically 3× the keepalive interval, default 180 seconds). Since the neighbor is reachable enough to have formed the session initially, the most likely cause is intermittent connectivity or packet loss dropping the keepalives, not a configuration mismatch.

Exam trap

The trap here is confusing BGP NOTIFICATION error codes: candidates see 'NOTIFICATION' and assume it means a configuration mismatch, but code 4/0 specifically indicates a timer expiry, which points to reachability or performance issues rather than misconfiguration.

How to eliminate wrong answers

Option A is wrong because an AS number mismatch produces a NOTIFICATION with error code 2 (Open Message Error) subcode 2 (Bad Peer AS), not 4/0. Option C is wrong because BGP does not have an 'update interval' that causes hold timer expiry; updates are event-driven, and excessive updates would not generate a Hold Timer Expired notification. Option D is wrong because soft-reconfiguration inbound affects memory usage for storing unmodified routes and does not cause hold timer expiry notifications.

1062
MCQmedium

A network engineer is troubleshooting an IPsec site-to-site VPN where the tunnel is not coming up. The engineer runs 'show crypto isakmp sa' and sees no active IKE SAs. The peer IP address is correctly configured. What should the engineer check first?

A.Verify that the crypto map is correctly applied to the outside interface.
B.Check the IP connectivity between the two public IP addresses using ping.
C.Check the IPsec transform set configuration on both routers.
D.Verify the pre-shared key is identical on both routers.
AnswerB

IKE SA negotiation requires UDP 500/4500 reachability between peers, so verifying IP connectivity to the peer's public address confirms the underlying transport exists before investigating ISAKMP policy mismatches, preshared keys or NAT-T issues that would also prevent SAs forming.

Why this answer

The absence of IKE SAs indicates that IKE phase 1 negotiation has not started or failed. The first step is to verify that the routers can reach each other at the IP layer, as a connectivity issue will prevent any IKE exchange.

1063
Multi-Selecthard

Which THREE symptoms indicate a misconfigured RSPAN session on a Cisco switch? (Choose THREE.)

Select 3 answers
A.The RSPAN VLAN is not allowed on the trunk between the source and destination switches.
B.The destination switch does not have the RSPAN VLAN created.
C.The source switch is missing the 'monitor session 1 source' command.
D.The native VLAN mismatch on the trunk link.
E.The routing protocol is not redistributing the RSPAN VLAN.
AnswersA, B, C

Blocking the RSPAN VLAN on the inter-switch trunk severs the remote monitoring path, so mirrored frames never reach the destination switch's destination port. The session appears configured locally yet captures nothing remotely, directly matching the stem's misconfiguration symptoms. RSPAN requires that VLAN to traverse every trunk between source and destination.

Why this answer

Option A is correct because the RSPAN VLAN must be permitted (allowed) on every trunk carrying the monitored traffic between the source and destination switches; if it is pruned or not allowed, the mirrored frames never reach the destination switch and the session fails. Option B is correct because the RSPAN VLAN must be created and active on all participating switches, including the destination switch, so it can forward the mirrored traffic out the destination port; without it, the session cannot deliver captured frames. Option C is correct because a source switch must define the traffic to be mirrored with the 'monitor session 1 source' command; if that command is missing, no traffic is copied into the RSPAN VLAN and the session produces no output.

Option D is not specific to RSPAN and a native VLAN mismatch is a general trunk misconfiguration, not a defined RSPAN symptom. Option E is incorrect because RSPAN operates at Layer 2 and does not depend on routing protocol redistribution of the RSPAN VLAN.

Exam trap

300-410 often tests whether candidates confuse RSPAN prerequisites (VLAN creation, trunk allowance, source command) with unrelated trunk or routing issues — the native VLAN mismatch and routing redistribution options are distractors that sound plausible but are technically irrelevant.

1064
MCQmedium

A network engineer is troubleshooting a flapping OSPFv2 adjacency between two Cisco IOS-XE routers on a broadcast segment. The log shows repeated %OSPF-5-ADJCHG messages with reason 'Dead timer expired'. The engineer confirms that both routers are in Area 0, have identical hello/dead intervals, and are not configured with authentication. Which action most likely resolves the issue?

A.Check for a Layer 2 loop or unidirectional link on the segment, because hellos are being lost in one direction and the dead timer expires.
B.Verify that the OSPF network type matches on both interfaces; a mismatch between broadcast and point-to-point prevents hellos from being processed correctly.
C.Confirm that the OSPF priority is set to 0 on both interfaces, because a priority of 0 prevents the router from sending hellos on broadcast networks.
D.Ensure that both routers have the same OSPF router ID, as duplicate router IDs cause the adjacency to continuously reset.
AnswerA

The 'Dead timer expired' message means hellos are not being received within the dead interval. Since authentication and timers are correct, the most likely cause is that hellos are lost in one direction due to a Layer 2 loop, unidirectional link, or a faulty cable/port. Verifying the Layer 2 path and interface counters will reveal dropped or missing hellos and resolve the flapping.

Why this answer

The repeated 'Dead timer expired' indicates that the router stopped receiving hellos from its neighbor within the dead interval. Since authentication, area, and timers are correct, the issue is at Layer 2—likely a unidirectional link or loop causing hello loss. Checking Layer 2 and interface counters is the correct troubleshooting step.

Other options address issues that would produce different symptoms, such as Init or 2-Way states, not a dead timer expiration.

Exam trap

The trap here is assuming that any adjacency problem is caused by OSPF configuration mismatches, when a dead timer expiration often points to a Layer 2 forwarding issue.

1065
Drag & Drophard

Drag and drop the steps to troubleshoot an MPLS L3VPN adjacency or connectivity failure into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Troubleshooting begins by verifying the PE-CE adjacency with 'show ip bgp vpnv4 vrf <name> summary'. If the adjacency is down, check the VRF interface status and IP connectivity using ping. Then verify that the VRF is correctly configured with 'show vrf'.

Next, confirm that the MPLS LSP to the remote PE is functional using 'show mpls lsp'. Finally, check that the VPNv4 routes are being exchanged between PEs with 'show bgp vpnv4 unicast all'.

1066
MCQhard

A network engineer is troubleshooting an IPv6 connectivity problem across an IPv4 MPLS network using 6PE. The 6PE routers have MP-BGP sessions to exchange IPv6 prefixes, and the tunnel between them is up. However, a customer edge router behind one 6PE router cannot reach an IPv6 prefix behind the other 6PE router. The engineer checks the 6PE router's BGP table and sees the prefix, but the routing table shows the next-hop as unreachable. What is the most likely cause?

A.The MPLS LDP session between the 6PE routers or between the 6PE and P routers is down, so no label exists for the BGP next-hop.
B.The 6PE router is missing the 'ipv6 unicast-routing' command.
C.The tunnel interface is not in the VRF of the customer.
D.The remote 6PE router is not advertising the IPv6 prefix via BGP.
AnswerA

6PE forwards IPv6 traffic by swapping the label bound to the IPv6 BGP next-hop. If LDP is down, no label exists for that next-hop, so the route appears in BGP but cannot be installed, leaving the next-hop unreachable.

Why this answer

In 6PE, the BGP next-hop for an IPv6 prefix is the IPv4 address of the remote 6PE router. The 6PE router must have a label-switched path (LSP) to that IPv4 next-hop, which requires a working MPLS LDP session to distribute a label for that IPv4 address. If the LDP session is down, no label exists for the BGP next-hop, making it unreachable in the routing table even though the BGP table contains the prefix.

Exam trap

Cisco often tests the distinction between BGP table presence and routing table reachability, trapping candidates who assume that seeing the prefix in BGP guarantees it is usable for forwarding.

How to eliminate wrong answers

Option B is wrong because the 'ipv6 unicast-routing' command enables IPv6 routing globally on the router, but the issue is that the next-hop is unreachable in the routing table, not that IPv6 routing is disabled. Option C is wrong because 6PE uses a global IPv6 routing table, not a VRF; the tunnel is an MPLS LSP, not a tunnel interface placed in a VRF. Option D is wrong because the BGP table already shows the prefix, confirming the remote 6PE router is advertising it; the problem is that the next-hop is unreachable, not that the prefix is missing.

1067
MCQeasy

In ERSPAN, what is the default encapsulation type used for transporting mirrored packets across an IP network?

A.IPsec
B.GRE
C.MPLS
D.VXLAN
AnswerB

ERSPAN tunnels mirrored frames inside GRE, which provides the IP delivery header allowing the traffic to traverse a routed network between source and destination. The original Ethernet frame is carried within the GRE payload, with the ERSPAN ID identifying the session.

Why this answer

ERSPAN uses GRE (Generic Routing Encapsulation) to encapsulate the original packets for transport over an IP network.

1068
MCQhard

A network administrator is troubleshooting an OSPFv3 network. Routers R1 and R2 are directly connected on a point-to-point link. R1 is configured with OSPFv3 area 0, and R2 is configured with OSPFv3 area 1. The administrator notices that no OSPFv3 adjacency forms between them. What is the most likely cause?

A.The OSPFv3 area numbers do not match on the link.
B.The OSPFv3 router IDs are not unique.
C.The OSPFv3 process is not enabled on the interfaces.
D.The OSPFv3 network type is mismatched.
AnswerA

OSPFv3, like OSPFv2, requires that routers on the same link be in the same area to form an adjacency. Since R1 is in area 0 and R2 is in area 1, the hello packets will not be accepted, and the adjacency will not form. This is the most likely cause of the problem described.

Why this answer

For OSPFv3 to form an adjacency, both routers on a common link must be configured in the same OSPF area. In this scenario, R1 is in area 0 and R2 is in area 1, which violates this requirement. The hello packets will be ignored, and no adjacency will form.

Other potential issues like duplicate router IDs or interface configuration are not indicated by the symptoms.

Exam trap

The trap here is focusing on advanced OSPFv3 features like router ID uniqueness while overlooking the fundamental requirement that area numbers must match on a link.

1069
MCQhard

A network administrator is troubleshooting an EIGRP named mode configuration on a Cisco IOS XE router. The router is not forming an adjacency with a neighbor. The administrator verifies that the AS number is 100, the K-values are default, and authentication is not configured. Which command should be used to verify the EIGRP hello and hold timers on the interface?

A.show ip eigrp neighbors detail
B.show ip eigrp interfaces detail
C.show ip protocols
D.show ip eigrp topology
AnswerB

The show ip eigrp interfaces detail command displays detailed EIGRP information for each interface, including the hello interval and hold time. This is the correct command to verify the timers, as mismatched timers are a common cause of adjacency failures. It also shows other parameters like split horizon and authentication, making it a comprehensive troubleshooting tool for EIGRP interface settings.

Why this answer

To verify EIGRP hello and hold timers on an interface, the show ip eigrp interfaces detail command is used. It provides per-interface EIGRP parameters, including hello interval and hold time. Other commands like show ip eigrp neighbors detail focus on neighbor state, while show ip protocols gives a global view.

The topology table shows routes, not timers. Therefore, the interfaces detail command is the correct choice for troubleshooting timer mismatches.

Exam trap

The trap here is confusing neighbor status commands with interface parameter commands; the detail keyword on the interfaces command is what reveals timers.

1070
MCQhard

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP-IN Class-map: CoPP-SNMP (match-all) 0 packets, 0 bytes 5 minute offered rate 0000 bps, drop rate 0000 bps Match: access-group 130 police: cir 32000 bps, bc 6000 bytes, be 6000 bytes conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop R1# show access-lists 130 Extended IP access list 130 10 permit udp any any eq snmp 20 permit udp any any eq snmptrap Based on this output, what is the most likely reason that no packets are matching the CoPP-SNMP class?

A.The access-list does not include the correct SNMP port numbers.
B.The SNMP traffic is being sent from the router itself, which is not processed through the input control plane policy.
C.The police rate is too low and is dropping all packets before counting.
D.The class-map is using 'match-all' instead of 'match-any'.
AnswerB

CoPP applies as an input service policy on the control plane, inspecting transit traffic destined to the route processor. SNMP generated by the router itself originates locally and bypasses that input path, so access list 130 never matches, explaining the zero counters.

Why this answer

The CoPP-SNMP class matches traffic via access-list 130, which permits SNMP and SNMP trap packets. However, the show policy-map control-plane output shows zero matched packets because the input control plane policy only processes traffic destined to the router (i.e., packets received on an interface and punted to the control plane). SNMP traffic generated by the router itself (e.g., traps or responses) is locally sourced and does not traverse the input control plane path; it is handled by the output control plane or bypasses CoPP entirely.

Thus, the policy never sees these self-generated packets.

Exam trap

Cisco often tests the distinction between traffic *destined* to the router (subject to input CoPP) and traffic *originated* by the router (subject to output CoPP or no CoPP), leading candidates to overlook the fact that self-generated packets do not match input policies.

How to eliminate wrong answers

Option A is wrong because access-list 130 correctly permits UDP ports 161 (SNMP) and 162 (SNMP trap), which are the standard SNMP port numbers. Option C is wrong because the police rate (32 kbps) is low but would still count packets as 'conformed' or 'exceeded' before dropping; the output shows zero packets in all counters (conformed, exceeded, violated), indicating no match occurred, not that policing dropped them. Option D is wrong because 'match-all' is appropriate here since the class-map has only one match condition (access-group 130); using 'match-all' versus 'match-any' makes no difference with a single match statement.

1071
MCQhard

A network engineer runs the following command to troubleshoot a VRF-Lite OSPF adjacency issue: R1# debug ip ospf adj vrf CUSTOMER_C Output: OSPF: 2 Way state received from 10.1.1.2 on interface GigabitEthernet0/1, address 10.1.1.2 OSPF: Neighbor 10.1.1.2 is eligible for DR election on interface GigabitEthernet0/1 OSPF: DR election: 10.1.1.1 (pri 1) is DR, 10.1.1.2 (pri 1) is BDR OSPF: Build router LSA for area 0, router ID 1.1.1.1, seq 0x80000001 OSPF: Neighbor 10.1.1.2 is FULL, state changed from LOADING to FULL What does this output indicate?

A.The OSPF adjacency failed because the neighbor remained in LOADING state.
B.The OSPF adjacency formed successfully, with 10.1.1.1 as DR and 10.1.1.2 as BDR.
C.The OSPF adjacency formed but the router ID is missing, causing instability.
D.The OSPF adjacency is stuck in 2-Way state due to mismatched area IDs.
AnswerB

The debug output shows the neighbour reaching FULL state, confirming the adjacency formed successfully within VRF CUSTOMER_C. DR election completed with 10.1.1.1 as DR and 10.1.1.2 as BDR, satisfying the broadcast network requirement. The LOADING to FULL transition indicates database synchronisation finished, so no VRF-Lite OSPF fault remains.

Why this answer

The debug output shows the neighbor state changing from LOADING to FULL, which means the OSPF adjacency successfully completed database exchange and reached the FULL state. It also shows that 10.1.1.1 was elected DR and 10.1.1.2 was elected BDR, confirming a stable adjacency on the segment. The earlier 2-Way state is a normal part of the DR/BDR election process before the adjacency progresses to FULL.

Exam trap

The trap is that candidates see '2 Way state received' and assume the adjacency is stuck in 2-Way, but the later line showing FULL indicates success; the 2-Way message is just part of the normal election sequence.

How to eliminate wrong answers

Option A is wrong because the output explicitly shows the state changed from LOADING to FULL, indicating the adjacency did not remain in LOADING. Option C is wrong because the router ID 1.1.1.1 is present in the output and there is no indication of instability. Option D is wrong because the adjacency is not stuck in 2-Way; it progressed to FULL, and there is no evidence of mismatched area IDs in the output.

1072
MCQeasy

In Policy-Based Routing (PBR), what is the default action for packets that do not match any route-map sequence?

A.They are dropped.
B.They are forwarded using the normal routing table.
C.They are forwarded using the default route.
D.They are sent to the next-hop specified in the last sequence.
AnswerB

PBR route-maps are evaluated top-down; if no sequence matches the packet, no set clause applies, so the packet falls through to the router's normal destination-based forwarding decision. The routing table, not a default drop or null route, therefore determines the next hop for unmatched traffic.

Why this answer

Route-maps have an implicit deny at the end. For PBR, if a packet does not match any permit sequence, it is not policy-routed and is forwarded using the normal routing table.

1073
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate management access using TACACS+. The TACACS+ server is reachable at 10.1.1.100. The engineer wants to ensure that if the TACACS+ server becomes unavailable, the router will fall back to using the local username database for authentication. Which command sequence correctly configures this fallback?

A.aaa authentication login default group tacacs+ local
B.aaa authentication login default group tacacs+ none
C.aaa authentication login default local group tacacs+
D.aaa authentication login default group tacacs+ enable
AnswerA

This command configures the default method list to first attempt TACACS+ authentication and then fall back to the local database if the server is unreachable. It meets the requirement by providing a backup authentication method, ensuring management access remains available even when the TACACS+ server fails.

Why this answer

The correct configuration uses the default method list with TACACS+ first and local second. This ensures that if the TACACS+ server is unreachable, the router will use the local username database for authentication, maintaining management access. The other options either use the wrong fallback method, reverse the order, or disable authentication entirely.

Exam trap

The trap here is assuming that any fallback method will work, but using 'enable' or 'none' changes the authentication behavior and does not provide local database fallback.

1074
MCQeasy

A network engineer is configuring a Cisco IOS XE router to act as a DHCP server for a subnet. The router must assign IP addresses from the 192.168.100.0/24 pool, but the first 10 addresses and the last address in the range must be excluded from dynamic assignment. Which command accomplishes this requirement?

A.ip dhcp excluded-address 192.168.100.1 192.168.100.10 192.168.100.254
B.ip dhcp excluded-address 192.168.100.1 192.168.100.10 and ip dhcp excluded-address 192.168.100.254
C.Two separate commands: ip dhcp excluded-address 192.168.100.1 192.168.100.10 and ip dhcp excluded-address 192.168.100.254
D.ip dhcp excluded-address 192.168.100.1 192.168.100.10
AnswerC

The ip dhcp excluded-address command can be entered multiple times to exclude different ranges or individual addresses. To exclude the first 10 addresses and the last address, you need two commands: one for the range 192.168.100.1 to 192.168.100.10, and another for the single address 192.168.100.254. This correctly meets all requirements.

Why this answer

The Cisco IOS DHCP server uses the ip dhcp excluded-address command to specify addresses that should not be assigned dynamically. You can configure multiple excluded addresses or ranges by entering the command multiple times. In this scenario, the first 10 addresses and the last address must be excluded, so two separate commands are needed: one for the range and one for the individual address.

Combining them into a single command with multiple arguments or using 'and' is not valid syntax.

Exam trap

The trap here is thinking that a single ip dhcp excluded-address command can exclude multiple non-contiguous ranges or that you can use 'and' to combine them, when in fact each exclusion requires its own command.

1075
MCQhard

A router is configured with PBR using a route-map that sets the next-hop to 10.0.0.2 for traffic from subnet 192.168.1.0/24. The route-map is applied inbound on interface GigabitEthernet0/0. The engineer also configures 'ip policy route-map' on the same interface. The engineer notices that PBR is working for TCP traffic but not for UDP traffic from the same subnet. What is the most likely cause?

A.The ACL in the route-map is configured to match only TCP traffic, so UDP packets are not policy-routed.
B.UDP traffic is not supported by PBR.
C.The next-hop 10.0.0.2 does not have a route for UDP traffic.
D.The route-map is missing a 'set ip next-hop' command for UDP.
AnswerA

The route-map's ACL defines which packets are policy-routed; if it matches only TCP, UDP packets bypass PBR and follow the routing table. The stem's symptom—TCP routed, UDP not—points directly to this match condition, not to interface or next-hop faults.

Why this answer

PBR itself is protocol-agnostic — it operates on IP packets regardless of whether they carry TCP, UDP, ICMP, or other protocols. If TCP traffic is policy-routed but UDP traffic from the same subnet is not, the most likely cause is that the ACL referenced by the route-map matches only TCP (e.g., 'permit tcp any any' or a specific port), so UDP packets fail the match and fall through to normal routing. The fix is to broaden the ACL to match all IP traffic or explicitly include UDP.

Exam trap

The trap is assuming PBR has protocol-specific limitations or requires separate configuration for UDP, when in reality the ACL match criteria are the sole reason UDP traffic is not being policy-routed.

How to eliminate wrong answers

Option B is wrong because PBR supports all IP protocols — there is no inherent limitation that excludes UDP, and Cisco documentation confirms PBR matches on IP headers regardless of transport protocol. Option C is wrong because the next-hop router's routing table is irrelevant to whether PBR matches the packet; PBR is a local forwarding decision made before the packet leaves the router, and the next-hop's routes do not affect the match. Option D is wrong because 'set ip next-hop' is a single statement that applies to all matched traffic — there is no per-protocol variant, so a missing UDP-specific set command is not a real configuration construct.

1076
MCQhard

A network uses PBR to route traffic from a specific VLAN (10.10.10.0/24) through a firewall (next-hop 192.168.1.1). After a firewall policy change, traffic from this VLAN is being dropped. Router R1 shows: 'show ip policy' shows PBR applied, 'debug ip policy' shows traffic being forwarded to 192.168.1.1, but 'debug ip packet' on R1 shows packets being sent to 192.168.1.1 and no response. Router R2 (firewall) shows: 'show ip route 10.10.10.0' returns a route via 192.168.2.1, but 'show access-lists' on the firewall shows an ACL that denies traffic from 10.10.10.0/24. What is the root cause?

A.The firewall has an ACL that denies traffic from 10.10.10.0/24. Update the ACL to allow this traffic.
B.The next-hop 192.168.1.1 is not reachable from R1 due to a routing issue.
C.The route-map on R1 is missing a 'set ip next-hop verify-availability' command, causing it to forward traffic to an unreachable next-hop.
D.The VLAN interface on R1 has an ACL that is blocking traffic from 10.10.10.0/24.
AnswerA

The firewall's ACL explicitly denies traffic sourced from 10.10.10.0/24, so packets arriving via PBR are dropped before any routing decision. Debug output confirms R1 forwards correctly to 192.168.1.1 with no reply, isolating the cause to that deny entry.

Why this answer

The firewall's ACL explicitly denies traffic from 10.10.10.0/24, which is why packets forwarded by PBR to 192.168.1.1 receive no response. The debug output on R1 confirms PBR is working and packets are being sent to the firewall, so the drop is happening at the firewall due to the ACL. Updating the ACL to permit this traffic resolves the issue.

Exam trap

300-410 often tests whether candidates stop troubleshooting at the PBR configuration when the real issue is a downstream ACL — always verify the entire path, especially when debug shows packets leaving the router successfully.

How to eliminate wrong answers

Option B is wrong because R1's debug ip policy shows traffic being forwarded to 192.168.1.1, and debug ip packet shows packets being sent, indicating the next-hop is reachable; if it were unreachable, PBR would fall back to the routing table or drop with an encapsulation failure. Option C is wrong because 'set ip next-hop verify-availability' is used to track next-hop reachability with object tracking; since the next-hop is reachable and packets are being sent, this is not the cause. Option D is wrong because the debug output shows packets leaving R1 toward 192.168.1.1, so any ACL on the VLAN interface is not blocking outbound traffic; the drop is on the firewall side.

1077
MCQhard

A network uses PBR to load-balance traffic from two subnets (10.1.1.0/24 and 10.2.2.0/24) across two ISPs (next-hops 100.64.1.1 and 100.64.2.2). After a routing change, traffic from 10.1.1.0/24 is being sent to both ISPs intermittently. Router R1 shows: 'show route-map' shows the route-map with two match clauses, 'debug ip policy' shows traffic from 10.1.1.0/24 being sent to both next-hops. What is the root cause?

A.The route-map has a match clause that matches both subnets, causing traffic to be load-balanced across both next-hops. Use specific ACLs or separate route-map entries.
B.The 'set ip next-hop' command is missing the 'load-balance' keyword, causing PBR to use both next-hops by default.
C.The routing table on R1 has equal-cost routes to both ISPs, causing PBR to be overridden by the routing table.
D.The interface where PBR is applied is in a VRF, causing the route-map to be applied incorrectly.
AnswerA

If the ACL in the route-map matches both subnets (e.g., using a wildcard mask that is too broad), traffic from 10.1.1.0/24 can match multiple clauses, leading to load-balancing. Using specific ACLs or separate route-map entries with sequence numbers ensures each subnet is matched by only one clause.

Why this answer

PBR route-maps can have multiple match clauses, but if the route-map does not have a 'sequence' number or if the match clauses are not mutually exclusive, traffic can match multiple clauses. In this case, the route-map likely has a match clause that matches both subnets (e.g., using a less specific ACL), causing traffic from 10.1.1.0/24 to match both clauses and be load-balanced. The solution is to ensure the ACLs in the route-map are mutually exclusive or use separate route-map entries with sequence numbers.

1078
MCQhard

An engineer configures an EEM applet to react to BGP prefix changes using the event syslog pattern 'BGP-5-ADJCHANGE'. The applet sends a custom SNMP trap. The BGP session between two routers is established, but when a route is withdrawn due to next-hop-self requirement for iBGP, the EEM applet does not trigger. Which is the most likely explanation?

A.The BGP-5-ADJCHANGE syslog is only generated for session state changes, not for individual route updates.
B.The EEM applet must be configured with 'event bgp' to monitor BGP prefix changes.
C.The next-hop-self requirement causes a BGP notification that generates a different syslog pattern.
D.The EEM applet requires the 'event manager directory' to be set for SNMP traps.
AnswerA

The BGP-5-ADJCHANGE syslog fires only on neighbour session state transitions (Idle, Active, Established), not on prefix withdrawal or next-hop-self route changes. Since the session stayed established, no syslog event was generated, so the EEM applet's pattern match never triggered.

Why this answer

The BGP-5-ADJCHANGE syslog message is generated only when the BGP session state changes (e.g., from Established to Idle or vice versa). It is not generated for individual prefix updates or withdrawals. When a route is withdrawn due to next-hop-self requirement, the BGP session remains established, so no ADJCHANGE event occurs.

The EEM applet will not trigger because the syslog pattern does not match any generated message.

1079
MCQmedium

A network engineer runs the following command to troubleshoot an MPLS L3VPN issue: R1# show bgp neighbors 10.0.0.2 received-routes Output: BGP table version is 10, local router ID is 10.0.0.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.3.3.0/24 10.0.0.2 0 100 0 65000 i *> 10.4.4.0/24 10.0.0.2 0 100 0 65000 i Total number of prefixes 2 What does this output indicate?

A.R1 is receiving two routes from BGP neighbor 10.0.0.2
B.R1 is advertising two routes to BGP neighbor 10.0.0.2
C.R1 has no BGP routes
D.R1 is using OSPF to learn these prefixes
AnswerA

The `received-routes` keyword displays prefixes accepted from the neighbour before inbound policy filtering, so the two entries confirm R1 is receiving both 10.3.3.0/24 and 10.4.4.0/24 from 10.0.0.2. This satisfies the stem's requirement to verify inbound advertisements on the MPLS L3VPN session.

Why this answer

The show bgp neighbors received-routes command displays routes received from the specified neighbor. Here, R1 has received two prefixes (10.3.3.0/24 and 10.4.4.0/24) from neighbor 10.0.0.2, with next hop 10.0.0.2 and AS path 65000. These are valid and best.

1080
MCQmedium

A network engineer runs the following command on router R3: R3# show monitor session 5 Session 5 --------- Type : ERSPAN Destination Session Status : Admin Enabled Source IP : 10.0.0.2 Destination Ports : Gi0/1 Encapsulation : Native Ingress : Disabled ERSPAN ID : 100 Based on this output, which statement is correct?

A.The ERSPAN destination session receives traffic from source IP 10.0.0.2 and sends it to Gi0/1.
B.The ERSPAN destination session sends traffic to source IP 10.0.0.2.
C.The session is an RSPAN destination session because it uses a destination port.
D.The session is misconfigured because the destination port has ingress disabled.
AnswerA

ERSPAN destination sessions decapsulate GRE-encapsulated traffic arriving from the configured source IP and forward the original frames out the destination port. Here, packets from 10.0.0.2 are stripped of their ERSPAN header and transmitted via Gi0/1, satisfying the session's role as the receiving endpoint.

Why this answer

The output shows 'Type: ERSPAN Destination Session' with 'Source IP: 10.0.0.2' and 'Destination Ports: Gi0/1'. In an ERSPAN destination session, the switch receives GRE-encapsulated mirrored traffic from the source IP (the ERSPAN source session's origin) and forwards the decapsulated traffic out the destination port Gi0/1. Therefore, the session receives traffic from 10.0.0.2 and sends it to Gi0/1.

Exam trap

300-410 often tests directionality in ERSPAN output — candidates misread 'Source IP' as the destination of mirrored traffic rather than the origin, and they misinterpret 'Ingress: Disabled' as an error when it is standard practice.

How to eliminate wrong answers

Option B is wrong because it reverses the direction — the destination session receives from the source IP, it does not send traffic to it; the source IP identifies where the ERSPAN traffic originates. Option C is wrong because the output explicitly states 'Type: ERSPAN Destination Session', not RSPAN; ERSPAN uses GRE encapsulation over IP, while RSPAN uses a Layer 2 VLAN. Option D is wrong because 'Ingress: Disabled' on the destination port is normal and expected — destination ports in SPAN/ERSPAN sessions should not accept ingress traffic to avoid loops and duplicate frames; it is not a misconfiguration.

1081
MCQhard

A network engineer runs the following command on Router R1: R1# show bfd neighbors detail IPv4 Sessions NeighborAddr LD/RD Int State Holdown(mult) Intf 10.1.1.2 1/3 Gi0/0 Down 0(0) Gi0/0 Session state is DOWN OurAddr: 10.1.1.1 Handle: 1 Local Diag: 1, Demand mode: 0, Poll bit: 0 MinTxInt: 1000000, MinRxInt: 1000000, Multiplier: 3 Received MinRxInt: 1000000, Received Multiplier: 3 Holddown (hits): 0(0) Rx Count: 0, Tx Count: 50 Based on this output, what is the most likely cause of the BFD session being down?

A.The neighbor router is not configured for BFD.
B.The BFD session is down because the local router is not sending BFD packets.
C.The BFD session is down because the neighbor is not responding to BFD packets, likely due to a network connectivity issue or neighbor misconfiguration.
D.The BFD session is down because the multiplier is set too low.
AnswerC

The session shows Tx Count 50 with Rx Count 0, meaning R1 transmits control packets but receives none from 10.1.1.2. Local Diag 1 indicates no diagnostic fault locally, so the failure lies beyond R1 — a connectivity break or misconfigured neighbour prevents replies, satisfying the stem's evidence of one-way BFD traffic.

Why this answer

The Local Diag field shows 1, which indicates 'Control Detection Time Expired'. This means the local router did not receive BFD control packets from the neighbor within the expected time. The Rx Count is 0, confirming no packets were received.

Tx Count is 50, so the local router is sending packets but not receiving any.

1082
MCQmedium

A network engineer runs the following command on switch SW1: SW1# show monitor session 1 Session 1 --------- Type : Local Session Source Ports : Both : Gi0/1, Gi0/2 Destination Ports : Gi0/3 Encapsulation : Native Ingress : Disabled Based on this output, which statement is correct?

A.The SPAN session is monitoring traffic on Gi0/1 and Gi0/2 and sending it to Gi0/3.
B.The SPAN session is monitoring traffic on Gi0/3 and sending it to Gi0/1 and Gi0/2.
C.The SPAN session is using RSPAN because the destination port has ingress disabled.
D.The SPAN session is not active because the destination port is not in forwarding state.
AnswerA

The output lists source ports Gi0/1 and Gi0/2 under "Both", meaning ingress and egress traffic on those ports is copied, and Gi0/3 as the destination port with native encapsulation. Monitored frames are therefore forwarded out Gi0/3.

Why this answer

In the SPAN output, the 'Source Ports' section lists Gi0/1 and Gi0/2 with 'Both' direction, meaning traffic in both ingress and egress directions on those ports is copied. The 'Destination Ports' section lists Gi0/3, which is where the mirrored traffic is sent for analysis. Therefore, the session monitors Gi0/1 and Gi0/2 and forwards copies to Gi0/3.

Exam trap

The trap is misreading the direction of the SPAN relationship — candidates often swap source and destination ports, or misinterpret 'Ingress : Disabled' as a fault rather than a normal destination-port setting.

How to eliminate wrong answers

Option B is wrong because it reverses the roles: Gi0/3 is the destination (monitor) port, not a source, and Gi0/1/Gi0/2 are sources, not destinations. Option C is wrong because the output explicitly states 'Type : Local Session' — RSPAN would show 'Remote Source Session' or 'Remote Destination Session' and would reference a VLAN rather than a local destination port. Option D is wrong because the output shows an active session with configured source and destination ports; 'Ingress : Disabled' refers to the destination port not accepting ingress traffic, which is normal for SPAN and does not deactivate the session.

1083
MCQeasy

Which of the following is true regarding the placement of an IPv4 ACL to filter traffic between two internal subnets?

A.Standard ACLs should be placed closest to the source.
B.Extended ACLs should be placed closest to the destination.
C.Standard ACLs should be placed closest to the destination.
D.Placement does not affect ACL functionality.
AnswerC

Standard ACLs filter only on source address, so placing them closest to the destination prevents them from blocking traffic to other destinations that share the same source. This satisfies the requirement to filter traffic between two internal subnets without unintended collateral filtering.

Why this answer

Standard ACLs filter based solely on the source IP address and lack the granularity to distinguish between different destination subnets. Placing a standard ACL closest to the destination ensures that traffic is filtered only after it has reached the target subnet, preventing the ACL from inadvertently blocking traffic to other destinations that share the same source. This placement aligns with the Cisco best practice of placing standard ACLs near the destination to minimize unintended filtering.

Exam trap

Cisco often tests the misconception that standard ACLs should be placed closest to the source (like extended ACLs), but the correct practice is to place standard ACLs closest to the destination due to their lack of destination-based filtering.

How to eliminate wrong answers

Option A is wrong because standard ACLs should be placed closest to the destination, not the source; placing them near the source can block all traffic from a source regardless of the destination, which is overly restrictive and can disrupt traffic to other subnets. Option B is wrong because extended ACLs should be placed closest to the source, not the destination; placing them near the destination wastes bandwidth by allowing unwanted traffic to traverse the network before being filtered. Option D is wrong because placement directly affects ACL functionality and efficiency; improper placement can cause unintended filtering or unnecessary network congestion.

1084
MCQmedium

Given the following partial configuration on router R1: router eigrp 100 network 10.0.0.0 0.255.255.255 network 192.168.1.0 0.0.0.255 ! interface GigabitEthernet0/0 ip address 10.1.1.1 255.255.255.0 ! interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 ! interface GigabitEthernet0/2 ip address 172.16.1.1 255.255.255.0 What is the effect of this configuration?

A.EIGRP will form adjacencies and advertise all three interfaces because the network statements use classful boundaries.
B.EIGRP will only advertise the 10.1.1.0/24 and 192.168.1.0/24 networks; the 172.16.1.0/24 network will not be advertised and no EIGRP adjacency will be formed on that interface.
C.EIGRP will advertise all three networks because the network 10.0.0.0 command includes all interfaces with an IP starting with 1, 172, or 192.
D.EIGRP will not form any adjacencies because the network statements must use exact subnet masks instead of wildcard masks.
AnswerB

EIGRP only enables the protocol on interfaces whose IP address falls within a network explicitly listed by a network statement. Here, 10.1.1.0/24 matches the 10.0.0.0/8 network statement, and 192.168.1.0/24 directly matches the 192.168.1.0 statement. However, 172.16.1.0/24 is part of the 172.16.0.0/16 major network, which is never referenced by any network statement, so EIGRP will not run on that interface and no adjacency will form there.

Why this answer

EIGRP uses the network command with a wildcard mask to determine which interfaces to enable EIGRP on. The network 10.0.0.0 0.255.255.255 matches interfaces with an IP address in the 10.x.x.x range, enabling EIGRP on GigabitEthernet0/0 (10.1.1.1). The network 192.168.1.0 0.0.0.255 matches the 192.168.1.0/24 subnet, enabling EIGRP on GigabitEthernet0/1 (192.168.1.1).

The 172.16.1.0/24 network is not matched by any network statement, so EIGRP is not enabled on GigabitEthernet0/2, and no adjacency is formed there.

Exam trap

Cisco often tests the misconception that a network statement with a wildcard mask will automatically include all interfaces with similar first octets, but in reality, the wildcard mask must explicitly match the exact subnet range for an interface to be enabled.

How to eliminate wrong answers

Option A is wrong because EIGRP does not use classful boundaries when a wildcard mask is specified; the network 10.0.0.0 0.255.255.255 is a classful match for the 10.0.0.0/8 major net, but it does not include the 172.16.1.0/24 network. Option C is wrong because the network 10.0.0.0 command does not include interfaces with IPs starting with 1, 172, or 192; it only matches addresses in the 10.0.0.0/8 range, and the 172.16.1.0/24 network is not covered. Option D is wrong because EIGRP network statements can use either a wildcard mask or no mask (defaulting to classful), and using wildcard masks is valid and common; the configuration will form adjacencies on matched interfaces.

1085
MCQmedium

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive traffic. The engineer wants to limit ICMP echo requests destined to the router to 100 packets per second, while allowing other traffic. Which configuration snippet correctly applies CoPP for this purpose?

A.class-map match-any ICMP match access-group 101 policy-map CoPP class ICMP police 100 conform-action transmit exceed-action drop interface GigabitEthernet0/0 service-policy input CoPP
B.access-list 101 permit icmp any any echo class-map match-any ICMP match access-group 101 policy-map CoPP class ICMP police 100 conform-action transmit exceed-action drop interface GigabitEthernet0/0 service-policy output CoPP
C.access-list 101 permit icmp any any echo class-map match-any ICMP match access-group 101 policy-map CoPP class ICMP police 100 conform-action transmit exceed-action drop control-plane service-policy input CoPP
D.access-list 101 permit icmp any any echo class-map match-any ICMP match access-group 101 policy-map CoPP class ICMP police 100 conform-action transmit exceed-action drop control-plane service-policy output CoPP
AnswerC

This configuration correctly defines an ACL to match ICMP echo requests, uses a class-map to reference the ACL, creates a policy-map to police the matched traffic at 100 pps, and applies the policy map to the control plane with 'service-policy input CoPP' under 'control-plane' mode. This is the proper way to implement CoPP.

Why this answer

CoPP is implemented by defining a class-map to match traffic, a policy-map to police it, and then applying the policy-map to the control plane with 'service-policy input' under the 'control-plane' configuration mode. The correct snippet uses an ACL to match ICMP echo requests, polices them at 100 pps, and applies the policy to the control plane. This protects the route processor from excessive ICMP traffic while allowing other traffic.

Exam trap

The trap here is applying the CoPP policy to an interface instead of the control plane, which would not protect the route processor.

1086
MCQhard

An engineer configures mutual redistribution between OSPF and EIGRP. After a few minutes, routing loops occur. The engineer did not use route tagging. Which is the most likely explanation?

A.Routes redistributed from OSPF into EIGRP have a higher administrative distance than the original OSPF routes, causing them to be preferred.
B.Redistributed routes retain their original metric, which can cause them to be preferred over the original route.
C.Without route tagging, OSPF redistributes EIGRP routes back into OSPF, and EIGRP redistributes OSPF routes back into EIGRP, creating a cycle.
D.The seed metric for redistribution is not set, causing the redistributed routes to be rejected.
AnswerC

Without route tagging, OSPF and EIGRP cannot distinguish routes that originated in their own domain from routes that were redistributed from the other protocol. OSPF redistributes an EIGRP route (which may already contain OSPF-derived prefixes) back into OSPF, and EIGRP does the same in reverse, so each protocol repeatedly re-injects the other's routes. This cycle creates route flapping and potential loops; a route-map that tags and then denies re-redistribution of tagged routes prevents the feedback.

Why this answer

Mutual redistribution without route tagging creates a feedback loop: OSPF redistributes EIGRP-learned routes back into OSPF, and EIGRP redistributes OSPF-learned routes back into EIGRP. Each protocol re-advertises the other's routes, causing them to be learned and re-injected repeatedly, which leads to routing loops. Route tagging (e.g., using a route-map to set a tag) is the standard method to prevent such cycles by filtering redistributed routes that already originated from the other protocol.

Exam trap

Cisco often tests the misconception that routing loops in mutual redistribution are caused by administrative distance or metric issues, when in fact the core problem is the lack of route tagging to prevent re-redistribution of routes back into their original protocol.

How to eliminate wrong answers

Option A is wrong because administrative distance (AD) is used to select between routes from different protocols, but in mutual redistribution, the issue is not about preferring one protocol over another—it is about the same route being re-injected and causing a loop. Option B is wrong because redistributed routes do not retain their original metric; OSPF uses a seed metric (default 20 for external routes) and EIGRP uses a seed metric (default infinity unless set), and metric manipulation does not directly cause loops—the loop stems from re-redistribution. Option D is wrong because if the seed metric is not set for EIGRP redistribution, the route is not rejected; EIGRP requires a seed metric (e.g., bandwidth, delay) to be configured, but OSPF uses a default seed metric of 20, so routes are still redistributed and can cause loops.

1087
MCQhard

A network engineer runs the following command on Router R1: R1# show flow monitor FLOW-MONITOR-1 cache format table Cache type: Normal Cache size: 1000 Current entries: 1000 High Watermark: 1000 Flows added: 50000 Flows aged: 49000 - Active timeout (1800 secs) 40000 - Inactive timeout (15 secs) 8000 - Event aged 0 - Watermark aged 1000 - Emergency aged 0 Based on this output, what is the most likely issue?

A.The cache size is too small, causing watermark aging and potential loss of flow data.
B.The active timeout is set too low at 1800 seconds.
C.The inactive timeout is set too low at 15 seconds.
D.The flow exporter is not configured.
AnswerA

The cache reached its 1000-entry maximum (High Watermark 1000), forcing 1000 flows to be aged via the watermark mechanism. With 50000 flows added against only 1000 slots, the cache is undersized, causing premature eviction and potential loss of flow data.

Why this answer

The cache is full (1000 current entries, high watermark 1000), and watermark aging has occurred (1000 flows aged due to watermark). This indicates the cache is overflowing, causing flows to be aged prematurely to make room for new flows. This can lead to incomplete data.

1088
MCQmedium

A network engineer runs the following command to troubleshoot SNMP traps: R1# show snmp host Host: 10.1.1.2 Port: 162 Timeout: 30 Retries: 3 Community: trap-public Version: 2c Filter: none Host: 10.1.1.3 Port: 162 Timeout: 30 Retries: 3 Community: trap-public Version: 2c Filter: none What does this output indicate?

A.SNMP traps are sent to two NMS hosts: 10.1.1.2 and 10.1.1.3 using SNMPv2c.
B.SNMP traps are sent to host 10.1.1.2 only.
C.The router is configured to receive traps from these hosts.
D.SNMPv3 is used for trap communication.
AnswerA

The output lists two trap destinations, 10.1.1.2 and 10.1.1.3, each on UDP port 162 with community string trap-public and Version 2c. This confirms the router forwards SNMPv2c notifications to both network management stations, satisfying the requirement to identify configured trap receivers.

Why this answer

The output of the 'show snmp host' command lists the configured SNMP trap receivers. Each entry shows a host IP address (10.1.1.2 and 10.1.1.3), port 162 (the standard SNMP trap port), and the SNMP version (2c). This confirms that the router is sending SNMPv2c traps to both NMS hosts, making option A correct.

Exam trap

Cisco often tests the distinction between 'show snmp host' (shows trap destinations) and 'snmp-server host' (configures trap destinations), leading candidates to mistakenly think the output shows incoming traps or only a single host.

How to eliminate wrong answers

Option B is wrong because the output clearly shows two separate host entries (10.1.1.2 and 10.1.1.3), indicating traps are sent to both, not just 10.1.1.2. Option C is wrong because 'show snmp host' displays the destinations to which the router sends traps, not the hosts from which it receives traps; receiving traps would be shown by 'snmp-server trap-source' or similar commands. Option D is wrong because the output explicitly states 'Version: 2c' for both hosts, confirming SNMPv2c is used, not SNMPv3.

1089
MCQeasy

A network administrator is configuring a Cisco IOS XE router for MPLS Traffic Engineering (TE). The administrator wants to ensure that the router can signal an MPLS TE tunnel using RSVP. Which protocol must be enabled on the interfaces along the path to reserve bandwidth and distribute labels?

A.BGP
B.LDP
C.OSPF
D.RSVP
AnswerD

RSVP (Resource Reservation Protocol) is the signaling protocol used for MPLS Traffic Engineering. It reserves bandwidth along the path and distributes labels for the TE tunnel. RSVP-TE extends RSVP to support traffic engineering by adding objects for explicit routes, bandwidth, and label requests. It must be enabled on all interfaces that the TE tunnel traverses to ensure resource reservation and label distribution.

Why this answer

MPLS Traffic Engineering requires RSVP to signal TE tunnels and reserve bandwidth along the path. RSVP-TE is an extension of RSVP that carries additional objects for traffic engineering, such as explicit route objects and label requests. It must be enabled on all interfaces that the tunnel traverses.

While OSPF or IS-IS with TE extensions are used to advertise link attributes, and BGP may be used for routing, RSVP is the protocol that performs the actual signaling and resource reservation.

Exam trap

The trap here is confusing the role of OSPF-TE, which advertises TE information, with RSVP, which actually signals and reserves resources for the tunnel.

1090
MCQmedium

A network engineer is deploying GET VPN across an MPLS L3VPN service provider network. The key server is reachable by all group members, and the engineer wants to avoid rekeying storms when many group members reboot simultaneously after a power outage. Which mechanism should the engineer configure on the key server to spread rekey retransmissions over a period of time?

A.Configure the key server with a rekey retransmit interval and a retransmit limit, and enable the rekey acknowledgment feature so members request unicast retransmissions.
B.Configure the key server with a rekey retransmit interval and disable the rekey acknowledgment, forcing members to pull rekeys at randomized intervals.
C.Configure the group members with a longer registration timeout so they wait longer before contacting the key server after reboot.
D.Configure the key server to use a shorter rekey lifetime so that keys expire quickly and members are forced to re-register frequently.
AnswerA

GET VPN rekey retransmission with acknowledgment lets the key server pace unicast retransmissions to members that did not receive the multicast rekey. When a large number of group members reboot together, the key server sends the multicast rekey, then retransmits at the configured interval to non-responding members, up to the retransmit limit. This prevents an overload of simultaneous unicast rekeys while still guaranteeing key delivery.

Why this answer

The key server in GET VPN distributes the group key via multicast and then uses reliable rekey retransmission with acknowledgment to unicast the rekey to members that did not receive it. Configuring a retransmit interval and retransmit limit spreads those unicast retransmissions over time, so a large number of members rebooting simultaneously do not overload the key server. This preserves key synchronization across the group without disabling the reliability mechanism that guarantees delivery.

Exam trap

The trap here is assuming that disabling rekey acknowledgment reduces load, when in fact acknowledgment is the mechanism that lets the key server retransmit missing rekeys reliably.

1091
MCQhard

An engineer configures PBR with a route-map that sets the next-hop to 10.0.0.2 for traffic matching ACL 100. The route-map is applied inbound on interface GigabitEthernet0/1. Traffic from a host on that interface is forwarded via 10.0.0.2, but the engineer notices that packets with destination IP 10.0.0.2 itself are also being redirected, causing a loop. Why does this happen?

A.The ACL 100 inadvertently matches the router's own IP address as source.
B.PBR is applied outbound, causing packets to the router to be re-routed.
C.The set ip next-hop command does not check if the next-hop is the router itself, so packets destined to the router are forwarded instead of being processed locally.
D.The route-map has a default route that sends all traffic to 10.0.0.2.
AnswerC

Policy-based routing rewrites the next hop before the packet is tested against the local forwarding table, and the set ip next-hop action does not verify whether that address belongs to the router itself. Traffic destined for 10.0.0.2 is therefore redirected out of the interface rather than delivered locally, producing the loop.

Why this answer

When PBR uses 'set ip next-hop', the router rewrites the forwarding decision for matched packets without checking whether the next-hop address belongs to the router itself. If the ACL matches traffic destined to the router's own IP (which is also the configured next-hop), the router forwards the packet out toward 10.0.0.2 instead of delivering it to its own control plane, creating a forwarding loop or black hole. The fix is to exclude the next-hop address (and the router's own addresses) from the ACL match.

Exam trap

The trap is overlooking that PBR does not exempt traffic destined to the configured next-hop address, so candidates assume the router would process such packets locally rather than forwarding them back out.

How to eliminate wrong answers

Option A is wrong because the issue is about the destination matching the next-hop, not the source being the router's own IP — the ACL is matching on destination, and the loop occurs because the destination equals the configured next-hop. Option B is wrong because the route-map is explicitly applied inbound on GigabitEthernet0/1; outbound PBR is not the cause, and outbound application would not explain the loop to the next-hop address. Option D is wrong because the scenario describes a specific 'set ip next-hop 10.0.0.2' statement, not a default route inside the route-map — a default route in the RIB would not cause this loop.

1092
MCQeasy

According to RFC 5424, which syslog severity level corresponds to 'Critical' conditions?

A.Severity 0
B.Severity 1
C.Severity 2
D.Severity 3
AnswerC

RFC 5424 numbers severities from 0 (Emergency) to 7 (Debug). Critical sits at severity 2, between Alert (1) and Error (3). This ordering is fixed by the standard, so any syslog implementation must map Critical conditions to the numeric value 2.

Why this answer

RFC 5424 defines eight syslog severity levels numbered 0 through 7. Severity 2 is explicitly named 'Critical', indicating critical conditions such as hard device errors. This sits between Emergency (0) and Alert (1) on the more severe end, and Error (3) on the less severe end.

Exam trap

300-410 often tests the inverted numeric scale of syslog severities, causing candidates to assume higher numbers mean higher severity and to confuse Critical (2) with Alert (1) or Error (3).

How to eliminate wrong answers

Option A is wrong because Severity 0 is 'Emergency' (system is unusable), the most severe level. Option B is wrong because Severity 1 is 'Alert' (action must be taken immediately). Option D is wrong because Severity 3 is 'Error' (error conditions), which is less severe than Critical.

1093
MCQhard

A network administrator is configuring a Cisco IOS router to authenticate users via TACACS+ using a TACACS+ server at 10.1.1.50. The administrator wants to ensure that if the TACACS+ server is unreachable, the router will fall back to using the local username database. Which command set achieves this?

A.aaa authentication login default group tacacs+ local
B.aaa authentication login default group tacacs+ none
C.aaa authentication login default group tacacs+ enable
D.aaa authentication login default local group tacacs+
AnswerA

This command configures the default login authentication method list to first try TACACS+ and then fall back to the local database if the TACACS+ server is unreachable. The 'local' keyword ensures that local authentication is attempted only if the TACACS+ servers do not respond, providing redundancy and preventing lockout.

Why this answer

The aaa authentication login default group tacacs+ local command sets TACACS+ as the primary authentication method and local as the fallback. This ensures that if the TACACS+ server is unreachable, the router will use its local username database, maintaining administrative access without compromising security.

Exam trap

The trap here is reversing the order of authentication methods, which would cause the router to check local credentials first and only use TACACS+ if local fails, contrary to the desired primary-backup relationship.

1094
MCQhard

Which statement correctly describes the default behavior of the 'flow monitor' in Flexible NetFlow regarding the collection of BGP next-hop information?

A.BGP next-hop is always collected by default in Flexible NetFlow monitors.
B.BGP next-hop is never collected in Flexible NetFlow, only in traditional NetFlow.
C.BGP next-hop is collected only if the flow record includes the 'match routing bgp next-hop' command.
D.BGP next-hop is collected by default only for IPv4 flows.
AnswerC

BGP next-hop is not part of the default key or non-key fields; it must be explicitly added to the flow record via 'match routing bgp next-hop'. Without that command, the exporter omits it, so the option correctly ties collection to that record configuration.

Why this answer

By default, Flexible NetFlow does not collect BGP next-hop information unless explicitly configured in the flow record.

1095
MCQmedium

A network engineer runs the following command to verify IPv6 binding table: R1# show ipv6 neighbors binding IPv6 Address Age Link-layer Addr State Interface VLAN Policy 2001:db8::1 10 0011.2233.4455 REACH Fa0/1 10 TRUSTED 2001:db8::2 5 00aa.bbcc.ddee STALE Fa0/0 10 INSPECT 2001:db8::3 0 1111.2222.3333 INCOMP Fa0/0 10 - What does this output indicate?

A.The binding table shows three entries: one reachable on trusted port, one stale on untrusted port, and one incomplete, indicating active ND learning.
B.The binding table is empty, indicating no ND activity.
C.The binding table shows all entries as reachable, indicating stable neighbor relationships.
D.The binding table is only for DHCPv6-learned addresses.
AnswerA

The binding table confirms IPv6 first-hop security is learning neighbour bindings across VLAN 10. The REACH entry on Fa0/1 carries TRUSTED policy, the STALE entry on Fa0/0 carries INSPECT, and the INCOMP entry shows an unresolved neighbour discovery attempt — satisfying the requirement to verify live ND learning states.

Why this answer

The output of 'show ipv6 neighbors binding' displays the IPv6 binding table used in First Hop Security (FHS) features like IPv6 Snooping. The entry for 2001:db8::1 has a REACH state on interface Fa0/1 with a TRUSTED policy, indicating it is reachable on a trusted port. The entry for 2001:db8::2 is STALE on Fa0/0 with an INSPECT policy, meaning it is on an untrusted port and requires verification.

The entry for 2001:db8::3 is INCOMP (incomplete) on Fa0/0, showing an ongoing Neighbor Discovery (ND) process where the link-layer address has not yet been resolved.

Exam trap

Cisco often tests the misinterpretation of the 'show ipv6 neighbors binding' output by confusing it with 'show ipv6 neighbors' (which shows the ND cache), leading candidates to overlook the FHS-specific policy column and state meanings, especially the significance of INCOMP and STALE states in security contexts.

How to eliminate wrong answers

Option B is wrong because the binding table is not empty; it clearly shows three entries with IPv6 addresses, ages, link-layer addresses, states, and policies. Option C is wrong because not all entries are reachable; one is STALE and one is INCOMP, indicating unstable or unresolved neighbor relationships. Option D is wrong because the binding table is populated by IPv6 Neighbor Discovery (ND) snooping and can include addresses learned via ND, not exclusively DHCPv6; the 'Policy' column (TRUSTED, INSPECT) is specific to FHS features like IPv6 RA Guard and ND inspection.

1096
MCQhard

A network engineer runs the following command to debug MPLS LDP session establishment: R1# debug mpls ldp session Output: *Mar 1 00:01:23.456: LDP: Session with 10.0.0.2:0 (0x1234) is UP *Mar 1 00:01:24.567: LDP: Session with 10.0.0.2:0 (0x1234) is DOWN *Mar 1 00:01:25.678: LDP: Session with 10.0.0.2:0 (0x1234) is UP *Mar 1 00:01:26.789: LDP: Session with 10.0.0.2:0 (0x1234) is DOWN What does this output indicate?

A.The LDP session with 10.0.0.2 is flapping
B.The LDP session with 10.0.0.2 is stable
C.The LDP session with 10.0.0.2 is using targeted hello
D.The LDP session with 10.0.0.2 is down permanently
AnswerA

Repeated UP/DOWN transitions for the same peer (10.0.0.2:0) within seconds indicate the LDP session is flapping, not merely failing once. The stem's constraint is session establishment instability, and the debug output directly evidences the session cycling between operational states, so this option matches the observed behaviour precisely.

Why this answer

The debug output shows the LDP session with neighbor 10.0.0.2 is flapping (repeatedly going UP and DOWN). This indicates instability in the LDP session.

1097
MCQhard

An engineer enables uRPF (unicast Reverse Path Forwarding) in strict mode on an interface connected to a DMVPN spoke. The spoke has multiple tunnels and receives traffic from the hub with a source IP that is not the best reverse path. Unexpectedly, the spoke drops all traffic from the hub, even though the hub is reachable via the tunnel. Which is the most likely explanation?

A.uRPF strict mode requires the reverse path to be via the same interface; asymmetric routing causes drops.
B.The hub's IP address is not in the routing table, so uRPF drops the packet.
C.uRPF must be configured with the `allow-default` option to accept packets with default route.
D.uRPF is not supported on tunnel interfaces; it must be applied on the physical interface.
AnswerA

Strict uRPF checks that the source address is reachable via the same interface the packet arrived on. With multiple DMVPN tunnels, the hub's source may return via a different tunnel interface, so the reverse path lookup fails and packets are dropped despite reachability.

Why this answer

uRPF strict mode verifies that the source IP of an incoming packet is reachable via the same interface the packet arrived on, using the FIB. In a DMVPN spoke scenario, traffic from the hub may arrive on a tunnel interface while the reverse path to the hub's source IP points to a different tunnel or the physical interface, causing strict mode to drop the packets. This is the classic asymmetric routing failure mode for strict uRPF.

Exam trap

The trap is assuming uRPF failures always mean 'the source isn't in the routing table'; in reality, strict mode fails whenever the reverse path uses a different interface, even if the source is perfectly reachable.

How to eliminate wrong answers

Option B is wrong because if the hub's IP were truly absent from the routing table, the tunnel itself would not be up and the symptom would be broader reachability failure, not selective drops of traffic from a reachable hub. Option C is wrong because 'allow-default' only permits the default route to satisfy the reverse-path lookup; it does not fix the asymmetric interface mismatch that strict mode enforces. Option D is wrong because uRPF is supported on tunnel interfaces (including GRE/mGRE used by DMVPN); the issue is the strict-mode interface-match requirement, not platform support.

1098
MCQmedium

A network engineer runs the following command to troubleshoot a Control Plane Policing (CoPP) issue: R1# show bgp neighbors 10.1.1.2 advertised-routes BGP table version is 10, local router ID is 10.1.1.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.2.2.0/24 0.0.0.0 0 32768 i Total number of prefixes 1 What does this output indicate?

A.BGP is not advertising routes due to CoPP dropping update packets.
B.BGP is advertising routes correctly, and CoPP is not affecting outbound updates.
C.BGP is receiving routes but not advertising them due to CoPP.
D.BGP session is down due to CoPP.
AnswerB

The route is advertised with weight 32768, indicating local origin, and no errors are shown.

Why this answer

The output shows that BGP has one prefix (10.2.2.0/24) in the advertised-routes table for neighbor 10.1.1.2, with the next hop set to 0.0.0.0 (indicating a locally originated route). This confirms that BGP is successfully advertising routes outbound, and there is no evidence of CoPP dropping update packets. CoPP would only affect control plane traffic destined to the router itself, not outbound BGP updates, which are forwarded in the data plane.

Exam trap

The trap here is that candidates assume CoPP can affect outbound BGP updates, but CoPP only polices inbound control plane traffic, so a successful advertised-routes output proves CoPP is not the cause of any advertisement failure.

How to eliminate wrong answers

Option A is wrong because the advertised-routes output shows a prefix being advertised, so CoPP is not dropping outbound update packets; CoPP polices inbound control plane traffic, not outbound updates. Option C is wrong because the command shows routes being advertised (not just received), and CoPP does not prevent BGP from advertising routes; it only filters traffic destined to the control plane. Option D is wrong because the BGP session is clearly up (as evidenced by the ability to run the show command and see advertised routes), and CoPP would not bring down a BGP session unless it dropped keepalives or updates inbound, which is not indicated here.

1099
MCQmedium

A network engineer is configuring DMVPN Phase 3 on a hub router. The hub has a public IP address and is reachable. Spokes are behind NAT devices and have dynamic public IP addresses. Which technology allows spokes to communicate directly without routing traffic through the hub?

A.NHRP redirect
B.NHRP resolution
C.NHRP shortcut
D.NHRP registration
AnswerC

NHRP shortcut allows a spoke to dynamically create a direct tunnel to another spoke when it receives an NHRP redirect from the hub. This enables direct spoke-to-spoke communication, bypassing the hub, which is a key feature of DMVPN Phase 3.

Why this answer

In DMVPN Phase 3, NHRP shortcut enables direct spoke-to-spoke tunnels. When a spoke sends traffic to another spoke via the hub, the hub sends an NHRP redirect, and the spoke then uses NHRP shortcut to establish a direct tunnel.

Exam trap

The trap here is confusing NHRP redirect with NHRP shortcut; redirect is the trigger, but shortcut is the mechanism that actually creates the direct tunnel.

1100
MCQeasy

What is the default BFD multiplier (detection time multiplier) on Cisco IOS-XE?

A.1
B.2
C.3
D.4
AnswerC

Cisco IOS-XE uses a default BFD detection multiplier of 3, meaning three consecutive missed control packets trigger a session-down event. Combined with the default 50 ms transmit interval, this yields a 150 ms detection time, satisfying the question's request for the default multiplier value.

Why this answer

The default BFD multiplier is 3, meaning the detection time is 3 times the negotiated hello interval.

1101
MCQmedium

A network engineer runs the following command on Router R1: R1# show ipv6 snooping policy Interface Policy Role State Gi0/0/0 GUARD_POLICY device-guard ACTIVE Gi0/0/1 GUARD_POLICY device-guard ACTIVE Gi0/0/2 (default) host ACTIVE Based on this output, which statement is correct?

A.Interface Gi0/0/2 is protected by the GUARD_POLICY policy.
B.Interface Gi0/0/2 is not protected by the custom guard policy and may be vulnerable to spoofing attacks.
C.All interfaces are equally protected by the same policy.
D.The role 'host' means Gi0/0/2 is acting as a device-guard.
AnswerB

The default policy provides minimal protection; the custom GUARD_POLICY is not applied to Gi0/0/2.

Why this answer

The output shows that Gi0/0/2 is using the default policy with a role of 'host', meaning it is not protected by the custom GUARD_POLICY. The device-guard feature, part of IPv6 First Hop Security, applies only to interfaces with a custom policy; a default policy does not enforce spoofing protection, leaving the interface vulnerable to attacks like rogue RA or ND spoofing.

Exam trap

Cisco often tests the misconception that all interfaces are equally protected by a guard policy, when in fact the (default) policy indicates no custom protection, leaving the interface vulnerable to spoofing attacks.

How to eliminate wrong answers

Option A is wrong because Gi0/0/2 is using the (default) policy, not GUARD_POLICY, so it is not protected by the custom guard policy. Option C is wrong because Gi0/0/0 and Gi0/0/1 are protected by GUARD_POLICY, while Gi0/0/2 uses the default policy, resulting in unequal protection. Option D is wrong because the role 'host' indicates the interface is treated as a host (not a device-guard), and the device-guard role is specifically assigned to interfaces with a custom policy like GUARD_POLICY.

1102
Drag & Dropmedium

Drag and drop the steps to configure a DHCP pool and relay agent on a Cisco router into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, you must define the DHCP pool with a name and network. Then, you set the default router and DNS server. Next, you exclude any addresses from the pool.

Finally, you enable the DHCP relay agent on the interface facing clients to forward requests to the DHCP server.

1103
MCQhard

What is the default maximum number of labels that can be imposed in the MPLS label stack on a Cisco IOS-XE router?

A.6 labels
B.3 labels
C.10 labels
D.Unlimited
AnswerA

The default maximum label stack depth is 6 labels.

Why this answer

The default maximum label stack depth is 6 labels on Cisco IOS-XE routers, though this can be increased with the 'mpls label range' command.

1104
MCQmedium

What is the default frequency (in seconds) for an IP SLA operation when no frequency is explicitly configured?

A.10 seconds
B.30 seconds
C.60 seconds
D.120 seconds
AnswerC

Correct. The default frequency for IP SLA operations is 60 seconds.

Why this answer

The default frequency for an IP SLA operation is 60 seconds. This means the probe is sent every 60 seconds unless a different frequency is configured under the IP SLA configuration.

1105
MCQhard

A network engineer configures SNMPv3 with authentication and privacy on a router. The NMS polls the router via the management interface. The engineer then adds a loopback interface and configures the router to send SNMP traps sourced from the loopback IP. The NMS stops receiving traps. Which is the most likely explanation?

A.The NMS is configured to accept traps only from the management interface IP address, not the loopback IP.
B.The loopback interface does not support SNMP trap generation.
C.The SNMP engine ID changed when the loopback interface was added.
D.The 'snmp-server trap-source' command requires a specific interface type.
AnswerA

SNMPv3 trap receivers filter by source IP. Changing the trap source to the loopback address alters the packet's source IP, so the NMS discards traps arriving from an address it does not recognise, satisfying the stem's constraint that traps stopped after the source change.

Why this answer

The NMS is likely configured with an ACL or trap receiver filter that only accepts SNMP traps from the management interface IP address. When the engineer configures 'snmp-server trap-source loopback0', the router changes the source IP of all outgoing traps to the loopback IP. If the NMS is not expecting traps from that IP, it will drop them, even though SNMPv3 authentication and privacy are correctly configured.

Exam trap

Cisco often tests the misconception that SNMPv3 security (auth/priv) is the cause of trap delivery failure, when in fact the issue is a source IP mismatch due to the 'snmp-server trap-source' command overriding the default source address.

How to eliminate wrong answers

Option B is wrong because loopback interfaces fully support SNMP trap generation; they are logical interfaces and can be used as the source for any IP traffic, including SNMP traps. Option C is wrong because adding a loopback interface does not change the SNMP engine ID; the engine ID is derived from the router's MAC address or configured manually, and it remains stable unless explicitly modified. Option D is wrong because the 'snmp-server trap-source' command accepts any interface type (e.g., GigabitEthernet, Loopback, VLAN), and there is no restriction on interface type for trap sourcing.

1106
MCQhard

A network engineer is troubleshooting a Cisco IOS XE router running OSPFv2. The router is an ABR between Area 0 and Area 1. Area 1 is configured as a Not-So-Stubby Area (NSSA). The engineer notices that a Type-7 LSA originated by an ASBR in Area 1 is not being translated into a Type-5 LSA by the ABR. Which condition would prevent the ABR from performing Type-7 to Type-5 translation?

A.The ABR has a static route to the NSSA ASBR's loopback interface but no OSPF adjacency with the ASBR.
B.The ABR is not configured with the `area 1 nssa translate type7 always` command and there is another ABR with a higher router ID in the NSSA.
C.The Type-7 LSA has the P-bit (Propagate bit) cleared, indicating that the LSA should not be translated by the ABR.
D.The forwarding address in the Type-7 LSA is set to 0.0.0.0 and the ABR has no route to the ASBR's router ID.
AnswerC

In NSSA, the P-bit in the Type-7 LSA options field indicates whether the LSA should be translated into a Type-5 LSA by the ABR. If the P-bit is cleared, the ABR will not translate the LSA. The P-bit is typically set by the ASBR when the LSA is originated, but it can be cleared under certain conditions, such as when the ASBR is also an ABR or when the LSA is redistributed without the proper configuration. This directly prevents translation.

Why this answer

Type-7 to Type-5 translation in an NSSA depends on the P-bit in the Type-7 LSA. If the P-bit is cleared, the ABR will not translate the LSA into a Type-5 LSA, preventing the external route from being propagated into the backbone area. This bit is set by the originating ASBR and can be cleared in specific scenarios.

Exam trap

The trap here is focusing on ABR election or forwarding address issues, when the P-bit in the Type-7 LSA is the direct control for whether translation occurs.

1107
MCQhard

Router R9 is configured with SNMP and NetFlow. The NMS uses SNMP to poll NetFlow statistics. The configuration includes: snmp-server community public RO, snmp-server enable traps netflow. However, the NMS cannot poll NetFlow MIB objects. The router's show snmp mib shows that the NetFlow MIB is not loaded. What is the root cause?

A.The NetFlow MIB is not loaded because NetFlow data export is not configured; the 'ip flow-export' command is missing.
B.The SNMP community string does not have read access to the NetFlow MIB.
C.The router's SNMP agent is not compatible with the NetFlow MIB.
D.The NMS is using an incorrect OID for NetFlow statistics.
AnswerA

The NetFlow MIB is only loaded when NetFlow is configured with 'ip flow-export' commands. Without it, the MIB is not available for SNMP polling.

Why this answer

The NetFlow MIB is only loaded into the router's SNMP agent when NetFlow data export is actively configured. Without the 'ip flow-export' command, the router does not instantiate the NetFlow MIB objects, so 'show snmp mib' reports the MIB as not loaded. The NMS cannot poll statistics that do not exist in the SNMP agent's MIB tree.

Exam trap

Cisco often tests the misconception that SNMP traps and MIB polling are independent of the underlying feature configuration; the trap here is assuming that enabling SNMP traps for NetFlow automatically loads the NetFlow MIB, when in fact the MIB requires the 'ip flow-export' command to be present.

How to eliminate wrong answers

Option B is wrong because the SNMP community string 'public RO' provides read-only access, which is sufficient for polling MIB objects; the issue is that the MIB itself is not loaded, not a permissions problem. Option C is wrong because the router's SNMP agent is fully compatible with the NetFlow MIB when NetFlow export is configured; the MIB is simply not instantiated without the export command. Option D is wrong because the NMS cannot poll using any OID if the MIB is not loaded in the router's agent; the problem is at the agent side, not the NMS's OID selection.

1108
MCQeasy

In the context of NAT and PAT, what is the purpose of the ip nat translation timeout command?

A.It sets the timeout for static NAT entries.
B.It configures the timeout for all dynamic NAT translations globally.
C.It sets the timeout only for TCP translations.
D.It configures the timeout for translations on a specific interface.
AnswerB

The command sets the aging timer for dynamic NAT and PAT entries in the global translation table, so idle translations are removed after the specified period. It satisfies the scenario's need to control how long all dynamic translations persist before expiry, rather than per-interface or static entries.

Why this answer

The `ip nat translation timeout` command sets the global idle timeout for all dynamic NAT translations, including both TCP and UDP. When a dynamic translation is no longer active, this timer determines how long the NAT entry remains in the table before being removed, freeing resources. Static NAT entries are not affected by this command because they are manually configured and persist indefinitely unless explicitly removed.

Exam trap

Cisco often tests the distinction between global and per-interface NAT configuration, leading candidates to incorrectly assume that `ip nat translation timeout` can be applied under a specific interface, when in fact it is always a global command that affects all dynamic translations on the router.

How to eliminate wrong answers

Option A is wrong because static NAT entries are not subject to timeouts; they remain in the translation table until manually deleted. Option C is wrong because the command applies to all dynamic translations, not just TCP; TCP has its own separate configurable timeout via `ip nat translation tcp-timeout`. Option D is wrong because the `ip nat translation timeout` command is a global configuration command; per-interface timeout behavior is not supported—timeouts are always global.

1109
MCQmedium

A network engineer runs the following command to verify redistribution with route-maps: R1# show ip route 10.10.10.0 255.255.255.0 Routing entry for 10.10.10.0/24 Known via "eigrp 100", distance 170, metric 2560002816 Tag 100, type internal Last update from 10.1.1.2 on GigabitEthernet0/0, 00:00:45 ago Routing Descriptor Blocks: * 10.1.1.2, from 10.1.1.2, 00:00:45 ago, via GigabitEthernet0/0 Route metric is 2560002816, traffic share count is 1 Total delay is 2000 microseconds, minimum bandwidth is 100000 Kbit Reliability 255/255, minimum MTU 1500 bytes Loading 1/255, Hops 1 What does the 'Tag 100' indicate?

A.The route was originated by EIGRP autonomous system 100.
B.The route has a tag of 100, likely set by a route-map during redistribution.
C.The route is internal to EIGRP and has a metric of 100.
D.The route is from a BGP AS 100.
AnswerB

The tag value 100 was attached to the route during redistribution, typically by a route-map using the set tag command. EIGRP carries this tag transparently, letting downstream routers identify the route's origin or apply policy based on it.

Why this answer

The 'Tag 100' indicates that a route-map applied during redistribution set the tag to 100. Route tags are often used for filtering or administrative purposes during redistribution.

1110
MCQmedium

Which of the following best describes the behavior of BGP when an 'aggregate-address' command is used without the 'summary-only' keyword?

A.The aggregate route is advertised, and all more specific routes are also advertised.
B.Only the aggregate route is advertised.
C.The aggregate route is not advertised unless a network command exists for it.
D.The more specific routes are withdrawn from the BGP table.
AnswerA

The aggregate-address command without summary-only advertises the aggregate and leaks all more specific component routes alongside it. Neighbours therefore receive both, which is the behaviour distinguishing it from the summary-only variant that suppresses the specifics.

Why this answer

Without the summary-only keyword, BGP advertises both the aggregate route and the more specific routes that are in the BGP table.

1111
MCQmedium

A network engineer is configuring OSPFv3 on a Cisco IOS XE router. The router has two interfaces: GigabitEthernet0/0 in Area 0 and GigabitEthernet0/1 in Area 1. The engineer wants to ensure that the router acts as an ABR and that inter-area routes are summarized. Which command must be configured under the OSPFv3 router configuration mode to enable ABR functionality?

A.No additional command is required; ABR is automatic.
B.area 1 range 2001:db8:1::/64
C.router-id 1.1.1.1
D.interface GigabitEthernet0/1
AnswerA

A router becomes an ABR automatically when it has at least two interfaces in different OSPF areas. No specific command enables ABR functionality. The engineer only needs to ensure that the interfaces are correctly assigned to different areas, which is already stated. Thus, no additional command under router configuration mode is needed to make the router an ABR.

Why this answer

ABR status in OSPFv3 is not enabled by a command; it is a role that a router assumes when it has interfaces in multiple areas. The engineer must ensure that the interfaces are assigned to different areas, which is already the case. Commands like area range are used for summarization but do not enable ABR.

The router ID is necessary for OSPFv3 operation but not for ABR functionality. Therefore, no additional command is required to make the router an ABR.

Exam trap

The trap here is assuming that a specific command enables ABR functionality, when in fact ABR status is automatic based on interface area assignments.

1112
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip nat translations Pro Inside global Inside local Outside local Outside global --- 192.0.2.10 10.0.0.10 203.0.113.5 203.0.113.5 --- 192.0.2.11 10.0.0.11 203.0.113.5 203.0.113.5 R1# show ip nat statistics Total active translations: 2 (0 static, 2 dynamic; 0 extended) Outside interfaces: GigabitEthernet0/1 Inside interfaces: GigabitEthernet0/0 Hits: 20 Misses: 0 CEF Translated packets: 20, CEF Punted packets: 0 Expired translations: 0 Dynamic mappings: -- Inside Source [Id] ip nat pool POOL1 192.0.2.10 192.0.2.20 netmask 255.255.255.240 refcount 2 map-id 1 [Id] ip nat inside source list ACL1 pool POOL1 refcount 2 Based on this output, which statement is correct?

A.NAT is configured without PAT; each inside host uses a unique global address.
B.PAT is enabled, but only two translations are active.
C.The pool is exhausted because two addresses are used.
D.Static NAT is configured for both hosts.
AnswerA

The pool is referenced without the overload keyword, and the statistics confirm zero extended translations. Each inside host therefore consumes a distinct global address from POOL1, with no port multiplexing, exactly as the two simple dynamic entries show.

Why this answer

The output shows two dynamic NAT translations, each with a unique inside global address (192.0.2.10 and 192.0.2.11) mapped to different inside local addresses (10.0.0.10 and 10.0.0.11). The absence of any port numbers in the 'Pro' column indicates that Port Address Translation (PAT) is not used; instead, each inside host receives a one-to-one mapping to a unique public IP from the pool. This confirms standard dynamic NAT without PAT.

Exam trap

Cisco often tests the distinction between NAT and PAT by hiding port numbers in the 'Pro' column; candidates mistakenly assume PAT is active when they see multiple translations, but the absence of port numbers and the presence of unique global addresses clearly indicate standard dynamic NAT.

How to eliminate wrong answers

Option B is wrong because PAT would show port numbers in the 'Pro' column and typically multiple inside hosts share a single global address, but here each host has a unique global address with no port information. Option C is wrong because the pool (192.0.2.10–192.0.2.20) has 16 addresses, and only two are used, so it is far from exhausted. Option D is wrong because the 'show ip nat statistics' explicitly states '0 static' and '2 dynamic', and the configuration references an ACL and pool, confirming dynamic NAT, not static NAT.

1113
MCQhard

A large enterprise network is experiencing intermittent reachability to a subnet 10.1.1.0/24 from the rest of the network. Router R1 has the following relevant configuration: router eigrp 100 redistribute ospf 1 metric 10000 100 255 1 1500 ! router ospf 1 redistribute eigrp 100 subnets summary-address 10.0.0.0 255.255.0.0 ! interface GigabitEthernet0/0 ip summary-address eigrp 100 10.0.0.0 255.255.0.0 5 Router R2 shows: R2# show ip route 10.1.1.0 Routing entry for 10.0.0.0/16, supernet Known via "eigrp 100", distance 90, metric 128256 Redistributing via eigrp 100 Last update from 10.10.10.1 on GigabitEthernet0/1 What is the root cause?

A.The OSPF summary-address command on R1 is blocking the redistribution of the specific /24 route.
B.The EIGRP metric values are too high, causing the route to be unreachable.
C.The redistribute ospf command under EIGRP is missing the subnets keyword.
D.The route is being filtered by a distribute-list on R2.
AnswerA

The OSPF summary-address creates an aggregate route, and combined with the EIGRP interface summary, the specific /24 is suppressed.

Why this answer

The issue is that R1 has both an OSPF summary-address and an EIGRP interface summary-address, causing the more specific /24 route to be suppressed by the /16 summary. The EIGRP summary-address command on the interface creates a null0 summary route, and the OSPF redistribution of the EIGRP summary further aggregates, losing the specific prefix. The fix is to remove the interface summary-address or adjust the summary to include the specific subnet.

1114
MCQeasy

A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue: R1# show access-lists 120 Extended IP access list 120 10 permit tcp 192.168.1.0 0.0.0.255 any eq 80 20 permit tcp 192.168.2.0 0.0.0.255 any eq 443 30 deny ip any any log What does this output indicate?

A.The ACL permits HTTP traffic from 192.168.1.0/24 and HTTPS traffic from 192.168.2.0/24, and denies all other traffic with logging.
B.The ACL permits all traffic from 192.168.1.0/24 and 192.168.2.0/24.
C.The ACL denies all traffic from 192.168.1.0/24 and 192.168.2.0/24.
D.The ACL is applied inbound on an interface and is blocking all traffic.
AnswerA

Sequence 10 permits TCP port 80 from 192.168.1.0/24, sequence 20 permits TCP port 443 from 192.168.2.0/24, and sequence 30 denies all remaining IP traffic while generating log entries. The implicit deny is made explicit and auditable by the log keyword.

Why this answer

The output shows an extended ACL with two permit statements: the first permits TCP traffic from 192.168.1.0/24 to any destination on port 80 (HTTP), and the second permits TCP traffic from 192.168.2.0/24 to any destination on port 443 (HTTPS). The final deny ip any any log statement explicitly denies all other IP traffic and logs matches, which is standard practice for ACL troubleshooting. Therefore, option A correctly describes the ACL's behavior.

Exam trap

Cisco often tests the ability to read ACL output precisely, and the trap here is that candidates may overlook the specific port restrictions (eq 80 and eq 443) and assume the ACL permits all traffic from the source networks, or misinterpret the 'log' keyword as affecting the permit/deny action.

How to eliminate wrong answers

Option B is wrong because the ACL does not permit all traffic from the specified subnets; it only permits HTTP from 192.168.1.0/24 and HTTPS from 192.168.2.0/24, and denies everything else. Option C is wrong because the ACL does not deny traffic from those subnets; it explicitly permits specific traffic from them. Option D is wrong because the output does not indicate where the ACL is applied (inbound or outbound) or that it is blocking all traffic; it only shows the ACL's configured entries, and the implicit deny at the end is standard, not a sign of blocking all traffic.

1115
MCQhard

A network engineer is configuring a Cisco IOS XE router as a LISP ITR. The router must encapsulate traffic from local EIDs to remote RLOCs. Which command is required to enable LISP functionality and allow the router to act as an ITR?

A.router lisp
B.lisp itr enable
C.feature lisp
D.ipv4 lisp
AnswerA

The router lisp command enters LISP configuration mode, where you can enable ITR functionality, define EID-to-RLOC database mappings, and configure map-resolvers. Without this global command, LISP processes are not activated, and the router cannot encapsulate or decapsulate LISP traffic. It is the foundational step for any LISP role.

Why this answer

On Cisco IOS XE, LISP is enabled by entering the router lisp global configuration command. This mode allows you to configure the router as an ITR, ETR, or both, and to define EID-to-RLOC mappings and map-resolvers. The other commands are either invalid in this context or belong to different platforms, so they would not enable LISP functionality.

Exam trap

The trap here is confusing the IOS XE command with NX-OS feature commands or assuming that the ITR enable command can be issued globally, when the correct entry point is the router lisp submode.

1116
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip vrf interfaces Interface VRF IP Address Protocol GigabitEthernet0/0 BLUE 10.1.1.1 up GigabitEthernet0/1 BLUE 10.1.2.1 up GigabitEthernet0/2 RED 192.168.1.1 up Loopback0 BLUE 10.0.0.1 up Loopback1 RED 192.168.0.1 up Based on this output, which statement is correct?

A.All interfaces are in the global routing table.
B.GigabitEthernet0/2 is in VRF RED with IP address 192.168.1.1.
C.Loopback0 is in VRF RED.
D.GigabitEthernet0/1 has IP address 10.1.2.2.
AnswerB

GigabitEthernet0/2 is bound to VRF RED and holds 192.168.1.1, exactly as the `show ip vrf interfaces` output lists it. The command maps each interface to its VRF and assigned address, so the RED row confirms both the VRF membership and the IP, satisfying the question's requirement to interpret the table directly.

Why this answer

The 'show ip vrf interfaces' command displays all interfaces assigned to VRFs and their IP addresses. The output shows that GigabitEthernet0/0, GigabitEthernet0/1, and Loopback0 are in VRF BLUE, while GigabitEthernet0/2 and Loopback1 are in VRF RED. There are no interfaces in the global routing table shown here, but that is normal for VRF-Lite.

1117
Drag & Drophard

Drag and drop the steps to troubleshoot a BFD adjacency or connectivity failure into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Start by checking basic IP connectivity to isolate layer 3 issues, then verify BFD parameters match on both sides, inspect BFD session state, check for interface or routing protocol mismatches, and finally enable debug to capture BFD packet exchange.

1118
MCQmedium

A network engineer is deploying GET VPN with Cisco IOS routers to provide any-to-any encrypted communication over a private MPLS WAN. The design requires that a router joining the group automatically receives the current group security policy from the group controller without any manual pre-shared key configuration on the member. Which protocol should the engineer configure to dynamically distribute the group encryption keys from the key server to the group members?

A.GDOI
B.IKEv2
C.ISAKMP
D.NHRP
AnswerA

GDOI is the group key management protocol used by GET VPN. The key server acts as the group controller/key server, and group members register with it using a group identity and IKE phase 1, then receive the rekey messages containing the IPsec SA policy and TEK/KEK keys. This allows automatic, scalable key distribution without per-member manual pre-shared key configuration, matching the scenario requirement exactly.

Why this answer

GET VPN relies on GDOI for group key management. The key server (group controller/key server) distributes the group security policy and encryption keys to registered group members via rekey messages, enabling scalable any-to-any encryption over a private WAN without point-to-point tunnels. GDOI is the protocol that dynamically distributes the group encryption keys, satisfying the requirement for automatic key delivery without manual pre-shared key configuration on each member.

Exam trap

The trap here is confusing the IKE phase 1 protocol used for registration with the group key management protocol that actually distributes the group encryption keys.

1119
MCQmedium

In IPv6 First Hop Security, what is the purpose of the 'device-role' command in a DHCP guard policy?

A.It specifies whether the interface is a server, client, or relay for DHCP filtering.
B.It sets the trust level for ND inspection.
C.It defines the VLAN membership for the interface.
D.It enables IPv6 routing on the interface.
AnswerA

The device-role command defines the trusted DHCP role for an interface within the DHCP guard policy, permitting server or relay messages only where expected. This satisfies the stem's requirement by enabling the switch to filter rogue DHCP advertisements, ensuring clients receive addressing solely from legitimate servers.

Why this answer

The 'device-role' command in a DHCP guard policy specifies the role of the interface as either a DHCP server, client, or relay. This allows the switch to filter DHCP messages based on the expected role, blocking unauthorized DHCP server messages on interfaces that should only have clients or relays. It is a key component of IPv6 First Hop Security to prevent rogue DHCPv6 servers.

Exam trap

Cisco often tests the distinction between DHCP guard and other First Hop Security features like RA guard or ND inspection, so candidates may confuse the 'device-role' command with trust settings for ND or RA messages.

How to eliminate wrong answers

Option B is wrong because the 'device-role' command is specific to DHCP guard, not ND inspection; ND inspection uses the 'nd inspection' command and trust settings. Option C is wrong because VLAN membership is configured with the 'switchport access vlan' or 'vlan' commands, not with a DHCP guard policy. Option D is wrong because IPv6 routing is enabled globally with 'ipv6 unicast-routing' or on an interface with 'ipv6 enable', not through a DHCP guard policy.

1120
MCQhard

A network engineer runs the following command to troubleshoot an EEM issue: R1# show event manager environment all No. Variable Name Value 1 _exit_status 1 2 _event_type syslog 3 _syslog_msg %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.2 on GigabitEthernet0/0 from LOADING to FULL, Loading Done 4 _syslog_severity 5 5 _syslog_facility OSPF 6 _syslog_mnemonic ADJCHG What does this output indicate?

A.The environment variables show that a syslog event with mnemonic ADJCHG triggered, and the applet can use these variables in actions.
B.The environment variables are configured manually by the engineer to define the applet behavior.
C.The output shows the current state of all EEM applets and their variables.
D.The _exit_status variable indicates the applet failed to execute.
AnswerA

The output lists EEM environment variables populated from a matched syslog event, including _syslog_mnemonic ADJCHG and _syslog_severity 5. These built-in variables are passed to the applet, letting its actions reference the triggering OSPF adjacency change without parsing the raw message.

Why this answer

The output shows the EEM environment variables that are set when an event triggers an applet. These variables contain information about the event, such as the event type, syslog message details, and exit status. This is useful for debugging applets that use these variables in their actions.

1121
MCQmedium

Which EIGRP packet type is used to confirm receipt of a route update during reliable transport?

A.Hello
B.Update
C.ACK
D.Query
AnswerC

EIGRP uses a distinct ACK packet to acknowledge received updates, sequence numbers and hello packets over RTP. Unlike the Update packet, which carries routing data, the ACK confirms receipt without payload, satisfying the reliable transport confirmation requirement in the stem.

Why this answer

EIGRP uses ACK packets (which are Hello packets with no data) to acknowledge reliable updates.

1122
Multi-Selecthard

Which TWO statements correctly describe the use of IKEv2 for IPsec site-to-site VPNs? (Choose TWO.)

Select 2 answers
A.IKEv2 uses UDP port 500 and 4500 for NAT traversal.
B.IKEv2 supports only pre-shared keys for authentication.
C.IKEv2 uses aggressive mode to establish the IKE SA.
D.IKEv2 can authenticate using EAP (Extensible Authentication Protocol).
E.The default IKEv2 SA lifetime is 3600 seconds.
AnswersA, D

IKEv2 negotiates its security associations over UDP port 500, while port 4500 carries traffic encapsulated in NAT-Traversal once a NAT device is detected along the path. This satisfies the stem's requirement for a correct IKEv2 site-to-site VPN statement, since both ports are integral to IKEv2 operation.

Why this answer

Option A is correct because IKEv2 negotiates its IKE_SA_INIT exchanges over UDP port 500, and when a NAT device is detected between the peers it switches to UDP port 4500 (NAT-Traversal encapsulation) for the IKE_AUTH and subsequent exchanges. Option D is correct because IKEv2 natively supports EAP as an authentication method (EAP-IKEv2, EAP-MSCHAPv2, EAP-TLS, etc.), which is one of its key enhancements over IKEv1 and enables flexible user/device authentication for site-to-site and remote-access IPsec. Option B is wrong because IKEv2 supports multiple authentication methods including pre-shared keys, RSA/ECDSA digital signatures, and EAP, not PSK only.

Option C is wrong because aggressive mode is an IKEv1 main-mode alternative; IKEv2 replaced it with a simpler two-exchange (IKE_SA_INIT and IKE_AUTH) process and does not use aggressive mode. Option E is wrong because the default IKEv2 SA (IKE SA) lifetime is typically 24 hours (86400 seconds) on many implementations, not 3600 seconds, which is a common default for the IPsec child SA (Phase 2) lifetime.

Exam trap

Cisco often tests the misconception that IKEv2 uses aggressive mode (like IKEv1) or that its default SA lifetime is 3600 seconds, when in fact IKEv2 uses a simpler exchange and a 24-hour default lifetime.

1123
MCQmedium

A network engineer runs the following command to troubleshoot OSPF route filtering: R1# show ip ospf database router 2.2.2.2 OSPF Router with ID (1.1.1.1) (Process ID 1) Router Link States (Area 0) LS age: 300 Options: (No TOS-capability, DC) LS Type: Router Links Link State ID: 2.2.2.2 Advertising Router: 2.2.2.2 LS Seq Number: 80000004 Checksum: 0x1234 Length: 48 Number of Links: 2 Link connected to: a Stub Network (Link ID) Network/subnet number: 10.1.1.0 (Link Data) Network Mask: 255.255.255.0 Number of TOS metrics: 0 TOS 0 Metrics: 10 Link connected to: a Transit Network (Link ID) Designated Router address: 10.1.1.2 (Link Data) Router Interface address: 10.1.1.1 Number of TOS metrics: 0 TOS 0 Metrics: 10 What does this output indicate?

A.Router 2.2.2.2 is advertising two links, one of which is a stub network 10.1.1.0/24.
B.Router 2.2.2.2 is filtering routes from area 0.
C.Router 2.2.2.2 is a DR for the transit network.
D.Router 2.2.2.2 has a mismatched area ID.
AnswerA

The Router Link States entry for 2.2.2.2 lists Number of Links: 2, with the first link described as a Stub Network whose Link ID is 10.1.1.0 and mask 255.255.255.0, giving 10.1.1.0/24. This matches the option exactly.

Why this answer

The output shows the OSPF router LSA from router 2.2.2.2. It lists two links: one stub network (10.1.1.0/24) and one transit network (via DR 10.1.1.2). This is normal OSPF operation.

1124
MCQhard

A network administrator is deploying a GET VPN using Cisco IOS routers. The key server is configured with a cooperative key server (COOP) for redundancy. The administrator notices that some group members are not registering with the primary key server. Which protocol and port must be allowed through the firewall for the group members to register with the key server?

A.GDOI on UDP port 848
B.ISAKMP on UDP port 500
C.IPsec ESP on IP protocol 50
D.NAT-T on UDP port 4500
AnswerA

GET VPN group members use the GDOI protocol to register with the key server. GDOI operates on UDP port 848. Allowing this port through the firewall is essential for group members to register and receive keys and policies from the key server.

Why this answer

GET VPN group members use GDOI on UDP port 848 to register with the key server. This port must be permitted through firewalls to allow registration and key retrieval.

Exam trap

The trap here is assuming GET VPN uses standard IPsec ports like UDP 500 or 4500 for registration, when it actually uses GDOI on UDP 848.

1125
MCQhard

A network engineer is configuring MPLS Traffic Engineering (TE) with RSVP-TE on a Cisco IOS XE router. The engineer wants to establish a TE tunnel from Router A to Router D. The path must be explicitly defined to go through Router B and then Router C. The engineer has configured the tunnel interface with the destination and an explicit path. However, the tunnel is not coming up. Which command is required to enable RSVP-TE on the core interfaces of Router A, B, C, and D?

A.mpls ldp router-id Loopback0 force
B.mpls traffic-eng tunnels
C.ip rsvp bandwidth
D.mpls traffic-eng tunnel-te 1
AnswerC

The ip rsvp bandwidth command must be configured on each core interface that will participate in RSVP-TE. This command enables RSVP on the interface and allocates a percentage or absolute amount of bandwidth for TE reservations. Without it, RSVP messages are not sent or processed on that interface, and the TE tunnel cannot be signaled. Therefore, this is the required interface-level command to enable RSVP-TE on the core links.

Why this answer

For RSVP-TE to signal a TE tunnel, RSVP must be enabled on every interface along the path. This is done with the ip rsvp bandwidth command, which also allocates bandwidth for reservations. While global MPLS TE commands and tunnel interface configuration are necessary, they do not activate RSVP on the physical links.

The tunnel will remain down if RSVP is not enabled on the core interfaces. Therefore, the correct answer is the interface-level command that enables RSVP and sets the reservable bandwidth.

Exam trap

The trap here is assuming that enabling MPLS TE globally or configuring the tunnel interface is enough, but RSVP signaling requires explicit interface-level enablement with bandwidth allocation.

Page 14

Page 15 of 19

Page 16